Mastodon
Gary P Shewan
  • Home
  • About Me
  • About this site
Sign in Subscribe
Security

CISA Red Team report

Gary Shewan

Gary Shewan

12 Jul 2024 1 min

This is a very good read for security teams. CISA’s Red Team report on how they breached a Federal organisation.

CISA Red Team’s Operations Against a Federal Civilian Executive Branch Organization Highlights the Necessity of Defense-in-Depth | CISA
Cybersecurity and Infrastructure Security Agency CISA

Read next

Fixed and fixed properly

This is interesting. 'Exclusive' article on Fortune today explaining how researchers discovered a zero-click attack on MS Copilot which starts with sending an email with hidden instructions (prompt injection). Microsoft have definitely fixed it though (https://fortune.com/2025/06/11/microsoft-copilot-vulnerability-ai-agents-echoleak-hacking/) BUT, because I have a memory
Gary Shewan 11 Jun 2025

Never on a Friday

I like Okta. It can get a bit pricey but it’s not bad. But if you’re going to start making it a habit of doing vulnerability notifications late on Friday evenings? I’m going to take ten mins on a Saturday to call it out. It’s a
Gary Shewan 02 Nov 2024

Sophos laying it on the table

This is a good thing to bookmark and read Sophos have released a report covering their five year research into Chinese groups attempting to hack their devices. Sophos’ Pacific Rim: Defense Against Nation-state HackersDiscover Sophos’ Pacific Rim defense against nation-state / Chinese hackers Volt Typhoon, APT31, and APT41 targeting critical infrastructure.
Gary Shewan 31 Oct 2024

Comments ()

Subscribe to Gary P Shewan

Don't miss out on the latest news. Sign up now to get access to the library of members-only articles.
  • Sign up
Gary P Shewan © 2026. Powered by Ghost