پن کیا گیا ٹویٹ
Dave Bell
4.1K posts

Dave Bell
@operant
Partner at Blackthorne Consulting; Former Red Team Director at GE and US Navy; Advisory Board member; Navy veteran Opinions are my own @[email protected]
Virginia Beach, VA شامل ہوئے Şubat 2009
602 فالونگ1.7K فالوورز
Dave Bell ری ٹویٹ کیا

.@Volexity shares #threatintel on how #StormBamboo compromised an ISP to conduct DNS poisoning attacks on targeted organizations & abuse insecure HTTP software updates, delivering custom malware on both macOS + Windows.
Read the full analysis: volexity.com/blog/2024/08/0…
#dfir
English
Dave Bell ری ٹویٹ کیا

Our friends over at @redcanary are hiring! Their Intel Analyst role is a full-time #synapse enterprise user!
jobs.lever.co/redcanary/bb7a…
English
Dave Bell ری ٹویٹ کیا

Praetorian is hiring for another 3 red teamers at the lead+ level of experience.
Have to be lead or above for this hiring round, no junior or senior for the red team until next quarter, but there are other open positions on our website. We filled 29 reqs in Q1 and are scaling quickly but sensibly.
Our clients have mature environments, you won’t have an easy life; but if you like to be challenged, this is a good place for you.
**I am slow in DMs, best apply via our website but drop me a note
English

OK #CTI nerds, you're presenting at a conference and you get to pick walk-up music (max 45 seconds) - what are you picking?
Me? I'm going with the opening of Judas Priest's Nightcrawler (which I think I did for SANS CTI Summit in 2019?)
English
Dave Bell ری ٹویٹ کیا

Special Advisor for Cyberspace Operations INSCOM | Serves as an Advisor to the Deputy Chief of Staff (DCS) G-2, the US Army Intelligence and Security Command (INSCOM) Commanding General and staff, and the Army Staff. Open: March 05 to 19, 2024, usajobs.gov/job/779918300

English

@andrewshumate Besides me? lol yeah a few other folks definitely looked like the walking dead
English
Dave Bell ری ٹویٹ کیا
Dave Bell ری ٹویٹ کیا
Dave Bell ری ٹویٹ کیا

First, I want to compliment @Microsoft for being forthright with details. Some of the problems I see in this report, I SEE EVERYWHERE due to VULNERABLE DEFAULTS.
Let's start with creating malicious OAuth applications. By default, ANY USER can create app registrations and consent to Graph permissions as well as sharing 3rd party company data. In tenants where this is hardened, ability to create app registrations require Application Administrator or Cloud-Application Administrator and admins must consent to permissions used by the application whether local or from another tenant.

English







