Cloud-Based Malware Delivery: The Evolution of GuLoader https://research.checkpoint.com/2023/cloud-based-malware-delivery-the-evolution-of-guloader/
Check Point Research
Cloud-Based Malware Delivery: The Evolution of GuLoader - Check Point Research
Key takeaways Introduction Antivirus products are constantly evolving to become more sophisticated and better equipped to handle complex threats. As a result, malware developers strive to create new threats that can bypass the defenses of antivirus products.…
Future Exploitation Vector: File Extensions as Top-Level Domains https://www.trendmicro.com/en_us/research/23/e/future-exploitation-vector-file-extensions-as-top-level-domains.html
Trend Micro
Future Exploitation Vector File Extensions as Top Level Domains
In this blog entry, we will examine the security risks related to file extension-related Top-Level Domains (TLDs) while also providing best practices and recommendations on how both individual users and organizations can protect themselves from these hazards.
Future Exploitation Vector: File Extensions as Top-Level Domains https://www.trendmicro.com/en_us/research/23/e/future-exploitation-vector-file-extensions-as-top-level-domains.html
Trend Micro
Future Exploitation Vector File Extensions as Top Level Domains
In this blog entry, we will examine the security risks related to file extension-related Top-Level Domains (TLDs) while also providing best practices and recommendations on how both individual users and organizations can protect themselves from these hazards.
Barracuda identified a vulnerability (CVE-2023-2868) in our Email Security Gateway appliance (ESG) https://status.barracuda.com/incidents/34kx82j5n4q9
Barracuda
Barracuda identified a vulnerability (CVE-2023-2868) in our Email Security Gateway appliance (ESG) on May 19, 2023.
Barracuda Networks's Status Page - Barracuda identified a vulnerability (CVE-2023-2868) in our Email Security Gateway appliance (ESG) on May 19, 2023..
Rooting with root cause: finding a variant of a Project Zero bug https://github.blog/2023-05-25-rooting-with-root-cause-finding-a-variant-of-a-project-zero-bug/
The GitHub Blog
Rooting with root cause: finding a variant of a Project Zero bug
In this blog, I’ll look at CVE-2022-46395, a variant of CVE-2022-36449 (Project Zero issue 2327), and use it to gain arbitrary kernel code execution and root privileges from the untrusted app domain on an Android phone that uses the Arm Mali GPU. I’ll also…
Debugging the Windows Kernel and Undocumented Structures https://twitter.com/Steph3nSims/status/1662156705457909760?s=20
Nice series here >> Hunting for Persistence in Linux (Part 1): Auditd, Sysmon, Osquery (and Webshells) https://pberba.github.io/security/2021/11/22/linux-threat-hunting-for-persistence-sysmon-auditd-webshell/ (and good summary map in https://pberba.github.io/assets/posts/common/20220201-linux-persistence.pdf)
pepe berba
Hunting for Persistence in Linux (Part 1): Auditd, Sysmon, Osquery (and Webshells)
An introduction to monitoring and logging in linux to look for persistence.
🔥1
Man-in-the-Middle Attacks without Rogue AP:
When WPAs Meet ICMP Redirects https://csis.gmu.edu/ksun/publications/WiFi_Interception_SP23.pdf
When WPAs Meet ICMP Redirects https://csis.gmu.edu/ksun/publications/WiFi_Interception_SP23.pdf
Threat Brief: Attacks on Critical Infrastructure Attributed to Insidious Taurus (aka Volt Typhoon) https://unit42.paloaltonetworks.com/volt-typhoon-threat-brief/
Unit 42
Threat Brief: Attacks on Critical Infrastructure Attributed to Insidious Taurus (Volt Typhoon)
Insidious Taurus, aka Volt Typhoon, is a nation-state TA attributed to the People's Republic of China. We provide an overview of their current activity and mitigations recommendations.
Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spyware https://blog.talosintelligence.com/mercenary-intellexa-predator/
Cisco Talos
Mercenary mayhem: A technical analysis of Intellexa's PREDATOR spyware
Commercial spyware use is on the rise, with actors leveraging these sophisticated tools to conduct surveillance operations against a growing number of targets. Cisco Talos has new details of a commercial spyware product sold by the spyware firm Intellexa…
🤔1
GobRAT malware written in Go language targeting Linux routers https://blogs.jpcert.or.jp/en/2023/05/gobrat.html
JPCERT/CC Eyes
GobRAT malware written in Go language targeting Linux routers - JPCERT/CC Eyes
JPCERT/CC has confirmed attacks that infected routers in Japan with malware around February 2023. This blog article explains the details of the attack confirmed by JPCERT/CC and GobRAT malware, which was used in the attack. ### Attack flow up to...
WinDiff: open-source web-based tool to browse and compare symbol and type information of Microsoft Windows binaries across different versions of the OS https://windiff.vercel.app/ GitHub: https://github.com/ergrelet/windiff
GitHub
GitHub - ergrelet/windiff: Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across…
Tool that allows comparing symbol, type and syscall information of Microsoft Windows binaries across different versions of the OS, using a Web UI and/or LLMs. - ergrelet/windiff
Meterpreter vs Modern EDR(s) https://redops.at/en/blog/meterpreter-vs-modern-edrs-in-2023
RedOps - English
Meterpreter vs Modern EDR(s) - RedOps
👍1
Don't Click That ZIP File! Phishers Weaponizing .ZIP Domains to Trick Victims https://thehackernews.com/2023/05/dont-click-that-zip-file-phishers.html
Fortinet Series 1 — Analysis of CVE-2022–40684 https://medium.com/@INTfinity/fortinet-series-1-analysis-of-cve-2022-40684-88870994e6e0
Medium
Fortinet Series 1 — Analysis of CVE-2022–40684
Introduction
FortiOS, FortiProxy, and FortiSwitchManager Authentication Bypass Technical Deep Dive (CVE-2022-40684) https://www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/
Horizon3.ai
FortiOS, FortiProxy, and FortiSwitchManager Authentication Bypass Technical Deep Dive (CVE-2022-40684)
Fortinet recently patched a critical authentication bypass vulnerability that gives an attacker the ability to login as an administrator,
Fortigate - Authentication Bypass Lead to Full Device Takeover https://labs.hakaioffsec.com/fortigate-authentication-bypass/
Hakai Offensive Security
Fortigate - Authentication Bypass Lead to Full Device Takeover
1Day vulnerability research by Hakai - Research Team
This post is about the journey to create a Proof-of-concept about CVE-2022-40684, this vulnerability has been assigned by Fortinet as an authentication bypass using an alternate path or channel vulnerability…
This post is about the journey to create a Proof-of-concept about CVE-2022-40684, this vulnerability has been assigned by Fortinet as an authentication bypass using an alternate path or channel vulnerability…
COMPSCI 390R
Reverse Engineering & Vulnerability Analysis (lectures and other material) https://pwn.umasscybersec.org/
Reverse Engineering & Vulnerability Analysis (lectures and other material) https://pwn.umasscybersec.org/