As a lawyer let me remind y'all that "UN-indicted co-conspirator" is not a legal term. It is a made up term to demonize Muslims, immigrants, & Black & brown people—simply anyone they want to depict as scary & dangerous.
An indictment requires "probable cause." "UN-indicted" means there wasn't even probable cause of wrongdoing. So when they attack Zohran for taking a photo with an "UN-indicted co-conspirator" they're pushing racist & bigoted propaganda—not facts. Recognize & reject it as such.
RE: https://infosec.exchange/@JohnHammond/115593709015887274
If you want to learn about how threat actors bypass MFA and security controls, this is a really good video. Spoiler: they just use infostealers.
It’s 2x real threat actor videos, where the threat actor recorded themselves. From 2023.
1st is YouTube account takeover replaying session cookie
2nd is corporate Outlook email theft using session token, via GraphAPI. As I’ve said before, attackers live in Graph now (yes, it’s a pivot of John Lambert’s saying).