A security flaw, named PetiPotam, in the Windows can be exploited to coerce remote Windows servers, including Domain Controllers, to authenticate with a malicious destination, thereby allowing an adversary to stage an NTLM relay attack and completely take over a Windows domain.


Due to a large growth in business Altitude Unlimited Inc. has relocated.


Threat actors are deploying the Mespinoza/ PYSA ransomware by accessing a system via remote desktop to copy and execute the ransomware on other systems on the network. Before deploying the ransomware to other systems, the attacker runs PowerShell scripts on the other systems on the network to exfiltrate files of interest and to maximize the impact of the ransomware.