Spotted that some UK newspaper websites have started asking visitors to Pay to Reject tracking cookies?(!) Er.. how are they allowed to do this under GDPR/Data Privacy Laws?
"We do ask the users for consent to process their personal data, but they can't opt out unless they pay"?
#Java: Popular Java Security Framework #pac4j Vulnerable to Remote Code Execution (#RCE) Critical Vulnerability CVE-2023-25581.
Great find and GitHub Advisory by @artsploit:
👇
https://t.co/URgUDiUeNb
This year we celebrate the 20th anniversary of the @OWASPLondon Chapter! 🚀
From the first meeting in a pub near Holborn in 2004 to the big stage at Google London in 2024: Join us on Feb 22nd as we invite our founders: @dcuthbert, @DinisCruz & @ivanristic to share their insights:
I have secured my ticket for Cloud & Cyber Security Expo London 2024! Join me 6-7 March at ExCeL London - register for your FREE ticket today! #CCSE#CloudSecurityExpo https://t.co/fE33WEGl7q
Generative #AI is transforming the customer experience in industries of every size across the globe 🌍
Our mental model will help users approach the risk and security implications based on the type of generative AI workload users are deploying. See more:
https://t.co/eZCU1UZEyr
🧠 Vulnerability Management: You should know about EPSS
@Magoo on the value of the Exploit Prediction Scoring System → the probability of a CVE being exploited in the wild within 30 days
Helps you prioritize, as most High/Crit CVSS are not exploited
https://t.co/w7eNNFAXXw
⚠️If you are using HTTP/2 beware of the novel #zeroday#vulnerability dubbed the “HTTP/2 Rapid Reset” attack disclosed today.
This attack exploits a weakness in the #HTTP2 protocol to generate enormous Distributed Denial of Service (#DDoS) attacks:
https://t.co/e1eQTjccSd
🔥 SaaS Attack Techniques
Like MITRE ATT&CK but for SaaS
Learn the attack techniques used against SaaS applications:
* SAMLjacking
* Evil twin integrations
* MFA fatigue
By @jacques_sec
🔖 Repo:
https://t.co/xv8wWtgPIe
#cybersecurity
https://t.co/Jivloe6htT
We found two 0-day vulnerabilities in @Ubuntu kernel and it all started by reading descriptions of old CVEs 📖
Thread about the discovery of #GameOverlay 🧵👇🏼
Protect your #APIs by building a perimeter protection layer with Amazon CloudFront, AWS WAF, and AWS Shield and putting it in front of Amazon API Gateway endpoints 🛡️
https://t.co/DGDZGw0YQl
#AmazonInspector is an automated vulnerability management service that continually scans AWS workloads for software vulnerabilities and unintended network exposure 🌐 ❌
Learn to periodically scan selected EC2 AMIs and take automated actions ⬇️
https://t.co/BuBhSysV3Z
Amazon CodeGuru Security helps you focus on #securityrisks that are relevant to your environment, along with contextually relevant remediation suggestions (provided as code diffs). Get all the feature and capability details here👇🔍 https://t.co/GakUB8BuMs
Pleased to announce the next @OWASPLondon meetup on August 3rd!
Don't miss fantastic talks from @RazProbstein on #DevSecOps Maturity Model (DSOMM) and from @mattrwa on some great examples and live demos of Generative #AI usage to automate AppSec tasks.
Register to attend here:👇
Pleased to announce the next @OWASPLondon meetup on May 30th at Amazon London offices. Don't miss fantastic talks from @urlichsanais on Security Chaos Engineering and from @Kerberosmansour on the Risks and Benefits of Generative AI for CyberSecurity. Register to attend here:👇