Jacques Louw

31 posts

Jacques Louw

Jacques Louw

@jacques_sec

Co-founder @pushsecurity

South Africa เข้าร่วม Kasım 2017
66 กำลังติดตาม68 ผู้ติดตาม
Jacques Louw
Jacques Louw@jacques_sec·
If you're interested in defending against Cyberhaven-style attacks against browser extension vendors, I wrote a guide around hardening browser extension deployments you might find interesting: pushsecurity.com/blog/guide-to-…
English
0
0
1
32
Jacques Louw รีทวีตแล้ว
Luke Jennings
Luke Jennings@jukelennings·
1/ A new class of phishing - how verification phishing and cross-idp impersonation can bypass your SSO. Here is a video demo, but this is one where you really need to read the full article too - pushsecurity.com/blog/a-new-cla… I'll summarize the key points in this thread.
English
5
19
54
7K
Jacques Louw รีทวีตแล้ว
Luke Jennings
Luke Jennings@jukelennings·
I wrote a blog post on the many defense mechanisms phishing kits are using to avoid discovery and analysis now. I used a recent instance of NakedPages and cover 9 different techniques, including Cloudflare Workers and Turnstile abuse. IOCs included. pushsecurity.com/blog/how-aitm-…
English
0
33
76
6K
Jacques Louw
Jacques Louw@jacques_sec·
@jukelennings Having seen the details I think these malware devs need to invest in a good PM and some integration testing 😅 Can't wait for the full write up!
English
0
0
0
28
Luke Jennings
Luke Jennings@jukelennings·
1/ It’s fascinating how many layers of protection even poorly written AiTM phishing kits put in place to frustrate discovery now. I’m talking about the type of kit where the authors forgot to implement the JS encryption function placeholder they wrote so it returns clear text😂
English
2
2
3
365
Jacques Louw รีทวีตแล้ว
Adam Bateman //O
Adam Bateman //O@ajaybateman·
Now you can detect and block identity attacks directly inside any web browser. 1. Stop corp password reuse and phishing 2. Detect EvilGinx/EvilNoVNC 3. Session Hijacking detection ... and more. Hear the full announcement on @riskybusiness risky.biz/snakeoilers19p…
Adam Bateman //O tweet media
English
0
8
11
2.2K
Jacques Louw รีทวีตแล้ว
Push
Push@PushSecurity·
Great interview with our CEO and co-founder @ajaybateman and @dspark on @CISOseries about "Securing identity in the age of self-service" "It's about creating a paved path for employees to walk..." Link in 🧵!
English
1
2
8
309
Jacques Louw รีทวีตแล้ว
Luke Jennings
Luke Jennings@jukelennings·
1/ I kinda accidentally owned myself with my own shadow workflow attack. I definitely think they are going to become a standard technique. I mean they are pretty much the offensive powershell of the SaaS world! So how did this happen?
English
1
6
10
774
Jacques Louw รีทวีตแล้ว
Push
Push@PushSecurity·
👋 New feature alert! Classify SaaS apps in the Push platform based on the sensitivity of the data they contain or the permissions they've been granted. Use the Approval status to capture your decision about an app -- is it in or out? Link in 🧵 #SaaSsecurity #security
GIF
English
2
3
7
635
Jacques Louw รีทวีตแล้ว
Luke Jennings
Luke Jennings@jukelennings·
I’ve just released some research into 38 SaaS-native attack techniques across the kill chain and produced a SaaS attack matrix to go along with it. github.com/pushsecurity/s… This is just the beginning but my hope is this will become an ongoing community project.
English
1
40
78
12.2K
Jacques Louw รีทวีตแล้ว
Push
Push@PushSecurity·
📣 NEW FEATURE ALERT - Uncover shared SaaS accounts Tldr - Push can now show you which app accounts are being used by multiple employees and who's using them. #shadowit #security #infosec #rogueit #RiskManagement Give it a try for free: buff.ly/40jLC7Z
GIF
English
0
2
3
169
Jacques Louw รีทวีตแล้ว
Push
Push@PushSecurity·
Some amazing praise from Jason Waits, CISO at Inductive Automation on why we won their POC. His comments on our user-centric approach made our day! 🙌
Push tweet media
English
0
3
10
0
Jacques Louw รีทวีตแล้ว
Push
Push@PushSecurity·
Managed browser extension deployments are here! You can now be up and running with Push, with all of your employees onboarded, in minutes. buff.ly/3TjcKBR #SaaSsecurity #cloudsecurity
GIF
English
0
2
5
0
Jacques Louw รีทวีตแล้ว
Push
Push@PushSecurity·
Stop blocking. Instead, equip employees to secure their SaaS. There's a better approach to securing SaaS than simply blocking and restricting unsanctioned apps buff.ly/3wCuzlT #SaaSsecurity #CASB #infosec
Push tweet media
English
0
2
10
0
Jacques Louw รีทวีตแล้ว
Push
Push@PushSecurity·
Here's a quick guide to finding the right SaaS security solution for your company. It's basically a choose-your-own-adventure for finding a good fit for your specific use case, infrastructure, and data. buff.ly/3cHHjAk #SaaSSecurity #CloudSecurity
Push tweet media
English
0
2
3
0