[Announce] Samba 4.15.2, 4.14.10, 4.13.14 Security Releases are available for Download
https://lists.samba.org/archive/samba-announce/2021/000583.html
https://lists.samba.org/archive/samba-announce/2021/000583.html
Mix of news
TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access
https://research.nccgroup.com/2021/11/08/ta505-exploits-solarwinds-serv-u-vulnerability-cve-2021-35211-for-initial-access/
PhoneSpy: The App-Based Cyberattack Snooping South Korean Citizens
https://blog.zimperium.com/phonespy-the-app-based-cyberattack-snooping-south-korean-citizens/
Critical Security Vulnerability Fixed In WordPress Reset PRO plugin
https://patchstack.com/wp-reset-pro-critical-vulnerability-fixed/
Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP Edition appliance Security Update
https://support.citrix.com/article/CTX330728
TA505 exploits SolarWinds Serv-U vulnerability (CVE-2021-35211) for initial access
https://research.nccgroup.com/2021/11/08/ta505-exploits-solarwinds-serv-u-vulnerability-cve-2021-35211-for-initial-access/
PhoneSpy: The App-Based Cyberattack Snooping South Korean Citizens
https://blog.zimperium.com/phonespy-the-app-based-cyberattack-snooping-south-korean-citizens/
Critical Security Vulnerability Fixed In WordPress Reset PRO plugin
https://patchstack.com/wp-reset-pro-critical-vulnerability-fixed/
Citrix Application Delivery Controller, Citrix Gateway, and Citrix SD-WAN WANOP Edition appliance Security Update
https://support.citrix.com/article/CTX330728
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Обход блокировки экрана от Apple и проведение безконтактных платежей
Исследование на эту тему:
https://practical_emv.gitlab.io/
Исследование на эту тему:
https://practical_emv.gitlab.io/
New Critical Vulnerabilities Found on Nucleus TCP/IP Stack
https://www.forescout.com/blog/new-critical-vulnerabilities-found-on-nucleus-tcp-ip-stack/
https://www.forescout.com/blog/new-critical-vulnerabilities-found-on-nucleus-tcp-ip-stack/
Forescout
New Critical Vulnerabilities Found on Nucleus TCP/IP Stack - Forescout
Forescout Research Labs, with support from Medigate Labs, have discovered a set of 13 new vulnerabilities affecting the Nucleus TCP/IP stack, which we are collectively calling NUCLEUS:13. The new vulnerabilities allow for remote code execution, denial of…
PhoneSpy: The App-Based Cyberattack Snooping South Korean Citizens
https://blog.zimperium.com/phonespy-the-app-based-cyberattack-snooping-south-korean-citizens/
Zero-Day Disclosure: Palo Alto Networks GlobalProtect VPN CVE-2021-3064
https://www.randori.com/blog/cve-2021-3064/
https://blog.zimperium.com/phonespy-the-app-based-cyberattack-snooping-south-korean-citizens/
Zero-Day Disclosure: Palo Alto Networks GlobalProtect VPN CVE-2021-3064
https://www.randori.com/blog/cve-2021-3064/
Zimperium
PhoneSpy: The App-Based Cyberattack Snooping South Korean Citizens - Zimperium
true
Researcher Details Vulnerabilities Found in AWS API Gateway
https://www.darkreading.com/vulnerabilities-threats/researcher-details-vulnerabilities-found-in-aws-api-gateway
https://www.darkreading.com/vulnerabilities-threats/researcher-details-vulnerabilities-found-in-aws-api-gateway
Darkreading
Researcher Details Vulnerabilities Found in AWS API Gateway
AWS fixed the security flaws that left the API service at risk of so-called HTTP header-smuggling attacks, says the researcher who discovered them.
Analyzing a watering hole campaign using macOS exploits
https://blog.google/threat-analysis-group/analyzing-watering-hole-campaign-using-macos-exploits/
https://blog.google/threat-analysis-group/analyzing-watering-hole-campaign-using-macos-exploits/
Google
Analyzing a watering hole campaign using macOS exploits
To protect our users, TAG routinely hunts for 0-day vulnerabilities exploited in-the-wild. In late August 2021, TAG discovered watering hole attacks targeting visitors t…
Windows User Profile Service 0day LPE
https://halove23.blogspot.com/2021/10/windows-user-profile-service-0day.html
https://halove23.blogspot.com/2021/10/windows-user-profile-service-0day.html
Sys-Admin InfoSec
В этом году состоится KolesaConf, где я скорее всего приму участие, по крайней мере тема доклада уже имеется: • Делаем свой Blender c блекджеком и шлюзами На самом деле тем будет много и темы по нашей части довольно интересные, мало того спикеры вполне…
Настал день и час Колес, думаю много интересных тем можно будет узнать и послушать. Трансляция:
youtu_be/ShbLEcSd7gA
up
В общем организаторы на время выпилили видео из паблика (к моей печали и моему неведению)
У кого есть видео, буду признателен
UP
Видос моего доклада:
https://youtu.be/d5vwr36yHoU
youtu_be/ShbLEcSd7gA
up
В общем организаторы на время выпилили видео из паблика (к моей печали и моему неведению)
У кого есть видео, буду признателен
UP
Видос моего доклада:
https://youtu.be/d5vwr36yHoU
YouTube
Blocky Listened Daemon (BLD) - AD-BLENDER
Проект представляет из себя открытый, бесплатный, превентивный сервис по - блокировке рекламы, а также вредоносных, фишинговых доменов, трекинговых и телеметрических сервисов. Не требует установки. Легко настраивается на домашних/рабочих роутерах, мобильных…
AT&T Alien Labs finds new Golang malware (BotenaGo) targeting millions of routers and IoT devices with more than 30 exploits
https://cybersecurity.att.com/blogs/labs-research/att-alien-labs-finds-new-golang-malwarebotenago-targeting-millions-of-routers-and-iot-devices-with-more-than-30-exploits
https://cybersecurity.att.com/blogs/labs-research/att-alien-labs-finds-new-golang-malwarebotenago-targeting-millions-of-routers-and-iot-devices-with-more-than-30-exploits
Алматы, 11 декабря, сбор на тему реверса/малвари/фаззинга/эсплоитов
И + любая бинарщина - будет на очередном, открытом митапе r0crewKZ, с бесплатным пивом (в разумных пределах) и конечно же докладами)
Глубокое погружение в темы:
• Мошенничество OLX: Итоги расследования (morty)
• Attacking Software Developers. Часть 1 (thatskriptkid)
• Почему вы этого не делаете? (novitoll)
• Attacking Software Developers. Часть 2 (thatskriptkid)
• Эксплоитить Линукс ядро стало сложнее, но нас не остановить (novitoll)
• ...тема уточняется...
• 11 декабря 2021г. в 18:00. Место: Lenore Pub, проспект Абая, 124, https://go.2gis.com/jozza
Открытая встреча среди профессионалов и не только, отличная площадка для общения и потребления новых знаний ИМХО
P.S. Онлайн вещание пока под вопросом
HTML smuggling surges: Highly evasive loader technique increasingly used in banking malware, targeted attacks
https://www.microsoft.com/security/blog/2021/11/11/html-smuggling-surges-highly-evasive-loader-technique-increasingly-used-in-banking-malware-targeted-attacks/
https://www.microsoft.com/security/blog/2021/11/11/html-smuggling-surges-highly-evasive-loader-technique-increasingly-used-in-banking-malware-targeted-attacks/
Microsoft News
HTML smuggling surges: Highly evasive loader technique increasingly used in banking malware, targeted attacks
HTML smuggling, a highly evasive malware delivery technique that leverages legitimate HTML5 and JavaScript features, is increasingly used in email campaigns that deploy banking malware, remote access Trojans (RATs), and other payloads related to targeted…
Groups Target Alibaba ECS Instances for Cryptojacking
https://www.trendmicro.com/en_us/research/21/k/groups-target-alibaba-ecs-instances-for-cryptojacking.html
https://www.trendmicro.com/en_us/research/21/k/groups-target-alibaba-ecs-instances-for-cryptojacking.html
Trend Micro
Groups Target Alibaba ECS Instances for Cryptojacking
We looked at how some malicious groups disable features in Alibaba Cloud ECS instances for illicit mining of Monero.
...
We demonstrate that it is possible to trigger Rowhammer bit flips on all DRAM devices today despite deployed mitigations on commodity off-the-shelf systems with little effort.
...
https://comsec.ethz.ch/research/dram/blacksmith/
We demonstrate that it is possible to trigger Rowhammer bit flips on all DRAM devices today despite deployed mitigations on commodity off-the-shelf systems with little effort.
...
https://comsec.ethz.ch/research/dram/blacksmith/
sec22summer_cherubin.pdf
3.3 MB
Website Fingerprinting:
Evaluating Website Fingerprinting Attacks on Tor in the Real World
Цифровой отпечаток в Тор.. Исследование.
Evaluating Website Fingerprinting Attacks on Tor in the Real World
Цифровой отпечаток в Тор.. Исследование.
Fake Ransomware Infection Spooks Website Owners
https://blog.sucuri.net/2021/11/fake-ransomware-infection-spooks-website-owners.html
https://blog.sucuri.net/2021/11/fake-ransomware-infection-spooks-website-owners.html
Sucuri Blog
Fake Ransomware Infection Spooks Website Owners
Starting this past Friday we have seen a number of websites showing a fake ransomware infection. Google search results for “FOR RESTORE SEND 0.1 BITCOIN”…
AI-driven adaptive protection against human-operated ransomware - Microsoft Security Blog
https://www.microsoft.com/security/blog/2021/11/15/ai-driven-adaptive-protection-against-human-operated-ransomware/
https://www.microsoft.com/security/blog/2021/11/15/ai-driven-adaptive-protection-against-human-operated-ransomware/
How to migrate Active Directory from Windows Server 2008 R2 to Windows Server 2022
https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-guide-active-directory-migration-from-windows/ba-p/2888117
https://techcommunity.microsoft.com/t5/itops-talk-blog/step-by-step-guide-active-directory-migration-from-windows/ba-p/2888117
TECHCOMMUNITY.MICROSOFT.COM
How to migrate Active Directory from Windows Server 2008 R2 to Windows Server 2022
The step by step guide on how to migrate Active Directory from Windows Server 2008 R2 to Windows Server 2022
Netgear SOHO Devices contain a vulnerability that allows an attacker within the device’s Local Area Network (LAN) to obtain Remote Code Execution (RCE) as root on the device
PoC
https://github.com/grimm-co/NotQuite0DayFriday/tree/trunk/2021.11.16-netgear-upnp
PoC
https://github.com/grimm-co/NotQuite0DayFriday/tree/trunk/2021.11.16-netgear-upnp
GitHub
NotQuite0DayFriday/2021.11.16-netgear-upnp at trunk · grimm-co/NotQuite0DayFriday
This is a repo which documents real bugs in real software to illustrate trends, learn how to prevent or find them more quickly. - grimm-co/NotQuite0DayFriday
Two technical analysis (pdf) - DNS poisoning and MiTM detecting
Catching Transparent Phish:
Analyzing and Detecting MITM Phishing Toolkits:
https://news.1rj.ru/str/sysadm_in_up/898
DNS Cache Poisoning Attack: Resurrections with Side Channels
https://news.1rj.ru/str/sysadm_in_up/899
Catching Transparent Phish:
Analyzing and Detecting MITM Phishing Toolkits:
https://news.1rj.ru/str/sysadm_in_up/898
DNS Cache Poisoning Attack: Resurrections with Side Channels
https://news.1rj.ru/str/sysadm_in_up/899
Telegram
Sys-Admin Up
Catching Transparent Phish:
Analyzing and Detecting MITM Phishing Toolkits
Analyzing and Detecting MITM Phishing Toolkits
Windows 11 known issues and notifications | Microsoft Docs
https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2
https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2
Docs
Windows 11, version 21H2 known issues and notifications
View announcements and review known issues and fixes for Windows 11, version 21H2