We just published the full breakdown of yesterday's 372 CVEs mapped against 2,300+ operating profiles.
See exactly what these flaws mean for your specific SLA queues and expected financial exposure.
Live Dashboard: https://t.co/y3BGqQ0Erm
#CyberSecurity#CISO
Stop treating every CVSS 9.8 the same.
Yesterday, 372 new vulnerabilities hit the NVD. 55 were rated Critical.
When we ran them through the RiskWarFare Intelligence Centre's financial models, one flaw eclipsed the rest with a staggering $276M expected loss.
With a public Proof-of-Concept already available, our FAIR models identified it as the ultimate pivot point for automated ransomware gangs.
This is why Volume ≠ Risk.
You don't need another severity score; you need a financial decision record.
Security teams don’t have a data problem. They have an execution problem. For 7 years in SOCs & Red Teams, I watched critical vulnerabilities get ignored because we spoke in CVSS scores while the business spoke in dollars. So I built a Risk OS to fix it. https://t.co/xftFIa5RmR
@MalwareJake It’s very difficult to change people’s psychology triggers with just awareness sessions, I find it helpful only for the users with some curiosity, if the employee doesn’t feel that he belongs to the company and it’s objectives, it’s very hard to make him cautious.
Security starts from hands on experience with attack techniques, everyone interested in learning about AI security risks, should take some time and try this AMAZING capture the flag created by @wiz_io researchers
All the queries from the KQL book that we wrote are now available on the books official repo for you to explore and use. If you buy the book, you will get all the context with them, like why we favour some operators over others, but have a read either way! https://t.co/gj2ycGut3Q
Placing the Suspect Behind the Keyboard: DFIR Investigative Mindset by @brettshavers is now available on Amazon!
UPDATE: Brett will adding a deal soon so wait a day before purchasing
I had the opportunity to be a beta reader for this book and I highly recommend it to both complete beginners to DFIR and seasoned professionals.
This book is full of practical exercises and techniques that will enhance your investigative skills.
https://t.co/tUVaM8bk4d
#DFIR
Series by @__pberba__ about persistence in Linux environments
Map: https://t.co/8KaO3celxe
Auditd: https://t.co/YFlzhgrWjX
Accounts: https://t.co/ZbQDAbSHf3
Systemd: https://t.co/Ud0KRHy1Gy
Scripts: https://t.co/I0eyxeP58I
Generators: https://t.co/pek92QyBtB
#Linux
This is a good article, showing how administrators can simulate risk detections for testing out Conditional Access Policies or detection capabilities.
Highly recommended ☝️
https://t.co/PpcvXJuxtX
Writing a pentest report is undoubtedly one of the most important skills you need to possess.
So, here are public pentest reports from 30+ companies to help you refine your skills. 📝🔒
https://t.co/IqGovjFjA0
#infosec
For anyone interested in learning Windows binary reverse engineering, these are excellent resources by Alexandre Borges (@ale_sp_brazil)
Article 01: https://t.co/YMjBxU3bNq
Article 02: https://t.co/CmltG7Vvw8
#infosec#windows
Found a Critical today: Nacos auth bypass - using default JWT Secret. The Nuclei template I used can be found here: https://t.co/6MblqtLTRu. #BugBounty
I get asked a lot about avoiding burnout, which is an incredibly tough question to answer because I think a lot of other issues get attributed to burnout. It seems people think a lack of motivation to start something == burn out, which isn't always the case. For me, it's more about the discipline to start something I don't want to. Once I start the task, I have plenty of motivation to keep working but starting is the hard thing.
A non-tech parallel is playing sports growing up. There were countless times when I did not want to wake up at 5 am to go to practice before school started. Heck, even on game day I remember not wanting to go out. However, I knew no matter once I was out the motivation would come to finish practice/game because I enjoyed it. The discipline (and peer pressure) to get to where I needed to be, carried me to the point where motivation could take over.
In tech, especially post-covid there's very little peer pressure to start on tasks. It can be tough to start coding, recording, or the toughest hitting to "go live" button to stream. Especially, when there's so much instant gratification out there (Discord, Twitter, Video Games, etc). The bar for instant gratification is constantly being moved which makes it tougher, for example, we don't even have to spend a few seconds to unlock our phone anymore. It's crazy but those few seconds typing in a pass-code sometimes sway people away from doing things.
So if you think you are "burned out" because you aren't producing the results you think you should. Try these three things first:
1. Establish some type of routine/ritual you do before you work. The best thing you can probably do is some type of low-impact aerobic exercise (bike, rower, elliptical) for 20-30 minutes. This will help your health, wake you up, and give you time to think before starting any activity. However, if this doesn't work for you it can be as simple as taking a vitamin or something and saying once I take this I am going to start a task.
2. At the end of your "productive" day (ex: quitting time). Take 10-15 minutes to write down your wins for the day, I prefer physically writing them down because you spend more time on the positives. Don't write down anything negative, spend this time on positivity. Not only will it help you become a more positive person but also lets you privately know what you can accomplish. There are plenty of times when I realize I didn't flip a page a single time in the week and catch myself before my discipline to start things slips.
3. Put your phone on DND Mode. If you require notifications from someone allow them, but mute everything else. Even work emails. For me, it is very easy to be focused on something, to have my phone go off and I don't know if it's important or not so I look at it. 9 times out of 10 it's not important but then I look at other things and my productivity is killed. The 5 seconds it took me to see the notification ends up easily costing me 15-30 minutes and that's if I even return to the task.
Hopefully, this helps someone out there.
During incident response it is easy to focus only on the technical issues, but IR is as much a people problem. Microsoft DART have released a downloadable interactive playbook to help navigate those problems through practical and people-focused guidance - https://t.co/AhXf1iwGuM
Windows rootkit development for red teaming and adversary emulation
Excellent series by @Idov31
Part 1: https://t.co/gLIk9tGiEI
Part 2: https://t.co/ryrPfTLJrR
Part 3: https://t.co/l6C4j7TMte
Part 4: https://t.co/SONhXgCEp7
PArt 5: https://t.co/KOsDQxfBGp
#windows#infosec