@adnanthekhan What has been your experience with Bedrock like specially around the cost? Have been thinking of doing something similar for a different use case but I am not sure what the cost would be like.
Yesterday a quasi-judicial body in Italy fined @Cloudflare $17 million for failing to go along with their scheme to censor the Internet. The scheme, which even the EU has called concerning, required us within a mere 30 minutes of notification to fully censor from the Internet any sites a shadowy cabal of European media elites deemed against their interests. No judicial oversight. No due process. No appeal. No transparency. It required us to not just remove customers, but also censor our 1.1.1.1 DNS resolver meaning it risked blacking out any site on the Internet. And it required us not just to censor the content in Italy but globally. In other words, Italy insists a shadowy, European media cabal should be able to dictate what is and is not allowed online.
That, of course, is DISGUSTING and even before yesterdayโs fine we had multiple legal challenges pending against the underlying scheme. We, of course, will now fight the unjust fine. Not just because itโs wrong for us but because it is wrong for democratic values.
In addition, we are considering the following actions: 1) discontinuing the millions of dollars in pro bono cyber security services we are providing the upcoming Milano-Cortina Olympics; 2) discontinuing Cloudflareโs Free cyber security services for any Italy-based users; 3) removing all servers from Italian cities; and 4) terminating all plans to build an Italian Cloudflare office or make any investments in the country.
Play stupid games, win stupid prizes. While there are things I would handle differently than the current U.S. administration, I appreciate @JDVance taking a leadership role in recognizing this type of regulation is a fundamental unfair trade issue that also threatens democratic values. And in this case @ElonMusk is right: #FreeSpeech is critical and under attack from an out-of-touch cabal of very disturbed European policy makers.
I will be in DC first thing next week to discuss this with U.S. administration officials and Iโll be meeting with the IOC in Lausanne shortly after to outlineย the risk to the Olympic Games if @Cloudflare withdraws our cyber security protection.
In the meantime, we remain happy to discuss this with Italian government officials who, so far, have been unwilling to engage beyond issuing fines. We believe Italy, like all countries, has a right to regulate the content on networks inside its borders. But they must do so following the Rule of Law and principles of Due Process. And Italy certainly has no right to regulate what is and is not allowed on the Internet in the United States, the United Kingdom, Canada, China, Brazil, India or anywhere outside its borders.
THIS IS AN IMPORTANT FIGHT AND WE WILL WIN!!!
If you are building a vibe coded app and launching a product out of it, hit us @OphionSecurity and we will do a security assessment and have actionable security measures ready within 72 hours. #vibecoding#security#cybersecurity
If you want free API keys just open the network tab on literally every vibe coded app.
In the last 24 hours i've looked at the requests of every vibe coded app I see and 9 times out of 10 they're leaking private credentials.
I just got access to an attacker's daily diary. Here is what I learned ๐
๐ 9:00 AM: Clock in.
๐ 9:12 AM: Google Dork says https://t.co/PpN8LQE7bz is still alive.
๐ 9:30 AM: No rate limits, no auth. Just vibes.
๐ 10:00 AM: Dumped staging DB from https://t.co/aa8ZDOvcp3.
๐ฌ 10:20 AM: Reused creds work on prod. Consistency is key.
๐ก 10:45 AM: Oh noโฆ a WAF!
๐ 10:46 AM: JK, itโs only on www. Your 12 forgotten subdomains are unprotected.
๐ฅช 12:00 PM: Lunch break. Your asset inventory is crying is forgottenland.
๐ 2:00 PM: You schedule a pentest.
๐ 2:01 PM: For next quarter.
๐ช 3:00 PM: Still pivoting. Still no alert.
๐ฏ 4:30 PM: Internal Jenkins on an old subdomain. Secrets everywhere.
๐ฐ 4:45 PM: Got user data, employee data, AWS keys. Itโs a buffet.
๐ 5:00 PM: Clock out. Easy day.
jk.....
Attackers donโt follow your IR plan.
They donโt wait for your quarterly pentest.
They donโt work 9โ5.
They hunt exposed assets, old creds, shadow subdomains, public GitHub leaks, leaked data in SaaS that will give away more information or give PII etc.
Theyโre hacking every minute.
Are you?
#attacksurfacemanagement #offensivesecurity #cybersecurity #hacking #continuousmonitoring #assetinventory #offensivemonitoring
๐ฅ Q1 Update from the Field: Real-World Hacking with Orion ๐ฅ
In Q1, we pointed Orion, our offensive Attack Surface Management platform, at a large enterprise to see what it could uncover. The results speak for themselves:
๐ ๐ต ๐๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ถ๐ฒ๐ ๐ฟ๐ฒ๐ฝ๐ผ๐ฟ๐๐ฒ๐ฑ
๐จ ๐ด ๐๐ฟ๐ถ๐๐ถ๐ฐ๐ฎ๐น, ๐ญ ๐๐ถ๐ด๐ต
๐ค The High severity finding was discovered entirely by Orion with no human involvement
๐ฐ Approximately $๐ฐ๐ฑ,๐ฌ๐ฌ๐ฌ in rewards from responsible disclosure
๐ Orion also surfaced multiple vulnerabilities in widely-used open-source software such as a supply chain vulnerability in a Microsoft repository
The 9 issues had the potential to expose millions of usersโ sensitive data including ๐ฆ๐ฆ๐ก๐, ๐๐ผ๐๐, ๐ฒ๐บ๐ฎ๐ถ๐น๐, ๐ฎ๐ป๐ฑ ๐ฎ๐ฑ๐ฑ๐ฟ๐ฒ๐๐๐ฒ๐. If exploited, they could have led to major regulatory fines, incident costs, and increased insurance premiums.
๐ค๐ฎ ๐ด๐ผ๐ฎ๐น: ๐ฑ๐ฌ+ ๐ฐ๐ฟ๐ถ๐๐ถ๐ฐ๐ฎ๐น ๐ณ๐ถ๐ป๐ฑ๐ถ๐ป๐ด๐ ๐ฎ๐ฐ๐ฟ๐ผ๐๐ ๐บ๐๐น๐๐ถ๐ฝ๐น๐ฒ ๐ผ๐ฟ๐ด๐ฎ๐ป๐ถ๐๐ฎ๐๐ถ๐ผ๐ป๐. ๐๐ฒ๐โ๐ ๐ด๐ผ ๐โ๏ธ
#OffensiveSecurity #AppSec #RedTeam #SecurityAutomation #BugBounty #ASM
Not yet a full multiplayer but doing some basic "Simon Says" style game with increasing difficulties. Will add leaderboard style system soon. Open to ideas to improve it further @levelsio https://t.co/H7LfymszAt
@aidenybai Not even kidding, @aidenybai you should look into integrating this into a phishing platform that security teams can use. It is killer to deploy quick phishing exercises in pentests.
tj-actions compromise is a great reminder that pinning the action/dependency to a commit SHA instead of a version tag is safer and securer. We monitor repositories of some public organizations, and most of them are safe because they use a SHA like tj-actions/changed-files@4edd678ac3f81e2dc578756871e4d00c19191daf.
However, if an organization is pinning the malicious commit they are still vulnerable: 0e58ed8671d6b60d0890c21b07f8835ace038e67
https://t.co/QKhwswitVD #github #supplychain
Oh wow, a popular GitHub Action (tj-actions/changed-files) was fully compromised. Someone committed a base64-encoded payload that runs a script that in turn prints out encoded secretsโฆ
Stay safe out there!
๐จ Continuous Monitoring Prevents Million-Dollar Breaches ๐จ
In cybersecurity, threats evolve but so should our defenses. At Ophion Security, we continuously monitor Fortune 500 companiesโ public assets not just domains and IPs, but also SaaS services, cloud assets, and web applications that often slip under the radar.
In October, we identified a vulnerability in a Fortune 500 subdomain that exposed highly sensitive PII (DoB, SSN, Addresses, Phone Numbers) to unauthenticated users.
Fast forward a few months: Our continuous monitoring flagged a new but similar asset: a different domain, but familiar API patterns in its JavaScript. Recognizing the fingerprint of a shared infrastructure, we re-tested the vulnerability from October. It was still exploitable. We immediately reported it.
๐ก Key takeaway? Cyber risks donโt end when you fix a single issue. Without continuous monitoring, this vulnerability could have gone unnoticed until an attacker found it first.
๐ก๏ธ Proactive security isnโt just an option itโs a necessity.
If youโre not continuously monitoring your entire attack surface, someone else is. And they may not have your best interests in mind.
#CyberSecurity #ContinuousMonitoring #BreachPrevention #AttackSurfaceManagement #CTEM #Pentest
I reached level 11 in Taptastic! ๐ฎ
Final speed: Super Fast
Tiles: 9
The pattern that defeated me: ๐ฉ ๐จ ๐จ ๐จ ๐ฆ ๐ฆ ๐ฆ ๐จ ๐ฆ ๐ฉ ๐ฉ ๐จ
Can you beat my score? #Taptastic#memorygame#challenge https://t.co/Cy4xhtaohH
๐งต Securing Your @DecagonAI Chat Bot ๐งต
We've seen a growing number of organizations using https://t.co/0shEeZqrsv's chat bot to enhance customer support with AI. A quick post on how to make sure you deploy it securely based on a recent issue we saw.
๐จ The issue?
If X-Decagon-Auth-Signature isn't required, chat history can be accessed solely using X-Decagon-Auth-User-Idโwhich is often just a User ID from the core application.
๐ Example scenario we tested:
1๏ธโฃ Log into the company's core app.
2๏ธโฃ Extract our User ID from the application.
3๏ธโฃ Use it in Decagon's SDK to authenticate and load past chat history.
4๏ธโฃ Identified ways to disclose User ID of other users in the company's core app.
5๏ธโฃ Used other user's User ID to get their chat history.
๐ก Why does this matter?
User IDs, even if UUID-based, are often not private and can be exposed in various parts of an application. If the same User ID is used for Decagon authentication without a secure signature mechanism, an attacker could extract and replay it to access someone else's chat history.
๐ Solution: Ensure your Decagon integration requires X-Decagon-Auth-Signature for proper authentication and does not rely solely on User IDs.
โ ๏ธ Important: This is NOT a Decagon vulnerability, it's a misconfiguration that security teams should be aware of as companies rapidly integrate AI-powered tools.
#genai #aisecurity #attacksurfacemanagement
Announcing: Ask Us Anything Security - A free security advisory for startups
Security often gets pushed to the back burner at startups until something breaks or a big deal requires it. But what if you could get expert security guidance without the overhead?
At Ophion Security, we have worked with startups and large enterprises to secure their products, cloud environments, and compliance posture without slowing down growth. As part of that mission, weโre offering free security advisory ask us anything, and weโll personally reply with actionable advice.
โ Worried about SOC 2, ISO 27001, or customer security questionnaires?
โ Unsure if youโre protecting customer data correctly?
โ Need guidance on securing your cloud infra, SaaS stack, or engineering workflows?
โ Question about getting the right pentest done and what should be in scope?
Drop your security questions here, and weโll respond within 24 hrs, no strings attached: https://t.co/pNyBnLONfU
#startupsecurity #growth #founders #security #TechStartups #CloudSecurity
Live chat histories contain treasure trove of data. From answers to security questions to credentials and more. We found a way to access it all in Cisco's Webex Connect. Read here: https://t.co/JcEA5TkyIE #vulnerability#vulnerabilitydisclosure#attacksurfacemanagement
As we build Orion actively, we run it against real world targets with disclosure policy. We did the same for Microsoft. Checkout the demo page to see how we are monitoring more than 4,000 users and 160,000 repositories of Microsoft and other organizations. https://t.co/1fRq4AfcjX
#githubactions #githubsecurity #bugbounty #attacksurfacemanagement