Malware News
15.5K subscribers
1.64K photos
7 videos
130 files
8.05K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
GitHub - reemertastic/infosec-spam-list: List of unwarranted sales email domains you can add to your junk mail filter
πŸ—£Reemertastic

I somehow got signed up for a conference and had my email get put on a list a few years back, so I've been adding domains to my Outlook junk mail list for a while. I figured others probably have the same issue, so I might as well share it. I could unsubscribe from the emails, but I don't want to fall victim to any phishing campaigns (especially when I've used that tactic for some of our phishing campaigns).
πŸ‘€Reemertastic


πŸŽ–@malwr
Ticket resellers infected with a credit card skimmer
πŸ—£ThisIsLibra

Great write up! Really informative
πŸ‘€naraaz


πŸŽ–@malwr
Unconfirmed Solarwinds Zero Day
Taken from another group - Thanks to Thomas F.

A security researcher has found a 0-day in N-central. Solarwinds has not replied in the 90 day window and it was released last night on PacketStorm (since removed until a patch is released).

According to the post, this was after the 90 day disclosure window lapsed. Huntressabs has confirmed the vulnerability, which passes default site credentials (domain administrator in most cases) in clear text: https://www.youtube.com/watch?v=YAEqkZSv6XI

There were ready-made tools already posted to Github that allowed anyone to take advantage of the exploit.

Solarwinds says they are working on a fix to be released today.

Immediate mitigation can be achieved by removing the default appliance credentials from each location in N-Central.
πŸ—£RobMSP

It's confirmed - even SW posted on it

https://success.solarwindsmsp.com/forum-post/X0D51T00007EEKLMSA5/
πŸ‘€madra05

The irony that SW had 90 days to address but didn't. We departed ncentral this summer because they promised improvements to report manager for over two years that never came. Just shows that lack of action in one area is a pretty good sign of a rotted culture.
πŸ‘€iloveurarse

Ouch
πŸ‘€SAL10000


πŸŽ–@malwr
Suspected Iranian hacking campaign targets European energy companies.


FULL LINK: https://www.zdnet.com/article/suspected-iranian-hacking-campaign-targets-european-energy-sector/
πŸ—£Spectrumsploit


πŸŽ–@malwr