home.social

#blueteam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #blueteam, aggregated by home.social.

  1. PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: radar.offseq.com/threat/paperc #OffSeq #PaperCut #ZeroDay #BlueTeam

  2. PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: radar.offseq.com/threat/paperc #OffSeq #PaperCut #ZeroDay #BlueTeam

  3. PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: radar.offseq.com/threat/paperc #OffSeq #PaperCut #ZeroDay #BlueTeam

  4. PaperCut NG/MF hit by CRITICAL zero-days (CVE-2026-82078, CVE-2026-81578) exploited in AI-driven attacks. Remote code exec, credential theft, & domain admin escalation seen on 440+ deployments. Patch ASAP. Details: radar.offseq.com/threat/paperc #OffSeq #PaperCut #ZeroDay #BlueTeam

  5. 2026-09-10 RDP #Honeypot IOCs - 2139 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 2001
    165.22.57.45 - 18
    80.66.83.43 - 18

    Top ASNs:
    AS135905 - 2001
    AS14061 - 39
    AS396982 - 27

    Top Accounts:
    hello - 2046
    Administr - 27
    Test - 9

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 2001
    DigitalOcean, LLC - 39
    Google LLC - 27

    Top Clients:
    Unknown - 2139

    Top Software:
    Unknown - 2139

    Top Keyboards:
    Unknown - 2139

    Top IP Classification:
    Unknown - 2016
    hosting - 120
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  6. 2026-09-10 RDP #Honeypot IOCs - 2139 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 2001
    165.22.57.45 - 18
    80.66.83.43 - 18

    Top ASNs:
    AS135905 - 2001
    AS14061 - 39
    AS396982 - 27

    Top Accounts:
    hello - 2046
    Administr - 27
    Test - 9

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 2001
    DigitalOcean, LLC - 39
    Google LLC - 27

    Top Clients:
    Unknown - 2139

    Top Software:
    Unknown - 2139

    Top Keyboards:
    Unknown - 2139

    Top IP Classification:
    Unknown - 2016
    hosting - 120
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  7. 2026-09-10 RDP #Honeypot IOCs - 2139 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 2001
    165.22.57.45 - 18
    80.66.83.43 - 18

    Top ASNs:
    AS135905 - 2001
    AS14061 - 39
    AS396982 - 27

    Top Accounts:
    hello - 2046
    Administr - 27
    Test - 9

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 2001
    DigitalOcean, LLC - 39
    Google LLC - 27

    Top Clients:
    Unknown - 2139

    Top Software:
    Unknown - 2139

    Top Keyboards:
    Unknown - 2139

    Top IP Classification:
    Unknown - 2016
    hosting - 120
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  8. 2026-09-10 RDP #Honeypot IOCs - 2139 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 2001
    165.22.57.45 - 18
    80.66.83.43 - 18

    Top ASNs:
    AS135905 - 2001
    AS14061 - 39
    AS396982 - 27

    Top Accounts:
    hello - 2046
    Administr - 27
    Test - 9

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 2001
    DigitalOcean, LLC - 39
    Google LLC - 27

    Top Clients:
    Unknown - 2139

    Top Software:
    Unknown - 2139

    Top Keyboards:
    Unknown - 2139

    Top IP Classification:
    Unknown - 2016
    hosting - 120
    hosting & proxy - 3

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  9. 2026-09-10 RDP #Honeypot IOCs - 1426 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 1334
    165.22.57.45 - 12
    80.66.83.43 - 12

    Top ASNs:
    AS135905 - 1334
    AS14061 - 26
    AS396982 - 18

    Top Accounts:
    hello - 1364
    Administr - 18
    Test - 6

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 1334
    DigitalOcean, LLC - 26
    Google LLC - 18

    Top Clients:
    Unknown - 1426

    Top Software:
    Unknown - 1426

    Top Keyboards:
    Unknown - 1426

    Top IP Classification:
    Unknown - 1344
    hosting - 80
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  10. 2026-09-10 RDP #Honeypot IOCs - 1426 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 1334
    165.22.57.45 - 12
    80.66.83.43 - 12

    Top ASNs:
    AS135905 - 1334
    AS14061 - 26
    AS396982 - 18

    Top Accounts:
    hello - 1364
    Administr - 18
    Test - 6

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 1334
    DigitalOcean, LLC - 26
    Google LLC - 18

    Top Clients:
    Unknown - 1426

    Top Software:
    Unknown - 1426

    Top Keyboards:
    Unknown - 1426

    Top IP Classification:
    Unknown - 1344
    hosting - 80
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  11. 2026-09-10 RDP #Honeypot IOCs - 1426 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 1334
    165.22.57.45 - 12
    80.66.83.43 - 12

    Top ASNs:
    AS135905 - 1334
    AS14061 - 26
    AS396982 - 18

    Top Accounts:
    hello - 1364
    Administr - 18
    Test - 6

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 1334
    DigitalOcean, LLC - 26
    Google LLC - 18

    Top Clients:
    Unknown - 1426

    Top Software:
    Unknown - 1426

    Top Keyboards:
    Unknown - 1426

    Top IP Classification:
    Unknown - 1344
    hosting - 80
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  12. 2026-09-10 RDP #Honeypot IOCs - 1426 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 1334
    165.22.57.45 - 12
    80.66.83.43 - 12

    Top ASNs:
    AS135905 - 1334
    AS14061 - 26
    AS396982 - 18

    Top Accounts:
    hello - 1364
    Administr - 18
    Test - 6

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 1334
    DigitalOcean, LLC - 26
    Google LLC - 18

    Top Clients:
    Unknown - 1426

    Top Software:
    Unknown - 1426

    Top Keyboards:
    Unknown - 1426

    Top IP Classification:
    Unknown - 1344
    hosting - 80
    hosting & proxy - 2

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  13. 2026-09-10 RDP #Honeypot IOCs - 713 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 667
    165.22.57.45 - 6
    80.66.83.43 - 6

    Top ASNs:
    AS135905 - 667
    AS14061 - 13
    AS396982 - 9

    Top Accounts:
    hello - 682
    Administr - 9
    Test - 3

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 667
    DigitalOcean, LLC - 13
    Google LLC - 9

    Top Clients:
    Unknown - 713

    Top Software:
    Unknown - 713

    Top Keyboards:
    Unknown - 713

    Top IP Classification:
    Unknown - 672
    hosting - 40
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  14. 2026-09-10 RDP #Honeypot IOCs - 713 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 667
    165.22.57.45 - 6
    80.66.83.43 - 6

    Top ASNs:
    AS135905 - 667
    AS14061 - 13
    AS396982 - 9

    Top Accounts:
    hello - 682
    Administr - 9
    Test - 3

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 667
    DigitalOcean, LLC - 13
    Google LLC - 9

    Top Clients:
    Unknown - 713

    Top Software:
    Unknown - 713

    Top Keyboards:
    Unknown - 713

    Top IP Classification:
    Unknown - 672
    hosting - 40
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  15. 2026-09-10 RDP #Honeypot IOCs - 713 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 667
    165.22.57.45 - 6
    80.66.83.43 - 6

    Top ASNs:
    AS135905 - 667
    AS14061 - 13
    AS396982 - 9

    Top Accounts:
    hello - 682
    Administr - 9
    Test - 3

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 667
    DigitalOcean, LLC - 13
    Google LLC - 9

    Top Clients:
    Unknown - 713

    Top Software:
    Unknown - 713

    Top Keyboards:
    Unknown - 713

    Top IP Classification:
    Unknown - 672
    hosting - 40
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  16. 2026-09-10 RDP #Honeypot IOCs - 713 scans
    Thread with top 3 features in each category and links to the full dataset
    #DFIR #InfoSec

    Top IPs:
    14.225.19.59 - 667
    165.22.57.45 - 6
    80.66.83.43 - 6

    Top ASNs:
    AS135905 - 667
    AS14061 - 13
    AS396982 - 9

    Top Accounts:
    hello - 682
    Administr - 9
    Test - 3

    Top ISPs:
    Vietnam Posts and Telecommunications Group - 667
    DigitalOcean, LLC - 13
    Google LLC - 9

    Top Clients:
    Unknown - 713

    Top Software:
    Unknown - 713

    Top Keyboards:
    Unknown - 713

    Top IP Classification:
    Unknown - 672
    hosting - 40
    hosting & proxy - 1

    Pastebin links with full 24-hr RDP Honeypot IOC Lists:
    Bad API request, invalid api_dev_key

    #CyberSec #SOC #Blueteam #SecOps #Security

  17. Bitwarden introduces “Cupid Vault” — a 2-user shared Organization vault available on the free plan.

    Security considerations:
    • End-to-end encryption
    • Vault isolation from personal storage
    • Fingerprint phrase verification (anti-ATMIT enrollment control)
    • Bidirectional sharing
    • Revocable access

    Limitations: 2 users, 2 collections. No RBAC granularity (reserved for paid tiers).

    Question for practitioners:
    Is secure shared vault architecture preferable to federated identity or delegated access models for small trust groups?

    Source: bleepingcomputer.com/news/secu

    Join the discussion below.
    Follow @technadu for actionable security insights.

    #InfoSec #PasswordManagement #ZeroTrust #Encryption #AccessControl #CyberDefense #Authentication #SecurityArchitecture #BlueTeam #PrivacyEngineering

  18. Last week I participated in #SANS Veterans Day #CTF🚩

    After two days of competition, I solved 43 of 45 challenges and luckily won this contest.

    As a #network analyst, I especially enjoyed the challenge fx01 (File analysis eXtreme level): a PCAP with a custom protocol

    sans.org/mlp/veterans-day-ctf

    #cybersecurity #blueteam #dfir #pentest #reverseengineering #exploitation #networkanalysis

  19. **Nihilist - Cisco IOS Security Inspector**

    #network #cisco #security #audit #nihilist #python #hardening #netsec #defensive #network_security #blueteam #cisco_ios #netsec_tools

    Nihilist is a security auditing tool designed for security engineers to assess the configuration of their own Cisco devices.

    Before use, make sure that you have permission to analyze device configurations. Use of this tool must comply with local laws and not violate the policies of the organizations that own the devices being tested.

    - Nihilist is not designed to hack into Cisco devices and does not contain vulnerability exploitation features;
    - The tool works solely by reading the device configuration and does not make any changes. It does not require an account with maximum privileges (privilege level 15) to operate. It is sufficient to grant access only to execute show commands (read-only), which makes auditing as secure as possible;
    - Nihilist uses SSH-only remote connectivity.

    github.com/casterbyte/Nihilist

  20. **Nihilist - Cisco IOS Security Inspector**

    #network #cisco #security #audit #nihilist #python #hardening #netsec #defensive #network_security #blueteam #cisco_ios #netsec_tools

    Nihilist, (github.com/casterbyte/Nihilist) инструмент, предназначенный для аудита безопасности Cisco IOS. Функциональность данного инструмента позволяет оценить защищённость маршрутизаторов и коммутаторов Cisco. Nihilist работает путём подключения по SSH и анализа конфигурации с использованием регулярных выражений. Он проводит оценку защищенности IOS, канального и сетевого уровня инфраструктуры. В отличие от известного CCAT, Nihilist проводит более глубокий аудит конфигурации Cisco, анализируя не только факт включения механизмов защиты, но и их корректность и соответствие сетевой среде.

    Подробное описание и информация по установке: github.com/casterbyte/Nihilist

  21. Happy Monday everyone!

    The Cisco Talos Intelligence Group shares their findings of APT #SneakyChef using the #SugarGh0st malware that targets a scope of contries in the EMEA region who use documents that appear to belong to government agencies. The researchers state that this campaign is on a wider scale than the previously witnessed back in November of 2023 but with all the same calling cards (link to older article is the second bullet of the summary, its a good read as well).

    Looking at the older report, we get an idea of what these documents did and how the group gained access to their victims machines and some technical details:

    Notable MITRE ATT&CK Tactics, Techniques, and sub-techniques:
    TA0001 - Initial Access
    T1566.001 - Phishing: Spearphishing Attachment - A RAR document containing an LNK file was delivered to the victims. In the recent campaign, an SFX script executes to drop a decoy document, DLL loader, encrypted SugarGh0st, and a malicious VB script.

    TA0003 - Persistence
    T1037.001 - Boot or Logon Initialization Scripts: Logon Script (Windows) - The malicious VB script gained persistence by writing a command to the registry key "UserInitMprLogonScript" which will run whatever script is defined in the value when a user that belongs to either a local workgroup or domain logs into the system. The command in this instances was "regsvr32.exe /s %temp%\update.dll (the DLL came from the malicious SFX script).

    TA0004/TA0005 - Privilige Escalation or Defense Evasion
    T1055 - Process Injection - After the user logs into a machine, the command that targets the DLL dropped in the attack executes. This command reads the encrypted SugarGh0st RAT "authz.lib", decrypts it and injects it into a process.

    These are just some of the TTPs seen in the new attack but I would highly recommend checking out the older article to get some more technical information about past behaviors associated with SneakyChef and the SugarGh0st RAT. Enjoy and Happy Hunting!

    Article Source:
    SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniques
    blog.talosintelligence.com/sne

    November 2023 Article:
    blog.talosintelligence.com/new

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #Intel471

  22. Happy Wednesday everyone!

    The Check Point Software researchers highlight a recent attack by an adversary they call #VoidManticore and the tools, TTPs, and behaviors they observed. A notable technique was the deployment of different variants of wipers that, if you analyze some of the behaviors they exhibited, could be confused with ransomware. There was the destruction of shadow copies using vssadmin and abuse bcdedit to modify the boot configuration to prevent recovery. But the added activity of removing partition information is what revealed the wiper's true identity. It is a very good read and I highly recommend it! Enjoy and Happy Hunting!

    BAD KARMA, NO JUSTICE: VOID MANTICORE DESTRUCTIVE ACTIVITIES IN ISRAEL
    research.checkpoint.com/2024/b

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  23. Happy Thursday everyone!

    The Volexity team share their findings from a recent incident that involved the APT known as #CharmingKitten (aka #CharmingCypress) and what lengths this group went to make their attack look as convincing as possible. The Volexity team also shared technical details about the malware that was used, specific commands seen, and TTPs used. Enjoy and Happy Hunting!

    CharmingCypress: Innovating Persistence
    volexity.com/blog/2024/02/13/c

    As always, I don't want to leave you empty handed! So take this Community Hunt Package from Cyborg Security to help you identify discovery behavior from adversaries!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    volexity.com/blog/2024/02/13/c

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #huntoftheday #gethunting

  24. Happy Thursday everyone!

    The Volexity team share their findings from a recent incident that involved the APT known as #CharmingKitten (aka #CharmingCypress) and what lengths this group went to make their attack look as convincing as possible. The Volexity team also shared technical details about the malware that was used, specific commands seen, and TTPs used. Enjoy and Happy Hunting!

    CharmingCypress: Innovating Persistence
    volexity.com/blog/2024/02/13/c

    As always, I don't want to leave you empty handed! So take this Community Hunt Package from Cyborg Security to help you identify discovery behavior from adversaries!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    volexity.com/blog/2024/02/13/c

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #huntoftheday #gethunting

  25. Happy Thursday everyone!

    The Volexity team share their findings from a recent incident that involved the APT known as #CharmingKitten (aka #CharmingCypress) and what lengths this group went to make their attack look as convincing as possible. The Volexity team also shared technical details about the malware that was used, specific commands seen, and TTPs used. Enjoy and Happy Hunting!

    CharmingCypress: Innovating Persistence
    volexity.com/blog/2024/02/13/c

    As always, I don't want to leave you empty handed! So take this Community Hunt Package from Cyborg Security to help you identify discovery behavior from adversaries!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    volexity.com/blog/2024/02/13/c

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #huntoftheday #gethunting

  26. Happy Thursday everyone!

    The Volexity team share their findings from a recent incident that involved the APT known as #CharmingKitten (aka #CharmingCypress) and what lengths this group went to make their attack look as convincing as possible. The Volexity team also shared technical details about the malware that was used, specific commands seen, and TTPs used. Enjoy and Happy Hunting!

    CharmingCypress: Innovating Persistence
    volexity.com/blog/2024/02/13/c

    As always, I don't want to leave you empty handed! So take this Community Hunt Package from Cyborg Security to help you identify discovery behavior from adversaries!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    volexity.com/blog/2024/02/13/c

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #huntoftheday #gethunting

  27. Happy Thursday everyone!

    The Volexity team share their findings from a recent incident that involved the APT known as #CharmingKitten (aka #CharmingCypress) and what lengths this group went to make their attack look as convincing as possible. The Volexity team also shared technical details about the malware that was used, specific commands seen, and TTPs used. Enjoy and Happy Hunting!

    CharmingCypress: Innovating Persistence
    volexity.com/blog/2024/02/13/c

    As always, I don't want to leave you empty handed! So take this Community Hunt Package from Cyborg Security to help you identify discovery behavior from adversaries!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    volexity.com/blog/2024/02/13/c

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #huntoftheday #gethunting

  28. Does anyone else enjoy a 40 page intel report to start their morning? Well, here it is!

    The Morphisec research team provides an in-depth technical report on the #Chae$ malware. First discovered by Cybereason, the malware was seen targeting e-commerce customers in Latin America and now is on its 4th generation and has received some upgrades which include increases stealth capabilities and a shift to #Python. The malware includes 7 different modules which exhibit different behaviors. I won't spoil the rest of the fun, you're going to have to read on for yourself (honestly I couldn't fit all the relevant details in here there are so many!). Enjoy and Happy Hunting!

    Threat Profile: Chae$ 4 Malware
    morphisec.com/hubfs/Morphisec_

    #CyborgSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday

  29. Look what finally arrived!!! 🥳📚

    I was already feeling a bit jealous; everyone already received their preordered copy, but my author copy was still missing until now 😄

    ⭐️📖 Get the book: packt.link/MiriamCW

    #PowerShell #Security #Hacking #RedTeam #BlueTeam #Packt

  30. My team just released a new MFA bombing testing tool. It can be used in purple & red team modes to execute MFA fatigue/spamming/bombing on #Okta users. After we'll add more IdPs
    AFAIK it is the first MFA bombing tool for Okta.

    github.com/authomize/mfa-…

    #mfa #mfabombing #purpleteam #blueteam #redteam #RedTeamBlues #toolbox #mfafatigue #purplet

  31. Death by a thousand PaperCuts, China's APT41 uses new tricks to skirt EDR, and a pair of no-patch vulnerabilities take the front page in this weeks newsletter:

    opalsec.substack.com/p/soc-gou

    The #PaperCut vulnerability continues to garner interest, with Iran's Mint SandStorm (formerly #PHOSPHORUS) and Mango SandStorm (formerly #MERCURY) seen using it opportunistically. A completely new exploit chain demo'd by Vulncheck researchers highlights the limitations of detection rules for assurances, and why patching is a must.

    Earth Longzhi - a subset of the Chinese #APT41 Threat Group - has emerged after months in the shadows with new techniques seen in recent campaigns. Using Windows #Defender to side-load malware; the BYOVD technique to kill #EDR processes, and a newly discovered technique called "stack rumbling" to ensure they can't recover - this one is definitely one to check out.

    Fortinet have warned of a recent wave of exploitation of a 5-year-old vulnerability with no patches being exploited en masse in late April, while #Cisco reveal a CVSS 9.8 vulnerability they have no plans to patch in their End-of-Support #VoIP phone adapters.

    There's a bunch of great write-ups for those in the #redteam, looking at bypassing WAF protections by running tools like SQLMap over #Tor, how to minimise the size of your #XSS payloads, and highlighting a bunch of lab/ctf-style environments to cut your teeth on Azure, AWS, Kubernetes, and more.

    The #blueteam can brush up on commonly abused misconfigurations in Active Directory, #AzureAD, and #Microsoft365, as well as some excellent tips on hunting the Open Source Posh, Deimos, and Havoc C2 frameworks using #Shodan and #Censys.

    Elastic Labs have also outdone themselves last week, releasing a suite of tools to decrypt, decompress, recompile, extract and/or parse various malware payloads distributed in recent #IcedID campaigns.

    There's lots to dig through before starting your work week, so get started here:

    opalsec.substack.com/p/soc-gou

    #infosec #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #exploitation #malware #ransomware #affiliate #dfir #soc #threatintel #threatintelligence #threathunting #detection #threatdetection #detectionengineering #MangoSandstorm #MintSandstorm #Iran #EarthLongzhi #StackRumbling #clop #PoC #exploit #securityresearch #BYOVD #AWS #Azure #Kubernetes #GCP #PoshC2 #DeimosC2 #HavocC2

  32. Get up to speed on the week's infosec news before another week in the trenches:

    opalsec.substack.com/p/soc-gou

    Last week's patch Tuesday had SmartScreen bypasses and the Ping of Death, but nothing could beat the #Outlook zero-click credential leak that #Microsoft patche-er, uh, wait, no not quite patched - turns out you can still abuse it locally to harvest NTLM credentials, yikes!

    Non-transitive trusts have one job - to enable cross-domain authentication between only the two domains that maintain it. Turns out, that's not the case - you can actually pivot between domains and forests, authenticating to Services well outside the intended scope of the trust. And Microsoft aren't going to fix it.

    #Emotet have realised in week two of their return that there's more to life than Macros, and have joined in the abuse of #OneNote files to deliver their lures.

    In the world of ransomware, #BianLian have opted to focus on exfil-and-extortion campaigns, after Avast released a pesky decryptor for their ransomware in January this year. #CISA have opened their books and shared a detailed profile on #LockBit 3.0's favoured TTPs and tooling that's worth a read.

    #Google TAG have ousted Microsoft taking the easy way out in their previous patch of a SmartScreen bypass, opting to issue a half-baked patch that the #Magniber ransomware crew quickly circumvented, enabling them to deliver over 100,000 malicous lures unencumbered by the now-patched security control.

    If you're running Adobe's ColdFusion, Aruba ClearPass, or SAP software - you're going to want to make sure you caught and patched these vulnerabilities that debuted last week.

    #Redteam members have a new and improved AD lab environment to play in, as well as new evasion techniques for remote shells and macros to add to the toolkit!

    Offensive Security have a gift for the #blueteam in the defensive Kali Purple distro, and we've caught a bunch of awesome write-ups to help in scaling Detection Engineering and mitigating common initial access vectors.

    Catch all this and much more in this week's newsletter:

    opalsec.substack.com/p/soc-gou

    #infosec #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #soc #threatintel #threatintelligence #patchtuesday #adobe #ColdFusion #Aruba #ClearPass #SAP #Kali

  33. forgetting to change web admin credentials during red v blue event and just getting absolutely blasted for 5 hours straight

    tl;dr: I choked CCDC quals, AMA

    #infosec #ccdc #redteam #blueteam

  34. A rich #training #offer at BSides Milano we have top-notch trainings, in some case for the first time in #Italy! All #in-person! The #event will be held from 4 to 8 July 2023. From 4 to 7 we will be focus on #learnitall on the 8 we will deep dive in our #amazing #conference. Ticket will be available from tonight for the trainings. We have an early bird rate until 30th April.
    Are you ready? We are!! join our group SecurityBsidesItalia #linkedin or on #discord lnkd.in/dBu7wkJG for detailed info! #cyber #threatintelligence #threatintel #cloud #redteaming #redteam #blueteam #threathunting #exploitation #secureboot #TTE #multicloud #hybridcloud #voip #Linux #Windows #LTE #baseband #deception #detection #evasion #edr #BSML23 #AWS #Azure #AzureAD #GCP #devops #cicd #RTOS #FalseFlag #HoneyNet #IDAPro #Python #reverseengineering #Ghidra #network #MITRE #TTPs #persistence #commandandcontrol #lateralmovement #osint #obfuscation #malware #malwareanalysis .
    Reserve your your spot!! lnkd.in/dZf-yyPv