Dark Reading: Attacks/Breaches
Colonial Pipeline CEO: Ransomware Attack Started via Pilfered 'Legacy' VPN Account
No multifactor authentication was attached to the stolen VPN password used by the attackers, Colonial Pipeline president & CEO Joseph Blount told a Senate committee today.
___________________________
@hacking_Attack
@Hacking_Video
Colonial Pipeline CEO: Ransomware Attack Started via Pilfered 'Legacy' VPN Account
No multifactor authentication was attached to the stolen VPN password used by the attackers, Colonial Pipeline president & CEO Joseph Blount told a Senate committee today.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Colonial Pipeline CEO: Ransomware Attack Started via Pilfered 'Legacy' VPN Account
No multi-factor authentication was attached to the stolen VPN password used by the attackers, Colonial Pipeline president & CEO Joseph Blount told a Senate committee today.
How i was able to bypass parental pin of showmax
https://abdulsec.medium.com/how-i-was-able-to-bypass-parental-pin-of-showmax-e6d6ec3af92d?source=rss------bug_bounty-5
Showmax is an online subscription video on demand service which launched in South Africa on 19 August 2015. Showmax is employing a…Continue reading on Medium » (https://abdulsec.medium.com/how-i-was-able-to-bypass-parental-pin-of-showmax-e6d6ec3af92d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
https://abdulsec.medium.com/how-i-was-able-to-bypass-parental-pin-of-showmax-e6d6ec3af92d?source=rss------bug_bounty-5
Showmax is an online subscription video on demand service which launched in South Africa on 19 August 2015. Showmax is employing a…Continue reading on Medium » (https://abdulsec.medium.com/how-i-was-able-to-bypass-parental-pin-of-showmax-e6d6ec3af92d?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
How i was able to bypass parental pin of showmax
Showmax is an online subscription video on demand service which launched in South Africa on 19 August 2015. Showmax is employing a…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Discussing Nation-State Cyber Intentions
https://cdn-images-1.medium.com/max/600/1*YwAZP8IQMnavXreOiYkEhQ.jpeg
Chaos for the Sake of Chaos? Yes, Nation-States Are That Cynical — Adam Darrah, Dark Reading, 6/2/2021
Continue reading on Hybrid Analyst »
___________________________
@hacking_Attack
@Hacking_Video
Discussing Nation-State Cyber Intentions
https://cdn-images-1.medium.com/max/600/1*YwAZP8IQMnavXreOiYkEhQ.jpeg
Chaos for the Sake of Chaos? Yes, Nation-States Are That Cynical — Adam Darrah, Dark Reading, 6/2/2021
Continue reading on Hybrid Analyst »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Discussing Nation-State Cyber Intentions
Chaos for the Sake of Chaos? Yes, Nation-States Are That Cynical — Adam Darrah, Dark Reading, 6/2/2021
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
PG — My-CMSMS— Walkthrough (Offensive Security Proving Grounds Play Boxes)
https://cdn-images-1.medium.com/max/600/1*_TTnT3KVrdE9RK90eg-jOg.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
PG — My-CMSMS— Walkthrough (Offensive Security Proving Grounds Play Boxes)
https://cdn-images-1.medium.com/max/600/1*_TTnT3KVrdE9RK90eg-jOg.png
Introduction
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
PG — My-CMSMS— Walkthrough (Offensive Security Proving Grounds Play Boxes)
Introduction
KitPloit - PenTest Tools!
ColdFire - Golang Malware Development Library
___________________________
@hacking_Attack
@Hacking_Video
ColdFire - Golang Malware Development Library
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
ColdFire - Golang Malware Development Library
How i was able to bypass parental pin of showmax
Showmax is an online subscription video on demand service which launched in South Africa on 19 August 2015. Showmax is employing a…Continue reading on Medium »
Read more...
Showmax is an online subscription video on demand service which launched in South Africa on 19 August 2015. Showmax is employing a…Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Federales ejecutaron en secreto una aplicación de chat encriptada falsa y arrestaron a más de 800…
https://cdn-images-1.medium.com/max/998/0*VmVu_kNhXJZ3tuWD.jpg
PUBLICADO EN 8 JUNIO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Federales ejecutaron en secreto una aplicación de chat encriptada falsa y arrestaron a más de 800…
https://cdn-images-1.medium.com/max/998/0*VmVu_kNhXJZ3tuWD.jpg
PUBLICADO EN 8 JUNIO, 2021 POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Federales ejecutaron en secreto una aplicación de chat encriptada falsa y arrestaron a más de 800 delincuentes.
PUBLICADO EN 8 JUNIO, 2021 POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
FBI HACKING?!!?!? Did they h4x0r Bitcoin?
No. No they did not.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
FBI HACKING?!!?!? Did they h4x0r Bitcoin?
No. No they did not.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
FBI HACKING?!!?!? Did they h4x0r Bitcoin?
No. No they did not.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Fun with a boarding pass: what information can you discover?
https://cdn-images-1.medium.com/max/2600/1*j5cxaHFp6MjzdAAUDBCaHw.jpeg
What data does that barcode contain? And what can you do with it? Everything, it turns out…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Fun with a boarding pass: what information can you discover?
https://cdn-images-1.medium.com/max/2600/1*j5cxaHFp6MjzdAAUDBCaHw.jpeg
What data does that barcode contain? And what can you do with it? Everything, it turns out…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Fun with a boarding pass: what information can you discover?
What data does that barcode contain? And what can you do with it? Everything, it turns out…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
This issue is needed to be addressed and you did it very well.
Thank you for the reminder, Carol Price!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
This issue is needed to be addressed and you did it very well.
Thank you for the reminder, Carol Price!
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
This issue is needed to be addressed and you did it very well.
Thank you for the reminder, Carol Price!
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Best Whatsapp Hacking Tools — Ripely Effective Messaging Spy Tool
https://cdn-images-1.medium.com/max/800/1*Fb1ANJT8-Ib31WURCQ898A.jpeg
Is there really such a thing as the Best Whatsapp Hacker for Hire? There are so many versions of Whimsical Hacker in the market that it..
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Best Whatsapp Hacking Tools — Ripely Effective Messaging Spy Tool
https://cdn-images-1.medium.com/max/800/1*Fb1ANJT8-Ib31WURCQ898A.jpeg
Is there really such a thing as the Best Whatsapp Hacker for Hire? There are so many versions of Whimsical Hacker in the market that it..
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Best Whatsapp Hacking Tools — Ripely Effective Messaging Spy Tool
Is there really such a thing as the Best Whatsapp Hacker for Hire? There are so many versions of Whimsical Hacker in the market that it..
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 FlawsPost Views: 53
Reading Time: 2 Minutes
Researchers discovered a highly targeted malware campaign launched in April, in which a new, unknown threat actor used two of the vulnerabilities that Microsoft said are under active attack.
Microsoft jumped on 50 vulnerabilities in this month’s Patch Tuesday update, issuing fixes for CVEs in Microsoft Windows, .NET Core and Visual Studio, Microsoft Office, Microsoft Edge (Chromium-based and EdgeHTML), SharePoint Server, Hyper-V, Visual Studio Code – Kubernetes Tools, Windows HTML Platform, and Windows Remote Desktop.
Five of the CVEs are rated Critical and 45 are rated Important in severity. Microsoft reported that six of the bugs are currently under active attack, while three are publicly known at the time of release.
The number might seem light – it represents six fewer patches than Microsoft released in May – but the number of critical vulnerabilities ticked up to five month-over-month.
Those actively exploited vulnerabilities can enable an attacker to hijack a system. They have no workarounds, so some security experts are recommending that they be patched as the highest priority.
The six CVEs under active attack in the wild include four elevation of privilege vulnerabilities, one information disclosure vulnerability and one remote code execution (RCE) vulnerability.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries Critical Bugs of NoteCVE-2021-31985 is a critical RCE vulnerability in Microsoft’s Defender antimalware software that should grab attention. A similar, critical bug in Defender was patched in January. The most serious of the year’s first Patch Tuesday, that earlier Defender bug was an RCE vulnerability that came under active exploit.
Another critical flaw is CVE-2021-31963, a Microsoft SharePoint Server RCE vulnerability. Jay Goodman, director of product marketing at Automox, said in a blog post that an attacker exploiting this vulnerability “could take control of a system where they would be free to install programs, view or change data, or create new accounts on the target system with full user rights.”
While Microsoft reports that this vulnerability is less likely to be exploited,Goodman suggested that organizations don’t let it slide: “Patching critical vulnerabilities in the 72-hour window before attackers can weaponize is an important first step to maintaining a safe and secure infrastructure,” he observed. https://media.threatpost.com/wp-content/uploads/sites/103/2021/06/08141612/Sophos-impact-chart-June-21-patch-Tuesday-e1623176186946.png A year-to-date summary of 2021 Microsoft vulnerability releases as of June. Source: Sophos
See Also: Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework Bugs Exploited in the WildMicrosoft fixed a total of seven zero-day vulnerabilities. One was CVE-2021-31968, Windows Remote Desktop Services Denial of Service Vulnerability that was publicly disclosed but hasn’t been seen in attacks. It was issued a CVSS score of 7.5.
These are the six flaws that MIcrosoft said are under active attack, all of them also zero days.
* CVE-2021-31955 – Windows Kernel Information Disclosure Vulnerability. Rating: Important. CVSS 5.5
* CVE-2021-31956 – Windows NTFS Elevation of Privilege Vulnerability. Rating: Important. CVSS 7.8
* CVE-2021-33739 – Microsoft DWM Core Library Elevation of Privilege Vulnerability. Rating: Importa[...]
___________________________
@hacking_Attack
@Hacking_Video
Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 Flaws
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Microsoft Patch Tuesday Fixes 6 In-The-Wild Exploits, 50 FlawsPost Views: 53
Reading Time: 2 Minutes
Researchers discovered a highly targeted malware campaign launched in April, in which a new, unknown threat actor used two of the vulnerabilities that Microsoft said are under active attack.
Microsoft jumped on 50 vulnerabilities in this month’s Patch Tuesday update, issuing fixes for CVEs in Microsoft Windows, .NET Core and Visual Studio, Microsoft Office, Microsoft Edge (Chromium-based and EdgeHTML), SharePoint Server, Hyper-V, Visual Studio Code – Kubernetes Tools, Windows HTML Platform, and Windows Remote Desktop.
Five of the CVEs are rated Critical and 45 are rated Important in severity. Microsoft reported that six of the bugs are currently under active attack, while three are publicly known at the time of release.
The number might seem light – it represents six fewer patches than Microsoft released in May – but the number of critical vulnerabilities ticked up to five month-over-month.
Those actively exploited vulnerabilities can enable an attacker to hijack a system. They have no workarounds, so some security experts are recommending that they be patched as the highest priority.
The six CVEs under active attack in the wild include four elevation of privilege vulnerabilities, one information disclosure vulnerability and one remote code execution (RCE) vulnerability.
See Also: RockYou2021: largest password compilation of all time leaked online – 8.4 billion entries Critical Bugs of NoteCVE-2021-31985 is a critical RCE vulnerability in Microsoft’s Defender antimalware software that should grab attention. A similar, critical bug in Defender was patched in January. The most serious of the year’s first Patch Tuesday, that earlier Defender bug was an RCE vulnerability that came under active exploit.
Another critical flaw is CVE-2021-31963, a Microsoft SharePoint Server RCE vulnerability. Jay Goodman, director of product marketing at Automox, said in a blog post that an attacker exploiting this vulnerability “could take control of a system where they would be free to install programs, view or change data, or create new accounts on the target system with full user rights.”
While Microsoft reports that this vulnerability is less likely to be exploited,Goodman suggested that organizations don’t let it slide: “Patching critical vulnerabilities in the 72-hour window before attackers can weaponize is an important first step to maintaining a safe and secure infrastructure,” he observed. https://media.threatpost.com/wp-content/uploads/sites/103/2021/06/08141612/Sophos-impact-chart-June-21-patch-Tuesday-e1623176186946.png A year-to-date summary of 2021 Microsoft vulnerability releases as of June. Source: Sophos
See Also: Offensive Security Tool: Pacu – The Amazon Web Services Exploitation Framework Bugs Exploited in the WildMicrosoft fixed a total of seven zero-day vulnerabilities. One was CVE-2021-31968, Windows Remote Desktop Services Denial of Service Vulnerability that was publicly disclosed but hasn’t been seen in attacks. It was issued a CVSS score of 7.5.
These are the six flaws that MIcrosoft said are under active attack, all of them also zero days.
* CVE-2021-31955 – Windows Kernel Information Disclosure Vulnerability. Rating: Important. CVSS 5.5
* CVE-2021-31956 – Windows NTFS Elevation of Privilege Vulnerability. Rating: Important. CVSS 7.8
* CVE-2021-33739 – Microsoft DWM Core Library Elevation of Privilege Vulnerability. Rating: Importa[...]
___________________________
@hacking_Attack
@Hacking_Video