guidomarilli's profile picture. SOC Team Lead @sentinelone • Fitness enthusiast • Cinephile • My Credly: https://www.credly.com/users/guido-marilli

Guido Marilli

@guidomarilli

SOC Team Lead @sentinelone • Fitness enthusiast • Cinephile • My Credly: https://www.credly.com/users/guido-marilli

#ENISA has just released #EUVD (European Union Vulnerability Database) - enisa.europa.eu/news/consult-t… It is accessible here: euvd.enisa.europa.eu #cve #vulnerability


Guido Marilli reposted

📺 On @Bloomberg: Our CISO Alex Stamos weighs in on DeepSeek, highlighting the IP and data security risks and the complexities of AI model training and usage: “Now there are some great breakthroughs here [in both training costs and inference costs] … [B]ut there's a lot of…


Guido Marilli reposted

Zeek 7 passive open-source network traffic analyzer debuts with comprehensive updates in scripting, telemetry, & analyzer configurations. linuxiac.com/zeek-7-network…

linuxiac's tweet image. Zeek 7 passive open-source network traffic analyzer debuts with comprehensive updates in scripting, telemetry, & analyzer configurations.
linuxiac.com/zeek-7-network…

Guido Marilli reposted

Open source #AI, licenses, and data! Freedom, #security, and safety! Sound interesting? Read our latest blog, "Why trust open source #AI?" We focus on "how the IBM Granite model is open source and why an open source model is inherently more trustworthy. red.ht/45ITAM1


Guido Marilli reposted

#CISA has recently further developed the concept of #Security by Design, and at Red Hat, we are embracing it in our products and #cloud services. Learn more in the blog, "Exploring security by design and loosening guides." red.ht/4euj18e


As the scope of responsibilities of CISOs are expanding, it might by the case to split such role, but what could be the pros and cons of doing so exactly? edt.csoonline.com/c/15VStvo3Px8M…


Guido Marilli reposted

Web Security Mindmap !

pwn4arn's tweet image. Web Security Mindmap !

Guido Marilli reposted

"YARA is dead, long live YARA-X!" 🎉 After 15 years, YARA gets a full rewrite in Rust, bringing enhanced performance, security, and user experience. Dive into the details in latest blog post by @plusvic : blog.virustotal.com/2024/05/yara-i…

virustotal's tweet image. "YARA is dead, long live YARA-X!" 🎉 

After 15 years, YARA gets a full rewrite in Rust, bringing enhanced performance, security, and user experience. 

Dive into the details in latest blog post by @plusvic : blog.virustotal.com/2024/05/yara-i…

Guido Marilli reposted

I still manually review, test and add new repositories to YARA Forge + 5 additions since the release by @cod3nym @craiu @WithSecure @harfanglab new repos github.com/YARAHQ/yara-fo… custom scoring (to reduce FPs) github.com/YARAHQ/yara-fo… main page yarahq.github.io

cyb3rops's tweet image. I still manually review, test and add new repositories to YARA Forge

+ 5 additions since the release

by @cod3nym @craiu @WithSecure @harfanglab 

new repos
github.com/YARAHQ/yara-fo…

custom scoring (to reduce FPs)
github.com/YARAHQ/yara-fo…

main page
yarahq.github.io
cyb3rops's tweet image. I still manually review, test and add new repositories to YARA Forge

+ 5 additions since the release

by @cod3nym @craiu @WithSecure @harfanglab 

new repos
github.com/YARAHQ/yara-fo…

custom scoring (to reduce FPs)
github.com/YARAHQ/yara-fo…

main page
yarahq.github.io
cyb3rops's tweet image. I still manually review, test and add new repositories to YARA Forge

+ 5 additions since the release

by @cod3nym @craiu @WithSecure @harfanglab 

new repos
github.com/YARAHQ/yara-fo…

custom scoring (to reduce FPs)
github.com/YARAHQ/yara-fo…

main page
yarahq.github.io

Guido Marilli reposted

A day the open source community will never forget! Check out Red Hat's collaborative response to the XZ security incident after Andres Freund disclosed his findings: red.ht/3xZdFkz #linux #security #vulnerability response #collaboration #open source communities


Among all of the Red Hat certifications that I have obtained so far, as a Cyber Security professional this has been the most fun. #EX415 #Linux #hardening #audit #SELinux #RedHat @RedHat credly.com/badges/bfd1d86…


Guido Marilli reposted

Check out Part 2 of our latest series: "What does Red Hat Product Security do?" We support our customers with the necessary tools and guidance to implement and achieve sensitive computing requirements compliance and IT systems security. red.ht/3TRwXzC


Guido Marilli reposted

Xzbot : Notes, honeypot, and exploit demo for the xz backdoor : github.com/amlweems/xzbot Timeline of the xz open source attack : research.swtch.com/xz-timeline The xz attack shell script : research.swtch.com/xz-script

binitamshah's tweet image. Xzbot : Notes, honeypot, and exploit demo for the xz backdoor : github.com/amlweems/xzbot

Timeline of the xz open source attack : research.swtch.com/xz-timeline 

The xz attack shell script : research.swtch.com/xz-script

Guido Marilli reposted

Want to play around with the xz backdoor? We have a quick blog post detailing how to make a vulnerable Kali install and validate if your system is or is not vulnerable. kali.org/blog/xz-backdo…

kalilinux's tweet image. Want to play around with the xz backdoor? We have a quick blog post detailing how to make a vulnerable Kali install and validate if your system is or is not vulnerable. 

kali.org/blog/xz-backdo…

Interesting take. #xz #xzbackdoor

The #xz/#liblzma backdoor is the ONLY package out of 245,032 malicious packages identified in 2023 (see report below) that was assigned a CVE (CVE-2024-3094, with the corresponding CWE-506 - Embedded Malicious Code). But should a malicious package be assigned a CVE? A 🧵 [1/6]

pyotam2's tweet image. The #xz/#liblzma backdoor is the ONLY package out of 245,032 malicious packages identified in 2023 (see report below) that was assigned a CVE (CVE-2024-3094, with the corresponding CWE-506 - Embedded Malicious Code).

But should a malicious package be assigned a CVE?

A 🧵 [1/6]


Guido Marilli reposted

Samples of the liblzma / xz backdoor have already been detected on VirusTotal, thanks to @cyb3rops ' YARA rules and Kaspersky's signatures

bquintero's tweet image. Samples of the liblzma / xz backdoor have already been detected on VirusTotal, thanks to @cyb3rops ' YARA rules and Kaspersky's signatures

Guido Marilli reposted

‼ Rilevata la distribuzione di pacchetti XZ Utils contenenti codice malevolo 🔗csirt.gov.it/contenuti/rile… 👉 Azioni di mitigazione disponibili

csirt_it's tweet image. ‼ Rilevata la distribuzione di pacchetti XZ Utils contenenti codice malevolo

🔗csirt.gov.it/contenuti/rile…

👉 Azioni di mitigazione disponibili

Guido Marilli reposted

The insertion of a backdoor into code used by most Linux distributions was discovered and fixed “before it posed a significant risk to the broader Linux community,” says @RedHat’s @vdanen. @RedHatSecurity bit.ly/3TFgNcp


Loading...

Something went wrong.


Something went wrong.