[German]Every Windows system is vulnerable to a specific NTLM relay attack that could allow attackers to escalate privileges from user to domain admin. This vulnerability has a status of "not being fixed" and was the subject of the PetitPotam approach I addressed over the weekend. Now Antonio Cocomazzi has pointed out the vulnerability called RemotePotato0. This uses the Windows RPC protocol for privilege escalation.
Translate
Blogs
Links
Social networks
Awards
Sponsors
(Paypal-Donations)
U.S. manufacturer Kaseya was the victim of a supply chain attack, and as a result, systems belonging to about 1,500 customers were encrypted with ransomware. Kaseya said this week that it has a universal decryptor to decrypt customer files. Affected parties may contact sales, it said. Now there are reports that Sales is not responding, and if contact is made, Kaseya is requiring victims to sign a confidentiality agreement before the data is decrypted. I've added the info in the post 

