Frida 12.8.15 is out w/ full support for iOS/arm64e and iOS 13.4
π£oleavr
Says it was released is December 2019?
π€tigr87
I simple getting started guide if interested.
https://frida.re/docs/ios/
π€littlejob
π@malwr
π£oleavr
Says it was released is December 2019?
π€tigr87
I simple getting started guide if interested.
https://frida.re/docs/ios/
π€littlejob
π@malwr
Frida β’ A world-class dynamic instrumentation toolkit
iOS
Observe and reprogram running programs on Windows, macOS, GNU/Linux, iOS, watchOS, tvOS, Android, FreeBSD, and QNX
Understanding Hardware-enforced Stack Protection
https://techcommunity.microsoft.com/t5/windows-kernel-internals/understanding-hardware-enforced-stack-protection/ba-p/1247815
π@malwr
https://techcommunity.microsoft.com/t5/windows-kernel-internals/understanding-hardware-enforced-stack-protection/ba-p/1247815
π@malwr
TECHCOMMUNITY.MICROSOFT.COM
Understanding Hardware-enforced Stack Protection
ROP (Return Oriented Programming) based control flow attacks have become a common form of attack. In this post, we will describe our efforts to harden control..
APT-C-36 new anti-detection tricks
https://lab52.io/blog/apt-c-36-new-anti-detection-tricks/
π@malwr
https://lab52.io/blog/apt-c-36-new-anti-detection-tricks/
π@malwr
Dear Windows Defender, please tell me where I can drop my malicious code
π£packmad
Lol Microsoft's response is great
π€wilhouse
π@malwr
π£packmad
Lol Microsoft's response is great
π€wilhouse
π@malwr
Medium
Dear Windows Defender, please tell me where I can drop my malicious code.
The Get-MpPreference cmdlet exposes the field ExclusionPath without administrator privilege.
How the Iranian Cyber Security Agency Detects Emissary Panda Malware
https://blog.team-cymru.com/2020/03/25/how-the-iranian-cyber-security-agency-detects-emissary-panda-malware/
π@malwr
https://blog.team-cymru.com/2020/03/25/how-the-iranian-cyber-security-agency-detects-emissary-panda-malware/
π@malwr
Team Cymru
Blog - Team Cymru
This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits
https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html
π@malwr
https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html
π@malwr
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany
https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/
π@malwr
https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/
π@malwr
Security Intelligence
TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany
Our team is closely monitoring TrickBot's developing capabilities, including its new cross-channel attacks using the TrickMo component.
Icnanker, a Linux Trojan-Downloader Protected by SHC
https://blog.netlab.360.com/icnanker-trojan-downloader-shc-en/
π@malwr
https://blog.netlab.360.com/icnanker-trojan-downloader-shc-en/
π@malwr
360 Netlab Blog - Network Security Research Lab at 360
Icnanker, a Linux Trojan-Downloader Protected by SHC
Background
On August 15, 2019, 360Netlab Threat Detecting System flagged an unknown ELF sample (5790dedae465994d179c63782e51bac1) which generated Elknot Botnet related network traffic. We manually took a look and noticed that it is a Trojan-Downloader whichβ¦
On August 15, 2019, 360Netlab Threat Detecting System flagged an unknown ELF sample (5790dedae465994d179c63782e51bac1) which generated Elknot Botnet related network traffic. We manually took a look and noticed that it is a Trojan-Downloader whichβ¦
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...
https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
π£chrisknight1985
π@malwr
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...
https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
π£chrisknight1985
π@malwr
BleepingComputer
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Chinese Hackers Attacked Foreign Health Care, Military, Oil Networks as Coronavirus Hit China
π£FourFans0fFreedom
π@malwr
π£FourFans0fFreedom
π@malwr
Defense One
Chinese Hackers Attacked Foreign Health Care, Military, Oil Networks as Coronavirus Hit China
In January, the βwidespreadβ assault targeted a vulnerability in virtual desktops, cloud computing, and network applications, FireEye announced.
Operation Poisoned News: Hong Kong Users Targeted With Mobile Malware via Local News Links
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/
π@malwr
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/
π@malwr
Trend Micro
Research, News, and Perspectives
Azorult loader stages
https://maxkersten.nl/binary-analysis-course/malware-analysis/azorult-loader-stages/
π@malwr
https://maxkersten.nl/binary-analysis-course/malware-analysis/azorult-loader-stages/
π@malwr
SharpML - Active Directory Password Hunting with ML for File-Shares
π£hunniccyber
Nice approach there!
You might want to have ML-folks/data scientists to chime in here; please add samples of the training data you used; above that, I couldnβt find any hints at the actual accuracy. NLP has seen some great results lately - keep experimenting!
Along the lines you mentioned potentially lacking (ML) domain knowledge - but still you will be offering a paid course - Iβd rather render this into a joint research/project initiative. But these are just my 2 quarantined cents =]
π€vornamemitd
π@malwr
π£hunniccyber
Nice approach there!
You might want to have ML-folks/data scientists to chime in here; please add samples of the training data you used; above that, I couldnβt find any hints at the actual accuracy. NLP has seen some great results lately - keep experimenting!
Along the lines you mentioned potentially lacking (ML) domain knowledge - but still you will be offering a paid course - Iβd rather render this into a joint research/project initiative. But these are just my 2 quarantined cents =]
π€vornamemitd
π@malwr
Hunnic Cyber Blog
Password Hunting with Machine Learning in Active Directory
tdlr: Situation: - Passwords embedded in files on fileshares lead to compromise. Complication: - It is hard to tell what is a password. Resolution: - Use SharpML toβ¦