Dino A. Dai Zovi(@dinodaizovi) 's Twitter Profileg
Dino A. Dai Zovi

@dinodaizovi

Coffee thoughts by $ddz

ID:14279598

linkhttps://duckduckgo.com/?q=dino+dai+zovi calendar_today02-04-2008 01:10:12

57,9K Tweets

40,0K Followers

8 Following

apenwarr(@apenwarr) 's Twitter Profile Photo

Love all the angry people in the replies who demand username/password with for every app… and then have a “recover password” button that lets the email address owner bypass it all anyway. More steps, same vulnerability.

account_circle
Dino A. Dai Zovi(@dinodaizovi) 's Twitter Profile Photo

So, everyone reading about Sisense and Palo Alto Networks this week... are we all thinking about least privilege architectures yet? I know 'secure by design' is a catchy phrase, but vendors are just going to say they are SxD now because there's still no way to confirm/dispute it.

account_circle
Cybersecurity and Infrastructure Security Agency(@CISAgov) 's Twitter Profile Photo

CISA advisors Jack Cable and æva black describe in our latest blog how we are responding to the XZ Utils compromise and how every tech manufacturer should take a approach to securing open source software: go.dhs.gov/JHf

CISA advisors @jackhcable and @aevavoom describe in our latest blog how we are responding to the XZ Utils compromise and how every tech manufacturer should take a #SecureByDesign approach to securing open source software: go.dhs.gov/JHf
account_circle
Thorsten Ball(@thorstenball) 's Twitter Profile Photo

Imagine if every team had someone who says 'hmm, no, I think we can get this done today' on a regular basis.

The effect is incredible.

account_circle
Marc Rogers(@marcwrogers) 's Twitter Profile Photo

STRONG RECOMMENDATION -
If you are a CISO and you have a 3rd party (Automation, AI, Analytics) that uses Sisense or you SUSPECT uses Sisense INSIST on an impact statement NOW.
I can 100% guarantee there are a lot of you with impact.

Your data was accessed by a threat actor.

account_circle
Marc Rogers(@marcwrogers) 's Twitter Profile Photo

The nature of sisense is they require access to their customers confidential data sources. They have direct access to JDBC connections, to SSH, and to SaaS platforms like Salesforce and many more. It also means they have tokens, credentials, certificates often upscoped. 1/2

account_circle
Lorenzo Franceschi-Bicchierai(@lorenzofb) 's Twitter Profile Photo

NEW: Apple notified people in 92 countries they may have been targeted with spyware, TechCrunch learned.

“Apple detected that you are being targeted by a mercenary spyware attack that is trying to remotely compromise the iPhone' linked to your Apple ID.

techcrunch.com/2024/04/10/app…

account_circle
Dan Lorenc(@lorenc_dan) 's Twitter Profile Photo

Sick of managing GitHub PATs? Check out octo-sts!

chainguard.dev/unchained/the-…

'In short: GitHub didn’t expose an STS, so we went ahead and built one.'

account_circle
TIDAL(@TIDAL) 's Twitter Profile Photo

Eid Mubarak! TIDAL is wishing a joyous day with delicious feasts and cherished moments to all who celebrate the end of Ramadan. tidal.link/3UaEr25

account_circle