Overwhelmed with security vulnerabilities? My new blog post delves into the challenges of vulnerability management and equips you with practical strategies to stay ahead of the curve. https://t.co/CPVoeTHUI2 #cybersecurity#appsec#vulnerabilitymanagement
Not all vulns are created equal! ⚖ My new blog breaks down VDRs & VEX, tools helping transparency in the software supply chain. Standardize your responses & streamline communication with vendors & users. https://t.co/IWHrjuS0X4 #AppSec#VulnerabilityManagement#SoftwareSecurity
From ❄️frosty fractals to cozy fireplaces, the only limit is your imagination. Dive into my #StableDiffusion Christmas journey and spark your creativity in the new year: https://t.co/9XTqjyhB2m
#HappyNewYear#AIArt#DigitalArt#Art#GenAI
Cyber threats evolve fast! Stay ahead of the curve with my top picks for the best cybersecurity websites, podcasts, & YouTube channels of 2023: https://t.co/DSIn34x5eL #cybersecurity#infosec#staysecure
The #cybersecurity landscape is changing and companies will be tightening their belts. Will you adapt? This blog post explores the evolving roles of #security champions and security engineers with GenAI. #appsec#securitychampions
https://t.co/slcT9FbL8A
On flight day 13 of the #Artemis I mission, @NASA_Orion reached its maximum distance from Earth, 268,563 miles away from home.
Orion has now traveled farther than any other spacecraft designed to carry humans to deep space & safely return them to Earth. https://t.co/tt0x4YDkxZ
From my experience all software developers are now security engineers wether they know it, admit to it or do it. Your code is now the security of the org you work for. #GoldenAgeOfDefense
Another great report from the team!
Notice how they exfiltrated important documents, backups and internal certificates.
Also, notice that there were:
🚫No Ransomware
🚫No Cobalt Strike
We have come to a new ransomless and beaconless era…
Intelligence acquired since the beginning of the Russian military operation over Ukraine has shown an immense lack of logistic support, making this war one of the most unique in 2022 when it comes to surveillance.
A thread 👇🧵
All organizations should upgrade to Log4j version 2.15.0 or apply appropriate vendor-recommended mitigations immediately.
Read more from @CISAgov about how to protect your organization ⬇️
There are no truly flat organizations in tech.
The choices are: (1) an explicit hierarchy w/ clear responsibilities and accountability or (2) implicit hierarchies with no clear responsibilities or accountability.
And it's false that (2) is inherently more meritocratic.
CVE 2020-1472 - Netlogon (MS-NRPC)
Start down the path recommended to be using Secure RPC. The patch released today puts events into your DC logs to find where you need to fix.
Once all fixed, you then enable Enforcement Mode.
In Feb, it’s mandatory.
https://t.co/N4kGl4KshY