Malware News
12.9K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
MSIFortune - LPE with MSI Installers
A quite long blogpost about several types of LPEs which I found in the msi repair function.

There is a lot of different stuff, much more then Mandiant reveiled a few months ago.

Tested about 1000 msi which was quite time consuming.

https://badoption.eu/blog/2023/10/03/MSIFortune.html
πŸ—£PfiatDe


πŸŽ–@malwr
πŸ‘1
TargetCompany Ransomware Abuses FUD Obfuscator Packers

In this entry, we detail our analysis of how the TargetCompany ransomware abused an iteration of fully undetectable (FUD) obfuscator engine BatCloak to infect vulnerable systems.

https://www.trendmicro.com/en_us/research/23/h/targetcompany-ransomware-abuses-fud-obfuscator-packers.html


πŸŽ–@malwr
πŸ‘1
Remote Code Execution In PyTorch Model Server TorchServe
Remote Code Execution In PyTorch Model Server TorchServe

Oligo's research team has uncovered a chain of critical vulnerabilities, named ShellTorch, including CVE-2023-43654 (CVSS: 9.8) in the PyTorch model server TorchServe.

This flaw allows unauthorized access to #AI models and enables Remote Code Execution (RCE) leaving countless services and end-users at risk.
πŸ—£BigBother59


πŸŽ–@malwr
😱1
2023-10-03 - Pikabot infection with Cobalt Strike

https://www.malware-traffic-analysis.net/2023/10/03/index.html


πŸŽ–@malwr
Quishing Triage 101: How to Investigate Suspicious QR Codes in Emails

Quishing, derived from combining β€œQR code” and β€œphishing,” has manifested as a significant cybersecurity threat, particularly noting a discernible surge in incidents since July 2023. This technique leverages QR codes, square barcodes decipherable by mobile device cameras, to mislead users into interacting with malicious digital content. When a user scans a QR code in a...

https://intezer.com/blog/alert-triage/quishing-triage-how-to-investigate-suspicious-qr-codes-in-emails/


πŸŽ–@malwr
Python SAST Security Tools?

So, for my apprenticeship i have to find a new SAST Security Tool to integrate into a pipeline. The only actual boundary is that it has to be open-source. Just so you know, the pipeline runs into a Docker container. It would be better if it easily implementable (in this project we use mainly Docker, maven and pip to install new tools in the container). Another guideline would be to find a tool that analyzes very used languages (like Python or Java). Alternately, can do other stuff but it should be simple enough to me to understand it (maybe policies tester are out of my league? i dunno).
We already use Trivy, Bandit, Semgrep, Safety, Checkov, [and under maven:\] Spotbugs, OWASP DC and Spotless (Techincally also Kubescape and Talisman but we have not fully developed them yet)
Before you ask, yes...i've tried to search on my own (pretty deeply, i think). So this what my precedent tries/alternatives are:
\- Flawfinder (a bit tricky to install and analyze only C/C++)
\- Pysa/Pyrecheck (it's not easy to install, hard to understand, and prints strange errors)
\- Bearer (probably my choice if i don't find a python alternative but...i hate Java)
Sorry for the long message and thanks to all for any advice or answer on the post. Of course i don't expect you to research, that is my job. Just write if anything pops in your mind.
Thx again!
πŸ—£Fanta_futuro

Your org is already using much of what is available for your needs so I’m not sure what OSS are available with your criteria that could offer you more or even in-addition too, but you’ve already first hand have seen this yourself.

I know many tools to meet your needs but now we’re moving away from OSS and into SaaS but my guess is you have no budget for that.

Off the cuff what are the odds that the ask could pivot to SCA provided you and everyone else are large consumers of OSS and need to/should maybe look to consider your OSS risk?

Otherwise the only thing I can offer you is this link to GitHub that may be of assistance.

https://github.com/analysis-tools-dev/static-analysis#python
πŸ‘€Sivyre


πŸŽ–@malwr
πŸ‘1
Binarly REsearch - Multiple Critical Vulnerabilities in Supermicro BMCs
πŸ—£netsec_burn

Aren't we past this stuff yet:


Unfortunately, as usually happens during the disclosure process, the vendor tried to reduce the final impact of the documented vulnerabilities. We believe this to be an extremely wrong position, since end customers will have incorrect information when assessing the severity of a particular update. We encourage system administrators to keep their BMC systems up to date and follow NSA and CISA hardening guidelines.
πŸ‘€derp6996


πŸŽ–@malwr