writeups.xyz writeups.xyz / Lateral Movement

Title Vulnerabilities Programs Authors
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD
The risk in malicious AI models: Wiz Research discovers critical vulnerability in AI-as-a-Service provider, Replicate
Lateral movement and on-prem NT hash dumping with Microsoft Entra Temporary Access Passes
Performance, Diagnostics, and WMI
#BrokenSesame: Accidental ‘write’ permissions to private registry allowed potential RCE to Alibaba Cloud Database Services
Your Browser is Not a Safe Space
Azure Ad Kerberos Tickets: Pivoting To The Cloud
Jumping into SOCKS
[RE:SCRUTINY] Delay Then Migrate Your Meterpreter
The power of adaptability through experience.
From Self-Hosted GitHub Runner to Self-Hosted Backdoor