干货铺 | 洋仔对单包授权认证(SPA)的思索(上)
我司洋仔对SPA的分析,说实话,我俩对SPA都不咋看好,有点隔靴搔痒的感觉。
Today FireEye shared that they were victim of a cyberattack and internal red teaming tooling was accessed by adversaries. More details in this NYT article.
This reminded me that I wanted to do a post on actively protecting pen testers and pen testing assets for a while.
Against persistent adversaries it is only a matter of time when they succeed, not if they will succeed. The big question is do you know when an adversary starts poking around, and when they succeed?