
Yehuda Smirnov
@yudasm_
Followers
747
Following
982
Media
12
Statuses
296
Security Researcher @Microsoft, opinions are my own.
Joined May 2022
RT @codewhitesec: We have reproduced "ToolShell", the unauthenticated exploit chain for CVE-2025-49706 + CVE-2025-49704 used by @_l0gg to p….
0
114
0
RT @delivr_to: It's here. The latest iteration of our Top 10 includes the most important developments in initial access tradecraft; from….
0
20
0
RT @watchtowrcyber: Happy Friday! We're ending the week by publishing our analysis of Fortinet's FortiWeb CVE-2025-25257. https://t.co/….
0
110
0
RT @SEKTOR7net: VEH² technique to bypass ETW-based detection. Hardware breakpoints abuse can be detected with Microsoft-Windows-Kernel-Aud….
0
47
0
RT @Bl4ckShad3: While researching in Azure with my partner @IdanLerman we found some cool misconfiguration in Azure role condition that ca….
0
5
0
RT @SEKTOR7net: Modern lateral movement techniques detection (mainly DCOM/DCE/RPC/RDP) with examples. Some assumptions worth mentioning: v….
0
62
0
RT @G3tSyst3m: Part 3 of the Buffer Overflows in Modern Era series has been posted! In this lengthy yet detailed walkthrough, we'll start….
0
52
0
RT @SEKTOR7net: Credentials access via Shadow Snapshots, WMI and SMB, all done remotely. Technique implemented inside impacket framework a….
0
85
0
RT @silentgh00st: #bugbountytip .Quick tip and script : ✅️. If you are hunting or scanning a WordPress instance, don't forget to look for e….
0
101
0
RT @SpecterOps: In the year since Misconfiguration Manager's release, the security community has been actively researching new tradecraft &….
0
33
0
RT @trickster012: This is my research project in creating read, write and allocate primitives that can be turned into an injection in order….
0
96
0
RT @Jonas_B_K: I publish two blog posts today! 📝🐫 . The first dives into how we're improving the way BloodHound models attack paths through….
0
69
0
RT @mrgretzky: If you're battling phishing detections through CSS canary tokens, make sure to add these entries into your Evilginx MS365 ph….
0
55
0
RT @SEKTOR7net: Swimming deep inside Windows Security Center service to re-engineer API access allowing to disable Windows Defender. COM i….
0
32
0
RT @SpecterOps: Get the scoop on the incoming Administrator Protection for Windows 11. @_xpn_ covers the architecture, access controls, an….
0
39
0