In today's WTF?!?!? moment
When a ESXi server is domain-joined, it assumes any "ESX Admins" group & its members should have full admin rights.
So.... anyone who can create & manage a group in AD, can get full admin rights to the VMware ESX hypervisors!
https://t.co/U3DiXHWQMR
If you own an iPhone. Update now to protect yourself from an active 0 day.
After updating….activate stolen device protection. Here is how you can do that 👇
About Stolen Device Protection for iPhone - Apple Support https://t.co/P9CwanKaU5
Igår avslöjade SVT att Cert-SE hade informerat Svenska kyrkan om sårbarheten innan attacken inträffade. Kom ihåg att rapportera era organisationers IP-adresser, domännamn och AS-nummer till Cert-SE:s kostnadsfria tjänst Ants.
https://t.co/ll3pLFd824
After the #FlipperZero threads, there's been a few people questioning the ethics and legality of these devices, particularly with respect to NFC cloning.
I think explaining some of the history of NFC security - particularly Mifare Classic - attacks might help.
Igår intervjuades @YlvaJohansson om massövervakningsförslaget Chat Control 2.0. Precis som vanligt framförde hon flera lögner. Precis som vanligt avslöjar jag lögnerna i en faktagranskningsartikel: https://t.co/Hv1BTDQgGl
#chatcontrol#svpol#eupol#EUvsChildSexualAbuse
All projects have bugs in them. Far from all projects handle security related bugs the way Curl’s creator @bagder does. https://t.co/LTz5bh0TWP
#curl#transparency#cve2023_38545
Why are there always issues related to Citrix CVEs?! Today they released a new for Citrix ADC (CVE-2023-4966, CVSS 9.4) and a few minutes later their download site crashes. The site is still down 6 hours later = you cannot download new firmware.. #Netscaler#CitrixADC#Shitrix
🧙♀️ CISO Story Time
This is not exaggeration.
I have a good friend. He's a CISO of a multinational organization in the technology sector. We talk often.
Market trends, sales, and business regulations had the business decide to open an facility in China.
a 🧵 👇
they're basically saying "threat actors are exploiting it for a while" and "patch your systems and you'll be fine" ... which is a lie
We've seen this so often in the past: customers installed the patches but the appliances were already compromised
CVE-2023-3519 #CitrixADC#Netscaler
Here are some "Best Practice" checks you can do to check for compromise or unauthorized changes.
Commands in the ALT Text
Finally! Someone put the two IP IOCs related to the #Citrix Netscaler ADC vuln CVE-2023-3519 in a Virustotal Graph, which allows me to share them
216[.]41[.]162[.]172
216[.]51[.]171[.]17
https://t.co/gmZaVnzkC6
I gave GPT-4 a budget of $100 and told it to make as much money as possible.
I'm acting as its human liaison, buying anything it says to.
Do you think it'll be able to make smart investments and build an online business?
Follow along 👀