AMNESIA:33 Multiple vulnerabilities found on open-source TCP/IP stacks https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01
Theft of FireEye Red Team Tools https://us-cert.cisa.gov/ncas/current-activity/2020/12/08/theft-fireeye-red-team-tools
List of browser exploitation tutorials https://github.com/Escapingbug/awesome-browser-exploit
GitHub
GitHub - Escapingbug/awesome-browser-exploit: awesome list of browser exploitation tutorials
awesome list of browser exploitation tutorials. Contribute to Escapingbug/awesome-browser-exploit development by creating an account on GitHub.
Hungry for data, ModPipe backdoor hits POS software used in hospitality sector https://www.welivesecurity.com/2020/11/12/hungry-data-modpipe-backdoor-hits-pos-software-hospitality-sector/
WeLiveSecurity
Hungry for data, ModPipe backdoor hits POS software used in hospitality sector
ESET researchers uncover ModPipe, a modular backdoor that targets POS software used by thousands of restaurants and hotels worldwide.
Firefox Vulnerability Research Part 2
https://blog.exodusintel.com/2020/11/10/firefox-vulnerability-research-part-2/
https://blog.exodusintel.com/2020/11/10/firefox-vulnerability-research-part-2/
Exodus Intelligence
Firefox Vulnerability Research Part 2 - Exodus Intelligence
By Arthur Gerkis and David Barksdale This series of posts makes public some old Firefox research which our Zero-Day customers had access to before it was known publicly, and then our N-Day customers after it was patched. We’ve also used this research to teach…
Vulnerability Spotlight: Code execution vulnerability in Microsoft Excel https://blog.talosintelligence.com/2020/12/vulnerability-spotlight-excel-rce-dec-patch-tuesday.html?m=1
Talosintelligence
Vulnerability Spotlight: Code execution vulnerability in Microsoft Excel
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
Reversing C++ Without Getting a Heart Attack – DEvirtualize VIrtual Calls With Devi https://insinuator.net/2020/11/reversing-c-without-getting-a-heart-attack-devirtualize-virtual-calls-with-devi/
Cryptominers Exploiting WebLogic RCE CVE-2020-14882 https://thedfirreport.com/2020/11/12/cryptominers-exploiting-weblogic-rce-cve-2020-14882/
The DFIR Report
Cryptominers Exploiting WebLogic RCE CVE-2020-14882
Intro Towards the end of October, we started seeing attackers take advantage of a WebLogic RCE vulnerability (CVE-2020-14882). Recently, SANS ISC talked about this vulnerability being exploited in …
bdshemu: The Bitdefender shellcode emulator https://hvmi.github.io/blog/2020/11/11/bdshemu.html
Advanced MSSQL Injection Tricks https://swarm.ptsecurity.com/advanced-mssql-injection-tricks/
[Linux Kernel Exploitation 0x0] Debugging the Kernel with QEMU https://blog.k3170makan.com/2020/11/linux-kernel-exploitation-0x0-debugging.html
DPWs are the new DPCs : Deferred Procedure Waits in Windows 10 21H1 https://windows-internals.com/dpws-are-the-new-dpcs-deferred-procedure-waits-in-windows-10-21h1/
Introducing x64 emulation in preview for Windows 10 on ARM PCs to the Windows Insider Program https://blogs.windows.com/windows-insider/2020/12/10/introducing-x64-emulation-in-preview-for-windows-10-on-arm-pcs-to-the-windows-insider-program/
Windows Insider Blog
Introducing x64 emulation in preview for Windows 10 on ARM PCs to the Windows Insider Program
Updated 11/16/2021: x64 emulation for Windows is now generally available in Windows 11. For those interested in experiencing this, a PC running Windows 11 on Arm is required. Today, we're releasing the first preview of x64 emulation
How to get root on Ubuntu 20.04 by pretending nobody’s /home https://securitylab.github.com/research/Ubuntu-gdm3-accountsservice-LPE
New APT32 Malware Campaign Targets Cambodian Government https://www.recordedfuture.com/apt32-malware-campaign/
Recordedfuture
New APT32 Malware Campaign Targets Cambodian Government
Recorded Future’s Insikt Group has discovered a new malware campaign targeting the Cambodian government using an ASEAN-themed spearphish.
Nice contribution » Diff tool for comparing symbols in PDB files https://github.com/WalkingCat/SymDiff
GitHub
GitHub - WalkingCat/SymDiff: Diff tool for comparing symbols in PDB files
Diff tool for comparing symbols in PDB files. Contribute to WalkingCat/SymDiff development by creating an account on GitHub.
CVE-2020-16995: Microsoft Azure Network Watcher Linux Extension EoP https://www.intezer.com/blog/cloud-security/cve-2020-16995-microsoft-azure-network-watcher-linux-extension/
Intezer
CVE-2020-16995: Microsoft Azure Network Watcher Linux Extension EoP
Disclosing a vulnerability in Microsoft Azure's VM extension known as the Network Watcher Agent for Linux.
Parent PID Spoofing (Stage 2) Ataware Ransomware – Part 0x3 https://www.securityinbits.com/malware-analysis/parent-pid-spoofing-stage-2-ataware-ransomware-part-3/
Securityinbits
Parent PID Spoofing (Stage 2) Ataware Ransomware - Part 0x3 - Securityinbits
Ataware Ransomware Stage 2 uses Parent PID Spoofing technique to change it parent PID to lsass.exe and download the final Ataware Ransomware.
Cryptofuzz - Differential cryptography fuzzing https://github.com/guidovranken/cryptofuzz
Introduction to Reverse Engineering with Ghidra: A Four Session Course https://wrongbaud.github.io/posts/ghidra-training/
Wrongbaud’s Blog
Introduction to Reverse Engineering with Ghidra: A Four Session Course
A blog focusing on hardware and software reverse engineering
Securing the fight against COVID-19 through open source https://securitylab.github.com/research/securing-the-fight-against-covid19-through-oss