🇫🇷 ANSSI does not recommend anymore to enforce password expiry, except for privileged accounts.
Of course renewal must be triggered if a leak is suspected.

Big change with the end of this old rule. France finally in line with other international recommendations. twitter.com/ANSSI_FR/status/14

Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP cameras/NVR firmware ,Patch now (*CVE-2021-36260) : watchfulip.github.io/2021/09/1 credits @Watchful_IP@twitter.com

[🛡️ ] Bienvenue à @ACEService2@twitter.com qui rejoint le .
ACE Service accompagne ses clients depuis plus de 10 ans sur leurs problématiques de cybersécurité en fournissant des services autour de : l'audit, l'intégration, la mise en œuvre et l'hébergement.

Sigma rule to detect CVE-2021-40444 exploitation activity

- Office program with control.exe child seems to be stable enough (1 exception)
- also works for the RTF vector twitter.com/WLesicki/status/14
- control.exe + .cpl isn't good enough


Top 10 2021 DRAFT is out!!!
Now available for peer review, comment, translation, and suggestions for improvements:


Need local admin and have physical access?
- Plug a Razer mouse (or the dongle)
- Windows Update will download and execute RazerInstaller as SYSTEM
- Abuse elevated Explorer to open Powershell with Shift+Right click

Tried contacting @Razer@twitter.com, but no answers. So here's a freebie

Here's a quick cheatsheet on moving your cursor quickly in bash.

idk why I havent thought of this before, but its very easy to hide those "external sender" warnings that get appended to your emails during phishing campaigns 🤔. Email gateways/FW just add HTML at the start/end of emails, simply add CSS to hide it!

See images:

tmpmail : A temporary email right from your terminal written in POSIX sh : github.com/sdushantha/tmpmail credits @sidheart@twitter.com

🥁 We're thrilled to announce that we've raised €16M in our Series B funding! So today, we want to thank you, hunters, for making up our community. We wouldn’t be here without you!
Full announcement: bit.ly/3hVXBWp

🚨 Grosse fuite de données chez LinkedIn : les données perso de presque tous les utilisateurs en vente 🔥💶 700M de personnes !! 9to5mac.com/2021/06/29/linkedi

➡️ Nom, email, tel📱, adresse, expériences... mais aussi le salaire déduit par 💰 (ce sujet va faire parler !)

Finally CrackMapExec can now fetch all domain users when the DC is vulnerable to NULL Session 🎉

Prior to this, CME what useless except for the password policy option 😓

No more enum4linux, rpclient etc, all great tools but I prefere one tool to rule them all 🔥

Ouch! Le dépot GIT de PHP semble avoir été backdooré...

NEW: Hackers have breached the internal Git repository of the PHP programming language and have added a backdoor to the PHP source code in an attack that took place over the weekend, on Sunday.


