nice post (I wish you the best of luck if you need to analyze this type of code) » Writing a VB6 P-Code Debugger https://decoded.avast.io/davidzimmer/writing-a-vb6-p-code-debugger/
Gendigital
Writing a VB6 P-Code Debugger
Developing a P-Code Debugger for Enhanced Malware Analysis
From Binary Patch to Proof-of-concept: a VMware ESXi vmxnet3 Case Study https://zerodayengineering.com/research/vmware-esxi-vmxnet3-from-patch-to-poc.html
How we bypassed bytenode and decompiled Node.js bytecode in Ghidra https://swarm.ptsecurity.com/how-we-bypassed-bytenode-and-decompiled-node-js-bytecode-in-ghidra/
1 TB Encryption Key? https://medium.com/asecuritysite-when-bob-met-alice/making-rsa-great-again-or-fishing-in-an-empty-barrel-3be801ebb9a1
Medium
1 TB Encryption Key?
The RSA method has stood the test of time, but its end may be nigh. It’s tried its hardest to keep up, and has continually expanded its…
CVE-2021-27075: Microsoft Azure Vulnerability Allows Privilege Escalation and Leak of Private Data https://www.intezer.com/blog/cloud-security/cve-2021-27075-microsoft-azure-vulnerability-allows-privilege-escalation-and-leak-of-data/
Intezer
CVE-2021-27075: Microsoft Azure Vulnerability
Vulnerability in Microsoft Azure VM Extension would allow privilege escalation and leak of private data.
Shared document about tools and utilities mentioned in "The Art of Mac Malware" (by Patrick Wardle) https://docs.google.com/document/d/1xOWmMueHHRke9aj3oRqNBgK69Y19hgZ7ehM4H9_Me-Y/edit
Google Docs
Tools for macOS malware analysis [PUBLIC]
Tools and utilities mentioned in The Art of Mac Malware by Patrick Wardle olevba is a script to parse Office documents to detect VBA Macros ProcessMonitor by Objective-See to monitor process creations and terminations TaskExplorer by Objective-See to visually…
Send My: Arbitrary data transmission via Apple's Find My network https://positive.security/blog/send-my
positive.security
Send My: Arbitrary data transmission via Apple's Find My network | Positive Security
Apple AirTags: Arbitrary data can be uploaded from non-internet-connected devices by sending Find My BLE broadcasts to nearby Apple devices. We're releasing an ESP32 firmware that turns the microcontroller into an (upload only) modem, and a macOS application…
D-Link Router CVE-2021-27342 Vulnerability Writeup https://blog.whtaguy.com/2021/05/d-link-router-cve-2021-27342.html
AHK RAT Loader Used in Unique Delivery Campaigns https://blog.morphisec.com/ahk-rat-loader-leveraged-in-unique-delivery-campaigns
Morphisec
AHK RAT Loader Used in Unique Delivery Campaigns
The AHK RAT Loader is a unique delivery mechanism for remote access trojans because it makes use of the AutoHotKey scripting language.
Threat Actors Use MSBuild to Deliver RATs Filelessly https://www.anomali.com/blog/threat-actors-use-msbuild-to-deliver-rats-filelessly
Anomali
MSBuild Used By Threat Actors to Deliver RATs Filelessly
Microsoft Build Engine or MSBuild to filelessly deliver Remcos remote access tool or RATs and a password-stealing malware commonly known as RedLine Stealer.
Nice write-up » From theory to practice: analysis and PoC development for CVE-2020-28018 (Use-After-Free in Exim) [code in https://github.com/lockedbyte/CVE-Exploits/tree/master/CVE-2020-28018] https://adepts.of0x.cc/exim-cve-2020-28018/
GitHub
CVE-Exploits/CVE-2020-28018 at master · lockedbyte/CVE-Exploits
PoC exploits for software vulnerabilities. Contribute to lockedbyte/CVE-Exploits development by creating an account on GitHub.
Abusing Teams client protocol to bypass Teams security policies https://o365blog.com/post/teams-policies/
Aadinternals
Abusing Teams client protocol to bypass Teams security policies
Administrators can use teams policies for controlling what users can do in Microsoft Teams.
In this blog, I’ll show that these policies are applied only in client and thus can be easily bypassed.
In this blog, I’ll show that these policies are applied only in client and thus can be easily bypassed.
Hacking GraphQL for Fun and Profit — Part 2— Methodology and Examples https://infosecwriteups.com/hacking-graphql-for-fun-and-profit-part-2-methodology-and-examples-5992093bcc24
Medium
Hacking GraphQL for Fun and Profit — Part 2— Methodology and Examples
Hi everyone!!
Exploiting custom protocol handlers for cross-browser tracking in Tor, Safari, Chrome and Firefox https://fingerprintjs.com/blog/external-protocol-flooding/
Fingerprint
Cross-browser tracking vulnerability in Tor, Safari, Chrome, and Firefox
Unveiling a scheme flooding vulnerability across major browsers. Learn how it threatens anonymous browsing.
Counter-Strike Global Offsets: reliable remote code execution https://secret.club/2021/05/13/source-engine-rce-join.html
secret club
Counter-Strike Global Offsets: reliable remote code execution
One of the factors contributing to Counter-Strike Global Offensive’s (herein “CS:GO”) massive popularity is the ability for anyone to host their own community server. These community servers are free to download and install and allow for a high grade of customization.…
Exploit Development: CVE-2021-21551 - Dell ‘dbutil_2_3.sys’ Kernel Exploit Writeup https://connormcgarr.github.io/cve-2020-21551-sploit/
Connor McGarr’s Blog
Exploit Development: CVE-2021-21551 - Dell ‘dbutil_2_3.sys’ Kernel Exploit Writeup
Analysis and writeup on weaponizing CVE-2021-21551 without a data-only attack and the importance of Virtualization-Based Security, Hypervisor-Protected Code Integrity, Kernel Control-Flow Guard, and other modern mitigations.
Transparent Tribe APT expands its Windows malware arsenal https://blog.talosintelligence.com/2021/05/transparent-tribe-infra-and-targeting.html
Cisco Talos
Transparent Tribe APT expands its Windows malware arsenal
Transparent Tribe, also known as APT36 and Mythic Leopard, continues to create fake domains mimicking legitimate military and defense organizations as a core component of their operations. Cisco Talos’ previous research has mainly linked this group to CrimsonRAT…
Analyzing APT19 malware using a step-by-step method https://cybergeeks.tech/analyzing-apt19-malware-using-a-step-by-step-method/
VMProtect 2 - Detailed Analysis of the Virtual Machine Architecture https://back.engineering/17/05/2021/#preamble
Fuzzing iOS code on macOS at native speed https://googleprojectzero.blogspot.com/2021/05/fuzzing-ios-code-on-macos-at-native.html?m=1
Blogspot
Fuzzing iOS code on macOS at native speed
Or how iOS apps on macOS work under the hood Posted by Samuel Groß, Project Zero This short post explains how code compiled for iOS ...
BazarCall Method: Call Centers Help Spread BazarLoader Malware https://unit42.paloaltonetworks.com/bazarloader-malware/
Unit 42
BazarCall Method: Call Centers Help Spread BazarLoader Malware
Call center operators offer to personally guide victims through a process designed to infect vulnerable computers with BazarLoader malware.