The recent WhatsApp accounts takeover is simple and genius.
This is how it works:
You're sleeping.
A "hacker" tries to login to your account via WhatsApp.
You get a text message with a pincode that says "Do not share this".
You don't share it, yet you still get hacked.
How?
🕸️Inside the Ransomware Economy🕸️
Ryuk is the biggest Saas unicorn u've never heard of.
$150M ARR.
3 yrs old.
Maybe it’s taboo to learn business strategy from a cybergang. But the ransomware industry-- from supply chain operations to market microstructures-- is truly genius.
👇
Scenario: Your CEO is worried about supply chain security and tells you to implement a program to "stop us from being hit with another SolarWinds." What *specifically* do you do to secure your software supply chain?
Please RT for reach. I'm interested in diverse opinions.
I'm not that great a chess player, but a pretty good hacker...so after watching The Queen's Gambit I of course put my skills to great use and found a board setup I could give to a chess engine to have it segfault when it tries to search for the next best move...
take that
Security Budgets - Supply and Demand Thinking
Think of budgeting as a supply & demand problem. Work both sides to make it a risk management exercise. It will bring clarity of thought and illustrates to your business that you are thinking commercially.
https://t.co/l1GDuQGncd
Without formal access, a college kid got hold of @OpenAI's GPT-3 and created a fake, AI-generated blog under a fake name. Within hours, his first post reached #1 on @newsycombinator. A case study in how people could (ab)use the model in the future. https://t.co/o9tbOC9Uu5
For 327 days, the impostor site https://t.co/I2Dnj5GvAe has been stealing traffic/privacy/users from https://t.co/kJk2Wkjqxc, a legit encrypted msg service. Worse: KrebsOnSecurity found https://t.co/I2Dnj5GvAe also will alter bitcoin addresses in messages. https://t.co/FKImFsr1gO
From the 15th-19th of June 2020, we will be bringing the best security minds together to take our participants on a unique experience.
All sessions will be recorded, LIVE streamed and shared : )
To register, head over to https://t.co/rf8TPGu9NR
We're excited to release TerraGoat, a vulnerable-by-design training tool for #Terraform! 🐐
📑 Read more about why we built TerraGoat: https://t.co/CZ9pDhfcM7
⭐ Check it out on GitHub: https://t.co/odFPivB8Ib
We chased an attacker in #AWS and want to share the story.
Our blog covers:
🔍 Initial lead w/ #CloudTrail
🕵️ Investigative approach
🤖 Use of orchestration "robots" to respond faster
✅ Steps to improve
☁️ #Mitre ATT&CK Cloud Tactics? 👍 Those too!
https://t.co/vUOX5irLs8