Investigate malicious Windows logon by visualizing and analyzing Windows event log https://github.com/JPCERTCC/LogonTracer
GitHub
GitHub - JPCERTCC/LogonTracer: Investigate malicious Windows logon by visualizing and analyzing Windows event log
Investigate malicious Windows logon by visualizing and analyzing Windows event log - JPCERTCC/LogonTracer
❤1
How LNK Files Are Abused by Threat Actors https://www.intezer.com/blog/malware-analysis/how-threat-actors-abuse-lnk-files/
Intezer
How LNK Files Are Abused by Threat Actors
LNK files (aka Windows shortcuts) may seem simple, but threat actors can use them to execute other binaries and inflict great harm.
Exploiting Race conditions with Nuclei https://blog.projectdiscovery.io/exploiting-race-conditons/ (demo here: https://github.com/projectdiscovery/php-app-race-condition)
ProjectDiscovery
Exploiting Race conditions with Nuclei — ProjectDiscovery Blog
What Is a Race Condition Vulnerability?
A race condition attack happens when a computing system that’s designed to
handle tasks in a specific sequence is forced to perform two or more operations
simultaneously. This technique takes advantage of a time gap…
A race condition attack happens when a computing system that’s designed to
handle tasks in a specific sequence is forced to perform two or more operations
simultaneously. This technique takes advantage of a time gap…
Copy-paste heist or clipboard-injector attacks on cryptousers https://securelist.com/copy-paste-heist-clipboard-injector-targeting-cryptowallets/109186/
Rhadamanthys: The “Everything Bagel” Infostealer https://research.checkpoint.com/2023/rhadamanthys-the-everything-bagel-infostealer/
Check Point Research
Rhadamanthys: The “Everything Bagel” Infostealer - Check Point Research
Key Takeaways Background What causes a man to wake up one day and say, “I’m going to build my own malware and go sell it to cybercriminals on the dark web”? After all, the market is saturated with competitors, and the product is judged on the one sole metric…
pipe_buffer arbitrary read write https://www.interruptlabs.co.uk/articles/pipe-buffer
DEF CON 30 - Mickey Shkatov, Jesse Michael - One Bootloader to Load Them All https://www.youtube.com/watch?v=99t7wEYs8h0
YouTube
DEF CON 30 - Mickey Shkatov, Jesse Michael - One Bootloader to Load Them All
Introduced in 2012, Secure Boot - the OG trust in boot - has become a foundational rock in modern computing and is used by millions of UEFI-enabled computers around the world due to its integration in their BIOS.
The way Secure Boot works is simple and…
The way Secure Boot works is simple and…
3CX Supply Chain Compromise Leads to ICONIC Incident https://www.volexity.com/blog/2023/03/30/3cx-supply-chain-compromise-leads-to-iconic-incident/
Volexity
3CX Supply Chain Compromise Leads to ICONIC Incident
[Update: Following additional analysis of shellcode used in ICONIC, in conjunction with other observations from the wider security community, Volexity now attributes the activity described in this post to the […]
Mélofée: a new alien malware in the Panda's toolset targeting Linux hosts https://blog.exatrack.com/melofee/
CVE-2022-27666: My file your memory https://albocoder.github.io/exploit/2023/03/13/KernelFileExploit.html
Erin Avllazagaj
CVE-2022-27666: My file your memory
Ironing out (the macOS) details of a Smooth Operator (Part I) https://objective-see.org/blog/blog_0x73.html
Objective-See
Ironing out (the macOS) details of a Smooth Operator (Part I)
The 3CX supply chain attack, gives us an opportunity to analyze a trojanized macOS application
Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife https://www.sentinelone.com/labs/dissecting-alienfox-the-cloud-spammers-swiss-army-knife/
SentinelOne
Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife
A sophisticated new toolset is being used to harvest credentials from multiple cloud service providers, including AWS SES and Microsoft Office 365.
Lord of the SID: How to Add the objectSID Attribute to a Certificate Manually https://elkement.blog/2023/03/30/lord-of-the-sid-how-to-add-the-objectsid-attribute-to-a-certificate-manually/
elkemental Force
Lord of the SID: How to Add the objectSID Attribute to a Certificate Manually
In May 2022 Microsoft has fixed a vulnerability related to certificate logon to Active Directory. As a non-privileged user you could escalate privileges by impersonating a Domain Controller, as you…
👍1
Technical Analysis of Xloader’s Code Obfuscation in Version 4.3 https://www.zscaler.com/blogs/security-research/technical-analysis-xloaders-code-obfuscation-version-43
Zscaler
Home | Zscaler
Zscaler, the zero trust cybersecurity leader, accelerates digital transformation with fast, secure connections between users, devices and apps over any network.
❤2
X-Force Prevents Zero Day from Going Anywhere https://securityintelligence.com/posts/x-force-prevents-zero-day-from-going-anywhere/
Security Intelligence
X-Force Prevents Zero Day from Going Anywhere
Dive into the investigation of a zero-day attack that took advantage of a vulnerability in Forta’s file-transfer tool, GoAnyWhere. Explore the research from IBM X-Force experts.
Meet the FSB contractor: 0Day Technologies https://clement-briens.com/2023/04/01/meet-the-fsb-contractor-0day-technologies/
❤1
Spyware vendors use 0-days and n-days against popular platforms https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/
Google
Spyware vendors use 0-days and n-days against popular platforms
Google’s Threat Analysis Group (TAG) tracks actors involved in information operations (IO), government backed attacks and financially motivated abuse. For years, TAG has…
RISC-V: Why The ISA Battles Aren’t Over Yet https://hackaday.com/2019/11/12/risc-v-why-the-isa-battles-arent-over-yet/
Hackaday
RISC-V: Why The ISA Battles Aren’t Over Yet
A computer processor uses a so-called Instruction Set Architecture to talk with the world outside of its own circuitry. This ISA consists of a number of instructions, which essentially define the f…
Magniber ransomware analysis: Tiny Tracer in action https://hshrzd.wordpress.com/2023/03/30/magniber-ransomware-analysis/
hasherezade's 1001 nights
Magniber ransomware analysis: Tiny Tracer in action
Intro Magniber is a ransomware that was initially targeting South Korea. My first report on this malware was written for Malwarebytes in 2017 (here). Since then, the ransomware was completely rewri…