Lessons learned: Only allow approved external tenants to contact your tenant and lock down unused RMM tools. 3/3
References: learn.microsoft.com/en-us/micros... and learn.microsoft.com/en-us/manage...
Lessons learned: Only allow approved external tenants to contact your tenant and lock down unused RMM tools. 3/3
References: learn.microsoft.com/en-us/micros... and learn.microsoft.com/en-us/manage...
The TA were able to contact the user because they allowed all external tenants to contact them and allowed all traffic to Microsoft through their proxy for their M365. 2/3
On a recent engagement, a user had been mailbombed with signup emails and then fallen for a phishing Teams call disguised as an IT support, where the TA had used Quickassist to remote control the computer, a built-in Microsoft RMM tool. 1/3
Der har ogsΓ₯ ligget et russisk kabel skib i noget tid i det irske hav www.navylookout.com/royal-navy-m... - kunne vΓ¦re et false flag for at fΓ₯ folk til at kigge dΓ©r imens man rodede med kabler i ΓΈstersΓΈen.
Munich, Eisbachwelle?