https://t.co/Vq3bDoa9ws
Like device code phishing but stronger.
TBH I'm surprised, I didn't think attackers will actually phish users to register passkeys
@UK_Daniel_Card I actually fall into this tax problem, but im the high income earner and my wife is a nurse. We lose her income after tax is approx £1.4K a month our childcare bill is 2.5K a month because i disqualify us from any of the tax relief. Then she has travel expenses etc.
RayInitiator & LINE VIPER
A sophisticated bootkit and user-mode capability, targeting
Cisco ASA devices. A significant advancement over LINE DANCER
and LINE RUNNER.
(Still down with a cold 🤧, staying in tonight. I’ll look at the YARA rules later this evening.)
https://t.co/D5PMGD5uZ6
If you’re returning from Mastodon or Bluesky and looking for solid infosec content on X
This “Cyber” list is a curated feed of high-signal accounts
- Pin it to get a timeline tab (see screenshots)
- Or follow the members directly
- Regularly updated
https://t.co/lZcrXsHXhi
The NHSE Threat Intelligence team have released a High Severity Alert for CVE-2024-47575 for FortiManager & Analyzer.
Fortinet state that this zero-dayvulnerability has been exploited and that the identified actions of this attack in the wild
https://t.co/sgPlZtiEr2
The NHS Transformation Directorate has just posted my blog on NHS England Threat Operations.
Lookout in the coming months for the launch of new capabilities, including the launch of our Threat Intelligence Service.
@UK_Daniel_Card If you have corporate access policies i dont see a problem with it really. I.E UK only, then why open to the world?
Not blocking access would only enable your staff to breach policy when they leave their device on while travelling.
The team have released a HSA with mitigation steps for CVE-2023-20198 an exploited zero-day vulnerability in Cisco IOS XE software.
We recommend defenders who have Cisco IOS logging search for the IOCs made available by Cisco Talos:
NHS Advisory:
https://t.co/NpVTvJArbT
@dasgrog@UK_Daniel_Card I personally don’t use network equipment, anything j do have is in azure.
Radius/TACAS+ and a password manager for the local creds is how iv previously done it. local password being the least preferred in authentication order so the cisco wont locally auth if DC is present.
@UK_Daniel_Card Hardware security keys have changed my life, using them in combo with a single identity such as apple or gmail is a game changer.
I dont know my passwords, i dont worry about avpassword manager getting owned.
People say to complex for mass use, but chip and pin is used.
We are recruiting for a Cyber Security Senior Advisor - Threat Intelligence. Join a highly skilled team operating in the cutting edge of cyber security through the analysis of healthcare and security information to produce cyber threat intelligence.
https://t.co/PiEaxcDtcd