c0rdis ری ٹویٹ کیا
c0rdis
571 posts

c0rdis ری ٹویٹ کیا

#GhostSec claims to have conducted the first ever #ransomwwre attack against an RTU - remote terminal unit used in ICS environments.
@uuallan @RobertMLee
#cybersecurity #infosecurity #infosec #cyber




English
c0rdis ری ٹویٹ کیا
c0rdis ری ٹویٹ کیا
c0rdis ری ٹویٹ کیا
c0rdis ری ٹویٹ کیا
c0rdis ری ٹویٹ کیا
c0rdis ری ٹویٹ کیا

Deep link on mobile app ➡️ Host-relative SSRF ➡️ Account takeover 🦾 (affecting @Pinterest) dphoeniixx.com/2020/12/13-2/

English
c0rdis ری ٹویٹ کیا
c0rdis ری ٹویٹ کیا

Security Budgets - Supply and Demand Thinking
Think of budgeting as a supply & demand problem. Work both sides to make it a risk management exercise. It will bring clarity of thought and illustrates to your business that you are thinking commercially.
bit.ly/3joAqlp

English
c0rdis ری ٹویٹ کیا
c0rdis ری ٹویٹ کیا

Without formal access, a college kid got hold of @OpenAI's GPT-3 and created a fake, AI-generated blog under a fake name. Within hours, his first post reached #1 on @newsycombinator. A case study in how people could (ab)use the model in the future. technologyreview.com/2020/08/14/100…
English
c0rdis ری ٹویٹ کیا

🛡️ Sensitive data leakage using .json 🛡️
#cybersecurity #infosec #ethicalhacking #bugbounty #bugbountytips #bugbountytip

English
c0rdis ری ٹویٹ کیا

For 327 days, the impostor site privnotes.com has been stealing traffic/privacy/users from privnote.com, a legit encrypted msg service. Worse: KrebsOnSecurity found privnotes.com also will alter bitcoin addresses in messages. krebsonsecurity.com/2020/06/privno…

English
c0rdis ری ٹویٹ کیا
c0rdis ری ٹویٹ کیا

From the 15th-19th of June 2020, we will be bringing the best security minds together to take our participants on a unique experience.
All sessions will be recorded, LIVE streamed and shared : )
To register, head over to …en-security-summit-2020.heysummit.com/checkout/selec…

English
c0rdis ری ٹویٹ کیا

I am just watching a great presentation about security & #WardleyMapping by @madplatt.
My notes are here, feel free to add notion.so/kdaniel/Evolut…
English
c0rdis ری ٹویٹ کیا

We're excited to release TerraGoat, a vulnerable-by-design training tool for #Terraform! 🐐
📑 Read more about why we built TerraGoat: bridge.dev/2XdwAlz
⭐ Check it out on GitHub: bridge.dev/3bLgOUt

English
c0rdis ری ٹویٹ کیا

We chased an attacker in #AWS and want to share the story.
Our blog covers:
🔍 Initial lead w/ #CloudTrail
🕵️ Investigative approach
🤖 Use of orchestration "robots" to respond faster
✅ Steps to improve
☁️ #Mitre ATT&CK Cloud Tactics? 👍 Those too!
expel.io/blog/finding-e…
Jon Hencinski@jhencinski
Highlights from chasing an attacker in #AWS this week: Initial lead: custom alert using #CloudTrail - SSH keygen from weird source IP enrichment helped Historical context for IAM user, "this isn't normal" #GuardDuty was not initial lead - Did have LOW sev high vol alerts
English












