Russian Malware Targeting Ukrainian Energy Sector
https://ift.tt/eaZxV75
Submitted April 13, 2022 at 02:01AM by entropydaemon5
via reddit https://ift.tt/rZkGi1y
https://ift.tt/eaZxV75
Submitted April 13, 2022 at 02:01AM by entropydaemon5
via reddit https://ift.tt/rZkGi1y
Medium
Industroyer2: The Worst Sequel
Background:
A real PoC for CVE-2022-21907 RCE DoS IIS
https://ift.tt/rdAX64u
Submitted April 13, 2022 at 10:41AM by yoursisterboy
via reddit https://ift.tt/WyaiEbJ
https://ift.tt/rdAX64u
Submitted April 13, 2022 at 10:41AM by yoursisterboy
via reddit https://ift.tt/WyaiEbJ
GitHub
GitHub - polakow/CVE-2022-21907: A REAL DoS exploit for CVE-2022-21907
A REAL DoS exploit for CVE-2022-21907. Contribute to polakow/CVE-2022-21907 development by creating an account on GitHub.
OpenSSH 9 released on 2022-04-08. By default it uses NTRU algorithm which is believed to resist attacks enabled by future quantum computers.
https://ift.tt/85xnWlS
Submitted April 13, 2022 at 01:28PM by mstromich
via reddit https://ift.tt/ejasx3d
https://ift.tt/85xnWlS
Submitted April 13, 2022 at 01:28PM by mstromich
via reddit https://ift.tt/ejasx3d
reddit
OpenSSH 9 released on 2022-04-08. By default it uses NTRU...
Posted in r/netsec by u/mstromich • 276 points and 34 comments
Around 50,000 GitHub credentials leaked as metadata inside commits
https://ift.tt/vljUn69
Submitted April 13, 2022 at 07:20PM by gid0rah
via reddit https://ift.tt/CX1f8iB
https://ift.tt/vljUn69
Submitted April 13, 2022 at 07:20PM by gid0rah
via reddit https://ift.tt/CX1f8iB
Notgitbleed
NotGitBleed - TL;DR
Research into potential credential leaks within github metadata
TallGrass: An AV exclusion enumeration tool written in Python
https://ift.tt/gyM6RsE
Submitted April 13, 2022 at 07:53PM by UnwearableCactus
via reddit https://ift.tt/Ik9LNQf
https://ift.tt/gyM6RsE
Submitted April 13, 2022 at 07:53PM by UnwearableCactus
via reddit https://ift.tt/Ik9LNQf
GitHub
GitHub - tid4l/TallGrass: An AV exclusion enumeration tool written in Python.
An AV exclusion enumeration tool written in Python. - GitHub - tid4l/TallGrass: An AV exclusion enumeration tool written in Python.
Citrix SDWAN Hard-Coded Credentials
https://ift.tt/MNDUopP
Submitted April 13, 2022 at 10:32PM by k1dney
via reddit https://ift.tt/xtuamD7
https://ift.tt/MNDUopP
Submitted April 13, 2022 at 10:32PM by k1dney
via reddit https://ift.tt/xtuamD7
CIS
Multiple Vulnerabilities in Citrix SD-WAN Contains Hard-Coded Credentials
<p>Multiple vulnerabilities have been discovered in Citrix SD-WAN. Citrix SD-WAN is a software defined Wide Area Network (WAN) which can allow for easier management of multiple networks. The most severe of these vulnerabilities contains hard-coded credentials.…
Microsoft Exposes Evasive Chinese Tarrask Malware Attacking Windows Computers. The Chinese-backed Hafnium hacking group has been linked to a piece of a new malware that's used to maintain persistence on compromised Windows environments.
https://ift.tt/nfBe6Ta
Submitted April 14, 2022 at 07:54AM by Late_Ice_9288
via reddit https://ift.tt/cX7sod2
https://ift.tt/nfBe6Ta
Submitted April 14, 2022 at 07:54AM by Late_Ice_9288
via reddit https://ift.tt/cX7sod2
Microsoft Security Blog
Tarrask malware uses scheduled tasks for defense evasion - Microsoft Security Blog
Microsoft Detection and Response Team (DART) researchers have uncovered malware that creates “hidden” scheduled tasks as a defense evasion technique. In this post, we will demonstrate how threat actors create scheduled tasks, how they cover their tracks,…
Extracting the hashed uninstall password for Cortex XDR being low privileged user
https://ift.tt/2b61ioy
Submitted April 14, 2022 at 12:43PM by gid0rah
via reddit https://ift.tt/DH2WS9q
https://ift.tt/2b61ioy
Submitted April 14, 2022 at 12:43PM by gid0rah
via reddit https://ift.tt/DH2WS9q
Mrd0X
Security Research | mr.d0x
Providing security research and red team techniques
Akamai Blog | Critical Remote Code Execution Vulnerabilities in Windows RPC Runtime
https://ift.tt/CZEJSg3
Submitted April 14, 2022 at 02:54PM by gquere
via reddit https://ift.tt/Ub7G4MA
https://ift.tt/CZEJSg3
Submitted April 14, 2022 at 02:54PM by gquere
via reddit https://ift.tt/Ub7G4MA
Akamai
Akamai Blog | Critical Remote Code Execution Vulnerabilities in Windows RPC Runtime
Microsoft’s April 2022 Patch Tuesday introduced patches to more than a hundred new vulnerabilities in various components. Three critical vulnerabilities were found and patched in Windows RPC (Remote Procedure Call) runtime:
CVE-2022-24492 and CVE-2022-24528…
CVE-2022-24492 and CVE-2022-24528…
[PYSA] Ransomware Group In-Depth Analysis
https://ift.tt/ZtM7Ho9
Submitted April 14, 2022 at 07:45PM by Egesploit
via reddit https://ift.tt/D5fFmK0
https://ift.tt/ZtM7Ho9
Submitted April 14, 2022 at 07:45PM by Egesploit
via reddit https://ift.tt/D5fFmK0
PRODAFT
PRODAFT – Cyber Threat Intelligence and Risk Intelligence
Explore advanced cybersecurity solutions, providing proactive defense against emerging threats. Learn more about our tailored intelligence, and cybercrime investigation solutions.
VSTO enabled Office documents allow for remote .NET assembly remote code execution
https://ift.tt/Q02g8o1
Submitted April 14, 2022 at 07:26PM by DanielS-AL
via reddit https://ift.tt/ucHOpUz
https://ift.tt/Q02g8o1
Submitted April 14, 2022 at 07:26PM by DanielS-AL
via reddit https://ift.tt/ucHOpUz
Medium
Make phishing great again. VSTO office files are the new macro nightmare?
Intro to the Office VSTO format, a capability that provides rich capabilities for attackers to phish users and gain code execution
CVE-2022-28345 - Signal client for iOS version 5.33.2 and below are vulnerable to RTLO Injection URI Spoofing using malicious URLs such as gepj.net/selif#/moc.elpmaxe which would appear as example.com/#files/ten.jpeg
https://ift.tt/m51oRxc
Submitted April 14, 2022 at 10:55PM by docker-osx
via reddit https://ift.tt/YHXl1O0
https://ift.tt/m51oRxc
Submitted April 14, 2022 at 10:55PM by docker-osx
via reddit https://ift.tt/YHXl1O0
Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips!
CVE-2022-28345 - Signal client for iOS version 5.33.2 and below are vulnerable to RTLO Injection URI Spoofing using malicious URLs…
Title CVE-2022-28345 – Signal client for iOS version 5.33.2 and below are vulnerable to RTLO Injection URI Spoofing using malicious URLs such as gepj.net/selif#/moc.elpmaxe which would appear as example.com/#files/ten.jpeg CVE ID CVE-2022-28345 CVSS Score…
Diving Deeper into WatchGuard Pre-Auth RCE - CVE-2022-26318
https://ift.tt/u6iT9Xq
Submitted April 15, 2022 at 03:26AM by Mempodipper
via reddit https://ift.tt/qnvwd5J
https://ift.tt/u6iT9Xq
Submitted April 15, 2022 at 03:26AM by Mempodipper
via reddit https://ift.tt/qnvwd5J
Assetnote
Diving Deeper into WatchGuard Pre-Auth RCE - CVE-2022-26318
Application security issues found by Assetnote
Cisco Security Advisory: Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability
https://ift.tt/Stu3RFU
Submitted April 15, 2022 at 05:28AM by ghost-train
via reddit https://ift.tt/sagheRP
https://ift.tt/Stu3RFU
Submitted April 15, 2022 at 05:28AM by ghost-train
via reddit https://ift.tt/sagheRP
Cisco
Cisco Security Advisory: Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability
A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to bypass authentication controls and log in to the device through the management interface
This vulnerability…
This vulnerability…
Blinding Snort: Breaking the Modbus OT Preprocessor
https://ift.tt/MbzWjnV
Submitted April 15, 2022 at 01:25AM by derp6996
via reddit https://ift.tt/F6U7mNy
https://ift.tt/MbzWjnV
Submitted April 15, 2022 at 01:25AM by derp6996
via reddit https://ift.tt/F6U7mNy
Claroty
Blinding Snort IDS/IPS: Breaking the Modbus OT Preprocessor
Team82 discovered a means by which it could blind the popular Snort intrusion detection and prevention system to malicious packets. Learn more with Claroty.
iViewed your API keys
https://ift.tt/PsOhi4p
Submitted April 15, 2022 at 06:28PM by Gallus
via reddit https://ift.tt/3MEgD8Q
https://ift.tt/PsOhi4p
Submitted April 15, 2022 at 06:28PM by Gallus
via reddit https://ift.tt/3MEgD8Q
Duale Siad
iViewed your API keys
Reporting on a security issue on ABC's iView.
Turncoat - Extract private messages from malware/phishing Telegram Bots
https://ift.tt/0KU8HEp
Submitted April 15, 2022 at 08:12PM by DoOrDieCalm
via reddit https://ift.tt/zjS96iW
https://ift.tt/0KU8HEp
Submitted April 15, 2022 at 08:12PM by DoOrDieCalm
via reddit https://ift.tt/zjS96iW
GitHub
GitHub - DODC/turncoat
Contribute to DODC/turncoat development by creating an account on GitHub.
New tool to exploit TURN servers - create a socks proxy into the internal network
https://ift.tt/ovtzBCd
Submitted April 15, 2022 at 11:04PM by FireFart
via reddit https://ift.tt/UbpgT40
https://ift.tt/ovtzBCd
Submitted April 15, 2022 at 11:04PM by FireFart
via reddit https://ift.tt/UbpgT40
GitHub
GitHub - firefart/stunner: Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers.
Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers. - GitHub - firefart/stunner: Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers.
Multiple Vulnerabilities in Cisco Expressway
https://ift.tt/AoNs6Le
Submitted April 15, 2022 at 11:01PM by FireFart
via reddit https://ift.tt/RIW9Bgu
https://ift.tt/AoNs6Le
Submitted April 15, 2022 at 11:01PM by FireFart
via reddit https://ift.tt/RIW9Bgu
firefart
Multiple Vulnerabilities in Cisco Expressway
Some time ago I stumbled across a [HackerOne report](https://hackerone.com/reports/333419) about abusing Slacks TURN server for proxy functionality inside their internal network. I found this interesting and decided to take a look at our videoconferencing…
PYSA Ransomware Group Technical Analysis
https://ift.tt/w5taY2P
Submitted April 16, 2022 at 02:33AM by wtfse
via reddit https://ift.tt/MUw74us
https://ift.tt/w5taY2P
Submitted April 16, 2022 at 02:33AM by wtfse
via reddit https://ift.tt/MUw74us
[Techmonitor.ai] Failed cyberattack on Ukraine's electricity grid could indicate Russia's growing willingness to attack critical infrastructure
https://ift.tt/8Ob1Uij
Submitted April 16, 2022 at 02:25AM by NoStarchPress
via reddit https://ift.tt/r6adhtM
https://ift.tt/8Ob1Uij
Submitted April 16, 2022 at 02:25AM by NoStarchPress
via reddit https://ift.tt/r6adhtM
Tech Monitor
Ukraine electricity grid cyberattack: More destructive attacks may follow
A failed cyberattack on Ukraine's electricity grid could indicate Russia's growing willingness to attack critical infrastructure.