■■□□□ Cyber-Attack: Non-state actors from Bangladesh and Sudan are launching attacks against Israel and its allies (incl. UAE).
They were able to take-down at least two government websites this weekend.
● mod.gov.ae (https://check-host.net/check-report/ff922fakef)
● moei.gov.ae (https://check-host.net/check-report/ff93a14k6d3)
They were able to take-down at least two government websites this weekend.
● mod.gov.ae (https://check-host.net/check-report/ff922fakef)
● moei.gov.ae (https://check-host.net/check-report/ff93a14k6d3)
■■■■□ Israel government torpedoed Morocco spyware deal - and caused NSO's competitor QuaDream to shut down.
https://www.haaretz.com/israel-news/security-aviation/2023-05-22/ty-article/.premium/israel-torpedoed-morocco-spyware-deal-and-nso-competitor-quadream-shut-down/00000188-425a-d805-a7c9-dbdbd7f50000
https://www.haaretz.com/israel-news/security-aviation/2023-05-22/ty-article/.premium/israel-torpedoed-morocco-spyware-deal-and-nso-competitor-quadream-shut-down/00000188-425a-d805-a7c9-dbdbd7f50000
Haaretz.com
Israel torpedoed Morocco spyware deal - and NSO competitor QuaDream shut down
***
cKure
■■□□□ Cyber-Attack: Non-state actors from Bangladesh and Sudan are launching attacks against Israel and its allies (incl. UAE). They were able to take-down at least two government websites this weekend. ● mod.gov.ae (https://check-host.net/check-report/ff922fakef)…
■□□□□ That actor shifts attention out of UAE for a while back to Israel.
The Cyber Attacks so far have not garnered anything significant other than service outage for a while.
The Cyber Attacks so far have not garnered anything significant other than service outage for a while.
■■■■□ Windows: From DA to EA with ESC5.
https://posts.specterops.io/from-da-to-ea-with-esc5-f9f045aa105c
https://posts.specterops.io/from-da-to-ea-with-esc5-f9f045aa105c
SpecterOps
From DA to EA with ESC5 - SpecterOps
You’ve heard of ESC1 and ESC8, but what about ESC5? See how an adversary can use ESC5 followed by ESC1 to turn DA in a child domain into EA at the forest root.
■■■□□ CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
https://github.com/dhmosfunk/CVE-2023-25690-POC
https://github.com/dhmosfunk/CVE-2023-25690-POC
GitHub
GitHub - dhmosfunk/CVE-2023-25690-POC: CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server…
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability. - dhmosfunk/CVE-2023-25690-POC
■■□□□ Exploiting Windows on ARM RDP Client (CVE-2023-24905).
https://cyolo.io/blog/dll-hijacking-strikes-back-exploiting-windows-on-arm-rdp-client-cve-2023-24905/
https://cyolo.io/blog/dll-hijacking-strikes-back-exploiting-windows-on-arm-rdp-client-cve-2023-24905/
Cyolo
DLL Hijacking Strikes Back: Exploiting Windows on ARM RDP Client (CVE-2023-24905)
Dor Dali of Cyolo uncovers CVE-2023-24905, a RCE vulnerability in Windows on ARM RDP Client. This blog explores the vulnerability’s root causes and significance.
■□□□□ Indian local news site taken down by Indonesian hackers. The attack is part on ongoing cyber activity against anti-muslim state.
https://swarajtv24.com/
Information shared via Telegram channel of 'Hacktivist Indonesia'
https://swarajtv24.com/
Information shared via Telegram channel of 'Hacktivist Indonesia'
Forwarded from cKure Red
CVE-2022-3723_PoC.js
668 B
CVE-2022-3723 Exploit PoC: Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
● @ckure has not verified the authenticity of the exploit.
● @ckure has not verified the authenticity of the exploit.
■■■□□ GitLab asks users to update critical flaw.
https://www.bleepingcomputer.com/news/security/gitlab-strongly-recommends-patching-max-severity-flaw-asap/
https://www.bleepingcomputer.com/news/security/gitlab-strongly-recommends-patching-max-severity-flaw-asap/
BleepingComputer
GitLab 'strongly recommends' patching max severity flaw ASAP
GitLab has released an emergency security update, version 16.0.1, to address a maximum severity (CVSS v3.1 score: 10.0) path traversal flaw tracked as CVE-2023-2825.
■■□□□ Massive Cyber Attack on UAE Banking Sector: Mysterious Team Bangladesh Claims to Hit First Abu Dhabi Bank.
Attack type: Distributed Denial of Service
https://thecyberexpress.com/cyber-attack-on-uae-banking-sector-adcb-nbf/amp/
Attack type: Distributed Denial of Service
https://thecyberexpress.com/cyber-attack-on-uae-banking-sector-adcb-nbf/amp/
The Cyber Express
Cyber Attack On UAE Banking Sector: ADCB, NBF Websites Hit
Cyber attack on UAE banking sector continues, with hacker group Mysterious Team Bangladesh claiming to take down ADCB and NBF websites
cKure
■■□□□ Massive Cyber Attack on UAE Banking Sector: Mysterious Team Bangladesh Claims to Hit First Abu Dhabi Bank. Attack type: Distributed Denial of Service https://thecyberexpress.com/cyber-attack-on-uae-banking-sector-adcb-nbf/amp/
■■□□□ UAE (opUAE update): ENOC services down as Sudan based hackers target the country.
Redeeming points via Yes app (owned by ENOC) disabled amid attacks.
Redeeming points via Yes app (owned by ENOC) disabled amid attacks.
■■□□□ Impacket Cheatsheet For Penetration Testers
Attribution link.
https://latesthackingnews.com/2023/05/22/impacket-cheatsheet-for-penetration-testers/
https://latesthackingnews.com/2023/05/22/impacket-cheatsheet-for-penetration-testers/
Attribution link.
https://latesthackingnews.com/2023/05/22/impacket-cheatsheet-for-penetration-testers/
https://latesthackingnews.com/2023/05/22/impacket-cheatsheet-for-penetration-testers/
LHN
Impacket Cheatsheet For Penetration Testers
Discover the power of Impacket, an incredibly versatile collection of Python classes for working with network protocols. In this Impacket cheatsheet, we will dive into some of the most essential command examples, outlining their functionalities
Forwarded from cKure Red
⚠️ ‘Despicable’ iPhone Hacks In Armenia Find NSO Spyware ‘In Active Warzone’.
For the first time, the Israeli company’s spyware has been used in a conflict zone, according to researchers.
In mid-2021, Apple sent a warning to Anna Naghdalyan, then a spokesperson for Armenia’s foreign affairs agency, that her iPhone had possibly been hacked by a foreign government.
https://www.forbes.com/sites/thomasbrewster/2023/05/25/iphone-hacks-in-armenia-show-nso-spyware-in-warzone/?sh=4b76625f1a56
For the first time, the Israeli company’s spyware has been used in a conflict zone, according to researchers.
In mid-2021, Apple sent a warning to Anna Naghdalyan, then a spokesperson for Armenia’s foreign affairs agency, that her iPhone had possibly been hacked by a foreign government.
https://www.forbes.com/sites/thomasbrewster/2023/05/25/iphone-hacks-in-armenia-show-nso-spyware-in-warzone/?sh=4b76625f1a56
Forbes
‘Despicable’ iPhone Hacks In Armenia Find NSO Spyware ‘In Active Warzone’
For the first time, the Israeli company’s spyware has been used in a conflict zone, according to researchers.
■■□□□ Cybercrime: Zyxel Firewalls Hacked by Mirai Botnet.
https://www.securityweek.com/zyxel-firewalls-hacked-by-mirai-botnet-via-recently-patched-vulnerability/
https://www.securityweek.com/zyxel-firewalls-hacked-by-mirai-botnet-via-recently-patched-vulnerability/
SecurityWeek
Zyxel Firewalls Hacked by Mirai Botnet
A Mirai botnet has been exploiting a recently patched vulnerability tracked as CVE-2023-28771 to hack many Zyxel firewalls.
■■■■□ AI enabled bug bounty.
How ChatGPT helped me find a bug?
https://abhishekgk.medium.com/how-chatgpt-helped-me-find-a-bug-b5a3795c722
How ChatGPT helped me find a bug?
https://abhishekgk.medium.com/how-chatgpt-helped-me-find-a-bug-b5a3795c722
Medium
How ChatGPT helped me find a bug
Hello and welcome to my latest Medium writeup! I’m thrilled to share my thoughts and insights with you today on How I used chatgpt to find…
■■■□□ Data-Leak from Indonesia as newtons police records hit darknet's 🌑 exposed forums.
● ckure has not verified the data and this post is based on speculation.
● ckure has not verified the data and this post is based on speculation.
■□□□□ Data-Leak from Japan 🗾 as https://www.mlit.go.jp/en/ data alleged is posted online.
As per attacker, records contain employee names and emails in csv format.
The actor has credentials for the administrative panel on the site.
● Never underestimate the power of weak credentials.
As per attacker, records contain employee names and emails in csv format.
The actor has credentials for the administrative panel on the site.
● Never underestimate the power of weak credentials.
● After quite some time @ckure has integrated its alerting systems with https://exposed.vc for news and updates.
webroker.vc
The domain name EXPOSED.VC is for sale | WeBroker.VC
The domain name EXPOSED.VC is for sale - WeBroker.VC