home.social

#threatmodeling — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatmodeling, aggregated by home.social.

  1. Evaluations show a frontier model can autonomously complete a full compromise of a production enterprise network, from discovery to execution. It matters because agent speed and scale break human-paced defense assumptions. #AutonomousAgents #EnterpriseSecurity #ThreatModeling

    cyberworldops.eu/en/autonomous

  2. Evaluations show a frontier model can autonomously complete a full compromise of a production enterprise network, from discovery to execution. It matters because agent speed and scale break human-paced defense assumptions. #AutonomousAgents #EnterpriseSecurity #ThreatModeling

    cyberworldops.eu/en/autonomous

  3. Check out ˗ˏˋ ⭒ lnkd.in/gE2wUqgc ⭒ ˎˊ˗ to see my intro whilst you listen.

    I'm thus re-naming this work as "CVE Keeper - Security at x+1; rethinking vulnerability management beyond CVSS & scanners". I must also thank @andrewpollock for reviewing several of my verbose drafts. 🫡

    So, Security at x+1; rethinking vulnerability management beyond CVSS & scanners -

    Most vulnerability tooling today is optimized for disclosure and alert volume, not for making correct decisions on real systems. CVEs arrive faster than teams can evaluate them, scores are generic, context arrives late, and we still struggle to answer the only question that matters: does this actually put my system at risk right now?

    Over the last few years working close to CVE lifecycle automation, I’ve been designing an open architecture that treats vulnerability management as a continuous, system-specific reasoning problem rather than a static scoring task. The goal is to assess impact on the same day for 0-days using minimal upstream data, refine accuracy over time as context improves, reason across dependencies and compound vulnerabilities, and couple automation with explicit human verification instead of replacing it.

    This work explores:

    ⤇ 1• Same-day triage of newly disclosed and 0-day vulnerabilities
    ⤇ 2• Dependency-aware and compound vulnerability impact assessment
    ⤇ 3• Correlating classical CVSS with AI-specific threat vectors
    ⤇ 4• Reducing operational noise, unnecessary reboots, and security burnout
    ⤇ 5• Making high-quality vulnerability intelligence accessible beyond enterprise teams

    The core belief is simple: most security failures come from misjudged impact, not missed vulnerabilities. Accuracy, context, and accountability matter more than volume.

    I’m sharing this to invite feedback from folks working in CVE, OSV, vulnerability disclosure, AI security, infra, and systems research. Disagreement and critique are welcome. This problem affects everyone, and I don’t think incremental tooling alone will solve it.

    P.S.

    • Super appreciate everyone that's spent time reviewing my drafts and reading all my essays lol. I owe you 🫶🏻
    • ... and GoogleLM. These slides would have taken me forever to make otherwise.

    Take my CVE-data User Survey to allow me to tailor your needs into my design - lnkd.in/gcyvnZeE
    See more at - lnkd.in/gGWQfBW5
    lnkd.in/gE2wUqgc

    #VulnerabilityManagement #Risk #ThreatModeling #CVE #CyberSecurity #Infosec #VulnerabilityManagement #ThreatIntelligence #ApplicationSecurity #SecurityOperations #ZeroDay #RiskManagement #DevSecOps #CVE #CVEAnalysis #VulnerabilityDisclosure #SecurityData #CVSS #VulnerabilityAssessment #PatchManagement #AI #AIML #AISecurity #MachineLearning #AIThreats #AIinSecurity #SecureAI #OSS #Rust #ZeroTrust #Security

    linkedin.com/feed/update/urn:l

  4. As privacy advocates and cybersecurity pros, we know that maintaining control over our digital footprint is a constant battle. In 2024, the threat landscape continues to evolve, requiring more advanced, proactive approaches to defend both our privacy and security.

    Here are key strategies for staying ahead of the curve:

    1. Update Vigilance
    Staying on top of OS and software updates is still one of the most effective ways to avoid exploits. Remember that vulnerabilities like BlueBorne and WPA2's KRACK have been successfully exploited but mitigated by timely patches. For those who prioritize control, manual updates are still the way to go. Review each changelog to assess any privacy concerns (i.e., telemetry changes)​.

    2. Minimalism as a Strategy
    The fewer programs you use, the smaller your attack surface. When it comes to privacy and security, minimalism isn't just a lifestyle—it's a tactic. Evaluate the software you install: does every app or service truly align with your goals? Stripping back unnecessary software reduces risks​​.

    3. Linux: A Secure, Customizable Option
    Consider adopting Linux for its robust control over security and privacy. Debian-based systems are known for stability, and with proper configuration, they provide a minimalistic and privacy-focused environment. Don't just stop at installation: configure your firewall, DNS, and daily operational scripts to reduce leaks and improve defense​.

    4. Virtual Machines (VMs) for Containment
    VMs, especially when combined with open-source virtualization software, offer excellent containment strategies. Whether you're doing OSINT, sandboxing risky software, or simply adding layers of defense between your host machine and the web, a well-configured virtual environment can drastically reduce exposure. This method is especially effective for isolating specific tasks, preventing cross-contamination between applications or services​​.

    5. Advanced Browser and DNS Configuration
    Use privacy-focused browsers like Firefox with hardened settings and explore the use of container tabs to isolate browsing sessions. For additional protection, employ DNS-over-HTTPS (DoH) or DNS-over-TLS to encrypt your DNS requests, mitigating man-in-the-middle attacks. Consider decentralized DNS services as a next step​​.

    6. Firewall and VPN Integration
    Layering firewalls with VPNs is essential. But go further: implement firewall rules that ensure your system doesn't make any network requests unless the VPN is active. This can protect you in case of VPN failure, ensuring that your data never travels over insecure networks​.

    7. Use of Public and Private Keys for Authentication
    Where possible, replace traditional passwords with public-key cryptography for authentication. This drastically reduces the threat of brute-force attacks and compromises on services requiring authentication.

    8. Steganography & Disinformation
    Beyond encryption, consider steganography for hiding critical data in plain sight. As an added layer of security, practice disinformation tactics: provide plausible but fake information that misleads adversaries, ensuring they pursue dead ends​.

    9. Breach Monitoring and Response
    With the rise in data breaches and logs from stealer malware, proactive monitoring of breach data can help defend against credential stuffing and identity theft. Regularly check breached data sites and consider using tools to alert you if any of your data appears in a public leak​​.

    10. Self-Hosting for True Control
    Take your privacy into your own hands by moving toward self-hosted solutions where possible. Whether it’s email, file storage, or other critical services, self-hosting allows you to maintain full control over your data and avoid the vulnerabilities that come with cloud providers​.

    Stay safe, stay secure, and continue advancing your privacy and security strategy for 2024. The adversaries aren’t getting any slower; neither should we.

    #Cybersecurity #Privacy #Infosec #AdvancedSecurity #Linux #VMs #OSINT #VPN #Firewalls #Minimalism #ThreatModeling #Disinformation #PublicKey #Steganography