Trickbot disrupted https://www.microsoft.com/security/blog/2020/10/12/trickbot-disrupted/
Microsoft Security Blog
Trickbot disrupted | Microsoft Security Blog
Microsoft took action against the Trickbot botnet, disrupting one of the world’s most persistent malware operations. Microsoft worked with telecommunications providers around the world to disrupt key Trickbot infrastructure.
DLL Execution via Excel.Application RegisterXLL() method https://medium.com/ryhanson/dll-execution-via-excel-application-registerxll-method-d03361a95f5c
Medium
DLL Execution via Excel.Application RegisterXLL() method
Originally posted on 07/23/2017 at gist.github.com
Taurus Project stealer now spreading via malvertising campaign https://blog.malwarebytes.com/malwarebytes-news/2020/09/taurus-project-stealer-now-spreading-via-malvertising-campaign/
Double Trouble: Ransomware with Data Leak Extortion, Part 1 https://www.crowdstrike.com/blog/double-trouble-ransomware-data-leak-extortion-part-1/
crowdstrike.com
Ransomware + Data Leak Extortion: Origins and Adversaries, Pt. 1
This first part of a two-part blog series explores the origins of ransomware, BGH and extortion, as well as introducing some of the criminal adversaries who are dominating this data leak extortion ecosystem.
German-made FinSpy spyware found in Egypt, and Mac and Linux versions revealed https://www.amnesty.org/en/latest/research/2020/09/german-made-finspy-spyware-found-in-egypt-and-mac-and-linux-versions-revealed/
Amnesty International
German-made FinSpy spyware found in Egypt, and Mac and Linux versions revealed
• FinSpy is a commercial spyware suite produced by the Munich-based company FinFisher Gmbh. Since 2011 researchers have documented numerous cases of targeting of Human Rights Defenders (HRDs) - including activists, journalists, and dissidents with the use…
BLUE TEAM: Very short survey, related to a SoK paper, and analysis of the current state of training https://docs.google.com/forms/d/e/1FAIpQLSdnyVTblRr3pMVL1I1m1Ihv7xQjhSpHsDuf7sBD62F4QTZTsw/viewform
Google Docs
Blue team training — current state
This form is related to a State of Knowledge paper, and in-depth analysis, conducted by students at a Danish university. The paper focuses on training of blue teams within cyber security and the current state of blue team training.
CVE-2020-16898 | Windows TCP/IP Remote Code Execution Vulnerability https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16898
you should patch now » CVE-2020-16898: “Bad Neighbor” https://www.mcafee.com/blogs/other-blogs/mcafee-labs/cve-2020-16898-bad-neighbor
McAfee Blog
CVE-2020-16898: “Bad Neighbor” | McAfee Blog
CVE-2020-16898: “Bad Neighbor” CVSS Score: 8.8 Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C Overview Today, Microsoft announced a
Internet Explorer CVE-2019–1367 Exploitation: p1 https://blog.confiant.com/internet-explorer-cve-2019-1367-exploitation-part-1-7ff08b7dcc8b, p2 https://blog.confiant.com/internet-explorer-cve-2019-1367-exploitation-part-2-8143242b5780, p3 https://blog.confiant.com/internet-explorer-cve-2019-1367-exploitation-part-3-a92d3011b38
Medium
Internet Explorer CVE-2019–1367 Exploitation — part 1
Extracting the Exploit from the PCAP
Microsoft Patch Tuesday for Oct. 2020 — Snort rules and prominent vulnerabilities https://blog.talosintelligence.com/2020/10/microsoft-patch-tuesday-for-oct-2020.html
Cisco Talos Blog
Microsoft Patch Tuesday for Oct. 2020 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Alex McDonnell and Nick Biasini.
Microsoft released its monthly security update Tuesday, disclosing just under 100 vulnerabilities across its array of products.
Fourteen of the vulnerabilities are considered “critical"…
Microsoft released its monthly security update Tuesday, disclosing just under 100 vulnerabilities across its array of products.
Fourteen of the vulnerabilities are considered “critical"…
Email-delivered MoDi RAT attack pastes PowerShell commands https://news.sophos.com/en-us/2020/09/24/email-delivered-modi-rat-attack-pastes-powershell-commands/
Sophos
Email-delivered MoDi RAT attack pastes PowerShell commands
Fileless attack scripts an interaction with the clipboard to evade detection
Beware the Bad Neighbor: Analysis and PoC of the Windows IPv6 Router Advertisement Vulnerability (CVE-2020-16898) https://blog.quarkslab.com/beware-the-bad-neighbor-analysis-and-poc-of-the-windows-ipv6-router-advertisement-vulnerability-cve-2020-16898.html
Quarkslab
Beware the Bad Neighbor: Analysis and PoC of the Windows IPv6 Router Advertisement Vulnerability (CVE-2020-16898) - Quarkslab's…
This blog post analyzes the vulnerability known as "Bad Neighbor" or CVE-2020-16898, a stack-based buffer overflow in the IPv6 stack of Windows, which can be remotely triggered by means of a malformed Router Advertisement packet.
Demystifying the “SVCHOST.EXE” Process and Its Command Line Options https://medium.com/@nasbench/demystifying-the-svchost-exe-process-and-its-command-line-options-508e9114e747
Medium
Demystifying the “SVCHOST.EXE” Process and Its Command Line Options
Understanding the “svchost.exe” process and its command line options
BH Asia 2020 briefings: "There are Apps in Apps Here is How to Break Them" https://i.blackhat.com/asia-20/Thursday/asia-20-Xing-The-Inside-Story-There-Are-Apps-In-Apps-And-Here-Is-How-To-Break-Them.pdf
A DFIR exercise --> The Case of the Stolen Szechuan Sauce https://dfirmadness.com/the-stolen-szechuan-sauce/
DFIR Madness
Case 001 - The Stolen Szechuan Sauce - DFIR Madness
The Stolen Szechuan Sauce is a digital forensics lab with you in mind. Share with your students or security team for scenario training.
An introduction to Linux kernel initcalls https://www.collabora.com/news-and-blog/blog/2020/07/14/introduction-to-linux-kernel-initcalls/
Collabora | Open Source Consulting
An introduction to Linux kernel initcalls
An overview of initcalls, including their purpose, their usage, ways to debug them (initcall_debug and FTrace), and more.
Network Detection for ZeroLogon (CVE-2020-1472) https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/network-detection-for-zerologon-cve-2020-1472/
Trustwave
Network Detection for ZeroLogon (CVE-2020-1472)
ZeroLogon has quickly become popular and well known because of multiple proofs of concept and exploits implemented in Python, .NET, Powershell, and Mimikatz implemented a module for it. So if you are an attacker or need to test your environment then you…
Nice use for your Rapsberry :) » TorPi - Raspberry Pi Tor Access Point https://3os.org/raspberryPi/TOR-Pi/