DEF CON 30 - Mickey Shkatov, Jesse Michael - One Bootloader to Load Them All https://www.youtube.com/watch?v=99t7wEYs8h0
YouTube
DEF CON 30 - Mickey Shkatov, Jesse Michael - One Bootloader to Load Them All
Introduced in 2012, Secure Boot - the OG trust in boot - has become a foundational rock in modern computing and is used by millions of UEFI-enabled computers around the world due to its integration in their BIOS.
The way Secure Boot works is simple and…
The way Secure Boot works is simple and…
3CX Supply Chain Compromise Leads to ICONIC Incident https://www.volexity.com/blog/2023/03/30/3cx-supply-chain-compromise-leads-to-iconic-incident/
Volexity
3CX Supply Chain Compromise Leads to ICONIC Incident
[Update: Following additional analysis of shellcode used in ICONIC, in conjunction with other observations from the wider security community, Volexity now attributes the activity described in this post to the […]
Mélofée: a new alien malware in the Panda's toolset targeting Linux hosts https://blog.exatrack.com/melofee/
CVE-2022-27666: My file your memory https://albocoder.github.io/exploit/2023/03/13/KernelFileExploit.html
Erin Avllazagaj
CVE-2022-27666: My file your memory
Ironing out (the macOS) details of a Smooth Operator (Part I) https://objective-see.org/blog/blog_0x73.html
Objective-See
Ironing out (the macOS) details of a Smooth Operator (Part I)
The 3CX supply chain attack, gives us an opportunity to analyze a trojanized macOS application
Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife https://www.sentinelone.com/labs/dissecting-alienfox-the-cloud-spammers-swiss-army-knife/
SentinelOne
Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife
A sophisticated new toolset is being used to harvest credentials from multiple cloud service providers, including AWS SES and Microsoft Office 365.
Lord of the SID: How to Add the objectSID Attribute to a Certificate Manually https://elkement.blog/2023/03/30/lord-of-the-sid-how-to-add-the-objectsid-attribute-to-a-certificate-manually/
elkemental Force
Lord of the SID: How to Add the objectSID Attribute to a Certificate Manually
In May 2022 Microsoft has fixed a vulnerability related to certificate logon to Active Directory. As a non-privileged user you could escalate privileges by impersonating a Domain Controller, as you…
👍1
Technical Analysis of Xloader’s Code Obfuscation in Version 4.3 https://www.zscaler.com/blogs/security-research/technical-analysis-xloaders-code-obfuscation-version-43
Zscaler
Home | Zscaler
Zscaler, the zero trust cybersecurity leader, accelerates digital transformation with fast, secure connections between users, devices and apps over any network.
❤2
X-Force Prevents Zero Day from Going Anywhere https://securityintelligence.com/posts/x-force-prevents-zero-day-from-going-anywhere/
Security Intelligence
X-Force Prevents Zero Day from Going Anywhere
Dive into the investigation of a zero-day attack that took advantage of a vulnerability in Forta’s file-transfer tool, GoAnyWhere. Explore the research from IBM X-Force experts.
Meet the FSB contractor: 0Day Technologies https://clement-briens.com/2023/04/01/meet-the-fsb-contractor-0day-technologies/
❤1
Spyware vendors use 0-days and n-days against popular platforms https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/
Google
Spyware vendors use 0-days and n-days against popular platforms
Google’s Threat Analysis Group (TAG) tracks actors involved in information operations (IO), government backed attacks and financially motivated abuse. For years, TAG has…
RISC-V: Why The ISA Battles Aren’t Over Yet https://hackaday.com/2019/11/12/risc-v-why-the-isa-battles-arent-over-yet/
Hackaday
RISC-V: Why The ISA Battles Aren’t Over Yet
A computer processor uses a so-called Instruction Set Architecture to talk with the world outside of its own circuitry. This ISA consists of a number of instructions, which essentially define the f…
Magniber ransomware analysis: Tiny Tracer in action https://hshrzd.wordpress.com/2023/03/30/magniber-ransomware-analysis/
hasherezade's 1001 nights
Magniber ransomware analysis: Tiny Tracer in action
Intro Magniber is a ransomware that was initially targeting South Korea. My first report on this malware was written for Malwarebytes in 2017 (here). Since then, the ransomware was completely rewri…
Dissecting redis CVE-2023-28425 with chatGPT as assistant https://tin-z.github.io/redis/cve/chatgpt/2023/04/02/redis-cve2023.html
Lambda driver blog
Dissecting redis CVE-2023-28425 with chatGPT as assistant
Intro
Windows Installer EOP (CVE-2023-21800) https://blog.doyensec.com//2023/03/21/windows-installer.html
Doyensec
Windows Installer EOP (CVE-2023-21800)
TL;DR: This blog post describes the details and methodology of our research targeting the Windows Installer (MSI) installation technology. If you’re only interested in the vulnerability itself, then jump right there
GoatRAT Attacks Automated Payment Systems https://labs.k7computing.com/index.php/goatrat-attacks-automated-payment-systems/
K7 Labs
GoatRAT Attacks Automated Payment Systems
Recently, we came across a detection in our telemetry report named “com.goatmw” which gained our attention. We decided to investigate […]
Pro-Russian hackers target elected US officials supporting Ukraine https://arstechnica.com/information-technology/2023/03/pro-russian-hackers-target-elected-us-officials-supporting-ukraine/
Ars Technica
Pro-Russian hackers target elected US officials supporting Ukraine
Group tracked since 2021 exploits unpatched Zimbra servers to hack email accounts.
👍1
Dridex malware, the banking trojan https://cybersecurity.att.com/blogs/security-essentials/dridex-malware-the-banking-trojan
AT&T Cybersecurity
Dridex malware, the banking trojan
The content of this post is solely the responsibility of the author. AT&T does not adopt or endorse any of the views, positions, or information provided by the author in this article. Introduction: Dridex, also known as Cridex or Bugat, is a banking Trojan…