T

862 posts

T

T

@tde_sec

CTI

Katılım Nisan 2021
348 Takip Edilen258 Takipçiler
T retweetledi
Stephen Fewer
Stephen Fewer@stephenfewer·
We just posted our AttackerKB @rapid7 Analysis for the recent Cisco ASA 0day chain; CVE-2025-20362 and CVE-2025-20333. The auth bypass appears to be a patch bypass of an older 2018 vuln. The buffer overflow is in a Lua endpoint, but unsafe native code operations allow a buffer to be overflowed and memory corruption to occur. Full technical root cause analysis here: attackerkb.com/topics/Szq5u0x…
English
4
70
204
50.5K
T retweetledi
SpecterOps
SpecterOps@SpecterOps·
Lateral movement getting blocked by traditional methods? @werdhaihai just dropped research on a new lateral movement technique using Windows Installer Custom Action Server, complete with working BOF code. ghst.ly/4pN03PG
English
1
114
283
32.2K
T retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English
140
902
3.2K
470.7K
T retweetledi
ANY.RUN
ANY.RUN@anyrun_app·
🚨 #Salty2FA is a new #phishkit linked to #Storm1575. Active since June, it bypasses 2FA to gain access beyond stolen creds. Using a unique domain pattern and multi-stage chain, it targets finance, energy, telecom and more. Read analysis: any.run/cybersecurity-…
ANY.RUN tweet media
English
1
26
93
6.3K
T retweetledi
Mandiant (part of Google Cloud)
🚨 We identified a ViewState deserialization attack affecting Sitecore deployments. The attacker leveraged an exposed ASP[.]NET machine key to perform remote code execution. Get the full details, indicators of compromise, and defensive recommendations: goo.gle/47oNWll
Mandiant (part of Google Cloud) tweet media
English
0
26
80
11.1K
T retweetledi
AiTM Feed
AiTM Feed@AiTM_Feed·
The surge to 30,000 AiTM infrastructure detections on Wednesday this week was very much driven by pages[.]dev and workers[.]dev use. Rather than playing whack-a-mole we've been blocking those domains and so far have only blocked AiTM nothing legit!! YMMV #AiTM #Cloudflare
AiTM Feed tweet media
English
0
1
0
86
T retweetledi
AiTM Feed
AiTM Feed@AiTM_Feed·
If you want to block ShadowCaptcha campaigns blocking these three domains will help: - cloudshielders[.]com - analytiwave[.]com - analyticanoden[.]com There is heavy geo/user-agent/os detection going on, so you may not see click-fix but your users might #clickFix #shadowCaptcha
English
0
2
0
175
T retweetledi
CISA Cyber
CISA Cyber@CISACyber·
🕷️🚨 Scattered Spider threat actors are using social engineering techniques like phishing, push bombing & SIM swap attacks to target #CriticalInfrastructure orgs & commercial facilities. Check out our updated joint advisory for recommended mitigations. 👉go.dhs.gov/ioX
CISA Cyber tweet media
English
8
119
270
42.2K
T retweetledi
Unit 42
Unit 42@Unit42_Intel·
On July 19, Microsoft issued guidance on CVE-2025-53770, a variant of CVE-2025-49706. At the time of posting, a patch is not available. Learn more about Microsoft’s customer guidance as the situation evolves: msrc.microsoft.com/blog/2025/07/c…
Unit 42@Unit42_Intel

We are observing active global exploitation of critical Microsoft SharePoint vulns CVE-2025-49704 and CVE-2025-49706. Orgs worldwide are being targeted. Patch immediately. The exploits are real, in-the-wild and pose a serious threat. IoCs we've seen: bit.ly/4kQZS2e

English
2
34
89
25.1K
T retweetledi
C.J. May
C.J. May@lawndoc·
New Defender detection "Suspicious Cloudflared Tunnel" 🔎 This detection will alert on Cloudflare tunnels that don't belong to your organization by parsing the --token parameter and checking it against your Cloudflare account ID. github.com/lawndoc/Advanc…
English
2
2
7
505
T retweetledi
SpecterOps
SpecterOps@SpecterOps·
Introducing the BloodHound Query Library! 📚 @martinsohndk & @joeydreijer explore the new collection of Cypher queries designed to help BloodHound users to unlock the full potential of the BloodHound platform by creating an open query ecosystem. ghst.ly/4jTgRQQ
English
3
113
283
21.8K