New National Cybersecurity Strategy

Last week, the Biden administration released a new National Cybersecurity Strategy (summary here). There is lots of good commentary out there. It’s basically a smart strategy, but the hard parts are always the implementation details. It’s one thing to say that we need to secure our cloud infrastructure, and another to detail what the means technically, who pays for it, and who verifies that it’s been done.

One of the provisions getting the most attention is a move to shift liability to software vendors, something I’ve been advocating for since at least 2003…

March 6, 2023
Read More >>

Hack The Box: (Forgot) – Varnish HTTP cache to retrieve any cache

What is Varnish’s HTTP cache? To be honest, it’s my debut of hearing about the Varnish HTTP cache and my first time exploiting it. As a result, let’s try to learn it together where my thought might be different from others. Varnish HTTP Cache is a high-level web application accelerator or also called caching HTTP […]

The post Hack The Box: (Forgot) – Varnish HTTP cache to retrieve any cache appeared first on Threatninja.net.

March 5, 2023
Read More >>