New Warning — Microsoft Copilot AI Can Access Restricted Passwords

Red team hackers have accessed restricted passwords using Microsoft’s Copilot AI for SharePoint — here’s what you need to know.

Forbes

@tessarakt
Korrekt.

Nach der mir zugänglichen Presse-Darstellung ist die Bedrohung (#Threat) bislang noch nicht realisiert worden.

Nach weit verbreiteter "#VW-Denke" existiert diese #Gefahr damit nicht.

Ich muss zugeben, wirkliches #RisikoManagement habe ich auch erst bei einem der Marktbegleiter aus dem #Premium-Segment gelernt.

Und dort hätte dieses Setup den Betriebsreife-Index nicht erreicht, weil die #Pentests entweder fehlten oder fehlgeschlagen wären.

If you want coverage aka get the maximum out of tests such as #Pentests, Scans and #testing in general, you shouldn't have only DEV, TEST, STAGE/INT and PROD environments, you should also provide an AUTO environment. The AUTO environment would be focused on supporting automation, meaning in the web app case simplifying authentication for scanners, don't aggressively invalidate sessions, remove CSRF protection etc.
Same for mobile apps btw.
#devsecops #devops
Została wydana nowa wersja dystrybucji Parrot Security OS 6.2. Parrot Security OS to specjalistyczna dystrybucja Linuksa stworzona do testów penetracyjnych, informatyki śledczej, łamania zabezpieczeń, testów zabezpieczeń https://linuxiarze.pl/parrot-6-2/ #linux #debian #cybersecurity #pentests
Parrot 6.2

Została wydana nowa wersja dystrybucji Parrot Security OS 6.2. Parrot Security OS to specjalistyczna dystrybucja Linuksa stworzona do testów penetracyjnych, informatyki śledczej, łamania zabezpieczeń…

Linuxiarze.pl

When GRC asks the red team "What tools do you use to conduct your penetration tests?"

Ummm.... I don't know.... All of them?

....I just wrote some new ones this morning...

#infosec #pentests #redteam #hacking

Was super fun to attend #aws #reinforce but this guy and another are glad I’m home and I think some customers want me to get busy on their #pentests!

Our #usdHeroLab professionals have uncovered a vulnerability in the online store software #Gambio during their #pentests.

Our analysts discovered a vulnerability in the password reset functionality. Exploiting this vulnerability would enable an attacker to change the password for any account and take over, for example, the administrator account of the application.

The vulnerability was reported to the vendor under the Responsible Disclosure Policy.

👉 More details: https://herolab.usd.de/en/security-advisories/usd-2024-0002/

Our #usdHeroLab analysts examined the #SONIX Technology Webcam during their #pentests.

1️⃣ Vulnerability Type: Incorrect Permission Assignment for Critical Resource (CWE-732)

🚨 Security Risk: High

The vulnerability was reported to the vendor under the Responsible Disclosure Policy.

👉More Details: https://herolab.usd.de/security-advisories/usd-2023-0029/

#Announcement: On Friday, our #usdHeroLab colleagues published a major release of our BurpSuite Plugin #FlowMate: https://github.com/usdAG/FlowMate/releases/tag/v1.1

During BlackHat USA 2023 and DEF CON 31, our colleagues received a lot of helpful feedback on their #tool: The new version 1.1 contains bug fixes and some new features. In our video, Florian Haag explains the advantages and possible use cases in the context of #WebApplication #Pentests: https://www.youtube.com/watch?v=BJhRhGmDATw

#CheckItOut #Security #Pentesting #Hacking #Tools #Community #moresecurity

Release FlowMate v1.1 · usdAG/FlowMate

Changelog After hard work we are proud to release our next major release of FlowMate! We put a lot of effort into integrating new features and fixing bugs along the way. The changelog below gives a...

GitHub

The #BurpSuite extension #CSTC by @usdAG saved my a** during several web app #pentests.

It allows you to easily transform HTTP requests and responses.

Use it to save time when you would otherwise have to write a bunch of custom code!

Here's everything you need to know about it 👇

#Pentesting #AppSec #InfoSec #CyberSecurity #BugBounty #Hacking #Burp