BeyondTrust Phantom Labs™

21 posts

BeyondTrust Phantom Labs™ banner
BeyondTrust Phantom Labs™

BeyondTrust Phantom Labs™

@btphantomlabs

Phantom Labs™ is driving innovation with cutting-edge threat research, vulnerability discovery, and real-world security insights.

Katılım Ekim 2024
43 Takip Edilen200 Takipçiler
BeyondTrust Phantom Labs™
BeyondTrust Phantom Labs™@btphantomlabs·
Breaking: Newly uncovered OpenAI Codex vuln enables command injection via GitHub branch names in task creation requests. Attackers could steal GitHub user access tokens & sensitive data. Full breakdown by Tyler Jespersen: lnkd.in/ewdTaiEa #OpenAI #BTPhantomLabs
BeyondTrust Phantom Labs™ tweet media
English
3
33
120
206.4K
BeyondTrust Phantom Labs™
BeyondTrust Phantom Labs™@btphantomlabs·
Heading to Seattle BSides next week? Don’t miss Sergio Garcia’s talk on the real identity attack surface and risks hidden in Bedrock. Live demo + detection. Feb 28 @ 2 PM. Event schedule: lnkd.in/eKfKF5We #Bsides #Bedrock
BeyondTrust Phantom Labs™ tweet media
English
0
1
0
140
BeyondTrust Phantom Labs™
BeyondTrust Phantom Labs™@btphantomlabs·
Secure your #Okta session policies with these 4 actionable tips (a thread) ⬇️ Misconfigurations within your global session policies can allow risky sessions and weaken access controls. Make sure that you check the following:
English
1
1
1
129
BeyondTrust Phantom Labs™ retweetledi
Fletcher Davis
Fletcher Davis@gymR4T·
Quick way to do passive Okta reconnaissance against an organization is by targeting the organization's metadata endpoint (.well-known/okta-organization). Here's an example using Curl:
Fletcher Davis tweet media
English
3
44
228
34.2K
BeyondTrust Phantom Labs™
BeyondTrust Phantom Labs™@btphantomlabs·
From guest access to Entra Admin in NINE steps?! Our research team recently exposed the “Evil VM” attack path - a new way attackers can hijack Azure VMs, steal PRTs, and take over your environment. Here's the 9 steps ⇾ lnkd.in/erv5Wh9u #EntraID #ZeroTrust
BeyondTrust Phantom Labs™ tweet media
English
1
0
3
154
BeyondTrust Phantom Labs™ retweetledi
SpecterOps
SpecterOps@SpecterOps·
Your certificate problems don’t end at the domain controller. In his #SOCON2025 presentation @gymR4T is exploring techniques to weaponize ADCS to gain access to the cloud through certificate template abuse and enrollment service manipulation.
SpecterOps tweet media
English
1
2
8
1.8K