cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar
cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

Re-up in preparation for Monday's talk in Bergen, Norway.

Have a listen to the episode of the Google Cloud Security Podcast, featuring me.

EP150 Taming the AI Beast: Threat Modeling for Modern AI Systems with Gary McGraw

https://berryvilleiml.com/2024/01/25/google-cloud-security-podcast-features-biml/

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

Thanks Stockholm. The breakfast seminar on was good. Next up is OSLO tomorrow morning (THURSDAY). If you are in Norway, please come join me!

I will also briefly cover machine learning security

https://www.lyyti.fi/reg/CDR-NO-18-04-2024

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

Software Security Seminar in Stockholm TOMORROW 17.4

Please join me for an early morning breakfast seminar on (with some thrown in for good measure). Build security in.

Register here https://www.lyyti.fi/reg/CDR-SV-17-04-2024

Thank you in advance for passing this on to dev types you know in Sweden. Please boost for reach.

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

The mid-April breakfast seminar I am giving in Stockholm still has plenty of space. If you happen to know anyone who would benefit from attending, please let them know!

Calling all Swedes interested in software security. (Thanks for passing this on.)

STOCKHOLM 17.4 https://www.lyyti.fi/reg/CDR-SV-17-04-2024

cigitalgem, to infosec
@cigitalgem@sigmoid.social avatar

I am giving two breakfast seminars back to back mid-April. If you are in Sweden, Norway or Finland, please consider coming. Pass it on to those who may be interested.

STOCKHOLM 17.4 https://www.lyyti.fi/reg/CDR-SV-17-04-2024

OSLO 18.4 https://www.lyyti.fi/reg/CDR-NO-18-04-2024

danielcornell, to random
@danielcornell@mastodon.social avatar

Reminder to all folks - especially consultants - writing secure code is harder than telling people to write secure code

haubles, (edited ) to web
@haubles@fosstodon.org avatar
cigitalgem, to security
@cigitalgem@sigmoid.social avatar

I will try to beat @0xmchow to the punch since it's my 58th birthday!

Secure your ML algorithms too while you're at it.

Sempf, to ai

I get to test a chatbot today. Any ideas?

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar
darrenpmeyer, to random

I can finally be public about my new role as a Staff Research Engineer at Endor Labs!

I’m going back to my research roots here, getting a chance to focus on topics for education, research work, and contributing to the OpenSource ecosystem. This role has been a year in the making, and I’m super excited to get started on the work!

OWASP_Ottawa, to Ottawa

Announcing the next Meetup on February 21st. Doors open at 6pm ET and Live stream starts at 6:30pm ET. Thank you to University of Ottawa Engineering for hosting.

https://www.meetup.com/owasp-ottawa/events/298931231

SheHacksPurple, to random

The Cross Site Scripting Vulnerability (XSS), simplified.
https://youtu.be/4R8IcMAXyrE?si=d4HdvBSDQOumyBzV

OWASP_Ottawa, to Ottawa

Are you passionate about a topic in security?

Would you like to present at an meetup in 2024?

Then fill in our simple online form with basic details and pitch your presentation. We accept various lengths and topics.

forms.gle/KKGk33Xr9rkUhaNr5

mttaggart, to random

So I guess @zaproxy is looking into new funding sources, as they're running into a bit of a shortfall.

This drives me a little nuts. Mozilla could pick this project up for peanuts and ensure we have an free and open solution.

But so could Microsoft or Google, with couch cushion money. It would cost them effectively nothing, and gain them significant good will.

Anyway projects like this shouldn't have to beg for support.

krelnik, to infosec

The YouTube channel just posted a set of videos from their global event in Washington and they are all just raw video of the speaker with no slides shown. (Well except for a tiny sliver on the edge proving that there were in fact slides at the live presention). Not even a link to slide deck below the video! Surely this was done in error? (Some of) the videos are even formatted with a big hunk of blank wall to the left of the speaker that is clearly intended for insertion of slides, while the actual slides are off camera to the right. Frustrating because some of these talks I'd really like to watch but it is difficult or impossible to follow a technical talk that had slides originally with just the speaker on screen.

cigitalgem, to ML
@cigitalgem@sigmoid.social avatar

Have a listen to the episode of the Google Cloud Security Podcast, featuring me.

EP150 Taming the AI Beast: Threat Modeling for Modern AI Systems with Gary McGraw

https://berryvilleiml.com/2024/01/25/google-cloud-security-podcast-features-biml/

SonarResearch, to jenkins

🔍Uncovering critical vulnerabilities in Jenkins, which could lead to RCE (CVE-2024-23898, CVE-2024-23897):

Check out our latest blog post for the technical details on how attackers could potentially gain unauthenticated RCE on

https://www.sonarsource.com/blog/excessive-expansion-uncovering-critical-security-vulnerabilities-in-jenkins/?utm_medium=social&utm_source=mastodon&utm_campaign=research&utm_content=blog-excessive-expansion-uncovering-critical-security-vulnerabilities-in-jenkins-240125-p1&utm_term=ww_en_all_x

j_opdenakker, to infosec

Imagine in 2024 organizations think you can defend against sql injection attacks (via a password) by banning certain characters and keywords.

University of Ljubljana: Hold my beer!

https://id.uni-lj.si/DigitalnaIdentiteta/PonastavitevGesla?culture=en-GB

OWASP_Ottawa, to Ottawa

Are you passionate about a topic in security?

Would you like to present at an meetup in 2024?

Then fill in our simple online form with basic details and pitch your presentation. We accept various lengths and topics.

forms.gle/KKGk33Xr9rkUhaNr5

SheHacksPurple, to random

Did you miss my talk "DevSecOps Worst Practices" at @OWASPLondon? Fear not, you can watch the recording here!

Https://youtu.be/-ZxY2XlM3-0

0x58, to infosec
OWASP_Ottawa, to Ottawa

Tomorrow, January 17th at 6PM ET starts 2024 with an invited panel of the security community from industry, academia, and the trenches to discuss on the greatest technology influences on the security industry.

https://meetup.com/owasp-ottawa/events/298475758/

krlaboratories, to Cybersecurity Ukrainian

ДЕЩО ПРО МЕРЕЖЕВІ З'ЄДНАННЯ WHATSAPP...

Приклад того як мобільний додаток WhatsApp Messenger лізе на нестандартні (5022) і незахищені (80) мережеві порти (в ідеалі має бути лише 443).

З'єднання відбуваються з інфраструктури Facebook і серверів Amazon.

З tcp 5022 впринципі зрозуміло - це XMPP, тобто Джаббер (завдяки якому WhatsApp такий швидкий в плані миттєвого обміну повідомленнями - https://isc.sans.edu/data/port/5222). А от 80-й, незахищений порт, навіщо? Про нього в довідці щось нічого не сказано: https://developers.facebook.com/docs/whatsapp/guides/network-requirements/

Цікаво, що деякі з цих IP-адрес мають шкідливі індикатори і б'ються по VirusTotal... Де гарантія того, що через них не пролізе бекдор...? Ми, звичайно, відфільтруємо подібні з'єднання фаєрволом і зашифруємось vpn'ом. А звичайний користувач? У нього усі "брами" відкриті по дефолту...

Виявляється, в інтернеті є мапа індикаторів, які були якось пов'язані з WhatsApp: https://www.virustotal.com/graph/embed/gc884e1c5d9b84730b3b00a90f2f4a73cc145436e48ae438794e2a7dd053993a1

Ось так, ведемо слідство над WhatsApp, щоб знати що поробляє жук Цук за спиною юзера... )

Далі буде.

#whatsapp #reverse #cybersecurity #messenger #messengers #audit #webappsec #appsec #network #networksecurity #networkintelligence #threatintel

image/png
image/png
image/jpeg

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • Durango
  • ngwrru68w68
  • thenastyranch
  • magazineikmin
  • hgfsjryuu7
  • DreamBathrooms
  • Youngstown
  • slotface
  • vwfavf
  • PowerRangers
  • everett
  • kavyap
  • rosin
  • normalnudes
  • khanakhh
  • tacticalgear
  • InstantRegret
  • cubers
  • mdbf
  • ethstaker
  • osvaldo12
  • GTA5RPClips
  • cisconetworking
  • tester
  • Leos
  • modclub
  • provamag3
  • All magazines