NetSPI

@netspi.bsky.social

New research from NetSPI from @kfosaaen.bsky.social & Thomas Elling reveals how Azure tenant IDs leaked through Entra ID authentication maps cloud resources to their owners. Check out the new ATEAM tool for automated discovery. Full technical breakdown: ow.ly/UOcu50WFzto

ATEAM - Azure Resource Attribution via Tenant ID Enumeration

At DEF CON 33, NetSPI presented a talk about how Azure resources supporting Entra ID authentication expose tenant IDs, enabling attackers to attribute cloud resources to specific organizations at scal...

ow.ly

New Vuln Research: NetSPI Principal Consultant Ceri Coburn exposes how Forescout SecureConnector agents can be hijacked via a named pipe vulnerability (CVE-2025-4660), turning endpoint security tools into attacker-controlled C2 channels. Read more: ow.ly/6hl250WqWrX

Bild

Microsoft Defender for Identity vulnerability (CVE-2025-26685) allows unauthenticated attackers to capture Net-NTLM hashes and potentially gain AD access. Security tools can become attack vectors - understanding this risk is crucial: ow.ly/UOc050W8inY

Bild

NetSPI's Sam Beaumont and Larry Trowell developed RayV Lite—a low-cost laser fault injection tool that makes advanced hardware security testing accessible beyond nation-states using open-source hardware & inexpensive IR-leaking lasers. ➡️ Read the full technical deep-dive: ow.ly/Nqtm50W4fjT

Bild

CVE-2025-27590: Oxidized Web v0.14 vulnerability allows attackers to overwrite local files via /migration page, enabling remote code execution. Read the article written by NetSPI's Jamie Riden & Jon O'Reilly to highlight the discovery, findings, & remediation of the vulnerability. ow.ly/HLwr50VxKJt

CVE-2025-27590 – Oxidized Web: Local File Overwrite to Remote Code Execution

Learn about a critical security vulnerability (CVE-2025-27590) in Oxidized Web v0.14 that allows attackers to overwrite local files and execute remote code execution.

ow.ly

The overall attack surface of Salesforce is often overlooked, and the result could be disastrous for your organization. ow.ly/CYZ350VrvEz NetSPI's Weylon Solis wrote an article that explores authorization issues and common bad practices to avoid. Learn more! #salesforce #proactivesecurity

A Not So Comprehensive Guide to Securing Your Salesforce Organization

Explore key background knowledge on authorization issues and common bad practices developers may unintentionally introduce in Salesforce Orgs.

ow.ly

Help us define the future of Trustworthy AI by contributing to our expanding benchmarks, from fairness to ethical alignment and beyond. Your insights could drive the next breakthroughs in balancing security and usability. ow.ly/S81y50Ux3nr

Bild

Balancing usability and security in deployments introduce new and unfamiliar risks to organizations. NetSPI created an open Large Language Model (LLM) framework to help clarify some ambiguity around LLM security. Read more about this framework in our most recent article: ow.ly/Nhjs50Usaio

Balancing Security and Usability of Large Language Models: An LLM Benchmarking Framework

Explore the integration of Large Language Models (LLMs) in critical systems and the balance between security and usability with a new LLM benchmarking framework.

netspi.com