■□□□□ 📢 According to CISA and the FBI, advanced persistent threat (APT) nation-state actors are exploiting known vulnerabilities in the Fortinet FortiOS.
■■■■■ Apple Mail Zero-Click Security Vulnerability Allows Email Snooping.
https://threatpost.com/apple-mail-zero-click-security-vulnerability/165238/
https://threatpost.com/apple-mail-zero-click-security-vulnerability/165238/
Threat Post
Apple Mail Zero-Click Security Vulnerability Allows Email Snooping
The researcher is offering details on CVE-2020-9922, which can be triggered just by sending a target an email with two .ZIP files attached.
● Many "technical" people have hard time understanding a URL. With many, I mean over 99.99% of technical people like devs, hackers.
For your ref.
Note: I've not added any encoding. And this URL is the login page of ProtonMail.
https://mobile.twitter.com/Aamer_Sha/status/1379374107800707072
For your ref.
http://www.microsoft.com%docs%id%3D1234@3108382902/login
Note: I've not added any encoding. And this URL is the login page of ProtonMail.
https://mobile.twitter.com/Aamer_Sha/status/1379374107800707072
■□□□□ Hackers Targeting professionals With 'more_eggs' Malware via LinkedIn Job Offers.
https://thehackernews.com/2021/04/hackers-targeting-professionals-with.html
https://www.infosecurity-magazine.com:443/news/linkedin-users-targeted-by/
https://thehackernews.com/2021/04/hackers-targeting-professionals-with.html
https://www.infosecurity-magazine.com:443/news/linkedin-users-targeted-by/
cKure
■■□□□ 533 Million Facebook data hack. https://www.ehackingnews.com/2021/04/533-million-facebook-users-phone.html #DataLeak
■□□□□ Facebook #DataLeak
Account info swiped in 2019 via security hole, sold online, now given away for free.
Account info swiped in 2019 via security hole, sold online, now given away for free.
■■■□□ CVE-2021-30161: An issue exists on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection mechanism after an incoming call has been terminated. The LG ID is LVE-SMP-210002 (April 2021).
https://vulmon.com/vulnerabilitydetails?qid=CVE-2021-30161
https://vulmon.com/vulnerabilitydetails?qid=CVE-2021-30161
cKure
■■□□□ Israel 🇮🇱 elector.co.il suffers alleged #DataLeak as actor sells data online for 300 USD.
■■■□□ Actor who has the data of elector.co.il (Israel 🇮🇱) was contacted and following are the key details shared:
》Records: 6.5 million
》511 MB (zipped in 3 files)
》Motivation: Money 💰
》Records: 6.5 million
》511 MB (zipped in 3 files)
》Motivation: Money 💰
■■■□□ BleedingTooth: Exploiting Bluetooth RCE in the Linux kernel.
BleedingTooth is a set of zero-click vulnerabilities in the Linux Bluetooth subsystem that can allow an unauthenticated remote attacker in short distance to execute arbitrary code with kernel privileges on vulnerable devices.
https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup
BleedingTooth is a set of zero-click vulnerabilities in the Linux Bluetooth subsystem that can allow an unauthenticated remote attacker in short distance to execute arbitrary code with kernel privileges on vulnerable devices.
https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup
security-research
BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
■□□□□ OSCP writeup.
https://infosecwriteups.com/how-i-passed-oscp-with-100-points-in-12-hours-without-metasploit-in-my-first-attempt-dc8d03366f33
https://infosecwriteups.com/how-i-passed-oscp-with-100-points-in-12-hours-without-metasploit-in-my-first-attempt-dc8d03366f33
Medium
How I Passed OSCP with 100 points in 12 hours without Metasploit in my first attempt
I’m 21 years old and I decided to take OSCP two years ago when I was 19 years old. I had to wait for 1 and a half years until I won an…
cKure
■■■□□ Massive #DataLeak, if true. Actor claiming to have admin access + full db(22,000,000) lines for biggest Airline company in UAE 🇦🇪.
■□□□□ Correction: The DataLeak information posted here (https://t.me/cKure/7479) was from a booking website and not airline.
Threat actor share incorrect information.
Threat actor share incorrect information.
Telegram
cKure
■■■□□ Massive #DataLeak, if true.
Actor claiming to have admin access + full db(22,000,000) lines for biggest Airline company in UAE 🇦🇪.
Actor claiming to have admin access + full db(22,000,000) lines for biggest Airline company in UAE 🇦🇪.
■■□□□ Belgium 🇧🇪: Belgian police seize 28 tons of cocaine after 'cracking' Sky ECC's chat app encryption.
https://go.theregister.com/feed/www.theregister.com/2021/04/08/sky_ecc_drugs/
https://go.theregister.com/feed/www.theregister.com/2021/04/08/sky_ecc_drugs/
The Register
Belgian police seize 28 tons of cocaine after 'cracking' Sky ECC's chat app encryption
Euro cops take $1.65bn of blow off the streets after poring over messages
■■■■□ AMD Admits Ryzen 5000 CPU Exploit Could Leave Your PC Open to Hackers.
https://www.ehackingnews.com/2021/04/amd-admits-ryzen-5000-cpu-exploit-could.html
https://www.ehackingnews.com/2021/04/amd-admits-ryzen-5000-cpu-exploit-could.html
■■■■□ PHP Site's User Database Was Hacked In Recent Source Code Backdoor Attack.
http://feedproxy.google.com/~r/TheHackersNews/~3/__u9zz5iI6c/php-sites-user-database-was-hacked-in.html
http://feedproxy.google.com/~r/TheHackersNews/~3/__u9zz5iI6c/php-sites-user-database-was-hacked-in.html
■■□□□ 📢 Attackers are actively exploiting the CVE-2018-13379 flaw in Fortinet VPN to deploy the Cring ransomware to organizations in the industrial sector.
https://securityaffairs.co/wordpress/116480/cyber-crime/cring-ransomware-fortinet-vpn-flaw.html
https://securityaffairs.co/wordpress/116480/cyber-crime/cring-ransomware-fortinet-vpn-flaw.html
Security Affairs
Cring ransomware deployed targeting unpatched Fortinet VPN devices
Hackers are actively exploiting the CVE-2018-13379 flaw in Fortinet VPNs to deploy Cring ransomware to organizations in the industrial sector
■□□□□ 📢 Global payments processor VISA warns that threat actors are increasingly deploying web shells on compromised servers to exfiltrate credit card information stolen from online store customers.
■□□□□ Alleged 400k http://www.mappery.com/ Email:Hash combination being sold online.
Mappery
real life map collection
mappery is a diverse collection of real life maps contributed by map lovers worldwide. Find and explore maps by keyword, location, or by browsing a map.