#egress — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #egress, aggregated by home.social.
-
5 ошибок в NetworkPolicy, из‑за которых ваши политики ничего не блокируют
NetworkPolicy могут выглядеть корректно, применяться без ошибок и при этом оставлять кластер открытым там, где вы уверены в изоляции. Разберём пять типичных ошибок — от CNI без поддержки политик до неверных селекторов — и покажем, как проверять правила реальным трафиком, а не по наличию объектов в API.
https://habr.com/ru/companies/otus/articles/1067158/
#Kubernetes #NetworkPolicy #сетевые_политики #CNI #Calico #Cilium #ingress #egress #сетевая_изоляция #безопасность_Kubernetes
-
Happy to reassure our users that the #egress evasion TTPs used by the Agent in the OpenAI and Hugging Face incident have long been mitigated in #DiscrimiNAT OTF (outbound traffic filtering). In fact, in our demos, we show these attacks being caught. #2 is SNI spoofing, btw.
https://huggingface.co/blog/agent-intrusion-technical-timeline
-
Update profile on APT28/Unit 26165/Fancy Bear by on Gov·UK [1].
"Unit 26165 accessed private IP cameras near military facilities, ports, train stations and border crossings in Ukraine, Moldova and 11 NATO countries to track the movement of foreign assistance"
They seem to have this X-Agent & X-Tunnel pair of malware to pull this off of "private IP" cameras. From ESET's 2016 analysis [2] of it, we can see that the X-Tunnel infected computer will initiate an outbound connection (direction #egress) to first the C2 server then to the victim in the private IP network.
While ingress firewalls can reduce noise and offer some degree of control, it's #egress filtering that offers stronger security.
[1] https://www.gov.uk/government/publications/profile-gru-cyber-and-hybrid-threat-operations/profile-gru-cyber-and-hybrid-threat-operations
[2] https://web-assets.esetstatic.com/wls/2016/10/eset-sednit-part-2.pdf -
65% of breaches could've been prevented according to this research by Niels Provos if only Hardware second factors, Egress control and Positive execution control would've been in place. I couldn't agree more when he says, "most companies don’t realize they need this protection" on #egress filtering.
Number of times I've had to explain outbound connections originating from within a network to DevOps, SecOps alike 🤯
https://securityblueprints.io/posts/three-security-invariants-ciso-challenge/
-
VPC Endpoint Bucket Policies are completely ineffectual in preventing exfiltration if the workload has access to the Internet. Just upload to the $otherCloud's storage endpoint.
This is where #egress filtering at the NAT gateway layer prevents a compromise.
-
Регион выхода — это инфраструктура, а не настройка у пользователя
Сервис открывается, отвечает, всё работает — но цены в другой валюте, половина функций спрятана, а платёжный шаг падает с невнятной ошибкой. Через час выясняется, что выдача зависит от того, из какого региона пришёл запрос, а вы ходите из «неправильного». Знакомо всем, кто проверял локализацию продукта или подключался к региональному B2B‑порталу из другой страны. Дальше обычно появляется VPN до нужного региона, и на этом задача считается решённой. На практике решённой она не считается — просто проблема переезжает в то место, где её не видно.
https://habr.com/ru/articles/1051676/
#policybased_routing #маршрутизация_трафика #egress #Squid #CDN #SNI #прокси
-
8 PoPs по миру за €46/мес: реальная экономика pet privacy-DNS в цифрах
Я полгода в одиночку пилю VantageDNS, privacy-focused recursive DNS с фильтрацией. Аналог NextDNS, юрисдикция EU. Ниже честный построчный разбор того, во что мне на самом деле обходится сеть из 8 нод по миру и контрол-плейн. Не маркетинговое «около ста евро», а реальная цифра, которая каждый месяц списывается с карты: €46.27. В конце таблица расходов и прикидка, сколько платных юзеров надо, чтобы это перестало быть хобби. Показать счёт
https://habr.com/ru/articles/1035616/
#VPS #инфраструктура #egress #DNSпровайдер #lowcost #индихакерство #биллинг #EU #экономика #soлоSaaS
-
RE: https://infosec.exchange/@ChaserSystems/116539334474822242
Our #egress filtering solution for containing agent behaviour in the cloud appears to be hardened enough as of today 🤞 . Of course, it is not a system you log into or get shell access during the course of work. And all input is first sanitised by the cloud APIs and then our own logic.
-
Agentic red teaming (or malicious activity) have lowered the bar for their human actors when it comes to #evasion around #egress #filtering tech; and raised the bar for vendors making such tech 🙋♂️
<insert bittersweet meme>
-
Is Post-Quantum Cryptography #PQC being used by your apps when calling other APIs?
New feature in the works that'll let you capture your progress with updating the crypto libs
#DiscrimiNAT is an #egress filter for your cloud with monitoring, analytics, dry-run & enforcement
-
Another fantastic review of our DiscrimiNAT Firewall. If you need a developer-friendly #egress filtering solution for AWS or GCP, book a demo here: https://chasersystems.com/
Link to review: https://www.g2.com/products/discriminat-firewall/reviews/discriminat-firewall-review-12435869
-
🤔 Oh, you're using #Squid 🦑 to control #Kubernetes egress? How delightfully retro! I'm sure your cluster will appreciate the walk down memory lane as it figures out what it's gossiping about behind your back. Just remember, it's not a real party until the #NetworkPolicy shows up and ruins the fun! 🎉
https://interlaye.red/kubernetes_002degress_002dsquid.html #Egress #RetroTech #CloudComputing #HackerNews #ngated -
Kubernetes Egress Control with Squid Proxy
https://interlaye.red/kubernetes_002degress_002dsquid.html
#HackerNews #Kubernetes #Egress #Control #with #Squid #Proxy #kubernetes #egress #squid #proxy #cloudnative #devops #networking
-
🎉 Wow, someone discovered that #XDP can handle #egress traffic! 🚀 Meanwhile, the rest of us are just trying to figure out why we should care about packet processing speeds when our network is already down. 😂 #KubeConBooth1752
https://loopholelabs.io/blog/xdp-for-egress-traffic #traffic #packetprocessing #KubeCon #networkperformance #technews #HackerNews #ngated -
Welcome to the team Lucas Pye! Lucas is joining us as an intern until mid-September and is researching what telemetry is gathered from developer machines by various popular agentic coding tools. When he's not intercepting #egress traffic you can find him climbing in the Peak District or his local gym.
(screenshot of MitMed Cursor)
-
Spaaaaaaaaace! (EVA on ISS egress)
-
Wildcards were a game-changer in GCP for this👇customer in reducing #egress management overhead.
✅Monitoring / Dry-Run mode
✅SNI spoofing proof tech
✅Public Suffix List / Effective TLD checks
✅TerraformDeploy now or get a demo from engineering: https://chasersystems.com/
👇
-
How AI and deepfakes are redefining social engineering threats https://www.helpnetsecurity.com/2025/01/07/phishing-trends-2024/ #AbnormalSecurity #OstermanResearch #cybercrime #Ironscales #LastPass #phishing #Zscaler #Egress #report #survey #News
-
Security measures fail to keep up with rising email attacks https://www.helpnetsecurity.com/2024/09/13/email-attacks-increase/ #AbnormalSecurity #cybersecurity #VIPRESecurity #emailsecure #cybercrime #Proofpoint #Coalition #Darktrace #Acronis #Cofense #Egress #report #survey #email #News
-
#egress filtering data from #healthcare and #financial sectors
-
Deepfakes: Seeing is no longer believing https://www.helpnetsecurity.com/2024/08/29/deepfakes-technology-threat/ #cybercrime #deepfakes #Telesign #Egress #GetApp #iProov #McAfee #report #survey #Jumio #News
-
Read about the risks in using wildcards in #egress domain names when allowing CSPs and CDNs, in the Philosophy section of this post. #kahneman
We've introduced a safer syntax that invokes the deliberative, #System2 mind to craft a more careful pattern.
https://chasersystems.com/blog/wildcards-and-system-2-thinking/
-
Find out which cyber threats you should be concerned about https://www.helpnetsecurity.com/2024/06/05/cyber-threat-landscape-statistics-2024/ #ArcticWolfNetworks #SecurityScorecard #AbnormalSecurity #CorvusInsurance #cybersecurity #VIPRESecurity #CatoNetworks #GitGuardian #NTTSecurity #VikingCloud #CheckPoint #cybercrime #Proofpoint #ReliaQuest #Don'tmiss #Trustpair #Hotstuff #BitSight #Mimecast #SpyCloud #Claroty #Delinea #Imperva #Verizon #Zscaler #Egress #report #Socure #Sophos #survey #AtBay
-
Phishing statistics that will make you think twice before clicking https://www.helpnetsecurity.com/2024/05/21/phishing-statistics-2024/ #OstermanResearch #VIPRESecurity #cybercrime #Ironscales #Proofpoint #Don'tmiss #Hotstuff #LastPass #phishing #Cofense #Zscaler #Egress #report #survey #News
-
Cybercrime stats you can’t ignore https://www.helpnetsecurity.com/2024/05/07/cybercrime-stats-2024/ #GuidePointSecurity #SecurityScorecard #AbnormalSecurity #OstermanResearch #cybersecurity #VIPRESecurity #cybercrime #Ironscales #ReliaQuest #Don'tmiss #Trustwave #Hotstuff #SpyCloud #Cofense #Imperva #Akamai #Egress #report #Sophos #survey #Thales #News #Visa