The many lives of BlackCat ransomware
https://ift.tt/KYthdFB
Submitted June 13, 2022 at 10:14PM by SCI_Rusher
via reddit https://ift.tt/RtMCBlS
https://ift.tt/KYthdFB
Submitted June 13, 2022 at 10:14PM by SCI_Rusher
via reddit https://ift.tt/RtMCBlS
Microsoft News
The many lives of BlackCat ransomware
The use of an unconventional programming language, multiple target devices and possible entry points, and affiliation with prolific threat activity groups have made the BlackCat ransomware a prevalent threat and a prime example of the growing ransomware-as…
Exposed Travis CI API Leaves All Free-Tier Users Open to Attack
https://ift.tt/jk2G7g1
Submitted June 14, 2022 at 02:30AM by mkatch
via reddit https://ift.tt/a3mLnjq
https://ift.tt/jk2G7g1
Submitted June 14, 2022 at 02:30AM by mkatch
via reddit https://ift.tt/a3mLnjq
Aquasec
Public Travis CI Logs (Still) Expose Users to Cyber Attacks
Team Nautilus found that many tokens of Travis CI users are exposed via an issue in its API which allows attackers to launch massive attacks in the cloud
OSCP monkeys vs stack buffer overflow
https://ift.tt/ENK69tT
Submitted June 14, 2022 at 10:33AM by Dreg_fr33project
via reddit https://ift.tt/aUGRNym
https://ift.tt/ENK69tT
Submitted June 14, 2022 at 10:33AM by Dreg_fr33project
via reddit https://ift.tt/aUGRNym
Medium
OSCP monkeys vs stack buffer overflow
Warning: this post is just for fun x-)
Quick Malware Analysis: Emotet Epoch 5 infection with spambot traffic pcap from 2022-04-04
https://ift.tt/upEZAVM
Submitted June 14, 2022 at 07:15PM by dougburks
via reddit https://ift.tt/6Kcn1tT
https://ift.tt/upEZAVM
Submitted June 14, 2022 at 07:15PM by dougburks
via reddit https://ift.tt/6Kcn1tT
blog.securityonion.net
Quick Malware Analysis: Emotet Epoch 5 infection with spambot traffic pcap from 2022-04-04
Thanks to Brad Duncan for sharing this pcap! https://www.malware-traffic-analysis.net/2022/04/04/index.html We did a quick analysis of this ...
Chaining vulnerabilities to criticality in Progress WhatsUp Gold
https://ift.tt/5pVK4Xg
Submitted June 14, 2022 at 08:29PM by Mempodipper
via reddit https://ift.tt/f0tzYPy
https://ift.tt/5pVK4Xg
Submitted June 14, 2022 at 08:29PM by Mempodipper
via reddit https://ift.tt/f0tzYPy
Assetnote
Chaining vulnerabilities to criticality in Progress WhatsUp Gold
Application security issues found by Assetnote
Credential Protection in Chromium-based Browsers
https://ift.tt/3XftKVk
Submitted June 14, 2022 at 08:17PM by jat0369
via reddit https://ift.tt/ge8VYyi
https://ift.tt/3XftKVk
Submitted June 14, 2022 at 08:17PM by jat0369
via reddit https://ift.tt/ge8VYyi
Cyberark
Go BLUE! A Protection Plan for Credentials in Chromium-based Browsers
In my previous blog post (here), I described a technique to extract sensitive data (passwords, cookies) directly from the memory of a Chromium-based browser’s [CBB] process. Google’s response to...
If you want to play with Dogwalk windows vulnerability
https://ift.tt/Ip1S8bG
Submitted June 14, 2022 at 07:52PM by cryptaureau
via reddit https://ift.tt/H8r59Lp
https://ift.tt/Ip1S8bG
Submitted June 14, 2022 at 07:52PM by cryptaureau
via reddit https://ift.tt/H8r59Lp
GitHub
GitHub - ariary/DogWalk-rce-poc: 🐾Dogwalk PoC (using diagcab file to obtain RCE on windows)
🐾Dogwalk PoC (using diagcab file to obtain RCE on windows) - GitHub - ariary/DogWalk-rce-poc: 🐾Dogwalk PoC (using diagcab file to obtain RCE on windows)
Zimbra Email - Stealing Clear-Text Credentials via Memcache injection
https://ift.tt/mXvlHfN
Submitted June 14, 2022 at 09:50PM by 0xdea
via reddit https://ift.tt/nbXemNT
https://ift.tt/mXvlHfN
Submitted June 14, 2022 at 09:50PM by 0xdea
via reddit https://ift.tt/nbXemNT
Sonarsource
Zimbra Email - Stealing Clear-Text Credentials via Memcache injection
We discovered flaws in Zimbra, an enterprise email solution, that allow attackers to steal credentials of users and gain access to their email accounts.
CVE-2022-25845 – Analyzing the Fastjson “Auto Type Bypass” RCE vulnerability
https://ift.tt/gST6anl
Submitted June 14, 2022 at 09:08PM by SRMish3
via reddit https://ift.tt/dbXscfy
https://ift.tt/gST6anl
Submitted June 14, 2022 at 09:08PM by SRMish3
via reddit https://ift.tt/dbXscfy
JFrog
CVE-2022-25845 - Fastjson RCE vulnerability analysis
CVE-2022-25845 has a high potential impact but conditions for attack are not trivial. Read technical analysis and mitigation guidance of the Fastjson RCE vulnerability
What if you don't secure SSH on EC2? - Analysis of the real threats
https://ift.tt/SaAZDuP
Submitted June 14, 2022 at 08:55PM by capitangolo
via reddit https://ift.tt/gaw4YPs
https://ift.tt/SaAZDuP
Submitted June 14, 2022 at 08:55PM by capitangolo
via reddit https://ift.tt/gaw4YPs
Sysdig
Securing SSH on EC2: What are the real threats?
Securing SSH is one of the main controls of CIS Benchmark, but what are the real threats to ssh exposure? Brute force, credential leaks, ...
Oblivious HTTP
https://ift.tt/nyEDsWp
Submitted June 14, 2022 at 11:24PM by nangaparbat
via reddit https://ift.tt/9HJTlte
https://ift.tt/nyEDsWp
Submitted June 14, 2022 at 11:24PM by nangaparbat
via reddit https://ift.tt/9HJTlte
www.ietf.org
Oblivious HTTP
This document describes a system for the forwarding of encrypted HTTP messages.
This allows a client to make multiple requests of a server without the server being able
to link those requests to the client or to identify the requests as having come
from the…
This allows a client to make multiple requests of a server without the server being able
to link those requests to the client or to identify the requests as having come
from the…
Hertzbleed - a new family of side-channel attacks
https://ift.tt/cEfmOvK
Submitted June 15, 2022 at 12:51AM by CyberMasterV
via reddit https://ift.tt/BwcHbzs
https://ift.tt/cEfmOvK
Submitted June 15, 2022 at 12:51AM by CyberMasterV
via reddit https://ift.tt/BwcHbzs
Hertzbleed
Hertzbleed Attack
Turning Power Side-Channel Attacks Into Remote Timing Attacks on x86
TPM Sniffing Attacks Against Non-Bitlocker Targets
https://ift.tt/CZsHQc0
Submitted June 15, 2022 at 06:59AM by Gallus
via reddit https://ift.tt/C6FXNLB
https://ift.tt/CZsHQc0
Submitted June 15, 2022 at 06:59AM by Gallus
via reddit https://ift.tt/C6FXNLB
English
TPM Sniffing Attacks Against Non-Bitlocker Targets | Secura
Preboot passwords are important when using BitLocker to prevent all kinds of attacks. One of those attacks is the ability to sniff the TPM chip communication and recover the decryption key. This article shows you how to attack Linux disk encryption and provides…
Bypassing CSP with dangling iframes
https://ift.tt/uLGfStT
Submitted June 15, 2022 at 06:57AM by Gallus
via reddit https://ift.tt/5ur87a1
https://ift.tt/uLGfStT
Submitted June 15, 2022 at 06:57AM by Gallus
via reddit https://ift.tt/5ur87a1
PortSwigger Research
Bypassing CSP with dangling iframes
Introduction Our Web Security Academy has a topic on dangling markup injection - a technique for exploiting sites protected by CSP. But something interesting happened when we came to update to Chrome
Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup
https://ift.tt/sErC2lI
Submitted June 15, 2022 at 11:29AM by alain_proviste
via reddit https://ift.tt/PzF31mR
https://ift.tt/sErC2lI
Submitted June 15, 2022 at 11:29AM by alain_proviste
via reddit https://ift.tt/PzF31mR
doar-e.github.io
Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup
Quick Malware Analysis: TA578 Thread-hijacked email, Bumblebee, and Cobalt Strike pcap from 2022-06-14
https://ift.tt/iq1vB0z
Submitted June 15, 2022 at 07:35PM by dougburks
via reddit https://ift.tt/fcTEe1n
https://ift.tt/iq1vB0z
Submitted June 15, 2022 at 07:35PM by dougburks
via reddit https://ift.tt/fcTEe1n
blog.securityonion.net
Quick Malware Analysis: TA578 Thread-hijacked email, Bumblebee, and Cobalt Strike pcap from 2022-06-14
Thanks to Brad Duncan for sharing this pcap! https://www.malware-traffic-analysis.net/2022/06/14/index.html We did a quick analysis of this ...
Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu
https://ift.tt/mrJkvWZ
Submitted June 15, 2022 at 07:29PM by Gallus
via reddit https://ift.tt/IynQhJK
https://ift.tt/mrJkvWZ
Submitted June 15, 2022 at 07:29PM by Gallus
via reddit https://ift.tt/IynQhJK
fred's notes
Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu
In this post, we attack the Nest Hub (2nd Gen), an always-connected smart home display from Google, in order to boot a custom OS. First, we explore both hardware and software attack surface in search of security vulnerabilities that could permit arbitrary…
Pulling MikroTik into the Limelight
https://ift.tt/4xWI2oX
Submitted June 16, 2022 at 01:48AM by 0xdea
via reddit https://ift.tt/tOPB4df
https://ift.tt/4xWI2oX
Submitted June 16, 2022 at 01:48AM by 0xdea
via reddit https://ift.tt/tOPB4df
Margin Research
Pulling MikroTik into the Limelight
A comprehensive guide to MikroTik internals, including IPC, hand-rolled cryptography, and a novel post-authentication jailbreak
fast and furious OSCP monkeys doing weird things - learn how to exploit validate suid
https://ift.tt/GmgC9fh
Submitted June 16, 2022 at 06:29AM by Dreg_fr33project
via reddit https://ift.tt/edJE3Nz
https://ift.tt/GmgC9fh
Submitted June 16, 2022 at 06:29AM by Dreg_fr33project
via reddit https://ift.tt/edJE3Nz
Medium
fast and furious OSCP monkeys doing weird things
disclaimer: these post series are just for fun and should not be readed by anyone
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
https://ift.tt/oGrJ5x7
Submitted June 16, 2022 at 09:42AM by cryptogram
via reddit https://ift.tt/eSOfwbF
https://ift.tt/oGrJ5x7
Submitted June 16, 2022 at 09:42AM by cryptogram
via reddit https://ift.tt/eSOfwbF
Volexity
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
Volexity frequently works with individuals and organizations heavily targeted by sophisticated, motivated, and well-equipped threat actors from around the world. Some of these individuals or organizations are attacked infrequently or […]
Think that a Ransomware cannot target your OneDrive and Sharepoint environments? Think again!
https://ift.tt/EFQuIa8
Submitted June 16, 2022 at 04:28PM by Environmental-Art446
via reddit https://ift.tt/OAfVohJ
https://ift.tt/EFQuIa8
Submitted June 16, 2022 at 04:28PM by Environmental-Art446
via reddit https://ift.tt/OAfVohJ
Proofpoint
Office 365 Allows Ransomware in OneDrive & SharePoint | Proofpoint US
Learn more about a potentially harmful Office 365 functionality that allows ransomware to encrypt files stored on SharePoint and OneDrive. Read more with Proofpoint.