Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
flexorium
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
flexorium
5mo ago
We appreciate this information you share in the open
2.
▲
by
flexorium
5mo ago
Nice! very useful
3.
▲
by
flexorium
5mo ago
That’s definitely part of the solution to limit the risk, but it does not eliminate it. That’s exactly something the tool demonstrates very well. If you can exploit , you can gently ask OIDC to mint you access on the fly. That’s what I call
4.
▲
by
flexorium
5mo ago
Thanks! I got tired of talking about it to defenders. I wanted to talk to Red Teamers too and SOC / detection engineering people. I wanted to build a tool that someone can just have the CISO try it directly.
5.
▲
by
flexorium
5mo ago
Absolutely not. The same TTPs apply almost 1-to-1 for Insider Threat scenarios. We've built the Deciduous Attack Trees (shout out to Kelly) for insider threats last year. It overlaps. So either you start with Initial Access that's
6.
▲
by
flexorium
5mo ago
OP here, mini AMA. Two years ago today, our small research team open sourced poutine, a SAST scanner for CI/CD pipelines (very similar to zizmor, but written in Go and customizable using Rego DSL). It finds the vulnerabilities in your
7.
▲
Show HN: SmokedMeat, like Metasploit, but for CI/CD (open-source)
(github.com)
13 points
by
flexorium
5mo ago
|
9 comments
8.
▲
by
flexorium
1y ago
We're pretty excited to finally talk about this new TTP.
9.
▲
by
flexorium
1y ago
I’m somewhat surprised to see that they use a KVM to switch between back and forth between a JWICS and SIPRNET. I would imagine it’s a special KVM as it’s essentially bridging the airgap between the two. I’m guessing that’s the product in q
10.
▲
by
flexorium
3y ago
In the audit log of the organization you can see an event, but by that time you have lost visibility into what the attacker really executed. So a malicious tag payload (stage 1) will still remain in events, but Stage 2 will be lost complete
11.
▲
by
flexorium
3y ago
When people think about Supply Chain security, they generally think of SBOM and vulnerabilities in your direct and transitive dependencies. But most people are completely blind of vulnerabilities in the Build Pipeline of those same dependen
12.
▲
Bug bounty write-up: DNS rebinding in EOSIO keosd wallet
(medium.com)
1 points
by
flexorium
8y ago
|
0 comments