Need to go under the radar downloading #mimikatz (and other suspect payloads)? Then newly discovered #lolbin "C:\Windows\System32\Cmdl32.exe" (signed by MS) is for you. It's like a new certutil.exe but absolutely unheard of by any antivirus software!
I found out "C:\Windows\System32\WorkFolders.exe" (signed by MS) can be used to run arbitrary executables in the current working directory with the name control.exe. It's like a new rundll32.exe #lolbin but for EXEs!
Today we are releasing GraphRunner, a post-exploitation toolset for M365 and Entra ID accounts that myself and @424f424f have been building for the last few months.
Read the blog post here: https://t.co/fWKFcLgld5
Code is here: https://t.co/yDhdkhbO7q
@jaysonstreet@defcon We bumped into each other twice but never really got the chance to really talk. Wish you all the best and thank you for all your work for the community, people and companies out there!
A suspect has been detained in yesterday's theft from the Tretyakov Gallery. The man, whom police say has previously been held for drugs possession, walked off with Arkhip Kuindzhi's "Ai-Petri. Crimea" in front of confused visitors
https://t.co/FilXU0YDU4
@__phw I think, we have included this issue into every second external pentesting report in the last 5 years. Sometimes it helps, but most new sites do start off with externally included scripts and fonts, again.
New study on the reliability and security of open proxies: https://t.co/qca6G4Rd2b As expected, they're wildly insecure. Stay away. Tor is doing better only because @torproject has dedicated volunteers who monitoring the network diligently.