Topic

Active Directory

🇷🇺Jul 21

Advanced Windows Auditing Configuration Guide for Effective Incident Response in SOC Environments

The article provides a detailed walkthrough on configuring advanced audit policies in Windows 10 and Windows 11 to generate meaningful security events for incident investigation. It explains the role of the LSASS service in logging activities to the Security event log and contrasts basic auditing with the more granular advanced auditing that offers 53 subcategories. The guide covers enabling key subcategories such as Logon, Process Creation, and Account Management using auditpol commands, along with registry tweaks for PowerShell Script Block Logging and command-line auditing in process creation events. Practical tests demonstrate real-world events including successful and failed logons (Event IDs 4624 and 4625), process creation with arguments (Event ID 4688), and user account creation (Event IDs 4720 and 4732). All steps are performed on a VMware Workstation virtual machine running Windows 10 Pro 22H2 to avoid impacting production systems.

Habr•Policy & Regulation
🇵🇹Jul 18

Cybercriminals Actively Exploiting Critical Zero-Day Vulnerabilities in SonicWall SMA1000 Appliances

Cybercriminals are actively exploiting a critical zero-day vulnerability in SonicWall SMA1000 appliances used for corporate remote access. The attack chain combines two flaws that together enable unauthenticated access to internal services and local privilege escalation, ultimately allowing remote code execution with maximum privileges on affected devices. The most severe issue, CVE-2026-15409, carries a maximum CVSS score of 10.0 and permits attackers to reach internal appliance services without authentication, while CVE-2026-15410 facilitates local privilege escalation. Impacted models include the SMA1000 Series 6210, 7210, and 8200v running firmware versions 12.4.3-03434 and 12.5.0-02800. SonicWall has confirmed that its SSL VPN firewalls and the SMA 100 product line remain unaffected. Compromised appliances have already been observed serving as stealthy entry points into corporate networks, where attackers harvested credentials, session data, and multi-factor authentication seeds before pivoting into Active Directory environments. Administrators are urged to apply the emergency patches that upgrade devices to firmware versions 12.4.3-03453, 12.5.0-02835, or later.

BoletimSec•Vulnerabilities & Exploits
🇷🇺Jul 16

Solar inRights 3.11 Automatically Blocks Corporate Accounts Whose Passwords Appear in Dark Web Leaks

GC Solar has released Solar inRights 3.11, a major update to its identity and access management platform that integrates directly with the Solar AURA threat monitoring service. The new version automatically detects corporate credentials exposed in open sources and dark web dumps, validates whether the same login-password pairs remain active inside the organization, and instantly revokes access while alerting the security team. The feature addresses the common scenario in which employees reuse work email addresses and passwords on third-party websites, allowing attackers to test stolen credentials against corporate systems in what appears to be legitimate login attempts. Research cited by Solar shows that a single large Russian company typically has more than 600 unique corporate accounts circulating in public and underground sources, although only about 4 percent directly indicate infrastructure compromise. Yandex Cloud data further reveals that valid account abuse featured in 54 percent of over 25,000 attacks on cloud and hybrid environments during the first half of 2025. In addition to the leak-response capability, version 3.11 introduces improved search, request filtering, and integration templates for Active Directory, Exchange, and 1C.

AntiMalware•Data Breaches & Leaks
🇷🇺Jul 15

Microsoft Patches Record 570 Windows Vulnerabilities in July Update, Including Three Actively Exploited Zero-Days

Microsoft released its largest Patch Tuesday update to date, addressing 570 vulnerabilities across Windows and related products. Among them are three zero-day flaws, two of which have already been exploited in real-world attacks. Fifty-nine issues were rated critical, with 48 enabling remote code execution. The company credited its use of AI for discovering more vulnerabilities in the Windows codebase. The update covers a wide range of components including .NET, Active Directory services, Microsoft Office, Azure services, and Microsoft Defender. Administrators are urged to apply the patches promptly to mitigate risks from privilege escalation, remote code execution, and information disclosure flaws.

AntiMalware•Vulnerabilities & Exploits