@vxunderground I find it funny that she probably isn’t big enough to wear the 4 profile shirt. I guess you must be XL or + for people to see all the mugshots?
@vxunderground (Quote)…”the only way a Threat Actor would be able to access Recall data is if they have physical access to the machine, unlocked it, and then signed in….”
Well, that would never happen, right? If you think that extortion pressure is bad from criminals now…
@vxunderground If “Kindly” is used in any context other than “thank you kindly” at the end, 97% chance it is scam/phish/malicious. Bet on it! Write a detection rule…
Okta is a symptom of a larger issue: too many orgs have outsourced their root of trust to a third party and have NO MECHANISM to detect abuse.
Be real: the only reason we know about this one is because the threat actor targeted top tier orgs who caught them, not because Okta did
@vxunderground Actually, in the last 6 months I have seen a person use it. The person was in Cyber Security. My theory is that she has seen too many scam emails and it became part of her vocabulary. The only other time has been in the south… in the context of “thank you kindly.”
You should be aware of the term "harvest now, decrypt later". At some point, the encryption we use today will be easily crackable. Don't rely too heavily on it. Better to be very protective of where your data ends up, even if it's encrypted.
@maddiestone@vladhiewsha@_clem1 I don't think the CVE-2023-36884 was patched in this cycle, if I am reading correctly. Mitigations are suggested through Defender or Registry edits.
https://t.co/Qcloh4HKdj
I’ve been laid off! I’d be a great fit for the following roles:
🔥CTI Analyst
🔥Hunt
🔥CTI Manager
8 GIAC Certs + MBA IT Management + DSc Cybersecurity
5 + years of CTI/Hunt experience
Thank you!