Redhotcyber · @redhotcyber
597 followers · 1860 posts · Server mastodon.bida.im
Constantin Milos · @Tinolle
15 followers · 121 posts · Server mastodon.uno
Milos Constantin · @Tinolle
72 followers · 205 posts · Server hachyderm.io
Mr.Trunk · @mrtrunk
12 followers · 19671 posts · Server dromedary.seedoubleyou.me
Nerdfallmanagement · @nerdfall
422 followers · 2891 posts · Server social.tchncs.de

Letztens kam ja diese Meldung heise.de/news/Jetzt-updaten-Ho, auch @gborn hat davon berichtet. Kann mir jemand sagen, warum weder CVE-2023-31102 noch CVE-2023-40481 beim noch beim des BSI gelistet sind? Braucht das so lange? Oder hab ich nen Denkfehler?

#mitre #wid

Last updated 1 year ago

Mr.Trunk · @mrtrunk
12 followers · 19567 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
12 followers · 19309 posts · Server dromedary.seedoubleyou.me

SecurityWeek: MITRE and CISA Release Open Source Tool for OT Attack Emulation securityweek.com/mitre-and-cis /OT

#ics #mitre #cisa #ot

Last updated 1 year ago

Abraxas3d · @abraxas3d
569 followers · 910 posts · Server fosstodon.org

@nicholdav @ruchowdh @scipy2023 @SciPyConf @osi and are putting up some solid work here.

#mitre

Last updated 1 year ago

fthy · @fthy
8 followers · 84 posts · Server mastodon.green

Mitre published another awesome framework called d3fend.mitre.org

It is using the att&ck framework but from a defenders perspective :-)

#infosec #cyber #mitre

Last updated 1 year ago

Marcel SIneM(S)US · @simsus
193 followers · 4094 posts · Server social.tchncs.de
Stefan Prandl · @redezem
88 followers · 203 posts · Server aus.social

I swear, the number of times I have to explain to people that detection is not the golden bullet they think it is is just mad. The amount of people that think that simply covering the ATT&CK framework is some kind of panacea just makes me want to give up and live as a druid.

Come to think of it, going and just living as a druid in the forests wouldn't be too bad... hmmm.... 🤔

#threat #mitre

Last updated 1 year ago

Sonja MGFX · @SonjaMGFX
82 followers · 146 posts · Server mograph.social
FOSSlife · @fosslife
1426 followers · 33 posts · Server fosstodon.org

New tool from the Cybersecurity and Infrastructure Security Agency aims to help defenders map attacker behavior to the MITRE ATT&CK framework fosslife.org/new-cisa-tool-sim

#foss #mitre #cisa #security #cybersecurity #tools #networking #opensource

Last updated 1 year ago

Aida Akl · @AAKL
236 followers · 564 posts · Server noc.social
tkteo · @tkteo
38 followers · 1181 posts · Server infosec.exchange

Microsoft and MITRE have developed a plug-in that combines several open-source software tools to help cybersecurity professionals better prepare for attacks on machine learning (ML) systems.

The Arsenal tool implements tactics and techniques defined in the MITRE ATLAS framework and has been collaboratively built off of Microsoft’s Counterfit as an automated adversarial attack library so security practitioners can accurately emulate attacks on systems that contain ML without having a deep background in ML or artificial intelligence (AI).

"Bringing these tools together is a major win for the cybersecurity community because it provides insights into how adversarial machine learning attacks play out," said Charles Clancy, Ph.D., senior vice president, general manager, MITRE Labs, and chief futurist. "Working together to address potential security flaws with machine learning systems will help improve user trust and better enable these systems to have a positive impact on society."

finance.yahoo.com/news/microso

microsoft.com/en-us/security/b

mitre.org/news-insights/news-r

#ai #cybersecurity #security #software #artificialintelligence #machinelearning #microsoft #mitre

Last updated 1 year ago

Gustav H Meyer · @inetpro
109 followers · 520 posts · Server infosec.exchange

Another unambiguous write up by Daniel Stenberg and very nice to learn some more about the subjective nature of the CVSS scores and how it all fits together.

How do we get the NVD to stop the insanity?

[...] In the curl project we decided to abandon CVSS years ago because of its inherent problems. Instead we use only the four severity names: Low, Medium, High, and Critical [...] I have talked to humans on the GitHub database team and I push for them to ignore or filter out the severity levels as set by NVD, if possible. But me being just a single complaining maintainer I do not expect this to have much of an effect. I would urge NVD to stop this insanity if I had any way to. [...]

daniel.haxx.se/blog/2023/03/06

#cvss #nvd #cve #mitre #vulnerabilitymanagement

Last updated 1 year ago

Andrea Fortuna :verified: · @andreafortuna
134 followers · 78 posts · Server mastodon.uno

The and Infrastructure Security Agency () recently launched a free tool called to help the cybersecurity community map threat actor behaviour to the ATT&CK Framework. andreafortuna.org/2023/03/03/c

#cybersecurity #cisa #decider #mitre

Last updated 1 year ago

VulDB :verified: · @vuldb
119 followers · 224 posts · Server infosec.exchange

[Hint] You want to publish a new vulnerability? Just submit and we will handle your CVE assignment in no time. vuldb.com/?id.add

#vuldb #CNA #cve #mitre #nvd

Last updated 1 year ago

ITSEC News · @itsecbot
1208 followers · 33903 posts · Server schleuss.online

Feds warn about right Royal ransomware rampage that runs the gamut of TTPs - Wondering which cybercrime tools, techniques and procedures to focus on? How about any an... nakedsecurity.sophos.com/2023/

#ttps #cisa #royal #mitre #dataloss #ransomware

Last updated 1 year ago

F0rm4t · @F0rm4t
36 followers · 41 posts · Server infosec.exchange