§ Category
Category

IA

Cyber Tools

Rebuild and Reissue: SMA 1000 Remediation After INC Ransomware

The SonicWall SMA 1000 exploit chain gets from unauthenticated HTTP to root through a loopback service and a control-service password derived from the appliance’s DMI product_uuid. Rapid7 and Resecurity assess INC Ransomware as the dominant actor now weaponizing it, and the loot — session databases and TOTP seeds — is why patching alone does not end the incident.

·
AC

Valid Credentials and Overbroad Grants: Inside the Hugging Face Intrusion

Hugging Face’s July 27 timeline of the autonomous agent intrusion reads as a sequence of identity operations: node impersonation via IMDS, TokenRequest minting, an over-scoped CSI ClusterRole spent on a privileged pod, and forged tokens from a stolen EdDSA signing key. The lessons sit in key custody and least privilege, plus one correction worth stating plainly: audience binding does not contain a compromised signer.

·
AC

DKM: The AD FS Master Key That Decrypts Your Token Signer

CVE-2026-56155 is an overly permissive ACL on the AD FS DKM container — the object holding the key that protects your token-signing certificate. The July patch ships the fix in audit mode, so read access to a Golden SAML enabler stays open until you flip a registry key or October arrives.

·
AC

Passkey Enrollment: The Most Direct Signal Is the Registration Event

O-UNC-066 appears built to walk a victim through a fake passkey enrollment while the operator registers an attacker-controlled passkey in the real Entra tenant. It survives the password reset, and the most direct durable evidence is the authentication-method registration audit trail — written from a session your controls let through because the registration action was protected only by relayable MFA.

·
AC

msDS-SupersededManagedAccountLink, the Target-Side Write That Forges a dMSA Migration

Microsoft’s August 2025 fix for BadSuccessor (CVE-2025-53779) works — but an attacker who controls a dMSA and can write a target’s migration-link attributes can forge the mutual pairing the KDC now demands and pull that account’s Kerberos key material out of the dMSA key package. The detection has to move from watching one attribute to watching the pairing on the target object.

·
Cyber Tools

IKEv1 Certificate Auth: The Session Is the Only Artifact

CVE-2026-50751 lets an unauthenticated client flip a Check Point gateway’s certificate-verification flag using a crafted IKEv1 vendor ID payload. The catch for defenders: the forged payload isn’t in your normal VPN security logs. The only artifact is a VPN session that came up when it shouldn’t have.

·
AC

The Broker Refresh Token Can Register a Device in Entra ID

Device code phishing doesn’t defeat MFA — it redirects a legitimately MFA-completed sign-in — and the naive detection drowns in legitimate CLI traffic. The durable signal is the Authentication Broker redemption and the device registration that follows, and the real fix is a Conditional Access authentication-flows block.

·
AC

ESC16 Strips the SID Extension Strong Mapping Depends On

Microsoft’s strong certificate mapping enforcement finally landed, and where it’s genuinely in force it does close the naive implicit-mapping hole that made ADCS escalation trivial — a certificate with only a weak name is denied. ESC16 strips the CA-issued SID so the mapping decision falls to whatever’s left: on a compatibility-mode DC that’s weak SAN mapping, and even on a fully-enforced DC it’s an attacker-supplied SID-in-SAN URI the KDC treats as strong. The audit events you’d hunt it with are off by default.

·