Over Security

Over Security

Asset Management & Data Classification: You Can’t Protect What You Can’t See
Asset Management & Data Classification: You Can’t Protect What You Can’t See
Part 4 of a series on creating information security policies. Visibility before Protection Organizations often invest heavily in cybersecurity tools: endpoint protection, firewalls, SIEM platforms, MFA, cloud security solutions, and threat detection services. Unfortunately, many security incidents still come down to a surprisingly simple problem: organizations do not fully understand what they own or where their sensitive data resides. Before an organization can protect its environment, it fi
·secjuice.com·
Asset Management & Data Classification: You Can’t Protect What You Can’t See
SecjuiceCON 2026
SecjuiceCON 2026
SecjuiceCON is an online event for infosec and OSINT industry insiders, and we'd love for you to talk to our audience about your wisdom and learnings.
·secjuice.com·
SecjuiceCON 2026
AI Vendor Vetting: An OK Practice Guide
AI Vendor Vetting: An OK Practice Guide
Practical guide to AI vendor vetting, covering key data, security, compliance, and risk questions to assess and manage AI third-party risks.
·secjuice.com·
AI Vendor Vetting: An OK Practice Guide
SCANT: A (kind-of-decent) Framework for Ethical Deepfake Creation & Distribution
SCANT: A (kind-of-decent) Framework for Ethical Deepfake Creation & Distribution
Contents 1. The Ethical Blueprint: Building Trust in Synthetic Media 1. S - Social Benefit 2. C - Consent 3. A - Accountability 4. N - Non-Deception 5. T - Transparency 2. Putting SCANT into Practice 3. TL;DR Checklist 4. It takes work! 5. AI - Embracing the Human 6. Speaking of ISO 42001 The Ethical Blueprint: Building Trust in Synthetic Media Lots of damage has been done with AI, and to keep from deep-sixing the forward-leaning tone I want in this article, I’ll re
·secjuice.com·
SCANT: A (kind-of-decent) Framework for Ethical Deepfake Creation & Distribution
Security Governance & Leadership
Security Governance & Leadership
Part 1 of a series on creating information security policies Contents * Security Starts at the Top (or, Governance Makes or Breaks Your Security Program) * Disclaimer * Why Governance Comes First * The Information Security Policy: Setting the Tone * Risk Management: Replace Guesswork with Discipline * Roles and Responsibilities: Eliminating the Accountability Gap * What Auditors Look For * Common Pitfalls to Avoid * Governance as a Force Multiplier * Afterword about Infosec Policy an
·secjuice.com·
Security Governance & Leadership
CTFs aren't Designed to Train Investigators. Hashclue is.
CTFs aren't Designed to Train Investigators. Hashclue is.
Real investigations start with noise, a fragment, a pattern, something that doesn't fit. Almost nothing in the standard training stack teaches you to work that problem. Hashclue is an attempt to build something that does.
·secjuice.com·
CTFs aren't Designed to Train Investigators. Hashclue is.
People, Policies, and Purpose: Framing Acceptable Use and Human Behavior in Information Security
People, Policies, and Purpose: Framing Acceptable Use and Human Behavior in Information Security
Part 2 of a series on creating information security policies Many breaches don’t start with sophisticated hackers; they start with ordinary users doing ordinary things in unsafe ways. Let’s look at 3 ways to work toward helping people in our organizations understand better how to safeguard everyone’s information. Because there are as many ways to create a policy as there are organizations - compounded with the numerous requirements from regulations - I won’t attempt to provide a one-size-fits-
·secjuice.com·
People, Policies, and Purpose: Framing Acceptable Use and Human Behavior in Information Security
The CTF Ecosystem Is Stagnant and Has Been for Twenty Years
The CTF Ecosystem Is Stagnant and Has Been for Twenty Years
CTFs haven't changed in decades. Better puzzles, same game. The problem isn't technical difficulty, it's that nobody has ever made you commit to anything.
·secjuice.com·
The CTF Ecosystem Is Stagnant and Has Been for Twenty Years
Your OSINT Is Only as Good as Your Thinking
Your OSINT Is Only as Good as Your Thinking
You pulled the threads, mapped the connections, built the timeline. The data looks clean and the narrative holds. Then someone asks a question you didn't consider and the whole picture shifts. The failure was not in your tooling.
·secjuice.com·
Your OSINT Is Only as Good as Your Thinking
Identity Is the New Perimeter: Access, Authentication, and Control That Actually Hold Up
Identity Is the New Perimeter: Access, Authentication, and Control That Actually Hold Up
Part 3 of a series on creating information security policies. Attackers don’t break in…they log in. That’s a bit of a dramatic exaggeration, and it seems cliché, but it’s not really too far off. Consider the 2022 Uber breach. The attacker didn’t exploit a sophisticated vulnerability; they obtained a contractor’s credentials and then bombarded the user with MFA push requests until one was approved. That single moment of fatigue opened the door to internal systems and broader access. Or look a
·secjuice.com·
Identity Is the New Perimeter: Access, Authentication, and Control That Actually Hold Up
For The Dogs
For The Dogs
An introduction to the canine intelligence cell, a volunteer investigative effort focused on exposing the criminal networks exploiting dogs through trafficking, legal loopholes, fraud, violence, and organised abuse.
·secjuice.com·
For The Dogs
Malware Analysis: Is It About Tools or Mindset?
Malware Analysis: Is It About Tools or Mindset?
Malware analysis is more than tools. Learn the mindset, goals, techniques, and workflows analysts need to dissect malware effectively.
·secjuice.com·
Malware Analysis: Is It About Tools or Mindset?
Asset Management & Data Classification: You Can’t Protect What You Can’t See
Asset Management & Data Classification: You Can’t Protect What You Can’t See
Part 4 of a series on creating information security policies. Visibility before Protection Organizations often invest heavily in cybersecurity tools: endpoint protection, firewalls, SIEM platforms, MFA, cloud security solutions, and threat detection services. Unfortunately, many security incidents still come down to a surprisingly simple problem: organizations do not fully understand what they own or where their sensitive data resides. Before an organization can protect its environment, it fi
·secjuice.com·
Asset Management & Data Classification: You Can’t Protect What You Can’t See
Clean GitHub repo tricks AI coding agents into running malware
Clean GitHub repo tricks AI coding agents into running malware
An agentic coding tool tasked with running a seemingly benign GitHub repository could execute a malicious payload that is invisible to both security agents and human reviewers.
·bleepingcomputer.com·
Clean GitHub repo tricks AI coding agents into running malware
FBI: Russian hackers now target Signal backup recovery keys
FBI: Russian hackers now target Signal backup recovery keys
The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' historical messages.
·bleepingcomputer.com·
FBI: Russian hackers now target Signal backup recovery keys
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited.
·bleepingcomputer.com·
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited.
·bleepingcomputer.com·
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
Polymarket customers lose $3 million in supply-chain attack
Polymarket customers lose $3 million in supply-chain attack
Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor.
·bleepingcomputer.com·
Polymarket customers lose $3 million in supply-chain attack
Cybersecurity firms targeted by fraudulent OpenAI organization invites
Cybersecurity firms targeted by fraudulent OpenAI organization invites
Threat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects.
·bleepingcomputer.com·
Cybersecurity firms targeted by fraudulent OpenAI organization invites
Your First GRC Agent: A Red Teamer's Walkthrough
Your First GRC Agent: A Red Teamer's Walkthrough
AI won't replace GRC analysts, but it can eliminate much of the repetitive work they do. Anecdotes walks through building an agent that continuously monitors controls, identifies evidence gaps, and opens remediation tasks.
·bleepingcomputer.com·
Your First GRC Agent: A Red Teamer's Walkthrough
Se il Garante sanziona chi insegna il GDPR: il caso Lepida e il valore della privacy by design
Se il Garante sanziona chi insegna il GDPR: il caso Lepida e il valore della privacy by design
Il Garante privacy ha sanzionato Lepida S.c.p.A., uno dei principali gestori SPID, per gravi violazioni di principi cardine del GDPR, tra cui privacy by design e by default, minimizzazione, limitazione della conservazione e sicurezza del trattamento. Con un provvedimento che va oltre la sanzione. Ecco perché
·cybersecurity360.it·
Se il Garante sanziona chi insegna il GDPR: il caso Lepida e il valore della privacy by design
Primo memeversario!
Primo memeversario!
Dopo un anno, l'appuntamento del memerdì è oramai una ricorrenza consolidata per fare cultura cyber in modo un po' meno ordinario. E un pretesto per ricordare i cinque meme più apprezzati
·cybersecurity360.it·
Primo memeversario!