LOTS of new attacks! come check it out!
You thought you knew #hate_crack 👀 Version 2.0 changed that. In Part 1 of our latest blog series, Principal Security Consultant @Bandrel walks through 13 new attack methods, menu restructuring, and local LLM integration. Read it now! hubs.la/Q04ydtJR0
3
17
1,650
Justin Bollinger retweeted
Replying to @UK_Daniel_Card
1
5
582
Justin Bollinger retweeted
Using Apple's Corelocation you can identify network devices in areas where Wigle simply doesn't have coverage. This is Pine Gap, a joint Australian and United States satellite communications and signals intelligence surveillance base. You cannot get within 25KM before getting stopped. Using Apple's own infrastructure you can map out the location of over 140 Fortinet devices on the base.
27
164
1,768
110,923
Justin Bollinger retweeted
New: hackers say they have data on all FBI employees and spouses. I got a sample of 5,000 alleged employees, including name, physical address, phone number, and in some cases spouses. Could be a massive national security and counterintelligence risk 404media.co/we-hacked-the-fb…
345
2,383
6,595
1,077,355
Justin Bollinger retweeted
I am pleased to announce that I’ve accepted the role of Chief Scientist at @octane_security! I’m excited to be working with @giovignone, @paologentry, and everyone on the Octane team to help build the next generation of their awesome AI-powered security analysis service.
16
9
97
5,206
Justin Bollinger retweeted
There are two main password attacks leveraged by adversaries; one is called Password Spraying and the other is called Kerberoasting. This post focuses on identifying accounts that may be targeted for Kerberoasting and how to harden the environment against Kerberoasting. Password spraying involves the attacker using a list of passwords and for each password attempts to authenticate as each user using that one password. After working through all users with the first password, they move on to the next password in the list. Successful authentication is noted along the way as these are compromised accounts. I wrote about detecting password spraying here: trustedsec.com/blog/detectin… Kerberoasting is possible when an Active Directory account has a Kerberos Service Principal Name (SPN) associated with it. In order to enable Kerberos authentication for an application, the associated service account needs a SPN. Kerberoasting takes advantage of the fact that one can request a service ticket using the SPN associated with a target service account and take that Kerberos service ticket offline to attempt to crack it. Attackers are most likely to attempt Kerberoasting on the accounts with passwords that are about 5 years and older since they are more likely to have poor passwords, though attackers may just attempt kerberoasting all AD accounts that have SPNs. For more information on how Kerberoasting works as well as detecting Kerberoasting, read this article: adsecurity.org/?p=3458 I wrote a short PowerShell script that identifies all accounts with SPNs as well as Active Directory admin accounts with SPNs (leverages the Active Directory PowerShell module): github.com/PyroTek3/ActiveDi… TO DO LIST: Remove SPNs from AD Admin accounts associated with people since they shouldn’t have any SPNs associated with them. If the default domain administrator account is listed here, work to remove the SPN associated with it. This account should never have a SPN. Remove SPNs from the other accounts associated with people since they shouldn’t have any SPNs associated with them. Identify service accounts identified as AD Admin accounts (those that are members of Administrators, Domain Admins, or Enterprise Admins). Remove accounts that don’t belong and leave only those accounts that require these privileges (should be a minimal to 0 list of service accounts). Identify the AD Admin accounts that have old passwords (> 5 years) and put together a plan to change those passwords, preferably with a password of >25 characters. Identify the other accounts that have old passwords (> 5 years) and put together a plan to change those passwords, preferably with a password of >25 characters. IMPORTANT NOTE: Ignore the krbtgt account with regard to these directions as this is required to be configured this way for AD Kerberos to work. The KRBTGT account requires special attention: adsecurity.org/?p=4597 Reference: adsecurity.org/?p=4955
4
32
109
5,473
lol, I wake up and I have normies asking for tea about salesforce. I have no idea what’s going on. Who’s got some to spill?
2
10
1,124
Justin Bollinger retweeted
NOW PLAYING UwU Underground "$ELL THE CAGE" ▶ ━━━━━●──────── 04:06 ⇆ㅤ ◁ㅤ ❚❚ㅤ ▷ㅤ ↻ ♫ BABY, BUILD THE MONSTER, SELL THE CAGE ♫
32
80
220
18,639
Justin Bollinger retweeted
This is probably along the lines of where I am mentally. Can’t slow down now - it’s already out of the bag and we sure don’t want other adversary countries leading in this… but damn.. gonna be a rough road imo.
Palantir CEO Alex Karp says people arguing we should pause AI development are not living in reality and de facto saying we should let our enemies win: "If we didn't have adversaries, I would be very in favor of pausing this technology completely, but we do.” Via @cnbc
47
7
181
21,761
Justin Bollinger retweeted
I had a great time interviewing my friend @rekdt yesterday for the next episode of The Phillip Wylie Show! His episode drops Tuesday!
1
4
27
3,101
Justin Bollinger retweeted
59
646
2,871
160,680
Justin Bollinger retweeted
The Anthropic report on what TAs did with the models is a lot more interesting than the reports about models going sandbox spelunking during cyber evals.
3
12
113
6,362
Justin Bollinger retweeted
MS PAINT RCE!!1 🎨🖌️ "This attack requires a user to open a specially crafted file from the attacker to initiate remote code execution."
8
44
393
28,499
does anyone still review submissions to the @nmap fingerprinting db? nmap.org/cgi-bin/submit.cgi?…
2
1
11
856
Justin Bollinger retweeted
>sam altman: "we tried this because there were rumor on the internet" >rumor: math professor close to solving navier-stokes >the professor: using codex for a year >openai: has all his logs >checked every codex session tagged to N-S >found the most promising one >spun up 10,000 agents to finish the proof where he couldn't >they got caught >told the guy if you say anything you'll destroy your own career >he ruins his career over this >openai: "we did not see his work" >also openai: "we cannot rule out that de-identified data from their usage helped improve our models" they stole it lmao
732
12,578
91,388
3,983,572