CVE-2022-27666: My file your memory https://albocoder.github.io/exploit/2023/03/13/KernelFileExploit.html
Erin Avllazagaj
CVE-2022-27666: My file your memory
Ironing out (the macOS) details of a Smooth Operator (Part I) https://objective-see.org/blog/blog_0x73.html
Objective-See
Ironing out (the macOS) details of a Smooth Operator (Part I)
The 3CX supply chain attack, gives us an opportunity to analyze a trojanized macOS application
Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife https://www.sentinelone.com/labs/dissecting-alienfox-the-cloud-spammers-swiss-army-knife/
SentinelOne
Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife
A sophisticated new toolset is being used to harvest credentials from multiple cloud service providers, including AWS SES and Microsoft Office 365.
Lord of the SID: How to Add the objectSID Attribute to a Certificate Manually https://elkement.blog/2023/03/30/lord-of-the-sid-how-to-add-the-objectsid-attribute-to-a-certificate-manually/
elkemental Force
Lord of the SID: How to Add the objectSID Attribute to a Certificate Manually
In May 2022 Microsoft has fixed a vulnerability related to certificate logon to Active Directory. As a non-privileged user you could escalate privileges by impersonating a Domain Controller, as you…
👍1
Technical Analysis of Xloader’s Code Obfuscation in Version 4.3 https://www.zscaler.com/blogs/security-research/technical-analysis-xloaders-code-obfuscation-version-43
Zscaler
Home | Zscaler
Zscaler, the zero trust cybersecurity leader, accelerates digital transformation with fast, secure connections between users, devices and apps over any network.
❤2
X-Force Prevents Zero Day from Going Anywhere https://securityintelligence.com/posts/x-force-prevents-zero-day-from-going-anywhere/
Security Intelligence
X-Force Prevents Zero Day from Going Anywhere
Dive into the investigation of a zero-day attack that took advantage of a vulnerability in Forta’s file-transfer tool, GoAnyWhere. Explore the research from IBM X-Force experts.
Meet the FSB contractor: 0Day Technologies https://clement-briens.com/2023/04/01/meet-the-fsb-contractor-0day-technologies/
❤1
Spyware vendors use 0-days and n-days against popular platforms https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/
Google
Spyware vendors use 0-days and n-days against popular platforms
Google’s Threat Analysis Group (TAG) tracks actors involved in information operations (IO), government backed attacks and financially motivated abuse. For years, TAG has…
RISC-V: Why The ISA Battles Aren’t Over Yet https://hackaday.com/2019/11/12/risc-v-why-the-isa-battles-arent-over-yet/
Hackaday
RISC-V: Why The ISA Battles Aren’t Over Yet
A computer processor uses a so-called Instruction Set Architecture to talk with the world outside of its own circuitry. This ISA consists of a number of instructions, which essentially define the f…
Magniber ransomware analysis: Tiny Tracer in action https://hshrzd.wordpress.com/2023/03/30/magniber-ransomware-analysis/
hasherezade's 1001 nights
Magniber ransomware analysis: Tiny Tracer in action
Intro Magniber is a ransomware that was initially targeting South Korea. My first report on this malware was written for Malwarebytes in 2017 (here). Since then, the ransomware was completely rewri…
Dissecting redis CVE-2023-28425 with chatGPT as assistant https://tin-z.github.io/redis/cve/chatgpt/2023/04/02/redis-cve2023.html
Lambda driver blog
Dissecting redis CVE-2023-28425 with chatGPT as assistant
Intro
Windows Installer EOP (CVE-2023-21800) https://blog.doyensec.com//2023/03/21/windows-installer.html
Doyensec
Windows Installer EOP (CVE-2023-21800)
TL;DR: This blog post describes the details and methodology of our research targeting the Windows Installer (MSI) installation technology. If you’re only interested in the vulnerability itself, then jump right there
GoatRAT Attacks Automated Payment Systems https://labs.k7computing.com/index.php/goatrat-attacks-automated-payment-systems/
K7 Labs
GoatRAT Attacks Automated Payment Systems
Recently, we came across a detection in our telemetry report named “com.goatmw” which gained our attention. We decided to investigate […]
Pro-Russian hackers target elected US officials supporting Ukraine https://arstechnica.com/information-technology/2023/03/pro-russian-hackers-target-elected-us-officials-supporting-ukraine/
Ars Technica
Pro-Russian hackers target elected US officials supporting Ukraine
Group tracked since 2021 exploits unpatched Zimbra servers to hack email accounts.
👍1
Dridex malware, the banking trojan https://cybersecurity.att.com/blogs/security-essentials/dridex-malware-the-banking-trojan
AT&T Cybersecurity
Dridex malware, the banking trojan
The content of this post is solely the responsibility of the author. AT&T does not adopt or endorse any of the views, positions, or information provided by the author in this article. Introduction: Dridex, also known as Cridex or Bugat, is a banking Trojan…
Windows Forensics: Examine Windows Files and Metadata https://belcyber.medium.com/windows-forensics-examine-windows-files-and-metadata-f8c3c43ea05a
Medium
Windows Forensics: (6–7 Examine Windows Files and Metadata)
The Windows forensics methodology comprises of 8 phases, and we have previously covered the initial five. If you wish to explore them…
👍1
How to use Steganography for attacks or to hide messages https://infosecwriteups.com/how-to-hide-messages-with-steganography-8b91c74b3594
Medium
How to hide messages with Steganography
Quick study of this wonderful technique
👍2
MacStealer malware: A growing threat to macOS users https://www.jamf.com/blog/macstealer-malware-macos-threat/
Jamf
Beware of MacStealer, a growing malware threat that affects macOS
The malware variant uses Telegram's communications protocol to hide its command and control (C2) processes while it exfiltrates sensitive data.