Lazarus Group Goes 'Fileless': an implant w/ remote download & in-memory execution https://objective-see.com/blog/blog_0x51.html
objective-see.org
Lazarus Group Goes 'Fileless'
an implant w/ remote download & in-memory execution
Good book from OWASP about TOCTOU vulnerabilities! » OWASP TimeGap Theory Handbook https://raw.githubusercontent.com/OWASP/TimeGap-Theory/master/OWASP%20TimeGap%20Theory%20Handbook.pdf
[Symbolic Execution 0x0] Solving easy CTFs with Angr and Symbolic Execution http://blog.k3170makan.com/2019/12/symbolic-execution-0x0-solving-easy.html
K3170Makan
[Symbolic Execution 0x0] Solving easy CTFs with Angr and Symbolic Execution
Hacking,Information Security,Penetration Testing,Google Hacking,Google Dorking,Keith Makan,Black Hat,Security Research,InfoSec,Web Site Security
Additional Analysis into the SUNBURST Backdoor https://www.mcafee.com/blogs/other-blogs/mcafee-labs/additional-analysis-into-the-sunburst-backdoor/
McAfee Blogs
McAfee Blogs
McAfee Blog
Additional Analysis into the SUNBURST Backdoor | McAfee Blog
Executive Summary There has been considerable focus on the recent disclosures associated with SolarWinds, and while existing analysis on the broader
Open-sourcing api-diff, a tool for side-by-side evaluations of JSON APIs https://radar.io/blog/open-source-api-diff-library
Radar Blog
Open-sourcing api-diff, a tool for side-by-side evaluations of JSON APIs
We’re open-sourcing our api-diff tool to help developers confidently iterate on their own search and ranking APIs.
Talos tools of the trade: https://blog.talosintelligence.com/2020/12/talos-tools-of-trade.html
Cisco Talos Blog
Talos tools of the trade
By Andrea Marcelli and Holger Unterbrink.
If you're looking for something to keep you busy while we're all stuck inside during the holidays, Cisco Talos has a few tools for you you can play with in the coming days and weeks.
We recently updated GhIDA to…
If you're looking for something to keep you busy while we're all stuck inside during the holidays, Cisco Talos has a few tools for you you can play with in the coming days and weeks.
We recently updated GhIDA to…
Protecting Against an Unfixed Kubernetes Man-in-the-Middle Vulnerability (CVE-2020-8554) https://unit42.paloaltonetworks.com/cve-2020-8554/
Unit 42
Protecting Against an Unfixed Kubernetes Man-in-the-Middle Vulnerability (CVE-2020-8554)
A currently unpatched, medium-severity issue affecting all Kubernetes versions, CVE-2020-8554 can be mitigated in several ways.
Really nice write-up! » Exploiting a Single Instruction Race Condition in Binder https://blog.longterm.io/cve-2020-0423.html
Fixing a Google Vulnerability https://security.love/blog/gcp/2020/11/22/lateral-movement-and-privesc-in-GCP.html
GCP Privlige Escalation and Lateral Movement
Fixing a Google Vulnerability
Overview This post details the journey it took to get Google issue numbers 134447889 and 155544987 closed out and resolved.
Bypassing Control Flow Guard in Windows 10 https://improsec.com/tech-blog/bypassing-control-flow-guard-in-windows-10
Improsec | improving security
Bypassing Control Flow Guard in Windows 10 — Improsec | improving security
In June of 2016 Theori published a blog post on an Internet Explorer vulnerability which was patched in MS16-063, the exploit they wrote was for Internet Explorer 11 on Windows 7, and as their own blog post indicates the exploit will not work on Windows 10…
Two Critical Flaws — CVSS Score 10 — Affect Dell Wyse Thin Client Devices https://thehackernews.com/2020/12/two-critical-flaws-cvss-score-10-affect.html
Detect RC4 in (malicious) binaries https://0xc0decafe.com/2020/12/23/detect-rc4-in-malicious-binaries/
0xC0DECAFE.com
Learn to quickly detect RC4 encryption in (malicious) binaries - 0xC0DECAFE.com
This blog post discusses how to detect RC4 encryption with you bare eyes and how you can leverage additional tools like capa or yara for its detection.
CVE-2020-9967 - Apple macOS 6LowPAN Vulnerability https://alexplaskett.github.io/CVE-2020-9967/
Amit Merchant - Software Engineer
CVE-2020-9967 - Apple macOS 6LowPAN Vulnerability
Inspired by Kevin Backhouse’s great work on finding XNU remote vulnerabilities I decided to spend some time looking at CodeQL and performing some variant analysis. This lead to the discovery of a local root to kernel (although documented by Apple as remote)…
CVE-2020-35489: Unrestricted File Upload Vulnerability found in Contact Form 7 plugin affects 5M+ websites https://blog.wpsec.com/contact-form-7-vulnerability/
WPSec
CVE-2020-35489: Unrestricted File Upload Vulnerability found in Contact Form 7 plugin affects 5M+ websites - WPSec
A high-severity Unrestricted File Upload vulnerability, tracked as CVE-2020–35489, was discovered in a popular WordPress plugin called Contact Form 7, currently installed on 5 Million+ websites making them vulnerable to attacks like phishing, complete site…
iBackDoor: High-Risk Code Hits iOS Apps https://www.fireeye.fr/blog/threat-research/2015/11/ibackdoor_high-risk.html
FireEye
iBackDoor: High-Risk Code Hits iOS Apps
FireEye mobile researchers recently discovered potentially “backdoored” versions of an ad library embedded in thousands of iOS apps originally published in the Apple App Store.
SUNBURST Additional Technical Details https://www.fireeye.com/blog/threat-research/2020/12/sunburst-additional-technical-details.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
Mobile Physical Memory Security https://corellium.com/blog/mobile-physical-memory-security
Corellium
Hardware Design Patterns for Better Physical Memory Security | Diagrams
Physical memory security is a key, but often overlooked, element of mobile hardware security. Recognizing design patterns greatly benefits mobile security researchers.
Although the decision was initially to close it, last news is Accenture Security will keep it alive! https://www.securityfocus.com/archive/1/542248 :) https://twitter.com/roman_soft/status/1350426455478566912?s=09
Twitter
☠ Román Medina-Heigl Hernández
Off since ~1y ago but now it's official: Bugtraq mailing list will be closed in 2 weeks :-((((( I'd like to express my gratitude for all these years of continuous service to the Security Community. Thank you Scott, "Aleph1", Ahmad, McKinney and rest of ppl…