cKure
■■■■■ Remote exploitation of a man-in-the-disk vulnerability in WhatsApp (CVE-2021-24027). https://census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/
■■■■□ WhatsApp exposure of TLS 1.2 cryptographic material to third party apps.
https://census-labs.com/news/2021/04/14/whatsapp-exposure-of-cryptographic-material-to-third-party-apps/
https://census-labs.com/news/2021/04/14/whatsapp-exposure-of-cryptographic-material-to-third-party-apps/
CENSUS
CENSUS — Cybersecurity for AI-driven unmanned systems
Cybersecurity for AI-driven unmanned systems. Platform Integrity, AI Trustworthiness and Secure Communications.
■□□□□ AppSpace Zero-Days
1. XSS - Stored
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27989
2. Broken Auth
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27990
Credits: https://www.linkedin.com/in/syedsohaibkarim
1. XSS - Stored
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27989
2. Broken Auth
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27990
Credits: https://www.linkedin.com/in/syedsohaibkarim
■■■□□ Swissknife - Scriptable VSCode Extension To Generate Or Manipulate Data.
https://github.com/luisfontes19/vscode-swissknife/
https://github.com/luisfontes19/vscode-swissknife/
GitHub
GitHub - luisfontes19/vscode-swissknife: Scriptable VSCode extension to generate or manipulate data. Stop pasting sensitive data…
Scriptable VSCode extension to generate or manipulate data. Stop pasting sensitive data in webpages. - luisfontes19/vscode-swissknife
■■■■■ Multiple one-click vulnerabilities have been discovered across a variety of popular software applications, allowing an attacker to potentially execute arbitrary code on target systems. The issues were discovered by Positive Security researchers Fabian Bräunlein and Lukas Euler and affect apps like Telegram, Nextcloud, VLC, LibreOffice, OpenOffice, Bitcoin/Dogecoin Wallets, Wireshark, and Mumble.
https://positive.security/blog/url-open-rce
https://thehackernews.com/2021/04/1-click-hack-found-in-popular-desktop.html
https://positive.security/blog/url-open-rce
https://thehackernews.com/2021/04/1-click-hack-found-in-popular-desktop.html
positive.security
Allow arbitrary URLs, expect arbitrary code execution | Positive Security
Insecure URL handling leading to 1-click code execution vulnerabilities in Telegram, Nextcloud (CVE-2021-22879), VLC, LibreOffice (CVE-2021-25631), OpenOffice (CVE-2021-30245), Bitcoin/Dogecoin Wallets, Wireshark (CVE-2021-22191) and Mumble (CVE-2021-27229).
■■■□□ United States 🇺🇸 Treasury sanctions Russia 🇷🇺 with sweeping new Sanctions Authority amid cyber attacks.
https://home.treasury.gov/news/press-releases/jy0127
https://home.treasury.gov/news/press-releases/jy0127
■□□□□ 📢 RaidForum's official account claims that fake news is being circulated about its closure.
https://mobile.twitter.com/1dot3dot3dot7/status/1382700999865995271
https://mobile.twitter.com/1dot3dot3dot7/status/1382700999865995271
Twitter
Omnipotent
Seen a bunch of fake news around; We are not being DDoS'd and nobody has been arrested. Our reverse-proxy server is offline due to shitty NOC Engineers.
This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ Unconfirmed: Team Fortress 2 remote code execution exploit triggered by joining a community server.
■■■□□ Over $760 million worth of Bitcoin that were stolen from cryptocurrency exchange Bitfinex in 2016 were moved to new accounts.
https://securityaffairs.co/wordpress/116858/digital-id/bitfinex-funds-moved.html
https://securityaffairs.co/wordpress/116858/digital-id/bitfinex-funds-moved.html
Security Affairs
Cyber thieves move $760 million stolen in the 2016 Bitfinex heist
Over $760 million worth of Bitcoin that were stolen from cryptocurrency exchange Bitfinex in 2016 were moved to new accounts.
cKure
■■■■■ For the second time in a week, a Chromium zero-day remote code execution exploit code has been released on Twitter, multiple browsers impacted. https://github.com/avboy1337/1195777-chrome0day https://securityaffairs.co/wordpress/116844/hacking/google…
■■□□□ Google Brings 37 Security Fixes to Chrome 90.
■■■□□ Defeat-Defender - Powerful Batch Script To Dismantle Complete Windows Defender Protection And Even Bypass Tamper Protection.
https://github.com/swagkarna/Defeat-Defender
https://github.com/swagkarna/Defeat-Defender
■■■■□ Severe Bugs Reported in EtherNet/IP Stack for Industrial Systems.
https://thehackernews.com/2021/04/severe-bugs-reported-in-ethernetip.html
https://thehackernews.com/2021/04/severe-bugs-reported-in-ethernetip.html
■■□□□ Uptycs’ threat research team recently detected several variants of the Linux-based botnet malware family, “Gafgyt,”some of them re-used Mirai code.
https://securityaffairs.co/wordpress/116882/cyber-crime/gafgyt-re-uses-mirai-code.html
https://securityaffairs.co/wordpress/116882/cyber-crime/gafgyt-re-uses-mirai-code.html
Security Affairs
Mirai code re-use in Gafgyt ____________________
Uptycs researchers recently detected several variants of the Linux-based botnet malware family, Gafgyt, some of them re-used Mirai code.
cKure
■□□□□ Data-Leak / Iraq 🇮🇶
■■□□□ Iraq 🇮🇶: Intelligence services downplay the Data-Leak incident that leaked many internal documents, most of which were sensitive.
The original post by ckure at https://t.me/cKure/7604 was confirmed after we assessed the sample data and images.
https://www.shorouknews.com/mobile/news/view.aspx?cdate=12042021&id=e2208673-0a4d-4f40-94f2-31276cd341e9
The original post by ckure at https://t.me/cKure/7604 was confirmed after we assessed the sample data and images.
https://www.shorouknews.com/mobile/news/view.aspx?cdate=12042021&id=e2208673-0a4d-4f40-94f2-31276cd341e9
Telegram
cKure
■□□□□ Data-Leak / Iraq 🇮🇶
■□□□□ #Exclusive | Data-Leak: Asus Middle East leaks 14K records due to Broken Authentication.
Note: This data has not been leaked and is under responsible disclosure for Asus to fix.
The data includes:
Email, Bill, Serial No. of device.
The bill has variety of informatiom like transaction IDs card details and other details what a normal bill from electronic store has.
Credits: M Shahnawaz.
https://mobile.twitter.com/Aamer_Sha/status/1383117859459629057
Note: This data has not been leaked and is under responsible disclosure for Asus to fix.
The data includes:
Email, Bill, Serial No. of device.
The bill has variety of informatiom like transaction IDs card details and other details what a normal bill from electronic store has.
Credits: M Shahnawaz.
https://mobile.twitter.com/Aamer_Sha/status/1383117859459629057
Twitter
Aamer Shah 🐦
@ASUS One of your websites is leaking information of 14K customers publicly with weak authorization checks. The data pertains to GCC customers. The website is in production. The bug was found by @_M_Shahnawaz
cKure
■■□□□ Scraped data of 500 million LinkedIn users being sold online, 2 million records leaked as proof. https://securityaffairs.co/wordpress/116528/security/linkedin-500m-users-dark-web.html
■□□□□ Facebook Faces Mass Legal Action Over Data Leak.
https://packetstormsecurity.com/news/view/32204/Facebook-Faces-Mass-Legal-Action-Over-Data-Leak.html
https://packetstormsecurity.com/news/view/32204/Facebook-Faces-Mass-Legal-Action-Over-Data-Leak.html
■■■□□ Cockpit CMS flaws exposed web servers to NoSQL injection exploits.
https://portswigger.net/daily-swig/cockpit-cms-flaws-exposed-web-servers-to-nosql-injection-exploits
https://portswigger.net/daily-swig/cockpit-cms-flaws-exposed-web-servers-to-nosql-injection-exploits
portswigger.net
Web Application Security, Testing, & Scanning - PortSwigger
PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.
■■□□□ GetSimple CMS My SMTP Contact Plugin 1.1.1 - CSRF to RCE.
https://www.exploit-db.com/exploits/49774
https://www.exploit-db.com/exploits/49774
Exploit Database
GetSimple CMS My SMTP Contact Plugin 1.1.1 - Cross-Site Request Forgery
GetSimple CMS My SMTP Contact Plugin 1.1.1 - Cross-Site Request Forgery.. webapps exploit for PHP platform
■□□□□ Indonesia 🇮🇩: Hackers arrested over $60 million US Covid-19 scam.
https://www.msn.com/en-xl/news/world/indonesian-hackers-arrested-over--million-us-covid-scam/ar-BB1fIjeS
https://www.msn.com/en-xl/news/world/indonesian-hackers-arrested-over--million-us-covid-scam/ar-BB1fIjeS