SecZen's Avatar

SecZen

@seczen.bsky.social

I love learning and discovering new security tools.

86 Followers  |  3 Following  |  71 Posts  |  Joined: 08.02.2024  |  1.5037

Latest posts by seczen.bsky.social on Bluesky


Newsletter 1 November 2024 Get the latest security insights, tech updates, and impactful tools reviewed in our November 1, 2024, newsletter.

πŸ”’ Decrypt Weekly – November 1 Issue
Check out this week’s edition for interesting reads, security tools, and updates on key changes in the cybersecurity world. Stay connected with weekly updates! #CyberSecurity

01.11.2024 12:09 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Defending Against Advanced Cyber Threats Integrating Time-Based Security, Intrusion Kill Chain, and MITRE ATT&CK

πŸ”’ Explore our guide on security architecture with threat-based modeling. Learn how integrating Time-Based Security, the Intrusion Kill Chain, and MITRE ATT&CK strengthens detection, response, and resilience against cyber threats. #CyberSecurity #ThreatModeling #SOC

31.10.2024 00:20 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

πŸ”— Chainloop - software supply chains πŸš€ v0.75.x Highlights:
Org membership API
Scoped invitations
Role info display in API
Set role during invitation
Read-only viewer role
Domain-based allow-listing
docs.chainloop.dev
#infosec #cybersecurity #devsecops #cicd

08.03.2024 00:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

mitmproxy πŸš€ 10.2.3 Release Highlights: Fixed IPv6 glitch, CONNECT URL bug, added arm64 macOS variant. Addressed DNS duplicates, wireguard config issue, and leaf cert creation bug. New mitmdump options and enhanced HTTP flow filters
mitmproxy.org
#infosec #cybersecurity #pentesting

07.03.2024 00:56 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Forwarder - MITM proxy πŸš€ v.1.2.0 πŸ†• Introducing idle timeout, armed TLS listener, and connection metrics. πŸ”’ Security boosts with automatic closure after 1hr of inactivity and enhanced ConnectTimeout. Added GOMEMLIMIT and GOMAXPROCS metrics. forwarder-proxy.io
#mitm #infosec #cybersecurity

05.03.2024 11:23 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

httpX - toolkit that allows running reliable multi threaded probes
#infosec #cybersecurity
github.com/projectdisco...

02.03.2024 14:01 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Teleport - πŸš€ v15.1.0 Release Highlights:
- Standalone tbot Docker image
- Custom mouse pointers for remote desktop sessions
- Okta groups and apps synchronization
- EKS auto-discovery in Access Management UI
- TLS routing native WebSocket connection upgrade support
goteleport.com
#infosec #devsecops

01.03.2024 10:51 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Release v0.70.0 Β· chainloop-dev/chainloop Highlights Hierarchical Dependency-Track project support @sedan07 extended the dependency-Track plugin to support attaching automatically created projects to existing parent projects. This enables ...

Chainloop - software supply chain control plane πŸš€ v0.70.0 release highlights
- support parent ID for auto-create hierarchical projects
- filter workflow runs by status
- added workflow latest_revision and description
#sbom #cicd #infosec #cybersecurity

01.03.2024 10:45 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Vault by HashiCorp Vault secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets critical in modern computing.

Vault - secrets manager πŸš€ Release v1.15.6
πŸ”’ Ensure secure client certificate validation by comparing public keys with trusted non-CA and leaf certificates, preventing trust in certs with the same serial but different keys or use of alternate certs with forged serial numbers.
#infosec #devsecops

29.02.2024 23:24 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
KICS - Keeping Infrastructure as Code Secure KICS is an open source solution for static code analysis of Infrastructure as Code.

Kicks - IaC vuln scanner πŸš€ v1.7.13 Release Highlights:
πŸ”„ Parallel scanning
βž• Terraform nifcloud queries
πŸ” Tencentcloud: cbs disk without encryption
πŸ” Various queries for CloudFormation, Docker, crossplane, pulumi, and more!
#iac #devsecops #infosec #cybersecurity

29.02.2024 23:15 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Open Policy Agent Policy-based control for cloud native environments

OPA - Open Policy Agent πŸš€ v0.62.0 Release:
πŸ”„ Environment variable backups for cmd flags
βž• Added WithBundleParserOpts to OCI downloader
πŸ” Logging optimization
πŸ”„ Allow bundles to contain calls to unknown Rego functions
πŸ›  Improved input validation in topdown/http
#infosec #cybersecurity

29.02.2024 22:29 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Kali Linux 2024.1 Release (Micro Mirror) | Kali Linux Blog Hello 2024! Today we are unveiling Kali Linux 2024.1. As this is our the first release of the year, it does include new visual elements! Along with this we also have some exciting new mirrors to talk ...

πŸ” Kali Linux 2024.1 Release is here: ✨ Kali project got more mirrors, Theme refresh, NetHunter Updates, and introducing new tools: blue-hydra, OpenTAXII, readpe, Snort, and Above!
#pentesting #infosec #cybersecurity

29.02.2024 02:01 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - gravitl/netmaker: Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks. Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks. - gravitl/netmaker

netmaker - wireguard based networks πŸš€ v0.23.0 update: ✨ Revamped Internet Gateways: Improved connectivity for hosts and clients! 🌐 Access internet gateways via Remote Access tab. πŸ’» PostUp/PostDown commands, EMQX cloud support, Metadata for Remote Access Gateways.
#selfhosted #netsec #vpn #zerotrust

28.02.2024 22:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - tenable/terrascan: Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure. Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure. - tenable/terrascan

πŸš€ Terrascan 1.18.12 is here! πŸ” Update includes:
✨ Fixed display line numbers in CloudFormation templates scan results.
Terrascan enhances IaC compliance and security.
#devsecops #terraform #cicd #infosec

27.02.2024 22:51 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - chris2511/xca: X Certificate and Key management X Certificate and Key management. Contribute to chris2511/xca development by creating an account on GitHub.

xca - CA certificate and key management
πŸš€ 2.6.0 Release Highlights:
🌐 Support for ovpn files
πŸ›  Fixes PKCS12 imports
πŸ” Support for legacy keys
#cryptography #certificates #infosec #cybersecurity

27.02.2024 00:48 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

HollowsHunter - scan Windows processes for malicious implants v0.3.9 release update
πŸš€ Added /pattern flag to allow search for custom signatures using SigFinder format
github.com/hasherezade/...
#malware #infosec #cybersecurity

25.02.2024 18:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - globaldatanet/aws-firewall-factory: Easily improve the security of your web applications with aws firewall factory. Protect your valuable assets with seamless WAF deployment, updates, and sta... Easily improve the security of your web applications with aws firewall factory. Protect your valuable assets with seamless WAF deployment, updates, and staging, all efficiently managed centrally wi...

aws-firewall-factory - Web AWS firewall factory 4.2.3 Release
- Check for Managed Rule Groups Labels and Rules
- Athena WAF log table support for easy analysis
- Fixes for customizable log group creation
#netsec #infosec #cybersecruity

23.02.2024 17:18 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - nitefood/asn: ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web tr... ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web traceroute server - ni...

asn - Network recon tool
πŸš€ v.0.76.0 release AS target lookup improvements:
⚑ Accelerate pWhois for AS OrgIDs & INETNUMs
πŸ” Faster INETNUM origin lookup via Team Cymru WHOIS
πŸš₯ Highlight unannounced INETNUMs
πŸ”„ Switched to RIPEStat API
#osint #shodan #infosec #cybersecurity

22.02.2024 13:44 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Truffle Security Co. Truffle Security is an open-source security software company that secures sensitive data by detecting and remediating leaked keys and credentials.

Trufflehog - credentials scanner v.3.68.0 release update
- Added canary detection without detonation
#securitytools #infosec #cybersecruity
trufflesecurity.com

21.02.2024 18:46 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Welcome | authentik Bring all of your authentication into a unified platform.

Authentik - Identity Provider focused on flexibility and versatility release 2024.2.0
- fix for webauthn retry
- fixed rbac in permission_required decorator
#securitytools #idp #sso #infosec #cybersecurity

21.02.2024 18:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
The Artemis security scanner Artemis is an open-source security vulnerability scanner developed by CERT PL. It is built to look for website misconfigurations and vulnerabilities on a large number of sites. It automatically prepar...

Artemis - security vulnerability scanner developed by CERT PL v2.6.0 release
- Finding selected Nuclei vulnerabilities
- WordPress plugin version check
- Added Known Exploited Vulnerabilities KEV source
#securitytools #infosec #cybersecurity

21.02.2024 18:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - projectdiscovery/cloudlist: Cloudlist is a tool for listing Assets from multiple Cloud Providers. Cloudlist is a tool for listing Assets from multiple Cloud Providers. - projectdiscovery/cloudlist

Cloudlist - listing assets from multi cloud v1.0.7 release update
- added integration with Kubernetes via config block. Specify connection details via file path or encoded kubeconfig. Priority to kubeconfig_encoded if both are provided.
#devops #k8s #infosec #cybersecurity

21.02.2024 13:32 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Release Prowler 3.14.0 - Paschendale Β· prowler-cloud/prowler Home, far away From the war, a chance to live again Home, far away But the war, no chance to live again Iron Maiden's Paschendale. Prowler 3.14 is here! Like the PI number, this version will drive ...

Prowler - Open Source CSPM v3.14.0 release update
- 25 new Azure checks
prowler.com
#securitytools #cspm #infosec #cybersecurity

21.02.2024 00:11 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Copacetic - Quickly patch containers for security without full rebuilds. Copa addresses operational gaps, enabling non-publishers like DevSecOps to patch images.
project-copacetic.github.io/copacetic/we...
#securitytools #vulnerabilities #infosec #cybersecurity

20.02.2024 22:15 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Security Onion 2.4.50 now available including some new features and lots of bug fixes! Security Onion 2.4.50 is now available! It includes some new features for our fellow defenders and lots of bug fixes! https://docs.securityo...

Security Onion - Threat hunting and security monitoring platform 2.4.50 release
- IKE pipeline
- DoD Stig compliance
- Integrations for Citrix, Nginx Winlog, RITA Logs
- Improved co-relations in SOC
#securitytools #ids #infosec #cybersecurity
blog.securityonion.net/2024/02/secu...

20.02.2024 20:05 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
garak: LLM vulnerability scanner garak is an open-source LLM vulnerability scanner, with dozens of plugins and thousands of prompts that test large language model security.

garak - LLM vulnerability scanner v0.9.0.12 release update
- added --buffs parameter
- plugins OpenAI, Low Res Lang, Rasa generator, Tree of Attacks
#securitytools #llm #ai #infosec #cybersecurity

20.02.2024 19:36 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

GOAD - Game of Active Directory
- GOAD 5vms 2 forests 3 domains
- GOAD-Light 3 vms 1 forest 2 domains
- NHA 5vms 2 domains
- Provision witth Virtualbox VmWare Proxmox Azure
#homelab #pentesting #infosec #cybersecurity
github.com/Orange-Cyber...

19.02.2024 13:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - iann0036/iamlive: Generate an IAM policy from AWS, Azure, or Google Cloud (GCP) calls using client-side monitoring (CSM) or embedded proxy Generate an IAM policy from AWS, Azure, or Google Cloud (GCP) calls using client-side monitoring (CSM) or embedded proxy - iann0036/iamlive

imalive - generate IAM policy from client monitoring v1.1.7 release
- updated policy maps
- added host flag
#securitytools #cloudsecurity #infosec #cybersecurity

18.02.2024 02:13 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub - chainloop-dev/chainloop: Chainloop is an open source software supply chain control plane, a single source of truth for artifacts plus a declarative attestation crafting process. Chainloop is an open source software supply chain control plane, a single source of truth for artifacts plus a declarative attestation crafting process. - chainloop-dev/chainloop

Chainloop - supply chain control plane v0.65.0 release update
- added secret types to prevent secret leaks in logs
- OCI credentials support
- dagger pipelines
#securitytools #sbom #infosec #cybersecurity

17.02.2024 02:39 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Release Teleport 15.0.2 Β· gravitational/teleport Description Fixed a potential panic in the tsh status command. #38305 Fixed SSO user locking in the setup access step of the RDS auto discover flow in the web UI. #38283 Optionally permit the auth...

Teleport - access infrastructure 15.0.2 Release Update
- Prevented access token leakage by removing them from URL parameters
- Enabled hardware key serial number validation option
#securitytools #infosec #cybersecurity

17.02.2024 02:32 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@seczen is following 3 prominent accounts