Sebocat's Avatar

Sebocat

@sebocat

#InfoSec #Bluehat #SystemEngineer #SecurityEngineer πŸ’» #Deep #Tech #House #Techno 🎢 Mastodon: https://infosec.exchange/@Sebocat Soundcloud: https://soundcloud.com/sebocat

41
Followers
142
Following
8
Posts
10.02.2024
Joined
Posts Following

Latest posts by Sebocat @sebocat

Preview
Notepad++ says Chinese government hackers hijacked its software updates for months | TechCrunch The developer of the popular text editor Notepad++ said hackers associated with the Chinese government hijacked its software update mechanism to deliver tainted software to users for months.

NEW: The developer of the long-running and popular open source text editor Notepad++ has confirmed that China government-backed hackers hijacked the software's update feature for months during 2025.

The hackers could access computers of victims who were running hijacked versions of Notepad++.

02.02.2026 18:23 πŸ‘ 48 πŸ” 33 πŸ’¬ 4 πŸ“Œ 3

Highly recommended password manager, and works nice in combination with Windows Hello and locked database πŸ‘ŒπŸ»πŸ‘πŸ»

09.12.2025 21:27 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

TPM is a very interesting topic - as far as i know there is fTPM for Firmware TPM (embedded TPM in CPU) and dTPM (Discrete TPM, dedicated TPM chip), which both can be Version 2.0, but, for example, fTPM is better mitigated against BitLocker coldboot attacks.

16.03.2025 20:16 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I don't know who needs to hear this, but there is no such thing as securing BYOD, especially non-mobile OSs

You may limit damage your regular users can cause, but you are not keeping out an attacker when you accept a model that allows access from unknown, unmanaged devices

12.02.2025 04:18 πŸ‘ 30 πŸ” 4 πŸ’¬ 2 πŸ“Œ 0

You should also read this great article by @ajf8729.com for Windows Firewall, too - needed it in the past for EntraID joined devices with certificate auth, highly recommended!

07.02.2025 15:32 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

You should watch Jessica Paynes amazing Windows Firewall presentation - and then read this excellent blog about endpoint isolation medium.com/@cryps1s/end...

06.02.2025 21:49 πŸ‘ 10 πŸ” 2 πŸ’¬ 0 πŸ“Œ 1

If you have to do with EntraID you must read and understand this amazing thread - and also follow @nathanmcnulty.com 😊

25.01.2025 18:53 πŸ‘ 13 πŸ” 1 πŸ’¬ 2 πŸ“Œ 0
Preview
On Secure Boot, TPMs, SBAT, and downgrades -- Why Microsoft hasn't fixed BitLocker yet On Secure Boot, TPMs, SBAT and Downgrades -- Why Microsoft hasn't fixed BitLocker yet

#BitLocker #Windows #Security

neodyme.io/en/blog/bitl...

19.01.2025 18:50 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

It's the best and most secure Windows ever - i like it, too πŸ˜‡ especially with enabled security baseline and enabled App Control (fka WDAC)

01.01.2025 19:19 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
NTLM v1 is removed from the latest version of Windows

NTLM v1 is removed from the latest version of Windows

Oh by the way

06.12.2024 01:08 πŸ‘ 101 πŸ” 35 πŸ’¬ 9 πŸ“Œ 6

Windows has issue:

Person: fuck this I'm going to Linux

Narrator: and they quickly learned to hate two operating systems.

26.11.2024 16:48 πŸ‘ 9823 πŸ” 741 πŸ’¬ 363 πŸ“Œ 90
Post image

Device-bound #passkeys in #EntraID are finally GA

https://aka.ms/Ignite2024/entra

#AiTM #Security #FIDO2

21.11.2024 14:17 πŸ‘ 59 πŸ” 13 πŸ’¬ 2 πŸ“Œ 0
Preview
Privilege escalation using Azure Service principal Introduction In Microsoft Azure, the management of access and permissions is critical for maintaining a secure environment. Azure Service Principals serve as non-human identities that allow applicatio...

In this blog post i breaks down how attackers can exploit and abuse service principals and what you can do to defend against it.
Check it out here:
laythchebbi.com/index.php/20...
#AzureSecurity #PrivilegeEscalation #OffensiveSecurity #CloudSecurity #Cybersecurity

21.11.2024 10:35 πŸ‘ 24 πŸ” 9 πŸ’¬ 0 πŸ“Œ 0
Post image

Microsoft CEO Satya Nadella on stage at Ignite announcing the company’s new Windows 365 Link mini cloud PC www.theverge.com/2024/11/19/2...

19.11.2024 14:41 πŸ‘ 148 πŸ” 22 πŸ’¬ 24 πŸ“Œ 23
πŸš€ Starter packs | Bluesky.ms Starter packs in Bluesky are curated collections of folks to follow. These packs are created by the community and are a great way to get started with Bluesky. You can bulk follow the folks in the pack...

Quick reminder to check out the #Microsoft community starter packs.

We have new starter packs + starter packs updated with new folks.

So hit up the page and update your follows so you can connect with more folks.

Please add if I've missed any.

bluesky.ms/starterpacks/

18.11.2024 09:52 πŸ‘ 48 πŸ” 15 πŸ’¬ 3 πŸ“Œ 0
What's New in Windows Security, Productivity and Cloud Do your best work on Windows. Join Pavan Davuluri, Navjot Virk, Aidan Marcuss, and David Weston to learn how Windows is transforming end user computing for all with the power of AI and the Microsoft c...

I am going at Microsoft Ignite talking about how Windows is changing post the CrowdStrike incident. See you there!!

ignite.microsoft.com/en-US/sessio...

17.11.2024 02:10 πŸ‘ 29 πŸ” 4 πŸ’¬ 1 πŸ“Œ 0

Great tip, i also used it in the past, so much better than Fiddler or Burp, always nice to use built-in tools without admin rights 😊

17.11.2024 14:43 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Almost embarrassed to post this, but I've always used Fiddler or Burp for capturing things like this...

I didn't have admin rights and was trying to capture network traffic from a pop-up, so Dev Tools wasn't working

Apparently this is built into Chrome/Edge! So cool :)

edge://net-export/

17.11.2024 06:49 πŸ‘ 187 πŸ” 45 πŸ’¬ 15 πŸ“Œ 3
Post image

How are you protecting your M365/Azure environment from on-premises attack vectors for compromise?

I always recommend reviewing this guide here as a checklist of actions you should be taking and implement them: aka.ms/protectm365 #entra #security #m365 #o365 #identity #azure #microsoft

15.11.2024 18:37 πŸ‘ 28 πŸ” 8 πŸ’¬ 3 πŸ“Œ 0
Austrian Airlines' farewell to the Twitter.

Austrian Airlines' farewell to the Twitter.

This was Austrian Airlines' final post over on the Twitter.

13.11.2024 18:08 πŸ‘ 11655 πŸ” 3047 πŸ’¬ 162 πŸ“Œ 328
Video thumbnail

Bluesky explained in 60 seconds!

13.11.2024 04:15 πŸ‘ 8252 πŸ” 2009 πŸ’¬ 444 πŸ“Œ 300
Preview
Search bluesky.ms Use this page to search for the Microsoft community on bluesky.ms.

πŸ¦‹ Introducing bluesky.ms πŸ‘ = A crowdsourced database of anyone and everyone in the Microsoft community on Bluesky.

πŸ‘‰ Add yourself and anyone you know today πŸ‘ˆ

πŸ«‚ All are welcome.

This is my v1, I'll add options to directly follow from the site itself but first πŸ‘‡

LET'S FILL IT UP! πŸ™

08.11.2024 15:51 πŸ‘ 606 πŸ” 266 πŸ’¬ 58 πŸ“Œ 35