Opens profile photo
Follow
Click to Follow clintgibler
Clint Gibler
@clintgibler
🗡️ Head of Security Research 📚 Creator of tldrsec.com newsletter
San Francisco, CAtldrsec.comJoined July 2012

Clint Gibler’s Tweets

Pinned Tweet
How do you get to 🧙‍♂️Staff🧙‍♂️ level in security? Hard to know, as there's not much guidance out there Where is the staffeng.com for security? went and got stories from 8 Staff+ Sec Engineers, go learn from their experiences 👇
7
93
Show this thread
Yay! Come and join us
Quote Tweet
📣 We're bringing together #security experts @dcuthbert @LewisArdern @AroraMinali and @_amanvir for a panel session in London on Feb 20! Join us and learn their best practices in building & scaling highly effective AppSec/ProdSec teams. Save your seat: bit.ly/3lf8gQ8
Scaling security programs can be challenging. From keeping up with the latest industry security threats and technologies to building a continuous scanning infrastructure, security engineering leaders have a lot on their plate when it comes to leading highly effective AppSec/ProdSec organizations.

Join @LewisArdern @AroraMinali and @_amanvir for a panel session in London on Feb 20! 

Come hear what they have to say about best practices in building & scaling highly effective AppSec/ProdSec teams.

Join our panel of experts in this webinar to learn:

- Best practices in building and scaling an efficient AppSec/ProdSec team
- Thoughts on the latest security engineering tools and processes to invest in
- Mitigating security risks in a fast-paced, rapidly-scaling environment
and more!
7
🥷 Ransacking your password reset tokens o how the "Ransack" Ruby library can be abused to exfiltrate sensitive data via char by char brute-force They compromised multiple applications this way and found 100s more that might be vulnerable
4
📦 Mitigating RBAC-Based Privilege Escalation in Popular Kubernetes Platforms walks through the different mitigations the platforms (AKS, EKS, GKE, ...) implemented to address privilege escalation and powerful permissions in #Kubernetes
4
Neat write-up by I enjoyed the nuances around bypassing the server's origin check, experimenting with how browsers treat special characters, and dealing with Same Origin Policy preflight requests
Quote Tweet
Recently I discovered a one-click RCE vulnerability in #Azure that affects Function apps, App services, and Logic apps. The vulnerability enables attackers to fully take over the targeted victim's application and managed identity token. This is the story of #EmojiDeploy ._. 🧵
Show this thread
Embedded video
GIF
1
8
☁️ Precloud An open source CLI that runs checks on infrastructure as code to catch potential deployment issues before deploying It works by comparing resources in CDK diffs and Terraform Plans against the state of your cloud account
11
🗒️ SBOM Scorecard When generating first-party SBOMs, it's hard to know if you're generating something good (e.g. rich metadata that you can query later) or not. This tool hopes to quantify what a well-generated SBOM looks like.
1
14
🐍 Using Semgrep with Jupyter Notebook files describes how using Semgrep's "extract" mode Extract mode can be used to analyze Bash in a Dockerfile, JS in HTML, etc. He also submitted a PR to make extract mode better, huzzah open source! 🙌
12
💳 Swipe right on our new credit card tokens! has released a new canary token type: credit cards They'll create a valid credit card (number, expiration, and CVC) for you, and you'll get notified if it ever gets used
2
7️⃣ Better visibility will improve with purpose-built tools (e.g. data lakes) 8️⃣ Cloud security will increase with automated reasoning 9️⃣ Security teams will get more serious about quantum-resistant cryptography For more, see the post 👇
2
Show this thread
4️⃣ Training best practices will inspire action and improve security 5️⃣ Embedded security will become more tangible with IaC 6️⃣ Orgs will increase investment and focus on business resiliency
1
Show this thread
🔮 AWS security heads offer top cybersecurity predictions for 2023 Nine predictions 🧵 1️⃣ MFA will become pervasive 2️⃣ Increasingly inclusive workforce will address talent gap 3️⃣ Collaboration across companies will improve preparedness and incident response
1
25
Show this thread