Neighbor is out here pruning my tree.
Notices by Fritz Adalis (fritzadalis@infosec.exchange)
-
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Saturday, 22-Feb-2025 05:37:02 JST Fritz Adalis
-
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Friday, 21-Feb-2025 17:19:13 JST Fritz Adalis
@SwiftOnSecurity
The IBM slide deck about computers making decisions. -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Thursday, 30-Jan-2025 01:11:00 JST Fritz Adalis
-
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Sunday, 19-Jan-2025 10:01:46 JST Fritz Adalis
@ryanc @jerry @shadownetworks @cR0w
Is this RFC 768 in the room with us right now? -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Sunday, 19-Jan-2025 09:34:19 JST Fritz Adalis
@ryanc @jerry @shadownetworks @cR0w
UDP packets aren't even real. -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Sunday, 19-Jan-2025 07:33:36 JST Fritz Adalis
KITTAY! That house is not for you!
-
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Saturday, 11-Jan-2025 08:52:29 JST Fritz Adalis
@sj
Doesn't VLC use ffmpeg? -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Thursday, 09-Jan-2025 11:33:44 JST Fritz Adalis
@ekis
They weren't stealing, they were playing short-necked plucked guitars. -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Thursday, 02-Jan-2025 23:00:14 JST Fritz Adalis
Wondering if anyone else has seen this behavior.
We received an alert from MS Defender for Cloud that a suspicious IP had downloaded from a storage blob using a SAS token. It turned out that someone was misusing the SAS token feature and had sent the URL via email.
Since then, we've determined that every URL sent via email (O365) is being downloaded immediately by... someone. We brought in someone for IR but they haven't seen anything similar and we can't find a cause. We even set up two secops mailboxes (which are supposed to bypass all MS security) and sending an email between them still triggers the downloads.
The source IPs so far have all been in the US, and Spur tags most with "Oculus Proxy" and most ASNs are "Constant" or "HostRoyale". User agents match Chrome 125 or 131.
The only thing I've found online is complaints on Reddit about this causing a 100% click rate in KnowBe4. No real resolution there though.
We're thinking it's something automated/enterprise, but I want to be sure. Has anyone seen anything similar? TIA.
-
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Tuesday, 31-Dec-2024 23:59:32 JST Fritz Adalis
@ekis
Maybe they're building the bunkers for all of us! -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Monday, 30-Dec-2024 09:18:27 JST Fritz Adalis
@ekis
We yearn to rise to mediocrity. -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Wednesday, 25-Dec-2024 05:34:07 JST Fritz Adalis
@azonenberg
Is that the Godot logo? -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Sunday, 22-Dec-2024 07:59:50 JST Fritz Adalis
-
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Saturday, 21-Dec-2024 12:51:37 JST Fritz Adalis
@ekis
This seems like good hacking music. -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Wednesday, 18-Dec-2024 21:54:54 JST Fritz Adalis
@jrconlin @ekis
Oh you mean hysteria, not a Martian invasion. -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Thursday, 12-Dec-2024 22:36:10 JST Fritz Adalis
@cR0w @screaminggoat
Is that the right cve? It looks like a different product. -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Tuesday, 10-Dec-2024 21:20:00 JST Fritz Adalis
@GossiTheDog
Those teeth are disturbing somehow. -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Tuesday, 10-Dec-2024 21:18:19 JST Fritz Adalis
@GossiTheDog
I should have looked at page 2...Server: Cleo LexiCom/4.5 (Windows NT (unknown))
-
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Tuesday, 10-Dec-2024 21:06:50 JST Fritz Adalis
@GossiTheDog
LOL
Server: Cleo LexiCom/4.2 (Windows 2000) -
Embed this notice
Fritz Adalis (fritzadalis@infosec.exchange)'s status on Saturday, 07-Dec-2024 11:40:25 JST Fritz Adalis
@silverwizard @GossiTheDog
Agreed, but sysadmins typically don't have a budget.