New TAG post on Countering Threats from Iran https://t.co/ZIVSArh5P1
Aim is to provide some new details on what Ajax and the team discovered and blocked from APT35 (also known as Rocket Kitten and some other names)
Folks doing security audit/hardening or pentesting in containers, in particular in Kubernetes, this tool might be relevant to your interests:
https://t.co/SoAvAsaajD
https://t.co/k1XZwRw8hB
(And thanks to @mahe_tardy I also learned about kubeletctl!)
In 2016, @dagrz gave one of the greatest cloud security talks ever, filled with new techniques that have been rediscovered repeatedly in the years since. I've remastered it from video obtained from an audience member and the slide deck. https://t.co/o0sMXeZPiw
Just finished Securing DevOps book from @jvehent. Wow thx a lot! The book is very well organized and explained well the topics. It gives you strategy to bring security in DevOps. Everybody should read it.
Protect yourself from dangers looming in the cloud! Securing DevOps, our Deal of the Day, teaches you how to secure your cloud services: https://t.co/GaGHId66fU #DevOps#security@jvehent#cloud#cloudsecurity
Just finshed reading @SecuringDevOps by @jvehent. What a great book! The part I liked most is chapter 13, where a high-level 3-year strategy for implementing security practices in an agile world is outlined. Highly recommended!
Devops looking for an approach to continuous security? Tune in to the latest episode of the @TestGuilds podcast hosted by @joecolantonio, starring @jvehent of Securing DevOps https://t.co/QaveRlrLyA #DevOps#security
Last week, the GCP team added a "Run With Google Cloud" button you can put on your READMEs to automatically ship an application to their cloud. I had to test it, so here ya go, 5min demo time! https://t.co/lTbuyrnb4E
Book recommendation for #DevSecOps, @SecuringDevOps by @jvehent. A great in-depth walkthrough of building a DevOps pipeline and then securing it. Highly recommend, especially for those looking to secure workloads in the public cloud. https://t.co/mgUpoS3ajs
About halfway through Securing DevOps by @jvehent. Fantastic DevSecOps book, especially if you are trying to focus on how security comes into play with the DevOps pipeline. #DevSecOps
If you didn't get your copy yet, this @ManningBooks "Deal of the Day" might be a good excuse 😉: Half off Securing DevOps using code dotd031619au at https://t.co/LZmIwOlHOa
What do you think of the Show&Tell so far? Should the episodes be shorter? Longer? More or less detailed?
Drop me feedback in replies or DM as I plan the next round of episodes.
Episode 3 of the Securing DevOps Show & Tell is out! I talk about secrets management with Mozilla Sops this time around, with a demo of encrypted config files with PGP, {AWS,GCP} KMS, and a discussion on the bootstrapping of trust problem. Check it out! https://t.co/YE3UmT7NRK
@Voulnet If you get it from https://t.co/r6zrZM8uwR, you also get access to the LiveBook HTML version. Highly recommended to annotate or link to parts of the book, or even leave comments to the author!