Philippe Tremblay 🇨🇦🇫🇷 🇺🇦

2.5K posts

Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 banner
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦

Philippe Tremblay 🇨🇦🇫🇷 🇺🇦

@philtrem2000

Husband, father, teammate. IT Product Owner and Solution Architect with a passion for cloud, code and empowering teams.

Toronto Katılım Aralık 2008
2.1K Takip Edilen445 Takipçiler
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 Microsoft calls this "intended behaviour," so here we go. How to dump the credentials of every user stored in Microsoft Edge: 1. Open Edge. Don't browse anywhere, just open it. 2. Flip to Task Manager, find Edge, expand the task. 3. Highlight the "browser" sub-task,
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
288
2.3K
13.3K
1M
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
Vercel
Vercel@vercel·
Our investigation has revealed that the incident originated from a third-party AI tool with hundreds of users whose Google Workspace OAuth app was compromised. We recommend that Google Workspace Administrators check for usage of this app immediately. #indicators-of-compromise-iocs" target="_blank" rel="nofollow noopener">vercel.com/kb/bulletin/ve…
English
94
378
1.7K
1.5M
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
Feross
Feross@feross·
@SocketSecurity We dug into this more: The blast radius is larger than it looks. Axios only needed to be resolved somewhere in the dependency graph during the window (e.g. via CLI tools, npx installs, CI jobs, etc). In some cases, you can check now and see nothing, even if it ran. 🫥
English
3
12
41
5.2K
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
More relevant than ever …
English
1
17
125
28.1K
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
Steven Lim
Steven Lim@0x534c·
Best practices for securing Microsoft Intune In view of the March 11, 2026 cyberattack against U.S.-based medical technology firm Stryker Corporation, which affected their Microsoft environment. Microsoft has newly released the following guidance: techcommunity.microsoft.com/blog/intunecus…
English
8
62
293
34K
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
Scott Hanselman 🌮
Scott Hanselman 🌮@shanselman·
daylight savings sucks Now I’m jet lagged and I haven’t even gone anywhere
English
12
8
220
16.5K
Rapid7
Rapid7@rapid7·
🚨 On 2/6/26, #BeyondTrust disclosed a critical RCE vulnerability affecting its Remote Support (RS) and Privileged Remote Access (PRA) products. The flaw has been assigned CVE-2026-1731 and a near-maximum CVSSv4 score of 9.9. More in the Rapid7 blog: r-7.co/4arAjln
English
9
28
68
10.4K
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs - update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe - file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll - network IOCs
Florian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet media
English
33
541
2.2K
419.4K
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
For convenience: I wrote a small collector that pulls all SHA-256, SHA-1 and MD5 hashes from Notepad++ releases and compiles them into big CSV + JSON files Use it to check if any Notepad++ installs in your org match known-good release hashes - and spot weird/malicious outliers
Florian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet media
English
17
142
909
192.7K
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
ian bremmer
ian bremmer@ianbremmer·
the brand new sensation that’s sweeping your nation it’s our special military operation m.youtube.com/shorts/Xq4TpiK…
English
16
35
149
50.1K
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
tobi lutke
tobi lutke@tobi·
My annual MRI scan gives me a USB stick with the data, but you need this commercial windows software to open it. Ran Claude on the stick and asked it to make me a html based viewer tool. This looks... way better.
tobi lutke tweet media
English
1K
1.8K
33.2K
7.5M
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
What frequently happens when people read threat reports is 1. they notice the IOCs 2. go to Virustotal and check if their org's AV covers the threat But they shouldn't stop there. They should click on "Security vendor's analysis on: ..." 3. select the earliest date 4. check
Florian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet mediaFlorian Roth ⚡️ tweet media
English
5
45
300
27.9K
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
tobi lutke
tobi lutke@tobi·
Amazing performance Blue Jays. We are still proud of you. Onwards.
English
44
65
1.5K
55.3K
Philippe Tremblay 🇨🇦🇫🇷 🇺🇦 retweetledi
Jake Williams
Jake Williams@MalwareJake·
The timelines in this CISA directive to patch F5 vulnerabilities are not grounded in the risk posed. The required remediation timelines have been artificially extended to ensure there's a possibility for compliance given staff impacted by the shutdowns. cisa.gov/news-events/di…
English
5
12
52
5.7K