Maxime Verac

45 Followers
60 Following
16 Posts

Cyber security consultant, mtg player, tooting about cybersecurity, basketball, computer & board games, and funny stuff. Father of 2. Opinions are my own.

Living in France, working in Luxembourg

@adulau Thank you! And for many org, PQC issues should not even be in their threat model. But that's probably a sexy name to get some attention and budget, but indeed, should not make it into the priority list for most org...

RE: https://infosec.exchange/@hack_lu/115412828163304713

Leveraging DNS data (along with CT data) to defend against cybercrime has always interested me and this talk was really interesting. And brought some arguments for the potential usefulness of AI 😉

@adulau yes this focus on certification is a real issue of our industry in many aspects... I was also surprised when I saw a NIS2 lead implementer certification and then I realized it was a real PECB certification scheme, all of this while I) the only available Implementing Regulation focus on the digital infrastructure sector/digital service providers and ii) the directive has been transposed in approx only half of the EU countries...
@bertrand to avoid any confusion I would suggest to rename API keys as API flowers or API candies otherwise I'm afraid you will have to repeat this again and again 😅

CVS ditches useless cold meds—but not bogus homeopathic products

Bogus homeopathic products based on pseudoscience will remain on shelves.

https://arstechnica.com/health/2023/10/cvs-ditches-useless-cold-meds-but-not-bogus-homeopathic-products/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

CVS ditches common cold meds after FDA advisers say they’re useless

Bogus homeopathic products based on pseudoscience will remain on shelves.

Ars Technica

My talk about usage of #ACME in private networks has finally been delivered on stage at @hack_lu 🚀

Due to Cooper hard work, video of the is already online: https://youtu.be/odUvmS5lDm4?feature=shared

Slides are available here: https://pretalx.com/hack-lu-2023/talk/Q9JHXM/

Thanks to #hacklu team for having me 🙏 and audience for their kind attention and feedback ❤️

Hack.lu 2023: ACME: Benefits Of An Internet Security Protocol In Your Network - Christophe Brocas

YouTube
Very interesting talk from @cbrocas at @hack_lu today, I believe MS own them money for trying to make ADCS sexy again by putting ACME proxy in front of it, love the idea!
@hack_lu talks recordings are also available on PeerTube 🤩 https://peertube.opencloud.lu/c/hack_lu2023/videos?s=1
Hack.lu 2023

2023.hack.lu (and CTI summit) is the 17th edition of the infosec conference in Luxembourg. 16th-19th October 2023 in Luxembourg.

PeerTube Luxembourg

We are developing vulnerability-lookup which is a rewrite of cve-search to support and improve various requirements which came during the past years:

  • Improve the NVD NIST feeders to support the new API v2
  • Allow multiple source of vulnerability feeds to be ingested even if there is no associated CVE id
  • Support of GSD feeds (mainly where the Linux kernelvulnerabilities are described) and GitHub security vulnerabilities (more to come very soon)
  • Easily find the overlaps or differences between vulnerabilities allocated
  • A very fast API (we got rid of MongoDB and replaced it with kvrocks) to get the original vulnerability description from the different feeds

This is still pretty alpha but an initial release is coming in the next weeks.

If you want to contribute, test or have any ideas of additional feeds to add, let us know.

#opensource #threatintel #cvd #vulnerability #cve

🔗 https://github.com/cve-search/vulnerability-lookup

GitHub - cve-search/vulnerability-lookup: Vulnerability Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD).

Vulnerability Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure ...

GitHub
@ldelavaissiere haha ca fait bien longtemps que c'est fait (TOTP 😉)