CyberSecurity.PH #042
Multiple APT groups using Windows shortcut exploit; Chain of compromised GitHub Actions; MS365 accounts targeted via OAuth; Apache Tomcat remote code execution; Velociraptor triage collector for Windows; Threat hunting for suspect M365 OAuth Apps