| Meritocracy | w00w00 |
| APT | FUZZYSNUGGLYDUCK |
| Hellsite | https://twitter.com/kikta |
| Meritocracy | w00w00 |
| APT | FUZZYSNUGGLYDUCK |
| Hellsite | https://twitter.com/kikta |
I'm confused about why CVE-2024-30078 hasn't gotten nearly any attention.
Is it the proximity need, by way of it being Wi-Fi?
I figured a pre-auth RCE in ALL VERSIONS OF WINDOWS would be getting some really hard attention.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30078
Do Fortinet make remote access devices?
Kinda…
This is exactly the sort of thing I am getting at when I drag policy suggestions to improve cybersecurity that require major investment. Microsoft has had the capability to prevent NTLM relay attacks available since *Win98*, but is only now making it the default for Win11.
Supposedly, the delay was because data transfer operations are impacted by enabling SMB signing… so upgrading from 10Mbps Ethernet to 100Mbps and then 1Gbps and beyond weren’t enough, but now two and a half decades later we’ve hit the magic LAN speeds to make this feasible and finally eliminate this class of attack??
We clearly remain fundamentally unserious about improving cybersecurity if this is where we are.