■■□□□ Britain 🇬🇧: Average British computer criminal is young, male and not highly skilled, researcher finds.
https://go.theregister.com/feed/www.theregister.com/2021/04/13/computer_misuse_act_convictions_analysis/
https://go.theregister.com/feed/www.theregister.com/2021/04/13/computer_misuse_act_convictions_analysis/
The Register
Average convicted British computer criminal is young, male, not highly skilled, researcher finds
Analysis of Computer Misuse Act cases also draws heavily on El Reg archives
■■□□□ ldsview: Search utility for LDAP directory dumps.
https://securityonline.info/ldsview-search-tool-for-ldap-directory-dumps/
https://securityonline.info/ldsview-search-tool-for-ldap-directory-dumps/
Daily CyberSecurity
Stay ahead with Daily CyberSecurity. We deliver rapid zero-hour alerts and expert analysis on critical vulnerabilities, CVEs, and emerging cyber threats.
■□□□□ #DataLeak: ParkMobile Breach Exposes License Plate Data, Mobile Numbers of 21M Users.
https://krebsonsecurity.com/2021/04/parkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users/
https://krebsonsecurity.com/2021/04/parkmobile-breach-exposes-license-plate-data-mobile-numbers-of-21m-users/
Krebs on Security
ParkMobile Breach Exposes License Plate Data, Mobile Numbers of 21M Users
Someone is selling account information for 21 million customers of ParkMobile, a mobile parking app that's popular in North America. The stolen data includes customer email addresses, phone numbers, license plate numbers, hashed passwords and mailing addresses.
■■■□□ PIN bruteforcing if lockout is not enabled | The software rubber duck.
https://www.instagram.com/reel/CNaBvcFgX1b/?igshid=u5csu09obux
https://www.instagram.com/reel/CNaBvcFgX1b/?igshid=u5csu09obux
■■□□□ Back in a Bit: Attacker Use of the Windows Background Intelligent Transfer Service.
https://www.fireeye.com/blog/threat-research/2021/03/attacker-use-of-windows-background-intelligent-transfer-service.html
https://www.fireeye.com/blog/threat-research/2021/03/attacker-use-of-windows-background-intelligent-transfer-service.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
■■■■□ Over 100,000 web pages hosted by Google for business form searches overrun with backdoor RATs.
eSentire warns of remote-access trojans masquerading as PDFs
https://go.theregister.com/feed/www.theregister.com/2021/04/14/google_sites_malware/
eSentire warns of remote-access trojans masquerading as PDFs
https://go.theregister.com/feed/www.theregister.com/2021/04/14/google_sites_malware/
The Register
Google Sites blight: Over 100,000 web pages for business form searches overrun with backdoor RATs
eSentire warns of remote-access trojans masquerading as PDFs
■■■■□ United States 🇺🇸: A court-approved FBI operation was conducted to remove web shells from compromised US-based Microsoft Exchange servers without first notifying the servers' owners.
https://www.bleepingcomputer.com/news/security/fbi-nuked-web-shells-from-hacked-exchange-servers-without-telling-owners/
https://www.bleepingcomputer.com/news/security/fbi-nuked-web-shells-from-hacked-exchange-servers-without-telling-owners/
BleepingComputer
FBI nuked web shells from hacked Exchange Servers without telling owners
A court-approved FBI operation was conducted to remove web shells from compromised US-based Microsoft Exchange servers without first notifying the servers' owners.
■■■■■ Microsoft today issued fixes for 114 vulnerabilities as part of its monthly security update release, which this month addressed 19 critical flaws, four critical Microsoft Exchange Server bugs found by the National Security Agency (NSA), and one zero-day bug in Desktop Window Manager.
CVE-2021-28310, a Win32k elevation of privilege vulnerability, is the only CVE under active attack patched this month.
Yesterday's patches also addressed four critical remote code execution vulnerabilities in Microsoft Exchange Server: CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, and CVE-2021-28483. All of these were discovered by the NSA and affect Exchange Server versions 2013 through 2019.
CVE-2021-28480 and CVE-2021-28481 have a CVSS score of 9.8 and require no authorization or user interaction to exploit.
CVE-2021-28310, a Win32k elevation of privilege vulnerability, is the only CVE under active attack patched this month.
Yesterday's patches also addressed four critical remote code execution vulnerabilities in Microsoft Exchange Server: CVE-2021-28480, CVE-2021-28481, CVE-2021-28482, and CVE-2021-28483. All of these were discovered by the NSA and affect Exchange Server versions 2013 through 2019.
CVE-2021-28480 and CVE-2021-28481 have a CVSS score of 9.8 and require no authorization or user interaction to exploit.
■■■■□ Traitor - Automatic Linux Privesc Via Exploitation Of Low-Hanging Fruit E.G. GTFOBin
https://github.com/liamg/traitor
https://github.com/liamg/traitor
GitHub
GitHub - liamg/traitor: :arrow_up: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit,…
:arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock - liamg/traitor
■□□□□ HackBar v2.0 release: HackBar plugin for Burpsuite.
https://github.com/d3vilbug/HackBar/releases
https://securityonline.info/hackbar-v2-0-releases-hackbar-plugin-for-burpsuite/
https://github.com/d3vilbug/HackBar/releases
https://securityonline.info/hackbar-v2-0-releases-hackbar-plugin-for-burpsuite/
GitHub
Releases · d3vilbug/HackBar
HackBar plugin for Burpsuite. Contribute to d3vilbug/HackBar development by creating an account on GitHub.
■■■■□ Adfsbrute - A Script To Test Credentials Against Active Directory Federation Services (ADFS), Allowing Password Spraying Or Bruteforce Attacks.
https://github.com/ricardojoserf/adfsbrute
https://github.com/ricardojoserf/adfsbrute
GitHub
GitHub - ricardojoserf/adfsbrute: A script to test credentials against Active Directory Federation Services (ADFS), allowing password…
A script to test credentials against Active Directory Federation Services (ADFS), allowing password spraying or bruteforce attacks. - ricardojoserf/adfsbrute
■■■■□ PoC / exploit utilities.
CVE-2020-6516 - Chrome
CVE-2021-24027 - WhatsApp
https://github.com/CENSUS/whatsapp-mitd-mitm
CVE-2020-6516 - Chrome
CVE-2021-24027 - WhatsApp
https://github.com/CENSUS/whatsapp-mitd-mitm
GitHub
GitHub - CENSUS/whatsapp-mitd-mitm: PoC and tools for exploiting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp)
PoC and tools for exploiting CVE-2020-6516 (Chrome) and CVE-2021-24027 (WhatsApp) - CENSUS/whatsapp-mitd-mitm
■■■■□ New JavaScript Exploit Can Now Carry Out DDR4 Rowhammer Attacks.
https://thehackernews.com/2021/04/new-javascript-exploit-can-now-carry.html
https://thehackernews.com/2021/04/new-javascript-exploit-can-now-carry.html
■■■■□ Airstrike Attack - FDE bypass and EoP on domain joined Windows workstations (CVE-2021-28316).
https://shenaniganslabs.io/2021/04/13/Airstrike.html
https://shenaniganslabs.io/2021/04/13/Airstrike.html
Shenanigans Labs
Airstrike Attack - FDE bypass and EoP on domain joined Windows workstations (CVE-2021-28316)
By default, domain joined Windows workstations allow access to the network selection UI from the lock screen.
An attacker with physical access to a locked device with WiFi capabilities (such as a laptop or a workstation) can abuse this functionality to force…
An attacker with physical access to a locked device with WiFi capabilities (such as a laptop or a workstation) can abuse this functionality to force…
■■■■□ Firefox 'fully compromised' in 15 minutes via SMASH attack.
https://go.theregister.com/feed/www.theregister.com/2021/04/15/rowhammer_ddr4/
https://go.theregister.com/feed/www.theregister.com/2021/04/15/rowhammer_ddr4/
The Register
Is it still possible to run malware in a browser using JavaScript and Rowhammer? Yes, yes it is (slowly)
Firefox 'fully compromised' in 15 minutes via SMASH attack