[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 1756896224158740.jpg (119 KB, 1200x660)
119 KB JPG
>They click and land on a genuine login.microsoftonline.com page: no spoofed URL, no red flags, nothing employees were ever trained to spot.
>Then it asks them to “approve” an app. One crucial click later, attackers have a foothold in that person’s email, Teams, SharePoint, OneDrive, and calendar – all without ever stealing a password.
>Researchers have identified more than 200 unique phishing emails that targeted users across approximately 120 organizations in two weeks, spanning a wide range of industries and countries worldwide. And it’s not a one-off.
>“This technique is already common and becoming increasingly widespread. It is a named and tracked technique in the MITRE ATT&CK framework, and in 2026, it evolved from a targeted, manually built attack into a service that virtually anyone can rent,”
>>
>>109416003
>now
>>
>>109416003
>Why is windows so easy to exploit now?
>>
My nigger, everything is easy to exploit now thanks to AI
>>
Doesn't their community bug reporting and bug bounty system basically fuck people over constantly? I'd imagine that + Jeet code.
>>
>>109416003
>phishing
You don't even have to be a hacker to pull this off.
>>
>>109416003
>windows
>“approve” an app
Train Karen in HR better, Rajesh.
>>
Meanwhile Linux users get exploited by curling random scripts and getting malicious dependencies pulled in. Mac users get the same because they need homebrew for any serious software outside the app store.
>>
exploit my system right now if its so easy.
>>
>>109417152
No examples?
That's what I thought kid
>>
>>109417163
https://www.truesec.com/hub/blog/supply-chain-attack-compromising-arch-linux-aur-packages-infostealer-rootkit
>>
>>109417174
nooooo I dont use any of those so they dont count nooooooooooooo
>>
>>109416465
Yeah, if you report a bug, you're often not allowed to make any disclosure, including a CVE report.

That's why microsoft has so little reported CVEs. And also it's poor incentives for researchers who create CVE reports for their career.
>>
>>109417174
>>109417178
the most popular and active packages wouldn't have been affected since to even insert the malware into an existing package it would have to have been orphaned first
>>
>>109416003
>phishing emails
why is linux so easy to exploit? Why is everything so easy to exploit?
>>
>>109417199
Didn't know this was an ESL thread
>>
>>109417182
Microsoft pays which is mpre than can be said for opensource shit.
>>
>>109417208
i accept your concession
>>
>>109417217
Are you that weed smoking multi-paragraph C defender guy?
>>
>>109417209
Open source rarely pays researchers, but institutions do. Here's there's a state institute that gives money when you report vulns, I heard the EU is doing something similar.
The problem about these institutions is that they're not the original project developer, so people try to max out the CVE score otherwise it's not worth it.

Also some companies will offer you money if you find a vuln in an open source software they use
>>
>>109417174
>Blog
Your anecdotes are fake and gay kid
>>
>>109417267
It's literally from TrueSec.
You asked for example, you got one and you are still complaining.
>>
>>109417208
Learn to read sukhdeep
>>
>>109417273
My dad also works for Nintendo
>>
>>109417278
>cant write
>tells other people to learn to read
>>
>>109417283
Both you and your dad have natal irreversible brain damage
>>
>>109417174
>>109417206
>>109417209
LDS Linux derangement syndrome
>>
>Then it asks them to “approve” an app.
lmao
I suppose people aren't trained for this but apps literally read your environment's data and should be trusted about as much as installing random software on your computer.
>>
>>109417287
Learn to read sukhdeep
>>
>>109416003
Oh no no no no, wangjeet-xirsters, our response?



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.