Case study: A minor update of an analytics library caused a major security incident—user credentials were sent to a third-party backend.
Learn how we found and fixed it: https://t.co/raqbBNdzYZ
#AppSecurity
We’re pleased to share that today @vixentael is speaking at the @NATO#TIDESprint 43 in Helsinki.
Check the Cyberspace track, where Anastasiia shares experience on protecting mission-critical systems and accelerating security decision-making.
Last week, we shared our experience in a cybersecurity workshop for defense tech companies organised by @BRAVE1ua. We covered topics from security fundamentals, like risk management and internal cybersecurity programs, to industry-specific technical challenges and approaches.
React Native is great for cross-platform apps, but their security can be a concern. In her recent article for @owasp, @julepka shares practical tips for assessing these apps, using #OWASP guidelines to identify common security risks.
➤ Read more: https://t.co/rGJNnPPXGm
Meet Anton Shepeta at CocoaTalks meetup!
If you are in Kyiv, don't miss Cossack Labs' Security Engineer, Anton Shepeta, discussing iOS reverse engineering tips & tricks at the CocoaTalks meetup on Tuesday, October 29. Thanks @macpaw for hosting!
➤ https://t.co/gY2oiOOett
Let’s focus on the Software Bill of Materials (#SBOM), its security and common problems.
Can SBOMs be trusted to enhance supply chain security and vulnerability management? Are there reasons they cannot?
➤https://t.co/zxM2exeyDp 👈
New release of Acra data security solution for databases and distributed apps. Enhanced MariaDB, MySQL, and PostgreSQL support. Simplified TLS config & optimised key management tools, updated Acra engineering examples.
➤ https://t.co/3jhdNjw11s 👈
How to protect your #ML models on mobile apps and edge devices against leakage, abuse and reverse engineering?
Guidelines and advice from @vixentael and Maksym Khanas:
➤ https://t.co/3nTYuC1Hh4 👈
On Ukraine's Independence Day, we reflect on our ongoing efforts to strengthen Ukraine’s cyber resilience in critical national infrastructure, mission-critical systems, govtech solutions, unmanned robotic systems, and many more.
➤ https://t.co/Xnts4zoRBu 👈
Introducing CL MSS: Mobile security verification framework for product security, assessments & SSDLC.
Thanks to main contributors: @julepka, @vixentael, Anton Shepeta, @G1ggg1L3s#SSDLC#appsec
➤ https://t.co/89GD4JLFBL 👈
Eugene Pilyankevich will join @aerorozvidka's 10th-anniversary stream and share details about UA DroneID. This technology improves the efficiency and security of deploying UAV and robotic systems during complex operations.
Розповідаємо про останній блок стріму - ROBOTIC SYSTEMS:
📍Чому ми вважаємо, що роботизовані системи - асиметрична відповідь ворогу
📍Проєкти напряму: DroneID, Група прототипування.
📍Майбутнє використання роботизованих систем: проблематика, перспективи, запит до спільноти
Cossack Labs is delighted to celebrate the 10th anniversary of our friend and ally @aerorozvidka, and to take part in the stream! Don't miss @vixentael talk on building security in mission-critical systems at https://t.co/pwPu8QUJPY
Сьогодні розповімо про блок C2IS:
Що таке бойові інформаційні системи і чому це важливо?
Які були передумови та виклики розробки системи ситуаційної обізнаності Дельта?
Які виклики постали з початком повномасштабного вторгнення?
Кібербезпека бойових інформаційних систем.
Meet @vixentael at #DOU Day 2024!
Don't miss Cossack Labs’ Head of Security Engineering @vixentaelʼs talk on building resilient mission-critical systems at DOU Day on May 18th.
Спільното, раді нарешті анонсувати для вас теми спікерів на DOU Day. І почнемо з @vixentael, Head of Security Engineering, Security software engineer в Cossack Labs😎
Using security autotests for measurable and stable software security processes: Check our pre-built templates and learn how to implement them into the CI/CD pipeline.
➤ https://t.co/SPyhpxZ4nD👈
Cossack Labs is proud to collaborate with @mintsyfra, @DefenceU & @aerorozvidka to develop UA DroneID: This innovative technology enables the protection of mission-critical assets and increases the efficiency of UAVs and unmanned robotic systems usage.
We are proud of our Lead Security Engineer, @julepka who is a director at @wwcodekyiv, for fostering professional development of the women's community in IT and co-organising the "Inspire & Connect" conference.
Deal with #OAuth2? Get savvy on OAuth2 mechanics, PKCE implementation, CSRF protection, and auto security checks to avoid common pitfalls.
A detailed guide to OAuth2 security is here:
➤ https://t.co/mWVoY46JXG 👈
Our Head of Security Engineering @vixentael shared unique expertise on building security for mission-critical apps and critical infrastructure at #NATO#TIDESprint 2024, Data Centric Security and Cybersecurity tracks.
Opportunity to meet @vixentael at #NATO#TideSprint 2024 event held by @NATO_ACT.
Don't miss Head of Security Engineering @vixentaelʼs talk about building secure architecture for mission-critical applications within the Data Centric Security track.
#TIDESprint'24: Advancing Interoperability!
@NATO’s leading think-tank arena aims at fostering advancements & innovations that rapidly evolve concepts and specifications to design more interoperable partnership between #NATO & Partner Nations.
📌https://t.co/jtc0dnSPaL
#WeAreNATO