God damn, this CopyFail has the most intense Linux nerds coming out.
People are commenting all sorts of stuff and I have ZERO CLUE what they're talking about.
Bro, I do WINDOWS MALWARE. You honestly think I have any idea how Linux actually works under the hood? I don't remember ANYTHING.
You know I how I use Linux? I ChatGPT my way through the terminal hoping I don't destroy the machine.
Before ChatGPT I Googled errors and ended up on forums and mail list archives.
I am an amateur. I know basic-basic usage. Don't even bother asking me anything remotely technical
we're starting rollout of GPT-5.5-Cyber, a frontier cybersecurity model, to critical cyber defenders in the next few days.
we will work with the entire ecosystem and the government to figure out trusted access for cyber; we want to rapidly help secure companies/infrastructure.
🤨 People keep asking how to protect yourself.
#1: set min-release-age=7 in .npmrc
#2: install Socket for GitHub (it's free!) to protect PRs from bad dependencies: https://t.co/D9bsRJj65R
#3: install Socket Firewall (also free!) to protect your laptop: https://t.co/u1NRD57PQ8
I've been building a "Cliff's Notes" version of the docs for deploying the Defender XDR stack, and during the process I discovered how good the new setup guides are 🔥
Even if you have already deployed the solution, might be worth a review :)
https://t.co/WoZMN4Ei9a
It’s Monday, and you know what that means?
A fresh new week of chaos in IR.
Here are some real red flags I’ve come across in AWS environments while investigating security events — the kind that make my brain twitch 🧠⚡👇
I have a hard time recognizing or appreciating Chinese innovation when I have spent my career responding to intrusions, particularly 🇨🇳 hacks of tech & data companies while at Mandiant. For so many in infosec, it’s impossible to differentiate breakthroughs from decades of cheating & theft.
Here are some memorable quotes from my time at Mandiant (2014-2020):
🗣️ "We probably have somewhere in the order of 2,000 active investigations that are just related to the Chinese government's effort to steal information." - Christopher Wray, FBI Director, at the U.S.-China Economic and Security Review Commission, 2020
🗣️ "The Chinese government is known for using their military's cyber capabilities to hack into private U.S. tech firms. They steal I.P. and then transfer the technology to state-run companies for profit off of its development." - Rep. Matt Gaetz, at a hearing on Chinese IP theft, 2017
🗣️ "The greatest transfer of wealth in history is from the U.S. to China through cyber theft, and it's happening every single day." - Mike Rogers, NSA Director, 2015
🗣️ "There are only two types of companies in the United States: those who have been hacked by the Chinese, and those who don't know they've been hacked by the Chinese." - Robert Mueller, FBI Director, 2014
I've said something akin to this before: CARTP and CARTE from Altered Security should be required training for security architects in cloud.
The same Oauth2 token and delegated API permissions problems exist in other clouds aside from M365 and Azure.
🎉 Announcing DFIR Labs! 🎉
Introducing our DFIR Labs based on real intrusions from our public reports and private threat briefs! Whether you're starting out or looking to deepen your skills, our labs can help.
1/2
So authentication flows just dropped in my lab tenant @_dirkjan
Can confirm. This is a powerful way to stop token theft via device codes. Will need to play around with it a bit more. If I go to the same resource without initiating a device code request then login functionality continues to flow normally. This is great because it doesn't require a conditional access stack such as requiring device compliance. cc: @ItsReallyNick
I still don't see enough orgs requiring hybrid Entra ID join in conditional access when accessing all cloud workloads. If done properly its a show stopper for external attackers especially if you are adding in device compliance rules in the mix. Usually when I see it I have to pivot to internal access via device compromise. External token theft is also a non starter.
This is the current Top 3 for our Microsoft Cloud Incident Response training. Our vetting procedures might not be airtight 😜
Get in on the action:
https://t.co/q6eps0pFsc
The fact that even doing basic Windows logging in a small Active Directory environment or environment with standalone machines is complex to setup and/or costly for no particular technical reason is one of the biggest fails of MS security.
And also one that won't be fixed.