

maxicorbs
148 posts
















Ending the year with a CVE from our Head of Adversarial Simulation @CorbridgeMax. Unauthenticated users are served the default Superuser account name and if the default password has been changed in IBM backup products, a single point of failure for backups labs.jumpsec.com/advisory-cve-2…


Did an investigation regarding DarkGate delivered by Teams together with my fantastic colleague Jakob Nordenlund at @Truesec. A lot of good IoC for all defenders! truesec.com/hub/blog/darkg…

Microsoft has identified highly targeted social engineering attacks by the threat actor Midnight Blizzard (previously NOBELIUM) using credential theft phishing lures sent as Microsoft Teams chats. Get detailed analysis, IOCs, and recommendations: msft.it/60199EEkv

Microsofts rebranding of Azure AD to Entra ID allows attackers to craft a nice fullchain attack. There were a lot good phishing domains not claimed, seems like Microsoft did not care about this. Made a PoC for @cyvisory. Details below:🧵👇





New tool exploits Microsoft Teams bug to send malware to users - @billtoulas bleepingcomputer.com/news/security/…