[PDF] OSS Supply Chain Security by the Linux Foundation
https://www.linuxfoundation.org/wp-content/uploads/2020/02/oss\_supply\_chain\_security.pdf
๐ฃdigicat
๐@malwr
https://www.linuxfoundation.org/wp-content/uploads/2020/02/oss\_supply\_chain\_security.pdf
๐ฃdigicat
๐@malwr
Workshop on Binary Analysis Research (BAR) 2020 at NDSS
๐ฃmttd
It would be nice to have the slides of the invited talks as well.
๐คXVilka
๐@malwr
๐ฃmttd
It would be nice to have the slides of the invited talks as well.
๐คXVilka
๐@malwr
ObliqueRAT, a new malware employed in attacks on government targets in Southeast Asia
๐ฃquellaman
๐@malwr
๐ฃquellaman
๐@malwr
Security Affairs
ObliqueRAT, a new malware employed in attacks on government targets
Cisco Talos researchers discovered a new malware, tracked as ObliqueRAT, that was employed targeted attacks against organizations in Southeast Asia.
Tutorial: Archive Azure AD logs to an Azure storage account
https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/quickstart-azure-monitor-route-logs-to-storage-account
๐ฃdigicat
๐@malwr
https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/quickstart-azure-monitor-route-logs-to-storage-account
๐ฃdigicat
๐@malwr
Docs
How to archive activity logs to a storage account - Microsoft Entra ID
Learn how to archive Microsoft Entra activity logs to a storage account through Diagnostic settings.
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations. (Note: it is designed to alert offense to defensive 'enquiries')
๐ฃdigicat
๐@malwr
๐ฃdigicat
๐@malwr
GitHub
GitHub - outflanknl/RedELK: Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as wellโฆ
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations. - outflanknl/RedELK
CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
๐ฃRedmondSecGnome
๐@malwr
๐ฃRedmondSecGnome
๐@malwr
Zero Day Initiative
Zero Day Initiative โ CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
This most recent Patch Tuesday, Microsoft released an Important-rated patch to address a remote code execution bug in Microsoft Exchange Server. This vulnerability was reported to us by an anonymous researcher and affects all supported versions of Microsoftโฆ
Defeating a Laptop's BIOS Password
๐ฃPowerOfLove1985
Remove the battery. Done.
๐คsmash_the_stack
๐@malwr
๐ฃPowerOfLove1985
Remove the battery. Done.
๐คsmash_the_stack
๐@malwr
GitHub
reblog/0000-defeating-a-laptops-bios-password/README.md at main ยท skysafe/reblog
SkySafe Miscellaneous Reverse Engineering Blog. Contribute to skysafe/reblog development by creating an account on GitHub.
North Korea Is Recycling Mac Malware
๐ฃCodePerfect
The great Best Korea is putting the environment first, even when it comes to software.
World leading!
๐คSamreinod
๐@malwr
๐ฃCodePerfect
The great Best Korea is putting the environment first, even when it comes to software.
World leading!
๐คSamreinod
๐@malwr
Wired
North Korea Is Recycling Mac Malware. That's Not the Worst Part
Lazarus Group hackers have long plagued the internetโusing at least one tool they picked up just by looking around online.
GWTUpload - vulnerability allowing to abuse the upload process and cause a total denial-of-service of a web server.
๐ฃlogicaltrust-net
๐@malwr
๐ฃlogicaltrust-net
๐@malwr
Security Audits, Penetration Tests - LogicalTrust
LogicalTrust - Blog - [EN] A-Z: GWTUpload - DoS
GWT is a Java web framework and GWTUpload is a library extending it with easier file upload.
We found a vulnerability allowing to abuse the upload process and cause a denial-of-service of a web application.
We found a vulnerability allowing to abuse the upload process and cause a denial-of-service of a web application.