274 Followers
55 Following
45 Posts
This machine kills passwords.
Twitterhttps://mobile.twitter.com/breditor
Okta Security teamhttps://sec.okta.com/articles
That was unexpected
Great story about a Microsoft security person who discovered the Golden SAML issue in ADFS and lobbied unsuccessfully to get it fixed long before SolarWinds. Particularly relevant now as Microsoft says it will pivot to doing security first over new features. #infosec https://www.propublica.org/article/microsoft-solarwinds-golden-saml-data-breach-russian-hackers
Whistleblower Says Microsoft Dismissed Warnings About a Security Flaw That Russians Later Used to Hack U.S. Government

Former employee says software giant dismissed his warnings about a critical flaw because it feared losing government business. Russian hackers later used the weakness to breach the National Nuclear Security Administration, among others.

ProPublica
This is a damning story: Microsoft knowingly chose its own profits over fixing a major SSO vulnerability that allowed the SolarWinds hack to take place. #technology #security https://www.propublica.org/article/microsoft-solarwinds-golden-saml-data-breach-russian-hackers
Whistleblower Says Microsoft Dismissed Warnings About a Security Flaw That Russians Later Used to Hack U.S. Government

Former employee says software giant dismissed his warnings about a critical flaw because it feared losing government business. Russian hackers later used the weakness to breach the National Nuclear Security Administration, among others.

ProPublica

From @paulbradleycarr of @sfstandard:

https://sfstandard.com/opinion/2024/06/12/opinion-crypto-bros-trump-fundraiser/

By framing Trump as the crypto candidate (as opposed to something else), the right hopes to unlock millions in donations from Bitcoin billionaires and NFT moguls who sold at the top of the market. In return, the crypto bros expect a president who will slash regulation and thus reduce the risk of their peers becoming bunkmates with Sam Bankman-Fried.

...

The truth is, what we’re seeing is not a change in Valley politics but a shift in power and attention away from the kind of leaders and companies who would sign a letter opposing Trump, towards the kind who would do whatever it takes to elect the guy who will keep their pals out of jail. An industry that once elevated innovators and mavericks today elevates grifters and jailbirds.

Opinion | Crypto bros are the most powerful new donor class—Trump’s SF fundraiser proved it

Donald Trump's new crypto buddies are convicted fraudsters, alleged gropers and bilkers fined billions of dollars. The ‘disrupters’ are lining up early in hopes of a pardon pipeline.

The San Francisco Standard

We already did a large package of RDP-related articles a few months back; this article focuses on abuse related to the RD Gateway, RD Web Access, and RD Session Host roles.

https://news.sophos.com/en-us/2024/03/20/remote-desktop-protocol-the-series/

Remote Desktop Protocol: The Series

What is RDP, why is it a very nearly ubiquitous finding in incident response, and how can investigators run it to ground it when it goes wrong? An Active Adversary Special Report

Sophos News
There is something potentially huge popping up now. Has to do with a compromise at business intelligence vendor Sisense. I'm hearing this is a supply chain attack affecting many millions of credentials and hundreds of tenants. This is a message the Sisense CISO just sent to customers.

As an ex-Microsoft guy, it’s the end of an era. We can no longer say we will always need desktop apps because they can’t put Photoshop on the web.

https://blog.adobe.com/en/publish/2023/09/27/photoshop-streamlines-power-precision-web

Adobe Photoshop streamlines power and precision for the web | Adobe Blog

Photoshop on the web is now generally available with Generative Fill, Generative Expand and core desktop capabilities.

UNC3944 Leverages SMS Phishing Campaigns for SIM Swapping, Ransomware, Extortion, and Notoriety | Mandiant

Mandiant

Ransomware crooks exploit unpatched 0-day in Cisco security appliances

With no patch available yet, users must enable workarounds. The best: enforce MFA.

https://arstechnica.com/security/2023/09/ransomware-crooks-exploit-unpatched-0-day-in-cisco-security-appliances/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

Cisco security appliance 0-day is under attack by ransomware crooks

With no patch available yet, users must enable workarounds. The best: enforce MFA.

Ars Technica
New blog from Okta recommends phishing-resistant methods, restricting privileged accounts, and monitoring anomalies after they observed attackers using social engineering to gain privileged roles, abuse accounts, and impersonate users
https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection
Cross-Tenant Impersonation: Prevention and Detection

Summary

Okta Security