[+- off]
2026-09-26 21:50
telegramthe_high_council_of_frens
OCR
Текст, распознанный с картинки.
r/AskNetsec u/SavingsProgress195 pushed unified vuln dashboard with live criticals to public github repo. team is melting down cannot even process what just happened. we have been grinding for weeks to unify vulnerability data from 12 different security tools into one dashboard. tenable, qualys, snyk, wiz, you name it, all feeding into one platform thing we set up. apis pulling scans, risk scores, everything normalized into single panes so management stops yelling about tool sprawl. finally got a demo view working friday. pulled all the feeds, built the unified queries, even added some fancy risk prioritization graphs. excited as hell so i made a repo to share with the team over weekend. forgot to init as private. pushed to my work github account which is public default because i use it for side scripts. commit message was literally 'unified vuln view with prod feeds live check this out monday morning slack explodes. external vuln scanner picks up our repo, indexes it, and now our entire high med crit list from prod environment is scraped and showing in public searches. customer names, asset tags, cvss scores for unpatched stuff across 500 servers. one of our biggest clients assets right there with 'immediate exploit' tags. heart stopped when i saw it trending in some threat intel feed. rushed to delete the repo but google cache and some scrapers already mirrored it. team lead is furious, ciso looping in legal, clients getting calls. spent all morning yanking api creds rotating tokens disabling feeds. dashboard is dark now but damage is done. how did i miss the public toggle. brain was fried from 50 hour week.
lang: ru+en
Пользовательские термины
Свои поисковые фразы (до 280 символов). При поиске по термину счётчик растёт.
Пока нет пользовательских терминов.