Drew Hjelm (@drewhjelm) 's Twitter Profile
Drew Hjelm

@drewhjelm

I do #DFIR on occasion, but I also do other things too. Tweets do not reflect my employer’s views. Self-employed. GSE#236

ID: 1312880490

calendar_today29-03-2013 07:08:09

2,2K Tweet

320 Takipçi

848 Takip Edilen

Kyle Hanslovan (@kylehanslovan) 's Twitter Profile Photo

Whelp, wasn’t expecting this ConnectWise RCE to become public today. Guess we’ll publish on Monday how Huntress went from a researcher’s tweet to the ability to push ransomware through ~5,000 R1Soft servers that are exposed on Shodan. #staytuned connectwise.com/company/trust/…

Whelp, wasn’t expecting this ConnectWise RCE to become public today. Guess we’ll publish on Monday how <a href="/HuntressLabs/">Huntress</a> went from a researcher’s tweet to the ability to push ransomware through ~5,000 R1Soft servers that are exposed on Shodan. #staytuned connectwise.com/company/trust/…
Mayfly (@m4yfly) 's Twitter Profile Photo

Welcome to the new AD Mindmap upgrade ! v2022_11 will be dark only (this is too painful to maintain two versions). Thx again to : Viking and Hocine for their help 👍 Full quality and zoomable version here : orange-cyberdefense.github.io/ocd-mindmaps/i… Overview :

Welcome to the new AD Mindmap upgrade !
v2022_11 will be dark only (this is too painful to maintain two versions).

Thx again to : <a href="/Vikingfr/">Viking</a> and <a href="/Sant0rryu/">Hocine</a>  for their help 👍

Full quality and zoomable version here :
orange-cyberdefense.github.io/ocd-mindmaps/i…

Overview :
Matt Kelly (@breakersall) 's Twitter Profile Photo

How to do a $50k social engineering pentest in a couple minutes via OpenAI playground. 1/2: Create a EC2 instance with EvilGenX 3. Limit your firewall via iptables to only accept target IP addresses 4. Purchase a domain 🧵 1/2

How to do a $50k social engineering pentest in a couple minutes via OpenAI playground.
1/2: Create a EC2 instance with EvilGenX
3. Limit your firewall via iptables to only accept target IP addresses
4. Purchase a domain

🧵 1/2
Sam Sweeney (@sweeneyabc) 's Twitter Profile Photo

BREAKING: This morning’s catastrophic FAA computer failure was likely caused by a mistake made during routine maintenance. An engineer “replaced one file with another,” not realizing the mistake was being made. Josh Margolin

BREAKING: This morning’s catastrophic FAA computer failure was likely caused by a mistake made during routine maintenance. An engineer “replaced one file with another,” not realizing the mistake was being made. <a href="/JoshMargolin/">Josh Margolin</a>
Drew Hjelm (@drewhjelm) 's Twitter Profile Photo

Found a neat quirk in #Intune configuration - applying Security Baseline was causing the RDP button to not work in Windows 10. Couldn't find any settings that would just block RDP. Turns out the issue was the firewall settings blocking RDP from being enabled.

Drew Hjelm (@drewhjelm) 's Twitter Profile Photo

Today is the last delivery of a #Boeing747 jumbo jet, but did you know that plane was influential in the creation of the stripe on credit cards? #aviation #technology #cybersecurity #finance #fraud #riskmanagement npr.org/transcripts/47…

NOP__ (@nop_0x090) 's Twitter Profile Photo

1/This simple powershell command blocks ongoing OneNote attacks! (Microsoft Defender) Add-MpPreference -AttackSurfaceReductionRules_Ids D4F940AB-401B-4EfC-AADC-AD5F3C50688A -AttackSurfaceReductionRules_Actions Enabled 🧵 #CyberSecurity #phishing #OneNote #malware #ASR

Drew Hjelm (@drewhjelm) 's Twitter Profile Photo

I did a talk at CYPHERCON about #businessemailcompromise and #mfa bypass. It was fun to "steal" $240k on stage! Slides and notes here: helm.is/mailfraud

Xbox (@xbox) 's Twitter Profile Photo

The perfect way to play Bluey The Videogame: with a #Bluey Xbox! Follow and RT with #BlueyXboxSweepstakes for a chance to win a custom Official Bluey TV Xbox Series X & controller. Ages 18+. Ends 12/13/23. Rules: xbx.lv/47iZyTV

The perfect way to play Bluey The Videogame: with a #Bluey Xbox!
 
Follow and RT with #BlueyXboxSweepstakes for a chance to win a custom <a href="/OfficialBlueyTV/">Official Bluey TV</a> Xbox Series X &amp; controller.
 
Ages 18+. Ends 12/13/23. Rules: xbx.lv/47iZyTV
MrBeast (@mrbeast) 's Twitter Profile Photo

I’m gonna give 10 random people that repost this and follow me $25,000 for fun (the $250,000 my X video made) I’ll pick the winners in 72 hours

P4x (@_hyp3ri0n) 's Twitter Profile Photo

folks please help me get this word out. @Crowdstrike named some ransomware PunkSpider, literally the name of one of the pieces of software I made. Completely unrelated of course, mine is a security tool. This is NOT cool, appreciate RTs to get them to change this.

Brian in Pittsburgh (@arekfurt) 's Twitter Profile Photo

Here's the thing about being involved in risk management on any kind of professional basis in any way (whether it be cybersecurity, life & safety, whatever): You are inevitably going to find yourself in conflicts with people who *only* care about maximizing efficiency *now*.