Why keeping track of user accounts is important
ID: 68dd5960-d62d-5292-9c24-07578d450014
STIX ID: report--68dd5960-d62d-5292-9c24-07578d450014
Feed Name: Malwarebytes Blog
CISA warns that an attacker used credentials from a former employee to access an organization’s VPN, escalate via a SharePoint server that stored domain admin credentials, and query on-premises AD and Azure AD (LDAP enumeration); the harvested host and user data was likely put up for sale on a dark-web brokerage site. The advisory recommends removing privileges for offboarded accounts, enforcing least privilege and separate admin accounts, using phishing-resistant MFA (FIDO/WebAuthn), improving asset management, patching, and enhanced logging/monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
