MemFuck: Bypassing User-Mode Hooks https://winternl.com/memfuck/
winternl
MemFuck: Bypassing User-Mode Hooks
Dynamic malware analysis is the preferred way to determine the legitimacy of an application for many AVs/EDRs/MDSs. Unlike static analysis, dynamic analysis can capture and analyze Windows API calls…
Let's Learn: In-Depth Reversing of Qakbot "qbot" Banker Part 1 https://www.vkremez.com/2018/07/lets-learn-in-depth-reversing-of-qakbot.html
1Win México
1win México ᐈ Сasino en línea - sitio web oficial
✅ Registrarse en sitio web oficial 1win casino & casa de apuestas en México ✓ Bono de 14.000 MXN ✔️ Juega con dinero real ✔ Tragaperras ✔️
Kernel exploitation: weaponizing CVE-2020-17382 MSI Ambient Link driver https://www.matteomalvica.com/blog/2020/09/24/weaponizing-cve-2020-17382/ (PoCs in https://github.com/uf0o/CVE-2020-17382)
Matteomalvica
Kernel exploitation: weaponizing CVE-2020-17382 MSI Ambient Link driver
Introduction to Windows Drivers Exploitation
MEDUZA: A more or less universal SSL unpinning tool for iOS https://github.com/kov4l3nko/MEDUZA
MacOS Injection via Third Party Frameworks https://blog.xpnsec.com/macos-injection-via-third-party-frameworks/
XPN InfoSec Blog
@_xpn_ - MacOS Injection via Third Party Frameworks
In this post, we are going to take a look at a couple of interesting methods of leveraging third-party technologies to achieve our code injection goals. For us, this translates to running code in the context of a target application without having to resort…
Micropatch for Zerologon, the "perfect" Windows vulnerability (CVE-2020-1472) https://blog.0patch.com/2020/09/micropatch-for-zerologon-perfect.html
0patch - Better Security Patches
Micropatch for Zerologon, the "perfect" Windows vulnerability (CVE-2020-1472)
Tiny reboot-less security patches for critical vulnerabilities in Windows, Microsoft Office, and other Windows products
Lambdas: From C++11 to C++20, Part 1 https://www.bfilipek.com/2019/02/lambdas-story-part1.html?m=1
C++ Stories
Lambdas: From C++11 to C++20, Part 1
Lambda expressions are one of the most powerful additions to C++11, and they continue to evolve with each new C++ language standard. In this article, we’ll go through history and see the evolution of this crucial part of modern C++.
The second part is available:…
The second part is available:…
Locating the Trojan inside an infected COVID-19 contact tracing app https://medium.com/@cryptax/locating-the-trojan-inside-an-infected-covid-19-contact-tracing-app-21e23f90fbfe
Medium
Locating the Trojan inside an infected COVID-19 contact tracing app
An italian company, SoftMining, developed an Android COVID-19 contact tracing application “SM-COVID-19”. Unfortunately, malware authors…
Code Review 101: How to perform source code review to find vulnerabilities in web applications https://vickieli.dev/hacking/code-review-101/
Vickie Li's Security Blog
Code Review 101
How to perform source code review to find vulnerabilities in web applications.
PDF from NSA to help selecting secure multi-factor authentication solutions https://media.defense.gov/2020/Sep/22/2002502665/-1/-1/0/CSI_MULTIFACTOR_AUTHENTICATION_SOLUTIONS_UOO17091520.PDF
uTorrent CVE-2020-8437 Vulnerability And Exploit Overview https://blog.whtaguy.com/2020/09/utorrent-cve-2020-8437-vulnerability.html
Mav Levin Security Research
uTorrent CVE-2020-8437 Vulnerability And Exploit Overview
The world’s most popular torrent client, uTorrent, contained a security vulnerability — later to be called CVE-2020-8437— that could be exploited by a remote...
Fuzzing Image Parsing in Windows, Part One: Color Profiles https://www.fireeye.com/blog/threat-research/2020/09/fuzzing-image-parsing-in-windows-color-profiles.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
Trickbot disrupted https://www.microsoft.com/security/blog/2020/10/12/trickbot-disrupted/
Microsoft Security Blog
Trickbot disrupted | Microsoft Security Blog
Microsoft took action against the Trickbot botnet, disrupting one of the world’s most persistent malware operations. Microsoft worked with telecommunications providers around the world to disrupt key Trickbot infrastructure.
DLL Execution via Excel.Application RegisterXLL() method https://medium.com/ryhanson/dll-execution-via-excel-application-registerxll-method-d03361a95f5c
Medium
DLL Execution via Excel.Application RegisterXLL() method
Originally posted on 07/23/2017 at gist.github.com
Taurus Project stealer now spreading via malvertising campaign https://blog.malwarebytes.com/malwarebytes-news/2020/09/taurus-project-stealer-now-spreading-via-malvertising-campaign/
Double Trouble: Ransomware with Data Leak Extortion, Part 1 https://www.crowdstrike.com/blog/double-trouble-ransomware-data-leak-extortion-part-1/
crowdstrike.com
Ransomware + Data Leak Extortion: Origins and Adversaries, Pt. 1
This first part of a two-part blog series explores the origins of ransomware, BGH and extortion, as well as introducing some of the criminal adversaries who are dominating this data leak extortion ecosystem.