A vulnerability in macOS, identified as CVE-2021-30970 and fixed by Apple in December, could allow an attacker to bypass Transparency, Consent, and Control (TCC) and gain unauthorized access to protected data. Read our analysis via @yo_yo_yo_jbo: https://t.co/vkkIw2HdZp
Want to know why threat actors are so interested in Microsoft Partners and Delegated Administrative Privileges (DAP)?
Check my blog at https://t.co/pyuhHKVJaP
#AzureAD#blueteam#redteam#infosec#AADInternals
PoC exploit now out for Azure Active Directory brute forcing flaw. Microsoft maintains it's not a vulnerability but appears to be working on a solution.
Includes additional commentary from @DrAzureAD@Secureworks.
👇👇👇
https://t.co/FihlJ2pAta
Backdoor #Office365 and #Azure AD by stealing AD FS certificate/key pair. Golden SAML attack will allow an attacker to:
> Bypass MFA to Azure / Office365
> Logon as any AD user regardless of password resets
> Method is usually valid for a year
https://t.co/16L9k10tB7
(1/x) M365 changes to be aware of
1) End-users can purchase PowerBI on their on personal credit cards to bypass IT
2) End-users can purchase Windows 365 Cloud PC VMs on their own personal credit cards to bypass IT
3) End-users can create security groups (even if you disabled it)
Researchers have uncovered a new class of vulnerabilities affecting major managed DNS providers that could allow attackers to spy on massive amount of DNS traffic and exfiltrate sensitive information from corporate networks.
Read: https://t.co/uQTMMaoElx
#infosec#cybersecurity
@360_trader@littlecaesars Little Caesars used to be garbage, but they've really improved the quality of the product in recent years. Can't beat a deep dish for $8.
Malicious Office365 apps are the ultimate insiders: They bypass 2FA, survive password resets, & give attackers launching point for more attacks. New research shows they're very effective at getting bad guys inside O365 organizations. https://t.co/orTC5b2ENA
What a time to be alive... Install the Microsoft signed Hybrid Connection Manager on victim host, link it up with your Azure app, enjoy persistent access to the on-prem network from your Azure portal. Only needs https outbound to Azure and line of sight from victim to target host
The #CryptoGathering#Sweepstakes 🚀
1 lucky person will receive $4500 in #BTC by the time this is over...
❤️/RT this post & follow @RealVision for a chance to #win.
🏆 will be announced 03/26 6pm ET here & at the event. https://t.co/DmHbGWeoAx
Terms👉 https://t.co/UgYCevNWHm
Microsoft observed a new family of human operated ransomware attack customers – detected as Ransom:Win32/DoejoCrypt.A. Human operated ransomware attacks are utilizing the Microsoft Exchange vulnerabilities to exploit customers. #DearCry@MsftSecIntel