The Cyber Threat Perspective

SecurIT360

Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. We’re bringing you fresh content from our journeys into penetration testing, threat research and various other interesting topics.brad@securit360.com

  1. 3d ago

    Your Employee Got Hacked. Now What? | Ep 198

    Users will get compromised. Someone will click the link, and credentials will get stolen. The question that really matters is what happens next. In this episode, Spencer and Brad walk through the Post-Compromise Risk Framework (PRID), a simple, repeatable way for IT and security teams to judge how exposed their environment is once an attacker gets in. Using a real-world-style ClickFix scenario involving "Susie in accounting," they trace how one compromised account can lead to lateral movement, credential dumping and sensitive data exposure. They also cover why so many of those steps go undetected. In this episode: Why the assume breach mindset is the best way to measure your securityPrivileges: what can a compromised user actually do?Reach: where can they go with that access?Impact: how bad would it be?Detection: would you even know it happened?How least privilege and network segmentation map to each stepWhy PS Remoting to a domain controller goes undetected nine times out of 10Why "that couldn't happen here" is not proof, and how to verify your controls"Inspect what you expect": testing your EDR instead of trusting itPick a user, assume they're compromised, and walk the path. You'll learn more about your environment, and you'll likely find issues you didn't know were there. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  2. Sep 25

    The Basics Still Win: What GreyNoise's PaperCut Report Shows | Ep 197

    One threat actor compromised at least 440 PaperCut instances across 395 organizations in 48 countries, using AI to run the same playbook at scale. The fastest path to domain admin took five minutes. But out of hundreds of organizations hit, the attacker only got domain admin at 12 of them. Spencer and Tyler use GreyNoise's recent PaperCut report to make the case that the basics matter more now than they ever have. The attack itself was not novel. It used a known vulnerability, a lab environment built to test exploits, an internet scanning service, and familiar offensive tools. AI (Codex and DeepSeek) is what took it from one target to hundreds. In this episode: How the attacker built a PaperCut and Active Directory lab to test exploits before going wideWhy five minutes to domain admin is fast but not unheard of, and how certificate abuse makes it possibleThe Conti playbook comparison, and how LLMs are turning attack playbooks into automated campaignsThe toolkit: Certify, Rubeus, SpoolSample, Impacket, NetExec, BloodHound, Mimikatz, and AMSI bypassesWhy letting hosts reach GitHub directly is a red flag, and how DNS and category filtering slow attackers downThe one case where Cloudflare's WAF stopped the attackWhy the 12 domain admin compromises are a hopeful sign that hardening worksWhere to start with AD hardening: tier zero permissions, dangerous rights on broad groups, service accounts, and certificate templatesMoving past EDR alone with application control, NDR, and identity-based detectionsComparing what a security tool costs to what a compromise costsSpencer and Tyler are penetration testers at SecurIT360. If you get something out of the show, subscribe and leave a rating or review. It helps more than you would think. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  3. Sep 18

    One Hacker, 42 Targets: Inside Anthropic's AI Threat Report | Ep 196

    One French-speaking hacktivist targeted 42 organizations and got internal access to 14 of them, working alone. That is the kind of detail Anthropic's September 2026 threat intelligence report put on the record, with data spanning December 2025 through August 2026. Spencer and Tyler walk through all six generative threat groups named in it and what actually changes for defenders. Their read: the attacks themselves are familiar. Stolen credentials, unpatched edge devices, exposed services, phishing, SQL injection. What AI changed is speed, automation, and scale, and that is enough to matter. In this episode: The skill floor for hacking has dropped, and solo operators are now running campaigns that used to take a teamThreat actors vibe coding phishing kits, credential dashboards, and custom toolingAutomated vulnerability discovery and exploit development, including one workflow that produced more than a dozen potential zero-day findings in a monthWhy older models with looser guardrails are showing up in operations while frontier models refuse the same requestsCustom harnesses and multi-agent pen testing frameworks that chain traditional offensive tools under an LLMStolen AI credentials and API keys as a high-priority target, plus resellers advertising discounted access to frontier modelsOn-the-fly obfuscation and retooling that breaks signature-based detectionWhy baselining, behavioral detection, application control, and external attack surface hygiene matter more than they did a year agoGroups covered: GTG-2006, GTG-50014, GTG-10007, GTG-50020, GTG-50021, and GTG-50029. Spencer and Tyler are penetration testers at SecurIT360.  If you get something out of the show, subscribe and leave a rating or review. It helps more than you would think. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  4. Sep 4

    Every IT Team Has a Joe | Ep 195

    Interested in a pen test? Visit securit360.com. Every organization has a Joe. He is the long tenured engineer or admin who built half the environment, maintains the other half, and keeps most of it in his head. Everybody depends on him and nobody wants to challenge him. Spencer and Tyler break down key man risk in IT, drawing on hundreds of internal pen tests across law firms, banks, credit unions, manufacturing, municipalities, and SaaS organizations. In this episode: Why tribal knowledge is a security risk, not just an operations problemHow word of mouth process handoffs turn into a game of telephoneThe reason remediations stall for an extra 30 daysShadow IT that originates inside the IT teamPrivilege creep and the single account that owns the environmentWhen Joe's resistance to change is the correct callCross training that does not add more work to Joe's plateIncentives, clear ownership, and update deadlines that actually stickSeparating fact gathering from decision making so seniority does not win by defaultThis is not a knock on senior admins. It is a look at the risk that accumulates when one person carries everything, and what IT leaders can do about it. All of our content can be found at Offsec.blog. Interested in a pen test? Visit securit360.com. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  5. Aug 27

    Service Accounts: The Shortest Path to Domain Admin | Ep 194

    Service accounts are one of the easiest paths to domain admin on an internal pen test, and one of the most neglected accounts in Active Directory. In this episode, Spencer and Tyler break down why service accounts keep falling: Kerberoasting every service account (not just the privileged ones), cracking the hashes offline, and spraying what cracks across the environment. Tyler shares a recent engagement where a non-administrative service account shared its password with a domain admin. Same password, one "SVC_" prefix apart. That spray handed over the domain. He's also seen the built-in RID 500 administrator account used as a service account on three separate engagements this year. They also get into where these credentials actually live: web.config files on open file shares, plaintext password files (present on roughly 90% of their pen tests), and one .eml attachment with the credentials sitting inside a screenshot. Then the fix list, in the order they'd actually do it: - Inventory the accounts and document where each one is used, before you touch a password - Delete the service accounts that don't need to exist - Strip privileges and restrict interactive logon rights - Get a password vault or PAM solution, and make every password long and unique - Alert on service accounts logging on interactively - Move to group managed service accounts (gMSA) where you can - Enforce 20-25 character minimums in the meantime. They've cracked 20+ character passphrases with a gaming rig, a 180 GB wordlist, and mutation rules producing roughly four quadrillion permutations Plus the three cleanup mistakes that cause the most damage, including the story of a $70 billion enterprise where one undocumented password reset turned into a 10-hour troubleshooting call. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

  6. Aug 20

    Your IT Job Doubled. Nobody Told Your Boss. | Ep 193

    In July 2026, Microsoft alone released 622 CVEs. In the 2010s, the monthly average was about a dozen. Nobody handed IT teams more time, budget, or headcount to match, and that gap is what burnout is actually made of. Somewhere in the last five to ten years, "keeping the lights on" became "and also prevent cyberattacks." Spencer Alessi and Brad Causey talk through how security landed on IT's plate, why capable admins end up feeling like they're failing, and what to do about it when hiring a dedicated security person isn't on the table. The core of the episode is a four-question framework for prioritizing when you can't do everything: - Harm: what would cause the greatest damage to the business? - Likelihood: what is most likely to actually be attacked? - Improve: what can you realistically fix with the people and tools you have today? - Accept: what risk must leadership explicitly own because your team can't address it? Brad's addition: don't start from the scan report, start from the crown jewels. Client matters if you're a law firm, financial data if you're a bank. From there, draw lines outward to whatever touches them. And executives need to get comfortable accepting risk, because zero risk tolerance isn't a strategy, it's a phrase. We also get into the language that works with leadership. "You gave me four things and I have time for two" is adversarial and doesn't give anyone enough to decide with. "I recommend A and C, here's why, and here's when B and D land if nothing else gets added" is managing up. Same for new projects: price the work honestly, including cost, timeline, and tradeoffs, then hand the decision back to the people with full business context. We close with the four things IT teams need to succeed: authority, budget, team, and support, including a trusted outside partner for the specialized work you shouldn't be doing yourself. Planning your next penetration test? Book a call with us at https://securit360.com If you enjoyed this episode, please share it with your network. See you next week. Work with Us: https://securit360.com Blog: https://offsec.blog/ Youtube: https://www.youtube.com/@cyberthreatpov Twitter: https://x.com/cyberthreatpov Follow Spencer on social ⬇ Spencer's Links: https://spenceralessi.com

5
out of 5
16 Ratings

About

Step into the ever-evolving world of cybersecurity with the offensive security group from SecurIT360. We’re bringing you fresh content from our journeys into penetration testing, threat research and various other interesting topics.brad@securit360.com

You Might Also Like