home.social

#cybesecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cybesecurity, aggregated by home.social.

fetched live
  1. C-level executives in #fintech strike a balance between the benefits #AI can offer their businesses and the need to guard against its #cybesecurity risks.

    This feature story includes two in-depth interviews with IT leaders. Each detailed how they used new tools and new approaches to how people work within their companies to avoid becoming the "party of no" regarding employees' use of AI -- while still maintaining security controls.

    Check it out: techtarget.com/it-strategy/new

  2. C-level executives in #fintech strike a balance between the benefits #AI can offer their businesses and the need to guard against its #cybesecurity risks.

    This feature story includes two in-depth interviews with IT leaders. Each detailed how they used new tools and new approaches to how people work within their companies to avoid becoming the "party of no" regarding employees' use of AI -- while still maintaining security controls.

    Check it out: techtarget.com/it-strategy/new

  3. C-level executives in strike a balance between the benefits can offer their businesses and the need to guard against its risks.

    This feature story includes two in-depth interviews with IT leaders. Each detailed how they used new tools and new approaches to how people work within their companies to avoid becoming the "party of no" regarding employees' use of AI -- while still maintaining security controls.

    Check it out: techtarget.com/it-strategy/new

  4. C-level executives in #fintech strike a balance between the benefits #AI can offer their businesses and the need to guard against its #cybesecurity risks.

    This feature story includes two in-depth interviews with IT leaders. Each detailed how they used new tools and new approaches to how people work within their companies to avoid becoming the "party of no" regarding employees' use of AI -- while still maintaining security controls.

    Check it out: techtarget.com/it-strategy/new

  5. C-level executives in #fintech strike a balance between the benefits #AI can offer their businesses and the need to guard against its #cybesecurity risks.

    This feature story includes two in-depth interviews with IT leaders. Each detailed how they used new tools and new approaches to how people work within their companies to avoid becoming the "party of no" regarding employees' use of AI -- while still maintaining security controls.

    Check it out: techtarget.com/it-strategy/new

  6. Cybersecurity nel mondo Education: perche’ i servizi MDR diventano strategici: Scuole e universita’ si trovano oggi ad affrontare uno scenario cyber sempre piu’ complesso, in cui ransomware, furti di dati e attacchi mirati mettono a rischio non...
    #SamueleZaniboni #ESETItalia #cybesecurity #IT #MDR dlvr.it/TSbBqL

  7. Cybersecurity nel mondo Education: perche’ i servizi MDR diventano strategici: Scuole e universita’ si trovano oggi ad affrontare uno scenario cyber sempre piu’ complesso, in cui ransomware, furti di dati e attacchi mirati mettono a rischio non...
    #SamueleZaniboni #ESETItalia #cybesecurity #IT #MDR dlvr.it/TSbBqL

  8. Weekendowa Lektura: odcinek 657 [2026-01-02]. Bierzcie i czytajcie

    🇵🇱 zaufanatrzeciastrona.pl/post/w

    🇬🇧 badcyber.com/it-security-weeke

    Przestępcy – jak można się było spodziewać – ani myślą o noworoczno-świątecznej przerwie, stąd całkiem sporo artykułów, które mieliśmy okazję przejrzeć i dla Was wybrać.

    #infosec #cyberbezpieczenstwo #cybesecurity #weekendowalektura

  9. Weekendowa Lektura: odcinek 657 [2026-01-02]. Bierzcie i czytajcie

    🇵🇱 zaufanatrzeciastrona.pl/post/w

    🇬🇧 badcyber.com/it-security-weeke

    Przestępcy – jak można się było spodziewać – ani myślą o noworoczno-świątecznej przerwie, stąd całkiem sporo artykułów, które mieliśmy okazję przejrzeć i dla Was wybrać.

    #infosec #cyberbezpieczenstwo #cybesecurity #weekendowalektura

  10. Weekendowa Lektura: odcinek 657 [2026-01-02]. Bierzcie i czytajcie

    🇵🇱 zaufanatrzeciastrona.pl/post/w

    🇬🇧 badcyber.com/it-security-weeke

    Przestępcy – jak można się było spodziewać – ani myślą o noworoczno-świątecznej przerwie, stąd całkiem sporo artykułów, które mieliśmy okazję przejrzeć i dla Was wybrać.

    #infosec #cyberbezpieczenstwo #cybesecurity #weekendowalektura

  11. Weekendowa Lektura: odcinek 657 [2026-01-02]. Bierzcie i czytajcie

    🇵🇱 zaufanatrzeciastrona.pl/post/w

    🇬🇧 badcyber.com/it-security-weeke

    Przestępcy – jak można się było spodziewać – ani myślą o noworoczno-świątecznej przerwie, stąd całkiem sporo artykułów, które mieliśmy okazję przejrzeć i dla Was wybrać.

    #infosec #cyberbezpieczenstwo #cybesecurity #weekendowalektura

  12. Weekendowa Lektura: odcinek 657 [2026-01-02]. Bierzcie i czytajcie

    🇵🇱 zaufanatrzeciastrona.pl/post/w

    🇬🇧 badcyber.com/it-security-weeke

    Przestępcy – jak można się było spodziewać – ani myślą o noworoczno-świątecznej przerwie, stąd całkiem sporo artykułów, które mieliśmy okazję przejrzeć i dla Was wybrać.

    #infosec #cyberbezpieczenstwo #cybesecurity #weekendowalektura

  13. Hello! I’m building a mentoring platform for aspiring #hackers and security learners who want deeper, non-corporate guidance. It’s for self-taught people and students (OSCP, cybersecurity degrees) who want 1-on-1 help. learn2hack.today is almost ready and accounts will open soon. If you're interested, fill this: tally.so/r/J9KZkz
    #hacking #mentoring #students #hackerculture #hackers #students #cybesecurity #security #redteam #pentesting #hackingisnotacrime #oscp #ctf #bughunting

  14. Hello! I’m building a mentoring platform for aspiring #hackers and security learners who want deeper, non-corporate guidance. It’s for self-taught people and students (OSCP, cybersecurity degrees) who want 1-on-1 help. learn2hack.today is almost ready and accounts will open soon. If you're interested, fill this: tally.so/r/J9KZkz
    #hacking #mentoring #students #hackerculture #hackers #students #cybesecurity #security #redteam #pentesting #hackingisnotacrime #oscp #ctf #bughunting

  15. Hello! I’m building a mentoring platform for aspiring #hackers and security learners who want deeper, non-corporate guidance. It’s for self-taught people and students (OSCP, cybersecurity degrees) who want 1-on-1 help. learn2hack.today is almost ready and accounts will open soon. If you're interested, fill this: tally.so/r/J9KZkz
    #hacking #mentoring #students #hackerculture #hackers #students #cybesecurity #security #redteam #pentesting #hackingisnotacrime #oscp #ctf #bughunting

  16. Hello! I’m building a mentoring platform for aspiring #hackers and security learners who want deeper, non-corporate guidance. It’s for self-taught people and students (OSCP, cybersecurity degrees) who want 1-on-1 help. learn2hack.today is almost ready and accounts will open soon. If you're interested, fill this: tally.so/r/J9KZkz
    #hacking #mentoring #students #hackerculture #hackers #students #cybesecurity #security #redteam #pentesting #hackingisnotacrime #oscp #ctf #bughunting

  17. Hello! I’m building a mentoring platform for aspiring #hackers and security learners who want deeper, non-corporate guidance. It’s for self-taught people and students (OSCP, cybersecurity degrees) who want 1-on-1 help. learn2hack.today is almost ready and accounts will open soon. If you're interested, fill this: tally.so/r/J9KZkz
    #hacking #mentoring #students #hackerculture #hackers #students #cybesecurity #security #redteam #pentesting #hackingisnotacrime #oscp #ctf #bughunting

  18. Wazuh: Детальный разбор localfile — настройка сбора логов в SIEM-системе

    Привет, хабровчане! Если вы занимаетесь DevOps, системным администрированием или кибербезопасностью, то Wazuh — это ваш must-have для мониторинга и SIEM. В этой статье (и соответствующем видео на моём канале) мы разберём секцию в конфигурации агента Wazuh. Это ключевой компонент Logcollector'а, который отвечает за сбор логов из файлов, системных событий, команд и даже journald. Без правильной настройки вы рискуете пропустить важные события или утонуть в шуме. Статья основана на официальной документации ( documentation.wazuh.com/curren ), с практическими примерами из реальных конфигов. Если необходимо видео, то можно посмотреть тут ( youtu.be/69mVhQsjXZU ).

    habr.com/ru/articles/964290/

    #siem #сием #wazuh #вазух #security #cybesecurity

  19. Wazuh: Детальный разбор localfile — настройка сбора логов в SIEM-системе

    Привет, хабровчане! Если вы занимаетесь DevOps, системным администрированием или кибербезопасностью, то Wazuh — это ваш must-have для мониторинга и SIEM. В этой статье (и соответствующем видео на моём канале) мы разберём секцию в конфигурации агента Wazuh. Это ключевой компонент Logcollector'а, который отвечает за сбор логов из файлов, системных событий, команд и даже journald. Без правильной настройки вы рискуете пропустить важные события или утонуть в шуме. Статья основана на официальной документации ( documentation.wazuh.com/curren ), с практическими примерами из реальных конфигов. Если необходимо видео, то можно посмотреть тут ( youtu.be/69mVhQsjXZU ).

    habr.com/ru/articles/964290/

    #siem #сием #wazuh #вазух #security #cybesecurity

  20. Wazuh: Детальный разбор localfile — настройка сбора логов в SIEM-системе

    Привет, хабровчане! Если вы занимаетесь DevOps, системным администрированием или кибербезопасностью, то Wazuh — это ваш must-have для мониторинга и SIEM. В этой статье (и соответствующем видео на моём канале) мы разберём секцию в конфигурации агента Wazuh. Это ключевой компонент Logcollector'а, который отвечает за сбор логов из файлов, системных событий, команд и даже journald. Без правильной настройки вы рискуете пропустить важные события или утонуть в шуме. Статья основана на официальной документации ( documentation.wazuh.com/curren ), с практическими примерами из реальных конфигов. Если необходимо видео, то можно посмотреть тут ( youtu.be/69mVhQsjXZU ).

    habr.com/ru/articles/964290/

    #siem #сием #wazuh #вазух #security #cybesecurity

  21. I'm not sure if you all read the news about the rogue communication devices found in Chinese solar power inverters?

    If not here is a short recap of the Reuters article from 2025-05-14:

    Two anonymous U.S experts stated that they found "rogue" communication devices that were not listed in product documents in some Chinese solar inverters.
    They also claimed that similar undocumented communication devices, including cellular radios, have also been found previously in some batteries from Chinese suppliers.

    These communication devices could be used to bypass firewalls and switch off inverters remotely, or change their settings, could destabilize power grids, damage energy infrastructure, and trigger widespread blackouts. In the end the devices could be used to physically destroy the grid.

    The whole article is here:
    reuters.com/sustainability/cli

    While Reuters stayed vague enough to not be wrong, other news outlets were quick to postulate that a Chinese “kill switches” had been found hidden in American solar farms.

    While I don't doubt the theoretical possibility of the envisioned attack, the story still feels off to me!

    The story just contains too few details. Reading it carefully it just states that undocumented components or undocumented communication devices were found. The "rogue" part is an interpretation. The theoretical consequences are valid nevertheless.

    It remind me a lot of the story of spy chips on server boards (2018), which The Register described as a "mishmash of disparate and inaccurate allegations" .
    theregister.com/2021/02/12/sup

    What do you think?

    #Cybesecurity #CriticalInfrastructure

  22. I'm not sure if you all read the news about the rogue communication devices found in Chinese solar power inverters?

    If not here is a short recap of the Reuters article from 2025-05-14:

    Two anonymous U.S experts stated that they found "rogue" communication devices that were not listed in product documents in some Chinese solar inverters.
    They also claimed that similar undocumented communication devices, including cellular radios, have also been found previously in some batteries from Chinese suppliers.

    These communication devices could be used to bypass firewalls and switch off inverters remotely, or change their settings, could destabilize power grids, damage energy infrastructure, and trigger widespread blackouts. In the end the devices could be used to physically destroy the grid.

    The whole article is here:
    reuters.com/sustainability/cli

    While Reuters stayed vague enough to not be wrong, other news outlets were quick to postulate that a Chinese “kill switches” had been found hidden in American solar farms.

    While I don't doubt the theoretical possibility of the envisioned attack, the story still feels off to me!

    The story just contains too few details. Reading it carefully it just states that undocumented components or undocumented communication devices were found. The "rogue" part is an interpretation. The theoretical consequences are valid nevertheless.

    It remind me a lot of the story of spy chips on server boards (2018), which The Register described as a "mishmash of disparate and inaccurate allegations" .
    theregister.com/2021/02/12/sup

    What do you think?

    #Cybesecurity #CriticalInfrastructure

  23. I'm not sure if you all read the news about the rogue communication devices found in Chinese solar power inverters?

    If not here is a short recap of the Reuters article from 2025-05-14:

    Two anonymous U.S experts stated that they found "rogue" communication devices that were not listed in product documents in some Chinese solar inverters.
    They also claimed that similar undocumented communication devices, including cellular radios, have also been found previously in some batteries from Chinese suppliers.

    These communication devices could be used to bypass firewalls and switch off inverters remotely, or change their settings, could destabilize power grids, damage energy infrastructure, and trigger widespread blackouts. In the end the devices could be used to physically destroy the grid.

    The whole article is here:
    reuters.com/sustainability/cli

    While Reuters stayed vague enough to not be wrong, other news outlets were quick to postulate that a Chinese “kill switches” had been found hidden in American solar farms.

    While I don't doubt the theoretical possibility of the envisioned attack, the story still feels off to me!

    The story just contains too few details. Reading it carefully it just states that undocumented components or undocumented communication devices were found. The "rogue" part is an interpretation. The theoretical consequences are valid nevertheless.

    It remind me a lot of the story of spy chips on server boards (2018), which The Register described as a "mishmash of disparate and inaccurate allegations" .
    theregister.com/2021/02/12/sup

    What do you think?

    #Cybesecurity #CriticalInfrastructure

  24. I'm not sure if you all read the news about the rogue communication devices found in Chinese solar power inverters?

    If not here is a short recap of the Reuters article from 2025-05-14:

    Two anonymous U.S experts stated that they found "rogue" communication devices that were not listed in product documents in some Chinese solar inverters.
    They also claimed that similar undocumented communication devices, including cellular radios, have also been found previously in some batteries from Chinese suppliers.

    These communication devices could be used to bypass firewalls and switch off inverters remotely, or change their settings, could destabilize power grids, damage energy infrastructure, and trigger widespread blackouts. In the end the devices could be used to physically destroy the grid.

    The whole article is here:
    reuters.com/sustainability/cli

    While Reuters stayed vague enough to not be wrong, other news outlets were quick to postulate that a Chinese “kill switches” had been found hidden in American solar farms.

    While I don't doubt the theoretical possibility of the envisioned attack, the story still feels off to me!

    The story just contains too few details. Reading it carefully it just states that undocumented components or undocumented communication devices were found. The "rogue" part is an interpretation. The theoretical consequences are valid nevertheless.

    It remind me a lot of the story of spy chips on server boards (2018), which The Register described as a "mishmash of disparate and inaccurate allegations" .
    theregister.com/2021/02/12/sup

    What do you think?

    #Cybesecurity #CriticalInfrastructure

  25. I'm not sure if you all read the news about the rogue communication devices found in Chinese solar power inverters?

    If not here is a short recap of the Reuters article from 2025-05-14:

    Two anonymous U.S experts stated that they found "rogue" communication devices that were not listed in product documents in some Chinese solar inverters.
    They also claimed that similar undocumented communication devices, including cellular radios, have also been found previously in some batteries from Chinese suppliers.

    These communication devices could be used to bypass firewalls and switch off inverters remotely, or change their settings, could destabilize power grids, damage energy infrastructure, and trigger widespread blackouts. In the end the devices could be used to physically destroy the grid.

    The whole article is here:
    reuters.com/sustainability/cli

    While Reuters stayed vague enough to not be wrong, other news outlets were quick to postulate that a Chinese “kill switches” had been found hidden in American solar farms.

    While I don't doubt the theoretical possibility of the envisioned attack, the story still feels off to me!

    The story just contains too few details. Reading it carefully it just states that undocumented components or undocumented communication devices were found. The "rogue" part is an interpretation. The theoretical consequences are valid nevertheless.

    It remind me a lot of the story of spy chips on server boards (2018), which The Register described as a "mishmash of disparate and inaccurate allegations" .
    theregister.com/2021/02/12/sup

    What do you think?

    #Cybesecurity #CriticalInfrastructure

  26. Explore the power of Urlex! 🌐✨ This amazing URL expander safely reveals the full links behind shortened URLs, making it the fastest and easiest way to unmask them. 🚀🔗 With batch expansion and custom timeouts, it's perfect for anyone needing efficiency! Check it out 👉 urlex.org #URLExpander #SafetyFirst #TechTools #WebUtility #privacy #cybesecurity

  27. Explore the power of Urlex! 🌐✨ This amazing URL expander safely reveals the full links behind shortened URLs, making it the fastest and easiest way to unmask them. 🚀🔗 With batch expansion and custom timeouts, it's perfect for anyone needing efficiency! Check it out 👉 urlex.org #URLExpander #SafetyFirst #TechTools #WebUtility #privacy #cybesecurity

  28. Explore the power of Urlex! 🌐✨ This amazing URL expander safely reveals the full links behind shortened URLs, making it the fastest and easiest way to unmask them. 🚀🔗 With batch expansion and custom timeouts, it's perfect for anyone needing efficiency! Check it out 👉 urlex.org #URLExpander #SafetyFirst #TechTools #WebUtility #privacy #cybesecurity

  29. Explore the power of Urlex! 🌐✨ This amazing URL expander safely reveals the full links behind shortened URLs, making it the fastest and easiest way to unmask them. 🚀🔗 With batch expansion and custom timeouts, it's perfect for anyone needing efficiency! Check it out 👉 urlex.org

  30. Explore the power of Urlex! 🌐✨ This amazing URL expander safely reveals the full links behind shortened URLs, making it the fastest and easiest way to unmask them. 🚀🔗 With batch expansion and custom timeouts, it's perfect for anyone needing efficiency! Check it out 👉 urlex.org #URLExpander #SafetyFirst #TechTools #WebUtility #privacy #cybesecurity

  31. Videosorveglianza e Privacy: la tutela dell’operatore in ambito Forze dell’Ordine, sanita’, trasporti. Relatori al convegno di Battipaglia: Il Comune di Battipaglia ospitera’ l’evento formativo l’8 ottobre prossimo, segniamo la data! Al centro dell’iniziativa e della serie di interventi, un tema emergente nel mondo dell’utenza pubblica e privata, in ambito sanitario, dei trasporti e della sicurezza urbana: la tutela...
    #Videosorveglianza #privacy #cybesecuritydlvr.it/TCPsWV

  32. Videosorveglianza e Privacy: la tutela dell’operatore in ambito Forze dell’Ordine, sanita’, trasporti. Relatori al convegno di Battipaglia: Il Comune di Battipaglia ospitera’ l’evento formativo l’8 ottobre prossimo, segniamo la data! Al centro dell’iniziativa e della serie di interventi, un tema emergente nel mondo dell’utenza pubblica e privata, in ambito sanitario, dei trasporti e della sicurezza urbana: la tutela...
    #Videosorveglianza #privacy #cybesecuritydlvr.it/TCPsWV

  33. In my last livestream you could witness LIVE, how not reading an exploit (or its code for that matter) can cause some unnecessary headaches (in the best case). Sometimes I fall into these kind of "amateur-ish" patterns (especially during livestreams). :ablobcatmelt:

    ⬇️ I downloaded this exploit and tried to run it with a simple "PHP GET-CMD" webshell:

    github.com/kimusan/pkwner/blob

    After failing to do some damage with that one, I finally read the code and saw the "/bin/bash" at the end (thanks to the walkthrough of @0xdf I found the exploit in the first place, and after reading the walkthrough I also saw the bash line there). :flan_hacker:

    And then I got the root flag thanks to the writeup :blobsmile:

    TL;DR: Read the Exploit Code and try to understand it...

    #hacking #cybesecurity #ctf #hackthebox

  34. In my last livestream you could witness LIVE, how not reading an exploit (or its code for that matter) can cause some unnecessary headaches (in the best case). Sometimes I fall into these kind of "amateur-ish" patterns (especially during livestreams). :ablobcatmelt:

    ⬇️ I downloaded this exploit and tried to run it with a simple "PHP GET-CMD" webshell:

    github.com/kimusan/pkwner/blob

    After failing to do some damage with that one, I finally read the code and saw the "/bin/bash" at the end (thanks to the walkthrough of @0xdf I found the exploit in the first place, and after reading the walkthrough I also saw the bash line there). :flan_hacker:

    And then I got the root flag thanks to the writeup :blobsmile:

    TL;DR: Read the Exploit Code and try to understand it...

    #hacking #cybesecurity #ctf #hackthebox

  35. In my last livestream you could witness LIVE, how not reading an exploit (or its code for that matter) can cause some unnecessary headaches (in the best case). Sometimes I fall into these kind of "amateur-ish" patterns (especially during livestreams). :ablobcatmelt:

    ⬇️ I downloaded this exploit and tried to run it with a simple "PHP GET-CMD" webshell:

    github.com/kimusan/pkwner/blob

    After failing to do some damage with that one, I finally read the code and saw the "/bin/bash" at the end (thanks to the walkthrough of @0xdf I found the exploit in the first place, and after reading the walkthrough I also saw the bash line there). :flan_hacker:

    And then I got the root flag thanks to the writeup :blobsmile:

    TL;DR: Read the Exploit Code and try to understand it...

    #hacking #cybesecurity #ctf #hackthebox

  36. In my last livestream you could witness LIVE, how not reading an exploit (or its code for that matter) can cause some unnecessary headaches (in the best case). Sometimes I fall into these kind of "amateur-ish" patterns (especially during livestreams). :ablobcatmelt:

    ⬇️ I downloaded this exploit and tried to run it with a simple "PHP GET-CMD" webshell:

    github.com/kimusan/pkwner/blob

    After failing to do some damage with that one, I finally read the code and saw the "/bin/bash" at the end (thanks to the walkthrough of @0xdf I found the exploit in the first place, and after reading the walkthrough I also saw the bash line there). :flan_hacker:

    And then I got the root flag thanks to the writeup :blobsmile:

    TL;DR: Read the Exploit Code and try to understand it...

    #hacking #cybesecurity #ctf #hackthebox

  37. #LLRX #CybeSecurity @bespacific

    Pete Recommends – Weekly highlights on cyber security issues, May 18, 2024

    Four highlights from this week: Google Accidentally Deleted $125 Billion Pension Fund's Account; Generating Harms: Generative AI’s New & Continued Impacts; What I wish I’d known before my smartphone was snatched; and Mortgage Brokers Sent People’s Estimated Credit, Address, and Veteran Status to Facebook.

    Posted in: AI, Cybercrime, Cybersecurity, Financial System, Legal Research, #privacy Social Media

    llrx.com/2024/05/pete-recommen

  38. #LLRX #CybeSecurity @bespacific

    Pete Recommends – Weekly highlights on cyber security issues, May 18, 2024

    Four highlights from this week: Google Accidentally Deleted $125 Billion Pension Fund's Account; Generating Harms: Generative AI’s New & Continued Impacts; What I wish I’d known before my smartphone was snatched; and Mortgage Brokers Sent People’s Estimated Credit, Address, and Veteran Status to Facebook.

    Posted in: AI, Cybercrime, Cybersecurity, Financial System, Legal Research, #privacy Social Media

    llrx.com/2024/05/pete-recommen

  39. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  40. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  41. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  42. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  43. @adamshostack @RuthMalan

    Sorry for the dummy follow up questions
    What does UW mean on this context 🥴?

    Today was the discussion and I learned a lot about #STPA/ #STAMP
    The checklist of hazards on each controller would IMHO be helpful in #cybesecurity
    Actually it feels to me that #STRIDE represents these hazards on one level

  44. The Canadian Centre for Cyber Security has an interesting article on #CybeSecurity #ThreatActors (adversaries) and their motivation.

    cyber.gc.ca/en/guidance/introd

    The article IMHO leaves out at some threat actors (which might not be that relevant for a commercial or critical infrastructure setting)

    • Abusive Partners
    • Stalkers
    • Kids

    while these could be seen as part of insider threats, I believe that their capabilities and opportunities are different from other insiders.
    And they are often overlooked when developing consumer products.
    Think of the problems with #AirTags or the bike theft "problem" with Strava.

    I really like this and are thinking of creating a game around it to raise security awareness (especially within development and designe of systems). #SeriousGames

    Idea is to have a collaborative game where you play through threats against your system. Starting with the Threat Actors, their intend, capabilities and opportunities.
    Going through techniques used (maybe using a subset of #MitreAttack but also common #SocialEngineering techniques).
    And then choosing mitigation and defense options.

    A bit of a mixture between #ElevationOfPrivilege/#EoP, #BackdoorsAndBreaches and #FearlessJourney

  45. The Canadian Centre for Cyber Security has an interesting article on #CybeSecurity #ThreatActors (adversaries) and their motivation.

    cyber.gc.ca/en/guidance/introd

    The article IMHO leaves out at some threat actors (which might not be that relevant for a commercial or critical infrastructure setting)

    • Abusive Partners
    • Stalkers
    • Kids

    while these could be seen as part of insider threats, I believe that their capabilities and opportunities are different from other insiders.
    And they are often overlooked when developing consumer products.
    Think of the problems with #AirTags or the bike theft "problem" with Strava.

    I really like this and are thinking of creating a game around it to raise security awareness (especially within development and designe of systems). #SeriousGames

    Idea is to have a collaborative game where you play through threats against your system. Starting with the Threat Actors, their intend, capabilities and opportunities.
    Going through techniques used (maybe using a subset of #MitreAttack but also common #SocialEngineering techniques).
    And then choosing mitigation and defense options.

    A bit of a mixture between #ElevationOfPrivilege/#EoP, #BackdoorsAndBreaches and #FearlessJourney

  46. The Canadian Centre for Cyber Security has an interesting article on #CybeSecurity #ThreatActors (adversaries) and their motivation.

    cyber.gc.ca/en/guidance/introd

    The article IMHO leaves out at some threat actors (which might not be that relevant for a commercial or critical infrastructure setting)

    • Abusive Partners
    • Stalkers
    • Kids

    while these could be seen as part of insider threats, I believe that their capabilities and opportunities are different from other insiders.
    And they are often overlooked when developing consumer products.
    Think of the problems with #AirTags or the bike theft "problem" with Strava.

    I really like this and are thinking of creating a game around it to raise security awareness (especially within development and designe of systems). #SeriousGames

    Idea is to have a collaborative game where you play through threats against your system. Starting with the Threat Actors, their intend, capabilities and opportunities.
    Going through techniques used (maybe using a subset of #MitreAttack but also common #SocialEngineering techniques).
    And then choosing mitigation and defense options.

    A bit of a mixture between #ElevationOfPrivilege/#EoP, #BackdoorsAndBreaches and #FearlessJourney

  47. The Canadian Centre for Cyber Security has an interesting article on #CybeSecurity #ThreatActors (adversaries) and their motivation.

    cyber.gc.ca/en/guidance/introd

    The article IMHO leaves out at some threat actors (which might not be that relevant for a commercial or critical infrastructure setting)

    • Abusive Partners
    • Stalkers
    • Kids

    while these could be seen as part of insider threats, I believe that their capabilities and opportunities are different from other insiders.
    And they are often overlooked when developing consumer products.
    Think of the problems with #AirTags or the bike theft "problem" with Strava.

    I really like this and are thinking of creating a game around it to raise security awareness (especially within development and designe of systems). #SeriousGames

    Idea is to have a collaborative game where you play through threats against your system. Starting with the Threat Actors, their intend, capabilities and opportunities.
    Going through techniques used (maybe using a subset of #MitreAttack but also common #SocialEngineering techniques).
    And then choosing mitigation and defense options.

    A bit of a mixture between #ElevationOfPrivilege/#EoP, #BackdoorsAndBreaches and #FearlessJourney

  48. The Canadian Centre for Cyber Security has an interesting article on #CybeSecurity #ThreatActors (adversaries) and their motivation.

    cyber.gc.ca/en/guidance/introd

    The article IMHO leaves out at some threat actors (which might not be that relevant for a commercial or critical infrastructure setting)

    • Abusive Partners
    • Stalkers
    • Kids

    while these could be seen as part of insider threats, I believe that their capabilities and opportunities are different from other insiders.
    And they are often overlooked when developing consumer products.
    Think of the problems with #AirTags or the bike theft "problem" with Strava.

    I really like this and are thinking of creating a game around it to raise security awareness (especially within development and designe of systems). #SeriousGames

    Idea is to have a collaborative game where you play through threats against your system. Starting with the Threat Actors, their intend, capabilities and opportunities.
    Going through techniques used (maybe using a subset of #MitreAttack but also common #SocialEngineering techniques).
    And then choosing mitigation and defense options.

    A bit of a mixture between #ElevationOfPrivilege/#EoP, #BackdoorsAndBreaches and #FearlessJourney

  49. In my previous post, I explored the integration of ChatGPT with Microsoft Sentinel.
    In this new post, I'll be sharing my experience of integrating ChatGPT with Jupyter Notebook, a popular open-source platform for data analysis.
    The aim of this Notebook is to provide an interface for asking questions to ChatGPT, assisting security analysts in investigating cyber threats with Microsoft Sentinel Notebooks.

    Blog post: medium.com/@antonio.formato/ge

    GitHub repo: github.com/format81/JupyterNot

    Demo: youtu.be/znvy2m97Cb0

    #microsoft #azure #microsoftsentinel #chatGPT #AI #GPT #cybesecurity #Jupiter #jupyternotebook #notebook #python #mysticpy #kql #azureml #cyberthreats #soc #analysts #incidentresponse #cyber #cloud #cloudnative #cloudsecurity #MulticloudMindset