Ben From KC

76 Followers
188 Following
622 Posts
"Vell, Ben's just zis guy, you know?" | He/Him | I like the outdoors (hiking/paddling/Jeeping), hacking (SecKC!), D&D, gaming, reading, and most things I try more than once. EFF Member.

Tired:
Software Bill Of Materials

Wired:
Build Dependencies for Software Management

New tool drop for all the @limacharlieio users out there!

You can now run this exporter and monitor your LimaCharlie orgs all together in your Prometheus tool of choice. Squiggle physics enabled!

PRs are encouraged, and I'm happy to answer any questions you have.

Be good.
https://github.com/ReconInfoSec/prometheus_lcexporter

GitHub - ReconInfoSec/prometheus_lcexporter: A Prometheus exporter for LimaCharlie

A Prometheus exporter for LimaCharlie. Contribute to ReconInfoSec/prometheus_lcexporter development by creating an account on GitHub.

GitHub
Have any of my secops peeps also noticed a huge increase in Windows Event Log volume since patch Tuesday?

🎼
Now I've heard there was a secret path
The hacker typed and it pleased the app
But you don't really sanitize it, do ya?
It goes like this, dot dot, then slash
Then up a dir, no not to /trash
The filesystem "just doing what I told ya"

../. ./.. /../ ../ ../ ../

#directorytraversalmemes

Cybersecurity professionals 🤜🏻🤛🏾 Tech journalists

Spontaneously being unemployed en masse by billionaires, landing in the resistance, and yelling about the fascists

I'm hiring an Information Security Generalist at 4DMedical. Ref: https://4dmedical.bamboohr.com/careers/115
"Generalist" means we're a small #infosec team so everyone on the team wears lots of hats.
4DMedical is headquartered in Australia, but this is a U.S. remote position. U.S. citizenship is required.
4D is small, about 145 people. We're doing great work that helps real people every day, and 4D truly cares about its staff.
 Please boost. Help people in the fedi get hired!
#GetFediHired #jobPosting
Information Security Generalist

United States (Remote)  We’re looking for an experienced, hands-on information security practitioner to help maintain and improve our information security program.  On 4DMedical’s information security team, one day you’ll write code to automate evidence collection, the next you’ll advise our research tea

4DMedical

Security vendors: Defenders only have to make one mistake and it's game over.

Same security vendors: Please buy our agentic AI security products.

Yo, I just got accused of both using LLMs to write content and shilling for the (current) US military industrial complex, and I have not seen a human being be more confidently incorrect on the internet since somebody mansplained Ian's own research to them.
I keep seeing reminders of this.
We did it, and everything else required.
Our big mistake was turning them back on the next day.