@joatmon08@ManningBooks Nice work! This will be helpful for the IT -> Eng paradigm shift. Appreciate the motivation for some security focused examples π
Help us make this the coolest 6th grade science experiment ever! Follow my GitHub link below to create your Ubuntu virtual machine today! If you can't figure it out, ping me. https://t.co/IpcqOsTi3w
My mission is to help prepare our youth for a successful career in technology. Most perceive what we're going to accomplish here as wizardry or approach tech with a fixed mindset "I can't do that". The intent is to break the barrier by demonstrating a 6th grader can do "it".
Here's a glimpse into my daily news. This is the norm and is only increasing. Help us protect our critical infrastructure! I'm creating a 6th grade cybersecurity science project for my son and am going to document the journey on my GitHub.
@notshenetworks Had the same dilemma with a promo clip for a recent DevOps Exchange presentation. Couldn't do the office scripted stuff, so I rode a motorcycle to the top of a mountain and one take freestyled it on an overlook stage there...https://t.co/qQWNOIx03i
@cyb3rops We're seeing the same issue. I'm working with our SOC on an SDLC / SecEng approach. Vision is an attack sim and detection pipeline. CICD style on Azure DevOps or GitHub actions.
@ChrisShort Surely we need a 100 line script with a function and everything as a $var to ping a machine, right? Maybe even write a c# app to ping? Def seeing a trend towards unneeded complexity. Maybe this KPI is the root cause!
@taosecurity The opposing view appears to falsely assume all companies actually have blue teams and security staff. To your point, it's the complete opposite. Lmk how many of these SMBs are capable of...say...patching! https://t.co/ZBrQbVq05q.
E.g. We do not have unknown, unpatched, machines publicly exposed running water treatment software in an administrative account with password βadminβ in a bloated Windows XP installation.
@ormondbeach Can we confidently say our city has the appropriate cybersecurity safeguards in place to prevent similar attacks? If not, happy to help anyway I can. No $ needed (Perhaps a police escorted wheelie session in exchange π) Our people come first.
https://t.co/cNMHPrFHqK
Something along the lines of: βWe have implemented NISTβs Cybersecurity Framework (CSF) and have repeatable (Tier 3) controls in place for asset, vulnerability & identity management, least-privilege, and least-functionality.β
@ejosterberg@0xAmit Truth. I frequently see dev articles with insecure configs like that. You can tell time to deploy is still the driver. Sans security of course. They will slow down the process!