Nokoyawa ransomware attacks with Windows zero-day https://securelist.com/nokoyawa-ransomware-attacks-with-windows-zero-day/109483/
Securelist
Nokoyawa ransomware attacks with Windows zero-day
In February 2023, we found a zero-day exploit, supporting different versions and builds of Windows, including Windows 11. This particular zero-day was used by a sophisticated cybercrime group that carries out ransomware attacks.
SecurePwn Part 2: Leaking Remote Memory Contents (CVE-2023-22897) https://www.rcesecurity.com/2023/04/securepwn-part-2-leaking-remote-memory-contents-cve-2023-22897/
Pretalx Vulnerabilities: How to get accepted at every conference https://www.sonarsource.com/blog/pretalx-vulnerabilities-how-to-get-accepted-at-every-conference/
Sonarsource
Pretalx Vulnerabilities: How to get accepted at every conference
We recently discovered two vulnerabilities in pretalx and found a generic technique to gain code execution from a file write.
Finding Something New About CVE-2022-1388 https://vulncheck.com/blog/new-cve-2022-1388
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Bypassing Windows Defender (10 Ways) https://www.fo-sec.com/articles/10-defender-bypass-methods
👍1
Remote Code Execution Vulnerability in Google They Are Not Willing To Fix https://giraffesecurity.dev/posts/google-remote-code-execution/
IPFS-tiny: attempting to take IPFS to Space https://libre.space/2023/04/12/ipfs-tiny/
Libre Space Foundation
IPFS-tiny: attempting to take IPFS to Space - Libre Space Foundation
IPFS-tiny attempts to take IPFS to space. It is an attempt made by Libre Space Foundation to make IPFS truly InterPlanetary.
nice repository » Gather and update all available and newest CVEs with their PoC https://github.com/trickest/cve
GitHub
GitHub - trickest/cve: Gather and update all available and newest CVEs with their PoC.
Gather and update all available and newest CVEs with their PoC. - trickest/cve
CVE-2019-8372: Local Privilege Elevation in LG Kernel Driver https://jackson_t.gitlab.io/lg-driver-lpe.html
How to Unpack Protected Android APK with Frida https://www.youtube.com/watch?v=PLX8_z0EmGw
YouTube
How to Unpack Protected Android APK with Frida
#androidpentest #dexdump #frida #apkunpacking #memdump
In this video we unpacked an APK file named AntiSplit-G2. All the classes in this application are protected using some kind of protector and the classes gets extracted into the memory as a de file by…
In this video we unpacked an APK file named AntiSplit-G2. All the classes in this application are protected using some kind of protector and the classes gets extracted into the memory as a de file by…
Windows LAPS - New Group Policy Settings https://www.kaidojarvemets.com/windows-laps-new-group-policy-settings/
Kaido Järvemets - Fuelled By Passion. Driven by Tech.
Windows LAPS – New Group Policy Settings - Kaido Järvemets
Explore the new Group Policy settings for Windows LAPS, providing IT admins with increased control over local administrator account passwords.
[Responsible Disclosure] How we could have deleted any Linkedin post https://www.pingsafe.com/blog/linkedin-vulnerability-delete-any-post
PingSafe
PingSafe
SentinelOne
Cloud
Protecting your cloud workloads from malicious attacks is critical to keep your business up and running. The Singularity Cloud Workload Security is a complete runtime protection solution for multi-cloud workloads that offers comprehensive security controls…
A Practical, AI-Generated Phishing PoC With ChatGPT https://curtbraz.medium.com/a-practical-ai-generated-phishing-poc-f81d3c3da76b
Medium
A Practical, AI-Generated Phishing PoC With ChatGPT
Intro
Memory corruption in JCRE: An unpatchable HSM may swallow your private key https://hardenedvault.net/blog/2023-04-18-java-card-runtime-memory-corruption/
hardenedvault.net
Memory corruption in JCRE: An unpatchable HSM may swallow your private key
Background The key has always been a core target of security protection.
Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2 https://www.cyberark.com/resources/threat-research-blog/breaking-docker-named-pipes-systematically-docker-desktop-privilege-escalation-part-2
Cyberark
Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2
In the previous blog post, we described how the Docker research started and showed how we could gain a full privilege escalation through a vulnerability in Docker Desktop. In this follow-up blog...
Threat Actors Rapidly Adopt Web3 IPFS Technology https://unit42.paloaltonetworks.com/ipfs-used-maliciously/
Unit 42
Threat Actors Rapidly Adopt Web3 IPFS Technology
Web3 technologies are seeing widespread adoption — including by TAs. We discuss Web3 technology InterPlanetary File System (IPFS), and malicious use of it.
👍1
APT28 Attacks on Cisco Routers: What We Know So Far https://www.securityengineering.dev/apt28-cisco-routers-vulnerability-april-2023/
Security Engineering Notebook
APT28 Attacks on Cisco Routers: What We Know So Far
Russian cyber-attack targets Cisco devices. Read on for the details and suggested mitigations.