33 DaysToGo - If Basic Auth remains enabled in your tenant, your data is at risk, and so your role is to get your clients and apps off Basic Auth, move them to stronger and better options, and then secure your tenant, before we do.
The bigger the org is, the slower it can be to respond but some excellent work was done on a US holiday to get this out to our customers #follina
https://t.co/Z6UJ4RrAJl
https://t.co/dIC2NXFMJu
@wgoderis@DebugPrivilege@SecGuru_OTX We're aware (as you can imagine). We know the root cause is the subject name is incorrectly used to map the cert to a machine account in AD rather than the DNSHostname in the subject alternative name on DCs that have installed 5b and we're working it.
Spring4Shell has generated lots of questions.
There are detections and hunting to be done in this article. But overall the exploit attempts really are low
Microsoft is currently assessing the impact associated with the Spring Framework for Java vulnerabilities. Sharing our analysis and guidance here: https://t.co/2mA1r82gMl
Enabled MFA? Yay! But threat actors who get past the first gate can wear down users with MFA requests. Expose it for where it’s from https://t.co/z1LVmwSaVG
Just how do you get into a container? How do you troubleshoot apps running in containers? No RDP here. It's more like Server Core only it's not. You'll get the idea.
https://t.co/8UQHELDhKK
User has access. But how long should user keep that access? What if their account is revoked/deleted, pwd changes, their location changes or their risk level increases? Continuous Access Evaluation in AAD is now enabled for all tenants https://t.co/bfTWthREiH
We have observed a China-based ransomware operator that we’re tracking as DEV-0401 exploiting the CVE-2021-44228 vulnerability in Log4j 2 (aka #log4shell) targeting internet-facing systems running VMWare Horizon. https://t.co/6GOdRwRTjk
On prem AD needs basic checks done every so often. CE Paul Harrison came up with some great PS scripts to to monitor known problems like any forgotten computers in the Computers container: https://t.co/lTjLigL5EC
Betty White, Y2K22, it better get better from here. 2010 and 2013 unaffected, 2016 and 2019 you have some work this morning (remember this is On Prem only)
https://t.co/LctAkZGVfC
Azure AD Password Protection provides coverage for this as well as character substitution (P@ssw0rd is normalized to password)
It also prevents admins from setting or resetting passwords to known bad/weak passwords
If you have Azure AD P1+, check it out:
https://t.co/gPdwC4SO9Q