This media is not supported in your browser
VIEW IN TELEGRAM
■■□□□ Unconfirmed: Team Fortress 2 remote code execution exploit triggered by joining a community server.
■■■□□ Over $760 million worth of Bitcoin that were stolen from cryptocurrency exchange Bitfinex in 2016 were moved to new accounts.
https://securityaffairs.co/wordpress/116858/digital-id/bitfinex-funds-moved.html
https://securityaffairs.co/wordpress/116858/digital-id/bitfinex-funds-moved.html
Security Affairs
Cyber thieves move $760 million stolen in the 2016 Bitfinex heist
Over $760 million worth of Bitcoin that were stolen from cryptocurrency exchange Bitfinex in 2016 were moved to new accounts.
cKure
■■■■■ For the second time in a week, a Chromium zero-day remote code execution exploit code has been released on Twitter, multiple browsers impacted. https://github.com/avboy1337/1195777-chrome0day https://securityaffairs.co/wordpress/116844/hacking/google…
■■□□□ Google Brings 37 Security Fixes to Chrome 90.
■■■□□ Defeat-Defender - Powerful Batch Script To Dismantle Complete Windows Defender Protection And Even Bypass Tamper Protection.
https://github.com/swagkarna/Defeat-Defender
https://github.com/swagkarna/Defeat-Defender
■■■■□ Severe Bugs Reported in EtherNet/IP Stack for Industrial Systems.
https://thehackernews.com/2021/04/severe-bugs-reported-in-ethernetip.html
https://thehackernews.com/2021/04/severe-bugs-reported-in-ethernetip.html
■■□□□ Uptycs’ threat research team recently detected several variants of the Linux-based botnet malware family, “Gafgyt,”some of them re-used Mirai code.
https://securityaffairs.co/wordpress/116882/cyber-crime/gafgyt-re-uses-mirai-code.html
https://securityaffairs.co/wordpress/116882/cyber-crime/gafgyt-re-uses-mirai-code.html
Security Affairs
Mirai code re-use in Gafgyt ____________________
Uptycs researchers recently detected several variants of the Linux-based botnet malware family, Gafgyt, some of them re-used Mirai code.
cKure
■□□□□ Data-Leak / Iraq 🇮🇶
■■□□□ Iraq 🇮🇶: Intelligence services downplay the Data-Leak incident that leaked many internal documents, most of which were sensitive.
The original post by ckure at https://t.me/cKure/7604 was confirmed after we assessed the sample data and images.
https://www.shorouknews.com/mobile/news/view.aspx?cdate=12042021&id=e2208673-0a4d-4f40-94f2-31276cd341e9
The original post by ckure at https://t.me/cKure/7604 was confirmed after we assessed the sample data and images.
https://www.shorouknews.com/mobile/news/view.aspx?cdate=12042021&id=e2208673-0a4d-4f40-94f2-31276cd341e9
Telegram
cKure
■□□□□ Data-Leak / Iraq 🇮🇶
■□□□□ #Exclusive | Data-Leak: Asus Middle East leaks 14K records due to Broken Authentication.
Note: This data has not been leaked and is under responsible disclosure for Asus to fix.
The data includes:
Email, Bill, Serial No. of device.
The bill has variety of informatiom like transaction IDs card details and other details what a normal bill from electronic store has.
Credits: M Shahnawaz.
https://mobile.twitter.com/Aamer_Sha/status/1383117859459629057
Note: This data has not been leaked and is under responsible disclosure for Asus to fix.
The data includes:
Email, Bill, Serial No. of device.
The bill has variety of informatiom like transaction IDs card details and other details what a normal bill from electronic store has.
Credits: M Shahnawaz.
https://mobile.twitter.com/Aamer_Sha/status/1383117859459629057
Twitter
Aamer Shah 🐦
@ASUS One of your websites is leaking information of 14K customers publicly with weak authorization checks. The data pertains to GCC customers. The website is in production. The bug was found by @_M_Shahnawaz
cKure
■■□□□ Scraped data of 500 million LinkedIn users being sold online, 2 million records leaked as proof. https://securityaffairs.co/wordpress/116528/security/linkedin-500m-users-dark-web.html
■□□□□ Facebook Faces Mass Legal Action Over Data Leak.
https://packetstormsecurity.com/news/view/32204/Facebook-Faces-Mass-Legal-Action-Over-Data-Leak.html
https://packetstormsecurity.com/news/view/32204/Facebook-Faces-Mass-Legal-Action-Over-Data-Leak.html
■■■□□ Cockpit CMS flaws exposed web servers to NoSQL injection exploits.
https://portswigger.net/daily-swig/cockpit-cms-flaws-exposed-web-servers-to-nosql-injection-exploits
https://portswigger.net/daily-swig/cockpit-cms-flaws-exposed-web-servers-to-nosql-injection-exploits
portswigger.net
Web Application Security, Testing, & Scanning - PortSwigger
PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.
■■□□□ GetSimple CMS My SMTP Contact Plugin 1.1.1 - CSRF to RCE.
https://www.exploit-db.com/exploits/49774
https://www.exploit-db.com/exploits/49774
Exploit Database
GetSimple CMS My SMTP Contact Plugin 1.1.1 - Cross-Site Request Forgery
GetSimple CMS My SMTP Contact Plugin 1.1.1 - Cross-Site Request Forgery.. webapps exploit for PHP platform
■□□□□ Indonesia 🇮🇩: Hackers arrested over $60 million US Covid-19 scam.
https://www.msn.com/en-xl/news/world/indonesian-hackers-arrested-over--million-us-covid-scam/ar-BB1fIjeS
https://www.msn.com/en-xl/news/world/indonesian-hackers-arrested-over--million-us-covid-scam/ar-BB1fIjeS
cKure
■■□□□ SolarWinds: SolarWinds Hackers Accessed DHS Chief's Email as several high-level government accounts were also breached in the attack. Russia 🇷🇺 / United States 🇺🇸
■■■□□ SolarWinds supply chain attack also impacted six European Union institutions, European Commissioner for Budget and Administration confirmed.
https://securityaffairs.co/wordpress/116914/hacking/solarwinds-eu-agencies-hacked.html
https://securityaffairs.co/wordpress/116914/hacking/solarwinds-eu-agencies-hacked.html
Security Affairs
6 out of 11 EU agencies running Solarwinds Orion software were hacked
SolarWinds supply chain attack also impacted six European Union institutions, European Commissioner for Budget and Administration confirmed.
■□□□□ A hacker claims to be selling sensitive data from OTP generating firm.
The OTP-generating firm has some of the top giants as clients including Google, Facebook, Amazon, Apple, Microsoft, Signal, Telegram and Twitter, etc.
https://www.hackread.com/hacker-selling-data-from-otp-generating-firm/
The OTP-generating firm has some of the top giants as clients including Google, Facebook, Amazon, Apple, Microsoft, Signal, Telegram and Twitter, etc.
https://www.hackread.com/hacker-selling-data-from-otp-generating-firm/
Hackread
A hacker claims to be selling sensitive data from OTP generating firm
Like us on Facebook @ /HackRead
■■□□□ IRTriage - Incident Response Triage - Windows Evidence Collection For Forensic Analysis.
https://github.com/AJMartel/IRTriage
https://github.com/AJMartel/IRTriage
GitHub
GitHub - AJMartel/IRTriage: Incident Response Triage - Windows Evidence Collection for Forensic Analysis
Incident Response Triage - Windows Evidence Collection for Forensic Analysis - AJMartel/IRTriage
■■■■□ India 🇮🇳: A large BGP routing leak that occurred last night disrupted the connectivity for thousands of major networks and websites around the world. Although the BGP routing leak occurred in Vodafone's autonomous network (AS55410) based in India, it has impacted U.S. companies, including Google, according to sources.
https://www.bleepingcomputer.com/news/security/major-bgp-leak-disrupts-thousands-of-networks-globally/
https://www.bleepingcomputer.com/news/security/major-bgp-leak-disrupts-thousands-of-networks-globally/
BleepingComputer
Major BGP leak disrupts thousands of networks globally
A large BGP routing leak that occurred last night disrupted the connectivity for thousands of major networks and websites around the world. Although the BGP routing leak occurred in Vodafone's autonomous network (AS55410) based in India, it has impacted U.S.…
■■■■□ Airstrike Attack - FDE bypass and EoP on domain joined Windows workstations (CVE-2021-28316).
https://shenaniganslabs.io/2021/04/13/Airstrike.html
https://shenaniganslabs.io/2021/04/13/Airstrike.html
Shenanigans Labs
Airstrike Attack - FDE bypass and EoP on domain joined Windows workstations (CVE-2021-28316)
By default, domain joined Windows workstations allow access to the network selection UI from the lock screen.
An attacker with physical access to a locked device with WiFi capabilities (such as a laptop or a workstation) can abuse this functionality to force…
An attacker with physical access to a locked device with WiFi capabilities (such as a laptop or a workstation) can abuse this functionality to force…
■■■□□ SysAdmin of Billion-Dollar Hacking Group Gets 10-Year Sentence.
Fedir Hladyr, a 35-year-old Ukrainian national, is said to have played a crucial role in a criminal scheme that compromised tens of millions of debit and credit cards, in addition to aggregating the stolen information, supervising other members of the group, and maintaining the server infrastructure that FIN7 used to attack and control victims' machines.
https://thehackernews.com/2021/04/sysadmin-of-billion-dollar-hacking.html
Fedir Hladyr, a 35-year-old Ukrainian national, is said to have played a crucial role in a criminal scheme that compromised tens of millions of debit and credit cards, in addition to aggregating the stolen information, supervising other members of the group, and maintaining the server infrastructure that FIN7 used to attack and control victims' machines.
https://thehackernews.com/2021/04/sysadmin-of-billion-dollar-hacking.html
■■■□□ Profil3r: OSINT tool to find a person’s accounts and emails + breached emails.
https://github.com/Rog3rSm1th/Profil3r
https://github.com/Rog3rSm1th/Profil3r
■□□□□ BazarLoader Malware Abuses Slack, BaseCamp Clouds.
https://threatpost.com/bazarloader-malware-slack-basecamp/165455/
https://threatpost.com/bazarloader-malware-slack-basecamp/165455/
Threat Post
BazarLoader Malware Abuses Slack, BaseCamp Clouds
Two cyberattack campaigns are making the rounds using unique social-engineering techniques.