Open in app

Sign In

Write

Sign In

Kevin Beaumont
Kevin Beaumont

3.6K Followers

Home

About

Published in DoublePulsar

·Dec 8, 2022

Microsoft’s Github facilitating Ukraine government in denial of service of Russian government infrastructure

Back in February 2022, Mykhailo Fedorov — Ukraine’s Deputy Prime Minister — launched the IT Army of Ukraine: The army, which has grown to 300,000 people at peak, has been fighting a digital war with the Russian government and private enterprise. It has been incredibly successful — I have…

Cybersecurity

4 min read

Microsoft’s Github facilitating Ukraine government in denial of service of Russian government…
Microsoft’s Github facilitating Ukraine government in denial of service of Russian government…
Cybersecurity

4 min read


Published in DoublePulsar

·Dec 3, 2022

Rackspace Cloud Office suffers destructive security breach

Thousands of small to medium size businesses are suffering as Rackspace have suffered a security breach on their Hosted Exchange service. Rackspace have now confirmed this is a ransomware incident. Yesterday, 2nd December 2022, Rackspace announced an outage to their Hosted Exchange Server: Updated followed through the day, but were…

Cybersecurity

9 min read

Rackspace Cloud Office suffers destructive security breach
Rackspace Cloud Office suffers destructive security breach
Cybersecurity

9 min read


Published in DoublePulsar

·Sep 29, 2022

ProxyNotShell— the story of the claimed zero days in Microsoft Exchange

Yesterday, cybersecurity vendor GTSC Cyber Security dropped a blog saying they had detected exploitation of a new Microsoft Exchange zero day: Warning: New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server | Blog | GTSC — Cung cấp các dịch vụ bảo mật toàn diện (gteltsc.vn) …

Cybersecurity

10 min read

ProxyNotShell— the story of the claimed zero day in Microsoft Exchange
ProxyNotShell— the story of the claimed zero day in Microsoft Exchange
Cybersecurity

10 min read


Published in DoublePulsar

·May 29, 2022

Follina — a Microsoft Office code execution vulnerability

Two days ago, on May 27th 2022, Nao_sec identified an odd looking Word document in the wild, uploaded from an IP address in Belarus. This turned out to be a zero day vulnerability in Office and/or Windows. This caught my attention, as Defender for Endpoint missed execution: The…

Follina

9 min read

Follina — a Microsoft Office code execution vulnerability
Follina — a Microsoft Office code execution vulnerability
Follina

9 min read


Published in DoublePulsar

·May 7, 2022

BPFDoor — an active Chinese global surveillance tool

Recently, PwC Threat Intelligence documented the existence of BPFDoor, a passive network implant for Linux they attribute to Red Menshen, a Chinese threat actor group. You can read more in PwC’s great, yearly threat intelligence brief, here. PwC plan to present their findings in June: BPFDoor is interesting…

Bpfdoor

3 min read

BPFDoor — an active Chinese global surveillance tool
BPFDoor — an active Chinese global surveillance tool
Bpfdoor

3 min read


Published in DoublePulsar

·Aug 21, 2021

Multiple threat actors, including a ransomware gang, exploiting Exchange ProxyShell vulnerabilities

For nearly a month, I have been watching mass in the wild exploitation of ProxyShell, a set of vulnerabilities revealed by Orange Tsai at BlackHat. These vulnerabilities are worse than ProxyLogon, the Exchange vulnerabilities revealed in March — they are more exploitable, and organisations largely haven’t patched. This post goes…

Proxyshell

7 min read

Multiple threat actors, including a ransomware gang, exploiting Exchange ProxyShell vulnerabilities
Multiple threat actors, including a ransomware gang, exploiting Exchange ProxyShell vulnerabilities
Proxyshell

7 min read


Published in DoublePulsar

·Jul 20, 2021

#HiveNightmare aka #SeriousSAM — anybody can read the registry in Windows 10

This is the story of how all non-admin users can read the registry — and so elevate privileges and access sensitive credential information — on various flavours of Windows 10. It appears this vulnerability has existed for years, and nobody noticed. In this post I made an exploit to test…

Cybersecurity

4 min read

#HiveNightmare aka #SeriousSAM — anybody can read the registry in Windows 10
#HiveNightmare aka #SeriousSAM — anybody can read the registry in Windows 10
Cybersecurity

4 min read


Published in DoublePulsar

·Jul 2, 2021

Kaseya supply chain attack delivers mass ransomware event to US companies

Kaseya VSA is a commonly used solution by MSPs — Managed Service Providers — in the United States and United Kingdom, which helps them manage their client systems. Kaseya’s website claims they have over 40,000 customers. Four hours ago, an apparent auto update in the product has delivered REvil ransomware. …

Cyberattack

8 min read

Kaseya supply chain attack delivers mass ransomware event to US companies
Kaseya supply chain attack delivers mass ransomware event to US companies
Cyberattack

8 min read


Published in DoublePulsar

·Jun 30, 2021

Zero day for every supported Windows OS version in the wild — PrintNightmare

zhiniang peng tweeted out a proof of concept exploit and explainer recently, and then quickly deleted it. This exploit and discussion contained an unpatched zero day in all supported and Extended Security Update verrsions of Windows OS. Unfortunately by this had already been forked on Github by then… and…

Printnightmare

6 min read

Zero day for every supported Windows OS version in the wild — PrintNightmare
Zero day for every supported Windows OS version in the wild — PrintNightmare
Printnightmare

6 min read


Published in DoublePulsar

·Jun 8, 2021

The hard truth about ransomware: we aren’t prepared, it’s a battle with new rules, and it hasn’t near reached peak impact.

I’ve talked about ransomware and extortion attacks on organizations for about a decade. I recently spent a year at Microsoft in Threat Intelligence in Redmond, which included tracking ransomware gangs. …

Ransomware

21 min read

The hard truth about ransomware: we aren’t prepared, it’s a battle with new rules, and it hasn’t…
The hard truth about ransomware: we aren’t prepared, it’s a battle with new rules, and it hasn’t…
Ransomware

21 min read

Kevin Beaumont

Kevin Beaumont

3.6K Followers

Everything here is my personal work and opinions.

Following
  • Wil Wheaton

    Wil Wheaton

  • Mark Manson

    Mark Manson

  • Mitch Edwards

    Mitch Edwards

  • James Watt

    James Watt

  • Jang

    Jang

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech