@iantshaw Profile picture

Ian Shaw

@iantshaw

CEO at https://t.co/qXDYH05H0D

Similar User
john fitzpatrick photo

@j0hn__f

nmonkee photo

@nmonkee

Gary Smith photo

@fl1bbl3

Luke Jennings photo

@jukelennings

Marc Wickenden photo

@marcwickenden

James Loureiro photo

@NerdKernel

Lifestyle.ca photo

@lifestyle_ca

Christopher Panayi photo

@Raiona_ZA

Scriptmonkey_ photo

@scriptmonkey_

Tyrone Erasmus photo

@metall0id

Matt Watkins photo

@MattWhatkins

lɐʍɹǝuɔǝ ɯnuɹo photo

@munrobotic

G Lafuente (G-man) photo

@Gman_H4ck3r

Ben Campbell photo

@Meatballs__

Trifon photo

@Trifonkat

Ian Shaw Reposted

1/ The ongoing Snowflake situation has made me realize just how dangerous ghost logins – a SaaS-based persistence technique that I coined last year – can be as an initial access vector. So what is a ghost login, exactly?


Ian Shaw Reposted

Remember our Fake Cisco research? labs.withsecure.com/content/dam/la…

Tweet Image 1

Counterfeit Cisco gear ended up in US military bases, used in combat operations trib.al/r7RSYBb



Ian Shaw Reposted

Oktajacking: A new attack using Okta's AD synchronization to do credential capture for you. Link to @jukelennings full post in 🧵 👊 Thanks to @_xpn_ @TrustedSec for the inspiration! #redteam #redteaming #pentest #pentesting #identitysecurity #SSO #okta #infosec


Ian Shaw Reposted

When the guy who fundamentally changed the way the world red-teams/pentests has something to say it's definitely worth a listen: @jukelennings of @PushSecurity on SAAS security talks to @SpecterOps - open.spotify.com/episode/6XQZtS…


Ian Shaw Reposted

Employees are self-adopting SaaS apps and creating new cloud identities on their own. 💡 Consider Push to find these identities & guide employees to harden their accounts against attacks. Read the blog in the 🧵 👇 #identitysecurity #saassecurity #security #IAM #tprm

Tweet Image 1

Ian Shaw Reposted

Attending #BlueHat? Don't miss Push's VP of Research @jukelennings speaking on the new SaaS cyber kill chain! #cybersecurity #saasattacks #saassecurity #infosec #security

Tweet Image 1

Ian Shaw Reposted

Going to #hacktivity2023? Catch Push's Luke Jennings on Thursday, Oct 5 at 9am in the Security Dome! Link in 🧵 #SaaSsecurity #SaaSattacks #security #infosec

Tweet Image 1

Ian Shaw Reposted

📣SPEAKER ANNOUNCEMENT📣 Our next #BlueHat speaker is Luke Jennings @jukelennings from Push Security! Luke will present a talk titled "The new SaaS cyber kill chain." 👏

Tweet Image 1

Ian Shaw Reposted

Find out why SSO helps, but doesn't completely solve this problem Read the blog: bit.ly/3PPn4BQ


Ian Shaw Reposted

Credential stuffing: the most common attack against SaaS identities. 💥 Auth0 recently reported that credential stuffing accounts for *34% of overall traffic/authentication events on their platform.* Link in the 🧵! #credentialstuffing #saasattacks #identitysecurity #iam

Tweet Image 1

Ian Shaw Reposted

Atos joins forces with @intigriti, the EU leading platform for #bugbounty and ethical hacking to offer a end-to-end service for organizations. But, what the hack is bug bounty? 🐛 And how can it help improve your digital security? Learn more 👇 spr.ly/6013yFgxP

Tweet Image 1

Ian Shaw Reposted

PowerSaaS, you're saying, then? Will try to stop branding it, sorry...

I feel like shadow workflows are the closest equivalent of offensive PowerShell for the SaaS world. Check out the second post in my series on chaining SaaS attacks and come see me speak about this and a lot more at #44con on Thursday 14th September! pushsecurity.com/blog/nearly-in…



Ian Shaw Reposted

While OAuth scopes and third-party integrations provide seamless online user authentication, they also carry significant risk. 👀 Watch out for these common, dangerous scopes (more in the blog post, linked in 🧵!) #security #OAuth #thirdpartyrisk #tprm #sspm #casb #infosec

Tweet Image 1
Tweet Image 2
Tweet Image 3
Tweet Image 4

Ian Shaw Reposted

GM! Time to repost one of my favourite places on earth, Preston Bus Station.

Tweet Image 1

Ian Shaw Reposted

Great interview with our CEO and co-founder @ajaybateman and @dspark on @CISOseries about "Securing identity in the age of self-service" "It's about creating a paved path for employees to walk..." Link in 🧵!


Ian Shaw Reposted

1/ I kinda accidentally owned myself with my own shadow workflow attack. I definitely think they are going to become a standard technique. I mean they are pretty much the offensive powershell of the SaaS world! So how did this happen?


Ian Shaw Reposted

🔎 Focus on account security to reduce SaaS risks 📑 Read our latest article to learn how to manage the risk of SaaS security, shadow IDs, identities, and accounts. Link in 🧵 #SaaSsecurity #shadowIT #shadowidentities #SaaSmanagement #SaaSsprawl #shadowaccounts

Tweet Image 1

Ian Shaw Reposted

👋 New feature alert! Classify SaaS apps in the Push platform based on the sensitivity of the data they contain or the permissions they've been granted. Use the Approval status to capture your decision about an app -- is it in or out? Link in 🧵 #SaaSsecurity #security


Loading...

Something went wrong.


Something went wrong.