■□□□□ Indian local news site taken down by Indonesian hackers. The attack is part on ongoing cyber activity against anti-muslim state.
https://swarajtv24.com/
Information shared via Telegram channel of 'Hacktivist Indonesia'
https://swarajtv24.com/
Information shared via Telegram channel of 'Hacktivist Indonesia'
Forwarded from cKure Red
CVE-2022-3723_PoC.js
668 B
CVE-2022-3723 Exploit PoC: Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
● @ckure has not verified the authenticity of the exploit.
● @ckure has not verified the authenticity of the exploit.
■■■□□ GitLab asks users to update critical flaw.
https://www.bleepingcomputer.com/news/security/gitlab-strongly-recommends-patching-max-severity-flaw-asap/
https://www.bleepingcomputer.com/news/security/gitlab-strongly-recommends-patching-max-severity-flaw-asap/
BleepingComputer
GitLab 'strongly recommends' patching max severity flaw ASAP
GitLab has released an emergency security update, version 16.0.1, to address a maximum severity (CVSS v3.1 score: 10.0) path traversal flaw tracked as CVE-2023-2825.
■■□□□ Massive Cyber Attack on UAE Banking Sector: Mysterious Team Bangladesh Claims to Hit First Abu Dhabi Bank.
Attack type: Distributed Denial of Service
https://thecyberexpress.com/cyber-attack-on-uae-banking-sector-adcb-nbf/amp/
Attack type: Distributed Denial of Service
https://thecyberexpress.com/cyber-attack-on-uae-banking-sector-adcb-nbf/amp/
The Cyber Express
Cyber Attack On UAE Banking Sector: ADCB, NBF Websites Hit
Cyber attack on UAE banking sector continues, with hacker group Mysterious Team Bangladesh claiming to take down ADCB and NBF websites
cKure
■■□□□ Massive Cyber Attack on UAE Banking Sector: Mysterious Team Bangladesh Claims to Hit First Abu Dhabi Bank. Attack type: Distributed Denial of Service https://thecyberexpress.com/cyber-attack-on-uae-banking-sector-adcb-nbf/amp/
■■□□□ UAE (opUAE update): ENOC services down as Sudan based hackers target the country.
Redeeming points via Yes app (owned by ENOC) disabled amid attacks.
Redeeming points via Yes app (owned by ENOC) disabled amid attacks.
■■□□□ Impacket Cheatsheet For Penetration Testers
Attribution link.
https://latesthackingnews.com/2023/05/22/impacket-cheatsheet-for-penetration-testers/
https://latesthackingnews.com/2023/05/22/impacket-cheatsheet-for-penetration-testers/
Attribution link.
https://latesthackingnews.com/2023/05/22/impacket-cheatsheet-for-penetration-testers/
https://latesthackingnews.com/2023/05/22/impacket-cheatsheet-for-penetration-testers/
LHN
Impacket Cheatsheet For Penetration Testers
Discover the power of Impacket, an incredibly versatile collection of Python classes for working with network protocols. In this Impacket cheatsheet, we will dive into some of the most essential command examples, outlining their functionalities
Forwarded from cKure Red
⚠️ ‘Despicable’ iPhone Hacks In Armenia Find NSO Spyware ‘In Active Warzone’.
For the first time, the Israeli company’s spyware has been used in a conflict zone, according to researchers.
In mid-2021, Apple sent a warning to Anna Naghdalyan, then a spokesperson for Armenia’s foreign affairs agency, that her iPhone had possibly been hacked by a foreign government.
https://www.forbes.com/sites/thomasbrewster/2023/05/25/iphone-hacks-in-armenia-show-nso-spyware-in-warzone/?sh=4b76625f1a56
For the first time, the Israeli company’s spyware has been used in a conflict zone, according to researchers.
In mid-2021, Apple sent a warning to Anna Naghdalyan, then a spokesperson for Armenia’s foreign affairs agency, that her iPhone had possibly been hacked by a foreign government.
https://www.forbes.com/sites/thomasbrewster/2023/05/25/iphone-hacks-in-armenia-show-nso-spyware-in-warzone/?sh=4b76625f1a56
Forbes
‘Despicable’ iPhone Hacks In Armenia Find NSO Spyware ‘In Active Warzone’
For the first time, the Israeli company’s spyware has been used in a conflict zone, according to researchers.
■■□□□ Cybercrime: Zyxel Firewalls Hacked by Mirai Botnet.
https://www.securityweek.com/zyxel-firewalls-hacked-by-mirai-botnet-via-recently-patched-vulnerability/
https://www.securityweek.com/zyxel-firewalls-hacked-by-mirai-botnet-via-recently-patched-vulnerability/
SecurityWeek
Zyxel Firewalls Hacked by Mirai Botnet
A Mirai botnet has been exploiting a recently patched vulnerability tracked as CVE-2023-28771 to hack many Zyxel firewalls.
■■■■□ AI enabled bug bounty.
How ChatGPT helped me find a bug?
https://abhishekgk.medium.com/how-chatgpt-helped-me-find-a-bug-b5a3795c722
How ChatGPT helped me find a bug?
https://abhishekgk.medium.com/how-chatgpt-helped-me-find-a-bug-b5a3795c722
Medium
How ChatGPT helped me find a bug
Hello and welcome to my latest Medium writeup! I’m thrilled to share my thoughts and insights with you today on How I used chatgpt to find…
■■■□□ Data-Leak from Indonesia as newtons police records hit darknet's 🌑 exposed forums.
● ckure has not verified the data and this post is based on speculation.
● ckure has not verified the data and this post is based on speculation.
■□□□□ Data-Leak from Japan 🗾 as https://www.mlit.go.jp/en/ data alleged is posted online.
As per attacker, records contain employee names and emails in csv format.
The actor has credentials for the administrative panel on the site.
● Never underestimate the power of weak credentials.
As per attacker, records contain employee names and emails in csv format.
The actor has credentials for the administrative panel on the site.
● Never underestimate the power of weak credentials.
● After quite some time @ckure has integrated its alerting systems with https://exposed.vc for news and updates.
webroker.vc
The domain name EXPOSED.VC is for sale | WeBroker.VC
The domain name EXPOSED.VC is for sale - WeBroker.VC
■■■■□ Cyber-Espionage amid Cyber-Attack on UAE as Iran uses Microsoft Exchange backdoor.
https://thehackernews.com/2023/05/new-powerexchange-backdoor-used-in.html
https://thehackernews.com/2023/05/new-powerexchange-backdoor-used-in.html
■■■■□ Cyber-Attack: Anonymous Sudan allegedly takes out Tinder and Airline Sites offline for a while using DoS attacks.
● The sites were down but we could not confirm if it was amid Cyber-Attack.
● The sites were down but we could not confirm if it was amid Cyber-Attack.
■■■□□ CVE-2023-2868: CISA warns govt agencies of recently patched Barracuda zero-day.
https://www.bleepingcomputer.com/news/security/cisa-warns-govt-agencies-of-recently-patched-barracuda-zero-day/
https://www.bleepingcomputer.com/news/security/cisa-warns-govt-agencies-of-recently-patched-barracuda-zero-day/
BleepingComputer
CISA warns govt agencies of recently patched Barracuda zero-day
CISA warned of a recently patched zero-day vulnerability exploited last week to hack into Barracuda Email Security Gateway (ESG) appliances.
■□□□□ Too little; too late.
Windows XP activation algorithm cracked after 21 years.
https://arstechnica.com/gadgets/2023/05/a-decade-after-it-mattered-windows-xps-activation-algorithm-is-cracked/
Windows XP activation algorithm cracked after 21 years.
https://arstechnica.com/gadgets/2023/05/a-decade-after-it-mattered-windows-xps-activation-algorithm-is-cracked/
Ars Technica
Green hills forever: Windows XP activation algorithm cracked after 21 years
Please, please, please do not actually install XP and use it. But if you must…
■■■□□ NetDahar: a tool that logs network activities of each process with the following data.
https://github.com/mamun-sec/NetDahar
https://github.com/mamun-sec/NetDahar
GitHub
GitHub - mamun-sec/NetDahar: A network logging tool that logs per process activities
A network logging tool that logs per process activities - mamun-sec/NetDahar
■■■■□ Iran claims to nab 14 members of ‘terrorist team’ linked to Israel apparently using Cyber counter intelligence tactics.
https://www.timesofisrael.com/iran-claims-to-nab-14-members-of-terrorist-team-linked-to-israel/
https://www.timesofisrael.com/iran-claims-to-nab-14-members-of-terrorist-team-linked-to-israel/
The Times of Israel
Iran claims to nab 14 members of ‘terrorist team’ linked to Israel
Judicial official says squad planned to carry out assassinations of 'various individuals,' without providing details