OceanLotus Old techniques, new backdoor https://www.welivesecurity.com/wp-content/uploads/2018/03/ESET_OceanLotus.pdf
nice talk on BH Asia20 >> Finding Backdoors in Applications https://i.blackhat.com/asia-20/Friday/asia-20-Loke-Patching-Loopholes-Finding-Backdoors-In-Applications.pdf
How to Find Vulnerabilities in Code: Bad Words
https://btlr.dev/blog/how-to-find-vulnerabilities-in-code-bad-words
https://btlr.dev/blog/how-to-find-vulnerabilities-in-code-bad-words
Sophisticated new Android malware marks the latest evolution of mobile ransomware https://www.microsoft.com/security/blog/2020/10/08/sophisticated-new-android-malware-marks-the-latest-evolution-of-mobile-ransomware/
Microsoft News
Sophisticated new Android malware marks the latest evolution of mobile ransomware
We found a piece of a particularly sophisticated Android ransomware with novel techniques and behavior, exemplifying the rapid evolution of mobile threats that we have also observed on other platforms.
PoetRAT: Malware targeting public and private sector in Azerbaijan evolves https://blog.talosintelligence.com/2020/10/poetrat-update.html
Cisco Talos Blog
PoetRAT: Malware targeting public and private sector in Azerbaijan evolves
By Warren Mercer, Paul Rascagneres and Vitor Ventura.
* The Azerbaijan public sector and other important organizations are still targeted by new versions of PoetRAT.
* This actor leverages malicious Microsoft Word documents alleged to be from the Azerbaijan…
* The Azerbaijan public sector and other important organizations are still targeted by new versions of PoetRAT.
* This actor leverages malicious Microsoft Word documents alleged to be from the Azerbaijan…
Audi A7 2014 MMI Mishandles the Format-string Specifiers https://tiger-team-1337.blogspot.com/2020/10/audi-a7-2014-mmi-mishandles-format.html
Blogspot
Audi A7 2014 MMI Mishandles the Format-string Specifiers
Date: 2020-10-13 Author: Kevin2600 CVE: CVE-2020-27524 Version: Audi A7 2014 MMI Vendor : https://www.audi.com/en.html Attack-Vector:...
More TA551 (Shathak) Word docs push IcedID (Bokbot) https://isc.sans.edu/forums/diary/More+TA551+Shathak+Word+docs+push+IcedID+Bokbot/26674/
Moving From Manual Reverse Engineering of UEFI Modules To Dynamic Emulation of UEFI Firmware https://labs.sentinelone.com/moving-from-manual-re-of-uefi-modules-to-dynamic-emulation-of-uefi-firmware/
SentinelOne
Moving From Manual Reverse Engineering of UEFI Modules To Dynamic Emulation of UEFI Firmware - SentinelLabs
Learn how to emulate, trace, debug, and Reverse Engineer UEFI modules in part 2 of our new blog series on Firmware Security
The Difficulties of Tracking Running Processes on Linux https://natanyellin.com/posts/tracking-running-processes-on-linux/
Natanyellin
The Difficulties of Tracking Running Processes on Linux
Introduction Everyone knows how to track which processes run on Linux, but almost no-one tracks them accurately. In fact, all of the methods listed in this post have some deficiency or another. Lets define requirements:
All processes should be logged including…
All processes should be logged including…
Technical Advisory – Pulse Connect Secure – RCE via Template Injection (CVE-2020-8243)
https://research.nccgroup.com/2020/10/06/technical-advisory-pulse-connect-secure-rce-via-template-injection-cve-2020-8243/
https://research.nccgroup.com/2020/10/06/technical-advisory-pulse-connect-secure-rce-via-template-injection-cve-2020-8243/
NCC Group Research
Technical Advisory – Pulse Connect Secure – RCE via Template Injection (CVE-2020-8243)
NCC Group Technical Advisory: Pulse Connect Secure - RCE via Template Injection (CVE-2020-8243)
Sandbox evasion: Identifying Blue Teams https://www.securityartwork.es/2020/10/12/sandbox-evasion-identifying-blue-teams/
Security Art Work
Sandbox evasion: Identifying Blue Teams - Security Art Work
Last March, Roberto Amado and I (Víctor Calvo) gave a talk at RootedCON 2020 titled Sandbox fingerprinting: Avoiding analysis environments. The talk consisted of two parts, the first of which dealt with classifying public sandbox environments for malware…
What Do You Need For A Career In Malware Analysis? https://www.ringzerolabs.com/2020/10/what-do-you-need-for-career-in-malware.html
Ringzerolabs
What Do You Need For A Career In Malware Analysis?
Here's what you need to begin a career in Malware Analysis.
Amazon Kindle: iOS App Reverse Engineering for eBooks Leaking https://abjurato.github.io/stories/kindleEbooks.html
anatoly.works
Amazon Kindle: iOS App Reverse Engineering for eBooks Leaking
The State of Exploit Development: 80% of Exploits Publish Faster than CVEs https://unit42.paloaltonetworks.com/state-of-exploit-development/
Unit 42
The State of Exploit Development: 80% of Exploits Publish Faster than CVEs
The typical timing of patch releases, exploit development and CVE publication underscores the need for effective vulnerability management.
Watson is a .NET tool designed to enumerate missing KBs and suggest exploits for Privilege Escalation vulnerabilities https://github.com/rasta-mouse/Watson
GitHub
GitHub - rasta-mouse/Watson: Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities
Enumerate missing KBs and suggest exploits for useful Privilege Escalation vulnerabilities - rasta-mouse/Watson
In Wild Critical Buffer Overflow Vulnerability in Solaris Can Allow Remote Takeover — CVE-2020-14871 https://www.fireeye.com/blog/threat-research/2020/11/critical-buffer-overflow-vulnerability-in-solaris-can-allow-remote-takeover.html
FireEye
In Wild Critical Buffer Overflow Vulnerability in Solaris Can Allow
Remote Takeover — CVE-2020-14871
Remote Takeover — CVE-2020-14871
After seeing Oracle Solaris compromises, we analyzed the exploit to determine how it worked and then reported it to Oracle.
Lemon Duck brings cryptocurrency miners back into the spotlight https://blog.talosintelligence.com/2020/10/lemon-duck-brings-cryptocurrency-miners.html
Cisco Talos Blog
Lemon Duck brings cryptocurrency miners back into the spotlight
By Vanja Svajcer, with contributions from Caitlin Huey.
* We are used to ransomware attacks and big-game hunting making headlines, but there are still methods adversaries use to monetize their efforts in less intrusive ways.
* Cisco Talos recently recorded…
* We are used to ransomware attacks and big-game hunting making headlines, but there are still methods adversaries use to monetize their efforts in less intrusive ways.
* Cisco Talos recently recorded…
How I Hacked Facebook Again! Unauthenticated RCE on MobileIron MDM https://blog.orange.tw/2020/09/how-i-hacked-facebook-again-mobileiron-mdm-rce.html
Orange Tsai
How I Hacked Facebook Again! Unauthenticated RCE on MobileIron MDM
📌 [ 繁體中文 | English ] Hi, it’s a long time since my last article. This new post is about my research this March, which talks about how I found vulnerabilities on a leading Mobile Device Management