Cyber security enthusiast, bug bounty hunter, I spend time reading what NASA is up to in space research too. But dont expect any tweet about Mars exploration
I don’t usually do #ff#followfriday but I’d like to shout out a few of my faves this week ❤️ You have all had such an impact on me during my time in infosec so far - thank you for your friendship and guidance! ✨
@z000nbug@zak_hax
@amysw_sec
@charlieamber94
1/2
.@Office365 Last week, @Practical365 published a script to create an inventory of #AzureAD integrated apps. Here's how to conduct a review of the apps to decide why stay and which should go. I managed to remove 35% of the apps registered in my tenant!
https://t.co/6cRUxNp0Ve
[PDF] Defending against Software Supply Chain attacks, taking into consideration recent high-profile attacks in the news. What are they and how to mitigate from CISA https://t.co/A1kC0MFkT0
[PDF] Cybersecurity advisory to defend against attacks from SVR. Understand the tactics, techniques, and procedures used by online threat actors to compromise your network. Mitigations within the document to protect yourself https://t.co/zXAKHPOJwh
Microsoft has announced the end-of-support for .NET Framework v4.5.2, 4.6, and 4.6.1 on April 26, 2022, as per Microsoft. Please make sure if you are applying for CE/CE+, then the version is updated to 4.6.2
Want to practice your #JWT#pentesting skills? Check out this JWT Hacking Challenges lab by @onsecru. Includes the following JWT signature attacks:
* none,
* weak secret key,
* key confusion,
* key injection,
* jwks spoofing,
* kid
https://t.co/8eU7zRyLfZ
Unlocked Gate - A loophole that would allow an attacker to trivially craft a macOS payload to bypass Gatekeeper has been patched in a recent Bigsur update.