

Yuval Gordon
105 posts

@YuG0rd
Security Researcher at Palo Alto Networks. Opinions are my own.




Took a break from LDAP, fell down the dMSA rabbit hole with @YuG0rd, and watched the snake eat its own tail. dMSA Ouroboros: self-sustaining credential extraction on patched Server 2025. Six commands. Survives attacker account deletion. huntress.com/blog/dmsa-ouro…













Wanting more from today's #BHEU talk on SCOM? Check out this two part blog series! 1️⃣ @unsigned_sh0rt maps SCOM’s roles, accounts, & trust boundaries, then shows how attackers can chain insecure defaults into full management group compromise. ghst.ly/3MBPeAW 🧵: 1/2


I feel like @YuG0rd's briefly mentioned new dMSA account takeover mechanism in his last blog didn't get enough attention. A new account takeover mechanism is on the horizon. I wrote a blog detailing it, releasing with a new BOF I wrote called BadTakeover specterops.io/blog/2025/10/2…





Akamai Hunt has uncovered a new strain of Docker-targeting malware that may be building the groundwork for a botnet. Read full write-up: akamai.com/blog/security-…







BadSuccessor is dead… or is it? The patch for CVE-2025-53779 fixed the priv-esc. While no longer a vulnerability, the tactic still applies in certain scenarios. Defenders should be aware of it. Details: akamai.com/blog/security-…





They fix badsuccessor but does anybody know how ? A restriction on who can create a dmsa ? 🤨