Marc Wickenden (@marcwickenden) 's Twitter Profile
Marc Wickenden

@marcwickenden

Cloud AppSec Bloke. Kubernetes, Go, Python, cycling, YAML engineering. Builder and breaker @4ARMED. It was like that when I found it.

ID: 254259832

linkhttps://www.4armed.com calendar_today18-02-2011 23:18:12

9,9K Tweet

1,1K Takipçi

1,1K Takip Edilen

Rory McCune (@raesene) 's Twitter Profile Photo

Carrying out with our #Kubernetes #Security fundamentals video series, this time we're starting to look at the security of Kubernetes APIs youtu.be/cB7RCAAS4ik?si…

Alexander Leslie (@aejleslie) 's Twitter Profile Photo

🚨 👀 - New Recorded Future report! This report examines a recent 🇷🇺 🇧🇾 TAG-70 (Winter Vivern) espionage campaign that exploited cross-site scripting (XSS) vulnerabilities in Roundcube webmail servers used by European government and military organizations. recordedfuture.com/russia-aligned…

Marc Wickenden (@marcwickenden) 's Twitter Profile Photo

Burn! I haven’t checked any of this but I respect Craig so I suspect he has a very valid point. Always been an Istio guy personally but Linkerd is used by more of our clients. On ramp is easier but maybe what lurks beyond is not so great.

Kris McConkey (@smoothimpact) 's Twitter Profile Photo

In September 2022, attendees at the inaugural LABScon heard about an actor I described then as "one of the most prolific, most deeply connected, and most technically advanced actors around". Events this week were a reminder that the video never went out, so here it is 👇

The Shadowserver Foundation (@shadowserver) 's Twitter Profile Photo

If running JetBrains TeamCity on-prem - make sure to patch for latest CVE-2024-27198 (remote auth bypass) & CVE-2024-27199 vulns NOW! We started seeing exploitation activity for CVE-2024-27198 around Mar 4th 22:00 UTC. 16 IPs seen scanning so far. blog.jetbrains.com/teamcity/2024/…

Marc Wickenden (@marcwickenden) 's Twitter Profile Photo

JetBrains’ version of events. Who is right here? JB are trying to do the right thing. Rapid7’s policy is valid re skilled attackers but it’s certain that publishing details arms the skiddies. Can Rapid7 hold vendors hostage? Is it just a self-serving marketing thing?

Marc Wickenden (@marcwickenden) 's Twitter Profile Photo

Toggle user privacy: Backend: Add protobuf spec, compile, add handler, add GraphQL mutation spec, compile, define handler. 5 minutes. Frontend: Add toggle switch that uses mutation on change. 1 hour and counting…. I hate doing front end. 😂