Freelance Cybersecurity Specialists in United States
Freelance Cybersecurity Specialists in United States
Sign Up
Post a job
Sign Up
Log In
Filters
2
Projects
People
Watheq Zboun
max
United States
Microsoft 365 & Azure Solutions Architect
$5k+
Earned
2x
Hired
5.0
Rating
14
Followers
Follow
Message
Microsoft 365 & Azure Solutions Architect
1
Have you wondered how hacekrs bypass MFA? Nowadays it is getting easier. There is a phishing kit called Mirage2FA that has been working against Microsoft 365 since late 2024. Here is how it goes. The user lands on a fake login page. They type their password. They approve the MFA prompt on their phone. Everything they enter is passed straight through to Microsoft in real time, so the sign-in genuinely succeeds and looks completely normal to them. Microsoft issues the session tokens, and the kit keeps a copy. With those cookies someone can read the mailbox, open SharePoint and OneDrive, and reach anything sitting behind SSO. They never see a second prompt, because the authentication already happened. ANY.RUN (http://ANY.RUN) put numbers on it. 9,426 accounts targeted across 3,518 domains, roughly 4,532 showing signs of compromise, most of them in the US. A third of the successful logins happened on phones, where you can barely see the URL you are looking at. The advice going around is to switch on Continuous Access Evaluation. I would switch it on too. Just read the documentation first, because it does something slightly different to what people assume. CAE sessions run tokens for up to 28 hours. The default is one hour. What you get in exchange is revocation when something happens, and Microsoft is specific about what counts: the account is disabled or deleted, the password is changed or reset, MFA gets turned on, an admin revokes refresh tokens, or ID Protection flags the user as high risk. Allow up to 15 minutes for that to propagate. IP location is the only one that applies straight away. Three things worth knowing before you lean on it. It covers Exchange Online, SharePoint Online and Teams. Guest accounts are not supported, which is where a lot of contractor access lives. And it only reads IP-based named locations, so a country-based policy buys you nothing here. If I were fixing this in a tenant tomorrow, in this order: Phishing-resistant sign-in first. A FIDO2 key checks the domain it is talking to, so it will not hand anything over to a proxy wearing Microsoft's face. CAE on, so revocation actually reaches the services. Then a runbook where you revoke sessions before you reset the password. Reset first and you have changed the lock while someone is still inside holding a key that works. If session cookies walked out of your tenant this morning, what would notice, and how long would it take? Source: ANY.RUN (http://ANY.RUN) threat research, 19 August 2026. CAE behaviour from Microsoft Learn.
1
1
66
0
Did you know that cybercrime is projected to cost the world $10.5 TRILLION a year. What is the average data breach in the US? $10.22 million which is at a record high. Here is my question to people here, if you could only strengthen 3 out of these 12 cybersecurity pillars, which would you pick? Disaster Recovery Authentication Authorization Encryption Vulnerability Management Audit & Compliance Network Security Endpoint Security Incident Response Container Security API Security Third-Party Management I would argue Authentication, Incident Response, and Third-Party Management, because the data shows 53% of breaches start with stolen credentials, and vendor compromises are surging.
0
198
0
GoDaddy Move-Away That Uncovered a Data Residency Problem
0
7
0
Microsoft Security Architecture Diagrams
0
6
Cybersecurity Specialist
(2)
Follow
Message
Paul Abulu Jr
Washington, USA
Cybersecurity| Robotics, Machine Learning & AI
Follow
Message
Cybersecurity| Robotics, Machine Learning & AI
0
Robotics: Fundamentals, Safety, and Security
0
31
0
Computer Vision Basics: No Math, No Code
0
28
0
The Personal IoT Security Playbook: A Beginner’s Guide
0
32
0
Personal Data on Wheels: 5 Steps to Protect Your Data
0
16
Cybersecurity Specialist
(4)
Follow
Message
Kenneth Lopez
San Diego, USA
Designing products in web3 & cybersecurity
Follow
Message
Designing products in web3 & cybersecurity
0
Browser Extension
0
29
0
Enterprise-Ready UX for Security at Scale
0
19
0
Designing the Vision for MindFort's YC Success
0
6
1
Web3 Product Design for StreamEx
1
26
Cybersecurity Specialist
(2)
Follow
Message
Steve Wachira
Worcester, USA
5 years of experience as a Software Engineer for startups.
Follow
Message
5 years of experience as a Software Engineer for startups.
0
The Official VibeCheck Funnel Site
0
10
0
Just pushed a fresh update to VibeCheck 🚀 It now fully supports vibe-coded apps built with Lovable Cloud, including their newest project structure and deploy flow. If you’re building on Lovable, you can now run a full self-audit in seconds: secrets, prompts, risks, everything. More updates coming this week.
0
60
1
The self-audit tool for Vibe Coding.
1
7
0
LinkedIn Connection Tutorial for Trender.ai
0
7
Cybersecurity Specialist
(3)
Follow
Message
jesse callistus
United States
"Fortifying digital defenses strategically."
Follow
Message
"Fortifying digital defenses strategically."
0
Web Application Developer & Security
0
6
0
Vulnerability Assessment Services DEMO
0
14
0
Pentest Engagements
0
17
View more →
Cybersecurity Specialist
(3)
Follow
Message
Umayma Essa
Minneapolis, USA
Cybersecurity & GRC Technical Writer 📝
Follow
Message
Cybersecurity & GRC Technical Writer 📝
0
Empowering Small Businesses with Cybersecurity Intelligence
0
9
0
Security Risk Assessment and Remediation for ALPHA CARE SERVICES
0
9
0
Staff training manual on cybersecurity best practices for Alpha
0
15
0
Alpha Company Security Policy Guide
0
18
Cybersecurity Specialist
(4)
Follow
Message
Catherine E
California, USA
Versatile Writer Specializing in Tech and Security
Follow
Message
Versatile Writer Specializing in Tech and Security
0
Clorox Cyberattack Causes Widespread Disruption, Shortages
0
13
0
MOVEit Hack: Over 600 Organizations Impacted, Millions of People
0
12
0
EXAMPLE - SOP for Replacing a UPS in an IDF
0
29
View more →
Cybersecurity Specialist
(2)
Follow
Message
Crispine Poe
California, USA
Experienced IT Specialist, Writer, Cybersecurity
Follow
Message
Experienced IT Specialist, Writer, Cybersecurity
0
Cybersecurity Risk Assessment for a Financial Institution
0
9
0
My approach on securing a client company's systems
0
9
0
The Rise of Quantum Computing: Unlocking the Future
0
9
View more →
Cybersecurity Specialist
(3)
Follow
Message
Explore people