Detecting Use-After-Free vulnerabilities using REVEN https://blog.tetrane.com/2020/vulnerability-detection-use-after-free.html
Escaping VirtualBox 6.1: Part 1 https://secret.club/2021/01/14/vbox-escape.html
secret club
Escaping VirtualBox 6.1: Part 1
This post is about a VirtualBox escape for the latest currently available version (VirtualBox 6.1.16 on Windows). The vulnerabilities were discovered and exploited by our team Sauercl0ud as part of the RealWorld CTF 2020/2021. The vulnerability was known…
Wireshark Tutorial: Examining Emotet Infection Traffic https://unit42.paloaltonetworks.com/wireshark-tutorial-emotet-infection/
Unit 42
Wireshark Tutorial: Examining Emotet Infection Traffic
This Wireshark tutorial reviews recent Emotet activity and provides some tips on identifying this malware based on examining Emotet infection traffic.
Nice paper on attribution! » "Identifying Authorship Style in Malicious Binaries: Techniques, Challenges & Datasets" https://arxiv.org/abs/2101.06124
Understanding “reversed” callstacks in Visual Studio and Perfview with async/await code https://medium.com/criteo-engineering/understanding-reversed-callstacks-in-visual-studio-and-perfview-with-async-await-code-11ebe5769332
Medium
Understanding “reversed” callstacks in Visual Studio and Perfview with async/await code
This post explains why profilers like Visual Studio could display “reversed” callstacks when dealing with async/await code.
Persistent malvertising attacker DCCBoost raged as the year faded https://blog.confiant.com/persistent-malvertising-attacker-dccboost-raged-as-the-year-faded-4d09340cd3f5
Medium
Persistent malvertising attacker DCCBoost raged as the year faded
500k malicious ads served the week leading up to new years eve, over 25M since.
VPNFilter Two Years Later: Routers Still Compromised https://www.trendmicro.com/en_us/research/21/a/vpnfilter-two-years-later-routers-still-compromised-.html
Trend Micro
VPNFilter Two Years Later: Routers Still Compromised
We look into VPNFilter, an IoT botnet discovered over two years ago, to see why there are still routers infected by the malware and what else can be done to minimize its potential risks.
Exploiting CVE-2014-3153 (Towelroot) https://elongl.github.io/exploitation/2021/01/08/cve-2014-3153.html
Elon Gliksberg
Exploiting CVE-2014-3153 (Towelroot)
Understanding The Kernel
Process Herpaderping – Windows Defender Evasion https://pentestlaboratories.com/2021/01/18/process-herpaderping-windows-defender-evasion/
Pentest Laboratories
Process Herpaderping – Windows Defender Evasion
Windows Defender has improved significantly the security posture of Windows environments since it has better detection capabilities compare to other security products. When a process is created Win…
All That for a Coinminer? https://thedfirreport.com/2021/01/18/all-that-for-a-coinminer/
The DFIR Report
All That for a Coinminer? - The DFIR Report
A threat actor recently brute forced a local administrator password using RDP and then dumped credentials using Mimikatz. They not only dumped LogonPasswords but they also exported all Kerberos tickets. The threat actor used Advanced IP Scanner to scan the…
Introduction to Ghidra Scripting for Embedded ELFs and UPX https://www.archcloudlabs.com/projects/ghidra_scripting_01/
Arch Cloud Labs
Introduction to Ghidra Scripting for Embedded ELFs and UPX
About the Project The more Cryptominer malware I look at (or anything targeting Linux), the more trends I’ve identified that are common regardless of the underlying intent. Everyone loves to use UPX.
And why wouldn’t they? It’s a free Open Source packer that…
And why wouldn’t they? It’s a free Open Source packer that…
Training Transformers for Cyber Security Tasks: A Case Study on Malicious URL Prediction https://www.fireeye.com/blog/threat-research/2021/01/training-transformers-for-cyber-security-tasks-malicious-url-prediction.html
Trellix
Research | Trellix Stories
Trellix Research, get the latest cybersecurity trends, best practices, security vulnerabilities, and more from industry leaders.
RIFT: Analysing a Lazarus Shellcode Execution Method https://research.nccgroup.com/2021/01/23/rift-analysing-a-lazarus-shellcode-execution-method/
Windows Exploitation Tricks: Trapping Virtual Memory Access https://googleprojectzero.blogspot.com/2021/01/windows-exploitation-tricks-trapping.html
projectzero.google
Windows Exploitation Tricks: Trapping Virtual Memory Access
Posted by James Forshaw, Project ZeroThis blog is a continuation of my series of Windows exploita...
Flare-On 7 – Task 10 https://hshrzd.wordpress.com/2021/01/05/flare-on-7-task-10/
hasherezade's 1001 nights
Flare-On 7 – Task 10
This year’s FlareOn was very interesting. I managed to finish it with 87th place. In this small series I will describe my favorite tasks, and how I solved them. I hope to provide some educati…
Playing with Process Memory Integrity on Linux https://redcanary.com/blog/process-memory-integrity-linux/
Red Canary
Red Canary
Red Canary
Playing with Process Memory Integrity on Linux environments
Exploit Primitive Playground demostrates how adversaries leverage remote code execution vulnerabilities to execute in-memory payloads.
OWASP Top-10 2021. Statistics-based proposal https://lab.wallarm.com/owasp-top-10-2021-proposal-based-on-a-statistical-data/
Wallarm
OWASP Top-10 2021. Statistics-based proposal. 📄— Wallarm
The statistics-based calculations of OWASP Top Ten 2021 ☝️It's based on an analysis of 2 millions of security reports from 144 public sources
KEMTLS: Post-quantum TLS without signatures https://blog.cloudflare.com/kemtls-post-quantum-tls-without-signatures/
The Cloudflare Blog
KEMTLS: Post-quantum TLS without signatures
The TLS 1.3 protocol has been around for quite some time, but it will be broken once quantum computers arrive. What can we do? In this blog post, we will examine a technique for achieving full post-quantum security for TLS 1.3 in the face of quantum computers:…
ManiMed: Market Analysis https://insinuator.net/2021/01/manimed-part-1/
Insinuator.net
ManiMed: Market Analysis
Manipulating Medical Devices
The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases…
The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases…