Windows Installer EOP (CVE-2023-21800) https://blog.doyensec.com//2023/03/21/windows-installer.html
Doyensec
Windows Installer EOP (CVE-2023-21800)
TL;DR: This blog post describes the details and methodology of our research targeting the Windows Installer (MSI) installation technology. If you’re only interested in the vulnerability itself, then jump right there
GoatRAT Attacks Automated Payment Systems https://labs.k7computing.com/index.php/goatrat-attacks-automated-payment-systems/
K7 Labs
GoatRAT Attacks Automated Payment Systems
Recently, we came across a detection in our telemetry report named “com.goatmw” which gained our attention. We decided to investigate […]
Pro-Russian hackers target elected US officials supporting Ukraine https://arstechnica.com/information-technology/2023/03/pro-russian-hackers-target-elected-us-officials-supporting-ukraine/
Ars Technica
Pro-Russian hackers target elected US officials supporting Ukraine
Group tracked since 2021 exploits unpatched Zimbra servers to hack email accounts.
👍1
Dridex malware, the banking trojan https://cybersecurity.att.com/blogs/security-essentials/dridex-malware-the-banking-trojan
AT&T Cybersecurity
Dridex malware, the banking trojan
The content of this post is solely the responsibility of the author. AT&T does not adopt or endorse any of the views, positions, or information provided by the author in this article. Introduction: Dridex, also known as Cridex or Bugat, is a banking Trojan…
Windows Forensics: Examine Windows Files and Metadata https://belcyber.medium.com/windows-forensics-examine-windows-files-and-metadata-f8c3c43ea05a
Medium
Windows Forensics: (6–7 Examine Windows Files and Metadata)
The Windows forensics methodology comprises of 8 phases, and we have previously covered the initial five. If you wish to explore them…
👍1
How to use Steganography for attacks or to hide messages https://infosecwriteups.com/how-to-hide-messages-with-steganography-8b91c74b3594
Medium
How to hide messages with Steganography
Quick study of this wonderful technique
👍2
MacStealer malware: A growing threat to macOS users https://www.jamf.com/blog/macstealer-malware-macos-threat/
Jamf
Beware of MacStealer, a growing malware threat that affects macOS
The malware variant uses Telegram's communications protocol to hide its command and control (C2) processes while it exfiltrates sensitive data.
Multiple vulnerabilities in Aten PE8108 power distribution unit https://www.pentagrid.ch/en/blog/multiple-vulnerabilities-in-aten-PE8108-power-distribution-unit/
Pentagrid AG
Multiple vulnerabilities in Aten PE8108 power distribution unit
A Pentagrid security advisory about multiple vulnerabilities in the Aten PE8108 PDU remote power outlet control.
CAN Injection: keyless car theft https://kentindell.github.io/2023/04/03/can-injection/
Ken Tindell’s blog
CAN Injection: keyless car theft
This is a detective story about how a car was stolen - and how it uncovered an epidemic of high-tech car theft. It begins with a tweet. In April 2022, my friend Ian Tabor tweeted that vandals had been at his car, pulling apart the headlight and unplugging…
Rorschach – A New Sophisticated and Fast Ransomware https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/
Check Point Research
Rorschach – A New Sophisticated and Fast Ransomware - Check Point Research
Research by: Jiri Vinopal, Dennis Yarizadeh and Gil Gekker Key Findings: Introduction While responding to a ransomware case against a US-based company, the CPIRT recently came across a unique ransomware strain deployed using a signed component of a commercial…
👍1
Malicious ISO File Leads to Domain Wide Ransomware https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/
The DFIR Report
Malicious ISO File Leads to Domain Wide Ransomware - The DFIR Report
IcedID continues to deliver malspam emails to facilitate a compromise. This case covers the activity from a campaign in late September of 2022. Post exploitation activities detail some familiar and some new techniques and tooling, which led to domain wide…
A Guide to Reversing Shared Objects with Ghidra https://medium.com/@cy1337/a-guide-to-reversing-shared-objects-with-ghidra-cec83d5031e6
Medium
A Guide to Reversing Shared Objects with Ghidra
I’m excited to announce that I will be returning this year to the Black Hat USA 2023 conference in Las Vegas. As with previous years’…
Ironing out (the macOS) details of a Smooth Operator (Part II) https://objective-see.org/blog/blog_0x74.html
Objective-See
Ironing out (the macOS) details of a Smooth Operator (Part II)
Analyzing UpdateAgent, the 2nd-stage macOS payload of the 3CX supply chain attack
Hackers Exploit WinRAR SFX Archives to Install Backdoors Undetected https://socradar.io/hackers-exploit-winrar-sfx-archives-to-install-backdoors-undetected/
SOCRadar® Cyber Intelligence Inc.
Hackers Exploit WinRAR SFX Archives to Install Backdoors Undetected
Threat actors exploit WinRAR self-extracting (SFX) archives containing decoy files by adding malicious functionality to install backdoors in target
The (Possible) Return of 2easy and What It Means for the Fraud Ecosystem https://flashpoint.io/blog/2easy-fraud-ecosystem/
Flashpoint
The (Possible) Return of 2easy and What It Means for the Fraud Ecosystem
2easy is a Russian-and English-language illicit shop that sells logs as well as user information collected from browsers via stealer malware.
Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign https://www.microsoft.com/en-us/security/blog/2023/04/11/guidance-for-investigating-attacks-using-cve-2022-21894-the-blacklotus-campaign/
Microsoft News
Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaign
A guide to assess whether users have been targeted or compromised by threat actors exploiting CVE-2022-21894 via BlackLotus UEFI bootkit.
Microsoft Outlook CVE-2023-23397: Critical Privilege Escalation Vulnerability https://www.darkrelay.com/post/cve-2023-23397-critical-microsoft-outlook-privilege-escalation-vulnerability
DARKRELAY
CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
IntroductionOn the latest Patch Tuesday, Microsoft released 83 security fixes, one of which is the "CVE-2023-23397" vulnerability that affects all versions of the Outlook desktop app on Windows systems. However, this vulnerability does not impact the Outlook…
Security Frameworks Unsere Erfahrungen https://www.scip.ch/?labs.20230406
www.scip.ch
Unsere Erfahrungen mit Sicherheits-Frameworks
Security Frameworks sind für die Verwaltung der IT-Sicherheitslage unerlässlich. CIS-CSC V8 hat sich zu einem sehr wertvollen Instrument für den Beginn des Sicherheitsmanagements kleiner und mittlerer Unternehmen entwickelt.