@statesman “retailers exploited the agriculture law to sell life-threatening, unregulated forms of THC”. I call bullshit and I have zero interest in using THC products. Legalize it.
LinkedIn is now using everyone's content to train their AI tool -- they just auto opted everyone in.
I recommend opting out now (AND that orgs put an end to auto opt-in, it's not cool)
Opt out steps: Settings and Privacy > Data Privacy > Data for Generative AI Improvement (OFF)
AppSec Tip:
If you’re going to use a one time code for multi-factor authentication (MFA), make sure it’s secure. This can be done by generating the code using a secure random function (Cryptographically Secure Pseudo-Random Number Generator). #AppSec#infosec#pentesting
AppSec Tip:
Always ensure your application gives a generic error message for failed login attempts. This will help prevent attackers from enumerating usernames that they could use to perform brute-force attacks.
#AppSec#informationsecurity#pentesting#softwaresecurity
In case you missed it, I launched a new podcast last weekend. I have three episodes available with new ones weekly. It’s available on @YouTube@spotifypodcasts@ApplePodcasts@amazonmusic and other platforms. Please check it out and subscribe! https://t.co/48erAYpWuH
Here is a list of free Cloud Security learning labs. They include CTF challenges, guided vulnerability labs, and workshops. If you are new to InfoSec or trying to advance your skills in Cloud Security, check them out. A great way to learn is hands on keyboard skill development. Thanks to many of the authors out there who created these labs. @ryananicholson @sethsec@0xdabbad00@Cyb3rWard0g@joshva_jebaraj
https://t.co/t4qycIM2bW
#azure #aws #gcp
AD Pentest mindmap upgrade :
Full version: https://t.co/hE0VKO5b2I
xmind version (slow, the map is big) :
https://t.co/D3Dck14tiq
Fell free to tell me what is missing !
Two of the most seemingly obvious things have made the biggest improvements on how we red team here. Standardizing sharing of notes/techniques/etc in Obsidian and having consultants debrief the entire red and research teams after every engagement is complete.