Exploit Development: Swimming In The (Kernel) Pool - Leveraging Pool Vulnerabilities From Low-Integrity Exploits, Part 1 https://connormcgarr.github.io/swimming-in-the-kernel-pool-part-1/
Connor McGarr’s Blog
Exploit Development: Swimming In The (Kernel) Pool - Leveraging Pool Vulnerabilities From Low-Integrity Exploits, Part 1
Leveraging the HackSysExtreme Vulnerable Driver to understand the Windows kernel pool, the impacts of kLFH, and bypassing kASLR from low integrity via out-of-bounds read vulnerabilities.
Not security, but good contribution :) » vim plugin to have insert completion https://github.com/ervandew/supertab
GitHub
GitHub - ervandew/supertab: Perform all your vim insert mode completions with Tab
Perform all your vim insert mode completions with Tab - ervandew/supertab
CVE-2021-31166: RCE in Microsoft HTTP.sys https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2021-31166-rce-in-microsoft-httpsys/
Trustwave
CVE-2021-31166: RCE in Microsoft HTTP.sys
In the May 2021 Microsoft update, Microsoft patched an HTTP.sys vulnerability that has the ability to become a wormable remote code execution exploit. This vulnerability is being tracked as CVE-2021-31166. A proof of concept quickly emerged showing a denial…
Privilege escalation with polkit: How to get root on Linux with a seven-year-old bug https://github.blog/2021-06-10-privilege-escalation-polkit-root-on-linux-with-bug/
The GitHub Blog
Privilege escalation with polkit: How to get root on Linux with a seven-year-old bug
polkit is a system service installed by default on many Linux distributions. It’s used by systemd, so any Linux distribution that uses systemd also uses polkit.
A tool similar to pafish and ours, incorporates common techniques of analysis-aware malware » https://github.com/LordNoteworthy/al-khaser
GitHub
GitHub - ayoubfaouzi/al-khaser: Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection. - ayoubfaouzi/al-khaser
ThunderCats Hack the FSB | Your Taxes Didn’t Pay For This Op https://labs.sentinelone.com/thundercats-hack-the-fsb-your-taxes-didnt-pay-for-this-op/
SentinelOne
ThunderCats Hack the FSB | Your Taxes Didn’t Pay For This Op - SentinelLabs
Early fingerpointing at Western governments for a hack against the Russian government was misplaced. Our taxes didn't pay for this one.
Gelsemium: When threat actors go gardening https://www.welivesecurity.com/2021/06/09/gelsemium-when-threat-actors-go-gardening/
WeLiveSecurity
Gelsemium: When threat actors go gardening
ESET researchers dissect new campaigns of the generally quiet Gelsemium APT group, which they believe is also behind the supply-chain attack against BigNox.
[BugTales] A Nerve-Racking Bug Collision in Samsung's NPU Driver https://labs.taszk.io/articles/post/bug_collision_in_samsungs_npu_driver/
labs.taszk.io
[BugTales] A Nerve-Racking Bug Collision in Samsung's NPU Driver
Last summer I have discovered several vulnerabilities in the implementation of Samsung's NPU device driver. While I was working on completing my proof of concept exploit
nice tools » A collection of tools to interact with Microsoft Security Response Center API https://github.com/Immersive-Labs-Sec/msrc-api
GitHub
GitHub - Immersive-Labs-Sec/msrc-api: A collection of tools to interact with Microsoft Security Response Center API
A collection of tools to interact with Microsoft Security Response Center API - Immersive-Labs-Sec/msrc-api
Finding Privilege Escalation Vulnerabilities in Windows using Process Monitor https://vuls.cert.org/confluence/display/Wiki/Finding+Privilege+Escalation+Vulnerabilities+in+Windows+using+Process+Monitor
worth reading » ALPACA Attack: "application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates" https://alpaca-attack.com/
Abusing SIP for Cross-Site Scripting? Most definitely! https://www.rtcsec.com/post/2021/06/abusing-sip-for-cross-site-scripting-most-definitely/
W1 Feb| EN | Story of the week: Stealers on the Darkweb https://medium.com/s2wlab/w1-feb-en-story-of-the-week-stealers-on-the-darkweb-49945a31601d
Medium
W1 Feb| EN | Story of the week: Stealers on the Darkweb
The hand is quicker than the eye
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring https://flattsecurity.medium.com/cve-2021-20226-a-reference-counting-bug-which-leads-to-local-privilege-escalation-in-io-uring-e946bd69177a
Medium
CVE-2021–20226 a reference counting bug which leads to local privilege escalation in io_uring.
Hello, I’m Shiga( @Ga_ryo_ ), a security engineer at Flatt Security Inc.
Hiding your syscalls https://passthehashbrowns.github.io/hiding-your-syscalls
CVE-2021-31939 Outlook, Office • <= 16.0.13628.20274 • Use After Free https://cpr-zero.checkpoint.com/vulns/cprid-2164/
CPR-Zero
CPR-Zero: CVE-2021-31939
Check Point Research Vulnerability Repository
Data poisoning in action https://blog.f-secure.com/data-poisoning-in-action/
F-Secure Blog
Data poisoning in action - F-Secure Blog
While machine learning applications can be exposed to common security threats at the hardware, application, and network level, they are also exposed to domain specific threats that are currently overlooked. Data poisoning is amongst the most serious threats…
Nice contribution » D3fend MITRE: A knowledge graph of cybersecurity countermeasures https://d3fend.mitre.org/