Viktor Hedberg 🛡💻 (@headburgh) 's Twitter Profile
Viktor Hedberg 🛡💻

@headburgh

I do security stuff @Truesec • MVP • Father • My tweets are my own • He/him

ID: 748138241593843713

linkhttps://hedbergtech.se calendar_today29-06-2016 12:57:11

1,1K Tweet

1,1K Followers

611 Following

Microsoft Threat Intelligence (@msftsecintel) 's Twitter Profile Photo

Microsoft has uncovered a vulnerability in ESXi hypervisors, identified as CVE-2024-37085, being exploited by threat actors to obtain full administrative permissions on domain-joined ESXi hypervisors and encrypt critical servers in ransomware attacks. msft.it/6012lbTai

Fabian Bader (@fabian_bader) 's Twitter Profile Photo

Microsoft Defender for Identity Expands to Entra Connect Server This includes new detections, new security recommendations, and a new activity type in the IdentityDirectoryEvents. Don't forget to configure you MDI gmsa account. #MDI #EntraID #Security techcommunity.microsoft.com/t5/microsoft-d…

✞ inversecos (@inversecos) 's Twitter Profile Photo

Understanding EVERY Token in Entra ID 🔎 Not all tokens are equal. There are many different types with different uses and benefits. In this blog, I break down each token and what they are used for and which tokens are the most "valuable" for an attacker to obtain. Full blog

Understanding EVERY Token in Entra ID 🔎

Not all tokens are equal. There are many different types with different uses and benefits.

In this blog, I break down each token and what they are used for and which tokens are the most "valuable" for an attacker to obtain.

Full blog
Microsoft Threat Intelligence (@msftsecintel) 's Twitter Profile Photo

The financially motivated cybercriminal group that Microsoft tracks as Storm-0501 has been observed exfiltrating data and deploying Embargo ransomware after moving laterally from on-premises to the cloud environment. msft.it/6013m5gnf

Viktor Hedberg 🛡💻 (@headburgh) 's Twitter Profile Photo

Spent the last couple of days in Stockholm speaking at #Teamsdagen. Made new friends and met old ones as well. The event was a huge success, and kudos to the organizers for an awesome event!

Spent the last couple of days in Stockholm speaking at #Teamsdagen. Made new friends and met old ones as well.

The event was a huge success, and kudos to the organizers for an awesome event!
Nicola Suter (@nicolonsky) 's Twitter Profile Photo

Pop quiz, which requirement providers can enforce MFA within Entra ID? #Azure Portal with 'request' & 'App requires MFA' will be next I guess (: github.com/nicolonsky/ITD…

Pop quiz, which requirement providers can enforce MFA within Entra ID? #Azure Portal with 'request' & 'App requires MFA' will be next I guess (: 
github.com/nicolonsky/ITD…
Viktor Hedberg 🛡💻 (@headburgh) 's Twitter Profile Photo

Wheels up tomorrow morning, prepping for mine and Mikael Nystrom's Masterclass at NIC 2025 on Wednesday, and our respective sessions on Thursday. #Truesec #NICConf #PreventBreach #MinimizeImpact

Wheels up tomorrow morning, prepping for mine and <a href="/mikael_nystrom/">Mikael Nystrom</a>'s Masterclass at <a href="/NICconf/">NIC 2025</a> on Wednesday, and our respective sessions on Thursday.

#Truesec #NICConf #PreventBreach #MinimizeImpact
Jan Bakker (@janbakker_) 's Twitter Profile Photo

Hey, Entra ID admins. Do you have Passkey (FIDO2) enabled, and does your setting look like this? Early next year, Passkey in Authenticator will be enabled automatically. If that's okay, sit back and relax while your users become phishing-resistant. If not, please act now!

Hey, Entra ID admins. Do you have Passkey (FIDO2) enabled, and does your setting look like this? Early next year, Passkey in Authenticator will be enabled automatically.

If that's okay, sit back and relax while your users become phishing-resistant. If not, please act now!
Merill Fernando (@merill) 's Twitter Profile Photo

⚡ Check out this new Microsoft Entra blog post 👇 Microsoft Entra PowerShell module now generally available techcommunity.microsoft.com/t5/microsoft-e…

AppManagEvent (@appmanagevent) 's Twitter Profile Photo

Enhance your AppManagEvent 2025 visit by attending an exclusive in-person IT-Pro training from top experts like Sami Laiho Paula Januszkiewicz Mikael Nystrom Viktor Hedberg 🛡💻 or Timothy Mangan – before and/or after the event! 🎟️ Bonus: Your training session includes a ticket to the event.

Enhance your AppManagEvent 2025 visit by attending an exclusive in-person IT-Pro training from top experts like <a href="/samilaiho/">Sami Laiho</a> <a href="/PaulaCqure/">Paula Januszkiewicz</a> <a href="/mikael_nystrom/">Mikael Nystrom</a> <a href="/headburgh/">Viktor Hedberg 🛡💻</a> or <a href="/TimothyMangan/">Timothy Mangan</a> – before and/or after the event!

🎟️ Bonus: Your training session includes a ticket to the event.
vx-underground (@vxunderground) 's Twitter Profile Photo

Department of Government Efficiency Good find. Those licenses cost on average $500,000,000/year. That saved the country potentially hundreds of billions of dollars. Now the government can put that money to good use such as reintroducing lead to paint to keep the photon radioactive waves out of our brains

Mikael Nystrom (@mikael_nystrom) 's Twitter Profile Photo

Restore and Repair – Don’t Build New After an Incident Truesec https://www.truesec.comhub/blog/restore-and-repair-dont-build-new-after-an-incident

Restore and Repair – Don’t Build New After an Incident
<a href="/Truesec/">Truesec</a> 

 https://www.truesec.comhub/blog/restore-and-repair-dont-build-new-after-an-incident
Viktor Hedberg 🛡💻 (@headburgh) 's Twitter Profile Photo

What's a red flag in IR 🚩? My colleague Mikael Nystrom takes you through some of the tools of the trade. Read more here: truesec.com/hub/blog/resto…