DevTestSecOps
138 subscribers
469 photos
29 videos
37 files
695 links
Forwards and notes on development, testing, security, and operations from @q587p.

About me: studied as System Architect, worked as a SysAdmin, working now as an Test Automation Engineer. Also, I'm interested in hacking (and everything related to it).

జ్
Download Telegram
#security #hack #OAuth

Dylan from truffleSecurity talks about a simple hole (it seems a bit loud to call it a vulnerability) that allows users of companies that use #Google authorization in services like Slack or Zoom to continue to have access even after being fired and having their access removed.

The hole is that such services use email as the user ID. But, obviously, you can create several different email addresses that receive the same emails (e.g. by adding words after "+"):

https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/
👏1👨‍💻1
1👎1👏1🤔1
The Microsoft security team detected a nation-state attack on our corporate systems on January 12, 2024, and immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium. As part of our ongoing commitment to responsible transparency as recently affirmed in our Secure Future Initiative (SFI), we are sharing this update.  

https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/
🤯2🔥1
The CODS Model:

- Control
- Observability
- Decomposability
- Simplicity
👏1🤔1👌1
👻3😁1🌚1
#password #way

Oh, someone at one time said the right and obvious thing. But as usual, they were not heard (how annoying are these requirements for frequent changes, often also on services that limit the length, like, less than 12 characters, and do not allow special characters 🤬):

https://tidbits.com/2022/03/03/never-change-your-password/
👍2💯2🤔1
Forwarded from Dev Meme / devmeme
😁2👌1🤪1
#security #study

This repository contains a 90-day cybersecurity study plan, along with resources and materials for learning various cybersecurity concepts and technologies. The plan is organized into daily tasks, covering topics such as Network+, Security+, Linux, Python, Traffic Analysis, Git, ELK, AWS, Azure, and Hacking. The repository also includes a `LEARN.md

https://github.com/farhanashrafdev/90DaysOfCyberSecurity
🔥1👏1