Analyzing APT19 malware using a step-by-step method https://cybergeeks.tech/analyzing-apt19-malware-using-a-step-by-step-method/
VMProtect 2 - Detailed Analysis of the Virtual Machine Architecture https://back.engineering/17/05/2021/#preamble
Fuzzing iOS code on macOS at native speed https://googleprojectzero.blogspot.com/2021/05/fuzzing-ios-code-on-macos-at-native.html?m=1
Blogspot
Fuzzing iOS code on macOS at native speed
Or how iOS apps on macOS work under the hood Posted by Samuel Groß, Project Zero This short post explains how code compiled for iOS ...
BazarCall Method: Call Centers Help Spread BazarLoader Malware https://unit42.paloaltonetworks.com/bazarloader-malware/
Unit 42
BazarCall Method: Call Centers Help Spread BazarLoader Malware
Call center operators offer to personally guide victims through a process designed to infect vulnerable computers with BazarLoader malware.
A detailed analysis of ELMER Backdoor used by APT16 https://cybergeeks.tech/a-detailed-analysis-of-elmer-backdoor-used-by-apt16/
A skidalicious cheat sheet of webapp exploitation techniques https://blog.oxagast.org/posts/skidalicious-webapp-exploit-cheat-sheet/
blog.oxagast.org
Web app exploitation techniques |
oxasploits
oxasploits
Some popular web application exploitation techniques
Tracking BokBot Infrastructure: Mapping a Vast and Currently Active BokBot Network https://team-cymru.com/blog/2021/05/19/tracking-bokbot-infrastructure/
Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot https://github.com/D3VI5H4/Antivirus-Artifacts
GitHub
GitHub - ethereal-vx/Antivirus-Artifacts: Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes…
Anti-virus artifacts. Listing APIs hooked by: Avira, BitDefender, F-Secure, MalwareBytes, Norton, TrendMicro, and WebRoot. - ethereal-vx/Antivirus-Artifacts
Reverse Engineering & Exploiting Dell CVE-2021-21551 https://voidsec.com/reverse-engineering-and-exploiting-dell-cve-2021-21551/
VoidSec
Reverse Engineering & Exploiting Dell CVE-2021-21551 - VoidSec
Didactic blog post regarding the process and methodology used to Reverse Engineering & Weaponize Dell's CVE-2021-21551.
The Full Story of the Stunning RSA Hack Can Finally Be Told https://www.wired.com/story/the-full-story-of-the-stunning-rsa-hack-can-finally-be-told/
WIRED
The Full Story of the Stunning RSA Hack Can Finally Be Told
In 2011, Chinese spies stole the crown jewels of cybersecurity—stripping protections from firms and government agencies worldwide. Here’s how it happened.
When Intrusions Don’t Align: A New Water Watering Hole and Oldsmar https://www.dragos.com/blog/industry-news/a-new-water-watering-hole/
Dragos
When Intrusions Don't Align: A New Water Watering Hole and Oldsmar
While investigating the Oldsmar water treatment facility breach, Dragos discovered malicious code being hosted on a utility contractor website (a watering hole). Read the threat analysis for more.
What’s new in Android Privacy https://android-developers.googleblog.com/2021/05/android-security-and-privacy-recap.html
Android Developers Blog
What’s new in Android Privacy
Posted by Sara N-Marandi, Product Manager, Android Platform Product People want an OS and apps that they can trust with the...
Vulnerability Spotlight: Heap-based buffer overflow in Google Chrome could lead to code execution https://blog.talosintelligence.com/2021/05/vuln-spotlight-google-chrome-heap.html
Cisco Talos Blog
Vulnerability Spotlight: Heap-based buffer overflow in Google Chrome could lead to code execution
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered an exploitable heap-based buffer overflow vulnerability in Google Chrome.
Google Chrome is a cross-platform web browser — and Chromium…
Cisco Talos recently discovered an exploitable heap-based buffer overflow vulnerability in Google Chrome.
Google Chrome is a cross-platform web browser — and Chromium…
Great tips » Guy's 30 Reverse Engineering Tips & Tricks https://blog.whtaguy.com/2020/04/guys-30-reverse-engineering-tips-tricks.html
Mav Levin Security Research
Mav's 30 Reverse Engineering Tips & Tricks
During April I challenged myself to tweet 1 reverse engineering tip every day. For your viewing pleasure, here I aggregated all 30 tips.Be sure to follow me ...
Students detect security breaches in popular apps https://cs.au.dk/news-events/pages/2021/students-detect-security-breaches-in-popular-apps/
cs.au.dk
Students detect security breaches in popular apps
How Flubot targets Android phone users and their money https://www.nortonlifelock.com/blogs/norton-labs/flubot-targets-android-phone-users
Nortonlifelock
How Flubot targets Android phone users and their money
Malware steals login credentials for banking and cryptocurrency apps — and it could spread around the world
What is Rootkit? https://computer0virusology.bloggi.co/rootkit-anatomy-1
Computer0Virusology
What is Rootkit ?
In our definition of "Rootkit" the key word is "undetectable"
The term rootkit has been around for more than 10 years. A rootkit is a "kit" consisting of small and useful programs that allow an attacker to maintain access to "root," the most powerful user…
The term rootkit has been around for more than 10 years. A rootkit is a "kit" consisting of small and useful programs that allow an attacker to maintain access to "root," the most powerful user…
A Practical Approach to Attacking IoT Embedded Designs (II) https://labs.ioactive.com/2021/02/a-practical-approach-to-attacking-iot_23.html
Ioactive
A Practical Approach to Attacking IoT Embedded Designs (II)
by Ruben Santamarta In this second and final blog post on this topic, we cover some OTA vulnerabilities we identified in wireless commun...
How to Kerberos? its components and function https://sheerazali.com/how-to-kerberos-its-components-and-function/
Sheeraz ali
How to Kerberos? its components and function - Sheeraz ali
Kerberos is used in windows authentication and the active directory. It is an authentication protocol that is if implemented is more secure ..