[go: up one dir, main page]

Shellsharks_" onclick='window.open("/","_self")'>

Infosec Feed

All of my infosec-specific content. You can subscribe to my just-infosec feed here.
Scroll quattuor Feb 21, 2025

Welcome to volume four of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity worlds. Featured topics for this week include how, and more importantly, why to start a personal website, as well as how to join and help grow the Fediverse. Enjoy!

#infosec #indieweb #fediverse
Infosec-only Feb 19, 2025

In the past, I’ve been a bit self-concious about how/what I posted on my site. I believe there’s some part of my readership that comes to my site specifically for infosec-related stuff. So anything NON-infosec that I post is something that they may see on my site, or in their RSS reader and cause them to lose interest in my site because it’s no longer just the infosec stuff they want to see.

#infosec #indieweb #blogging
Scroll tres Feb 14, 2025

Welcome to volume three of Scrolls, a weekly newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity worlds.

#infosec #indieweb #fediverse
What cybersecurity certs to take? Feb 13, 2025

Answering the age old question, “what certification or training should I take?”

#infosec #certs
Scroll duo Feb 07, 2025

Welcome to volumen duo of Scrolls, a newsletter for sharing cool stuff from the IndieWeb, Fediverse & Cybersecurity worlds.

#infosec #indieweb #fediverse
No More -ishings! Feb 04, 2025

*Takes a breath.*

STOP. Please. Just stop. No more. We as a community (the infosec community) must band together and collectively agree to stop creating new phishing name variants. It’s gone too far. There’s too many! Won’t someone think of the aspiring CISSPs? In addition to cramming fire suppression factoids and bollard types into their heads, they will also need to memorize every god forsaken -ishing term too. Back in my day you had just a few, e.g. phishing, vishing, spear phishing, whaling, blah blah - and this was still way too many. What’s with us infosec folks? Why do we do this to ourselves? (Theory: self-loathing, it actually explains a lot about infosec practitioners really). But it was the way it was, and I never complained.

#infosec #funny
Scroll ūnus Feb 04, 2025

Welcome all to the first issue of Scrolls, a newsletter-ish type thing that I hope to compile each week with all sorts of stuff from across the IndieWeb / Fediverse / Cybersecurity realms. The name “Scrolls” is, as you may have already gathered, a play on a piece of writing, the scrolling we do across our various feeds/sites, and the general magic of the web. Enjoy!

#infosec #indieweb #fediverse
Security scanner directory Jan 30, 2025

A reference directory of known vulnerability scanners.

#infosec
Infosec and Social Web RSS feeds Jan 22, 2025

If there is anyone out there who subscribes to my blog’s RSS feed who would like to only get the infosec / cybersecurity-related things I write about, I now have an infosec-only RSS feed you can sub to.

#technology #social #indieweb #socialweb #infosec
FIN URG PSH Dec 23, 2024



                   ★                         
                  ***                        
                 **O**                       
                *******                      
               *********                     
              ***********                   
               ******o**                     
              ***********                    
             **SYN********                   
            ***************                  
           ****o***o********                 
          *******************                
        ***********************              
           *****O***********                 
          ********ACK********                
         ****************o****               
        **O********************              
       ***********o********O****             
     *****************************           
         *********************               
        ***o*******************              
       ***********o*****FIN*****             
      ***************************            
     ***********************O*****           
    ***O***************************          
  ***********************************        
       *************************             
      *******o********o**********            
     *****************************           
    **************o****************          
   *************************O*******         
  ***URG*****************************        
**************o************************      
      ***************************            
     ***********PSH***************           
    ***********o*******************          
   **************************O******         
  ***o******************O************        
***o***********o****************o******      
                  ###                        
                  ###                        
                  ###                        
              ###########                    
              SHELLSHARKS
              ###########



#infosec #xmas
ClownStrike Jul 19, 2024

On July 19, 2024, CrowdStrike delivered a malformed content update to their global fleet of Windows Falcon agents which resulted in a mass BSOD event affecting ~8.5 million systems worldwide. This event has become known as “ClownStrike”.

#infosec #funny
R7 Attack Intel Report 2024: A few takeaways May 22, 2024

Rapid 7 released their 2024 Attack Intelligence Report, an annual writeup containing curated vulnerability data and in-depth analyses of exploit trends. Below I’ve listed a few of my own personal takeaways after reading through the report…

#infosec #weblogpomo2024 #blogpomo
CTF vs Enterprise Security May 21, 2024

On the difficulty of exploitation in a CTF environment versus actual enterprise organizations…

#infosec #weblogpomo2024 #blogpomo
CSC at Home (Part 3): Vulnerability Management May 13, 2024

Welcome to part 3 of the CSC at Home series where I provide practical guidance on how one could implement the CIS Top 20 controls in their home or small-business environment.

#infosec #cis #csc #openvas #vm #scanning #blopomo #weblogpomo2024
CSC at Home (Part 2): Software Inventory and Control May 12, 2024

Welcome to part 2 of my CSC at Home series where I provide practical guidance on how one could implement the CIS Top 20 controls in their home or small-business environment.

#infosec #cis #csc #openvas #vm #scanning #blopomo #weblogpomo2024
CSC at Home (Part 1): Hardware Inventory and Control May 11, 2024

This is the first in a series of posts discussing the CIS Top 20 controls and how they can be implemented in a home or small-business environment. Before getting into the first of these controls, I’ll begin by providing some introductory background on the CIS Top 20.

#infosec #cis #csc #openvas #vm #scanning #blopomo #weblogpomo2024
Security lone wolf Apr 11, 2024

CIS Critical Security Controls and/or NIST CSF as frameworks to help put you in the right mindset. But so much of what you should do first depends on some variables imo.

#infosec
Breaking in is the hard part Apr 03, 2024

In response to one Reddit user’s breaking into infosec plight

#infosec
Infosec work life balance Apr 03, 2024

A commonly asked question is whether infosec / cybersecurity is “stressful” and generally “what is the work life balance like?”. I think there are three main things that contribute to whether a job is stressful, none of them particularly unique to infosec.

#infosec
Reverse Syndication, i.e. PESOS Apr 02, 2024

Reverse syndication”, i.e. archiving discussions I have elsewhere on the web (PESOS) on my site is very valuable to me for a few reasons…

#infosec
Cybersecurity: A life-long pursuit Apr 02, 2024

A redditor asks

#infosec
The current infosec job market Apr 02, 2024

I see a lot of questions about the infosec / cybersecurity job market…

#infosec
xz/liblzma Compromise Link Roundup Mar 31, 2024

The infosec/technology world is abuzz with discussions and analyses pertaining to the recently identified compromise of the open-source xz/liblzma compression library, i.e. CVE-2024-3094. Here is a roundup of links related to everything going on…

#infosec #supplychain
Mammoth Indiesec Smart List Mar 21, 2024

If you are in #infosec / #cybersecurity and looking for an easier way to follow interesting infosec accounts that are relatively high signal-to-noise without having to scour the Fediverse, consider checking out the #mammoth Mastodon client and subscribing to the new #indiesec Smart List! Smart Lists are a unique feature pioneered by Mammoth which offers curated lists of accounts in a number of different subject areas.

#infosec #mastodon #fediverse #nosearch
A hashtag for asking questions to the infosec Fediverse Mar 14, 2024

What does the #infosec / #cybersecurity (or infosec-adjacent) community think of “establishing” a go-to hashtag for asking infosec-related questions? Something like #AskSecFedi or #AskFediSec? Personally I think the latter has a better ring to it but curious what others think. I’ve seen a lot of people in the community ask questions that don’t get answered due to classic social reach issues but perhaps a dedicated hashtag could help alleviate some of that. (If you have a catchier tag feel free to comment!)

#infosec #mastodon #fediverse
The basics of infosec are not basic Mar 03, 2024

@lcamtuf@infosec.exchange I’ve always said something very similar with regard to infosec disciplines that many regard as “junior” or “easy”. Vulnerability Management is one such role that I think is pretty easy to get started in (and many in security do) and for many considered to just be something that is easy/junior when in reality, doing advanced VM is something that takes a lot of finesse, organizational knowledge, cross-disciplinary skills, coding chops, etc… Same could be said for things like “SOC Analyst”. Sure you can run junior folks through that role but there is definitely a spectrum of proficiency that should not be overlooked.

#infosec
How the Internet discovers my site Jan 23, 2024

@john_fisherman Hey! I read your post here and wanted to let you know about my own experience as a random writer on the web (understanding that everyone’s experience differs). I started my blog in 2019 and expected to never really get any interest from people in terms of reading, using or getting feedback on what I had written. After nearly 5 years I’ve been blown away with the reception and level of feedback I have gotten! So what do I think has helped me in terms of people discovering my site, enjoying it and giving me feedback?…

#technology #indieweb #infosec
Strategy for finding news Jan 12, 2024

@LaGrange Here’s my “find news” strategy…

#infosec #technology #rss #mastodon #feedly #fediverse
Using bird.makeup as a canary Jan 12, 2024

Pro Tip: If for whatever reason you still have a Twitter/X account but don’t really use the platform, follow it from here using bird.makeup. This way, if you ever DO see something from there, you’ll know it was hacked somehow 😅. Because apparently getting your X account pwned is something even Mandiant can’t prevent 🤦‍♂️.

#infosec #mastodon #nosearch
Named vuln counts by year Jan 05, 2024

Here are the number of “named vulnerabilitiesper year (based on data I’ve captured here). Vulnerabilities are counted for a given year based on A. what their CVE ID is, or B. If they don’t have a CVE, when the original article about that vuln was posted.

#infosec