Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
APT-C-36 new anti-detection tricks
https://lab52.io/blog/apt-c-36-new-anti-detection-tricks/


πŸŽ–@malwr
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users


The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.

Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...

https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
πŸ—£chrisknight1985


πŸŽ–@malwr
Q U I C K T I P
πŸ—£appleseed666


πŸŽ–@malwr
SharpML - Active Directory Password Hunting with ML for File-Shares
πŸ—£hunniccyber

Nice approach there!

You might want to have ML-folks/data scientists to chime in here; please add samples of the training data you used; above that, I couldn’t find any hints at the actual accuracy. NLP has seen some great results lately - keep experimenting!

Along the lines you mentioned potentially lacking (ML) domain knowledge - but still you will be offering a paid course - I’d rather render this into a joint research/project initiative. But these are just my 2 quarantined cents =]
πŸ‘€vornamemitd


πŸŽ–@malwr
Looking to learn about system exploitation, but don't know where to start? This (very) detailed guide covers all the basics. Contains 21 detailed CTF solutions, plenty of theory, and zero times the phrase "exercise left to the reader".
πŸ—£ynvb

> The standard answer is often an embarrassed mumble that there are no golden rules, and that you should probably follow this or that person on Twitter to get tips, then β€œgo practice, like you would with CTF exercises.”
CTF exercises are basically self-contained challenges that require the player to crack some problem and recover some piece of text (the β€œflag”) as a proof of having cracked the problem.

This is always my answer to this question.
πŸ‘€MaliciouSSymbol

Thank you!!!
πŸ‘€redimusu76

This is a great read. I hope more of this pops up.
πŸ‘€snake_case_believer


πŸŽ–@malwr