π™Žπ™šπ™˜π™π™žπ™œπ™π™©π˜Ύπ™‘π™ͺ𝙗 (@secfightclub) 's Twitter Profile
π™Žπ™šπ™˜π™π™žπ™œπ™π™©π˜Ύπ™‘π™ͺ𝙗

@secfightclub

if we are godz unwanted children... SO be it...
We will become Digital GODZ

ID: 1367881152548151296

calendar_today05-03-2021 16:54:41

4,4K Tweet

283 TakipΓ§i

212 Takip Edilen

Gary McGraw (@cigitalgem) 's Twitter Profile Photo

The Log4j defect is a FLAW (not a bug) that is now deeply impacting everyone. ARA. IriusRisk "Lack of strict separation between data and control instructions, and as a result processing control instructions received from an untrusted source." bit.ly/ieee-CSD-gem

Chris Wysopal (@weldpond) 's Twitter Profile Photo

The patched version of log4j 2.15.0 requires a minimum of Java 8. If you are on Java 7 you will need to upgrade to Java8 When there is active exploitation and you need to patch fast it is beneficial if you have been updating your other dependencies over time.

Jake Williams (@malwarejake) 's Twitter Profile Photo

Nothing says "brace for impact" on a vulnerability like coin miners being deployed. This is bottom feeder activity, consider it like a low water mark.

John Hammond (@_johnhammond) 's Twitter Profile Photo

I've prepared a TryHackMe room to demonstrate #log4j #log4shell CVE-2021-44228, explaining the vulnerability, attack vector, and more importantly, detection, mitigations and patching. Working with THM staff to get this in your hands -- it should be available soon.

I've prepared a <a href="/RealTryHackMe/">TryHackMe</a> room to demonstrate #log4j #log4shell CVE-2021-44228, explaining the vulnerability, attack vector, and more importantly, detection, mitigations and patching. Working with THM staff to get this in your hands -- it should be available soon.
Gary McGraw (@cigitalgem) 's Twitter Profile Photo

We just made 24 new @kiva micro-loans for the new year using paybacks from earlier loans. Please join us! KIVA is awesome. bit.ly/cigitalgem-kiva

We just made 24 new @kiva micro-loans for the new year using paybacks from earlier loans.  Please join us!  KIVA is awesome. bit.ly/cigitalgem-kiva
R M βš‘πŸ‡ΊπŸ‡¦ (@kingthorin_rm) 's Twitter Profile Photo

I came across this bit my Simon Bennetts βš‘πŸ‡ΊπŸ‡¦ in my bookmarks so I thought I'd send people after it again because it's a good read. #juiceshop #zaproxy #owasp #mozilla hacks.mozilla.org/2018/03/hands-…

Jake Williams (@malwarejake) 's Twitter Profile Photo

Repeat after me: most individuals do not need a VPN to "protect against eavesdropping from your ISP" or to "maximize your privacy." Using a consumer grade VPN may result in less privacy. ISPs/LE/etc know VPN exit nodes and they're likely under near perpetual surveillance.

π™Žπ™šπ™˜π™π™žπ™œπ™π™©π˜Ύπ™‘π™ͺ𝙗 (@secfightclub) 's Twitter Profile Photo

If I hit 1,000 follower I will take this to the next level, some actions are restricted on Twitter : ) Who is in for Security Fight Club? Some of the best security hands on skills, I will line up some strong killerz : )