opinionated about security.
knowledge hubs at rami.wiki, thoughts at ramimac.me
What you can expect to see here:
* infrequent, but hopefully high signal posting
* promoting and amplifying interesting security work (including dreaded self-promotion)
* scaling security programs & cloud security
* ironic(?) usage of scooby-doo
ramimac.me
HuggingFace, Azure OpenAI, Weights & Biases, and Groq.
Read more:
www.wiz.io/blog/leaking...
HuggingFace, Azure OpenAI, Weights & Biases, and Groq.
Read more:
www.wiz.io/blog/leaking...
> To report exposed Google Cloud credentials, please contact [email protected]
cloud.google.com/blog/product... really buried the lede!
> To report exposed Google Cloud credentials, please contact [email protected]
cloud.google.com/blog/product... really buried the lede!
Covers permissions, secrets, 3rd-party Actions, ++
Use it to avoid learning these lessons the hard way:
www.wiz.io/blog/github-...
Covers permissions, secrets, 3rd-party Actions, ++
Use it to avoid learning these lessons the hard way:
www.wiz.io/blog/github-...
Today's options, and tomorrow's possibilities
www.wiz.io/blog/mcp-sec...
Today's options, and tomorrow's possibilities
www.wiz.io/blog/mcp-sec...
Our own @ramimac.me helps dive into GitHub supply chain attacks, IngressNightmare, and Oracle breach rumors.
Tune in for the latest cloud security insights!
🎧 podcasts.apple.com/us/podcast/q...
Our own @ramimac.me helps dive into GitHub supply chain attacks, IngressNightmare, and Oracle breach rumors.
Tune in for the latest cloud security insights!
🎧 podcasts.apple.com/us/podcast/q...
www.wiz.io/blog/new-git...
www.wiz.io/blog/new-git...
And the results? Wild.
I've joined the amazing @wiz_io research team
My goal is the "work for the security industry, at Wiz"
I wrote a blog post explaining why, and what that means:
ramimac.me/joining-wiz
I've joined the amazing @wiz_io research team
My goal is the "work for the security industry, at Wiz"
I wrote a blog post explaining why, and what that means:
ramimac.me/joining-wiz
We don’t hear nearly as much about the value of a well-considered, strategically deployed “No”
I've pulled together guidance on giving a better, more constructive No:
ramimac.me/saying-no
We don’t hear nearly as much about the value of a well-considered, strategically deployed “No”
I've pulled together guidance on giving a better, more constructive No:
ramimac.me/saying-no
Unclear how pervasive this was!
Unclear how pervasive this was!
You know, the ones that use data from their CSPM product
And I've realized the findings substantially reflect how well that tool helps customers secure their clouds
I wrote up some examples, both good and bad (🔗 in 🧵)
You know, the ones that use data from their CSPM product
And I've realized the findings substantially reflect how well that tool helps customers secure their clouds
I wrote up some examples, both good and bad (🔗 in 🧵)
This has made it into the Silicon Valley water table; it must be dealt with. There are some good nuggets within; let's dig them out.
charity.wtf/2024/12/17/f...
This has made it into the Silicon Valley water table; it must be dealt with. There are some good nuggets within; let's dig them out.
charity.wtf/2024/12/17/f...
1. Find the Crunchbase page of a cybersecurity company that just raised VC funding
2. Change the page details (which anyone with a Crunchbase account can do) to a personal CashApp page
3. ????
4. Profit! (?)
1. Find the Crunchbase page of a cybersecurity company that just raised VC funding
2. Change the page details (which anyone with a Crunchbase account can do) to a personal CashApp page
3. ????
4. Profit! (?)
His core advice:
1. Make lives easier - e.g roll out yubikeys
2. Define Security Invariants
3. Plan & Practice IR
4. Balance Risks & Threats
5. Security is a People Problem - use focus groups for new controls!
youtu.be/BPh4Hc3TH74
His core advice:
1. Make lives easier - e.g roll out yubikeys
2. Define Security Invariants
3. Plan & Practice IR
4. Balance Risks & Threats
5. Security is a People Problem - use focus groups for new controls!
youtu.be/BPh4Hc3TH74
> IAM-PolicyRefiner, a tool that automatically synthesizes refined AWS IAM access control policies from access logs
> fast (<5s per policy), effective and does not overfit
Not open source, but maybe a sign of things to come?
assets.amazon.science/cf/bc/58e56f...
> IAM-PolicyRefiner, a tool that automatically synthesizes refined AWS IAM access control policies from access logs
> fast (<5s per policy), effective and does not overfit
Not open source, but maybe a sign of things to come?
assets.amazon.science/cf/bc/58e56f...
I've come up with a Rule of Thumb:
Hire your first security person when security is an unavoidable distraction from scaling your business
ramimac.me/start-security
h/t @grims.bsky.social & @mag00.bsky.social
I've come up with a Rule of Thumb:
Hire your first security person when security is an unavoidable distraction from scaling your business
ramimac.me/start-security
h/t @grims.bsky.social & @mag00.bsky.social
Tuesday is going to be ok 👍
www.computer.org/csdl/proceed...
I track the latest evidence against phishing simulations: rami.wiki/phishing-sim...
www.computer.org/csdl/proceed...
I track the latest evidence against phishing simulations: rami.wiki/phishing-sim...
Interesting tidbits in 🧵
paved roads 🛣️: “layers multiple offerings together into easy-to-use workflows”
vs
railways 🚟 building to fill a "meaningful gap that is not covered by any existing product”
Interesting tidbits in 🧵
paved roads 🛣️: “layers multiple offerings together into easy-to-use workflows”
vs
railways 🚟 building to fill a "meaningful gap that is not covered by any existing product”
What you can expect to see here:
* infrequent, but hopefully high signal posting
* promoting and amplifying interesting security work (including dreaded self-promotion)
* scaling security programs & cloud security
* ironic(?) usage of scooby-doo
ramimac.me
What you can expect to see here:
* infrequent, but hopefully high signal posting
* promoting and amplifying interesting security work (including dreaded self-promotion)
* scaling security programs & cloud security
* ironic(?) usage of scooby-doo
ramimac.me