Navigating the Shift: Keeping Your ConfigMgr Environment Healthy During the Move to Modern Management

For decades, Microsoft Configuration Manager (ConfigMgr, formerly SMS) has been the trusted solution for managing Windows servers and clients in organizations worldwide. At baseVISION, our team brings decades of hands-on experience in designing, implementing, and maintaining ConfigMgr infrastructures for organizations of all sizes. We are ready to support customers for Read more…

baseVISION TI – Game Over: Build Trust, Deploy Malware

In our latest Threat Intelligence report, baseVISION investigates a malware campaign that spreads through malicious game mods to compromise gamers and potentially corporate environments. The campaign leverages social engineering and the Stealit credential stealer to harvest sensitive data, showing how attackers exploit trusted communities and human behavior rather than technical Read more…

baseVISION TI – Hijacking Microsoft company accounts via TikTok open redirection abuse is still a thing

In our latest TI report, baseVISION uncovers a phishing campaign that abuses TikTok’s open redirect feature to hijack Microsoft credentials. The attackers use multi-stage redirect chains, IP-based cloaking, and Adversary-in-the-Middle (AiTM) phishing pages to bypass MFA and steal session tokens. We break down the full attack chain, indicators of compromise, Read more…

baseVISION TI – Click, Paste and Compromise: When User’s Trust Becomes Your Greatest Vulnerability

In a world where cyber threats evolve faster than ever, one thing remains constant: attackers are still betting on human error. Our latest report, “Click, Paste and Compromise: When User Trust Becomes Your Greatest Vulnerability,” dives deep into the rise of ClickFix—a social engineering technique that tricks users into executing malicious commands through Read more…

Microsoft has awarded us the Advanced Specialization for Information Protection and Governance

baseVISION reaches a new milestone in Microsoft Security This specialization not only confirms our deep expertise, but also our proven project experience with Microsoft Purview and related solutions. It marks another important milestone for us – as we now hold all four available Microsoft Security Advanced Specializations. What is this Read more…

baseVISION has been named a Microsoft Entra Suite Integration Partner! 

For the past three years, baseVISION has successfully delivered engagements and solutions using the capabilities of the Microsoft Entra Suite. Since 2022 we were expanding our consulting and engineering services with Microsoft’s growing product portfolio and gained important hands-on knowledge in the areas of identity governance and administration (IGA), Security Read more…

baseVISION TI – Patch, Exploit, Repeat: A Never-Ending Cycle for Windows Common Log File System Driver Vulnerabilities

Since 2024, multiple zero-day vulnerabilities in the Windows Common Log File System (CLFS) driver have been exploited by ransomware groups like RansomEXX and Play (Balloonfly). These Elevation of Privilege (EoP) flaws enabled SYSTEM-level access and were used in real-world attacks before patches were released. Microsoft issued fixes across several Patch Read more…

Welcome Keith

We’re excited to welcome Keith Potter to the baseVISION team!As a Senior Security Consultant, he brings deep expertise and fresh perspective to our security services. We’re looking forward to a great collaboration – welcome aboard, Keith! New job? We are always looking for new, motivated people to join our team. Read more…