Fabian Bader

1,081 Followers
256 Following
563 Posts

My Disobey talk "Are passkeys as secure as you think" is now available on YouTube

https://youtu.be/DQ4dnXibaoM?is=9CPtIvRQ8-uzOpWo

Microsoft just announced official support to store device bound Passkeys for Entra ID in the Windows Hello container. No app, no external hardware key but built in support. Sadly no attestation while in preview.

https://mc.merill.net/message/MC1247893

#Passkey #EntraID

MC1247893 - Microsoft Entra passkeys on Windows now support phishing-resistant sign-in | Microsoft 365 Message Center Archive

Microsoft Entra passkeys on Windows enable phishing-resistant, passwordless sign-in using Windows Hello on Entra-protected resources, including unmanaged devices. Public preview starts mid-March 2026. Organizations must opt in and configure policies to enable this feature; no impact occurs without activation.

We found that Wi-Fi client isolation can often be bypassed. This allows an attacker who can connect to a network, either as a malicious insider or by connecting to a co-located open network, to attack others.

NDSS'26 paper: https://www.ndss-symposium.org/wp-content/uploads/2026-f1282-paper.pdf
GitHub: https://github.com/vanhoefm/airsnitch

High-level article on the work by Dan Goodin: https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/ I'd say we bypass Wi-Fi encryption though, in the sense that we can bypass client isolation. We don't break Wi-Fi authentication or encryption. Crypto is often bypassed instead of broken. And we bypass it ;) If you don't rely on client/network isolation, you are safe: we can't just break any Wi-Fi network.

@jtig
Happy to see you

Today at 15:00 CET #YellowHat will start. It's a free live streamed conference around Microsoft Security and we have amazing speakers and topics lined up for you.

Register now to reserve your free spot.

https://yellowhat.live

#XDR #EDR #Defender #Microsoft #Security

Yellowhat

Yellowhat is a cutting-edge cybersecurity event dedicated to Microsoft Security Technology, offering advanced deep-dive sessions (level 400+) for seasoned professionals. It brings together experts and innovators to explore the latest tools, techniques, and strategies in securing digital environments. At Yellowhat, you’ll gain actionable insights, connect with industry leaders, and elevate your cybersecurity expertise to new heights.

Yellowhat

With the unified SOC experience there might be some ANRs you want to exclude from XDR correlation. Now you can!

Either using the UI or add #DONT_CORR# at the beginning of the ANR description.

https://learn.microsoft.com/en-us/defender-xdr/exclude-analytics-rules-correlation

Exclude analytics rules from correlation in Microsoft Defender XDR - Microsoft Defender XDR

Learn how to exclude specific analytics rules from the correlation engine to maintain static incident grouping behavior similar to Microsoft Sentinel.

So @cyb3rops has made a MongoBleed log detection tool https://github.com/Neo23x0/mongobleed-detector

I’ve tried it and it works on a pwned server.

GitHub - Neo23x0/mongobleed-detector: Detection Script for MongoBleed Exploitation

Detection Script for MongoBleed Exploitation. Contribute to Neo23x0/mongobleed-detector development by creating an account on GitHub.

GitHub

@_dirkjan and my joint talk at #TROOPERS25 is now available on YouTube.

"Finding Entra ID CA Bypasses - the structured way" @WEareTROOPERS

https://youtu.be/yYQBeDFEkps

#Entra #ConditionalAccess

TROOPERS25: Finding Entra ID CA Bypasses - The Structured Way

YouTube

Custom data collection in Microsoft Defender for Endpoint was just announced in the November release notes.

Documentation is already available

https://learn.microsoft.com/en-us/defender-endpoint/custom-data-collection

Predictive shielding sounds also very interesting...
#MDE #XDR

Microsoft Defender just got the September 2025 update

◽Improved core service startup behavior
◽ Security fixes for missing input validation of RPC services
◽Fixed threat exclusion handling
◽Restored performance optimization for network file access

https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-antivirus-updates#september-2025-platform-418250903009--engine-11250903001