Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

Security BSides Sofia 2022 - Daniel Rankov's 'Common Security Pitfalls In AWS Public Cloud For Highly Regulated Industries' →

May 18, 2022 by Marc Handelman in Security BSides Sofia, Republic of Bulgaria, NATO Member State, United States Allies, Security Conferences, Education, Security, Cybersecurity Education, Security Education, Cloud Security

Our thanks to Security BSides Sofia for publishing their Presenter’s Security BSides Sofia 2022 superb security videos on the organization’s’ YouTube channel.

May 18, 2022 /Marc Handelman
Security BSides Sofia, Republic of Bulgaria, NATO Member State, United States Allies, Security Conferences, Education, Security, Cybersecurity Education, Security Education, Cloud Security

DEF CON 27, Cloud Village - Chris Le Roy's 'Build To Hack Hack To Build' →

March 05, 2020 by Marc Handelman in Conferences, DEF CON 27, Cloud Security, Education

via the Comic Noggins of Nitrozac and Snaggy at The Joy of Tech®! 1:

March 05, 2020 /Marc Handelman
Conferences, DEF CON 27, Cloud Security, Education

DEF CON 27, Cloud Village - Ayman Elsawah's 'Using Paretos Principle For Securing AWS With SCPs' →

March 04, 2020 by Marc Handelman in Conferences, DEF CON 27, Education, Cloud Security, Information Security

Thanks to Def Con 27 Volunteers, Videographers and Presenters for publishing their superlative conference videos via their YouTube Channel for all to see, enjoy and learn.

March 04, 2020 /Marc Handelman
Conferences, DEF CON 27, Education, Cloud Security, Information Security

DEF CON 27, Cloud Village - Erick Galinkin's 'Your Blacklist Is Dead Airgap Everything' →

March 04, 2020 by Marc Handelman in Conferences, DEF CON 27, Education, Cloud Security, Information Security

Thanks to Def Con 27 Volunteers, Videographers and Presenters for publishing their superlative conference videos via their YouTube Channel for all to see, enjoy and learn.

March 04, 2020 /Marc Handelman
Conferences, DEF CON 27, Education, Cloud Security, Information Security

DEF CON 27, Cloud Village - Rotem Bar's 'Hacking Into Automative Clouds' →

March 03, 2020 by Marc Handelman in Conferences, DEF CON 27, Education, Cloud Security, Information Security

Thanks to Def Con 27 Volunteers, Videographers and Presenters for publishing their superlative conference videos via their YouTube Channel for all to see, enjoy and learn.

March 03, 2020 /Marc Handelman
Conferences, DEF CON 27, Education, Cloud Security, Information Security

DEF CON 27, Cloud Village - Rod Soto's and José Hernandez' 'Using Splunk Or ELK For Auditing AWS GCP Azure Security' →

March 03, 2020 by Marc Handelman in Conferences, DEF CON 27, Education, Cloud Security, Information Security

Thanks to Def Con 27 Volunteers, Videographers and Presenters for publishing their superlative conference videos via their YouTube Channel for all to see, enjoy and learn.

March 03, 2020 /Marc Handelman
Conferences, DEF CON 27, Education, Cloud Security, Information Security

DEF CON 27, Cloud Village - Setu Parimi's 'PacBot Policy As Code From T-Mobile OSS' →

March 02, 2020 by Marc Handelman in Conferences, Cloud Security, Education, Information Security, Security Policy

Thanks to Def Con 27 Volunteers, Videographers and Presenters for publishing their superlative conference videos via their YouTube Channel for all to see, enjoy and learn.

March 02, 2020 /Marc Handelman
Conferences, Cloud Security, Education, Information Security, Security Policy

DEF CON 27, Cloud Village - Tanya Janca's 'DYI Azure Security Assessment' →

March 02, 2020 by Marc Handelman in Conferences, DEF CON 27, Cloud Security, Education, Information Security

Thanks to Def Con 27 Volunteers, Videographers and Presenters for publishing their superlative conference videos via their YouTube Channel for all to see, enjoy and learn.

March 02, 2020 /Marc Handelman
Conferences, DEF CON 27, Cloud Security, Education, Information Security

And Then There's This

February 12, 2020 by Marc Handelman in Information Security, Cloud Security

via InformationWeek's DarkReading blog - and written by Corey Nachreiner, comes a rather dire warning of the inevitable movement of ransomeware toting miscreants targeting cloud deployments... Ignore the fear,ladies and gentlemen, and remediate the fundamentally flawed security infrastructure you've migrated to the web whilst comfortably enveloped in the vainglorious effort to 'digitally transform' your 'environment.

'As cloud services become increasingly critical to more businesses' daily operations, ransomware authors will follow to maximize profits. The good news is that the cloud can be secured with many of the same best practices that apply to physical networks. Make every effort to keep your cloud deployments safe and secure today. In the future, you might be glad you did.' - via InformationWeek's DarkReading blog and scribed by Corey Nachreiner

February 12, 2020 /Marc Handelman
Information Security, Cloud Security

USENIX Enigma 2019, Neha Rungta's 'Provable Security At AWS' →

September 13, 2019 by Marc Handelman in Conferences, Cloud Security, Education, Information Security, USENIX Enigma 2019

Thanks to USENIX for publishing the USENIX Enigma 2019

outstanding conference videos on their YouTube Channel

September 13, 2019 /Marc Handelman
Conferences, Cloud Security, Education, Information Security, USENIX Enigma 2019

Security BSides London 2019, Paul Schwarzenberger's 'AWS Vs Azure Security' →

September 06, 2019 by Marc Handelman in Cloud Security, BSides London 2019, Conferences, Education, Information Security

Many thanks to Security BSides London for publishing their outstanding conference videos on YouTube.

September 06, 2019 /Marc Handelman
Cloud Security, BSides London 2019, Conferences, Education, Information Security

ASUS Cloud Services: Backdoor In Motion

May 20, 2019 by Marc Handelman in Cloud Security, Information Insecurity, Security Incompetence, Must Read

via the eponymous Dan Goodin, writing at Ars Technica, comes news of a cloud solution gone spuriously out-of-control. Certainly a clear-enough indication the 'Cloud' is not to be trusted, at any time, nor from any vendor - regardless of claims to the contrary. Today's Must Read.

May 20, 2019 /Marc Handelman
Cloud Security, Information Insecurity, Security Incompetence, Must Read

BSides Delaware 2018, Jeff Silver's 'Cloud Proxy Technology: The Changing Landscape' →

January 15, 2019 by Marc Handelman in BSides Delaware, Conferences, Education, Information Security, Cloud Security
January 15, 2019 /Marc Handelman
BSides Delaware, Conferences, Education, Information Security, Cloud Security

Black Hills Infosec 'RDP Logging Bypass And Azure Active Directory Recon' →

January 03, 2019 by Marc Handelman in Information Security, Network Security, Cloud Security
January 03, 2019 /Marc Handelman
Information Security, Network Security, Cloud Security

Meanwhile, In News of the Coming Software Apocalypse...

October 31, 2018 by Marc Handelman in Clown Car, Cloud Security, Cloud Data Storage

via Paul Kunert, writing at El Reg, comes this story of persistent login issues with Microsoft Corporation's (Nasdaq: MSFT) 'Cloud' based Office Not-So-Productive productivity product, monikered O365 - Oh, but you knew that, since you've been unable to fire up good ol' Word for days... Perhaps a non - Cloud based solution to run your business might be in order, eh?

October 31, 2018 /Marc Handelman
Clown Car, Cloud Security, Cloud Data Storage

ShowMeCon 2018, Arnar Gunnarsson's 'We Don't Have To Worry About That, It's In The Cloud.' →

August 08, 2018 by Marc Handelman in Cloud Security, Conferences, Education, Information Security, ShowMeCon
August 08, 2018 /Marc Handelman
Cloud Security, Conferences, Education, Information Security, ShowMeCon

CircleCity Con 2018, Bryan McAninch's 'The FaaS And The Curious: AWS Lambda Threat Modeling' →

July 26, 2018 by Marc Handelman in Conferences, Education, Information Security, AWS, Cloud Security, Security Automation, Security Architecture, AWS Lambda Architecture, AWS Lambda, Circle City Con
July 26, 2018 /Marc Handelman
Conferences, Education, Information Security, AWS, Cloud Security, Security Automation, Security Architecture, AWS Lambda Architecture, AWS Lambda, Circle City Con

The Secrets Mangler

April 21, 2018 by Marc Handelman in Information Security, Cloud Security, Must Read

via Tom Krazit, writing at GeekWire, details the need for security tooling assistance targeting the apparent shortcomings of customer security comprehension. Really? I chalk this up to customer facing security tooling, and enablement (Hows' that for Corporate DoubleSpeak?). Far be it for me to denigrate customer security understanding... Today's MustRead!

April 21, 2018 /Marc Handelman
Information Security, Cloud Security, Must Read

Coinhive Cryptojacker, The Prevaler →

February 12, 2018 by Marc Handelman in Crime, Cryptocurrency, Cryptomining, Information Security, Cloud Security, Web Security

Check Point Software Technologies Ltd. has noted (via the comapny's well traveled blog) a new milestone for malicious wares/scripts et cetera; this time Coinhive takes the blue ribbon award for the most pernicious installations on our beloved interwebs, according to the Check Point's research.

February 12, 2018 /Marc Handelman
Crime, Cryptocurrency, Cryptomining, Information Security, Cloud Security, Web Security

'Firestarter: Architecting Your Cloud With Accounts' from Securosis, LLC on Vimeo.

Securosis, 'Firestarter: Architecting Your Cloud With Accounts'

February 03, 2018 by Marc Handelman in Cloud Security, Education, Information Security
February 03, 2018 /Marc Handelman
Cloud Security, Education, Information Security
  • Newer
  • Older