Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.7K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Twilio discloses data breach after SMS phishing attack on employees

Twilio discloses data breach after SMS phishing attack on employeesPost Views: 20 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon-1.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Cloud communications company Twilio says some of its customers’ data was accessed by attackers who breached internal systems after stealing employee credentials in an SMS phishing attack.“On August 4, 2022, Twilio became aware of unauthorized access to information related to a limited number of Twilio customer accounts through a sophisticated social engineering attack designed to steal employee credentials,” Twilio said over the weekend.

“The attackers then used the stolen credentials to gain access to some of our internal systems, where they were able to access certain customer data.”

The company also revealed the attackers gained access to its systems after tricking and stealing credentials from multiple employees targeted in the phishing incident.

To do that, they impersonated Twilio’s IT department, asking them to click URLs containing “Twilio,” “Okta,” and “SSO” keywords that would redirect them to a Twilio sign-in page clone.

​The SMS phishing messages baited Twilio’s employees into clicking the embedded links by warning them that their passwords had expired or were scheduled to be changed.
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course
​Twilio’s EMEA Communications Director Katherine James declined to provide more information when asked how many employees had their accounts compromised in the phishing attack and how many customers were affected by the breach, saying the company has “no additional comment to provide at this time beyond what is posted in the blog.”
https://www.bleepstatic.com/images/news/u/1109292/2022/Twilio_phishing_SMS.png
<figcaptionTwilio SMS phishing message (Twilio)
“The text messages originated from U.S. carrier networks. We worked with the U.S. carriers to shut down the actors and worked with the hosting providers serving the malicious URLs to shut those accounts down,” Twilio added.

“We have heard from other companies that they, too, were subject to similar attacks, and have coordinated our response to the threat actors – including collaborating with carriers to stop the malicious messages, as well as their registrars and hosting providers to shut down the malicious URLs. Despite this response, the threat actors have continued to rotate through carriers and hosting providers to resume their attacks.”
Trending: Find Hidden Info using Google Dorking manually, and Automated using Pagodo
Trending: Offensive Security Tool: Offensive-Azure Credentials revoked, attackers yet to be identifiedThe company has not yet identified the attackers, but it’s working with law enforcement as part of an ongoing investigation.

Twilio revoked the employee accounts compromised during the attack to block the attackers’ access to its systems and has started notifying customers affected by this incident.

“As the threat actors were able to access a limited number of accounts’ data, we have been notifying the affected customers on an individual basis with the details,” Twilio also revealed.

The company also disclosed in May 2021 that it was impacted by last year’s Codecov supply-chain attack where threat actors modified the legitimate Codecov Bash Uploader tool to steal credentials, secret keys, and user tokens from Codecov customers.

With more than 5,000 employees in 26 offices in 17 countries, Twillio provides programmable voice, text, chat, video, and email APIs used by over 10 mi[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Twilio discloses data breach after SMS phishing attack on employees Twilio discloses data breach after SMS phishing attack on employeesPost Views: 20 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Patreon…
llion developers and 150,000 businesses to build customer engagement platforms.

Twilio also acquired Authy in February 2015, a popular two-factor authentication (2FA) provider for end users, developers, and enterprises with millions of users worldwide.
Trending: New Linux malware called RapperBot brute-forces Linux SSH servers to breach networks
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-5-300x150.png Researcher bypass email filter – XSS in Gmail’s AMP For EmailAugust 9, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-3-1-300x150.png Twitter confirms zero-day used to expose data of 5.4 million accountsAugust 8, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-2-300x150.png New Linux malware called RapperBot brute-forces Linux SSH servers to breach networksAugust 5, 2022
Reading Time: 4 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/08/Images-for-the-News-posts-1-300x150.png Jenkins security: Unpatched XSS, CSRF bugs included in latest plugin advisoryAugust 4, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post Twilio discloses data breach after SMS phishing attack on employees first appeared on Black Hat Ethical Hacking.
MrKaplan - Tool Aimed To Help Red Teamers To Stay Hidden By Clearing Evidence Of Execution
http://www.kitploit.com/2022/08/mrkaplan-tool-aimed-to-help-red-teamers.html
MrKaplan is a tool aimed to help red teamers (https://www.kitploit.com/search/label/Red%20Teamers) to stay hidden (https://www.kitploit.com/search/label/Hidden) by clearing evidence of execution. It works by saving information such as the time it ran, snapshot of files and associate each evidence to the related user. This tool is inspired by MoonWalk (https://github.com/mufeedvh/moonwalk), a similar tool for Unix machines. You can read more about it in the wiki (https://github.com/idov31/MrKaplan/wiki) page.
Features Stopping event logging. Clearing files artifacts. Clearing registry (https://www.kitploit.com/search/label/Registry) artifacts. Can run for multiple users. Can run as user and as admin (Highly recommended to run as admin). Can save timestamps of files. Can exclude certian operations (https://www.kitploit.com/search/label/Operations) and leave artifacts to blue teams. Usage Before you start your operations on the computer, run MrKaplan with begin flag and whenever your finish run it again with end flag. DO NOT REMOVE MrKaplan registry key, otherwise MrKaplan will not be able to use the information. IOCs Powershell process that access (https://www.kitploit.com/search/label/Access) to the artifacts mentioned in the wiki page. Powershell importing weird base64 blob. Powershell process that performs Token Manipulation. MrKaplan's registry key: HKCU:\Software\MrKaplan. Acknowledgements PowerSploit (https://github.com/PowerShellMafia/PowerSploit) Phant0m (https://github.com/hlldz/Phant0m) ForensicArtifacts (https://github.com/ForensicArtifacts/artifacts/blob/main/data/windows.yaml) Disclaimer I'm not responsible in any way for any kind of damage that is done to your computer / program as cause of this project. I'm happily accept contribution, make a pull request and I will review it!

Download MrKaplan (https://github.com/Idov31/MrKaplan)
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
MrKaplan - Tool Aimed To Help Red Teamers To Stay Hidden By Clearing Evidence Of Execution

https://blogger.googleusercontent.com/img/a/AVvXsEjVzZflpt_RNPgIMXcYGuCD4exXELaGPG9DIfm72NSrXe6kh2AjSQI_5g1GgFC6URJQha1wDQMx8NlaF1svT6J_V9u0jd2PIVRbZ1skA00HahwQcAWjAs9iBHdTbcAXaEB4i_F0Iy47gxMkypTPtK1UbSp4iTc1Toy5P1S3iVOQZwWItl-wzxo7M7s6=w640-h476
MrKaplan is a tool aimed to help red teamers to stay hidden by clearing evidence of execution. It works by saving information such as the time it ran, snapshot of files and associate each evidence to the related user.

This tool is inspired by MoonWalk, a similar tool for Unix machines.

You can read more about it in the wiki page.
Features

* Stopping event logging.
* Clearing files artifacts.
* Clearing registry artifacts.
* Can run for multiple users.
* Can run as user and as admin (Highly recommended to run as admin).
* Can save timestamps of files.
* Can exclude certian operations and leave artifacts to blue teams.

Usage

* Before you start your operations on the computer, run MrKaplan with begin flag and whenever your finish run it again with end flag.
* DO NOT REMOVE MrKaplan registry key, otherwise MrKaplan will not be able to use the information.

IOCs

*
Powershell process that access to the artifacts mentioned in the wiki page.

*
Powershell importing weird base64 blob.

*
Powershell process that performs Token Manipulation.

*
MrKaplan's registry key: HKCU:\Software\MrKaplan.
Acknowledgements

*
PowerSploit

*
Phant0m

*
ForensicArtifacts
Disclaimer

I'm not responsible in any way for any kind of damage that is done to your computer / program as cause of this project. I'm happily accept contribution, make a pull request and I will review it!
Download MrKaplan
Dark Reading: Attacks/Breaches
Human Threat Hunters Are Essential to Thwarting Zero-Day Attacks

Machine-learning algorithms alone may miss signs of a successful attack on your organization.
Dark Reading: Attacks/Breaches
Don't Take the Cyber Safety Review Board's Log4j Report at Face Value

Given the lack of reporting requirements, the findings are more like assumptions. Here's what organizations can do to minimize exposure.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Lacework Updates Threat Detection To Uncover More Malicious Activity and Speed Investigation at Scale

New time series model and enhanced alerting experience make it easy for organizations to address more threats in the cloud while enabling faster investigations.