
ITCertDoctor(.com)
2.2K posts

ITCertDoctor(.com)
@ITCertDoctor
Active I.T. Infrastructure Engineer and Trainer I have an A+ and Network+ course you can get on my website


It’s a Lenovo. It will survive the apocalypse.

‼️🚨 BREAKING: Microsoft Exchange Server CVE-2026-42897 lets an attacker execute arbitrary JavaScript in a victim's browser just by getting them to open an email in Outlook Web Access. It is being exploited in the wild. Microsoft classified it as... "spoofing." 🤔 Affected: on-premises Exchange Server 2016, 2019 and SE. Exchange Online is not impacted.

Microsoft: PowerShell is simple and easy to use. Actual PowerShell command: Remove-MgIdentityAuthenticationEventFlowAsOnGraphAPretributeCollectionExternalUserSelfServiceSignUpAttributeIdentityUserFlowAttributeByRef No, this isn't a joke. This was noted by @NathanMcNulty


‼️🚨 MAJOR IMPACT: AI just found an 18-year-old NGINX critical remote code execution vulnerability. It has been disclosed on GitHub including PoC code. - Affects NGINX 0.6.27 through 1.30.0 - Triggered via the rewrite and set directives in config - Update NGINX ASAP - NGINX is a widely used HTTP web server, be sure to check its prevalence in other products


Ridiculous experiences with passwords… - cracked 4 20+ char pass phrases because they were popular Bible verses and song lyrics - guessed an admin password after cracking a service account hash that was named similarly to the admin account - cracked a RID 500 account that was configured as a service account, password was 7 characters - sprayed a password a client gave me on a purple team (for the telemetry) and found it was used on hundred of enabled accounts Let’s hear yours 😅











