macOS Big Sur 11.4 Addresses Vulnerability That Could Let Attackers Take Secret Screenshots https://www.macrumors.com/2021/05/24/macos-big-sur-11-4-malware-screenshots/
MacRumors
macOS Big Sur 11.4 Addresses Vulnerability That Could Let Attackers Take Secret Screenshots
macOS Big Sur 11.4, which was released this morning, addresses a zero-day vulnerability that could allow attackers to piggyback off of apps like...
My RCE PoC walkthrough for (CVE-2021–21974) VMware ESXi OpenSLP heap-overflow vulnerability https://straightblast.medium.com/my-poc-walkthrough-for-cve-2021-21974-a266bcad14b9
Medium
My RCE PoC walkthrough for (CVE-2021–21974) VMware ESXi OpenSLP heap-overflow vulnerability
Introduction
Building a malware analysis Lab: How to become a malware analysis hunter https://cybersecurity.att.com/blogs/security-essentials/building-a-home-lab-to-become-a-malware-hunter-a-beginners-guide
AT&T Cybersecurity
Building a malware analysis Lab: How to become a malware analysis hunter
As time goes by, criminals are developing more and more complex methods of obscuring how their malware operates, making it increasingly difficult to detect and analyze. The list of tactics used is seemingly endless and can include obfuscation, packers, executing…
COM Objects P.1: The Hidden Backdoor in Your System https://medium.com/maltrak/com-objects-p-1-the-hidden-backdoor-in-your-system-947ac4285e85
Medium
COM Objects P.1: The Hidden Backdoor in Your System
In the last few years, attackers have abused COM Objects to craft their Fileless attacks, evade defenses, bypass whitelisting, and even…
Cobalt Strikes Again: An Analysis of Obfuscated Malware https://www.huntress.com/blog/cobalt-strike-analysis-of-obfuscated-malware?utm_content=167704222&utm_medium=social&utm_source=twitter&hss_channel=tw-3330464153
Huntress
Cobalt Strikes Again: An Analysis of Obfuscated Malware
Join us for a threat hunting adventure as we analyze a suspicious run key that leads us to Cobalt Strike malware hidden across nearly 700 registry values.
Malware Analysis Series - Part 2, How to Isolate our Homelab with Network Segmentation https://blog.openthreatresearch.com/how_to_isolate_homelab
Open Threat Research Blog
Malware Analysis Series - Part 2, How to Isolate our Homelab with Network Segmentation
Introduction: In part one of this series, we established a solid foundation to begin our malware analysis journey. We successfully stood up two VMs; a Windows(FLARE) machine and a Linux(REMnux) machine. Put them on their own isolated virtual network without…
CVE-2021-33564 Argument Injection in Ruby Dragonfly https://zxsecurity.co.nz/research/argunment-injection-ruby-dragonfly/
zxsecurity.co.nz
Ruby Dragonfly - ZX Security
Full spectrum IT security services
Nice analysis » What EDRs Hook on Microsoft Windows i.e. where the gaps exist in terms of telemetry / detection coverage https://www.reddit.com/r/blueteamsec/comments/n8fufb/what_edrs_hook_on_microsoft_windows_ie_where_the
reddit
What EDRs Hook on Microsoft Windows i.e. where the gaps exist in...
Posted in r/blueteamsec by u/digicat • 105 points and 7 comments
Know Your Enemy: Exploiting the Dell BIOS Driver Vulnerability to Defend Against It https://www.crowdstrike.com/blog/cve-2021-21551-learning-through-exploitation/
CrowdStrike.com
CVE-2021-21551: Learning Through Exploitation | CrowdStrike
Using CVE-2021-21551 as an example, learn how adversaries approach weaponizing vulnerabilities, and the technologies that work best to mitigate their tactics.
Advisory X41-2021-002: nginx DNS Resolver Off-by-One Heap Write Vulnerability https://x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/
X41 D-Sec - Penetration Tests and Source Code Audits
nginx DNS Resolver Off-by-One Heap Write Vulnerability
An off-by-one error in ngx_resolver_copy() while processing DNS responses allows a network attacker to write a dot character (‘.’, 0x2E) out of bounds in a heap allocated buffer.
A PoC of Transacted Hollowoing, a PE injection technique (by @hasherezade) https://github.com/hasherezade/transacted_hollowing
GitHub
GitHub - hasherezade/transacted_hollowing: Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and…
Transacted Hollowing - a PE injection technique, hybrid between ProcessHollowing and ProcessDoppelgänging - hasherezade/transacted_hollowing
Forensic Analysis: jackcr difr challenge https://digitalitskills.com/forensic-analysis-jackcr-difr-challenge/
Guide to P-code Injection: Changing the intermediate representation of code on the fly in Ghidra https://swarm.ptsecurity.com/guide-to-p-code-injection/
32 bits, 32 gigs, 1 click... Exploitation of a JavaScriptCore WebAssembly Vulnerability https://blog.ret2.io/2021/06/02/pwn2own-2021-jsc-exploit/
RET2 Systems Blog
32 bits, 32 gigs, 1 click...
In this post we will examine a vulnerability in the WebAssembly subsystem of JavaScriptCore, the JavaScript engine used in WebKit and Apple Safari. The issue...
Threat Hunting: Log Monitoring Lab Setup with ELK https://www.hackingarticles.in/threat-hunting-log-monitoring-lab-setup-with-elk/
Hacking Articles
Threat Hunting: Log Monitoring Lab Setup with ELK
Learn Threat hunting with ELK log monitoring lab setup, configuration & analysis for security incident response & threat detection techniques
Revisiting the NSIS-based crypter https://blog.malwarebytes.com/threat-analysis/2021/05/revisiting-the-nsis-based-crypter/
ThreatDown by Malwarebytes
Revisiting the NSIS-based crypter - ThreatDown by Malwarebytes
This blog post was authored by hasherezade NSIS (Nullsoft Scriptable Install System) is a framework dedicated to creating software installers. It…
Malware Can Use This Trick to Bypass Ransomware Defense in Antivirus Solutions https://thehackernews.com/2021/06/malware-can-use-this-trick-to-bypass.html
The Hacker News
Malware Can Use This Trick to Bypass Ransomware Defense in Antivirus Solutions
Malware Can Use This New Trick to Bypass Ransomware Defense in Popular Antivirus Solutions
iOS Malicious Bit Hunter: malicious plug-in detection engine for iOS applications https://securityonline.info/ios-malicious-bit-hunter/
Cybersecurity News
iOS Malicious Bit Hunter: malicious plug-in detection engine for iOS applications
iOS Malicious Bit Hunter can analyze the head of the macho file of the injected dylib dynamic library based on runtime, and can perform behavior analysis