How attackers use exposed Prometheus server to exploit Kubernetes clusters

You might think that your metrics are harmless from a security point of view. Well, that’s not true, and in this talk at KubeCon Valencia 2022, we share the risk of exposed Prometheus server and how attackers use this information to successfully access a Kubernetes cluster. The slides are available here, and we also collected some mentions in social media and blogs and the feedback was very positive: It was our first time as speakers at KubeCon and expectations were really high.

How to build a secure WebSocket server in Python

Typically, when a web app needs something from an external server, the client sends a request to that server, the server responds, and the connection is subsequently closed. Consider a web app that shows stock prices. The client must repeatedly request updated prices from the server to provide the latest prices.

Vector Capital Acquires Majority Ownership of WatchGuard Technologies

Today, WatchGuard announced that Vector Capital, a leading private equity firm specializing in transformational investments in established technology businesses, closed the deal to acquire interests previously owned by other co-investors, and become the company’s majority shareholder.

Vector Capital Acquires Majority Ownership of WatchGuard Technologies

Sandy Gill, Managing Director at Vector Capital, a leading private equity firm specializing in transformational investments in established technology businesses, talks about Vector acquiring majority ownership of WatchGuard Technologies, and why the company is uniquely positioned to take advantage of two major market forces – the rise of the MSP as the dominant and fastest growing source of cybersecurity, and the maturation of platform-based security offerings.

Cyber Security Professionals Shortage, Burnout & How To Protect Against It | Razorwire Podcast

Welcome to another episode of Razorwire Podcast! In this episode, our guests are Oliver Rochford of Techcron, who you've met in earlier episodes, and Stefania Chaplain, a solutions architect, discussing the skills shortage, burnout in cyber careers, and remote working. Cybersecurity offers both rewards and challenges simultaneously. Security providers in their early careers struggle to find work, while recruiters struggle to find the proper role and qualification for their security needs as cybersecurity is a multifaceted field.

The True Cost of a Security Breach

There have been many articles about the cost of a security breach. With the emergence of privacy regulations that assign penalties based on a business’ profit, or those that calculate a value for each compromised record, it is possible to calculate the cost of a breach based on those metrics. However, it would seem that these hard numbers are not detailed enough to placate many security professionals.

The Evolution Of Cyber Security & Trends To Watch For | Razorwire Podcast

Welcome to another episode of Razorwire Podcast! There is no doubt that the world has gone through massive changes over the past few years. We have faced pandemics, lockdowns, wars, supply chain issues and economic crises. As the whole world moves online, large scale innovations have been boosted. To infosec enthusiasts, this raises an interesting question: what is in store for the industry?

Where a CISO Should Sit Within an Organisation - Razorwire Podcast

Welcome to Razor Wire Podcast! In this episode, we’re joined by Claire Davies of Arriva and Keith Christie-Smith of Claroty to discuss where a CISO fits best within an organisation, a bit of the history behind it, where trends have been in recent years, and where we think it’ll going to be in future. The role of CISO has traditionally been a part of IT and they often report to the CIO. This trend has been steadily changing over recent years, but the question remains: where should the CISO sit within an organisation? With security events increasing in cost and complexity, is it time that the CISO should sit on the board? Claire, Keith and cyber security consultancy MD James Rees - your host - share their opinions on the subject from the perspective of a CISO currently in the role and with insights from an Accounts Director who deals with CISOs from multiple companies across a wide range of different sectors. The format of our show is a group of us sitting here talking like we are down the pub talking about what we do for a living. So I am inviting you to join us in this episode to learn about CISO. Listen to this episode on your favourite podcasting platform.