I am back with a new blog mini series. This is for any of my Incident Response folks or people who need to secure their AWS environment but are still mostly new to it. Or anyone who believes investigating on-premises is the same as the cloud. #AWS#TDR
https://t.co/1u4mdY9VnG
Today we're releasing details of how our AI, Sift, stole a 0day in an IP Camera and we reported it and got it fixed.
To reiterate- we did not develop the vuln.
1st blood is overrated. I'm all about 2nd blood.
Marketing blog here: https://t.co/MRDJaNNi7n
Grimoire blog below:
We're excited to introduce Kyle O'Meara, a cybersecurity veteran with 18+ years in threat hunting & adversary tracking. 👏🏻
From the NSA to Dragos, Kyle has been at the forefront of critical cybersecurity efforts. 🙌🏻
See y’all soon at #CYBERWARCON!
https://t.co/12b29mb4fu
25 years ago on Sep 29, 1999, MITRE announced the CVE Initiative. There's too much to say, so I'll be brief. CVE was not possible without a concerted, mostly-voluntary, community-wide effort. It's accomplished a lot, but it's daunting to see how much still needs to be done...
If you are at BH on Thursday - be sure to watch my amazing teammates Rushank and Ryan present on how they broke Immutable Backups: https://t.co/6Pk0HOa8UC
🚨 We're tracking new 0-day RCE CVE-2024-3400 in Palo Alto Networks PAN-OS 10.2-11.1 allowing unauthenticated root access in certain configs, check out the blog for more details. https://t.co/o9FV8HGah3
@GergelyOrosz@_ontologic It’s closer to 10 years old, started at Google as their BeyondCorp model before getting generalized.
paper on it: https://t.co/t4iiosVH3O
In his latest blog, @harmj0y unpacks one specific use case for large language models in the security domain & announces RAGnarok, a proof-of-concept local chatbot frontend, for Nemesis.
Check out the post to learn more! https://t.co/NH2BJbt5IC
@ImposeCost This is something we talked about at CERT/CC a few years ago. We had the benefit of being a non-profit and the thought was the donation of a vulnerability would be tax deductible based off the value. Lawyers didn’t think it would past muster in current law