The Jingle Thief campaign targets cloud-based service to maintain longterm persistence and, ultimately, conduct gift card fraud. This enables near-instant cash flow. Learn how the scheme works: https://t.co/Fn5w0IiPkz
From MSAs to dMSAs: Unit 42 traces the evolution of Managed Service Accounts and explains the BadSuccessor attack vector in Windows Server 2025. This article includes discussion of the PoC SharpSuccessor. https://t.co/vPdtVSP3LY
Cybercriminals can leverage the vendor-agnostic #LDAP for lateral movement and to target critical assets. Stay informed about the risks and learn how to detect and mitigate LDAP-based attacks. https://t.co/ys6TUst0cg
Hidden in the depths of the Microsoft Learn Docs are some really great Azure AD incident response playbooks covering phishing, password sprays, app consent grants and compromised & malicious apps, including some really great flow charts - https://t.co/1DN5eAVFIv
If you are investigating suspicious Office 365 activity, chances are you will be deep into the Unified Audit Log before you know it. One of our very smart @MicrosoftDART team members put together some tips for good UAL hunting - https://t.co/VV0Pn45dgi
GMSA passwords aren’t what you think.
Read all about it in @YuG0rd’s post, where he dives into how gMSA passwords are generated and introduces the Golden GMSA attack.
https://t.co/chc379EdHY
Excited to share our research and detection on the CVE-2021-42278 and CVE-2021-4487 Kerberos vulnerabilities with @cortexbypanw
https://t.co/wOfFKB31p1
So with some help from @_EthicalChaos_ I found a way to weaponise CVE-2021-42287/CVE-2021-42278 and more help from @4ndr3w6S we put some detections together:
https://t.co/FwQuI2DiPQ
hello world!
we're launching pandas tutor! it visualizes Python pandas code step-by-step: https://t.co/Kt9PClWEyX
(developed with my advisor philip guo)