<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Naushad Saboor — Writing</title>
    <link>https://www.naushad.co.uk/</link>
    <description>Naushad Saboor — founder of QuantumHandshake™ and AiiDIS™, building post-quantum trust infrastructure for regulated systems. Two decades in offensive security, SOC leadership and digital forensics.</description>
    <language>en-GB</language>
    <atom:link href="https://www.naushad.co.uk/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Udemy Certifications</title>
      <link>https://www.naushad.co.uk/udemy/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/udemy/</guid>
      <pubDate>Wed, 04 Nov 2020 17:20:24 +0000</pubDate>
      <description></description>
    </item>
    <item>
      <title>A Majority of Attacks Successfully Infiltrate Enterprise Environments Without Detection</title>
      <link>https://www.naushad.co.uk/a-majority-of-attacks-successfully-infiltrate-enterprise-environments-without-detection/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/a-majority-of-attacks-successfully-infiltrate-enterprise-environments-without-detection/</guid>
      <pubDate>Sat, 09 May 2020 12:46:21 +0000</pubDate>
      <description>FireEye  released  the  Mandiant® Security Effectiveness Report   2020  which reveals data about how well organizations are protecting themselves against cyber threats and the overall effectiveness of their security infrastructure. The report summarizes the results of thousands of tests performed by experts from the Mandiant Security Validation (previously known as Verodin) team. The tests consist</description>
    </item>
    <item>
      <title>Mysterious Raspberry Pi &amp; a Mobile phone in the server room.</title>
      <link>https://www.naushad.co.uk/malicious-raspberry-pi-in-the-network-closet/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/malicious-raspberry-pi-in-the-network-closet/</guid>
      <pubDate>Fri, 18 Jan 2019 16:13:55 +0000</pubDate>
      <description>Last week I discovered two Mysterious devices in our server room an image attached. Message from my co-worker I asked him to unplug it, store it in a safe location, take photos of all parts and to make an image from the SD card (since I mostly work remote). I have worked on many Raspberry Pi projects and I felt confident I could find out what it does. At this point nobody thought it was going to b</description>
    </item>
    <item>
      <title>Threat Intelligence and Analytics: Staying Ahead of Cyber Criminals</title>
      <link>https://www.naushad.co.uk/threat-intelligence/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/threat-intelligence/</guid>
      <pubDate>Fri, 04 Jan 2019 19:07:51 +0000</pubDate>
      <description>NOTE: This document incomplete, still DRAFT Mode… The intelligence, in terms of security, is a collection of security-related information which when analysed provides meaningful foresight. The threat intelligence likewise is an analysis of information collected about the cyber threat so that it provides reliable and structured information about cybersecurity threats. Thus, threat intelligence form</description>
    </item>
    <item>
      <title>AppSec Check list Mine Map</title>
      <link>https://www.naushad.co.uk/application-security-mine-map/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/application-security-mine-map/</guid>
      <pubDate>Sat, 23 Jun 2018 12:29:23 +0000</pubDate>
      <description>Application security encompasses measures taken to improve the security of an application often by finding, fixing and preventing security vulnerabilities. From the risk management strategic point of view, the mitigation of application security risks is not a one time exercise; rather it is an ongoing activity that requires paying close attention to emerging threats and planning ahead for the depl</description>
    </item>
    <item>
      <title>DarkWeb &amp; DeepWeb Threat Intelligence</title>
      <link>https://www.naushad.co.uk/darkweb-deepweb-threat-intelligence/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/darkweb-deepweb-threat-intelligence/</guid>
      <pubDate>Sun, 29 Apr 2018 16:18:49 +0000</pubDate>
      <description>Many of your company’s most valuable assets are at risk to criminal activities carried out on the Dark Web – and you don’t even know it. Turning a blind eye to this will impact your: Brand and reputation Customer loyalty Intellectual Property Legal defenses Sales IT baselines Cybersecurity strategy And much more! Monitoring the Dark Web Working out whether your data is being sold on the dark web i</description>
    </item>
    <item>
      <title>Canada’s First Cybersecurity Law | BILL C-59 – Secure Knowledge Management</title>
      <link>https://www.naushad.co.uk/canadas-first-cybersecurity-law-bill-c-59-secure-knowledge-management/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/canadas-first-cybersecurity-law-bill-c-59-secure-knowledge-management/</guid>
      <pubDate>Wed, 25 Apr 2018 11:38:25 +0000</pubDate>
      <description>Canada’s First Cybersecurity Law | BILL C-59 – Secure Knowledge Management SUMMARY Part 1 enacts the National Security and Intelligence Review Agency Act, which establishes the National Security and Intelligence Review Agency and sets out its composition, mandate and powers. It repeals the provisions of the Canadian Security Intelligence Service Actestablishing the Security Intelligence Review Com</description>
    </item>
    <item>
      <title>Top 100 Hacking Books</title>
      <link>https://www.naushad.co.uk/top-100-hacking-books/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/top-100-hacking-books/</guid>
      <pubDate>Mon, 23 Apr 2018 11:06:17 +0000</pubDate>
      <description>A hundred books on offensive security, reverse engineering, network defence and forensics — assembled in 2018 from the titles that came up most often when practitioners were asked what they actually learned from. This is a reading list, nothing more. There are no downloads here. Every one of these is in print or sold as an ebook by its publisher, and that is where they should come from — the peopl</description>
    </item>
    <item>
      <title>Database of Abuse IP address for sysadmins</title>
      <link>https://www.naushad.co.uk/database-of-abuse-ip-address-for-sysadmins/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/database-of-abuse-ip-address-for-sysadmins/</guid>
      <pubDate>Mon, 26 Mar 2018 12:34:35 +0000</pubDate>
      <description>Here is my personal collection of IP addresses engaging in abusive behavior on the networks, for webmasters and sysadmins to block IP addresses engaging in abusive behavior on their networks. BLOCK ALL AbuseIP’s 93.115.86.8 93.115.86.4 185.112.157.135 172.105.231.26 40.69.62.87 144.217.161.119 92.222.207.228 2001:4ba0:cafe:9f::1 62.141.39.47 2001:470:d:6dd:11::beef 64.27.17.140 51.15.81.222 208.11</description>
    </item>
    <item>
      <title>First – Fix the Plumbing – What’s broken in cyberspace and How to Fix it</title>
      <link>https://www.naushad.co.uk/first-fix-the-plumbing-whats-broken-in-cyberspace-and-how-to-fix-it/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/first-fix-the-plumbing-whats-broken-in-cyberspace-and-how-to-fix-it/</guid>
      <pubDate>Sun, 25 Mar 2018 14:44:22 +0000</pubDate>
      <description>Live webinar: http://goo.gl/VVKxS3 Way back in 2000 it was common practice to spend considerable time configuring and tinkering the plumbing of what we today call cyberspace. The technology was embryonic, immature and often hours were spent ensuring nothing broke and that the business operations carried on smoothly. Today, those flaky technologies are settled and stable. – AI and Machine Learning </description>
    </item>
    <item>
      <title>Creating an IP-based rate-limiter</title>
      <link>https://www.naushad.co.uk/creating-an-ip-based-rate-limiter/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/creating-an-ip-based-rate-limiter/</guid>
      <pubDate>Mon, 12 Mar 2018 16:21:38 +0000</pubDate>
      <description>Basic rate-limiting middleware for Express. Use to limit repeated requests to public APIs and/or endpoints such as password reset. A brute-force protection middleware for express routes that rate-limits incoming requests, increasing the delay with each request in a fibonacci-like sequence. Here is the full control functions; store An instance of ExpressBrute.MemoryStore or some other ExpressBrute </description>
    </item>
    <item>
      <title>test</title>
      <link>https://www.naushad.co.uk/test/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/test/</guid>
      <pubDate>Sun, 11 Feb 2018 22:29:38 +0000</pubDate>
      <description>Mitigate-DDoS</description>
    </item>
    <item>
      <title>GDPR Audit Checklist</title>
      <link>https://www.naushad.co.uk/gdpr-audit-checklist/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/gdpr-audit-checklist/</guid>
      <pubDate>Wed, 07 Feb 2018 13:51:35 +0000</pubDate>
      <description>The first steps towards GDPR compliance are understanding your obligations, what your current processes are and identifying any gaps. Undertaking a data protection audit is essential to achieving compliance. This checklist is intended to provide a starting point, rather than providing an exhaustive audit. GDPR Audit Checklist</description>
    </item>
    <item>
      <title>Cyberlympic ‘Ethical Hacking’ World Championship</title>
      <link>https://www.naushad.co.uk/cyberlympic/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/cyberlympic/</guid>
      <pubDate>Mon, 30 Oct 2017 17:25:28 +0000</pubDate>
      <description>Today, the best hackers in the world competed in the Global CyberLympics final during Cyber Security Week in The Hague. This is an international online hacking competition aimed at improving the level of national cyber security and strengthening international cooperation. The Dutch Team Hack.ERS came out as the glorious number one. The Global CyberLympics consists of a series of ‘ethical hacking’ </description>
    </item>
    <item>
      <title>AutoBlock IPs that do a dictionary attack on your SSH server</title>
      <link>https://www.naushad.co.uk/autoblock-ips-that-do-a-dictionary-attack-on-your-ssh-server/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/autoblock-ips-that-do-a-dictionary-attack-on-your-ssh-server/</guid>
      <pubDate>Thu, 05 Oct 2017 19:41:25 +0000</pubDate>
      <description></description>
    </item>
    <item>
      <title>Google Safe Browsing?</title>
      <link>https://www.naushad.co.uk/google-safe-browsing/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/google-safe-browsing/</guid>
      <pubDate>Tue, 26 Sep 2017 19:46:51 +0000</pubDate>
      <description>Why is Ubuntu desktop download (17.04) redirecting me to a supposedly known malicious domain/mirror? Google Safe Browsing recently detected malware on mirror.scalabledns.com . Websites that are normally safe are sometimes infected with malware. Read More: https://transparencyreport.google.com/safe-browsing/search?url=http:%2F%2Fmirror.scalabledns.com%2Fubuntu-releases%2F17.04%2Fubuntu-17.04-deskto</description>
    </item>
    <item>
      <title>Blocking Tor proxy users to your Linux server</title>
      <link>https://www.naushad.co.uk/blocking-tor-proxy-users-to-your-linux-server/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/blocking-tor-proxy-users-to-your-linux-server/</guid>
      <pubDate>Sun, 10 Sep 2017 19:59:04 +0000</pubDate>
      <description></description>
    </item>
    <item>
      <title>GDPR will require 28,000 DPOs</title>
      <link>https://www.naushad.co.uk/gdpr-will-require-28000-dpos/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/gdpr-will-require-28000-dpos/</guid>
      <pubDate>Thu, 24 Aug 2017 22:19:22 +0000</pubDate>
      <description>[pdfviewer width=”600px” height=”849px” beta=”true/false”]https://www.naushad.co.uk/pdf/library/EUR_0616_ezine_19pp.pdf[/pdfviewer]</description>
    </item>
    <item>
      <title>CCISO Table of Contents</title>
      <link>https://www.naushad.co.uk/cciso-table-of-contents/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/cciso-table-of-contents/</guid>
      <pubDate>Mon, 21 Aug 2017 22:03:17 +0000</pubDate>
      <description>[pdfviewer width=”600px” height=”849px” beta=”true/false”]https://www.naushad.co.uk/pdf/library/CCISO-Table-of-Contents.pdf[/pdfviewer]</description>
    </item>
    <item>
      <title>Discover NMAP</title>
      <link>https://www.naushad.co.uk/nmap/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/nmap/</guid>
      <pubDate>Mon, 29 May 2017 16:30:43 +0000</pubDate>
      <description>Nmap is a great tool for discovering the network services and ports that your server is exposing to the network. In this guide, we will discuss some basic information, network scanning and advanced techniques covers how to use one of the most powerful and flexible network scanners available. 1 NMAP Flags……………………………………………………….. 2 Common Nmap Uses………………………………………………….. 3 Scan Types…………………………………………………</description>
    </item>
    <item>
      <title>GCHQ Certified Cyber Incident Planning &amp; Response</title>
      <link>https://www.naushad.co.uk/gchq-certified-cyber-incident-planning-response/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/gchq-certified-cyber-incident-planning-response/</guid>
      <pubDate>Sun, 28 May 2017 14:08:05 +0000</pubDate>
      <description>The recent WannaCry ransomware attack not only affected computers and billboards but actually impacted human life on a mass scale as hundreds of operations had to be delayed or cancelled. Organisations continue to suffer from external and internal attacks yet Cyber Incident Management is an afterthought in most companies. Is your organisation prepared to respond to a data breach? Questions you may</description>
    </item>
    <item>
      <title>Stop Blaming Russia &amp; China for all Cyber Attacks</title>
      <link>https://www.naushad.co.uk/stop-blaming-russia-china-for-all-cyber-attacks/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/stop-blaming-russia-china-for-all-cyber-attacks/</guid>
      <pubDate>Sun, 28 May 2017 13:31:52 +0000</pubDate>
      <description>Cyber-attacks can originate from anywhere, but there appears to be an unabated trend of pointing the finger on either “sophisticated attackers” or, more blatantly, naming and blaming nation-states like Russia, China and now North Korea (alright, maybe even Iran). The truth about attribution (who is the attacker) is often overlooked for something more dramatic, especially in situations where sensit</description>
    </item>
    <item>
      <title>NSA wasn’t creating these exploits to act as proof-of-concepts</title>
      <link>https://www.naushad.co.uk/nsa-wasnt-creating-these-exploits-to-act-as-proof-of-concepts/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/nsa-wasnt-creating-these-exploits-to-act-as-proof-of-concepts/</guid>
      <pubDate>Sun, 16 Apr 2017 10:08:10 +0000</pubDate>
      <description>In particular, one thing that perfectly ties Snowden’s latest documents with this toolkit is a note of tracking an exploit through a 16-character string (ace02468bdf13579) which happens to be found in the code of one exploit from the collection, called SECONDDATE. Previously leaked NSA documents painted a picture of such exploits infecting millions of PCs, so it’s clear that an exploit like SECOND</description>
    </item>
    <item>
      <title>Most 2FA Solutions are Insecure, Is Yours One of them?</title>
      <link>https://www.naushad.co.uk/most-2fa-solutions/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/most-2fa-solutions/</guid>
      <pubDate>Thu, 02 Mar 2017 19:56:18 +0000</pubDate>
      <description>Everyone knows two-factor authentication right? or do you just know how to use it? Something you know and something you own is a phrase we can all recite but very few actually understand two-factor authentication and its true benefits. How it works, why two solutions are not alike or what to look for in a true secure solution are just some of the conversation topics covered in this webinar. Full V</description>
    </item>
    <item>
      <title>PhD in CyberSecurity</title>
      <link>https://www.naushad.co.uk/phd-in-cybersecurity/</link>
      <guid isPermaLink="true">https://www.naushad.co.uk/phd-in-cybersecurity/</guid>
      <pubDate>Mon, 30 Jan 2017 11:02:29 +0000</pubDate>
      <description>Research Interests: Computer and Network Security, Authentication protocols and Cryptography, VoIP Security and QoS, Secure protocol(s) implementation and testing for real-time traffic, Trust and security issues in Cloud environments.</description>
    </item>
  </channel>
</rss>
