Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Darkside of GraphQL

GraphQL is a query language for APIs that provides a powerful and efficient way to query and manipulate data. As powerful and versatile as GraphQL is, its downside is that it can be vulnerable to certain security threats. In this presentation, we will discuss the security vulnerabilities associated with GraphQL, from the basics to more advanced threats, and how to best protect against them. After this presentation, attendees will have a better understanding of security vulnerabilities in GraphQL, as well as an understanding of the steps needed to protect against them.

Shells and Flipper Hells: SSH Problems and Pocket Hacking

In the first episode of 2024, Bill and Robin dive into a vulnerability impacting SSH across the world, as well as explore how something in your pocket may get you unwarranted attention. What is the Terrapin attack, and why should you leave your FlipperZero in check-in luggage? Learn all this and more on the latest episode of the Ring of Defense!

Why should developers care about container security?

Container scanning tools, industry publications, and application security experts are constantly telling us about best practices for how to build our images and run our containers. Often these non-functional requirements seem abstract and are not described well enough for those of us that don’t have an appsec background to fully understand why they are important.

Defending the Digital Seas: Dismantling Cyber Crime with Disincentives and Alternatives #podcast

In this eye-opening video, we delve into the intriguing parallels between historical piracy and the contemporary world of cybercrime. Remember when pirates sailed the seas, preying on everyone in their path without any official refuge? Fast forward to today, where cybercriminals, like modern-day pirates, target unsuspecting individuals. Join me as we explore the concept of disincentivizing cybercrime, making it harder to succeed, and more painful if caught, and promoting alternative paths.