Secrets Revealed in Container Images:
An Internet-wide Study on Occurrence and Impact
https://arxiv.org/pdf/2307.03958.pdf
An Internet-wide Study on Occurrence and Impact
https://arxiv.org/pdf/2307.03958.pdf
TTPs: BadStrings
In this writeup we discuss a mutli-step methodology for beating string detection by Mandiant's FLOSS string deobfuscator:
— https://steve-s.gitbook.io/0xtriboulet/ttps/ttps-badstrings
In this writeup we discuss a mutli-step methodology for beating string detection by Mandiant's FLOSS string deobfuscator:
— https://steve-s.gitbook.io/0xtriboulet/ttps/ttps-badstrings
steve-s.gitbook.io
TTPs: BadStrings | 0xTriboulet
In this writeup we discuss a mutli-step methodology for beating string detection by Mandiant's FLOSS string deobfuscator
Kaspersky v21.3.10.391 Bypassed by Chunked CobaltStrike Payloads
— https://www.youtube.com/watch?v=yNbUner6yZg
— https://www.youtube.com/watch?v=yNbUner6yZg
YouTube
Kaspersky v21.3.10.391 Bypassed by Chunked CobaltStrike Payloads
Kaspersky v21.3.10.391 with last update 2023/06/17 Fully Bypassed!
via Chunked cobaltstrike payloads and code will run #inmemory step by step via #chunked payloads in 4 separated sections ;p , in this code i used rtlmovemomory but i can use other win #apis…
via Chunked cobaltstrike payloads and code will run #inmemory step by step via #chunked payloads in 4 separated sections ;p , in this code i used rtlmovemomory but i can use other win #apis…
VirusTotal Data Leak
German Lang Report from BSI:
— https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2022/2022-206270-1032.html
German Lang Report from BSI:
— https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2022/2022-206270-1032.html
Bundesamt für Sicherheit in der Informationstechnik
Datenabfluss im Falle von Dateiprüfungen bei VirusTotal
Im Rahmen eines Vorfalls wurde entdeckt, dass in einer Institution regelmäßig verdächtige E-Mail Anhänge, die in die Quarantäne verschoben werden, teil-automatisiert zu VirusTotal hochgeladen werden. Bei den verdächtigen Dateien handelte es sich in Einzelfällen…
How Cloudflare optimizes web content for faster page loads
https://www.cloudflare.com/resources/assets/slt3lc6tev37/5ghrabxM7vxfsvQR5g5XFx/4d2e48d839026fcc9ae8ae960e68f64c/How_Cloudflare_optimizes_web_content_for_faster_page_loads.pdf
https://www.cloudflare.com/resources/assets/slt3lc6tev37/5ghrabxM7vxfsvQR5g5XFx/4d2e48d839026fcc9ae8ae960e68f64c/How_Cloudflare_optimizes_web_content_for_faster_page_loads.pdf
Prominent Threat Actor Accidentally Infects Own Computer with Info-Stealer
https://hudsonrock.com/blog/prominent-threat-actor-accidentally-infects-own-computer-with-info-stealer
https://hudsonrock.com/blog/prominent-threat-actor-accidentally-infects-own-computer-with-info-stealer
Hudson Rock
Hudson Rock - Infostealer Intelligence Solutions
Powered by Hudson Rock's continuously augmented cybercrime database, composed of millions of machines compromised by Infostealers in global malware spreading campaigns.
5G Network Slicing:
Security Considerations for Design, Deployment, and Maintenance
https://media.defense.gov/2023/Jul/17/2003260829/-1/-1/0/ESF%205G%20NETWORK%20SLICING-SECURITY%20CONSIDERATIONS%20FOR%20DESIGN,%20DEPLOYMENT,%20AND%20MAINTENANCE_FINAL.PDF
Security Considerations for Design, Deployment, and Maintenance
https://media.defense.gov/2023/Jul/17/2003260829/-1/-1/0/ESF%205G%20NETWORK%20SLICING-SECURITY%20CONSIDERATIONS%20FOR%20DESIGN,%20DEPLOYMENT,%20AND%20MAINTENANCE_FINAL.PDF
PowershellKerberos
Some noscripts to abuse kerberos using Powershell
https://github.com/MzHmO/PowershellKerberos/tree/main
Some noscripts to abuse kerberos using Powershell
https://github.com/MzHmO/PowershellKerberos/tree/main
GitHub
GitHub - MzHmO/PowershellKerberos: Some noscripts to abuse kerberos using Powershell
Some noscripts to abuse kerberos using Powershell. Contribute to MzHmO/PowershellKerberos development by creating an account on GitHub.
Kevin David Mitnick R.I.P. ⚰️
Peer connection has been lost… Peace.
— https://www.dignitymemorial.com/obituaries/las-vegas-nv/kevin-mitnick-11371668
Peer connection has been lost… Peace.
— https://www.dignitymemorial.com/obituaries/las-vegas-nv/kevin-mitnick-11371668
Dignity Memorial
Kevin Mitnick Obituary - Las Vegas, NV
Celebrate the life of Kevin Mitnick, leave a kind word or memory and get funeral service information care of King David Memorial Chapel & Cemetery.
KAZ CTF - Категорийный турнир с призовыми от команд SPACE и КАИБ
Множество категорий с 30+ тасков тематик:
— web, crypto, reverse, pwn, osint, misc, noscripting, malware analysis
Можно участвовать как в соло так и с командой до 5 человек. Призы организаторами обещаны хорошие 💪
— Все детали здесь - ctf.kazctf.kz
Множество категорий с 30+ тасков тематик:
— web, crypto, reverse, pwn, osint, misc, noscripting, malware analysis
Можно участвовать как в соло так и с командой до 5 человек. Призы организаторами обещаны хорошие 💪
— Все детали здесь - ctf.kazctf.kz
CISA Adds One Known Exploited Vulnerability to Catalog (ivanti)
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability:
https://www.cisa.gov/news-events/alerts/2023/07/25/cisa-adds-one-known-exploited-vulnerability-catalog
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability:
https://www.cisa.gov/news-events/alerts/2023/07/25/cisa-adds-one-known-exploited-vulnerability-catalog
Beyond File Search: A Novel Method for Exploiting the "search-ms" URI Protocol Handler
https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html
https://www.trellix.com/en-us/about/newsroom/stories/research/beyond-file-search-a-novel-method.html
Trellix
Beyond File Search: A Novel Method
Join us as we delve into the mysterious world of the "search" or "search-ms" URI protocol attack. Threat actors craft deceptive emails and compromised websites to trick users into executing malicious code disguised as trusted files.
Incident Management with ChatGPT on Azure Sentinel
https://azuresecurityschool.com/incident-management-with-chatgpt-on-azure-sentinel-step-by-step-guide-for-integration/
https://azuresecurityschool.com/incident-management-with-chatgpt-on-azure-sentinel-step-by-step-guide-for-integration/
Azure Security School
Incident Management with ChatGPT on Azure Sentinel. Step by Step
Integrating ChatGPT with Microsoft Sentinel for incident management offers numerous benefits such as automating responses, providing accurate and timely answers, and streamlining incident management workflow