Nice content here » A repository for learning various heap exploitation techniques https://github.com/shellphish/how2heap
GitHub
GitHub - shellphish/how2heap: A repository for learning various heap exploitation techniques.
A repository for learning various heap exploitation techniques. - shellphish/how2heap
Cost of a Cyber Incident: Systematic Review and Cross-Validation https://www.cisa.gov/publication/cost-cyber-incident-systematic-review-and-cross-validation
www.cisa.gov
Cost of a Cyber Incident: Systematic Review and Cross-Validation | CISA
Cost of a Cyber Incident: Systematic Review and Cross-Validation. In order to support stakeholders with understanding the impacts, costs, and losses from cyber incidents, CISA has cleared for release this October 2020 study. The objectives of the study…
A deep dive into Saint Bot, a new downloader https://blog.malwarebytes.com/threat-analysis/2021/04/a-deep-dive-into-saint-bot-downloader/
Gamifying machine learning for stronger security and AI models https://www.microsoft.com/security/blog/2021/04/08/gamifying-machine-learning-for-stronger-security-and-ai-models/
Microsoft News
Gamifying machine learning for stronger security and AI models
We are open sourcing the Python source code of a research toolkit we call CyberBattleSim, an experimental research project that investigates how autonomous agents operate in a simulated enterprise environment using high-level abstraction of computer networks…
Very detailed post » Dissecting the UNIX v6 Allocator https://ljrk.codeberg.page/unixv6-alloc.html
ljrk.codeberg.page
Dissecting the UNIX v6 Allocator
Analysis of a Windows IPv6 Fragmentation Vulnerability: CVE-2021-24086 https://blog.quarkslab.com/analysis-of-a-windows-ipv6-fragmentation-vulnerability-cve-2021-24086.html
Quarkslab
Analysis of a Windows IPv6 Fragmentation Vulnerability: CVE-2021-24086 - Quarkslab's blog
In this blog post we analyze a denial of service vulnerability affecting the IPv6 stack of Windows. This issue, whose root cause can be found in the mishandling of IPv6 fragments, was patched by Microsoft in their February 2021 security bulletin.
Four Bytes of Power: exploiting CVE-2021-26708 in the Linux kernel https://a13xp0p0v.github.io/2021/02/09/CVE-2021-26708.html
Alexander Popov
Four Bytes of Power: Exploiting CVE-2021-26708 in the Linux kernel
CVE-2021-26708 is assigned to five race condition bugs in the virtual socket implementation of the Linux kernel. I discovered and fixed them in January 2021. In this article I describe how to exploit them for local privilege escalation on Fedora 33 Server…
We're open sourcing Protocol Fuzzer Community Edition! https://about.gitlab.com/blog/2021/03/23/gitlab-open-sources-protocol-fuzz-test-engine/
GitLab
We're open sourcing Protocol Fuzzer Community Edition!
GitLab is releasing an open source protocol fuzz testing repository.
Investigating a unique “form” of email delivery for IcedID malware https://www.microsoft.com/security/blog/2021/04/09/investigating-a-unique-form-of-email-delivery-for-icedid-malware/
Microsoft News
Investigating a unique “form” of email delivery for IcedID malware
Microsoft threat analysts have been tracking activity where contact forms published on websites are abused to deliver malicious links to enterprises using emails with fake legal threats. The emails instruct recipients to click a link to review supposed evidence…
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware https://www.trendmicro.com/en_us/research/21/d/iron-tiger-apt-updates-toolkit-with-evolved-sysupdate-malware-va.html
Trend Micro
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
This blog details how Iron Tiger threat actors have updated their toolkit with an updated SysUpdate malware variant that now uses five files in its infection routine instead of the usual three.
A journey into IonMonkey: root-causing CVE-2019-9810 https://doar-e.github.io/blog/2019/06/17/a-journey-into-ionmonkey-root-causing-cve-2019-9810/
doar-e.github.io
A journey into IonMonkey: root-causing CVE-2019-9810.
Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely https://github.com/0vercl0k/CVE-2021-24086
GitHub
GitHub - 0vercl0k/CVE-2021-24086: Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely.
Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely. - 0vercl0k/CVE-2021-24086
Hackers Exploit Unpatched VPNs to Install Ransomware on Industrial Targets https://thehackernews.com/2021/04/hackers-exploit-unpatched-vpns-to.html
Reverse-engineering tcpip.sys: mechanics of a packet of the death (CVE-2021-24086) https://doar-e.github.io/blog/2021/04/15/reverse-engineering-tcpipsys-mechanics-of-a-packet-of-the-death-cve-2021-24086/
doar-e.github.io
Reverse-engineering tcpip.sys: mechanics of a packet of the death (CVE-2021-24086)
nice post >> Dancing With Shellcodes: Cracking the latest version of Guloader https://elis531989.medium.com/dancing-with-shellcodes-cracking-the-latest-version-of-guloader-75083fb15cb4
Medium
Dancing With Shellcodes: Cracking the latest version of Guloader
Guloader is a downloader that has been active since 2019. It is known to deliver various malware, more notably: Agent-Tesla, Netwire…
Analysis of a raw TCP/IP packet https://inc0x0.com/tcp-ip-packets-introduction/tcp-ip-packets-2-analysis-of-a-raw-tcp-ip-packet/
inc0x0
TCP/IP packets - 2 Analysis of a raw TCP/IP packet - inc0x0
Analysis of a raw TCP/IP packet In this chapter we are going to have a close look at some captured network packets and apply our knowledge from the previous parts of this series on them. You will see, that a lot of bits and bytes in packets will make much…
Information Leak via Compromised Sandboxed Browser https://ptr-yudai.hatenablog.com/entry/2021/04/19/140802
CTFするぞ
Information Leak via Compromised Sandboxed Browser - CTFするぞ
This article covers the exploit part. Check this one written by s1r1us for the web and chromium-security part. I solved some pwnable tasks from PlaidCTF 2021. T…
jojojo don't trust Telegram attachments }:) >> Malware author made $560,000 just from a simple clipboard hijacker https://therecord.media/malware-author-made-560000-just-from-a-simple-clipboard-hijacker/
Details on the Unlocking of the San Bernardino Terrorist’s iPhone https://www.schneier.com/blog/archives/2021/04/details-on-the-unlocking-of-the-san-bernardino-terrorists-iphone.html
Schneier on Security
Details on the Unlocking of the San Bernardino Terrorist's iPhone - Schneier on Security
The Washington Post has published a long story on the unlocking of the San Bernardino Terrorist’s iPhone 5C in 2016. We all thought it was an Israeli company called Cellebrite. It was actually an Australian company called Azimuth Security. Azimuth specialized…
keep an eye, good post >> Volatile Memory Analysis With Volatility : Coreflood Trojan https://digitalitskills.com/volatile-memory-analysis-with-volatility-coreflood-trojan/
Volatility | Memory Forensics | Malware| DIGITAL IT SKILLS - Skills that matter
Volatile Memory Analysis With Volatility : Coreflood Trojan - Volatility | Memory Forensics | Malware| DIGITAL IT SKILLS
Introduction This is the first post of multi part series in which we will walk through basics of volatile Memory analysis with Volatility. Though some knowledge of Windows Internal is desirable but I will try to cover things as we progress. In this post,…