(Post exclusivamente em PT-BR). Introdução Nos últimos meses, tenho feito a mesma apresentação para alguns públicos diferentes: quais os diferentes papéis dentro de cibersegurança, o que eles fazem, como interagem, e como compõem uma equipe de cyber. Para quem é de fora, serve para entender o que diabos acontece dentro de uma equipe de ciber,…
Category: Uncategorized
GCP: A script to list existing API Keys in your organization with Gemini access
Truffle Security recently reported that, depending on certain GCP configurations, existing public keys can now be used to access the Gemini API, potentially allowing access to sensitive data or allowing financial DOS attacks: https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules This issue happens when:1 – A GCP Project has at least one existing key that is published somewhere (E.g., firebase or…
The WAF Swiss-Knife
This blogpost showcases some not-so-commonly-advertised benefits and features that modern WAFs have, and how they can be used in an average company to gain benefits ranging from technical to political. It also provides some tips and tricks that I would have liked to know a few years ago. This was originally presented as a talk…
Google Workspace / GSuite with GAM – Extract all Drive files shared externally
This is a useful command for extracting all files shared with at least one external user in Google Drive. I recommend running this command regularly to keep an eye on data exfiltration and improper sharing outside the company. Views: 324
Eu
Views: 139