#pam

InfosecK2KInfosecK2K
2025-04-29

Cyber Security Myth Busters: Unravelling the truth behind cyber security misconceptions.

Get the facts straight and stay secure.

Visit our website to see how we can help you and your business stay safe: www.infoseck2k.com

Source: securifyidentity.com/post/iam-

2025-04-26

This is not about protecting classified information. This is about covering up her own complicity in unlawful renditions.

#DOJ #Pam #Fascism #Coup #Press

emptywheel.net/2025/04/26/pam-

DeNitro_SocialNitro_Social@mamot.fr
2025-04-25

Le Programme alimentaire mondial de l’ONU a annoncé vendredi avoir « épuisé tous ses stocks » à Gaza, où Israël bloque l’entrée de toute aide humanitaire et où son armée a lancé un nouvel appel à évacuer des secteurs du territoire en prévision de nouveaux bombardements. lapresse.ca/international/moye
Selon la Défense civile palestinienne, au moins 40 personnes ont été tuées dans la journée dans la bande de Gaza.

#GazaGenocide #PAM

Felix Palmen :freebsd: :c64:zirias@bsd.cafe
2025-04-25

Just released: #swad 0.5

swad is the "Simple Web Authentication Daemon", meant to add authentication using a #cookie and a #login form to your reverse proxy. It's designed for #nginx' "auth_request" module. It's written in pure #C with very few external dependencies (zlib, and depending on build options OpenSSL/LibreSSL and #PAM).

And with this release, it also allows guest logins using the crypto puzzle you may already know from #Anubis!

Read more in the release notes, grab the .tar.xz and build/install it 😎

github.com/Zirias/swad/release

InfosecK2KInfosecK2K
2025-04-24

Seamless business application onboarding starts with the right security foundation. At Infosec K2K, we ensure your applications are integrated securely into IAM and PAM from day one.

From tailored onboarding plans to rigorous testing and full integration, our process ensures privileged access is managed, monitored, and protected at every stage. Ready to streamline your access management? Get in touch with us today.

infoseck2k.com/business-applic

RamirezCA :mastodon:Ramirezca
2025-04-23

"Habemus pal'pam"

Léxico callejero en la zona suroccidental de

Felix Palmen :freebsd: :c64:zirias@bsd.cafe
2025-04-22

Oh boy, I discovered two quite problematic bugs after releasing #swad 0.3:

* The #PAM checker could cause swad to deadlock under unlikely, but possible circumstances: Creating another PAM checker instance when the PAM helper process already died (or couldn't be started at all)

* The file checker had a bug of the stupid kind, it failed to authenticate users that *don't* have a "real name" set in the password file because it didn't correctly strip the newline following the hash in this case. 🙈

Fixed them both now!

I think I'll do something you normally should never do: Re-roll the existing #release. It's IMHO kind of acceptable because this is still an incomplete 0.x version AND there are (as far as I know) no packagers yet.

Felix Palmen :freebsd: :c64:zirias@bsd.cafe
2025-04-21

Just released: #swad v0.3!

github.com/Zirias/swad/release

swad is the "Simple Web Authentication Daemon", your tiny, efficient and (almost) dependency-free solution to add #cookie + login #form #authentication to whatever your #reverse #proxy offers. It's written in pure #C, portable across #POSIX platforms. It's designed with #nginx' 'auth_request' in mind, example configurations are included.

This release brings a file-based credential checker in addition to the already existing one using #PAM. Also lots of improvements, see details in the release notes.

I finally added complete build instructions to the README.md:

github.com/Zirias/swad

And there's more documentation available: manpages as well as a fully commented example configuration file.

2025-04-18

Public sector cyber defenses just leveled up. 🛡️

Keeper Security’s new partnership with immixGroup makes KeeperPAM readily available to government agencies and education institutions, because breaches shouldn’t be part of public service.

#cybersecurity #PAM #partnership

mansi18mans18
2025-04-15

Privileged Access Management (PAM) is key to protecting critical systems and data by controlling and monitoring access to sensitive accounts. Strengthen your cybersecurity posture with PAM!

Join our 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 course - infosectrain.com/cybersecurity

InfosecK2KInfosecK2K
2025-04-14

PAM isn’t an option - it’s essential! Whether you're a large business or a small firm, managing your accounts and implementing strong PAM policies is critical for protecting data and staying compliant.

Tune in to The Keys 2 Your Digital Kingdom for expert insights on securing your organisation. Subscribe now!

infoseck2k.com/podcast

2025-04-14

PAM-платформа против техник MITRE ATT&CK

В этой статье вы узнаете, как PAM-платформа СКДПУ НТ может использоваться для митигации техник злоумышленников, описанных в матрице MITRE ATT&CK. Показываем, какие конкретные механизмы защиты можно применить на практике. Будет интересно: Специалистам по ИБ , которые хотят глубже разобраться в технологиях защиты. Архитекторам безопасности , ищущим способы закрыть ключевые векторы атак. Техническим руководителям , оценивающим инструменты для противодействия сложным угрозам.

habr.com/ru/companies/best_pam

#pam #иб #безопасность_данных #безопасность #mitre #кибербезопасность #информационная_безопасность #доступ_к_данным #защита_данных #защита_информации

Felix Palmen :freebsd: :c64:zirias@bsd.cafe
2025-04-10

Just released: #swad v0.2

SWAD is the "Simple Web Authentication Daemon", meant to add #cookie #authentication with a simple #login form and configurable credential checker modules to a reverse #proxy supporting to delegate authentication to a backend service, like e.g. #nginx' "auth_request". It's a very small piece of software written in pure #C with as little external dependencies as possible. It requires some #POSIX (or "almost POSIX", like #Linux, #FreeBSD, ...) environment, OpenSSL (or LibreSSL) for TLS and zlib for response compression.

Currently, the only credential checker module available offers #PAM authentication, more modules will come in later releases.

swad 0.2 brings a few bugfixes and improvements, especially helping with security by rate-limiting the creation of new sessions as well as failed login attempts. Read details and grab it here:

github.com/Zirias/swad/release

InfosecK2KInfosecK2K
2025-04-10

Cyber Security Myth Busters: Unravelling the truth behind cyber security misconceptions.

Get the facts straight and stay secure.

Visit our website to see how we can help you and your business stay safe: www.infoseck2k.com

#

Source: assets.beyondtrust.com/assets/

2025-04-08

I'm not wild about the "Year of" trope, but I think we can go ahead and call this the Year of Agentic AI. I've rarely seen one topic so thoroughly absorb the entire industry's attention.

#Cybersecurity often follows the initial hype around the latest shiny object. Still, some IT pros and vendors are considering what #agenticAI means for security, particularly in identity and access management.

In this feature that was months in the making, experts from academic, vendor, and enterprise backgrounds weighed in.

#AIagents #IAM #identityandaccessmanagement #SecOps #ITOps #identitysecurity #PAM #abac #accesscontrols #AI #GenAI #LLMs

techtarget.com/searchitoperati

Chuck Darwincdarwin@c.im
2025-04-07

Trump has been nominating,
and the Senate has been confirming,
one pliant and obsequious instrument of the president’s pleasure after another.

This is nowhere more true than in appointments to the Department of Justice.

To understand Martin’s danger, it is important to understand how the department in which he would serve as a confirmed official has been operating in Trump 2.0.

At Attorney General #Pam #Bondi’s swearing-in ceremony, she pledged to
“not let [Trump] down”
and to “make [him] proud.”

In her introduction of President Trump before his speech in the Great Hall at the Justice Department,
she called Trump
“the greatest president in the history of our country”
and proclaimed that the department was
“so proud to work at [his] directive”
and would “never stop fighting for” Trump.

She has portrayed Justice Department attorneys as the president’s lawyers.

Bondi signaled fierce loyalty to Trump at her confirmation hearing but nonetheless pledged that,
“If confirmed, I will fight every day to restore confidence and integrity to the Department of Justice
and each of its components.

The partisanship, the weaponization, will be gone. America will have one tier of justice for all.”

🔥In office Bondi has done precisely the opposite
—aggressively so.

She has engaged in a range of politicizing actions,
including dropping the Eric Adams prosecution,
withdrawing charges against and pulling back from investigations of other Trump-allied current or former officials, halting prosecution of a Trump family crypto partner,
and firing or demoting career attorneys who worked on cases involving the president.

She established a “Weaponization Working Group”
that is going after the president’s perceived enemies
and must report on its progress to the White House quarterly.

(Martin is a member of the group.)

The weaponization group is implementing the president’s core philosophy:
“If they screw you, screw them back ten times as hard.”

The goal may be to eliminate future weaponization against Trump interests;
but the tactics are weaponization on a scale never before imagined.

At the same time, Bondi, the chief legal officer of the executive branch after Trump,
is stewarding the rule of law in a disastrous fashion.

She has facilitated the elimination of DOJ independence from the White House,
despite pledges to the contrary.

Her lawyers have been unprepared in court and shown courts unprecedented disrespect.

They have sought to defend the president’s plainly lawless extortionate actions against law firms,
among other lawless executive actions.

Bondi and her lawyers are not restoring confidence and integrity in the department
—they are weakening them.

Bondi had signaled a pro-Trump agenda during her confirmation process,
but now we know the scale on which she is using the department to do the president’s political and personal bidding.

The Senate’s enabling of these actions in confirming Bondi is the proper background to assess Martin’s nomination

#EdwardMartin

Michael Adeyeye Oshínmaoshin@ngportal.com
2025-04-06
@dexter reblog status of @zirias@bsd.cafe:
Released: #swad v0.1 🥳
Looking for a simple way to add #authentication to your #nginx reverse proxy? Then swad could be for you!
swad is the "Simple Web Authentication Daemon", written in pure #C (+ #POSIX) with almost no external dependencies. #TLS support requires #OpenSSL (or #LibreSSL). It's designed to work with nginx' "auth_request" module and offers authentication using a #cookie and a login form.
Well, this is a first release and you can tell by the version number it isn't "complete" yet. Most notably, only one single credentials checker is implemented: #PAM. But as pam already allows pretty flexible configuration, I already consider this pretty useful 🙈
If you want to know more, read here:
https://github.com/Zirias/swad

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst