Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique to Achieve Process Injection https://www.fireeye.com/blog/threat-research/2017/11/ursnif-variant-malicious-tls-callback-technique.html
FireEye
Newly Observed Ursnif Variant Employs Malicious TLS Callback Technique
to Achieve Process Injection
to Achieve Process Injection
We recently came across a Ursnif/Gozi-ISFB sample that manipulated TLS callbacks while injecting to child process.
Multiple vulnerabilities through filename manipulation (CVE-2020-28948 and CVE-2020-28949) in PEAR https://github.com/pear/Archive_Tar/issues/33
GitHub
Multiple vulnerabilities through filename manipulation (CVE-2020-28948 and CVE-2020-28949) · Issue #33 · pear/Archive_Tar
I have submitted this to the PEAR bug tracker as well as the PEAR group mailing list, and I'm not sure if either has gone through, so opening an issue here with the hope that this is the right ...
Extraordinary Vulnerabilities Discovered in TCL Android TVs, Now World’s 3rd Largest TV Manufacturer https://sick.codes/extraordinary-vulnerabilities-discovered-in-tcl-android-tvs-now-worlds-3rd-largest-tv-manufacturer/
Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips!
Extraordinary Vulnerabilities Discovered in TCL Android TVs, Now World’s 3rd Largest TV Manufacturer. - Sick Codes - Security Research…
The following piece is the culmination of a three-month long investigation into Smart TVs running Android. Having lived through this research experience, I can wholeheartedly say that there were multiple moments that I, and another security researcher that…
xpcspy - Bidirectional XPC message interception and more (with Frida) https://github.com/hot3eed/xpcspy
GitHub
GitHub - hot3eed/xpcspy: Bidirectional XPC message interception and more. Powered by Frida
Bidirectional XPC message interception and more. Powered by Frida - hot3eed/xpcspy
Not related to security, but it's a MUST tool >> hyperfine: a command-line benchmarking tool https://github.com/sharkdp/hyperfine
GitHub
GitHub - sharkdp/hyperfine: A command-line benchmarking tool
A command-line benchmarking tool. Contribute to sharkdp/hyperfine development by creating an account on GitHub.
Flare-On 2020 Solutions Write-Ups http://tonyweb.xyz/index.php/2020/11/07/flare-on-2020-solutions-write-ups/
Windows Defender Attack Surface Reduction Rules bypass https://oddvar.moe/2018/03/15/windows-defender-attack-surface-reduction-rules-bypass/
Oddvar Moe's Blog
Windows Defender Attack Surface Reduction Rules bypass
I discovered an easy way to bypass the Windows Defender Attack Surface Reduction Rules using code inside a macro. This issue has already been fixed with the Windows Defender virus definition versio…
Resourceful macOS Malware Hides in Named Fork https://labs.sentinelone.com/resourceful-macos-malware-hides-in-named-fork/
SentinelLabs
Resourceful macOS Malware Hides in Named Fork - SentinelLabs
Threat actors targeting macOS are deploying a new trick to hide payloads and avoid detection thanks to an old technology: the named resource fork.
Everyone Talks About Insecure Randomness, But Nobody Does Anything About It https://www.airza.net/2020/11/09/everyone-talks-about-insecure-randomness-but-nobody-does-anything-about-it.html
www.airza.net
Everyone Talks About Insecure Randomness, But Nobody Does Anything About It
In which I take a crack at pointing a neural network at random noise, and achieve 95+% predictive bitwise accuracy against my hated foe in this world, Xorshift128.
AMNESIA:33 Multiple vulnerabilities found on open-source TCP/IP stacks https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01
Theft of FireEye Red Team Tools https://us-cert.cisa.gov/ncas/current-activity/2020/12/08/theft-fireeye-red-team-tools
List of browser exploitation tutorials https://github.com/Escapingbug/awesome-browser-exploit
GitHub
GitHub - Escapingbug/awesome-browser-exploit: awesome list of browser exploitation tutorials
awesome list of browser exploitation tutorials. Contribute to Escapingbug/awesome-browser-exploit development by creating an account on GitHub.
Hungry for data, ModPipe backdoor hits POS software used in hospitality sector https://www.welivesecurity.com/2020/11/12/hungry-data-modpipe-backdoor-hits-pos-software-hospitality-sector/
WeLiveSecurity
Hungry for data, ModPipe backdoor hits POS software used in hospitality sector
ESET researchers uncover ModPipe, a modular backdoor that targets POS software used by thousands of restaurants and hotels worldwide.
Firefox Vulnerability Research Part 2
https://blog.exodusintel.com/2020/11/10/firefox-vulnerability-research-part-2/
https://blog.exodusintel.com/2020/11/10/firefox-vulnerability-research-part-2/
Exodus Intelligence
Firefox Vulnerability Research Part 2 - Exodus Intelligence
By Arthur Gerkis and David Barksdale This series of posts makes public some old Firefox research which our Zero-Day customers had access to before it was known publicly, and then our N-Day customers after it was patched. We’ve also used this research to teach…
Vulnerability Spotlight: Code execution vulnerability in Microsoft Excel https://blog.talosintelligence.com/2020/12/vulnerability-spotlight-excel-rce-dec-patch-tuesday.html?m=1
Talosintelligence
Vulnerability Spotlight: Code execution vulnerability in Microsoft Excel
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
Reversing C++ Without Getting a Heart Attack – DEvirtualize VIrtual Calls With Devi https://insinuator.net/2020/11/reversing-c-without-getting-a-heart-attack-devirtualize-virtual-calls-with-devi/
Cryptominers Exploiting WebLogic RCE CVE-2020-14882 https://thedfirreport.com/2020/11/12/cryptominers-exploiting-weblogic-rce-cve-2020-14882/
The DFIR Report
Cryptominers Exploiting WebLogic RCE CVE-2020-14882
Intro Towards the end of October, we started seeing attackers take advantage of a WebLogic RCE vulnerability (CVE-2020-14882). Recently, SANS ISC talked about this vulnerability being exploited in …
bdshemu: The Bitdefender shellcode emulator https://hvmi.github.io/blog/2020/11/11/bdshemu.html
Advanced MSSQL Injection Tricks https://swarm.ptsecurity.com/advanced-mssql-injection-tricks/
[Linux Kernel Exploitation 0x0] Debugging the Kernel with QEMU https://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x0-debugging.html