RESTler: a (stateful) REST API fuzzing tool for automatically testing cloud services through their REST APIs (from Microsoft!) https://github.com/microsoft/restler-fuzzer
GitHub
GitHub - microsoft/restler-fuzzer: RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services…
RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services. - microsoft/restler...
Dissecting APT21 samples using a step-by-step approach https://cybergeeks.tech/dissecting-apt21-samples-using-a-step-by-step-approach/
Securing RDP Connections with Trusted SSL/TLS Certificates http://woshub.com/securing-rdp-connections-trusted-ssl-tls-certificates/
Windows OS Hub
Using SSL/TLS Certificates for Remote Desktop (RDP) | Windows OS Hub
This article aims to help administrators manage SSL/TLS certificates used to secure RDP connections in Windows. First, we will look at how to replace a self-signed RDP certificate with a…
Linux kernel heap quarantine versus use-after-free exploits https://a13xp0p0v.github.io/2020/11/30/slab-quarantine.html
Alexander Popov
Linux kernel heap quarantine versus use-after-free exploits
It's 2020. Quarantines are everywhere – and here I'm writing about one, too. But this quarantine is of a different kind. In this article I'll describe the Linux Kernel Heap Quarantine that I developed for mitigating kernel use-after-free exploitation.
CVE-2020-14418: madCodeHook Library Local Privilege Escalation https://labs.nettitude.com/blog/cve-2020-14418-madcodehook-library-local-privilege-escalation/
LRQA
CVE-2020-14418: madCodeHook Library Local Privilege Escalation
Nettitude discovered a vulnerability in the ‘madCodeHook’ third party library which caused a number of security products, including Cisco AMP and Morphisec Unified Threat Prevention Platform, to contain a local privilege escalation vulnerability.
An iOS zero-click radio proximity exploit odyssey https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-click-radio-proximity.html
projectzero.google
An iOS zero-click radio proximity exploit odyssey
Posted by Ian Beer, Project ZeroNOTE: This specific issue was fixed before the launch of Privacy-...
iOS 1-day hunting: uncovering and exploiting CVE-2020-27950 kernel memory leak https://www.synacktiv.com/publications/ios-1-day-hunting-uncovering-and-exploiting-cve-2020-27950-kernel-memory-leak.html
Synacktiv
iOS 1-day hunting: uncovering and exploiting CVE-2020-27950 kernel
PyOracle2: a python-based padding oracle exploitation tool https://blog.liquidsec.net/2020/11/30/introducing-pyoracle2/
Paul Mueller (@paulmmueller)
Introducing PyOracle2
I’d like to introduce PyOracle2. It is a python-based padding oracle exploitation tool. Why make another tool? Yes, several other padding oracle exploitation tools already exist. Some of them are r…
Threat actor leverages coin miner techniques to stay under the radar – here’s how to spot them https://www.microsoft.com/security/blog/2020/11/30/threat-actor-leverages-coin-miner-techniques-to-stay-under-the-radar-heres-how-to-spot-them/
Microsoft News
Threat actor leverages coin miner techniques to stay under the radar – here’s how to spot them
BISMUTH, which has been running increasingly complex cyberespionage attacks as early as 2012, deployed Monero coin miners in campaigns from July to August 2020. The group's use of coin miners was unexpected, but it was consistent with their longtime methods…
2020: The year in malware https://blog.talosintelligence.com/2020/12/2020-year-in-malware.html
Cisco Talos
2020: The year in malware
By Jon Munshaw. Nothing was normal in 2020. Our ideas of working from offices, in-person meetings, hands-on learning and basically everything else was thrown into disarray early in the year. Since then, we defenders have had to adapt. But so have workers…
Nice reading of an old friend :) » Hindering Threat Hunting, a tale of evasion in a restricted environment https://www.blackarrow.net/hindering-threat-hunting-a-tale-of-evasion-in-a-restricted-environment/
Tarlogic Security
BlackArrow - Offensive security services
BlackArrow is the offensive and defensive security services division of Tarlogic Security. A team of high level professionals
Bug or Feature: Privilege Escalation in Windows Autopilot https://sec-consult.com/en/blog/2020/11/bug-oder-feature-privilege-escalation-in-windows-autopilot/
SEC Consult
Bug Or Feature: Privilege Escalation In Windows Autopilot
SEC Consult identified a local privilege escalation vulnerability in the Windows Autopilot deployment process.
Shadows from the past threaten Italian enterprises https://yoroi.company/research/shadows-from-the-past-threaten-italian-enterprises/
Tinexta Cyber
Il polo italiano della Cyber Security
Innovazione digitale sicura Protezione per un futuro digitale resiliente Tinexta Cyber è il polo italiano della cyber security. Parte del gruppo Tinexta, nasce dalla sintesi di tre eccellenze – Corvallis, Swascan e Yoroi – con l’obiettivo di supportare le…
BruteShark: a Network Forensic Analysis Tool (NFAT) that performs deep processing and inspection of network traffic https://github.com/odedshimon/BruteShark
GitHub
GitHub - odedshimon/BruteShark: Network Analysis Tool
Network Analysis Tool. Contribute to odedshimon/BruteShark development by creating an account on GitHub.
"Old but gold" » How to get every detail about SSDT , GDT , IDT in a blink of an eye https://rayanfam.com/topics/how-to-get-every-details-about-ssdt-gdt-idt-in-a-blink-of-an-eye/
Rayanfam Blog
How to get every detail about SSDT , GDT , IDT in a blink of an eye
We write about Windows Internals, Hypervisors, Linux, and Networks.
How anti-fingerprinting extensions tend to make fingerprinting easier https://palant.info/2020/12/10/how-anti-fingerprinting-extensions-tend-to-make-fingerprinting-easier/
Almost Secure
How anti-fingerprinting extensions tend to make fingerprinting easier
Browser extensions claiming to protect against fingerprinting will typically result in more data available for fingerprinting.
This is for the Pwners: Exploiting a WebKit 0-day in PlayStation 4 https://www.synacktiv.com/publications/this-is-for-the-pwners-exploiting-a-webkit-0-day-in-playstation-4.html
Synacktiv
This is for the Pwners: Exploiting a WebKit 0-day in PlayStation 4
WES-NG provides the list of vulnerabilities the Windows OS is vulnerable to, including any exploits for these vulnerabilities https://github.com/bitsadmin/wesng
GitHub
GitHub - bitsadmin/wesng: Windows Exploit Suggester - Next Generation
Windows Exploit Suggester - Next Generation. Contribute to bitsadmin/wesng development by creating an account on GitHub.
CVE-2020-17143 and CVE-2020-17141 PoCs (XXE bugs against Exchange Server) https://twitter.com/steventseeley/status/1337415647593107457?s=20
Twitter
ϻг_ϻε
I provided PoC exploits for CVE-2020-17143 and CVE-2020-17141 which demonstrate the XXE bugs against Exchange Server. - Low privileged authentication only - CVE-2020-17141 is interesting because its in the EWS API https://t.co/yYB8Frzwsl https://t.co/wmtGRPMpVB