
Aseem Shrey
@aseemshrey
๐ค Founder - SecureMyOrg
๐จโTeaching people get into Security
๐น youtube.com/c/HackingSImplโฆ
Talk about #cybersec #privacy
ID: 880863186936750082
https://securemyorg.com 30-06-2017 18:58:44
982 Tweet
8,8K Followers
2,2K Following

๐๐๐๐ถ๐น๐ฑ๐ถ๐ป๐ด ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฎ๐ ๐ฆ๐๐ฎ๐ฟ๐๐๐ฝ๐ โ Part 4: Container Vulnerabilities ๐ ๐ฃ๐ฟ๐ผ๐ฏ๐น๐ฒ๐บ: Base images with known CVEs slip into prod containers. โข Fast builds โ skipping scans โข No image registry policy โ any image is OK โข Manual patch cycles โ


๐๐๐๐ถ๐น๐ฑ๐ถ๐ป๐ด ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฎ๐ ๐ฆ๐๐ฎ๐ฟ๐๐๐ฝ๐ โ Part 5: Real-Time Detection ๐ ๐ฃ๐ฟ๐ผ๐ฏ๐น๐ฒ๐บ: You donโt know what you canโt seeโuntil a breach alert arrives. โข No runtime monitoring โ lateral movement missed โข Alert fatigue โ critical events drown in noise โข


๐๐ผ๐ ๐ฎ ๐ง๐ฒ๐๐ ๐ฃ๐ถ๐ฝ๐ฒ๐น๐ถ๐ป๐ฒ ๐๐ผ๐บ๐ฝ๐ฟ๐ผ๐บ๐ถ๐๐ฒ๐ฑ ๐ฃ๐ฟ๐ผ๐ฑ ๐ถ๐ป ๐ฑ ๐ ๐ถ๐ป๐ ๐ฆ๐๐ผ๐ฟ๐๐๐ถ๐บ๐ฒ โ ๏ธ A developer added an unvetted npm package to the CI tests. That package contained hidden malwareโrunning under the ๐๐๐๐๐๐๐ service account. Since the same CI role had















