Fuzzing Android Native libraries with libFuzzer + QEMU 🦥 https://fuzzing.science/blog/Fuzzing-Android-Native-libraries-with-libFuzzer-Qemu
SSD Advisory – Roundcube markasjunk RCE https://ssd-disclosure.com/ssd-advisory-roundcube-markasjunk-rce/
SSD Secure Disclosure
SSD Advisory - Roundcube markasjunk RCE - SSD Secure Disclosure
Summary A vulnerability in Roundcube’s markasjunk plugin allows attackers that send a specially crafted identity email address to cause the plugin to execute arbitrary code. Credit An independent security researcher, Selim Enes Karaduman, working with SSD…
How to Create F.L.I.R.T Signature Using Yara Rules for Static Analysis of ELF Malware https://blogs.jpcert.or.jp/en/2023/06/autoyara4flirt.html
JPCERT/CC Eyes
How to Create F.L.I.R.T Signature Using Yara Rules for Static Analysis of ELF Malware - JPCERT/CC Eyes
It has been observed that ELF malware removes symbol information during its build. This creates extra work in malware analysis to identify each function name because you do not know them. In addition, in IDA, an analysis tool, existing F.L.I.R.T...
OPC UA Deep Dive (Part 3): Exploring the OPC UA Protocol https://claroty.com/team82/research/opc-ua-deep-dive-part-3-exploring-the-opc-ua-protocol
Claroty
OPC UA Deep Dive (Part 3): Exploring the OPC UA Protocol
Explore the intricacies of the OPC UA protocol in Part 3 of Team82's Deep Dive series. Understand the protocol's layers, messaging types, security features, and more in this comprehensive guide to OPC UA for unified OT communication.
Abusing undocumented features to spoof PE section headers https://secret.club/2023/06/05/spoof-pe-sections.html
secret club
Abusing undocumented features to spoof PE section headers
Introduction Some time ago, I accidentally came across some interesting behaviour in PE files while debugging an unrelated project. I noticed that setting the SectionAlignment value in the NT header to a value lower than the page size (4096) resulted in significant…
🔥1
Process Herpaderping https://jxy-s.github.io/herpaderping/
herpaderping
Process Herpaderping
Detection Evasion Exploit
👍1
Incident Response in a Microsoft cloud environment https://m365internals.com/2021/04/17/incident-response-in-a-microsoft-cloud-environment/
Microsoft 365 Security
Incident Response in a Microsoft cloud environment
Microsoft Detection and Response (DART) team recently shared a PowerShell module, that they are using in their IR engagements, so I thought it would be great to blog about it. I’ve previously…
Breaking TikTok: Our Journey to Finding an Account Takeover Vulnerability https://medium.com/@mrhavit/breaking-tiktok-our-journey-to-finding-an-account-takeover-vulnerability-b0646aba1c4b
Medium
Breaking TikTok: Our Journey to Finding an Account Takeover Vulnerability
Hello, fellow security researchers and bug bounty hunters!
No Alloc, No Problem: Leveraging Program Entry Points for Process Injection https://bohops.com/2023/06/09/no-alloc-no-problem-leveraging-program-entry-points-for-process-injection/
bohops
No Alloc, No Problem: Leveraging Program Entry Points for Process Injection
Introduction Process Injection is a popular technique used by Red Teams and threat actors for defense evasion, privilege escalation, and other interesting use cases. At the time of this publishing,…
🔥1
Windows Memory Dump Analysis With Volatility https://digitalinvestigator.blogspot.com/2022/07/windows-memory-dump-analysis-with.html
Digital Investigator
Windows Memory Dump Analysis With Volatility
These volatility modules parse these structures and substructures within them and presents the examiner a beautiful tabular view for analysis
Detecting and mitigating a multi-stage AiTM phishing and BEC campaign https://www.microsoft.com/en-us/security/blog/2023/06/08/detecting-and-mitigating-a-multi-stage-aitm-phishing-and-bec-campaign/
Microsoft News
Detecting and mitigating a multi-stage AiTM phishing and BEC campaign
A multi-stage adversary-in-the-middle (AiTM) and business email compromise (BEC) attack targets banking and financial services organizations.
Two Factor Authentication Apps: Mistakes To Malware https://hackaday.com/2023/05/17/two-factor-authentication-apps-mistakes-to-malware/
Hackaday
Two Factor Authentication Apps: Mistakes To Malware
Everyone in security will tell you need two-factor authentication (2FA), and we agree. End of article? Nope. The devil, as always with security, is in the details. Case in point: in the last few we…
The REST API Handbook – How to Build, Test, Consume, and Document REST APIs https://www.freecodecamp.org/news/build-consume-and-document-a-rest-api/
freeCodeCamp.org
The REST API Handbook – How to Build, Test, Consume, and Document REST APIs
Hi everyone! In this tutorial we're going to take a deep dive into REST APIs. I recently wrote this article where I explained the main differences between common API types nowadays. And this tutorial aims to show you an example of how you can fully i...
ITG10 Likely Targeting South Korean Entities of Interest to the Democratic People’s Republic of Korea (DPRK) https://securityintelligence.com/posts/itg10-targeting-south-korean-entities/
Security Intelligence
ITG10 Likely Targeting South Korean Entities of Interest to the Democratic People’s Republic of Korea (DPRK)
Cybercriminal group ITG10 is likely targeting South Korean government, universities, think tanks, and dissidents. IBM Security X-Force shares the analysis.
How is Threat Intelligence Used to Monitor Criminal Activity on the Dark Web? https://socradar.io/how-is-threat-intelligence-used-to-monitor-criminal-activity-on-the-dark-web/
SOCRadar® Cyber Intelligence Inc.
How is Threat Intelligence Used to Monitor Criminal Activity on the Dark Web?
The dark web is a part of the Internet that differs from the regular Internet as it is a network that offers anonymity and privacy. Because of its structure,
Meet the Finalists for the 2023 Pwnie Awards https://www.darkreading.com/edge/meet-the-finalists-for-the-2023-pwnie-awards
Dark Reading
Meet the Finalists for the 2023 Pwnie Awards
Hosts Sophia d'Antoine and Ian Roos presented the list at Summercon in Brooklyn, New York, where they also handed out a surprise Lifetime Achievement Award.