WSL now has built in Linux container support with both a CLI and an API, announced today and coming soon by the end of the month!
You can read more about it here (While our official docs are building :) )
https://t.co/o9RaROfswP
https://t.co/r67jck8ZGo just got a visual refresh 🌟
Explore 600+ documented DLL Hijacking cases, including:
• JSON/CSV/YAML feeds
• Sigma detection content for every DLL
• A single Sigma rule covering all DLLs
Check it out: https://t.co/2PJCgKEZwO
🌟 MS Icons : une ressource pratique pour vos diagrammes d’architecture Microsoft
Plus de 2 400 icônes téléchargeables, vraiment cool !
Ma publication à ce sujet :
- https://t.co/isj2M7LLlZ
#microsoft#ressource
Google Chrome is rolling out device-bound session credentials to all users. Session cookies get cryptographically tied to your device, so stolen cookies can't be replayed from a different machine. Attackers who exfiltrate your cookie database get nothing usable.
On recrute un(e) Tech Lead Incident Response pour le #CERT Michelin. Si jamais vous êtes intéressé(e), pingez moi en direct.
Job de l'annonce : https://t.co/VtLwRMFwXw
Merci de republier pour plus de reach :)
#infosec#job#cert#michelin
#JeuConcours 🎁 Tentez de remporter le nouvel aspirateur sans fil Lamzien V8 MAX !
✨ Puissance d’aspiration améliorée à 45000 PA et autonomie de 45 minutes ✨
Pour participer :
🔁 RT + ❤️ + Follow @Darty_Officiel
📆 TAS le 3/06
🏆 1 gagnant
🍀 Bonne chance !
Great insight on how Tycoon 2FA operates. Very interesting to see how they rely on using custom authentication flows for M365 and Google Workspace to acquire access tokens and not the the classic session cookie capture.
Detecting #Tycoon2FA AiTM attacks across Entra ID and Google Workspace. We map telemetry fingerprints across both platforms, ship detection rules for both tiers, and contain incidents in under 10 seconds with Elastic Workflows.
https://t.co/mSxH6m0bGB
I’ll be speaking at the Threat Hunting Summit on June 17 about hunt memory and building lightweight repos your AI assistant can actually use during investigations.
Because most hunts still end up in “wait… have we seen this before?”
Come hang 👀
https://t.co/RZ1lQRxVxC
🔥 npm now requires human 2FA approval before staged package releases become installable — even from CI/CD workflows.
https://t.co/Nv3wV9rPag
New package versions uploaded with staged publishing are placed into a queue and must be explicitly approved by a maintainer before release.
Requirements:
• npm CLI 11.15.0+
• 2FA enabled
• Existing npm package
• Use npm stage publish
npm also added new install controls:
--allow-file
--allow-remote
--allow-directory
The updates are designed to strengthen defenses against software supply chain attacks targeting open-source ecosystems.
@KTLYST_labs @mthcht2 Let's assume Threat Actors are using ngrok to exfiltrate data. IOCs such as domains linked to tunnel creation will almost never change, expect maybe a portion of subdomain. If tunneling is not allowed in your company, it will be perfect for long-term detection.
The malicious vscode extension could be one of these extensions recently removed from the store DevCrew.devc-python-toolkit🤔? not shared yet by microsoft, check https://t.co/YG1EmNv9zv and use https://t.co/eKm9YvAP1A to automatically block and uninstall these
🚨 We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. (1/6)
🚀 ZLinky longue distance : nouvelle étape franchie !
Notre prototype LoRa 2.4 GHz vient d'atteindre 200 m de portée en milieu semi-urbain — à travers murs, étages et obstacles 🏠🌳
Et le tout sans pile, sans alim externe 🔋
Le module se contente de l'énergie fournie par la TIC du compteur Linky pour fonctionner ET transmettre ⚡
📶 Pourquoi LoRa 2.4 GHz et pas le 868 MHz classique ?
Parce qu'à 2.4 GHz il n'y a aucune restriction de duty cycle : on transmet aussi souvent qu'on veut, là où le 868 MHz est plafonné à 1 % du temps. Résultat → suivi quasi temps réel, et pas quelques trames par heure.
📊 Ce qui remonte côté box :
⏱️ Toutes les 2 sec → puissance instantanée, mode (mono/tri, historique/standard), alertes du compteur (dépassements ADPS, contacts secs, état STGE…)
🔁 En cycle complémentaire → index d'énergie par tarif (soutirée & injectée), courants & tensions par phase, puissances max du jour, énergies journalières, pointe mobile, configuration tarifaire…
🎯 Il ne reste plus qu'à finaliser le récepteur côté box pour que la solution complète soit prête à l'usage.
Stay tuned 👀
#ZLinky #Lixée #Linky #LoRa #LoRa24GHz #IoT #SmartEnergy #SmartMeter #MadeInFrance #ÉnergieConnectée #Innovation
📤We've updated our Linux tools support, and we're releasing Autoruns, ProcDump, ZoomIt, DebugView, NotMyFault, ProcExp, and Procmon with improvements.
Get the tools at https://t.co/zlch58GEpK.
See what's new on the Sysinternals Blog: https://t.co/w53poPXiyH
CTI and SOC folks, you’ll like this one!
ThreatCheck lets you select IOCs from any web page, bulk-extract and dedupe them, then pivot across 29 threat intel platforms with optional auto API enrichment.
https://t.co/2gXI7WdLN7
https://t.co/d5bPzSPlVQ