Resta valido anche il metodo più “arcaico”: davanti anche al minimo dubbio, si alza il telefono, si chiama direttamente l’ente o l’ufficio interessato usando un contatto verificato e si chiede conferma 😅
AI may eventually become the new Cold War: everyone keeps building more powerful systems because they can’t afford to let the other side get ahead. Chip manufacturers may become the equivalent of uranium supplier controlling access to the resource that makes the race possible
Agreed on moving toward modern auth, but “modern” doesn’t automatically mean “more secure.” The right approach is migration and secure configuration of all protocols , also of the legacy protocols (yes it is possible) that are still widely used.
Just to be clear, this is NOT a PoC for CVE-2026-26119. It’s a nice python script that authenticates and calls WAC REST endpoints to perform code execution. You could achieve the same thing directly through the web interface. semperis.com/blog/what-you-n…
Super cool research from my colleague Shai Laron on new attack paths to Active Directory that can lead to full domain takeover 😜 . It was presented at Black Hat and he will be speaking again at DEF CON this weekend.
Don't miss this 💪 :
semperis.com/blog/identity-c…
Nested group memberships are a privilege-escalation machine waiting to happen. They’re hard to reason about, easy to mismanage, and almost impossible to audit. But suggest a flatter access model and people look at you like you’re an alien.
A few days ago, I published a complete overview of Windows dangerous privileges and how they can be abused. It might be a useful reference too
semperis.com/blog/windows-pr…
Although this is a well-known topic, it's still one of my favorites. I put together a concise reference covering the most dangerous Windows privileges, how they can be abused, and why you should think twice before assigning them 👉 semperis.com/blog/windows-pr…
Vi ricordo che, per le raccomandate inviate dall’Agenzia delle Entrate e da altri enti pubblici, è possibile attivare il domicilio digitale, che consentirà di ricevere direttamente le comunicazioni e le raccomandate sulla vostra PEC.
Turning an idea into something more concrete: importing vulnerable GPOs into Neo4j/BH and creating dedicated relationship edges to make GPO-based attack paths easier to visualize.