Black Hat 2023 – Las Vegas, NV – One of my personal focuses is understanding the “Why” behind changes in the threat landscape. In simple terms understanding the Why of something gives you a good understanding of potential pivots and changes. After all a personal Why is what motivates and moves you, it stands to reason that identifying the Why behind threat groups gives you an insight into their motivations and drivers (besides money). With this in mind I sat down with Don Smith, VP of Threat Intelligence, Counter Threat Unit. The same team that identified the abandoned reply URL flaw in Power Platform.
Microsoft has not been having the greatest of months. First it was identified that a stollen MSA signing key was used by a Nation State to access personal and low-side US government tenants (Low-Side it the unclassified side of Government Cloud Computing). This disclosure seems to have focused all of the attention on Microsoft as more and more security researchers are diving into their cloud services. That being said, there are and have always been researchers that keep Microsoft on their Radar, just because there is always something going on there. That is the case of the latest news to hit the street about Entra ID (formerly Azure AD).
Read more: Now Patched Flaw Leverages Abandoned Reply URL...
Black Hat 2023, Las Vegas – At Black Hat one of my favorite things to do is see what the latest buzzword(s)/phrases are. One of my favorites from this year was “code to cloud” while others focused on the big shiny object that is AI. Fortunately for me, I usually am afforded a chance to talk with amazing technical resources to allow me to continue my mission to cut through the marketing and get to the meat of the technology or issue. This brings me to my conversation with Denis Mandich, co-founder, and CTO of Qrypt, a quantum security company that has an interesting improvement on current methods to generate and provide access to true quantum random numbers (QRN).
Black Hat 2023 Las Vegas – One of the areas I wanted to focus on this year while at both Black Hat and Def Con was to get an understanding of the threat landscape from both an industry and attacker perspective. My conversations (I don’t really do interviews) all included parts that related to the general attack landscape. So, it only made sense that one of my conversations needed to be with ZeroFox For those of you that might not be aware, ZeroFox throws a great Black Hat party… no wait. ZeroFox is an external attack surface management company. If you only think of them in terms of social media intelligence, then you probably need to revisit them.
Read more: ZeroFox Talks about the Value of Proper Attack...
It used to be a common phrase that the only certain things are Death and Taxes. These days it seems the list has been extended to Death, Taxes, and 0-days in enterprise tools sets. We have seen a number of zero days being abused since the beginning of 2023 such as Barracuda spam filters, MoveIT MFT, Citrix File share MFT, and (the subject of today’s article) Ivanti’s Sentry (the service formerly known as MobileIron). The uptick in exploitation of 0-days is very concerning just on their own, but when looked at as part of a larger effort, it is borderline frightening.
Page 6 of 33