■■□□□AutoHotkey-Based Password Stealer Targeting US, Canadian Banking Users.
https://thehackernews.com/2020/12/autohotkey-based-password-stealer.html
https://thehackernews.com/2020/12/autohotkey-based-password-stealer.html
■■■■■ A Google Docs Bug Could Have Allowed Hackers See Your Private Documents.
https://blog.geekycat.in/google-vrp-hijacking-your-screenshots/
https://blog.geekycat.in/google-vrp-hijacking-your-screenshots/
■■■□□ CVE-2020-17530: APACHE STRUCTS VULNERABILITY EXPLOITED IN THE WILD.
https://securitynews.sonicwall.com/xmlpost/cve-2020-17530-apache-structs-vulnerability-exploited-in-the-wild/
https://securitynews.sonicwall.com/xmlpost/cve-2020-17530-apache-structs-vulnerability-exploited-in-the-wild/
■□□□□ #DataLeak: Japanese Aerospace Firm Kawasaki Warns of Data Breach.
https://threatpost.com/japanese-aerospace-firm-kawasaki-warns-of-data-breach/162642/
https://threatpost.com/japanese-aerospace-firm-kawasaki-warns-of-data-breach/162642/
Threat Post
Japanese Aerospace Firm Kawasaki Warns of Data Breach
The Japanese aerospace manufacturer said that starting in June, overseas unauthorized access to its servers may have compromised customer data.
■■□□□ #IoT: Pranksters are hijacking smart devices to live-stream swatting incidents, says FBI.
https://www.zdnet.com/article/fbi-pranksters-are-hijacking-smart-devices-to-live-stream-swatting-incidents
https://www.zdnet.com/article/fbi-pranksters-are-hijacking-smart-devices-to-live-stream-swatting-incidents
ZDNet
FBI: Swatters are hijacking smart devices to live-stream swatting incidents
The FBI said it's working with smart device makers to address the issue.
■■□□□ Nullify AMSI Scanner with PowerShell.
http://binaryhax0r.blogspot.com/2020/12/nullify-amsi-scanner-with-powershell.html
http://binaryhax0r.blogspot.com/2020/12/nullify-amsi-scanner-with-powershell.html
Blogspot
Nullify AMSI Scanner with PowerShell
AMSI as per Microsoft is: "The Windows Antimalware Scan Interface (AMSI) is a versatile interface standard that allows your applications a...
■■■■□ Declaring War Against Cyber Negligence.
https://www.ehackingnews.com/2020/12/declaring-war-against-cyber-negligence.html
https://www.ehackingnews.com/2020/12/declaring-war-against-cyber-negligence.html
■□□□□ The head of Group-IB Mr. Sachkov described the portrait of a typical Russian hacker.
https://www.ehackingnews.com/2020/12/the-head-of-group-ib-mr-sachkov.html
https://www.ehackingnews.com/2020/12/the-head-of-group-ib-mr-sachkov.html
■□□□□ #IoT: Lawsuit Claims Flawed Facial Recognition Led to Man’s Wrongful Arrest.
https://threatpost.com/lawsuit-claims-flawed-facial-recognition-led-to-mans-wrongful-arrest/162663/
https://threatpost.com/lawsuit-claims-flawed-facial-recognition-led-to-mans-wrongful-arrest/162663/
Threat Post
Lawsuit Claims Flawed Facial Recognition Led to Man’s Wrongful Arrest
Black man sues police after being falsely ID’d by facial recognition, joining other Black Americans falling victim to the technology’s racial bias.
cKure
■■■□□ SolarWinds has released an updated advisory for the additional SuperNova malware discovered to have been distributed through the company's network management platform. https://www.bleepingcomputer.com/news/security/solarwinds-releases-updated-advisory…
■■□□□ SolarWinds / Solorigate attackers wanted to access cloud ☁️ data of the victims.
■■■■■ #Exclusive
#DataLeak: Hacker group RedRabbit Team have created a website which sends details of AirTel #India 🇮🇳 over the email.
We have tested the data for authenticity. Takes around 10 hours to send details. This will be the most audacious leak as it is available on .com clear-net website.
#DataLeak: Hacker group RedRabbit Team have created a website which sends details of AirTel #India 🇮🇳 over the email.
We have tested the data for authenticity. Takes around 10 hours to send details. This will be the most audacious leak as it is available on .com clear-net website.
■■□□□ Apple loses lawsuit against cyber security startup Corellium.
https://www.hackread.com/apple-loses-lawsuit-cyber-security-startup-corellium/
https://www.hackread.com/apple-loses-lawsuit-cyber-security-startup-corellium/
Hackread - Latest Cybersecurity, Tech, Crypto & Hacking News
Good news for security researchers - Apple loses lawsuit against Corellium
Like us on Facebook @ /HackRead
■■■■■ Responder now supports SMBv2, shows if smb1 is disabled or not, which Os/Build version, if RDP is open, domain joined, last reboot, etc. And.. you get all that information in less than 5 seconds per class C.
https://github.com/lgandx/Responder
https://github.com/lgandx/Responder
GitHub
GitHub - lgandx/Responder: Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication…
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat...
cKure
■■■■■ #Exclusive #DataLeak: Hacker group RedRabbit Team have created a website which sends details of AirTel #India 🇮🇳 over the email. We have tested the data for authenticity. Takes around 10 hours to send details. This will be the most audacious leak as…
● The website was taken down. The attackers created another domain though.
Apparently the domain was posted by the attacker related account in our discussion group (@ckureg). The group is followed by various blue teams and threat intel platforms that can directly take action against such domains.
Apparently the domain was posted by the attacker related account in our discussion group (@ckureg). The group is followed by various blue teams and threat intel platforms that can directly take action against such domains.
■■□□□#DataLeak: Emotet campaign hits Lithuania’s National Public Health Center and several state institutions.
https://securityaffairs.co/wordpress/112817/malware/emotet-campaign-hit-lithuania.html
https://securityaffairs.co/wordpress/112817/malware/emotet-campaign-hit-lithuania.html
Security Affairs
Emotet campaign hits Lithuania's National Public Health Center
An Emotet campaign hit Lithuania, the malware has infected systems at the National Center for Public Health (NVSC) and several municipalities.