It Only Takes A Minute to Clone a Credit Card, Thanks to a 50-Year-Old Problem https://www.cyberdlab.com/content/dam/cyberdlab/insights/it-only-takes-a-minute-to-clone-a-credit-card-thanks-to-a-50-year-old-problem/It_Only_Takes_a_Minute_to_Clone_a_Credit_Card_%20Thanks_to_a_50_Year_Old_Problem.pdf
Reversing DexGuard, Part 3 – Code Virtualization
https://www.pnfsoftware.com/blog/reversing-dexguard-virtualization/
https://www.pnfsoftware.com/blog/reversing-dexguard-virtualization/
Detecting Linux memfd_create() Fileless Malware with Command Line Forensics https://www.sandflysecurity.com/blog/detecting-linux-memfd_create-fileless-malware-with-command-line-forensics/
Sandfly Security - Agentless Linux EDR and Incident Response
Linux Malware Detection | Ubuntu, Debian, Redhat, Suse, Fedora, Raspberry Pi etc Malware Detect
How to investigate fileless malware on Linux for different distributions: Ubuntu, Debian, Redhat, Suse, Fedora, Raspberry Pi, Arch Linux, CentOS... using simple command line tools and techniques. Easily find create_memfd() injection attacks and more.
The iPhone Data Recovery Myth: What You Can and Cannot Recover https://blog.elcomsoft.com/2020/07/the-iphone-data-recovery-myth-what-you-can-and-cannot-recover/
ElcomSoft blog
The iPhone Data Recovery Myth: What You Can and Cannot Recover
There is no lack of tools claiming the ability to recover lost or deleted information from the iPhone. These tools’ claims range from “Recover data lost due to water damaged, broken, deletion, device loss, etc.” to the much more reserved “Selectively recovers…
Structured fuzzing Android's NFC
https://securitylab.github.com/research/fuzzing_android_nfc
https://securitylab.github.com/research/fuzzing_android_nfc
GitHub Security Lab
Structured fuzzing Android’s NFC
Man Yue Mo built and open sourced a fuzzer for the Android Near Field Communication (NFC) component. He shares here some design considerations when building the fuzzer.
Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520 https://github.com/patois/winmagic_sd
GitHub
GitHub - patois/winmagic_sd: Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520
Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520 - patois/winmagic_sd
McAfee Total Protection (MTP) < 16.0.R26 Escalation of Privilege (CVE-2020-7283) https://labs.redyops.com/index.php/2020/07/14/mcafee-total-protection-mtp-16-0-r26-escalation-of-privilege-cve-2020-7283/
REDYOPS Labs
McAfee Total Protection (MTP) < 16.0.R26 EoP (CVE-2020-7283)
Exploit Code and WriteUp for McAfee Total Protection (MTP) < 16.0.R26 Escalation of Privilege (CVE-2020-7283)
capa: Automatically Identify Malware Capabilities https://www.fireeye.com/blog/threat-research/2020/07/capa-automatically-identify-malware-capabilities.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
Seven 'no log' VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet https://www.theregister.com/2020/07/17/ufo_vpn_database/
The Register
Seven 'no log' VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet
Maybe it was the old Lionel Hutz play: 'No-logging VPN? I meant, No! Logging VPN!'
Welcome Chat as a secure messaging app? Nothing could be further from the truth https://www.welivesecurity.com/2020/07/14/welcome-chat-secure-messaging-app-nothing-further-truth/
WeLiveSecurity
Welcome Chat as a secure messaging app? Nothing could be further from the truth
ESET research uncovers a malicious operation that spies on Android users via Welcome Chat, an app posing as a secure chat service available in Google Play.
SCANdalous! (External Detection Using Network Scan Data and Automation) https://www.fireeye.com/blog/threat-research/2020/07/scandalous-external-detection-using-network-scan-data-and-automation.html
Google Cloud Blog
SCANdalous! (External Detection Using Network Scan Data and Automation) | Mandiant | Google Cloud Blog
Exploiting an Elevation of Privilege bug in Windows 10 (CVE-2020-1362) https://github.com/Q4n/CVE-2020-1362
Weaponizing Mapping Injection with Instrumentation Callback for stealthier process injection https://splintercod3.blogspot.com/p/weaponizing-mapping-injection-with.html
Internet Explorer CVE-2019–1367 Exploitation — part 3 https://blog.confiant.com/internet-explorer-cve-2019-1367-exploitation-part-3-a92d3011b38
Medium
Internet Explorer CVE-2019–1367 Exploitation — part 3
Shellcode Analysis
Micropatch Available for "SIGRed", the Wormable Remote Code Execution in Windows DNS Server (CVE-2020-1350) https://blog.0patch.com/2020/07/micropatch-available-for-sigred.html
0Patch
Micropatch Available for "SIGRed", the Wormable Remote Code Execution in Windows DNS Server (CVE-2020-1350)
by Mitja Kolsek, the 0patch Team This month's Patch Tuesday included a fix for CVE-2020-1350, a critical memory corruption vuln...
Runtime Mobile Security provides a web interface that helps you to manipulate Android and iOS Apps at Runtime (relies on FRIDA) https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security
GitHub
GitHub - m0bilesecurity/RMS-Runtime-Mobile-Security: Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps…
Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime - m0bilesecurity/RMS-Runtime-Mobile-Security
Painless Cuckoo Sandbox Installation https://blog.nviso.eu/2018/04/12/painless-cuckoo-sandbox-installation/
NVISO Labs
Painless Cuckoo Sandbox Installation
TLDR: As part of our SANS SEC599 development efforts, we updated (fixed + added some new features) an existing Cuckoo Auto Install script by Buguroo Security to automate Cuckoo sandbox installation…