Kernel Object Names Lifetime https://scorpiosoftware.net/2023/05/15/kernel-object-names-lifetime/
Pavel Yosifovich
Kernel Object Names Lifetime
Much of the Windows kernel functionality is exposed via kernel objects. Processes, threads, events, desktops, semaphores, and many other object types exist. Some object types can have string-based …
CS:GO: From Zero to 0-day https://neodyme.io/blog/csgo_from_zero_to_0day/
neodyme.io
CS:GO: From Zero to 0-day
We identified three independent remote code execution (RCE) vulnerabilities in the popular Counter-Strike: Global Offensive game. Each vulnerability can be triggered when the game client connects to our malicious python CS:GO server. This post details our…
You’ve been kept in the dark (web): exposing Qilin’s RaaS program https://www.group-ib.com/blog/qilin-ransomware/?utm_source=twitter&utm_campaign=qilin-ransomware&utm_medium=social
Group-IB
The Qilin Ransomware: Analysis and Protection Strategies
Discover how Qilin ransomware threatens cybersecurity. Learn prevention tips and stay protected. ✓ Read more now and safeguard your data!
2023 ransomware insights https://assets.barracuda.com/assets/docs/dms/2023-Ransomware-insights-report.pdf
Linux IPv6 "Route of Death" 0day https://www.interruptlabs.co.uk/articles/linux-ipv6-route-of-death
Quasar Rat Analysis - Identification of 64 Quasar Servers Using Shodan and Censys https://embee-research.ghost.io/hunting-quasar-rat-shodan/
Embee Research
How To Track Quasar Rat C2 Infrastructure Using TLS Certificates
Extraction of Quasar C2 configuration via Dnspy, and using this information to pivot to additional servers utilising Shodan and Censys.
rax30 patch diff analysis & nday exploit for zdi-23-496 https://blog.coffinsec.com/nday/2023/05/12/rax30-patchdiff-nday-analysis.html
hyprblog
RAX30 Patch Diff Analysis & Nday Exploit for ZDI-23-496
patch diff analysis of the latest patches for the netgear rax30 and an nday exploit for one of them (ZDI-23-496)
The Race to Patch: Attackers Leverage Sample Exploit Code in WordPress Plug-in https://www.akamai.com/blog/security-research/attackers-leverage-sample-exploit-wordpress-plugin
Akamai
The Race to Patch: Attackers Leverage Sample Exploit Code in WordPress Plug-in | Akamai
The time for attackers to respond to known vulnerabilities is shrinking. See an example of an attacker using sample code.
CVE-2023-26818 - Bypass TCC with Telegram in macOS https://danrevah.github.io/2023/05/15/CVE-2023-26818-Bypass-TCC-with-Telegram/
Dan Revah’s Blog
CVE-2023-26818 - Bypassing TCC with Telegram in macOS
Preface
SID filter as security boundary between domains? (Part 1) - Kerberos authentication explained [7 parts, this is the first one] https://improsec.com/tech-blog/o83i79jgzk65bbwn1fwib1ela0rl2d
itm8.dk
Skal vi skabe nutidens og fremtidens IT sammen? itm8
Hvad er en itm8? Vi er præcis, hvad navnet siger: Din m8* (*mate), der er ekspert i IT. Vi er din partner til 360 graders IT.
Triple Threat: Breaking Teltonika Routers Three Ways https://claroty.com/team82/research/triple-threat-breaking-teltonika-routers-three-ways
Claroty
Triple Threat: Breaking Teltonika Routers Three Ways
Discover the vulnerabilities of Teltonika routers in this groundbreaking research by Team82. Explore three effective methods used to breach the security of these routers, providing valuable insights for network administrators and cybersecurity professionals.…
Hardware Hacking 101: Identifying and Dumping eMMC Flash https://www.riverloopsecurity.com/blog/2020/03/hw-101-emmc/
River Loop Security
Hardware Hacking 101: Identifying and Dumping eMMC Flash
Cybersecurity solutions for the whole lifecycle of IoT and embedded systems.
Avast Anti-Virus privileged arbitrary file create on virus restore (CVE-2023-1586) https://the-deniss.github.io/posts/avast-privileged-arbitrary-file-create-on-restore/
the-deniss.github.io
Avast Anti-Virus privileged arbitrary file create on virus restore (CVE-2023-1586)
And today I’m sharing the report describing the vulnerability (CVE-2023-1586) in Avast file restore functionality and exploitation of this vulnerability to execute arbitrary code in the “NT AUTHORITY\SYSTEM” context
Exploiting Windows’ vulnerabilities with Hyper-V: A Hacker’s swiss army knife https://reversing.info/posts/hyperdeceit/
Xyrem Engineering
Exploiting Windows' vulnerabilities with Hyper-V: A Hacker's swiss army knife
In this blog, we explore how to leverage the implementation of the Hyper-V virtualization technology to exploit and attack Windows systems and learn what measures should be taken to mitigate this vulnerability. Join us as we explore the world of Windows hacking…
👍1
Testing a new encrypted messaging app's extraordinary claims https://crnkovic.dev/testing-converso/
crnkovic.dev
Testing a new encrypted messaging app's extraordinary claims
How I breached a nonexistent database and found every private key in a 'state-of-the-art' encrypted messenger.
Sticky notes for pentesting. https://exploit-notes.hdks.org/
‘FriendlyName’ Buffer Overflow Vulnerability in Wemo Smart Plug V2 https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/
Sternum IoT
‘FriendlyName’ Buffer Overflow Vulnerability in Wemo Smart Plug V2 | Sternum IoT
Manufacturer chooses not to patch the Sternum-identified buffer overflow vulnerability (CVE-2023-27217) in the Wemo Mini Smart Plug V2.
👍3
Finding the Footprints of Hidden Shellcode https://i.blackhat.com/Asia-23/AS-23-Uhlmann-You-Can-Run-But-You-Cant-Hide.pdf
👍1
New Strain of Sotdas Malware Discovered https://blog.qualys.com/vulnerabilities-threat-research/2023/05/17/new-strain-of-sotdas-malware-discovered
Qualys
New Strain of Sotdas Malware Discovered | Qualys
There are numerous malicious codes that are currently active on smart devices, such as Ddosf, Dofloo, Gafgyt, MrBlack, Persirai, Sotdas, Tsunami, Triddy, Mirai, Moose, and Satori, among others.
Black Basta: Anatomy of the Attack https://blogs.infoblox.com/cyber-threat-intelligence/black-basta-anatomy-of-the-attack/
Infoblox Blog
Black Basta: Anatomy of the Attack
Black Basta, is an active cybercriminal group targeting Europe and English-speaking countries. Uncover their tactics, including double extortion, and delve into their recent attack on ABB in this article.