Technical analysis of the Genesis Market https://sector7.computest.nl/post/2023-04-technical-analysis-genesis-market/
DEFION Security
Technical analysis of the Genesis Market | DEFION Research Labs
GHSL-2023-023: Type confusion in the Chrome renderer - CVE-2023-1214 https://securitylab.github.com/advisories/GHSL-2023-023_Chromium/
GitHub Security Lab
GHSL-2023-023: Type confusion in the Chrome renderer - CVE-2023-1214
Type confusion in the Chrome renderer reachable from a malicious website.
AI, ChatGPT and Identity Security’s Critical Human Element https://www.cyberark.com/resources/blog/ai-chatgpt-and-identity-securitys-critical-human-element
Cyberark
AI, ChatGPT and Identity Security’s Critical Human Element
In 1999, a far-fetched movie about a dystopia run by intelligent machines captured our imaginations (and to this day, remains my favorite film). Twenty-four years later, the line between fact and...
👍1
Escaping Adobe Sandbox: Exploiting an Integer Overflow in Microsoft Windows Crypto Provider https://blog.exodusintel.com/2023/04/06/escaping-adobe-sandbox-exploiting-an-integer-overflow-in-microsoft-windows/
Exodus Intelligence
Escaping Adobe Sandbox: Exploiting an Integer Overflow in Microsoft Windows Crypto Provider - Exodus Intelligence
By Michele Campa Overview We describe a method to exploit a Windows Nday vulnerability to escape the Adobe sandbox. This vulnerability is assigned CVE-2021-31199 and it is present in multiple Windows 10 versions. The vulnerability is an out-of-bounds write…
Hacking Brightway scooters: A case study https://robocoffee.de/?p=436
Obfu[DE]scate: de-obfuscation tool for Android APKs that uses fuzzy comparison logic to identify similarities between functions https://github.com/user1342/Obfu-DE-Scate
GitHub
GitHub - user1342/Obfu-DE-Scate: Obfu[DE]scate is a de-obfuscation tool for Android APKs that uses fuzzy comparison logic to identify…
Obfu[DE]scate is a de-obfuscation tool for Android APKs that uses fuzzy comparison logic to identify similarities between functions, even if they have been renamed as part of obfuscation. It compar...
OrBit: advanced analysis of a Linux dedicated malware https://www.stormshield.com/news/orbit-analysis-of-a-linux-dedicated-malware/
Stormshield
OrBit malware: analysis of a threat to Linux | Stormshield
Stealer, backdoor, executable, dropper and library: a complete analysis of the OrBit malware with Stormshield's CTI team.
Logging strategies for security incident response https://aws.amazon.com/blogs/security/logging-strategies-for-security-incident-response/
Amazon
Logging strategies for security incident response | Amazon Web Services
Effective security incident response depends on adequate logging, as described in the AWS Security Incident Response Guide. If you have the proper logs and the ability to query them, you can respond more rapidly and effectively to security events. If a security…
Binarly Unveils Next-Gen Firmware Protection Transparency Platform, Revolutionizing Device Supply Chain Security https://www.businesswire.com/news/home/20230411005485/en/Binarly-Unveils-Next-Gen-Firmware-Protection-Transparency-Platform-Revolutionizing-Device-Supply-Chain-Security
BusinessWire
Binarly Unveils Next-Gen Firmware Protection Transparency Platform, Revolutionizing Device Supply Chain Security
Binarly today announced the general release of the Binarly Transparency Platform, delivering unprecedented transparency for device supply chains enabl
Shell in the Ghost: Ghostscript CVE-2023-28879 writeup https://offsec.almond.consulting/ghostscript-cve-2023-28879.html
Heads up! Xdr33, A Variant Of CIA’s HIVE Attack Kit Emerges https://blog.netlab.360.com/headsup_xdr33_variant_of_ciahive_emeerges/
360 Netlab Blog - Network Security Research Lab at 360
Heads up! Xdr33, A Variant Of CIA’s HIVE Attack Kit Emerges
Overview
On Oct 21, 2022, 360Netlab's honeypot system captured a suspicious ELF file ee07a74d12c0bb3594965b51d0e45b6f, which propagated via F5 vulnerability with zero VT detection, our system observces that it communicates with IP 45.9.150.144 using SSL…
On Oct 21, 2022, 360Netlab's honeypot system captured a suspicious ELF file ee07a74d12c0bb3594965b51d0e45b6f, which propagated via F5 vulnerability with zero VT detection, our system observces that it communicates with IP 45.9.150.144 using SSL…
Stepping Insyde System Management Mode https://research.nccgroup.com/2023/04/11/stepping-insyde-system-management-mode/
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
x64dbg XFG Marker Plugin: An x64dbg plugin which marks XFG call signatures as data https://github.com/m417z/x64dbg-xfg-marker
GitHub
GitHub - m417z/x64dbg-xfg-marker: An x64dbg plugin which marks XFG call signatures as data
An x64dbg plugin which marks XFG call signatures as data - m417z/x64dbg-xfg-marker
QueueJumper: Critical Unauthenticated RCE Vulnerability in MSMQ Service https://research.checkpoint.com/2023/queuejumper-critical-unauthorized-rce-vulnerability-in-msmq-service/
Check Point Research
QueueJumper: Critical Unauthorized RCE Vulnerability in MSMQ Service
Check Point Research recently discovered three vulnerabilities in the "Microsoft Message Queuing" service, commonly known as MSMQ. These vulnerabilities were disclosed to Microsoft and patched in the April Patch Tuesday update. The most severe of these, dubbed…
Nokoyawa ransomware attacks with Windows zero-day https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/
Securelist
Nokoyawa ransomware attacks with Windows zero-day
In February 2023, we found a zero-day exploit, supporting different versions and builds of Windows, including Windows 11. This particular zero-day was used by a sophisticated cybercrime group that carries out ransomware attacks.
SecurePwn Part 2: Leaking Remote Memory Contents (CVE-2023-22897) https://www.rcesecurity.com/2023/04/securepwn-part-2-leaking-remote-memory-contents-cve-2023-22897/
Pretalx Vulnerabilities: How to get accepted at every conference https://www.sonarsource.com/blog/pretalx-vulnerabilities-how-to-get-accepted-at-every-conference/
Sonarsource
Pretalx Vulnerabilities: How to get accepted at every conference
We recently discovered two vulnerabilities in pretalx and found a generic technique to gain code execution from a file write.
Finding Something New About CVE-2022-1388 https://vulncheck.com/blog/new-cve-2022-1388
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.