Post B6KWKJpa76s8CF0irA by Mustardfacial@infosec.exchange
(DIR) More posts by Mustardfacial@infosec.exchange
(DIR) Post #B6K9GCwDVAneiLBWdM by nyanbinary@infosec.exchange
0 likes, 0 repeats
Are you struggling to ensure the security program at your organisation is Mythos ready? Here are some simple tips that will help you achieve it!Implement a Asset Inventory as well as processes to ensure it's completes & correctnessPut processes for regular & emergency patching processes into place & monitor adherence to identity gaps or infeasible processes/timelinesEnsure the use of soft- and hardware for which security patches are made available in a timely manner, as well as including security aspects in vendor selections.Continously monitor your environment for insecure software, both outdated & fundamentally not in line with your security requirements/generally risky.Monitor & reduce attack surfaces, both externally & internally, especially for critical, complex, or slow-to-patch systems.Follow me for more tips on how to elevate your organisations security posture to survive the AI vulnerapocalypse.
(DIR) Post #B6K9GDZv7YYihTlEWG by nyanbinary@infosec.exchange
0 likes, 0 repeats
man, writing this one hurt & this is the first time I considered outsourcing it to a chatbot but the soul of the shitpost comes from the suffering of it's author so fuck this shit.
(DIR) Post #B6K9GDu7uQipi9DN0y by nyanbinary@infosec.exchange
0 likes, 0 repeats
I am actually kinda pissed because all the architecture decisions of "eh, lets put it on the internet, will be fine & so much less work" will truly come back to haunt us if we see a speedup in exploitation and/or increased volume of vulnerabilities. Even if they end up being mostly non-exploitable checking this is still a shitload of work.
(DIR) Post #B6K9GE9iyRCOUWVpKK by DaveMWilburn@infosec.exchange
0 likes, 0 repeats
@nyanbinary
(DIR) Post #B6K9GEMqBfgt9CeIls by cR0w@infosec.exchange
0 likes, 0 repeats
@DaveMWilburn @nyanbinary Where did you get these pictures of my CIO?
(DIR) Post #B6K9GEafMGkXq57LJw by jackryder@infosec.exchange
0 likes, 0 repeats
@cR0w @DaveMWilburn @nyanbinary
(DIR) Post #B6K9GEqcOxVgdYa5BY by badsamurai@infosec.exchange
0 likes, 0 repeats
@jackryder @cR0w @DaveMWilburn @nyanbinary I don’t know if these memes have a hashtag, but I’m in!
(DIR) Post #B6K9GEzpqgsn68tRYG by cR0w@infosec.exchange
1 likes, 0 repeats
@badsamurai @jackryder @DaveMWilburn @nyanbinary #fuckTheFundamentals
(DIR) Post #B6KWKJ92fGqQ4J6kYC by Mustardfacial@infosec.exchange
0 likes, 0 repeats
@nyanbinary gather round while I tell you the story of how I was pushed to self-host a password manager that was:hosted on-premhad no access to the internethad a WAF in front of it (just in case)had full passkey supportwas fully logged out of every service that could write a logDB encrypted (obviously) but also hosted on another serverencrypted backups that pushed to immutable storagecould be spun up from a bare VM with a single scriptAnd when it was all complete they went with a cloud hosting service because it was "less hassle/work"
(DIR) Post #B6KWKJZH5jpPNfNhRI by nyanbinary@infosec.exchange
0 likes, 0 repeats
@Mustardfacial oh, ours is internet-accessible, Identity Layer will fix it :blobcatupsidedown:
(DIR) Post #B6KWKJpa76s8CF0irA by Mustardfacial@infosec.exchange
0 likes, 1 repeats
@nyanbinary