■□□□□ A hacker claims to be selling sensitive data from OTP generating firm.
The OTP-generating firm has some of the top giants as clients including Google, Facebook, Amazon, Apple, Microsoft, Signal, Telegram and Twitter, etc.
https://www.hackread.com/hacker-selling-data-from-otp-generating-firm/
The OTP-generating firm has some of the top giants as clients including Google, Facebook, Amazon, Apple, Microsoft, Signal, Telegram and Twitter, etc.
https://www.hackread.com/hacker-selling-data-from-otp-generating-firm/
Hackread
A hacker claims to be selling sensitive data from OTP generating firm
Like us on Facebook @ /HackRead
■■□□□ IRTriage - Incident Response Triage - Windows Evidence Collection For Forensic Analysis.
https://github.com/AJMartel/IRTriage
https://github.com/AJMartel/IRTriage
GitHub
GitHub - AJMartel/IRTriage: Incident Response Triage - Windows Evidence Collection for Forensic Analysis
Incident Response Triage - Windows Evidence Collection for Forensic Analysis - AJMartel/IRTriage
■■■■□ India 🇮🇳: A large BGP routing leak that occurred last night disrupted the connectivity for thousands of major networks and websites around the world. Although the BGP routing leak occurred in Vodafone's autonomous network (AS55410) based in India, it has impacted U.S. companies, including Google, according to sources.
https://www.bleepingcomputer.com/news/security/major-bgp-leak-disrupts-thousands-of-networks-globally/
https://www.bleepingcomputer.com/news/security/major-bgp-leak-disrupts-thousands-of-networks-globally/
BleepingComputer
Major BGP leak disrupts thousands of networks globally
A large BGP routing leak that occurred last night disrupted the connectivity for thousands of major networks and websites around the world. Although the BGP routing leak occurred in Vodafone's autonomous network (AS55410) based in India, it has impacted U.S.…
■■■■□ Airstrike Attack - FDE bypass and EoP on domain joined Windows workstations (CVE-2021-28316).
https://shenaniganslabs.io/2021/04/13/Airstrike.html
https://shenaniganslabs.io/2021/04/13/Airstrike.html
Shenanigans Labs
Airstrike Attack - FDE bypass and EoP on domain joined Windows workstations (CVE-2021-28316)
By default, domain joined Windows workstations allow access to the network selection UI from the lock screen.
An attacker with physical access to a locked device with WiFi capabilities (such as a laptop or a workstation) can abuse this functionality to force…
An attacker with physical access to a locked device with WiFi capabilities (such as a laptop or a workstation) can abuse this functionality to force…
■■■□□ SysAdmin of Billion-Dollar Hacking Group Gets 10-Year Sentence.
Fedir Hladyr, a 35-year-old Ukrainian national, is said to have played a crucial role in a criminal scheme that compromised tens of millions of debit and credit cards, in addition to aggregating the stolen information, supervising other members of the group, and maintaining the server infrastructure that FIN7 used to attack and control victims' machines.
https://thehackernews.com/2021/04/sysadmin-of-billion-dollar-hacking.html
Fedir Hladyr, a 35-year-old Ukrainian national, is said to have played a crucial role in a criminal scheme that compromised tens of millions of debit and credit cards, in addition to aggregating the stolen information, supervising other members of the group, and maintaining the server infrastructure that FIN7 used to attack and control victims' machines.
https://thehackernews.com/2021/04/sysadmin-of-billion-dollar-hacking.html
■■■□□ Profil3r: OSINT tool to find a person’s accounts and emails + breached emails.
https://github.com/Rog3rSm1th/Profil3r
https://github.com/Rog3rSm1th/Profil3r
■□□□□ BazarLoader Malware Abuses Slack, BaseCamp Clouds.
https://threatpost.com/bazarloader-malware-slack-basecamp/165455/
https://threatpost.com/bazarloader-malware-slack-basecamp/165455/
Threat Post
BazarLoader Malware Abuses Slack, BaseCamp Clouds
Two cyberattack campaigns are making the rounds using unique social-engineering techniques.
■■■■□ PwnLnX: advanced multi-threaded, multi-client python reverse shell for hacking linux systems.
https://github.com/spectertraww/PwnLnX
https://securityonline.info/pwnlnx/
https://github.com/spectertraww/PwnLnX
https://securityonline.info/pwnlnx/
GitHub
GitHub - thatstraw/PwnLnX: An advanced multi-threaded, multi-client python reverse shell for hacking linux systems. There's still…
An advanced multi-threaded, multi-client python reverse shell for hacking linux systems. There's still more work to do so feel free to help out with the development. Disclaimer: This revers...
■■■□□ How a WhatsApp status loophole is aiding cyberstalkers.
https://traced.app/2021/04/13/whatsapp-status-loophole-is-aiding-cyberstalkers/
https://traced.app/2021/04/13/whatsapp-status-loophole-is-aiding-cyberstalkers/
Trustd Mobile
How a WhatsApp status loophole is aiding cyberstalkers | Trustd Mobile
Cyberstalkers typically like to collect as much information about their target as possible. They want to know where they
■■■■□ #Exclusive | Zero-Day: Privilege Escalation in Nvidia Control Panel.
As per the researcher, the vulnerability was identified using alert 📢 mechanism based on an earlier UAC bypass (CVE-2019-1388).
https://twitter.com/_M_Shahnawaz/status/1383686714087010311
As per the researcher, the vulnerability was identified using alert 📢 mechanism based on an earlier UAC bypass (CVE-2019-1388).
https://twitter.com/_M_Shahnawaz/status/1383686714087010311
Twitter
Muhammed Shameem
In 2019 I had setup an EDR Alert for exploitation of privilege escalation on UAC vulnerability CVE-2019-1388 , 4 days ago it triggered and found that @nvidia Control panel upgrade gives away SYSTEM privilege to any user. Funniest finding ever
■■□□□ Privacy violation by app | Interesting thread: https://mobile.twitter.com/0dayCTF/status/1383494676141903877
Twitter
Ryan M. Montgomery
I was proxying traffic from a mobile crypto app called "Pi", I noticed that 3700 of my contacts were being uploaded to their server and are stored/searchable. - Any explanation @PiCoreTeam? - #cryptocurrency #picoin #cryptocurrencies #altcoin #minepi #cybersecurity…
■■■■■ The Code Testing Company CodeCov Suffers a Data Breach Which Went Undetected for Months.
U.S. federal authorities are investigating a safety violation at Codecov, which works on selling a tool that allows developers to calculate their codebase coverage and works for more than 29,000 clients worldwide. The organization acknowledged the violation and reported that for months it remained unnoticed.
https://www.ehackingnews.com/2021/04/the-code-testing-company-codecov.html
U.S. federal authorities are investigating a safety violation at Codecov, which works on selling a tool that allows developers to calculate their codebase coverage and works for more than 29,000 clients worldwide. The organization acknowledged the violation and reported that for months it remained unnoticed.
https://www.ehackingnews.com/2021/04/the-code-testing-company-codecov.html
■□□□□ Data-Leak | Russia 🇷🇺 : Database containing e-mail addresses of Navalny's supporters leaked onto the Internet.
https://www.ehackingnews.com/2021/04/database-containing-e-mail-addresses-of.html
https://www.ehackingnews.com/2021/04/database-containing-e-mail-addresses-of.html
■■□□□ Sish - HTTP(S)/WS(S)/TCP Tunnels To Localhost Using Only SSH.
https://github.com/antoniomika/sish
https://github.com/antoniomika/sish
GitHub
GitHub - antoniomika/sish: HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.
HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. - antoniomika/sish
■□□□□ India 🇮🇳: CERT-IN Issues "High" Severity Rating Advisory for WhatsApp Threats.
■■■■□ HttpDoom - A Tool For Response-Based Inspection Of Websites Across A Large Amount Of Hosts For Quickly Gaining An Overview Of HTTP-based Attack Surface.
https://github.com/filipi86/httpdoom
https://github.com/filipi86/httpdoom
GitHub
GitHub - filipi86/httpdoom: HttpDoom is a tool for response-based inspection of websites across a large amount of hosts for quickly…
HttpDoom is a tool for response-based inspection of websites across a large amount of hosts for quickly gaining an overview of HTTP-based attack surface. - filipi86/httpdoom
■■■■■ (POC) Remove any Facebook’s live video ($14,000 bounty) | by Ahmad Talahmeh | Apr, 2021.
https://infosecwriteups.com/poc-remove-any-facebooks-live-video-14-000-bounty-70c8135b7b4c
https://infosecwriteups.com/poc-remove-any-facebooks-live-video-14-000-bounty-70c8135b7b4c
Medium
(POC) Remove any Facebook’s live video ($14,000 bounty)
Description / Impact