capa: Automatically Identify Malware Capabilities https://www.fireeye.com/blog/threat-research/2020/07/capa-automatically-identify-malware-capabilities.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
Seven 'no log' VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet https://www.theregister.com/2020/07/17/ufo_vpn_database/
The Register
Seven 'no log' VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet
Maybe it was the old Lionel Hutz play: 'No-logging VPN? I meant, No! Logging VPN!'
Welcome Chat as a secure messaging app? Nothing could be further from the truth https://www.welivesecurity.com/2020/07/14/welcome-chat-secure-messaging-app-nothing-further-truth/
WeLiveSecurity
Welcome Chat as a secure messaging app? Nothing could be further from the truth
ESET research uncovers a malicious operation that spies on Android users via Welcome Chat, an app posing as a secure chat service available in Google Play.
SCANdalous! (External Detection Using Network Scan Data and Automation) https://www.fireeye.com/blog/threat-research/2020/07/scandalous-external-detection-using-network-scan-data-and-automation.html
Google Cloud Blog
SCANdalous! (External Detection Using Network Scan Data and Automation) | Mandiant | Google Cloud Blog
Exploiting an Elevation of Privilege bug in Windows 10 (CVE-2020-1362) https://github.com/Q4n/CVE-2020-1362
Weaponizing Mapping Injection with Instrumentation Callback for stealthier process injection https://splintercod3.blogspot.com/p/weaponizing-mapping-injection-with.html
Internet Explorer CVE-2019–1367 Exploitation — part 3 https://blog.confiant.com/internet-explorer-cve-2019-1367-exploitation-part-3-a92d3011b38
Medium
Internet Explorer CVE-2019–1367 Exploitation — part 3
Shellcode Analysis
Micropatch Available for "SIGRed", the Wormable Remote Code Execution in Windows DNS Server (CVE-2020-1350) https://blog.0patch.com/2020/07/micropatch-available-for-sigred.html
0Patch
Micropatch Available for "SIGRed", the Wormable Remote Code Execution in Windows DNS Server (CVE-2020-1350)
by Mitja Kolsek, the 0patch Team This month's Patch Tuesday included a fix for CVE-2020-1350, a critical memory corruption vuln...
Runtime Mobile Security provides a web interface that helps you to manipulate Android and iOS Apps at Runtime (relies on FRIDA) https://github.com/m0bilesecurity/RMS-Runtime-Mobile-Security
GitHub
GitHub - m0bilesecurity/RMS-Runtime-Mobile-Security: Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps…
Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime - m0bilesecurity/RMS-Runtime-Mobile-Security
Painless Cuckoo Sandbox Installation https://blog.nviso.eu/2018/04/12/painless-cuckoo-sandbox-installation/
NVISO Labs
Painless Cuckoo Sandbox Installation
TLDR: As part of our SANS SEC599 development efforts, we updated (fixed + added some new features) an existing Cuckoo Auto Install script by Buguroo Security to automate Cuckoo sandbox installation…
Writing an iOS Kernel Exploit from Scratch https://secfault-security.com/blog/chain3.html
Let's Learn: In-Depth Reversing of Recent Gozi ISFB Banking Malware Version 2.16/2.17 (portion of ISFB v3) & "loader.dll/client.dll" https://www.vkremez.com/2018/08/lets-learn-in-depth-reversing-of-recent.html
Vkremez
Let's Learn: In-Depth Reversing of Recent Gozi ISFB Banking Malware Version 2.16/2.17 (portion of ISFB v3) & "loader.dll/client.dll"
Goal : Reverse engineer and analyze one of the latest Gozi "ISFB" ( also called "Ursnif'" amongst various researchers) banking malware varia...
Video-tutorial on inspecting Windows Kernel Crash Dumps with Cerbero Suite https://www.youtube.com/watch?v=HcxH0_97taA&feature=youtu.be
YouTube
Inspecting Windows Kernel Crash Dumps with Cerbero Suite - YouTube
Exploiting an Envoy heap vulnerability https://blog.envoyproxy.io/exploiting-an-envoy-heap-vulnerability-96173d41792
Medium
Exploiting an Envoy heap vulnerability
Overview
CVE-2020-1350 - Windows DNS Server Vulnerability - SIGRed https://vrls.ws/posts/cve-2020-1350-windows-dns-server-vulnerability-sigred/
Card Fraud in a PSD2 World: A Few Examples https://www.cyberdlab.com/insights/card-fraud-in-a-psd2-world-a-few-examples
Cyberdlab
Card Fraud in a PSD2 World: A Few Examples
In this research, we share how it’s possible to bypass PSD2 required multi-factor authentication for both MasterCard and Visa cards.
Forwarded from CCN-CERT
Publicada una #vulnerabilidad en un módulo Node.js, que permitiría a un atacante producir una denegación de servicio #DoS. ¡Actualiza! https://t.co/USU7OZkaIr https://t.co/Ax67YLbf9I
www.ccn-cert.cni.es
CCN-CERT AV 66/20 Vulnerabilidad en Node.js
Bienvenido al portal de CCN-CERT
A cheatsheet with commands that can be used to perform kerberos attacks · GitHub
https://gist.github.com/TarlogicSecurity/2f221924fef8c14a1d8e29f3cb5c5c4a
https://gist.github.com/TarlogicSecurity/2f221924fef8c14a1d8e29f3cb5c5c4a
Gist
A cheatsheet with commands that can be used to perform kerberos attacks
A cheatsheet with commands that can be used to perform kerberos attacks - kerberos_attacks_cheatsheet.md