@4A4133@Andrew___Morris@GreyNoiseIO I don't have specific data evidence, just going by experience and intuition, but it's likely to exist because the world isn't simply black and white; there are gray areas.
Be careful about those CVE-2022-26809 PoCs online, especially when they try to sell it to you. Actually I think a PoC is not important for defense purpose, apply the patch, do not expose your RPC ports (not only for this bug but a basic security baseline), that would be enough.
The ultimate problem of security, all operable and input variables are code execution loopholes, because all variables may be printed in logs. This is a loophole in the annals of history, the ultimate dream of hackers, and the jewel in the crown.
A joke, the automatic discovery of the windows client normally does not request the TLD, but the external network firewall may block all the automatic discovery requests of the client, causing it to eventually go to the TLD.
@NathanMcNulty@N805DN The reason lies in the network security strategy. The client's automatic discovery generally does not traverse to the TLD domain, but the external network firewall may intercept the client's automatic discovery request, causing it to eventually go to the TLD domain.
This is not a new thing, a semi-public red team technique, Microsoft's official domain name can become the c&c of cobalt strike! Reference https://t.co/RFSutQVvsY
Automatic on-premises Exchange Server mitigation is now in Microsoft Defender Antivirus. We have taken this additional step to further support our customers who have not yet implemented the complete security update. Learn more: https://t.co/QUlXgUZdZp