■■□□□ CVE-2021-25160: A remote arbitrary file modification vulnerability exists in some Aruba Instant Access Point (IAP) products.
https://vulmon.com/vulnerabilitydetails?qid=CVE-2021-25160
https://vulmon.com/vulnerabilitydetails?qid=CVE-2021-25160
■■■■■ 8.2 TB #DataLeak from India 🇮🇳.
Popular Mobile payments service MobiKwik on Monday came under fire after 8.2 terabytes (TB) of data belonging to millions of its users began circulating on the dark web in the aftermath of a major data breach that came to light earlier this month.
https://thehackernews.com/2021/03/mobikwik-suffers-major-breach-kyc-data.html
Popular Mobile payments service MobiKwik on Monday came under fire after 8.2 terabytes (TB) of data belonging to millions of its users began circulating on the dark web in the aftermath of a major data breach that came to light earlier this month.
https://thehackernews.com/2021/03/mobikwik-suffers-major-breach-kyc-data.html
cKure
■■■■■ 8.2 TB #DataLeak from India 🇮🇳. Popular Mobile payments service MobiKwik on Monday came under fire after 8.2 terabytes (TB) of data belonging to millions of its users began circulating on the dark web in the aftermath of a major data breach that came…
Statement by Mobikwik:
https://mobile.twitter.com/MobiKwik/status/1367489330902675463
Comment by Troy Hunt:
https://mobile.twitter.com/troyhunt/status/1376656147218800641
https://mobile.twitter.com/MobiKwik/status/1367489330902675463
Comment by Troy Hunt:
https://mobile.twitter.com/troyhunt/status/1376656147218800641
Twitter
MobiKwik
A media-crazed so-called security researcher has repeatedly over the last week presented concocted files wasting precious time of our organization while desperately trying to grab media attention.We thoroughly investigated his allegations and did not find…
cKure
Statement by Mobikwik: https://mobile.twitter.com/MobiKwik/status/1367489330902675463 Comment by Troy Hunt: https://mobile.twitter.com/troyhunt/status/1376656147218800641
● cKure has acquired the alleged data of MobiKwik leak. However, verification has not been made.
■■■■■ ⚠️ Following is the list of C2 servers of MetaSploit or CobaltStrike likely used by hackers to attack.
The list was provided via security researcher Michael.
https://gist.github.com/MichaelKoczwara/3a0037ad46c373bc71a6e22daf69d70e
The list was provided via security researcher Michael.
https://gist.github.com/MichaelKoczwara/3a0037ad46c373bc71a6e22daf69d70e
Gist
Cobalt Strike & Metasploit servers
Cobalt Strike & Metasploit servers. GitHub Gist: instantly share code, notes, and snippets.
cKure
■■■■■ ⚠️ Following is the list of C2 servers of MetaSploit or CobaltStrike likely used by hackers to attack. The list was provided via security researcher Michael. https://gist.github.com/MichaelKoczwara/3a0037ad46c373bc71a6e22daf69d70e
■■■□□ CobaltStrike hunting list.
https://docs.google.com/spreadsheets/d/1bYvBh6NkNYGstfQWnT5n7cSxdhjSn1mduX8cziWSGrw/edit#gid=766378683
https://docs.google.com/spreadsheets/d/1bYvBh6NkNYGstfQWnT5n7cSxdhjSn1mduX8cziWSGrw/edit#gid=766378683
Google Docs
CobaltStrike_Hunting
■■□□□ Proper compilation of defences against Cobalt Strike.
》Hunting & detection tools
》Yara & Sigma rules
》Indicators
》Research articles
https://mobile.twitter.com/certbund/status/1376556022131658767
https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence
》Hunting & detection tools
》Yara & Sigma rules
》Indicators
》Research articles
https://mobile.twitter.com/certbund/status/1376556022131658767
https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence
■□□□□ Cracking OSWE/AWAE by Atul Shedage.
https://atulshedage.medium.com/how-i-cracked-oswe-awae-in-two-attempts-xd-847e25a7470c
https://atulshedage.medium.com/how-i-cracked-oswe-awae-in-two-attempts-xd-847e25a7470c
Medium
How I Cracked OSWE/AWAE in TWO Attempts xD
Well it’s been approximately 8 months I have completed the OSWE aka AWAE certification, it took me 2 attempts to clear the exam. Now…
■■■■■ Spectre bypass in Linux.
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spectre-bypass-linux-vulnerabilities
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spectre-bypass-linux-vulnerabilities
Security
Newly-Discovered Vulnerabilities Could Allow for Bypass of Spectre Mitigations in Linux
Bugs could allow a malicious user to access data belonging to other users.
■■■■□ 📢 Ubiquiti had disclosed earlier this year that a breach involving a third-party cloud provider had exposed customer account credentials. Now a source who participated in the response to that breach alleges Ubiquiti massively downplayed a “catastrophic” incident to minimize the hit to its stock price, and that the third-party cloud provider claim was a fabrication.
https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-breach-catastrophic/
https://krebsonsecurity.com/2021/03/whistleblower-ubiquiti-breach-catastrophic/
Krebs on Security
Final Thoughts on Ubiquiti
Last year, I posted a series of articles about a purported "breach" at Ubiquiti. My sole source for that reporting was the person who has since been indicted by federal prosecutors for his alleged wrongdoing – which includes providing false…
■□□□□ IoT security. https://youtu.be/JbHJ4JHlVyA
YouTube
The IOT Security Nightmare: How bad could it be? w/Retia
IOT devices are everywhere, but could hackers use them to create a nightmare for their owners? In this episode we explore what a hacker can do to your IOT devices, inspired by hacking scenes from Mr Robot!
Chapters:
0:00 Intro
0:43 Mr.Robot Inspiration…
Chapters:
0:00 Intro
0:43 Mr.Robot Inspiration…
■■■■□ Vulnx 🕷️ is An Intelligent Bot Auto Shell Injector that detects vulnerabilities in multiple types of CMS'.
https://github.com/anouarbensaad/vulnx
https://github.com/anouarbensaad/vulnx
GitHub
GitHub - anouarbensaad/vulnx: vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security…
vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform a quick CMS security detection, information colle...
cKure
● cKure has acquired the alleged data of MobiKwik leak. However, verification has not been made.
■■■■□ #DataLeak | India 🇮🇳: Payment app MobiKwik has denied its security has been breached, and said it it's true, as has been claimed, that its customers' information has appeared on the dark web, then some other platform was totally responsible for that.
"Some users have reported that their data is visible on the dark web," reads a message from the company, dated March 30.
https://blog.mobikwik.com/message-from-the-company/
"Some users have reported that their data is visible on the dark web," reads a message from the company, dated March 30.
https://blog.mobikwik.com/message-from-the-company/
■■■■■ Tax scammers in China 🇨🇳 turn photos into vids to crack tax dept facial recognition system.
https://go.theregister.com/feed/www.theregister.com/2021/03/31/tax_scammers_fool_ai_facial_recognition/
https://go.theregister.com/feed/www.theregister.com/2021/03/31/tax_scammers_fool_ai_facial_recognition/
The Register
Pair accused of turning photos into vids to crack tax dept facial recognition system in China
Then issuing tens of millions in fake invoices
■■■■□ A vulnerability in Kaspersky / KAVKIS 2020 products family allows full disabling of protection.
Scope: Application
Product name: Kaspersky Internet Security
Product version:20.0.14.1085
OS name and version (incl SP): Windows 10 RS5
Attack type: Bypass
Maximum user privileges needed to reproduce your issue: no privileges
https://hackerone.com/reports/870615
Scope: Application
Product name: Kaspersky Internet Security
Product version:20.0.14.1085
OS name and version (incl SP): Windows 10 RS5
Attack type: Bypass
Maximum user privileges needed to reproduce your issue: no privileges
https://hackerone.com/reports/870615
HackerOne
Kaspersky disclosed on HackerOne: [Fixed] A vulnerability in KAVKIS...
> Note! Thank you for your report. For the purposes of the further analysis of the vulnerability, that you kindly report to us, could you please fill *all* fields [in square brackets]. This...
■■□□□ #DataLeak / India 🇮🇳
The server of Maharashtra Industrial Development Corporation was hacked as of late. The ransomware 'SYNack' affected the applications and database servers facilitated at the MIDC headquarters in Mumbai by encrypting the information put away in these servers. Hackers have demanded Rs 500 crore, they have mailed a demand of Rs 500 crore on MIDC's official mail ID, sources said.
https://www.ehackingnews.com/2021/03/midcs-server-hacked-threat-to-destroy.html
The server of Maharashtra Industrial Development Corporation was hacked as of late. The ransomware 'SYNack' affected the applications and database servers facilitated at the MIDC headquarters in Mumbai by encrypting the information put away in these servers. Hackers have demanded Rs 500 crore, they have mailed a demand of Rs 500 crore on MIDC's official mail ID, sources said.
https://www.ehackingnews.com/2021/03/midcs-server-hacked-threat-to-destroy.html
■■□□□ Japan 🇯🇵: Dubbed "A41APT" by Kaspersky researchers, the findings delve into a new slew of attacks undertaken by APT10 (aka Stone Panda or Cicada) using previously undocumented malware to deliver as many as three payloads such as SodaMaster, P8RAT, and FYAnti.
https://www.ehackingnews.com/2021/03/midcs-server-hacked-threat-to-destroy.html
https://www.ehackingnews.com/2021/03/midcs-server-hacked-threat-to-destroy.html
■□□□□ Using containers to have multiple sessions for single site per browser in Firefox.
https://addons.mozilla.org/en-US/firefox/addon/multi-account-containers/
https://addons.mozilla.org/en-US/firefox/addon/multi-account-containers/
addons.mozilla.org
Firefox Multi-Account Containers – Get this Extension for 🦊 Firefox (en-US)
Download Firefox Multi-Account Containers for Firefox. Firefox Multi-Account Containers lets you keep parts of your online life separated into color-coded tabs. Cookies are separated by container, allowing you to use the web with multiple accounts and integrate…