curated infosec & other content, personal, not=employer.

Joined October 2012
354 Photos and videos
stuart smiles retweeted
Microsoft introduces Backup and Recovery for Microsoft Entra ID! Entra Backup and Recovery solution enables you to quickly recover from malicious attacks or accidental changes by reverting your core tenant objects to any previous state within the last 5 days. With automated backups and granular recovery capabilities, it ensures minimal downtime and supports your business continuity in the face of unexpected disruptions. Entra automatically generates one backup per day, retaining the last 5 days of backup history. You can recover key properties of the following core tenant objects: - Users - Groups - Applications - Conditional access policies - Service principals - Organization - Authentication methods - Authorization policy - Named locations #EntraID #Microsoft365 #Microsoft
13
139
618
92,500
there's an AWS outage in me-central-1 because it got bombed
154
1,393
17,113
3,280,762
stuart smiles retweeted
๐Ÿ”’ Secure Bits ๐Ÿ’ก ๐—ฆ๐— ๐—ง๐—ฃ ๐—”๐—จ๐—ง๐—› ๐—ถ๐—ป ๐—˜๐˜…๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ ๐—ข๐—ป๐—น๐—ถ๐—ป๐—ฒ ๐—ถ๐˜€ ๐—ผ๐—ณ๐—ณ๐—ถ๐—ฐ๐—ถ๐—ฎ๐—น๐—น๐˜† ๐—ด๐—ผ๐—ถ๐—ป๐—ด ๐—ฎ๐˜„๐—ฎ๐˜† โ€” ๐˜๐—ต๐—ฒ ๐˜๐—ถ๐—บ๐—ฒ๐—น๐—ถ๐—ป๐—ฒ ๐—ถ๐˜€ ๐—ป๐—ผ๐˜„ ๐˜‚๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ๐—ฑ. Microsoft has published an ๐˜‚๐—ฝ๐—ฑ๐—ฎ๐˜๐—ฒ๐—ฑ ๐—ฑ๐—ฒ๐—ฝ๐—ฟ๐—ฒ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐˜๐—ถ๐—บ๐—ฒ๐—น๐—ถ๐—ป๐—ฒ ๐—ณ๐—ผ๐—ฟ ๐—ฆ๐— ๐—ง๐—ฃ ๐—”๐—จ๐—ง๐—› ๐˜‚๐˜€๐—ถ๐—ป๐—ด ๐—•๐—ฎ๐˜€๐—ถ๐—ฐ ๐—”๐˜‚๐˜๐—ต๐—ฒ๐—ป๐˜๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป in Exchange Online - and it will end fairly soon. If you still rely on SMTP AUTH for: - Applications and scripts - Printers and scanners - Legacy systems or monitoring tools โ€ฆ those systems ๐˜„๐—ถ๐—น๐—น ๐˜€๐˜๐—ผ๐—ฝ ๐˜€๐—ฒ๐—ป๐—ฑ๐—ถ๐—ป๐—ด emails once deprecation is enforced. โฐ ๐—ช๐—ต๐—ฎ๐˜ ๐—ถ๐˜€ ๐˜๐—ต๐—ฒ ๐˜๐—ถ๐—บ๐—ฒ๐—น๐—ถ๐—ป๐—ฒ? - ๐—˜๐—ป๐—ฑ ๐—ผ๐—ณ ๐——๐—ฒ๐—ฐ๐—ฒ๐—บ๐—ฏ๐—ฒ๐—ฟ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ: SMTP AUTH Basic Authentication will be disabled for existing tenants. Administrators will still be able to enable it if needed. - ๐—๐—ฎ๐—ป๐˜‚๐—ฎ๐—ฟ๐˜† ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿณ: SMTP AUTH Basic Authentication will be unavailable for newly created tenants. OAuth will be the supported authentication method. - ๐—ฆ๐—ฒ๐—ฐ๐—ผ๐—ป๐—ฑ ๐—ต๐—ฎ๐—น๐—ณ ๐—ผ๐—ณ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿณ: Microsoft will announce the final removal date for SMTP AUTH Basic Authentication. ๐Ÿค” ๐—ช๐—ต๐˜† ๐˜๐—ต๐—ถ๐˜€ ๐—บ๐—ฎ๐˜๐˜๐—ฒ๐—ฟ๐˜€ SMTP AUTH is one of those things that often runs in the background. More often the not, critical service or system relies on it. When it breaks, the impact is very visible โ€” invoices not sent, alerts not delivered, workflows failing โ€” but the root cause is often not obvious. Fixing it usually isnโ€™t a checkbox. It often requires ๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ถ๐—ป๐—ด ๐—ต๐—ผ๐˜„ ๐—ฎ๐—ฝ๐—ฝ๐—น๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป๐˜€ ๐˜€๐—ฒ๐—ป๐—ฑ ๐—บ๐—ฎ๐—ถ๐—น, not just tweaking a setting. ๐Ÿ›ก๏ธ ๐—ช๐—ต๐—ฎ๐˜ ๐—œ ๐˜„๐—ผ๐˜‚๐—น๐—ฑ ๐—ฑ๐—ผ - If you are using SMTP AUTH to send emails to ๐—ถ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐—ฎ๐—น ๐—ฟ๐—ฒ๐—ฐ๐—ถ๐—ฝ๐—ถ๐—ฒ๐—ป๐˜๐˜€, you can use High Volume Email for Microsoft 365 - If sending to ๐—ถ๐—ป๐˜๐—ฒ๐—ฟ๐—ป๐—ฎ๐—น ๐—ฎ๐—ป๐—ฑ ๐—ฒ๐˜…๐˜๐—ฒ๐—ฟ๐—ป๐—ฎ๐—น ๐—ฟ๐—ฒ๐—ฐ๐—ถ๐—ฝ๐—ถ๐—ฒ๐—ป๐˜๐˜€, use Azure Communication Services Email. - If you have an ๐—˜๐˜…๐—ฐ๐—ต๐—ฎ๐—ป๐—ด๐—ฒ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ ๐—ถ๐—ป ๐—ต๐˜†๐—ฏ๐—ฟ๐—ถ๐—ฑ ๐—ฐ๐—ผ๐—ป๐—ณ๐—ถ๐—ด, you can use Basic auth against the Exchange Server - If you are done changing your systems, I would advise to disable the SMTP AUTH beforehand. โš™๏ธ ๐——๐—ถ๐˜€๐—ฎ๐—ฏ๐—น๐—ฒ ๐—ฆ๐— ๐—ง๐—ฃ ๐—”๐—จ๐—ง๐—› ๐—ถ๐—ป ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ผ๐—ฟ๐—ด 1. Sign in to the Exchange admin center. 2. Click Settings > Mail Flow. 3. Toggle the setting labeled "Turn off SMTP AUTH protocol for your organization". 4. Click Save. Even after SMTP AUTH is disabled tenant-wide, it can still be enabled for individual users. Make sure that you run a PowerShell script to retrieve all the mailboxes where SMTP AUTH is enabled and disable it. โš ๏ธ ๐—œ๐—บ๐—ฝ๐—ผ๐—ฟ๐˜๐—ฎ๐—ป๐˜ First, identify if itโ€™s still used via sign-in logs in Entra ID, then change your systems to use modern counterparts ๐—ป๐—ผ๐˜„, while you still have time to test and redesign them. ๐Ÿ’ฌ Do you know exactly which apps or devices in your tenant are still using SMTP AUTH? ๐˜ˆ๐˜ถ๐˜ต๐˜ฉ๐˜ฐ๐˜ณ ๐˜ฐ๐˜ง ๐˜ต๐˜ฉ๐˜ฆ ๐˜ฑ๐˜ฐ๐˜ด๐˜ต: @strnad10 #Microsoft365 #ExchangeOnline #SMTPAuth #SecureBits #HorizonSecured #CloudSecurity
2
28
145
14,585
stuart smiles retweeted
โ€ผ๏ธInsane: Meta's Director of AI Safety and Alignment gave OpenClaw bot full access to her computer and email. She couldn't stop it from deleting her entire inbox. She's supposed to guardrail Meta's AI and future AGI.
207
625
3,831
506,624
stuart smiles retweeted
16 Aug 2025
$5 Membership sale is live for the next 24 hours: account.shodan.io/billing/meโ€ฆ

125
631
1,565
502,014
stuart smiles retweeted
2/ My prediction for the UK's Age Verification? The failure to protect children will become obvious. But the systems that force grownups to provide their IDs before sharing political views will persist. Because too many bureaucrats and certain big corporations benefit.
1
6
16
3,043
stuart smiles retweeted
NOOOOOOOO
7
10
220
25,261
Hi @LoveIsland what is the remix of Beats international Dub be good to me called and where is it available on Spotify please @FatboySlim
58
stuart smiles retweeted
Introducing #BSidesLDN2025 the 'SOC and Awe' Edition... 13/12/25 at the Novotel London West. Dates for tickets and 'Calls' are available on: bsides.london/event-informatโ€ฆ If you wish to sponsor #BSideLDN2025 get in touch, spaces are very limited! More info: bsides.london/s/Bsides-Londoโ€ฆ
2
16
39
5,466
Kylie Tonight !!
38
reddit.com/r/LegalAdviceUK/sโ€ฆ reddit.com/r/LegalAdviceUK/sโ€ฆ Need to reset a timer every x days, boss sacked person, they don't know how to reset timer, person being charged with computer misuse? How would computer orientated solicitor be found? @james_christie
1
108
stuart smiles retweeted
15 Apr 2025
BREAKING. From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
116
713
1,878
643,774
stuart smiles retweeted
You've heard of @AB_Camping ... This is AI camping. o.0
1
2
5
510
stuart smiles retweeted
#PostOfficeScandal #PostOfficeInquiry #StateSponsoredCrime #HumanRightsViolations Please do watch the inimitable @FloraClairePage deliver her Heilbron Lecture entitled: "NO CHOICE BUT to TRUST - The Predicament of the Powerless". As we have all come to expect from her sublime questioning of Witnesses at the Inquiry, her Lecture is a triumph of humanity, compassion and intellect. Chapeau FLORA! x๐Ÿฅ‚ @SeemaMisra7 @CastletonLee @TjX50 @Janetsk20073533 @TracyF882 @lisa_castleton @PaulMar72224296 @gouldsblog @edwardhenry1 @23essexstreet @mountforduk @hodgejonesallen @PostOffInquiry @barstandards @thebarcouncil @TheLawSociety @lawsocgazette @ExeterLawSchool @UKHouseofLords @CommonsJustice @RtHonKevanJones @JohnHyde1982 @nickwallis @TimBushLondon @VarchasPatel @2BedfordRow @ReutersLegal @JoshuaRozenberg @5essexchambers
8
29
65
14,419