ioc.exchange is one of the many independent Mastodon servers you can use to participate in the fediverse.
INDICATORS OF COMPROMISE (IOC) InfoSec Community within the Fediverse. Newbies, experts, gurus - Everyone is Welcome! Instance is supposed to be fast and secure.

Administered by:

Server stats:

1.3K
active users

#printnightmare

0 posts0 participants0 posts today
Lukas Beran<p>𝐇𝐎𝐖 𝐓𝐎 𝐃𝐈𝐒𝐀𝐁𝐋𝐄 𝐏𝐑𝐈𝐍𝐓 𝐒𝐏𝐎𝐎𝐋𝐄𝐑 𝐎𝐍 𝐃𝐎𝐌𝐀𝐈𝐍 𝐂𝐎𝐍𝐓𝐑𝐎𝐋𝐋𝐄𝐑𝐒</p><p>Print Spooler is a service that takes care of print management. This includes, but is not limited to, managing printer drivers, scheduling print jobs, etc.</p><p>Print Spooler had a critical vulnerability in the past referred to as PrintNightmare (CVE-2021-34527). This vulnerability allowed attackers to execute code with administrator privileges.</p><p>The Print Spooler vulnerability was patched promptly, so if you have updated systems, the immediate risk associated with PrintNightmare is no longer present. And for normal systems, it is usually not feasible to disable Print Spooler. It would make printing impossible, which is usually not desirable.</p><p>But domain controllers are a critical part of Active Directory and need to be as secure as possible, which means blocking everything that is not needed. And you certainly should not need to print on domain controllers, so it’s a good idea to disable Print Spooler on domain controllers.</p><p>📺 Watch my YouTube video bellow on how to disable Print Spooler on Domain Controllers 👇 👇 <br><a href="https://youtu.be/O80HHKdnbcQ" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">youtu.be/O80HHKdnbcQ</span><span class="invisible"></span></a></p><p><a href="https://infosec.exchange/tags/cswlrd" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cswlrd</span></a> <a href="https://infosec.exchange/tags/printspooler" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>printspooler</span></a> <a href="https://infosec.exchange/tags/domaincontrollers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>domaincontrollers</span></a> <a href="https://infosec.exchange/tags/printnightmare" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>printnightmare</span></a> <a href="https://infosec.exchange/tags/videotutorial" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>videotutorial</span></a></p>
Pyrzout :vm:<p>PrintNightmare Aftermath: Windows Print Spooler is Better. What’s Next? – Source: www.darkreading.com <a href="https://ciso2ciso.com/printnightmare-aftermath-windows-print-spooler-is-better-whats-next-source-www-darkreading-com/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">ciso2ciso.com/printnightmare-a</span><span class="invisible">ftermath-windows-print-spooler-is-better-whats-next-source-www-darkreading-com/</span></a> <a href="https://social.skynetcloud.site/tags/rssfeedpostgeneratorecho" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>rssfeedpostgeneratorecho</span></a> <a href="https://social.skynetcloud.site/tags/DarkReadingSecurity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DarkReadingSecurity</span></a> <a href="https://social.skynetcloud.site/tags/CyberSecurityNews" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurityNews</span></a> <a href="https://social.skynetcloud.site/tags/PrintNightmare" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PrintNightmare</span></a> <a href="https://social.skynetcloud.site/tags/DARKReading" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DARKReading</span></a></p>
Just Another Blue Teamer<p>Happy Monday everyone!</p><p>I am sifting through the Cisco Talos Intelligence Group &quot;Year In Review&quot; report that was recently published and highlighting some of the things that I found useful/interesting from my perspective. </p><p>Top Targeted Vulnerabilities:<br />7/10 of the top CVE&#39;s belonged to <a href="https://ioc.exchange/tags/Microsoft" class="mention hashtag" rel="tag">#<span>Microsoft</span></a>. Now I am not pointing fingers, I think it is there simply because the vast majority of environments are Windows. <br />What IS concerning is that there are multiple vulnerabilities that were being exploited that were either 10 years old or ALMOST 10 years old. <br />8/10 of the top CVE&#39;s had a score of 9 or above. </p><p>One of these CVE&#39;s was CVE-2021-1675, which is a remote code execution vulnerability that exists when the Windows Print Spooler service improperly performs privileged file operations. One product of this vulnerability was the <a href="https://ioc.exchange/tags/PrintNightmare" class="mention hashtag" rel="tag">#<span>PrintNightmare</span></a> exploit that was leveraged by the <a href="https://ioc.exchange/tags/Magniber" class="mention hashtag" rel="tag">#<span>Magniber</span></a> ransomware group.</p><p>Stay tuned for more as we work our way through this report! Enjoy and Happy Hunting!</p><p><a href="https://blog.talosintelligence.com/talos-year-in-review-2022/" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://</span><span class="ellipsis">blog.talosintelligence.com/tal</span><span class="invisible">os-year-in-review-2022/</span></a></p>
dispatch<p>Microsoft Patch Tuesday, August 2021 Edition <a href="https://krebsonsecurity.com/2021/08/microsoft-patch-tuesday-august-2021-edition/" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://</span><span class="ellipsis">krebsonsecurity.com/2021/08/mi</span><span class="invisible">crosoft-patch-tuesday-august-2021-edition/</span></a> <a href="https://ioc.exchange/tags/TrendMicroZeroDayInitiative" class="mention hashtag" rel="tag">#<span>TrendMicroZeroDayInitiative</span></a> <a href="https://ioc.exchange/tags/sansinternetstormcenter" class="mention hashtag" rel="tag">#<span>sansinternetstormcenter</span></a> <a href="https://ioc.exchange/tags/PatchTuesdayAugust2021" class="mention hashtag" rel="tag">#<span>PatchTuesdayAugust2021</span></a> <a href="https://ioc.exchange/tags/WindowsUpdateMedic" class="mention hashtag" rel="tag">#<span>WindowsUpdateMedic</span></a> <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-26424 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-34481 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-34535 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-36936 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-36948 <a href="https://ioc.exchange/tags/PrintNightmare" class="mention hashtag" rel="tag">#<span>PrintNightmare</span></a> <a href="https://ioc.exchange/tags/ImmersiveLabs" class="mention hashtag" rel="tag">#<span>ImmersiveLabs</span></a> <a href="https://ioc.exchange/tags/AskWoody" class="mention hashtag" rel="tag">#<span>AskWoody</span></a>.com <a href="https://ioc.exchange/tags/DustinChilds" class="mention hashtag" rel="tag">#<span>DustinChilds</span></a> <a href="https://ioc.exchange/tags/TimetoPatch" class="mention hashtag" rel="tag">#<span>TimetoPatch</span></a> <a href="https://ioc.exchange/tags/KevinBreen" class="mention hashtag" rel="tag">#<span>KevinBreen</span></a></p>
dispatch<p>Microsoft Patch Tuesday, July 2021 Edition <a href="https://krebsonsecurity.com/2021/07/microsoft-patch-tuesday-july-2021-edition/" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://</span><span class="ellipsis">krebsonsecurity.com/2021/07/mi</span><span class="invisible">crosoft-patch-tuesday-july-2021-edition/</span></a> <a href="https://ioc.exchange/tags/MicrosoftPatchTuesdayJuly2021" class="mention hashtag" rel="tag">#<span>MicrosoftPatchTuesdayJuly2021</span></a> <a href="https://ioc.exchange/tags/ChadMcNaughton" class="mention hashtag" rel="tag">#<span>ChadMcNaughton</span></a> <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-31979 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-33771 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-34448 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-34458 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-34473 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-34494 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-34523 <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-34527 <a href="https://ioc.exchange/tags/PrintNightmare" class="mention hashtag" rel="tag">#<span>PrintNightmare</span></a> <a href="https://ioc.exchange/tags/Windowsupdates" class="mention hashtag" rel="tag">#<span>Windowsupdates</span></a> <a href="https://ioc.exchange/tags/SecurityTools" class="mention hashtag" rel="tag">#<span>SecurityTools</span></a> <a href="https://ioc.exchange/tags/SatnamNarang" class="mention hashtag" rel="tag">#<span>SatnamNarang</span></a> <a href="https://ioc.exchange/tags/TimetoPatch" class="mention hashtag" rel="tag">#<span>TimetoPatch</span></a> <a href="https://ioc.exchange/tags/Automox" class="mention hashtag" rel="tag">#<span>Automox</span></a> <a href="https://ioc.exchange/tags/Tenable" class="mention hashtag" rel="tag">#<span>Tenable</span></a></p>
dispatch<p>Microsoft Issues Emergency Patch for Windows Flaw <a href="https://krebsonsecurity.com/2021/07/microsoft-issues-emergency-patch-for-windows-flaw/" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://</span><span class="ellipsis">krebsonsecurity.com/2021/07/mi</span><span class="invisible">crosoft-issues-emergency-patch-for-windows-flaw/</span></a> <a href="https://ioc.exchange/tags/LatestWarnings" class="mention hashtag" rel="tag">#<span>LatestWarnings</span></a> <a href="https://ioc.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a>-2021-34527 <a href="https://ioc.exchange/tags/PrintNightmare" class="mention hashtag" rel="tag">#<span>PrintNightmare</span></a> <a href="https://ioc.exchange/tags/SecurityTools" class="mention hashtag" rel="tag">#<span>SecurityTools</span></a> <a href="https://ioc.exchange/tags/SatnamNarang" class="mention hashtag" rel="tag">#<span>SatnamNarang</span></a> <a href="https://ioc.exchange/tags/TimetoPatch" class="mention hashtag" rel="tag">#<span>TimetoPatch</span></a> <a href="https://ioc.exchange/tags/KB5004945" class="mention hashtag" rel="tag">#<span>KB5004945</span></a> <a href="https://ioc.exchange/tags/Tenable" class="mention hashtag" rel="tag">#<span>Tenable</span></a></p>
dispatch<p>PrintNightmare zero day exploit for Windows is in the wild – what you need to know <a href="https://grahamcluley.com/printnightmare-zero-day-exploit/" target="_blank" rel="nofollow noopener noreferrer" translate="no"><span class="invisible">https://</span><span class="ellipsis">grahamcluley.com/printnightmar</span><span class="invisible">e-zero-day-exploit/</span></a> <a href="https://ioc.exchange/tags/PrintNightmare" class="mention hashtag" rel="tag">#<span>PrintNightmare</span></a> <a href="https://ioc.exchange/tags/Vulnerability" class="mention hashtag" rel="tag">#<span>Vulnerability</span></a> <a href="https://ioc.exchange/tags/vulnerability" class="mention hashtag" rel="tag">#<span>vulnerability</span></a> <a href="https://ioc.exchange/tags/Microsoft" class="mention hashtag" rel="tag">#<span>Microsoft</span></a> <a href="https://ioc.exchange/tags/Malware" class="mention hashtag" rel="tag">#<span>Malware</span></a> <a href="https://ioc.exchange/tags/printer" class="mention hashtag" rel="tag">#<span>printer</span></a> <a href="https://ioc.exchange/tags/ZeroDay" class="mention hashtag" rel="tag">#<span>ZeroDay</span></a></p>