Exactly what @david_jursa has been telling us for years: block LLMNR and mDNS on public networks, as Avast Firewall does! Incredibly detailed blogpost. Thanks, @tiraniddo!
"Can you still relay authentication in a Windows domain if NTLM is disabled?", I asked myself. "Perhaps I should research that" I said. Here's a blog post about what I found out. https://t.co/u5B7MVShCi
Facebook employees aren't able to even login to the company servers because their access badges are tied to Facebook's internal network which is entirely offline – this is the mother of all outages.
Microsoft is rushing to register autodiscover.[TLD] domains that could leak Windows credentials after @0xAmit report about faulty implementations of the Microsoft Exchange Autodiscover protocol.
* 68 confirmed registered domains
* 38 more we can't confirm
https://t.co/12hnEkTpD8
Just generated some stats on the last year of attacks against @Microsoft’s sensor network.
Attacks collected >14 billion
Top 3 increases
⬆️ RDP 325%
⬆️ Network printing 178%
⬆️ Docker/K8s 110%
Top 3 decreases
⬇️ HTTP 36% 😮
⬇️ FTP 40%
⬇️ Telnet 56%
% is change from last year
This is *exactly* how an organisation should manage an incident and handle public disclosure. Fantastically documented by @jayabaloo and the @avast security team. https://t.co/tGZCN8NpMs #threatintel#infosec
Botnet operator's first choice when choosing a certificate authority (CA) for getting a SSL certificate for their botnet C&C is @letsencrypt. No surprise, as they provide certificates for free and refuse to revoke such that have been issued fraudulently
https://t.co/burLeBEgxX
Great work by @thinkcz and @vopratko. BTW vulnerable #MikroTik routers are detected by Avast HNS aka Wifi Inspector and the mining scripts are blocked by Avast WebShield.
Security Update: The #MikroTik#cryptomining campaign is still very much alive. In just the past 7 days, Avast blocked 5 million infected URLs on nearly 94,000 infected routers.
More updates and a deeper analysis to come; stay tuned.