Security Dive




New articles!
Storm-0588 Azure AD Token Forging Attack
Downfall Vulnerability (CVE-2022-40982)
WormGPT when GenAI also serves malicious actors
Articles
Focus on information exchange between DevSecOps
Red Team Lessons Learned Series – Episode 3 Focus on information exchange between DevSecOps Introduction In this series of blog posts I wanted to highlight…
Do not neglect security in development systems
Red Team Lessons Learned Series – Episode 2 Do not neglect security in development systems Introduction In this series of blog posts I wanted to highlight…
Never feel afraid to report a security incident
Red Team Lessons Learned Series – Episode 1 Never feel afraid to report a security incident Introduction In this series of blog posts I wanted…
Public to public credential access
Introduction The goal of this post is to draw some attention to a couple of very simple and effective attack vectors that let our team stealthily compromise an entire shared…
IOC Diversification as an Approach to Eradication Avoidance
A while ago, during my first Red Team engagement with Atos, I came up with a tactical anti-eradication approach, which was directly inspired by my former…
Digital Security magazine








