CVE-2021-21551- Hundreds Of Millions Of Dell Computers At Risk Due to Multiple BIOS Driver Privilege Escalation Flaws https://labs.sentinelone.com/cve-2021-21551-hundreds-of-millions-of-dell-computers-at-risk-due-to-multiple-bios-driver-privilege-escalation-flaws/
SentinelOne
CVE-2021-21551- Hundreds Of Millions Of Dell Computers At Risk Due to Multiple BIOS Driver Privilege Escalation Flaws - SentinelLabs
Update your Dell devices now! SentinelLabs discover five high severity flaws in Dell firmware update driver impacting desktops, laptops, notebooks and more.
byeintegrity-uac: Bypass UAC by hijacking a DLL https://securityonline.info/byeintegrity-uac-bypass-uac-by-hijacking-a-dll/
Cybersecurity News
byeintegrity-uac: Bypass UAC by hijacking a DLL
ByeIntegrity - Bypass User Account Control (UAC) to gain elevated (Administrator) privileges to run any program at a high integrity level.
"Configuration Recommendations for Hardening of Windows 10 Using Built-in Functionalities" and "Microsoft Office Telemetry" (from @BSI_Bund) https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Cyber-Security/SiSyPHuS/AP11/Hardening_Guideline.pdf?__blob=publicationFile&v=3 https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Studien/Office_Telemetrie/Office_Telemetrie.pdf?__blob=publicationFile&v=1
Trickbot Brief: Creds and Beacons https://thedfirreport.com/2021/05/02/trickbot-brief-creds-and-beacons/
The DFIR Report
Trickbot Brief: Creds and Beacons
In an intrusion from this past month, Trickbot threat actors were seen enumerating and collecting information related to the domain as well as dumping passwords before leaving the network. Cobalt Strike Beacons were deployed and remained connected despite…
Anatomy of Cobalt Strike's DLL Stager https://blog.nviso.eu/2021/04/26/anatomy-of-cobalt-strike-dll-stagers/
NVISO Labs
Anatomy of Cobalt Strike’s DLL Stager
This blog post will cover the Cobalt Strike DLL stager's anatomy, design choices and highlight ways to reduce both log footprint and time-to-shellcode.
@RicardoJRdez and @daniel_uroz explain us their recent work published at @wootsecurity. Do not miss it! » "How powerful are Return Oriented Programming attacks?" https://reversea.me/index.php/how-powerful-are-return-oriented-programming-attacks/ great job guys!
cool new attacks on WiFi » FragAttacks (fragmentation and aggregation attacks): a collection of new security vulnerabilities that affect Wi-Fi devices (by @vanhoefm) https://www.fragattacks.com/ related paper: https://papers.mathyvanhoef.com/usenix2021.pdf
Fragattacks
FragAttacks: Security flaws in all Wi-Fi devices
We present three security design flaws in Wi-Fi and widepread implementation flaws. These can be abused to exfiltrate user data and attack local devices.
Engineering antivirus evasion (Part II) https://blog.scrt.ch/2020/07/15/engineering-antivirus-evasion-part-ii/ (source code in https://github.com/scrt/avcleaner)
21Nails: Multiple Critical Vulnerabilities in Exim Mail Server https://blog.qualys.com/vulnerabilities-research/2021/05/04/21nails-multiple-vulnerabilities-in-exim-mail-server
Qualys
21Nails: Multiple Critical Vulnerabilities in Exim Mail Server | Qualys
Update May 7, 2021: Exim has released a security update to address multiple vulnerabilities in Exim versions prior to 4.94.2. See the CISA announcement. Original Post: The Qualys Research Team has…
MRM3 – Curiosities of the wildest banking malware https://blog.fox-it.com/2021/05/04/rm3-curiosities-of-the-wildest-banking-malware/
Fox-IT International blog
RM3 – Curiosities of the wildest banking malware
fumik0_ & the RIFT Team TL:DR Our Research and Intelligence Fusion Team have been tracking the Gozi variant RM3 for close to 30 months. In this post we provide some his…
Shining a Light on DARKSIDE Ransomware Operations https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html
Google Cloud Blog
Shining a Light on DARKSIDE Ransomware Operations | Google Cloud Blog
The creators of DARKSIDE ransomware have launched a global crime spree affecting organizations in more than 15 countries and multiple industry verticals.
ValueDeFi’s Invalid Share Calculation Exploit In-depth Analysis https://inspextech.medium.com/value-defis-invalid-share-calculation-exploit-in-depth-analysis-1c8f97c1416e
Medium
ValueDeFi’s Invalid Share Calculation Exploit In-depth Analysis
Started from 08:13:06 PM UTC on May 7th, 2021, ValueDeFi’s multi-strategy WBNB vault was exploited due to an invalid share calculation…
TeaBot: a new Android malware emerged in Italy, targets banks in Europe https://www.cleafy.com/documents/teabot
Cleafy
TeaBot, a new Android malware targeting banks in Europe | Cleafy
TeaBot, a new Android malware targeting European banks, has been discovered in Italy by the threat intelligence team of Cleafy: here's the technical analysis.
Q1 2021 DDoS attacks and BGP incidents https://blog.qrator.net/en/q1-2021-report_129/
Tracking One Year of Malicious Tor Exit Relay Activities (Part II) https://nusenu.medium.com/tracking-one-year-of-malicious-tor-exit-relay-activities-part-ii-85c80875c5df
Medium
Tracking One Year of Malicious Tor Exit Relay Activities (Part II)
>25% of the Tor network’s exit capacity has been attacking Tor users
New publication from NIST: "Key Practices in Cyber Supply Chain
Risk Management: Observations from Industry" https://csrc.nist.gov/publications/detail/nistir/8276/final
Risk Management: Observations from Industry" https://csrc.nist.gov/publications/detail/nistir/8276/final
CSRC | NIST
NIST Internal or Interagency Report (NISTIR) 8276, Key Practices in Cyber Supply Chain Risk Management: Observations from Industry
In today’s highly connected, interdependent world, all organizations rely on others for critical products and services. However, the reality of globalization, while providing many benefits, has resulted in a world where organizations no longer fully control—and…
CVE‑2021‑1079 – NVIDIA GeForce Experience Command Execution https://voidsec.com/nvidia-geforce-experience-command-execution/
VoidSec
CVE‑2021‑1079 - NVIDIA GeForce Experience Command Execution - VoidSec
CVE-2021-1079: NVIDIA GeForce Experience (GFE) v.<= 3.21 is affected by an Arbitrary File Write vulnerability which lead to Command Execution.
nice post (I wish you the best of luck if you need to analyze this type of code) » Writing a VB6 P-Code Debugger https://decoded.avast.io/davidzimmer/writing-a-vb6-p-code-debugger/
Gendigital
Writing a VB6 P-Code Debugger
Developing a P-Code Debugger for Enhanced Malware Analysis
From Binary Patch to Proof-of-concept: a VMware ESXi vmxnet3 Case Study https://zerodayengineering.com/research/vmware-esxi-vmxnet3-from-patch-to-poc.html
How we bypassed bytenode and decompiled Node.js bytecode in Ghidra https://swarm.ptsecurity.com/how-we-bypassed-bytenode-and-decompiled-node-js-bytecode-in-ghidra/