Windows Security Updates for Hackers
https://ift.tt/30cT77a
Submitted November 17, 2021 at 12:32PM by 0xdea
via reddit https://ift.tt/30sRoec
https://ift.tt/30cT77a
Submitted November 17, 2021 at 12:32PM by 0xdea
via reddit https://ift.tt/30sRoec
bitsadm.in
Windows Security Updates for Hackers « Bitsadmin's blog - Mystery guest in your IT infrastructure
Frequently colleagues and clients get to my (virtual) desk and pose the following question to me: “I know which patches (KBs) are installed on a Windows syst...
Easily Identify Malicious Servers on the Internet with JARM.
https://ift.tt/38RZwXG
Submitted November 17, 2021 at 09:47PM by j_b_11
via reddit https://ift.tt/3FjPoUG
https://ift.tt/38RZwXG
Submitted November 17, 2021 at 09:47PM by j_b_11
via reddit https://ift.tt/3FjPoUG
Salesforce Engineering Blog
Easily Identify Malicious Servers on the Internet with JARM - Salesforce Engineering Blog
JARM is an active Transport Layer Security server fingerprinting tool that provides the ability to identify and group malicious servers.
CVE-2021-41349 Exchange XSS PoC
https://ift.tt/3wTB4PG
Submitted November 16, 2021 at 07:52PM by 0x0021h
via reddit https://ift.tt/3CCLZPj
https://ift.tt/3wTB4PG
Submitted November 16, 2021 at 07:52PM by 0x0021h
via reddit https://ift.tt/3CCLZPj
Cobalt Strike: Decrypting Obfuscated Traffic – Part 4
https://ift.tt/3HxJyRt
Submitted November 18, 2021 at 02:35AM by ksr_malware
via reddit https://ift.tt/3nshPde
https://ift.tt/3HxJyRt
Submitted November 18, 2021 at 02:35AM by ksr_malware
via reddit https://ift.tt/3nshPde
TPM sniffing
https://ift.tt/3oDfyep
Submitted November 18, 2021 at 08:49AM by Gallus
via reddit https://ift.tt/3ntcFNK
https://ift.tt/3oDfyep
Submitted November 18, 2021 at 08:49AM by Gallus
via reddit https://ift.tt/3ntcFNK
reddit
TPM sniffing
Posted in r/netsec by u/Gallus • 220 points and 32 comments
How to build a network scanning analysis platform — Part II
https://ift.tt/3DtuhP7
Submitted November 18, 2021 at 05:08PM by ntestoc3
via reddit https://ift.tt/3qOUSmr
https://ift.tt/3DtuhP7
Submitted November 18, 2021 at 05:08PM by ntestoc3
via reddit https://ift.tt/3qOUSmr
When You sysWhisper Loud Enough for AV to Hear You
https://ift.tt/3coR8zD
Submitted November 18, 2021 at 05:06PM by CaptMeelo
via reddit https://ift.tt/30vVVfY
https://ift.tt/3coR8zD
Submitted November 18, 2021 at 05:06PM by CaptMeelo
via reddit https://ift.tt/30vVVfY
Hack.Learn.Share
When You sysWhisper Loud Enough for AV to Hear You
Evading Windows Defender when SysWhisper got caught!
[Conti] Ransomware Group In-Depth Analysis
https://ift.tt/3cFHU2h
Submitted November 18, 2021 at 07:47PM by Egesploit
via reddit https://ift.tt/3wXBsg6
https://ift.tt/3cFHU2h
Submitted November 18, 2021 at 07:47PM by Egesploit
via reddit https://ift.tt/3wXBsg6
PRODAFT
PRODAFT – Cyber Threat Intelligence and Risk Intelligence
Explore advanced cybersecurity solutions, providing proactive defense against emerging threats. Learn more about our tailored intelligence, and cybercrime investigation solutions.
The Art of PerSwaysion: Investigation of a Long-Lived Phishing Kit
https://ift.tt/3238vnA
Submitted November 18, 2021 at 07:40PM by 0xDAV1D
via reddit https://ift.tt/32dFpCe
https://ift.tt/3238vnA
Submitted November 18, 2021 at 07:40PM by 0xDAV1D
via reddit https://ift.tt/32dFpCe
www.seclarity.io
Blog - The Art of PerSwaysion: Investigation of a Long-Lived Phishing Kit
Instant. Actionable. Insights.
Backdooring Rust crates for fun and profit
https://ift.tt/3DrHE2n
Submitted November 18, 2021 at 10:16PM by Gallus
via reddit https://ift.tt/328fXOl
https://ift.tt/3DrHE2n
Submitted November 18, 2021 at 10:16PM by Gallus
via reddit https://ift.tt/328fXOl
Sylvain Kerkour
Backdooring Rust crates for fun and profit
Supply chains attacks are all the rage these days, whether to deliver RATs, cryptocurrencies miners, or credential stealers. In Rust, packages are called crates and are (most of the time) hosted on a central repository: https://crates.io for better discoverability.…
Python Malware Imitates Signed PyPI Traffic in Novel Exfiltration Technique
https://ift.tt/3oFlkMK
Submitted November 18, 2021 at 11:43PM by SRMish3
via reddit https://ift.tt/3cmYYdb
https://ift.tt/3oFlkMK
Submitted November 18, 2021 at 11:43PM by SRMish3
via reddit https://ift.tt/3cmYYdb
JFrog
Python Malware Imitates Signed PyPI Traffic in Novel Exfiltration Technique
Software supply chain security threat: automated scanning of Python packages in the PyPI repository uncovered stealthy malware and more. Find out about our latest findings.
How we protect our most sensitive secrets from the most determined attackers
https://ift.tt/3qNqGYK
Submitted November 19, 2021 at 12:14AM by BasedSweet
via reddit https://ift.tt/3csOr06
https://ift.tt/3qNqGYK
Submitted November 19, 2021 at 12:14AM by BasedSweet
via reddit https://ift.tt/3csOr06
CVE-2021-37580 Apache ShenYu 2.3.0/2.4.0 authentication bypass
https://ift.tt/3kN1a1V
Submitted November 19, 2021 at 10:59AM by 0x0021h
via reddit https://ift.tt/3nxUzKw
https://ift.tt/3kN1a1V
Submitted November 19, 2021 at 10:59AM by 0x0021h
via reddit https://ift.tt/3nxUzKw
Prevent Secrets Leaks at Scale in Repositories
https://ift.tt/3kS54qi
Submitted November 19, 2021 at 07:43PM by epiblas279
via reddit https://ift.tt/3nvN6f1
https://ift.tt/3kS54qi
Submitted November 19, 2021 at 07:43PM by epiblas279
via reddit https://ift.tt/3nvN6f1
All Roads Lead to OpenVPN: Pwning Industrial Remote Access Client
https://ift.tt/3CsiUWA
Submitted November 19, 2021 at 09:21PM by n0llbyte
via reddit https://ift.tt/3DAteNE
https://ift.tt/3CsiUWA
Submitted November 19, 2021 at 09:21PM by n0llbyte
via reddit https://ift.tt/3DAteNE
New ransomware actor uses password-protected archives to bypass encryption protection
https://ift.tt/3Cnjl4o
Submitted November 19, 2021 at 09:10PM by ksr_malware
via reddit https://ift.tt/3qTCWqI
https://ift.tt/3Cnjl4o
Submitted November 19, 2021 at 09:10PM by ksr_malware
via reddit https://ift.tt/3qTCWqI
Sophos News
New ransomware actor uses password-protected archives to bypass encryption protection
Calling themselves “Memento team”, actors use Python-based ransomware that they reconfigured after setbacks.
Why it is time to get rid of passwords in our infrastructure
https://ift.tt/3x5MPm8
Submitted November 20, 2021 at 12:11AM by Valien
via reddit https://ift.tt/2Z5jDiT
https://ift.tt/3x5MPm8
Submitted November 20, 2021 at 12:11AM by Valien
via reddit https://ift.tt/2Z5jDiT
Goteleport
Why it is time to get rid of passwords in our infrastructure
Passwordless is a phrase generating a lot of buzz in the consumer space. But our infrastructure is full of passwords too and that needs to stop.
Building WireGate: A WireGuard front to detect compromised keys
https://ift.tt/3CwaL3j
Submitted November 20, 2021 at 02:27AM by thinkst
via reddit https://ift.tt/3xioH05
https://ift.tt/3CwaL3j
Submitted November 20, 2021 at 02:27AM by thinkst
via reddit https://ift.tt/3xioH05
Thinkst Thoughts
Building WireGate: A WireGuard front to detect compromised keys
Earlier this year we released our WireGuard Canarytoken. This allows you to add a “fake” wireguard VPN endpoint on your device in seconds. The idea is that if your device is compromised, a knowledg…
Hadoop Yarn RPC RCE
https://ift.tt/3CB2tXO
Submitted November 20, 2021 at 10:39AM by 0x0021h
via reddit https://ift.tt/3FxW2a5
https://ift.tt/3CB2tXO
Submitted November 20, 2021 at 10:39AM by 0x0021h
via reddit https://ift.tt/3FxW2a5
GitHub
expbox/Hadoop Yarn RPC RCE.md at main · 0x0021h/expbox
Vulnerability Exploitation Code Collection Repository - expbox/Hadoop Yarn RPC RCE.md at main · 0x0021h/expbox
GitHub - mrexodia/dumpulator: An easy-to-use library for emulating code in minidump files.
https://ift.tt/3p5fIf1
Submitted November 21, 2021 at 04:40AM by mrexodia
via reddit https://ift.tt/3oTa4wq
https://ift.tt/3p5fIf1
Submitted November 21, 2021 at 04:40AM by mrexodia
via reddit https://ift.tt/3oTa4wq
GitHub
GitHub - mrexodia/dumpulator: An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction…
An easy-to-use library for emulating memory dumps. Useful for malware analysis (config extraction, unpacking) and dynamic analysis in general (sandboxing). - mrexodia/dumpulator
CVE-2021-41277 MetaBase Arbitrary File Read
https://ift.tt/3CA2vzd
Submitted November 21, 2021 at 06:44AM by 0x0021h
via reddit https://ift.tt/3DJXp5a
https://ift.tt/3CA2vzd
Submitted November 21, 2021 at 06:44AM by 0x0021h
via reddit https://ift.tt/3DJXp5a