■■■■■ Golden SAML: Attack Technique Forges Authentication.
https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps
https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps
Cyberark
Golden SAML: Newly Discovered Attack Technique Forges Authentication to Cloud Apps
CyberArk Labs discovered a new attack vector, dubbed “golden SAML,” which allows an attacker to authenticate across every service that uses SAML 2.0 protocol as an SSO mechanism.
■■■□□ Joker’s Stash .Bazar Site Allegedly Seized By Law Enforcement.
● Well don't know what this is then: https://jstash-bazar.cm
https://thehackernews.com/2020/12/law-enforcement-seizes-jokers-stash.html
● Well don't know what this is then: https://jstash-bazar.cm
https://thehackernews.com/2020/12/law-enforcement-seizes-jokers-stash.html
■■■■■ Cookie Tossing to RCE on Google Cloud JupyterLab.
https://blog.s1r1us.ninja/bug-bounty/cookie-tossing-to-rce-on-google-cloud-jupyter-notebooks
https://blog.s1r1us.ninja/bug-bounty/cookie-tossing-to-rce-on-google-cloud-jupyter-notebooks
blog.s1r1us.ninja
s1r1us - cookie-tossing-to-rce-on-google-cloud-jupyter-notebooks
Blog Location changed to here : https://blog.s1r1us.ninja/research/cookie-tossing-to-rce-on-google-cloud-jupyter-notebooks
■■■■■ #AirGap: Keytap2 - acoustic keyboard eavesdropping based on language n-gram frequencies.
https://github.com/ggerganov/kbd-audio/discussions/31
https://github.com/ggerganov/kbd-audio/discussions/31
GitHub
Keytap2 - acoustic keyboard eavesdropping based on language n-gram frequencies · ggerganov kbd-audio · Discussion #31
Introduction Keytap is my hobby project for acoustic keyboard eavesdropping. In short, it works like this: Train an algorithm with the sounds that a specific keyboard emits when pressing its keys R...
■■■□□ Ransomware delivery via hastebin.
https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/negasteal-uses-hastebin-for-fileless-delivery-of-crysis-ransomware
https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/negasteal-uses-hastebin-for-fileless-delivery-of-crysis-ransomware
Trendmicro
Negasteal Uses Hastebin for Fileless Delivery of Crysis Ransomware
We discovered a Negasteal variant that uses hastebin to filelessly deliver Crysis ransomware to the victim's system.
■■■□□ Windows zero-day with bad patch gets new public exploit code.
https://www.bleepingcomputer.com/news/security/windows-zero-day-with-bad-patch-gets-new-public-exploit-code/ | #Zeroday #0day
https://www.bleepingcomputer.com/news/security/windows-zero-day-with-bad-patch-gets-new-public-exploit-code/ | #Zeroday #0day
BleepingComputer
Windows zero-day with bad patch gets new public exploit code
Back in June, Microsoft released a fix for a vulnerability in the Windows operating system that enabled attackers to increase their permissions to kernel level on a compromised machine. The patch did not stick.
■□□□□ #NorthKorea 🇰🇵 is trying to steal #COVID19 Vaccine data files.
https://thehackernews.com/2020/12/north-korean-hackers-trying-to-steal.html
https://thehackernews.com/2020/12/north-korean-hackers-trying-to-steal.html
■■■■□ Malicious Word Document Delivering an Octopus Backdoor 🐙 that does not use macros but 2 embedded object files that require user interaction / clicks.
https://isc.sans.edu/diary/rss/26918
https://isc.sans.edu/diary/rss/26918
■□□□□ #CyberWar: #Iran 🇮🇷 behind pro-Trump ‘enemies of the people’ doxing site, says FBI, #UnitedStates 🇺🇸.
https://www.bleepingcomputer.com/news/security/fbi-iran-behind-pro-trump-enemies-of-the-people-doxing-site/
https://www.bleepingcomputer.com/news/security/fbi-iran-behind-pro-trump-enemies-of-the-people-doxing-site/
BleepingComputer
FBI: Iran behind pro-Trump ‘enemies of the people’ doxing site
Iranian cyber actors are likely behind a campaign that encouraged deadly violence against U.S. state officials certifying the 2020 election results.
■□□□□ Account Takeover via common misconfiguration in Facebook login.
https://ankitthku.medium.com/account-takeover-via-common-misconfiguration-in-facebook-login-a2ac8b479b3
https://ankitthku.medium.com/account-takeover-via-common-misconfiguration-in-facebook-login-a2ac8b479b3
Medium
Account Takeover via common misconfiguration in Facebook login
Hello folks,
■□□□□ New Lawsuit Takes Aim at Ring After Smart Doorbell Hijacking.
https://www.infosecurity-magazine.com:443/news/new-lawsuit-aim-ring-smart/
https://www.infosecurity-magazine.com:443/news/new-lawsuit-aim-ring-smart/
Infosecurity Magazine
New Lawsuit Takes Aim at Ring After Smart Doorbell Hijacking
Incidents led to murder and sexual assault threats for users
■□□□□ 📢 Ongoing DDoS attack impacting Netscaler ADCS.
https://www.bleepingcomputer.com/news/security/citrix-confirms-ongoing-ddos-attack-impacting-netscaler-adcs/
https://www.bleepingcomputer.com/news/security/citrix-confirms-ongoing-ddos-attack-impacting-netscaler-adcs/
BleepingComputer
Citrix confirms ongoing DDoS attack impacting NetScaler ADCs
Citrix has confirmed today that an ongoing 'DDoS attack pattern' using DTLS as an amplification vector is affecting Citrix Application Delivery Controller (ADC) networking appliances with EDT enabled.
■■□□□ #Zeroday / #0day: The LPE bug could allow an attacker to install programs; view, change, or delete data; or create new accounts with full user rights.
https://threatpost.com/windows-zero-day-circulating-faulty-fix/162610/
https://threatpost.com/windows-zero-day-circulating-faulty-fix/162610/
Threat Post
Windows Zero-Day Still Circulating After Faulty Fix
The LPE bug could allow an attacker to install programs; view, change, or delete data; or create new accounts with full user rights.
■■■□□ Censys-Python - An Easy-To-Use And Lightweight API Wrapper For The Censys Search Engine.
https://github.com/censys/censys-python
https://github.com/censys/censys-python
GitHub
GitHub - censys/censys-python: An easy-to-use and lightweight API wrapper for Censys APIs.
An easy-to-use and lightweight API wrapper for Censys APIs. - censys/censys-python
■■■■□ Vulmap - Web Vulnerability Scanning And Verification Tools.
https://github.com/zhzyker/vulmap
https://www.kitploit.com/2020/12/vulmap-web-vulnerability-scanning-and.html
https://github.com/zhzyker/vulmap
https://www.kitploit.com/2020/12/vulmap-web-vulnerability-scanning-and.html
GitHub
GitHub - zhzyker/vulmap: Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能
Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能 - zhzyker/vulmap
■■■□□ Microsoft Warns CrowdStrike of Hackers Targeting Azure Cloud Customers and alleged unsuccessful attempt to compromise CrowdStrike.
https://thehackernews.com/2020/12/microsoft-warns-crowdstrike-of-hackers.html
https://thehackernews.com/2020/12/microsoft-warns-crowdstrike-of-hackers.html
cKure
■□□□□ 📢 Ongoing DDoS attack impacting Netscaler ADCS. https://www.bleepingcomputer.com/news/security/citrix-confirms-ongoing-ddos-attack-impacting-netscaler-adcs/
■■□□□ Citrix confirmed that a DDoS attack is targeting Citrix Application Delivery Controller (ADC) networking equipment.
cKure
Screenshot_20201223-004909_Chrome.jpg
■■■■■ Update: Signal – the World’s Most Encrypted App – Was Not Hacked by Israeli 🇮🇱 firm Cellebrite. #Israel
https://www.haaretz.com/amp/israel-news/tech-news/.premium-no-signal-the-world-s-most-encrypted-app-was-not-hacked-by-israeli-firm-cellebr-1.9398118
https://www.haaretz.com/amp/israel-news/tech-news/.premium-no-signal-the-world-s-most-encrypted-app-was-not-hacked-by-israeli-firm-cellebr-1.9398118
Haaretz.com
No, Signal – the world’s most encrypted app – was not hacked by Israeli firm Cellebrite
***
■■□□□ Russian crypto-exchange Livecoin hacked after it lost control of its servers.
https://www.zdnet.com/article/russian-crypto-exchange-livecoin-hacked-after-it-lost-control-of-its-servers/
https://www.zdnet.com/article/russian-crypto-exchange-livecoin-hacked-after-it-lost-control-of-its-servers/
ZDNet
Russian crypto-exchange Livecoin hacked after it lost control of its servers
Hackers gained access to the Livecoin portal and modified exchange rates to 10-15 times their normal values.