§ Tag
Tag

Compliance

Cyber Tools

Rebuild and Reissue: SMA 1000 Remediation After INC Ransomware

The SonicWall SMA 1000 exploit chain gets from unauthenticated HTTP to root through a loopback service and a control-service password derived from the appliance’s DMI product_uuid. Rapid7 and Resecurity assess INC Ransomware as the dominant actor now weaponizing it, and the loot — session databases and TOTP seeds — is why patching alone does not end the incident.

·
AC

DKM: The AD FS Master Key That Decrypts Your Token Signer

CVE-2026-56155 is an overly permissive ACL on the AD FS DKM container — the object holding the key that protects your token-signing certificate. The July patch ships the fix in audit mode, so read access to a Golden SAML enabler stays open until you flip a registry key or October arrives.

·
AU

The Renumber Step Is What Closes the EventRecordID Gap

An attacker who can manipulate the active or offline EVTX can pull a single 4624 out of the Security log without inherently firing Event ID 1102 — and, by renumbering the records that follow, without leaving a hole in the EventRecordID sequence your rule watches. Here is why gap detection misses that, and what actually catches it.

·
Policies

The DPRK Worker’s Overseas IP Is in Your Connection Logs

Eight US-based ‘laptop farmers’ sentenced in five months, across cases spanning more than 100 US companies in one prosecution and nearly 70 in others: the North Korean IT worker is already on payroll, and what resolves it is correlating unauthorized remote-access tooling with the connection and endpoint telemetry it throws off — not the hiring interview, and not sign-in geography alone.

·
CM

The pnpm Cache Poisoning Primitive GitHub Closed in June

The TanStack compromise published 84 poisoned npm versions across 42 packages by writing a cache entry into the default-branch scope from an untrusted fork PR. GitHub has since made that write path read-only for low-trust triggers — but cache creation still never touches the audit log, so post-hoc detection has to live on the runner and in cache-inventory differencing instead.

·
AC

Passkey Enrollment: The Most Direct Signal Is the Registration Event

O-UNC-066 appears built to walk a victim through a fake passkey enrollment while the operator registers an attacker-controlled passkey in the real Entra tenant. It survives the password reset, and the most direct durable evidence is the authentication-method registration audit trail — written from a session your controls let through because the registration action was protected only by relayable MFA.

·
Artificial Intelligence

F3 A0: The Two-Byte Prefix Behind Every Invisible Tag Character

A block of Unicode characters that renders as nothing can carry a full paragraph of instructions into your LLM, and your content filter can miss it because it inspects a sanitized or transformed representation while the model receives the original code points. Here is where the detection actually has to live, and what you spend the first week of tuning on.

·