maxicorbs (@corbridgemax) 's Twitter Profile
maxicorbs

@corbridgemax

Principal Security Consultant based in London

ID: 4835386599

calendar_today22-01-2016 15:31:51

149 Tweet

124 Followers

107 Following

JUMPSEC (@jumpsec) 's Twitter Profile Photo

UnSafeLeaks - an emerging threat disregarding rules of engagement, getting personal and vicious against organisations and individuals. Read more about the implications their activity could have here. ➡ jumpsec.com/guides/compoun… #ransomware #cybernews #CybersecurityNews

Jeffrey Appel | Microsoft MVP (@jeffreyappel7) 's Twitter Profile Photo

NEW BLOG: AiTM/ MFA phishing attacks in combination with “new” Microsoft protections (2023 edition) In this blog, I'm going to explore all the new and existing capabilities (Token protection/ attack disruption and more) jeffreyappel.nl/aitm-mfa-phish… #AzureAD #MicrosoftSecurity

NEW BLOG: AiTM/ MFA phishing attacks in combination with “new” Microsoft protections (2023 edition)

In this blog, I'm going to explore all the new and existing capabilities (Token protection/ attack disruption and more)

jeffreyappel.nl/aitm-mfa-phish…

#AzureAD #MicrosoftSecurity
Tom E (@tde_sec) 's Twitter Profile Photo

Its nice to see some tooling off the back of some of our prior research. This demonstrates the impact of allowing external Teams collaboration.

Help Net Security (@helpnetsecurity) 's Twitter Profile Photo

Malware delivery to Microsoft Teams users made easy - helpnetsecurity.com/2023/07/10/mic… - Octoberfest7 Andrea Santese maxicorbs Tom E #MicrosoftTeams #Phishing #RedTeam #SocialEngineering #Vulnerability #InitialAccess #CybersecurityNews #InfosecNews

Malware delivery to Microsoft Teams users made easy - helpnetsecurity.com/2023/07/10/mic… - <a href="/Octoberfest73/">Octoberfest7</a> <a href="/Medu554/">Andrea Santese</a> <a href="/CorbridgeMax/">maxicorbs</a> <a href="/tde_sec/">Tom E</a> #MicrosoftTeams #Phishing #RedTeam #SocialEngineering #Vulnerability #InitialAccess #CybersecurityNews #InfosecNews
Tom E (@tde_sec) 's Twitter Profile Photo

Having the external collab setting as default (allowing cross org comms) has allowed us use that technique during red teams on several occasions. It also led to maxicorbs and I finding this: labs.jumpsec.com/advisory-idor-… Not limiting external collab is a real, impactful gap.

Tom E (@tde_sec) 's Twitter Profile Photo

We warned Microsoft back in June about the risk of external tenant interaction being used for initial access, I’m honestly expecting the prevalence of this to sky rocket in coming months. That doesn’t even take into account the IDOR they chose not to fix. labs.jumpsec.com/advisory-idor-…

JUMPSEC LABS (@jumpseclabs) 's Twitter Profile Photo

The vast amount of data that builds up during a #purpleteam engagement can quickly become overwhelming if not managed properly. Check out our experience of using the #opensource framework VECTR to solve this problem! labs.jumpsec.com/vectr-for-purp…

JUMPSEC (@jumpsec) 's Twitter Profile Photo

Great to see Max Corbett, at UKCyberWeek presenting insights about #cloud #redteaming and security concerns that are being introduced & how red teamers and threat actors are leveraging them to great effect! #azure, #aws #gcp #security #cybersecurity #risk

Great to see <a href="/Maxicorbs/">Max Corbett</a>, at <a href="/UKCyberWeek/">UKCyberWeek</a>   presenting insights about #cloud #redteaming and security concerns that are being introduced &amp; how red teamers and threat actors are leveraging them to great effect!

#azure, #aws #gcp #security #cybersecurity #risk
JUMPSEC LABS (@jumpseclabs) 's Twitter Profile Photo

🚨 Tool Release 🚨 We've just open-sourced our #automation scripts for setting up #vulnerable #Azure environments to practice #cloud red teaming. It's basically free to run and has hints to help you along your journey if needed 💪 #AHHHZURE github.com/gladstomych/AH…

JUMPSEC (@jumpsec) 's Twitter Profile Photo

A great weekend for our #Adversary simulation team at BSides Cymru. Big shout out and thanks to Sunny and maxicorbs for fantastic presentations and some great insights. A job well done! JUMPSEC LABS #redteam #bsides

A great weekend for our #Adversary simulation team at <a href="/BSidescymru/">BSides Cymru</a>. Big shout out and thanks to Sunny and <a href="/CorbridgeMax/">maxicorbs</a> for fantastic presentations and some great insights. A job well done!

<a href="/JumpsecLabs/">JUMPSEC LABS</a> #redteam #bsides
JUMPSEC LABS (@jumpseclabs) 's Twitter Profile Photo

Tool Release! We've been having a lot of fun recently bypassing swathes of security controls using alternative web technologies to smuggle payloads right past mail security products. We've open-sourced the tool that we've been using to leverage WASM: github.com/JumpsecLabs/WA…

JUMPSEC LABS (@jumpseclabs) 's Twitter Profile Photo

Imagine the feeling of a long-forgotten canary token triggering in one of your client's estates, which leads you down a path to catch and remove a sophisticated red team... No need to imagine, as Umair has written up a blog: labs.jumpsec.com/active-cyber-d…

maxicorbs (@corbridgemax) 's Twitter Profile Photo

🚀My biggest AI watershed moment since getting ChatGPT to write a poem in Jamaican dialect. I’ll be diving deeper into the security side of all this in my new blog 'Securing AI: A Learning Journey' Join the ride! 🧵👇 #AI #VibeCoding #MCP #LLMs maxcorbridge.substack.com

🚀My biggest AI watershed moment since getting ChatGPT to write a poem in Jamaican dialect.  

I’ll be diving deeper into the security side of all this in my new blog 'Securing AI: A Learning Journey'

Join the ride! 🧵👇 #AI #VibeCoding #MCP #LLMs 
maxcorbridge.substack.com
maxicorbs (@corbridgemax) 's Twitter Profile Photo

This week in 'Securing AI: A Learning Journey' I got hands on with the awesome #spikee tool. I also broke down the differences between prompt injection and jailbreaking attacks in the world of LLM cybersecurity. Check it out: maxcorbridge.substack.com #AI #cybersecurity

This week in 'Securing AI: A Learning Journey' I got hands on with the awesome #spikee tool. 

I also broke down the differences between prompt injection and jailbreaking attacks in the world of LLM cybersecurity.   

Check it out:  maxcorbridge.substack.com 

#AI 
#cybersecurity