home.social

#cybesecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cybesecurity, aggregated by home.social.

  1. Hello! I’m building a mentoring platform for aspiring #hackers and security learners who want deeper, non-corporate guidance. It’s for self-taught people and students (OSCP, cybersecurity degrees) who want 1-on-1 help. learn2hack.today is almost ready and accounts will open soon. If you're interested, fill this: tally.so/r/J9KZkz
    #hacking #mentoring #students #hackerculture #hackers #students #cybesecurity #security #redteam #pentesting #hackingisnotacrime #oscp #ctf #bughunting

  2. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  3. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  4. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  5. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  6. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  7. The Canadian Centre for Cyber Security has an interesting article on #CybeSecurity #ThreatActors (adversaries) and their motivation.

    cyber.gc.ca/en/guidance/introd

    The article IMHO leaves out at some threat actors (which might not be that relevant for a commercial or critical infrastructure setting)

    • Abusive Partners
    • Stalkers
    • Kids

    while these could be seen as part of insider threats, I believe that their capabilities and opportunities are different from other insiders.
    And they are often overlooked when developing consumer products.
    Think of the problems with #AirTags or the bike theft "problem" with Strava.

    I really like this and are thinking of creating a game around it to raise security awareness (especially within development and designe of systems). #SeriousGames

    Idea is to have a collaborative game where you play through threats against your system. Starting with the Threat Actors, their intend, capabilities and opportunities.
    Going through techniques used (maybe using a subset of #MitreAttack but also common #SocialEngineering techniques).
    And then choosing mitigation and defense options.

    A bit of a mixture between #ElevationOfPrivilege/#EoP, #BackdoorsAndBreaches and #FearlessJourney