As CrowdStrike continues to work with customers and partners to resolve this incident, our team has written a technical overview of today’s events. We will continue to update our findings as the investigation progresses. https://t.co/xIDlV7yKVh
Microsoft has identified targeted attacks against the defense sector in Ukraine and Eastern Europe by the threat actor Secret Blizzard (KRYPTON, UAC-0003) leveraging DeliveryCheck, a novel .NET backdoor used to deliver a variety of second stage payloads. https://t.co/mWoyzOoydF
Mars Habitat Tour 📹
CHAPEA, or Crew Health and Performance Exploration Analog, is @NASA's first one-year ground-based mission that will simulate living on @NASAMars. The crew will live and work in this 3D-printed, 1,700-square-foot habitat.
MORE: https://t.co/aA6dSIRWLG
Proofpoint Threat Research has observed intermittent injections on a media company that serves many major news outlets. This media company serves content via #Javascript to its partners. By modifying the codebase of this otherwise benign JS, it is now used to deploy #SocGholish.
Microsoft has detected social engineering campaigns targeting employees of orgs across industries in the US, UK, India, Russia. MSTIC attributes the campaigns to North Korea-based actor ZINC, which used multiple weaponized open-source software. More info: https://t.co/kqIYnTGg6u
In case you missed it at #BHUSA, check out @tr1ana's Monkey365, a tool for security consultants to easily conduct not only Microsoft 365, but also Azure subscriptions and Azure Active Directory security configuration reviews
https://t.co/cuUDNQN7Sw
Hey all!! We are running yet another Pay What You Can for SOC Core Skills next week!
Yes, $0 is an option.
Let's break some gates down and get more cool people in the industry.
https://t.co/DloQ3Tqdwy
@MSwannMSFT 0365 account takeovers that send phishing emails w/links to docs hosted on 1drive/SPO that are protected with MIP. These docs then have phishing links or malware but are hard to analyze by infosec teams because they are restricted to the user who received the fileshare/email.