Allow arbitrary URLs, expect arbitrary code execution https://positive.security/blog/url-open-rce
positive.security
Allow arbitrary URLs, expect arbitrary code execution | Positive Security
Insecure URL handling leading to 1-click code execution vulnerabilities in Telegram, Nextcloud (CVE-2021-22879), VLC, LibreOffice (CVE-2021-25631), OpenOffice (CVE-2021-30245), Bitcoin/Dogecoin Wallets, Wireshark (CVE-2021-22191) and Mumble (CVE-2021-27229).
Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild https://securelist.com/zero-day-vulnerability-in-desktop-window-manager-cve-2021-28310-used-in-the-wild/101898/
Airstrike Attack - FDE bypass and EoP on domain joined Windows workstations (CVE-2021-28316) https://shenaniganslabs.io/2021/04/13/Airstrike.html
Shenanigans Labs
Airstrike Attack - FDE bypass and EoP on domain joined Windows workstations (CVE-2021-28316)
By default, domain joined Windows workstations allow access to the network selection UI from the lock screen.
An attacker with physical access to a locked device with WiFi capabilities (such as a laptop or a workstation) can abuse this functionality to force…
An attacker with physical access to a locked device with WiFi capabilities (such as a laptop or a workstation) can abuse this functionality to force…
Exploiting the Math.expm1 typing bug in V8 https://abiondo.me/2019/01/02/exploiting-math-expm1-v8/
0x41414141 in ?? ()
Exploiting the Math.expm1 typing bug in V8
Minus zero behaves like zero, right?
Good idea, a place to collect legal threats against security researchers >> https://github.com/disclose/research-threats
GitHub
GitHub - disclose/research-threats: Collection of legal threats against good faith Security Researchers; vulnerability disclosure…
Collection of legal threats against good faith Security Researchers; vulnerability disclosure gone wrong. A continuation of work started by @attritionorg - disclose/research-threats
Remote exploitation of a man-in-the-disk vulnerability in WhatsApp (CVE-2021-24027) https://census-labs.com/news/2021/04/14/whatsapp-mitd-remote-exploitation-CVE-2021-24027/; code in https://github.com/CENSUS/whatsapp-mitd-mitm
CENSUS
CENSUS — Cybersecurity for AI-driven unmanned systems
Cybersecurity for AI-driven unmanned systems. Platform Integrity, AI Trustworthiness and Secure Communications.
SSH Tunnelling https://marcusedmondson.com/2021/04/12/ssh-tunnelling/
Marcus Edmondson | Threat Hunting | Information Security
SSH Tunnelling
In today’s blog post I wanted to talk about Secure Shell (SSH) and some of its powerful features. We will start with some of the basics such as what it is, what it does, and then more advance…
Hacking Reolink cameras for fun and profit https://www.thirtythreeforty.net/posts/2020/05/hacking-reolink-cameras-for-fun-and-profit/
Godzilla Vs. Kong Vs … Ghidra? - Ghidra Scripting, PCode Emulation, and Password Cracking on a GBA ROM https://wrongbaud.github.io/posts/kong-vs-ghidra/
Wrongbaud’s Blog
Godzilla Vs. Kong Vs … Ghidra? - Ghidra Scripting, PCode Emulation, and Password Cracking
Godzilla Vs. Kong Vs … Ghidra? - Ghidra Scripting, PCode Emulation and Password Cracking
Designing sockfuzzer, a network syscall fuzzer for XNU https://googleprojectzero.blogspot.com/2021/04/designing-sockfuzzer-network-syscall.html
projectzero.google
Designing sockfuzzer, a network syscall fuzzer for XNU
Posted by Ned Williamson, Project Zero Introduction When I started my 20% project – an in...
A year of Fajan evolution and Bloomberg themed campaigns https://blog.talosintelligence.com/2021/04/a-year-of-fajan-evolution-and-bloomberg.html
Cisco Talos Blog
A year of Fajan evolution and Bloomberg themed campaigns
By Vanja Svajcer.
News summary
* Some malware campaigns are designed to spread malware to as many people as possible — while some others carefully choose their targets. Cisco Talos recently discovered a malware campaign that does not fit in any of the…
News summary
* Some malware campaigns are designed to spread malware to as many people as possible — while some others carefully choose their targets. Cisco Talos recently discovered a malware campaign that does not fit in any of the…
Perun's Fart - yet another unhooking method https://blog.sektor7.net/#!res/2021/perunsfart.md
Run your malicious VBA macros anywhere! https://www.virusbulletin.com/virusbulletin/2021/04/run-your-malicious-vba-macros-anywhere/
Virusbulletin
Virus Bulletin :: Run your malicious VBA macros anywhere!
Kurt Natvig wanted to understand whether it’s possible to recompile VBA macros to another language, which could then easily be ‘run’ on any gateway, thus revealing a sample’s true nature in a safe manner. In this article he explains how he recompiled malicious…
Uncovering and Disclosing a Signature Spoofing Vulnerability in Windows Installer: CVE-2021-26413 https://sec.okta.com/articles/2021/04/uncovering-and-disclosing-signature-spoofing-vulnerability-windows
Okta Security
Uncovering and Disclosing a Signature Spoofing Vulnerability in Windows Installer: CVE-2021-26413
Executive SummaryOkta Security has discovered and disclosed a new bypass in Windows Installer (MSI) Authenticode signature validation that could all
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective https://signal.org/blog/cellebrite-vulnerabilities/?s=09
Signal
Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective
Cellebrite makes software to automate physically extracting and indexing data from mobile devices. They exist within the grey – where enterprise branding joins together with the larcenous to be called “digital intelligence.” Their customer list has included…
New event type in Sysmon 13.10 — FileDeleteDetected https://medium.com/falconforce/sysmon-13-10-filedeletedetected-fe2475cb419e
Medium
Sysmon 13.10 — FileDeleteDetected
The Sysinternals team has released Sysmon 13.10 and adds the FileDeleteDetected event
CertStealer: A .NET tool for exporting and importing certificates without touching disk https://github.com/TheWover/CertStealer
GitHub
GitHub - TheWover/CertStealer: A .NET tool for exporting and importing certificates without touching disk.
A .NET tool for exporting and importing certificates without touching disk. - TheWover/CertStealer
CVE-2020-9900 & CVE-2021-1786 - Abusing macOS Crash Reporter https://theevilbit.github.io/posts/macos_crashreporter/
theevilbit blog
CVE-2020-9900 & CVE-2021-1786 - Abusing macOS Crash Reporter
I plan to discuss two symlink attacks in this blog post. The first, more severe one, CVE-2020-9900 was reported by Zhongcheng Li (CK01) of Zero-dayits Team of Legendsec at Qi’anxin Group, and fixed in Catalina 10.15.6. Apple’s advisory said that with a symlink…
Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day https://www.fireeye.com/blog/threat-research/2021/04/suspected-apt-actors-leverage-bypass-techniques-pulse-secure-zero-day.html
Google Cloud Blog
Authentication Bypass Techniques and Pulse Secure Zero-Day | Google Cloud Blog
We examine multiple techniques for bypassing single & multifactor authentication on Pulse Secure VPN devices and maintaining access through webshells.