ManiMed: Market Analysis https://insinuator.net/2021/01/manimed-part-1/
Insinuator.net
ManiMed: Market Analysis
Manipulating Medical Devices
The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases…
The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases…
DNS Hijacking – Taking Over Top-Level Domains and Subdomains https://blog.detectify.com/2021/01/19/dns-hijacking-taking-over-top-level-domains-and-subdomains/
Detectify Blog
DNS Hijacking – Taking Over Top-Level Domains and Subdomains - Detectify Blog
An ethical hacker recently claimed a country-code top-level domain. Learn how this DNS hijacking occured and more on subodmain takeovers
Windows 7 TCP/IP hijacking http://blog.pi3.com.pl/?p=850
Defeat Bitdefender total security using windows API unhooking to perform process injection https://shells.systems/defeat-bitdefender-total-security-using-windows-api-unhooking-to-perform-process-injection/
Shells.Systems
Defeat Bitdefender total security using windows API unhooking to perform process injection - Shells.Systems
Estimated Reading Time: 14 minutesBypassing endpoint protections such as AVs/EDRs is a phase that you need to take care of when you prepare for your red team operation, it could take some time to understand how these solutions are working before you try…
Remotely Exploitable 0day in Internet Explorer Gets a Free Micropatch https://blog.0patch.com/2021/02/remotely-exploitable-0day-in-internet.html
Nice presentation on Windows Process Hollowing (by @ochsenmeier) https://www.winitor.com/pdf/Windows-Process-Hollowing.pdf
Emulation of Kernel Mode Rootkits With Speakeasy https://www.fireeye.de/blog/threat-research/2021/01/emulation-of-kernel-mode-rootkits-with-speakeasy.html
FireEye
Emulation of Kernel Mode Rootkits With Speakeasy
In this blog post we discuss how Speakeasy can be effective at automatically identifying rootkit activity from the kernel mode binary.
Ghidra 101: Decoding Stack Strings https://www.tripwire.com/state-of-security/security-data-protection/ghidra-101-decoding-stack-strings/
Tripwire
Ghidra 101: Decoding Stack Strings
This stack string technique is a way for a programmer to obscure string data within a program by blending it as opaque operand instructions
Reverse Engineering iMessage: Leveraging the Hardware to Protect the Software https://www.nowsecure.com/blog/2021/01/27/reverse-engineering-imessage-leveraging-the-hardware-to-protect-the-software/
Nowsecure
Reverse Engineering iMessage to Help Improve Security | NowSecure
Our researcher reverse engineered Apple iMessage to explore extending it the secure messaging app to other systems. See how he fared.
nice vuln report >> Heap-based buffer overflow in Sudo (CVE-2021-3156) https://www.qualys.com/2021/01/26/cve-2021-3156/baron-samedit-heap-based-overflow-sudo.txt
DNSpooq - dnsmasq cache poisoning (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685) https://github.com/knqyf263/dnspooq
GitHub
GitHub - knqyf263/dnspooq: DNSpooq - dnsmasq cache poisoning (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685)
DNSpooq - dnsmasq cache poisoning (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685) - knqyf263/dnspooq
Detecting zero days in software supply chain with static and dynamic analysis https://ajinabraham.com/blog/detecting-zero-days-in-software-supply-chain-with-static-and-dynamic-analysis
Ajin Abraham
Detecting zero days in software supply chain with static and dynamic analysis
This blog shares some ideas about detecting zero-days in the software supply chain even before they get flagged by your typical Software Composition Analysis (SCA) or Dependency checking tools. Also shares the proof of concept code to detect malicious behavior…
Too much % makes Event Viewer drunk http://www.hexacorn.com/blog/2019/01/27/too-much-makes-event-viewer-drunk/
New campaign targeting security researchers https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/
Google
New campaign targeting security researchers
Details on an ongoing campaign, which we attribute to a government-backed entity based in North Korea, targeting security researchers working on vulnerability research and development.
Nice analysis from 360 >> Necro is going to version 3 and using PyInstaller and DGA https://blog.netlab.360.com/necro/
360 Netlab Blog - Network Security Research Lab at 360
Necro is going to version 3 and using PyInstaller and DGA
Overview.
Necro is a classic family of botnet written in Python that was first discovered in 2015, at the beginning, it targeted Windows systems and often tagged by security vendors as Python.IRCBot and called N3Cr0m0rPh (Necromorph) by the author himself.…
Necro is a classic family of botnet written in Python that was first discovered in 2015, at the beginning, it targeted Windows systems and often tagged by security vendors as Python.IRCBot and called N3Cr0m0rPh (Necromorph) by the author himself.…
Déjà vu-lnerability: A Year in Review of 0-days Exploited In-The-Wild in 2020 https://googleprojectzero.blogspot.com/2021/02/deja-vu-lnerability.html
Blogspot
Déjà vu-lnerability
A Year in Review of 0-days Exploited In-The-Wild in 2020 Posted by Maddie Stone, Project Zero 2020 was a year full of 0-day exploits. Many o...
Critical RCE and SLP Protocol Vulnerabilities in VMWare https://securityboulevard.com/2021/02/critical-rce-and-slp-protocol-vulnerabilities-in-vmware
Security Boulevard
Critical RCE and SLP Protocol Vulnerabilities in VMWare
The post Critical RCE and SLP Protocol Vulnerabilities in VMWare appeared first on Fidelis Cybersecurity.
Major Vulnerabilities discovered and patched in Realtek RTL8195A Wi-Fi Module https://www.vdoo.com/blog/realtek-rtl8195a-vulnerabilities-discovered
CVE-2020-XXXXX - Getting root on webOS https://blog.recurity-labs.com/2021-02-03/webOS_Pt1.html
hadowMove: Lateral Movement by Duplicating Existing Sockets https://www.ired.team/offensive-security/lateral-movement/shadowmove-lateral-movement-by-stealing-duplicating-existing-connected-sockets
www.ired.team
ShadowMove: Lateral Movement by Duplicating Existing Sockets | Red Team Notes