headburgh Profile Banner
Viktor Hedberg 🛡💻 Profile
Viktor Hedberg 🛡💻

@headburgh

Followers
1K
Following
4K
Media
148
Statuses
2K

I do security stuff @Truesec • MVP • Father • My tweets are my own • He/him

Sweden
Joined June 2016
Don't wanna be here? Send us removal request.
@headburgh
Viktor Hedberg 🛡💻
4 years
219 domain admins.
@cinnamon_msft
Kayla Cinnamon ☕
4 years
Write a scary story in 6 words or less.
2
3
26
@0x534c
Steven Lim
12 days
Azure Bastion CVE-2025-49752 👀 CVSS Score: 10/10 Affected: All Azure Bastion deployments prior to the security update released on November 20, 2025 https://t.co/MTpd2zaxeL
Tweet card summary image
zeropath.com
This post provides a brief summary of CVE-2025-49752, a critical authentication bypass vulnerability in Azure Bastion. It covers technical details, affected versions, and vendor security history...
2
60
169
@UK_Daniel_Card
mRr3b00t
23 days
Key things seen in ransomware incidents: 1) VPN does not require MFA 2) Standard User VPN access gives access to management interfaces 3) LDAP access leads to domain admin via: Passwords in description fields, kerberoasting and other common escalation points (but seriously the
22
67
383
@janbakker_
Jan Bakker
5 months
I'm just going to leave this here, as I keep seeing surprised faces when I tell people about Windows Hello multifactor unlock. Yes, you can enforce 2️⃣ factors to unlock your Windows machine! See for yourself. https://t.co/dQTMYHKkUe
Tweet card summary image
learn.microsoft.com
Learn how to configure Windows Hello for Business multi-factor unlock by extending Windows Hello with trusted signals.
11
35
213
@MVPAward
Microsoft MVP Communities
5 months
🎉 A warm welcome to all the new MVPs! 🎉 You’ve joined a global community of passionate experts, builders, and changemakers who go above and beyond to share knowledge, support others, and drive innovation. Whether you’re leading user groups, writing code, creating content, or
5
29
136
@headburgh
Viktor Hedberg 🛡💻
6 months
What's a red flag in IR 🚩? My colleague @mikael_nystrom takes you through some of the tools of the trade. Read more here: https://t.co/JS9rqnJDaO
Tweet card summary image
truesec.com
Learn from Mikael Nyström: After a cyber incident, restore and repair systems - don’t rebuild from scratch. It’s faster and less disruptive.
0
2
2
@mikael_nystrom
Mikael Nystrom
6 months
1
7
12
@UK_Daniel_Card
mRr3b00t
8 months
🤣
51
1K
19K
@vxunderground
vx-underground
9 months
@DOGE Good find. Those licenses cost on average $500,000,000/year. That saved the country potentially hundreds of billions of dollars. Now the government can put that money to good use such as reintroducing lead to paint to keep the photon radioactive waves out of our brains
30
73
3K
@appmanagevent
AppManagEvent
10 months
Enhance your AppManagEvent 2025 visit by attending an exclusive in-person IT-Pro training from top experts like @samilaiho @PaulaCqure @mikael_nystrom @headburgh or @TimothyMangan – before and/or after the event! 🎟️ Bonus: Your training session includes a ticket to the event.
0
3
4
@merill
Merill Fernando
10 months
⚡ Check out this new Microsoft Entra blog post 👇 Microsoft Entra PowerShell module now generally available https://t.co/VHNfraXmy2
1
18
45
@merill
Merill Fernando
1 year
That's him. He's the one forcing us to change our passwords every 90 days.
8
12
154
@janbakker_
Jan Bakker
1 year
Hey, Entra ID admins. Do you have Passkey (FIDO2) enabled, and does your setting look like this? Early next year, Passkey in Authenticator will be enabled automatically. If that's okay, sit back and relax while your users become phishing-resistant. If not, please act now!
3
20
134
@headburgh
Viktor Hedberg 🛡💻
1 year
Wheels up tomorrow morning, prepping for mine and @mikael_nystrom's Masterclass at @NICconf on Wednesday, and our respective sessions on Thursday. #Truesec #NICConf #PreventBreach #MinimizeImpact
0
1
5
@nicolonsky
Nicola Suter
1 year
Pop quiz, which requirement providers can enforce MFA within Entra ID? #Azure Portal with 'request' & 'App requires MFA' will be next I guess (: https://t.co/h7LjU5WFrz
0
8
19
@headburgh
Viktor Hedberg 🛡💻
1 year
Spent the last couple of days in Stockholm speaking at #Teamsdagen. Made new friends and met old ones as well. The event was a huge success, and kudos to the organizers for an awesome event!
0
0
0
@MsftSecIntel
Microsoft Threat Intelligence
1 year
The financially motivated cybercriminal group that Microsoft tracks as Storm-0501 has been observed exfiltrating data and deploying Embargo ransomware after moving laterally from on-premises to the cloud environment. https://t.co/U7uQseDxE8
3
124
290
@inversecos
inversecos
1 year
Understanding EVERY Token in Entra ID 🔎 Not all tokens are equal. There are many different types with different uses and benefits. In this blog, I break down each token and what they are used for and which tokens are the most "valuable" for an attacker to obtain. Full blog
17
228
727
@fabian_bader
Fabian Bader
1 year
Microsoft Defender for Identity Expands to Entra Connect Server This includes new detections, new security recommendations, and a new activity type in the IdentityDirectoryEvents. Don't forget to configure you MDI gmsa account. #MDI #EntraID #Security https://t.co/KCy9vE4J7k
Tweet card summary image
techcommunity.microsoft.com
We are excited to announce a new Microsoft Defender for Identity sensor for Entra Connect servers. This addition is a significant step in our ongoing...
2
38
141