Olúwatóyìn

223 posts

Olúwatóyìn banner
Olúwatóyìn

Olúwatóyìn

@themultitee

Cybersecurity Enthusiast

Katılım Temmuz 2022
109 Takip Edilen16 Takipçiler
Olúwatóyìn retweetledi
NEDU
NEDU@Nedu_brazil01·
They asked their Nigerian mum to pronounce some English words 😂😂… she made it funnier than expected 😭
English
12
65
311
13.5K
Cisco Nerd
Cisco Nerd@OnijeC·
CCNP Sec ✅ God did 🙏🏽
Indonesia
111
50
631
13.8K
Jobs with Aramide
Jobs with Aramide@AramideOyekunle·
What's the motto of your secondary school? 😂
English
867
56
1.2K
184.3K
Awelewa 😍🥰❤️
Awelewa 😍🥰❤️@a4lasade·
Name a popular spot in your school and let people guess which institution you attend.
English
288
40
293
22.8K
Olúwatóyìn retweetledi
NaijaFarmer
NaijaFarmer@Nig_Farmer·
Wowwww....this makes a lot of sense. We learn new things everyday.
English
36
170
437
84K
Olúwatóyìn retweetledi
Oluwabukolami
Oluwabukolami@eleshomorenike·
If you are a lady, I just found an opportunity for you to learn AI skills for free and get a certification. The duration is 3 hours and you will be taught by top women CEOs in different fields. Don’t miss out on this life changing opportunity. Link to Apply: founderz.com/ai-skills-4-wo… Reshare for every woman to benefit from this.
English
51
227
644
38.9K
Olúwatóyìn retweetledi
folowosele adeboye
folowosele adeboye@boye4christ2006·
Dear MSc and PHD students. Stop using ChatGPT to write research proposals. Here are websites that help you write better ones.
English
48
718
2.5K
304.5K
Peter Agboola
Peter Agboola@baba_Omoloro·
What's the total number of triangles in this triangle?
Peter Agboola tweet media
English
12
0
3
1.5K
NaijaFarmer
NaijaFarmer@Nig_Farmer·
Trivia Questions with NaijaFarmer 🎊🎊 How good are you with puzzles? Let's test you. Write out just five words that can be gotten from these letters. Let's go 🚀🚀
NaijaFarmer tweet media
English
123
8
59
7.7K
Olúwatóyìn retweetledi
The Sound
The Sound@thesoundhub_·
You are worthy of the highest worship and praise Jesus!
English
3
29
152
4.6K
Olúwatóyìn retweetledi
Talk Church
Talk Church@churchtalkative·
Lust will kill everything you built if you don’t have self control💯
English
24
438
1.9K
54.1K
Olúwatóyìn retweetledi
Judah Olorunmaiye
Judah Olorunmaiye@JudahMaiye·
Here are my brief thoughts on sermon preparations.
English
7
30
200
3.5K
Olúwatóyìn retweetledi
Olúmáyòwá.dev
Olúmáyòwá.dev@akintunero·
"If you really look closely, most overnight successes took a long time." – Steve Jobs
English
5
15
96
3.1K
Olúwatóyìn retweetledi
Elizabeth Ekedoro
Elizabeth Ekedoro@Lizettle_·
𝗨𝗿𝗴𝗲𝗻𝘁 𝗰𝗮𝗹𝗹 𝗳𝗼𝗿 𝗮𝗹𝗹 𝗖𝗜𝗦𝗢𝘀 𝗮𝗻𝗱 𝗘𝗺𝗽𝗹𝗼𝘆𝗲𝗲𝘀 𝗪𝗵𝗼 𝗨𝘀𝗲 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗧𝗼𝗼𝗹𝘀 I read about a newly identified 𝗣𝗵𝗶𝘀𝗵𝗶𝗻𝗴 𝘁𝗲𝗰𝗵𝗻𝗶𝗾𝘂𝗲 called "𝗖𝗼𝗣𝗵𝗶𝘀𝗵" and I thought to share. This attack exploits Microsoft’s Copilot Studio agents to steal OAuth (access) tokens. 𝗪𝗵𝗮𝘁 𝗺𝗮𝗸𝗲𝘀 𝗶𝘁 𝘀𝗼 𝗱𝗮𝗻𝗴𝗲𝗿𝗼𝘂𝘀? The link looks perfectly safe ( because it’s a real Microsoft URL) but behind it is a malicious chatbot asking you (or your admin) to "sign in" or "grant access." Once you do, attackers can quietly steal your session token and access company data undetected. 𝗔 𝘀𝘂𝗺𝗺𝗮𝗿𝘆 𝗼𝗳 𝗵𝗼𝘄 𝘁𝗵𝗶𝘀 𝗮𝘁𝘁𝗮𝗰𝗸 𝘄𝗼𝗿𝗸: - Attackers build fake Copilot agents using Microsoft’s Copilot Studio. - These agents live on genuine Microsoft sites, making them appear trustworthy. - When you log in or approve access, your authentication token is sent to the attacker. - Since the URL is a legitimate one, it is easier for a user to fall for the trick and log in thinking it is just another Microsoft Copilot service. - Because the token was sent from Copilot using Microsoft's IP address, the connection to the attacker will not show in the user's web traffic. 𝗪𝗵𝘆 𝘁𝗵𝗶𝘀 𝗺𝗮𝘁𝘁𝗲𝗿𝘀: Phishing isn’t just about fake emails anymore. Trusted platforms are now being abused to bypass traditional defenses. What this means is that, "safe domain" doesn’t always mean "safe page." 𝗥𝗲𝗰𝗼𝗺𝗺𝗲𝗻𝗱𝗮𝘁𝗶𝗼𝗻𝘀: 1. Set up rules in Microsoft Entra ID to ensure users cannot grant permissions to risky or unverified apps without an admin checking them first. 2. Disable default user app creation, preventing regular users from registering or deploying new applications unless necessary. 3. Security teams should closely monitor logs for new Copilot agents or app permission requests. 4. Train your employees to question unexpected consent or sign-in requests. 5. Encourage reporting by making it easy for employees to report anything odd. 6. Finally, review and revoke unused or suspicious OAuth tokens to reduce the attack surface and stop potential misuse of outdated credentials. 📌 Microsoft has confirmed a fix is coming, but awareness is our best defense right now. 📷 Below are images showing the Microsoft-hosted login page and how the CoPhish attack works. 𝗜𝗺𝗮𝗴𝗲 𝗦𝗼𝘂𝗿𝗰𝗲: Datadog Tag every CISO and Security Analyst you know in the comments. #CyberSecurity #Phishing #CoPhish
Elizabeth Ekedoro tweet mediaElizabeth Ekedoro tweet media
English
8
115
386
33.4K
Olúwatóyìn retweetledi
RAVI KUMAR SAHU
RAVI KUMAR SAHU@RAVIKUMARSAHU78·
Don't copy and paste answers from ChatGPT!!! ChatGPT writing is easily detectable. Here's a secret hack to humanize your text:
English
29
49
382
1.8M
Jobs with Aramide
Jobs with Aramide@AramideOyekunle·
Who’s interested in Graphic Design, Logo Design, Photoshop, Adobe Illustrator, or Portfolio Creation? I’ve got fully loaded material for you — all for FREE!
English
2.5K
497
5.2K
366.4K