Gal Shpantzer

54.1K posts

Gal Shpantzer

Gal Shpantzer

@Shpantzer

Information security and data engineering advisor. Virtual CISO with interdisciplinary skillset to solve complex business and technical problems. Not CISSP/10X

Wherever there's trouble Katılım Şubat 2009
4.7K Takip Edilen10.6K Takipçiler
Sabitlenmiş Tweet
Gal Shpantzer
Gal Shpantzer@Shpantzer·
Availability is the new confidentiality(TM). Gal Shpantzer, 2016
English
2
3
24
0
Gal Shpantzer
Gal Shpantzer@Shpantzer·
Reposting some ransomware stuff from years ago, thinking about how this stuff evolved and how many are still vulnerable to/surprised by ye olde ways
English
0
0
0
124
Gal Shpantzer retweetledi
John Lambert
John Lambert@JohnLaTwC·
This #ransomware has no Word macro. It tricks users to run the embedded OLE package and delete their backups.
John Lambert tweet mediaJohn Lambert tweet media
English
8
135
110
0
Gal Shpantzer retweetledi
NetBlocks
NetBlocks@netblocks·
⚠️ Update: It has now been 24 hours since #Iran implemented a nationwide internet shutdown, with connectivity flatlining at 1% of ordinary levels. The ongoing digital blackout violates the fundamental rights and liberties of Iranians while masking regime violence ⏱
NetBlocks tweet media
English
530
2.4K
4.1K
428.8K
Gal Shpantzer retweetledi
Stephan Berger
Stephan Berger@malmoeb·
This one here is a goodie! A customer called us because they had several incidents where the system time "magically" jumped days, sometimes even months, back and forth (see screenshot). You can imagine the issues inflicted by this behavior. So the question was.. Cyber? Attacker? Misconfiguration? If you have never heard of Secure Time Seeding, you might want to read the article on Ars Technica. It might save your day eventually. [1] Microsoft introduced the time-keeping feature in 2016 as a way to ensure that system clocks were accurate. Windows systems with clocks set to the wrong time can cause disastrous errors when they can’t properly parse timestamps in digital certificates or they execute jobs too early, too late, or out of the prescribed order. “You may ask - why doesn’t the device ask the nearest time server for the current time over the network?” Microsoft engineers wrote. “Since the device is not in a state to communicate securely over the network, it cannot obtain time securely over the network as well, unless you choose to ignore network security or at least punch some holes into it by making exceptions.” To avoid making security exceptions, Secure Time Seeding sets the time based on data inside an SSL handshake the machine makes with remote servers. Despite the checks and balances built into STS to ensure it provides accurate time estimates, the time jumps indicate the feature sometimes makes wild guesses that are off by days, weeks, months, or even years. 🤯 You can turn this feature off, as our client did. [2] [1] arstechnica.com/security/2023/… [2] #secure-time-seeding" target="_blank" rel="nofollow noopener">learn.microsoft.com/en-us/windows-…
Stephan Berger tweet media
English
8
24
209
31.5K
Gal Shpantzer retweetledi
Stephan Berger
Stephan Berger@malmoeb·
In various business email compromise (BEC) cases, we later discovered that although the customer had set up a conditional access (CA) policy to enforce multi-factor authentication, mistakes had been made during the implementation of said policies. For example, certain resources were excluded, allowing attackers to access data despite the policy. In other cases, specific user agents were excluded. The list is relatively long. There are various tools that allow you to automatically test different login processes, user agents, and resources. I briefly tried NoPrompt over the weekend, and it was super easy to use. [1] This is also a simple step that I, as a cloud administrator, can take to identify low-hanging fruit for attackers. Otherwise, you might lull yourself into a false sense of security that can be easily circumvented. [1] claranet.com/us/blog/noprom…
Stephan Berger tweet media
English
7
92
450
40.6K
Mick Douglas 🇺🇦🌻
Mick Douglas 🇺🇦🌻@bettersafetynet·
@DFS_JasonJ or... more disturbingly, those teams have been chronically under performing. There's a vast difference between good and... not. ;-)
English
1
0
4
364
Mick Douglas 🇺🇦🌻
Mick Douglas 🇺🇦🌻@bettersafetynet·
The problem here? These AI grifters are doing some insane damage. I had a chat w/ the cyber security director of REDACTED. They wanted to have AI fully automate all level 1 activity, CTI, and detection creation. When I explored what current state is w/ them, they got mad. 1
solst/ICE of Astarte@IceSolst

@bettersafetynet Founderspeak is generally delusional, marketing with the intent to get investors, never nuanced

English
15
19
300
35.8K
Gal Shpantzer
Gal Shpantzer@Shpantzer·
@anton_chuvakin Drink water, eat more fiber, eat less salt, wash your hands. The treadmill won’t stop.
English
0
0
0
52
Dr. Anton Chuvakin
Dr. Anton Chuvakin@anton_chuvakin·
Quick weird #question: is it valuable to continue giving the same security advice that people have been giving for 30+ years, IF you believe that it is philosophically correct? (1/2)
English
42
9
60
15.8K
Visegrád 24
Visegrád 24@visegrad24·
Sweden Deputy Prime Minister and Minister of Energy Ebba Busch stated today that "she's furious with Germany" for dismantling its nuclear power plants, causing a spike in energy prices in Sweden. Southern Sweden has record-high energy prices today due to having send electricity to Germany via undersea power cables today. Cold weather coupled with no wind has driven up the demand in Germany from other sources than wind. EU regulations force Sweden to send that electricity to Germany, driving up prices in southern Sweden today to be nearly 200 times higher than they are in northern Sweden. A 10-minute shower in southern Sweden costs around USD 5 during today's price spike. Ebba Busch added that Germany's decision to dismantle its nuclear power plants has also other detrimental effects for Europe: "I'm furious with the Germans. They have made a decision for their country, which they have the right to make; it's their right to decide. But it has had very serious consequences, also for the EU's competitiveness because we see that German competitiveness has dropped significantly." She said that Germany's actions have also reduced its ability to help Ukraine. - “After Russia's invasion of Ukraine, they still chose to dismantle their nuclear power plants... I respect that people can have different opinions about nuclear power plants, but we could have kept it. They are important because they are baseload power plants. Having access to such baseload power plants would have increased the transmission capacity from Germany to other electricity price areas in Europe, driving down prices for all of us"
Visegrád 24 tweet media
English
621
2.4K
13.7K
1.5M
Gal Shpantzer retweetledi
Halvar Flake
Halvar Flake@halvarflake·
Kinda wild that this "AI coding assistant" that creates GitHub PRs according to changes I request was almost entirely written by me prompting ChatGPT. About 700 lines of code, and really just two evenings performing iterated prompting & some cut/paste & some minor edits.
English
3
2
36
4.5K
Gal Shpantzer retweetledi
Matt Johansen
Matt Johansen@mattjay·
Got to connect with @RachelTobac on some of the latest AI deepfake news about Taylor Swift. Rachel is one of the top experts in all things social engineering and we decided to start recording our side chats for you all.
English
3
12
76
20.4K
Gal Shpantzer retweetledi
Robert Graham
Robert Graham@robertgraham·
Everyone: Telegram is encrypted. Experts: Telegram IS NOT an encrypted messaging app <CEO gets arrested> News: Telegram is an encrypted messaging app. Experts: Telegram IS NOT an encrypted messaging app.
English
93
1.2K
14.3K
897.9K
Gal Shpantzer retweetledi
Ray [REDACTED]
Ray [REDACTED]@RayRedacted·
This is what it looks and sounds like when your child breaks the world record at the Olympics. This is shot live from my perspective.
English
215
221
2.3K
264.3K
Gal Shpantzer retweetledi
Yarden Shafir
Yarden Shafir@yarden_shafir·
Please make this happen. I would love nothing more than to have an image parser run during a bugcheck
English
23
79
1.4K
67K
Gal Shpantzer retweetledi
Jake Williams
Jake Williams@MalwareJake·
Has anyone in my network deployed Copilot for Microsoft 365 and users feel they're getting $30/mo value from it?
English
49
15
93
45.7K
Gal Shpantzer retweetledi
JS0N Haddix
JS0N Haddix@Jhaddix·
Dear Platforms: Stored blind XSS is NOT social engineering
English
14
16
180
19K