Legalizing Gay Marriage in Crusader Kings III with Ghidra https://waffleironer.medium.com/legalizing-gay-marriage-in-crusader-kings-iii-with-ghidra-2602e6aa8689
Medium
Legalizing Gay Marriage in Crusader Kings III with Ghidra
Crusader Kings III is a pretty impressive game. It’s impressive not only for its official content, but also for its extensive modding…
Nice DFIR post >> Chromebook Data Locations https://www.magnetforensics.com/blog/chromebook-data-locations/
Magnet Forensics
Chromebook Data Locations - Magnet Forensics
Jessica Hyde provides a summary list of data locations for Chromebook artifacts with multiple locations listed for each artifact type.
The leap of a Cycldek-related threat actor https://securelist.com/the-leap-of-a-cycldek-related-threat-actor/101243/
Securelist
The leap of a Cycldek-related threat actor
The investigation described in this article started with one such file which caught our attention due to the various improvements it brought to this well-known infection vector.
Cisco Will Not Patch Critical RCE Flaw Affecting End-of-Life Business Routers https://thehackernews.com/2021/04/cisco-will-not-patch-critical-rce-flaw.html
This man thought opening a TXT file is fine, he thought wrong. macOS CVE-2019-8761 https://www.paulosyibelo.com/2021/04/this-man-thought-opening-txt-file-is.html
Blog
Blog: This man thought opening a TXT file is fine, he thought wrong. macOS CVE-2019-8761
data:blog.metaDescription
Exploiting Windows RPC to bypass CFG mitigation: analysis of CVE-2021-26411 in-the-wild sample https://iamelli0t.github.io/2021/04/10/RPC-Bypass-CFG.html
iamelli0t’s blog
Exploiting Windows RPC to bypass CFG mitigation: analysis of CVE-2021-26411 in-the-wild sample
The general method of browser render process exploit is: after exploiting the vulnerability to obtain user mode arbitrary memory read/write primitive, the vtable of DOM/js object is tampered to hijack the code execution flow. Then VirtualProtect is called…
Rainbow Tables (probably) aren’t what you think — Part 1: Precomputed Hash Chains https://rsheasby.medium.com/rainbow-tables-probably-arent-what-you-think-30f8a61ba6a5
Medium
Rainbow Tables (probably) aren’t what you think — Part 1: Precomputed Hash Chains
A deep dive into how rainbow tables actually work, and how they’re different from lookup tables.
Nice content here » A repository for learning various heap exploitation techniques https://github.com/shellphish/how2heap
GitHub
GitHub - shellphish/how2heap: A repository for learning various heap exploitation techniques.
A repository for learning various heap exploitation techniques. - shellphish/how2heap
Cost of a Cyber Incident: Systematic Review and Cross-Validation https://www.cisa.gov/publication/cost-cyber-incident-systematic-review-and-cross-validation
www.cisa.gov
Cost of a Cyber Incident: Systematic Review and Cross-Validation | CISA
Cost of a Cyber Incident: Systematic Review and Cross-Validation. In order to support stakeholders with understanding the impacts, costs, and losses from cyber incidents, CISA has cleared for release this October 2020 study. The objectives of the study…
A deep dive into Saint Bot, a new downloader https://blog.malwarebytes.com/threat-analysis/2021/04/a-deep-dive-into-saint-bot-downloader/
Gamifying machine learning for stronger security and AI models https://www.microsoft.com/security/blog/2021/04/08/gamifying-machine-learning-for-stronger-security-and-ai-models/
Microsoft News
Gamifying machine learning for stronger security and AI models
We are open sourcing the Python source code of a research toolkit we call CyberBattleSim, an experimental research project that investigates how autonomous agents operate in a simulated enterprise environment using high-level abstraction of computer networks…
Very detailed post » Dissecting the UNIX v6 Allocator https://ljrk.codeberg.page/unixv6-alloc.html
ljrk.codeberg.page
Dissecting the UNIX v6 Allocator
Analysis of a Windows IPv6 Fragmentation Vulnerability: CVE-2021-24086 https://blog.quarkslab.com/analysis-of-a-windows-ipv6-fragmentation-vulnerability-cve-2021-24086.html
Quarkslab
Analysis of a Windows IPv6 Fragmentation Vulnerability: CVE-2021-24086 - Quarkslab's blog
In this blog post we analyze a denial of service vulnerability affecting the IPv6 stack of Windows. This issue, whose root cause can be found in the mishandling of IPv6 fragments, was patched by Microsoft in their February 2021 security bulletin.
Four Bytes of Power: exploiting CVE-2021-26708 in the Linux kernel https://a13xp0p0v.github.io/2021/02/09/CVE-2021-26708.html
Alexander Popov
Four Bytes of Power: Exploiting CVE-2021-26708 in the Linux kernel
CVE-2021-26708 is assigned to five race condition bugs in the virtual socket implementation of the Linux kernel. I discovered and fixed them in January 2021. In this article I describe how to exploit them for local privilege escalation on Fedora 33 Server…
We're open sourcing Protocol Fuzzer Community Edition! https://about.gitlab.com/blog/2021/03/23/gitlab-open-sources-protocol-fuzz-test-engine/
GitLab
We're open sourcing Protocol Fuzzer Community Edition!
GitLab is releasing an open source protocol fuzz testing repository.
Investigating a unique “form” of email delivery for IcedID malware https://www.microsoft.com/security/blog/2021/04/09/investigating-a-unique-form-of-email-delivery-for-icedid-malware/
Microsoft News
Investigating a unique “form” of email delivery for IcedID malware
Microsoft threat analysts have been tracking activity where contact forms published on websites are abused to deliver malicious links to enterprises using emails with fake legal threats. The emails instruct recipients to click a link to review supposed evidence…
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware https://www.trendmicro.com/en_us/research/21/d/iron-tiger-apt-updates-toolkit-with-evolved-sysupdate-malware-va.html
Trend Micro
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
This blog details how Iron Tiger threat actors have updated their toolkit with an updated SysUpdate malware variant that now uses five files in its infection routine instead of the usual three.
A journey into IonMonkey: root-causing CVE-2019-9810 https://doar-e.github.io/blog/2019/06/17/a-journey-into-ionmonkey-root-causing-cve-2019-9810/
doar-e.github.io
A journey into IonMonkey: root-causing CVE-2019-9810.
Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely https://github.com/0vercl0k/CVE-2021-24086
GitHub
GitHub - 0vercl0k/CVE-2021-24086: Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely.
Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely. - 0vercl0k/CVE-2021-24086
Hackers Exploit Unpatched VPNs to Install Ransomware on Industrial Targets https://thehackernews.com/2021/04/hackers-exploit-unpatched-vpns-to.html