After almost two years of non-existent Saturday’s, proud to say I have officially completed my graduate degree in a field that I am very excited about! #usfgrad#masters#cyberintelligence#commencement
In 2022 Jen Psaki was asked about claims that we were operating biolabs in Ukraine. She denied the existence of "bioweapons" programs and then called the whole thing Russian disinformation.
MagicSword now integrates LOLExfil and ExtSentry, two community intelligence sources that close two of the widest gaps in endpoint security.
⚙️LOLExfil: 200+ tools attackers use to get your data out. Blocked.
🧩ExtSentry: malicious and compromised browser extensions. Blocked.
No rules to write. No lists to maintain. Automated.
This integration is built on the work of @mthcht2, threat hunter, detection engineer, and the mind behind LOLExfil, ExtSentry, ThreatHunting-Keywords, LOLC2, BADGUIDs, and more. Projects like these represent the best of community-driven security research: freely available, actively maintained, and built for operational use.
Why it matters: attackers rarely show up with suspicious software. They use the same tools already installed on the system, file transfer utilities, cloud backup clients, remote access tools, browser extensions with broad permissions. The same tools IT teams use every day. In December 2024, a single phishing campaign compromised 35 Chrome extensions and exposed 2.6 million users. None of it looked malicious. Now it gets blocked.
👉 https://t.co/Og7NmnjUHa
🚨 BREAKING: CPUID has been compromised as users were served malicious HWMonitor and CPU-Z downloads through the official website.
The malware was hosted on r2[.]dev.
The setup application contains Cyrillic (Russian) characters and displays HWiNFO instead of HWMonitor.
Taken from the Stryker Handala / Intune Detection Pack v2
"Check PIM role settings for Global Administrator, Intune Administrator, and Cloud Device Administrator. If you see only the "Require Azure MFA" checkbox and no Authentication Context configured, you have the same gap that enabled the Stryker wipe. Configure Authentication Context with FIDO2 or certificate-based auth today.
Enable Intune Multi-Admin Approval for wipe, retire, and delete actions. Tenant Administration > Multi Admin Approval. Under 10 minutes. No additional licensing required.
Deploy Rule 13 (bulk wipe threshold alert). Five wipes in 15 minutes from a single identity fires the alert. Wire it to a Logic App that calls revokeSignInSessions on the triggering account via Microsoft Graph.
"
link to Detection Pack v2 blog and direct download.
Please share so others can lock down their InTune environments please
https://t.co/nLhS49kxut