Hola! Hemos habilitado las discusiones en el canal, por si alguien quiere dejar algún comentario sobre los post que enviamos
TroubleGrabber: El malware que utiliza Discord como servidor de control https://unaaldia.hispasec.com/2020/11/troublegrabber-el-malware-que-utiliza-discord-como-servidor-de-control.html/amp?__twitter_impression=true
Una al Día
TroubleGrabber: El malware que utiliza Discord como servidor de control — Una al Día
Recientemente se han detectado nuevas muestras de malware que están aprovechando los servicios de Discord como servidor de control, que recibe la información privada robada de las máquinas infectad…
Major Vulnerabilities Discovered in Qualcomm QCMAP https://www.vdoo.com/blog/qualcomm-qcmap-vulnerabilities
Malwoverview is a first response tool used for downloading and screening malware samples, suspicious URLs, IP address, domains https://github.com/alexandreborges/malwoverview
GitHub
GitHub - alexandreborges/malwoverview: Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis…
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, ...
Chrome: Use-after-free in XRSystem::FocusedFrameChanged and FocusController::NotifyFocusChangedObservers https://bugs.chromium.org/p/project-zero/issues/detail?id=2069
#Instagram_RCE: Code Execution Vulnerability in Instagram App for Android and iOS https://research.checkpoint.com/2020/instagram_rce-code-execution-vulnerability-in-instagram-app-for-android-and-ios/
Check Point Research
#Instagram_RCE: Code Execution Vulnerability in Instagram App for Android and iOS - Check Point Research
Research by: Gal Elbaz Background Instagram, with over 100+ million photos uploaded every day, is one of the most popular social media platforms. For that reason, we decided to audit the security of the Instagram app for both Android and iOS operating systems.…
Espressif ESP32: Bypassing Encrypted Secure Boot (CVE-2020-13629) https://raelize.com/posts/espressif-esp32-bypassing-encrypted-secure-boot-cve-2020-13629/
Secret fragments: Remote code execution on Symfony based websites https://www.ambionics.io/blog/symfony-secret-fragment
Vulnerabilities in ATM Milano's mobile app https://blog.jacopojannone.com/en/post/atm-app-vulnerability/
MindShaRE: How to “Just Emulate It With QEMU https://www.zerodayinitiative.com/blog/2020/5/27/mindshare-how-to-just-emulate-it-with-qemu
Zero Day Initiative
Zero Day Initiative — MindShaRE: How to “Just Emulate It With QEMU”
MindShaRE is our periodic look at various reverse engineering tips and tricks. The goal is to keep things small and discuss some everyday aspects of reversing. You can view previous entries in this series here .
Researchers Warn of Critical Flaw Affecting Industrial Automation Systems https://thehackernews.com/2020/11/researchers-warn-of-critical-flaws.html
Twitter Investigation Report: Report on Investigation of Twitter’s July 15, 2020 Cybersecurity Incident and the Implications for Election Security
https://www.dfs.ny.gov/Twitter_Report
https://www.dfs.ny.gov/Twitter_Report
CVE-2020-15157 "ContainerDrip" Write-up https://darkbit.io/blog/cve-2020-15157-containerdrip
Finding New Bluetooth Low Energy Exploits via Reverse Engineering Multiple Vendors' Firmwares (BH USA'20 presentation) https://i.blackhat.com/USA-20/Wednesday/us-20-Kovah-Finding-New-Bluetooth-Low-Energy-Exploits-Via-Reverse-Engineering-Multiple-Vendors-Firmwares.pdf
How To Host Your Own DNS-over-HTTPS And DNS-over-TLS Services https://blog.technitium.com/2020/07/how-to-host-your-own-dns-over-https-and.html
Technitium
How To Host Your Own DNS-over-HTTPS, DNS-over-TLS, And DNS-over-QUIC Services
Updated: 2 May 2026 With Technitium DNS Server , you can not just consume DNS-over-HTTPS (DoH), DNS-over-TLS (DoT), or DNS-over-QUIC...
Let’s build a high-performance fuzzer with GPUs! https://blog.trailofbits.com/2020/10/22/lets-build-a-high-performance-fuzzer-with-gpus/
The Trail of Bits Blog
Let’s build a high-performance fuzzer with GPUs!
TL;DR: Can we use GPUs to get 10x performance/dollar when fuzzing embedded software in the cloud? Based on our preliminary work, we think the answer is yes! Fuzzing is a software testing technique that supplies programs with many randomized inputs in an attempt…
Ryuk in 5 Hours https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/
The DFIR Report
Ryuk in 5 Hours - The DFIR Report
Intro The Ryuk threat actors went from a phishing email to domain wide ransomware in 5 hours. They escalated privileges using Zerologon (CVE-2020-1472), less than 2 hours after the initial phish. They used tools such as Cobalt Strike, AdFind, WMI, and PowerShell…