Yonathan Grunewald

988 posts

Yonathan Grunewald

Yonathan Grunewald

@yonigrin

npub1dj9luvqgquzhjm6hrla4nrhf4lyatd9pemzyl4dw50f2pfw3kddqmmz4h0

Jerusalem Katılım Temmuz 2011
534 Takip Edilen46 Takipçiler
Yonathan Grunewald
Yonathan Grunewald@yonigrin·
@TalMorgenstern מדיניות הפרטיות לעומת זאת, לכאורה מאפשרת להם לאסוף המון מידע, כולל אישי/עסקי. למשל הם מקבלים לא רק את הטקסט שמכתיבים אלא את הטקסט שבמסך של האפליקציה שמכתיבים לה.
עברית
0
0
1
90
Yonathan Grunewald
Yonathan Grunewald@yonigrin·
@orcarmi @Meir_Rubin הסוגריים שלך כל מהותן המשך התחפרות - אני תמיד בסדר וגם כשאני לא בסדר אני בסדר, ואין לי ספק שX לא בסדר. שורה תחתונה, כתבת תגובה צינית וארסית שקיבלה לייקים ושיתופים מחדש. גם על כותב הפוסט וגם על חבר הכנסת, אחרי ״בדיקה לא מספיק יסודית״…
עברית
0
0
0
33
מאיר רובין Meir Rubin
מאיר רובין Meir Rubin@Meir_Rubin·
מי שאחראים למחדל המטורף הזה צריכים לשבת בכלא. מצד אחד חוסמים פה ייבוא חקלאי מארה"ב או מאירופה מכל מינוי נימוקים מופרכים, או מטילים סטנדרטים מופרכים, מצד שני מכניסים רעלים קשים כדי שלא לעכב סחורה מהרש"פ במחסומי הבדיקה עד לקבלת תוצאות מעבדה.
גלי ישראל@IsraelGaley

ח"כ עמית הלוי בחשיפה מזעזעת: רעל פלסטיני בסלט שלכם בחסות המתפ"ש ח"כ הלוי הבוקר לשי גולדשטיין וארז תדמור: "השורה התחתונה היא שהסלט שאתם אוכלים מכיל הרבה מאוד רעל פלסטיני. פירות וירקות שמגיעים מכל מקום אחר בעולם נעצרים בנמל ומועברים למחסן עד שמבוצעת בהם בדיקה. אם נמצאות בהם דגימות רעילות - הם מושמדים. זה קורה בסחורה מכל מקום, חוץ ממקום אחד - מהרשות הפלסטינית. ולא רק שרוב התוצרת לא עוברת בדיקה, מה שמטורף הוא שגם מה שכן עובר בדיקה ונמצא שיש בו, לדוגמה, פי עשרה זרחן אורגני שגורם לפגיעה במערכת העצבים, בעוברים ואף מסרטן - גם כשזה מתגלה בדגימה, המשאית ממשיכה לעבור ולהיכנס לישראל" ארז: "זה קורה כי למתפ"ש הכי חשוב שהכלכלה הפלסטינית לא תיפגע. יש להם מטרת-על: לשמור עליה, גם אם המשמעות היא לשחרר רעל לאזרחי ישראל" הלוי: "אנחנו הרי בוגרי הקונספציה של השבעה באוקטובר שהתפוצצה לנו בפנים. אבל כאן אומרים לנו עכשיו: תשמרו על שקט, תאכלו רעל בשקט, תמותו בשקט..." צילום: נתי שוחט, פלאש 90

עברית
36
66
558
20K
Yonathan Grunewald
Yonathan Grunewald@yonigrin·
@orcarmi @Meir_Rubin למה שלא תבדוק *לפני* שאתה כותב או עונה? במיוחד תגובות קנטרניות כאלו…
עברית
0
0
0
95
Or Carmi • אור כרמי
@Meir_Rubin קראתי, ולשם שינוי מסתבר שאתה צדקת, ואני טעיתי: יש תימוכין של משרד הבריאות לטענות העובדתיות של מר הלוי (להבדיל מהטענות הפוליטיות). כשאני טועה - אני מתקן את עצמי, מוחק ומתנצל. ממליץ לך לנהוג באופן דומה.
עברית
4
0
2
150
Yonathan Grunewald retweetledi
The Mossad: Satirical and Awesome
BREAKING: MOSSAD ATTEMPTED MURDER IN NEW YORK That's right. A man named AHMAD MOSSAD has been charged with attempted murder for setting another man on fire in Times Square on March 16, 2025 using gasoline from his food cart leaving the victim in a coma for weeks. Finally you can all say "it was Mossad"
The Mossad: Satirical and Awesome tweet media
English
16
49
346
18.7K
Fabian Bader
Fabian Bader@fabian_bader·
#Entra sunday question: You have implemented a Conditional Access policy without any exclusions, enforcing MFA. Can somebody test a user + pwd combo without showing in the logs as 50074 - Strong Authentication is required?
English
7
2
19
5.4K
Ru Campbell
Ru Campbell@rucam365·
New post: focusing on the key biggest Microsoft 365 security considerations. READ: campbell.scot/microsoft-365-… When we talk about Microsoft 365 security, we are talking about two things: (a) securing Microsoft 365 the platform, (b) using Microsoft 365 security tooling.
English
4
23
127
8K
Merill Fernando
Merill Fernando@merill·
🤔 Imagine asking your tenant, "Do I have any global admins that don't have phishing resistant authentication?" and getting an instant, accurate answer without writing a single line of code. 🤯 The way we interact with Microsoft Graph is changing forever. In this episode of Entra Chat, we sit down with @Licantrop0 from the Entra AI Innovations team to discuss the launch of the Microsoft MCP Server for Enterprise. Why is this a big deal? 🌀 Solves the "Context Window" issue: Standard LLMs get confused by the massive amount of data in Graph APIs. This MCP server uses patented "magic sauce" (RAG + few-shot prompting) to translate natural language into optimized queries. 🌀 Admin Control is King: Unlike other AI tools, this isn't just "plug and play" insecurity. Admins explicitly provision the service principle and granularly assign permissions. You decide exactly what the AI can see. 🌀 Future-Proofing: While it’s currently read-only, the team is working on enabling write operations and even generating full PowerShell scripts from your prompts. Whether you are a developer looking to learn Graph or an admin tired of mundane reporting tasks or you are working with agents, this is going to be a standard part of the future of tenant management. Listen to the full deep dive here: entra.chat #MicrosoftEntra #MicrosoftGraph #AI #MCP #SysAdmin #CloudSecurity #PowerShell
Merill Fernando tweet media
English
10
18
105
6.4K
Yonathan Grunewald
Yonathan Grunewald@yonigrin·
@merill Sign in logs were just an example of licensed features that might affect data
English
0
0
1
40
Merill Fernando
Merill Fernando@merill·
@yonigrin The sign in logs are only used on two of the charts. You wouldn't gain much going back more than 30days
English
1
0
0
303
Yonathan Grunewald retweetledi
Merill Fernando
Merill Fernando@merill·
👋 Folks, I'm super excited to announce the launch of the Microsoft Zero Trust Assessment! I've been working on this project for the past year at Microsoft with an extended team including our security researchers, product feature teams and docs Here's what it does 🧵👇
Merill Fernando tweet media
English
35
167
790
57.5K
Tal Be'ery
Tal Be'ery@TalBeerySec·
For WhatsApp research, I need someone NOT in my WhatsApp contacts to help test non-contact visibility behavior (but preferably know each other from Twitter). Nothing malicious - just documenting the expected security boundaries. If you're interested, please DM
English
1
0
0
455
Sourav Kalal
Sourav Kalal@Ano_F_·
4 months of code, tests, and rewrites later {} ProxyBridge 2.0 is live! A Windows proxy client with full UDP support, authentication, rule-based routing, and more. UDP and proxying finally made simple ♥️ github.com/InterceptSuite…
English
1
1
0
158
Yonathan Grunewald
Yonathan Grunewald@yonigrin·
@RavivTamir 1. Why? What about customers that don’t want to onboard DCs to MDE and/or using other security products? 2. Will the development of standalone v2 continue? Will there be a standalone v3 ?
English
0
0
0
17
Yonathan Grunewald
Yonathan Grunewald@yonigrin·
@DebugPrivilege @NathanMcNulty To be fair, It’s in the product name..ofc requires permissions to fully function. User can manually choose the permissions they configure in Entra (like monitoring only). the worst is the “Wizard” that asks you to consent with a global a admin so they can do it for you :(
English
0
0
1
35
Nathan McNulty
Nathan McNulty@NathanMcNulty·
I bet at least 80% of Entra admins would blindly grant RoleManagement.ReadWrite.All to an Enterprise app that was purchased by their company Most wouldn't even know what that means - and in doing so, they practically give Global Admin level permissions to the application vendor
Stian A. Strysse@stianstrysse

@IAMERICAbooted Yeah, not long ago an app requested app role RoleManagement.ReadWrite.All - and by using Graph logs in a dev tenant I found out that the ONLY reason was that the automated onboarding process had to assign a non-GA Entra role to a service principal. 😵‍💫 «How ‘bout no»

English
15
41
255
60.2K
Yonathan Grunewald
Yonathan Grunewald@yonigrin·
@IceSolst @vercel Can’t believe you are so smart and yet, compare a random selfie with the unknowing Israeli PM with arming a ww2 camp. Do your research, like you do in InfoSec.
English
0
0
0
266
Yonathan Grunewald retweetledi
Sean Metcalf
Sean Metcalf@PyroTek3·
Over the weekend I wrote an ADSecurity.org article on "How to Improve Entra ID Security More Quickly" based on my recent @BSides_NoVA talk. This covers important areas including user & guest user configuration, Entra ID roles, admin protections, application permissions, conditional access policies, etc. adsecurity.org/?p=4825
Sean Metcalf tweet media
English
2
58
252
13.9K
Yonathan Grunewald
Yonathan Grunewald@yonigrin·
@NathanMcNulty Very true! + A. the logo can be copied in real time by phishing frameworks like nginx, can’t trust it blindly B. Great tip on wildcard-vendors (including MS) advise customers to whitelist *.blob.core.windows.net and other svcs through proxy/fw (for products to work). Don’t :)
English
0
0
0
17
Nathan McNulty
Nathan McNulty@NathanMcNulty·
This has been going on for a very long time, with varying degrees of responsiveness from Microsoft on takedowns If you use Defender for Endpoint, you really should be using the new streamlined connectivity Don't block all blob storage, you will break things. Check service URLs.
ALI TAJRAN@alitajran

ATTENTION: Phishing Attack Uses Azure Blob Storage to Impersonate Microsoft! Attackers have found a new method to trick end users into logging in to a malicious login page, intercepting tokens, and infiltrating the tenant. What makes this particularly sneaky is that they are using Microsoft URLs. The link they receive is forms.office.com followed by a value. Clicking that takes them to a strange URL with a PDF, which they then have to log in with their M365 account. And that's where the real danger lies. The URL ends in windows.net and is therefore considered valid. If you log in and the URL isn't login.microsoftonline.com, you can assume it's a bad one. Block the endpoint *.blob.core.windows.net entirely, and only allow access to the specific storage account you trust, like: .blob.core.windows.net Now that you're aware of this, please also set up company branding in your Microsoft 365 tenant! It helps users trust the sign-in page. When they see your logo and colors, they know it's safe. If they see a random portal, they'll think twice before entering their credentials! Read more: learn.microsoft.com/en-us/entra/fu… #Microsoft365 #EntraID #CloudSecurity #IdentityProtection

English
7
27
156
22.9K
Yonathan Grunewald
Yonathan Grunewald@yonigrin·
@alitajran Very true! + A. the logo can be copied in real time by phishing frameworks like nginx, can’t trust it blindly B. Great tip on wildcard-vendors (including MS) advise customers to whitelist *.blob.core.windows.net and other svcs through proxy/fw (for products to work). Don’t :)
English
0
0
0
103
ALI TAJRAN
ALI TAJRAN@alitajran·
ATTENTION: Phishing Attack Uses Azure Blob Storage to Impersonate Microsoft! Attackers have found a new method to trick end users into logging in to a malicious login page, intercepting tokens, and infiltrating the tenant. What makes this particularly sneaky is that they are using Microsoft URLs. The link they receive is forms.office.com followed by a value. Clicking that takes them to a strange URL with a PDF, which they then have to log in with their M365 account. And that's where the real danger lies. The URL ends in windows.net and is therefore considered valid. If you log in and the URL isn't login.microsoftonline.com, you can assume it's a bad one. Block the endpoint *.blob.core.windows.net entirely, and only allow access to the specific storage account you trust, like: .blob.core.windows.net Now that you're aware of this, please also set up company branding in your Microsoft 365 tenant! It helps users trust the sign-in page. When they see your logo and colors, they know it's safe. If they see a random portal, they'll think twice before entering their credentials! Read more: learn.microsoft.com/en-us/entra/fu… #Microsoft365 #EntraID #CloudSecurity #IdentityProtection
ALI TAJRAN tweet media
English
10
123
473
60.8K
Open Source Intel
Open Source Intel@Osint613·
BREAKING 🔴 Mohammed Nazal, a senior Hamas official in Qatar: “Hamas will not disarm. We will maintain control over Gaza’s security. This ceasefire is only a temporary ‘hudna’, a pause to rebuild our strength and regain some breathing room.”
Open Source Intel tweet media
English
2.1K
6.1K
11.5K
1.2M