Sign in

Rami

@ramimac.me
393 followers 228 following 36 posts

security, for the internet, at Wiz opinionated about security. knowledge hubs at rami.wiki, thoughts at ramimac.me

PostsRepliesMedia
Rami @ramimac.me · 27/03/2026
There is currently a wave of supply chain attacks clustered around TeamPCP, a financially motivated threat actor. Today, the latest news was telnyx's python package had malicious versions pushed. This follows trivy, checkmarx (kics), and litellm incidents. Get the details: ramimac.me/teampcp
ramimac.me
TeamPCP Supply Chain Campaign | Attack Timeline & IOCs
Timeline and IOCs for TeamPCP's March 2026 supply chain campaign. Trivy, KICS, LiteLLM, and 45+ npm packages compromised through chained credential theft.
021
Reposted by Rami
Wiz io @wiz.io · 15/10/2025
🚨 Wiz Research uncovered 100+ leaked VSCode publisher tokens that could let attackers push malicious updates to 185K+ installs. We partnered with Microsoft to secure tokens and protect the ecosystem.
wiz.io
Supply Chain Risk in VSCode Extension Marketplaces | Wiz Blog
Wiz Research uncovered 500+ leaked secrets in VSCode and Open VSX extensions, exposing 150K installs to risk. Learn what happened and how it was fixed.
021
Reposted by Rami
Wiz io @wiz.io · 18/06/2025
🚨 We scanned GitHub and found *hundreds* of valid secrets, 4 of the top 5 were AI-related: HuggingFace, Azure OpenAI, Weights & Biases, and Groq. Read more: www.wiz.io/blog/leaking...
031
Rami @ramimac.me · 17/06/2025
> We've set up a web endpoint so vetted ... security researchers can submit suspected exposed credentials for review > To report exposed Google Cloud credentials, please contact gcp-credentials-reports@google.com cloud.google.com/blog/product... really buried the lede!
cloud.google.com
Securing open-source credentials at scale | Google Cloud Blog
We’ve developed a powerful tool to scan open-source package and image files by default for leaked Google Cloud credentials. Here’s how to use it.
021
Rami @ramimac.me · 05/05/2025
In light of recent GitHub Actions incidents (Ultralytics, tj-actions...), I wrote up a practical guide to hardening for @wizsecurity.bsky.social Covers permissions, secrets, 3rd-party Actions, ++ Use it to avoid learning these lessons the hard way: www.wiz.io/blog/github-...
wiz.io
Hardening GitHub Actions: Lessons from Recent Attacks | Wiz Blog
Build resilient GitHub Actions workflows with insights from real attacks, missteps to avoid, and security tips GitHub’s docs don’t fully cover.
074
Rami @ramimac.me · 17/04/2025
Synthesized 20+ sources and internal @wizsecurity.bsky.social expertise to come out with a comprehensive guide to MCP security Today's options, and tomorrow's possibilities www.wiz.io/blog/mcp-sec...
wiz.io
MCP and LLM Security Research Briefing | Wiz Blog
Explore the evolving Model Context Protocol (MCP), its security risks, and how to prepare for safe adoption as LLMs connect to external systems.
041
Reposted by Rami
Wiz io @wiz.io · 09/04/2025
🎙️ New episode! Our own @ramimac.me helps dive into GitHub supply chain attacks, IngressNightmare, and Oracle breach rumors. Tune in for the latest cloud security insights! 🎧 podcasts.apple.com/us/podcast/q...
podcasts.apple.com
Quadruple Supply Chain Attack, IngressNightmare Exploited, and Rumors Abound
Podcast Episode · Crying Out Cloud · 04/09/2025 · 29m
021
Reposted by Rami
Scott Piper @scottpiper.bsky.social · 20/03/2025
It's been awesome getting to team up with @ramimac.me to dig into a new AWS feature! Read our thoughts on AWS's new CloudTrail network activity events (aka VPC endpoint logs): www.wiz.io/blog/aws-vpc...
wiz.io
CloudTrail Network Activity Events for AWS VPC Endpoints | Wiz Blog
How AWS VPC Endpoint CloudTrail logs can help you troubleshoot endpoint policies and strengthen your network's security against data exfiltration.
092
Rami @ramimac.me · 17/03/2025
Turns out when you investigate a compromised Github Actions you ... find another compromised Github Action: www.wiz.io/blog/new-git...
wiz.io
GitHub Action supply chain attack: reviewdog/action-setup | Wiz Blog
A supply chain attack on tj-actions/changed-files leaked secrets. Wiz Research found another attack on reviewdog/actions-setup, possibly causing the compromise.
1158
Rami @ramimac.me · 06/02/2025
Very fun to help put final polish on this report in week 3 at Wiz - anecdata is fun, data is funner :)
051
Rami @ramimac.me · 28/01/2025
New year, new job! I've joined the amazing @wiz_io research team My goal is the "work for the security industry, at Wiz" I wrote a blog post explaining why, and what that means: ramimac.me/joining-wiz
ramimac.me
🧙 Why I’m Joining Wiz
I’m joining the leading cloud security startup, hoping to “work for the Security Industry, at Wiz.”
3324
Rami @ramimac.me · 30/12/2024
Lately, every BSides seems to have a talk on reframing security teams as a “Department of Yes” We don’t hear nearly as much about the value of a well-considered, strategically deployed “No” I've pulled together guidance on giving a better, more constructive No: ramimac.me/saying-no
ramimac.me
How to Say “No” Well
Security’s pivot from ‘Department of No’ to ‘Department of Yes’ misses the real lesson - how to say ‘No’ the right way.
02110
Rami @ramimac.me · 26/12/2024
Keep an eye out for notices - AWS RDS Protection for Guardduty seems to have had some issues collecting logs. Unclear how pervasive this was!
174
Rami @ramimac.me · 24/12/2024
reminds me of ramimac.me/poisoning-ss... 😉
ramimac.me
Poisoning the SSM Command Document Well
Responsibly disclosing risks in using SSM Command Docs for software distribution.
020
Rami @ramimac.me · 18/12/2024
One recent report highlighted that roughly a third of their customers have “at least one cloud workload that is publicly exposed, critically vulnerable and highly privileged.” If you’re this vendor, should I really buy your product? ramimac.me/state-of-clo...
ramimac.me
State of ‘State of Cloud Security’ Reports: Insights or Self-Owns?
Dozens of hours reading State of Cloud Security reports that I think miss the mark.
010
Rami @ramimac.me · 18/12/2024
I've spent dozens of hours reading State of Cloud Security reports You know, the ones that use data from their CSPM product And I've realized the findings substantially reflect how well that tool helps customers secure their clouds I wrote up some examples, both good and bad (🔗 in 🧵)
184
Reposted by Rami
Charity Majors @charity.wtf · 17/12/2024
I (finally) wrote up my thoughts on "Founder Mode" and the Brian Chesky morality tale about how he turned around Airbnb company culture. This has made it into the Silicon Valley water table; it must be dealt with. There are some good nuggets within; let's dig them out. charity.wtf/2024/12/17/f...
charity.wtf
“Founder Mode” and the Art of Mythmaking
I’ve never been good at “hot takes”. Anyone who knows anything about marketing can tell you that the best time to share your opinion about something is when everyone is all worked up about it. Hot …
2629393
Rami @ramimac.me · 18/12/2024
www.cybok.org/media/downlo...
130
Reposted by Rami
Mike Privette @returnonsecurity.com · 09/12/2024
New Threat Vector Unlocked 1. Find the Crunchbase page of a cybersecurity company that just raised VC funding 2. Change the page details (which anyone with a Crunchbase account can do) to a personal CashApp page 3. ???? 4. Profit! (?)
152
Rami @ramimac.me · 09/12/2024
Somehow <50 people have caught this talk from Coinbase's CSO?? His core advice: 1. Make lives easier - e.g roll out yubikeys 2. Define Security Invariants 3. Plan & Practice IR 4. Balance Risks & Threats 5. Security is a People Problem - use focus groups for new controls! youtu.be/BPh4Hc3TH74
youtu.be
A decade of defense: securing the largest US crypto exchange | Philip Martin | MSSN CTRL 2024
YouTube video by LimaCharlie
0121
Rami @ramimac.me · 09/12/2024
Just keep dm'ing them to me so I can bully you into publishing 😈
020
Rami @ramimac.me · 01/12/2024
Interesting research out of AWS! > IAM-PolicyRefiner, a tool that automatically synthesizes refined AWS IAM access control policies from access logs > fast (<5s per policy), effective and does not overfit Not open source, but maybe a sign of things to come? assets.amazon.science/cf/bc/58e56f...
assets.amazon.science
071
Rami @ramimac.me · 21/11/2024
IIRC, re:Inforce was a bust for security announcements. I wish some of these announcements got time center stage there, versus being pre:Invent announcements now. Hopefully re:Invent makes space alongside the GenAI noise!
020
Rami @ramimac.me · 20/11/2024
I've been chatting a lot re:when to make the first security hire" recently I've come up with a Rule of Thumb: Hire your first security person when security is an unavoidable distraction from scaling your business ramimac.me/start-security h/t @grims.bsky.social & @mag00.bsky.social
0101
Rami @ramimac.me · 19/11/2024
This webinar will be more relay-race than sparring match when it's with folks like @nanook.bsky.social and @jamesberthoty.bsky.social!
030
Rami @ramimac.me · 18/11/2024
I think it's pretty easy to dig up research that ties phishing simulations to a decrease in metrics like Click Through Rate or improvement in "awareness" - but I'd argue those aren't the metrics that matter! Ex. hcis-journal.springeropen.com/articles/10....
hcis-journal.springeropen.com
Don’t click: towards an effective anti-phishing training. A comparative literature review - Human-centric Computing and Information Sciences
Email is of critical importance as a communication channel for both business and personal matters. Unfortunately, it is also often exploited for phishing attacks. To defend against such threats, many ...
010
Rami @ramimac.me · 18/11/2024
I love when new research comes out to back up my "phishing training is bad practice" priors: www.computer.org/csdl/proceed... I track the latest evidence against phishing simulations: rami.wiki/phishing-sim...
computer.org
CSDL | IEEE Computer Society
262
Rami @ramimac.me · 18/11/2024
Wondering “What Does Success Look Like?” Check out the book! There is incredible depth, detail, and color provided that I can only hint at in this format: www.oreilly.com/library/view... Thank you to Camille and Ian for sharing their expertise
oreilly.com
Platform Engineering
Until recently, infrastructure was the backbone of organizations operating software they developed in-house. But now that cloud vendors run the computers, companies can finally bring the benefits of a...
072
Rami @ramimac.me · 18/11/2024
“Saying “No” Without Ruining the Relationship” - “Not yet, priority call” → give options and how they can help - “Not yet, technical call” → take time to explain the details - “No, product strategy call” → accept shadow IT or alternative platforms - “No, technical call” → beware magical thinking
110
Rami @ramimac.me · 18/11/2024
Use the handy-dandy power-interest grid to prioritize stakeholder management!
high power + low interest = keep satisfied
low power + low interest = monitor with minimum effort
high power + high interest = manage closely
low power + high interest  = keep informed
110
Rami @ramimac.me · 18/11/2024
📦 Tips & Tricks for Migrations * Minimize Glue and Limit Variation * Transparent Migrations * Usage Metadata * Automate as much as possible * Focus documentation on on-ramps and off-ramps
110
Rami @ramimac.me · 18/11/2024
“If you don’t end up regretting your early technology decisions, you probably overengineered. -Randy Schoup” Don't do a v2 (Pioneer mindset, new features, and scale don't mix!), just change the plane's engine in midair. Rearchitect with a focus on “reliability, features, efficiency, and security”
120
Rami @ramimac.me · 18/11/2024
🍑 Artifacts to gather for bottom up planning * An estimate of KTLO work * An estimate of all mandated (top down) projects * Your roadmap, highlighting customer and stakeholder desired for the platform * Three stacked-rank lists of projects to improve efficiency, reliability, and security
110
Rami @ramimac.me · 18/11/2024
📈 Potential Metrics Overhead of using the platform Benefits (time or money) from using the platform Voluntary adoption / Customer demand CSAT / NPS / Customer satisfaction Platform Stability (efficiency, availability, correctness)
120
Rami @ramimac.me · 18/11/2024
🛒 Internal Customers come with baggage A captive, evolving audience with competing incentives, that can go rogue and compete with you. The solution? determining “revealed preferences”, and driving towards customer love (ramimac.me/customer-love) pro-tip: a customer support rotation for engineers
110
Rami @ramimac.me · 18/11/2024
👥 Platform Engineering is a culture A "curated product approach" moves focus to people and usability, over “cost, scale, and process” You can't just add PMs. You need to interview for customer empathy, invest in support, tune your recognize & reward models, and accept the non-coding overhead
110
Rami @ramimac.me · 18/11/2024
🤡 How to commonly fail: * start too early or underestimate the change * wrong blend of people * insufficient product management * failure to operate your platform * strong to continually deliver new value * stuck with naive architectures * migrations burn goodwill * fail to show value
140
Rami @ramimac.me · 18/11/2024
🤖 How will GenAI change things? * lots of room to platform and optimize MLOps * data is a major ML predicate, requiring a focus on “controls and data entitlements” * a platform to curate and operationalize the ecosystem of LLMs is a large opportunity.
110
Rami @ramimac.me · 18/11/2024
The features of a good platform (“cheaper, safer, and easier to use”): * Self-service, with easy-to-use defaults and power user options * Observability: “tell whether they’re doing something wrong or the platform is doing something wrong” h/t @whereistanya.bsky.social * Guardrails & multi-tenancy
110
Rami @ramimac.me · 18/11/2024
Speed reading @skamille.bsky.social & Ian Nowland's new book: Platform Engineering Interesting tidbits in 🧵 paved roads 🛣️: “layers multiple offerings together into easy-to-use workflows” vs railways 🚟 building to fill a "meaningful gap that is not covered by any existing product”
Cover image for the book "Platform Engineering", from O'Reilly, with a green gecko(?)
1275
Rami @ramimac.me · 18/11/2024
An empty feed is staring into the void... What you can expect to see here: * infrequent, but hopefully high signal posting * promoting and amplifying interesting security work (including dreaded self-promotion) * scaling security programs & cloud security * ironic(?) usage of scooby-doo ramimac.me
ramimac.me
High Signal Security
YAIB (Yet Another Infosec blog).
0100
Rami @ramimac.me · 31/10/2024
Crushed this @mccune.org.uk! The whole time you were talking about Tiller I was waiting to see if you'd mention SAPwned 😆😭 The future of k8s security is here, it's just not evenly distributed...
010