Malware News
12.9K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
2023-10-03 - Pikabot infection with Cobalt Strike

https://www.malware-traffic-analysis.net/2023/10/03/index.html


๐ŸŽ–@malwr
Quishing Triage 101: How to Investigate Suspicious QR Codes in Emails

Quishing, derived from combining โ€œQR codeโ€ and โ€œphishing,โ€ has manifested as a significant cybersecurity threat, particularly noting a discernible surge in incidents since July 2023. This technique leverages QR codes, square barcodes decipherable by mobile device cameras, to mislead users into interacting with malicious digital content. When a user scans a QR code in a...

https://intezer.com/blog/alert-triage/quishing-triage-how-to-investigate-suspicious-qr-codes-in-emails/


๐ŸŽ–@malwr
Python SAST Security Tools?

So, for my apprenticeship i have to find a new SAST Security Tool to integrate into a pipeline. The only actual boundary is that it has to be open-source. Just so you know, the pipeline runs into a Docker container. It would be better if it easily implementable (in this project we use mainly Docker, maven and pip to install new tools in the container). Another guideline would be to find a tool that analyzes very used languages (like Python or Java). Alternately, can do other stuff but it should be simple enough to me to understand it (maybe policies tester are out of my league? i dunno).
We already use Trivy, Bandit, Semgrep, Safety, Checkov, [and under maven:\] Spotbugs, OWASP DC and Spotless (Techincally also Kubescape and Talisman but we have not fully developed them yet)
Before you ask, yes...i've tried to search on my own (pretty deeply, i think). So this what my precedent tries/alternatives are:
\- Flawfinder (a bit tricky to install and analyze only C/C++)
\- Pysa/Pyrecheck (it's not easy to install, hard to understand, and prints strange errors)
\- Bearer (probably my choice if i don't find a python alternative but...i hate Java)
Sorry for the long message and thanks to all for any advice or answer on the post. Of course i don't expect you to research, that is my job. Just write if anything pops in your mind.
Thx again!
๐Ÿ—ฃFanta_futuro

Your org is already using much of what is available for your needs so Iโ€™m not sure what OSS are available with your criteria that could offer you more or even in-addition too, but youโ€™ve already first hand have seen this yourself.

I know many tools to meet your needs but now weโ€™re moving away from OSS and into SaaS but my guess is you have no budget for that.

Off the cuff what are the odds that the ask could pivot to SCA provided you and everyone else are large consumers of OSS and need to/should maybe look to consider your OSS risk?

Otherwise the only thing I can offer you is this link to GitHub that may be of assistance.

https://github.com/analysis-tools-dev/static-analysis#python
๐Ÿ‘คSivyre


๐ŸŽ–@malwr
๐Ÿ‘1
Binarly REsearch - Multiple Critical Vulnerabilities in Supermicro BMCs
๐Ÿ—ฃnetsec_burn

Aren't we past this stuff yet:


Unfortunately, as usually happens during the disclosure process, the vendor tried to reduce the final impact of the documented vulnerabilities. We believe this to be an extremely wrong position, since end customers will have incorrect information when assessing the severity of a particular update. We encourage system administrators to keep their BMC systems up to date and follow NSA and CISA hardening guidelines.
๐Ÿ‘คderp6996


๐ŸŽ–@malwr
Qakbot-affiliated actors distribute Ransom Night malware despite infrastructure takedown

The threat actors behind the Qakbot malware have been conducting a campaign since early August 2023 in which they have been distributing Ransom Knight ransomware and the Remcos backdoor via phishing emails.

https://blog.talosintelligence.com/qakbot-affiliated-actors-distribute-ransom/


๐ŸŽ–@malwr
Is it bad to have a major security incident on your rรฉsumรฉ? (Seriously I donโ€™t know)

Plus, Qakbot appears to be still active, despite efforts from the FBI and other international law enforcement agencies to disrupt the massive botnet.

https://blog.talosintelligence.com/threat-source-newsletter-oct-5-2023/


๐ŸŽ–@malwr
How can I improve my chances of getting a role in DF?
I've worked for a while as a cop alongside university, and I'm really enjoying investigative work. By the end of the year I will have a BSc in Forensic Investigation, only one of the units was Digital Forensics which I scored a high first in. I've been working in IT for years now doing various repairs (hardware and software), soldering, including data recovery etc.

If I want to join as a Digital Forensics investigator in law enforcement, is there any hope, or have I sabotaged myself by not doing a computer science degree, as unsurprisingly it is a minimum starting point for a few positions I've found. Can accreditations like CompTIA or EC Council give me a better chance at these roles?
๐Ÿ—ฃForensiss

That background would get you a job with us and any number of other agencies I know. Guy I work with, an amazing examiner, but his degree was in forensic science. He wanted and applied to be in crime scene, but they saw he had a computer class so they said this is forensics too! 22 years later he's still in the game and schooling us every day. I wish DF did a better job with delineating the positions and levels out there. I feel like a lot of people are thinking everyone is responding to a DDoS and then reverse engineering malware when the real world is vastly different. Some days it's converting VHS tapes to digital to make the examination faster. It's not a super hard program so you don't need to be a computer science degree, but you'll need more than the some decent excel skills and the ability to reboot stuff. Now yes some people are doing amazingly advanced stuff and are Cyber Spooks, but sometimes you're the guy doing a logical on the phone of a victim of insurance fraud. Noble work in the end and you are more than qualified.
๐Ÿ‘คJerseyJunto

What has your own investigation into DF told you so far?

Just being LE (on its own) doesn't really qualify you for anything DF related.

A college course with one unit in DF doesn't do really that much.Soldering? Haven't used it once in over 23 years.

So, it boils down to how much past the few pages of Google do you look?What can you do that the person next to you can't?

Same as going for Sgt., Lt. or Detective. You get to the boards, how can you articulate your skills to the person wanting to retain you?

Can you withstand having your skills questioned by a competent attorney or judge?

What I hear from people at conferences and boards is that people jump in and want to join the DF world, talk about investigative experience, then don't mention what that experience is. Branch out and talk about your skills to the group and maybe someone here can help guide ya.
๐Ÿ‘คclarkwgriswoldjr

Do colleges have career centers to help students anymore?
๐Ÿ‘คMDCDF


๐ŸŽ–@malwr
โค1๐Ÿ‘1