This is how it’s supposed to work. This is how everyone levels up while protecting more people/orgs in parallel. More vendors should seek to mimic this type of collaboration.
We’re all on the same team…unless you only look at Security as a business, but that’s another tweet :)
#ESETResearch has discovered the first known AI-powered ransomware, which we named #PromptLock. The PromptLock malware uses the gpt-oss:20b model from OpenAI locally via the Ollama API to generate malicious Lua scripts on the fly, which it then executes 1/6
Tickets are now on sale for our #bsidesboulder annual event on 13 June! Your ticket purchase comes with lunch and a t-shirt. We expect our @KC7cyber CTF workshop will sell out given the limited seats, so get your ticket now.
https://t.co/Lt84auyMTm
Excited to share that @amrandazz and I will be speaking at @fwdcloudsec in Denver on June 30th! We’ll be diving into the many lessons we’ve learned from a year of threat hunting in the cloud.
https://t.co/dAe8CNxVgC
Something I'm really proud of: I made it to the number 1 spot on the AWS Vulnerability Disclosure Program Leaderboard! I'm excited to continue helping improve AWS' security posture and help root out categories of vulnerability in AWS services/technologies!
https://t.co/fWEigaN3F5
Today our @datadoghq Security Research and Detection Engineering team released our first threat roundup report!
Datadog has unique visibility into threat actor activity targeting cloud environments - this report highlights our key findings from Q4 2024.
https://t.co/BCEoecaSLB
Long-lived, unmanaged credentials remain a risk across all cloud providers. Learn more in our 2024 State of Cloud Security study: https://t.co/J7K3lnRIFn
🤝 @datadoghq Cloud Security Management Identity Risks uses #AWSIAM Access Analyzer to further improve the detection of permissions gaps to provide right-sized policy recommendations. Learn more about this integrated solution. https://t.co/4oOpquW4zG
🔎 A guide to threat hunting & monitoring in Snowflake
Detecting initial access, defense evasion, persistent access, credential access, data collection, exfiltration
With example queries and what to look for in the results
By @JulieASparks, @sethsec
https://t.co/DCWB12k6N9
@cci_forensics You will leave behind a lasting positive impact on both the company and the security industry as a whole from your time at Cb. It was a honor working with you and wishing you all the best in your next adventure!
Swee Lai Lee is an extremely talented threat researcher and malware analyst from my team. Laid off after 8 years as part of the Carbon Black acquisition into Broadcom
Based in Malaysia, spoke at RSA, analysis writeups, large-scale malware tests against vendor products
Hire her!
New from Datadog Security Research! We found a vulnerability in AWS Amplify that exposed IAM roles associated with Amplify projects, making them assumable by anyone in the world! Both the Amplify CLI and Studio had this behavior.
https://t.co/Jy6kS9Dry1
New from Datadog Security Research! Analysis of SNS enumeration across AWS led to the takedown of a phishing site that was impersonating the French government in our latest blog:
https://t.co/nZzuWp1pcP
#CloudSecurity#AWS#Smishing#Phishing