c0rdis 리트윗함
c0rdis
571 posts

c0rdis 리트윗함

#GhostSec claims to have conducted the first ever #ransomwwre attack against an RTU - remote terminal unit used in ICS environments.
@uuallan @RobertMLee
#cybersecurity #infosecurity #infosec #cyber




English
c0rdis 리트윗함
c0rdis 리트윗함
c0rdis 리트윗함
c0rdis 리트윗함
c0rdis 리트윗함
c0rdis 리트윗함

Deep link on mobile app ➡️ Host-relative SSRF ➡️ Account takeover 🦾 (affecting @Pinterest) dphoeniixx.com/2020/12/13-2/

English
c0rdis 리트윗함
c0rdis 리트윗함

Security Budgets - Supply and Demand Thinking
Think of budgeting as a supply & demand problem. Work both sides to make it a risk management exercise. It will bring clarity of thought and illustrates to your business that you are thinking commercially.
bit.ly/3joAqlp

English
c0rdis 리트윗함
c0rdis 리트윗함

Without formal access, a college kid got hold of @OpenAI's GPT-3 and created a fake, AI-generated blog under a fake name. Within hours, his first post reached #1 on @newsycombinator. A case study in how people could (ab)use the model in the future. technologyreview.com/2020/08/14/100…
English
c0rdis 리트윗함

🛡️ Sensitive data leakage using .json 🛡️
#cybersecurity #infosec #ethicalhacking #bugbounty #bugbountytips #bugbountytip

English
c0rdis 리트윗함

For 327 days, the impostor site privnotes.com has been stealing traffic/privacy/users from privnote.com, a legit encrypted msg service. Worse: KrebsOnSecurity found privnotes.com also will alter bitcoin addresses in messages. krebsonsecurity.com/2020/06/privno…

English
c0rdis 리트윗함
c0rdis 리트윗함

From the 15th-19th of June 2020, we will be bringing the best security minds together to take our participants on a unique experience.
All sessions will be recorded, LIVE streamed and shared : )
To register, head over to …en-security-summit-2020.heysummit.com/checkout/selec…

English
c0rdis 리트윗함

I am just watching a great presentation about security & #WardleyMapping by @madplatt.
My notes are here, feel free to add notion.so/kdaniel/Evolut…
English
c0rdis 리트윗함

We're excited to release TerraGoat, a vulnerable-by-design training tool for #Terraform! 🐐
📑 Read more about why we built TerraGoat: bridge.dev/2XdwAlz
⭐ Check it out on GitHub: bridge.dev/3bLgOUt

English
c0rdis 리트윗함

We chased an attacker in #AWS and want to share the story.
Our blog covers:
🔍 Initial lead w/ #CloudTrail
🕵️ Investigative approach
🤖 Use of orchestration "robots" to respond faster
✅ Steps to improve
☁️ #Mitre ATT&CK Cloud Tactics? 👍 Those too!
expel.io/blog/finding-e…
Jon Hencinski@jhencinski
Highlights from chasing an attacker in #AWS this week: Initial lead: custom alert using #CloudTrail - SSH keygen from weird source IP enrichment helped Historical context for IAM user, "this isn't normal" #GuardDuty was not initial lead - Did have LOW sev high vol alerts
English












