Sys-Admin InfoSec – Telegram
Sys-Admin InfoSec
12.7K subscribers
235 photos
2 videos
103 files
4.55K links
News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Forum - forum.sys-adm.in
* Chat - @sysadm_in
* Job - @sysadm_in_job
* ? - @sysadminkz
Download Telegram
/ New CatB Ransomware Employs 2-Year Old DLL Hijacking Technique To Evade Detection

https://minerva-labs.com/blog/new-catb-ransomware-employs-2-year-old-dll-hijacking-technique-to-evade-detection/
/ PurpleUrchin Bypasses CAPTCHA and Steals Cloud Platform Resources

…automated account creation cases bypassed CAPTCHA images using simple image analysis techniques... creation of more than 130,000 user accounts created on various cloud platform services like Heroku, Togglebox and GitHub..:

https://unit42.paloaltonetworks.com/purpleurchin-steals-cloud-resources/
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
Invictus-AWS

Is a python noscript that will help automatically enumerate and acquire relevant data from an AWS environment. The tool doesn't require any installation it can be run as a standalone noscript with minimal configuration required. The goal for Invictus-AWS is to allow incident responders or other security personnel to quickly get an insight into an AWS environment:

https://github.com/invictus-ir/Invictus-AWS
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
/ After scanned every package on PyPi and found 57 live AWS keys

from organisations like:

- Amazon themselves
- Intel
- Stanford, Portland and Louisiana University
- The Australian Government
- ...

https://tomforb.es/i-scanned-every-package-on-pypi-and-found-57-live-aws-keys/
/ Microsoft Exchange Server Elevation of Privilege Vulnerability

Released: 8 Nov 2022 Last updated: 15 Dec 2022:

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41080
/ Linux kernel stack buffer overflow in nftables

https://www.openwall.com/lists/oss-security/2023/01/13/2