Appendix C: References and Further Reading¶
The sources below are cited across the seven parts of this handbook, grouped by type for easier navigation.
Standards and Frameworks¶
- OWASP Smart Contract Security Testing Guide (SCSTG) / Smart Contract Weakness Enumeration (SCWE)
- OWASP Smart Contract Security Verification Standard (SCSVS)
- OWASP Access Control Cheat Sheet
- OWASP Authentication Cheat Sheet
- OWASP API Security Top 10, API4:2023 Unrestricted Resource Consumption
- OWASP Top 10 CI/CD Security Risks
- NIST CSF 2.0, ID.AM (Asset Management)
- NIST SP 800-53 Rev. 5, AC-6 (Least Privilege)
- NIST SP 800-53 Rev. 5, PS-4 (Personnel Termination)
- NIST SP 800-63B, Digital Identity Guidelines (Rev. 3)
- NIST SP 800-63B, Digital Identity Guidelines (Rev. 4)
- NIST SP 800-207, Zero Trust Architecture
- NIST SP 800-207, Zero Trust Architecture (PDF)
- NIST SP 800-162, Guide to Attribute Based Access Control (ABAC)
- NIST SP 1800-35, Implementing a Zero Trust Architecture
- NIST SP 800-41 Rev. 1, Guidelines on Firewalls and Firewall Policy
- NIST SP 800-52 Rev. 2, Guidelines for TLS Implementations
- NIST SP 800-81 Rev. 3, Secure Domain Name System Deployment Guide
- NIST SP 800-92, Guide to Computer Security Log Management
- CISA Zero Trust Maturity Model v2.0
- CISA Known Exploited Vulnerabilities (KEV) Catalog
- CISA Binding Operational Directive 18-01, Enhance Email and Web Security
- CISA Binding Operational Directive 22-01, Reducing the Risk of Known Exploited Vulnerabilities
- CISA, Insider Threat Mitigation
- CIS Benchmarks
- CIS Controls
- CIS Control 1, Inventory and Control of Enterprise Assets
- CIS Control 4, Secure Configuration of Enterprise Assets and Software
- CIS Control 8, Audit Log Management
- MITRE ATT&CK, Network Denial of Service (T1498)
- MITRE ATT&CK, Detection Strategy for T1498
- MITRE AADAPT Cyber Threat Framework for Digital Assets
- FIDO Alliance, FIDO2
- W3C Web Authentication (WebAuthn) Level 3
- AWS Shared Responsibility Model
- OMB Memorandum M-21-31, Improving the Federal Government's Investigative and Remediation Capabilities
- RFC 4033, DNS Security Introduction and Requirements
- RFC 4033, DNS Security Introduction and Requirements
- RFC 4034, Resource Records for the DNS Security Extensions
- RFC 4035, Protocol Modifications for the DNS Security Extensions
- RFC 4255, Using DNS to Securely Publish SSH Key Fingerprints
- RFC 4255, Using DNS to Securely Publish SSH Key Fingerprints
- RFC 4509, Use of SHA-256 in DNSSEC Delegation Signer (DS) Resource Records
- RFC 6376, DomainKeys Identified Mail (DKIM) Signatures
- RFC 6376, DomainKeys Identified Mail (DKIM) Signatures
- RFC 6594, Use of SHA-256/ECDSA in SSHFP Resource Records
- RFC 6698, DNS-Based Authentication of Named Entities (DANE) TLSA
- RFC 6781, DNSSEC Operational Practices, Version 2
- RFC 7208, Sender Policy Framework (SPF)
- RFC 7208, Sender Policy Framework (SPF)
- RFC 7479, Using Ed25519 in SSHFP Resource Records
- RFC 7489, Domain-based Message Authentication, Reporting and Conformance (DMARC)
- RFC 7489, Domain-based Message Authentication, Reporting and Conformance (DMARC)
- RFC 8446, The Transport Layer Security (TLS) Protocol Version 1.3
- RFC 8624, Algorithm Implementation Requirements for DNSSEC
- RFC 8659, DNS Certification Authority Authorization (CAA) Resource Record
- RFC 8659, DNS Certification Authority Authorization (CAA) Resource Record
- RFC 8945, Secret Key Transaction Authentication for DNS (TSIG)
- RFC 9162, Certificate Transparency Version 2.0
- RFC 9989, DMARC (updated multi-document specification)
Incidents and Case Studies¶
- Codecov Bash Uploader compromise (January 31 to April 1, 2021)
- AppSecco, SSRF, privileged AWS keys, and the Capital One breach
- Cloudflare, defending the internet: blocking a monumental 7.3 Tbps DDoS
- CoinMarketCap Academy, Infura outage and decentralization concerns
- Cointelegraph, Manta Network DDoS attack amid exchange listing
- Cybernews, NCX exchange data leak exposes wallets
- Cybernews, Squarespace DNS hijack targets crypto domains
- Decrypt, DNS attacks driving wallet-drainer redirects on DeFi protocols
- Decrypt, Curve Finance DNS record attack
- Decrypt, MetaMask and Ethereum apps down in Infura outage
- Electrek, Tesla cloud hijacked by cryptomining hackers
- Wikipedia, Knight Capital Group trading-code deployment failure
- GitHub Security Advisory GHSA-v9jh-j8px-98vq (CVE-2023-42319, Geth GraphQL DoS)
- Krebs on Security, GoDaddy employees used in attacks on cryptocurrency services
- Offchain Labs, post-mortem report on the May 2023 Ethereum mainnet finality incident
- Palo Alto Networks Unit 42, "Leaky Vessels" container escape vulnerabilities
- rekt.news, Curve Finance
- Okta Security, root cause analysis of the October 2023 support system breach
- TechCrunch, Vercel confirms security incident after breach at Context AI
- Vercel incident bulletin, April 2026 security incident
- BleepingComputer, DNS hijacks target crypto platforms registered with Squarespace
- BleepingComputer, hackers stole over $20 million from misconfigured Ethereum clients (June 2018)
- CCN, AWS outage takes down Coinbase, Robinhood, Venmo and other platforms
- CCN, Solana survives 6 Tbps DDoS attack amid Sui downtime
- CertiK, BGP hijacking and the $1.9M KLAYswap attack
- CNBC, Coinbase says hackers bribed staff to steal customer data
- Coinbase, protecting our customers and standing up to extortionists
- CoinDesk, BadgerDAO reveals details of how it was hacked for $120M
- CoinDesk, $150K stolen from MyEtherWallet users in DNS server hijacking (April 2018)
- CoinDesk, Compound Finance site compromised in phishing attack
- CoinDesk, AWS outage halts some crypto apps
- Dark Reading, Uber breach via external contractor MFA bombing attack
- Fastly, summary of the June 8 outage
- Halborn, the BadgerDAO hack explained (December 2021)
- The Block, Curve Finance's front end targeted in DNS attack
- The Block, Ethereum infrastructure provider Infura is down
- ThousandEyes, Amazon Route 53 DNS and BGP hijack analysis
- ThousandEyes, inside the Fastly outage and lessons learned
- Uber, 2016 data incident disclosure (newsroom)
Tools and Documentation¶
- Cloudflare, how DNSSEC works
- GitHub Docs, security hardening your deployments with OpenID Connect (OIDC)
- Open Policy Agent (OPA)
- Open Policy Agent (OPA) documentation and Rego
- Red Hat Enterprise Linux 9, auditing the system
- tfsec check library documentation
- Chainstack, RPC security and access rules
- HashiCorp Cloud Platform, Vault Secrets auto-rotation
- AWS IAM, security best practices
- OpenZeppelin Defender documentation
- Web3Signer, slashing protection
- ethereum.org, client diversity
- Geth (go-ethereum), security documentation
- OpenZeppelin Monitor (GitHub)
- OpenZeppelin Relayer (GitHub)
- Gitleaks (GitHub)
- Cartography (GitHub)
- Prowler (GitHub)
- driftctl (GitHub)
- Steampipe AWS plugin (GitHub)
- ICANNWiki, Domain Locking
- NHI Management Group, break-glass account glossary
- OpenBao
- Prowler
- SPIFFE
- SPIRE, about the project
- Suricata
- Tailscale
- Trivy, IaC scanning coverage
- TruffleHog
- Ubuntu, hardening automation for CIS benchmarks on Ubuntu 24.04 LTS
- Checkov
- Conftest
- HashiCorp Sentinel
- Pulumi CrossGuard documentation
- QuickNode, Ethereum endpoint security
- Red Hat, what is a configuration management database (CMDB)
- Tenderly, Alerting and Monitor products
- WireGuard
- Yubico, phishing-resistant MFA glossary
- Zeek
- Forta
- CyberArk, what is just-in-time access
Further Reading¶
- Cloudflare, Q3 2025 DDoS threat report
- Cloudflare, Q4 2025 DDoS threat report
- CryptoSlate, French regulator calls out DeFi centralization as cloud providers fall
- DNSChkr, DNSSEC adoption 2026
- PowerDMARC, Google and Yahoo bulk sender email authentication requirements
- Mailgun, state of email deliverability: the "Yahoogle" bulk sender rules
- 7BlockLabs, Ethereum/Erigon/Geth archive and full node disk size comparison (2026)
- BeyondTrust, guide to just-in-time privileged access management
- CyberArk, 2025 State of Machine Identity Security Report
- Figment, distributed validator technology and infrastructure resilience
- HashiCorp, rotated vs. dynamic secrets: which should you use
- Latacora, OIDC workload identity on AWS
- technologychecker.io, DNSSEC adoption
- AWS Security Blog, defense in depth: open firewalls, reverse proxies, SSRF, and the EC2 instance metadata service