C.J. May's Avatar

C.J. May

@lawndoc.cjmay.info

64
Followers
86
Following
34
Posts
10.02.2024
Joined
Posts Following

Latest posts by C.J. May @lawndoc.cjmay.info

I assume 3rd party CNAs will continue to function? This is about to get messy either way, though...

15.04.2025 18:24 👍 4 🔁 0 💬 1 📌 0
Post image

BREAKING.

From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.

15.04.2025 17:23 👍 679 🔁 414 💬 36 📌 201
Post image

Happy friggin Tuesday

08.04.2025 16:54 👍 0 🔁 0 💬 0 📌 0

My team calls it "eating your vegetables" 🥦

26.03.2025 20:47 👍 1 🔁 0 💬 1 📌 0

I'm impressed that it changed the facial expression of the woman to match the context of her text

26.03.2025 20:46 👍 2 🔁 0 💬 0 📌 0
Preview
Google acquires cybersecurity firm Wiz for $32 billion It’ll be Google’s most expensive deal to date if it goes ahead.

God forbid there be any more than three companies involved in cloud technologies. This is a win for Wiz, and a loss for its users.

www.theverge.com/goo...

18.03.2025 13:19 👍 11 🔁 4 💬 1 📌 0
Post image

My coworkers and I bring this one back up at least twice a year

21.02.2025 11:19 👍 6 🔁 0 💬 0 📌 0
Self-Hosting Infisical: A Guide to Securing Your Homelab's Secrets Learn how to self-host Infisical to secure your homelab secrets. Step-by-step tutorial covers Docker deployment, backup key protection, and just-in-time secret injection.

I see. Another thing you could look into is Infisical which is a pretty intuitive self hosted secret manager. I just wrote a blog post for them that shows how to set it up and use their CLI for just-in-time ENV injection. Which works if you're manually running commands

infisical.com/blog/self-ho...

15.02.2025 15:42 👍 2 🔁 0 💬 0 📌 0

Not sure what you're working with, but most CI platforms are able to issue short lived JWTs to jobs that securely attest what the job is so you can federate access with OIDC. Might be worth looking into if you haven't already. Or it might not be possible as you said without platform support.

15.02.2025 15:01 👍 1 🔁 0 💬 1 📌 0

Have you tried using OIDC auth to access the vault with a machine identity? IMO that's the best solution to the "recursive secrets" problem

15.02.2025 14:48 👍 0 🔁 0 💬 1 📌 0
Post image

I've been adding muted words on this account to reduce the politics on my timeline (I have another account and news for that).

What words am I missing?

07.02.2025 23:53 👍 1 🔁 0 💬 0 📌 0
Preview
Linux Detection Engineering - A Continuation on Persistence Mechanisms — Elastic Security Labs This document continues the exploration of Linux detection engineering, emphasizing advancements in monitoring persistence mechanisms. By building on past practices and insights, it provides a roadmap...

Elastic blog by Ruben Groenewoud:

www.elastic.co/security-lab...

04.02.2025 16:24 👍 0 🔁 0 💬 0 📌 0

It's so easy to use, our high school intern with zero previous Linux experience has been able to use it in our lab to document what we detect and what our gaps are.

It's been a great project for him to learn about Linux and detection engineering.

04.02.2025 16:22 👍 0 🔁 0 💬 1 📌 0
GitHub - Aegrah/PANIX: Customizable Linux Persistence Tool for Security Research and Detection Engineering. Customizable Linux Persistence Tool for Security Research and Detection Engineering. - Aegrah/PANIX

Just saw an Elastic blog about detecting PANIX techniques, and wanted to give a big s/o to the tool.

github.com/Aegrah/PANIX

04.02.2025 16:22 👍 0 🔁 0 💬 1 📌 0

bsky.app/profile/lawn...

01.02.2025 05:44 👍 1 🔁 0 💬 0 📌 0

The hardest part of writing this blog post is to not sound like I'm vomiting buzzwords like an auditor who pretends to understand how security works

01.02.2025 05:42 👍 0 🔁 0 💬 0 📌 0

There are way too many acronyms and buzzwords in the identity security space...

I'm writing an article for a client that I could literally title:
"PKI, APIs, JWTs, and SSH: The IAM challenges of Zero Trust ILM for NHIs"

01.02.2025 05:42 👍 2 🔁 0 💬 1 📌 1

Accurate 😂 and optionally buy a domain

31.01.2025 00:03 👍 1 🔁 0 💬 0 📌 0

And lots of times things get re-invented

25.01.2025 14:21 👍 1 🔁 0 💬 1 📌 0

Nothing is "old school" if it still works 🤷

25.01.2025 14:20 👍 1 🔁 0 💬 1 📌 0

Really appreciate the content and tooling you contribute to the community. Congrats on 5 years!

25.01.2025 14:15 👍 0 🔁 0 💬 0 📌 0

I worry what it will do to entry level positions, which will in turn raise the bar for someone to get a job that can't be automated with AI agents. I agree that there will always need to be qualified human oversight, but how do those people get trained?

25.01.2025 14:09 👍 1 🔁 0 💬 0 📌 0

I think the difference between authn and authz in general is commonly misunderstood

25.01.2025 14:06 👍 1 🔁 0 💬 1 📌 0

"trust, but verify" 💯

25.01.2025 14:03 👍 0 🔁 0 💬 0 📌 0

#100DaysOfKQL

Day 24 - LOLDRIVERS Malicious Driver Observed or Loaded

Featuring the awesome LOLDrivers project from @magicswordio

Anything they release is amazing and worth integrating in your detection/threat hunting rules, check them out!

github.com/SecurityAura...

25.01.2025 03:23 👍 6 🔁 1 💬 0 📌 0

If you work at an organization where tighter security ALWAYS means more profit (security vendor, consultant, cyber education, standards research), understand that this is not the case for most companies.

03.01.2025 23:26 👍 0 🔁 0 💬 0 📌 0
The Chats - Identity Theft
The Chats - Identity Theft YouTube video by The Chats

youtu.be/TOuGH9Gpeos?...

09.12.2024 05:31 👍 0 🔁 0 💬 0 📌 0
Post image

How do we feel about MS claim that Windows 11 is "Secure by default" lol
query.prod.cms.rt.microsoft.com/cms/api/am/b...

19.11.2024 16:00 👍 0 🔁 0 💬 0 📌 0

That darn #OST

13.11.2024 19:11 👍 0 🔁 0 💬 0 📌 0
Post image

Look mom I'm famous 😅

13.11.2024 19:11 👍 0 🔁 0 💬 1 📌 0