home.social

#zero-trust — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zero-trust, aggregated by home.social.

fetched live
  1. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  2. Security Tip: Enforce the Principle of Least Privilege (PoLP). 🛡️ In a Zero Trust framework, permissions are the new firewall. By granting entities only the bare minimum access needed, you significantly reduce the potential damage from a compromised account. Regularly audit permissions and remove unused access. Track emerging vulnerabilities at: cvedatabase.com #CyberSecurity #InfoSec #ZeroTrust #PoLP #ITSecurity #Privacy

  3. Netbird is showing some new showstoppers. It's very easy to publish a service from internal network. Netbird uses internally Traefik for reverse proxy, and it all gets configured automatically - certificates and all.

    But there is downside: there are no usual options available for reverse proxy customization like URL rewrite, response rewrite, caching etc. I can do a little bit of tweaking with docker labels, but it's already an uphill battle. I can apparently replace the whole reverse proxy with e.g. nginx, but then i lose all the automation from Netbird+Traefik.

    Netbird should also be able to do TCP/UDP port forwarding. But after defining one, it doesn't work. When checking the reverse proxy machine, i see nothing listening that port nor anything in iptables.

    I have some management tools using http internally, which i hoped to be able to wrap into https. They have links to e.g. consoles. These are typically like http://ip:port, and auto-generated from e.g. container definitions. Netbird can rewrite the address of the tool itself, but not these links to other services.

    I think i'll look some alternatives. I have one service which absolutely needs cache at the edge, and few others using TCP/UDP port forwarding.
    #homelab #vpn #netbird #zerotrust #security #opensource #selfhosting

  4. die brutale #datenschutz weisheit die sich jeder merken sollte:

    wo getrackt werden KANN, da WIRD auch getrackt.

    #zerotrust #privacy

  5. eine kleine #datenschutz erinnerung an alle mastodon.social user.

    die betreiber von mastodon.social können theoretisch diese infos über dich sammeln:

    sie sehen deine IP-adresse, dein komplettes nutzerverhalten auf der instanz, d.h.welche posts du öffnest, wie lange du sie anschaust, wonach du suchst, welche
    profile du besuchst und wann du aktiv bist. sie können deine DMs lesen, geräteinfos und metadaten abgreifen.

    #zerotrust #privacy #mastodon

  6. was ich an der #unplugtrump bzw. #unplugbigtech bewegung seltsam finde:

    warum sollte europäisches #bigtech besser sein, als amerikanisches oder chinesisches bigtech?

    ich sehe keinen unterschied.

    #zerotrust

  7. ich vertraue nicht der #privacy community.

    ich vertraue nicht den produkten die sie bewerben und empfehlen.

    weil ich weiß, dass sie nicht die ganze geschichte erzählen.

    sie tun so, als wären ihre produkte die lösung. doch dabei verheimlichen sie immer die risiken und gefahren.

    sie weigern sich das ganze, hässliche bild zu zeigen.

    darum erscheint mir die privacy community wie eine religion.

    #zerotrust #datenschutz

  8. 🏅 Mañana miércoles 19 de agosto iniciamos el Curso Maltego Graph ⚔️ 19, 20, y 21 de Agosto 2026 ♾ De 8:00 pm a 11:00 pm (UTC -05:00) [9 horas] 🌎 WhatsApp: https://wa.me/reydes 🚀 Información: https://www.reydes.com/archivos/cursos/Curso_Maltego.pdf #cybersecurity #infosec #security #cyber #zerotrust #incidentresponse #endpointsecurity
  9. wer spätestens seit #snowden immer noch kein erbarmungsloser #zerotrust maximalist ist, der belügt sich einfach nur selbst.

    hört auf den "guten" zu vertrauen. sie sind lügner.

    "open source" ist das ablenkungsmanöver dieser lügner. sie tun so, als würden sie mit offenen karten spielen. aber wir müssen davon ausgehen, dass sie vor uns etwas verheimlichen.

    #datenschutz #privacy #dsgvo

  10. Second try to install Netbird is going smoothly. My first attemp ran into showstoppers after deploying Netbird into hosts running virtual and containers, and to clients. This time:
    - Didn't install Netbird to hosts nor clients.
    - Deployed a Netbird client container to each VLAN.
    - Created network definitions in Netbird manager for each VLAN.
    - Added the Netbird client containers as routing peer in their corresponding network.
    - Added container/vm endpoints as https services in their corresponding network definition. Target ip/port is their location in VLAN, In access rights added SSO requirement plus limited their global visibility.

    After those steps I have services available both in old home network and in Netbird. At home I can access e.g. HTTP://syncthing.local:8384/ , and the same via Netbird at syncthing.home.example.com/ . The Netbird address is public but protected by Netbird SSO login. Both work at the same time.

    The good thing is that I can migrate and test each service in a stable environment over several weeks. Few test migrations have now proved it.

    The bad thing is that this is only half-secure. But my first attempt failed because going fully into Netbird was too demanding, needing everything configured at once. Now I can migrate gradually.

    The next step is to finish publishing all services in Netbird.

    In third step I plan to isolate the VLANs, and close the old, local access in their firewall. I can e.g. isolate a Syncthing VLAN, remove access to its GUI in firewall, and allow only the p2p traffic between Syncthing instances. The GUI is accessible only via the Netbird routing peer container, placed into same segment. When finished, all client access to services would be through public Netbird endpoints, all authenticated and controlled access rights.

    Fourth step would be migrating all user clients into Netbird. That would allow me to move some services away from public visibility into Netbird-internal-only. For each service I just replace external SSO login with internal-only access rights.

    The last step, migrating hosts, I'm unsure of. It's months away, and needs solutions for e.g. how to put containers into Netbird network. I'll think about it later.
    #homelab #vpn #netbird #zerotrust #security #opensource #selfhosting

  11. 💸 Webinar Gratuito: "Fundamentos de Finanzas Empresariales" ⚙️ Miércoles 19 de Agosto 2026. De 11:00 am a 11:45 am (UTC -05:00) 🆓 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLScesLnXuVWAIjM5liWUZ5A06BUHghVL0G6GZnWjANCvA9ssBg/viewform #cybersecurity #dataprotection #zerotrust #ransomeware #cyberresilience #phishing
  12. I have to tear down my Netbird installation and rethink it. The main issue is that it is too invasive. It cuts old connections. That would be OK after everything is migrated to Netbird. The all-or-nothing is a showstopper. I need a path of gradual migration.

    I think I need to leave main hosts out of Netbird, and only migrate their containers and virtuals one at a time. I probably need to start by adding a routing container/vm per each VLAN to replace routing via hosts. The old containers stay at old address. The new routing containers would do the NAT/routing between mesh and old VLAN.

    Then DNS is second issue. Netbird disables old DNS settings. That was too harsh. I can solve that by leaving client computers away from the initial Netbird network. Then I can continue accessing unmigrated services through private DNS, and migrated services as external client through public DNS with enforced authentication.

    #homelab #vpn #netbird #zerotrust #security #opensource #selfhosting

  13. Netbird is great - and terrible. Netbird is an open source program that creates a virtual zero-trust network. I'm setting up a self-hosted version of it. With it I'm trying to reorganize my homelab with two decades of rigging, and also reorganize the public servers i'm sharing.

    So far Netbird has managed to do all i've thrown into it: multiple segments, multiple VLANs, segments behind segments, etc. Policies work, permissions work, and security looks great. But also i've fallen to many bogholes with it.

    Some lessons:
    - Ignore all docs about environment variables. It's config.yaml now.
    - You can make public servers into address like matrix.chat.example.com, and then have private services at files.home.example.com. Just add to manager's docker compose files, proxy.env, one more line: NB_PROXY_PRIVATE=true
    found in some release note. O_o
    - While e.g. Android connects to private server fine, Windows won't until you add a Netbird DNS server to resolve e.g. home.example.com. Without explicit DNS Windows resolves internal names to manager node's external address, which then rejects the connection because it's coming from the outside.
    - The program auto-generates all Traefik rules and fetches certificates in few secs. Having been writing years nginx-confs by hand, or by NPM, or by OPNSense, i'm awestruck.

    I guess the program is under speedy development, and documents lag behind. They are dropping updates *every day*, which is great - and terrible.
    #homelab #vpn #netbird #zerotrust #security #opensource #selfhosting

  14. 🚀 Transforma tu metodología de investigación ⏰ Participa en el Curso Maltego Graph CE 2026 🎯 🕵️ Miércoles 19, Jueves 20, y Viernes 21 de Agosto (9 horas) 🔌 De 8:00 pm a 11:00 pm (UTC -05:00) 🪓 WhatsApp: https://wa.me/reydes 🎯 Información: https://www.reydes.com/e/Curso_Maltego #cybersecurity #infosec #cybersecurityawareness #dataprotection #cyberdefense #zerotrust
  15. ☁️ Cloud security is about more than the cloud.

    Identity, APIs, applications, infrastructure, availability and resilience all need to work together.

    📍 SANS Cloud Security Exchange 2026
    📅 August 17–23
    📌 San Francisco

    RELIANOID will be following the conversations around Zero Trust, cloud security, DevSecOps and cyber resilience — and how secure application delivery can help protect modern cloud environments.

    🚀 Attending? Let’s connect!

    🔗 relianoid.com/about-us/events/

  16. With FedRAMP High, Cloudflare helps agencies modernize faster, reduce risk and protect highly sensitive data - with a single platform for security, performance and application development.

    Built for mission-critical work. Ready for what’s next.

    Discover our innovative approach: cloudflare.com/fed/

    #Cloudflare #FedRAMP #PublicSector #ZeroTrust #Cybersecurity

  17. Critical vulnerabilities found in Connective, Belgium's eID digital identity extension used by over 2 million citizens. The browser plugin, developed by Nitro Software Belgium, exposes PINs, electronic signatures, and devices to compromise.

    #DigitalIdentity #BelgianEID #CriticalInfrastructure #ZeroTrust

    cyberworldops.eu/en/critical-v

  18. 📈 Webinar Gratuito: "Secretos para una Presentación Exitosa de Ciberseguridad" ✅ Miércoles 12 de Agosto 2026. De 11:00 am a 11:45 am (UTC -05:00) 🚀 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLScR624fU_3w9gmw5fNmXHxn4-5Ulhd3RpTiMqWQKcYdC7MU7w/viewform #cybersecurity #infosec #cyber #security #threatintel #incidentresponse #malware #vulnerability #zerotrust
  19. Almost Half of Malware Samples Communicate Direct to IP

    Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.

    Pulse ID: 6a71e43a0127c62218b7c365
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: AlienVault
    Created: 2026-08-04 13:08:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault

  20. Your corporate inbox is a direct line for threat actors straight to your perimeter. Standard firewalls won't save you. Stop relying on human awareness and start aggressively hardening your infrastructure with strict DMARC policies and FIDO2 tokens. 🔒🛡️

    #Cybersecurity #ZeroTrust #InfoSec

    bdking71.wordpress.com/2026/08