π Decrypt Weekly β November 1 Issue
Check out this weekβs edition for interesting reads, security tools, and updates on key changes in the cybersecurity world. Stay connected with weekly updates! #CyberSecurity
@seczen.bsky.social
I love learning and discovering new security tools.
π Decrypt Weekly β November 1 Issue
Check out this weekβs edition for interesting reads, security tools, and updates on key changes in the cybersecurity world. Stay connected with weekly updates! #CyberSecurity
π Explore our guide on security architecture with threat-based modeling. Learn how integrating Time-Based Security, the Intrusion Kill Chain, and MITRE ATT&CK strengthens detection, response, and resilience against cyber threats. #CyberSecurity #ThreatModeling #SOC
31.10.2024 00:20 β π 0 π 0 π¬ 0 π 0π Chainloop - software supply chains π v0.75.x Highlights:
Org membership API
Scoped invitations
Role info display in API
Set role during invitation
Read-only viewer role
Domain-based allow-listing
docs.chainloop.dev
#infosec #cybersecurity #devsecops #cicd
mitmproxy π 10.2.3 Release Highlights: Fixed IPv6 glitch, CONNECT URL bug, added arm64 macOS variant. Addressed DNS duplicates, wireguard config issue, and leaf cert creation bug. New mitmdump options and enhanced HTTP flow filters
mitmproxy.org
#infosec #cybersecurity #pentesting
Forwarder - MITM proxy π v.1.2.0 π Introducing idle timeout, armed TLS listener, and connection metrics. π Security boosts with automatic closure after 1hr of inactivity and enhanced ConnectTimeout. Added GOMEMLIMIT and GOMAXPROCS metrics. forwarder-proxy.io
#mitm #infosec #cybersecurity
httpX - toolkit that allows running reliable multi threaded probes
#infosec #cybersecurity
github.com/projectdisco...
Teleport - π v15.1.0 Release Highlights:
- Standalone tbot Docker image
- Custom mouse pointers for remote desktop sessions
- Okta groups and apps synchronization
- EKS auto-discovery in Access Management UI
- TLS routing native WebSocket connection upgrade support
goteleport.com
#infosec #devsecops
Chainloop - software supply chain control plane π v0.70.0 release highlights
- support parent ID for auto-create hierarchical projects
- filter workflow runs by status
- added workflow latest_revision and description
#sbom #cicd #infosec #cybersecurity
Vault - secrets manager π Release v1.15.6
π Ensure secure client certificate validation by comparing public keys with trusted non-CA and leaf certificates, preventing trust in certs with the same serial but different keys or use of alternate certs with forged serial numbers.
#infosec #devsecops
Kicks - IaC vuln scanner π v1.7.13 Release Highlights:
π Parallel scanning
β Terraform nifcloud queries
π Tencentcloud: cbs disk without encryption
π Various queries for CloudFormation, Docker, crossplane, pulumi, and more!
#iac #devsecops #infosec #cybersecurity
OPA - Open Policy Agent π v0.62.0 Release:
π Environment variable backups for cmd flags
β Added WithBundleParserOpts to OCI downloader
π Logging optimization
π Allow bundles to contain calls to unknown Rego functions
π Improved input validation in topdown/http
#infosec #cybersecurity
π Kali Linux 2024.1 Release is here: β¨ Kali project got more mirrors, Theme refresh, NetHunter Updates, and introducing new tools: blue-hydra, OpenTAXII, readpe, Snort, and Above!
#pentesting #infosec #cybersecurity
netmaker - wireguard based networks π v0.23.0 update: β¨ Revamped Internet Gateways: Improved connectivity for hosts and clients! π Access internet gateways via Remote Access tab. π» PostUp/PostDown commands, EMQX cloud support, Metadata for Remote Access Gateways.
#selfhosted #netsec #vpn #zerotrust
π Terrascan 1.18.12 is here! π Update includes:
β¨ Fixed display line numbers in CloudFormation templates scan results.
Terrascan enhances IaC compliance and security.
#devsecops #terraform #cicd #infosec
xca - CA certificate and key management
π 2.6.0 Release Highlights:
π Support for ovpn files
π Fixes PKCS12 imports
π Support for legacy keys
#cryptography #certificates #infosec #cybersecurity
HollowsHunter - scan Windows processes for malicious implants v0.3.9 release update
π Added /pattern flag to allow search for custom signatures using SigFinder format
github.com/hasherezade/...
#malware #infosec #cybersecurity
aws-firewall-factory - Web AWS firewall factory 4.2.3 Release
- Check for Managed Rule Groups Labels and Rules
- Athena WAF log table support for easy analysis
- Fixes for customizable log group creation
#netsec #infosec #cybersecruity
asn - Network recon tool
π v.0.76.0 release AS target lookup improvements:
β‘ Accelerate pWhois for AS OrgIDs & INETNUMs
π Faster INETNUM origin lookup via Team Cymru WHOIS
π₯ Highlight unannounced INETNUMs
π Switched to RIPEStat API
#osint #shodan #infosec #cybersecurity
Trufflehog - credentials scanner v.3.68.0 release update
- Added canary detection without detonation
#securitytools #infosec #cybersecruity
trufflesecurity.com
Authentik - Identity Provider focused on flexibility and versatility release 2024.2.0
- fix for webauthn retry
- fixed rbac in permission_required decorator
#securitytools #idp #sso #infosec #cybersecurity
Artemis - security vulnerability scanner developed by CERT PL v2.6.0 release
- Finding selected Nuclei vulnerabilities
- WordPress plugin version check
- Added Known Exploited Vulnerabilities KEV source
#securitytools #infosec #cybersecurity
Cloudlist - listing assets from multi cloud v1.0.7 release update
- added integration with Kubernetes via config block. Specify connection details via file path or encoded kubeconfig. Priority to kubeconfig_encoded if both are provided.
#devops #k8s #infosec #cybersecurity
Prowler - Open Source CSPM v3.14.0 release update
- 25 new Azure checks
prowler.com
#securitytools #cspm #infosec #cybersecurity
Copacetic - Quickly patch containers for security without full rebuilds. Copa addresses operational gaps, enabling non-publishers like DevSecOps to patch images.
project-copacetic.github.io/copacetic/we...
#securitytools #vulnerabilities #infosec #cybersecurity
Security Onion - Threat hunting and security monitoring platform 2.4.50 release
- IKE pipeline
- DoD Stig compliance
- Integrations for Citrix, Nginx Winlog, RITA Logs
- Improved co-relations in SOC
#securitytools #ids #infosec #cybersecurity
blog.securityonion.net/2024/02/secu...
garak - LLM vulnerability scanner v0.9.0.12 release update
- added --buffs parameter
- plugins OpenAI, Low Res Lang, Rasa generator, Tree of Attacks
#securitytools #llm #ai #infosec #cybersecurity
GOAD - Game of Active Directory
- GOAD 5vms 2 forests 3 domains
- GOAD-Light 3 vms 1 forest 2 domains
- NHA 5vms 2 domains
- Provision witth Virtualbox VmWare Proxmox Azure
#homelab #pentesting #infosec #cybersecurity
github.com/Orange-Cyber...
imalive - generate IAM policy from client monitoring v1.1.7 release
- updated policy maps
- added host flag
#securitytools #cloudsecurity #infosec #cybersecurity