# Endpoint security

Published articles for Endpoint security.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## CrowdStrike Accelerates Real-Time Data Classification with On-Device AI

DevFeed: [CrowdStrike Accelerates Real-Time Data Classification with On-Device AI](<https://devfeed.tech/articles/crowdstrike-accelerates-real-time-data-classification-with-on-device-ai-31503.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/crowdstrike-accelerates-real-time-data-classification-with-on-device-ai/>)

Author: Lior Ribak

Published: 2026-09-17T01:38:53.400452Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [On-device AI](<https://devfeed.tech/topics/on-device-ai.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>), [Language models](<https://devfeed.tech/topics/language-models.md>), [Endpoint security](<https://devfeed.tech/topics/endpoint-security.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [intel](<https://devfeed.tech/topics/intel.md>)

Tags: [data-security](<https://devfeed.tech/tags/data-security.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [intel](<https://devfeed.tech/tags/intel.md>), [language-models](<https://devfeed.tech/tags/language-models.md>), [npu](<https://devfeed.tech/tags/npu.md>), [on-device-ai](<https://devfeed.tech/tags/on-device-ai.md>)

### AI overview

CrowdStrike and Intel introduced a Falcon Data Security capability that uses language models running on-device on dedicated AI hardware to classify sensitive data. The article explains that local inference is intended to avoid cloud latency and keep sensitive customer data on the endpoint while meeting real-time protection requirements.

### Source excerpt

CrowdStrike worked closely with Intel to introduce a new capability in Falcon Data Security that classifies sensitive data using language models that run on-device using dedicated hardware for AI. Learn more!

## How to Build an Endpoint Data Loss Prevention Strategy for Your Development Team

DevFeed: [How to Build an Endpoint Data Loss Prevention Strategy for Your Development Team](<https://devfeed.tech/articles/how-to-build-an-endpoint-data-loss-prevention-strategy-for-your-development-team-26899.md>)

Original publisher: [Read original article](<https://www.freecodecamp.org/news/build-an-endpoint-data-loss-prevention-strategy-for-your-dev-team/>)

Author: Alex Tray

Published: 2026-09-15T21:03:09Z

Content type: tutorial

Language: en

Sources: [freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More](<https://devfeed.tech/sources/freecodecamp-programming-tutorials-python-javascript-git-more.md>)

Topics: [data loss prevention](<https://devfeed.tech/topics/data-loss-prevention.md>), [Development](<https://devfeed.tech/topics/development.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [cybersecurityawareness](<https://devfeed.tech/tags/cybersecurityawareness.md>), [data-loss-prevention](<https://devfeed.tech/tags/data-loss-prevention.md>), [data-protection](<https://devfeed.tech/tags/data-protection.md>), [database](<https://devfeed.tech/tags/database.md>), [development](<https://devfeed.tech/tags/development.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [hardcoded-credentials](<https://devfeed.tech/tags/hardcoded-credentials.md>), [it-security](<https://devfeed.tech/tags/it-security.md>), [net-conf](<https://devfeed.tech/tags/net-conf.md>), [remote-access](<https://devfeed.tech/tags/remote-access.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>), [web-development](<https://devfeed.tech/tags/web-development.md>)

### AI overview

A tutorial for development teams on building endpoint data loss prevention strategies. It covers auditing laptops for secrets and sensitive data, removing unnecessary copies, rotating exposed credentials, and establishing access controls.

### Source excerpt

A developer's laptop holds more sensitive data than most people realize: API keys, database credentials, staging environment secrets, and sometimes entire copies of production data pulled down "just f

## The hidden work of modernizing Malwarebytes

DevFeed: [The hidden work of modernizing Malwarebytes](<https://devfeed.tech/articles/the-hidden-work-of-modernizing-malwarebytes-8434.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/inside-malwarebytes/2026/09/the-hidden-work-of-modernizing-malwarebytes>)

Author: Anna Tukhtarova

Published: 2026-09-04T17:15:42Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [.NET](<https://devfeed.tech/topics/net.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>)

Tags: [diagnostics](<https://devfeed.tech/tags/diagnostics.md>), [drivers](<https://devfeed.tech/tags/drivers.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [inside-malwarebytes](<https://devfeed.tech/tags/inside-malwarebytes.md>), [migration](<https://devfeed.tech/tags/migration.md>), [modernization](<https://devfeed.tech/tags/modernization.md>), [net](<https://devfeed.tech/tags/net.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains Malwarebytes' migration of its managed Windows components to .NET 10 and why runtime and dependency upgrades require security-feature-level rigor in endpoint software.

### Source excerpt

Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.

## The security attack that hid inside your observability data

DevFeed: [The security attack that hid inside your observability data](<https://devfeed.tech/articles/the-security-attack-that-hid-inside-your-observability-data-4836.md>)

Original publisher: [Read original article](<https://www.elastic.co/blog/security-attack-hiding-in-observability-data>)

Author: Roberto Arico

Published: 2026-09-03T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Blog - Elasticsearch, Kibana, and ELK Stack](<https://devfeed.tech/sources/elastic-blog-elasticsearch-kibana-and-elk-stack.md>)

Topics: [SIEM, Security, Observability](<https://devfeed.tech/topics/siem-security-observability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [cpu](<https://devfeed.tech/topics/cpu.md>)

Tags: [cost](<https://devfeed.tech/tags/cost.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [endpoint-security-observability-security-siem-log-analytics](<https://devfeed.tech/tags/endpoint-security-observability-security-siem-log-analytics.md>), [observability](<https://devfeed.tech/tags/observability.md>), [security](<https://devfeed.tech/tags/security.md>), [security-analytics-security-compliance-threat-hunting-tool-consolidation-agentic-ai-alerting](<https://devfeed.tech/tags/security-analytics-security-compliance-threat-hunting-tool-consolidation-agentic-ai-alerting.md>)

### AI overview

The article explains how separating observability and security platforms can conceal threats such as cryptominers, duplicate data costs, and prevent teams from seeing the full operational and security picture.

### Source excerpt

Your ops team sees a CPU spike. Your security team sees nothing. The cryptominer runs for six hours. Avoid duplication of cost and time and see how a unified observability and security platform with grounded AI closes the gap.

## Bring your security stack into Edge for Business -- with support for more partners

DevFeed: [Bring your security stack into Edge for Business -- with support for more partners](<https://devfeed.tech/articles/bring-your-security-stack-into-edge-for-business-with-support-for-more-partners-4250.md>)

Original publisher: [Read original article](<https://blogs.windows.com/msedgedev/2026/08/04/bring-your-security-stack-into-edge-for-business-with-support-for-more-partners/>)

Author: Microsoft Edge Team

Published: 2026-08-04T16:00:24Z

Content type: article

Language: en

Sources: [Microsoft Edge Blog](<https://devfeed.tech/sources/microsoft-edge-blog.md>)

Topics: [Edge for Business](<https://devfeed.tech/topics/edge-for-business.md>), [browser](<https://devfeed.tech/topics/browser.md>), [Cisco Secure Access](<https://devfeed.tech/topics/cisco-secure-access.md>), [Security](<https://devfeed.tech/topics/security.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [browser](<https://devfeed.tech/tags/browser.md>), [cisco-secure-access](<https://devfeed.tech/tags/cisco-secure-access.md>), [edge-for-business](<https://devfeed.tech/tags/edge-for-business.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [integrations](<https://devfeed.tech/tags/integrations.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

This Microsoft Edge Blog article announces expanded Edge for Business security connector integrations. It highlights Cisco Secure Access, Tanium, and Clever integrations for browser-based security, telemetry, endpoint visibility, compliance validation, data protection, AI guardrails, and streamlined MFA in education environments.

### Source excerpt

At a glance Edge for Business security connectors extend your security tools into the browser, so you gain visibility and enforcement where work happens. This update adds new partner integrations, including Cisco Secure Access, The post Bring your security stack into Edge for Business -- with support for more partners appeared first on Microsoft Edge Blog.

## Securing the future of AI agents

DevFeed: [Securing the future of AI agents](<https://devfeed.tech/articles/securing-the-future-of-ai-agents-6240.md>)

Original publisher: [Read original article](<https://deepmind.google/blog/securing-the-future-of-ai-agents/>)

Author: Rohin Shah; Four Flynn

Published: 2026-06-16T15:46:31Z

Content type: article

Language: en

Sources: [Google DeepMind News](<https://devfeed.tech/sources/google-deepmind-news.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Endpoint security](<https://devfeed.tech/topics/endpoint-security.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [google](<https://devfeed.tech/tags/google.md>), [knowledge-base](<https://devfeed.tech/tags/knowledge-base.md>), [model](<https://devfeed.tech/tags/model.md>), [prompt-injection](<https://devfeed.tech/tags/prompt-injection.md>), [responsibility-safety](<https://devfeed.tech/tags/responsibility-safety.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article presents Google's AI Control Roadmap for securing internal systems against increasingly capable but imperfectly aligned AI agents. It combines model alignment with defense-in-depth safeguards such as sandboxing, endpoint security, prompt injection resistance, behavior-based permissions, and threat modeling based on adversary tactics and techniques.

### Source excerpt

Securing internal systems with an AI Control Roadmap, combining traditional safeguards and real-time monitoring.

## Chainguard customers safe from Mini Shai-Hulud worm targeting @redhat-cloud-services npm packages with 100K+ weekly downloads

DevFeed: [Chainguard customers safe from Mini Shai-Hulud worm targeting @redhat-cloud-services npm packages with 100K+ weekly downloads](<https://devfeed.tech/articles/chainguard-customers-safe-from-mini-shai-hulud-worm-targeting-redhat-cloud-services-npm-packages-with-100k-weekly-downloads-12938.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-customers-safe-from-mini-shai-hulud-worm-targeting-redhat-cloud-services-npm-packages>)

Published: 2026-06-01T00:00:00Z

Content type: news

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [npm packages](<https://devfeed.tech/topics/npm-packages.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [obfuscation](<https://devfeed.tech/topics/obfuscation.md>), [payload](<https://devfeed.tech/topics/payload.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>)

Tags: [chainguard-actions](<https://devfeed.tech/tags/chainguard-actions.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [malware](<https://devfeed.tech/tags/malware.md>), [mini-shai-hulud](<https://devfeed.tech/tags/mini-shai-hulud.md>), [npm](<https://devfeed.tech/tags/npm.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [packages](<https://devfeed.tech/tags/packages.md>), [payload](<https://devfeed.tech/tags/payload.md>), [red-hat](<https://devfeed.tech/tags/red-hat.md>), [redhat-cloud-services](<https://devfeed.tech/tags/redhat-cloud-services.md>), [security](<https://devfeed.tech/tags/security.md>), [shai-hulud](<https://devfeed.tech/tags/shai-hulud.md>), [tokens](<https://devfeed.tech/tags/tokens.md>)

### AI overview

The article reports that the Mini Shai-Hulud worm compromised more than 90 @redhat-cloud-services npm packages through a hijacked GitHub account and GitHub Actions OIDC trusted publishing. The worm spreads tampered packages and malicious workflows, executes an obfuscated payload during installation, and steals cloud, Vault, GitHub, npm, and CI credentials. Chainguard customers using Chainguard Libraries for JavaScript and Chainguard Actions were unaffected.

### Source excerpt

A new npm worm hit 90+ Red Hat packages. Chainguard customers stayed protected by blocking install-time scripts and hardening CI/CD workflows.

## Seeking symmetry during ATT&CK® season: How to harness today's diverse analyst and tester landscape to paint a security masterpiece

DevFeed: [Seeking symmetry during ATT&CK® season: How to harness today's diverse analyst and tester landscape to paint a security masterpiece](<https://devfeed.tech/articles/seeking-symmetry-during-att-ck-season-how-to-harness-today-s-diverse-analyst-and-tester-landscape-to-paint-a-security-masterpiece-8340.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/seeking-symmetry-attck-season-harness-todays-diverse-analyst-tester-landscape-paint-security-masterpiece/>)

Author: Márk Szabó James Shepperd Ben Tudor

Published: 2025-12-10T15:03:51Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Detection engineering](<https://devfeed.tech/topics/detection-engineering.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [analysts](<https://devfeed.tech/tags/analysts.md>), [article](<https://devfeed.tech/tags/article.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [incident](<https://devfeed.tech/tags/incident.md>), [industry](<https://devfeed.tech/tags/industry.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [practitioner](<https://devfeed.tech/tags/practitioner.md>), [report](<https://devfeed.tech/tags/report.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>)

### AI overview

The article explains how security practitioners can interpret and connect cybersecurity reports and tests from analyst firms and independent testing labs. It focuses on endpoint security, including product evaluations, feature testing, broader market analyses, and assessments against known advanced adversary attacks, to support more informed protection-stack and purchasing decisions.

### Source excerpt

Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.

## Rolling out Santa without freezing productivity: Tips from securing Figma's fleet

DevFeed: [Rolling out Santa without freezing productivity: Tips from securing Figma's fleet](<https://devfeed.tech/articles/rolling-out-santa-without-freezing-productivity-tips-from-securing-figma-s-fleet-10031.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/rolling-out-santa-without-freezing-productivity/>)

Author: Aaron Osborne

Published: 2025-07-02T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Endpoint security](<https://devfeed.tech/topics/endpoint-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Credential theft](<https://devfeed.tech/topics/credential-theft.md>), [App](<https://devfeed.tech/topics/app.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Script](<https://devfeed.tech/topics/script.md>), [Extension](<https://devfeed.tech/topics/extension.md>)

Tags: [authorization](<https://devfeed.tech/tags/authorization.md>), [browser](<https://devfeed.tech/tags/browser.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [santa](<https://devfeed.tech/tags/santa.md>), [security](<https://devfeed.tech/tags/security.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Figma describes rolling out Santa, an open-source binary authorization tool, across its employees' macOS laptops to improve endpoint security without disrupting productivity. The article covers monitoring-based ruleset development, user self-service for unblocking, file access authorization for browser cookies, and a staged rollout.

### Source excerpt

We scaled Santa, an open-source binary authorization tool, across all Figmates' laptops to boost endpoint security while keeping workflows seamless. Here's how we tackled the challenges and ensured a smooth rollout.

## Designing for security and usability: Figma's modern endpoint strategy

DevFeed: [Designing for security and usability: Figma's modern endpoint strategy](<https://devfeed.tech/articles/designing-for-security-and-usability-figma-s-modern-endpoint-strategy-9715.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/figmas-modern-endpoint-strategy/>)

Author: Lamarr Henry

Published: 2025-04-04T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Security](<https://devfeed.tech/topics/security.md>), [Usability](<https://devfeed.tech/topics/usability.md>), [User experience (UX)](<https://devfeed.tech/topics/ux.md>), [macOS](<https://devfeed.tech/topics/macos.md>)

Tags: [browsers](<https://devfeed.tech/tags/browsers.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware-prevention](<https://devfeed.tech/tags/malware-prevention.md>), [security](<https://devfeed.tech/tags/security.md>), [usability](<https://devfeed.tech/tags/usability.md>), [ux](<https://devfeed.tech/tags/ux.md>)

### AI overview

Figma describes an endpoint security strategy designed around usability. Its Endpoint Security Baseline uses controls such as browser updates, disabled remote login, and prevention of kernel extensions to protect corporate devices while keeping security self-serve and minimizing employee friction.

### Source excerpt

At Figma, security doesn't have to slow you down. We've designed our corporate endpoint security with UX in mind, making it seamless and self-serve.

## What caused 8.5 million Windows computers to crash in the CrowdStrike Falcon incident

DevFeed: [What caused 8.5 million Windows computers to crash in the CrowdStrike Falcon incident](<https://devfeed.tech/articles/here-s-what-really-caused-8-5-million-computers-to-crash-17967.md>)

Original publisher: [Read original article](<https://newsletter.betterstack.com/p/heres-what-really-caused-85-million>)

Author: Richard Oliver Bray

Published: 2024-08-28T13:00:58Z

Content type: article

Language: en

Sources: [Hacking Scale by Better Stack](<https://devfeed.tech/sources/hacking-scale-by-better-stack.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Machine learning](<https://devfeed.tech/topics/machine-learning.md>)

Tags: [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This article explains how a CrowdStrike Falcon software issue caused 8.5 million Windows machines to crash on July 19, 2024. It describes Falcon's endpoint-security architecture, including cloud servers, machine-learning analysis, threat intelligence, and kernel-level sensors.

### Source excerpt

How one security product crippled the world because of bad programming

## Cybersecurity hygiene in co-working spaces: A practical guide

DevFeed: [Cybersecurity hygiene in co-working spaces: A practical guide](<https://devfeed.tech/articles/cybersecurity-hygiene-in-co-working-spaces-a-practical-guide-13018.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/cybersecurity-hygiene-in-co-working-spaces-a-practical-guide>)

Published: 2024-01-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Endpoint security](<https://devfeed.tech/topics/endpoint-security.md>), [network security](<https://devfeed.tech/topics/network-security.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Incident response](<https://devfeed.tech/topics/incident-response.md>), [Git](<https://devfeed.tech/topics/git.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [USB](<https://devfeed.tech/topics/usb.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [git](<https://devfeed.tech/tags/git.md>), [github-vulnerability](<https://devfeed.tech/tags/github-vulnerability.md>), [guide](<https://devfeed.tech/tags/guide.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-security](<https://devfeed.tech/tags/kubernetes-security.md>), [least-privilege](<https://devfeed.tech/tags/least-privilege.md>), [network-security](<https://devfeed.tech/tags/network-security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [usb](<https://devfeed.tech/tags/usb.md>)

### AI overview

A practical guide to cybersecurity hygiene in co-working spaces. It covers Kubernetes security, Git repository protection, device safety, layered defenses, incident response, and security awareness training.

### Source excerpt

Navigate the cybersecurity landscape in shared work environments with essential tips on device safety and incident response.

## Unmanaged Code Execution with .NET Dynamic PInvoke

DevFeed: [Unmanaged Code Execution with .NET Dynamic PInvoke](<https://devfeed.tech/articles/unmanaged-code-execution-with-net-dynamic-pinvoke-20504.md>)

Original publisher: [Read original article](<https://bohops.com/2022/04/02/unmanaged-code-execution-with-net-dynamic-pinvoke/>)

Author: bohops

Published: 2022-04-02T16:45:49Z

Content type: tutorial

Language: en

Sources: [Bohops](<https://devfeed.tech/sources/bohops.md>)

Topics: [.NET](<https://devfeed.tech/topics/net.md>), [C#](<https://devfeed.tech/topics/csharp.md>), [Code](<https://devfeed.tech/topics/code.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>)

Tags: [c-sharp](<https://devfeed.tech/tags/c-sharp.md>), [code](<https://devfeed.tech/tags/code.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [interop](<https://devfeed.tech/tags/interop.md>), [native](<https://devfeed.tech/tags/native.md>), [net](<https://devfeed.tech/tags/net.md>), [security](<https://devfeed.tech/tags/security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

This developer article explains classic P/Invoke in .NET and introduces Dynamic PInvoke, a technique for calling and executing native code differently from managed code. It discusses limitations, .NET executable structure, and possible defensive-evasion implications.

### Source excerpt

Yes, you read that correctly - "Dynamic Pinvoke" as in "Dynamic Platform Invoke" Background Recently, I was browsing through Microsoft documentation and other blogs to gain a better understanding of .NET dynamic types and objects. I've always found the topic very interesting mainly due to its relative obscurity and the offensive opportunities for defensive evasion. [...]

## Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion

DevFeed: [Investigating .NET CLR Usage Log Tampering Techniques For EDR Evasion](<https://devfeed.tech/articles/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion-20500.md>)

Original publisher: [Read original article](<https://bohops.com/2021/03/16/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion/>)

Author: bohops

Published: 2021-03-16T04:08:58Z

Content type: article

Language: en

Sources: [Bohops](<https://devfeed.tech/sources/bohops.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [.NET](<https://devfeed.tech/topics/net.md>), [Security](<https://devfeed.tech/topics/security.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>)

Tags: [code](<https://devfeed.tech/tags/code.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [logging](<https://devfeed.tech/tags/logging.md>), [net](<https://devfeed.tech/tags/net.md>), [process](<https://devfeed.tech/tags/process.md>), [processes](<https://devfeed.tech/tags/processes.md>), [security](<https://devfeed.tech/tags/security.md>), [uncategorized](<https://devfeed.tech/tags/uncategorized.md>)

### AI overview

This article examines how .NET CLR Usage Logs can help defenders detect and investigate .NET execution, including assembly injection into process memory. It describes how the CLR creates Usage Log files and discusses tampering techniques intended to evade endpoint detection, along with monitoring opportunities for identifying that tampering.

### Source excerpt

Introduction In recent years, there have been numerous published techniques for evading endpoint security solutions and sources such as A/V, EDR and logging facilities. The methods deployed to achieve the desired result usually differ in sophistication and implementation, however, effectiveness is usually the end goal (of course, with thoughtful consideration of potential tradeoffs). Defenders can [...]