Tarnkappe.info · @tarnkappeinfo
2313 followers · 4713 posts · Server social.tchncs.de
iCyberFighter · @iCyberFighter
325 followers · 325 posts · Server infosec.exchange

[] Microsoft has released a patch for a critical elevation of privilege that has purportedly been used by threat actors linked to Russian Military Intelligence to compromise multiple European organizations over the past year.

According to Microsoft, "The attacker could exploit this vulnerability by sending a specially crafted email which triggers automatically when it is retrieved and processed by the Outlook client. This could lead to exploitation BEFORE the email is viewed in the Preview Pane."

(External attackers could send specially crafted emails that will cause a connection from the victim to an external UNC location of attackers' control. This will leak the Net-NTLMv2 hash of the victim to the attacker who can then relay this to another service and authenticate as the victim.)

All supported versions of Microsoft for Windows are vulnerable. Online versions of Microsoft Outlook such as Android, iOS, Mac, as well as Outlook on the web and other M365 services are not affected.

There is a script to help determine if your organization was targeted by actors attempting to use this vulnerability.

Bottom line: Test and patch this ASAP if your org uses Outlook.

Links to more info: exchange.xforce.ibmcloud.com/v

msrc.microsoft.com/update-guid

#PatchNOW #zeroday #vulnerability #outlook #ntlmrelay #passthehash

Last updated 2 years ago

Matt "msw" Wilson · @msw
2350 followers · 1004 posts · Server mstdn.social

"AWS announces Credential Guard support for Windows instances on Amazon EC2"

Protect those secrets!

An OS like has a hard time doing it without based security, provided by a like the one found in the .

aws.amazon.com/about-aws/whats

#pth #passthehash #ActiveDirectory #Security #AWS #nitrosystem #Hypervisor #virtualization #Windows #Lsass

Last updated 3 years ago

mrjhnsn :verified: :donor: · @mrjhnsn
147 followers · 109 posts · Server infosec.exchange

I have a client that is a royal pain to get any proper maintenance for security or upgrades for security scheduled, but thinks they are secure cuz they have, MFA, Sophos and users pass phishing tests.

I took one look at their AD and network and laughed at how pwnable it was.

Today I got back the results from the internal and low and behold... and a bunch of other shit I've been trying to get permission to fix.
I guess I'll get that scheduled now 🤣🤣🤣

#greybox #pentest #Kerberoasting #passthehash

Last updated 3 years ago