@ponceto91@pbeyssac Peut être aussi jouer sur l'accès aux données et le masquage de ces données : est-ce que l'utilisateur victime avait besoin d'accéder à l'intégralité de ces données pour faire son travail ?
🚨 Après les récentes cyberattaques visant la DGFiP, Bercy détaille son plan pour renforcer la cybersécurité de l’administration fiscale.
- La double authentification pour les agents de la DGFiP doit être généralisée à l’ensemble des services de la plateforme d’ici la fin de l’année.
- Les campagnes internes de faux phishing vont être intensifiées afin de sensibiliser les agents et mesurer régulièrement leur niveau de vigilance. Les formations en cybersécurité seront également renforcées en tirant les enseignements des dernières attaques.
- Les dispositifs de détection doivent être revus, notamment pour mieux repérer les usurpations de comptes et les comportements anormaux. Des systèmes de quotas d’accès, déjà utilisés sur certains fichiers comme FICOBA, doivent aussi être davantage généralisés.
- Face à des attaquants utilisant de plus en plus l’intelligence artificielle, Bercy veut également s’en servir pour se défendre : tester ses propres systèmes, simuler des attaques et identifier des vulnérabilités avant qu’elles ne soient exploitées.
- Un système de bug bounty va être mis en place afin d’identifier et de corriger de manière proactive les failles de sécurité avant qu’elles ne puissent être exploitées.
🇫🇷 Enfin, Bercy évoque le développement d’une IA souveraine, afin de renforcer ses capacités de défense sans créer une nouvelle dépendance technologique susceptible de devenir, à terme, une nouvelle vulnérabilité.
@k_firsov If the app/service correctly checks that the host/SNI is incorrect (https://t.co/KmBhXTCdnY instead of https://t.co/vSSoYBeYxh) then this attack should fail.
@_SaxX_ Pour les entreprises, on peut mettre en place des solutions de chiffrement par DLP.
Pour les particuliers, il existe relativement peu de solutions simples. Le moins pire est d'utiliser une solution de chiffrement d'objets (ex: cryptomator)
@dgfip_officiel Bonne idée pour la double authentification, mais dommage que ça reste par email. Une projet de double authent par SMS ou OTP ? Voire même une passkey ?
📚 L'ANSSI publie de nouvelles recommandations relatives au #ZeroTrust.
👀 L’objectif principal du modèle Zero Trust est de réduire la confiance implicite accordée à un sujet souhaitant accéder au système d’information (#SI).
Plus d'informations sur :
🔗 https://t.co/m2EIZYjPDJ
Non-privileged Windows Hello abuse.
This attack only works when performing an RDP session to a non TPM protected device using Windows Hello for Business credentials. Before a user can do this, specific configuration as mentioned in the article needs to be in place.
The attack scenario is this one:
- An attacker performs a RDP connection from the victim device with TPM to a non-TPM protected device using Windows Hello for Business, in order to expose the Windows Hello for Business keys on the non-TPM protected device.
- With these keys and the assertion that can be generated on the victim device in user context without prompting for any credentials, the attacker can request an Entra ID PRT token on the non-TPM device using RoadTools.
- Once the attacker has the PRT, he can request access tokens for all different kind of applications with device state and phishing resistant MFA claims in the tokens, evading most of the strongest conditional access policies.
https://t.co/rXRkG72e3o
#TrustEverybodyButCutTheCards
Microsoft recently launched/refreshed guidance on how to protect against token theft and token replay:
1️⃣https://t.co/V5PcB20UC9
2️⃣https://t.co/3xICAUYu8W\
Go check!
30 cybersecurity search engines for researchers:
1. DeHashed—View leaked credentials.
2. SecurityTrails—Extensive DNS data.
3. DorkSearch—Really fast Google dorking.
4. ExploitDB—Archive of various exploits.
5. ZoomEye—Gather information about targets.
We finally have more info about how exactly Microsoft was hacked by Chinese threat actors. It’s a doozy, so strap in.
Back in June, hacking group Storm-0558 accessed the cloud-based Outlook email systems for 25 organizations, including at least two US government agencies. We finally know how they managed to pull it off.
The hackers got their hands on a Microsoft account consumer signing key, all the way back in 2021. This cryptographic key is used to generate authentication ‘tokens’ that prove a user’s identity before they’re allowed to access data and services. This is usually stored in a highly isolated and restricted ‘production environment.’
However, during an April 2021 consumer signing system crash, the signing key made its way out of this secure environment and into a crash dump, which should not happen under normal circumstances. A race condition allowed the key to be present in the crash dump, which Microsoft did not know at the time, and this mass of data was subsequently moved from the isolated production network into the company’s debugging environment on the internet-connected corporate network.
At some point after this, Storm-0558 successfully compromised a Microsoft engineer’s corporate account, which had access to the debugging environment containing the crash dump, and subsequently the signing key.
@Microsoft’s explanation covers this whole controversy, and the company has since patched the accumulation of errors and issues that led to this, but the one missing link is how the threat actors got their hands on this engineer’s account.
As my good friend Jacob Williams put it in the article below, “All the best hacks are deaths by 1,000 paper cuts, not something where you exploit a single vulnerability and then get all the goods.”
Indeed, the best threat actors are cunning, patient and perseverent - so much so that they can infiltrate global corporations.
Here’s the news story: https://t.co/pZ9511acZD
Microsoft’s post-mortem report on the attack: https://t.co/YfZv0YZSL9
For my non-French speaking followers: BX1, accused of running the PyLocky ransomware from a US prison, was to be judged yesterday in FR but all charges were dropped because the accusation got the name of the malware wrong in their citation 🤦🏻♂️
Check-in on your lawyers, folks.
Lots of people are new to M365/Microsoft Entra ID forensics, so I thought I would put together a completely free & open-source forensics 'kit' to learn. First, somewhere to store your data, Kusto Free tier is perfect, zero cost and no card required - https://t.co/ZBbIZHCONz