Everett Cooley
2.6K posts


@UK_Daniel_Card Is there anything that Rami touches that DOESNT turn into freaking gold?
English


#Solarwinds are back in the CyberSecurity headlines today with their world-famous 'Solarwinds123' password (Google it).
Yet another hardcoded credential in Solarwinds product prompts CISA to add CVE-2024-2898 to Known Exploited Vulnerabilities (KEV):
👇
computing.co.uk/news/2024/secu…
Sam Stepanyan@securestep9
#Solarwinds: issues fixes for 9 Critical (CVSS 9.6) vulnerabilities: 👇 solarwinds.com/trust-center/s… Every time Solarwinds is mentioned I remember their CEO testimony to the Congress committee:
English

@SwiftOnSecurity Start…. I thought we were all members already 😂
English

@FrankMcG Source for this? Last I knew there wasn't a price per Service Principal.
English

By me @Forbes: Just when you thought it was safe to go back in the Windows water.
CVE-2024-6768 explained.
#infosec
forbes.com/sites/daveywin…
English

@awakecoding (New-Object -COM Shell.Application).WindowsSecurity()
English

@merill Very interested, you're always providing useful tools!
English

Dear Microsoft,
Quit messing with the AzureActivity logging tables. You are going to cause one of your customers to get hacked.
Sincerely me.....
So tldr; I've updated the detection for subscription privilege escalation in Azure. This detection also works if a compromised managed identity assigns rights to a compromised user id. I've posted the KQL query in my github.
I'm going back to red teaming your cloud now.
github.com/rootsecdev/Mic…
English
Everett Cooley retweetledi

this might catch it.....
EmailEvents
| where TimeGenerated > ago(180d)
| where SenderFromAddress == "mbsupport@microsoft.com"
| sort by TimeGenerated desc
English

@mckjerral @scottgu @AzureDevOps Typo or invisible character in the yaml reference to the existing build agent?
English















