Papéis em Cibersegurança: um resumo e um fluxograma

(Post exclusivamente em PT-BR). Introdução Nos últimos meses, tenho feito a mesma apresentação para alguns públicos diferentes: quais os diferentes papéis dentro de cibersegurança, o que eles fazem, como interagem, e como compõem uma equipe de cyber. Para quem é de fora, serve para entender o que diabos acontece dentro de uma equipe de ciber,…

GCP: A script to list existing API Keys in your organization with Gemini access

Truffle Security recently reported that, depending on certain GCP configurations, existing public keys can now be used to access the Gemini API, potentially allowing access to sensitive data or allowing financial DOS attacks: https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules This issue happens when:1 – A GCP Project has at least one existing key that is published somewhere (E.g., firebase or…

The WAF Swiss-Knife

This blogpost showcases some not-so-commonly-advertised benefits and features that modern WAFs have, and how they can be used in an average company to gain benefits ranging from technical to political. It also provides some tips and tricks that I would have liked to know a few years ago. This was originally presented as a talk…