1Y for #NotPetya. 1Y for #EternalBlues stats.
182 countries. 4.5M computers. 10% are vulnerable to #EternalBlue. 34% of networks are vulnerable. #SMBv1 is still enabled with most computers.
Check out https://t.co/8vgumLIn8y for trends by date, country, network size and more... 🎷
NEW FINDING: There's a 1 bit flag hidden in #SUNBURST DNS requests indicating whether or not the victim has been targeted and the backdoor has progressed to "stage 2" operation.
https://t.co/xxe0SoBgKU
@campuscodi@craiu@megabeets_@prevasio@Truesec - great job on sharing latest research and infected domains! 👏 I have a few more which were not mentioned till now (some are giants), and list keeps growing... Wondering about the best way to share it ethically. Thoughts?
Malicious cyber actors are using two sets of #TTPs to access protected data in the #cloud. Detect and mitigate against this activity by reviewing our latest #cybersecurity advisory: https://t.co/scmnGlM7cP
Too many unpatched #SolarWindsOrion are still live.
Indicators (html body): "SolarWinds.Logo.Footer.svg" AND ("2020.2" OR ("2019.4" AND "Orion Platform HF5"))
https://t.co/Pe51IOUe3o
https://t.co/Ly6GA4Nr1o
#SolarWinds#SolarWindsHack
Was reading about a sophisticated attack on FireEye leveraging Solarwinds. Hmmm how that would happened?🤔. Then realized their password was *****123 🤣 #FireEye#SolarWinds
Fellow data nerds: here's a snapshot of the vulnerability root cause trends for Microsoft Remote Code Execution (RCE) CVEs, 2006 through 2017.
A few callouts: heap corruption, type confusion, and uninit increased in 2017. Use after free steady y/y but proportionally declined.
@jlenkows Are you trying to scan more hosts than the default 256? If so, #EternalBlues supports a scan up to 16,384 IPs in one scan - just edit the IP range.
If you're looking for full automation, I highly recommend #metasploit.