Dependency Confusion, Suspender Falls, Web Shells, & AppSec Scale – ASW #140
This week on the Application Security News, Dependency confusion for internal packages, Chrome pulls down the Great Suspender, Microsoft highlights web shells, some strategies on scaling AppSec, & more!
Announcements
We're always looking for great guests for all of the Security Weekly shows! Submit your suggestions by visiting https://securityweekly.com/guests and completing the form!
If you missed Security Weekly Unlocked, you can now access all of the content on-demand, whether you registered before the live event or not, by visiting https://securityweekly.com/unlocked and clicking either the button to register or the button to login!
Hosts
Mike Shema
Tech Lead at Block
- 1. Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other CompaniesThe package is coming from inside the house! -- except not really. Our horror trope returns with a dash of DNS and publicly posted internal item names.
- 2. The Great Suspender Chrome extension’s fall from graceA different sort of supply chain sneakiness, something we might call "usurped trust" or "trust laundering".
- 3. Web shell attacks continue to riseA tour through some visual obfuscation and nefarious scripting. A nice read to learn about post-exploitation techniques along with some reasonable recommendations to counter them. We last touched this specific topic from Microsoft back on February 10, 2020 in episode 95.
- 4. Let’s Encrypt Gears Up to Replace 200M Certificates a DayAvailability is important to services that provide security as much as it's an important piece of the CIA triad. Confidentially isn't as confidential if you can get the certs to make the communications confidential! You can find more details at https://letsencrypt.org/2021/02/10/200m-certs-24hrs.html
- 5. Appsec Development: Keeping it all together at scaleWhat if scaling security reviews was the wrong strategy all along?
- 6. completely ridiculous API (crAPI) will help you to understand the ten most critical API security risksLearn about API security by poking at an insecure API.
- 7. Apple Outlines 2021 Security, Privacy RoadmapHow would you document the security for your own product or SaaS platform? You can read the full guide online or download the 196-page PDF at https://support.apple.com/guide/security/welcome/web