Adithya V
6 followers · 5 following · 958 views
on the atlas — 71
- A Cynic’s Guide To Fintech. Several business models that are bound… | by Dan Davies | Bull Market | Medium2 savers
- Approximating KL Divergence11 savers
- the-algorithm/README.md at main · twitter/the-algorithm2 savers
- Revoke user access in an emergency in Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn1 savers
- Microsoft 365: Identifying Mailbox Access | Aon1 savers
- New IDR Log Search Enhancements | Rapid7 Blog1 savers
- When MFA isn’t an option: The legacy of ROPC | Red Canary1 savers
- Legacy authentication: The curious case of BAV2ROPC1 savers
- Responding to Adversary in the Middle attacks1 savers
- Ahead of the (Yield) Curve - by Abraham Thomas - Pivotal1 savers
- Threat actors misuse OAuth applications to automate financially driven attacks | Microsoft Security Blog1 savers
- Email Compromise To Mass Phishing Campaign | Darktrace Blog1 savers
- Common Oauth Apps Used in Business Email Compromise – Syne's Cyber Corner1 savers
- Malicious Usage of eM Client In Business Email Compromise – Syne's Cyber Corner1 savers
- Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise – Syne's Cyber Corner1 savers
- How Palantir Meets IL6 Security Requirements with Apollo | by Palantir | Palantir Blog1 savers
- Ads Don't Work That Way9 savers
- Book Summary: Positioning by Al Ries and Jack Trout1 savers
- Book Summary: The 22 Immutable Laws of Marketing by Al Ries1 savers
- 5 Things I Wish Somebody Told Me Before I Founded My SaaS - Stacking the Bricks1 savers
- Shifting detection left for more effective ITDR1 savers
- Chinese threat actor Storm-0940 uses credentials from password spray attacks from a covert network | Microsoft Security Blog1 savers
- Abuse of "PerfectData Software" May Create a Perfect Storm | Darktrace Blog1 savers
- Exposing and shutting down an inbox heist in action1 savers
- The Soze Syndicate - Business Email Compromise1 savers
- Mamba 2FA: A new contender in the AiTM phishing ecosystem - Sekoia.io Blog1 savers
- New Mamba 2FA bypass service targets Microsoft 365 accounts1 savers
- The hidden danger that kills search products1 savers
- Entra ID service principals in business email compromise schemes1 savers
- Cloud coverage: Detecting an email payroll diversion attack1 savers
- Central Nodes3 savers
- How to Become a Master Negotiator Using These 7 Practical Negotiation Techniques2 savers
- Use customizable anomalies to detect threats in Microsoft Sentinel | Microsoft Learn2 savers
- Book Summary: Ogilvy on Advertising | Sam Thomas Davies2 savers
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 22 savers
- Software Supply Chain Security (Part 1)2 savers
- A Deep Dive Into The Cloud & Application Security Ecosystem2 savers
- App Developers: Start with Security | Federal Trade Commission2 savers
- Codifying a ChatGPT workflow into a malleable GUI2 savers
- Panther Labs' Jack Naglieri on Cloud-Native SIEM and Self-Growth2 savers
- The biggest bottleneck for large language model startups is UX | by Davis Treybig | Innovation Endeavors | Nov, 2022 | Medium3 savers
- The Illusion of Knowledge6 savers
- The Only Crypto Story You Need, by Matt Levine8 savers
- How to Do Great Work51 savers
- The Illustrated Transformer – Jay Alammar – Visualizing machine learning one concept at a time.35 savers
- The Grug Brained Developer29 savers
- How to Optimize a CUDA Matmul Kernel for cuBLAS-like Performance: a Worklog24 savers
- ChatGPT Is a Blurry JPEG of the Web | The New Yorker22 savers
- What Is ChatGPT Doing … and Why Does It Work?—Stephen Wolfram Writings19 savers
- I Will Fucking Piledrive You If You Mention AI Again — Ludicity18 savers
- The Art of Scaling Taste17 savers
- The Waluigi Effect (mega-post) - LessWrong16 savers
- Yes you should understand backprop | by Andrej Karpathy | Medium14 savers
- Strategy Letter V – Joel on Software14 savers
- The Arc Product-Market Fit Framework | Sequoia Capital14 savers
- How Duolingo reignited user growth - by Jorge Mazal13 savers
- Illustrating Reinforcement Learning from Human Feedback (RLHF)13 savers
- Superlinear Returns11 savers
- Visualizing A Neural Machine Translation Model (Mechanics of Seq2seq Models With Attention) – Jay Alammar – Visualizing machine learning one concept at a time.9 savers
- Too much efficiency makes everything worse: overfitting and the strong version of Goodhart’s law | Jascha’s blog8 savers
- How the most successful B2B startups came up with their original idea8 savers
- Building and operating a pretty big storage system called S3 | All Things Distributed7 savers
- Malleable software in the age of LLMs7 savers
- - Your AI Product Needs Evals7 savers
- Billionaires Build7 savers
- Twitter's Recommendation Algorithm5 savers
- AI Revolution - Transformers and Large Language Models (LLMs)5 savers
- Who Owns the Generative AI Platform? | Andreessen Horowitz5 savers
- The gossip trap - by Erik Hoel - The Intrinsic Perspective5 savers
- Can LLMs Critique and Iterate on Their Own Outputs? | Eric Jang4 savers
- A Few Good Stories · Collab Fund2 savers
highlights — 3387
For applications using access tokens, the user loses access when the access token expires. For applications that use session tokens, the existing sessions end as soon as the token expires. If the disabled state of the user is synchronized to the application, the application can automatically revoke the user's existing sessions if it's configured to do so. The time it takes depends on the frequency of synchronization between the application and Microsoft Entra ID.
Revoke user access in an emergency in Microsoft Entra ID - Microsoft Entra ID | Microsoft LearnOnce the application issues its own session token, the application controls access based on its authorization policies.
Revoke user access in an emergency in Microsoft Entra ID - Microsoft Entra ID | Microsoft LearnThe adversaries eventually logged into the My Profile application identified by the application ID 8c59ead7-d703-4a27-9e55-c96a0054c8d2, which displays some of the user’s account information such as job title, sign-in data, and devices used. Exactly what they viewed (or potentially modified) within this application was not displayed in any log we had available to us at the time. However, we suspect it was part of their account reconnaissance steps as we’ve also witnessed this pattern in other account compromises.
Exposing and shutting down an inbox heist in actionBe sure to note forwarding addresses to suspicious external domains, such as phishing domains or personal email accounts.
Microsoft 365: Identifying Mailbox Access | AonIn Stroz Friedberg’s testing, mail items accessed via applications were associated with bind events and log the specific message IDs associated with those events.
Microsoft 365: Identifying Mailbox Access | AonUpon unauthorized access into a mailbox, sync operations indicate that investigators should assume that all mail items in the synced folder are copied locally and have been compromised.
Microsoft 365: Identifying Mailbox Access | Aon“Client=ActiveSync” “Client=POP3\/IMAP4;Protocol=POP3” “Client=POP3\/IMAP4;Protocol=IMAP4”
Microsoft 365: Identifying Mailbox Access | AonFor exact match searches, like identifying a compromised IP address or hunting for a suspicious hash value where(hash.sha="..."), Bloom Filters optimize search time by ruling out irrelevant data - enabling the algorithm to skip logs that would not have matches
New IDR Log Search Enhancements | Rapid7 Blog50105: Your administrator has configured the application {appName} ({appId}) to block users unless they are specifically granted (assigned) access to the application. The signed in user {user} is blocked because they are not a direct member of a group with access, nor had access directly assigned by an administrator. Please contact your administrator to assign access to this application. 65002: Consent between first party application {applicationId} and first-party resource {resourceId} must be configured via preauthorization—applications owned and operated by Microsoft must get approval from …
When MFA isn’t an option: The legacy of ROPC | Red CanaryAstute readers familiar with Azure AD attacks may have also noticed the “foci” field in the token information above. This indicates that the issued Microsoft Teams refresh token can be used to obtain an access token for other applications, effectively widening the scopes available to an adversary without even requesting consent.
When MFA isn’t an option: The legacy of ROPC | Red CanaryOne application they might target to validate the credentials and gain access is Microsoft Teams (Application ID: 1fec8e78-bce4-4aaf-ab1b-5451cc387264), which supports the ROPC flow. With only a single web request, they can validate the credentials and obtain an access token with which they could gain access to the victim resources.
When MFA isn’t an option: The legacy of ROPC | Red CanaryClient=Hub Transport;User=test@some_tenant.onmicrosoft.com;IsClientSubmission=True
Legacy authentication: The curious case of BAV2ROPCauthenticationProtocol is ROPC, and the clientAppUsed used is Authenticated SMTP.
Legacy authentication: The curious case of BAV2ROPCWith BAV2ROPC, you can (sort of) enforce MFA in that authentication can be blocked for protocols that don’t support MFA when MFA is enabled on a user principal.
Legacy authentication: The curious case of BAV2ROPCWe have confirmed through testing that this user agent is set by Microsoft when it identifies basic/legacy authentication from legacy protocols like SMTP AUTH.
Legacy authentication: The curious case of BAV2ROPCResource Owner Password Credential (ROPC) that allows a client to accept and transmit valid credentials and pass them on to the IdP for token grants,
Legacy authentication: The curious case of BAV2ROPCbasic authentication is an outdated industry standard that allows applications to send usernames and passwords with every authentication request, making it easier for attackers to capture and abuse user credentials
Legacy authentication: The curious case of BAV2ROPCSMTP AUTH will remain supported because devices that don’t support modern authentication—like scanners and printers—continue to rely on it
Legacy authentication: The curious case of BAV2ROPCHowever, it 12 hours later flagged the session with an offline detection due to an anomalous token detection, which according to Microsoft indicated:
Responding to Adversary in the Middle attacksThat time the whole trading system had to be paused for weeks because of a devilish bug: a low-level optimization routine kept flipping between two equally valid solutions (it was a ‘slightly’ under-determined system) — we eventually figured out it was due to an unstable interaction between our annealing algorithm, our random number generator, and the way eigenvalues work.
Ahead of the (Yield) Curve - by Abraham Thomas - PivotalThen, for any market move in between our 60-minute resets, we’d just do a linear approximation — a simple matrix multiplication sufficed to generate the new parameter values, and another one sufficed to generate the predicted yields elsewhere on the curve
Ahead of the (Yield) Curve - by Abraham Thomas - Pivotaland use them to solve for the 4 daily-changing parameters (4 equations, 4 unknowns). The model would then be able to predict yields at every other point; we could then buy (sell) bonds that appeared cheap (rich) relative to their predicted yields. (Taking into account coupon effects, cashflow timing, financing costs, liquidity and other niggly details of course.)
Ahead of the (Yield) Curve - by Abraham Thomas - Pivotal8 of the parameters were constants, denoting unchanging structural aspects of the economy; we'd calibrate these about once a year, running an optimization (the EM algorithm) that took many hours to run, over a decade-plus of historical data
Ahead of the (Yield) Curve - by Abraham Thomas - Pivotalwe needed to construct a universe of ‘virtual’ bonds with constant maturities, that were linear combinations of actual bonds.
Ahead of the (Yield) Curve - by Abraham Thomas - PivotalOCR tech wasn't great in those days, so we had two separate back offices, in Tokyo and Hong Kong, manually entering prices from these runs.
Ahead of the (Yield) Curve - by Abraham Thomas - PivotalRealize that a rough hedge done instantly is superior to a perfect hedge that takes time or costs money.
Ahead of the (Yield) Curve - by Abraham Thomas - PivotalLTCM and Simplex both specialized in ‘convergence trading’ — building quantitative models of relationships between different securities; placing bets to exploit inconsistencies (‘mispricings’) in those relationships; and profiting when those inconsistencies resolved (‘converged’).
Ahead of the (Yield) Curve - by Abraham Thomas - PivotalThe threat actors misused the OAuth applications with high privilege permissions to deploy virtual machines (VMs) for cryptocurrency mining, establish persistence following business email compromise (BEC), and launch spamming activity using the targeted organization’s resources and domain name.
Threat actors misuse OAuth applications to automate financially driven attacks | Microsoft Security BlogThese logins were carried out from the same VPN endpoints as the attacker’s original logins. On February 11, the attacker was observed creating an inbox rule named “ , ” on one of these accounts. Shortly after, the attacker went on to register and grant permissions to the same mass-mailing application,
Email Compromise To Mass Phishing Campaign | Darktrace Blogyou’ll see that you can link the site to a 365 account via an app consent, grant it permission to view your contacts
Common Oauth Apps Used in Business Email Compromise – Syne's Cyber CornerThankfully, usage of this application has dropped significantly, as it now appears to require administrator consent to be used.
Common Oauth Apps Used in Business Email Compromise – Syne's Cyber CornerThe only problem that I can see, is that the only actions I find in the UAL are the Bind type, while I would expect them to instead be the Sync type.
Malicious Usage of eM Client In Business Email Compromise – Syne's Cyber CornerAs I mentioned earlier, eM Client’s use of EWS means that it has many features and settings that are interesting and potentially useful during a BEC.
Malicious Usage of eM Client In Business Email Compromise – Syne's Cyber CornerSince multiple accounts for multiple email providers can be added, this application would allow threat actors to easily switch between many compromised accounts without having to sign in/out.
Malicious Usage of eM Client In Business Email Compromise – Syne's Cyber CornerThe exact permissions granted to the applications are your standard permissions for most integrated oauth applications, with the addition of EWS.AccessAsUser.All.
Malicious Usage of eM Client In Business Email Compromise – Syne's Cyber CornerFor M365, this means opening a browser and using the modern authentication login. After logging in, you are presented with a request to accept the application’s permissions.
Malicious Usage of eM Client In Business Email Compromise – Syne's Cyber CornerFor M365, this means opening a browser and using the modern authentication login. After logging in, you are presented with a request to accept the application’s permissions.
Malicious Usage of eM Client In Business Email Compromise – Syne's Cyber CornerIt connects using Exchange Web Services, which is an API that allows non-Microsoft applications to integrate with Exchange Online and On-Premise Exchange.
Malicious Usage of eM Client In Business Email Compromise – Syne's Cyber CornerMy testing has shown me that this tool cannot be used to back up mailboxes that the user has delegated access to
Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise – Syne's Cyber CornerNow, remember what I said about administrative users? Well, this tool will allow an administrative account to back up as many mailboxes as a person wants.
Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise – Syne's Cyber CornerSince it’s a PST, it grabs calendar events and contacts on top of emails and attachments.
Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise – Syne's Cyber CornerThis application is used to take a backup of the entire mailbox from the cloud and export it to PST. Assume that everything within the mailbox is lost, and any useful information will be used for future fraud or sold on the dark net. Oh, and if it was an administrative user compromised? It could potentially be every mailbox within the organization.
Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise – Syne's Cyber CornerWith secrets and other configuration decoupled from the Kubernetes cluster or VMs that run the services, we can easily reapply them onto new infrastructure should an incident ever pop up, making it simple to isolate and replace nodes of a service.
How Palantir Meets IL6 Security Requirements with Apollo | by Palantir | Palantir BlogInstead, brands carve out a relatively narrow slice of brand-identity space and occupy it for decades. And the cultural imprinting model explains why. Brands need to be relatively stable and put on a consistent "face" because they're used by consumers to send social messages, and if the brand makes too many different associations, (1) it dilutes the message that any one person might want to send, and (2) it makes people uncomfortable about associating themselves with a brand that jumps all over the place, firing different brand messages like a loose cannon.
Ads Don't Work That WayThe answer, I think, is that going to a gas station is a personal rather than a social activity, whereas drinking a soda is so often done in the company of others.
Ads Don't Work That WayBecause during the Superbowl, everyone knows that everyone else is watching, and so any brand image that's conveyed during the Superbowl is almost guaranteed to take root in the broader culture, and therefore to be perceived "correctly" at a later date.
Ads Don't Work That WayPeer pressure is an extremely powerful force, and if advertising can tap into it even a fraction of that power, it can have a sizable effect.
Ads Don't Work That WayOver time and with enough exposure, the customer will realize that "Nike" is synonymous with "athletic excellence" out in the broader culture.
Ads Don't Work That Wayin other words, in broadcast media
Ads Don't Work That WayI have to see the ad, but I also have to know (or suspect) that most of my friends have seen the ad too
Ads Don't Work That Way