Here's What you can Learn from the Palo Alto Breach
SANS Cloud Security Flight School News | May 2024

Here's What you can Learn from the Palo Alto Breach

"Security products often provide web applications that administrators and users can access. However, overlooking basic security measures in these applications can result in severe consequences. For instance, Palo Alto Networks did not properly validate the format of session IDs before using them as file names. This oversight led to a path traversal vulnerability. Compounded by a configuration error, the vulnerability’s severity increased, allowing attackers to write files in locations that the telemetry process would later execute. This capability to create files escalated to an unauthenticated remote code execution problem. Recent history has shown that such fundamental vulnerabilities in products like Ivanti Connect Secure and Citrix Gateway can cause significant damage." - Dr. Johannes Ullrich , SANS Faculty Fellow and founder of the Internet Storm Center

Read the article


Free Curated Cloud Security Resources

SANS Hands-on Workshop | AviataCloud Solo Flight Challenge Chapter 3: Wings of Innovation: Transitioning to Containerization with Ahmed Abugharbia | Thursday, June 13 | 10am ET | 1400 UTC | Sans.org/ace135
Wings of Innovation: Transitioning to Containerization | Aviata Cloud Hands-on Workshop Chapter 3

Wings of Innovation: Transitioning to Containerization | Hands-on Workshop

FREE Thursday, June 13 | 10am ET | 1400 UTC

Aviata Cloud Chapter 3: Wings of Innovation: Transitioning to Containerization is a hands-on workshop led by Ahmed Abugharbia that delves into the essentials of Kubernetes, teaching participants about it's architecture, deployment options, and security practices to facilitate a successful transition to a containerized infrastructure. Learn to deploy and secure applications effectively through free, practical exercises this June.

Free Registration

The adventures of the Aviata Cloud company and our SANS Cloud Security workshop series will run monthly from April through December 2024.


SANS Cloud Security | Nine Key Cloud Security Concentrations & Swat Checklist | Poster
Nine Key Cloud Security Concentrations Poster | SWAT Checklist

Nine Key Cloud Security Concentrations & SWAT Checklist | Poster

This free downloadable poster describes top cloud security concentrations broken down by each of the Big 3 Cloud providers: AWS, Azure, and GCP. It also includes a SWAT checklist that provides an easy-to-reference set of best practices that raise awareness and help development teams create more secure applications.

Download Your Copy


Webcast | JWTs: The Good, the Bad, and the Ugly (Security Edition) with Joshua Barone
JWTs: The Good, the Bad, and the Ugly (Security Edition) Webcast

JWTs: The Good, the Bad, and the Ugly (Security Edition) | Webcast | GitHub

Cybersecurity expert and SANS certified instructor, Joshua Barone , unpacks the complexities of JWT security, reveals common vulnerabilities, and shares essential best practices to enhance your token-based authentication strategies.

This webcast includes a demo environment for authentication and authorization using JSON Web Tokens (JWT) and demonstrates potential security vulnerabilities associated with JWT.

Register to Access the Webcast


SANS Research Program | 2024 Multicloud Survey | Securing Multiple Clouds Amidst Constant Changes | Survey Authors: Kenneth G. Hartman & Simon Vernon | Closes May 28, 2024 | Take the Survey Today for a Chance to Win a $400 Amazon Gift Card
SANS Research Program 2024 Multicloud Survey


Take the SANS 2024 Multicloud Survey: Securing Multiple Clouds Amid Constant Changes

This survey explores the reasons multicloud users make specific cloud adoption decisions, as highlighted in past surveys.

Complete this survey for a chance to win a $400 Amazon gift card as a thank you for your participation.

Take the Survey


SANS Security Awareness Training | Web Application Security Awareness Training Free Trial
Web Applications Security Awareness Training | Free Trial

Web Application Security Awareness Training FREE Trial

Role-based developer training for any skill level. Don't let security vulnerabilities compromise your applications or your organization's reputation. Access your trial today and bring consistent secure coding principles to your development teams

Access Your Trial


SANS CloudSecNext 2024 Summit & Training | Denver CO | Summit: Sept 30 - Oct 1 | Training: Oct 2 - 7 | In-Person & Live Online
SANS CloudSecNext Summit 2024 | Denver CO | Summit Sept 30-Oct 1 | Courses Oct 2-Oct 7

CloudSecNext 2024 | Summit | Training

Dive into the future of cybersecurity at the CloudSecNext Summit, where industry leaders converge in person or online to tackle the latest cloud security challenges through expert-led workshops, real-world case studies, and invaluable networking opportunities, enhancing your skills and career in an ever-evolving digital landscape.

"Summits are a great way to meet and talk to the trail blazers; the individuals who each in their own way help shine a light for the rest of the community." - Michael D, ViaSat, Inc.

Learn More and Register


It's not a Matter of If, but When. Be Prepared for a Web Attack

SEC522: Application Security: Securing Web Apps, APIs, and Microservices | GIAC Certified Web Application Defender (GWEB)
SEC522: Application Security: Securing Web Apps, APIs, and Microservices | GWEB

Application Security: Securing Web Applications, APIs, and Microservices | SEC522

Security teams need a deep understanding of AWS, Azure, and Google Cloud services to lock them down properly. Checking off compliance requirements is not enough to protect the confidentiality, integrity, and availability of your organization's data, nor will it prevent attackers from taking your critical systems down. With the right controls, organizations can reduce their attack surface and prevent security incidents from becoming breaches. Mistakes happen. Limit the impact of the inevitable.

Take the Course Demo

Did you know that any SANS Alumni of SEC522 can take it at anytime in the future for 50% off? Email [email protected] for more information.

"I am very glad I took this course because there are not many instructors on platforms like Udemy or YouTube that have the knowledge the instructor has. He is very knowledgeable and when asking a question, he goes in-depth about the concept. What I love the most is that his professional experience working in the field helps us understand more about real-life examples." - Alisa C, SEC522 Student

GWEB | GIAC Certified Web Application Defender Certification
GIAC Certified Web Application Defender Certification | GWEB | GIAC Certification

GIAC Web Application Defender Certification | GWEB

The GIAC Web Application Defender (GWEB) certification validates expertise in securing web applications. It focuses on key issues like input validation flaws, XSS, and SQL injection, and includes comprehensive knowledge of authentication, access control, and session management. Candidates will demonstrate their ability to use current tools to manage security risks and enhance the safety of both new and existing web applications.

Learn More About GWEB


SANS Cloud Security Engineer Journey | Prevent - Automate - Defend
SANS Cloud Security Engineer Journey | Prevent - Automate - Defend

Cloud Ace Engineer | Prevent - Automate - Defend

Looking to become a Cloud Security Engineer ? Here’s how:

Learn more about the SANS Cloud Ace Journey Training Paths


Visit the SANS Cloud Security Curriculum Page | Preview SANS Courses | Connect with Our Solutions Team | Join the SANS Community


要查看或添加评论,请登录

社区洞察

其他会员也浏览了