Microsoft Defender research details a multi-stage intrusion that began with a compromised internet-facing firewall appliance and pivoted to an internal Linux host, where a vulnerable SaaS application was exploited to run authentication attacks. https://t.co/C4NfRj0QBT
This activity reflects a broader pattern where internet-facing edge devices are used as entry points to access internal systems and identities. Because they’re often exposed, lightly monitored, and implicitly trusted, compromising these devices provides threat actors a durable, low-visibility foothold.
The incident highlights how threat actors move from infrastructure compromise to identity abuse across environments. Defenders should prioritize visibility across edge devices, internal applications, and identity systems to better assess and disrupt attack paths early.
A Google Cloud engineer just showed how to build a full app with Claude from scratch
he spent 26 minutes showing exactly what one person with Claude can do, completely free
worth more than any $500 vibe-coding course
here's what he covers:
> raw idea to deployed app in a single session
> using Claude as the entire engineering team
> the exact workflow they use at Google
> no big team, no prior experience needed
the people who figure out what Claude can actually do are building things everyone else thinks requires a team
that's exactly why I put together a guide on Claude features most people have no idea exist
the guide is in the article below
NeuroSploitv2 - an advanced, AI-powered penetration testing framework designed to automate and augment various aspects of offensive security operations. Leveraging the capabilities of large language models (LLMs) https://t.co/O0onfHicQH
🎁 Monthly Giveaway 🎁
Hack The Box 12-month VIP+ x1
- Follow, Like, and Retweet to join!
- Winner will be picked randomly on 3 September.
#hackthebox#giveaway#projectsekaictf
If you've been considering Investigating Windows Endpoints, someone published a new blog post comparing the course to FOR500. It's filled with great information! Check it out here: https://t.co/eI11qvPccl #DFIR
The only leadership cheat sheet you will ever need:
It’s like a whole leadership book condensed into a single page.
Based on 20+ years of experience as a leader, 100s of leadership books & resources, and 1,000s of hours coaching aspiring leaders.
This is a query that I always find useful; using Defender for Cloud Apps, find when an inbox rule is created that uses only special characters for its name, such as '..' or '...'. This continues to be common behaviour for email-based attacks like BEC - https://t.co/u9vFLEgZPJ
Five reasons why you should read our new blog on email forwarding rules in Microsoft 365 🔍🧵
https://t.co/CuYNOVwWCN
1. You'll learn the difference between the New-InboxRule and UpdateInboxRules Operation
2. Learn how to find forwarding rules without Exchange logging 🤯
Useful diagram and explanation of the order of operations for mail flow in Exchange Online Protection / Defender for Office 365 found in my MS Learn travels, including this neat visual - https://t.co/4vpeaPIxXH
Ever see sign-ins to apps in your Azure AD tenant and you are unsure if they are Microsoft apps? There is a good guide here to verify if they belong to Microsoft. It also includes a table of commonly seen first party apps - https://t.co/vEPNnbOs5a
If you haven't read the Threat Hunting Survival Guide, it is probably worth your time. While it's focused on Defender, but there are a lot of great takeaways in there with regards to hunting methodology and mindset regardless of technology - https://t.co/1NPIAKyOob