Cutting Through the Noise: Security Insights by Josh Foster

SEARCH

CATEGORIES

TAGS

    On-Prem Misconfigurations Lead to Entra Tenant Compromise 

    As enterprises continue to transition on-premises infrastructure and information systems to the cloud, hybrid cloud systems have emerged as a vital solution, balancing the benefits of both environments to optimize performance, scalability, and ease of change on users and administrators. However, there can be risks involved when connecting a misconfigured or ill-protected network to cloud…

    The Elephant In the Room – NTLM Coercion and Understanding Its Impact

    January 9, 2024
    Since introducing NTLM coercion techniques such as PetitPotam into the NodeZero platform, we frequently have security practitioners request help understanding these techniques and what impact they have to their enterprise. There is a lack of concise resources to inform Blue Teams on how these techniques work, and clearly distinguishing them from other misconfigurations/vulnerabilities in the…

    Cisco IOS XE Web UI Vulnerability: A Glimpse into CVE-2023-20198

    October 19, 2023
    On Monday, 16 October, Cisco reported a critical zero-day vulnerability in the web UI feature of its IOS XE software actively being exploited by threat actors to install Remote Access Tools (RATs) and backdoor vulnerable devices exposed on the internet.