Dirk-jan Mollema found one of the most severe vulnerabilities ever discovered in Microsoft Entra ID.
One that could have compromised every tenant in the cloud.
In this episode, we unpack the story, the stress, and the mindset behind responsible disclosure. π₯
               
            
            
                24.10.2025 13:24 β π 13    π 3    π¬ 1    π 1                      
            
         
            
        
            
            
            
            
            
    
    
            
                            
                        
                PingOne Attack Paths - SpecterOps
                You can use PingOneHound in conjunction with BloodHound Community Edition to discover, analyze, execute, and remediate identity-based attack paths in PingOne instances.
            
        
    
    
            Introducing PingOneHound! This OpenGraph extension for BloodHound can help you identify, analyze, execute, and remediate attack paths in PingOne organizations. Read the introductory blog post here: specterops.io/blog/2025/10...
               
            
            
                20.10.2025 17:43 β π 9    π 10    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            Can you please reach out to me via either email or Discord. 
You must have received an email from me when you bought your ticket. 
Thank you!
               
            
            
                12.10.2025 16:52 β π 0    π 0    π¬ 0    π 0                      
            
         
            
        
            
        
            
            
            
            
            
    
    
    
    
            Happy #BloodHoundBasics Day from @scoubi.bsky.social!
By now, you've probably heard about our Query Library. But did you know you can run any query in your own instance of BHE/BHCE and then save the query to your Personal Library?
Follow the steps threaded below!
π§΅: 1/5
               
            
            
                26.09.2025 18:18 β π 1    π 2    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
                                                
                                            the cast of Hackers (1995) posing in a series of adjacent phone booths 
                                                
    
    
    
    
            Today is the 30th anniversary of Hackers
               
            
            
                15.09.2025 23:56 β π 3634    π 1054    π¬ 75    π 327                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            You should wear them proudly at @deathcon.io in Montreal! π
               
            
            
                07.09.2025 01:17 β π 2    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
                                                
                                                
    
    
    
    
            The final round of #DEATHCon2025 online tickets will drop on 9/9 at 0900 UTC deathcon.io/tickets.html
In-person tickets still available at some sites (1/4)
               
            
            
                06.09.2025 18:10 β π 1    π 2    π¬ 1    π 1                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            There is only one in Montreal π€£
But itβs 1 DEATHcon and multiple locations. Same content is available everywhere but each site is free to choose which Workshops theyβll showcase during the weekend. 
All content is also available for at least 1 month online for all attendees.
               
            
            
                20.08.2025 21:16 β π 1    π 0    π¬ 0    π 0                      
            
         
            
        
            
        
            
            
            
            
            
    
    
            
                        
                DEATHcon Montreal - On Site
                2 days of hands-on Detection Engineering and Threat Hunting workshops! Join us Live in Montreal.
            
        
    
    
            Interested in hands-on learning of #DetectionEngineering and #ThreatHunting ?
We still have a few tickets left for @DEATHCon2025 in #Montreal
We are lucky enough to have 4 Workshops Leaders with us that will be able to hosts a Live Play of their workshop and help you complete it!
               
            
            
                20.08.2025 16:45 β π 1    π 2    π¬ 2    π 0                      
            
         
            
        
            
            
            
            
                                                
                                                
    
    
    
    
            Fucking do it, I dare you.
               
            
            
                17.08.2025 21:29 β π 19    π 1    π¬ 3    π 0                      
            
         
            
        
            
            
            
            
                                                
                                                
    
    
    
    
            What all do you need to know about BloodHound CE 8.0 & OpenGraph? @scoubi.bsky.social is joining @redsiege.com's Wednesday Offensive tomorrow to dive into the JSON schema for OpenGraph, how to ingest nodes & edges, best practices, & how to create custom icons.
Join π ghst.ly/46MNltn
               
            
            
                12.08.2025 16:00 β π 5    π 3    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            Word!
               
            
            
                03.08.2025 02:16 β π 2    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
            
                            
                        
                NoiseLetter July 2025
                Get GreyNoise updates! Read the July 2025 NoiseLetter for product news, key resources, the latest tags and vulnerabilities, and more.
            
        
    
    
            This month's NoiseLetter will make the perfect light reading for a trip to say...Vegas? Make sure to check it out (even if you're not headed to BlackHat/DEF CON there is something in it for you). π€
               
            
            
                01.08.2025 20:46 β π 3    π 2    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
            
                            
                        
                Hackers target Python devs in phishing attacks using fake PyPI site
                The Python Software Foundation warned users this week that threat actors are trying to steal their credentials in phishing attacks using a fake Python Package Index (PyPI) website.
            
        
    
    
            The Python Software Foundation warns of phishing emails directing users to a fake PyPI site (pypj. org) to steal credentials. PyPI isnβt hacked, but users are urged to stay alert.
www.bleepingcomputer.com/news/securit...
Via @bleepingcomputer.com 
#hacking #infosec #cybersecurity
               
            
            
                31.07.2025 13:51 β π 3    π 2    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            This is AMAZING
               
            
            
                30.07.2025 19:22 β π 23    π 9    π¬ 3    π 0                      
            
         
            
        
            
            
            
            
                                                
                                                
    
    
    
    
            Think being compliant = being secure? Think again. π€
Hear from @scoubi.bsky.social at #BSidesLV as he exposes the gap between blindly following rules & security posture.
Get the info on password security & what to do when "compliant" passwords fail you. ghst.ly/4o66cWk
               
            
            
                25.07.2025 13:21 β π 4    π 1    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            How did it go??
               
            
            
                12.07.2025 12:12 β π 0    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
                                                
                                                
    
    
    
    
            Happy #BloodHoundBasics Day from @scoubi.bsky.social! π
Have you ever run a Cypher Query & get so many nodes you couldn't see anything? You Pinch Zoom to get a closer look and it worked fine, but you Pinch Un-zoom & the application resized.
π§΅: 1/2
               
            
            
                11.07.2025 18:34 β π 2    π 1    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            Only 3 Early Bird tickets left!!
               
            
            
                11.07.2025 02:17 β π 1    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
            
                        
                DEATHcon Montreal - On Site
                2 days of hands-on Detection Engineering and Threat Hunting workshops! Join us Live in Montreal.
            
        
    
    
            Tickets for #DEATHcon in Montreal are on sale now!
Book now to secure your place. FYI, Virtual Tickets for round 1 are already Sold Out!
eventbrite.ca/e/deathcon-m...
Additional info (like workshops) for the con can be found here : deathcon.io
Please like & repost for reach
               
            
            
                10.07.2025 12:59 β π 3    π 2    π¬ 0    π 1                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            Ohm-I and Ed Skoudis duet
               
            
            
                29.06.2025 22:51 β π 0    π 0    π¬ 1    π 0                      
            
         
            
        
            
            
            
            
            
    
    
            
                        
                DEATHcon Montreal - On Site
                2 days of hands-on Detection Engineering and Threat Hunting workshops! Join us Live in Montreal.
            
        
    
    
            Tickets for "DEATHcon - Montreal On Site" go on sale July 8th at 8am. 
www.eventbrite.ca/e/deathcon-m...
Be with 50 other DE&TH aficionados for a whole weekend Nov 8-9 2025!!
#DEATHcon #Workshops #DetectionEngineering #ThreatHunting
               
            
            
                28.06.2025 16:55 β π 2    π 0    π¬ 0    π 0                      
            
         
            
        
            
        
            
            
            
            
            
    
    
            
                            
                        
                Ghostwriter v6: Introducing Collaborative Editing - SpecterOps
                Ghostwriter now supports real-time collaborative editing for observations, findings, and report fields using the YJS framework, Tiptap editor, and Hocuspocus server, enabling multiple users to edit si...
            
        
    
    
            Ghostwriter v6's new collaborative editing feature is π₯
Alex Parrill & @printingprops.com discuss the new real-time collaborative editing for observations, findings, & report fields, enabling multiple users to edit simultaneously without overwriting each other. ghst.ly/4jVqdvG
               
            
            
                18.06.2025 20:14 β π 7    π 2    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
                                                
                                                
    
    
    
    
            #HuntingTipOfTheDay: a personal favourite, command-line obfuscation. Substituting or inserting special Unicode characters might allow attackers to bypass string-based detections. Look for command lines with unusual Unicode characters. Checkout ArgFuscator.net for more fun!
               
            
            
                11.06.2025 09:02 β π 3    π 1    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
                                                
                                                        
                                                
    
    
    
    
            #HuntingTipOfTheDay: macOS has a built-in SSH mechanism that is disabled by default. Would you detect it if someone enables it and logs in remotely? Look for remote login events, and investigate the associated session.
               
            
            
                10.06.2025 09:02 β π 3    π 1    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
            
    
    
    
    
            Awesome!
Post here when done π
               
            
            
                09.06.2025 17:30 β π 0    π 0    π¬ 0    π 0                      
            
         
            
        
            
            
            
            
                                                
                                                
    
    
    
    
            Personalized my work laptop a bit
               
            
            
                07.06.2025 16:30 β π 3    π 0    π¬ 1    π 0                      
            
         
    
         
        
            
        
                            
                    
                    
                                            Web App (mostly) Hacker | Cybersecurity Educator | Content Creator | Ex-Brit | Links: http://linktr.ee/tib3rius (he/him) πΊπΈ A mostly unserious person. @therealc3rul34n.bsky.social is bae π₯°
                                     
                            
                    
                    
                                            Hunt & Response @ Huntress
Author of Constructing Defense 
π¨π¦
                                     
                            
                    
                    
                                            #ThreatIntel #InsiktGroup #RecordedFuture  | OG #BlueTeamVillage #TraceLabs #L0nelyH4ckers | #DEFCON #DemoLabs Co-Lead
                                     
                            
                    
                    
                                            A mountain man with an Internet connection and a professional interest in malware.
                                     
                            
                            
                    
                    
                                            Threat Detection & Response. Interested in cyber security, tech and politics. Views are my own, unless retweeted.
                                     
                            
                    
                    
                                    
                            
                    
                    
                                            I like making computers misbehave.  Does stuff at http://specterops.io.
Github: https://github.com/leechristensen
Mastodon: @tifkin_@infosec.exchange
                                     
                            
                    
                    
                                            @its_a_feature_ on Twitter | Mythic developer | @SpecterOps
                                     
                            
                    
                    
                                            Senior Security Researcher at SpecterOps. All opinions are my own.
                                     
                            
                    
                    
                                            Penetration Testing, Purple Team, Red Team & Adversary Emulation.
Let our Offense, Prepare your Defense. https://redsiege.com
#weareoffensive
                                     
                            
                    
                    
                                            CTO of Microsoft Azure, author of novels Rogue Code, Zero Day and Trojan Horse, Windows Internals, Sysinternals tools. Opinions are my own.
                                     
                            
                            
                    
                    
                                            GCIH, GCFE  | DFIR, Threat Hunting, Detection Engineering | @CuratedIntel DFIR Member
SecurityAura.com
http://infosec.exchange/@SecurityAura
                                     
                            
                    
                    
                                            Placeholder profile : https://x.com/cyb3rops | glad to be in this respectful safe space | vi/vim
                                     
                            
                    
                    
                                            Real Intrusions by Real Attackers, the Truth Behind the Intrusion.
https://thedfirreport.com
                                     
                            
                    
                    
                                            Creators of BloodHound | Experts in Adversary Tradecraft | Leaders in Identity Attack Path Management
                                     
                            
                            
                    
                    
                                            Security researcher in Google Project Zero. Author of Attacking Network Protocols. Posts are my own etc.