CoinHelper Research | Avast
https://blog.avast.com/coinhelper-research-avast
https://blog.avast.com/coinhelper-research-avast
Avast
CoinHelper hides in repackaged installers of software, Windows 11, games, and antivirus
Fortunately, there’s an easy way to protect yourself from CoinHelper: don’t download illegal, cracked, unauthorized, repackaged copies of games, cheats, applications, security software, and operating systems.
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Прям свежак, свежак - Установщик GVM 21 на Ubuntu 20+
Пока поддерживается убунту, после планируется Rocky, CentOS. Ставит и собирает готовое vulnerability scanning решение из исходников.
https://github.com/m0zgen/install-gvm21
Билдится согласно оф. ману:
https://greenbone.github.io/docs/gvm-21.04/index.html#setting-up-an-admin-user
Доп. инфо
Как ставить сканер уязвимостей GVM 21 на CentOS 8 из Atomic репы:
* https://sys-adm.in/systadm/nix/964-kak-ustanovit-skaner-uyazvimostej-greenbone-openvas-21-v-centos-8-2022.html
====
(EN) OpenVAS GVM 21 Ubuntu 20+ Installer
You can read REDME.md in repo:
https://github.com/m0zgen/install-gvm21
Script wrote according official documentation:
https://greenbone.github.io/docs/gvm-21.04/index.html#setting-up-an-admin-user
Пока поддерживается убунту, после планируется Rocky, CentOS. Ставит и собирает готовое vulnerability scanning решение из исходников.
https://github.com/m0zgen/install-gvm21
Билдится согласно оф. ману:
https://greenbone.github.io/docs/gvm-21.04/index.html#setting-up-an-admin-user
Доп. инфо
Как ставить сканер уязвимостей GVM 21 на CentOS 8 из Atomic репы:
* https://sys-adm.in/systadm/nix/964-kak-ustanovit-skaner-uyazvimostej-greenbone-openvas-21-v-centos-8-2022.html
====
(EN) OpenVAS GVM 21 Ubuntu 20+ Installer
You can read REDME.md in repo:
https://github.com/m0zgen/install-gvm21
Script wrote according official documentation:
https://greenbone.github.io/docs/gvm-21.04/index.html#setting-up-an-admin-user
Magecart Groups Abuse Google Tag Manager
https://geminiadvisory.io/magecart-google-tag-manager/
Critical update to Chrome
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html?m=1
https://geminiadvisory.io/magecart-google-tag-manager/
Critical update to Chrome
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop.html?m=1
Fraud Intelligence - Gemini Advisory
Magecart Groups Abuse Google Tag Manager
12/06/2021 Key Findings Gemini analysts have identified 316 e-commerce sites worldwide infected with trojanized Google Tag Manager (GTM) containers as part of an ongoing Magecart campaign. This tac…
USB Over Ethernet | Multiple Vulnerabilities in AWS and Other Major Cloud Services
https://www.sentinelone.com/labs/usb-over-ethernet-multiple-privilege-escalation-vulnerabilities-in-aws-and-other-major-cloud-services/
https://www.sentinelone.com/labs/usb-over-ethernet-multiple-privilege-escalation-vulnerabilities-in-aws-and-other-major-cloud-services/
SentinelOne
USB Over Ethernet | Multiple Vulnerabilities in AWS and Other Major Cloud Services
25 CVEs and counting: SentinelLabs' latest research reveals millions of cloud users are exposed to privilege escalations from bugs in shared driver software
Note: BLD Сервис - Замена сервера (RU)
Сегодня было решено заменить сервер с IP
"Старый" IP будет работать еще 3 дня, после чего сервер будет удален, пожалуйста обновите/измените IP адреса, кто использует "старый" IP адрес.
Заранее всем спасибо за понимание.
Note: BLD Service - Server replacement (EN)
Today it was decided to replace the server with IP
The "old" IP will work for another 3 days, after which the server will be deleted, please update / change the IP who is using the "old" IP.
Thanks in advance for your understanding.
~~~
What is BLD DNS service - lab.sys-adm.in
Сегодня было решено заменить сервер с IP
193.178.169.33 на другой, более мощный в другом дата-центре с новым IP 49.12.234.130"Старый" IP будет работать еще 3 дня, после чего сервер будет удален, пожалуйста обновите/измените IP адреса, кто использует "старый" IP адрес.
Заранее всем спасибо за понимание.
Note: BLD Service - Server replacement (EN)
Today it was decided to replace the server with IP
193.178.169.33 with another, more powerful one in another data center with a new IP 49.12.234.130The "old" IP will work for another 3 days, after which the server will be deleted, please update / change the IP who is using the "old" IP.
Thanks in advance for your understanding.
~~~
What is BLD DNS service - lab.sys-adm.in
lab.sys-adm.in
Sys-Admin Laboratory
Open Sys-Admin BLD DNS - Focus on information for free with adblocking and implicit cybersecurity threat prevention.
CVE-2021-38759 | Raspberry Pi OS hard-coded password (CNVD-2021-43968)
https://vuldb.com/?id.187741
https://vuldb.com/?id.187741
Vuldb
CVE-2021-38759 Raspberry Pi OS hard-coded password (CNVD-2021-43968 / EDB-50576)
A vulnerability classified as problematic was found in Raspberry Pi OS up to 5.10. This vulnerability is known as CVE-2021-38759. Configuration settings should be changed. Several companies clearly confirm that VulDB is the primary source for best vulnerability…
Mirai-based Botnet - Moobot Targets Hikvision Vulnerability
https://www.fortinet.com/blog/threat-research/mirai-based-botnet-moobot-targets-hikvision-vulnerability
https://www.fortinet.com/blog/threat-research/mirai-based-botnet-moobot-targets-hikvision-vulnerability
Fortinet Blog
Mirai-based Botnet - Moobot Targets Hikvision Vulnerability
FortiGuard Labs analyzes how an attacker can leverage CVE-2021-36260 to create targets for Moobot which is a DDoS botnet based on Mirai. In this blog we explain how an attacker delivers this payloa…
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Exploiting Vulnerabilities in a TLD Registrar to Takeover Tether, Google, and Amazon — Palisade
https://palisade.consulting/blog/tld-hacking
https://palisade.consulting/blog/tld-hacking
Malicious npm Packages Are After Your Discord Tokens – 17 New Packages Disclosed
https://jfrog.com/blog/malicious-npm-packages-are-after-your-discord-tokens-17-new-packages-disclosed/
https://jfrog.com/blog/malicious-npm-packages-are-after-your-discord-tokens-17-new-packages-disclosed/
JFrog
Malicious npm Packages Are After Your Discord Tokens - 17 New Packages Disclosed
Software supply chain security threat: automated scanning of open-source packages in the npm registry uncovered malware that puts sensitive data and devices at risk.
A new StrongPity variant hides behind Notepad++ installation
https://blog.minerva-labs.com/a-new-strongpity-variant-hides-behind-notepad-installation
--up--
RCE 0-day exploit found in log4j, a popular Java logging package
- https://www.lunasec.io/docs/blog/log4j-zero-day/
PoC and etc:
- https://github.com/tangxiaofeng7/apache-log4j-poc
- https://github.com/YfryTchsGD/Log4jAttackSurface
- https://gist.github.com/gnremy/c546c7911d5f876f263309d7161a7217
P.S. thx for the some links dear subscribers ✌️
https://blog.minerva-labs.com/a-new-strongpity-variant-hides-behind-notepad-installation
--up--
RCE 0-day exploit found in log4j, a popular Java logging package
- https://www.lunasec.io/docs/blog/log4j-zero-day/
PoC and etc:
- https://github.com/tangxiaofeng7/apache-log4j-poc
- https://github.com/YfryTchsGD/Log4jAttackSurface
- https://gist.github.com/gnremy/c546c7911d5f876f263309d7161a7217
P.S. thx for the some links dear subscribers ✌️
Kali Linux 2021.4 Release | Kali Linux Blog
https://www.kali.org/blog/kali-linux-2021-4-release/
https://www.kali.org/blog/kali-linux-2021-4-release/
Kali Linux
Kali Linux 2021.4 Release | Kali Linux Blog
With the end of 2021 just around the corner, we are pushing out the last release of the year with Kali Linux 2021.4, which is ready for immediate download or updating.
The summary of the changelog since the 2021.3 release from September 2021 is:
Improved…
The summary of the changelog since the 2021.3 release from September 2021 is:
Improved…
When Honey Bees Become Murder Hornets - Eclypsium
What do you do when two million cheap and powerful devices become the launchpad for one of the most powerful botnets ever? You stop treating the threat like a newly discovered and unexpected honey bee hive and you start remediating like you’ve discovered a Murder Hornet nest.
Based in Latvia, MikroTik may not be a household name, but it has been a popular supplier of routers and wireless ISP devices since 1996 with more than 2,000,000 devices deployed worldwide. These devices are both powerful, and as our research shows, often highly vulnerable. For the money, there is hardly a more powerful device a consumer can get their hands on
https://eclypsium.com/2021/12/09/when-honey-bees-become-murder-hornets/
What do you do when two million cheap and powerful devices become the launchpad for one of the most powerful botnets ever? You stop treating the threat like a newly discovered and unexpected honey bee hive and you start remediating like you’ve discovered a Murder Hornet nest.
Based in Latvia, MikroTik may not be a household name, but it has been a popular supplier of routers and wireless ISP devices since 1996 with more than 2,000,000 devices deployed worldwide. These devices are both powerful, and as our research shows, often highly vulnerable. For the money, there is hardly a more powerful device a consumer can get their hands on
https://eclypsium.com/2021/12/09/when-honey-bees-become-murder-hornets/
Eclypsium | Supply Chain Security for the Modern Enterprise
When Honey Bees Become Murder Hornets - Eclypsium | Supply Chain Security for the Modern Enterprise
What do you do when two million cheap and powerful devices become the launchpad for one of the most powerful botnets ever? You stop treating the threat like a newly discovered and unexpected honey bee hive and you start remediating like you’ve discovered…
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Напоминаю: Сегодня в Алматы в 18:00 начнётся Бинарный эвент вместе с r0crewKZ
- Ресерчинг, Атаки, Эксплуатация, и Пиво конечно :)
Детали:
- https://news.1rj.ru/str/sysadm_in_up/916
~~
Remind: Today in Almaty at 06:00 PM we will start Binary event with r0crewKZ
- Researching, Attacking, Exploiting and Beer 🍻 of course :)
Details:
- https://news.1rj.ru/str/sysadm_in_up/916
- Ресерчинг, Атаки, Эксплуатация, и Пиво конечно :)
Детали:
- https://news.1rj.ru/str/sysadm_in_up/916
~~
Remind: Today in Almaty at 06:00 PM we will start Binary event with r0crewKZ
- Researching, Attacking, Exploiting and Beer 🍻 of course :)
Details:
- https://news.1rj.ru/str/sysadm_in_up/916
Telegram
Sys-Admin Up
Алматы, 11 декабря, сбор на тему бинарщины (update)
В прошлый раз я писал о грядущей встрече, тему бинарщины и не только, осталось менее 10 дней до этой движухи.
В виду чего высылаю почти окончательный вариант тем:
1. Мошенничество OLX: Итоги расследования…
В прошлый раз я писал о грядущей встрече, тему бинарщины и не только, осталось менее 10 дней до этой движухи.
В виду чего высылаю почти окончательный вариант тем:
1. Мошенничество OLX: Итоги расследования…
1.6 Million WordPress Sites Hit With 13.7 Million Attacks In 36 Hours From 16,000 IPs
https://www.wordfence.com/blog/2021/12/massive-wordpress-attack-campaign/
TP-Link TL-WR840N EU v5 Remote Code Execution
https://k4m1ll0.com/cve-2021-41653.html
CVE-2021-43798 Grafana directory traversal
https://www.openwall.com/lists/oss-security/2021/12/09/2
https://www.wordfence.com/blog/2021/12/massive-wordpress-attack-campaign/
TP-Link TL-WR840N EU v5 Remote Code Execution
https://k4m1ll0.com/cve-2021-41653.html
CVE-2021-43798 Grafana directory traversal
https://www.openwall.com/lists/oss-security/2021/12/09/2
Wordfence
1.6 Million WordPress Sites Hit With 13.7 Million Attacks In 36 Hours From 16,000 IPs
Today, on December 9, 2021, our Threat Intelligence team noticed a drastic uptick in attacks targeting vulnerabilities that make it possible for attackers to update arbitrary options on vulnerable sites. This led us into an investigation which uncovered an…
How SASE is saving the marriage between network and security | VentureBeat
https://venturebeat.com/2021/06/03/how-sase-is-saving-the-marriage-between-network-and-security/
https://venturebeat.com/2021/06/03/how-sase-is-saving-the-marriage-between-network-and-security/
VentureBeat
How SASE is saving the marriage between network and security
The barrier between security and networking teams creates friction which could potentially delay ongoing digital transformation projects.
..being exploited in the wild
https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html?m=1
https://blog.talosintelligence.com/2021/12/apache-log4j-rce-vulnerability.html?m=1
Cisco Talos Blog
Threat Advisory: Critical Apache Log4j vulnerability being exploited in the wild
Update History
DateDenoscription of UpdatesDec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021…
DateDenoscription of UpdatesDec. 20, 2021
Additional coverage and IOCs; additional detection capabilities for customers via Cisco Global Threat Alerts.
Dec. 18, 2021
Additional mitigation guidance; updated coverage information.
Dec. 17, 2021…
Apache Log4Shell Vaccine
https://www.cybereason.com/blog/cybereason-releases-vaccine-to-prevent-exploitation-of-apache-log4shell-vulnerability-cve-2021-44228
P.S. thx for the link BORODA(C) ✌️
https://www.cybereason.com/blog/cybereason-releases-vaccine-to-prevent-exploitation-of-apache-log4shell-vulnerability-cve-2021-44228
P.S. thx for the link BORODA(C) ✌️
Cybereason
UPDATED: Cybereason Log4Shell Vaccine Offers Permanent Mitigation Option for Log4j Vulnerabilities (CVE-2021-44228 and CVE-2021…
Cybereason researchers have released an updated "vaccine” with permanent mitigation option for the Log4Shell vulnerabilities (CVE-2021-44228 and CVE-2021-45046) which is freely available on GitHub and relatively simple to implement...
About the security content of iOS 15.2 and iPadOS 15.2 - Apple Support
https://support.apple.com/en-us/HT212976
https://support.apple.com/en-us/HT212976
Apple Support
About the security content of iOS 15.2 and iPadOS 15.2
This document describes the security content of iOS 15.2 and iPadOS 15.2.
Microsoft back to its old tricks to get an edge on the competition. | Vivaldi Browser
https://vivaldi.com/blog/microsoft-back-to-its-old-tricks-to-get-an-edge-on-the-competition/
https://vivaldi.com/blog/microsoft-back-to-its-old-tricks-to-get-an-edge-on-the-competition/
Vivaldi Browser
Microsoft back to its old tricks to get an edge on the competition. | Vivaldi Browser
What if Microsoft put the same effort into improving their Internet Explorer (Edge) browser as they do making it so hard for you to use a different browser on Windows? Vivaldi is not afraid of…
Update Google Chrome to Patch New Zero-Day Exploit Detected in the Wild
https://thehackernews.com/2021/12/update-google-chrome-to-patch-new-zero.html?m=1
Chrome Releases
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html
https://thehackernews.com/2021/12/update-google-chrome-to-patch-new-zero.html?m=1
Chrome Releases
https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html
Chrome Releases
Stable Channel Update for Desktop
The Stable channel has been updated to 96.0.4664.110 for Windows, Mac and Linux which will roll out over the coming days/weeks. Extended sta...