BlackBox (Security) Archiv – Telegram
BlackBox (Security) Archiv
4.16K subscribers
183 photos
393 videos
167 files
2.67K links
👉🏼 Latest viruses and malware threats
👉🏼 Latest patches, tips and tricks
👉🏼 Threats to security/privacy/democracy on the Internet

👉🏼 Find us on Matrix: https://matrix.to/#/!wNywwUkYshTVAFCAzw:matrix.org
Download Telegram
The Battle for Biometric Privacy

The pushback against ubiquitous surveillance and targeted deepfaking has begun—but regulation may fail to keep up with AI advances.


In 2024, increased adoption of biometric surveillance systems, such as the use of AI-powered facial recognition in public places and access to government services, will spur biometric identity theft and anti-surveillance innovations. Individuals aiming to steal biometric identities to commit fraud or gain access to unauthorized data will be bolstered by generative AI tools and the abundance of face and voice data posted online.

https://www.wired.com/story/the-battle-for-biometric-privacy/

#biometric #privacy #deepfake
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
👍5
You can not simply publicly access private secure links, can you?

turns out, you can even search for them with powerful search engines!


Popular malware/url analysis tools such as urlscan.io, Hybrid Analysis, and Cloudflare radar url scanner store a large number of links for intelligence gathering and sharing. However, it is not as widely known that these services also store a large amount of private and sensitive links, thanks to:

- Sensitive links accidentally submitted for scanning by users unaware that they are public information

- Misconfigured scanners and extensions that submit private links scanned from emails as public data

https://vin01.github.io/piptagole/security-tools/soar/urlscan/hybrid-analysis/data-leaks/urlscan.io/cloudflare-radar%22/2024/03/07/url-database-leaks-private-urls.html

#securelinks #security #tools #urlscan #analysis
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
👍53
Docker Security – Step-by-Step Hardening (Docker Hardening)

This article provides practical recommendations for configuring Docker platform aimed at increasing its security. It also suggests tools helpful in automation of some tasks related to securing Docker.


My intention is to guide the reader step by step through the process of preparing a secure configuration. As such, this guide may prove to be more extensive than other similar publications. However, this is a conscious choice. My goal is not merely to present a dry list of parameters and ready-made configuration snippets, but to provide the reader with a fuller context. I want the reader to understand why certain modifications are necessary and what benefits their implementation will bring.

https://reynardsec.com/en/docker-platform-security-step-by-step-hardening/

#docker #hardening #guide
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
👍4
Ransomware Diaries Volume 5: Unmasking LockBit

Before you read this volume of the Ransomware Diaries, please understand that LockBitSupp’s identity only became known earlier today. Therefore, please make your own assessment and validate my findings before using this research for real-world actions. I have been chasing LockBit for a long time and when I found out the DoJ planned to release this information, I decided to publish my research quicker than I intended.

https://analyst1.com/ransomware-diaries-volume-5-unmasking-lockbit/

#lockbit
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
1👍1
Dell admits to data breach: sensitive user data in peril

The American technology giant has notified some of its customers about a data breach that involved sensitive data, including users’ physical addresses.

Dell Technologies says that it’s currently investigating an incident “involving a Dell portal,” which contains a database with customer information related to purchases.

https://cybernews.com/news/dell-data-breach/

#dell #breach
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
👍4😱1
Lethal Injection: How We Hacked Microsoft's Healthcare Chat Bot

We have discovered multiple security vulnerabilities in the Azure Health Bot service, a patient-facing chatbot that handles medical information. The vulnerabilities, if exploited, could allow access to sensitive infrastructure and confidential medical data.


All vulnerabilities have been fixed quickly following our report to Microsoft. Microsoft has not detected any sign of abuse of these vulnerabilities. We want to thank the people from Microsoft for their cooperation in remediating these issues: Dhawal, Kirupa, Gaurav, Madeline, and the engineering team behind the service.

The first vulnerability allowed access to authentication credentials belonging to the customers. With continued research, we’ve found vulnerabilities allowing us to take control of a backend server of the service. That server is shared across multiple customers and has access to several databases that contain information belonging to multiple tenants.

https://www.breachproof.net/blog/lethal-injection-how-we-hacked-microsoft-ai-chat-bot

#microsoft #healthcare #ai #chatbot #hacked
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
👍1
Telegram has launched a pretty intense campaign to malign Signal as insecure, with assistance from Elon Musk. The goal seems to be to get activists to switch away from encrypted Signal to mostly-unencrypted Telegram. I want to talk about this a bit....

https://twitter.com/matthew_d_green/status/1789687898863792453

#signal #telegram #durov #elonmusk
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
👎8👍5😱1
ShodanX

ShodanX is a versatile information gathering tool that harnesses the power of Shodan's extensive database. it offers multiple modes and flexible queries to extract valuable insights for security assessments, reconnaissance, and threat intelligence. With colorful output and intuitive commands, ShodanX empowers users to efficiently gather and analyze data from Shodan's facets, enhancing their cybersecurity efforts.

https://github.com/RevoltSecurities/ShodanX/tree/main

#shodan #shodanx #pentesting #cybersecurity #infosec
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
👍3
A Threat Actor Claims Sale of Outlook RCE Exploit 0-Day for $1,700,000

In a concerning development, a threat actor known as “Cvsp” has announced the sale of an alleged Outlook Remote Code Execution (RCE) exploit 0-day. This alleged exploit, designed to target various versions of Microsoft Office across both x86 and x64 architectures, poses a significant security threat to users worldwide.

https://dailydarkweb.net/a-threat-actor-claims-sale-of-outlook-rce-exploit-0-day-for-1700000/

#outlook #zeroday #exploit
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
👍31
Foxit PDF “Flawed Design” Exploitation

Check Point Research has identified an unusual pattern of behavior involving PDF exploitation, mainly targeting users of Foxit Reader. This exploit triggers security warnings that could deceive unsuspecting users into executing harmful commands. Check Point Research has observed variants of this exploit being actively utilized in the wild. Its low detection rate is attributed to the prevalent use of Adobe Reader in most sandboxes or antivirus solutions, as Adobe Reader is not susceptible to this specific exploit. Additionally, Check Point Research has observed various exploit builders, ranging from those coded in .NET to those written in Python, being used to deploy this exploit.

https://research.checkpoint.com/2024/foxit-pdf-flawed-design-exploitation/

#exploit #foxit #pdf
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
👍2
CensysGPT Beta

CensysGPT beta simplifies building queries and empowers users to conduct efficient and effective reconnaissance operations. The tool enables users to quickly and easily gain insights into hosts on the internet, streamlining the process and allowing for more proactive threat hunting and exposure management.

https://gpt.censys.io/

#cybersecurity #infosec #ai #censys #gpt
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
👍3
no-defender

A slightly more fun way to disable windows defender.


There's a WSC (Windows Security Center) service in Windows which is used by antiviruses to let Windows know that there's some other antivirus in the hood and it should disable Windows Defender.

This WSC API is undocumented and furthermore requires people to sign an NDA with Microsoft to get its documentation, so I decided to take an interesting approach for such a thing and used an already existing antivirus called Avast. This AV engine includes a so-called wsc_proxy.exe service, which essentially sets up the WSC API for Avast.

With a little bit of reverse engineering, I turned this service into a service that could add my own stuff there.

https://github.com/es3n1n/no-defender

#reverseengineering #windows #defender #microsoft
📡@cRyPtHoN_INFOSEC_IT
📡
@cRyPtHoN_INFOSEC_FR
📡
@cRyPtHoN_INFOSEC_EN
📡
@cRyPtHoN_INFOSEC_DE
📡
@BlackBox_Archiv
🔥7👍51