We wrapped ourselves in ourselves, like closing a cocoon. Will we become butterflies? π«₯
Anyway,
More Zero-Days !!!
β Citrix fixes critical RCE flaws (CVE-2023-6548, CVE-2023-6549) exploited in wild.
β VMware Aria Automation bug (CVE-2023-34063) allows attacker control.
β Atlassian issues fixes for 24+ flaws, including RCE.
Patch, Update ASAP:
https://thehackernews.com/2024/01/citrix-vmware-and-atlassian-hit-with.html
DFIR
Infographics
"Log Sources v.1.1", 12.2023.
https://github.com/Neo23x0/Talks
ββ Hackstack Security ββ
@hackstacksecurity
Follow Us On Twitter: https://twitter.com/hackstacksec
Contact Us: https://hackstacksecure.com/contact
Anyway,
More Zero-Days !!!
β Citrix fixes critical RCE flaws (CVE-2023-6548, CVE-2023-6549) exploited in wild.
β VMware Aria Automation bug (CVE-2023-34063) allows attacker control.
β Atlassian issues fixes for 24+ flaws, including RCE.
Patch, Update ASAP:
https://thehackernews.com/2024/01/citrix-vmware-and-atlassian-hit-with.html
DFIR
Infographics
"Log Sources v.1.1", 12.2023.
https://github.com/Neo23x0/Talks
ββ Hackstack Security ββ
@hackstacksecurity
Follow Us On Twitter: https://twitter.com/hackstacksec
Contact Us: https://hackstacksecure.com/contact
Exploring FBot: Python-Based Malware Targeting Cloud and Payment Services
https://www.sentinelone.com/labs/exploring-fbot-python-based-malware-targeting-cloud-and-payment-services
ββ Hackstack Security ββ
@hackstacksecurity
Follow Us On Twitter: https://twitter.com/hackstacksec
Contact Us: https://hackstacksecure.com/contact
https://www.sentinelone.com/labs/exploring-fbot-python-based-malware-targeting-cloud-and-payment-services
ββ Hackstack Security ββ
@hackstacksecurity
Follow Us On Twitter: https://twitter.com/hackstacksec
Contact Us: https://hackstacksecure.com/contact
SentinelOne
Exploring FBot | Python-Based Malware Targeting Cloud and Payment Services
FBot arms threat actors with a multi-function attack tool designed to hijack cloud, Saas and web services.
By living deeply in the present moment we can understand the past better and we can prepare for a better future
Top 10 Vulnerabilities of 2023:
1. CVE-2023-34362: MOVEit Vulnerability
2. CVE-2023-23397: MS Outlook PE
3. CVE-2023-43641: 1-Click RCE on GNOME
4. CVE-2023-28252: Windows CLFS PE
5. CVE-2023-2868: Barracuda ESG CI
6. CVE-2023-26360: Adobe ColdFusion
7. CVE-2023-4966: Citrix Bleed
8. CVE-2023-22952: SugarCRM RCE
9. CVE-2023-24880: Win Smart Screen Bypass
https://www.vicarius.io/vsociety/posts/windows-smartscreen-security-feature-bypass-cve-2023-24880
10. CVE-2022-42475:
FortiOS heap-based buffer overflow in sslvpnd
https://bishopfox.com/blog/exploit-cve-2022-42475
https://github.com/scrt/cve-2022-42475
ββ Hackstack Security ββ
@hackstacksecurity
Follow Us On Twitter: https://twitter.com/hackstacksec
Follow Our Page On LinkedIn: https://www.linkedin.com/company/hackstack-security/
Follow Us On Instagram: https://www.instagram.com/hackstacksecurity/
Contact Us: https://hackstacksecure.com/contact
1. CVE-2023-34362: MOVEit Vulnerability
2. CVE-2023-23397: MS Outlook PE
3. CVE-2023-43641: 1-Click RCE on GNOME
4. CVE-2023-28252: Windows CLFS PE
5. CVE-2023-2868: Barracuda ESG CI
6. CVE-2023-26360: Adobe ColdFusion
7. CVE-2023-4966: Citrix Bleed
8. CVE-2023-22952: SugarCRM RCE
9. CVE-2023-24880: Win Smart Screen Bypass
https://www.vicarius.io/vsociety/posts/windows-smartscreen-security-feature-bypass-cve-2023-24880
10. CVE-2022-42475:
FortiOS heap-based buffer overflow in sslvpnd
https://bishopfox.com/blog/exploit-cve-2022-42475
https://github.com/scrt/cve-2022-42475
ββ Hackstack Security ββ
@hackstacksecurity
Follow Us On Twitter: https://twitter.com/hackstacksec
Follow Our Page On LinkedIn: https://www.linkedin.com/company/hackstack-security/
Follow Us On Instagram: https://www.instagram.com/hackstacksecurity/
Contact Us: https://hackstacksecure.com/contact
www.vicarius.io
Windows SmartScreen Security Feature bypass (CVE-2023-24880) - vsociety
Are you looking for FREE cybersecurity certifications?
1. Vulnerability Management: https://lnkd.in/g64maMet
2. Global IT Asset Inventory: https://lnkd.in/gXR5bD5N
3. Scanning Strategies: https://lnkd.in/g6cQjQuh
4. Reporting Strategies: https://lnkd.in/gs6Vn-DA
5. Patch Management: https://lnkd.in/gnWVDCNp
6. Policy Compliance: https://lnkd.in/g5SXKncJ
7. PCI Compliance: https://lnkd.in/gZns6Xdf
8. Endpoint Detection & Response: https://lnkd.in/gw22Y__E
9. Vulnerability Management: https://lnkd.in/gYAFfAuT
10. Cloud Security Assessment & Response: https://lnkd.in/grrHivcW
11. API Fundamentals: https://lnkd.in/gngVxhbu
12. Cloud Agent: https://lnkd.in/gngVxhbu
13. Container Security: https://lnkd.in/gYNCGY8A
14. File Integrity Monitoring: https://lnkd.in/gYNCGY8A
15. Web Application Scanning: https://lnkd.in/ggpJ-vG6
Here are 15 FREE courses provided by the Qualys.
https://www.linkedin.com/posts/hackstack-security_cybersecurity-freecourses-infosec-activity-7154837232141402112-4kjb
ββ Hackstack Security ββ
@hackstacksecurity
Contact Us: https://hackstacksecure.com/contact/
1. Vulnerability Management: https://lnkd.in/g64maMet
2. Global IT Asset Inventory: https://lnkd.in/gXR5bD5N
3. Scanning Strategies: https://lnkd.in/g6cQjQuh
4. Reporting Strategies: https://lnkd.in/gs6Vn-DA
5. Patch Management: https://lnkd.in/gnWVDCNp
6. Policy Compliance: https://lnkd.in/g5SXKncJ
7. PCI Compliance: https://lnkd.in/gZns6Xdf
8. Endpoint Detection & Response: https://lnkd.in/gw22Y__E
9. Vulnerability Management: https://lnkd.in/gYAFfAuT
10. Cloud Security Assessment & Response: https://lnkd.in/grrHivcW
11. API Fundamentals: https://lnkd.in/gngVxhbu
12. Cloud Agent: https://lnkd.in/gngVxhbu
13. Container Security: https://lnkd.in/gYNCGY8A
14. File Integrity Monitoring: https://lnkd.in/gYNCGY8A
15. Web Application Scanning: https://lnkd.in/ggpJ-vG6
Here are 15 FREE courses provided by the Qualys.
https://www.linkedin.com/posts/hackstack-security_cybersecurity-freecourses-infosec-activity-7154837232141402112-4kjb
ββ Hackstack Security ββ
@hackstacksecurity
Contact Us: https://hackstacksecure.com/contact/
lnkd.in
LinkedIn
This link will take you to a page thatβs not on LinkedIn
π3
236 - Bypassing Chromecast Secure-Boot and Exploiting Factorio
https://dayzerosec.com/podcast/236.html
https://dayzerosec.com/podcast/236.html
dayzerosec
Bypassing Chromecast Secure-Boot and Exploiting Factorio
A bit of a game special this week, with a Counter-Strike: Global Offensive vulnerability and an exploit for Factorio. We also have a Linux kernel bug and a Chromecast secure-boot bypass with some hardware hacking mixed in.
π₯1
1. CVE-2023-5347, CVE-2023-5376:
Korenix JetNet Series Unauthenticated Access
https://packetstormsecurity.com/files/176550/Korenix-JetNet-Series-Unauthenticated-Access.html
2. CVE-2023-51252:
XSS vulnerability caused by file uploads in PublicCMS V4.0
https://github.com/sanluan/PublicCMS/issues/79
3. CVE-2023-50643:
Arbitrary code execution in MacOS Evernote
https://github.com/V3x0r/CVE-2023-50643
Korenix JetNet Series Unauthenticated Access
https://packetstormsecurity.com/files/176550/Korenix-JetNet-Series-Unauthenticated-Access.html
2. CVE-2023-51252:
XSS vulnerability caused by file uploads in PublicCMS V4.0
https://github.com/sanluan/PublicCMS/issues/79
3. CVE-2023-50643:
Arbitrary code execution in MacOS Evernote
https://github.com/V3x0r/CVE-2023-50643
packetstorm.news
Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers
PoC to takeover Android using another Android by exploiting critical Bluetooth vulnerability to install Metasploit without proper Bluetooth pairing (CVE-2023-45866). It still affects Android 10 and bellow.
https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/
https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/
Mobile Hacker
Exploiting 0-click Android Bluetooth vulnerability to inject keystrokes without pairing - Mobile Hacker
[update 2024-02-19] This vulnerability can be even used to remotely wipe data of targeted Android smartphone. Using this vulnerability it is possible to guess user lock screen PIN. After five incorrect PINs device is locked out for 30 seconds. This operationβ¦