Luke Bailiff

808 posts

Luke Bailiff

Luke Bailiff

@lukebailiff

Katılım Mayıs 2009
263 Takip Edilen34 Takipçiler
Andrew Thompson
Andrew Thompson@ImposeCost·
Listen, if this much supply chain compromise is happening, that says something about the supply chain.
English
15
10
135
8.6K
Luke Bailiff
Luke Bailiff@lukebailiff·
@WarMonitor3 It sounds like it was agreed upon as the anchor to negotiate off of. Thats it.
English
0
0
0
235
Zack Korman
Zack Korman@ZackKorman·
The Delve stuff is bad, but all of these compliance platforms (Vanta, Drata, etc) have their "trusted auditors" they recommend. That is the core issue that corrupts this space.
Zack Korman tweet media
English
22
8
202
20.4K
Luke Bailiff
Luke Bailiff@lukebailiff·
@UK_Daniel_Card Probably want to Control this setting if you allow claude: To enable it automatically for every session, run /config inside Claude Code and set Enable Remote Control for all sessions to true. Set it back to false to disable.
English
0
0
1
57
Luke Bailiff
Luke Bailiff@lukebailiff·
ATTN: web app developers. An oldie but still relevant. - client side input filtering is for user experience - server side input filtering is for security You MAY do client side input filtering. You SHALL do server side input filtering
English
0
0
0
14
Luke Bailiff
Luke Bailiff@lukebailiff·
The Pentesters that were stuck in a local political battle between the state of iowa and dallas county governments were awarded 600k for their lawsuit. arstechnica.com/security/2026/…
English
0
1
2
352
Luke Bailiff
Luke Bailiff@lukebailiff·
Very cool idea. AI can speed things up but presents risk. This is a way to reduce that risk and hopefully get consistent results that still speed up processes. Should be able to use this with your locally approved AI too.
Kostas@Kostastsale

𝗝𝘂𝘀𝘁 𝗹𝗮𝘂𝗻𝗰𝗵𝗲𝗱 𝗮𝘄𝗲𝘀𝗼𝗺𝗲-𝗱𝗳𝗶𝗿-𝘀𝗸𝗶𝗹𝗹𝘀 𝘄𝗶𝘁𝗵 @fr0gger_ ! Designed to save time during investigations and everyday DFIR tasks Thomas has built an excellent malware triage skill, and I’ve added a couple of timeline analysis skills to help you get started. Feel free to contribute and use these skills to save a ton of time, like we already do. github.com/tsale/awesome-… Learn about skills: - developers.openai.com/codex/skills/ - support.claude.com/en/articles/12…

English
0
0
2
25
Luke Bailiff retweetledi
Kostas
Kostas@Kostastsale·
𝗝𝘂𝘀𝘁 𝗹𝗮𝘂𝗻𝗰𝗵𝗲𝗱 𝗮𝘄𝗲𝘀𝗼𝗺𝗲-𝗱𝗳𝗶𝗿-𝘀𝗸𝗶𝗹𝗹𝘀 𝘄𝗶𝘁𝗵 @fr0gger_ ! Designed to save time during investigations and everyday DFIR tasks Thomas has built an excellent malware triage skill, and I’ve added a couple of timeline analysis skills to help you get started. Feel free to contribute and use these skills to save a ton of time, like we already do. github.com/tsale/awesome-… Learn about skills: - developers.openai.com/codex/skills/ - support.claude.com/en/articles/12…
English
8
81
360
28.4K
Luke Bailiff
Luke Bailiff@lukebailiff·
@ImposeCost I was thinking the same thing. Why were we not already doing this? Was there some sort of peace deal with ISIS that I missed?
English
0
0
1
17
Andrew Thompson
Andrew Thompson@ImposeCost·
My thing is I don't necessarily get "retaliatory strikes" against entities like ISIS. If you know where ISIS is, you prosecute the target continuously and not in response to them killing our people.
U.S. Central Command@CENTCOM

U.S. Forces Unleash Massive Strike Against ISIS in Syria TAMPA, Fla. – U.S. forces have commenced a large-scale strike against ISIS infrastructure and weapons sites in Syria. This massive strike follows the attack on U.S. and partner forces in Syria on Dec. 13. We will provide additional information soon.

English
2
2
28
3.2K
Luke Bailiff retweetledi
Bipul Sinha
Bipul Sinha@bipulsinha·
This. is. big. Rubrik launches Rubrik Agent Cloud to accelerate Enterprise AI Agent deployments. rubrik.com/products/rubri…
GIF
English
4
6
41
11K
Luke Bailiff
Luke Bailiff@lukebailiff·
Great overview of forensic artifacts related to rdp on both client and server.
Mathias Fuchs@mathias_fuchs

Attackers love RDP for sneaky lateral moves—but every pixel leaves a clue! 🕵️‍♂️ Check out my latest blog on tracking attackers through logs, bitmap caches, and clipboard trails (plus a printer tale too funny to miss). #DFIR #BlueTeam #CyberSecurity @mathias.fuchs/chasing-ghosts-over-rdp-lateral-movement-in-tiny-bitmaps-328d2babd8ec" target="_blank" rel="nofollow noopener">medium.com/@mathias.fuchs…

English
0
0
1
34
Luke Bailiff retweetledi
Fabian Bader
Fabian Bader@fabian_bader·
Exposing your multi tenant service principal secret to everybody is not just bad security but it’s completely wrong. Great finding by @_harleo - Sad to see that @Synology handled the disclosure so badly. Use managed identities! modzero.com/en/blog/when-b…
English
0
11
56
2.9K
Luke Bailiff
Luke Bailiff@lukebailiff·
$20 million reward fund. Extortionist requested 20 million. Instead of paying, coinbase set up a reward fund for information leading to the Extortionist. coinbase.com/blog/protectin…
English
0
0
0
93
Luke Bailiff retweetledi
Jai Minton
Jai Minton@CyberRaiju·
I've confirmed Samsung's MagicINFO 21.1050 is VULNERABLE to the publicly reported POC in the blog below. ssd-disclosure.com/ssd-advisory-s… The media is reporting this as CVE-2024-7399, but if it is then the patch is incomplete. There is currently NO PATCH AVAILABLE!
English
2
22
51
15.2K
Luke Bailiff retweetledi
4n6lady
4n6lady@4n6lady·
It’s Monday, and you know what that means? A fresh new week of chaos in IR. Here are some real red flags I’ve come across in AWS environments while investigating security events — the kind that make my brain twitch 🧠⚡👇
English
4
51
271
25.5K