Top Security News for 21/05/2023
SparkRAT Being Distributed Within a Korean VPN Installer
https://www.reddit.com/r/Malware/comments/13my6l8/sparkrat_being_distributed_within_a_korean_vpn/
Being accused of triggering a ransomware attack...
https://www.reddit.com/r/Malware/comments/13mq3gx/being_accused_of_triggering_a_ransomware_attack/
Old Oracle WebLogic vulnerability leveraged in cryptomining attacks
https://malware.news/t/old-oracle-weblogic-vulnerability-leveraged-in-cryptomining-attacks/69752#post_1
PoC for Decrypting SAP Cloud Connector SSFS: Utilizing 'getRecord' Function to Decrypt SSFS Properties without Information of Encryption Algorithm
https://www.reddit.com/r/netsec/comments/13mwlse/poc_for_decrypting_sap_cloud_connector_ssfs/
Cybercrime gang FIN7 returned and was spotted delivering Clop ransomware
https://securityaffairs.com/146465/cyber-crime/fin7-delivering-clop-ransomware.html
Phishing Kit Collecting Victim's IP Address, (Sat, May 20th)
https://malware.news/t/phishing-kit-collecting-victims-ip-address-sat-may-20th/69750#post_1
Who says the perfect heist doesn't exist?
https://thecyberwire.com/podcasts/hacking-humans-goes-to-the-movies/19/notes
SFX Gateway removal
https://www.reddit.com/r/Malware/comments/13mzfmu/sfx_gateway_removal/
Millions of Android devices pre-installed with Guerilla malware
https://malware.news/t/millions-of-android-devices-pre-installed-with-guerilla-malware/69753#post_1
US CISA warns of a Samsung vulnerability under active exploitation
https://securityaffairs.com/146457/security/cisa-warns-samsung-flaw.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
SparkRAT Being Distributed Within a Korean VPN Installer
https://www.reddit.com/r/Malware/comments/13my6l8/sparkrat_being_distributed_within_a_korean_vpn/
Being accused of triggering a ransomware attack...
https://www.reddit.com/r/Malware/comments/13mq3gx/being_accused_of_triggering_a_ransomware_attack/
Old Oracle WebLogic vulnerability leveraged in cryptomining attacks
https://malware.news/t/old-oracle-weblogic-vulnerability-leveraged-in-cryptomining-attacks/69752#post_1
PoC for Decrypting SAP Cloud Connector SSFS: Utilizing 'getRecord' Function to Decrypt SSFS Properties without Information of Encryption Algorithm
https://www.reddit.com/r/netsec/comments/13mwlse/poc_for_decrypting_sap_cloud_connector_ssfs/
Cybercrime gang FIN7 returned and was spotted delivering Clop ransomware
https://securityaffairs.com/146465/cyber-crime/fin7-delivering-clop-ransomware.html
Phishing Kit Collecting Victim's IP Address, (Sat, May 20th)
https://malware.news/t/phishing-kit-collecting-victims-ip-address-sat-may-20th/69750#post_1
Who says the perfect heist doesn't exist?
https://thecyberwire.com/podcasts/hacking-humans-goes-to-the-movies/19/notes
SFX Gateway removal
https://www.reddit.com/r/Malware/comments/13mzfmu/sfx_gateway_removal/
Millions of Android devices pre-installed with Guerilla malware
https://malware.news/t/millions-of-android-devices-pre-installed-with-guerilla-malware/69753#post_1
US CISA warns of a Samsung vulnerability under active exploitation
https://securityaffairs.com/146457/security/cisa-warns-samsung-flaw.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
[deleted by user] : r/Malware
77K subscribers in the Malware community. A place for malware reports and information.
Top Security News for 22/05/2023
PyPI Repository temporarily suspends user sign-ups and package uploads due to ongoing attacks
https://securityaffairs.com/146488/cyber-crime/pypi-repository-suspends-sign-ups-package-uploads.html
PyPI Repository Under Attack: User Sign-Ups and Package Uploads Temporarily Halted
https://thehackernews.com/2023/05/pypi-repository-under-attack-user-sign.html
Security Affairs newsletter Round 420 by Pierluigi Paganini – International edition
https://securityaffairs.com/146483/breaking-news/security-affairs-newsletter-round-420.html
ISC StormCast for Monday, May 22nd, 2023
https://isc.sans.edu/podcastdetail/8506
Distribution of Remcos RAT Exploiting sqlps.exe Utility of MS-SQL Servers
https://malware.news/t/distribution-of-remcos-rat-exploiting-sqlps-exe-utility-of-ms-sql-servers/69760#post_1
How the ILOVEYOU worm exposed human beings as the Achilles Heel of cybersecurity
https://malware.news/t/how-the-iloveyou-worm-exposed-human-beings-as-the-achilles-heel-of-cybersecurity/69764#post_1
Cybersecurity moneyball: First principles applied to the workforce gap.
https://thecyberwire.com/podcasts/cso-perspectives/104/notes
Another Malicious HTA File Analysis - Part 3, (Sun, May 21st)
https://malware.news/t/another-malicious-hta-file-analysis-part-3-sun-may-21st/69759#post_1
Ransomware with known Registry Persistence
https://www.reddit.com/r/Malware/comments/13nwu1c/ransomware_with_known_registry_persistence/
BatLoader campaign impersonates ChatGPT and Midjourney to deliver Redline Stealer
https://securityaffairs.com/146496/malware/batloader-campaign-impersonates-chatgpt-midjourney.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
PyPI Repository temporarily suspends user sign-ups and package uploads due to ongoing attacks
https://securityaffairs.com/146488/cyber-crime/pypi-repository-suspends-sign-ups-package-uploads.html
PyPI Repository Under Attack: User Sign-Ups and Package Uploads Temporarily Halted
https://thehackernews.com/2023/05/pypi-repository-under-attack-user-sign.html
Security Affairs newsletter Round 420 by Pierluigi Paganini – International edition
https://securityaffairs.com/146483/breaking-news/security-affairs-newsletter-round-420.html
ISC StormCast for Monday, May 22nd, 2023
https://isc.sans.edu/podcastdetail/8506
Distribution of Remcos RAT Exploiting sqlps.exe Utility of MS-SQL Servers
https://malware.news/t/distribution-of-remcos-rat-exploiting-sqlps-exe-utility-of-ms-sql-servers/69760#post_1
How the ILOVEYOU worm exposed human beings as the Achilles Heel of cybersecurity
https://malware.news/t/how-the-iloveyou-worm-exposed-human-beings-as-the-achilles-heel-of-cybersecurity/69764#post_1
Cybersecurity moneyball: First principles applied to the workforce gap.
https://thecyberwire.com/podcasts/cso-perspectives/104/notes
Another Malicious HTA File Analysis - Part 3, (Sun, May 21st)
https://malware.news/t/another-malicious-hta-file-analysis-part-3-sun-may-21st/69759#post_1
Ransomware with known Registry Persistence
https://www.reddit.com/r/Malware/comments/13nwu1c/ransomware_with_known_registry_persistence/
BatLoader campaign impersonates ChatGPT and Midjourney to deliver Redline Stealer
https://securityaffairs.com/146496/malware/batloader-campaign-impersonates-chatgpt-midjourney.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Security Affairs
PyPI Repository temporarily suspends user sign-ups and package uploads due to ongoing attacks
The Python Package Index (PyPI) maintainers have temporarily disabled the sign up and package upload processes due to an ongoing attack.
Top Security News for 23/05/2023
passkey (noun)
https://thecyberwire.com/podcasts/word-notes/149/notes
Verified Twitter Accounts Spread AI-Generated Hoax of Pentagon Explosion
https://www.vice.com/en_us/article/7kx84b/ai-generated-pentagon-explosion-hoax-twitter
US medical center employee abuses access to patient data. New York bank discloses third-party data breach.
https://thecyberwire.com/podcasts/privacy-briefing/533/notes
Critical Security Vulnerability In PowerVM Hypervisor
https://www.reddit.com/r/netsec/comments/13op2gj/critical_security_vulnerability_in_powervm/
ISC Stormcast For Tuesday, May 23rd, 2023 https://isc.sans.edu/podcastdetail/8508, (Tue, May 23rd)
https://isc.sans.edu/diary/rss/29872
ports.sh
https://www.reddit.com/r/netsec/comments/13ooxgk/portssh/
A week in security (May 15-21)
https://www.malwarebytes.com/blog/news/2023/05/a-week-in-security-may-15-21
U.S. Intelligence Building System to Track Mass Movement of People Around the World
https://www.vice.com/en_us/article/88xq54/us-intelligence-building-system-to-track-mass-movement-of-people-around-the-world
Microsoft reports jump in business email compromise activity
https://www.csoonline.com/article/3697152/microsoft-reports-jump-in-business-email-compromise-activity.html#tk.rss_all
I'm looking for a reverse engineer
https://0x00sec.org/t/im-looking-for-a-reverse-engineer/35175
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
passkey (noun)
https://thecyberwire.com/podcasts/word-notes/149/notes
Verified Twitter Accounts Spread AI-Generated Hoax of Pentagon Explosion
https://www.vice.com/en_us/article/7kx84b/ai-generated-pentagon-explosion-hoax-twitter
US medical center employee abuses access to patient data. New York bank discloses third-party data breach.
https://thecyberwire.com/podcasts/privacy-briefing/533/notes
Critical Security Vulnerability In PowerVM Hypervisor
https://www.reddit.com/r/netsec/comments/13op2gj/critical_security_vulnerability_in_powervm/
ISC Stormcast For Tuesday, May 23rd, 2023 https://isc.sans.edu/podcastdetail/8508, (Tue, May 23rd)
https://isc.sans.edu/diary/rss/29872
ports.sh
https://www.reddit.com/r/netsec/comments/13ooxgk/portssh/
A week in security (May 15-21)
https://www.malwarebytes.com/blog/news/2023/05/a-week-in-security-may-15-21
U.S. Intelligence Building System to Track Mass Movement of People Around the World
https://www.vice.com/en_us/article/88xq54/us-intelligence-building-system-to-track-mass-movement-of-people-around-the-world
Microsoft reports jump in business email compromise activity
https://www.csoonline.com/article/3697152/microsoft-reports-jump-in-business-email-compromise-activity.html#tk.rss_all
I'm looking for a reverse engineer
https://0x00sec.org/t/im-looking-for-a-reverse-engineer/35175
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
N2K CyberWire
passkey (noun)
A passwordless authentication protocol based on the FIDO2 standard.
Top Security News for 24/05/2023
Former Uber CSO Joe Sullivan and lessons learned from the infamous 2016 Uber breach
https://www.csoonline.com/article/3697136/former-uber-cso-joe-sullivan-and-lessons-learned-from-the-infamous-2016-uber-breach.html#tk.rss_all
ISC Stormcast For Wednesday, May 24th, 2023 https://isc.sans.edu/podcastdetail/8510, (Wed, May 24th)
https://malware.news/t/isc-stormcast-for-wednesday-may-24th-2023-https-isc-sans-edu-podcastdetail-8510-wed-may-24th/69856#post_1
Google to pay $40m for "deceptive and unfair" location tracking practices
https://www.malwarebytes.com/blog/news/2023/05/google-out-of-pocket-by-40m-after-location-tracking-lawsuit
March 2023 Deep Web & Dark Web Threat Trend Report
https://malware.news/t/march-2023-deep-web-dark-web-threat-trend-report/69853#post_1
Against the Clock: Cyber Incident Response Plan
https://malware.news/t/against-the-clock-cyber-incident-response-plan/69855#post_1
China Bans U.S. Chip Giant Micron, Citing "Serious Cybersecurity Problems"
https://thehackernews.com/2023/05/china-bans-us-chip-giant-micron-citing.html
Teleport releases Teleport 13 with automatic vulnerability patching, enhanced DevOps security
https://www.csoonline.com/article/3697017/teleport-releases-teleport-13-with-automatic-vulnerability-patching-enhanced-devops-security.html#tk.rss_all
BlackCat Ransomware affiliate uses signed kernel driver to evade detection
https://securityaffairs.com/146536/malware/blackcat-ransomware-uses-kernel-driver.html
ASEC Weekly Malware Statistics (May 15th, 2023 – May 21st, 2023)
https://malware.news/t/asec-weekly-malware-statistics-may-15th-2023-may-21st-2023/69857#post_1
BlackCat ransomware group uses signed kernel driver to evade detection. AhRat exfiltrates files and records audio on Android devices. ChatGPT-themed fleeceware.
https://thecyberwire.com/podcasts/research-briefing/169/notes
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Former Uber CSO Joe Sullivan and lessons learned from the infamous 2016 Uber breach
https://www.csoonline.com/article/3697136/former-uber-cso-joe-sullivan-and-lessons-learned-from-the-infamous-2016-uber-breach.html#tk.rss_all
ISC Stormcast For Wednesday, May 24th, 2023 https://isc.sans.edu/podcastdetail/8510, (Wed, May 24th)
https://malware.news/t/isc-stormcast-for-wednesday-may-24th-2023-https-isc-sans-edu-podcastdetail-8510-wed-may-24th/69856#post_1
Google to pay $40m for "deceptive and unfair" location tracking practices
https://www.malwarebytes.com/blog/news/2023/05/google-out-of-pocket-by-40m-after-location-tracking-lawsuit
March 2023 Deep Web & Dark Web Threat Trend Report
https://malware.news/t/march-2023-deep-web-dark-web-threat-trend-report/69853#post_1
Against the Clock: Cyber Incident Response Plan
https://malware.news/t/against-the-clock-cyber-incident-response-plan/69855#post_1
China Bans U.S. Chip Giant Micron, Citing "Serious Cybersecurity Problems"
https://thehackernews.com/2023/05/china-bans-us-chip-giant-micron-citing.html
Teleport releases Teleport 13 with automatic vulnerability patching, enhanced DevOps security
https://www.csoonline.com/article/3697017/teleport-releases-teleport-13-with-automatic-vulnerability-patching-enhanced-devops-security.html#tk.rss_all
BlackCat Ransomware affiliate uses signed kernel driver to evade detection
https://securityaffairs.com/146536/malware/blackcat-ransomware-uses-kernel-driver.html
ASEC Weekly Malware Statistics (May 15th, 2023 – May 21st, 2023)
https://malware.news/t/asec-weekly-malware-statistics-may-15th-2023-may-21st-2023/69857#post_1
BlackCat ransomware group uses signed kernel driver to evade detection. AhRat exfiltrates files and records audio on Android devices. ChatGPT-themed fleeceware.
https://thecyberwire.com/podcasts/research-briefing/169/notes
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
CSO
Former Uber CSO Joe Sullivan and lessons learned from the infamous 2016 Uber breach
Will Joe Sullivan’s conviction for obstruction in the reporting of the 2016 Uber privacy breach send a chill through the cybersecurity profession? Sullivan tells CSOs he’s worried it just might.
Top Security News for 25/05/2023
N. Korean Lazarus Group Targets Microsoft IIS Servers to Deploy Espionage Malware
https://thehackernews.com/2023/05/n-korean-lazarus-group-targets.html
Hyatt’s CISO, Intel Briefing, & Third-Party Risk Management with Cyber GRX
https://thecyberwire.com/podcasts/rh-isac/28/notes
Iranian Agrius Hackers Targeting Israeli Organizations with Moneybird Ransomware
https://thehackernews.com/2023/05/iranian-agrius-hackers-targeting.html
Legion Malware Upgraded to Target SSH Servers and AWS Credentials
https://thehackernews.com/2023/05/legion-malware-upgraded-to-target-ssh.html
What if we had the SockPuppet vulnerability in iOS 16? - Apple Security Research
https://www.reddit.com/r/netsec/comments/13qgujz/what_if_we_had_the_sockpuppet_vulnerability_in/
Exploring P4 Protocol: Usage, Implementation, and CVE-2021-37535
https://www.reddit.com/r/netsec/comments/13qt3l9/exploring_p4_protocol_usage_implementation_and/
GitHub - avilum/secimport: seccomp Python sandbox, powered by eBPF and Dtrace
https://www.reddit.com/r/netsec/comments/13qfd5x/github_avilumsecimport_seccomp_python_sandbox/
Obsidian ORB Ransomware Demands Gift Cards as Payment
https://malware.news/t/obsidian-orb-ransomware-demands-gift-cards-as-payment/69886#post_1
Cyber Attacks Strike Ukraine's State Bodies in Espionage Operation
https://thehackernews.com/2023/05/cyber-attacks-strike-ukraines-state.html
BlackCat Ransomware Takes Control With New Kernel Driver
https://packetstormsecurity.com/news/view/34651/BlackCat-Ransomware-Takes-Control-With-New-Kernel-Driver.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
N. Korean Lazarus Group Targets Microsoft IIS Servers to Deploy Espionage Malware
https://thehackernews.com/2023/05/n-korean-lazarus-group-targets.html
Hyatt’s CISO, Intel Briefing, & Third-Party Risk Management with Cyber GRX
https://thecyberwire.com/podcasts/rh-isac/28/notes
Iranian Agrius Hackers Targeting Israeli Organizations with Moneybird Ransomware
https://thehackernews.com/2023/05/iranian-agrius-hackers-targeting.html
Legion Malware Upgraded to Target SSH Servers and AWS Credentials
https://thehackernews.com/2023/05/legion-malware-upgraded-to-target-ssh.html
What if we had the SockPuppet vulnerability in iOS 16? - Apple Security Research
https://www.reddit.com/r/netsec/comments/13qgujz/what_if_we_had_the_sockpuppet_vulnerability_in/
Exploring P4 Protocol: Usage, Implementation, and CVE-2021-37535
https://www.reddit.com/r/netsec/comments/13qt3l9/exploring_p4_protocol_usage_implementation_and/
GitHub - avilum/secimport: seccomp Python sandbox, powered by eBPF and Dtrace
https://www.reddit.com/r/netsec/comments/13qfd5x/github_avilumsecimport_seccomp_python_sandbox/
Obsidian ORB Ransomware Demands Gift Cards as Payment
https://malware.news/t/obsidian-orb-ransomware-demands-gift-cards-as-payment/69886#post_1
Cyber Attacks Strike Ukraine's State Bodies in Espionage Operation
https://thehackernews.com/2023/05/cyber-attacks-strike-ukraines-state.html
BlackCat Ransomware Takes Control With New Kernel Driver
https://packetstormsecurity.com/news/view/34651/BlackCat-Ransomware-Takes-Control-With-New-Kernel-Driver.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
The CyberWire
Hyatt’s CISO, Intel Briefing, & Third-Party Risk Management with Cyber GRX
In this episode of the Retail & Hospitality ISAC podcast, host Luke Vander Linden is joined by Ben Vaughn, senior vice president and CISO at Hyatt. During the second part of this interview, Ben reviews Hyatt’s guiding principles and how Hyatt optimizes cyber…
Top Security News for 26/05/2023
How to check for new exploits in real time? VulnCheck has an answer
https://www.csoonline.com/article/3697749/how-to-check-for-new-exploits-in-real-time-vulncheck-has-an-answer.html#tk.rss_all
6 ways generative AI chatbots and LLMs can enhance cybersecurity
https://www.csoonline.com/article/3697137/6-ways-generative-ai-chatbots-and-llms-can-enhance-cybersecurity.html#tk.rss_all
BrandPost: Adding the operation focus to OT security
https://www.csoonline.com/article/3697730/adding-the-operation-focus-to-ot-security.html#tk.rss_all
Inactive accounts pose significant account takeover security risks
https://www.csoonline.com/article/3696941/inactive-accounts-pose-significant-account-takeover-security-risks.html#tk.rss_all
China's Stealthy Hackers Infiltrate U.S. and Guam Critical Infrastructure Undetected
https://thehackernews.com/2023/05/chinas-stealthy-hackers-infiltrate-us.html
Volt Typhoon targets US critical infrastructure with living-off-the-land techniques
https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
Alert: Brazilian Hackers Targeting Users of Over 30 Portuguese Banks
https://thehackernews.com/2023/05/alert-brazilian-hackers-targeting-users.html
APTs increasingly target SMBs, regional MSPs
https://malware.news/t/apts-increasingly-target-smbs-regional-msps/69931#post_1
"Beautiful Cookie Consent Banner" WordPress plugin vulnerability: Update now!
https://malware.news/t/beautiful-cookie-consent-banner-wordpress-plugin-vulnerability-update-now/69933#post_1
Eating Disorder Helpline Fires Staff, Transitions to Chatbot After Unionization
https://www.vice.com/en_us/article/n7ezkm/eating-disorder-helpline-fires-staff-transitions-to-chatbot-after-unionization
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
How to check for new exploits in real time? VulnCheck has an answer
https://www.csoonline.com/article/3697749/how-to-check-for-new-exploits-in-real-time-vulncheck-has-an-answer.html#tk.rss_all
6 ways generative AI chatbots and LLMs can enhance cybersecurity
https://www.csoonline.com/article/3697137/6-ways-generative-ai-chatbots-and-llms-can-enhance-cybersecurity.html#tk.rss_all
BrandPost: Adding the operation focus to OT security
https://www.csoonline.com/article/3697730/adding-the-operation-focus-to-ot-security.html#tk.rss_all
Inactive accounts pose significant account takeover security risks
https://www.csoonline.com/article/3696941/inactive-accounts-pose-significant-account-takeover-security-risks.html#tk.rss_all
China's Stealthy Hackers Infiltrate U.S. and Guam Critical Infrastructure Undetected
https://thehackernews.com/2023/05/chinas-stealthy-hackers-infiltrate-us.html
Volt Typhoon targets US critical infrastructure with living-off-the-land techniques
https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
Alert: Brazilian Hackers Targeting Users of Over 30 Portuguese Banks
https://thehackernews.com/2023/05/alert-brazilian-hackers-targeting-users.html
APTs increasingly target SMBs, regional MSPs
https://malware.news/t/apts-increasingly-target-smbs-regional-msps/69931#post_1
"Beautiful Cookie Consent Banner" WordPress plugin vulnerability: Update now!
https://malware.news/t/beautiful-cookie-consent-banner-wordpress-plugin-vulnerability-update-now/69933#post_1
Eating Disorder Helpline Fires Staff, Transitions to Chatbot After Unionization
https://www.vice.com/en_us/article/n7ezkm/eating-disorder-helpline-fires-staff-transitions-to-chatbot-after-unionization
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
CSO
How to check for new exploits in real time? VulnCheck has an answer
VulnCheck’s new database tracks exploits for fresh vulnerabilities in real time and allows for search using CVE IDs.
Top Security News for 27/05/2023
New PowerExchange Backdoor linked to an Iranian APT group
https://securityaffairs.com/146690/apt/powerexchange-backdoor-iran.html
DocuSign-themed email leads to script-based infection, (Sat, May 27th)
https://isc.sans.edu/diary/rss/29888
Kevin Kirkwood, Deputy CISO from LogRhythm, joins to discuss how to overcome extortion attempts.
https://thecyberwire.com/podcasts/interview-selects/160/notes
Zyxel patches two critical vulnerabilities
https://malware.news/t/zyxel-patches-two-critical-vulnerabilities/69958#post_1
2023-05-24 - Bye bye Pikabot... We're back to Qak! (obama264 Qakbot infection)
https://malware.news/t/2023-05-24-bye-bye-pikabot-were-back-to-qak-obama264-qakbot-infection/69957#post_1
CosmicEnergy: OT and ICS malware from Russia, maybe for red teaming. Updates on Volt Typhoon. Legion malware upgraded for the cloud. Natural-disaster-themed online fraud.
https://thecyberwire.com/podcasts/daily-podcast/1832/notes
Researchers find new ICS malware toolkit designed to cause electric power outages
https://www.csoonline.com/article/3697850/researchers-find-new-ics-malware-toolkit-designed-to-cause-electric-power-outages.html#tk.rss_all
5 Must-Know Facts about 5G Network Security and Its Cloud Benefits
https://thehackernews.com/2023/05/5-must-know-facts-about-5g-network.html
BrandPost: New report reveals tips for building a skilled cybersecurity workforce
https://www.csoonline.com/article/3697790/new-report-reveals-tips-for-building-a-skilled-cybersecurity-workforce.html#tk.rss_all
GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
https://www.reddit.com/r/netsec/comments/13smejr/gcp_cloudsql_vulnerability_leads_to_internal/
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
New PowerExchange Backdoor linked to an Iranian APT group
https://securityaffairs.com/146690/apt/powerexchange-backdoor-iran.html
DocuSign-themed email leads to script-based infection, (Sat, May 27th)
https://isc.sans.edu/diary/rss/29888
Kevin Kirkwood, Deputy CISO from LogRhythm, joins to discuss how to overcome extortion attempts.
https://thecyberwire.com/podcasts/interview-selects/160/notes
Zyxel patches two critical vulnerabilities
https://malware.news/t/zyxel-patches-two-critical-vulnerabilities/69958#post_1
2023-05-24 - Bye bye Pikabot... We're back to Qak! (obama264 Qakbot infection)
https://malware.news/t/2023-05-24-bye-bye-pikabot-were-back-to-qak-obama264-qakbot-infection/69957#post_1
CosmicEnergy: OT and ICS malware from Russia, maybe for red teaming. Updates on Volt Typhoon. Legion malware upgraded for the cloud. Natural-disaster-themed online fraud.
https://thecyberwire.com/podcasts/daily-podcast/1832/notes
Researchers find new ICS malware toolkit designed to cause electric power outages
https://www.csoonline.com/article/3697850/researchers-find-new-ics-malware-toolkit-designed-to-cause-electric-power-outages.html#tk.rss_all
5 Must-Know Facts about 5G Network Security and Its Cloud Benefits
https://thehackernews.com/2023/05/5-must-know-facts-about-5g-network.html
BrandPost: New report reveals tips for building a skilled cybersecurity workforce
https://www.csoonline.com/article/3697790/new-report-reveals-tips-for-building-a-skilled-cybersecurity-workforce.html#tk.rss_all
GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
https://www.reddit.com/r/netsec/comments/13smejr/gcp_cloudsql_vulnerability_leads_to_internal/
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Security Affairs
New PowerExchange Backdoor linked to an Iranian APT group
An alleged Iran-linked APT group targeted an organization linked to the United Arab Emirates (U.A.E.) with the new PowerExchange backdoor.
Top Security News for 18/06/2023
How to find industrial control devices
https://0x00sec.org/t/how-to-find-industrial-control-devices/35620
Lorna Mahlock: Build bridges. [Combat support]
https://thecyberwire.com/podcasts/career-notes/154/notes
Reverse Engineering: iOS App Extraction & Analysis
https://www.reddit.com/r/netsec/comments/14bt9qe/reverse_engineering_ios_app_extraction_analysis/
From Cryptojacking to DDoS Attacks: Diicot Expands Tactics with Cayosin Botnet
https://thehackernews.com/2023/06/from-cryptojacking-to-ddos-attacks.html
The Week that Was: US Government discloses exploitation of MOVEit instances. An update on CosmicEnergy: it’s "not an immediate threat." AI-generated phishing attacks. A 2021 ransomware attack put a hospital under financial pressure that caused it to close.
https://thecyberwire.com/newsletters/week-that-was/7/23
CISA SBOM standards efforts stymied by confusion, inertia | TechTarget
https://www.reddit.com/r/netsec/comments/14bz3q5/cisa_sbom_standards_efforts_stymied_by_confusion/
Update: zipdump.py Version 0.0.26
https://malware.news/t/update-zipdump-py-version-0-0-26/70585#post_1
Explainer: Dominion vulnerabilities reported by Halderman
https://www.reddit.com/r/netsec/comments/14c6ep9/explainer_dominion_vulnerabilities_reported_by/
Law enforcement shutdown a long-standing DDoS-for-hire service
https://securityaffairs.com/147564/cyber-crime/ddos-for-eye-service-seized.html
harbian-audit v0.7 releases: security audit and hardening for Debian 12
https://www.reddit.com/r/netsec/comments/14boalg/harbianaudit_v07_releases_security_audit_and/
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
How to find industrial control devices
https://0x00sec.org/t/how-to-find-industrial-control-devices/35620
Lorna Mahlock: Build bridges. [Combat support]
https://thecyberwire.com/podcasts/career-notes/154/notes
Reverse Engineering: iOS App Extraction & Analysis
https://www.reddit.com/r/netsec/comments/14bt9qe/reverse_engineering_ios_app_extraction_analysis/
From Cryptojacking to DDoS Attacks: Diicot Expands Tactics with Cayosin Botnet
https://thehackernews.com/2023/06/from-cryptojacking-to-ddos-attacks.html
The Week that Was: US Government discloses exploitation of MOVEit instances. An update on CosmicEnergy: it’s "not an immediate threat." AI-generated phishing attacks. A 2021 ransomware attack put a hospital under financial pressure that caused it to close.
https://thecyberwire.com/newsletters/week-that-was/7/23
CISA SBOM standards efforts stymied by confusion, inertia | TechTarget
https://www.reddit.com/r/netsec/comments/14bz3q5/cisa_sbom_standards_efforts_stymied_by_confusion/
Update: zipdump.py Version 0.0.26
https://malware.news/t/update-zipdump-py-version-0-0-26/70585#post_1
Explainer: Dominion vulnerabilities reported by Halderman
https://www.reddit.com/r/netsec/comments/14c6ep9/explainer_dominion_vulnerabilities_reported_by/
Law enforcement shutdown a long-standing DDoS-for-hire service
https://securityaffairs.com/147564/cyber-crime/ddos-for-eye-service-seized.html
harbian-audit v0.7 releases: security audit and hardening for Debian 12
https://www.reddit.com/r/netsec/comments/14boalg/harbianaudit_v07_releases_security_audit_and/
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
0x00sec - The Home of the Hacker
How to find industrial control devices
How to find industrial control devices (e.g. Siemens) on the corporate intranet or internet, how to detect them and be able to access and control these industrial control devices.Whenever I do a penetration testing project, I am usually told by my collaborators…
Top Security News for 19/06/2023
Soft DDOS technique to bypass Play Store security measures
https://www.reddit.com/r/netsec/comments/14baa2t/soft_ddos_technique_to_bypass_play_store_security/
PentestGPT, a gpt-powered penetration testing tool, open source
https://www.reddit.com/r/netsec/comments/14d25yr/pentestgpt_a_gptpowered_penetration_testing_tool/
Brute-Force ZIP Password Cracking with zipdump.py, (Sun, Jun 18th)
https://isc.sans.edu/diary/rss/29948
US govt offers $10 million bounty for info linking Clop ransomware gang to a foreign government.
https://securityaffairs.com/147577/cyber-crime/clop-ransomware-reward.html
Three attacks against geth-based Ethereum clients: "Speculative Denial-of-Service Attacks in Ethereum"
https://www.reddit.com/r/netsec/comments/14che5g/three_attacks_against_gethbased_ethereum_clients/
How to create an hacking lab on apple silicon
https://www.reddit.com/r/netsec/comments/14cim3p/how_to_create_an_hacking_lab_on_apple_silicon/
Microsoft: June Outlook and cloud platform outages were caused by DDoS
https://securityaffairs.com/147605/hacking/microsoft-outages-ddos.html
Need advice on unpacking .dll
https://0x00sec.org/t/need-advice-on-unpacking-dll/35635
CrowdStrike Automates Zero-Day Malware Classification | CrowdStrike
https://www.reddit.com/r/Malware/comments/14cdvyy/crowdstrike_automates_zeroday_malware/
Easiest Way to learn the WinAPI for Malware (Embedding Shellcode)
https://www.reddit.com/r/Malware/comments/14cswu8/easiest_way_to_learn_the_winapi_for_malware/
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Soft DDOS technique to bypass Play Store security measures
https://www.reddit.com/r/netsec/comments/14baa2t/soft_ddos_technique_to_bypass_play_store_security/
PentestGPT, a gpt-powered penetration testing tool, open source
https://www.reddit.com/r/netsec/comments/14d25yr/pentestgpt_a_gptpowered_penetration_testing_tool/
Brute-Force ZIP Password Cracking with zipdump.py, (Sun, Jun 18th)
https://isc.sans.edu/diary/rss/29948
US govt offers $10 million bounty for info linking Clop ransomware gang to a foreign government.
https://securityaffairs.com/147577/cyber-crime/clop-ransomware-reward.html
Three attacks against geth-based Ethereum clients: "Speculative Denial-of-Service Attacks in Ethereum"
https://www.reddit.com/r/netsec/comments/14che5g/three_attacks_against_gethbased_ethereum_clients/
How to create an hacking lab on apple silicon
https://www.reddit.com/r/netsec/comments/14cim3p/how_to_create_an_hacking_lab_on_apple_silicon/
Microsoft: June Outlook and cloud platform outages were caused by DDoS
https://securityaffairs.com/147605/hacking/microsoft-outages-ddos.html
Need advice on unpacking .dll
https://0x00sec.org/t/need-advice-on-unpacking-dll/35635
CrowdStrike Automates Zero-Day Malware Classification | CrowdStrike
https://www.reddit.com/r/Malware/comments/14cdvyy/crowdstrike_automates_zeroday_malware/
Easiest Way to learn the WinAPI for Malware (Embedding Shellcode)
https://www.reddit.com/r/Malware/comments/14cswu8/easiest_way_to_learn_the_winapi_for_malware/
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
Soft DDOS technique to bypass Play Store security measures : r/netsec
482K subscribers in the netsec community. /r/netsec is a community-curated aggregator of technical information security content. Our mission is to…
Top Security News for 20/06/2023
CISA (noun)
https://thecyberwire.com/podcasts/word-notes/153/notes
Finding the Nirvana of information access control or something like it
https://www.csoonline.com/article/3699397/finding-the-nirvana-of-information-access-control-or-something-like-it.html#tk.rss_all
US dangles $10 million reward for information about Cl0p ransomware gang
https://www.malwarebytes.com/blog/news/2023/06/rewards-up-to-10-million-for-information-about-cl0p-ransomware-operation
A week in security (June 12 - 18)
https://malware.news/t/a-week-in-security-june-12-18/70614#post_1
Expanding horizons—Microsoft Security’s continued commitment to multicloud
https://www.microsoft.com/en-us/security/blog/2023/06/14/expanding-horizons-microsoft-securitys-continued-commitment-to-multicloud/
ISC Stormcast For Tuesday, June 20th, 2023 https://isc.sans.edu/podcastdetail/8544, (Tue, Jun 20th)
https://malware.news/t/isc-stormcast-for-tuesday-june-20th-2023-https-isc-sans-edu-podcastdetail-8544-tue-jun-20th/70617#post_1
UK set to ramp up citizen surveillance program
https://malware.news/t/uk-set-to-ramp-up-citizen-surveillance-program/70620#post_1
8 notable entry-level cybersecurity career and skills initiatives in 2023
https://www.csoonline.com/article/3699668/8-notable-entry-level-cybersecurity-career-and-skills-initiatives-in-2023.html#tk.rss_all
EU member states are urged to restrict without delay 5G equipment from risky suppliers
https://securityaffairs.com/147617/laws-and-regulations/eu-restrict-5g-risky-suppliers.html
Hacktivist group Anonymous Sudan a ‘bear in wolf’s clothing’
https://malware.news/t/hacktivist-group-anonymous-sudan-a-bear-in-wolf-s-clothing/70618#post_1
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
CISA (noun)
https://thecyberwire.com/podcasts/word-notes/153/notes
Finding the Nirvana of information access control or something like it
https://www.csoonline.com/article/3699397/finding-the-nirvana-of-information-access-control-or-something-like-it.html#tk.rss_all
US dangles $10 million reward for information about Cl0p ransomware gang
https://www.malwarebytes.com/blog/news/2023/06/rewards-up-to-10-million-for-information-about-cl0p-ransomware-operation
A week in security (June 12 - 18)
https://malware.news/t/a-week-in-security-june-12-18/70614#post_1
Expanding horizons—Microsoft Security’s continued commitment to multicloud
https://www.microsoft.com/en-us/security/blog/2023/06/14/expanding-horizons-microsoft-securitys-continued-commitment-to-multicloud/
ISC Stormcast For Tuesday, June 20th, 2023 https://isc.sans.edu/podcastdetail/8544, (Tue, Jun 20th)
https://malware.news/t/isc-stormcast-for-tuesday-june-20th-2023-https-isc-sans-edu-podcastdetail-8544-tue-jun-20th/70617#post_1
UK set to ramp up citizen surveillance program
https://malware.news/t/uk-set-to-ramp-up-citizen-surveillance-program/70620#post_1
8 notable entry-level cybersecurity career and skills initiatives in 2023
https://www.csoonline.com/article/3699668/8-notable-entry-level-cybersecurity-career-and-skills-initiatives-in-2023.html#tk.rss_all
EU member states are urged to restrict without delay 5G equipment from risky suppliers
https://securityaffairs.com/147617/laws-and-regulations/eu-restrict-5g-risky-suppliers.html
Hacktivist group Anonymous Sudan a ‘bear in wolf’s clothing’
https://malware.news/t/hacktivist-group-anonymous-sudan-a-bear-in-wolf-s-clothing/70618#post_1
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
N2K CyberWire
CISA (noun)
A US Department of Homeland Security agency tasked with supporting cyber and physical security for US critical infrastructure.
Top Security News for 21/06/2023
CISO stress levels are out of control
https://malware.news/t/ciso-stress-levels-are-out-of-control/70676#post_1
NEW 'Off The Wall' ONLINE
https://www.2600.com/wall/20-06-2023
Black Cat ransomware group wants $4.5m from Reddit or will leak stolen files
https://www.malwarebytes.com/blog/news/2023/06/black-cat-ransomware-group-wants-4-5m-from-reddit-or-will-leak-stolen-files
RedEyes Group Wiretapping Individuals (APT37)
https://malware.news/t/redeyes-group-wiretapping-individuals-apt37/70678#post_1
Western Digital blocks unpatched My Cloud devices
https://www.csoonline.com/article/3700050/western-digital-blocks-unpatched-my-cloud-devices.html#tk.rss_all
Leaking secrets through caching with Bunny CDN
https://www.reddit.com/r/netsec/comments/14edbp3/leaking_secrets_through_caching_with_bunny_cdn/
Reddit sees bad luck as a BlackCat attack crosses their path. The C2C market is more mystical nowadays. Hacktivist auxiliaries and false flags in the hybrid war.
https://thecyberwire.com/podcasts/daily-podcast/1847/notes
Keep it simple, Scanner
https://portswigger.net/blog/keep-it-simple-scanner
CYBER: Big Tech Wants You to Think AI Will Kill Us All
https://www.vice.com/en_us/article/wxjjay/cyber-big-tech-wants-you-to-think-ai-will-kill-us-all
Two US universities added to Cl0p's target list. The dangers of using public Wi-Fi.
https://thecyberwire.com/podcasts/privacy-briefing/852/notes
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
CISO stress levels are out of control
https://malware.news/t/ciso-stress-levels-are-out-of-control/70676#post_1
NEW 'Off The Wall' ONLINE
https://www.2600.com/wall/20-06-2023
Black Cat ransomware group wants $4.5m from Reddit or will leak stolen files
https://www.malwarebytes.com/blog/news/2023/06/black-cat-ransomware-group-wants-4-5m-from-reddit-or-will-leak-stolen-files
RedEyes Group Wiretapping Individuals (APT37)
https://malware.news/t/redeyes-group-wiretapping-individuals-apt37/70678#post_1
Western Digital blocks unpatched My Cloud devices
https://www.csoonline.com/article/3700050/western-digital-blocks-unpatched-my-cloud-devices.html#tk.rss_all
Leaking secrets through caching with Bunny CDN
https://www.reddit.com/r/netsec/comments/14edbp3/leaking_secrets_through_caching_with_bunny_cdn/
Reddit sees bad luck as a BlackCat attack crosses their path. The C2C market is more mystical nowadays. Hacktivist auxiliaries and false flags in the hybrid war.
https://thecyberwire.com/podcasts/daily-podcast/1847/notes
Keep it simple, Scanner
https://portswigger.net/blog/keep-it-simple-scanner
CYBER: Big Tech Wants You to Think AI Will Kill Us All
https://www.vice.com/en_us/article/wxjjay/cyber-big-tech-wants-you-to-think-ai-will-kill-us-all
Two US universities added to Cl0p's target list. The dangers of using public Wi-Fi.
https://thecyberwire.com/podcasts/privacy-briefing/852/notes
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Malware Analysis, News and Indicators
CISO stress levels are out of control
A recent survey gauging the mental well-being of CISOs revealed 94% suffer from work-related stress – here’s what to do about it. Article Link: CISO stress levels are out of control | SC Media
Top Security News for 22/06/2023
Using Threat Intelligence to Counter Ransomware
https://malware.news/t/using-threat-intelligence-to-counter-ransomware/70718#post_1
Targeting Core OPC UA Components
https://www.reddit.com/r/netsec/comments/14f7822/targeting_core_opc_ua_components/
Risky chat applications.
https://thecyberwire.com/podcasts/hacking-humans/248/notes
BrandPost: Reducing Cyber Risks by Upskilling Your Security Talent
https://www.csoonline.com/article/3700648/reducing-cyber-risks-by-upskilling-your-security-talent.html#tk.rss_all
Apple patches exploited zero-days
https://malware.news/t/apple-patches-exploited-zero-days/70719#post_1
Android Malware on the Rise – A case study of AhMyth RAT
https://www.reddit.com/r/netsec/comments/14f8ix2/android_malware_on_the_rise_a_case_study_of/
GitHub Dataset Reveals Millions Potentially Vulnerable to RepoJacking
https://www.reddit.com/r/netsec/comments/14famln/github_dataset_reveals_millions_potentially/
extsyncrequest.com unknown
https://www.reddit.com/r/Malware/comments/14fh6ig/extsyncrequestcom_unknown/
ScarCruft Hackers Exploit Ably Service for Stealthy Wiretapping Attacks
https://thehackernews.com/2023/06/scarcruft-hackers-exploit-ably-service.html
Alert! Hackers Exploiting Critical Vulnerability in VMware's Aria Operations Networks
https://thehackernews.com/2023/06/alert-hackers-exploiting-critical.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Using Threat Intelligence to Counter Ransomware
https://malware.news/t/using-threat-intelligence-to-counter-ransomware/70718#post_1
Targeting Core OPC UA Components
https://www.reddit.com/r/netsec/comments/14f7822/targeting_core_opc_ua_components/
Risky chat applications.
https://thecyberwire.com/podcasts/hacking-humans/248/notes
BrandPost: Reducing Cyber Risks by Upskilling Your Security Talent
https://www.csoonline.com/article/3700648/reducing-cyber-risks-by-upskilling-your-security-talent.html#tk.rss_all
Apple patches exploited zero-days
https://malware.news/t/apple-patches-exploited-zero-days/70719#post_1
Android Malware on the Rise – A case study of AhMyth RAT
https://www.reddit.com/r/netsec/comments/14f8ix2/android_malware_on_the_rise_a_case_study_of/
GitHub Dataset Reveals Millions Potentially Vulnerable to RepoJacking
https://www.reddit.com/r/netsec/comments/14famln/github_dataset_reveals_millions_potentially/
extsyncrequest.com unknown
https://www.reddit.com/r/Malware/comments/14fh6ig/extsyncrequestcom_unknown/
ScarCruft Hackers Exploit Ably Service for Stealthy Wiretapping Attacks
https://thehackernews.com/2023/06/scarcruft-hackers-exploit-ably-service.html
Alert! Hackers Exploiting Critical Vulnerability in VMware's Aria Operations Networks
https://thehackernews.com/2023/06/alert-hackers-exploiting-critical.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Malware Analysis, News and Indicators
Using Threat Intelligence to Counter Ransomware
Although ransomware groups appear to strike suddenly with impunity, effective use of threat intelligence can result in early warning to avoid infections. Article Link: https://intel471.com/blog/using-threat-intelligence-to-counter-ransomware
Top Security News for 23/06/2023
Secfault Security - LibreOffice Arbitrary File Write (CVE-2023-1883)
https://www.reddit.com/r/netsec/comments/14fwsfz/secfault_security_libreoffice_arbitrary_file/
Apple Patches Exploited Vulnerabilities in iOS/iPadOS, macOS, watchOS and Safari, (Thu, Jun 22nd)
https://isc.sans.edu/diary/rss/29972
UPS warns customers of phishing attempts after data accessed
https://www.malwarebytes.com/blog/news/2023/06/ups-warns-customers-of-phishing-attempts-after-data-accessed
Hybrid Microsoft network/cloud legacy settings may impact your future security posture
https://www.csoonline.com/article/3700529/hybrid-microsoft-network-cloud-legacy-settings-may-impact-your-future-security-posture.html#tk.rss_all
Word Document with an Online Attached Template, (Fri, Jun 23rd)
https://isc.sans.edu/diary/rss/29976
Callisto - Automated Binary Vulnerability Discovery Tool
https://www.reddit.com/r/netsec/comments/14fvrzh/callisto_automated_binary_vulnerability_discovery/
Reducing your attack surface is more effective than playing patch-a-mole
https://www.malwarebytes.com/blog/news/2023/06/reducing-your-attack-surface-is-more-effective-than-playing-patch-a-mole
6 tips for a cybersecure honeymoon
https://www.malwarebytes.com/blog/personal/2023/06/6-tips-for-a-cybersecure-honeymoon
Need Help Identifying this Malware
https://www.reddit.com/r/Malware/comments/14em9zf/need_help_identifying_this_malware/
Malwarebytes only vendor to win every MRG Effitas award in 2022 & 2023
https://www.malwarebytes.com/blog/business/2023/06/malwarebytes-only-vendor-to-win-every-mrg-effitas-certification-award-in-2022
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Secfault Security - LibreOffice Arbitrary File Write (CVE-2023-1883)
https://www.reddit.com/r/netsec/comments/14fwsfz/secfault_security_libreoffice_arbitrary_file/
Apple Patches Exploited Vulnerabilities in iOS/iPadOS, macOS, watchOS and Safari, (Thu, Jun 22nd)
https://isc.sans.edu/diary/rss/29972
UPS warns customers of phishing attempts after data accessed
https://www.malwarebytes.com/blog/news/2023/06/ups-warns-customers-of-phishing-attempts-after-data-accessed
Hybrid Microsoft network/cloud legacy settings may impact your future security posture
https://www.csoonline.com/article/3700529/hybrid-microsoft-network-cloud-legacy-settings-may-impact-your-future-security-posture.html#tk.rss_all
Word Document with an Online Attached Template, (Fri, Jun 23rd)
https://isc.sans.edu/diary/rss/29976
Callisto - Automated Binary Vulnerability Discovery Tool
https://www.reddit.com/r/netsec/comments/14fvrzh/callisto_automated_binary_vulnerability_discovery/
Reducing your attack surface is more effective than playing patch-a-mole
https://www.malwarebytes.com/blog/news/2023/06/reducing-your-attack-surface-is-more-effective-than-playing-patch-a-mole
6 tips for a cybersecure honeymoon
https://www.malwarebytes.com/blog/personal/2023/06/6-tips-for-a-cybersecure-honeymoon
Need Help Identifying this Malware
https://www.reddit.com/r/Malware/comments/14em9zf/need_help_identifying_this_malware/
Malwarebytes only vendor to win every MRG Effitas award in 2022 & 2023
https://www.malwarebytes.com/blog/business/2023/06/malwarebytes-only-vendor-to-win-every-mrg-effitas-certification-award-in-2022
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Reddit
r/netsec on Reddit: Secfault Security - LibreOffice Arbitrary File Write (CVE-2023-1883)
Posted by u/Xadartt - No votes and no comments
Top Security News for 24/06/2023
US, India subjected to phishing attacks with RATs
https://malware.news/t/us-india-subjected-to-phishing-attacks-with-rats/70807#post_1
Fortinet fixes critical RCE flaw in FortiNAC zero-trust product
https://malware.news/t/fortinet-fixes-critical-rce-flaw-in-fortinac-zero-trust-product/70806#post_1
Emergency review of Japan's My Number cards. CalPERS and CalSTRS hit by third-party MOVEit breach. Extortionists threaten to expose plastic surgery photos.
https://thecyberwire.com/newsletters/privacy-briefing/5/120
JavaScript Dropper Delivers Bumblebee And IcedID Malware
https://packetstormsecurity.com/news/view/34748/JavaScript-Dropper-Delivers-Bumblebee-And-IcedID-Malware.html
A brief summary about a SSTI to RCE in Bagisto
https://www.reddit.com/r/netsec/comments/14gvrkp/a_brief_summary_about_a_ssti_to_rce_in_bagisto/
VMware fixed five memory corruption issues in vCenter Server
https://securityaffairs.com/147774/hacking/vmware-vcenter-server-memory-corruption-bugs.html
New Cryptocurrency Mining Campaign Targets Linux Systems and IoT Devices
https://thehackernews.com/2023/06/new-cryptocurrency-mining-campaign.html
The Week that Was: 6.24.23
https://thecyberwire.com/newsletters/week-that-was/7/24
Powerful JavaScript Dropper PindOS Distributes Bumblebee and IcedID Malware
https://thehackernews.com/2023/06/powerful-javascript-dropper-pindos.html
Karen Worstell from VMware discusses technical debt.
https://thecyberwire.com/podcasts/interview-selects/164/notes
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
US, India subjected to phishing attacks with RATs
https://malware.news/t/us-india-subjected-to-phishing-attacks-with-rats/70807#post_1
Fortinet fixes critical RCE flaw in FortiNAC zero-trust product
https://malware.news/t/fortinet-fixes-critical-rce-flaw-in-fortinac-zero-trust-product/70806#post_1
Emergency review of Japan's My Number cards. CalPERS and CalSTRS hit by third-party MOVEit breach. Extortionists threaten to expose plastic surgery photos.
https://thecyberwire.com/newsletters/privacy-briefing/5/120
JavaScript Dropper Delivers Bumblebee And IcedID Malware
https://packetstormsecurity.com/news/view/34748/JavaScript-Dropper-Delivers-Bumblebee-And-IcedID-Malware.html
A brief summary about a SSTI to RCE in Bagisto
https://www.reddit.com/r/netsec/comments/14gvrkp/a_brief_summary_about_a_ssti_to_rce_in_bagisto/
VMware fixed five memory corruption issues in vCenter Server
https://securityaffairs.com/147774/hacking/vmware-vcenter-server-memory-corruption-bugs.html
New Cryptocurrency Mining Campaign Targets Linux Systems and IoT Devices
https://thehackernews.com/2023/06/new-cryptocurrency-mining-campaign.html
The Week that Was: 6.24.23
https://thecyberwire.com/newsletters/week-that-was/7/24
Powerful JavaScript Dropper PindOS Distributes Bumblebee and IcedID Malware
https://thehackernews.com/2023/06/powerful-javascript-dropper-pindos.html
Karen Worstell from VMware discusses technical debt.
https://thecyberwire.com/podcasts/interview-selects/164/notes
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Malware Analysis, News and Indicators
US, India subjected to phishing attacks with RATs
U.S.- and India-based organizations have been targeted by the new MULTI#STORM phishing campaign that involved a multi-stage attack chain concluding with the deployment of Warzone RAT, also known as Ave Maria, Quasar RAT, and various other remote access trojan…
Top Security News for 25/06/2023
Someone is sending mysterious smartwatches to the US Military personnel
https://securityaffairs.com/147788/intelligence/unsolicited-smartwatches-us-army.html
Email Spam with Attachment Modiloader, (Sat, Jun 24th)
https://malware.news/t/email-spam-with-attachment-modiloader-sat-jun-24th/70813#post_1
DFIR Core Principles
https://malware.news/t/dfir-core-principles/70812#post_1
Ukraine at D+485: “We are dying for the Russian people.”
https://thecyberwire.com/stories/bf07fd1eec87497a88e1a7704c42bce6/ukraine-at-d487
Slavik Markovich: Time is of the essence. [CEO]
https://thecyberwire.com/podcasts/career-notes/155/notes
Twitter Hacker Sentenced to 5 Years in Prison for $120,000 Crypto Scam
https://thehackernews.com/2023/06/twitter-hacker-sentenced-to-5-years-in.html
Google pledges $20M for cyber clinic expansion
https://malware.news/t/google-pledges-20m-for-cyber-clinic-expansion/70810#post_1
NYC DOE Hacked.
https://www.reddit.com/r/Malware/comments/14i6eab/nyc_doe_hacked/
Email Spam with Attachment Modiloader, (Sat, Jun 24th)
https://isc.sans.edu/diary/rss/29978
U.S. Cybersecurity Agency Adds 6 Flaws to Known Exploited Vulnerabilities Catalog
https://thehackernews.com/2023/06/us-cybersecurity-agency-adds-6-flaws-to.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Someone is sending mysterious smartwatches to the US Military personnel
https://securityaffairs.com/147788/intelligence/unsolicited-smartwatches-us-army.html
Email Spam with Attachment Modiloader, (Sat, Jun 24th)
https://malware.news/t/email-spam-with-attachment-modiloader-sat-jun-24th/70813#post_1
DFIR Core Principles
https://malware.news/t/dfir-core-principles/70812#post_1
Ukraine at D+485: “We are dying for the Russian people.”
https://thecyberwire.com/stories/bf07fd1eec87497a88e1a7704c42bce6/ukraine-at-d487
Slavik Markovich: Time is of the essence. [CEO]
https://thecyberwire.com/podcasts/career-notes/155/notes
Twitter Hacker Sentenced to 5 Years in Prison for $120,000 Crypto Scam
https://thehackernews.com/2023/06/twitter-hacker-sentenced-to-5-years-in.html
Google pledges $20M for cyber clinic expansion
https://malware.news/t/google-pledges-20m-for-cyber-clinic-expansion/70810#post_1
NYC DOE Hacked.
https://www.reddit.com/r/Malware/comments/14i6eab/nyc_doe_hacked/
Email Spam with Attachment Modiloader, (Sat, Jun 24th)
https://isc.sans.edu/diary/rss/29978
U.S. Cybersecurity Agency Adds 6 Flaws to Known Exploited Vulnerabilities Catalog
https://thehackernews.com/2023/06/us-cybersecurity-agency-adds-6-flaws-to.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Security Affairs
Someone is sending mysterious smartwatches to the US Military personnel
U.S. Army’s Criminal Investigation Division warns that US military personnel have reported receiving unsolicited smartwatches in the mail.
❤1
Top Security News for 26/06/2023
Cybersecurity Is a Social, Policy, and Wicked Problem
https://taosecurity.blogspot.com/2023/06/cybersecurity-is-social-policy-and.html
Security Affairs newsletter Round 425 by Pierluigi Paganini – International edition
https://securityaffairs.com/147797/breaking-news/security-affairs-newsletter-round-425-by-pierluigi-paganini-international-edition.html
Ukraine at D+486: The march on Moscow is over.
https://thecyberwire.com/stories/8de9e9d7525146818e428fcc90c3f1fe/ukraine-at-d486
BSides Athens 2023 Wrap-Up
https://blog.rootshell.be/2023/06/25/bsides-athens-2023-wrap-up/
Bejtlich Skills and Interest Radar from July 2005
https://taosecurity.blogspot.com/2023/06/bejtlich-skills-and-interest-radar-from.html
Five ways to get the board to think more seriously about OT security
https://malware.news/t/five-ways-to-get-the-board-to-think-more-seriously-about-ot-security/70817#post_1
ISC StormCast for Monday, June 26th, 2023
https://isc.sans.edu/podcastdetail/8550
My Last Email with W. Richard Stevens
https://taosecurity.blogspot.com/2023/06/my-last-email-with-w-richard-stevens.html
HWL Ebsworth hack: sensitive information from dozens of government agencies may be compromised
https://www.theguardian.com/australia-news/2023/jun/26/hwl-ebsworth-hack-sensitive-information-from-dozens-of-government-agencies-may-be-compromised
Core Writing Word and Page Counts
https://taosecurity.blogspot.com/2023/06/core-writing-word-and-page-counts.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Cybersecurity Is a Social, Policy, and Wicked Problem
https://taosecurity.blogspot.com/2023/06/cybersecurity-is-social-policy-and.html
Security Affairs newsletter Round 425 by Pierluigi Paganini – International edition
https://securityaffairs.com/147797/breaking-news/security-affairs-newsletter-round-425-by-pierluigi-paganini-international-edition.html
Ukraine at D+486: The march on Moscow is over.
https://thecyberwire.com/stories/8de9e9d7525146818e428fcc90c3f1fe/ukraine-at-d486
BSides Athens 2023 Wrap-Up
https://blog.rootshell.be/2023/06/25/bsides-athens-2023-wrap-up/
Bejtlich Skills and Interest Radar from July 2005
https://taosecurity.blogspot.com/2023/06/bejtlich-skills-and-interest-radar-from.html
Five ways to get the board to think more seriously about OT security
https://malware.news/t/five-ways-to-get-the-board-to-think-more-seriously-about-ot-security/70817#post_1
ISC StormCast for Monday, June 26th, 2023
https://isc.sans.edu/podcastdetail/8550
My Last Email with W. Richard Stevens
https://taosecurity.blogspot.com/2023/06/my-last-email-with-w-richard-stevens.html
HWL Ebsworth hack: sensitive information from dozens of government agencies may be compromised
https://www.theguardian.com/australia-news/2023/jun/26/hwl-ebsworth-hack-sensitive-information-from-dozens-of-government-agencies-may-be-compromised
Core Writing Word and Page Counts
https://taosecurity.blogspot.com/2023/06/core-writing-word-and-page-counts.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Blogspot
Cybersecurity Is a Social, Policy, and Wicked Problem
Richard Bejtlich's blog on digital security, strategic thought, and military history.
Top Security News for 27/06/2023
How CISOs can balance the risks and benefits of AI
https://www.csoonline.com/article/3700152/the-challenge-of-balancing-risks-and-benefits-of-ai-for-cisos.html#tk.rss_all
OpenSSH trojan campaign targets Linux systems and IoT devices
https://www.malwarebytes.com/blog/news/2023/06/openssh-trojan-campaign-targets-linux-systems-and-iot-devices
All About PowerShell Attacks: The No. 1 ATT&CK Technique
https://securityintelligence.com/articles/all-about-powershell-attacks/
2023-06-23 - 30 days of Formbook: Day 19, Friday 2023-06-23 - "P1A4"
https://malware.news/t/2023-06-23-30-days-of-formbook-day-19-friday-2023-06-23-p1a4/70854#post_1
The Importance of Malware Triage, (Tue, Jun 27th)
https://malware.news/t/the-importance-of-malware-triage-tue-jun-27th/70857#post_1
How cybercrime is impacting SMBs in 2023
https://securelist.com/smb-threat-report-2023/110097/
How Generative AI Can Dupe SaaS Authentication Protocols — And Effective Ways To Prevent Other Key AI Risks in SaaS
https://thehackernews.com/2023/06/how-generative-ai-can-dupe-saas.html
9 basic security tips for seniors
https://www.malwarebytes.com/blog/news/2023/06/9-basic-security-tips-for-seniors
The Importance of Malware Triage, (Tue, Jun 27th)
https://isc.sans.edu/diary/rss/29984
BrandPost: What is the key to optimized DevSecOps?
https://www.csoonline.com/article/3700611/what-is-the-key-to-optimized-devsecops.html#tk.rss_all
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
How CISOs can balance the risks and benefits of AI
https://www.csoonline.com/article/3700152/the-challenge-of-balancing-risks-and-benefits-of-ai-for-cisos.html#tk.rss_all
OpenSSH trojan campaign targets Linux systems and IoT devices
https://www.malwarebytes.com/blog/news/2023/06/openssh-trojan-campaign-targets-linux-systems-and-iot-devices
All About PowerShell Attacks: The No. 1 ATT&CK Technique
https://securityintelligence.com/articles/all-about-powershell-attacks/
2023-06-23 - 30 days of Formbook: Day 19, Friday 2023-06-23 - "P1A4"
https://malware.news/t/2023-06-23-30-days-of-formbook-day-19-friday-2023-06-23-p1a4/70854#post_1
The Importance of Malware Triage, (Tue, Jun 27th)
https://malware.news/t/the-importance-of-malware-triage-tue-jun-27th/70857#post_1
How cybercrime is impacting SMBs in 2023
https://securelist.com/smb-threat-report-2023/110097/
How Generative AI Can Dupe SaaS Authentication Protocols — And Effective Ways To Prevent Other Key AI Risks in SaaS
https://thehackernews.com/2023/06/how-generative-ai-can-dupe-saas.html
9 basic security tips for seniors
https://www.malwarebytes.com/blog/news/2023/06/9-basic-security-tips-for-seniors
The Importance of Malware Triage, (Tue, Jun 27th)
https://isc.sans.edu/diary/rss/29984
BrandPost: What is the key to optimized DevSecOps?
https://www.csoonline.com/article/3700611/what-is-the-key-to-optimized-devsecops.html#tk.rss_all
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
CSO
How CISOs can balance the risks and benefits of AI
Rapid growth and development of AI is pushing the limits of cybersecurity and CISOs must take charge now to be ahead of a range of risks including data leak, compliance and prompt injection attacks.
Top Security News for 28/06/2023
Mockingjay process injection technique allows EDR bypass
https://securityaffairs.com/147887/hacking/mockingjay-process-injection-technique.html
Why endpoint management is key to securing an AI-powered future
https://www.microsoft.com/en-us/security/blog/2023/06/26/why-endpoint-management-is-key-to-securing-an-ai-powered-future/
New Mockingjay Process Injection Technique Could Let Malware Evade Detection
https://thehackernews.com/2023/06/new-mockingjay-process-injection.html
Time and Expectations
https://dale-peterson.com/2023/06/27/time-and-expectations/?utm_source=rss&utm_medium=rss&utm_campaign=time-and-expectations
Securing the Store of the Future & Intel Briefing
https://thecyberwire.com/podcasts/rh-isac/30/notes
ISC StormCast for Wednesday, June 28th, 2023
https://isc.sans.edu/podcastdetail/8554
Survey reveals mass concern over generative AI security risks
https://www.csoonline.com/article/3700613/survey-reveals-mass-concern-over-generative-ai-security-risks.html#tk.rss_all
Siemens Energy, UCLA Latest Confirmed Victims In MOVEit Hack
https://packetstormsecurity.com/news/view/34756/Siemens-Energy-UCLA-Latest-Confirmed-Victims-In-MOVEit-Hack.html
SupremeBot and Mario cross the finish line together
https://www.malwarebytes.com/blog/news/2023/06/supremebot-and-mario-cross-the-finish-line-together
Prominent Cryptocurrency Exchange Infected With Previously Unseen Mac Malware
https://packetstormsecurity.com/news/view/34757/Prominent-Cryptocurrency-Exchange-Infected-With-Previously-Unseen-Mac-Malware.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Mockingjay process injection technique allows EDR bypass
https://securityaffairs.com/147887/hacking/mockingjay-process-injection-technique.html
Why endpoint management is key to securing an AI-powered future
https://www.microsoft.com/en-us/security/blog/2023/06/26/why-endpoint-management-is-key-to-securing-an-ai-powered-future/
New Mockingjay Process Injection Technique Could Let Malware Evade Detection
https://thehackernews.com/2023/06/new-mockingjay-process-injection.html
Time and Expectations
https://dale-peterson.com/2023/06/27/time-and-expectations/?utm_source=rss&utm_medium=rss&utm_campaign=time-and-expectations
Securing the Store of the Future & Intel Briefing
https://thecyberwire.com/podcasts/rh-isac/30/notes
ISC StormCast for Wednesday, June 28th, 2023
https://isc.sans.edu/podcastdetail/8554
Survey reveals mass concern over generative AI security risks
https://www.csoonline.com/article/3700613/survey-reveals-mass-concern-over-generative-ai-security-risks.html#tk.rss_all
Siemens Energy, UCLA Latest Confirmed Victims In MOVEit Hack
https://packetstormsecurity.com/news/view/34756/Siemens-Energy-UCLA-Latest-Confirmed-Victims-In-MOVEit-Hack.html
SupremeBot and Mario cross the finish line together
https://www.malwarebytes.com/blog/news/2023/06/supremebot-and-mario-cross-the-finish-line-together
Prominent Cryptocurrency Exchange Infected With Previously Unseen Mac Malware
https://packetstormsecurity.com/news/view/34757/Prominent-Cryptocurrency-Exchange-Infected-With-Previously-Unseen-Mac-Malware.html
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Security Affairs
Mockingjay process injection technique allows EDR bypass
Mockingjay is a new process injection technique that can be exploited to bypass security solutions to execute malware on compromised systems.
Top Security News for 29/06/2023
Andariel’s silly mistakes and a new malware family
https://securelist.com/lazarus-andariel-mistakes-and-easyrat/110119/
The spy becomes the spied-upon. Genworth Financial suffers third-party data breach. Siemens and UCLA become latest victims of MOVEit bug.
https://thecyberwire.com/podcasts/privacy-briefing/858/notes
8Base Ransomware Spikes in Activity, Threatens U.S. and Brazilian Businesses
https://thehackernews.com/2023/06/8base-ransomware-spikes-in-activity.html
Critical cyber threats persist on federal networks despite recent directives
https://malware.news/t/critical-cyber-threats-persist-on-federal-networks-despite-recent-directives/70936#post_1
Critical SQL Injection Flaws Expose Gentoo Soko to Remote Code Execution
https://thehackernews.com/2023/06/critical-sql-injection-flaws-expose.html
A Software Bill of Materials Helps Secure Your Supply Chain
https://securityintelligence.com/posts/a-software-bill-of-materials-helps-secure-your-supply-chain/
Alert: New Electromagnetic Attacks on Drones Could Let Attackers Take Control
https://thehackernews.com/2023/06/alert-new-electromagnetic-attacks-on.html
Log-in lookout: Verosint CTO details how adaptive identity proofing curbs account fraud
https://malware.news/t/log-in-lookout-verosint-cto-details-how-adaptive-identity-proofing-curbs-account-fraud/70935#post_1
Andariel’s silly mistakes and a new malware family
https://securelist.com/lazarus-andariel-mistakes-and-easyrat/110119/
High-severity Chrome vulnerabilities addressed
https://malware.news/t/high-severity-chrome-vulnerabilities-addressed/70932#post_1
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Andariel’s silly mistakes and a new malware family
https://securelist.com/lazarus-andariel-mistakes-and-easyrat/110119/
The spy becomes the spied-upon. Genworth Financial suffers third-party data breach. Siemens and UCLA become latest victims of MOVEit bug.
https://thecyberwire.com/podcasts/privacy-briefing/858/notes
8Base Ransomware Spikes in Activity, Threatens U.S. and Brazilian Businesses
https://thehackernews.com/2023/06/8base-ransomware-spikes-in-activity.html
Critical cyber threats persist on federal networks despite recent directives
https://malware.news/t/critical-cyber-threats-persist-on-federal-networks-despite-recent-directives/70936#post_1
Critical SQL Injection Flaws Expose Gentoo Soko to Remote Code Execution
https://thehackernews.com/2023/06/critical-sql-injection-flaws-expose.html
A Software Bill of Materials Helps Secure Your Supply Chain
https://securityintelligence.com/posts/a-software-bill-of-materials-helps-secure-your-supply-chain/
Alert: New Electromagnetic Attacks on Drones Could Let Attackers Take Control
https://thehackernews.com/2023/06/alert-new-electromagnetic-attacks-on.html
Log-in lookout: Verosint CTO details how adaptive identity proofing curbs account fraud
https://malware.news/t/log-in-lookout-verosint-cto-details-how-adaptive-identity-proofing-curbs-account-fraud/70935#post_1
Andariel’s silly mistakes and a new malware family
https://securelist.com/lazarus-andariel-mistakes-and-easyrat/110119/
High-severity Chrome vulnerabilities addressed
https://malware.news/t/high-severity-chrome-vulnerabilities-addressed/70932#post_1
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Securelist
Kaspersky crimeware report: Andariel’s mistakes and EasyRat malware
In this crimeware report, Kaspersky researchers provide insights into Andariel’s activity targeting organizations: clumsy commands executed manually, off-the-shelf tools and EasyRat malware.
👍1
Top Security News for 30/06/2023
Log Centralization: The End Is Nigh?
https://medium.com/anton-on-security/log-centralization-the-end-is-nigh-b28efaa98379?source=rss----8e8c3ed26c4c---4
Top contenders in Endpoint Security revealed: G2 Summer 2023 results
https://www.malwarebytes.com/blog/business/2023/06/top-contenders-in-endpoint-security-revealed-g2-summer-2023-results
Malware Execution Method Using DNS TXT Record
https://malware.news/t/malware-execution-method-using-dns-txt-record/70981#post_1
2023-06-29 - 30 days of Formbook: Day 25, Thursday 2023-06-29 - "CS94"
https://malware.news/t/2023-06-29-30-days-of-formbook-day-25-thursday-2023-06-29-cs94/70978#post_1
Hacking Auto-GPT and escaping its docker container
https://www.reddit.com/r/netsec/comments/14m6uv9/hacking_autogpt_and_escaping_its_docker_container/
Webcrawlers copying my site
https://0x00sec.org/t/webcrawlers-copying-my-site/35803
New developments in the ransomware threat. Lazarus needs some AI? Charming Kitten spearphishes. Updates from the hybrid war.
https://thecyberwire.com/newsletters/daily-briefing/12/124
ISC Stormcast For Friday, June 30th, 2023 https://isc.sans.edu/podcastdetail/8558, (Fri, Jun 30th)
https://isc.sans.edu/diary/rss/29996
NoMoreCookies: Protection against stealers/rats
https://www.reddit.com/r/netsec/comments/14mmkok/nomorecookies_protection_against_stealersrats/
Discover the Power of OSINT: 350+ Integrated Tools for Passive Online Investigation and Analysis
https://www.reddit.com/r/netsec/comments/14lwi38/discover_the_power_of_osint_350_integrated_tools/
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Log Centralization: The End Is Nigh?
https://medium.com/anton-on-security/log-centralization-the-end-is-nigh-b28efaa98379?source=rss----8e8c3ed26c4c---4
Top contenders in Endpoint Security revealed: G2 Summer 2023 results
https://www.malwarebytes.com/blog/business/2023/06/top-contenders-in-endpoint-security-revealed-g2-summer-2023-results
Malware Execution Method Using DNS TXT Record
https://malware.news/t/malware-execution-method-using-dns-txt-record/70981#post_1
2023-06-29 - 30 days of Formbook: Day 25, Thursday 2023-06-29 - "CS94"
https://malware.news/t/2023-06-29-30-days-of-formbook-day-25-thursday-2023-06-29-cs94/70978#post_1
Hacking Auto-GPT and escaping its docker container
https://www.reddit.com/r/netsec/comments/14m6uv9/hacking_autogpt_and_escaping_its_docker_container/
Webcrawlers copying my site
https://0x00sec.org/t/webcrawlers-copying-my-site/35803
New developments in the ransomware threat. Lazarus needs some AI? Charming Kitten spearphishes. Updates from the hybrid war.
https://thecyberwire.com/newsletters/daily-briefing/12/124
ISC Stormcast For Friday, June 30th, 2023 https://isc.sans.edu/podcastdetail/8558, (Fri, Jun 30th)
https://isc.sans.edu/diary/rss/29996
NoMoreCookies: Protection against stealers/rats
https://www.reddit.com/r/netsec/comments/14mmkok/nomorecookies_protection_against_stealersrats/
Discover the Power of OSINT: 350+ Integrated Tools for Passive Online Investigation and Analysis
https://www.reddit.com/r/netsec/comments/14lwi38/discover_the_power_of_osint_350_integrated_tools/
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
Medium
Log Centralization: The End Is Nigh?
So I woke up the other day [A.C. — well, the other year as this blog has lingered] with the scary thought: what if we will run out of the…
Top Security News for 01/07/2023
The Week that Was: Vulcan’s Q2 2023 Vulnerability Watch report details notable issues. Russia's hybrid war against Ukraine: lessons learned.
https://thecyberwire.com/newsletters/week-that-was/7/25
Manoj Sharma of Symantec to discuss trends he's hearing about generative AI.
https://thecyberwire.com/podcasts/interview-selects/165/notes
OpenAI faces lawsuit for scraping of internet data. Study shows 25% of kids apps violate COPPA. UoM attack reportedly exposed over one million NHS patients.
https://thecyberwire.com/newsletters/privacy-briefing/5/125
Reversing Citrix Gateway for XSS
https://www.reddit.com/r/netsec/comments/14n28jb/reversing_citrix_gateway_for_xss/
Sandfly Security, (Sat, Jul 1st)
https://malware.news/t/sandfly-security-sat-jul-1st/71013#post_1
Beware: New 'Rustbucket' Malware Variant Targeting macOS Users
https://thehackernews.com/2023/07/beware-new-rustbucket-malware-variant.html
3 Reasons SaaS Security is the Imperative First Step to Ensuring Secure AI Usage
https://thehackernews.com/2023/06/3-reasons-saas-security-is-imperative.html
Sandfly Security, (Sat, Jul 1st)
https://isc.sans.edu/diary/rss/29998
"Free" Evil Dead Rise movie scam lurks in Amazon listings
https://www.malwarebytes.com/blog/news/2023/06/free-evil-dead-rise-movie-scam-lurks-in-amazon-listings
Most fucked up redirect
https://www.reddit.com/r/Malware/comments/14ng7df/most_fucked_up_redirect/
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
The Week that Was: Vulcan’s Q2 2023 Vulnerability Watch report details notable issues. Russia's hybrid war against Ukraine: lessons learned.
https://thecyberwire.com/newsletters/week-that-was/7/25
Manoj Sharma of Symantec to discuss trends he's hearing about generative AI.
https://thecyberwire.com/podcasts/interview-selects/165/notes
OpenAI faces lawsuit for scraping of internet data. Study shows 25% of kids apps violate COPPA. UoM attack reportedly exposed over one million NHS patients.
https://thecyberwire.com/newsletters/privacy-briefing/5/125
Reversing Citrix Gateway for XSS
https://www.reddit.com/r/netsec/comments/14n28jb/reversing_citrix_gateway_for_xss/
Sandfly Security, (Sat, Jul 1st)
https://malware.news/t/sandfly-security-sat-jul-1st/71013#post_1
Beware: New 'Rustbucket' Malware Variant Targeting macOS Users
https://thehackernews.com/2023/07/beware-new-rustbucket-malware-variant.html
3 Reasons SaaS Security is the Imperative First Step to Ensuring Secure AI Usage
https://thehackernews.com/2023/06/3-reasons-saas-security-is-imperative.html
Sandfly Security, (Sat, Jul 1st)
https://isc.sans.edu/diary/rss/29998
"Free" Evil Dead Rise movie scam lurks in Amazon listings
https://www.malwarebytes.com/blog/news/2023/06/free-evil-dead-rise-movie-scam-lurks-in-amazon-listings
Most fucked up redirect
https://www.reddit.com/r/Malware/comments/14ng7df/most_fucked_up_redirect/
Follow Top Cyber News at https://t.me/TopCyberTechNews
Feel free to DM me at https://twitter.com/ShayaFeedman
The CyberWire
The Week that Was: Vulcan’s Q2 2023 Vulnerability Watch report details notable issues. Russia's hybrid war against Ukraine: lessons…
Vulcan’s Q2 2023 Vulnerability Watch report details notable issues. Russia's hybrid war against Ukraine: lessons learned. The fracturing of Conti, and the rise of its successors. Canadian energy company SUNCOR reports a cyberattack. Report: Unauthorized access…