Interesting thread on Windows logon activty behind the curtain https://twitter.com/SteveSyfuhs/status/1297957799079510018?s=09
Twitter
Steve Syfuhs
Have you ever wondered what happens behind the scenes when you type your password into the Windows logon screen and hit enter? I'm waiting for a build to complete, so I'm gonna tell you.
An Interview With RedBear: A Hacker Training the Next Generation of Cybercriminals https://therecord.media/an-interview-with-redbear-a-hacker-training-the-next-generation-of-cybercriminals/
The Record
An Interview With RedBear: A Hacker Training the Next Generation of Cybercriminals
A security intelligence analyst interviews RedBear, a hacker and malware tester who is training the next generation of cybercriminals.
Transparent Tribe: Evolution analysis,
part 1 https://securelist.com/transparent-tribe-part-1/98127/
part 1 https://securelist.com/transparent-tribe-part-1/98127/
Malicious Apps Could Take Over Samsung Devices https://char49.com/articles/malicious-apps-could-take-over-samsung-devicesv
Nice description of Windows internals --> One Windows Kernel https://techcommunity.microsoft.com/t5/windows-kernel-internals/one-windows-kernel/ba-p/267142
TECHCOMMUNITY.MICROSOFT.COM
One Windows Kernel
Windows is one of the most versatile and flexible operating systems out there, running on a variety of machine architectures and available in multiple SKUs. It currently supports x86, x64, ARM and ARM64 architectures. Windows used to support Itanium, PowerPC…
Exploit Development: Between a Rock and a (Xtended Flow) Guard Place: Examining XFG https://connormcgarr.github.io/examining-xfg/
Connor McGarr’s Blog
Exploit Development: Between a Rock and a (Xtended Flow) Guard Place: Examining XFG
Taking a look at Microsoft’s new forward-edge CFI solution: Xtended Flow Guard
A Voyage to Uncovering Telemetry: Identifying RPC Telemetry for Detection Engineers https://ipc-research.readthedocs.io/en/latest/subpages/RPC.html
Full disclosure: 0day vulnerability (backdoor) in firmware for Xiaongmai-based DVRs, NVRs and IP cameras https://habr.com/en/post/486856/
Habr
Full disclosure: 0day vulnerability (backdoor) in firmware for Xiaongmai-based DVRs, NVRs and IP cameras
This is a full disclosure of recent backdoor integrated into DVR/NVR devices built on top of HiSilicon SoC with Xiaongmai firmware. Described vulnerability...
Russia’s Approach to Cyber Warfare (by CNA) https://www.cna.org/cna_files/pdf/DOP-2016-U-014231-1Rev.pdf
Detailed Analysis of Ghostcat Vulnerability (Cve-2020–1938) in Apache Tomcat Servers https://medium.com/bugbountywriteup/detailed-analysis-of-ghostcat-vulnerability-cve-2020-1938-in-apache-tomcat-servers-and-using-it
Improvements of fuzzing techniques in Vuzzer https://hajjik666.blogspot.com/2020/08/improvements-of-fuzzing-techniques-in.html
Blogspot
Improvements of fuzzing techniques in Vuzzer
Hi, this is my report of my academic internship at the University of Bristol’s Cyber security group. This Cyber security group works on ...
Why you should always scan UDP ports (part 1/2) https://medium.com/bugbountywriteup/why-you-should-always-scan-udp-ports-part-1-2-d8ee7eb26727
Medium
Why you should always scan UDP ports (part 1/2)
IntroductIn this story we’ll see how we exploited snmp vulnerabilities, bypassed firewall rules and AppArmor to compromise the network.
Proxyjump, the SSH option you probably never heard of https://medium.com/maverislabs/proxyjump-the-ssh-option-you-probably-never-heard-of
An Exhaustively-Analyzed IDB for ComRAT v4 https://www.msreverseengineering.com/blog/2020/8/31/an-exhaustively-analyzed-idb-for-comrat-v4
Möbius Strip Reverse Engineering
An Exhaustively-Analyzed IDB for ComRAT v4 — Möbius Strip Reverse Engineering
This blog entry announces the release of an exhaustive analysis of ComRAT v4. You can find the IDBs here . More specifically, an IDB for the sample with hash 0139818441431C72A1935E7F740A1CC458A63452, which was mentioned in the ESET report (see especially…
Nice descriptions of CVE-2020-0751, CVE-2020-0890 and CVE-2020-0904 https://labs.bluefrostsecurity.de/advisories/bfs-sa-2020-002/ https://labs.bluefrostsecurity.de/advisories/bfs-sa-2020-003/ https://labs.bluefrostsecurity.de/advisories/bfs-sa-2020-001/
labs.bluefrostsecurity.de
Microsoft Hyper-V NULL Pointer Dereference Denial of Service | Bluefrostsecurity
Gozi: The Malware with a Thousand Faces https://research.checkpoint.com/2020/gozi-the-malware-with-a-thousand-faces/
Check Point Research
Gozi: The Malware with a Thousand Faces - Check Point Research
Introduction Most of the time, the relationship between cybercrime campaigns and malware strains is simple. Some malware strains, like the gone-but-not-forgotten GandCrab, are intimately tied to a single actor, who is using the malware directly or distributing…
Security in PRIME networks – Current status https://www.tarlogic.com/en/blog/security-in-prime-networks-current-status/
Tarlogic Security - Cyber Security and Ethical hacking
Security in PRIME networks - Current status
Since January 2019, all electricity meters for low power customers (up to 15 kW) in Spain are (or have been replaced by) smart electricity meters, allowing distributors to carry out consumption measurements and various supply point management operations remotely.…