https://worldofeuc.com logo
Join Slack
Powered by
# _security
  • s

    Slackbot

    02/19/2024, 1:31 PM
    This message was deleted.
    c
    s
    • 3
    • 4
  • j

    Jaymes Davis

    05/26/2024, 12:44 AM
    https://thehackernews.com/2024/05/google-detects-4th-chrome-zero-day-in.html?m=1
    👀 1
  • d

    Daniel Madsen

    07/22/2024, 11:52 AM
    I have a customer, who's been using WDAC for quite some time. They just had a pentest and a couple of user-writeable paths were flagged. They advised us to look through WDAC and remove the ability to execute executables from these paths. Including the users own desktop. Anyone has a hint, as how to configure WDAC to remove that ability?
  • a

    Arthur

    08/14/2024, 8:52 AM
    RCE bug in TCP/IP module: • CVE-2024-38063 (CVSS 9.8): 0-Click RCE Affects All Windows Systems https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063
    😮 6
    s
    s
    • 3
    • 3
  • j

    Jaymes Davis

    08/14/2024, 2:41 PM
    https://www.linkedin.com/pulse/kasm-workspaces-mitigating-0000-browser-flaw-containers-3gdlc/?trackingId=7mvySyrg2pO4eXnuc4GO1w%3D%3D
  • m

    Michael Shuster

    08/19/2024, 3:03 PM
    Hi, curious if anyone has a best practices list for configuring MS Defender in VDI environments?
    👀 1
  • v

    vAndu

    09/30/2024, 10:36 AM
    Does anyone know of a good ticketing/monitoring tool that allows importing vulnerabilities from various scanning software into one platform for centralized management and ticket creation?
  • p

    Patrick Coble

    10/03/2024, 8:48 PM
    that would be cool
  • p

    Patrick Coble

    10/03/2024, 8:49 PM
    if the ticketing solution could digest a CSV then many Vuln scanners can export to that to make tickets so it could be automated but don’t know of any integrations
  • s

    Steven Brown

    10/04/2024, 12:50 AM
    I would be surprised if Service Now didn't have something.
  • v

    vAndu

    10/04/2024, 6:14 PM
    Service Now is too expensive. but I have heard it has, but not practical at all
  • v

    vAndu

    10/04/2024, 6:15 PM
    The reason I’m asking is that I might start developing this software and would like to see how many people/companies would be interested in it.
  • v

    vAndu

    10/04/2024, 6:15 PM
    Maybe this Nucleus. Never heard of it before.
  • v

    vAndu

    10/04/2024, 6:16 PM
    seems similar idea.
  • v

    vAndu

    10/04/2024, 6:17 PM
    how big is the need for this
  • v

    vAndu

    10/04/2024, 6:22 PM
    I would like to speak with people who are responsible for vulnerability management to learn how they are handling it and how they have solved it
  • r

    RSRevord

    10/04/2024, 9:24 PM
    i like the concept, the service now edition is crazy i think it has to integrate with tenable
  • r

    RSRevord

    10/04/2024, 9:24 PM
    i worry that can you make it cost effective enough for a customer that isn't intersted in serviceLater
  • v

    vAndu

    10/05/2024, 5:53 PM
    Service now is very expensive. I have heard even higher than VMware Broadcom and other licences combined.
  • v

    vAndu

    10/05/2024, 6:01 PM
    I’d like to find a few companies interested in paying for this kind of tool and developing the product with me, so I can create something that truly meets their needs.
  • p

    Patrick Coble

    10/11/2024, 4:08 PM
    I have officially found my favorite Windows Security Feature. Microsoft Defender SmartScreen won’t allow Microsoft Outlook (new) to launch.
    👍 2
    😂 1
    📪 1
    s
    j
    • 3
    • 3
  • b

    Balint Oberrauch

    10/15/2024, 3:54 PM
    Can someone share their Sentinel One configuration for non-persistent VDI? I’m experiencing perfomance issues in almost every project with Sentinel. Never experienced this performance gaps with Crowdstrike or Defender:
    👀 2
    r
    s
    +2
    • 5
    • 12
  • c

    c4rm0

    11/06/2024, 4:46 PM
    Can someone sanity check this for me please. In our enviroment events.teams.microsoft.com stopped working you get a blank white screen and nothing else. When i have investigated using the chrome developer options i see CSP (Content security policy violations) where javascript is unable to run from https://wcpstatic.microsoft.com see screenshots . When i check the CSP http headers for https://events.teams.microsoft.com the url https://wcpstatic.microsoft.com is listed under script-src as a trusted domain to run javascripts from. The issue we have seems to stem from Zscaler performing SSL inspection on https://wcpstatic.microsoft.com as when i go to that URL i see the Zscaler certificate being used which in turn changes the Origin URL to the Zscaler url + original url see screenhot and because this URL isnt allowed in the CSP the request is blocked by the browser. My security team are telling me its a local client browser issue !!! but i am pretty certain its a Zscaler issue and all they need to do is turn SSL inspection off for that URL where the javascript file is located. Using a CSP chrome add-in to strip out the CSP header the page loads fine
    j
    • 2
    • 2
  • b

    Balint Oberrauch

    12/04/2024, 11:42 AM
    How looks your Jumphost hardening? The Jumphosts are accessible via NS GW and all CTX Security Policies like file transfer ecc. are in place I have in mind: CIS Hardening Policies, Applocker, Credential Guard
    j
    d
    • 3
    • 6
  • d

    Daniel Madsen

    01/28/2025, 12:03 PM
    OSConfig for configuring AppControl for business(new new new name for Windows Defender Application Control), on a non-persistent Windows Server 2025. Any experience? Let's for the fun of it, say that the build VM, doesn't have access to the internet.
    k
    • 2
    • 2
  • j

    Jan Tytgat

    01/30/2025, 5:46 PM
    https://www.feistyduck.com/newsletter/issue_121_the_slow_death_of_ocsp
  • d

    Daniel Madsen

    01/31/2025, 3:56 PM
    https://cybersecuritynews.com/hackers-exploit-rdp-protocol-to-gain-windows-access/ Who needs to Citrix?
    j
    l
    • 3
    • 3
  • e

    Eric Beiers

    02/18/2025, 1:10 PM
    Citrix released two security bulletins today, https://support.citrix.com/s/article/CTX692579-netscaler-console-and-netscaler-agent-security-bulletin-for-cve202412284 https://support.citrix.com/s/article/CTX692679-citrix-secure-access-client-for-mac-security-bulletin-for-cve20251222-and-cve20251223
    ✅ 1
  • d

    Daniel Möser

    02/19/2025, 3:38 PM
    Hello, We have deployed Windows Defender for Endpoint with Device Control on our FAT clients to block USB devices locally (which works), but they are still being mapped in Citrix and remain accessible. Any ideas?
    b
    • 2
    • 2
  • j

    Jon Bucud

    03/04/2025, 4:24 PM
    Apparently, there are 3 CVSS 9/10 ESXi zero-days that are being actively exploited in the wild today. Patch, patch, patch.
    Kevin Beaumont
    3 different VMware zero days, under active exploitation by ransomware group
    CVE-2025-22224, CVE-2025-22225, CVE-2025-22226
    https://cyberplace.social/@GossiTheDog/114104596316369139