Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
CVE-2024-2389 – Progress Flowmon Exploit PoC Released!

Progress published a critical security advisory on April 19th, 2024 for a vulnerability in Flowmon (CVE-2024-2389), allowing unauthenticated command injection. Rhino Security Labs released a proof of concept for this exploit. Users are urged to update to versions 12.3.5 or 11.1.14 to prevent exploitation. The threat of public exploitation remains significant.

https://hackhunting.com/2024/04/24/cve-2024-2389-progress-flomon-exploit-poc-released/


🎖@malwr
ArcaneDoor - New espionage-focused campaign found targeting perimeter network devices

ArcaneDoor is a campaign that is the latest example of state-sponsored actors targeting perimeter network devices from multiple vendors. Coveted by these actors, perimeter network devices are the perfect intrusion point for espionage-focused campaigns.

https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/


🎖@malwr
👍1
NetNTLM is still a thing?

In 2024 NetNTLM leaking is still a thing! In this post we will cover some parts of: Coerce User Authentication via NetNTLM and a file drop The mystery around HTTP.SYS Relaying without admin privileges Relaying with an active Windows firewall SSH Port forwarding

https://badoption.eu/blog/2024/04/25/netntlm.html


🎖@malwr
👍1
GitLab XSS Via Autocomplete Results

Overview The SonicWall Capture Labs threat research team became aware of a cross-site scripting vulnerability in GitLab, assessed its impact and developed mitigation measures. GitLab, an open-source code-sharing platform, published an advisory on this vulnerability

https://blog.sonicwall.com/en-us/2024/04/gitlab-xss-via-autocomplete-results/


🎖@malwr
Brokewell – Unknown Malware family Discovered to target Banking Applications

Brokewell is a new mobile malware targeting the banking industry. It includes a dropper with Android 13+ bypass capability. Victims are lured through phishing pages posing as browser updates. The malware can steal data, control devices remotely, and has specific commands for actions. The threat actor, identified as "Baron Samedit," also developed a bypass tool. Threat Fabric has published a comprehensive report on this malware.

https://hackhunting.com/2024/04/26/brokewell-unknown-malware-family-discovered-to-target-banking-applications/


🎖@malwr
Zombieware: Malware That Never Dies...
Self-replicating malware, long abandoned by its operators, continues to contribute significant volume and noise to malware feeds. We investigate this trend, which we refer to as Zombieware.

https://blog.unpac.me/2024/04/25/zombieware/


🎖@malwr
luijait/DarkGPT: DarkGPT is an OSINT assistant based on GPT-4-200K (recommended use) designed to perform queries on leaked databases, thus providing an artificial intelligence assistant that can be useful in your traditional OSINT processes.

https://github.com/luijait/DarkGPT


🎖@malwr
Embed A Malicious Executable in a Normal PDF or EXE | by Sam Rothlisberger | Medium
Today we’re going to show how to create a malicious executable that looks like a PDF, word doc, or web browser executable with the functionality of the normal file/program, but also our embedded…

https://medium.com/@sam.rothlisberger/embed-a-malicious-executable-in-a-normal-pdf-or-exe-81ee5339707e


🎖@malwr
Nightmare: One Byte to ROP // Deep Dive Edition - HackMD
# Nightmare: One Byte to ROP // Deep Dive Edition ## Introduction In this write-up, we'll discuss ho

https://hackmd.io/@pepsipu/ry-SK44pt


🎖@malwr
Hunting for a Sliver in a haystack
Explore how the Sliver framework is used by threat actors for covert control and information gathering. Learn about detection methods and hunting tactics in this insightful post.

https://www.huntandhackett.com/blog/hunting-for-a-sliver


🎖@malwr