Joshua Small
jsmall@infosec.exchange
Posts
-
Post #4342726
Microsoft's latest advisory has a bunch of slop related typos. Really the part that worries me is the take away from these sort of write ups is "Buy Nord VPN" or some stupid shit when Device Code phishing and Clickfix 100% do not care.
-
Post #4271272
Synergy Wholesale's SSL purchase form sure is something else.
-
Post #4229041
Are there any Ruby people with views on [CVE-2026-66066] ? The official release uses wording like "In a default configuration" but as far as I can see the exploit is down to using a specific method storing and user uploaded images and then doing something specific with them? Image manipulation has always been a huge attack surface, it's the sort of thing I always would have put in its own backend or container.
-
Post #4122154
Telstra Custdata logon (business DNS management) calling themselves "Multifactor" on an email magic link logon.
-
Post #4027903
One of the ways the security landscape has changed - which I haven't seen discussed - is that URL blocklists seem a lot easier for attackers to evade. I had a Clickfix incident three days ago. I used a https://app.any.run/ sandbox to replicate that loading the site, which was full of hidden online casino SEO spam, delivered a password stealer. Reported to Google Safebrowse, Fortigate, Palo Alto, Microsoft. Today the URL has absolutely 0 flags on Virustotal.
-
Post #3999735
What in hell is this Microsoft will the pilot group be included or exlcuded?
-
Post #3417964
The update to Microsoft's certification credentials is basically just a big removal of everything not AI related. For example, they've replaced "Microsoft Certified: Azure Security Engineer Associate" with "Microsoft Certified: Cloud and AI Security Engineer Associate (Exam SC-500)" and "Microsoft 365 Certified: Administrator Expert" with "Microsoft 365 Certified: AI Services Administrator Associate (Exam AB-650)". There's a whole bunch of st...