Uploaded April 2019 | Updated September 2026, 2 weeks ago
A recent study by NCSU found that there are way more API keys and tokens uploaded to GitHub than previously thought. In fact, there's almost a near constant stream of secrets being exposed...why?!?
It boils down to operational security. Automated build pipelines and access to cloud services that amplify what your team is capable of. Moving faster without some smart guardrails can lead to these issues.
The good news? A cybersecurity view of the same tool sets that are exposing this lack of opsec can help address it. Automated checks for secrets, tools specifically designed to handle secrets, and education around these issues can help reduce the likelihood of recurrence or prevent it from happening in the first place.
References;
- the research page from NCSU (PDF), ndss-symposium.org/wp-content/uploads/2019/02/ndss2019_04B-3_Meli_paper.pdf
- recent MongoDB issues via Brian Krebs, krebsonsecurity.com/tag/mongodb
// MWM Y2 no. 022
A recent study by NCSU found that there are way more API keys and tokens uploaded to GitHub than previously thought. In fact, there's almost a near constant stream of secrets being exposed...why?!?
It boils down to operational security. Automated build pipelines and access to cloud services that amplify what your team is capable of. Moving faster without some smart guardrails can lead to these issues.
The good news? A cybersecurity view of the same tool sets that are exposing this lack of opsec can help address it. Automated checks for secrets, tools specifically designed to handle secrets, and education around these issues can help reduce the likelihood of recurrence or prevent it from happening in the first place.
References;
- the research page from NCSU (PDF), ndss-symposium.org/wp-content/uploads/2019/02/ndss2019_04B-3_Meli_paper.pdf
- recent MongoDB issues via Brian Krebs, krebsonsecurity.com/tag/mongodb
// MWM Y2 no. 022

![Lazio & BlackMatter Bring Ransomware Into the Spotlight…Again #shorts
The region of Lazio was hit by a ransomware attack and is struggling to recover. The criminals have yet to be identified or claim responsibility for this attack on critical infrastructure.
At the same time, we see a new ransomware supergroup called BlackMatter emerge with a pledge not to attack critical infrastructure like this.
What does this mean for ransomware? For you?
More in this short...
Index:
- [0:00] Lazio attack
- [0:16] Risky move
- [0:26] BlackMatter supergroup
- [0:42] Profit
#shorts Lazio & BlackMatter Bring Ransomware Into the Spotlight…Again #shorts](https://i.ytimg.com/vi/G87fniLVqGw/mqdefault.jpg)



![Ransomware Attack On Kaseya Still Very Real For Victims #shorts
Long after the headlines pass, victims of ransomware are left struggling to get back to normal operations. IT is hard. Cybersecurity is harder still.
More in this short...
References:
- Ransomware Costs Double in Q4 as Ryuk Sodinokibi Proliferate by Coveware, https://www.coveware.com/blog/2020/1/22/ransomware-costs-double-in-q4-as-ryuk-sodinokibi-proliferate
- Ransomware Report: Sophos State of Ransomware Report 2021, https://secure2.sophos.com/en-us/content/state-of-ransomware.aspx
Cybereason, Report: Ransomware Attacks and the True Cost to Business, https://www.cybereason.com/blog/report-ransomware-attacks-and-the-true-cost-to-business
- Kevin Beaumont (@GossiTheDog) on Twitter, https://twitter.com/gossithedog/status/1414549083495272453?s=21
Index:
- [0:00] Kaseya
- [0:10] Back to normal?
- [0:32] Continued risk
- [0:42] Long road
#shorts Ransomware Attack On Kaseya Still Very Real For Victims #shorts](https://i.ytimg.com/vi/I7lpgLpjH6A/mqdefault.jpg)



![New Ransomware Resources For Defenders #shorts
Two new resources launched to help people understand the challenges associated with ransomware.
StopRansomware.gov collects resources for individuals and business trying to prevent ransomware and those impacted by an attack.
RansomWhe.re tracks payments made to ransomware cryptocurrency wallets.
Learn more in this short...
References:
- https://StopRansomware.gov from the US federal government
- https://RansomWhe.re from the Krebs Stamos Group
- Coverage of the US government site launch, $10 million rewards bolster White House anti-ransomware bid, https://apnews.com/article/technology-joe-biden-europe-business-government-and-politics-cd21d84b5fd070421f871610b40e91d0
- Ransomwhere project tracks payment demands, https://finance.yahoo.com/finance/news/ransomwhere-project-tracks-payment-demands-132133459.html
Index:
- [0:00] 2 New Resources
- [0:06] StopRansomware.gov
- [0:24] RansomWhe.re
#shorts New Ransomware Resources For Defenders #shorts](https://i.ytimg.com/vi/JebWBUO0prc/mqdefault.jpg)
