Category: Cybersecurity
Everything filed under Cybersecurity.
Davos 2020 World Economic Forum 2020 Global Risk Report Cyber Cliffs Notes
Each year the World Economic Forum releases their Global Risk Report around the time of the annual Davos conference. This year's report is out and below are notes on the "cyber" content to help others speed-read through those sections (in…
Handling & Sharing PCAPs Like a Boss with PacketTotal
The fine folks over at @PacketTotal bequeathed an API token on me so I cranked out an R package for it to enable more dynamic investigations work (RStudio makes for an amazing incident responder investigations console given that you can…
Collecting Content Security Policy Violation Reports in S3 ('Effortlessly'/'Freely')
In the previous post I tried to explain what Content Security Policies (CSPs) are and how to work with them in R. In case you didn't RTFPost the TLDR is that CSPs give you control over what can be loaded along with your web content and can…
CRAN Mirror "Security"
In the "Changes on CRAN" section of the latest version of the The R Journal (Vol. 10/2, December 2018) had this short blurb entitled "CRAN mirror…
Acquisitions and Supply Chains: The Achilles' heel of Product/Organizational Security
Over at the $WORK blog we posted some research into the fairly horrible Cisco RV320/RV325 router vulnerability. The work blog is the work blog and this blog is my blog (i.e. opinions are my own, yada, yada, yada) and I felt compelled to…
Certifiably Gone Phishing
Phishing is [still] the primary way attackers either commit a primary criminal act (i.e. phish a target to, say, install ransomware) or is the initial vehicle used to gain a foothold in an organization so they can perform other criminal…
Use GitHub Vulnerability Alerts to Keep Users of Your R Packages Safe
Despite their now inherent evil status, GitHub has some tools other repository aggregators do not. One such tool is the free vulnerability alert service which will scan repositories for outdated+vulnerable…
GDPR Unintended Consequences Part 1 — Increasing WordPress Blog Exposure
I pen this mini-tome on "GDPR Enforcement Day". The spirit of GDPR is great, but it's just going to be another Potempkin Village in most organizations much like PCI or SOX . For now, the only thing GDPR has done is made GDPR consulting…
RIPE 76 Selected Talks
Do not read anything more into the order than the end-number of the "Main URL" since this was auto-generated from a script that processed my Firefox tab…
Does Congress Really Care About Your Privacy?
Said bad words include "Facebook", "Mark Zuckerberg" and many referrals to entities within the U.S. Government. Given the topic, it cannot be…