Investigating a unique “form” of email delivery for IcedID malware https://www.microsoft.com/security/blog/2021/04/09/investigating-a-unique-form-of-email-delivery-for-icedid-malware/
Microsoft News
Investigating a unique “form” of email delivery for IcedID malware
Microsoft threat analysts have been tracking activity where contact forms published on websites are abused to deliver malicious links to enterprises using emails with fake legal threats. The emails instruct recipients to click a link to review supposed evidence…
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware https://www.trendmicro.com/en_us/research/21/d/iron-tiger-apt-updates-toolkit-with-evolved-sysupdate-malware-va.html
Trend Micro
Iron Tiger APT Updates Toolkit With Evolved SysUpdate Malware
This blog details how Iron Tiger threat actors have updated their toolkit with an updated SysUpdate malware variant that now uses five files in its infection routine instead of the usual three.
A journey into IonMonkey: root-causing CVE-2019-9810 https://doar-e.github.io/blog/2019/06/17/a-journey-into-ionmonkey-root-causing-cve-2019-9810/
doar-e.github.io
A journey into IonMonkey: root-causing CVE-2019-9810.
Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely https://github.com/0vercl0k/CVE-2021-24086
GitHub
GitHub - 0vercl0k/CVE-2021-24086: Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely.
Proof of concept for CVE-2021-24086, a NULL dereference in tcpip.sys triggered remotely. - 0vercl0k/CVE-2021-24086
Hackers Exploit Unpatched VPNs to Install Ransomware on Industrial Targets https://thehackernews.com/2021/04/hackers-exploit-unpatched-vpns-to.html
Reverse-engineering tcpip.sys: mechanics of a packet of the death (CVE-2021-24086) https://doar-e.github.io/blog/2021/04/15/reverse-engineering-tcpipsys-mechanics-of-a-packet-of-the-death-cve-2021-24086/
doar-e.github.io
Reverse-engineering tcpip.sys: mechanics of a packet of the death (CVE-2021-24086)
nice post >> Dancing With Shellcodes: Cracking the latest version of Guloader https://elis531989.medium.com/dancing-with-shellcodes-cracking-the-latest-version-of-guloader-75083fb15cb4
Medium
Dancing With Shellcodes: Cracking the latest version of Guloader
Guloader is a downloader that has been active since 2019. It is known to deliver various malware, more notably: Agent-Tesla, Netwire…
Analysis of a raw TCP/IP packet https://inc0x0.com/tcp-ip-packets-introduction/tcp-ip-packets-2-analysis-of-a-raw-tcp-ip-packet/
inc0x0
TCP/IP packets - 2 Analysis of a raw TCP/IP packet - inc0x0
Analysis of a raw TCP/IP packet In this chapter we are going to have a close look at some captured network packets and apply our knowledge from the previous parts of this series on them. You will see, that a lot of bits and bytes in packets will make much…
Information Leak via Compromised Sandboxed Browser https://ptr-yudai.hatenablog.com/entry/2021/04/19/140802
CTFするぞ
Information Leak via Compromised Sandboxed Browser - CTFするぞ
This article covers the exploit part. Check this one written by s1r1us for the web and chromium-security part. I solved some pwnable tasks from PlaidCTF 2021. T…
jojojo don't trust Telegram attachments }:) >> Malware author made $560,000 just from a simple clipboard hijacker https://therecord.media/malware-author-made-560000-just-from-a-simple-clipboard-hijacker/
Details on the Unlocking of the San Bernardino Terrorist’s iPhone https://www.schneier.com/blog/archives/2021/04/details-on-the-unlocking-of-the-san-bernardino-terrorists-iphone.html
Schneier on Security
Details on the Unlocking of the San Bernardino Terrorist's iPhone - Schneier on Security
The Washington Post has published a long story on the unlocking of the San Bernardino Terrorist’s iPhone 5C in 2016. We all thought it was an Israeli company called Cellebrite. It was actually an Australian company called Azimuth Security. Azimuth specialized…
keep an eye, good post >> Volatile Memory Analysis With Volatility : Coreflood Trojan https://digitalitskills.com/volatile-memory-analysis-with-volatility-coreflood-trojan/
Volatility | Memory Forensics | Malware| DIGITAL IT SKILLS - Skills that matter
Volatile Memory Analysis With Volatility : Coreflood Trojan - Volatility | Memory Forensics | Malware| DIGITAL IT SKILLS
Introduction This is the first post of multi part series in which we will walk through basics of volatile Memory analysis with Volatility. Though some knowledge of Windows Internal is desirable but I will try to cover things as we progress. In this post,…
Unpacking RAGNARLOCKER via emulation https://blog.reversing.xyz/docs/posts/unpacking_ragnarlocker_via_emulation/
Analysis of a VB Script Heap Overflow (CVE-2019-0666) https://www.malwaretech.com/2019/04/analysis-of-a-vb-script-heap-overflow.html
Malwaretech
Analysis of a VB Script Heap Overflow (CVE-2019-0666) – MalwareTech
Anyone who uses RegEx knows how easy it is to shoot yourself in the foot; but, is it possible to write RegEx so badly that it can lead to RCE? With VB Script, the answer is yes!
for your bookmarks >> Frida Cheatsheet https://rehex.ninja/posts/frida-cheatsheet/
reHex Ninja
Frida Cheatsheet
Blog About Reversing
Cheatsheet: XSS that works in 2021 https://netsec.expert/posts/xss-in-2021/
Sam's Hacking Wonderland
Cheatsheet: XSS that works in 2021
XSS Cheatsheet for 2021 and onwards.
Exploiting CVE-2014-3153 (Towelroot) https://elongl.github.io/exploitation/2021/01/08/cve-2014-3153.html
Elon Gliksberg
Exploiting CVE-2014-3153 (Towelroot)
Understanding The Kernel
Allow arbitrary URLs, expect arbitrary code execution https://positive.security/blog/url-open-rce
positive.security
Allow arbitrary URLs, expect arbitrary code execution | Positive Security
Insecure URL handling leading to 1-click code execution vulnerabilities in Telegram, Nextcloud (CVE-2021-22879), VLC, LibreOffice (CVE-2021-25631), OpenOffice (CVE-2021-30245), Bitcoin/Dogecoin Wallets, Wireshark (CVE-2021-22191) and Mumble (CVE-2021-27229).
Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild https://securelist.com/zero-day-vulnerability-in-desktop-window-manager-cve-2021-28310-used-in-the-wild/101898/