Nice chart about the connections between cybercrime groups » https://www.zdnet.com/article/this-chart-shows-the-connections-between-cybercrime-groups/
ZDNET
This chart shows the connections between cybercrime groups
CrowdStrike puts together a list of connections and how cybercrime groups cooperate with each other.
1Password has none, KeePass has none... So why are there seven embedded trackers in the LastPass Android app? https://www.theregister.com/2021/02/25/lastpass_android_trackers_found/
The Register
1Password has none, KeePass has none... So why are there seven embedded trackers in the LastPass Android app?
Third-party code in security-critical apps is obviously suboptimal, but company says you can opt out
Network Graph Analysis for Suricata and Zeek using Brim and NetworkX https://medium.com/brim-securitys-knowledge-funnel/visualizing-network-cyber-attacks-with-suricata-and-zeek-using-brim-and-networkx-332dd265d4b6
Medium
Visualizing Network Cyber Attacks with Suricata and Zeek using Brim and NetworkX
Gaining meaningful Insights out of Security Data
VMware vCenter Server CVE-2021-21972 Remote Code Execution Vulnerability checker https://github.com/alt3kx/CVE-2021-21972
GitHub
GitHub - alt3kx/CVE-2021-21972
Contribute to alt3kx/CVE-2021-21972 development by creating an account on GitHub.
An Exploration of JSON Interoperability Vulnerabilities https://labs.bishopfox.com/tech-blog/an-exploration-of-json-interoperability-vulnerabilities
Bishop Fox
An Exploration & Remediation of JSON Interoperability Vulnerabilities
Learn more about how the same JSON document can be parsed with different values across microservices, leading to a variety of potential security risks.
Nice discussion on the need of changing CVSS, as it does not reflect appropriately the risks to a vulnerable system » "Time to Change the CVSS?" https://ieeexplore.ieee.org/abstract/document/9382369
ieeexplore.ieee.org
Time to Change the CVSS?
According to its creators, the Common Vulnerability Scoring System (CVSS) "provides a way to capture the principal characteristics of a vulnerability ... reflecting its severity ... to help organizations properly assess and prioritize their vulnerability…
POCs for Shellcode Injection via Callbacks https://github.com/ChaitanyaHaritash/Callback_Shellcode_Injection
GitHub
GitHub - ChaitanyaHaritash/Callback_Shellcode_Injection: POCs for Shellcode Injection via Callbacks
POCs for Shellcode Injection via Callbacks. Contribute to ChaitanyaHaritash/Callback_Shellcode_Injection development by creating an account on GitHub.
It's always important to refresh our knowledge » A brief introduction to PE format https://medium.com/ax1al/a-brief-introduction-to-pe-format-6052914cc8dd
Medium
A brief introduction to PE format
good idea » A Journey Combining Web Hacking and Binary Exploitation in Real World! https://blog.orange.tw/2021/02/a-journey-combining-web-and-binary-exploitation.html
Orange Tsai
A Journey Combining Web Hacking and Binary Exploitation in Real World!
Hi, this blog post is just a short post to address the technique part in one of my Red Team cases last year. I believe it’s worth sharing, so I reproduced this in my lab environment and made this topi
D-LINKGATE - A Preauth RCE to Root Chain on D-Link https://suid.ch/research/DAP-2020_Preauth_RCE_Chain.html
Pwn2Own Tokyo 2020: Defeating the TP-Link AC1750 https://www.synacktiv.com/en/publications/pwn2own-tokyo-2020-defeating-the-tp-link-ac1750.html
Synacktiv
Pwn2Own Tokyo 2020: Defeating the TP-Link AC1750
write-up » Hack The Box: Passage https://khaoticdev.net/hack-the-box-passage/
About the security content of iOS 14.4.1 and iPadOS 14.4.1 https://support.apple.com/en-us/HT212221
Apple Support
About the security content of iOS 14.4.1 and iPadOS 14.4.1
This document describes the security content of iOS 14.4.1 and iPadOS 14.4.1.
VU#782301: pppd vulnerable to buffer overflow due to a flaw in EAP packet processing https://www.kb.cert.org/vuls/id/782301/
www.kb.cert.org
CERT/CC Vulnerability Note VU#782301
pppd vulnerable to buffer overflow due to a flaw in EAP packet processing
Bazar Drops the Anchor https://thedfirreport.com/2021/03/08/bazar-drops-the-anchor/
The DFIR Report
Bazar Drops the Anchor
Intro The malware identified as Anchor first entered the scene in late 2018 and has been linked to the same group as Trickbot, due to similarities in code and usage of the two different malware families in the same intrusions. In 2020 the Bazar malware family…
New SUNSHUTTLE Second-Stage Backdoor Uncovered Targeting U.S.-Based Entity; Possible Connection to UNC2452 https://www.fireeye.com/blog/threat-research/2021/03/sunshuttle-second-stage-backdoor-targeting-us-based-entity.html
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
Qualcomm IPQ40xx: Analysis of Critical QSEE Vulnerabilities https://raelize.com/blog/qualcomm-ipq40xx-analysis-of-critical-qsee-vulnerabilities/
Raelize
Qualcomm IPQ40xx: Analysis of Critical QSEE Vulnerabilities
Raelize provides top-notch embedded device security serrvices like consultancy, testing, research and training.
Zero-day vulnerabilities in Microsoft Exchange Server https://securelist.com/zero-day-vulnerabilities-in-microsoft-exchange-server/101096/
Securelist
Zero-day vulnerabilities in Microsoft Exchange Server
The four vulnerabilities inside Microsoft Exchange Server allow an attacker to gain access to all registered email accounts, or to execute arbitrary code (RCE) within the Exchange Server context.
Automated Detection of Control-flow Flattening https://synthesis.to/2021/03/03/flattening_detection.html