This media is not supported in your browser
VIEW IN TELEGRAM
#CVE-2022-22947 Spring Cloud Gateway SpEL Remote Code Execution
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
π£pyn3rd
π@malwr
https://wya.pl/2022/02/26/cve-2022-22947-spel-casting-and-evil-beans/
π£pyn3rd
π@malwr
Android Malware Research (aka the team I'm on :) is looking for an experienced Android malware reverse engineer in NYC!
https://careers.google.com/jobs/results/105670070832636614-senior-security-engineer-android-security/
π£maldr0id
π@malwr
https://careers.google.com/jobs/results/105670070832636614-senior-security-engineer-android-security/
π£maldr0id
π@malwr
Google
Build for Everyone - Google Careers
Careers at Google - find a job at Google. Look inside engineering jobs at Google.
Announcing Windows 11 Insider Preview Build 22567
https://blogs.windows.com/windows-insider/2022/03/02/announcing-windows-11-insider-preview-build-22567/
π£windowsblog
π@malwr
https://blogs.windows.com/windows-insider/2022/03/02/announcing-windows-11-insider-preview-build-22567/
π£windowsblog
π@malwr
Windows Insider Blog
Announcing Windows 11 Insider Preview Build 22567
UPDATE 3/7: We are starting to roll out Cumulative Update Build 22567.200 (KB5012432). This update does not include anything new and is designed to test our servicing pipeline for builds in the Dev Channel.
NOTE: Windows Insider
NOTE: Windows Insider
Ghidra for beginners - Pwn Zero To Hero
π£PinkDraconian
Great video as always
π€navneetmuffin
π@malwr
π£PinkDraconian
Great video as always
π€navneetmuffin
π@malwr
YouTube
Ghidra - Pwn Zero To Hero 0x02
Full Pwn Zero To Hero playlist: https://www.youtube.com/playlist?list=PLeSXUd883dhjmKkVXSRgI1nJEZUDzgLf_
Crackmes: https://crackmes.one/
βΆοΈ YouTube: https://www.youtube.com/c/PinkDraconian
π Patreon: https://www.patreon.com/PinkDraconian
π¦ Twitter: httβ¦
Crackmes: https://crackmes.one/
βΆοΈ YouTube: https://www.youtube.com/c/PinkDraconian
π Patreon: https://www.patreon.com/PinkDraconian
π¦ Twitter: httβ¦
A deep dive into HermeticWiper's internals
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/digging-into-hermeticwiper.html
βΉοΈ Sent from one of our channel members
π@malwr
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/digging-into-hermeticwiper.html
βΉοΈ Sent from one of our channel members
π@malwr
Trellix
Digging into HermeticWiper
The HermeticWiper malware aims to destroy the boot sectors of any (removable) disk on the infected machine, with the help of a benign partition manager driver.
π1
Find out how two flaws in NETGEAR DGND3700v2 devices allow remote unauthenticated attackers to trigger bypass the authentication mechanism and run commands as root
π£SSDisclosure
π@malwr
π£SSDisclosure
π@malwr
SSD Secure Disclosure
SSD Advisory β NETGEAR DGND3700v2 PreAuth Root Access - SSD Secure Disclosure
Find out how a vulnerability in multiple Uniview devices allow remote unauthenticated attackers to trigger a remote code execution vulnerability in the products the company offers.
Reversing embedded device bootloader (U-Boot) & decrypt the firmware - (Part
1 - Shielder ) : https://www.shielder.it/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.1/ credits
@zi0Black @Th3Zer0
π£binitamshah
π@malwr
1 - Shielder ) : https://www.shielder.it/blog/2022/03/reversing-embedded-device-bootloader-u-boot-p.1/ credits
@zi0Black @Th3Zer0
π£binitamshah
π@malwr
π1
http://phishstats.info detected 111 new websites hosting #phishing | new today: 788 | #infosec #cybersecurity #malware
π£PhishStats
π@malwr
π£PhishStats
π@malwr
Malfrat's OSINT Map is live on https://map.malfrats.industries !
We forked http://osintframework.com since this is no longer maintained, so you can easily contribute on our repo.
Thanks for their original work.
π£MalfratsInd
π@malwr
We forked http://osintframework.com since this is no longer maintained, so you can easily contribute on our repo.
Thanks for their original work.
π£MalfratsInd
π@malwr
If you're looking to practice your #malware #analysis skills, I have several exercises available:
π https://github.com/jstrosch/malware-samples
These include challenge tasks and detailed walk-throughs. You'll also find them as CTF challenges at CyberDefenders
π https://cyberdefenders.org/blueteam-ctf-challenges/
π£jstrosch
π@malwr
π https://github.com/jstrosch/malware-samples
These include challenge tasks and detailed walk-throughs. You'll also find them as CTF challenges at CyberDefenders
π https://cyberdefenders.org/blueteam-ctf-challenges/
π£jstrosch
π@malwr
Day 78 #100DaysofYARA - fun with the dotnet module
looking for user strings (typically wide strings) that imply command execution. Why look in this way vs just as strings?
Well this rule tells us immediately that the file is a dotnet executable
π£greglesnewich
π@malwr
looking for user strings (typically wide strings) that imply command execution. Why look in this way vs just as strings?
Well this rule tells us immediately that the file is a dotnet executable
π£greglesnewich
π@malwr
A nice bit of #HermeticWiper reversing by @eln0tyβ
https://eln0ty.github.io/malware%20analysis/HermeticWiper/
π£juanandres_gs
π@malwr
https://eln0ty.github.io/malware%20analysis/HermeticWiper/
π£juanandres_gs
π@malwr
eln0ty
HermeticWiper/FoxBlade Analysis (in-depth)
The malware which targeting Ukrainian infrastructure (Specially windows devices) has since been observed in the neighboring countries of Latvia and Lithuania and manipulating the MBR resulting in subsequent boot failure.
Full Reverse Engineering of Sony Memory Stick
π£dmitrygr
Is there any easy way to spoof the card serial number?
A MCU acting as man-in-the-middle, or something else?
I need it to unbrick a PSP 2000.
π€RainyShadow
Nice!
Sony, the king of proprietary mediums. What a nightmare for consumers and devs alike.
π€usernamenottakenwooh
MagicGate still holding up?
π€TailSpinBowler
π@malwr
π£dmitrygr
Is there any easy way to spoof the card serial number?
A MCU acting as man-in-the-middle, or something else?
I need it to unbrick a PSP 2000.
π€RainyShadow
Nice!
Sony, the king of proprietary mediums. What a nightmare for consumers and devs alike.
π€usernamenottakenwooh
MagicGate still holding up?
π€TailSpinBowler
π@malwr
Dmitry.GR
Sony Memory Stick - Dmitry.GR
Dmitry.GR: The first complete documentation of Sony Memory Stick from HW to DATA
Debugger and analyzer for ELF executables named "donna" made by me . Im still a HS student so any help would be appreciated. Made in C++ btw.
π£suibex
Writing a debugger in high school? Color me impressed.
π€jameson71
Suggestion: remove all the random empty lines you have littered throughout the code or just run you code through a formatter.
π€magion
π@malwr
π£suibex
Writing a debugger in high school? Color me impressed.
π€jameson71
Suggestion: remove all the random empty lines you have littered throughout the code or just run you code through a formatter.
π€magion
π@malwr
GitHub
GitHub - suibex/donna: Debugger and analyzer for ARM ELF executables.
Debugger and analyzer for ARM ELF executables. Contribute to suibex/donna development by creating an account on GitHub.
Suspected Conti Ransomware Activity in the Auto Manufacturing Sector - looks like they used Netflow to understand who the victims were
π£digicat
π@malwr
π£digicat
π@malwr
Dragos
Suspected Conti Ransomware Activity in the Auto Manufacturing Sector
Dragos is observing evidence of multiple automotive manufacturers compromised by Emotet. A malware strain & a cybercrime operation.
DirtyMoe: Worming Modules - The DirtyMoe malware is deployed using various kits like PurpleFox or injected installers of Telegram Messenger that require user interaction. Complementary to this deployment, one of the modules expands the malware using worm-like techniques that require no interaction
π£digicat
π@malwr
π£digicat
π@malwr
Gendigital
DirtyMoe: Worming Modules
DirtyMoe's Rapid Worming Expansion