A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.
There’s so much missing in these reports, which vendors are missing out.
Eg the main ‘attack’ was on a bank portal which had no form of MFA (at all). They also scraped the customer records by changing the account number in the URL.
@sawaba the devices had admin accounts with known passwords from prior breaches, and the attackers dumped the config including password hashes and then cracked the hashes
This thread is for those InfoSec leaders circulating the ‘OpenAI has solved maths’ posts. There’s a lot of them. Try asking experts in the field, rather than repeating corporate claims.
All credits to them for explaining this btw. The UK power station thing being targeted by Iran recently was actually foundational issues, same with the US water treatment incidents.
Because orgs don’t openly talk about what actually causes security incidents, it’s left a void of AI techbros filling executive ears.
@da_667 yep, it was during their ‘what’s next for Windows’ live stream two days ago.
They ended up with fewer viewers than before the presentation started, as they spent the entire hour talking about AI.. people roasted them in the comments and stopped watching.
The presentations had multiple typos in them, microphones didn’t work, the auto queue didn’t work properly, and the preorders didn’t work as the MS store website was already offline.
Cybersecurity weather person and award winning shitposter. Shitposting is an anagram of Top Insights. You may be surprised to know I am not representing my employer here and these are not their opinions.I have Direct Messages disabled - you can send them, but I will never receive them.