Hey happy Monday! I hope you had super great weekend. I put time and attention into trying to deliver a valuable newsletter. A newsletter that I myself would look forward to reading. I hope I am able to deliver on that for you. If you do get value, please hit reply and let me know which section you like the most! Thanks so much 🙏 Have an awesome week! 🩺Threat PulseRansomware gang encrypted network from a webcam to bypass EDRWhat you should take away from this article:
Ransomware poseurs are trying to extort businesses through physical lettersRansomware criminals are some of the lowest of the low. Let this remind you that they will without a doubt do anything for a buck. Obviously if you get any kind of mail like this…do your due diligence and independently verify it. Chances are good it’s a scam because honestly who gets physical mail these days..😅 Silk Typhoon Targeting IT Supply ChainA long read (worthwhile if you have the time), but here’s some of my takeaways from this:
What you can do to protect your organization:
Cybercriminals picked up the pace on attacks last yearRansomware threat actors are banking on you moving slow to respond to threats. They are hoping your SOC/MDR/MSSP is slow to trigger alarms and send emails. They are hoping you’re caught up troubleshooting some network issue to investigate the potential security incident. The speed at which some threat actors are moving is concerning. One way to combat this, is with canaries. Dropping canaries, like the free ones from Thinkst CanaryTokens are really great early warning systems. I highly recommend using canarytokens to help defend your organization. Not only are they easy to use and maintain, but they provide HIGH fidelity, low false positive threat detection. 🔐Securing the StackHow NOT get hacked from a webcam… Step 1 - Change default passwords. One of the biggest banes of the IoT industry is default passwords. Develop a process for changing these defaults BEFORE rolling out to production. Step 2 - Network isolation. If you do nothing else…make 100% you’re absolutely sure that those webcams/IoT cameras are separated from your corporate LAN. There’s ZERO reasons to have them connected. Step 3 - Patch or replace. If you can’t patch it and it’s old and it’s vulnerable. Replace it. What are you waiting for? 😊 😆Memes & MayhemReddit doesn’t disappoint when you’re looking for a good laugh. If you have OCD you may NOT want to read this…. Ok this one really really cracked me up! hah. This person made a post on Reddit about how his sole job is to make Outlook search as miserable and terrible and rotten as possible. 🤣😂 Unfortunately, this post has since been taken down. You'll have to trust me it was pure gold. hah 👨💻Behind the ConsoleI’m working on a Windows Defender Application Control/PowerShell restrictions presentation with Michael Haag. Here’s the overly ambitious outline for it. We’re thinking about doing this live on March 21st 1pm eastern. Subscribe to my YouTube so you know when we go live. You can expect more and more YouTube content out of me in the coming months. That’s all for now. Hope you have a super awesome week!
|
Pentester/recovering sysadmin Self-proclaimed Ethical Threat Active Directory Security Connoisseur Offensive stuff — securit360.com Host Cyber Threat POV — offsec.blog SWAG — swag.ethicalthreat.com
What's up everyone! Happy Monday. It's another great week over here because yes, I am again on another internal pentest engagement. This time the clients in the financial services industry. The last few before that have been law firms. Lot of exciting stuff in the works for me personally and with SecurIT360, so stay tuned. Have an awesome week! I appreciate you being a part of this newsletter community. 🙏 🩺Threat Pulse Microsoft’s killing script used to avoid Microsoft Account in Windows 11...
Happy Monday! For those following cybersecurity news, this past week has been a doozy! While I hope this newsletter helps you stay up to date I am really focused on the insights we can obtain from all that’s going on. If you get value and you’d like to reciprocate, the best way to do that is by sharing my newsletter subscribe link on social media. Truly appreciate you! Have an amazing week. 🙏 🩺Threat Pulse VSCode extensions found downloading early-stage ransomware Two malicious Visual Studio...
It's been an incredibly busy few weeks over here, I haven't had much time to get outside and touch some grass. But the weather is getting warming and I am so ready for it! I hope you enjoy this weeks email! I would love if you would reply and tell me which parts you liked or didn't care for. It won't hurt my feelings, I promise! 🩺Threat Pulse Malicious Adobe, DocuSign OAuth apps target Microsoft 365 accounts Cybercriminals are deploying fake Microsoft OAuth applications disguised as Adobe and...