Okta: Give me a HAR and we’ll let you know when we find out from other customers.
Helpful context: www.beyondtrust.com/blog/entry/o...
Much less helpful context response: sec.okta.com/harfiles
Okta: Give me a HAR and we’ll let you know when we find out from other customers.
Helpful context: www.beyondtrust.com/blog/entry/o...
Much less helpful context response: sec.okta.com/harfiles
r.mtdv.me/TrustThis
r.mtdv.me/TrustThis
I'm very biased but I think we're a great team in the D&R space across a production & corporate environment. Big fans of open sourcing projects, managing components via source control where possible
I'm very biased but I think we're a great team in the D&R space across a production & corporate environment. Big fans of open sourcing projects, managing components via source control where possible
permiso.io/blog/lucr-3-...
permiso.io/blog/lucr-3-...
Substation v0.9.2 is here: github.com/brexhq/substation/d…
In addition to a new bitmath inspector I wrote, this release brings some QoL improvements, let us know if you find use-cases for these additions. XDR onwards!
Substation v0.9.2 is here: github.com/brexhq/substation/d…
In addition to a new bitmath inspector I wrote, this release brings some QoL improvements, let us know if you find use-cases for these additions. XDR onwards!
.app
.boo
.channel
.dad
.day
.dev
.esq
.foo
.how
.mov
.new
.nexus
.page
.phd
.prof
.rsvp
.soy
A simple detection for command lines w/ “security find-generic-password
https://iamdeadlyz.gitbook.io/malware-research/july-2023/fake-blockchain-games-deliver-redline-stealer-and-realst-stealer-a-new-macos-infostealer-malware#realst-stealer-macos
A simple detection for command lines w/ “security find-generic-password
https://iamdeadlyz.gitbook.io/malware-research/july-2023/fake-blockchain-games-deliver-redline-stealer-and-realst-stealer-a-new-macos-infostealer-malware#realst-stealer-macos
https://www.mandiant.com/resources/blog/north-korea-supply-chain
https://www.mandiant.com/resources/blog/north-korea-supply-chain
- https://permiso.io/blog/s/agile-approach-to-mass-cloud-cred-harvesting-and-cryptomining/
- https://www.sentinelone.com/labs/cloudy-with-a-chance-of-credentials-aws-targeting-cred-stealer-expands-to-azure-gcp/
- https://permiso.io/blog/s/agile-approach-to-mass-cloud-cred-harvesting-and-cryptomining/
- https://www.sentinelone.com/labs/cloudy-with-a-chance-of-credentials-aws-targeting-cred-stealer-expands-to-azure-gcp/
https://vertex.link/blogs/mitre-attack/
- 2 talks on DPRK malware analysis
- 1 talk from Kaspersky on Triangulation (🦅)
- ... and more on bug hunting across the OS and user applications!
- 2 talks on DPRK malware analysis
- 1 talk from Kaspersky on Triangulation (🦅)
- ... and more on bug hunting across the OS and user applications!
iOS: https://support.apple.com/en-us/HT213823
macOS: https://support.apple.com/en-us/HT213825
iOS: https://support.apple.com/en-us/HT213823
macOS: https://support.apple.com/en-us/HT213825
https://posts.specterops.io/sowing-chaos-and-reaping-rewards-in-confluence-and-jira-7a90ba33bf62
https://posts.specterops.io/sowing-chaos-and-reaping-rewards-in-confluence-and-jira-7a90ba33bf62
I added the mdls command used by common adware like Genio
I added the mdls command used by common adware like Genio
New *OS releases (see https://support.apple.com/en-us/HT213814) from today include a mention of the Kaspersky team for CVE-2023-32434 so it seems like there was some level of 0-day with the Triangulation attack
New *OS releases (see https://support.apple.com/en-us/HT213814) from today include a mention of the Kaspersky team for CVE-2023-32434 so it seems like there was some level of 0-day with the Triangulation attack
https://www.bitdefender.com/blog/labs/fragments-of-cross-platform-backdoor-hint-at-larger-mac-os-attack/
https://www.bitdefender.com/blog/labs/fragments-of-cross-platform-backdoor-hint-at-larger-mac-os-attack/
https://9to5google.com/2023/06/15/google-domains-squarespace/
the design and use of https://substation.readme.io
at Brex! 🔥
https://www.youtube.com/watch?v=ZvdYgL6b9xE
the design and use of https://substation.readme.io
at Brex! 🔥
https://www.youtube.com/watch?v=ZvdYgL6b9xE
Refuse to buy appliances where you can't maintain the security your customers deserver (ESXi, Fortinet, routers, etc)
Refuse to buy appliances where you can't maintain the security your customers deserver (ESXi, Fortinet, routers, etc)
Imagine your VC-backed startup has a .ai domain...
https://hackcompute.com/hacking-epp-servers/
Imagine your VC-backed startup has a .ai domain...
https://hackcompute.com/hacking-epp-servers/
ozuriexv.github.io/rule-metada…
I highly recommend adding this site to your RSS feed to catch all new posts as they come 👏
ozuriexv.github.io/rule-metada…
I highly recommend adding this site to your RSS feed to catch all new posts as they come 👏
- tech-debt interest rates
- tech-debt to equity/income
- tech debt risk and leverage
- tech debt refinancing/bankruptcy
https://apenwarr.ca/log/20230605
- tech-debt interest rates
- tech-debt to equity/income
- tech debt risk and leverage
- tech debt refinancing/bankruptcy
https://apenwarr.ca/log/20230605