MRM3 – Curiosities of the wildest banking malware https://blog.fox-it.com/2021/05/04/rm3-curiosities-of-the-wildest-banking-malware/
Fox-IT International blog
RM3 – Curiosities of the wildest banking malware
fumik0_ & the RIFT Team TL:DR Our Research and Intelligence Fusion Team have been tracking the Gozi variant RM3 for close to 30 months. In this post we provide some his…
Shining a Light on DARKSIDE Ransomware Operations https://www.fireeye.com/blog/threat-research/2021/05/shining-a-light-on-darkside-ransomware-operations.html
Google Cloud Blog
Shining a Light on DARKSIDE Ransomware Operations | Google Cloud Blog
The creators of DARKSIDE ransomware have launched a global crime spree affecting organizations in more than 15 countries and multiple industry verticals.
ValueDeFi’s Invalid Share Calculation Exploit In-depth Analysis https://inspextech.medium.com/value-defis-invalid-share-calculation-exploit-in-depth-analysis-1c8f97c1416e
Medium
ValueDeFi’s Invalid Share Calculation Exploit In-depth Analysis
Started from 08:13:06 PM UTC on May 7th, 2021, ValueDeFi’s multi-strategy WBNB vault was exploited due to an invalid share calculation…
TeaBot: a new Android malware emerged in Italy, targets banks in Europe https://www.cleafy.com/documents/teabot
Cleafy
TeaBot, a new Android malware targeting banks in Europe | Cleafy
TeaBot, a new Android malware targeting European banks, has been discovered in Italy by the threat intelligence team of Cleafy: here's the technical analysis.
Q1 2021 DDoS attacks and BGP incidents https://blog.qrator.net/en/q1-2021-report_129/
Tracking One Year of Malicious Tor Exit Relay Activities (Part II) https://nusenu.medium.com/tracking-one-year-of-malicious-tor-exit-relay-activities-part-ii-85c80875c5df
Medium
Tracking One Year of Malicious Tor Exit Relay Activities (Part II)
>25% of the Tor network’s exit capacity has been attacking Tor users
New publication from NIST: "Key Practices in Cyber Supply Chain
Risk Management: Observations from Industry" https://csrc.nist.gov/publications/detail/nistir/8276/final
Risk Management: Observations from Industry" https://csrc.nist.gov/publications/detail/nistir/8276/final
CSRC | NIST
NIST Internal or Interagency Report (NISTIR) 8276, Key Practices in Cyber Supply Chain Risk Management: Observations from Industry
In today’s highly connected, interdependent world, all organizations rely on others for critical products and services. However, the reality of globalization, while providing many benefits, has resulted in a world where organizations no longer fully control—and…
CVE‑2021‑1079 – NVIDIA GeForce Experience Command Execution https://voidsec.com/nvidia-geforce-experience-command-execution/
VoidSec
CVE‑2021‑1079 - NVIDIA GeForce Experience Command Execution - VoidSec
CVE-2021-1079: NVIDIA GeForce Experience (GFE) v.<= 3.21 is affected by an Arbitrary File Write vulnerability which lead to Command Execution.
nice post (I wish you the best of luck if you need to analyze this type of code) » Writing a VB6 P-Code Debugger https://decoded.avast.io/davidzimmer/writing-a-vb6-p-code-debugger/
Gendigital
Writing a VB6 P-Code Debugger
Developing a P-Code Debugger for Enhanced Malware Analysis
From Binary Patch to Proof-of-concept: a VMware ESXi vmxnet3 Case Study https://zerodayengineering.com/research/vmware-esxi-vmxnet3-from-patch-to-poc.html
How we bypassed bytenode and decompiled Node.js bytecode in Ghidra https://swarm.ptsecurity.com/how-we-bypassed-bytenode-and-decompiled-node-js-bytecode-in-ghidra/
1 TB Encryption Key? https://medium.com/asecuritysite-when-bob-met-alice/making-rsa-great-again-or-fishing-in-an-empty-barrel-3be801ebb9a1
Medium
1 TB Encryption Key?
The RSA method has stood the test of time, but its end may be nigh. It’s tried its hardest to keep up, and has continually expanded its…
CVE-2021-27075: Microsoft Azure Vulnerability Allows Privilege Escalation and Leak of Private Data https://www.intezer.com/blog/cloud-security/cve-2021-27075-microsoft-azure-vulnerability-allows-privilege-escalation-and-leak-of-data/
Intezer
CVE-2021-27075: Microsoft Azure Vulnerability
Vulnerability in Microsoft Azure VM Extension would allow privilege escalation and leak of private data.
Shared document about tools and utilities mentioned in "The Art of Mac Malware" (by Patrick Wardle) https://docs.google.com/document/d/1xOWmMueHHRke9aj3oRqNBgK69Y19hgZ7ehM4H9_Me-Y/edit
Google Docs
Tools for macOS malware analysis [PUBLIC]
Tools and utilities mentioned in The Art of Mac Malware by Patrick Wardle olevba is a script to parse Office documents to detect VBA Macros ProcessMonitor by Objective-See to monitor process creations and terminations TaskExplorer by Objective-See to visually…
Send My: Arbitrary data transmission via Apple's Find My network https://positive.security/blog/send-my
positive.security
Send My: Arbitrary data transmission via Apple's Find My network | Positive Security
Apple AirTags: Arbitrary data can be uploaded from non-internet-connected devices by sending Find My BLE broadcasts to nearby Apple devices. We're releasing an ESP32 firmware that turns the microcontroller into an (upload only) modem, and a macOS application…
D-Link Router CVE-2021-27342 Vulnerability Writeup https://blog.whtaguy.com/2021/05/d-link-router-cve-2021-27342.html
AHK RAT Loader Used in Unique Delivery Campaigns https://blog.morphisec.com/ahk-rat-loader-leveraged-in-unique-delivery-campaigns
Morphisec
AHK RAT Loader Used in Unique Delivery Campaigns
The AHK RAT Loader is a unique delivery mechanism for remote access trojans because it makes use of the AutoHotKey scripting language.
Threat Actors Use MSBuild to Deliver RATs Filelessly https://www.anomali.com/blog/threat-actors-use-msbuild-to-deliver-rats-filelessly
Anomali
MSBuild Used By Threat Actors to Deliver RATs Filelessly
Microsoft Build Engine or MSBuild to filelessly deliver Remcos remote access tool or RATs and a password-stealing malware commonly known as RedLine Stealer.
Nice write-up » From theory to practice: analysis and PoC development for CVE-2020-28018 (Use-After-Free in Exim) [code in https://github.com/lockedbyte/CVE-Exploits/tree/master/CVE-2020-28018] https://adepts.of0x.cc/exim-cve-2020-28018/
GitHub
CVE-Exploits/CVE-2020-28018 at master · lockedbyte/CVE-Exploits
PoC exploits for software vulnerabilities. Contribute to lockedbyte/CVE-Exploits development by creating an account on GitHub.
Abusing Teams client protocol to bypass Teams security policies https://o365blog.com/post/teams-policies/
Aadinternals
Abusing Teams client protocol to bypass Teams security policies
Administrators can use teams policies for controlling what users can do in Microsoft Teams.
In this blog, I’ll show that these policies are applied only in client and thus can be easily bypassed.
In this blog, I’ll show that these policies are applied only in client and thus can be easily bypassed.