AWS CloudQuarry: Digging for Secrets in Public AMIs – Security Café
Money, secrets and mass exploitation: This research unveils a quarry of sensitive data stored in public AMIs. Digging through each AMI we managed to collect 500 GB of credentials, private repositories, access keys and more. The present article is the detailed analysis of how we did it and what the data represents. We did a…
https://securitycafe.ro/2024/05/08/aws-cloudquarry-digging-for-secrets-in-public-amis/
🎖@malwr
Money, secrets and mass exploitation: This research unveils a quarry of sensitive data stored in public AMIs. Digging through each AMI we managed to collect 500 GB of credentials, private repositories, access keys and more. The present article is the detailed analysis of how we did it and what the data represents. We did a…
https://securitycafe.ro/2024/05/08/aws-cloudquarry-digging-for-secrets-in-public-amis/
🎖@malwr
Security Café
AWS CloudQuarry: Digging for Secrets in Public AMIs
Money, secrets and mass exploitation: This research unveils a quarry of sensitive data stored in public AMIs. Digging through each AMI we managed to collect 500 GB of credentials, private repositor…
APT28 campaign directed against Polish government institutions
CERT Polska is observing a malicious e-mail campaign conducted by the APT28 group against Polish government institutions.
https://cert.pl/en/posts/2024/05/apt28-campaign/
🎖@malwr
CERT Polska is observing a malicious e-mail campaign conducted by the APT28 group against Polish government institutions.
https://cert.pl/en/posts/2024/05/apt28-campaign/
🎖@malwr
cert.pl
APT28 campaign targeting Polish government institutions
CERT Polska is observing a malicious e-mail campaign targeting Polish government institutions conducted by the APT28 group.
👍1
Iran-Aligned Emerald Divide Influence Campaign Evolves to Exploit Israel-Hamas Conflict
Explore how Iran-aligned Emerald Divide exploits the Israel-Hamas conflict in an ongoing influence campaign to deepen divisions within Israeli society.
https://www.recordedfuture.com/iran-aligned-emerald-divide-influence-campaign-evolves-to-exploit-israel-hamas-conflict
🎖@malwr
Explore how Iran-aligned Emerald Divide exploits the Israel-Hamas conflict in an ongoing influence campaign to deepen divisions within Israeli society.
https://www.recordedfuture.com/iran-aligned-emerald-divide-influence-campaign-evolves-to-exploit-israel-hamas-conflict
🎖@malwr
👍1
LNK File Disguised as Certificate Distributing RokRAT Malware - ASEC BLOG
AhnLab Security Emergency response Center
https://asec.ahnlab.com/en/65076/
🎖@malwr
AhnLab Security Emergency response Center
https://asec.ahnlab.com/en/65076/
🎖@malwr
ASEC
LNK File Disguised as Certificate Distributing RokRAT Malware - ASEC
LNK File Disguised as Certificate Distributing RokRAT Malware ASEC
Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three — Elastic Security Labs
In previous articles in this multipart series, malware researchers on the Elastic Security Labs team dove into the REMCOS execution flow. In this article, you’ll learn more about REMCOS configuration structure and its C2 commands.
https://www.elastic.co/security-labs/dissecting-remcos-rat-part-three
🎖@malwr
In previous articles in this multipart series, malware researchers on the Elastic Security Labs team dove into the REMCOS execution flow. In this article, you’ll learn more about REMCOS configuration structure and its C2 commands.
https://www.elastic.co/security-labs/dissecting-remcos-rat-part-three
🎖@malwr
www.elastic.co
Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three — Elastic Security Labs
In previous articles in this multipart series, malware researchers on the Elastic Security Labs team dove into the REMCOS execution flow. In this article, you’ll learn more about REMCOS configuration structure and its C2 commands.
madhuakula/kubernetes-goat: Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
https://github.com/madhuakula/kubernetes-goat
🎖@malwr
https://github.com/madhuakula/kubernetes-goat
🎖@malwr
GitHub
GitHub - madhuakula/kubernetes-goat: Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes…
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀 - madhuakula/kubernetes-goat
From Spam to AsyncRAT: Tracking the Surge in Non-PE Cyber Threats
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/from-spam-to-asyncrat-tracking-the-surge-in-non-pe-cyber-threats/
🎖@malwr
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/from-spam-to-asyncrat-tracking-the-surge-in-non-pe-cyber-threats/
🎖@malwr
McAfee Blog
From Spam to AsyncRAT: Tracking the Surge in Non-PE Cyber Threats | McAfee Blog
Authored by Yashvi Shah and Preksha Saxena AsyncRAT, also known as "Asynchronous Remote Access Trojan," represents a highly sophisticated malware variant
JavaScript Debugging with Maglev Compiler | by VXRL | Medium
Other than fuzzing for vulnerabilities of our previous blogpost, it would be good to understand how Maglev compiler works via debugging. In the following article, we are going to briefly introduce…
https://vxrl.medium.com/javascript-debugging-with-maglev-compiler-6b2a26cb1a3a
🎖@malwr
Other than fuzzing for vulnerabilities of our previous blogpost, it would be good to understand how Maglev compiler works via debugging. In the following article, we are going to briefly introduce…
https://vxrl.medium.com/javascript-debugging-with-maglev-compiler-6b2a26cb1a3a
🎖@malwr
Medium
JavaScript Debugging with Maglev Compiler
Twitter: @Darkfloyd1014
CrowdStrike Enhances Cloud Asset Visualization to Accelerate Risk Prioritization
The massive increase in cloud adoption has driven adversaries to focus their efforts on cloud environments — a shift that led to cloud intrusions increasing by 75% in 2023, emphasizing the need for stronger cloud security. Larger scale leads to larger risk. As organizations increase their quantity of cloud assets, their attack surface grows. Each...
https://www.crowdstrike.com/blog/enhanced-cloud-asset-visualization/
🎖@malwr
The massive increase in cloud adoption has driven adversaries to focus their efforts on cloud environments — a shift that led to cloud intrusions increasing by 75% in 2023, emphasizing the need for stronger cloud security. Larger scale leads to larger risk. As organizations increase their quantity of cloud assets, their attack surface grows. Each...
https://www.crowdstrike.com/blog/enhanced-cloud-asset-visualization/
🎖@malwr
CrowdStrike.com
CrowdStrike Enhances Cloud Asset Visualization to Accelerate Risk Prioritization
We have enhanced CrowdStrike Falcon® Cloud Security capabilities so security analysts can easily visualize their cloud assets’ connections and better understand and prioritize risks.
Russia-Linked CopyCop Uses LLMs to Weaponize Influence Content at Scale
Insikt Group shares research on CopyCop: a Russian-linked network using AI for disinformation to influence US, UK, and French politics. Dive into the details.
https://www.recordedfuture.com/russia-linked-copycop-uses-llms-to-weaponize-influence-content-at-scale
🎖@malwr
Insikt Group shares research on CopyCop: a Russian-linked network using AI for disinformation to influence US, UK, and French politics. Dive into the details.
https://www.recordedfuture.com/russia-linked-copycop-uses-llms-to-weaponize-influence-content-at-scale
🎖@malwr
CVE-2024-21115: An Oracle VirtualBox LPE Used to Win Pwn2Own
https://www.thezdi.com/blog/2024/5/9/cve-2024-21115-an-oracle-virtualbox-lpe-used-to-win-pwn2own
🎖@malwr
https://www.thezdi.com/blog/2024/5/9/cve-2024-21115-an-oracle-virtualbox-lpe-used-to-win-pwn2own
🎖@malwr
Zero Day Initiative
Zero Day Initiative — CVE-2024-21115: An Oracle VirtualBox LPE Used to Win Pwn2Own
In this guest blog from Pwn2Own winner Cody Gallagher, he details CVE-2024-21115 – an Out-of-Bounds (OOB) Write that occurs in Oracle VirtualBox that can be leveraged for privilege escalation. This bug was recently patched by Oracle in April. Cody has…
zEus Stealer Distributed via Crafted Minecraft Source Pack | FortiGuard Labs
FortiGuard Labs analysis of a zEus batch stealer distributed via a crafted Minecraft source pack.
https://www.fortinet.com/blog/threat-research/zeus-stealer-distributed-via-crafted-minecraft-source-pack
🎖@malwr
FortiGuard Labs analysis of a zEus batch stealer distributed via a crafted Minecraft source pack.
https://www.fortinet.com/blog/threat-research/zeus-stealer-distributed-via-crafted-minecraft-source-pack
🎖@malwr
Fortinet Blog
zEus Stealer Distributed via Crafted Minecraft Source Pack
FortiGuard Labs analysis of a zEus batch stealer distributed via a crafted Minecraft source pack. Learn more.…
Fuel for thought: Can a driverless car get arrested?
What happens when problems caused by autonomous vehicles are not the result of errors, but the result of purposeful attacks?
https://www.welivesecurity.com/en/cybersecurity/fuel-thought-can-driverless-car-get-arrested/
🎖@malwr
What happens when problems caused by autonomous vehicles are not the result of errors, but the result of purposeful attacks?
https://www.welivesecurity.com/en/cybersecurity/fuel-thought-can-driverless-car-get-arrested/
🎖@malwr
Welivesecurity
Fuel for thought: Can a driverless car get arrested?
What happens when problems caused by autonomous vehicles are not the result of errors, but the result of purposeful attacks?
Coverage guided fuzzing for native Android libraries (Frida & Radamsa) - KnifeCoat
Coverage guided fuzzing for native Android libraries (Frida & Radamsa) - KnifeCoat
https://knifecoat.com/Posts/Coverage+guided+fuzzing+for+native+Android+libraries+(Frida+%26+Radamsa)
🎖@malwr
Coverage guided fuzzing for native Android libraries (Frida & Radamsa) - KnifeCoat
https://knifecoat.com/Posts/Coverage+guided+fuzzing+for+native+Android+libraries+(Frida+%26+Radamsa)
🎖@malwr
KnifeCoat
Coverage guided fuzzing for native Android libraries (Frida & Radamsa) - KnifeCoat
Intro Recently I have been getting into userland application testing on Android. I want to credit Iddo and Jacob for their excellent course on attacking IM Applications which I took at zer0con. As a …
2024-05-09: GootLoader activity
https://www.malware-traffic-analysis.net/2024/05/09/index.html
🎖@malwr
https://www.malware-traffic-analysis.net/2024/05/09/index.html
🎖@malwr
Telekopye: Chamber of Neanderthals’ secrets
Insight into groups operating Telekopye bots that scam people in online marketplaces
https://www.welivesecurity.com/en/eset-research/telekopye-chamber-neanderthals-secrets/
🎖@malwr
Insight into groups operating Telekopye bots that scam people in online marketplaces
https://www.welivesecurity.com/en/eset-research/telekopye-chamber-neanderthals-secrets/
🎖@malwr
Welivesecurity
Telekopye: Chamber of Neanderthals’ secrets
ESET research shares insights about groups operating Telekopye, Telegram bots that scam people in online marketplaces, their internal onboarding process, different tricks of trade that Neanderthals use, and more.
Doctor Web’s annual virus activity review for 2023
https://news.drweb.com/show/?i=14851&lng=en&c=5
🎖@malwr
https://news.drweb.com/show/?i=14851&lng=en&c=5
🎖@malwr
Exploring the Depths of SolarMarker's Multi-tiered Infrastructure
Uncover SolarMarker’s multi-tiered infrastructure and its impact on sectors like education, healthcare, and government. Learn more.
https://www.recordedfuture.com/exploring-the-depths-of-solarmarkers-multi-tiered-infrastructure
🎖@malwr
Uncover SolarMarker’s multi-tiered infrastructure and its impact on sectors like education, healthcare, and government. Learn more.
https://www.recordedfuture.com/exploring-the-depths-of-solarmarkers-multi-tiered-infrastructure
🎖@malwr
XWiki Remote Code Execution Vulnerability
Overview The SonicWall Capture Labs threat research team became aware of CVE-2024-31984, which is a code injection vulnerability in XWiki’s management of space titles and has a critical CVSS score of 9.9. After assessing the
https://blog.sonicwall.com/en-us/2024/05/xwiki-remote-code-execution-vulnerability/
🎖@malwr
Overview The SonicWall Capture Labs threat research team became aware of CVE-2024-31984, which is a code injection vulnerability in XWiki’s management of space titles and has a critical CVSS score of 9.9. After assessing the
https://blog.sonicwall.com/en-us/2024/05/xwiki-remote-code-execution-vulnerability/
🎖@malwr
Foxit PDF “Flawed Design” Exploitation
https://research.checkpoint.com/2024/foxit-pdf-flawed-design-exploitation/
🎖@malwr
https://research.checkpoint.com/2024/foxit-pdf-flawed-design-exploitation/
🎖@malwr
Check Point Research
Foxit PDF “Flawed Design” Exploitation - Check Point Research
Check Point Research has identified an unusual pattern of behavior involving PDF exploitation, mainly targeting users of Foxit Reader. This exploit triggers security warnings that could deceive unsuspecting users into executing harmful commands. Check Point…
GitCaught: Threat Actor Leverages GitHub Repository for Malicious Infrastructure
Discover how Russian-speaking hackers leverage GitHub to host malware disguised as legitimate software. Explore the campaign, implications, and protection strategies.
https://www.recordedfuture.com/gitcaught-threat-actor-leverages-github-repository-for-malicious-infrastructure
🎖@malwr
Discover how Russian-speaking hackers leverage GitHub to host malware disguised as legitimate software. Explore the campaign, implications, and protection strategies.
https://www.recordedfuture.com/gitcaught-threat-actor-leverages-github-repository-for-malicious-infrastructure
🎖@malwr