.net core evasion detection https://pentestlaboratories.com/2020/07/02/net-core-evasion-detection/
Pentest Laboratories
.NET Core Evasion Detection
Environments that have installed the .NET Core (version 3.11) are affected by a directory traversal vulnerability since the environment variable doesn’t sanitize user input and therefore cust…
Securing Critical Infrastructure: 4 Steps for Reducing Cyber Risk https://www.tenable.com/blog/securing-critical-infrastructure-four-steps-for-reducing-cyber-risk
Tenable®
Securing Critical Infrastructure: 4 Steps for Reducing Cyber Risk
For critical infrastructure organizations, the gains of automation and IoT technology have also meant heightened threats.
Would you like some RCE with your Guacamole? https://research.checkpoint.com/2020/apache-guacamole-rce/
Check Point Research
Would you like some RCE with your Guacamole? - Check Point Research
Research by: Eyal Itkin Overview In many companies, the daily routine involves coming to the office each day to work on your company computer, safely inside the corporate network. Once in a while, a worker may need special offsite access and will connect…
Remote Code Execution Vulnerability in Zoom Client for Windows (0day) https://blog.0patch.com/2020/07/remote-code-execution-vulnerability-in.html
0Patch
Remote Code Execution Vulnerability in Zoom Client for Windows (0day)
by Mitja Kolsek, the 0patch Team [Update 7/13/2020: Zoom only took one (!) day to issue a new version of Client for Windows that fixes this...
PhishINvite with Malicious ICS Files https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/phishinvite-with-malicious-ics-files/
Trustwave
PhishINvite with Malicious ICS Files | Trustwave
Employing a popular type of file as an attachment to malicious emails is a common trick by cybercriminals to boost the success rate of their cyber-attacks. As iCalendars files are not included in the list of automatically blocked attachments by email clients…
Hardware breakpoints and exceptions on Windows https://ling.re/hardware-breakpoints/
LingSec
Hardware breakpoints and exceptions on Windows
Hardware breakpoints on Windows and common detection vectors
Combinig LUAFV PostLuafvPostReadWrite Race Condition PE with DiagHub collector exploit -> from standard user to SYSTEM https://decoder.cloud/2019/04/29/combinig-luafv-postluafvpostreadwrite-race-condition-pe-with-diaghub-collector-exploit-from-standard-user-to-system/
Decoder's Blog
Combinig LUAFV PostLuafvPostReadWrite Race Condition PE with DiagHub collector exploit -> from standard user to SYSTEM
In this short post I will show you how to combine Forshaw’s Microsoft Windows 10 1809 – LUAFV PostLuafvPostReadWrite SECTION_OBJECT_POINTERS Race Condition Privilege Escalation with F…
Great contribution --> Introducing Kernel Data Protection, a new platform security technology for preventing data corruption https://www.microsoft.com/security/blog/2020/07/08/introducing-kernel-data-protection-a-new-platform-security-technology-for-preventing-data-corruption/
Microsoft News
Introducing Kernel Data Protection, a new platform security technology for preventing data corruption
Kernel Data Protection (KDP) is a set of APIs that provide the ability to mark some kernel memory as read-only, preventing attackers from ever modifying protected memory.
A Comprehensive Guide to JAVA Serialization Vulnerability https://medium.com/bugbountywriteup/a-comprehensive-guide-to-java-serialization-vulnerability-18fad6e37b64
Medium
A Comprehensive Guide to JAVA Serialization Vulnerability
TLDR
Understanding the root cause of F5 Networks K52145254: TMUI RCE vulnerability CVE-2020-5902
https://research.nccgroup.com/2020/07/12/understanding-the-root-cause-of-f5-networks-k52145254-tmui-rce-vulnerability-cve-2020-5902/
https://research.nccgroup.com/2020/07/12/understanding-the-root-cause-of-f5-networks-k52145254-tmui-rce-vulnerability-cve-2020-5902/
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
Bean Stalking: Growing Java beans into RCE https://securitylab.github.com/research/bean-validation-RCE
GitHub Security Lab
Bean Stalking: Growing Java beans into RCE
In this post I’ll show how input validation which should be used to prevent malformed inputs to enter our applications, open up the doors to Remote Code Execution (RCE).
Google open-sources Tsunami vulnerability scanner https://www.zdnet.com/article/google-open-sources-tsunami-vulnerability-scanner/
ZDNET
Google open-sources Tsunami vulnerability scanner
Google says Tsunami is an extensible network scanner for detecting high-severity vulnerabilities with as little false-positives as possible.
Purple Fox EK Adds Exploits for CVE-2020-0674 and CVE-2019-1458 to its Arsenal https://www.proofpoint.com/us/blog/threat-insight/purple-fox-ek-adds-exploits-cve-2020-0674-and-cve-2019-1458-its-arsenal
Proofpoint
Purple Fox Malware EK Adds More Exploits to Its Arsenal | Proofpoint US
Purple Fox is an exploit kit (EK) that has been built to replace the RIG exploit kit (EK) in the distribution chain of Purple Fox malware. Learn more.
Reverse engineering of the Anubis malware https://orangecyberdefense.com/uk/blog/uncategorized/reverse-engineering-of-the-anubis-malware/
United Kingdom
Reverse engineering of the Anubis malware | Orange Cyberdefense
Anubis is an Android malware. It is known for stealing banking credentials and allowing its master to spy on the smartphone’s user. Find out more about reverse engineering of this malware.
Apache Tomcat RCE by deserialization (CVE-2020-9484) – write-up and exploit
https://www.redtimmy.com/java-hacking/apache-tomcat-rce-by-deserialization-cve-2020-9484-write-up-and-exploit/
https://www.redtimmy.com/java-hacking/apache-tomcat-rce-by-deserialization-cve-2020-9484-write-up-and-exploit/