cKure
Photo
■■■□□ Anonymous Hacktivists Leak 180 GB of Data from Web Host Epik.
https://www.ehackingnews.com/2021/09/anonymous-hacktivists-leak-180-gb-of.html
https://www.ehackingnews.com/2021/09/anonymous-hacktivists-leak-180-gb-of.html
cKure
■■□□□ Novastar-VNNOX-iCare(Novaicare) V7.16.0 [Multiple Privilege Escalation flaws] https://github.com/viperbluff/Novastar-VNNOX-iCare-Privilege-Escalation
● ICYMI: The vulnerabilities in this (t.me/cKure/9386) post have not been fixed by the vendor. So technically they are zero-day issues.
Telegram
cKure
■■□□□ Novastar-VNNOX-iCare(Novaicare) V7.16.0 [Multiple Privilege Escalation flaws]
https://github.com/viperbluff/Novastar-VNNOX-iCare-Privilege-Escalation
https://github.com/viperbluff/Novastar-VNNOX-iCare-Privilege-Escalation
■□□□□ Information security specialists from Kaspersky Lab reported that hackers are trying to attack Russian companies through a new vulnerability in Microsoft Office products. At least one attack targeted government agencies. Using the vulnerability, attackers can not only spy on users of the infected system, but also download malicious programs like ransomware viruses into it. Experts expect that hackers will actively exploit the system's flaw, as users are slow to install updates.
https://www.ehackingnews.com/2021/09/hackers-attack-russian-organizations.html
https://www.ehackingnews.com/2021/09/hackers-attack-russian-organizations.html
■□□□□ ntlm_theft: A tool for generating multiple types of NTLMv2 hash theft files.
https://github.com/Greenwolf/ntlm_theft
https://github.com/Greenwolf/ntlm_theft
GitHub
GitHub - Greenwolf/ntlm_theft: A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf)
A tool for generating multiple types of NTLMv2 hash theft files by Jacob Wilkin (Greenwolf) - Greenwolf/ntlm_theft
■■■□□ Hunting for OMI Vulnerability Exploitation with Azure Sentinel.
https://techcommunity.microsoft.com/t5/azure-sentinel/hunting-for-omi-vulnerability-exploitation-with-azure-sentinel/ba-p/2764093
https://techcommunity.microsoft.com/t5/azure-sentinel/hunting-for-omi-vulnerability-exploitation-with-azure-sentinel/ba-p/2764093
TECHCOMMUNITY.MICROSOFT.COM
Hunting for OMI Vulnerability Exploitation with Azure Sentinel | Microsoft Community Hub
Microsoft Threat Intelligence Center (MSTIC) have been monitoring for signs of exploitation of the OMI vulnerability and...
■■■■□ Zero-click RCE vulnerability in Hikvision security cameras could lead to network compromise
https://portswigger.net/daily-swig/zero-click-rce-vulnerability-in-hikvision-security-cameras-could-lead-to-network-compromise
https://portswigger.net/daily-swig/zero-click-rce-vulnerability-in-hikvision-security-cameras-could-lead-to-network-compromise
portswigger.net
Web Application Security, Testing, & Scanning - PortSwigger
PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & identify the very latest vulnerabilities.
👍1
■■■■■ A (v3.5 compatible) .NET tool for stealing and importing certificates in the Windows certificate store without touching disk. Useful for red team operations where you need to poach a certificate for pivoting purposes and want to do so with an in-memory post-ex payload.
This is similar to Benjamin Delpy's Mimikatz.
https://github.com/TheWover/CertStealer
This is similar to Benjamin Delpy's Mimikatz.
https://github.com/TheWover/CertStealer
GitHub
GitHub - TheWover/CertStealer: A .NET tool for exporting and importing certificates without touching disk.
A .NET tool for exporting and importing certificates without touching disk. - TheWover/CertStealer
■■■■■ Zero-Day: PoC CVE-2021-30632 - Out of bounds write in V8.
Tested against Samsung Internet Browser v15.0.2.47, which does not yet have Google's patch.
https://github.com/Phuong39/PoC-CVE-2021-30632
Tested against Samsung Internet Browser v15.0.2.47, which does not yet have Google's patch.
https://github.com/Phuong39/PoC-CVE-2021-30632
GitHub
GitHub - Phuong39/PoC-CVE-2021-30632: PoC CVE-2021-30632 - Out of bounds write in V8
PoC CVE-2021-30632 - Out of bounds write in V8. Contribute to Phuong39/PoC-CVE-2021-30632 development by creating an account on GitHub.
■■□□□ Interesting thread: 🌐 BlackMatter Ransomware group just ransomed another food critical infrastructure in the US, The ransom demand is 5,900,000$ for now 🚨
The victim is playing by the rules: "@CISAgov is going to be demanding answers from us within the next 12 hours" 🧐
#BlackMatter
https://twitter.com/ido_cohen2/status/1439863554606305286
The victim is playing by the rules: "@CISAgov is going to be demanding answers from us within the next 12 hours" 🧐
#BlackMatter
https://twitter.com/ido_cohen2/status/1439863554606305286
Twitter
DarkFeed
🌐 BlackMatter #Ransomware group just ransomed another food critical infrastructure in the US, The ransom demand is 5,900,000$ for now 🚨 The victim is playing by the rules: "@CISAgov is going to be demanding answers from us within the next 12 hours" 🧐#BlackMatter
■■■■□ Privacy / Zero-Day: VPN users unmasked by zero-day vulnerability in Virgin Media routers.
https://portswigger.net/daily-swig/vpn-users-unmasked-by-zero-day-vulnerability-in-virgin-media-routers
https://portswigger.net/daily-swig/vpn-users-unmasked-by-zero-day-vulnerability-in-virgin-media-routers
The Daily Swig | Cybersecurity news and views
VPN users unmasked by zero-day vulnerability in Virgin Media routers
Disclosure comes two years after privacy-busting flaw was discovered
■■■□□ Payment API Vulnerabilities Exposed "Millions" of Users.
https://www.infosecurity-magazine.com/news/payment-api-vulnerabilities/
https://www.infosecurity-magazine.com/news/payment-api-vulnerabilities/
Infosecurity Magazine
Payment API Vulnerabilities Exposed "Millions" of Users
Researchers claim developers are overlooking best practices
■■■□□ Interesting thread: CVE-2021-41073 (Linux LPE Kernel bug - 5.1 to 5.14.6)
https://twitter.com/chompie1337/status/1439743758447398918
https://twitter.com/chompie1337/status/1439743758447398918
Twitter
chompie
this is a neat kernel bug I found in io_uring that is exploitable for LPE. was fun learning about and breaking another Linux kernel meme twitter.com/cvenew/status/…
■■■□□ Data-Leak from United States 🇺🇸 as US farmer cooperative hit by $5.9M BlackMatter ransomware attack.
https://www.bleepingcomputer.com/news/security/us-farmer-cooperative-hit-by-59m-blackmatter-ransomware-attack/
https://www.bleepingcomputer.com/news/security/us-farmer-cooperative-hit-by-59m-blackmatter-ransomware-attack/
BleepingComputer
US farmer cooperative hit by $5.9M BlackMatter ransomware attack
U.S. farmers cooperative NEW Cooperative has suffered a BlackMatter ransomware attack demanding $5.9 million not to leak stolen data and provide a decryptor.
■□□□□ 🇨🇳: TikTok China just limited kids to 40 minutes' use each day.
https://go.theregister.com/feed/www.theregister.com/2021/09/20/douyin_youth_mode_time_limits/
https://go.theregister.com/feed/www.theregister.com/2021/09/20/douyin_youth_mode_time_limits/
The Register
Tick, tick, tick … TikTok China just limited kids to 40 minutes' use each day
And added a bug bounty program to detect any holes in its 'youth mode'
■□□□□ Two XOR-encryption, one structure reordering and one ROT shifting bypassed.
https://katyscode.wordpress.com/2021/01/15/reverse-engineering-adventures-league-of-legends-wild-rift-il2cpp
https://katyscode.wordpress.com/2021/01/15/reverse-engineering-adventures-league-of-legends-wild-rift-il2cpp
Adventures in code and reverse engineering
Reverse Engineering Adventures: League of Legends Wild Rift (IL2CPP)
The most common issue I receive on the tracker for Il2CppInspector is “this file won’t load”. Oftentimes this is due to a bug in the tool, but sometimes it leads me down a reverse…
Forwarded from Free Press Kashmir
India used our software to spy on Pakistan, China, says US Intel company | Free Press Kashmir https://freepresskashmir.news/2021/09/19/india-used-our-software-to-spy-on-pakistan-china-says-us-intel-company/
Free Press Kashmir
India used our software to spy on Pakistan, China, says US Intel company
Texas-based Exodus Intelligence believed India used its “zero-day”, security vulnerabilities that hackers can use to attack systems, to spy on Pakistan and China. According to a report published in Forbes, Exodus CEO and co-founder Logan Brown said that,…