The fact that sites now are being build with AI is fine with me, but when they slap that Google recaptcha on it and ask me to verify that I'm not a robot...
🚨 Today's Headline: "GitHub hit by a compromised VSCode extension"
Every defender is now scrambling to answer the critical question: Which VSCode extensions are installed across my MDE users, and is there any impact to their development environment?
For those running Microsoft Defender for Endpoint, here’s a KQLWizard query to instantly extract the full list of VSCode extensions executed by your users. (Answering to @IAMERICAbooted SOS Call 🫡)
https://t.co/7W96rFNamy
Go hunt down those malicious extensions before they hunt you. 🧙♂️✨
Microsoft is enabling Flex Routing for EU, meaning that LLM Modules is allowed to inferencing outside EU Data Boundary.
You can disable this function in the admin portal by going to CoPilot->Settings ->(View all)->Flex routing during peak load periods
https://t.co/PW3lFemTPu
Please stop using Private browser sessions for cloud admin accounts
Look, we all know we shouldn't be using admin accounts while signed into our productivity account, but if you're gonna do it, at least use browser profiles so you can enforce compliance
https://t.co/e8I882Lh9w
Claude is not allowed to write outside the workspace.
But it wanted to.
So Claude wrote a python script and executed it via bash to modify the file essentially hacking my permissions.
Yeah, so pretty much @IntCyberDigest got wind of Adobe allegedly* being compromised by a Threat Actor operating under the moniker Mr. Racoon, by all accounts it appears this compromise is legitimate. However, I believe there are some caveats that need to be emphasized to avoid confusion.
Adobe's internal networks were not compromised. Adobe had their helpdesk system compromised. Yes, both are Adobe, but a compromise to helpdesk support is different than a network compromise. Adobe, like many other large companies, intentionally segregates different business components.
A network compromise could potentially impact the organization itself, proprietary source code, etc. A helpdesk compromise will likely unveil sensitive information on users.
In simpler terms, anyone who submitted a helpdesk ticket to Adobe, or requested assistance in any capacity, could be impacted.
However, the scope of impact is unknown at this time. It is being reported that 13,000,000 support tickets have been exfiltrated, but that could be anything from a simple question to something more consequential like billing questions. Furthermore, we don't know how far these support tickets to back. But 13 million is an astronomically large number.
A closing thought on this is that this compromise was the result of a BPO employee (outsourced labor). This BPO employee (according to the Threat Actor) was infected with malware, they WERE NOT an Insider Threat. Once the BPO employee was compromised the Threat Actors pivoted by phishing a manager.
More information is needed, Adobe will likely make a statement later (or not depending on what their legal team suggests). It has been a very dramatic week in cybersecurity
@awakecoding You have to specify and be able to resolve the full FQDNS of the target machine, else it wont work. I also have tested that you can be able to authenticate with the target by during some hosts edit on the machine you are on.
Haven't had any issue so far.
🙂
🚨 CISA confirms active exploitation of a critical VMware vCenter Server flaw.
CVE-2024-37079 allows remote code execution via a DCE/RPC heap overflow if an attacker has network access.
🔗 Details → https://t.co/YcVd5W3p29
IMPORTANT: Secure Boot certificates used by most Windows devices are set to expire starting in June 2026. This might affect the ability of certain personal and business devices to boot securely if not updated in time. To avoid disruption, we recommend reviewing the guidance and taking action to update certificates in advance. Learn more by visiting the Secure Boot playbook.
https://t.co/900AYLgXup
(🧵6/7)
New scrape: Instagram allegedly had 17M rows of largely public data scraped from an API and posted to a hacking forum this week. 6.2M rows also included an email address, and some rows a phone number. 100% were already in @haveibeenpwned. Read more: https://t.co/VG5mTRF9xD
🚨 Cisco switches are entering reboot loops due to a fatal DNS client bug.
Multiple CBS, SG, and Catalyst models are affected, with devices crashing after DNS lookup failures.
Admins report disabling DNS stops the reboots.
Full details 👇
https://t.co/04SuCLO8KC
Meet Razer Project AVA, your all-in-one AI companion: https://t.co/EAni1mS2Lv
From planning your day to analyzing spreadsheets and game starts, Razer Project AVA leverages advanced AI inferencing and reasoning that dynamically evolves based on your personal interactions. Select your 5.5" companion from an expanding library of characters from esports legends to custom anime-inspired Razer designs. Be among the first to sign up for Razer Project AVA at release.
#CES2026Razer #RazerCES2026 #CES2026
@VogonTechnician@IceSolst@acxtrila I believe you are able to change it with PowerToys, and also make the shortcut do something else.
Then there should also be a regedit key somewhere to change/delete it.
Anyone have any idea what Dragon Administrator in Entra ID actually does? (Or actually use it?) Or is just some badass role we can give ourselves that nobody sees but we feel good about it? ����