Leading a team of Detection & Response Engineers at global company. Former Sr. Security Engineer and Dir. of Commercial Services @politoinc. Tweets are my own.
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: https://t.co/jD6EaGtsn3
New research from #ElasticSecurityLabs uncovers a new ClickFix campaign! Learn how attackers are using GHOSTPULSE and ARECHCLIENT2 (SECTOPRAT) in multi-stage attacks to deploy RATs and steal data. Stay informed: https://t.co/ndKdRIj76P
As one of many who has also investigated intrusions by Chinese threat actors and followed the threat intel, this captures very well what first came to mind when I first heard about today's AI news and how it already affected the US stock market.
I have a hard time recognizing or appreciating Chinese innovation when I have spent my career responding to intrusions, particularly 🇨🇳 hacks of tech & data companies while at Mandiant. For so many in infosec, it’s impossible to differentiate breakthroughs from decades of cheating & theft.
Here are some memorable quotes from my time at Mandiant (2014-2020):
🗣️ "We probably have somewhere in the order of 2,000 active investigations that are just related to the Chinese government's effort to steal information." - Christopher Wray, FBI Director, at the U.S.-China Economic and Security Review Commission, 2020
🗣️ "The Chinese government is known for using their military's cyber capabilities to hack into private U.S. tech firms. They steal I.P. and then transfer the technology to state-run companies for profit off of its development." - Rep. Matt Gaetz, at a hearing on Chinese IP theft, 2017
🗣️ "The greatest transfer of wealth in history is from the U.S. to China through cyber theft, and it's happening every single day." - Mike Rogers, NSA Director, 2015
🗣️ "There are only two types of companies in the United States: those who have been hacked by the Chinese, and those who don't know they've been hacked by the Chinese." - Robert Mueller, FBI Director, 2014
NEW: Data-loss prevention startup Cyberhaven said hackers took over its official Chrome extension, pushing a malicious version designed to steal passwords and session tokens.
.@jaimeblascob told us Cyberhaven may be one several other hacked extensions.
https://t.co/ywjlpcLTaT
FortiManager cases are incoming. We see the exact same TTPs as outlined by Mandiant in their blog post [1].
"Once the threat actor successfully exploited the FortiManager, their unknown Fortinet device appeared in the FortiManager console."
And, most importantly:
"Organizations that may have their FortiManager exposed to the internet should conduct a forensic investigation immediately."
Do it now! ⏰
[1] https://t.co/1LuR60gABN
SEC just fined 4 cyber firms millions for deliberately misleading the public about the infamous SolarWinds cyber attack incident in 2020. Unisys, CheckPoint, Mimecast, Avaya failed to admit they too had been breached in the huge espionage attack allegedly carried about by Russia
The latest Microsoft Digital Defense Report is available, covering trends and insights about the cyber threat landscape, taken from Microsoft’s unique perspective, to best practices for securing your environment - https://t.co/58wPAg2c9R
Happy #cybersecurityawareness Month! To celebrate, we’re excited to release the 2024 @elastic Global Threat Report. Explore the top threats being deployed and review our threat landscape forecasts.
Download the 2024 Elastic Global Threat Report → https://t.co/JcjSLwajsn
Researchers found a flaw in a Kia web portal that let them track millions of cars, unlock doors, and start engines at will—the latest in a plague of web bugs that’s affected a dozen carmakers. https://t.co/0ugqbd8CA9
LinkedIn is now using everyone's content to train their AI tool -- they just auto opted everyone in.
I recommend opting out now (AND that orgs put an end to auto opt-in, it's not cool)
Opt out steps: Settings and Privacy > Data Privacy > Data for Generative AI Improvement (OFF)
Okay, I've seen *a lot* of misunderstanding around this.
Microsoft *is not* changing kernel level access for security vendors. Or, at least, it has made no announcement suggesting that.
Instead, MS is trying to convince more vendors they don't need to use kernel access.
Over the years Microsoft DART has put together an immense amount of valuable information about preventing, detecting and responding to threats, from blogs to forensic guides. They are all now available to you in one spot via their very own Ninja Hub - https://t.co/XtIbiIXKLB
With the ever-growing prominence of browser 0day exploitation threats you could make a very good argument that now would be a perfect time for Microsoft to be doubling down on investing in Application Guard for Edge (WDAG) on Windows.
Instead of, you know, killing it on Win11.☹️
We're excited to present: A new DC hacker conference designed to bring together builders, breakers, and fixers to do cool sh*t. *
Join our list to get notified when tickets go live. https://t.co/IDECUCpLTE
Microsoft has uncovered a vulnerability in ESXi hypervisors, identified as CVE-2024-37085, being exploited by threat actors to obtain full administrative permissions on domain-joined ESXi hypervisors and encrypt critical servers in ransomware attacks. https://t.co/7NUvHGrzXM