While most attacks against cloud identities still rely on traditional password-based techniques, such as password spraying, credential stuffing, and brute-force attacks, these methods have become less effective as multi-factor authentication (MFA) has become more widespread. As a result, attackers are increasingly turning to token-based techniques, including token theft, adversary-in-the-middle (AiTM) attacks, device code phishing, and ConsentFix, which get around MFA instead of trying to break it.
As one of the most widely deployed identity platforms, Microsoft Entra ID is a prime target for these evolving attack techniques. This raises the question: how well does its defense-in-depth strategy actually hold up against this shift? We put it to the test.
In our presentation, we explored the security challenges of namespace-based multi-tenancy in Kubernetes. We demonstrated real-world attacks against Kubeflow, Istio, and Traefik that can break the intended isolation between namespaces and workloads. One of the highlights was demonstrating a privilege-escalation attack we discovered that allowed us to gain cluster-admin privileges.
With this blog post I am pleased to announce the publication of a new ERNW White
Paper about our incident analysis and digital forensics framework. It is
available on our website.
Due to the increasing number and impact of computer security incidents, it has
become essential to develop and implement efficient measures for their
investigation. However, comprehensive forensic analyses are time-consuming, and
this time is often not available to security analysts during computer security
incidents. As a result, automated tools are increasingly being used. These
tools, however, often cover only a limited scope of the necessary analyses and
typically require deep technical expertise to be used effectively.
Hardening a Linux client system to an acceptable degree is a time-consuming
process, one that demands familiarity with a broad set of configuration
parameters, framework recommendations, and the reasoning behind each control.
This post introduces our new Linux client hardening guide
(MD,
PDF), a comprehensive, publicly
available hardening reference for Linux systems.
Motivation and Scope
The guide covers the full breadth of controls needed to significantly raise the
security posture of a modern Linux installation while preserving operational
usability (this will be very subjective, the guide reflects my opinion of
“usable”). It has been developed and validated against Ubuntu 24.04 LTS as the
primary reference platform, and cross-tested on Fedora, Debian 12, and Arch
Linux as well as on traditionally server-oriented distributions like openSUSE
Leap 15.6, Debian 12, Rocky Linux 9, and Red Hat Enterprise Linux 9 while not
focussing on those as the guide is created for Linux clients.
After seven years, we’re publishing a new macOS hardening guide. Fully updated,
modernized, and now publicly available on
GitHub
as
Markdown
and on our website as
PDF.
The previous guide, written for macOS Mojave (10.14), reflected a very different
macOS security model. At the time, hardening often meant working around the
operating system, manually enforcing controls, and compensating for missing
platform guarantees. That guide served its purpose, but the platform has
fundamentally changed since then.
Today we are releasing a new white paper that delivers a technical analysis of
security weaknesses discovered in WinpMem, an open-source Windows memory
acquisition driver widely used in digital forensics.
After a concise primer on relevant Windows internals (virtual vs. physical
memory, page tables and PTEs, CR3 context switching, and kernel and user memory
separation), the report examines how both the fundamental design of WinpMem and
specific implementation choices create severe risk.
I am glad to announce the release of the ERNW whitepaper 71 containing
information about quarantine file formats of different AV software vendors. It
is available
here.
Anti-Virus Software
I took quarantine files from real-life incidents and created some in a lab
environment. Afterwards I tried to identify metadata, like timestamps, path
names, malware names, and the actual malicious file in the quarantine files. One
goal was to use this information to support our incident analyses: Using the
results, we can now easily create timelines showing information about
quarantined files, extract the detected malware, and sometimes even find
information about processes that created the malicious files.
With this blog post I am pleased to announce the publication of a new ERNW White
Paper about the HL7 FHIR communication standard.
Introduction
Digital networking is already widespread in many areas of life. More and more
medical devices are also being networked in the healthcare industry. This growth
makes the development and use of new medical communication standards necessary
since existing solutions can only meet the changing requirements with great
effort. The HL7 FHIR standard is an example of such a medical communication
standard. FHIR is said to have increased the interoperability between different
medical contexts,e.g., administration, billing, and clinical care, to enable
data exchange of various systems. The FHIR standard addresses the security risks
associated with strongly networked communication from a large number of systems
across the trust and organizational boundaries only indirectly because FHIR does
not define mandatory security controls or requirements.
With this blog post I am pleased to announce the publication of a new ERNW White
Paper [1]. The paper
is about severe vulnerabilities in an insulin pump we assessed during project
ManiMed and we are proud to publish this subset of the results today.
Manipulating Medical Devices
The German Federal Office for Information Security (BSI), in its role as the
Federal Cyber Security Authority in Germany, aims to sensitize manufacturers and
the public regarding security risks of networked medical devices. In response to
the often fatal security reports and press releases of networked medical
devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed)
in 2019. In this project, a security analysis of selected products is carried
out through security assessments. In the context of this project, severe
vulnerabilities were identified during the assessment of the DANA Diabecare RS
system.