Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Creating a Culture of Security

Just as DevOps is more than just CI/CD tooling, DevSecOps is more than simply scanning code for vulnerabilities in your deployment pipeline. Creating a culture where every engineer is invested in reducing risk and values security can be challenging. In this panel session, we’ll chat with engineering leaders from security, development, and operations to learn how they’re fostering a culture of security in their organizations.

The 443 Podcast - Episode 255 - Def Con 2023 Recap

On this week's episode, we chat about some of our favorite talks from this year's Def Con security conference. We'll cover several topics including artificial intelligence, hacking mobile point of sale devices, and how worried we should or shouldn't be about cyber warfare. You can view more information on the CISA guidance as well as Blaze Lab's full blog post at the links below: The 443 Security Simplified is a weekly podcast that gets inside the minds of leading white-hat hackers and security researchers, covering the latest cybersecurity headlines and trends.

How we found a Prototype Pollution in protobuf.js

Our colleagues Peter Samarin, Norbert Schneider and Fabian Meumertzheim recently built a new bug detector enabling our JavaScript fuzzing engine Jazzer.js to identify Prototype Pollution. This work is now bearing its first fruits: As part of our ongoing collaboration with Google’s OSS-Fuzz, Jazzer.js recently uncovered a new Prototype Pollution vulnerability in protobuf.js (CVE-2023-36665). This finding puts affected applications at risk of remote code execution and denial of service attacks.

Detect Code Leaks On Public GitHub With GitGuardian Honeytoken

When your private code becomes publicly visible, you want to know about it immediately. GitGuardian Honeytoken is a quick and easy way to add leakage detection to your repositories. Get a detailed email informing you that your honeytoken has been publicly exposed. GitGuardian Honeytoken gives you the timestamp, IP address, and user agent of who triggered it, as well as what action they were trying to take.

The 443 Podcast - Episode 254 - BlackHat 2023 Recap

In this special end-of-week episode of The 443, we cover some of our favorite talks from this year's edition of the BlackHat cybersecurity conference in Las Vegas. We'll discuss the trends we saw and summaries of interesting topics including AI, nation state warfare, and improving cyber defense. You can view more information on the CISA guidance as well as Blaze Lab's full blog post at the links below.

Data Loss Prevention with Cato Networks [Demo]

Learn how quick and easy it is to secure your sensitive information with DLP from Cato Networks! In this video Robin will show you how to configure, and test, DLP Policies in less time than it would take you to drink a coffee. DLP enables organizations to define a set of rules which govern the movement of data to and from their applications. This is achieved by identifying sensitive information which matches defined data types and taking the appropriate action. DLP also identifies the file type of an asset being requested and can prevent its download of so defined.

Overcoming Fear in Cybersecurity: Building Confidence in the Industry

Embarking on a journey in the cybersecurity industry can be daunting, as the fear of making a mistake or tarnishing one's credibility looms large. In this candid discussion, join us as we hear from a seasoned professional who shares their personal experience of battling hesitations and reluctance in the early years of their career. With six to seven years of industry wisdom under their belt, they shed light on how time and experience have led to increased security in their decisions. The struggle to balance credibility and growth is real, especially in the initial phases. Tune in to discover valuable insights on nurturing a sense of security, and find out how providing coaching and support to team members who might be grappling with similar fears can lead to remarkable transformations. If you're a part of the cybersecurity landscape, this is a must-watch for gaining confidence and helping others thrive.