David Eckel
@mcdave2k1
Cybersecurity nerd | Ethical hacker | Foodie | Hiker | Let's hack the digital world together! #ethicalhacking #infosec #dfir #kaeferjaeger
ID: 1291405375644864514
https://www.sectepe.de 06-08-2020 16:07:02
1,1K Tweet
526 Takipรงi
3,3K Takip Edilen
New downgrade attack can bypass FIDO auth in Microsoft Entra ID - Bill Toulas bleepingcomputer.com/news/security/โฆ bleepingcomputer.com/news/security/โฆ
Xbow raised $117M to build AI hacker agents, in Alias Robotics open-sourced it and made it completely free. Github: github.com/aliasrobotics/โฆ Paper: arxiv.org/abs/2504.06017
๐จ ๐ช๐ฒ'๐๐ฒ ๐๐ป๐ฐ๐ผ๐๐ฒ๐ฟ๐ฒ๐ฑ ๐๐ต๐ฒ ๐ณ๐ถ๐ฟ๐๐ ๐บ๐ฎ๐น๐ถ๐ฐ๐ถ๐ผ๐๐ ๐ ๐๐ฃ ๐๐ฒ๐ฟ๐๐ฒ๐ฟ ๐ถ๐ป ๐๐ต๐ฒ ๐๐ถ๐น๐ฑ. It was only a matter of time. The postmark-mcp npm package (1,500+ weekly downloads) has been backdoored since v1.0.16 - silently BCCing every email to the attacker's
We detected a new somewhat sophisticated campaign abusing spoofed Microsoft Teams installer. The malware is hosted on a legitimate looking website, which seems to be part of redirect chain. Each new download produces a unique file hash - so that is not reliable indicator. The
Intune now has dedicated security recommendations docs just like Entra ๐ฅ The Entra security docs are extremely popular, and I love seeing other teams publishing this kind of guidance Thanks to my collegaue (Josh Gatewood) for pointing this out! learn.microsoft.com/en-us/intune/iโฆ
OK, Rocket Software believes that the likelihood of my unauthenticated RCE "being exploited is rare"...๐คฆโโ๏ธ docs.rocketsoftware.com/bundle/trufusiโฆ #security
๐จ๐ฟ๐ด๐ฒ๐ป๐ ๐ฐ๐ฎ๐น๐น ๐ณ๐ผ๐ฟ ๐ฎ๐น๐น ๐๐๐ฆ๐ข๐ ๐ฎ๐ป๐ฑ ๐๐บ๐ฝ๐น๐ผ๐๐ฒ๐ฒ๐ ๐ช๐ต๐ผ ๐จ๐๐ฒ ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐ง๐ผ๐ผ๐น๐ I read about a newly identified ๐ฃ๐ต๐ถ๐๐ต๐ถ๐ป๐ด ๐๐ฒ๐ฐ๐ต๐ป๐ถ๐พ๐๐ฒ called "๐๐ผ๐ฃ๐ต๐ถ๐๐ต" and I thought to share. This attack exploits Microsoftโs Copilot