Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520 https://github.com/patois/winmagic_sd
GitHub
GitHub - patois/winmagic_sd: Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520
Technical Write-Up on and PoC Exploit for CVE-2020-11519 and CVE-2020-11520 - patois/winmagic_sd
McAfee Total Protection (MTP) < 16.0.R26 Escalation of Privilege (CVE-2020-7283) https://labs.redyops.com/index.php/2020/07/14/mcafee-total-protection-mtp-16-0-r26-escalation-of-privilege-cve-2020-7283/
REDYOPS Labs
McAfee Total Protection (MTP) < 16.0.R26 EoP (CVE-2020-7283)
Exploit Code and WriteUp for McAfee Total Protection (MTP) < 16.0.R26 Escalation of Privilege (CVE-2020-7283)
capa: Automatically Identify Malware Capabilities https://www.fireeye.com/blog/threat-research/2020/07/capa-automatically-identify-malware-capabilities.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
Seven 'no log' VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet https://www.theregister.com/2020/07/17/ufo_vpn_database/
The Register
Seven 'no log' VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet
Maybe it was the old Lionel Hutz play: 'No-logging VPN? I meant, No! Logging VPN!'
Welcome Chat as a secure messaging app? Nothing could be further from the truth https://www.welivesecurity.com/2020/07/14/welcome-chat-secure-messaging-app-nothing-further-truth/
WeLiveSecurity
Welcome Chat as a secure messaging app? Nothing could be further from the truth
ESET research uncovers a malicious operation that spies on Android users via Welcome Chat, an app posing as a secure chat service available in Google Play.
SCANdalous! (External Detection Using Network Scan Data and Automation) https://www.fireeye.com/blog/threat-research/2020/07/scandalous-external-detection-using-network-scan-data-and-automation.html
Google Cloud Blog
SCANdalous! (External Detection Using Network Scan Data and Automation) | Mandiant | Google Cloud Blog
Exploiting an Elevation of Privilege bug in Windows 10 (CVE-2020-1362) https://github.com/Q4n/CVE-2020-1362
Weaponizing Mapping Injection with Instrumentation Callback for stealthier process injection https://splintercod3.blogspot.com/p/weaponizing-mapping-injection-with.html
Internet Explorer CVE-2019–1367 Exploitation — part 3 https://blog.confiant.com/internet-explorer-cve-2019-1367-exploitation-part-3-a92d3011b38
Medium
Internet Explorer CVE-2019–1367 Exploitation — part 3
Shellcode Analysis
Micropatch Available for "SIGRed", the Wormable Remote Code Execution in Windows DNS Server (CVE-2020-1350) https://blog.0patch.com/2020/07/micropatch-available-for-sigred.html
0Patch
Micropatch Available for "SIGRed", the Wormable Remote Code Execution in Windows DNS Server (CVE-2020-1350)
by Mitja Kolsek, the 0patch Team This month's Patch Tuesday included a fix for CVE-2020-1350, a critical memory corruption vuln...
Runtime Mobile Security provides a web interface that helps you to manipulate Android and iOS Apps at Runtime (relies on FRIDA) https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security
GitHub
GitHub - m0bilesecurity/RMS-Runtime-Mobile-Security: Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps…
Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime - m0bilesecurity/RMS-Runtime-Mobile-Security
Painless Cuckoo Sandbox Installation https://blog.nviso.eu/2018/04/12/painless-cuckoo-sandbox-installation/
NVISO Labs
Painless Cuckoo Sandbox Installation
TLDR: As part of our SANS SEC599 development efforts, we updated (fixed + added some new features) an existing Cuckoo Auto Install script by Buguroo Security to automate Cuckoo sandbox installation…
Writing an iOS Kernel Exploit from Scratch https://secfault-security.com/blog/chain3.html
Let's Learn: In-Depth Reversing of Recent Gozi ISFB Banking Malware Version 2.16/2.17 (portion of ISFB v3) & "loader.dll/client.dll" https://www.vkremez.com/2018/08/lets-learn-in-depth-reversing-of-recent.html
Vkremez
Let's Learn: In-Depth Reversing of Recent Gozi ISFB Banking Malware Version 2.16/2.17 (portion of ISFB v3) & "loader.dll/client.dll"
Goal : Reverse engineer and analyze one of the latest Gozi "ISFB" ( also called "Ursnif'" amongst various researchers) banking malware varia...
Video-tutorial on inspecting Windows Kernel Crash Dumps with Cerbero Suite https://www.youtube.com/watch?v=HcxH0_97taA&feature=youtu.be
YouTube
Inspecting Windows Kernel Crash Dumps with Cerbero Suite - YouTube
Exploiting an Envoy heap vulnerability https://blog.envoyproxy.io/exploiting-an-envoy-heap-vulnerability-96173d41792
Medium
Exploiting an Envoy heap vulnerability
Overview
CVE-2020-1350 - Windows DNS Server Vulnerability - SIGRed https://vrls.ws/posts/cve-2020-1350-windows-dns-server-vulnerability-sigred/