⤷ Title: Behind Closed Doors: Safeguarding Secrets in DevSecOps Workflow
════════════════════════
𐀪 Author: Revel Aldwin
════════════════════════
ⴵ Time: Mon, 28 Apr 2025 10:05:25 GMT
════════════════════════
⌗ Tags: #devsecops #secret_management_tools #application_security #sdlc #secrets
════════════════════════
𐀪 Author: Revel Aldwin
════════════════════════
ⴵ Time: Mon, 28 Apr 2025 10:05:25 GMT
════════════════════════
⌗ Tags: #devsecops #secret_management_tools #application_security #sdlc #secrets
Medium
Behind Closed Doors: Safeguarding Secrets in DevSecOps Workflow
by Revel Aldwin (DevSecOps Consultant at ITSEC Asia)
⤷ Title: The Persistence Problem: Why Exposed Credentials Linger Like Uninvited Guests ️♂️
════════════════════════
𐀪 Author: Ismail Tasdelen
════════════════════════
ⴵ Time: Mon, 12 May 2025 15:59:39 GMT
════════════════════════
⌗ Tags: #application_security #code_security #devsecops #cybersecurity #secret_management_tools
════════════════════════
𐀪 Author: Ismail Tasdelen
════════════════════════
ⴵ Time: Mon, 12 May 2025 15:59:39 GMT
════════════════════════
⌗ Tags: #application_security #code_security #devsecops #cybersecurity #secret_management_tools
Medium
The Persistence Problem: Why Exposed Credentials Linger Like Uninvited Guests 🕵️♂️
Imagine this: you accidentally leave your house keys under the doormat, and a nosy neighbor spots them. You’re told about it, but instead…
⤷ Title: Emojis: Your Digital Smile Isn’t Always Friendly
════════════════════════
𐀪 Author: Aastha Thakker
════════════════════════
ⴵ Time: Thu, 22 May 2025 17:54:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #emerging_threats #secret_codes #emojisaredangerous #emoji
════════════════════════
𐀪 Author: Aastha Thakker
════════════════════════
ⴵ Time: Thu, 22 May 2025 17:54:50 GMT
════════════════════════
⌗ Tags: #cybersecurity #emerging_threats #secret_codes #emojisaredangerous #emoji
Medium
Emojis: Your Digital Smile Isn’t Always Friendly
We speak in emojis. Now, so do the threats.
⤷ Title: Varunastra: Securing the Depths of Docker
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Jun 2025 00:27:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Asset Extraction #Container Security #cybersecurity #DevOps #Docker #secret scanning #security #Varunastra #vulnerability scanning
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 04 Jun 2025 00:27:26 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #Asset Extraction #Container Security #cybersecurity #DevOps #Docker #secret scanning #security #Varunastra #vulnerability scanning
Penetration Testing Tools
Varunastra: Securing the Depths of Docker
Discover Varunastra, the powerful new tool for robust Docker security. Detect vulnerabilities, scan for secrets, and extract assets for enhanced protection.
⤷ Title: TryHackMe Walkthrough — Secret Recipe
════════════════════════
𐀪 Author: Nicholas Abundis
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 23:39:59 GMT
════════════════════════
⌗ Tags: #secret_recipe #tryhackme_writeup #tryhackme #tryhackme_walkthrough #soc
════════════════════════
𐀪 Author: Nicholas Abundis
════════════════════════
ⴵ Time: Mon, 09 Jun 2025 23:39:59 GMT
════════════════════════
⌗ Tags: #secret_recipe #tryhackme_writeup #tryhackme #tryhackme_walkthrough #soc
Medium
TryHackMe Walkthrough — Secret Recipe
Perform Registry Forensics to Investigate a case.
⤷ Title: BFScan: Uncover Hidden URLs, Paths, & Secrets in JAR/WAR/APK Files
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:39:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #apk #application security #BFScan #cybersecurity #HTTP Request Generation #JAR #OpenAPI #Secret Detection #security tool #URL Discovery #WAR
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 16 Jun 2025 00:39:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Assessment #apk #application security #BFScan #cybersecurity #HTTP Request Generation #JAR #OpenAPI #Secret Detection #security tool #URL Discovery #WAR
Penetration Testing Tools
BFScan: Uncover Hidden URLs, Paths, & Secrets in JAR/WAR/APK Files
BFScan is a powerful tool to extract URLs, paths, and secrets from JAR, WAR, and APK files, generating raw HTTP requests and OpenAPI specs for security analysis.
⤷ Title: A Secret Store Is NOT A Substitute For Actually Protecting Your API Keys
════════════════════════
𐀪 Author: Andrew Zuo
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 21:58:44 GMT
════════════════════════
⌗ Tags: #api_key #secret_store #api_security #secret_management_tools #cybersecurity
════════════════════════
𐀪 Author: Andrew Zuo
════════════════════════
ⴵ Time: Mon, 30 Jun 2025 21:58:44 GMT
════════════════════════
⌗ Tags: #api_key #secret_store #api_security #secret_management_tools #cybersecurity
Medium
A Secret Store Is NOT A Substitute For Actually Protecting Your API Keys
I was in Cloudflare the other day and I saw this:
⤷ Title: Leaking Secrets : Building an LLM-Powered Secret Scanner for Codebases
════════════════════════
𐀪 Author: Aishwarya Athreya
════════════════════════
ⴵ Time: Sat, 26 Jul 2025 22:44:33 GMT
════════════════════════
⌗ Tags: #secret_scanner #application_security #security_tool #llm_security
════════════════════════
𐀪 Author: Aishwarya Athreya
════════════════════════
ⴵ Time: Sat, 26 Jul 2025 22:44:33 GMT
════════════════════════
⌗ Tags: #secret_scanner #application_security #security_tool #llm_security
Medium
Leaking Secrets : Building an LLM-Powered Secret Scanner for Codebases
Scan for secrets using regex+entropy with LLM
⤷ Title: Russian State Hackers Spy on Moscow Embassies via ISP-Level AiTM Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 02:53:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #adversary_in_the_middle #AiTM #ApolloShadow #Cyberespionage #Embassies #Moscow #russia #Secret Blizzard #SORM #turla
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 Aug 2025 02:53:35 +0000
════════════════════════
⌗ Tags: #Cyber Security #adversary_in_the_middle #AiTM #ApolloShadow #Cyberespionage #Embassies #Moscow #russia #Secret Blizzard #SORM #turla
Daily CyberSecurity
Russian State Hackers Spy on Moscow Embassies via ISP-Level AiTM Attacks
Microsoft reveals Russian state actor Secret Blizzard is targeting foreign embassies in Moscow with ISP-level AiTM attacks, deploying ApolloShadow malware to spy on diplomats.
⤷ Title: Preventing and Fixing Secret Leaks in Git Repos — A CloudOps Guide
════════════════════════
𐀪 Author: CloudweldOps
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 05:29:54 GMT
════════════════════════
⌗ Tags: #devops #cybersecurity #cloud_security #secret_management_tools #gitleaks
════════════════════════
𐀪 Author: CloudweldOps
════════════════════════
ⴵ Time: Mon, 11 Aug 2025 05:29:54 GMT
════════════════════════
⌗ Tags: #devops #cybersecurity #cloud_security #secret_management_tools #gitleaks
Medium
Preventing and Fixing Secret Leaks in Git Repos — A CloudOps Guide
In the age of cloud-native development, a single leaked API key can cost thousands — or worse, lead to a breach.
From AWS access keys to…
From AWS access keys to…
⤷ Title: U.S. Airlines Caught Selling Passenger Data for Warrantless Searches
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 09:19:08 +0000
════════════════════════
⌗ Tags: #Data Leak #Airlines #Airlines Reporting Corporation #cybersecurity #Data Broker #privacy #Secret Service #Surveillance
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Sep 2025 09:19:08 +0000
════════════════════════
⌗ Tags: #Data Leak #Airlines #Airlines Reporting Corporation #cybersecurity #Data Broker #privacy #Secret Service #Surveillance
Penetration Testing Tools
U.S. Airlines Caught Selling Passenger Data for Warrantless Searches
A new report reveals a data broker owned by major U.S. airlines is selling billions of passenger records to government agencies for warrantless searches.
⤷ Title: MI6 Launches a Darknet Portal to Recruit Spies and Informants
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 02:25:56 +0000
════════════════════════
⌗ Tags: #Cyber Security #cybersecurity #Darknet #Espionage #intelligence #MI6 #Secret Intelligence Service #Silent Courier #Tor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 22 Sep 2025 02:25:56 +0000
════════════════════════
⌗ Tags: #Cyber Security #cybersecurity #Darknet #Espionage #intelligence #MI6 #Secret Intelligence Service #Silent Courier #Tor
Penetration Testing Tools
MI6 Launches a Darknet Portal to Recruit Spies and Informants
MI6 has launched Silent Courier, a darknet portal and YouTube channel that allows anyone to securely and anonymously contact British intelligence.
⤷ Title: Silent Threat: Secret Service Dismantles Network Capable of Crippling NYC’s Communications
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Sep 2025 07:53:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Espionage #National Security #Secret Service #Telecommunications
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 24 Sep 2025 07:53:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Espionage #National Security #Secret Service #Telecommunications
Penetration Testing Tools
Silent Threat: Secret Service Dismantles Network Capable of Crippling NYC's Communications
The Secret Service has dismantled a massive, covert network near the UN in NYC, capable of disrupting mobile towers and launching devastating cyberattacks.
⤷ Title: Secret Service Busts Covert Telecom Network Capable of Crippling NYC
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 00:00:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #cybersecurity #national security #Secret Service #Telecommunications
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Sep 2025 00:00:16 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime #cybersecurity #national security #Secret Service #Telecommunications
Daily CyberSecurity
Secret Service Busts Covert Telecom Network Capable of Crippling NYC
The Secret Service has dismantled a vast telecom network near the UN capable of disabling cell towers, disrupting communications, and aiding foreign threats.
⤷ Title: Web3 Crisis: Sub-$1k Hardware Attack Fully Extracts Intel SGX Attestation Key, Compromising Encrypted Blockchains
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:43:13 +0000
════════════════════════
⌗ Tags: #Vulnerability #blockchain #confidential computing #Crust #DCAP #Hardware Attack #Intel SGX #Phala #Secret #TEE Bypass #Web3
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 03 Oct 2025 03:43:13 +0000
════════════════════════
⌗ Tags: #Vulnerability #blockchain #confidential computing #Crust #DCAP #Hardware Attack #Intel SGX #Phala #Secret #TEE Bypass #Web3
Penetration Testing Tools
Web3 Crisis: Sub-$1k Hardware Attack Fully Extracts Intel SGX Attestation Key, Compromising Encrypted Blockchains
Researchers extracted the Intel SGX DCAP attestation key using a sub-$1k hardware interposer. This attack breaks the root of trust, allowing attackers to forge quotes and compromise Web3 ecosystems.
⤷ Title: Hackers abused a legitimate forensic tool “Velociraptor”, to Sneak into the Networks and build…
════════════════════════
𐀪 Author: Mohana Reddy
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 07:10:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #forensic_tool_exploit #velociraptor_tool_abuse #ransomware #secret_tunnels_hack
════════════════════════
𐀪 Author: Mohana Reddy
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 07:10:14 GMT
════════════════════════
⌗ Tags: #cybersecurity #forensic_tool_exploit #velociraptor_tool_abuse #ransomware #secret_tunnels_hack
Medium
Hackers abused a legitimate forensic tool “Velociraptor”, to Sneak into the Networks and build…
Cybersecurity is like a game where the Security Implementers try to protect computers, but the malicious actors keeps finding the new ways…
⤷ Title: Jenkins Faces Wave of Plugin Flaws, Including SAML Authentication Bypass (CVE-2025-64131)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 02:08:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_64131 #Jenkins #Plugin Vulnerability #SAML #Secret Exposure #Session Hijacking
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Oct 2025 02:08:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CI/CD #CVE_2025_64131 #Jenkins #Plugin Vulnerability #SAML #Secret Exposure #Session Hijacking
Daily CyberSecurity
Jenkins Faces Wave of Plugin Flaws, Including SAML Authentication Bypass (CVE-2025-64131)
Jenkins warned of a Critical SAML Plugin flaw (CVE-2025-64131) that allows session replay/hijacking due to a missing cache. Multiple plugins also expose API tokens in plaintext.