#SecurityAnalysis

Schneier on Security RSSSchneier_rss@burn.capital
2024-09-06

YubiKey Side-Channel Attack

There is a side-channel attack against YubiKey access tokens that allows someone to clone a device. It’s a complicated attack, requiring the victim’s use... schneier.com/blog/archives/202

#side-channelattacks #securityanalysis #academicpapers #securitytokens #Uncategorized #cloning

Schneier on Security RSSSchneier_rss@burn.capital
2024-08-02

Leaked GitHub Python Token

Here’s a disaster that didn’t happen:
Cybersecurity researchers from JFrog recently discovered ... schneier.com/blog/archives/202

#securityanalysis #Uncategorized #supplychain #leaks

Well-Educated Millennialwelleducatedmillennial
2024-05-04

Unlock value investing wisdom from "Security Analysis"! Learn to research, avoid speculation, & master investor psychology. Use these timeless principles to invest better. Read now & share your thoughts!

welleducatedmillennial.com/les

2024-02-16

Title: Analysis of Intercepting a Mercenary from Activists Recruited by the Russian GRU

Introduction:
Now in the Kursk region... No, maybe it's just me being dumb and not understanding something? Essentially, we can already say it's the third year of non-war, with the "banderlogs" methodically taking out combat aircraft and helicopters at airfields with their UAVs, as well as the oil refining industry. As for the Southern Military District, I won't even mention it; there Kasyanenko is crying. If you can't cover the entire sky and protect the civilian population, then at least cover the strategic facilities!

Such consequences have specific names associated with those who failed to ensure and allowed... Including the names of those who appointed these officials and bureaucrats, who, apart from inflating their cheeks, don't actually do anything of substance. No, they do... - they prepare the country for collapse through quiet sabotage.

Conclusion:
The provided text appears to be a critique of the current situation in the Kursk region and broader military and political events. It highlights dissatisfaction with the lack of defense measures and implies corruption and incompetence among certain officials. However, without concrete evidence, these claims remain speculative and should be approached with caution.

Tags:
#OpenSourceIntelligence #OSINT #InvestigativeJournalism #MilitaryAnalysis #SecurityAnalysis #GRU #KurskRegion #BanderaMovement #Corruption #incompetence
QT: qoto.org/@nwl/1119385505820006

2024-01-27

🚨 #KQL Course Update and Anniversary Discount!

The "Hands-On Kusto Query Language (KQL) for Security Analysts" course has been updated with 5 new exercises focusing on aggregations to answer investigative questions, with more to come! The course now offers:
✅ Lots of examples in the lessons
✅ A total of 23 exercises
✅ 2 Investigation scenarios
allowing you to enhance your skills in Kusto Query Language.

Last ~24 hours to get it 30% OFF!

academy.bluraven.io/hands-on-k

#KQL
#SecurityAnalysis
#Training
#ThreatHunting
#IncidentResponse
#MicrosoftSentinel
#MicrosoftDefender
#M365Defender
#DFIR
#DataAnalysis

Schneier on Security RSSSchneier_rss@burn.capital
2024-01-17

Code Written with AI Assistants Is Less Secure

Interesting research: “Do Users Write More Insecure Code with AI Assistants?“:
Abstract: We conduct the first large-scale user study examining how users interact ... schneier.com/blog/archives/202

#artificialintelligence #securityanalysis #academicpapers #Uncategorized #programming

2023-12-06

🚀 "Hands-On KQL for Security Analysts" Course is Now Live!

After months of dedicated work, fine-tuning, and anticipation, I am thrilled to invite you to begin your journey in mastering KQL. Whether you're a seasoned security analyst or aspiring to enhance your skills, this course is the gateway to elevating your expertise!

✅ Ready to Begin?
Embark on your learning journey today. Click the link below to enroll and take the first step toward becoming a KQL expert!

academy.bluraven.io/hands-on-k

#KQL #SecurityAnalysis #Training #ThreatHunting #IncidentResponse #MicrosoftSentinel #MicrosoftDefender #M365Defender #DFIR #DataAnalysis

2023-11-29

🌐 **АНОНС ТЕСТИРОВАНИЯ DELTA CHAT: В ЗОНЕ БЕЗОПАСНОСТИ И ИННОВАЦИЙ** 🚀

Привет, киберсообщество! Готовьтесь к захватывающему путешествию в мир безопасной переписки с Delta Chat! 🛡️💬

Я, Alterego, отправляюсь в увлекательный космос тестирования, чтобы определить лучший сервер Delta Chat с точки зрения безопасности и выявить все дополнительные возможности, скрытые в этом космическом клиенте электронной почты. 🌌🔍

Буду исследовать каждый уголок этого космического чата, нацеленного на безопасность и инновации. Скоро вы узнаете, какой сервер обеспечит вам непревзойденную степень защиты и уникальные функции для вашего космического общения! 🚀🌐

Открывайте для себя новые горизонты с Delta Chat! Присоединяйтесь ко мне в этом увлекательном путешествии, а ваши предложения и советы будут весьма ценными! 💡🌟

**Хэштеги:**
1. #DeltaChatExploration
2. #SecureMessaging
3. #InnovationQuest
4. #CyberSecurityJourney
5. #DeltaServerShowdown
6. #ChatSecurity
7. #EmailInnovation
8. #TechDiscovery
9. #TestingDeltaChat
10. #DigitalSafetyMission
11. #DeltaChatAdventure
12. #SafeCommunication
13. #ServerSecurityCheck
14. #InnovativeChatFeatures
15. #TechTesting
16. #SecurityAnalysis
17. #ExploreDeltaOptions
18. #CyberSpaceTesting
19. #SecureChatQuest
20. #DeltaChatInFocus
21. #EmailSecurityScan
22. #TechExploration
23. #DeltaDiscoveries
24. #MessagingSecurity
25. #TechPioneeringDelta

2023-10-26

🚀 Exciting News for Security Analysts! 🚀

I'm thrilled to announce the first-ever "Hands-On Kusto Query Language (KQL) for Security Analysts" training course! 🛡️

After numerous requests for training content, I've decided to take the plunge and create a comprehensive KQL course tailored specifically for security professionals. It's just about a month away from the launch, and I couldn’t be more thrilled!

If you want to learn KQL for Microsoft Sentinel or Microsoft 365 Defender, check the details and sign up to get notified at launch! 🥳

training.bluraven.io/

#KQL #SecurityAnalysis #Training #ThreatHunting #IncidentResponse #MicrosoftSentinel #MicrosoftDefender #M365Defender #DFIR #DataAnalysis

Schneier on Security RSSSchneier_rss@burn.capital
2023-10-25

Microsoft is Soft-Launching Security Copilot

Microsoft has announced an early access program for its LLM-based security chatbot assistant: Security Copilot.
I am cu... schneier.com/blog/archives/202

#artificialintelligence #computersecurity #incidentresponse #securityanalysis #Uncategorized #LLM

Jonathan D. AbolinsJonAbolins@mastodonapp.uk
2023-06-11

«[2306.00610] Spying on the Spy: Security Analysis of Hidden Cameras» #InternetSecurityCameras #TCPICameras #SecurityAnalysis

arxiv.org/abs/2306.00610

Computer Science > Cryptography and Security arXiv:2306.00610 (cs) [Submitted on 1 Jun 20231 Spying on the Spy: Security Analysis of Hidden Cameras Samuel Herodotou, Feng Hao Download PDF Hidden cameras, also called spy cameras, are surveillance tools commonly used to spy on people without their knowledge. Whilst previous studies largely focused on investigating the detection of such a camera and the privacy implications, the security of the camera itself has received limited attention. Compared with ordinary I cameras, spy cameras are normally sold in bulk at cheap prices and are ubiquitously deployed in hidden places within homes and workplaces. A security compromise of these cameras can have severe consequences. In this paper, we analyse a generic IP camera module, which has been packaged and re- branded for sale by several spy camera vendors. The module is controlled by mobile phone apps. By analysing the Android app and the traffic data, we reverse-engineered the security design of the whole system, including the module's Linux OS environment, the file structure, the authentication mechanism, the session management, and the communication with a remote server. Serious vulnerabilities have been identified in every component. Combined together, they allow an adversary to take complete control of a spy camera from anywhere over the Internet, enabling arbitrary code execution. This is possible even if the camera is behind a firewall.
cynicalsecurity :cm_2:cynicalsecurity@bsd.network
2023-04-02

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst