Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
I'm inheriting a massive vulnerability debt and taking on a vulnerability management position with very little experience.


Piss and poo poo. Here we go.

Adbot
ADBOT LOVES YOU

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc

This cuts deep, op.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc

Wibla posted:

I had no meetings today :sun:

I've got 22.

I'll attend 5.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
Can anybody recommend some decent resources for getting up to speed with the CISSP? There's so much noise for this cert, I'm not sure what is going to be most effective. Free is best until I can sucker work into paying.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc

AlternateAccount posted:

Most comprehensive is still prolly https://www.sunflower-cissp.com

I'll take a peek. Thank you!

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
Guy training me wants me to help him train 30k users on using a password manager. I'm not sure that's gonna happen.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
I'm new to the space, but that seems to be the concern with our infra teams per our discussions. Red Team starts from "compromised device within the firewall" and suddenly they're finding lots of stuff! I, too, am a master thief when invited in and with the house unlocked.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
Totally understood, I wasn't stating that there should only be one layer. These are complaints from my infra guys when they're getting raked over the coals for Red Team findings.

I'm the schlub that has to make the argument now that these findings are of paramount importance, despite the risk assessment completely ignoring the fact that we weren't breached.

I guess I was just venting.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc

Sickening posted:

The culture you build in security should be to embrace findings with positivity. Having a green scorecard is the goal but is far more likely a symptom of your company having blind spots.

Findings being used to cause conflict should be shut down most times. Otherwise, you are creating a culture where people will avoid bringing awareness to problems or going out of there way to hide them.

Of course you are going to find situations where the dirty laundry is caused purposeful neglect and or purposeful recklessness, I have no choice but to poo poo on those people because i can't help it.

This is my mid term goal. Short term is figuring out where someone is hiding all the findings and the toys, and get my house in order. :haw: medium term is turning some insular groups into an integrated service.

JehovahsWetness posted:

We get that security requests can really gently caress up a roadmap and we pitch in as much as we can so sec doesn't get seen as the bad guys. (We stress that we're an engineering org and are part of product development / corp infra it and we're here to help.

Exactly my goal. It's complicated by the fact that this is a place quilted together by m&a.

Cannon_Fodder fucked around with this message at 21:15 on Oct 14, 2023

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc

PalaNIN posted:

Apparently a 0-day exploit going around for the Signal messaging app, related to the data within message previews:

https://hax0rbana.social/@adam/111236822600142276

What's the usual disclosure path for these things?

Rumor on twitter/mastodon -> https://www.zero-day.cz/database/?s...ORS%5D%5B%5D=16 -> ?

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
Hint to vendors, if you're in a call with your client and they've pulled in cyber security and legal, don't try to justify why things are not really technically a vulnerability. I'm amazed by the balls on some of these people. Just fix your poo poo, guy.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
Any of you dorks at QSC'23?

:spooky:

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
I prefer e-privateer, personally.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
Yeah, that certainly strikes a note.



Are there any good RSS feeds for emergent vulnerabilities? I made the mistake of asking our SOC folks about some of the stuff mentioned in this thread over the last few weeks and now they think I'm in the "know". Might as well ask around for them.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
Thanks guys/gals.


Coming from app Security on an ERP, the greater VM world is pretty vast and overwhelming. I appreciate the resources.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
The sobriety patch is stuck in qa approvals, this will have to wait until after the holiday

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc

Arivia posted:

This is why I rearchitected on Linux with GNU Cloaca. Everything is a mess and it all just gets stuck together but there's only one big hole now to worry about.

:golfclap:

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
I just got told I need to be in the office at least 2 days a week.

I asked my boss who was going to check


Nobody.



Congrats me in continuing to be full time remote.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
1password has been set up, based on thread recommendation.

For anyone not already onboard, if you're coming from a browser, you can mass import your saved passwords from there.

Then the little watchtower feature yells at you because you're a lazy dick and deserve it.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc

Sickening posted:

Nobody wants to work in compliance. It’s often a place of exile.

:tif:

I feel seen.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
1password rules, thank you for the suggestions

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
I would love to know what a cyber attack triage specialist consultant costs because I'm sure these guys are making stupid money.

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc

post hole digger posted:

You need to apply strategic defenses to your perimeter to maximize your security ROI and strengthen your overall security posture in alignment with NIST 800-53 best practices. Do you have XDR? SOAR? CSPM? CNAPP? MDR? ZTNA? Let me set up a few calls with vendors. I won’t be able to attend due to scheduling conflicts but these guys are great, you’re in good hands. That will be $95,000.

An hour, I presume.

I mean the hands on keyboard "unfuck your poo poo" mercenaries that batman in during an ongoing security event

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
Apparently Stuxnet 2 electric boogaloo is now being leveraged against Russian targets by Ukraine and called fuxnet

How long till that starts getting recycled?

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc

Wibla posted:

Do you have a link to more info about this?

https://www.securityweek.com/destructive-ics-malware-fuxnet-used-by-ukraine-against-russian-infrastructure/

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc
Who's Amir?

Adbot
ADBOT LOVES YOU

Cannon_Fodder
Jul 17, 2007

"Hey, where did Steve go?"
Design by Kamoc

rafikki posted:

Sounds like things are getting bad out there with the Palo exploit. RIP to all the IR teams

:dogstare::hf::unsmigghh:

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply