■■■□□ New data suggests someone has compromised more than 21,000 Microsoft Exchange Server email systems worldwide and infected them with malware that invokes both KrebsOnSecurity and Yours Truly by name.
https://krebsonsecurity.com/2021/03/no-i-did-not-hack-your-ms-exchange-server/
https://krebsonsecurity.com/2021/03/no-i-did-not-hack-your-ms-exchange-server/
Krebs on Security
No, I Did Not Hack Your MS Exchange Server
New data suggests someone has compromised more than 21,000 Microsoft Exchange Server email systems worldwide and infected them with malware that invokes both KrebsOnSecurity and Yours Truly by name. Let's just get this out of the way right now: It…
■■■■■ CVE-2021-21123
https://youtu.be/Mr95IeGiTj0
https://www.rapid7.com/db/vulnerabilities/google-chrome-cve-2021-21123/
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html
https://youtu.be/Mr95IeGiTj0
https://www.rapid7.com/db/vulnerabilities/google-chrome-cve-2021-21123/
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html
YouTube
google chrome bug | CVE-2021-21123 PoC
Credit : @PuliczeK
Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski
#Bug is rewarded with $5000.
GitHub: https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome
YouTube : https://www.youtube.com/channel/UCW3hDq…
Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski
#Bug is rewarded with $5000.
GitHub: https://github.com/Puliczek/CVE-2021-21123-PoC-Google-Chrome
YouTube : https://www.youtube.com/channel/UCW3hDq…
■■■□□ #CyberAttack | Australia 🇦🇺
A cyber attack has hit the Australian Channel Nine’s live broadcasts causing the disruption of its operations. The broadcaster was unable to air its Sunday morning news program, which runs from 7:00 am to 1:00 pm from Sidney.
https://hackademicus.nl/hackers-disrupted-live-broadcasts-at-channel-nine-is-it-a-russian-retaliation/
A cyber attack has hit the Australian Channel Nine’s live broadcasts causing the disruption of its operations. The broadcaster was unable to air its Sunday morning news program, which runs from 7:00 am to 1:00 pm from Sidney.
https://hackademicus.nl/hackers-disrupted-live-broadcasts-at-channel-nine-is-it-a-russian-retaliation/
■■■■□ A critical flaw in the official Facebook for WordPress plugin could be abused exploited for remote code execution attacks.
https://securityaffairs.co/wordpress/116063/social-networks/facebook-wordpress-plugin-attacks.html
https://securityaffairs.co/wordpress/116063/social-networks/facebook-wordpress-plugin-attacks.html
Security Affairs
Experts found two flaws in Facebook for WordPress Plugin
A critical flaw in the official Facebook for WordPress plugin could be exploited by attackers for remote code execution attacks.
■■■■□ Intigriti — XSS Challenge 0321
XSS with CSRF Bypass
https://fh4ntke.medium.com/intigriti-xss-challenge-0321-472ae0a48254
XSS with CSRF Bypass
https://fh4ntke.medium.com/intigriti-xss-challenge-0321-472ae0a48254
Medium
Intigriti — XSS Challenge 0321
XSS with CSRF Bypass
■□□□□ ⚠️ Actor selling data allegedly of multiple organisations spread across Arabian peninsular / GCC incl. UAE 🇦🇪, KSA 🇸🇦, Qatar 🇶🇦, Kuwait 🇰🇼.
We requested for a sample and found the data to be inconsistent; in one instance the mail did not exist. Apparently another fraudster.
https://raidforums.com/Thread-SELLING-GCC-Countries-Big-Company-Base-UAE-Saudi-Arabia-Qatar-Kuveyt
We requested for a sample and found the data to be inconsistent; in one instance the mail did not exist. Apparently another fraudster.
https://raidforums.com/Thread-SELLING-GCC-Countries-Big-Company-Base-UAE-Saudi-Arabia-Qatar-Kuveyt
■■■■■ php hacked viz. a supply chain attack.
On 28th March, 2021 two malicious commits were pushed to the php-src repo from the names of Rasmus Lerdorf and myself. We don't yet know how exactly this happened, but everything points towards a compromise of the git.php.net server (rather than a compromise of an individual git account).
https://news-web.php.net/php.internals/113838
On 28th March, 2021 two malicious commits were pushed to the php-src repo from the names of Rasmus Lerdorf and myself. We don't yet know how exactly this happened, but everything points towards a compromise of the git.php.net server (rather than a compromise of an individual git account).
https://news-web.php.net/php.internals/113838
■■□□□ Solution for YesWeHack’s #8 DOJO Challenge.
https://holme-sec.medium.com/solution-for-yeswehacks-8-dojo-challenge-c1044d1ab586
https://holme-sec.medium.com/solution-for-yeswehacks-8-dojo-challenge-c1044d1ab586
Medium
Solution for YesWeHack’s #8 DOJO Challenge
For the latest addition to YesWeHack’s Dojo series, we’re faced with the challenge of fetching the secret that EvilCorp2.0 is storing on…
■■□□□ Session monitoring scripts prompt dozens of privacy lawsuits against Big Biz, mainly in California and Florida.
https://go.theregister.com/feed/www.theregister.com/2021/03/30/intel_wiretapping_data/
https://go.theregister.com/feed/www.theregister.com/2021/03/30/intel_wiretapping_data/
The Register
Intel accused of wiretapping because it uses analytics to track keystrokes, mouse movements on its website
Session monitoring scripts prompt dozens of privacy lawsuits against Big Biz, mainly in California and Florida
cKure
■■□□□ Session monitoring scripts prompt dozens of privacy lawsuits against Big Biz, mainly in California and Florida. https://go.theregister.com/feed/www.theregister.com/2021/03/30/intel_wiretapping_data/
This media is not supported in your browser
VIEW IN TELEGRAM
● Even ckure.xyz has 1 page under video surveillance.
PortScan test video log.
If you are in someone else's property (domain), you abide by its rules of surveillance. As only public information about user is collected.
PortScan test video log.
If you are in someone else's property (domain), you abide by its rules of surveillance. As only public information about user is collected.
■■□□□ SolarWinds: SolarWinds Hackers Accessed DHS Chief's Email as several high-level government accounts were also breached in the attack.
Russia 🇷🇺 / United States 🇺🇸
Russia 🇷🇺 / United States 🇺🇸
■■□□□ CVE-2021-25160: A remote arbitrary file modification vulnerability exists in some Aruba Instant Access Point (IAP) products.
https://vulmon.com/vulnerabilitydetails?qid=CVE-2021-25160
https://vulmon.com/vulnerabilitydetails?qid=CVE-2021-25160
■■■■■ 8.2 TB #DataLeak from India 🇮🇳.
Popular Mobile payments service MobiKwik on Monday came under fire after 8.2 terabytes (TB) of data belonging to millions of its users began circulating on the dark web in the aftermath of a major data breach that came to light earlier this month.
https://thehackernews.com/2021/03/mobikwik-suffers-major-breach-kyc-data.html
Popular Mobile payments service MobiKwik on Monday came under fire after 8.2 terabytes (TB) of data belonging to millions of its users began circulating on the dark web in the aftermath of a major data breach that came to light earlier this month.
https://thehackernews.com/2021/03/mobikwik-suffers-major-breach-kyc-data.html
cKure
■■■■■ 8.2 TB #DataLeak from India 🇮🇳. Popular Mobile payments service MobiKwik on Monday came under fire after 8.2 terabytes (TB) of data belonging to millions of its users began circulating on the dark web in the aftermath of a major data breach that came…
Statement by Mobikwik:
https://mobile.twitter.com/MobiKwik/status/1367489330902675463
Comment by Troy Hunt:
https://mobile.twitter.com/troyhunt/status/1376656147218800641
https://mobile.twitter.com/MobiKwik/status/1367489330902675463
Comment by Troy Hunt:
https://mobile.twitter.com/troyhunt/status/1376656147218800641
Twitter
MobiKwik
A media-crazed so-called security researcher has repeatedly over the last week presented concocted files wasting precious time of our organization while desperately trying to grab media attention.We thoroughly investigated his allegations and did not find…
cKure
Statement by Mobikwik: https://mobile.twitter.com/MobiKwik/status/1367489330902675463 Comment by Troy Hunt: https://mobile.twitter.com/troyhunt/status/1376656147218800641
● cKure has acquired the alleged data of MobiKwik leak. However, verification has not been made.
■■■■■ ⚠️ Following is the list of C2 servers of MetaSploit or CobaltStrike likely used by hackers to attack.
The list was provided via security researcher Michael.
https://gist.github.com/MichaelKoczwara/3a0037ad46c373bc71a6e22daf69d70e
The list was provided via security researcher Michael.
https://gist.github.com/MichaelKoczwara/3a0037ad46c373bc71a6e22daf69d70e
Gist
Cobalt Strike & Metasploit servers
Cobalt Strike & Metasploit servers. GitHub Gist: instantly share code, notes, and snippets.
cKure
■■■■■ ⚠️ Following is the list of C2 servers of MetaSploit or CobaltStrike likely used by hackers to attack. The list was provided via security researcher Michael. https://gist.github.com/MichaelKoczwara/3a0037ad46c373bc71a6e22daf69d70e
■■■□□ CobaltStrike hunting list.
https://docs.google.com/spreadsheets/d/1bYvBh6NkNYGstfQWnT5n7cSxdhjSn1mduX8cziWSGrw/edit#gid=766378683
https://docs.google.com/spreadsheets/d/1bYvBh6NkNYGstfQWnT5n7cSxdhjSn1mduX8cziWSGrw/edit#gid=766378683
Google Docs
CobaltStrike_Hunting
■■□□□ Proper compilation of defences against Cobalt Strike.
》Hunting & detection tools
》Yara & Sigma rules
》Indicators
》Research articles
https://mobile.twitter.com/certbund/status/1376556022131658767
https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence
》Hunting & detection tools
》Yara & Sigma rules
》Indicators
》Research articles
https://mobile.twitter.com/certbund/status/1376556022131658767
https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence
■□□□□ Cracking OSWE/AWAE by Atul Shedage.
https://atulshedage.medium.com/how-i-cracked-oswe-awae-in-two-attempts-xd-847e25a7470c
https://atulshedage.medium.com/how-i-cracked-oswe-awae-in-two-attempts-xd-847e25a7470c
Medium
How I Cracked OSWE/AWAE in TWO Attempts xD
Well it’s been approximately 8 months I have completed the OSWE aka AWAE certification, it took me 2 attempts to clear the exam. Now…