Micropatch for Zerologon, the "perfect" Windows vulnerability (CVE-2020-1472) https://blog.0patch.com/2020/09/micropatch-for-zerologon-perfect.html
0patch - Better Security Patches
Micropatch for Zerologon, the "perfect" Windows vulnerability (CVE-2020-1472)
Tiny reboot-less security patches for critical vulnerabilities in Windows, Microsoft Office, and other Windows products
Lambdas: From C++11 to C++20, Part 1 https://www.bfilipek.com/2019/02/lambdas-story-part1.html?m=1
C++ Stories
Lambdas: From C++11 to C++20, Part 1
Lambda expressions are one of the most powerful additions to C++11, and they continue to evolve with each new C++ language standard. In this article, we’ll go through history and see the evolution of this crucial part of modern C++.
The second part is available:…
The second part is available:…
Locating the Trojan inside an infected COVID-19 contact tracing app https://medium.com/@cryptax/locating-the-trojan-inside-an-infected-covid-19-contact-tracing-app-21e23f90fbfe
Medium
Locating the Trojan inside an infected COVID-19 contact tracing app
An italian company, SoftMining, developed an Android COVID-19 contact tracing application “SM-COVID-19”. Unfortunately, malware authors…
Code Review 101: How to perform source code review to find vulnerabilities in web applications https://vickieli.dev/hacking/code-review-101/
Vickie Li's Security Blog
Code Review 101
How to perform source code review to find vulnerabilities in web applications.
PDF from NSA to help selecting secure multi-factor authentication solutions https://media.defense.gov/2020/Sep/22/2002502665/-1/-1/0/CSI_MULTIFACTOR_AUTHENTICATION_SOLUTIONS_UOO17091520.PDF
uTorrent CVE-2020-8437 Vulnerability And Exploit Overview https://blog.whtaguy.com/2020/09/utorrent-cve-2020-8437-vulnerability.html
Mav Levin Security Research
uTorrent CVE-2020-8437 Vulnerability And Exploit Overview
The world’s most popular torrent client, uTorrent, contained a security vulnerability — later to be called CVE-2020-8437— that could be exploited by a remote...
Fuzzing Image Parsing in Windows, Part One: Color Profiles https://www.fireeye.com/blog/threat-research/2020/09/fuzzing-image-parsing-in-windows-color-profiles.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
Trickbot disrupted https://www.microsoft.com/security/blog/2020/10/12/trickbot-disrupted/
Microsoft Security Blog
Trickbot disrupted | Microsoft Security Blog
Microsoft took action against the Trickbot botnet, disrupting one of the world’s most persistent malware operations. Microsoft worked with telecommunications providers around the world to disrupt key Trickbot infrastructure.
DLL Execution via Excel.Application RegisterXLL() method https://medium.com/ryhanson/dll-execution-via-excel-application-registerxll-method-d03361a95f5c
Medium
DLL Execution via Excel.Application RegisterXLL() method
Originally posted on 07/23/2017 at gist.github.com
Taurus Project stealer now spreading via malvertising campaign https://blog.malwarebytes.com/malwarebytes-news/2020/09/taurus-project-stealer-now-spreading-via-malvertising-campaign/
Double Trouble: Ransomware with Data Leak Extortion, Part 1 https://www.crowdstrike.com/blog/double-trouble-ransomware-data-leak-extortion-part-1/
crowdstrike.com
Ransomware + Data Leak Extortion: Origins and Adversaries, Pt. 1
This first part of a two-part blog series explores the origins of ransomware, BGH and extortion, as well as introducing some of the criminal adversaries who are dominating this data leak extortion ecosystem.
German-made FinSpy spyware found in Egypt, and Mac and Linux versions revealed https://www.amnesty.org/en/latest/research/2020/09/german-made-finspy-spyware-found-in-egypt-and-mac-and-linux-versions-revealed/
Amnesty International
German-made FinSpy spyware found in Egypt, and Mac and Linux versions revealed
• FinSpy is a commercial spyware suite produced by the Munich-based company FinFisher Gmbh. Since 2011 researchers have documented numerous cases of targeting of Human Rights Defenders (HRDs) - including activists, journalists, and dissidents with the use…
BLUE TEAM: Very short survey, related to a SoK paper, and analysis of the current state of training https://docs.google.com/forms/d/e/1FAIpQLSdnyVTblRr3pMVL1I1m1Ihv7xQjhSpHsDuf7sBD62F4QTZTsw/viewform
Google Docs
Blue team training — current state
This form is related to a State of Knowledge paper, and in-depth analysis, conducted by students at a Danish university. The paper focuses on training of blue teams within cyber security and the current state of blue team training.
CVE-2020-16898 | Windows TCP/IP Remote Code Execution Vulnerability https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16898
you should patch now » CVE-2020-16898: “Bad Neighbor” https://www.mcafee.com/blogs/other-blogs/mcafee-labs/cve-2020-16898-bad-neighbor
McAfee Blog
CVE-2020-16898: “Bad Neighbor” | McAfee Blog
CVE-2020-16898: “Bad Neighbor” CVSS Score: 8.8 Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C Overview Today, Microsoft announced a
Internet Explorer CVE-2019–1367 Exploitation: p1 https://blog.confiant.com/internet-explorer-cve-2019-1367-exploitation-part-1-7ff08b7dcc8b, p2 https://blog.confiant.com/internet-explorer-cve-2019-1367-exploitation-part-2-8143242b5780, p3 https://blog.confiant.com/internet-explorer-cve-2019-1367-exploitation-part-3-a92d3011b38
Medium
Internet Explorer CVE-2019–1367 Exploitation — part 1
Extracting the Exploit from the PCAP
Microsoft Patch Tuesday for Oct. 2020 — Snort rules and prominent vulnerabilities https://blog.talosintelligence.com/2020/10/microsoft-patch-tuesday-for-oct-2020.html
Cisco Talos Blog
Microsoft Patch Tuesday for Oct. 2020 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Alex McDonnell and Nick Biasini.
Microsoft released its monthly security update Tuesday, disclosing just under 100 vulnerabilities across its array of products.
Fourteen of the vulnerabilities are considered “critical"…
Microsoft released its monthly security update Tuesday, disclosing just under 100 vulnerabilities across its array of products.
Fourteen of the vulnerabilities are considered “critical"…
Email-delivered MoDi RAT attack pastes PowerShell commands https://news.sophos.com/en-us/2020/09/24/email-delivered-modi-rat-attack-pastes-powershell-commands/
Sophos
Email-delivered MoDi RAT attack pastes PowerShell commands
Fileless attack scripts an interaction with the clipboard to evade detection