After not receiving a raise in the four years I’ve worked at BHIS they’ve now decided to reduce my pay by $40k after coming back from maternity leave and moving my role to solely pentesting. So I am looking for a new position effective immediately if anyone has any leads 😇
It only took 14 years… but it’s finally here 😊
Meet NexPhone — a smartphone built to run Android, launch Linux (Debian) on demand, and dual-boot Windows 11. My 14-year founder story: https://t.co/uWxLLnroj3
If you want to support what we’re building, a repost helps a lot.
You can grab the latest copy of our quarterly security research roundup at https://t.co/4noer7uyR6¹
For this issue, we selected work from over 1,370 talks & 1,200 blog posts.
Available as PDF, ePUB (or audio highlights)
__
¹ As always, completely free
We are currently experiencing alerting failures on our Azure login certificate Canarytoken.
This affects both free and paid Consoles. The problem appears to be due to changes on Azure - but we are still investigating.
We will update with more information when we have it.
Today we released our new (free) AWS Infrastructure Canarytoken.
It catches attackers in your AWS account by putting tempting assets in their way and alerting you if they get probed.
Extending our old work on fake AWS assets, this makes it even easier to deploy juicy S3 buckets, DynamoDB tables, SSM parameters, SecretsManager secrets, and SQS queues, that attackers will want to browse.
We help you design and build a Terraform module that’s unique to your environment, then you deploy when ready.
It's live on https://t.co/fwk6wkWL7q. Check out our blog for more, including how to deploy your first AWS infrastructure Canarytoken.
__
¹ https://t.co/M7yd9IziA8
It's our birthday, so we created a tiny skunk(worksy) game for you to play..
Complete all 7 continents, and we will send you a limited-edition, 10-year t-shirt.
Have fun!! (but watch out for the Canaries)
https://t.co/PP1kXvxM6H
In April this year, @grafana had a security incident due to an insecure GitHub Action. The attackers even tried covering their tracks.
How were they discovered? Canarytokens..
Check out their (super transparent) post¹ on how they use our tokens at scale..
__
¹ link follows
When we first built @ThinkstCanary we were proud that it took less than 4 minutes to be useful when bought.
Now it takes less than two...
Catching attackers is the game the whole family can play...
This Valentines your Canary Console offers you a walk down memory lane, with our homage to flappy-bird..
It's a bit of a distance from what we do.. but.. it's also totally what we do 💪💚
Academic work on honeypots and deception are often kinda disappointing, but this paper by @debi_ashenden and Reeves is worth the skim (especially since it confirms lots of our @ThinkstCanary takes 😉)
tl;dr : Canaries work, Use ‘em.
—
¹ https://t.co/LAAJdbsBZk
Our @wleightond just pushed out a brand new Canarytoken.
1) Visit https://t.co/712OurVT2I;
2) Create a fake app¹;
3) Download it to your home-screen;
4) Get an alert when anyone else opens it!
Read more about it at https://t.co/pPHrpzQIXG
__
¹ Still completely free
We’ve revamped https://t.co/C3FsUr5RDd
A new interface, new functionality, and the results of our latest security assessment¹
You can read more at:
https://t.co/1i2e00Smfx
__
¹ Still completely free
This year @ThinkstCanary cleared $19m in ARR.
- We still have less than 40 people...
- We still do "no" outbound sales...
We believe more security-product companies can do this too, by focusing a little more on customer-love.
We spoke about it at the @DecibelVC event at RSAC.
The agenda for Security Samvad is out🎉👏
Check out the amazing sessions and insightful talks where experts will dive into all things security🛡️
Register to learn some new stuff, hang out, and meet like-minded people!👇
https://t.co/2oOnIquPAC
#punemeetup#pune#techmeetup