Microsoft Teams, Patreon, and Uber

Published: Sept. 19, 2022, 1:53 a.m.

This week, Adam and Andy talk about Microsoft Teams and the post-exploit technique that was discovered by Vetra's Project Team and the decision of Patreon to lay off their entire internal information security team. The also talk about Uber's on-going cybersecurity incident including some initial reports of how it happened as well as mitigations to prevent this type of attack in the future.

\n

-------------------------------------------

\n

Youtube Video Link: https://youtu.be/FWnEma4hOWQ

\n

-------------------------------------------

\n

Documentation:

\n

https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens

\n

https://techcrunch.com/2022/09/09/patreon-security-layoffs/

\n

https://learn.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-passwordless

\n

https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-faqs

\n

-------------------------------------------

\n

Contact Us:

\n

Website: http://bluesecuritypod.com

\n

Twitter: https://twitter.com/bluesecuritypod

\n

Linkedin: https://www.linkedin.com/company/bluesecpod

\n

Youtube: https://www.youtube.com/c/BlueSecurityPodcast

\n

Instagram: https://www.instagram.com/bluesecuritypodcast/

\n

Facebook: https://www.facebook.com/bluesecpod

\n

Twitch: https://www.twitch.tv/bluesecuritypod

\n

-------------------------------------------

\n

Andy Jaw

\n

Twitter: https://twitter.com/ajawzero

\n

LinkedIn: https://www.linkedin.com/in/andyjaw/

\n

Email: andy@bluesecuritypod.com

\n

-------------------------------------------

\n

Adam Brewer

\n

Twitter: https://twitter.com/ajbrewer

\n

LinkedIn: https://www.linkedin.com/in/adamjbrewer/

\n

Email: adam@bluesecuritypod.com

\n\n--- \n\nSend in a voice message: https://podcasters.spotify.com/pod/show/blue-security-podcast/message