lepoulsdumonde.com is one of the many independent Mastodon servers you can use to participate in the fediverse.
Small french Mastodon instance for friends, family and useful bots

Administered by:

Server stats:

52
active users

#pentesting

7 posts7 participants0 posts today
0x40k<p>Whoa, looks like BlackLock got hacked. Seriously, it just hammers home how vital good security practices are – even if you're on the *other* side of the fence! Major OPSEC blunder right there, wouldn't you say? 😉</p><p>And hey, this really drives home another point: relying *only* on automated scans? That's just not cutting it for real-deal pentesting, people. You absolutely have to get hands-on and dig in manually. There's no substitute for it.</p><p>Honestly, that’s the kind of thorough work our clients appreciate – when we actually probe deeper than just the surface findings. It makes a difference.</p><p>So, what’s your take? Seems like OPSEC gets overlooked way too often, doesn't it? Curious to hear your thoughts!</p><p><a href="https://infosec.exchange/tags/Ransomware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Ransomware</span></a> <a href="https://infosec.exchange/tags/Pentesting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Pentesting</span></a> <a href="https://infosec.exchange/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://infosec.exchange/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://infosec.exchange/tags/OPSEC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OPSEC</span></a></p>
0x40k<p>Man, npm and supply chain security... seriously a never-ending story. 🙄 Just caught an article about "ethers-provider2" and "ethers-providerz". Get this: these things are actually infecting packages you *already* have installed! 🤯</p><p>Speaking as a pentester, let me tell ya: you absolutely *have* to run regular checks. Your `package-lock.json`, `yarn.lock`... check 'em all! Trust me, SCA tools are worth their weight in gold in these situations. And listen up, people, MFA for your npm account? That's not some optional extra, it's a straight-up *MUST*!</p><p>I literally just had a client who thought, "Ah, npm's pretty safe, right?". Yeah, famous last words! 🤦‍♂️</p><p>So, what're your most insane supply chain attack stories? Lay 'em on me!</p><p><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/pentesting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pentesting</span></a> <a href="https://infosec.exchange/tags/supplychain" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>supplychain</span></a> <a href="https://infosec.exchange/tags/npmsecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>npmsecurity</span></a></p>
Roy 😷<p>Kitty and myself will be presenting “two workshops (<a href="https://infosec.exchange/tags/resumereviews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>resumereviews</span></a> &amp; <a href="https://infosec.exchange/tags/mockinterviews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mockinterviews</span></a> ) at <span class="h-card" translate="no"><a href="https://infosec.exchange/@owaspboston" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>owaspboston</span></a></span> ‘s annual Boston Application Security Conference (BASC) on Saturday (04/05) <a href="https://infosec.exchange/tags/resume" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>resume</span></a> <a href="https://infosec.exchange/tags/interviews" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>interviews</span></a> <a href="https://infosec.exchange/tags/basc" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>basc</span></a> <a href="https://infosec.exchange/tags/basconf" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>basconf</span></a> Sign-ups for all workshops will be available the day of the conference. More information at: <a href="https://basconf.org" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">basconf.org</span><span class="invisible"></span></a> <a href="https://infosec.exchange/tags/appsec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>appsec</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/students" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>students</span></a> <a href="https://infosec.exchange/tags/professionals" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>professionals</span></a> <a href="https://infosec.exchange/tags/pentesting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pentesting</span></a> <a href="https://infosec.exchange/tags/career" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>career</span></a> <a href="https://infosec.exchange/tags/careertransition" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>careertransition</span></a> CC <span class="h-card" translate="no"><a href="https://infosec.exchange/@owasp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>owasp</span></a></span> </p><p>-&gt; Limited tickets available, be fast - they will sell out at: <a href="https://www.eventbrite.com/e/owasp-basc-2025-tickets-1277927157529" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">eventbrite.com/e/owasp-basc-20</span><span class="invisible">25-tickets-1277927157529</span></a></p><p>BASC 2025 Schedule - <a href="https://basconf.org/schedule/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">basconf.org/schedule/</span><span class="invisible"></span></a></p><p>Note: 🚨This yearly conference is always “free” for all <a href="https://infosec.exchange/tags/students" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>students</span></a> with valid ID in which the fees get refunded back! <a href="https://infosec.exchange/tags/freeforstudents" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>freeforstudents</span></a> so please make them aware! All $ goes back to conference and upcoming <span class="h-card" translate="no"><a href="https://infosec.exchange/@owaspboston" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>owaspboston</span></a></span> meetings. ‼️<a href="https://infosec.exchange/tags/edu" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>edu</span></a> <a href="https://infosec.exchange/tags/colleges" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>colleges</span></a> <a href="https://infosec.exchange/tags/universities" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>universities</span></a> <a href="https://infosec.exchange/tags/massachusetts" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>massachusetts</span></a> <a href="https://infosec.exchange/tags/burlington" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>burlington</span></a> <a href="https://infosec.exchange/tags/education" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>education</span></a></p><p>This annual conference includes breakfast, lunch, happy hour, <a href="https://infosec.exchange/tags/CTF" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CTF</span></a> , prizes, training, <a href="https://infosec.exchange/tags/presentations" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>presentations</span></a> <a href="https://infosec.exchange/tags/freeparking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>freeparking</span></a> , <a href="https://infosec.exchange/tags/workshops" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>workshops</span></a>, <a href="https://infosec.exchange/tags/vendors" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vendors</span></a> , <a href="https://infosec.exchange/tags/networking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>networking</span></a> <a href="https://infosec.exchange/tags/network" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>network</span></a> and ample time to <a href="https://infosec.exchange/tags/meet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>meet</span></a> old and new people and <a href="https://infosec.exchange/tags/learn" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>learn</span></a> new things 🙏👍 <a href="https://infosec.exchange/tags/attendees" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>attendees</span></a> <a href="https://infosec.exchange/tags/volunteers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>volunteers</span></a> <a href="https://infosec.exchange/tags/sponsors" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sponsors</span></a> <a href="https://infosec.exchange/tags/relationships" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>relationships</span></a> <a href="https://infosec.exchange/tags/bsides" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bsides</span></a> <a href="https://infosec.exchange/tags/defcongroups" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>defcongroups</span></a> <a href="https://infosec.exchange/tags/isaca" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>isaca</span></a> <a href="https://infosec.exchange/tags/issa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>issa</span></a> <a href="https://infosec.exchange/tags/iapp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iapp</span></a> </p><p>We look forward to presenting, connecting with people and meeting you 👍 &amp; thank you for spreading this information to your <a href="https://infosec.exchange/tags/networks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>networks</span></a> network!</p>
0x40k<p>Whoa, 112 SaaS apps per company? Seriously?! 🤯 Most folks don't even realize what's going on...</p><p>SaaS security is a *huge* deal. I mean, who's actually patching Office 365 correctly? And are you really keeping an eye on permissions? Probably not.</p><p>We've got Shadow IT, misconfigurations, and third-party risks – the whole shebang! Every app's different. One wrong setting? It is Jackpot time for attackers!</p><p>As a pentester, I often see how much SaaS is underestimated. I had a client once tell me, "We've got a firewall!" Yeah, but that doesn't cover, well, *everything*.</p><p>Your SaaS security needs a holistic approach. AI can help, sure, but it's not a magic bullet. Data is crucial for AI, as we know! And AI likes to, shall we say, make stuff up sometimes!</p><p>So, go check your SaaS configs! Keep an eye out for Shadow IT and third-party vendors. AI tools are cool for monitoring. But, you know, keep it real! Don't forget about those penetration tests!</p><p>How are *you* securing your SaaS environment? What red flags have you spotted? Let's hear it!</p><p><a href="https://infosec.exchange/tags/SaaS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SaaS</span></a> <a href="https://infosec.exchange/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://infosec.exchange/tags/AI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AI</span></a> <a href="https://infosec.exchange/tags/Pentesting" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Pentesting</span></a> <a href="https://infosec.exchange/tags/CloudSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CloudSecurity</span></a></p>