Attack landscape update: Ransomware 2.0, automated recon, and supply chain attacks https://blog.f-secure.com/attack-landscape-update-h1-2021/
F-Secure Blog
Attack landscape update: Ransomware 2.0, automated recon, and supply chain attacks - F-Secure Blog
Data-stealing ransomware attacks, information harvesting malware, and supply chain attacks are some of the critical threats facing organizations highlighted in F-Secure’s latest attack landscape update. According to the report, a new type of extortion researchers…
Web skimmer hides within EXIF metadata, exfiltrates credit cards via image files https://blog.malwarebytes.com/threat-analysis/2020/06/web-skimmer-hides-within-exif-metadata-exfiltrates-credit-cards-via-image-files/
Malwarebytes
Web skimmer hides within EXIF metadata, exfiltrates credit cards via image files | Malwarebytes Labs
This credit card skimmer hides in plain sight, quite literally, as it resides inside the metadata of image files. We analyze the threat.
APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign https://securelist.com/apt10-sophisticated-multi-layered-loader-ecipekac-discovered-in-a41apt-campaign/101519/
Securelist
APT10: sophisticated multi-layered loader Ecipekac discovered in A41APT campaign
A41APT is a long-running campaign with activities detected from March 2019 to the end of December 2020. Most of the discovered malware families are fileless malware and they have not been seen before.
Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897) https://blog.0patch.com/2021/03/analyzing-and-micropatching-with.html
0Patch
Analyzing And Micropatching With Tetrane REVEN (Part 1, CVE-2021-26897)
by Mitja Kolsek, the 0patch Team March 2021 Windows Updates included fixes for seven vulnerabilities in Windows DNS Server, two of which w...
Royal Flush: Privilege Escalation Vulnerability in Azure Functions https://www.intezer.com/blog/cloud-security/royal-flush-privilege-escalation-vulnerability-in-azure-functions/
Intezer
Royal Flush: Privilege Escalation Vulnerability in Azure Functions
To demonstrate how an attacker can change any arbitrary file we gained control over /etc/passwd.
Analysis of a Windows IPv6 Fragmentation Vulnerability: CVE-2021-24086 https://blog.quarkslab.com/analysis-of-a-windows-ipv6-fragmentation-vulnerability-cve-2021-24086.html
Quarkslab
Analysis of a Windows IPv6 Fragmentation Vulnerability: CVE-2021-24086 - Quarkslab's blog
In this blog post we analyze a denial of service vulnerability affecting the IPv6 stack of Windows. This issue, whose root cause can be found in the mishandling of IPv6 fragments, was patched by Microsoft in their February 2021 security bulletin.
Do You Really Know About LSA Protection (RunAsPPL)? https://itm4n.github.io/lsass-runasppl/
itm4n’s blog
Do You Really Know About LSA Protection (RunAsPPL)?
When it comes to protecting against credentials theft on Windows, enabling LSA Protection (a.k.a. RunAsPPL) on LSASS may be considered as the very first recommendation to implement. But do you really know what a PPL is? In this post, I want to cover some…
Nice content >> "CS 253 Web Security" https://web.stanford.edu/class/cs253/
web.stanford.edu
CS253 - Web Security
Principles of web security. The fundamentals and state-of-the-art in web security. Attacks and countermeasures. Topics include: the browser security model, web app vulnerabilities, injection, denial-of-service, TLS attacks, privacy, fingerprinting, same-origin…
BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution https://google.github.io/security-research/pocs/linux/bleedingtooth/writeup.html
security-research
BleedingTooth: Linux Bluetooth Zero-Click Remote Code Execution
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
New Wormable Android Malware Spreads by Creating Auto-Replies to Messages in WhatsApp https://research.checkpoint.com/2021/new-wormable-android-malware-spreads-by-creating-auto-replies-to-messages-in-whatsapp/
Check Point Research
New Wormable Android Malware Spreads by Creating Auto-Replies to Messages in WhatsApp - Check Point Research
Research by: Aviran Hazum, Bodgan Melnykov & Israel Wenik Overview Check Point Research (CPR) recently discovered malware on Google Play hidden in a fake application that is capable of spreading itself via users’ WhatsApp messages. If the user downloaded…
Legalizing Gay Marriage in Crusader Kings III with Ghidra https://waffleironer.medium.com/legalizing-gay-marriage-in-crusader-kings-iii-with-ghidra-2602e6aa8689
Medium
Legalizing Gay Marriage in Crusader Kings III with Ghidra
Crusader Kings III is a pretty impressive game. It’s impressive not only for its official content, but also for its extensive modding…
Nice DFIR post >> Chromebook Data Locations https://www.magnetforensics.com/blog/chromebook-data-locations/
Magnet Forensics
Chromebook Data Locations - Magnet Forensics
Jessica Hyde provides a summary list of data locations for Chromebook artifacts with multiple locations listed for each artifact type.
The leap of a Cycldek-related threat actor https://securelist.com/the-leap-of-a-cycldek-related-threat-actor/101243/
Securelist
The leap of a Cycldek-related threat actor
The investigation described in this article started with one such file which caught our attention due to the various improvements it brought to this well-known infection vector.
Cisco Will Not Patch Critical RCE Flaw Affecting End-of-Life Business Routers https://thehackernews.com/2021/04/cisco-will-not-patch-critical-rce-flaw.html
This man thought opening a TXT file is fine, he thought wrong. macOS CVE-2019-8761 https://www.paulosyibelo.com/2021/04/this-man-thought-opening-txt-file-is.html
Blog
Blog: This man thought opening a TXT file is fine, he thought wrong. macOS CVE-2019-8761
data:blog.metaDescription
Exploiting Windows RPC to bypass CFG mitigation: analysis of CVE-2021-26411 in-the-wild sample https://iamelli0t.github.io/2021/04/10/RPC-Bypass-CFG.html
iamelli0t’s blog
Exploiting Windows RPC to bypass CFG mitigation: analysis of CVE-2021-26411 in-the-wild sample
The general method of browser render process exploit is: after exploiting the vulnerability to obtain user mode arbitrary memory read/write primitive, the vtable of DOM/js object is tampered to hijack the code execution flow. Then VirtualProtect is called…
Rainbow Tables (probably) aren’t what you think — Part 1: Precomputed Hash Chains https://rsheasby.medium.com/rainbow-tables-probably-arent-what-you-think-30f8a61ba6a5
Medium
Rainbow Tables (probably) aren’t what you think — Part 1: Precomputed Hash Chains
A deep dive into how rainbow tables actually work, and how they’re different from lookup tables.
Nice content here » A repository for learning various heap exploitation techniques https://github.com/shellphish/how2heap
GitHub
GitHub - shellphish/how2heap: A repository for learning various heap exploitation techniques.
A repository for learning various heap exploitation techniques. - shellphish/how2heap
Cost of a Cyber Incident: Systematic Review and Cross-Validation https://www.cisa.gov/publication/cost-cyber-incident-systematic-review-and-cross-validation
www.cisa.gov
Cost of a Cyber Incident: Systematic Review and Cross-Validation | CISA
Cost of a Cyber Incident: Systematic Review and Cross-Validation. In order to support stakeholders with understanding the impacts, costs, and losses from cyber incidents, CISA has cleared for release this October 2020 study. The objectives of the study…
A deep dive into Saint Bot, a new downloader https://blog.malwarebytes.com/threat-analysis/2021/04/a-deep-dive-into-saint-bot-downloader/