■■■■□ Microsoft admits to signing rootkit malware in supply-chain fiasco.
https://www.bleepingcomputer.com/news/security/microsoft-admits-to-signing-rootkit-malware-in-supply-chain-fiasco/
https://www.bleepingcomputer.com/news/security/microsoft-admits-to-signing-rootkit-malware-in-supply-chain-fiasco/
BleepingComputer
Microsoft admits to signing rootkit malware in supply-chain fiasco
Microsoft has now confirmed signing a malicious driver being distributed within gaming environments. This driver, called "Netfilter," is in fact a rootkit that was observed communicating with Chinese command-and-control IPs.
■■■□□ DFIR – Windows and Active Directory persistence and malicious configurations.
https://m365internals.com/2021/06/23/dfir-windows-and-active-directory-persistence-and-malicious-configurations/amp/
https://m365internals.com/2021/06/23/dfir-windows-and-active-directory-persistence-and-malicious-configurations/amp/
■■■□□ REvil Hits French Connection, Grupo Fleury.
https://securityboulevard.com/2021/06/revil-hits-french-connection-grupo-fleury/
https://securityboulevard.com/2021/06/revil-hits-french-connection-grupo-fleury/
Security Boulevard
REvil Hits French Connection, Grupo Fleury
The REvil ransomware gang continues its destructive trek around the globe, routing out and exploiting vulnerabilities at (often) high-profile targets. One
■■■□□ Hackers target Cisco ASA devices after a PoC exploit code was published online.
https://securityaffairs.co/wordpress/119442/hacking/cisco-asa-under-attack.html
https://securityaffairs.co/wordpress/119442/hacking/cisco-asa-under-attack.html
Security Affairs
Hackers target Cisco ASA after a PoC exploit code was published online
Experts warn of attacks against Cisco ASA devices after researchers have published a PoC exploit code on Twitter for a known XSS flaw.
■■■□□ An open-source application called WhyNotWin11 acts as a better drop-in replacement for Microsoft's PC Health Check app to determine if your hardware is compatible with Windows 11.
■■□□□ Russia 🇷🇺: Microsoft: Russia-linked SolarWinds hackers breached three new entities.
https://securityaffairs.co/wordpress/119425/apt/solarwinds-nobelium-ongoing-campaign.html
https://securityaffairs.co/wordpress/119425/apt/solarwinds-nobelium-ongoing-campaign.html
Security Affairs
Microsoft: Russia-linked SolarWinds hackers breached three new entities
Microsoft discovered that Russia-linked SolarWinds hackers, tracked as Nobelium, have breached the network of three new organizations.
■■■■□ Black Shadow group that hacked the Israeli 🇮🇱 insurance company and leaked data of millions of its citizens hosts their website sharing the data publicly.
https://blackshadow.to/
https://blackshadow.to/
■■■□□ 📢 The REvil ransomware operation is now using a Linux encryptor that targets and encrypts Vmware ESXi virtual machines.
■■■■□ Analyzing CVE-2021-1665 – Remote Code Execution Vulnerability in Windows GDI+
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-cve-2021-1665-remote-code-execution-vulnerability-in-windows-gdi/
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/analyzing-cve-2021-1665-remote-code-execution-vulnerability-in-windows-gdi/
McAfee Blog
Analyzing CVE-2021-1665 – Remote Code Execution Vulnerability in Windows GDI+ | McAfee Blog
Introduction Microsoft Windows Graphics Device Interface+, also known as GDI+, allows various applications to use different graphics functionality on
■■■■■ PrintNightmare (CVE-2021-1675): Remote code execution in Windows Spooler Service
https://github.com/afwu/PrintNightmare
https://github.com/afwu/PrintNightmare
■■■■□ Microsoft Edge Translator contained uXSS flaw exploitable ‘on any web page’.
https://portswigger.net/daily-swig/microsoft-edge-translator-contained-uxss-flaw-exploitable-on-any-web-page
https://portswigger.net/daily-swig/microsoft-edge-translator-contained-uxss-flaw-exploitable-on-any-web-page
portswigger.net
Web Application Security, Testing, & Scanning - PortSwigger
PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.
■□□□□ Colombian police arrest Gozi malware suspect after 8 years at large.
https://nakedsecurity.sophos.com/2021/06/30/colombian-police-arrest-gozi-malware-suspect-after-8-years-at-large/
https://nakedsecurity.sophos.com/2021/06/30/colombian-police-arrest-gozi-malware-suspect-after-8-years-at-large/
■■■■□ SolarWinds update!
Russia-linked threat actors compromised Denmark’s 🇩🇰 central bank (Danmarks Nationalbank) and remained in its systems for months.
https://securityaffairs.co/wordpress/119527/cyber-warfare-2/denmarks-central-bank-solarwinds-hackers.html
Russia-linked threat actors compromised Denmark’s 🇩🇰 central bank (Danmarks Nationalbank) and remained in its systems for months.
https://securityaffairs.co/wordpress/119527/cyber-warfare-2/denmarks-central-bank-solarwinds-hackers.html
Security Affairs
SolarWinds hackers remained in Denmark's central bank for months
Russia-linked threat actors compromised Denmark’s central bank (Danmarks Nationalbank) and remained in its systems for months.
cKure
■■■■■ PrintNightmare (CVE-2021-1675): Remote code execution in Windows Spooler Service https://github.com/afwu/PrintNightmare
■■■■■ zero-day: Leaked print spooler exploit lets Windows users remotely execute code as system on your domain controller.
https://go.theregister.com/feed/www.theregister.com/2021/06/30/windows_print_spool_vuln_rce/
https://go.theregister.com/feed/www.theregister.com/2021/06/30/windows_print_spool_vuln_rce/
The Register
Leaked print spooler exploit lets Windows users remotely execute code as system on your domain controller
Kill this service immediately
■■■□□ 📢 Domain, server of DoubleVPN used by ransomware gangs seized.
https://www.hackread.com/doublevpn-domain-server-ransomware-gangs-seized/
https://www.hackread.com/doublevpn-domain-server-ransomware-gangs-seized/
Hackread
Domain, server of DoubleVPN used by ransomware gangs seized
Follow us on Twitter @HackRead
■■■■□ Microsoft Discloses Critical Bugs Allowing Takeover of NETGEAR Routers.
https://thehackernews.com/2021/06/microsoft-discloses-critical-bugs.html
https://thehackernews.com/2021/06/microsoft-discloses-critical-bugs.html
■■■■□ A leaked tool used by the Babuk Locker operation to create custom ransomware executables is now being used by another threat actor in a very active campaign targeting victims worldwide.
https://www.bleepingcomputer.com/news/security/leaked-babuk-locker-ransomware-builder-used-in-new-attacks/
https://www.bleepingcomputer.com/news/security/leaked-babuk-locker-ransomware-builder-used-in-new-attacks/
BleepingComputer
Leaked Babuk Locker ransomware builder used in new attacks
A leaked tool used by the Babuk Locker operation to create custom ransomware executables is now being used by another threat actor in a very active campaign targeting victims worldwide.