🧵 THREAD: A federal whistleblower just dropped one of the most disturbing cybersecurity disclosures I’ve ever read.
He's saying DOGE came in, data went out, and Russians started attempting logins with new valid DOGE passwords
Media's coverage wasn't detailed enough so I dug into his testimony:
Just released Cable v1.0! New changes include but aren't limited to: reading/writing DACL entries on objects, a complete reformatting of the output into a tree style, adding computer accounts as apart of an RBCD attack, and writing DONT_REQ_PREAUTH.
https://t.co/GFIZYLZkjM
Created another write-up, this time on NTLM relay attacks to LDAP(S), including details of WebClient coercion, NTLM transport vulnerabilities, and finally device takeover after achieving authentication. You can read about it on my blog :)
https://t.co/iXMAGeEpne
I spent some time today trying to write a POC for a self unpacking LNK payload.The python code is a bit convoluted, but the payload that it generates is fully functional and able to run without any external file dependencies. https://t.co/uTESiu9635
Another week, another SSLVPN RCE - this time, it's CVE-2024-3400 in Palo Alto's GlobalProtect.
But, we've seen no public analysis 🙁 so, allow us..
https://t.co/OBzVNi4XWl