Adventures of a honeypot!
Want to see some cyber reality? come check this out tweeps! This is literally how someone major incidents start.
https://t.co/p4vYFdJLYp
One of the most insecure defaults is getting less insecure at the end of this month. Microsoft is limiting what permissions a user can consent to. This is very interesting for everyone doing #BEC investigations. Curious to see if this will impact malicious app usage.
More info (https://t.co/JGO1pFaVPz)
#stayInvictus #BEC #CloudIncidentResponse
This BBC reporter was offered 25% of a ransom payout if he gave hackers access to the corporate network.
He played along, so we got a look inside their tactics here:
π« These threat actors tried to hide their code behind the GPU. We caught them anyways.
πΊ Our @AWNetworks Labs team uncovered a threat actor abusing GitHubβs repository structure and Google Ads to redirect users to a malicious download, while a GPU-gated decryption routine kept the payload encrypted on systems without a GPU. We have named this new attack technique #GPUGate.
π Full research here: https://t.co/dJVfJ6LHVI
#CTI #ThreatResearch #ThreatIntel #ArcticWolf #SecOps #SOC
I just started a new blog, and this is my first post. I took a bit of PTO, so this is a little record of some fun I had playing around with Intune during that time. It's about enrollment restriction bypassπ
https://t.co/o9CcXHN4b8
A Windows #Clickfix alternative seen in the wild on a mass-spreading malware campaign bypassing traditional Win+R shortcut restrictions
User is asked to open the Windows Power User menu (Win+X), open a Powershell terminal and paste and running a malicious Clickfix-style command
First Microsoft introduces the ability to disable direct send after all the abuse, and now Salesforce is providing a method to stop the abuse exploited by ShinyHunters. Better late than never!
**NEW** BHIS | Blog
Did you know your M365 tenant accepts unauthenticated email for your tenant domains by default?
Stop Spoofing Yourself! Disabling M365 Direct Send
by: @Securecake
Published: 8/20/2025
Learn more: https://t.co/4rqbE7ayTi