The Most Prolific Ransomware Families: A Defenders Guide https://www.domaintools.com/resources/blog/the-most-prolific-ransomware-families-a-defenders-guide
DomainTools | Start Here. Know Now.
The Most Prolific Ransomware Families: A Defenders Guide - DomainTools | Start Here. Know Now.
In this article, DomainTools researchers provide a look at the three most prolific ransomware families and their toolsets.
Analysis of a use-after-free Vulnerability in Adobe Acrobat Reader DC https://blog.exodusintel.com/2021/04/20/analysis-of-a-use-after-free-vulnerability-in-adobe-acrobat-reader-dc/
Exodus Intelligence
Analysis of a use-after-free Vulnerability in Adobe Acrobat Reader DC - Exodus Intelligence
By Sergi Martinez This post analyses CVE-2020-9715, a use-after-free vulnerability affecting several versions of the Adobe Acrobat and Adobe Acrobat Reader products. The vulnerability was discovered by Mark Vincent Yason, who reported it to the Zero Day Initiative…
Inside commercial malware sandboxes https://albocoder.github.io/malware/2021/06/01/SandboxStudy.html
FRIDA-DEXDump: Fast search and dump dex on memory https://securityonline.info/frida-dexdump-fast-search-and-dump-dex-on-memory/
Cybersecurity News
FRIDA-DEXDump v2.0.1 releases: Fast search and dump dex on memory
FRIDA-DEXDump support fuzzy search broken header dex, fix struct data of dex-header, compatible with all android version(frida supported).
GHSL-2021-034_043: Multiple pre-auth RCEs in Apache Dubbo - CVE-2021-25641, CVE-2021-30179, CVE-2021-30180, CVE-2021-30181, CVE-2021-32824 https://securitylab.github.com/advisories/GHSL-2021-034_043-apache-dubbo/
GitHub Security Lab
GHSL-2021-034_043: Multiple pre-auth RCEs in Apache Dubbo - CVE-2021-25641, CVE-2021-30179, CVE-2021-30180, CVE-2021-30181, CVE…
Multiple vulnerabilities have been found in Apache Dubbo enabling attackers to compromise and run arbitrary system commands on both Dubbo consumers and providers.
MODeflattener - Miasm's OLLVM Deflattener https://mrt4ntr4.github.io/MODeflattener/
mrT4ntr4's Blog
MODeflattener - Miasm's OLLVM Deflattener
So recently a challenge(Layers) from 3kCTF featured control flow flattening using OLLVM. Although I did know about control flow flattening I hadn’t encountered it personally. And as I’ve been experime
Intercepting Flutter iOS Application https://bhattsameer.github.io/2021/06/23/Intercepting-flutter-iOS-application.html
bhattsameer.github.io
Intercepting Flutter iOS Application
TL;DR Hi, this is Debugger ready to debug Mobile Application. In this blog I will share how I have intercepted the traffic of Flutter based iOS application for dynamic analysis, Also we will see the root detection and SSL verification bypass method I have…
CVE-2021-31955 Windows Kernel Information Disclosure POC https://github.com/mavillon1/CVE-2021-31955-POC
Exploiting the Sudo Baron Samedit vulnerability (CVE-2021-3156) on VMWare vCenter Server 7.0
https://research.nccgroup.com/2021/07/06/exploiting-the-sudo-baron-samedit-vulnerability-cve-2021-3156-on-vmware-vcenter-server-7-0/
https://research.nccgroup.com/2021/07/06/exploiting-the-sudo-baron-samedit-vulnerability-cve-2021-3156-on-vmware-vcenter-server-7-0/
Realtek WiFi Firmware and a Fully 8051-based Keylogger Using RealWOW Technology https://8051enthusiast.github.io/2021/07/05/002-wifi_fun.html
sqlvet: performs static analysis on raw SQL queries https://securityonline.info/sqlvet-performs-static-analysis-on-raw-sql-queries/
Cybersecurity News
sqlvet v1.1.7 releases: performs static analysis on raw SQL queries
Sqlvet performs static analysis on raw SQL queries in your Go codebase to surface potential runtime errors at build time.
Fuzzing ImageMagick and Digging Deeper into CVE-2020-27829 https://www.mcafee.com/blogs/other-blogs/mcafee-labs/fuzzing-imagemagick-and-digging-deeper-into-cve-2020-27829/
McAfee Blog
Fuzzing ImageMagick and Digging Deeper into CVE-2020-27829 | McAfee Blog
Introduction: ImageMagick is a hugely popular open source software that is used in lot of systems around the world. It is available for the Windows,
TrickBot Botnet Found Deploying A New Ransomware Called Diavol https://thehackernews.com/2021/07/trickbot-botnet-found-deploying-new.html
CVE-2021-20595: Unauthenticated XXE in Multiple Mitsubishi Electric Air Conditioner Control Systems https://www.aon.com/cyber-solutions/aon_cyber_labs/cve-2021-20595-unauthenticated-xxe-in-multiple-mitsubishi-electric-air-conditioner-control-systems/
Aon
CVE-2021-20595: Unauthenticated XXE in Multiple Mitsubishi Electric Air Conditioner Control Systems | Aon
Aon’s Cyber Solutions discovered a security vulnerability affecting over 20 Mitsubishi Electric Air Conditioner Control Systems leading to information disclosure and/or denial of service via unauthenticated XML External Entity Injection (XXE). For a complete…
Snake Keylogger’s Many Skins: Analysing Code Reuse Among Infostealers https://threatresearch.ext.hp.com/the-many-skins-of-snake-keylogger/
HP Wolf Security
Snake Keylogger's Many Skins: Analysing Code Reuse Among Infostealers | HP Wolf Security
Don’t let cyber threats get the best of you. Read our post, Snake Keylogger's Many Skins: Analysing Code Reuse Among Infostealers, to learn more about cyber threats and cyber security.
Reverse Engineering the M6 Smart Fitness Bracelet https://rbaron.net/blog/2021/07/06/Reverse-engineering-the-M6-smart-fitness-band.html
rbaron.net
Reverse Engineering the M6 Smart Fitness Bracelet
A blog post on hacking the $6 M6 fitness tracker.
Adding a native sniffer to your implants: decomposing and recomposing PktMon https://adepts.of0x.cc/pktmon-dissection/
Adding a native sniffer to your implants: decomposing and recomposing PktMon |
Adding a native sniffer to your implants: decomposing and recomposing PktMon | AdeptsOf0xCC
Disecting PktMon.exe utility and building our own sniffer based on it
Microsoft Teams user enumeration
https://www.immunit.ch/blog/2021/07/05/microsoft-teams-user-enumeration/
https://www.immunit.ch/blog/2021/07/05/microsoft-teams-user-enumeration/
Hancitor Making Use of Cookies to Prevent URL Scraping https://www.mcafee.com/blogs/other-blogs/mcafee-labs/hancitor-making-use-of-cookies-to-prevent-url-scraping/
McAfee Blog
Hancitor Making Use of Cookies to Prevent URL Scraping | McAfee Blog
This blog was written by Vallabh Chole & Oliver Devane Over the years, the cybersecurity industry has seen many threats get taken down, such as the
Alan Framework: post-exploitation framework https://securityonline.info/alan-framework-post-exploitation-framework/