This blog post explains a #phishing technique using #FIDO cross‑device authentication. An attacker can run an AitM proxy that shows a fake, OS‑like QR code prompt. The attack requires placing Bluetooth beacons within the victim’s Bluetooth range.
denniskniep.github.io/posts/14-fido-…#EntraID
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
Big LOLDrivers Update! 🚨
Here’s what’s new:
1️⃣ SIEM Queries: Now you can detect vulnerable/malicious drivers right inside your SIEM with ready-to-use queries for Microsoft Defender & Splunk.
2️⃣ Toolbox for LOLDrivers: A list of detection and scanning tools (Nessus plugin,…
hashcat v7.0.0 released!
After nearly 3 years of development and over 900,000 lines of code changed, this is easily the largest release we have ever had.
Detailed writeup is available here: hashcat.net/forum/thread-1…
321 Followers 483 FollowingIT Security #SBB / #schwyzerörgeli/ #Riaz #Gruyère / #zerowaste / j'aime la moutarde de bénichon / as old as MS-DOS / HCFG Fan
261 Followers 1K FollowingTech Lead CTI // Senior Security Analyst (@swisscom_csirt) at Swisscom // GSMA T-ISAC | Posts reflect my own opinions and not my employer | follow ≠ support
58 Followers 942 FollowingTech superhero 🦸♂️ Solving problems and making magic happen 💻️ 20+ years in IT management, and still having fun! 💪️ #ITManagement | #ManagedServiceProvider
375 Followers 780 FollowingInfoSec Technical Team Lead & Cyber 🤡 - ♥️ to be forever n00bing & enjoy a good 🍻 *MyViewsAreMyOwn* @a41con Orga, #DC4131 @defconch 🇨🇭🏴
245 Followers 1K FollowingI work as an InfoSec and Infrastructure specialist living in the U.K. In my spare time, I enjoy football and boxing! All views expressed here are my own.
231 Followers 502 FollowingDie Fehler der Vergangenheit möchte keiner mehr machen. Da kommt die Zukunft gerade recht, um neue zu begehen.
Wolfgang Schuch
7K Followers 2K FollowingRhino Security Labs is a top penetration testing and security assessment firm with a focus on cloud (AWS, GCP, Azure), network, and web application pentesting.
5K Followers 32 FollowingOfficial account for Cobalt Strike. Benchmark red teaming tool known for its flexibility and powerful user community. Follow for new releases and other updates.
4K Followers 411 Following@mitmproxy developer, making cloud more secure at @google.
Mostly active on https://t.co/oQYW6YsbwO and https://t.co/3TjzXTVFMO.
311 Followers 0 FollowingAn association for experts, practitioners, and learners with the shared goal of developing and expanding their knowledge of open-source intelligence techniques.
248 Followers 2 FollowingDie Redguard AG ist ein auf Informationssicherheit und Cyber Security spezialisiertes Unternehmen mit Sitz in Bern, Zürich und Neuchâtel.
143 Followers 63 FollowingBrought to you by BSides Switzerland (@BSidesHelvetia) We are @BSidesZurich cousin. Register to our newsletter at https://t.co/OUzUEoutQd #BSidesBE #StayTuned
7K Followers 2K FollowingGlobal leader in hands-on learning for enterprise and cloud security education. Join 40000+ infosec professionals from 130+ countries
20K Followers 438 FollowingHacker, Infosec Researcher, Military Affairs & History, PowerShell, AD and Azure pwner, Creator of Nishang and others :)
Founder @alteredsecurity
83K Followers 16 FollowingTrend Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
38K Followers 132 FollowingDetect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.
No recent Favorites. New Favorites will appear here.