Sys-Admin InfoSec – Telegram
Sys-Admin InfoSec
12.7K subscribers
235 photos
2 videos
103 files
4.55K links
News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Forum - forum.sys-adm.in
* Chat - @sysadm_in
* Job - @sysadm_in_job
* ? - @sysadminkz
Download Telegram
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
 
Бот Маша благодарна за Вашу помощь

Бот Маша через меня попросила передать, что благодаря Вашей помощи, у нее теперь больше ресурсов, а на аватар добавился кристалл счастья и звезда дающая + 10 к силе

Соседние боты, молча поддерживают Машу и радуются бОльшему свободному пространству и памяти на обновленном сервере, который обеспечен благодаря Вам ресурсами вплоть до середины 2023 года

От себя же и в целом от всех кому не безразлична судьба Маши, как члена нашего Sys-Admin коммьюнити, желаем Успехов!

Респект тебе, дружище. Peace ✌️
 
 
Summary of free and open Sys-Admin activities (2021)

Hello everybody. This year was very interesting and productive for Sys-Admin activities, in generally:

• We had an open IT, Information Security, Dev(Sec)Ops and etc - Open SysConf Conference
• Created and published free Check Windows and Control Configs and Security - CWiCCS PowerShell tool
• Created and Deployed Chat Prettier bot
Sys-Admin Laboratory reincarnated
• Created many free / open tools and published on GitHub Repositories
• And finally: Sys-Admin BLD free&fast anti-malicious project was started

Try to use BLD for preventig attack, send your feedbacks and take care of yourself, your loved ones and your personal and corporative data.

Thanks to everyone who helped and helps to Sys-Admin Community, who reads the news and gives feedback - Good luck to all of you!

Happy New Year. Sys-Admins POWER, Peace ✌️
Sys-Admin InfoSec pinned «  Summary of free and open Sys-Admin activities (2021) Hello everybody. This year was very interesting and productive for Sys-Admin activities, in generally: • We had an open IT, Information Security, Dev(Sec)Ops and etc - Open SysConf Conference • Created…»
Forensic Issues and Techniques to Improve Security in SSD with Flex Capacity Feature

https://arxiv.org/ftp/arxiv/papers/2112/2112.13923.pdf

~
How to Disable Telemetry on Windows 10 and 11

https://www.makeuseof.com/windows-10-11-disable-telemetry/

~
Email Stuck in Exchange On-premises Transport Queues

The problem relates to a date check failure with the change of the new year and it not a failure of the AV engine itself:

https://techcommunity.microsoft.com/t5/exchange-team-blog/email-stuck-in-exchange-on-premises-transport-queues/ba-p/3049447

P.S. thx for one of the link @clevergod ✌️
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
doorLock

A persistent denial of service vulnerability affecting iOS 15.2 - iOS 14.7 (and likely through 14.0), triggered via HomeKit

https://trevorspiniolas.com/doorlock/doorlock.html
Bunch of News

~
Persistence without “Persistence”: Meet The Ultimate Persistence Bug – “NoReboot”

https://blog.zecops.com/research/persistence-without-persistence-meet-the-ultimate-persistence-bug-noreboot/

~
Vulnerability in QVPN Service

https://www.qnap.com/en/security-advisory/qsa-21-61

~
A New Web Skimmer Campaign Targets Real Estate Websites Through Attacking Cloud Video Distribution Supply Chain

https://unit42.paloaltonetworks.com/web-skimmer-video-distribution

~
VMware Workstation, Fusion and ESXi updates address a heap-overflow vulnerability (CVE-2021-22045)

https://www.vmware.com/security/advisories/VMSA-2022-0001.html

~
New Zloader Campaign exploits Microsoft’s Signature Verification putting users at risk

https://research.checkpoint.com/2022/can-you-trust-a-files-digital-signature-new-zloader-campaign-exploits-microsofts-signature-verification-putting-users-at-risk/

~
Vulnerability in Apache HTTP Server

Security researchers have discovered a buffer overflow vulnerability (CVE-2021-44790) in Apache HTTP Server. Successful exploitation could allow an attacker to perform a remote code execution attack.

https://www.csa.gov.sg/singcert/Alerts/al-2022-072
Patchwork APT caught in its own web

Patchwork is an Indian threat actor that has been active since December 2015 and usually targets Pakistan via spear phishing attacks. In its most recent campaign from late November to early December 2021, Patchwork has used malicious RTF files to drop a variant of the BADNEWS (Ragnatela) Remote Administration Trojan (RAT).

What is interesting among victims of this latest campaign, is that the actor has for the first time targeted several faculty members whose research focus is on molecular medicine and biological science.

https://blog.malwarebytes.com/threat-intelligence/2022/01/patchwork-apt-caught-in-its-own-web/
WordPress Security Release

This security release features four security fixes. Because this is a security release, it is recommended that you update your sites immediately. All versions since WordPress 3.7 have also been updated.

https://wordpress.org/news/2022/01/wordpress-5-8-3-security-release/
Abcbot - An Evolution of Xanthe

The malware was named Xanthe and its main purpose is to hijack the resources of a compromised host to mine cryptocurrency.

https://www.cadosecurity.com/abcbot-an-evolution-of-xanthe/

~
Would You Exchange Your Security for a Gift Card?

This letter was supposedly from Best Buy giving out a $50 gift card to its loyal customers. Included in this letter is seemingly a USB drive that claims to contain a list of items to spend on…

Bad USB as phisycal attachment)

https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/would-you-exchange-your-security-for-a-gift-card/
CVE-2021-20038..42: SonicWall SMA 100 Multiple Vulnerabilities

Over the course of routine security research, Rapid7 researcher Jake Baines discovered and reported five vulnerabilities involving the SonicWall Secure Mobile Access (SMA) 100 series of devices, which includes SMA 200, 210, 400, 410, and 500v. The most serious of these issues can lead to unauthenticated remote code execution (RCE) on affected devices.

https://www.rapid7.com/blog/post/2022/01/11/cve-2021-20038-42-sonicwall-sma-100-multiple-vulnerabilities-fixed-2/