When I look at this table, the first thing I see is that size matters more
I reckon users prefer being told: „use a password with at least 10 letters“ instead of „use at least 8 characters, lower and upper case letters, numbers and symbols“
https://t.co/gl64aVUsiz
ICYMI: The FBI, NSA, US Cyber Command, and international partners have warned of Russian hackers from #APT28 (FancyBears) exploiting compromised Ubiquiti EdgeRouters for data theft and #botnet creation.
Read: https://t.co/hcQzRR3m6U
#CyberSecurity#CyberAttack#Ubiquiti
An exciting year is about to end in which cyber security experts have reported more than 250,000 malware sites to URLhaus 🪲 and shared over 160,000 IOCs on ThreatFox 🦊
We have processed 7,844,382 malware samples 📄, conducted 41,847,925 YARA scans on YARAify 🔍 and generated almost 5 Petabyte of network traffic 👀
Our heros of the year (top contributors) have been:
👉 URLhaus: 🥇@geenensp 🥈@lrz_urlhaus
👉 ThreatFox: 🥇@Gi7w0rm 🥈 @drb_ra
👉 MalwareBazaar: 🥇@andretavare5 🥈 @zbetcheckin
👉 YARAify: 🥇 @Casperinous 🥈 @0xThiebaut
Keep up the great work! 💪
Here are 3 Paths to Landing your First Job in Cyber
After 25 years of working in IT and Cyber, I've found that you need to choose one of these three choices if you are looking for your first entry level job.
3 paths that you need to pick from:
1. Offensive Security
2. Defensive Security
3. Security Auditing
I'm not saying these are the only routes that you can take, but I'm narrowing them down into these 3 categories. Let me explain.
For someone getting into Cyber Security, the playing field is very large. Knowing where to start, who to talk to, and which direction to go can be very overwhelming and can tend to scare people away.
Choose a path and develop skills around one of these specific paths and it will set you apart from others who are trying to break into this field.
Let me give you a brief of each path.
1. Offensive Security
Penetration Testers (often called Red Team) are the offensive players in security. They find vulnerabilities, holes in networks, bugs in applications, and basically try to find vulnerabilities before the bad guys do. The risk of vulnerabilities is communicated to the business, as well as advising on mitigation techniques and helping them understand the possible impact.
If you choose Offensive Security, you need to setup labs and learn industry standard tools such as (but of course not limited to) Nmap, Kali (Openvas, Metasploit, other tools within). Learn to use know how to use these tools inside and out. For application penetration testing, learn what OWASP is, learn how to use Burp (by Portswigger) and study the OWASP testing guidelines. These things by themselves do not make you a penetration tester, but if you dive into these tools, learn how they work and the language around them, you will have a great head start as a penetration tester. All of the tools I listed above are free.
2. Defensive Security
Defensive Security (Blue Team) is of course the defensive side of security. Learn how to watch for anomalies, detect intrusions, etc. This type of work typically consists of working with in a SOC (Security Operation Center), where you will be part of a team helping protect digital assets.
If you chose Defensive Security, start diving in by learning network packets. Learn how to "read the wire", meaning using tools such as Wireshark and being able to break down packets and understand them. Learn about different SIEM (Security Information and Event Manager) solutions. I also started years ago by installing tools such as SNORT, OSSIM, OSSEC, and others. Get familiar with what Splunk is. This won't make you a pro, but it will give you the knowledge, language, and some know-how of blue team.
3. Security Auditing
Fortunately and unfortunately one of the biggest drivers for information security is compliance driven.
Fortunately compliance forces companies and organizations to comply with certain standards around their security implementation. Unfortunately, many companies are only spending money because of compliance. Compliance absolutely does not equal security, but it is still the reason that companies are spending proactive money to protect their digital assets.
There are various frameworks that companies adhere to. Part of being an auditor is learning various frameworks (PCI, NIST, ISO, etc) and helping a company align their security posture with the required framework.
If you want free weekly tips, visit my site at https://t.co/GcdJet8jHq and subscribe to my email list. Each week I send out actionable items on how you can further your career in Cyber Security.
Your journey is yours. Never let anyone slow you down on reaching your destination.
#cybersecurity #informationsecurity #infosec #leadershipbyexample
25. GreyNoise—Search for devices connected to the internet.
26. Hunter—Search for email addresses belonging to a website.
27. Censys—Assessing attack surface for internet connected devices.
28. IntelligenceX—Search Tor, I2P, data leaks, domains, and emails.
21. CRT sh—Search for certs that have been logged by CT.
22. Wigle—Database of wireless networks, with statistics.
23. PublicWWW—Marketing and affiliate marketing research.
24. Binary Edge—Scans the internet for threat intelligence.
16. URL Scan—Free service to scan and analyse websites.
17. Vulners—Search vulnerabilities in a large database.
18. WayBackMachine—View content from deleted websites.
19. Shodan—Search for devices connected to the internet.
20. Netlas—Search and monitor internet connected assets.