hellosct1@mamot.fr · @hellosct1
161 followers · 1191 posts · Server mamot.fr
hellosct1@mamot.fr · @hellosct1
161 followers · 1188 posts · Server mamot.fr

Les données sensibles dans la sera le fil rouge du meetup @lizard Un joli programme à découvrir mamot.fr/@lizard/1105192033109

#cybersecurite #devsecops #secdevops #secops

Last updated 1 year ago

Doyensec · @doyensec
15 followers · 11 posts · Server infosec.exchange

Congrats @felix on "Hacking the cloud with SAML" making PortSwigger's Top 10 Web Hacking Techniques! To celebrate, is releasing our tool to generate exploitation PoCs for one of the issues he found. Enjoy!

github.com/doyensec/CVE-2022-3

portswigger.net/research/top-1

#doyensec #appsec #devsecops #secdevops

Last updated 2 years ago

Doyensec · @doyensec
12 followers · 6 posts · Server infosec.exchange

Need help securing against the arbitrary file read described in CVE-2022-44268? The pictured policy change can mitigate it for you.

For more recommendations on hardening your security policies check out our free tool at:
imagemagick-secevaluator.doyen

#imagemagick #doyensec #appsec #secdevops #securityresearch

Last updated 2 years ago

Doyensec · @doyensec
11 followers · 5 posts · Server infosec.exchange

Teleport just published the report from our latest round of auditing their Microsoft RDP Desktop Access tool. Read it today to see the findings & our approach to clients' product security

doyensec.com/research.html#96

#doyensec #appsec #security #devsecops #secdevops

Last updated 2 years ago

Ben Stroz6i · @stroz
135 followers · 801 posts · Server infosec.exchange

Went ahead and fixed the cert for the SecDevSecOpsSec site and added a flat hmtl index.

No content, haven't quite decided on that yet. For now, just a silly domain

secdevsecopssec.com/

#devsecops #secdevops #devopssec #secdevsecopssec #devopssecurity #shiftleft #shifteverywhere #sdsos

Last updated 2 years ago

Chema Alonso :verified: · @chemaalonso
643 followers · 113 posts · Server ioc.exchange
Jeremy · @jredmond
16 followers · 47 posts · Server infosec.exchange

Requesting some community help, I'm looking for some data/articles introducing a pipeline. This would allow cybersecurity to apply IaC security features like Azure NSG/Policy etc. instead of allowing to open their own ports etc. I want to prevent cybersecurity from slowing things down but also want cybersecurity to have some control. Anyone have any good data on this to back me up?

#cybersecurity #iac #devops #devsecops #secdevops

Last updated 2 years ago

Jay Thoden van Velzen · @jaythvv
226 followers · 1341 posts · Server infosec.exchange

I often talk about SecDevOps - a DevOps approach to security operations, with rapid iterations, a focus on scale and automation, and responsive to the community of developer/DevOps teams we serve with scans, alerts, or other findings.

Aside from the ability for SecOps teams to transform their operations for the cloud, this also helps align teams to the pace and agility of developer teams following a DevSecOps approach, and therefore better support them during the service lifecycle as they herd the cattle.

Security can only be a successful enabler for developer teams in if we meet those we support where they are and synchronize our frequencies.

#cloudsecurity #sharedfate #devsecops #secdevops

Last updated 2 years ago

ITSEC News · @itsecbot
1107 followers · 33105 posts · Server schleuss.online
Nick Anderson · @nickanderson
33 followers · 152 posts · Server fosstodon.org

Day 18/25: The Samba software enables file and printer sharing, and is typically used in mixed and environments. It can provide an attack vector and has been affected by vulnerabilities in the past. If not used, it should be removed:

build.cfengine.com/modules/uni

#linux #windows #security #secdevops #compliance #cve #devops #cfengine

Last updated 2 years ago

farimani · @farimani
68 followers · 35 posts · Server infosec.exchange

What is SecDevOps vs. DevSecOps?

"Philosophically, you can think of it as a sort of DevOps for security operations where people who develop the code (in this case, detection logic) are the same people who operate it (in this case, respond to signals and alerts)."

Brilliant article by @jaythvv.

linkedin.com/pulse/secdevops-a

#decsecops #secdevops

Last updated 2 years ago

Recon InfoSec · @recon_infosec
450 followers · 16 posts · Server infosec.exchange

ICYMI -- @shortstack wrote an awesome blog on secure remote access tools for the modern sysadmin.

Gone are the days of exposing services directly to the internet -- is more than buzz word, its a way of life!

A few of our favorite tools for the job: StrongDM, @tailscale, @zerotier

blog.reconinfosec.com/remote-a

#zerotrust #infosec #networksecurity #devops #secdevops

Last updated 2 years ago

Jay Thoden van Velzen · @jaythvv
56 followers · 106 posts · Server infosec.exchange

ohai 👋​

I am Jay, 🇳🇱​, but for over 20 years on the California coast.
Managed to turn my ability to break things into productive channels, after a long stint in Analytics and Consulting.

I ran Multicloud Security Operations for a large cloud service provider for several years, finding out that secure cloud transformation is really difficult, but absolutely fascinating - especially since we're all still just figuring it out.

Now trying to translate the experience into strategy

#introduction #secdevops

Last updated 2 years ago

With web design skills like this, who wouldn't want to hire me :ablobcool:​ In all seriousness though, this was a simple little HTML-only page (I added CSS for flair :black_sparkles:​) that I created for my Security for Software Developers course lab with the purpose of successfully attacking a locally hosted instance of a fake bank using Cross-Site Request Forgery, and "withdrawing" some amount from that users account if they happen to click my button while still logged into the fake bank on another tab. The other attack I made was using a page with a form that I made hidden, that would pass the parameters to the bank withdrawal page and submit the form automatically using a couple lines of JavaScript.

#infosec #csrf #webdevelopment #securesoftwaredevelopment #netbeans #informationsecurity #secdevops

Last updated 2 years ago

ITSEC News · @itsecbot
856 followers · 32559 posts · Server schleuss.online
ITSEC News · @itsecbot
856 followers · 32557 posts · Server schleuss.online
hellosct1@mamot.fr · @hellosct1
151 followers · 1090 posts · Server mamot.fr

Après une phase de repos, Les Le foo du roi "The Joker" font connaissance de la famille.

Je pense qu'ils seront présent à la le 16 décembre pour se faire adopter programmez.com/page-devcon/dev

#elephpants #DevCon12 #php #cybersécurité #devsecops #secdevops

Last updated 3 years ago

hellosct1@mamot.fr · @hellosct1
151 followers · 1090 posts · Server mamot.fr

Jeudi prochain (4/11) se déroule les Je parlerais de "La sécurité applicative par le design"
gsdays.fr

#gsdays #devsecops #secdevops #cybersecurity

Last updated 3 years ago

Lizard_secu · @lizard
11 followers · 87 posts · Server mamot.fr

Retrouvez les slides de @alexandreoda@twitter.com sur Vault présenté à notre dernier meetup speakerdeck.com/secu/la-gestio

#cybersecurite #devsecops #secdevops

Last updated 4 years ago