New macOS vulnerability, Migraine, could bypass System Integrity Protection https://www.microsoft.com/en-us/security/blog/2023/05/30/new-macos-vulnerability-migraine-could-bypass-system-integrity-protection/
Microsoft News
New macOS vulnerability, Migraine, could bypass System Integrity Protection
A new vulnerability could allow an attacker with root access to bypass SIP in macOS and perform arbitrary operations on a device.
STARFACE: Authentication with Password Hash Possible https://www.redteam-pentesting.de/en/advisories/rt-sa-2022-004/-starface-authentication-with-password-hash-possible
www.redteam-pentesting.de
RedTeam Pentesting - STARFACE: Authentication with Password Hash Possible
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext passwords in an application’s…
Printerlogic multiple vulnerabilities https://seclists.org/fulldisclosure/2023/May/16
seclists.org
Full Disclosure: Printerlogic multiple vulnerabilities
Operation Triangulation: iOS devices targeted with previously unknown malware https://securelist.com/operation-triangulation/109842/
Supply Chain Risk from Gigabyte App Center Backdoor https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
Eclypsium | Supply Chain Security for the Modern Enterprise
Supply Chain Risk from Gigabyte App Center Backdoor
Eclypsium Research discovers that Gigabyte motherboards have an embedded backdoor in their firmware, which drops a Windows executable that can download and execute additional payloads insecurely. The backdoor affects gaming PCs and high-end computers.
NoirGate provides on-demand ephemeral anonymous shells secured by TOTP https://github.com/Shell-Company/Noirgate
GitHub
GitHub - Shell-Company/Noirgate: NoirGate provides on-demand ephemeral anonymous shells secured by TOTP
NoirGate provides on-demand ephemeral anonymous shells secured by TOTP - GitHub - Shell-Company/Noirgate: NoirGate provides on-demand ephemeral anonymous shells secured by TOTP
Restoring Dyld Memory Loading https://blog.xpnsec.com/restoring-dyld-memory-loading/
XPN Infosec Blog
@_xpn_ - Restoring Dyld Memory Loading
Up until recently, we've enjoyed in-memory loading of Mach-O bundles courtesy of dyld and its NSCreateObjectFileImageFromMemory/NSLinkModule API methods. And while these methods still exist today, there is a key difference.. memory modules are now persisted…
🔥2
Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices https://unit42.paloaltonetworks.com/mirai-variant-iz1h9/
Unit 42
Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices
We analyze Mirai variant IZ1H9, which targets IoT devices. Our overview includes campaigns observed, botnet configuration and vulnerabilities exploited.
Froxlor v2.0.6 Remote Command Execution (CVE-2023-0315) https://shells.systems/category/static-code-analysis/
🔥2
Python byte code used to avoid detection and load malware https://www.scmagazine.com/news/third-party-risk/python-byte-code-avoid-detection-load-malware
SC Media
Python byte code used to avoid detection and load malware
ReversingLabs researchers say the ability to execute malicious Python byte code files poses yet another supply chain risk.
👍1
ФСБ России вскрыта разведывательная акция американских спецслужб с использованием мобильных устройств фирмы Apple http://www.fsb.ru/fsb/press/message/single.htm!id=10439739@fsbMessage.html
🤡6😱4
Beyond the Veil of Surveillance: Private Sector Offensive Actors (PSOAs) https://socradar.io/beyond-the-veil-of-surveillance-private-sector-offensive-actors-psoas/
SOCRadar® Cyber Intelligence Inc.
Beyond the Veil of Surveillance: Private Sector Offensive Actors (PSOAs) - SOCRadar® Cyber Intelligence Inc.
Privacy and surveillance are two sides of a coin, and the conditions that have blurred the boundaries between them have also paved the way for the thriving of
👍1
RCE via LDAP truncation on hg.mozilla.org https://0day.click/recipe/pash/
0day.click
RCE via LDAP truncation on hg.mozilla.org
Given my interest in SCM and CI systems I was a little keen to see how this is done at Mozilla as part of their bug bounty program. Thanks to freddy I was granted Level 1 access to Mozilla’s SCM at hg.mozilla.org in late 2022. As Mozilla is a pretty transparent…
Tokenizer: Kernel Mode Driver for Elevating Process Privileges https://securityonline.info/tokenizer-kernel-mode-driver-for-elevating-process-privileges
Cybersecurity News
Tokenizer: Kernel Mode Driver for Elevating Process Privileges
Tokenizer is a kernel mode driver project that allows the replacement of a process token in EPROCESS with a system token
Using PANDA to search for F.L.I.R.T. signatures during process execution https://blog.nietaanraken.nl/posts/pandare-flirt/
Blog by Joren Vrancken
Using PANDA to search for F.L.I.R.T. signatures during process execution
When a malware analyst gets a new malware sample to analyze, one of the first questions they might have, is what functions are called during the execution of the sample. To solve this problem, we can use any old debugger to walk through the sample manually…
Understanding PE Bloat with Malcat https://squiblydoo.blog/2023/06/05/understanding-pe-bloat-with-malcat/
Squiblydoo.blog
Understanding PE Bloat with Malcat
This post is an introduction to the tool for others and demonstrates how the tool can be used to understand portable executables and bloated resources.
👍1
MOVEit Transfer Critical Vulnerability CVE-2023-34362 Rapid Response https://www.huntress.com/blog/moveit-transfer-critical-vulnerability-rapid-response
Huntress
MOVEit Transfer Critical Vulnerability CVE-2023-34362 | Huntress
Our team is tracking in-the-wild exploitation of a zero-day vulnerability against Progress' MOVEit Transfer web application that allows for escalated privileges and unauthorized access.
Rust Binary Analysis, Feature by Feature https://research.checkpoint.com/2023/rust-binary-analysis-feature-by-feature/
Check Point Research
Rust Binary Analysis, Feature by Feature - Check Point Research
Problem Statement You attempt to analyze a binary file compiled in the Rust programming language. You open the file in your favorite disassembler. Twenty minutes later you wish you had never been born. You’ve trained yourself to think like g++ and msvc: Here’s…
🔥1
CVE-2022-32902: Patch One Issue and Introduce Two https://jhftss.github.io/CVE-2022-32902-Patch-One-Issue-and-Introduce-Two/
jhftss.github.io
CVE-2022-32902: Patch One Issue and Introduce Two
A year ago, I discovered a TCC-bypass issue in the system daemon service named com.apple.fontmover. Three months later, Apple addressed it as CVE-2022-32902. After checking how Apple addressed the issue, I found two new issues introduced by patching the issue.…
Is Cloud Forensics just Log Analysis? Kind Of. https://www.cadosecurity.com/is-cloud-forensics-just-log-analysis-kind-of/
Cado Security | Cloud Forensics & Incident Response
Is Cloud Forensics just Log Analysis? Kind Of. - Cado Security | Cloud Forensics & Incident Response
Is Cloud Forensics just Log Analysis? This blog addresses this question to help clarify the rapidly emerging field of cloud forensics.