A brief daily summary of what is important in information security. The podcast is published every weekday and designed to get you ready for the day with a brief, usually 5 minutes long summary of current network security related events. The content is late breaking, educational and based on listener input as well as on input received by the SANS Internet Storm Center. You may submit questions and comments via our contact form at https://isc.sans.edu/contact.html .
Linux Shell Forensic: Let s Dive Into Atuin!
https://isc.sans.edu/diary/Linux+Shell+Forensic+Lets+Dive+Into+Atuin/33226
Apple Patches macOS Screen Sharing Vulnerability
https://support.apple.com/en-us/148170
More N-Able N-Central Issues
https://www.n-able.com/blog/n-central-security-update-august-6-2026
Metabase Unauthenticated SQL injection
https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary]
https://isc.sans.edu/diary/22+Seconds+to+Compromise+How+Automated+SSH+Actors+Move+From+Login+to+Persistence+Before+You+Can+Blink+Guest+Diary/33220
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/
Ill Bloom: Crypto Wallet Vulnerability
https://illbloom.org
Benchmarking Free-Tier Large Language Models as Cognitive Aids for Operationalizing Unstructured Cyber Threat Intelligence
https://www.sans.edu/cyber-research/benchmarking-free-tier-large-language-models-cognitive-aids-operationalizing-unstructured-cyber-threat-intelligence
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm
https://isc.sans.edu/diary/Don%27t%20Revoke%20That%20Token%20Yet%3A%20Inside%20the%20keyv%20cacheable%20npm%20Worm/33218
IP and DNS Leaks in WebKit Affecting Proxy Browsers and Apple iCloud Private Relay
https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/?ref=404media.co
COLDCARD Issues
https://x.com/threatinsight/status/2084328552481112429
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Botnet Hunting for Vulnerabilities in Diagnostic Tools
https://isc.sans.edu/diary/Botnet%20Hunting%20for%20Vulnerabilities%20in%20Diagnostic%20Tools/33214
Inside Greatness: Telegram-Distributed M365 AiTM PhaaS
https://zerobec.com/blog/greatness-phaas-aitm-and-device-code-phishing
A Deep Dive Into the Latest XCSSET Version
https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
Strengthening NuGet Supply Chain Security: Reducing API Key Lifetime
https://devblogs.microsoft.com/dotnet/strengthening-nuget-supply-chain-security-reducing-api-key-lifetime/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
AUR packages adoption disabled
https://lists.archlinux.org/archives/list/aur-general@lists.archlinux.org/thread/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP/
Apple's iCloud File Sharing Left Ex-Employees With Access to Secret Documents
https://www.macrumors.com/2026/08/03/apple-icloud-sharing-ex-employees/
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
https://unit42.paloaltonetworks.com/passwordless-authentication-security-risks/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
zipdump.py Metadata Encoding
https://isc.sans.edu/diary/zipdumppy+Metadata+Encoding/33202/
Atomic MacOS (AMOS) stealer infection
https://isc.sans.edu/diary/Atomic%20MacOS%20%28AMOS%29%20stealer%20infection/33208
Phishing Campaigns Targeting AI Solutions Providers
https://isc.sans.edu/diary/Phishing+Campaigns+Targeting+AI+Solutions+Providers/33206/
Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner
https://isc.sans.edu/diary/Reconnaissance%20First%3A%20An%20SSH%20Bot%20That%20Sizes%20Up%20Your%20Hardware%20Before%20Deploying%20a%20Miner%20%5BGuest%20Diary%5D/33198
Cisco Secure Firewall Management Center Software Static Credential Vulnerability Exploited CVE-2026-20316
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
Inconsistent Group Chats
https://www.usenix.org/conference/usenixsecurity26/presentation/gegenhuber
https://www.heise.de/en/news/Encrypted-but-wrong-Group-chats-vulnerable-to-manipulated-content-11384112.html
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Apple Patch Summary / Postscript
https://isc.sans.edu/diary/Apple%20Patches%20Everything%20%28July%202026%29/33196
IPMI Admin Password Hash Leak
https://lavahq.io/research/bmc-exposure-alert
Patches for VMWare
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
OpenWRT Patch, odhcpd vulnerability CVE-2026-53921
https://github.com/openwrt/odhcpd/security/advisories/GHSA-7fwx-hhrg-3496
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
AutoIT Payload Injector
https://isc.sans.edu/diary/AutoIT%20Payload%20Injector%20/33192
Apple Security Update
https://support.apple.com/en-us/100100
SourTrade: Browser-Assembled Malware Delivered Through Malvertising
https://blog.confiant.com/p/sourtrade-browser-assembled-malware
NGINX Exploit CVE-2026-42530, CVE-2026-42533
https://github.com/DepthFirstDisclosures/Nginx-Rift/tree/main
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Java Spring Boot "heapdump" scans
https://isc.sans.edu/diary/Java%20Spring%20Boot%20%22heapdump%22%20scans/33188
VBULLETIN RUNTIME TEMPLATE RUNMATHS PREAUTH RCE
https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
Microsoft Defender for Linux Update may disable restart
https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases#issues-have-been-found-with-versions-101260420000101260420009
MongoDB Updates CVE-2026-13072
https://github.com/advisories/GHSA-wvx7-gr2m-7rf5
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Scans for ESAFENET CDG 3 Document Management System Weak Logins
https://isc.sans.edu/diary/Scans%20for%20ESAFENET%20CDG%203%20Document%20Management%20System%20Weak%20Logins/33184
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/
Silent Replacement of Trusted macOS App Executables
https://mysk.blog/2026/07/23/macos-overwrite-app-executables/
GitHub and PyPi Defense updates
https://github.blog/security/supply-chain-security/the-case-for-a-cooldown-why-dependabot-now-waits-before-issuing-version-updates/
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-14-days/
https://www.bleepingcomputer.com/news/security/github-pypi-add-time-absed-defenses-against-supply-chain-attacks/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
When the "Autonomous Attacker" Is Your Own AI Model
https://isc.sans.edu/diary/When%20the%20%22Autonomous%20Attacker%22%20Is%20Your%20Own%20AI%20Model/33180
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
https://cert.gov.ua/article/6318634
https://cybersecuritynews.com/hackers-abuse-notepad-plugins/
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Rondo Meets Geoserver
https://isc.sans.edu/diary/Rondo%20Meets%20Geoserver/33176
Oracle July Patch Update
https://www.oracle.com/security-alerts/cpujul2026.html
OpenAI and Hugging Face partner to address security incident during model evaluation
https://openai.com/index/hugging-face-model-evaluation-security-incident/
Checkpoint July 2026 Security Advisory (CVE-2026-16232)
https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Captive Portal Detection
https://isc.sans.edu/diary/Captive%20Portal%20Detection/33172
Critical SolarWinds Serv-U Update
https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
Zimbra Update with Critical Security Fixes
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
Apple Fixed Hide My E-Mail Leak
https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
WordPress Exploitation Underway (CVE-2026-63030)
https://isc.sans.edu/diary/WordPress%20Exploitation%20Underway%20%28CVE-2026-63030%29/33168
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
https://www.group-ib.com/blog/hollowgraph-microsoft-365/
Gitea Vulnerablity CVE-2026-58443
https://github.com/go-gitea/gitea/security/advisories/GHSA-xxjv-752h-3vp2
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Scans for Hikvision Intelligent Security API
https://isc.sans.edu/diary/Scans%20for%20Hikvision%20Intelligent%20Security%20API/33164
LG Monitor Spyware
https://www.techradar.com/televisions/lgs-gaming-monitors-and-tvs-are-facing-a-user-revolt https://www.youtube.com/watch?v=Q9uefFYe6bM
Huggingface Hack
https://huggingface.co/blog/security-incident-july-2026
Wordpress Core RCE
https://wp2shell.com
German Federal Information Security Office Analyzes Windows Hello for Business
https://www.heise.de/en/news/BSI-dissects-Windows-Hello-Where-Microsoft-s-login-reaches-its-limits-11366125.html
https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/Studies/Windows_dissected/AP1_Windows-Hello-for-Business.pdf?__blob=publicationFile&v=7
NGINX Vulnerability
https://my.f5.com/manage/s/article/K000162097
7-Zip XZ Decompression CVE-2026-14266
https://www.zerodayinitiative.com/advisories/ZDI-26-444/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
DShield SIEM Update
https://isc.sans.edu/diary/Recent%20DShield%20SIEM%20Update/33156
Microsoft Patch Tuesday vs. Dell Intel Innovation Platform Framework (IPF) drivers
https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875
Zoom Account Takeover Patch
https://www.zoom.com/en/trust/security-bulletin/zsb-26014/
Forgotten UEFI shims undermining Secure Boot
https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Here
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202026%20-%20The%20AI%20Acopolypse%20is%20Here%20/33154
LegacyHive : Windows user profile service arbitrary hive load elevation of privileges vulnerability
https://git.projectnightcrawler.dev/NightmareEclipse/LegacyHive
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero-day-flaw-behind-storage-zone-shutdown/
xAI/Grok Exfiltrating Data and Secrets
https://cereblab.com
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials
https://isc.sans.edu/diary/Someone%20Is%20Scanning%20for%20Your%20MCP%20Servers%20and%20AI%20Assistant%20Credentials/33150
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-194a
OAuth Client ID Spoofing
https://www.proofpoint.com/us/blog/threat-insight/oauth-client-id-spoofing-why-fake-client-ids-are-gaining-traction-stealthy
Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854
https://www.veeam.com/kb4869
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Progress Sharefile Emergency Shutdown Notice
https://status.sharefile.com
https://www.reddit.com/r/sysadmin/comments/1usohco/psa_shutdown_your_sharefile_storage_zone/
https://www.bleepingcomputer.com/news/security/progress-urges-sharefile-customers-to-shut-down-servers-over-credible-threat/
U-Boot Vulnerabilities
https://www.binarly.io/blog/unfit-to-boot-breaking-u-boots-fit-signature-verification
Nightmare Eclipse Releases Next Microsoft Defender Exploit
https://blog.projectnightcrawler.dev/posts/2026-07-09-some-interesting-findings-in-windows-defender/
Cisco Increases Patch Cadence
https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary]
https://isc.sans.edu/diary/_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_%20%5BGuest%20Diary%5D/33130
Apple Discontinuing Support for Encrypted Mac OS Extended disks in macOS 28
https://support.apple.com/en-us/125615
Google Chrome Update
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html
Microsoft Patches Rogue Planet Vulnerability CVE-2026-50656
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
My Stack Simulator https://isc.sans.edu/diary/My%20Stack%20Simulator/33138
RootAsRole
https://github.com/LeChatP/RootAsRole
Hoymiles Inverter Vulnerability
https://www.ccc.de/system/uploads/382/original/hoymiles_dtu_vuln.pdf
Git Hash Chain Malleability
https://arxiv.org/abs/2607.02820
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
More Odd DNS Records: NIMLOC
https://isc.sans.edu/diary/More%20Odd%20DNS%20Records%3A%20NIMLOC/33128
From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations
https://www.seqrite.com/blog/from-invoice-to-anydesk-uncovering-a-phishing-campaign-targeting-russian-aerospace-organizations/
Tenda firmware (multiple versions) contains hidden authentication backdoor
https://kb.cert.org/vuls/id/213560
GitLost: GitHub AI Agent Leak
https://noma.security/wp-content/uploads/GitLostWorkflow_2.gif
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
RCS and DNS: The NAPTR Record
https://isc.sans.edu/diary/RCS%20and%20DNS%3A%20The%20NAPTR%20Record/33124
OpenSSH 10.4 released
https://seclists.org/oss-sec/2026/q3/62
Beyond Trust Advisory CVE-2026-40138 CVE-2026-40139
https://www.beyondtrust.com/trust-center/security-advisories/bt26-03
PolinRider: North Korea-Linked Supply Chain Campaign
https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Apple Updated Patch Policy
https://www.reuters.com/business/apple-says-it-is-releasing-updates-early-response-ai-cybersecurity-concerns-2026-06-29/
T3MP3ST multi-agent offensive-security framework
https://github.com/elder-plinius/T3MP3ST
Seven FatFs bugs, one very large blast radius
https://www.runzero.com/blog/fatfs-bugs/
OpenWRT Releases v25.12.5
https://github.com/openwrt/openwrt/releases
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Why Ask Credentials If There Are Secret Codes?
https://isc.sans.edu/diary/Why%20Ask%20Credentials%20If%20There%20Are%20Secret%20Codes%3F/33118
Adobe Patches and Updated Patch Release Policy
https://helpx.adobe.com/security/Home.html
https://blog.adobe.com/security/protecting-customers-faster-how-adobe-is-responding-to-ai-accelerated-vulnerability-discovery
Google Chrome Update (link had issues loading while recording)
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0175352312.html
Apple Hide My Email Vulnerability
https://www.404media.co/apple-hide-my-email-vulnerability-reveals-peoples-real-email-addresses/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
June 2026 Apple Updates
https://isc.sans.edu/diary/June%202026%20Apple%20Updates/33114
SimpleHelp Exploit used to reply TaskWeaver
https://blackpointcyber.com/blog/a-djinn-in-the-machine-taskweavers-node-js-intrusion-chain/
DNS Tricks to Load Malware into Cloned Repository
https://0din.ai/blog/clone-this-repo-and-i-own-your-machine
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Adding some Automation to the favicon.ico method of Host Recon
https://isc.sans.edu/diary/Adding%20some%20Automation%20to%20the%20favicon.ico%20method%20of%20Host%20Recon/33110
Russian Intelligence Services Continue to Target Commercial Messaging Applications
https://www.ic3.gov/PSA/2026/PSA260626
Google Gemini CLI Vulnerability CVE-2026-12537
https://github.com/advisories/GHSA-jj69-4grx-fqj5
IPv6 Frag Escape
https://github.com/sgkdev/ipv6_frag_escape
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime
https://isc.sans.edu/diary/What%20do%20Ports%20Hear%20When%20Nobody%27s%20Listening%3F%20An%20Assessment%20of%20Automated%20Cybercrime%20%5BGuest%20Diary%5D/33104
Linux Process Name Masquerading
https://isc.sans.edu/diary/Linux+Process+Name+Masquerading/33102
Amazon Q VS Code Extension Vulnerability
https://www.wiz.io/blog/amazon-q-vulnerability
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
CVE-2024-40766: The Patch Fixed the Bug. Nobody Fixed the Configuration.
https://isc.sans.edu/diary/CVE-2024-40766%3A%20The%20Patch%20Fixed%20the%20Bug.%20Nobody%20Fixed%20the%20Configuration./33094
libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c
https://www.vulncheck.com/advisories/libssh2-out-of-bounds-write-via-unchecked-packet-length-in-transport-c
PixelSmash Critical FFmpeg Vulnerability Turns Media Files into Weapons
https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Webshells Remain Popular
https://isc.sans.edu/diary/Webshells%20Remain%20Popular/33096
Safer pull_request_target defaults for GitHub Actions checkout
https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/
Private Access Control Tokens
https://cloudflare.net/news/news-details/2026/Cloudflare-Collaborates-With-Leading-Browsers-to-Develop-a-Privacy-First-Protocol-For-the-Global-Internet/default.aspx
https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/
Fortibleed Update
https://socradar.io/resources/whitepapers/dismantling-fortibleed-inside-a-russian-fortinet-compromise-operation/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address
https://isc.sans.edu/diary/eBanking%20Phishing%20Delivered%20Through%20IPv4-Mapped%20IPv6%20Address/33090
NGINX ngx_http_v3_module vulnerability CVE-2026-42530
https://my.f5.com/manage/s/article/K000161616
Squidbleed (CVE-2026-47729)
https://blog.calif.io/p/squidbleed-cve-2026-47729
AMD will reinstate memory encryption on Ryzen 9000 CPUs through a BIOS update in July
https://www.tomshardware.com/pc-components/cpus/amd-will-reinstate-memory-encryption-on-ryzen-9000-cpus-through-a-bios-update-in-july-tsme-is-coming-back-after-valuable-community-feedback
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
The browser blind spot: Why your security tool may not be blocking what you think it is [Guest Diary]
https://isc.sans.edu/diary/The%20browser%20blind%20spot%3A%20Why%20your%20security%20tool%20may%20not%20be%20blocking%20what%20you%20think%20it%20is%20%5BGuest%20Diary%5D/33084
Android 17 Security Patches
https://source.android.com/docs/security/bulletin/android-17
Oracle Critical Security Patch Update Advisory - June 2026
https://www.oracle.com/security-alerts/cspujun2026.html
Multiple JetBrains IDE plugins caught stealing AI keys
https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
From a VHDX File to a Remcos RAT
https://isc.sans.edu/diary/From%20a%20VHDX%20File%20to%20a%20Remcos%20RAT/33080
A backdoor in a LinkedIn job offer
https://roman.pt/posts/linkedin-backdoor/
A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack
https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html
Copilot M365 Data Leakage
https://www.varonis.com/blog/searchleak
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Evil MSI Background: BASE64 Statistical Analysis
https://isc.sans.edu/diary/Evil%20MSI%20Background%3A%20BASE64%20Statistical%20Analysis/33072
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ
TSME/SME not activating on Ryzen 7 9700X
https://github.com/AMDESE/AMDSEV/issues/292
Deep-Research Agents Can Be Poisoned via User-Generated Content
https://arxiv.org/pdf/2605.24245
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Atomic Arch: Attackers Hijack Trusted AUR Packages to Deliver Rootkit-Like Malware
https://www.sonatype.com/blog/atomic-arch-npm-campaign-adds-malicious-dependency
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/
A Fake Bug Report Hijacks Your AI Coding Agent and Nothing Catches It.
https://tenetsecurity.ai/blog/agentjacking-coding-agents-with-fake-sentry-errors/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
More Bitlocker Issues: GreatXML
https://git.churchofmalware.org/Nightmare_Eclipse/GreatXML
Security Advisory Ivanti Sentry (CVE-2026-10520, CVE-2026-10523)
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US
Oracle Security Alert Advisory - CVE-2026-35273
https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
https://www.bleepingcomputer.com/news/security/oracle-mitigates-peoplesoft-zero-day-exploited-in-data-theft-attacks/
How Deceptive Installers Are Targeting macOS Users
https://www.huntress.com/blog/deceptive-installers-macos-infostealers
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
How has use of framing protection security headers changed in the past 3 years?
https://isc.sans.edu/diary/How%20has%20use%20of%20framing%20protection%20security%20headers%20changed%20in%20the%20past%203%20years%3F/33068
Preparing for npm v12: install scripts and non-registry sources become opt-in
https://github.com/orgs/community/discussions/198547
Adobe Patches
https://helpx.adobe.com/security.html
Rogue Planet new Microsoft Defender Vulnerability
https://github.com/MSNightmare/RoguePlanet
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Microsoft June 2026 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20June%202026%20Patch%20Tuesday/33064
Miasma Software Supply Chain Attack Toolkit Source Published
https://safedep.io/inside-the-miasma-supply-chain-attack-toolkit/
Fortinet FortiSandbox Vulnerability
https://fortiguard.fortinet.com/psirt/FG-IR-26-141
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack
https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents
Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/
Missing IPsec Integrity Protection for IMS SIP Signaling in Verizon VoLTE Deployments
https://kb.cert.org/vuls/id/615987
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
The Evil MSI Background is Back!
https://isc.sans.edu/diary/The%20Evil%20MSI%20Background%20is%20Back!/33054
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
https://blog.includesecurity.com/2026/06/the-smart-tv-in-your-livingroom-is-a-node-in-the-aiscraping-economy/
Brute force attack on Dashlane user accounts
https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts#update-jun-4
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Microsoft's Coreutils for Windows
https://isc.sans.edu/diary/Microsoft%27s%20Coreutils%20for%20Windows/33048
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability CVE-2026-20230
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW
Firmware Update for Acer Connect W6x Router
https://community.acer.com/en/kb/articles/19672
OAuth marketplace apps keep access after publishers vanish
https://www.helpnetsecurity.com/2026/06/04/oauth-marketplace-apps-audit/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Continuing Scans for swagger.json
https://isc.sans.edu/diary/Continuing+Scans+for+swaggerjson/33044/#comments
Fake call detection on Android
https://blog.google/security/android-fake-call-detection/
Anthropic's coordinated vulnerability disclosure dashboard
https://red.anthropic.com/2026/cvd/
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
New Wave Of Phishing Emails with SVG Files
https://isc.sans.edu/diary/New%20Wave%20Of%20Phishing%20Emails%20with%20SVG%20Files/33040
Android 2026-06-01 security patch level vulnerability details
https://source.android.com/docs/security/bulletin/2026/2026-06-01
Poly Voice Possible Remote Control of Certain Poly Devices CVE-2026-0826
https://support.hp.com/us-en/document/ish_15052661-15052687-16/hpsbpy04083
https://www.rapid7.com/blog/post/ve-cve-2026-0826-critical-unauthenticated-stack-buffer-overflow-hp-poly-vvx-trio-voip-phones-fixed/
Security Advisory Ivanti Neurons for ITSM (CVE-2026-9614)
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Neurons-for-ITSM-CVE-2026-9614?language=en_US
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Unidentified RAT pushes NetSupport RAT
https://isc.sans.edu/diary/Unidentified%20RAT%20pushes%20NetSupport%20RAT/33034
CVE-2026-41089: Windows Netlogon Vulnerability Exploited
https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102
RedHat npm Packages Affected
https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm
Dashlane Locking Accounts after Brute Force
https://status.dashlane.com/pages/5aabcb89fccc4b04d3774443
My Upcoming Classes
https://www.sans.org/profiles/dr-johannes-ullrich
Announcing Bitskrieg
https://deadeclipse666.blogspot.com/2026/05/announcing-bitskrieg.html
Vulnerability in Gogs
https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/
Oracle Critical Security Patch Update Advisory - May 2026
https://www.oracle.com/security-alerts/cspumay2026.html
GlobalProtect Authentication Bypass Vulnerabilities CVE-2026-0257
https://security.paloaltonetworks.com/CVE-2026-0257
Research Review Journal
https://assets.contentstack.io/v3/assets/blt83c410d686aa5f84/blt3cff46f63887f83e/research-review-journal
https://www.sans.edu/cyber-research
Analysis of a Year of Files Uploaded to DShield Sensors
https://isc.sans.edu/diary/Analysis%20of%20a%20Year%20of%20Files%20Uploaded%20to%20DShield%20Sensors/33026
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
https://amibeingpwned.com/blog/urban-vpn-postmessage-command-injection
Silent Ransom Group Impersonating IT Personnel through Social Engineering
https://www.ic3.gov/CSA/2026/260526.pdf
Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs
https://isc.sans.edu/diary/Reconstructing%20an%20Akira%20Ransomware%20Kill%20Chain%20from%20Perimeter%20and%20Endpoint%20Logs/33024
Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html
From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities
https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/
Possible ACR Stealer From Page Impersonating Claude
https://isc.sans.edu/diary/Possible%20ACR%20Stealer%20From%20Page%20Impersonating%20Claude/33018
Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-45659
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45659
Multiple Vulnerabilities in Angular Language Service VS Code Extension
https://github.com/angular/angular/security/advisories/GHSA-ccq4-xmxr-8hcq
Microsoft Access VBA
https://isc.sans.edu/diary/Microsoft%20Access%20VBA/33012
An Example of Stack String in High Level Language
https://isc.sans.edu/diary/An%20Example%20of%20Stack%20String%20in%20High%20Level%20Language/33008
Cross-Platform NPM Stealer
https://isc.sans.edu/diary/Cross-Platform%20NPM%20Stealer/33006
Laravel Lang Compromised with RCE Backdoor Across
https://socket.dev/blog/laravel-lang-compromise
Google API keys keep working after you delete them
https://www.aikido.dev/blog/google-api-keys-deletion
Selective HTTP Proxying in Linux
https://isc.sans.edu/diary/Selective%20HTTP%20Proxying%20in%20Linux/33002
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows/
MSFT Patches Recent Windows Defender Flaws CVE-2026-41091, CVE-2026-45498, CVE-2026-45584
https://x.com/fabian_bader/status/2057198207243804881
Cisco Secure Workload Unauthorized API Access Vulnerability CVE-2026-20223
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy
GitHub Breach
https://x.com/github/status/2056949168208552080
Agentic Threat Intelligence Feed - VS Code Extensions
https://agentmesh.knostic.ai/extensions
More NGINX Vulnerabilities
https://x.com/nebusecurity/status/2057071579876753643
https://my.f5.com/manage/s/article/K000161307
Microsoft Publishes YellowKey Mitigation CVE-2026-45585
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585
Incomplete Sonicwall Patch CVE-2024-12802
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0001
TeamPCP Supply Chain Campaign: Activity Through 2026-05-17
https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Activity%20Through%202026-05-17/32994
https://slsa.dev/spec/v0.1/levels
Github Action Compromise
https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials
How Storm-2949 turned a compromised identity into a cloud-wide breach
https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/
New Malware Libraries means New Signatures
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897
https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498
Microsoft Authenticator Update CVE-2026-41615
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615
ssh-keysign-pwn (CVE-2026-46333) Patches Released
https://almalinux.org/blog/2026-05-15-ssh-keysign-pwn-cve-2026-46333/
Tearing apart website fraud to see how it works. (@sans_edu)
https://isc.sans.edu/diary/%5BGUEST%20DIARY%5D%20Tearing%20apart%20website%20fraud%20to%20see%20how%20it%20works./32958
Simple bypass of the link preview function in Outlook Junk folder
https://isc.sans.edu/diary/Simple%20bypass%20of%20the%20link%20preview%20function%20in%20Outlook%20Junk%20folder/32990
NGINX Vulnerability
https://depthfirst.com/nginx-rift
Cisco SDWan 0-Day
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW
Proxying the Unproxyable? Sending EXE traffic to a Proxy
https://isc.sans.edu/diary/Proxying%20the%20Unproxyable%3F%20Sending%20EXE%20traffic%20to%20a%20Proxy/32982
New Nightmare Eclipse Vulnerabilities Disclosed
https://github.com/Nightmare-Eclipse/YellowKey
https://github.com/Nightmare-Eclipse/GreenPlasma
Adobe Patches
https://helpx.adobe.com/security.html
Microsoft Patch Tuesday
https://isc.sans.edu/diary/32980
Tanstack npm and others compromised
https://socket.dev/blog/tanstack-npm-packages-compromised-mini-shai-hulud-supply-chain-attack
Ruby Gems Attack
https://x.com/maciejmensfeld/status/2054164602577940619
Apple Patches Everything
https://isc.sans.edu/diary/Apple%20Patches%20Everything/32976
End-to-End Encrypted RCS Messages
https://www.apple.com/newsroom/2026/05/end-to-end-encrypted-rcs-messaging-begins-rolling-out-today-in-beta/
Why we use CAPTCHAs
https://isc.sans.edu/diary/Why%20we%20use%20CAPTCHAs/32974
Checkmarx Jenkins AST plugin compromise
https://checkmarx.com/blog/ongoing-security-updates/
Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag
https://isc.sans.edu/diary/Another%20Universal%20Linux%20Local%20Privilege%20Escalation%20%28LPE%29%20Vulnerability%3A%20Dirty%20Frag/32968
PAM Backdoors Steel Passwords
https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web
CPanel Updates
https://support.cpanel.net/hc/en-us/sections/360007088193-Security
Let s Encrypt Briefly Halts Certificate Issuance
https://letsencrypt.status.io
An Adaptive Cyber Analytics UI for Web Honeypot Logs
https://isc.sans.edu/diary/An%20Adaptive%20Cyber%20Analytics%20UI%20for%20Web%20Honeypot%20Logs%20%5BGuest%20Diary%5D/32962
Ivanti May Patchday
https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-Multiple-CVEs
Redis Security advisory: [CVE 2026 23479] [CVE 2026 25243] [CVE-2026-25588] [CVE 2026 25589] [CVE-2026-23631]
https://redis.io/blog/security-advisory-cve202623479-cve202625243-cve-2026-25588-cve202625589-cve-2026-23631/
@sans_edu research paper: Marcio Enriquez
[link will be added once the paper has been published]
Technical issue with .de domains
https://blog.denic.de/en/technical-issue-with-de-domains-resolved/
CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID Authentication Portal
https://security.paloaltonetworks.com/CVE-2026-0300
Android Security Bulletin May 2026 CVE-2026-0073
https://source.android.com/docs/security/bulletin/2026/2026-05-01
Cleartext Passwords in MS Edge? In 2026?
https://isc.sans.edu/diary/Cleartext%20Passwords%20in%20MS%20Edge%3F%20In%202026%3F/32954
SSL.com rotates its root certificate today
https://isc.sans.edu/diary/SSL.com%20rotates%20their%20root%20certificate%20today/32956
DEAMONTOOLS Compromise
https://securelist.com/tr/daemon-tools-backdoor/119654/
DShield Honeypot Update
https://isc.sans.edu/diary/DShield%20Honeypot%20Update/32948
MOVEit Automation Critical Security Alert Bulletin April 2026 (CVE-2026-4670, CVE-2026-5174)
https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174
Apache httpd http2 vulnerability
https://seclists.org/oss-sec/2026/q2/387
Malicious Ad for Homebrew Leads to MacSync Stealer
https://isc.sans.edu/diary/Malicious%20Ad%20for%20Homebrew%20Leads%20to%20MacSync%20Stealer/32942
Wireshark Update
https://www.wireshark.org/docs/relnotes/wireshark-4.6.5.html
Digicert Microsoft Defender False Positive
https://www.reddit.com/r/cybersecurity/comments/1t2hfsh/mde_flagging_digi_cert_certificate_as_malicious/
https://bugzilla.mozilla.org/show_bug.cgi?id=2033170
cPanel Exploited
https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026
Danger of Libredtail
https://isc.sans.edu/diary/Danger%20of%20Libredtail%20%5BGuest%20Diary%5D/32936
FreeBSD dhclient vulnerability
https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc
Linux Copy-Fail Vulnerability CVE-2026-31431
https://copy.fail
Bryan Nice Research Paper
https://www.linkedin.com/in/bryannice/
https://www.sans.edu/cyber-research/detecting-ai-pickling
Today's Odd Web Requests
https://isc.sans.edu/diary/Today%27s%20Odd%20Web%20Requests/32934
Incomplete Patch of APT28's Zero-Day Leads to CVE-2026-32202
https://www.akamai.com/blog/security-research/2026/apr/incomplete-patch-apt28s-zero-day-cve-2026-32202
Assess Secure Boot status with Microsoft Defender
https://techcommunity.microsoft.com/blog/MicrosoftDefenderATPBlog/assess-secure-boot-status-with-microsoft-defender/4510356
Deprecating Legacy TLS and Endpoints for POP and IMAP in Exchange Online
https://techcommunity.microsoft.com/blog/exchange/deprecating-legacy-tls-and-endpoints-for-pop-and-imap-in-exchange-online/4515201
SAP Related npm Packages Compromised
https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared
HTTP Requests with X-Vercel-Set-Bypass-Cookie Header
https://isc.sans.edu/diary/HTTP%20Requests%20with%20X-Vercel-Set-Bypass-Cookie%20Header/32930
GitHub Vulnerability CVE-2026-3854
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
Microsoft RDP Notification Bug
https://support.microsoft.com/en-us/topic/april-14-2026-kb5083768-os-build-28000-1836-839e4a25-d979-4158-b70c-182333045883
TeamPCP Update
https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20008%20-%2026-Day%20Pause%20Ends%20with%20Three%20Concurrent%20Compromises%20%28Checkmarx%20KICS%2C%20Bitwarden%20CLI%20Cascade%2C%20xinference%20PyPI%29%2C%20CanisterSprawl%20npm%20Worm%20Identified%2C%20and%20Tier%201%20Coverage%20Returns/32926
https://socket.dev/blog/73-open-vsx-sleeper-extensions-glassworm
https://checkmarx.com/blog/checkmarx-security-update-april-26/
89 vulnerabilities in XAPI / Citrix XenServer
https://shittrix.moksha.dk/#rationale
Phantom RPC
https://securelist.com/phantomrpc-rpc-vulnerability/119428/
Pi-Hole Vulnerability CVE-2026-41489
https://github.com/pi-hole/pi-hole/security/advisories/GHSA-6w8x-p785-6pm4
Linux Kernel Problem CVE-2026-41651
https://nvd.nist.gov/vuln/detail/CVE-2026-41651
Apple Patches Exploited Notification Flaw
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Notification%20Flaw/32922
Bitwarden CLI Compromised
https://socket.dev/blog/bitwarden-cli-compromised
https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127
Microsoft Security Advisory CVE-2026-40372 ASP.NET Core Elevation of Privilege
https://github.com/dotnet/announcements/issues/395
Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Beyond%20Cryptojacking%3A%20Telegram%20tdata%20as%20a%20Credential%20Harvesting%20Vector%2C%20Lessons%20from%20a%20Honeypot%20Incident/32888
Checkmarx Compromise
https://socket.dev/blog/checkmarx-supply-chain-compromise
Oracle Quarterly Critical Patch Update
https://www.oracle.com/security-alerts/cpuapr2026.html
Firefox 150 - Mythos AI
https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/
A .WAV With A Payload
https://isc.sans.edu/diary/A%20.WAV%20With%20A%20Payload/32910
The Phishy GitHub Issue Case
https://blog.atsika.ninja/posts/the-phishy-github-issue-case/
P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the Internet
https://morganrobertson.net/p4wned/
Handling the CVE Flood With EPSS
https://isc.sans.edu/diary/Handling%20the%20CVE%20Flood%20With%20EPSS/32914
Windows Server 2025 Out of Band Patch
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#4835
QEMU abused to evade detection and enable ransomware delivery
https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery
Lumma Stealer infection with Sectop RAT (ArechClient2)
https://isc.sans.edu/diary/Lumma%20Stealer%20infection%20with%20Sectop%20RAT%20%28ArechClient2%29/32904
Three Recent Windows Defender Vulnerabilities Exploited (one 0-day)
https://x.com/HuntressLabs/status/2044882115574091960
FortiSandbox PoC Exploit CVE-2026-39808
https://github.com/samu-delucas/CVE-2026-39808?tab=readme-ov-file
NIST Updates NVD Operations to Address Record CVE Growth
https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth
Compromised DVRs and Finding Them in the Wild
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Compromised%20DVRs%20and%20Finding%20Them%20in%20the%20Wild/32886
Cisco ISE RCE Vulnerability and WebEx Auth Bypass CVE-2026-20184 CVE-2026-20180 CVE-2026-20186
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL
Windows Defender 0-Day (RedSun)
https://github.com/Nightmare-Eclipse/RedSun
Sonatype Vulnerability CVE-2026-5189
https://support.sonatype.com/hc/en-us/articles/50817138825491-CVE-2026-5189-Nexus-Repository-3-Hardcoded-Credential-in-Internal-Database-Component-2026-04-15
Scanning for AI Models
https://isc.sans.edu/diary/Scanning%20for%20AI%20Models/32896
Microsoft Update Problems
https://support.microsoft.com/en-us/topic/april-14-2026-kb5082063-os-build-26100-32690-c57e289d-27c9-47cd-a183-72fabc62c5d7#:~:text=Known%20issues%20in%20this%20update
Microsoft RDP File Warnings
https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/remotepc/understanding-security-warnings
AI GitHub Action Vulnerabilities
https://oddguan.com/blog/comment-and-control-prompt-injection-credential-theft-claude-code-gemini-cli-github-copilot/
https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/
Wireguard Update
https://lists.zx2c4.com/pipermail/wireguard/2026-April/009561.html
Microsoft Patch Tuesday April 2026
https://isc.sans.edu/forums/diary/Microsoft%20Patch%20Tuesday%20April%202026./32898/
Adobe Patches
https://helpx.adobe.com/security/Home.html
Fortinet Patches
https://fortiguard.fortinet.com/psirt
Scans for EncystPHP Webshell
https://isc.sans.edu/diary/Scans%20for%20EncystPHP%20Webshell/32892
CPUID Compromise
https://securelist.com/tr/cpu-z/119365/
https://x.com/d0cTB/status/2042520961824559150
OpenAI Mac Application Update due to Axios Compromise
https://openai.com/index/axios-developer-tool-compromise/
Axios Vulnerability CVE-2026-40175
https://github.com/axios/axios/security/advisories/GHSA-fvcv-3m26-pcqx
Obfuscated JavaScript or Nothing
https://isc.sans.edu/diary/Obfuscated%20JavaScript%20or%20Nothing/32884
Numbers in Passwords
https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords%3A%20Take%20Two/32866
Adobe 0-Day Patch CVE-2026-34621
https://helpx.adobe.com/security/products/acrobat/apsb26-43.html
ClickFix Bypass via ScriptEditor
https://www.jamf.com/blog/clickfix-macos-script-editor-atomic-stealer/
Honeypot Fingerprinting
https://isc.sans.edu/diary/More%20Honeypot%20Fingerprinting%20Scans/32878
Microsoft Locks Accounts for Privacy/Encryption Related Developers
https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/ https://news.ycombinator.com/item?id=47687884 https://x.com/windscribecom/status/2041929519628443943
https://windowsforum.com/threads/april-2026-windows-update-ends-cross-signed-kernel-driver-trust.410487/
Remote Code Execution in Apache ActiveMQ (CVE-2026-34197)
https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/
A Little Bit Pivoting: What Web Shells are Attackers Looking for Today?
https://isc.sans.edu/diary/A%20Little%20Bit%20Pivoting%3A%20What%20Web%20Shells%20are%20Attackers%20Looking%20for%3F/32874
WatchGuard Firebox Arbitrary File Write via Path Traversal in Fireware Web UI
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00009
Project Glasswing
https://www.anthropic.com/glasswing
Current Threats Against Kubernetes
https://unit42.paloaltonetworks.com/modern-kubernetes-threats/
How often are redirects used in phishing in 2026?
https://isc.sans.edu/diary/How%20often%20are%20redirects%20used%20in%20phishing%20in%202026%3F/32870
Hackerone Suspends Internet Bug Bounty
https://hackerone.com/ibb?type=team
https://www.linkedin.com/posts/danielstenberg_hackerone-share-7446667043380076545-RX9b/
Bluehammer Windows 0-day Privilege Escalation
https://github.com/Nightmare-Eclipse/BlueHammer
https://deadeclipse666.blogspot.com/2026/04/public-disclosure.html
https://deepwiki.com/Nightmare-Eclipse/BlueHammer
Keycloak MFA Bypass CVE-2026-3429
https://access.redhat.com/security/cve/cve-2026-3429
Team PCP Update and Axios Post Mortem
https://isc.sans.edu/diary/32864
https://github.com/axios/axios/issues/10636
Strapi NPM Packages Compromised
https://safedep.io/malicious-npm-strapi-plugin-events-c2-agent/
Fortinet CVE-2026-35616 exctively exploited
https://fortiguard.fortinet.com/psirt/FG-IR-26-099
Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208)
https://isc.sans.edu/diary/Attempts%20to%20Exploit%20Exposed%20%22Vite%22%20Installs%20%28CVE-2025-30208%29/32860
OpenSSH 10.3 Release
https://seclists.org/oss-sec/2026/q2/7
Claude Code Vulnerability
https://adversa.ai/claude-code-security-bypass-deny-rules-disabled/
Malicious Script That Gets Rid of ADS
https://isc.sans.edu/diary/Malicious%20Script%20That%20Gets%20Rid%20of%20ADS/32854
Google Chrome Update fixes 21 Vulnerabilities and 0-Day
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html
Apple Addresses Darksword Vulnerabilities for older devices
https://support.apple.com/en-us/126793
Application Control Bypass for Data Exfiltration
https://isc.sans.edu/diary/Application%20Control%20Bypass%20for%20Data%20Exfiltration/32850
Axios NPM Module Supply Chain Compromise
https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan
https://www.linkedin.com/events/7444763050819092480/
TeamPCP vs. Cloud Resources
https://www.wiz.io/blog/tracking-teampcp-investigating-post-compromise-attacks-seen-in-the-wild
Honeypot Session Lifetime
https://isc.sans.edu/diary/DShield%20%28Cowrie%29%20Honeypot%20Stats%20and%20When%20Sessions%20Disconnect/32840
Let s Encrypt Tests Mass Revocation
https://community.letsencrypt.org/t/lets-encrypt-2026-mass-revocation-simulation/245960
https://www.certkit.io/blog/ari-solves-mass-certificate-revocation
https://www.certkit.io/blog/lets-encrypt-mass-revocation-simulation
F5 Vulnerability Re-Classified (and already exploited) as RCE
https://my.f5.com/manage/s/article/K000156741
TeamPCP Update #2: Telnyx PyPi Compromise
https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20002%20-%20Telnyx%20PyPI%20Compromise%2C%20Vect%20Ransomware%20Mass%20Affiliate%20Program%2C%20and%20First%20Named%20Victim%20Claim/32838
Citrix Netscaler Vulnerability Details
https://labs.watchtowr.com/the-sequels-are-never-as-good-but-were-still-in-pain-citrix-netscaler-cve-2026-3055-memory-overread/
macOS Clickfix Warning
https://x.com/ClassicII_MrMac/status/2036797948911141129
Windows Smart Install
https://textslashplain.com/2026/03/24/windows-choose-where-to-get-apps/
TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available
https://isc.sans.edu/diary/TeamPCP%20Supply%20Chain%20Campaign%3A%20Update%20001%20-%20Checkmarx%20Scope%20Wider%20Than%20Reported%2C%20CISA%20KEV%20Entry%2C%20and%20Detection%20Tools%20Available/32834
DarkSword and This Weeks iOS Updates
https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain
LangFlow Exploited
https://www.cisa.gov/news-events/alerts/2026/03/25/cisa-adds-one-known-exploited-vulnerability-catalog
Apple Patches (almost) everything again. March 2026 edition.
https://isc.sans.edu/diary/Apple%20Patches%20%28almost%29%20everything%20again.%20March%202026%20edition./32830
SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2)
https://isc.sans.edu/diary/SmartApeSG%20campaign%20pushes%20Remcos%20RAT%2C%20NetSupport%20RAT%2C%20StealC%2C%20and%20Sectop%20RAT%20%28ArechClient2%29/32826
Trivy/LiteLLM/TeamPCP Updates
https://www.sans.org/webcasts/when-security-scanner-became-weapon
https://rosesecurity.dev/2026/03/24/sha-pinning-is-not-enough.html
Google Moves Up Quantum Crypto Deadline
https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/
Special Webcast about Trivy Supply Chain Attacks
https://www.sans.org/webcasts/when-security-scanner-became-weapon
Detecting IP KVM Usage
https://isc.sans.edu/diary/Detecting%20IP%20KVMs/32824
TeamPCP, Trivy, liteLLM, Iran and more
https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran
https://www.aquasec.com/blog/trivy-supply-chain-attack-what-you-need-to-know/
https://blog.gitguardian.com/trivys-march-supply-chain-attack-shows-where-secret-exposure-hurts-most/
https://www.sysdig.com/blog/teampcp-expands-supply-chain-compromise-spreads-from-trivy-to-checkmarx-github-actions
From W-2 to BYOVD: How a Tax Search Leads to Kernel-Mode AV/EDR Kill
https://www.huntress.com/blog/w2-malvertising-to-kernel-mode-edr-kill
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-3055 and CVE-2026-4368
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300
gRPC-Go Authorization bypass via missing leading slash in :path CVE-2026-33186
https://github.com/grpc/grpc-go/security/advisories/GHSA-p77j-4mvh-x3m3
GSocket Backdoor Delivered Through Bash Script
https://isc.sans.edu/diary/GSocket+Backdoor+Delivered+Through+Bash+Script/32816/#comments
Oracle Security Alert CVE-2026-21992 Released
https://blogs.oracle.com/security/alert-cve-2026-21992
Rockwell Automation Reiterates Customer Guidance to Disconnect Devices from the Internet and Harden PLCs to Protect from Cyber Threats
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1771.html
Interesting Cowrie Strings
https://isc.sans.edu/diary/Interesting+Message+Stored+in+Cowrie+Logs/32810
Microsoft Intune Hardening Advice
https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117
https://www.cisa.gov/news-events/alerts/2026/03/18/cisa-urges-endpoint-management-system-hardening-after-cyberattack-against-us-organization
Unifi Network Update
https://community.ui.com/releases/Security-Advisory-Bulletin-062-062/c29719c0-405e-4d4a-8f26-e343e99f931b
Scans for "adminer"
https://isc.sans.edu/diary/Scans%20for%20%22adminer%22/32808
Background Security Improvement for WebKit
https://support.apple.com/en-us/126604
Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC)
https://lists.gnu.org/archive/html/bug-inetutils/2026-03/msg00031.html
ScreenConnect 26.1 Security Hardening
https://www.connectwise.com/company/trust/security-bulletins/2026-03-17-screenconnect-bulletin
IPv4 Mapped IPv6 Addresses
https://isc.sans.edu/diary/IPv4%20Mapped%20IPv6%20Addresses/32804
More IP KVM Vulnerabilities
https://eclypsium.com/blog/your-kvm-is-the-weak-link-how-30-dollar-devices-can-own-your-entire-network/
AWS Bedrock AgentCore Code Interpreter DNS Leak
https://www.beyondtrust.com/blog/entry/pwning-aws-agentcore-code-interpreter
/proxy/ URL scans with IP addresses
https://isc.sans.edu/forums/diary/proxy+URL+scans+with+IP+addresses/32800/
Local Network Address Restrictions
https://learn.microsoft.com/en-us/deployedge/ms-edge-local-network-access#how-to-mitigate-impact-for-cross-origin-iframes https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel
European Security Vendor Targeted by Hackers Fronting as Cisco Domain
https://specopssoft.com/blog/phishing-campaign-cisco/
SmartApeSG campaign uses ClickFix page to push Remcos RAT
https://isc.sans.edu/diary/SmartApeSG%20campaign%20uses%20ClickFix%20page%20to%20push%20Remcos%20RAT/32796
A React-based phishing page with credential exfiltration via EmailJS
https://isc.sans.edu/diary/32794
Google Chrome announced two zero-day fixes, then removed one.
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html
AdGuard Vulnerability
https://github.com/AdguardTeam/AdGuardHome/releases/tag/v0.107.73
When your IoT Device Logs in as Admin, It s too Late!
https://isc.sans.edu/diary/When%20your%20IoT%20Device%20Logs%20in%20as%20Admin%2C%20It%3Fs%20too%20Late!%20%5BGuest%20Diary%5D/32788
Apple Patches
https://support.apple.com/en-us/100100
Veeam Patches
https://www.veeam.com/kb4830
Analyzing "Zombie Zip" Files (CVE-2026-0866)
https://isc.sans.edu/diary/Analyzing%20%22Zombie%20Zip%22%20Files%20%28CVE-2026-0866%29/32786
How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit
https://pentesterlab.com/blog/freshrss-bcrypt-truncation-auth-bypass
Microsoft Patch Tuesday, March 2026
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20March%202026/32782
Fortinet Updates
https://fortiguard.fortinet.com/psirt
Adobe Updates
https://helpx.adobe.com/security.html
Zoom Update
https://www.instagram.com/direct/t/17848218473607233/
Encrypted Client Hello: Ready for Prime Time?
https://isc.sans.edu/diary/Encrypted%20Client%20Hello%3A%20Ready%20for%20Prime%20Time%3F/32778
The ExifTool vulnerability: how an image can infect macOS systems
https://www.kaspersky.com/blog/exiftool-macos-picture-vulnerability-mitigation-cve-2026-3102/55362/
Remote code execution in Nextcloud Flow via vulnerable Windmill version
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g7vj-98x3-qvjf
YARA-X 1.14.0 Release https://isc.sans.edu/diary/YARA-X%201.14.0%20Release/32774
INTERPLAY BETWEEN IRANIAN TARGETING OF IP CAMERAS AND PHYSICAL WARFARE IN THE MIDDLE EAST
https://research.checkpoint.com/2026/interplay-between-iranian-targeting-of-ip-cameras-and-physical-warfare-in-the-middle-east/
Announcing the Node.js LTS Upgrade and Modernization Program
https://openjsf.org/blog/nodejs-lts-upgrade-program
nginx UI Vulnerability
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762
Differentiating Between a Targeted Intrusion and an Automated Opportunistic Scanning [Guest Diary]
https://isc.sans.edu/diary/Differentiating%20Between%20a%20Targeted%20Intrusion%20and%20an%20Automated%20Opportunistic%20Scanning%20%5BGuest%20Diary%5D/32768
CVE-2026-29000: Critical Authentication Bypass in pac4j-jwt - Using Only a Public Key (CVSS 10)
https://www.codeant.ai/security-research/pac4j-jwt-authentication-bypass-public-key
FreeScout Help Desk Vulnerability
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-mw88-x7j3-74vc
Microsoft Authenticator Not Supported on Graphene OS
https://www.heise.de/en/news/GrapheneOS-Microsoft-Authenticator-does-not-support-secure-Android-OS-11200495.html
Want More XWorm?
https://isc.sans.edu/diary/Want%20More%20XWorm%3F/32766
Cisco Secure Firewall Management Center Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
LastPass Phishing
https://www.securityweek.com/lastpass-users-targeted-with-backup-themed-phishing-emails/
Bruteforce Scans for CrushFTP
https://isc.sans.edu/diary/Bruteforce%20Scans%20for%20CrushFTP%20/32762
Android March 2026 Patches, including 0-Day (CVE-2026-21385)
https://source.android.com/docs/security/bulletin/2026/2026-03-01
OAuth redirection abuse enables phishing and malware delivery
https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/
Quick Howto: ZIP Files Inside RTF
https://isc.sans.edu/diary/Quick+Howto+ZIP+Files+Inside+RTF/32696/#comments
Keeping the Internet fast and secure: introducing Merkle Tree Certificates
https://blog.cloudflare.com/bootstrap-mtc/
Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel
https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/
Fake Fedex Email Delivers Donuts!
https://isc.sans.edu/diary/Fake%20Fedex%20Email%20Delivers%20Donuts!/32754
Abusing .ARPA: The TLD that isn t supposed to host anything
https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/
MC1179154 - Microsoft Authenticator app: Upcoming changes to jailbreak and root detection
https://mc.merill.net/message/MC1179154
SECURITY BULLETIN: Apex One and Apex One (Mac) - February 2026
https://success.trendmicro.com/en-US/solution/KA-0022458
Special Webcast: AirSnitch How Worried Should You Be?
https://www.sans.org/webcasts/airsnitch-how-worried-should-you-be
Finding Signal in the Noise: Lessons Learned Running a Honeypot with AI Assistance [Guest Diary]
https://isc.sans.edu/diary/Finding%20Signal%20in%20the%20Noise%3A%20Lessons%20Learned%20Running%20a%20Honeypot%20with%20AI%20Assistance%20%5BGuest%20Diary%5D/32744
Google API Keys Weren't Secrets. But then Gemini Changed the Rules.
https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules
AirSnitch: Demystifying and Breaking Client Isolation in Wi-Fi Networks
https://www.ndss-symposium.org/ndss-paper/airsnitch-demystifying-and-breaking-client-isolation-in-wi-fi-networks/
The CLAIR Model: A Synthesized Conceptual Framework for Mapping Critical Infrastructure Interdependencies [Guest Diary]
https://isc.sans.edu/diary/The+CLAIR+Model+A+Synthesized+Conceptual+Framework+for+Mapping+Critical+Infrastructure+Interdependencies+Guest+Diary/32748
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability CVE-2026-20127
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk https://blog.talosintelligence.com/uat-8616-sd-wan/
Abusing Cortex XDR Live
https://labs.infoguard.ch/posts/abusing_cortex_xdr_live_response_as_c2/
OpenSSL Vulnerability CVE-2025-15467
https://seclists.org/oss-sec/2026/q1/220
Open Redirects: A Forgotten Vulnerability?
https://isc.sans.edu/diary/Open%20Redirects%3A%20A%20Forgotten%20Vulnerability%3F/32742
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148
https://hacks.mozilla.org/2026/02/goodbye-innerhtml-hello-sethtml-stronger-xss-protection-in-firefox-148/
More telnetd issues
https://seclists.org/oss-sec/2026/q1/199
Another day, another malicious JPEG
https://isc.sans.edu/diary/Another%20day%2C%20another%20malicious%20JPEG/32738
Calibre Path Traversal Leading to Arbitrary File Write and Potentially Code Execution CVE-2026-26064 CVE-2026-26065
https://github.com/kovidgoyal/calibre/security/advisories/GHSA-72ch-3hqc-pgmp
https://github.com/kovidgoyal/calibre/security/advisories/GHSA-vmfh-7mr7-pp2w
CVE-2026-25755: PDF Object Injection in jsPDF (addJS Method)
https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-25755.md
Roundcube Webmail Exploited CVE-2025-49113 https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10
https://www.openwall.com/lists/oss-security/2025/06/02/3
Japanese-Language Phishing Emails
https://isc.sans.edu/diary/Japanese-Language%20Phishing%20Emails/32734
'God-Like' Attack Machines: AI Agents Ignore Security Policies
https://www.darkreading.com/application-security/ai-agents-ignore-security-policies
Starkiller: New Phishing Framework Proxies Real Login Pages to Bypass MFA
https://abnormal.ai/blog/starkiller-phishing-kit
Under the Hood of DynoWiper
https://isc.sans.edu/diary/Under%20the%20Hood%20of%20DynoWiper/32730
Vibe Password Generation: Predictable by Design
https://www.irregular.com/publications/vibe-password-generation
Vulnerabilities (CVE-2025-65715, CVE-2025-65716, CVE-2025-65717) in four popular IDE Extensions
https://www.ox.security/blog/four-vulnerabilities-expose-a-massive-security-blind-spot-in-ide-extensions/
Grandstream GXP1600 VoIP Phones
https://www.rapid7.com/blog/post/ve-cve-2026-2329-critical-unauthenticated-stack-buffer-overflow-in-grandstream-gxp1600-voip-phones-fixed/
Tracking Malware Campaigns With Reused Material
https://isc.sans.edu/diary/Tracking%20Malware%20Campaigns%20With%20Reused%20Material/32726
From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day
https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day
Windows Admin Center Elevation of Privilege Vulnerability CVE-2026-26119
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26119
DNS-PERSIST-01: A New Model for DNS-based Challenge Validation
https://letsencrypt.org/2026/02/18/dns-persist-01.html
Defending Web Apps
https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices
Fake Incident Report Used in Phishing Campaign
https://isc.sans.edu/diary/Fake%20Incident%20Report%20Used%20in%20Phishing%20Campaign/32722
Divide and conquer: how the new Keenadu backdoor exposed links between major Android botnets https://securelist.com/keenadu-android-backdoor/118913/
CVE-2026-25903: Apache NiFi: Missing Authorization of Restricted Permissions for Component Updates https://seclists.org/oss-sec/2026/q1/166
The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time
https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/
Encrypted RCS in iOS/iPadOS
https://developer.apple.com/documentation/ios-ipados-release-notes/ios-ipados-26_4-release-notes
2026 64-Bits Malware Trend
https://isc.sans.edu/diary/2026%2064-Bits%20Malware%20Trend/32718
A Comparative Security Analysis of Three Cloud-based Password Managers
https://zkae.io
Infostealer Infection Targeting OpenClaw Configurations
https://www.infostealers.com/article/hudson-rock-identifies-real-world-infostealer-infection-targeting-openclaw-configurations/
AI-Powered Knowledge Graph Generator & APTs
https://isc.sans.edu/diary/AI-Powered%20Knowledge%20Graph%20Generator%20%26%20APTs/32712
nslookup and ClickFix
https://x.com/MsftSecIntel/status/2022456612120629742
Google Chrome 0-Day Patch
https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html
TURN Security Threats
https://www.enablesecurity.com/blog/turn-server-security-threats/
Four Seconds to Botnet - Analyzing a Self-Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary]
https://isc.sans.edu/diary/Four%20Seconds%20to%20Botnet%20-%20Analyzing%20a%20Self%20Propagating%20SSH%20Worm%20with%20Cryptographically%20Signed%20C2%20%5BGuest%20Diary%5D/32708
OpenSSH Update on MacOS
https://www.openssh.org/releasenotes.html
Employee Monitoring and SimpleHelp Software Abused in Ransomware Operations
https://www.huntress.com/blog/employee-monitoring-simplehelp-abused-in-ransomware-operations
WSL in the Malware Ecosystem https://isc.sans.edu/diary/32704
Apple Patches Everything: February 2026
https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20February%202026/32706
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
Microsoft Patch Tuesday - February 2026
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20February%202026/32700
Refreshing the root of trust
https://blogs.windows.com/windowsexperience/2026/02/10/refreshing-the-root-of-trust-industry-collaboration-on-secure-boot-certificate-updates/
Fake 7-Zip downloads are turning home PCs into proxy nodes
https://www.malwarebytes.com/blog/threat-intel/2026/02/fake-7-zip-downloads-are-turning-home-pcs-into-proxy-nodes
FortiNet Vulnerabilities
https://fortiguard.fortinet.com/psirt/FG-IR-25-093 https://fortiguard.fortinet.com/psirt/FG-IR-25-1052
Quick Howto: Extract URLs from RTF files
https://isc.sans.edu/diary/Quick%20Howto%3A%20Extract%20URLs%20from%20RTF%20files/32692
German Agencies Warn of Signal Phishing Targeting Politicians, Military, Journalists
German: https://thehackernews.com/2026/02/german-agencies-warn-of-signal-phishing.html English: https://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-02-06-gemeinsame-warnmitteilung-phishing.pdf?__blob=publicationFile&v=3
Someone Knows Bash Far Too Well, And We Love It - Pre-Auth RCEs
https://labs.watchtowr.com/someone-knows-bash-far-too-well-and-we-love-it-ivanti-epmm-pre-auth-rces-cve-2026-1281-cve-2026-1340/
Pre-Auth RCE in BeyondTrust Remote Support & PRA CVE-2026-1731
https://www.hacktron.ai/blog/cve-2026-1731-beyondtrust-remote-support-rce
https://www.beyondtrust.com/trust-center/security-advisories/bt26-02
Fortinet FortiClientEMS SQLi in the administrative interface
https://fortiguard.fortinet.com/psirt/FG-IR-25-1142
Microsoft Patches Four Azure Vulnerabilities (three critical)
https://msrc.microsoft.com/update-guide/vulnerability
Evaluating and mitigating the growing risk of LLM-discovered 0-days
https://red.anthropic.com/2026/zero-days/
Gitlab AI Gateway Vulnerability CVE-2026-1868
https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/
Broken Phishing URLs
https://isc.sans.edu/diary/Broken+Phishing+URLs/32686/
n8n command injection vulnerability
https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8
Android February Update
https://source.android.com/docs/security/bulletin/pixel/2026/2026-02-01?hl=en
Watchguard Firebox LDAP Injection
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00001
Malicious Script Delivering More Maliciousness
https://isc.sans.edu/diary/Malicious+Script+Delivering+More+Maliciousness/32682
Synectix LAN 232 TRIO Unauthenticated Web Admin CVE-2026-1633
https://www.cisa.gov/news-events/ics-advisories/icsa-26-034-04
Google Chrome Patches
https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop.html
LookOut: Discovering RCE and Internal Access on Looker (Google Cloud & On-Prem)
https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout
Detecting and Monitoring OpenClaw (clawdbot, moltbot)
https://isc.sans.edu/diary.html/Detecting+and+Monitoring+OpenClaw+%28clawdbot%2C+moltbot%29/32678/#comment
Synology telnetd Patch
https://www.synology.com/en-us/releaseNote/DSM
GlassWorm Loader Hits Open VSX via Developer Account Compromise
https://socket.dev/blog/glassworm-loader-hits-open-vsx-via-suspected-developer-account-compromise
Scanning for exposed Anthropic Models https://isc.sans.edu/diary/Scanning%20for%20exposed%20Anthropic%20Models/32674
Notepad++ Hijacked by State-Sponsored Hackers https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/
https://notepad-plus-plus.org/news/hijacked-incident-info-update/
Insecure Websockets in OpenClaw
https://zeropath.com/blog/openclaw-clawdbot-credential-theft-vulnerability
Malicious OpenClaw Skills
https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting
Exposed OpenClaw Instances
https://censys.com/blog/openclaw-in-the-wild-mapping-the-public-exposure-of-a-viral-ai-assistant
Google Presentation Abuse
https://isc.sans.edu/diary/Google+Presentations+Abused+for+Phishing/32668/
Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 & CVE-2026-1340)
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US
Microsoft NTLM Strategy
https://techcommunity.microsoft.com/blog/windows-itpro-blog/advancing-windows-security-disabling-ntlm-by-default/4489526
No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network
Google dismantled the IPIDEA network that used residential proxies to route malicious traffic.
https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network
Fake Clawdbot VS Code Extension Installs ScreenConnect RAT
The news about Clawdbot (now Moltbot) is used to distribute malware, in particular malicious VS Code extensions.
https://www.aikido.dev/blog/fake-clawdbot-vscode-extension-malware
Threat Bulletin: Critical eScan Supply Chain Compromise
Anti-virus vendor eScan was compromised, and its update servers were used to install malware on some customer systems.
https://www.morphisec.com/blog/critical-escan-threat-bulletin/
Odd WebLogic Request. Possible CVE-2026-21962 Exploit Attempt or AI Slop?
We are seeing attempts to attack CVE-2026-21962, a recent weblog vulnerability, using a non-working AI slop exploit
https://isc.sans.edu/diary/Odd%20WebLogic%20Request.%20Possible%20CVE-2026-21962%20Exploit%20Attempt%20or%20AI%20Slop%3F/32662
Fortinet Patches are Rolling Out
Fortinet is starting to roll out patches for the recent SSO vulnerability
https://fortiguard.fortinet.com/psirt/FG-IR-26-060
SolarWinds Web Helpdesk Vulnerability
Another set of vulnerabilities in SolarWinds Web Helpdesk may result in unauthenticated system access
https://horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/
Initial Stages of Romance Scams [Guest Diary]
Romance scams often start with random text messages that appear to be misrouted . This guest diary by Faris Azhari is following some of the initial stages of such a scam.
https://isc.sans.edu/diary/Initial%20Stages%20of%20Romance%20Scams%20%5BGuest%20Diary%5D/32650
Denial of Service Vulnerabilities in React Server Components
Another folowup fix for the severe React vulnerability from last year, but now only fixing a DoS condition.
https://github.com/facebook/react/security/advisories/GHSA-83fc-fqcc-2hmg
OpenSSL Updates
OpenSSL released its monthly updates, fixing a potential RCE.
https://openssl-library.org/news/vulnerabilities/
Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission
Many Kubernetes Helm Charts are vulnerable to possible remote code executions due to unclear defined access controls.
https://grahamhelton.com/blog/nodes-proxy-rce
Scanning Webserver with pwd as a Starting Path
Attackers are adding the output of the pwd command to their web scans.
https://isc.sans.edu/diary/x/32654
Microsoft Office Security Feature Bypass Vulnerability CVE-2026-21509
Microsoft released an out-of-band patch for Office fixing a currently exploited vulnerability.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21509
Exposed Clawdbot Instances
Many users of the AI tool clawdbot expose instances without access control.
https://x.com/theonejvo/status/2015485025266098536
Analysis of Single Sign-On Abuse on FortiOS
Fortinet released an advisory. FortiOS devices are vulnerable if configured with any SAML integration, not just FortiCloud
https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios
Outlook OOB Update
Microsoft released a non-security OOB Update for Outlook, fixing an issue introduced with this months security patches.
https://support.microsoft.com/en-us/topic/january-24-2026-kb5078127-os-builds-26200-7628-and-26100-7628-out-of-band-cf5777f6-bb4e-4adb-b9cd-2b64df577491
VMware vCenter Server Vulnerabilities Exploited (CVE-2024-37079, CVE-2024-37080, CVE-2024-37081)
A VMWare vCenter vulnerability patched last June is now actively exploited.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453
Is AI-Generated Code Secure?
Xavier used the free static code analysis tool Bandit to review code he wrote with heavy AI support.
https://isc.sans.edu/diary/Is%20AI-Generated%20Code%20Secure%3F/32648
Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts
Arctic Wolf summarized some of the attacks it is seeing against FortiGate devices via the insufficiently patched SSL vulnerability.
https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/
ISC BIND DoS vulnerability in Drone ID Records
HHIT and BRID records, which are used as part of Drone ID, can be used to crash named if their length is 3 bytes.
https://marlink.com/resources/knowledge-hub/isc-bind-vulnerability-discovered-and-disclosed-by-marlink-cyber/
SmarterTools SmarterMail Password Reset Vulnerability
SmarterTools recently patched a trivial vulnerability in SmarterMail that would allow anybody without authentication to reset administrator passwords.
https://labs.watchtowr.com/attackers-with-decompilers-strike-again-smartertools-smartermail-wt-2026-0001-auth-bypass/
Automatic Script Execution In Visual Studio Code
Visual Studio Code will read configuration files within the source code that may lead to code execution.
https://isc.sans.edu/diary/Automatic%20Script%20Execution%20In%20Visual%20Studio%20Code/32644
Cisco Unified Communications Products Remote Code Execution Vulnerability A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-voice-rce-mORhqY4b
Zoom Vulnerability
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to execute remote code on the MMR via network access.
https://www.zoom.com/en/trust/security-bulletin/zsb-26001/
Possible new SSO Exploit (CVE-2025-59718) on 7.4.9
https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/
SANS SOC Survey
The 2026 SOC Survey is open, and we need your input to create a meaningful report. Please share your experience so we can advocate for what actually works in the trenches.
https://survey.sans.org/jfe/form/SV_3ViqWZgWnfQAzkO?is=socsurveystormcenter
Add Punycode to your Threat Hunting Routine
Punycode patterns in DNS queries make excellent hunting opportunities.
https://isc.sans.edu/diary/Add%20Punycode%20to%20your%20Threat%20Hunting%20Routine/32640
GNU InetUtils Security Advisory: remote authentication by-pass intelnetd
telnetd shipping with InetUtils suffers from a critical authentication by-pass vulnerability.
https://www.openwall.com/lists/oss-security/2026/01/20/2
6-day and IP Address Certificates are Generally Available
Let s Encrypt will now offer 6-day certificates as an option. These short-lived certificates can be used for IP addresses.
https://letsencrypt.org/2026/01/15/6day-and-ip-general-availability
Oracle Quarterly Critical Patch Update
Oracle released its first quarterly patches for 2026, fixing 337 vulnerabilities
https://www.oracle.com/security-alerts/cpujan2026.html#AppendixFMW
"How many states are there in the United States?"
Attackers are actively scanning for LLMs, fingerprinting them using the query How many states are there in the United States? .
https://isc.sans.edu/diary/%22How%20many%20states%20are%20there%20in%20the%20United%20States%3F%22/32618
Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation
Mandiant is publicly releasing a comprehensive dataset of Net-NTLMv1 rainbow tables to underscore the urgency of migrating away from this outdated protocol.
https://cloud.google.com/blog/topics/threat-intelligence/net-ntlmv1-deprecation-rainbow-tables
Out-of-band update to address issues observed with the January 2026 Windows security update
Microsoft has identified issues upon installing the January 2026 Windows security update. To address these issues, an out-of-band (OOB) update was released today, January 17, 2026
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center
Battling Cryptojacking, Botnets, and IABs
Cryptojacking often comes with less obvious addons, like SSH backdoors
https://isc.sans.edu/diary/Battling%20Cryptojacking%2C%20Botnets%2C%20and%20IABs%20%5BGuest%20Diary%5D/32632
Microsoft Copilot Reprompt Attacks
Adding a query parameter to the URL may prefill a Copilot prompt, altering the meaning of the prompts that follow.
https://www.varonis.com/blog/reprompt
Hijacking Bluetooth Accessories Using Google Fast Pair
Google s fast pair protocol is often not implemented correctly, allowing the Hijacking of Bluetooth accessories
https://whisperpair.eu/#about
Infection repeatedly adds scheduled tasks and increases traffic to the same C2 domain
https://isc.sans.edu/diary/Infection%20repeatedly%20adds%20scheduled%20tasks%20and%20increases%20traffic%20to%20the%20same%20C2%20domain/32628
BodySnatcher (CVE-2025-12420): A Broken Authentication and Agentic Hijacking Vulnerability in ServiceNow
https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/
Starlink Terminal GPS Spoofing/Jamming Detection in Iran
https://github.com/narimangharib/starlink-iran-gps-spoofing/blob/main/starlink-iran.md
Microsoft Patch Tuesday January 2026
Microsoft released patches for 113 vulnerabilities. This includes one already exploited vulnerability, one that was made public before today and eight critical vulnerabilities.
https://isc.sans.edu/diary/January%202026%20Microsoft%20Patch%20Tuesday%20Summary/32624
Adobe Patches
Adobe released patches for five products. The code execution vulnerabilities in ColdFusion and Acrobat Reader deserve special attention.
https://helpx.adobe.com/security.html
Fortinet Patches
Fortnet patched two products today, one suffering from an SSRF vulnerability.
https://fortiguard.fortinet.com/psirt/FG-IR-25-783
https://fortiguard.fortinet.com/psirt/FG-IR-25-084
ConsentFix: Analysing a browser-native ClickFix-style attack that hijacks OAuth consent grants
Attackers are tricking victims to copy/paste OAUTH URLs, including credentials, to a fake CAPTCHA
https://pushsecurity.com/blog/consentfix
n8n supply chain attack
Malicious npm pagackages were used to attempt to obtain user OAUTH credentials for NPM.
https://www.endorlabs.com/learn/n8mare-on-auth-street-supply-chain-attack-targets-n8n-ecosystem
Gogs 0-Day Exploited in the Wild
An at the time unpachted flaw in Gogs was exploited to compromise git repos.
https://www.wiz.io/blog/wiz-research-gogs-cve-2025-8110-rce-exploit
Telegram Proxy Link Abuse
Telegram proxy links have been abused to deanonymize users
https://x.com/GangExposed_RU/status/2009961417781457129
Malicious Process Environment Block Manipulation
The process environment block contains metadata about particular processes, but can be manipulated.
https://isc.sans.edu/diary/Malicious+Process+Environment+Block+Manipulation/32614/
YARA-X 1.11.0 Release: Hash Function Warnings
The latest version of YARA will warn users if a hash rule attempts to match an invalid hash.
https://isc.sans.edu/diary/YARA-X%201.11.0%20Release%3A%20Hash%20Function%20Warnings/32616
VideoLAN Security Bulletin VLC 3.0.22 CVE-2025-51602
VideoLAN fixed several vulnerabilities in its VLC software.
https://www.videolan.org/security/sb-vlc3022.html
Apache NimBLE Bluetooth vulnerabilities
NimBLE is a Bluetooth stack popular in IoT devices. An update fixes some eavesdropping and pairing vulnerabilities.
https://mynewt.apache.org/cve/
Analysis using Gephi with DShield Sensor Data
Gephi is a neat tool to create interactive data visualizations. It can be applied to honeypot data to find data clusters.
https://isc.sans.edu/diary/Analysis%20using%20Gephi%20with%20DShield%20Sensor%20Data/32608
zlib v1.3.1.2 Global Buffer Overflow in TGZfname() of zlib untgz Utility
The untgz utility that is part of zlib suffers from a straightforward buffer overflow in the filename parameter
https://seclists.org/fulldisclosure/2026/Jan/3
GnuPG Vulnerabilities
Several vulnerabilities in GnuPG were disclosed during a recent talk at the CCC congress.
https://gpg.fail
Cisco DNS Bug Reboot
Last night, several Cisco users reported that their switches rebooted. The issue appears to be related to a change Cloudflare made in the order of CNAME records. Only users using 1.1.1.1 as a recursive resolver appear to be affected.
https://community.cisco.com/t5/switches-small-business/got-fatal-error-cbs350-24t-4g/td-p/5359883?utm_source=chatgpt.com
A phishing campaign with QR codes rendered using an HTML table
Phishing emails are bypassing filters by encoding QR codes as HTML tables.
https://isc.sans.edu/diary/A%20phishing%20campaign%20with%20QR%20codes%20rendered%20using%20an%20HTML%20table/32606
n8n vulnerabilities
In recent days, several new n8n vulnerabilities were disclosed. Ensure that you update any on-premises installations and carefully consider what to use n8n for.
https://www.cyera.com/research-labs/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858
https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg
Power bank feature creep is out of control
Simple power banks are increasingly equipped with advanced features, including networking, which may expose them to security risks.
https://www.theverge.com/tech/856225/power-banks-are-the-latest-victims-of-feature-creep
Tool Review: Tailsnitch
Tailsnitch is a tool to audit your Tailscale configuration. It does a comprehensive analysis of your configuration and suggests (or even applies) fixes.
https://isc.sans.edu/diary/Tool%20Review%3A%20Tailsnitch/32602
D-Link DSL Command Injection via DNS Configuration Endpoint
A new vulnerability in very old D-Link DSL modems is currently being exploited.
https://www.vulncheck.com/advisories/dlink-dsl-command-injection-via-dns-configuration-endpoint
TOTOLINK EX200 firmware-upload error handling can activate an unauthenticated root telnet service
TOTOLINK extenders may start a telnet server and allow unauthenticated access if a firmware update fails.
https://kb.cert.org/vuls/id/295169
Risks of OOB Access via IP KVM Devices
Recently, cheap IP KVMs have become popular. But their deployment needs to be secured.
https://isc.sans.edu/diary/Risks%20of%20OOB%20Access%20via%20IP%20KVM%20Devices/32598
Tailsnitch
Tailsnitch is a tool to review your Tailscale configuration for vulnerabilities
https://github.com/Adversis/tailsnitch
Net-SNMP snmptrapd vulnerability
A new vulnerability in snmptrapd may lead to remote code execution
https://github.com/net-snmp/net-snmp/security/advisories/GHSA-4389-rwqf-q9gq
Cryptocurrency Scam Emails and Web Pages As We Enter 2026
Scam emails are directing victims to confidence scams attempting to steal cryptocurrencies.
https://isc.sans.edu/diary/Cryptocurrency%20Scam%20Emails%20and%20Web%20Pages%20As%20We%20Enter%202026/32594
Debugging DNS response times with tshark
tshark is a powerful tool to debug DNS timing issues.
https://isc.sans.edu/diary/Debugging+DNS+response+times+with+tshark/32592/
Old Fortinet Devices Have not been updated
Over 10,000 Fortinet devices are still vulnerable to a five year old vulnerability
https://www.bleepingcomputer.com/news/security/over-10-000-fortinet-firewalls-exposed-to-ongoing-2fa-bypass-attacks/
MongoDB Unauthenticated Attacker Sensitive Memory Leak CVE-2025-14847
Over the Christmas holiday, MongoDB patched a sensitive memory leak vulnerability that is now actively being exploited
https://www.mongodb.com/community/forums/t/important-mongodb-patch-available/332977
https://github.com/mongodb/mongo/commit/505b660a14698bd2b5233bd94da3917b585c5728
https://www.ox.security/blog/attackers-could-exploit-zlib-to-exfiltrate-data-cve-2025-14847/
https://github.com/joe-desimone/mongobleed/
DLLs & TLS Callbacks
As a follow-up to last week's diary about DLL Entrypoints, Didier is looking at TLS ( Thread Local Storage ) and how it can be abused.
https://isc.sans.edu/diary/DLLs%20%26%20TLS%20Callbacks/32580
FreeBSD Remote code execution via ND6 Router Advertisements
A critical vulnerability in FreeBSD allows for remote code execution. But an attacker must be on the same network.
https://www.freebsd.org/security/advisories/FreeBSD-SA-25:12.rtsold.asc
NIST Time Server Problems
The atomic ensemble time scale at the NIST Boulder campus has failed due to a prolonged utility power outage. One impact is that the Boulder Internet Time Services no longer have an accurate time reference.
https://tf.nist.gov/tf-cgi/servers.cgi https://groups.google.com/a/list.nist.gov/g/internet-time-service/c/o0dDDcr1a8I
Positive trends related to public IP range from the year 2025
Fewer ICS systems, as well as fewer systems with outdated SSL versions, are exposed to the internet than before. The trend isn t quite clean for ISC, but SSL2 and SSL3 systems have been cut down by about half.
https://isc.sans.edu/diary/Positive%20trends%20related%20to%20public%20IP%20ranges%20from%20the%20year%202025/32584
Hewlett-Packard Enterprise OneView Software, Remote Code Execution
HPs OneView Software allows for unauthenticated code execution
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbgn04985en_us&docLocale=en_US#vulnerability-summary-1
Trufflehog Detecting JWTs with Public Keys
Trufflehog added the ability to detect JWT tokens and validate them using public keys.
https://trufflesecurity.com/blog/trufflehog-now-detects-jwts-with-public-key-signatures-and-verifies-them-for-liveness
Maybe a Little Bit More Interesting React2Shell Exploit
Attackers are branching out to attack applications that initial exploits may have missed. The latest wave of attacks is going after less common endpoints and attempting to exploit applications that do not have Next.js exposed.
https://isc.sans.edu/diary/Maybe%20a%20Little%20Bit%20More%20Interesting%20React2Shell%20Exploit/32578
UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager
Cisco s Security Email Gateway and Secure Email and Web Manager patch an already-exploited vulnerability.
https://blog.talosintelligence.com/uat-9686/
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4
SONICWALL SMA1000 APPLIANCE LOCAL PRIVILEGE ESCALATION VULNERABILITY
A local privilege escalation vulnerability, which SonicWall patched today, is already being exploited.
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019
Google releases vulnerability details
Google updated last week s advisory by adding a CVE to the mystery vulnerability and adding a statement that it affects WebGPU. No new patch was released.
https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_16.html
Beyond RC4 for Windows authentication
Microsoft outlined its transition plan to move away from RC4 for authentication and published guidance and tools to facilitate this change.
https://www.microsoft.com/en-us/windows-server/blog/2025/12/03/beyond-rc4-for-windows-authentication
FortiCloud SSO Login Vuln Exploited
Arctic Wolf observed exploit attempts against vulnerable FortiGate appliances.
https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/
FrePBX Vulnerability
Horizon3.ai identified three distinct vulnerabilities in FreePBX. In particular, the authentication by-pass issue should be of concern, but default FreePBX installs do not use the vulnerable web authentication feature.
https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/
More React2Shell Exploits CVE-2025-55182
Our honeypots continue to detect numerous React2Shell variants. Some using slightly modified exploits
https://isc.sans.edu/diary/More%20React2Shell%20Exploits%20CVE-2025-55182/32572
The Fragile Lock: Novel Bypasses For SAML Authentication
SAML is a tricky protocol to implement correctly, in particular if different XML parsers are used that may not always agree on how to parse a specific message
https://portswigger.net/research/the-fragile-lock
December Updates Causes issues with Microsoft Message Queuing
https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#message-queuing--msmq--might-fail-with-the-december-2025-windows-security-update
Abusing DLLs EntryPoint for the Fun
DLLs will not just execute code when some of their functions are called, but also as they are loaded.
https://isc.sans.edu/diary/Abusing%20DLLs%20EntryPoint%20for%20the%20Fun/32562
Apple Patches Everything: December 2025 Edition
Apple released patches for all of its operating systems, fixing two already exploited vulnerabilities.
ClickFix Attacks Still Using the Finger
ClickFix Attacks Still Using the Finger
Two examples of ClickFix attacks abusing the finger protocol to load additional malware
Denial of Service and Source Code Exposure in React Server Components
Denial of Service and Source Code Exposure in React Server Components
After last week's critical patch, three more, but less critical, vulnerabilities were identified in React Server Components.
https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components
Using AI Gemma 3 Locally with a Single CPU
Installing AI models on modes hardware is possible and can be useful to experiment with these models on premise
https://isc.sans.edu/diary/Using%20AI%20Gemma%203%20Locally%20with%20a%20Single%20CPU%20/32556
Mystery Google Chrome 0-Day Vulnerability
Google released an update for Google Chrome fixing a vulnerability that is already being exploited, but has not CVE number assigned to it yet
https://chromereleases.googleblog.com/2025/12/stable-channel-update-for-desktop_10.html
SOAPwn: Pwning NET Framework Applications Through HTTP Client Proxies And WSDL
Watchtwr identified a common vulnerability in SOAP implementations using .Net
https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/
Possible exploit variant for CVE-2024-9042 (Kubernetes OS Command Injection)
We observed HTTP requests with our honeypot that may be indicative of a new version of an exploit against an older vulnerability. Help us figure out what is going on.
https://isc.sans.edu/diary/Possible%20exploit%20variant%20for%20CVE-2024-9042%20%28Kubernetes%20OS%20Command%20Injection%29/32554
React2Shell: Technical Deep-Dive & In-the-Wild Exploitation of CVE-2025-55182
Wiz has a writeup with more background on the React2Shell vulnerability and current attacks
https://www.wiz.io/blog/nextjs-cve-2025-55182-react2shell-deep-dive
Notepad++ Update Hijacking
Notepad++ s vulnerable update process was exploited
https://notepad-plus-plus.org/news/v889-released/
New macOS PackageKit Privilege Escalation
A PoC was released for a new privilege escalation vulnerability in macOS. Currently, there is no patch.
https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html
Microsoft Patch Tuesday
Microsoft released its regular monthly patch on Tuesday, addressing 57 flaws.
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202025/32550
Adobe Patches
Adobe patched five products. The remote code execution in ColdFusion, as well as the code execution issue in Acrobat, will very likely see exploits soon.
https://helpx.adobe.com/security.html
Ivanti Endpoint Manager Patches
Ivanti patched four vulnerabilities in End Point Manager.
https://forums.ivanti.com/s/article/Security-Advisory-EPM-December-2025-for-EPM-2024?language=en_US
Fortinet FortiCloud SSO Vulnerability
Due to a cryptographic vulnerability, Forinet s FortiCloud SSO authentication is bypassable.
https://fortiguard.fortinet.com/psirt/FG-IR-25-647
ruby-saml vulnerability
Ruby fixed a vulnerability in ruby-saml. The issue is due to an incomplete patch for another vulnerability a few months ago.
https://github.com/SAML-Toolkits/ruby-saml/security/advisories/GHSA-9v8j-x534-2fx3
nanoKVM Vulnerabilities
The nanoKVM device updates firmware insecurely; however, the microphone that the authors of the advisory referred to as undocumented may actually be documented in the underlying hardware description.
https://www.tomshardware.com/tech-industry/cyber-security/researcher-finds-undocumented-microphone-and-major-security-flaws-in-sipeed-nanokvm
Ghostframe Phishing Kit
The Ghostframe phishing kit uses iFrames and random subdomains to evade detection
https://blog.barracuda.com/2025/12/04/threat-spotlight-ghostframe-phishing-kit
WatchGuard Advisory
WatchGuard released an update for its Firebox appliance, fixing ten vulnerabilities. Five of these are rated as High.
https://www.watchguard.com/wgrd-psirt/advisories
AutoIT3 Compiled Scripts Dropping Shellcodes
Malicious AutoIT3 scripts are usign the FileInstall function to include additional scripts at compile time that are dropped as temporary files during execution.
https://isc.sans.edu/diary/AutoIT3%20Compiled%20Scripts%20Dropping%20Shellcodes/32542
React2Shell Update
The race is on to patch vulnerable systems. Various groups are aggressively scanning the internet with different exploit variants. Some attempt to bypass WAFs.
https://blog.cloudflare.com/5-december-2025-outage/
https://aws.amazon.com/blogs/security/china-nexus-cyber-threat-groups-rapidly-exploit-react2shell-vulnerability-cve-2025-55182/
Apache Tika XXE Flaw
Apache s Tika library patched a XXE flaw.
https://lists.apache.org/thread/s5x3k93nhbkqzztp1olxotoyjpdlps9k
Nation-State Attack or Compromised Government? [Guest Diary]
An IP address associated with the Indonesian Government attacked one of our interns' honeypots.
https://isc.sans.edu/diary/Nation-State%20Attack%20or%20Compromised%20Government%3F%20%5BGuest%20Diary%5D/32536
React Update
Working exploits for the React vulnerability patched yesterday are not widely available
Array Networks Array AG Vulnerablity
A recently patched vulnerability in Array Networks Array AG VPN gateways is actively exploited.
https://www.jpcert.or.jp/at/2025/at250024.html
Attempts to Bypass CDNs
Our honeypots recently started receiving scans that included CDN specific headers.
https://isc.sans.edu/diary/Attempts%20to%20Bypass%20CDNs/32532
React Vulnerability CVE-2025-55182
React patched a critical vulnerability in React server components. Exploitation is likely imminent.
https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components
Unveiling 3 PickleScan Vulnerabilities
The PyTorch AI model security tool, PickleScan, has patched three critical vulnerabilities.
https://jfrog.com/blog/unveiling-3-zero-day-vulnerabilities-in-picklescan/
SmartTube Android App Compromise
The key a developer used to sign the Android YouTube player SmartTube was compromised and used to publish a malicious version.
https://github.com/yuliskov/SmartTube/issues/5131#issue-3670629826
https://github.com/yuliskov/SmartTube/releases/tag/notification
Two Years, 17K Downloads: The NPM Malware That Tried to Gaslight Security Scanners
Over the course of two years, a malicious NPM package was updated to evade detection and has now been identified, in part, due to its attempt to bypass AI scanners through prompt injection.
https://www.koi.ai/blog/two-years-17k-downloads-the-npm-malware-that-tried-to-gaslight-security-scanners
Stored XSS Vulnerability via SVG Animation, SVG URL, and MathML Attributes
Angular fixed a store XSS vulnerability.
https://github.com/angular/angular/security/advisories/GHSA-v4hv-rgfq-gp49
Hunting for SharePoint In-Memory ToolShell Payloads
A walk-through showing how to analyze ToolShell payloads, starting with acquiring packets all the way to decoding embedded PowerShell commands.
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Hunting%20for%20SharePoint%20In-Memory%20ToolShell%20Payloads/32524
Android Security Bulletin December 2025
Google fixed numerous vulnerabilities with its December Android update. Two of these vulnerabilities are already being exploited.
https://source.android.com/docs/security/bulletin/2025-12-01
4.3 Million Browsers Infected: Inside ShadyPanda's 7-Year Malware Campaign
A group or individual released several browser extensions that worked fine for years until an update injected malicious code into the extension
https://www.koi.ai/blog/4-million-browsers-infected-inside-shadypanda-7-year-malware-campaign
Fake adult websites pop realistic Windows Update screen to deliver stealers via ClickFix
The latest variant of ClickFix tricks users into copy/pasting commands by displaying a fake blue screen of death.
https://www.acronis.com/en/tru/posts/fake-adult-websites-pop-realistic-windows-update-screen-to-deliver-stealers-via-clickfix/
B2B Guest Access Creates an Unprotected Attack Vector
Users may be tricked into joining an external Teams workspace as a guest, bypassing protections typically enabled for Teams workspaces.
https://www.ontinue.com/resource/blog-microsoft-chat-with-anyone-understanding-phishing-risk/
Geoserver XXE Vulnerability CVE-2025-58360
Geoserver patched an external XML entity (XXE) vulnerability.
https://helixguard.ai/blog/CVE-2025-58360
Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications
Spyware attacks messaging applications in part by triggering vulnerabilities in messaging applications but also by deploying tools like keystroke loggers and screenshot applications.
https://www.cisa.gov/news-events/alerts/2025/11/24/spyware-allows-cyber-threat-actors-target-users-messaging-applications
Stop Putting Your Passwords Into Random Websites Yes. Just Stop!
https://labs.watchtowr.com/stop-putting-your-passwords-into-random-websites-yes-seriously-you-are-the-problem/
Fluentbit Vulnerability
https://www.oligo.security/blog/critical-vulnerabilities-in-fluent-bit-expose-cloud-environments-to-remote-takeover
Happy Thanksgiving. Next podcast on Monday after Thanksgiving.
Conflicts between URL mapping and URL based access control.
Mapping different URLs to the same script, and relying on URL based authentication at the same time, may lead to dangerous authentication and access control gaps.
https://isc.sans.edu/diary/Conflicts%20between%20URL%20mapping%20and%20URL%20based%20access%20control./32518
Sha1-Hulud, The Second Coming
A new, destructive variant of the Shai-Hulud worm is currently spreading through NPM/Github repos.
https://www.koi.ai/incident/live-updates-sha1-hulud-the-second-coming-hundred-npm-packages-compromised
Hacklore: Cleaning up Outdated Security Advice
A new website, hacklore.org, has published an open letter from former CISOs and other security leaders aimed at addressing some outdated security advice that is often repeated.
https://www.hacklore.org
Use of CSS stuffing as an obfuscation technique?
Phishing sites stuff their HTML with benign CSS code. This is likely supposed to throw of simple detection engines
https://isc.sans.edu/diary/Use%20of%20CSS%20stuffing%20as%20an%20obfuscation%20technique%3F/32510
Critical Oracle Identity Manager Flaw Possibly Exploited as Zero-Day
Early exploit attempts for the vulnerability were part of Searchlight Cyber s research effort
https://www.securityweek.com/critical-oracle-identity-manager-flaw-possibly-exploited-as-zero-day/
ClamAV Cleaning Signature Database
ClamAV will significantly clean up its signature database
https://blog.clamav.net/2025/11/clamav-signature-retirement-announcement.html
Oracle Identity Manager Exploit Observation from September (CVE-2025-61757)
We observed some exploit attempts in September against an Oracle Identity Manager vulnerability that was patched in October, indicating that exploitation may have occurred prior to the patch being released.
https://isc.sans.edu/diary/Oracle%20Identity%20Manager%20Exploit%20Observation%20from%20September%20%28CVE-2025-61757%29/32506
https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/
DigitStealer: a JXA-based infostealer that leaves little footprint
https://www.jamf.com/blog/jtl-digitstealer-macos-infostealer-analysis/
SonicWall DoS Vulnerability
Sonicwall patched a DoS vulnerability in SonicOS
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0016
Adam Wilson: Automating Generative AI Guidelines: Reducing Prompt Injection Risk with 'Shift-Left' MITRE ATLAS Mitigation Testing
Unicode: It is more than funny domain names.
Unicode can cause a number of issues due to odd features like variance selectors and text direction issues.
https://isc.sans.edu/diary/Unicode%3A%20It%20is%20more%20than%20funny%20domain%20names./32472
FortiWeb Multiple OS command injection in API and CLI
A second silently patched vulnerability in FortiWeb is already being exploited in the wild.
https://fortiguard.fortinet.com/psirt/FG-IR-25-513
DLink DIR-878 Vulnerability
DLink disclosed four different vulnerabilities in its popular DIR-878 router. The router is end-of-life and DLink will not release patches
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10475
Operation WrtHug, The Global Espionage Campaign Hiding in Your Home Router
A new report, Operation WrtHug, has uncovered a massive, coordinated effort that has compromised thousands of ASUS routers worldwide.
https://securityscorecard.com/blog/operation-wrthug-the-global-espionage-campaign-hiding-in-your-home-router/
KongTuke Activity
This diary investigates how a recent Kong Tuke infections evolved all the way from starting with a ClickFix attack.
https://isc.sans.edu/diary/KongTuke%20activity/32498
Cloudflare Outage
Cloudflare suffered a large outage today after an oversized configuration file was loaded into its bot protection service
https://x.com/dok2001
Google Patches Chrome 0-Day
Google patched two vulnerabilities in Chrome. One of them is already being exploited.
https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop_17.html
Decoding Binary Numeric Expressions
Didier updated his number to hex script to support simple arithmetic operations in the text.
https://isc.sans.edu/diary/Decoding%20Binary%20Numeric%20Expressions/32490
Tea Token NPM Pollution
The NPM repository was hit with around 150,000 submissions that did not contain any useful contributions, but instead attempted to fake contributions to earn a new tea coin.
https://aws.amazon.com/blogs/security/amazon-inspector-detects-over-150000-malicious-packages-linked-to-token-farming-campaign/
IBM AIX NIMSH Vulnerabilities
IBM patched several critical vulnerablities in the NIMSH daemon
https://www.ibm.com/support/pages/node/7251173
Fortiweb Vulnerability
Fortinet, with significant delay, acknowledged a recently patched vulnerability after exploit attempts were seen publicly.
https://isc.sans.edu/diary/Honeypot+FortiWeb+CVE202564446+Exploits/32486
https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/
https://fortiguard.fortinet.com/psirt/FG-IR-25-910?ref=labs.watchtowr.com
Flnger.exe and ClickFix
Attackers started to use the finger.exe binary to retrieve additional payload in ClickFix attacks
https://isc.sans.edu/diary/Finger.exe%20%26%20ClickFix/32492
SmartApeSG campaign uses ClickFix page to push NetSupport RAT
A detailed analysis of a recent SamtApeSG campaign taking advantage of ClickFix
https://isc.sans.edu/diary/32474
Formbook Delivered Through Multiple Scripts
An analysis of a recent version of Formbook showing how it takes advantage of multiple obfuscation tricks
https://isc.sans.edu/diary/32480
sudo-rs vulnerabilities
Two vulnerabilities were patched in sudo-rs, the version of sudo written in Rust, showing that while Rust does have an advantage when it comes to memory safety, there are plenty of other vulnerabilities to worry about
https://ubuntu.com/security/notices/USN-7867-1
https://github.com/trifectatechfoundation/sudo-rs/security/advisories/GHSA-c978-wq47-pvvw?ref=itsfoss.com
SANS Holiday Hack Challenge
https://sans.org/HolidayHack
OWASP Top 10 2025 Release Candidate
OWASP published a release candidate for the 2025 version of its Top 10 list
https://owasp.org/Top10/2025/0x00_2025-Introduction/
Citrix/Cisco Exploitation Details
Amazon detailed how Citrix and Cisco vulnerabilities were used by advanced actors to upload webshells
https://aws.amazon.com/blogs/security/amazon-discovers-apt-exploiting-cisco-and-citrix-zero-days/
Testing Quantum Readyness
A website tests your services for post-quantum computing-resistant cryptographic algorithms
https://qcready.com/
Microsoft Patch Tuesday for November 2025
https://isc.sans.edu/diary/Microsoft+Patch+Tuesday+for+November+2025/32468/
Gladinet Triofox Vulnerability
Triofox uses the host header in lieu of proper access control, allowing an attacker to access the page managing administrators by simply setting the host header to localhost.
https://cloud.google.com/blog/topics/threat-intelligence/triofox-vulnerability-cve-2025-12480/
SAP November 2025 Patch Day
SAP fixed a critical vulnerability, fixed default credentials in its SQL Anywhere Monitor
https://onapsis.com/blog/sap-security-patch-day-november-2025/
Ivanti Endpoint Manager Updates
https://forums.ivanti.com/s/article/Security-Advisory-EPM-November-2025-for-EPM-2024?language=en_US
It isn t always defaults: Scans for 3CX Usernames
Our honeypots detected scans for usernames that may be related to 3CX business phone systems
https://isc.sans.edu/diary/It%20isn%27t%20always%20defaults%3A%20Scans%20for%203CX%20usernames/32464
Watchguard Default Password Controversy
A CVE number was assigned to a default password commonly used in Watchguard products. This was a documented username and password that was recently removed in a firmware upgrade.
https://github.com/cyberbyte000/CVE-2025-59396/blob/main/CVE-2025-59396.txt
https://nvd.nist.gov/vuln/detail/CVE-2025-59396
JavaScript expr-eval Vulnerability
The JavaScript expr-eval library was vulnerable to a code execution issue.
https://www.kb.cert.org/vuls/id/263614
Honeypot Requests for Code Repository
Attackers continue to scan websites for source code repositories. Keep your repositories outside your document root and proactively scan your own sites.
https://isc.sans.edu/diary/Honeypot%3A%20Requests%20for%20%28Code%29%20Repositories/32460
Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads
Newly discovered malicious .NET packages attempt to deliver a time-delayed attack targeting ICS systems.
https://socket.dev/blog/9-malicious-nuget-packages-deliver-time-delayed-destructive-payloads
Side Channel Leaks in Encrypted Traffic to LLMs
Traffic to LLMs can be profiled to discover the nature of prompts sent by a user based on the amount and structure of the encrypted data.
https://www.microsoft.com/en-us/security/blog/2025/11/07/whisper-leak-a-novel-side-channel-cyberattack-on-remote-language-models/
Binary Breadcrumbs: Correlating Malware Samples with Honeypot Logs Using PowerShell [Guest Diary]
Windows, with PowerShell, has a great scripting platform to match common Linux/Unix command line utilities.
https://isc.sans.edu/diary/Binary%20Breadcrumbs%3A%20Correlating%20Malware%20Samples%20with%20Honeypot%20Logs%20Using%20PowerShell%20%5BGuest%20Diary%5D/32454
RondoDox v2 Increases Exploits
The RondoDox (or RondoWorm) added a substantial amount of new exploits to its repertoire.
https://beelzebub.ai/blog/rondo-dox-v2/
Google Chrome Updates
Google released an update for Google Chrome addressing five vulnerabilities.
https://chromereleases.googleblog.com/2025/11/stable-channel-update-for-desktop.html
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
Cisco patched two critical vulnerabilities in its Contact Center Express software. These vulnerabilities may lead to a full system compromise.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-unauth-rce-QeN8h7mQ
Updates to Domainname API
Some updates to our domainname API will make it more flexible and make it easier and faster to get the complete dataset.
https://isc.sans.edu/diary/Updates%20to%20Domainname%20API/32452
Microsoft Teams Impersonation and Spoofing Vulnerabilities
Checkpoint released details about recently patched spoofing and impersonation vulnerabilities in Microsoft Teams
https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/
NViso Report: VSHELL
NViso published an amazingly detailed report describing the remote control implant VSHELL. The report includes details about the inner workings of the tool as well as detection ideas.
https://www.nviso.eu/blog/nviso-analyzes-vshell-post-exploitation-tool
Apple Patches Everything, Again
Apple released a minor OS upgrade across its lineup, fixing a number of security vulnerabilities.
https://isc.sans.edu/diary/Apple%20Patches%20Everything%2C%20Again/32448
Remote Access Tools Used to Compromise Trucking and Logistics
Attackers infect trucking and logistics companies with regular remote management tools to inject malware into other companies or learn about high-value loads in order to steal them.
https://www.proofpoint.com/us/blog/threat-insight/remote-access-real-cargo-cybercriminals-targeting-trucking-and-logistics
Google Android Patch Day
Google released its usual monthly Android updates this week
https://source.android.com/docs/security/bulletin/2025-11-01
XWiki SolrSearch Exploit Attempts CVE-2025-24893
We have detected a number of exploit attempts against XWiki taking advantage of a vulnerability that was added to the KEV list on Friday.
https://isc.sans.edu/diary/XWiki%20SolrSearch%20Exploit%20Attempts%20%28CVE-2025-24893%29%20with%20link%20to%20Chicago%20Gangs%20Rappers/32444
AMD Zen 5 Random Number Generator Bug
The RDSEED function for AMD s Zen 5 processors does return 0 more often than it should.
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7055.html
SleepyDuck malware invades Cursor through Open VSX
Yet another Open VSX extension stealing crypto credentials
https://secureannex.com/blog/sleepyduck-malware/
Scans for WSUS: Port 8530/8531 TCP, CVE-2025-59287
We did observe an increase in scans for TCP ports 8530 and 8531. These ports are associated with WSUS and the scans are likely looking for servers vulnerable to CVE-2025-59287
https://isc.sans.edu/diary/Scans%20for%20Port%208530%208531%20%28TCP%29.%20Likely%20related%20to%20WSUS%20Vulnerability%20CVE-2025-59287/32440
BADCANDY Webshell Implant Deployed via
The Australian Signals Directorate warns that they still see Cisco IOS XE devices not patches for CVE-2023-20198. A threat actor is now using this vulnerability to deploy the BADCANDY implant for persistent access
https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/badcandy
Improvements to Open VSX Security
In reference to the Glassworm incident, OpenVSX published a blog post outlining some of the security improvements they will make to prevent a repeat of this incident.
https://blogs.eclipse.org/post/mika l-barbero/open-vsx-security-update-october-2025
X-Request-Purpose: Identifying "research" and bug bounty related scans?
Our honeypots captured a few requests with bug bounty specific headers. These headers are meant to make it easier to identify requests related to bug bounty, and they are supposed to identify the researcher conducting the scans
https://isc.sans.edu/diary/X-Request-Purpose%3A%20Identifying%20%22research%22%20and%20bug%20bounty%20related%20scans%3F/32436
Proton Breach Observatory
Proton opened up its breach observatory. This website will collect information about breaches affecting companies that have not yet made the breach public.
https://proton.me/blog/introducing-breach-observatory
Microsoft Exchange Server Security Best Practices
A new document published by a collaboration of national cyber security agencies summarizes steps that should be taken to harden Exchange Server.
https://www.nsa.gov/Portals/75/documents/resources/cybersecurity-professionals/CSI_Microsoft_Exchange_Server_Security_Best_Practices.pdf?ver=9mpKKyUrwfpb9b9r4drVMg%3d%3d
MOVEit Vulnerability
Progress published an advisory for its file transfer program MOVEIt . This software has had heavily exploited vulnerabilities in the past.
https://community.progress.com/s/article/MOVEit-Transfer-Vulnerability-CVE-2025-10932-October-29-2025
How to Collect Memory-Only Filesystems on Linux Systems
Getting forensically sound copies of memory-only file systems on Linux can be tricky, as tools like dd do not work.
https://isc.sans.edu/diary/How%20to%20collect%20memory-only%20filesystems%20on%20Linux%20systems/32432
Microsoft Azure Front Door Outage
Today, Microsoft s Azure Front Door service failed, leading to users not being able to authenticate to various Azure-related services.
https://azure.status.microsoft/en-us/status
Docker-Compose Vulnerability
A vulnerability in docker-compose may be used to trick users into creating files outside the docker-compose directory
https://github.com/docker/compose/security/advisories/GHSA-gv8h-7v7w-r22q
Phishing with Invisible Characters in the Subject Line
Phishing emails use invisible UTF-8 encoded characters to break up keywords used to detect phishing (or spam). This is aided by mail clients not rendering some characters that should be rendered.
https://isc.sans.edu/diary/A%20phishing%20with%20invisible%20characters%20in%20the%20subject%20line/32428
Apache Tomcat PUT Directory Traversal
Apache released an update to Tomcat fixing a directory traversal vulnerability in how the PUT method is used. Exploits could upload arbitrary files, leading to remote code execution.
https://lists.apache.org/thread/n05kjcwyj1s45ovs8ll1qrrojhfb1tog
BIND9 DNS Spoofing Vulnerability
A PoC exploit is now available for the recently patched BIND9 spoofing vulnerability
https://gist.github.com/N3mes1s/f76b4a606308937b0806a5256bc1f918
Bytes over DNS
Didiear investigated which bytes may be transmitted as part of a hostname in DNS packets, depending on the client resolver and recursive resolver constraints
https://isc.sans.edu/diary/Bytes%20over%20DNS/32420
Unifi Access Vulnerability
Unifi fixed a critical vulnerability in it s Access product
https://community.ui.com/releases/Security-Advisory-Bulletin-056-056/ce97352d-91cd-40a7-a2f4-2c73b3b30191
OpenAI Atlas Omnibox Prompt Injection
OpenAI s latest browser can be jailbroken by inserting prompts in URLs
https://neuraltrust.ai/blog/openai-atlas-omnibox-prompt-injection
Bilingual Phishing for Cloud Credentials
Guy observed identical phishing messages in French and English attempting to phish cloud credentials
https://isc.sans.edu/diary/Phishing%20Cloud%20Account%20for%20Information/32416
Kaitai Struct WebIDE
The binary file analysis tool Kaitai Struct is now available in a web only version
https://isc.sans.edu/diary/Kaitai%20Struct%20WebIDE/32422
WSUS Emergency Update
Microsoft released an emergency patch for WSUS to fix a currently exploited critical vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287
Network Security Devices Endanger Orgs with 90s-era Flaws
Attackers increasingly use simple-to-exploit network security device vulnerabilities to compromise organizations.
https://www.csoonline.com/article/4074945/network-security-devices-endanger-orgs-with-90s-era-flaws.html
Infostealer Targeting Android Devices
This infostealer, written in Python, specifically targets Android phones. It takes advantage of Termux to gain access to data and exfiltrates it via Telegram.
https://isc.sans.edu/diary/Infostealer%20Targeting%20Android%20Devices/32414
Attackers exploit recently patched Adobe Commerce Vulnerability CVE-2025-54236
Six weeks after Adobe's emergency patch, SessionReaper (CVE-2025-54236) has entered active exploitation. E-Commerce security company SanSec has detected multiple exploit attempts.
https://sansec.io/research/sessionreaper-exploitation
Patch for BIND and unbound nameservers CVE-2025-40780
The Internet Systems Consortium (ISC.org), as well as the Unbound project, patched a flaw that may allow for DNS spoofing due to a weak random number generator.
https://kb.isc.org/docs/cve-2025-40780
WSUS Exploit Released CVE-2025-59287
Hawktrace released a walk through showing how to exploit the recently patched WSUS vulnerability
https://hawktrace.com/blog/CVE-2025-59287
webctrl.cgi/Blue Angel Software Suite Exploit Attempts. Maybe CVE-2025-34033 Variant?
Our honeypots detected attacks that appear to exploit CVE-2025-34033 or a similar vulnerability in the Blue Angle Software Suite.
https://isc.sans.edu/diary/webctrlcgiBlue+Angel+Software+Suite+Exploit+Attempts+Maybe+CVE202534033+Variant/32410
Oracle Critical Patch Update
Oracle released its quarterly critical patch update. The update includes patches for 374 vulnerabilities across all of Oracle s products. There are nine more patches for Oracle s e-Business Suite.
https://www.oracle.com/security-alerts/cpuoct2025.html#AppendixEBS
Rust TAR Library Vulnerability
A vulnerability in the popular, but no longer maintained, async-tar vulnerability could lead to arbitrary code execution
https://edera.dev/stories/tarmageddon
What time is it? Accuracy of pool.ntp.org.
How accurate and reliable is pool.ntp.org? Turns out it is very good!
https://isc.sans.edu/diary/What%20time%20is%20it%3F%20Accuracy%20of%20pool.ntp.org./32390
Xubuntu Compromise
The Xubuntu website was compromised last weekend and served malware
https://floss.social/@bluesabre/115401767635718361
Squid Proxy Vulnerability
The Squid team fixed an information disclosure vulnerabilty that may leak authentication credentials.
https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr
Lanscope Endpoint Manager Vulnerablity
https://jvn.jp/en/jp/JVN86318557/index.html
Using Syscall() for Obfuscation/Fileless Activity
Fileless malware written in Python can uses syscall() to create file descriptors in memory, evading signatures.
https://isc.sans.edu/diary/Using%20Syscall%28%29%20for%20Obfuscation%20Fileless%20Activity/32384
AWS Outages
AWS has had issues most of the day on Monday, affecting numerous services.
https://health.aws.amazon.com/health/status
Time Server Hack
China reports a compromise of its time standard servers.
https://thehackernews.com/2025/10/mss-claims-nsa-used-42-cyber-tools-in.html
TikTok Videos Promoting Malware InstallationTikTok Videos Promoting Malware Installation
Tiktok videos advertising ways to obtain software like Photoshop for free will instead trick users into downloading
https://isc.sans.edu/diary/TikTok%20Videos%20Promoting%20Malware%20Installation/32380
Google Ads Advertise Malware Targeting MacOS Developers
Hunt.io discovered Google ads that pretend to advertise tools like Homebrew and password managers to spread malware
https://hunt.io/blog/macos-odyssey-amos-malware-campaign
Satellite Transmissions are often unencrypted
A large amount of satellite traffic is unencrypted and easily accessible to eavesdropping
https://satcom.sysnet.ucsd.edu
New DShield Support Slack Workspace
Due to an error on Salesforce s side, we had to create a new Slack Workspace for DShield support.
https://isc.sans.edu/diary/New%20DShield%20Support%20Slack/32376
Attackers Exploiting Recently Patched Cisco SNMP Flaw (CVE-2025-20352)
Trend Micro published details explaining how attackers took advantage of a recently patched Cisco SNMP Vulnerability
https://www.trendmicro.com/en_us/research/25/j/operation-zero-disco-cisco-snmp-vulnerability-exploit.html
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte
Framework BIOS Backdoor
The mm command impleneted in Framework BIOS shells can be used to compromise a device pre-boot.
https://eclypsium.com/blog/bombshell-the-signed-backdoor-hiding-in-plain-sight-on-framework-devices/
SANS.edu Research: Mark Stephens, Validating the Effectiveness of MITRE Engage and Active Defense
https://www.sans.edu/cyber-research/validating-effectiveness-mitre-engage-active-defense/
Clipboard Image Stealer
Xavier presents an infostealer in Python that steals images from the clipboard.
https://isc.sans.edu/diary/Clipboard%20Pictures%20Exfiltration%20in%20Python%20Infostealer/32372
F5 Compromise
F5 announced a wide-ranging compromise today. Source code and information about unpatched vulnerabilities were stolen.
https://my.f5.com/manage/s/article/K000157005 https://my.f5.com/manage/s/article/K000156572 https://my.f5.com/manage/s/article/K000154696
Adobe Updates
Adobe updated 12 different products yesterday.
https://helpx.adobe.com/security.html
SAP Patchday
Among the critical vulnerabilities patched in SAP s products are two deserialization vulnerabilities with a CVSS score of 10.0
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/october-2025.html
https://onapsis.com/blog/sap-security-patch-day-october-2025/
Microsoft Patch Tuesday
Microsoft not only released new patches, but also the last patches for Windows 10, Office 2016, Office 2019, Exchange 2016 and Exchange 2019.
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20October%202025/32368
Ivanti Advisory
Ivanti released an advisory with some mitigation steps users can take until the recently made public vulnerablities are patched.
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-October-2025?language=en_US
Fortinet Patches
https://fortiguard.fortinet.com/psirt/FG-IR-25-010
https://fortiguard.fortinet.com/psirt/FG-IR-24-361
Scans for ESAFENET CDG V5
We do see some increase in scans for the Chinese secure document management system, ESAFENET.
https://isc.sans.edu/diary/Heads%20Up%3A%20Scans%20for%20ESAFENET%20CDG%20V5%20/32364
Investigating targeted payroll pirate attacks affecting US universities
Microsoft wrote about how payroll pirates redirect employee paychecks via phishing.
https://www.microsoft.com/en-us/security/blog/2025/10/09/investigating-targeted-payroll-pirate-attacks-affecting-us-universities/
Attacks against Edge via IE Mode
Microsoft Edge offers an IE legacy mode to support websites created for Internet Explorer. The old JavaScript engine, which is part of this mode, has been abused in recent attacks, and Microsoft will make it more difficult to enable IE Mode to counter these attacks.
https://microsoftedge.github.io/edgevr/posts/Changes-to-Internet-Explorer-Mode-in-Microsoft-Edge/
New Oracle E-Business Suite Patches
Oracle released one more patch for the e-business suite. Oracle does not state if it is already exploited, but the timing of the patch suggests that it should be expedited.
https://www.oracle.com/security-alerts/alert-cve-2025-61884.html
Widespread Sonicwall SSLVPN Compromise
Huntress Labs observed the widespread compromise of the Sonicwall SSLVPN appliance.
https://www.huntress.com/blog/sonicwall-sslvpn-compromise
Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw (CVE-2025-11371)
An unpatched vulnerability in the secure file sharing solutions Gladinet CentreStack and TrioFox is being exploited.
https://www.huntress.com/blog/gladinet-centrestack-triofox-local-file-inclusion-flaw
Two 7-Zip Vulnerabilities CVE-2025-11002, CVE-2025-11001
7-Zip patched two vulnerabilities that may lead to arbitrary code execution
https://www.zerodayinitiative.com/advisories/ZDI-25-949/
https://www.zerodayinitiative.com/advisories/ZDI-25-950/
Building Better Defenses: RedTail Observations
Defending against attacks like RedTail is more then blocking IoCs, but instead one must focus on the techniques and tactics attackers use.
https://isc.sans.edu/diary/Guest+Diary+Building+Better+Defenses+RedTail+Observations+from+a+Honeypot/32312
Sonicwall: It wasn t the user s fault
Sonicwall admits to a breach resulting in the loss of user configurations stored in its cloud service
https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330
Crowdstrike has Issues
Crowdstrike fixes two vulnerabilities in the Windows version of its Falcon sensor.
https://www.crowdstrike.com/en-us/security-advisories/issues-affecting-crowdstrike-falcon-sensor-for-windows/
Interrogators: Attack Surface Mapping in an Agentic World
A SANS.edu master s degree student research paper by Michael Samson
https://isc.sans.edu/researchpapers/pdfs/michael_samson.pdf
keywords: ai; agentic; attack surface; crowdstrike; sonicwall; ivanti; zero day; initiative; redline
Polymorphic Python Malware
Xavier discovered self-modifying Python code on Virustotal. The remote access tool takes advantage of the inspect module to modify code on the fly.
https://isc.sans.edu/diary/Polymorphic%20Python%20Malware/32354
SSH ProxyCommand Vulnerability
A user cloning a git repository may be tricked into executing arbitrary code via the SSH proxycommand option.
https://dgl.cx/2025/10/bash-a-newline-ssh-proxycommand-cve-2025-61984
Framelink Figma MCP Server CVE-2025-53967
Framelink Figma s MCP server suffers from a remote code execution vulnerability.
FreePBX Exploit Attempts (CVE-2025-57819)
A FreePBX SQL injection vulnerability disclosed in August is being used to execute code on affected systems.
https://isc.sans.edu/diary/Exploit%20Against%20FreePBX%20%28CVE-2025-57819%29%20with%20code%20execution./32350
Disrupting Threats Targeting Microsoft Teams
Microsoft published a blog post outlining how to better secure Teams.
https://www.microsoft.com/en-us/security/blog/2025/10/07/disrupting-threats-targeting-microsoft-teams/
Kibana XSS Patch CVE-2025-25009
Elastic patched a stored XSS vulnerability in Kibana
https://discuss.elastic.co/t/kibana-8-18-8-8-19-5-9-0-8-and-9-1-5-security-update-esa-2025-20/382449
QT SVG Vulnerabilities CVE-2025-10728, CVE-2025-10729,
The QT group fixed two vulnerabilities in the QT SVG module. One of the vulnerabilities may be used for code execution
https://www.qt.io/blog/security-advisory-uncontrolled-recursion-and-use-after-free-vulnerabilities-in-qt-svg-module-impact-qt
More Details About Oracle 0-Day
The exploit is now widely distributed and has been analyzed to show the nature of the underlying vulnerabilities.
https://isc.sans.edu/diary/Quick%20and%20Dirty%20Analysis%20of%20Possible%20Oracle%20E-Business%20Suite%20Exploit%20Script%20%28CVE-2025-61882%29%20%5BUPDATED%5B/32346
https://labs.watchtowr.com/well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882well-well-well-its-another-day-oracle-e-business-suite-pre-auth-rce-chain-cve-2025-61882/
Redis Vulnerability
Redis patched a ciritcal use after free vulnerability that could lead to arbitrary code execution.
https://redis.io/blog/security-advisory-cve-2025-49844/
GoAnywhere Bug Exploited
Microsoft is reporting about the exploitation of the recent GoAnywhere vulnerability
https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/
Oracle E-Business Suite 0-Day CVE-2025-61882
Last week, the Cl0p ransomware gang sent messages to many businesses stating that an Oracle E-Business Suite vulnerability was used to exfiltrate data. Initially, Oracle believed the root cause to be a vulnerability patched in June, but now Oracle released a patch for a new vulnerability.
https://www.oracle.com/security-alerts/alert-cve-2025-61882.html
Zimbra Exploit Analysis
An exploit against a Zimbra system prior to the patch release is analyzed. These exploits take advantage of .ics files to breach vulnerable systems.
https://strikeready.com/blog/0day-ics-attack-in-the-wild/
Unity Editor Vulnerability CVE-2025-59489
The Unity game editor suffered from a code execution vulnerablity that would also expose software developed with vulnerable versions
https://unity.com/security/sept-2025-01
More .well-known scans
Attackers are using API documentation automatically published in the .well-known directory for reconnaissance.
https://isc.sans.edu/diary/More%20.well-known%20Scans/32340
RedHat Patches Openshift AI Services
A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for example, as a data scientist using a standard Jupyter notebook, can escalate their privileges to a full cluster administrator.
https://access.redhat.com/security/cve/cve-2025-10725#cve-affected-packages
TOTOLINK X6000R Vulnerabilities
Paloalto released details regarding three recently patched vulnerabilities in TotalLink-X6000R routers.
https://unit42.paloaltonetworks.com/totolink-x6000r-vulnerabilities/
DrayOS Vulnerability Patched
Draytek fixed a single memory corruption vulnerability in its Vigor series router. An unauthenticated user may use it to execute arbitrary code.
https://www.draytek.com/about/security-advisory/use-of-uninitialized-variable-vulnerabilities
Comparing Honeypot Passwords with HIBP
Most passwords used against our honeypots are also found in the Have I been pwn3d list. However, the few percent that are not found tend to be variations of known passwords, extending them to find likely mutations.
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Comparing%20Honeypot%20Passwords%20with%20HIBP/32310
Breaking Server SGX via DRAM Inspection
By observing read and write operations to memory, it is possible to derive keys stored in SGX and break the security of systems relying on SGX.
https://wiretap.fail/files/wiretap.pdf
OneLogin OIDC Vulnerability
A vulnerability in OneLogin can be used to read secret application keys
https://www.clutch.security/blog/onelogin-many-secrets-clutch-uncovers-vulnerability-exposing-client-credentials
OpenSSL Patch
OpenSSL patched three vulnerabilities. One could lead to remote code execution, but the feature is used infrequently, and the exploit is difficult, according to OpenSSL
Sometimes you don t even need to log in
Applications using simple, predictable cookies to verify a user s identity are still exploited, and relatively recent vulnerabilities are still due to this very basic mistake.
https://isc.sans.edu/diary/%22user%3Dadmin%22.%20Sometimes%20you%20don%27t%20even%20need%20to%20log%20in./32334
Western Digital My Cloud Vulnerability
Western Digital patched a critical vulnerability in its MyCloud device.
https://nvd.nist.gov/vuln/detail/CVE-2025-30247
sudo vulnerability exploited
A recently patched vulnerability in sudo is now being exploited.
https://www.sudo.ws/security/advisories/
Apple Patches
Apple released patches for iOS, macOS, and visionOS, fixing a single font parsing vulnerability
https://isc.sans.edu/diary/Apple%20Patches%20Single%20Vulnerability%20CVE-2025-43400/32330
Increase in Scans for Palo Alto Global Protect Vulnerability (CVE-2024-3400).
Our honeypots detected an increase in scans for a Palo Alto Global Protect vulnerability.
https://isc.sans.edu/diary/Increase%20in%20Scans%20for%20Palo%20Alto%20Global%20Protect%20Vulnerability%20%28CVE-2024-3400%29/32328
Nimbus Manticore / Charming Kitten Malware update
Checkpoint released a report with details regarding a new Nimbus Manticore exploit kit. The malware in this case uses valid SSL.com-issued certificates.
https://research.checkpoint.com/2025/nimbus-manticore-deploys-new-malware-targeting-europe/
Converting Timestamps in .bash_history
Unix shells offer the ability to add timestamps to commands in the .bash_history file. This is often done in the form of Unix timestamps. This new tool converts these timestamps into a more readable format.
https://isc.sans.edu/diary/New%20tool%3A%20convert-ts-bash-history.py/32324
Cisco ASA/FRD Compromises
Exploitation of the vulnerabilities Cisco patched last week may have bone back about a year. Cisco and CISA have released advisories with help identifying affected devices.
https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks
https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices
Github Notification Phishing
Github notifications are used to impersonate YCombinator and trick victims into installing a crypto drainer.
https://www.bleepingcomputer.com/news/security/github-notifications-abused-to-impersonate-y-combinator-for-crypto-theft/
Webshells Hiding in .well-known Places
Our honeypots registered an increase in scans for URLs in the .well-known directory, which appears to be looking for webshells.
https://isc.sans.edu/diary/Webshells%20Hiding%20in%20.well-known%20Places/32320
Cisco Patches Critical Exploited Vulnerabilities
Cisco released updates addressing already-exploited vulnerabilities in the VPN web server for the ASA and FTD appliances.
https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW
XCSSET Evolves Again
Microsoft detected a new XCSSET variant, an infostealer infecting X-Code projects.
https://www.microsoft.com/en-us/security/blog/2025/09/25/xcsset-evolves-again-analyzing-the-latest-updates-to-xcssets-inventory/
Exploitation of Fortra GoAnywhere MFT CVE-2025-10035
watchTowr analyzed the latest GoAnywhere MFT vulnerability and exploits used against it.
https://labs.watchtowr.com/it-is-bad-exploitation-of-fortra-goanywhere-mft-cve-2025-10035-part-2/
Exploit Attempts Against Older Hikvision Camera Vulnerability
Out honeypots observed an increase in attacks against some older Hikvision issues. A big part of the problem is weak passwords, and the ability to send credentials as part of the URL.
https://isc.sans.edu/diary/Exploit%20Attempts%20Against%20Older%20Hikvision%20Camera%20Vulnerability/32316
Cisco Patches Already Exploited SNMP Vulnerability
Cisco patched a stack-based buffer overflow in the SNMP subsystem. It is already exploited in the wild, but requires
admin privileges to achieve code execution.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-snmp-x4LPhte
SonicWall Anti-Rootkit Update
SonicWall released a firmware update for its SMA100 devices specifically designed to eradicate a commonly deployed rootkit.
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0015
Extended Windows 10 Support
Microsoft will extend free Windows 10 essential support for US and European customers.
https://www.straitstimes.com/world/united-states/microsoft-offers-no-cost-windows-10-lifeline
Distracting the Analyst for Fun and Profit
Our undergraduate intern, Tyler House analyzed what may have been a small DoS attack that was likely more meant to distract than to actually cause a denial of service
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Distracting%20the%20Analyst%20for%20Fun%20and%20Profit/32308
GitHub s plan for a more secure npm supply chain
GitHub outlined its plan to harden the supply chain, in particular in light of the recent attack against npm packages
https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/
SolarWinds Web Help Desk AjaxProxy Deserialization of Untrusted Data Remote Code Execution Vulnerability (CVE-2025-26399)
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399
Vulnerabilities in Supermicro BMC Firmware CVE-2025-7937 CVE-2025-6198
Supermicro fixed two vulnerabilities that could allow an attacker to compromise the BMC with rogue firmware.
https://www.supermicro.com/en/support/security_BMC_IPMI_Sept_2025
CISA Reports Ivanti EPMM Exploit Sightings
Two different organizations submitted backdoors to CISA, which are believed to have been installed using Ivanti vulnerabilities patched in May.
https://www.cisa.gov/news-events/analysis-reports/ar25-261a
Lastpass Observes Impersonation on GitHub
Lastpass noted a number of companies being impersonated via fake GitHub repositories in order to trick victims to download Mac malware.
https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages
Oracle Scheduler Ransomware
Ransomware has been discovered that gained access to systems via an exposed Oracle Database Scheduler service.
https://labs.yarix.com/2025/09/elons-proxima-black-shadow-related-ransomware-attack-via-oracle-dbs-external-jobs/
Help Wanted: What are these odd requests about?
An odd request is hitting a number of our honeypots with a somewhat unusual HTTP request
header. Please let me know if you no what the request is about.
https://isc.sans.edu/forums/diary/Help+Wanted+What+are+these+odd+reuqests+about/32302/
Forta GoAnywhere MFT Vulnerability
Forta s GoAnywhere MFT product suffers from a critical deserialization vulnerability. Forta released
an advisory disclosing the vulnerability on Thursday.
https://www.fortra.com/security/advisories/product-security/fi-2025-012
EDR Freeze
A new tool, EDR Freeze, allows regular users to suspend EDR processes.
https://www.zerosalarium.com/2025/09/EDR-Freeze-Puts-EDRs-Antivirus-Into-Coma.html
Exploring Uploads in a Dshield Honeypot Environment
This guest diary by one of our SANS.edu undergraduate interns shows how to analyze files uploaded to Cowrie
https://isc.sans.edu/diary/Exploring%20Uploads%20in%20a%20Dshield%20Honeypot%20Environment%20%5BGuest%20Diary%5D/32296
Sonicwall Breach
SonicWall MySonicWall accounts were breached via credential brute forcing
https://www.sonicwall.com/support/knowledge-base/mysonicwall-cloud-backup-file-incident/250915160910330
DeepSeek Bias
Cloudflare found significant biases in code created by the Chinese AI engine DeepSeek. Code for organizations not aligned with China s politics contained significantly more bugs
https://www.washingtonpost.com/technology/2025/09/16/deepseek-ai-security/
Google Chrome 0-day
Google fixed an already-exploited vulnerability in Google Chrome
https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html
CTRL-Z DLL Hooking
Attackers may use a simple reload trick to overwrite breakpoints left by analysts to reverse malicious binaries.
https://isc.sans.edu/diary/CTRL-Z%20DLL%20Hooking/32294
Global Admin in every Entra ID tenant via Actor tokens
As part of September s patch Tuesday, Microsoft patched CVE-2025-55241. The discoverer of the vulnerability,
Dirk-jan Mollema has published a blog post showing how this vulnerability could have been exploited.
https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/
WatchGuard Firebox iked Out of Bounds Write Vulnerability CVE-2025-9242
WatchGuard patched an out-of-bounds write vulnerability, which could allow an unauthenticated attacker to compromise the devices.
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00015
NVidia Triton Inference Server
NVIDIA patched critical vulnerabilities in its Triton Inference Server.
https://nvidia.custhelp.com/app/answers/detail/a_id/5691
Why You Need Phishing-Resistant Authentication NOW.
The recent compromise of a number of high-profile npmjs.com accounts has yet again shown how dangerous a simple phishing email can be.
https://isc.sans.edu/diary/Why%20You%20Need%20Phishing%20Resistant%20Authentication%20NOW./32290
S1ngularity/nx Attackers Strike Again
A second wave of attacks has hit over a hundred npm-related GitHub repositories. The updated payload implements a worm that propagates itself to other repositories.
https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again
ChatGPT s Calendar Integration Can Be Exploited to Steal Emails
ChatGPT s new MCP integration can be used, via prompt injection, to affect software connected to ChatGPT via MCP.
https://www.linkedin.com/posts/eito-miyamura-157305121_we-got-chatgpt-to-leak-your-private-email-activity-7372306174253256704-xoX1/
Apple Updates
Apple released major updates for all of its operating systems. In addition to new features, these updates patch 33 different vulnerabilities.
https://isc.sans.edu/diary/Apple%20Updates%20Everything%20-%20iOS%20macOS%2026%20Edition/32286
Microsoft End of Life
October 14th, support for Windows 10, Exchange 2016, and Exchange 2019 will end.
https://support.microsoft.com/en-us/windows/windows-10-support-ends-on-october-14-2025-2ca8b313-1946-43d3-b55c-2b95b107f281#:~:text=As%20a%20reminder%2C%20Windows%2010,one%20that%20supports%20Windows%2011.
https://techcommunity.microsoft.com/blog/exchange/t-9-months-exchange-server-2016-and-exchange-server-2019-end-of-support/4366605
Phishing Targeting Rust Developers
Rust developers are reporting similar phishing emails as the emails causing the major NPM compromise last week.
https://github.com/rust-lang/crates.io/discussions/11889#discussion-8886064
Samsung Patches 0-Day
Samsung released its monthly updates for its flagship phones fixing, among other vulnerability, an already exploited 0-day.
https://security.samsungmobile.com/securityUpdate.smsb
Web Searches For Archives
Didier observed additional file types being searched for as attackers continue to focus on archive files as they spider web pages
https://isc.sans.edu/diary/Web%20Searches%20For%20Archives/32282
FBI Flash Alert: Salesforce Attacks
The FBI is alerting users of Salesforce of two different threat actors targeting Salesforce. There are no new vulnerabilities disclosed, but the initial access usually takes advantage of social engineering or leaked data from the Salesdrift compromise.
https://www.ic3.gov/CSA/2025/250912.pdf
VSCode Cursor Extensions Malware
Koe Security unmasked details about a recent malicious cursor extension campaign they call White Cobra.
https://www.koi.security/blog/whitecobra-vscode-cursor-extensions-malware
BSides Augusta
https://bsidesaugusta.org/
DShield SIEM Docker Updates
Guy updated the DShield SIEM which graphically summarizes what is happening inside your honeypot.
https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/32276
Again: Sonicwall SSL VPN Compromises
The Australian Government s Signals Directorate noted an increase in compromised Sonicwall devices.
https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/ongoing-active-exploitation-of-sonicwall-ssl-vpns-in-australia
Website Keystroke Logging
Many websites log every keystroke, not just data submitted in forms.
https://arxiv.org/pdf/2508.19825
BASE64 Over DNS
The base64 character set exceeds what is allowable in DNS. However, some implementations will work even with these invalid characters.
https://isc.sans.edu/diary/BASE64%20Over%20DNS/32274
Google Chrome Update
Google released an update for Google Chrome, addressing two vulnerabilities. One of the vulnerabilities is rated critical and may allow code execution.
https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_9.html
Ivanti Updates
Ivanti patched a number of vulnerabilities, several of them critical, across its product portfolio.
https://forums.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs
Sophos Patches
Sophos resolved authentication bypass vulnerability in Sophos AP6 series wireless access point firmware (CVE-2025-10159)
https://www.sophos.com/en-us/security-advisories/sophos-sa-20250909-ap6
Apple Introduces Memory Integrity Enforcement
With the new hardware promoted in yesterday s event, Apple also introduced new memory integrity features based on this new hardware.
https://security.apple.com/blog/memory-integrity-enforcement/
Microsoft Patch Tuesday
As part of its September patch Tuesday, Microsoft addressed 177 different vulnerabilities, 86 of which affect Microsoft products. None of the vulnerabilities has been exploited before today. Two of the vulnerabilities were already made public. Microsoft rates 13 of the vulnerabilities are critical.
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20September%202025/32270
Adobe Patches
Adobe released patches for nine products, including Adobe Commerce, Coldfusion, and Acrobat.
https://helpx.adobe.com/security/security-bulletin.html
SAP Patches
SAP patched vulnerabilities across its product portfolio. Particularly interesting are a few critical vulnerabilities in Netweaver, one of which scored a perfect 10.0 CVSS score.
https://onapsis.com/blog/sap-security-notes-september-2025-patch-day/
Major npm compromise
A number of high-profile npm libraries were compromised after developers fell for a phishing email. This compromise affected libraries with a total of hundreds of millions of downloads a week.
https://bsky.app/profile/bad-at-computer.bsky.social/post/3lydioq5swk2y https://github.com/orgs/community/discussions/172738 https://github.com/chalk/chalk/issues/656#issuecomment-3266894253
https://www.aikido.dev/blog/npm-debug-and-chalk-packages-compromised
HTTP Request Signatures
It looks like some search engines and AI bots are starting to use the HTTP request signature. This should make it easier to identify bot traffic.
https://isc.sans.edu/diary/HTTP%20Request%20Signatures/32266
From YARA Offsets to Virtual Addresses
Xavier explains how to convert offsets reported by YARA into offsets suitable for the use with debuggers.
https://isc.sans.edu/diary/From%20YARA%20Offsets%20to%20Virtual%20Addresses/32262
Phishing via JavaScript in SVG Files
Virustotal uncovered a Colombian phishing campaign that takes advantage of JavaScript in SVG files.
https://blog.virustotal.com/2025/09/uncovering-colombian-malware-campaign.html
FreePBX Patches
FreePBX released details regarding two vulnerabilities patched last week. One of these vulnerabilities was already actively exploited.
https://github.com/FreePBX/security-reporting/security/advisories/GHSA-3r47-p39v-vqqf
Unauthorized Issuance of Certificate for 1.1.1.1
Cloudflare published a blog post with more details regarding the bad 1.1.1.1 certificate that was issued by Fina.
https://blog.cloudflare.com/unauthorized-issuance-of-certificates-for-1-1-1-1/
AI Model Namespace Reuse
Deleted accounts on Huggingface can be taken over by other entities unrelated to the original owner.
https://unit42.paloaltonetworks.com/model-namespace-reuse/
macOS vulnerability allowed Keychain and iOS app decryption without a password
Excessive entitlements for the gcore binary facilitated access to key material that was sufficient to access secrets stored in Apple s keychain.
https://www.helpnetsecurity.com/2025/09/04/macos-gcore-vulnerability-cve-2025-24204/
Exploit Attempts for Dassault DELMIA Apriso. CVE-2025-5086
Our honeypots detected attacks against the manufacturing management system DELMIA Apriso. The deserialization vulnerability was patched in June and is one of a few critical vulnerabilities patched in recent months.
https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Dassault%20DELMIA%20Apriso.%20CVE-2025-5086/32256
Android Bulletin
Google released its September update, fixing two already-exploited privilege escalation flaws and some remote code execution issues.
https://source.android.com/docs/security/bulletin/2025-09-01
Mis-issued Certificates for SAN iPAddress:1.1.1.1 by Fina RDC 2020
Certificate authority Fina RDC issues a certificate for Cloudflare s IP address 1.1.1.1
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/SgwC1QsEpvc
A Quick Look at Sextortion at Scale
Jan analyzed 1900 different sextortion messages using 205 different Bitcoin addresses to look at the success rate, lifetime, and other metrics defining these campaigns.
https://isc.sans.edu/diary/A%20quick%20look%20at%20sextortion%20at%20scale%3A%201%2C900%20messages%20and%20205%20Bitcoin%20addresses%20spanning%20four%20years/32252
Azure AD Client Secret Leak
Attackers are stealing Azure AD client secrets from websites that are leaving them exposed.
https://www.resecurity.com/blog/article/azure-ad-client-secret-leak-the-keys-to-cloud
Covert Channel via ICMP and DNS
A new bot combines ICMP and DNS in new ways for covert communication. The DNS requests use domains with a fixed prefix followed by a base64 encoded command, and the ICMP echo request packets include commands as a payload.
https://blog.xlab.qianxin.com/mystrodx_covert_dual-mode_backdoor_en/
Official Release of Critical FreePBX Patch
Sangoma has announced that the experimental patch released for the exploited FreePBX vulnerability is now considered stable, and users should update to apply it.
https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203
pdf-parser: All Streams
Didier released a new version of pdf-parser.py. This version fixes a problem with dumping all filtered streams.
https://isc.sans.edu/diary/pdf-parser%3A%20All%20Streams/32248
Salesloft Drift Putting OAuth Tokens at Risk
OAuth tokens used by Salesloft Drift users to provide access to integrations with Salesforce, Google Workspace, and others have been compromised and heavily abused for additional compromise and large-scale data exfiltration from exposed services.
https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift
Velociraptor incident response tool abused for remote access
Attackers are using the open source incident response tool Velociraptor to access remote systems in breached networks. Tools like Velocitraptor are ideal for attackers to perform lateral movement.
https://news.sophos.com/en-us/2025/08/26/velociraptor-incident-response-tool-abused-for-remote-access/
Default Password in NeuVector (Rancher Desktop)
SuSE fixed a default password vulnerability in NeuVector, a security tool included in Rancher Desktop.
https://github.com/neuvector/neuvector/security/advisories/GHSA-8pxw-9c75-6w56
Increasing Searches for ZIP Files
Attackers are scanning our honeypots more and more for .zip files. They are looking for backups of credential files and the like left behind by careless administrators and developers.
https://isc.sans.edu/diary/Increasing%20Searches%20for%20ZIP%20Files/32242
FreePBX Vulnerability
An upatched vulnerability in FreePBX is currently being exploited. FreePBX offers mitigation advice and has also just released a beta patch.
https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203
Passwordstate Vulnerability
Clickstudios patched an authentication bypass vulnerability in its password manager, Passwordstate. The vulnerability can be used to access the emergency password page.
https://www.clickstudios.com.au/passwordstate-changelog.aspx
Interesting Technique to Launch a Shellcode
Xavier came across malware that PowerShell and the CallWindowProcA() API to launch code.
https://isc.sans.edu/diary/Interesting%20Technique%20to%20Launch%20a%20Shellcode/32238
NX Compromised to Steal Wallets and Credentials
The popular open source NX build package was compromised. Code was added that uses the help of AI tools like Claude and Gemini to steal credentials from affected systems
https://semgrep.dev/blog/2025/security-alert-nx-compromised-to-steal-wallets-and-credentials/
Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed the Global Espionage System
Several law enforcement and cybersecurity agencies worldwide collaborated to release a detailed report on the recent Volt Typhoon incident.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a
Getting a Better Handle on International Domain Names and Punycode
International Domain names can be used for phishing and other attacks. One way to identify suspect names is to look for mixed script use.
https://isc.sans.edu/diary/Getting%20a%20Better%20Handle%20on%20International%20Domain%20Names%20and%20Punycode/32234
Citrix Netscaler Vulnerabilities CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424
Citrix patched three vulnerabilities in Netscaler. One is already being exploited
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_7775_CVE_2025_7776_and_CVE_2025_8424
git vulnerability exploited (CVE-2025-48384)
A git vulnerability patched in early July is now being exploited
https://github.com/git/git/security/advisories/GHSA-vwqx-4fm8-6qc9
Reading Location Position Value in Microsoft Word Documents
Jessy investigated how Word documents store the last visited document location in the registry.
https://isc.sans.edu/diary/Reading%20Location%20Position%20Value%20in%20Microsoft%20Word%20Documents/32224
Weaponizing image scaling against production AI systems
AI systems often downscale images before processing them. An attacker can create a harmless looking image that would reveal text after downscaling leading to prompt injection
https://blog.trailofbits.com/2025/08/21/weaponizing-image-scaling-against-production-ai-systems/
IBM Jazz Team Server Vulnerability CVE-2025-36157
IBM patched a critical vulnerability in its Jazz Team Server
https://www.ibm.com/support/pages/node/7242925
The end of an era: Properly formatted IP addresses in all of our data.
When initiall designing DShield, addresses were zero padded , an unfortunate choice. As of this week, datafeeds should no longer be zero padded .
https://isc.sans.edu/diary/The%20end%20of%20an%20era%3A%20Properly%20formated%20IP%20addresses%20in%20all%20of%20our%20data./32228
.desktop files used in an attack against Linux Desktops
Pakistani attackers are using .desktop files to target Indian Linux desktops.
https://www.cyfirma.com/research/apt36-targets-indian-boss-linux-systems-with-weaponized-autostart-files/
Malicious Go Module Disguised as SSH Brute Forcer Exfiltrates Credentials via Telegram
A go module advertising its ability to quickly brute force passwords against random IP addresses, has been used to exfiltrate credentials from the person running the module.
https://socket.dev/blog/malicious-go-module-disguised-as-ssh-brute-forcer-exfiltrates-credentials
Limiting Onmicrosoft Domain Usage for Sending Emails
Microsoft is limiting how many emails can be sent by Microsoft 365 users using the onmicrosoft.com domain.
https://techcommunity.microsoft.com/blog/exchange/limiting-onmicrosoft-domain-usage-for-sending-emails/4446167
Don't Forget The "-n" Command Line Switch
Disabling reverse DNS lookups for IP addresses is important not just for performance, but also for opsec. Xavier is explaining some of the risks.
https://isc.sans.edu/diary/Don%27t%20Forget%20The%20%22-n%22%20Command%20Line%20Switch/32220
watchTowr releases details about recent Commvault flaws
Users of the Commvault enterprise backup solution must patch now after watchTowr released details about recent vulnerabilities
https://labs.watchtowr.com/guess-who-would-be-stupid-enough-to-rob-the-same-vault-twice-pre-auth-rce-chains-in-commvault/?123
Docker Desktop Vulnerability CVE-2025-9074
A vulnerability in Docker Desktop allows attackers to escape from containers to attack the host.
https://docs.docker.com/desktop/release-notes/#4443
Airtel Router Scans and Mislabeled Usernames
A quick summary of some odd usernames that show up in our honeypot logs
https://isc.sans.edu/diary/Airtel%20Router%20Scans%2C%20and%20Mislabeled%20usernames/32216
Apple Patches 0-Day CVE-2025-43300
Apple released an update for iOS, iPadOS and MacOS today patching a single, already exploited, vulnerability in ImageIO.
https://support.apple.com/en-us/124925
Microsoft Copilot Audit Logs
A user retrieving data via copilot obscures the fact that the user may have had access to data in a specific file
https://pistachioapp.com/blog/copilot-broke-your-audit-log
Password Managers Susceptible to Clickjacking
Many password managers are susceptible to clickjacking, and only few have fixed the problem so far
https://marektoth.com/blog/dom-based-extension-clickjacking/
Increased Elasticsearch Recognizance Scans
Our honeypots noted an increase in reconnaissance scans for Elasticsearch. In particular, the endpoint /_cluster/settings is hit hard.
https://isc.sans.edu/diary/Increased%20Elasticsearch%20Recognizance%20Scans/32212
Microsoft Patch Tuesday Issues
Microsoft noted some issues deploying the most recent patches with WSUS. There are also issues with certain SSDs if larger files are transferred.
https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2#3635msgdesc
https://www.tomshardware.com/pc-components/ssds/latest-windows-11-security-patch-might-be-breaking-ssds-under-heavy-workloads-users-report-disappearing-drives-following-file-transfers-including-some-that-cannot-be-recovered-after-a-reboot
SAP Vulnerabilities Exploited CVE-2025-31324, CVE-2025-42999
Details explaining how to take advantage of two SAP vulnerabilities were made public
https://onapsis.com/blog/new-exploit-for-cve-2025-31324/
Keeping an Eye on MFA Bombing Attacks
Attackers will attempt to use authentication fatigue by bombing users with MFA authentication requests. Rob is talking in this diary about how to investigate these attacks in a Microsoft ecosystem.
https://isc.sans.edu/diary/Keeping+an+Eye+on+MFABombing+Attacks/32208
Critical Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability
An OS command injection vulnerability may be abused to gain access to the Cisco Secure Firewall Management Center software.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79
F5 Access for Android vulnerability
An attacker with a network position that allows them to intercept network traffic may be able to read and/or modify data in transit. The attacker would need to intercept vulnerable clients specifically, since other clients would detect the man-in-the-middle (MITM) attack.
https://my.f5.com/manage/s/article/K000152049
SNI5GECT: Sniffing and Injecting 5G Traffic Without Rogue Base Stations
Researchers from the Singapore University of Technology and Design released a new framework, SNI5GECT, to passively sniff and inject traffic into 5G data streams, leading to DoS, downgrade and other attacks.
https://isc.sans.edu/diary/SNI5GECT%3A%20Sniffing%20and%20Injecting%205G%20Traffic%20Without%20Rogue%20Base%20Stations/32202
Plex Vulnerability
Plex patched a vulnerability in the Plex Media Server. Make sure you have updated to at least 1.42.1.
https://forums.plex.tv/t/plex-media-server-security-update/928341
FortiWeb Exploit Public
A security researcher published details about the recent FortiWeb vulnerability, including demonstrating a PoC exploit.
https://www.bleepingcomputer.com/news/security/researcher-to-release-exploit-for-full-auth-bypass-on-fortiweb/
Flowise OS vulnerability
https://research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578/
AI and Faster Attack Analysis
A few use cases for LLMs to speed up analysis
https://isc.sans.edu/diary/AI%20and%20Faster%20Attack%20Analysis%20%5BGuest%20Diary%5D/32198
Proxyware Malware Being Distributed on YouTube Video Download Site
Popular YouTube download sites will attempt to infect users with proxyware.
https://asec.ahnlab.com/en/89574/
Xerox Freeflow Core Vulnerability
Horizon3.ai discovered XXE Injection (CVE-2025-8355) and Path Traversal (CVE-2025-8356) vulnerabilities in Xerox FreeFlow Core, a print orchestration platform. These vulnerabilities are easily exploitable and enable unauthenticated remote attackers to achieve remote code execution on vulnerable FreeFlow Core instances.
https://horizon3.ai/attack-research/attack-blogs/from-support-ticket-to-zero-day/
SANS.edu Research: Darren Carstensen Evaluating Zero Trust Network Access: A Framework for Comparative Security Testing
Not all Zero Trust Network Access (ZTNA) solutions are created equal, and despite bold marketing claims, many fall short of delivering proper Zero Trust security.
https://www.sans.edu/cyber-research/evaluating-zero-trust-network-access-framework-comparative-security-testing/
CVE-2017-11882 Will Never Die
The (very) old equation editor vulnerability is still being exploited, as this recent sample analyzed by Xavier shows. The payload of the Excel file attempts to download and execute an infostealer to exfiltrate passwords via email.
https://isc.sans.edu/diary/CVE-2017-11882%20Will%20Never%20Die/32196
Windows Kerberos Elevation of Privilege Vulnerability
Yesterday, Microsoft released a patch for a vulnerability that had already been made public. This vulnerability refers to the privilege escalation taking advantage of a path traversal issue in Windows Kerberos affecting Exchange Server in hybrid mode.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53779
Persistent Risk: XZ Utils Backdoor Still Lurking in Docker Images
Some old Debian Docker images containing the xz-utils backdoor are still available for download from Docker Hub via the official Debian account.
https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images
FortiSIEM / FortiWeb Vulnerablities
Fortinet patched already exploited vulnerabilities in FortiWeb and FortiSIEM
https://fortiguard.fortinet.com/psirt/FG-IR-25-152
https://fortiguard.fortinet.com/psirt/FG-IR-25-448
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20August%202025%20Patch%20Tuesday/32192
https://cymulate.com/blog/zero-click-one-ntlm-microsoft-security-patch-bypass-cve-2025-50154/
libarchive Vulnerability
A libarchive vulnerability patched in June was upgraded from a low CVSS score to a critical one. Libarchive is used by compression software across various operating systems, making this a difficult vulnerability to patch
https://www.freebsd.org/security/advisories/FreeBSD-SA-25:07.libarchive.asc
Adobe Patches
Adobe released patches for 13 different products.
https://helpx.adobe.com/security/Home.html
Erlang OTP SSH Exploits
A recently patched and easily exploited vulnerability in Erlang/OTP SSH is being exploited. Palo Alto collected some of the details about this exploit activity that they observed.
https://unit42.paloaltonetworks.com/erlang-otp-cve-2025-32433/
WinRAR Exploited
WinRAR vulnerabilities are actively being exploited by a number of threat actors. The vulnerability allows for the creation of arbitrary files as the archive is extracted.
https://thehackernews.com/2025/08/winrar-zero-day-under-active.html
Citrix Netscaler Exploit Updates
The Dutch Center for Cyber Security is updating its guidance on recent Citrix Netscaler attacks. Note that the attacks started before a patch became available, and attackers are actively hiding their tracks to make it more difficult to detect a compromise.
https://www.ncsc.nl/actueel/nieuws/2025/07/22/casus-citrix-kwetsbaarheid https://www.bleepingcomputer.com/news/security/netherlands-citrix-netscaler-flaw-cve-2025-6543-exploited-to-breach-orgs/
OpenSSH Post Quantum Encryption
Starting in version 10.1, OpenSSH will warn users if they are using quantum-unsafe algorithms
https://www.openssh.com/pq.html
Google Paid Ads for Fake Tesla Websites
Someone is setting up fake Tesla lookalike websites that attempt to collect credit card data from unsuspecting users trying to preorder Tesla products.
https://isc.sans.edu/diary/Google%20Paid%20Ads%20for%20Fake%20Tesla%20Websites/32186
Compromising USB Devices for Persistent Stealthy Access
USB devices, like Linux-based web cams, can be compromised to emulate malicious USB devices like keyboards that inject malicious commands.
https://eclypsium.com/blog/badcam-now-weaponizing-linux-webcams/
Win-DoS Epidemic: A crash course in abusing RPC for Win-DoS & Win-DDoS
Internet-exposed DCs can be used in very powerful DoS attacks.
https://defcon.org/html/defcon-33/dc-33-speakers.html#content_60389
Mass Internet Scanning from ASN 43350
Our undergraduate intern Duncan Woosley wrote up aggressive scans from ASN 43350
https://isc.sans.edu/diary/Mass+Internet+Scanning+from+ASN+43350+Guest+Diary/32180/#comments
HTTP/1.1 Desync Attacks
Portswigger released details about new types of HTTP/1.1 desync attacks it uncovered. These attacks are particularly critical for organizations using middleboxes to translate from HTTP/2 to HTTP/1.1
https://portswigger.net/research/http1-must-die
Microsoft Warns of Exchange Server Vulnerability
An attacker with admin access to an Exchange Server in a hybrid configuration can use this vulnerability to gain full domain access. The issue is mitigated by an April hotfix, but was not noted in the release of the April Hotfix.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786
Sonicwall Update
Sonicwall no longer believes that a new vulnerability was used in recent compromises
https://www.sonicwall.com/support/notices/gen-7-and-newer-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430
SANS.edu Research: Wellington Rampazo, Shift Left the Awareness and Detection of Developers Using Vulnerable Open-Source Software Components
https://www.sans.edu/cyber-research/shift-left-awareness-detection-developers-using-vulnerable-open-source-software-components/
Do Sextortion Scams Still Work in 2025?
Jan looked at recent sextortion emails to check if any of the crypto addresses in these emails received deposits. Sadly, some did, so these scams still work.
https://isc.sans.edu/diary/Do%20sextortion%20scams%20still%20work%20in%202025%3F/32178
Akira Ransomware Group s use of Drivers
Guidepoint Security observed the Akira ransomware group using specific legitimate drivers for privilege escalation
https://www.guidepointsecurity.com/blog/gritrep-akira-sonicwall/
Adobe Patches Critical Experience Manager Vulnerability
Adobe released emergency patches for a vulnerability in Adobe Experience Manager after a PoC exploit was made public.
https://slcyber.io/assetnote-security-research-center/struts-devmode-in-2025-critical-pre-auth-vulnerabilities-in-adobe-experience-manager-forms/
https://helpx.adobe.com/security/products/aem-forms/apsb25-82.html
Trend Micro Apex One Vulnerability
Trend Micro released an emergency patch for an actively exploited pre-authentication remote code execution vulnerability in the Apex One management console.
https://success.trendmicro.com/en-US/solution/KA-0020652
Stealing Machinekeys for fun and profit (or riding the SharePoint wave)
Bojan explains in detail how .NET uses Machine Keys to protect the VIEWSTATE, and how to abuse the VIEWSTATE for code execution if the Machine Keys are lost.
https://isc.sans.edu/diary/Stealing%20Machine%20Keys%20for%20fun%20and%20profit%20%28or%20riding%20the%20SharePoint%20wave%29/32174
Perplexity is using stealth, undeclared crawlers to evade website no-crawl directives
Perplexity will change its User Agent, or use different originating IP addresses, if it detects being blocked from scanning websites
https://blog.cloudflare.com/perplexity-is-using-stealth-undeclared-crawlers-to-evade-website-no-crawl-directives/
Gen 7 SonicWall Firewalls SSLVPN Recent Threat Activity
Over the past 72 hours, there has been a notable increase in both internally and externally reported cyber incidents involving Gen 7 SonicWall firewalls where SSLVPN is enabled.
https://www.sonicwall.com/support/notices/gen-7-sonicwall-firewalls-sslvpn-recent-threat-activity/250804095336430
Daily Trends Report
A new trends report will bring you daily data highlights via e-mail.
https://isc.sans.edu/diary/New%20Feature%3A%20Daily%20Trends%20Report/32170
NVidia Triton RCE
Wiz found an interesting information leakage vulnerability in NVidia s Triton servers that can be leveraged to remote code execution.
https://www.wiz.io/blog/nvidia-triton-cve-2025-23319-vuln-chain-to-ai-server
Cursor AI MCP Vulnerability
An attacker could abuse negligent Cursor MCP configurations to implement backdoors into developer machines.
https://www.aim.security/lp/aim-labs-curxecute-blogpost
Scans for pop3user with guessable password
A particular IP assigned to a network that calls itself Unmanaged has been scanning telnet/ssh for a user called pop3user with passwords pop3user or 123456 . I assume they are looking for legacy systems that either currently run pop3 or ran pop3 in the past, and left the user enabled.
https://isc.sans.edu/diary/Legacy%20May%20Kill/32166
Possible Sonicwall SSL VPN 0-Day
Arcticwolf observed compromised Sonicwall SSL VPN devices used by the Akira group to install ransomware. These devices were fully patched, and credentials were recently rotated.
https://arcticwolf.com/resources/blog/arctic-wolf-observes-july-2025-uptick-in-akira-ransomware-activity-targeting-sonicwall-ssl-vpn/
PAM Based Linux Backdoor
For over a year, attackers have used a PAM-based Linux backdoor that so far has gotten little attention from anti-malware vendors. PAM-based backdoors can be stealthy, and this one in particular includes various anti-forensics tricks.
https://www.nextron-systems.com/2025/08/01/plague-a-newly-discovered-pam-based-backdoor-for-linux/
Scattered Spider Related Domain Names
A quick demo of our domain feeds and how they can be used to find Scattered Spider related domains
https://isc.sans.edu/diary/Scattered+Spider+Related+Domain+Names/32162
Excel External Workbook Links to Blocked File Types Will Be Disabled by Default
Excel will discontinue allowing links to dangerous file types starting as early as October.
https://support.microsoft.com/en-us/topic/external-workbook-links-to-blocked-file-types-will-be-disabled-by-default-6dd12903-0592-463d-9e68-0741cf62ee58
CISA Releases Thorium
CISA announced that it released its malware analysis platform, Thorium, as open-source software.
https://www.cisa.gov/news-events/alerts/2025/07/31/thorium-platform-public-availability
Securing Firebase: Lessons Re-Learned from the Tea Breach
Inspried by the breach of the Tea app, Brendon Evans recorded a video to inform of Firebase security issues
https://isc.sans.edu/diary/Securing%20Firebase%3A%20Lessons%20Re-Learned%20from%20the%20Tea%20Breach/32158
WebKit Vulnerability Exploited before Apple Patch
A WebKit vulnerablity patched by Apple yesterday has already been exploited in Google Chrome. Google noted the exploit with its patch for the same vulnerability in Chrome.
https://nvd.nist.gov/vuln/detail/CVE-2025-6558
Scattered Spider Update
CISA released an update for its report on Scattered Spider, noting that the group also calls helpdesks impersonating users, not just the other way around.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a
Apple Updates Everything: July 2025 Edition
Apple released updates for all of its operating systems patching 89 different vulnerabilities. Many vulnerabilities apply to multiple operating systems.
https://isc.sans.edu/diary/Apple%20Updates%20Everything%3A%20July%202025/32154
Python Triage
A quick python script by Xavier to efficiently search through files, even compressed once, for indicators of compromise.
https://isc.sans.edu/diary/Triage+is+Key+Python+to+the+Rescue/32152/
PaperCut Attacks
CISA added a 2024 Papercut vulnerability to the known exploited vulnerability list.
https://www.cisa.gov/news-events/alerts/2025/07/28/cisa-adds-three-known-exploited-vulnerabilities-catalog
Parasitic SharePoint Exploits
We are seeing attacks against SharePoint itself and attempts to exploit backdoors left behind by attackers.
https://isc.sans.edu/diary/Parasitic%20Sharepoint%20Exploits/32148
Cisco ISE Vulnerability Exploited
A recently patched vulnerability in Cisco ISE is now being exploited. The Zero Day Initiative has released a blog detailing the exploit chain to obtain code execution as an unauthenticated user.
https://www.zerodayinitiative.com/blog/2025/7/24/cve-2025-20281-cisco-ise-api-unauthenticated-remote-code-execution-vulnerability
MyAsus Vulnerablity
The MyAsus tool does not store its access tokens correctly, potentially providing an attacker with access to sensitive functions
https://www.asus.com/content/security-advisory/
Linux Namespaces
Linux namespaces can be used to control networking features on a process-by-process basis. This is useful when trying to present a different network environment to a process being analysed.
https://isc.sans.edu/diary/Sinkholing%20Suspicious%20Scripts%20or%20Executables%20on%20Linux/32144
Coyote in the Wild: First-Ever Malware That Abuses UI Automation
Akamai identified malware that takes advantage of Microsoft s UI Automation Framework to programatically interact with the user s system and steal credentials.
https://www.akamai.com/blog/security-research/active-exploitation-coyote-malware-first-ui-automation-abuse-in-the-wild
Testing REST APIs with Autoswagger
The tool Autoswagger can be used to automate the testing of REST APIs following the OpenAPI/Swagger standard.
https://github.com/intruder-io/autoswagger/
New File Integrity Tool: ficheck.py
Jim created a new tool, ficheck.py, that can be used to verify file integrity. It is a drop-in replacement for an older tool, fcheck, which was written in Perl and no longer functions well on modern Linux distributions.
https://isc.sans.edu/diary/New%20Tool%3A%20ficheck.py/32136
Mitel Vulnerability
Mitel released a patch for a vulnerability in its MX-ONE product. The authentication bypass could provide an attacker with user or even admin privileges.
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2025-0009
SonicWall SMA 100 Vulnerability
SonicWall fixed an arbitrary file upload issue in its SMA 100 series firewalls. But exploitation will require credentials.
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0014
Reversing SharePoint Toolshell Exploits CVE-2025-53770 and CVE-2025-53771
A quick walk-through showing how to decode the payload of recent SharePoint exploits
https://isc.sans.edu/diary/Analyzing%20Sharepoint%20Exploits%20%28CVE-2025-53770%2C%20CVE-2025-53771%29/32138
Compromised JavaScript NPM is Package
The popular npm package is was compromised by malware. Luckily, the malicious code was found quickly, and it was reversed after about five hours.
https://socket.dev/blog/npm-is-package-hijacked-in-expanding-supply-chain-attack
Microsoft Quick Machine Recovery
Microsoft added a new quick machine recovery feature to Windows 11. If the system is stuck in a reboot loop, it will boot to a rescue partition and attempt to find fixes from Microsoft.
https://learn.microsoft.com/en-gb/windows/configuration/quick-machine-recovery/?tabs=intune
Microsoft Updates SharePoint Vulnerability Guidance CVE-2025-53770 and CVE-2025-53771
Microsoft released its update for SharePoint 2016, completing the updates across all currently supported versions.
https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
WinZip MotW Privacy
Starting with version 7.10, WinZip introduced an option to no longer include the download URL in zip files as part of the Mark of the Web (MotW).
https://isc.sans.edu/diary/WinRAR%20MoTW%20Propagation%20Privacy/32130
Interlock Ransomware
Several government agencies collaborated to create an informative and comprehensive overview of the Interlock ransomware. Just like prior writeups, this writeup is very informative, including many technical details useful to detect and block this ransomware.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-203a
Sophos Firewall Updates
Sophos patched five different vulnerabilities in its firewalls. Two of them are critical, but these only affect a small percentage of users.
https://www.sophos.com/en-us/security-advisories/sophos-sa-20250721-sfos-rce
Microsoft Released Patches for SharePoint Vulnerability CVE-2025-53770 CVE-2025-53771
Microsoft released a patch for the currently exploited SharePoint vulnerability. It also added a second CVE number identifying the authentication bypass vulnerability.
https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/
How Quickly Are Systems Patched?
Jan took Shodan data to check how quickly recent vulnerabilities were patched. The quick answer: Not fast enough.
https://isc.sans.edu/diary/How%20quickly%20do%20we%20patch%3F%20A%20quick%20look%20from%20the%20global%20viewpoint/32126
HP Enterprise Instant On Access Points Vulnerability
HPE patched two vulnerabilities in its Instant On access points (aka Aruba). One allows for authentication bypass, while the second one enables arbitrary code execution as admin.
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04894en_us
Revealing the AppLocker Bypass Risks in The Suggested Block-list Policy
AppLocker sample policies suffer from a simple bug that may enable some rule bypass, but only if signatures are not enforced.
While reviewing Microsoft s suggested configuration, Varonis Threat Labs noticed a subtle but important issue: the MaximumFileVersion field was set to 65355 instead of the expected 65535.
https://www.varonis.com/blog/applocker-bypass-risks
Ghost Crypt Malware Leverages Zoho WorkDrive
The Ghost malware tricks users into downloading by sending links to Zoho WorkDrive locations.
https://www.esentire.com/blog/ghost-crypt-powers-purerat-with-hypnosis
SharePoint Servers Exploited via 0-day CVE-2025-53770
Late last week, CodeWhite found a new remote code execution exploit against SharePoint. This vulnerability is now actively exploited.
https://isc.sans.edu/diary/Critical+Sharepoint+0Day+Vulnerablity+Exploited+CVE202553770+ToolShell/32122/
Veeam Voicemail Phishing
Attackers appear to impersonate VEEAM in recent voicemail-themed phishing attempts.
https://isc.sans.edu/diary/Veeam%20Phishing%20via%20Wav%20File/32120
Passkey Phishing Attack
A currently active phishing attack takes advantage of the ability to use QR codes to complete the Passkey login procedure
https://expel.com/blog/poisonseed-downgrading-fido-key-authentications-to-fetch-user-accounts/
Hiding Payloads in Linux Extended File Attributes
Xavier today looked at ways to hide payloads on Linux, similar to how alternate data streams are used on Windows. Turns out that extended file attributes do the trick, and he presents some scripts to either hide data or find hidden data.
https://isc.sans.edu/diary/Hiding%20Payloads%20in%20Linux%20Extended%20File%20Attributes/32116
Cisco Patches Critical Identity Services Engine Flaw CVE-2025-20281, CVE-2025-20337, CVE-2025-20282
An unauthenticated user may execute arbitrary code as root across the network due to improperly validated data in Cisco s Identity Services Engine.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6
Oracle Critical Patch Update
Oracle patched 309 flaws across 111 products. 9 of these vulnerabilities have a critical CVSS score of 9.0 or higher.
https://www.oracle.com/security-alerts/cpujul2025.html
Broadcom releases VMware Updates
Broadcom fixed a number of vulnerabilities for ESXi, Workstation, Fusion, and Tools.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/35877
More Free File Sharing Services Abuse
The free file-sharing service catbox.moe is abused by malware. While it officially claims not to allow hosting of executables, it only checks extensions and is easily abused
https://isc.sans.edu/diary/More%20Free%20File%20Sharing%20Services%20Abuse/32112
Ongoing SonicWall Secure Mobile Access (SMA) Exploitation Campaign using the OVERSTEP Backdoor
A group Google identifies as UNC6148 is exploiting the Sonicwall SMA 100 series appliance. The devices are end of life, but even fully patched devices are exploited. Google assumes that these devices are compromised because credentials were leaked during prior attacks. The attacker installs the OVERSTEP backdoor after compromising the device.
https://cloud.google.com/blog/topics/threat-intelligence/sonicwall-secure-mobile-access-exploitation-overstep-backdoor
Weaponizing Trust in File Rendering Pipelines
RenderShock is a comprehensive zero-click attack strategy that targets passive file preview, indexing, and automation behaviours in modern operating systems and enterprise environments. It leverages built-in trust mechanisms and background processing in file systems, email clients, antivirus tools, and graphical user interfaces to deliver payloads without requiring any user interaction.
https://www.cyfirma.com/research/rendershock-weaponizing-trust-in-file-rendering-pipelines/
Keylogger Data Stored in an ADS
Xavier came across a keystroke logger that stores data in alternate data streams. The data includes keystroke logs as well as clipboard data
https://isc.sans.edu/diary/Keylogger%20Data%20Stored%20in%20an%20ADS/32108
Malvertising Homebrew
An attacker has been attempting to trick users into installing a malicious version of Homebrew. The fake software is advertised via paid Google ads and directs users to the attacker s GitHub repo.
https://medium.com/deriv-tech/brewing-trouble-dissecting-a-macos-malware-campaign-90c2c24de5dc
CVE-2025-5333: Remote Code Execution in Broadcom Altiris IRM
LRQA have discovered a critical unauthenticated remote code execution (RCE) vulnerability in the Broadcom Symantec Altiris Inventory Rule Management (IRM) component of Symantec Endpoint Management.
https://www.lrqa.com/en/cyber-labs/remote-code-execution-in-broadcom-altiris-irm/
Code highlighting with Cursor AI for $500,000
A syntax highlighting extension for Cursor AI was used to compromise a developer s workstation and steal $500,000 in cryptocurrency.
https://securelist.com/open-source-package-for-cursor-ai-turned-into-a-crypto-heist/116908/
DShield Honeypot Log Volume Increase
Within the last few months, there has been a dramatic increase in honeypot log volumes and how often these high volumes are seen. This has not just been from Jesse s residential honeypot, which has historically seen higher log volumes, but from all of the honeypots that Jesse runs.
https://isc.sans.edu/diary/DShield+Honeypot+Log+Volume+Increase/32100
Google and Microsoft Trusted Them. 2.3 Million Users Installed Them. They Were Malware.
Koi Security s investigation of a single verified color picker exposed a coordinated campaign of 18 malicious extensions that infected a massive 2.3 million users across Chrome and Edge.
https://blog.koi.security/google-and-microsoft-trusted-them-2-3-million-users-installed-them-they-were-malware-fb4ed4f40ff5
RDP Forensics
Comprehensive overview of Windows RDP Forensics
https://medium.com/@mathias.fuchs/chasing-ghosts-over-rdp-lateral-movement-in-tiny-bitmaps-328d2babd8ec
Experimental Suspicious Domain Feed
Our new experimental suspicious domain feed uses various criteria to identify domains that may be used for phishing or other malicious purposes.
https://isc.sans.edu/diary/Experimental%20Suspicious%20Domain%20Feed/32102
Wing FTP Server RCE Vulnerability Exploited CVE-2025-47812
Huntress saw active exploitation of Wing FTP Server remote code execution (CVE-2025-47812) on a customer on July 1, 2025. Organizations running Wing FTP Server should update to the fixed version, version 7.4.4, as soon as possible.
https://www.huntress.com/blog/wing-ftp-server-remote-code-execution-cve-2025-47812-exploited-in-wild
https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/
FortiWeb Pre-Auth RCE (CVE-2025-25257)
An exploit for the FortiWeb RCE Vulnerability is now available and is being used in the wild.
https://pwner.gg/blog/2025-07-10-fortiweb-fabric-rce
NVIDIA Vulnerable to Rowhammer
NVIDIA has received new research related to the industry-wide DRAM issue known as Rowhammer . The research demonstrates a potential Rowhammer attack against an NVIDIA A6000 GPU with GDDR6 Memory. The purpose of this notice is to reinforce already known mitigations to Rowhammer attacks.
https://nvidia.custhelp.com/app/answers/detail/a_id/5671/~/security-notice%3A-rowhammer---july-2025
SSH Tunneling in Action: direct-tcp requests
Attackers are compromising ssh servers to abuse them as relays. The attacker will configure port forwarding direct-tcp connections to forward traffic to a victim. In this particular case, the Yandex mail server was the primary victim of these attacks.
https://isc.sans.edu/diary/SSH%20Tunneling%20in%20Action%3A%20direct-tcp%20requests%20%5BGuest%20Diary%5D/32094
Fortiguard FortiWeb Unauthenticated SQL injection in GUI (CVE-2025-25257)
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
https://www.fortiguard.com/psirt/FG-IR-25-151
Ruckus Virtual SmartZone (vSZ) and Ruckus Network Director (RND) contain multiple vulnerabilities
Ruckus products suffer from a number of critical vulnerabilities. There is no patch available, and users are advised to restrict access to the vulnerable admin interface.
https://kb.cert.org/vuls/id/613753
Setting up Your Own Certificate Authority for Development: Why and How.
Some tips on setting up your own internal certificate authority using the smallstep CA.
https://isc.sans.edu/diary/Setting%20up%20Your%20Own%20Certificate%20Authority%20for%20Development%3A%20Why%20and%20How./32092
Animation-Driven Tapjacking on Android
Attackers can use a click-jacking like trick to trick victims into clicking on animated transparent dialogs opened from other applications.
https://taptrap.click/usenix25_taptrap_paper.pdf
Adobe Patches
Adobe patched 13 different products yesterday. Most concerning are vulnerabilities in Coldfusion that include code execution and arbitrary file disclosure vulnerabilities.
https://helpx.adobe.com/security/security-bulletin.html
Microsoft Patch Tuesday, July 2025
Today, Microsoft released patches for 130 Microsoft vulnerabilities and 9 additional vulnerabilities not part of Microsoft's portfolio but distributed by Microsoft. 14 of these are rated critical. Only one of the vulnerabilities was disclosed before being patched, and none of the vulnerabilities have so far been exploited.
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%2C%20July%202025/32088
Opposum Attack
If a TLS server is configured to allow switching from HTTP to HTTPS on a specific port, an attacker may be able to inject a request into the data stream.
https://opossum-attack.com/
Ivanti Security Updates
Ivanty fixed vulnerabilities in Ivanty Connect Secure, EPMM, and EPM. In particular the password decryption vulnerabliity may be interesting.
https://www.ivanti.com/blog/july-security-update-2025
What s My File Name
Malware may use the GetModuleFileName API to detect if it was renamed to a name typical for analysis, like sample.exe or malware.exe
https://isc.sans.edu/diary/What%27s%20My%20%28File%29Name%3F/32084
Atomic macOS infostealer adds backdoor for persistent attacks
Malware analyst discovered a new version of the Atomic macOS info-stealer (also known as 'AMOS') that comes with a backdoor, to attackers persistent access to compromised systems.
https://moonlock.com/amos-backdoor-persistent-access
HOUKEN SEEKING A PATH BY LIVING ON THE EDGE WITH ZERO-DAYS
At the beginning of September 2024, an attacker repeatedly exploited vulnerabilities CVE-2024- 8190, CVE-2024-8963, and CVE-2024-9380 vulnerabilities to remotely execute arbitrary code on vulnerable Ivanti Cloud Service Appliance devices.
https://www.cert.ssi.gouv.fr/uploads/CERTFR-2025-CTI-009.pdf
SEO Scams Targeting Putty, WinSCP, and AI Tools
Paid Google ads are advertising trojaned versions of popuplar tools like ssh and winscp
https://arcticwolf.com/resources/blog-uk/malvertising-campaign-delivers-oyster-broomstick-backdoor-via-seo-poisoning-and-trojanized-tools/
Interesting ssh/telnet usernames
Some interesting usernames observed in our honeypots
https://isc.sans.edu/diary/A%20few%20interesting%20and%20notable%20ssh%20telnet%20usernames/32080
More sudo trouble
The host option in Sudo can be exploited to execute commands on unauthorized hosts.
https://www.stratascale.com/vulnerability-alert-CVE-2025-32462-sudo-host
CitrixBleed2 PoC Posted (CVE-2025-5777)
WatchTwer published additional details about the recently patched CitrixBleed vulnerability, including a PoC exploit.
https://labs.watchtowr.com/how-much-more-must-we-bleed-citrix-netscaler-memory-disclosure-citrixbleed-2-cve-2025-5777/
Instagram Using Six Day Certificates
Instagram changes their TLS certificates daily and they use certificates that are just about to expire in a week.
https://hereket.com/posts/instagram-single-day-certificates/
Sudo chroot Elevation of Privilege
The sudo chroot option can be leveraged by any local user to elevate privileges to root, even if no sudo rules are defined for that user.
https://www.stratascale.com/vulnerability-alert-CVE-2025-32463-sudo-chroot
Polymorphic ZIP Files
A zip file with a corrupt End of Central Directory Record may extract different data depending on the tool used to extract the files.
https://hackarcana.com/article/yet-another-zip-trick
Cisco Unified Communications Manager Static SSH Credentials Vulnerability
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssh-m4UBdpE7
Scattered Spider Update
The threat actor known as Scattered Spider is in the news again, this time focusing on airlines. But the techniques used by Scattered Spider, social engineering, are still some of the most dangerous techniques used by various threat actors.
https://cloud.google.com/blog/topics/threat-intelligence/unc3944-proactive-hardening-recommendations?e=48754805
AMI BIOS Vulnerability Exploited CVE-2024-54085
A vulnerability in the Redfish remote access software, including AMI s BIOS, is now being exploited.
https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf
https://eclypsium.com/blog/ami-megarac-vulnerabilities-bmc-part-3/
Act now: Secure Boot certificates expire in June 2026
The Microsoft certificates used in Secure Boot are the basis of trust for operating system security, and all will be expiring beginning June 2026.
https://techcommunity.microsoft.com/blog/windows-itpro-blog/act-now-secure-boot-certificates-expire-in-june-2026/4426856
The Windows Resiliency Initiative: Building resilience for a future-ready enterprise
Microsoft announced more details about its future security and resilience strategy for Windows. In particular, security tools will no longer have kernel access, which is supposed to prevent a repeat of the Cloudflare issue, but may also restrict security tools functionality.
https://blogs.windows.com/windowsexperience/2025/06/26/the-windows-resiliency-initiative-building-resilience-for-a-future-ready-enterprise/
Open-VSX Flaw Puts Developers at Risk
A flaw in the open-vsx extension marketplace could have let to the compromise of any extension offered by the marketplace.
https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44
Bluetooth Vulnerability Could Allow Eavesdropping
A vulnerability in the widely used Airoha Bluetooth chipset can be used to compromise devices and use them for eavesdropping.
https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/
Critical Cisco Identity Services Engine Vulnerability
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-6543
Citrix patched a memory overflow vulnerability leading to unintended control flow and denial of service.
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788
Remote code execution in CentOS Web Panel - CVE-2025-48703
An arbitrary file upload vulnerability in the user (not admin) part of Web Panel can be used to execute arbitrary code
https://fenrisk.com/rce-centos-webpanel
Gogs Arbitrary File Deletion Vulnerability
Due to the insufficient patch for the CVE-2024-39931, it's still possible to delete files under the .git directory and achieve remote command execution.
https://github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7
Let s Encrypt Will Soon Issue IP Address-Based Certs
Let s Encrypt is almost ready to issue certificates for IP address SANs from Let's Encrypt's production environment. They'll only be available under the short-lived profile (which has a 6-day validity period), and that profile will remain allowlist-only for a while.
https://community.letsencrypt.org/t/getting-ready-to-issue-ip-address-certificates/238777
Quick Password Brute Forcing Evolution Statistics
After collecting usernames and passwords from our ssh and telnet honeypots for about a decade, I took a look back at how scans changed. Attackers are attempting more passwords in each scans than they used to, but the average length of passwords did not change.
https://isc.sans.edu/diary/Quick%20Password%20Brute%20Forcing%20Evolution%20Statistics/32068
Introducing FileFix A New Alternative to ClickFix Attacks
Attackers may trick the user into copy/pasting strings into file explorer, which will execute commands similar to the ClickFix attack that tricks users into copy pasting the command into the start menu s cmd feature.
https://www.mobile-hacker.com/2025/06/24/introducing-filefix-a-new-alternative-to-clickfix-attacks/
Threat Actors Modify and Re-Create Commercial Software to Steal User s Information
A fake Sonicwall Netextender clone will steal user s credentials
https://www.sonicwall.com/blog/threat-actors-modify-and-re-create-commercial-software-to-steal-users-information
Scans for Ichano AtHome IP Cameras
A couple days ago, a few sources started scanning for the username super_yg and the password 123. This is associated with Ichano IP Camera software.
https://isc.sans.edu/diary/Scans%20for%20Ichano%20AtHome%20IP%20Cameras/32062
Critical Netscaler Security Update CVE-2025-5777
CVE 2025-5777 is a critical severity vulnerability impacting NetScaler Gateway, i.e. if NetScaler has been configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server.
https://www.netscaler.com/blog/news/critical-security-updates-for-netscaler-netscaler-gateway-and-netscaler-console/
WinRar Vulnerability CVE-2025-6218
WinRar may be tricked into extracting files into attacker-determined locations, possibly leading to remote code execution
https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=276&cHash=b5165454d983fc9717bc8748901a64f9
ADS & Python Tools
Didier explains how to use his tools cut-bytes.py and filescanner to extract information from alternate data streams.
https://isc.sans.edu/diary/ADS%20%26%20Python%20Tools/32058
Enhanced security defaults for Windows 365 Cloud PCs
Microsoft announced more secure default configurations for its Windows 365 Cloud PC offerings.
https://techcommunity.microsoft.com/blog/windows-itpro-blog/enhanced-security-defaults-for-windows-365-cloud-pcs/4424914
CVE-2025-34508: Another File Sharing Application, Another Path Traversal
Horizon3 reveals details of a recently patched directory traversal vulnerability in zend.to.
https://horizon3.ai/attack-research/attack-blogs/cve-2025-34508-another-file-sharing-application-another-path-traversal/
Unexpected security footguns in Go's parsers
Go parsers for JSON and XML are not always compatible and can parse data in unexpected ways. This blog by Trails of Bits goes over the various security implications of this behaviour.
https://blog.trailofbits.com/2025/06/17/unexpected-security-footguns-in-gos-parsers/
How Long Until the Phishing Starts? About Two Weeks
After setting up a Google Workspace and adding a new user, it took only two weeks for the new employee to receive somewhat targeted phishing emails.
https://isc.sans.edu/diary/How%20Long%20Until%20the%20Phishing%20Starts%3F%20About%20Two%20Weeks/32052
Scammers hijack websites of Bank of America, Netflix, Microsoft, and more to insert fake phone numbers
Scammers are placing Google ads that point to legitimate companies sites, but are injecting malicious text into the page advertising fake tech support numbers
https://www.malwarebytes.com/blog/news/2025/06/scammers-hijack-websites-of-bank-of-america-netflix-microsoft-and-more-to-insert-fake-phone-number
What s in an ASP? Creative Phishing Attack on Prominent Academics and Critics of Russia
Targeted attacks are tricking victims into creating app-specific passwords to Google resources.
https://cloud.google.com/blog/topics/threat-intelligence/creative-phishing-academics-critics-of-russia
Extracting Data From JPEGs
Didier shows how to efficiently extract data from JPEGs using his tool jpegdump.py
https://isc.sans.edu/diary/A%20JPEG%20With%20A%20Payload/32048
Windows Recall Export in Europe
In its latest insider build for Windows 11, Microsoft is testing an export feature for data stored by Recall. The feature is limited to European users and requires that you note an encryption key that will be displayed only once as Recall is enabled.
https://blogs.windows.com/windows-insider/2025/06/13/announcing-windows-11-insider-preview-build-26120-4441-beta-channel/
Anubis Ransomware Now Wipes Data
The Anubis ransomware, usually known for standard double extortion, is now also wiping data preventing any recovery even if you pay the ransom.
https://www.trendmicro.com/en_us/research/25/f/anubis-a-closer-look-at-an-emerging-ransomware.html
Mitel Vulnerabilities CVE-2025-47188
Mitel this week patched a critical path traversal vulnerability (sadly, no CVE), and Infoguard Labs published a PoC exploit for an older file upload vulnerability.
https://labs.infoguard.ch/posts/cve-2025-47188_mitel_phone_unauthenticated_rce/ https://www.mitel.com/support/mitel-product-security-advisory-misa-2025-0007
Katz Stealer in JPG
Xavier found some multistage malware that uses an Excel Spreadsheet and an HTA file to load an image that includes embeded a copy of Katz stealer.
https://isc.sans.edu/diary/More+Steganography/32044
https://unit42.paloaltonetworks.com/malicious-javascript-using-jsfiretruck-as-obfuscation/
JavaScript obfuscated with JSF*CK is being used on over 200,000 websites to direct victims to malware
Expired Discord Invite Links Used for Malware Distribution
Expired discord invite links are revived as vanity links to direct victims to malware sites
https://research.checkpoint.com/2025/from-trust-to-threat-hijacked-discord-invites-used-for-multi-stage-malware-delivery/
Automated Tools to Assist with DShield Honeypot Investigations
https://isc.sans.edu/diary/Automated%20Tools%20to%20Assist%20with%20DShield%20Honeypot%20Investigations%20%5BGuest%20Diary%5D/32038
EchoLeak: Zero-Click Microsoft 365 Copilot Data Leak
Microsoft fixed a vulnerability in Copilot that could have been abused to exfiltrate data from Copilot users. Copilot mishandled instructions an attacker included in documents inspected by Copilot and executed them.
https://www.aim.security/lp/aim-labs-echoleak-blogpost
Thunderbolt Vulnerability
Thunderbolt users may be tricked into downloading arbitrary files if an email includes a mailbox:/// URL.
https://www.mozilla.org/en-US/security/advisories/mfsa2025-49/
Quasar RAT Delivered Through Bat Files
Xavier is walking you through a quick reverse analysis of a script that will injection code extracted from a PNG image to implement a Quasar RAT.
https://isc.sans.edu/diary/Quasar%20RAT%20Delivered%20Through%20Bat%20Files/32036
Delayed Windows 11 24H2 Rollout
Microsoft slightly throttled the rollout of windows 11 24H2 due to issues stemming from the patch Tuesday fixes.
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3570
An In-Depth Analysis of CVE-2025-33073
Patch Tuesday fixed an already exploited SMB client vulnerability. A blog by Synacktiv explains the nature of the issue and how to exploit it.
https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025
Connectwise Rotating Signing Certificates
Connectwise is rotating signing certificates after a recent compromise, and will release a new version of its Screen share software soon to harden its configuration.
https://www.connectwise.com/company/trust/advisories
KDE Telnet URL Vulnerablity
The Konsole delivered as part of KDE may be abused to execute arbitrary code via telnet URLs.
https://kde.org/info/security/advisory-20250609-1.txt
Microsoft Patch Tuesday
Microsoft today released patches for 67 vulnerabilities. 10 of these vulnerabilities are rated critical. One vulnerability has already been exploited and another vulnerability has been publicly disclosed before today.
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202025/32032
Adobe Vulnerabilities
Adobe released patches for 7 different applications. Two significant ones are Adobe Commerce and Adobe Acrobat Reader. All vulnerabilities patched for Adobe Commerce can only be exploited by an authenticated user. The Adobe Acrobat Reader vulnerabilities are exploited by a user opening a crafted PDF, and the exploit may execute arbitrary code.
https://helpx.adobe.com/security/Home.html
OctoSQL & Vulnerability Data
OctoSQL is a neat tool to query files in different formats using SQL. This can, for example, be used to query the JSON vulnerability files from CISA or NVD and create interesting joins between different files.
https://isc.sans.edu/diary/OctoSQL+Vulnerability+Data/32026
Mirai vs. Wazuh
The Mirai botnet has now been observed exploiting a vulnerability in the open-source EDR tool Wazuh.
https://www.akamai.com/blog/security-research/botnets-flaw-mirai-spreads-through-wazuh-vulnerability
DNS4EU
The European Union created its own public recursive resolver to offer a public resolver compliant with European privacy laws. This resolver is currently operated by ENISA, but the intent is to have a commercial entity operate and support it by a commercial entity.
https://www.joindns4.eu/
WordPress FAIR Package Manager
Recent legal issues around different WordPress-related entities have made it more difficult to maintain diverse sources of WordPress plugins. With WordPress plugins usually being responsible for many of the security issues, the Linux Foundation has come forward to support the FAIR Package Manager, a tool intended to simplify the management of WordPress packages.
https://github.com/fairpm
Extracting With pngdump.py
Didier extended his pngdump.py script to make it easier to extract additional data appended to the end of the image file.
https://isc.sans.edu/diary/Extracting%20With%20pngdump.py/32022
16 React Native Packages for GlueStack Backdoored Overnight
16 npm packages with over a million weekly downloads between them were compromised. The compromised packages include a remote admin tool that was seen before in similar attacks.
https://www.aikido.dev/blog/supply-chain-attack-on-react-native-aria-ecosystem
Atomic MacOS Stealer Exploits Clickfix
MacOS users are now also targeted by fake captchas, tricking users into running exploit code.
https://www.cloudsek.com/blog/amos-variant-distributed-via-clickfix-in-spectrum-themed-dynamic-delivery-campaign-by-russian-speaking-hackers
Microsoft INETPUB Script
Microsoft published a simple PowerShell script to restore the inetpub folder in case you removed it by mistake.
https://www.powershellgallery.com/packages/Set-InetpubFolderAcl/1.0
Be Careful With Fake Zoom Client Downloads
Miscreants are tricking victims into downloading fake Zoom clients (and likely other meeting software) by first sending them fake meeting invites that direct victims to a page that offers malware for download as an update to the Zoom client.
https://isc.sans.edu/diary/Be%20Careful%20With%20Fake%20Zoom%20Client%20Downloads/32014
Python tarfile Vulnerability
Recently, the Python tarfile module introduced a filter option to help mitigate some of the insecure behavior common to software unpacking archives. This filter is, however, not working quite as well as it should.
https://mail.python.org/archives/list/security-announce@python.org/thread/MAXIJJCUUMCL7ATZNDVEGGHUMQMUUKLG/
Hewlett Packard Enterprise Insight Remote Support processAttachmentDataStream Directory Traversal Remote Code Execution Vulnerability
HP fixed, among other vulnerabilities, a critical remote code execution vulnerability in Insight Remote Support (IRS)
https://www.zerodayinitiative.com/advisories/ZDI-25-325/
Phishing e-mail that hides malicious links from Outlook users
Jan found a phishing email that hides the malicious link from Outlook users. The email uses specific HTML comment clauses Outlook interprets to render or not render specific parts of the email s HTML code. Jan suggests that the phishing email is intented to not expose users of
https://isc.sans.edu/diary/Phishing%20e-mail%20that%20hides%20malicious%20link%20from%20Outlook%20users/32010
Amazon changing default logging from blocking to non-blocking
Amazon will change the default logging mode from blocking to non-blocking. Non-blocking logging will not stop the application if logging fails, but may result in a loss of logs.
https://aws.amazon.com/blogs/containers/preventing-log-loss-with-non-blocking-mode-in-the-awslogs-container-log-driver/
Cisco Removes Backdoor
Cisco fixed a Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-aws-static-cred-FPMjUcm7
Infoblox Vulnerability Details disclosed
Details regarding several vulnerabilities recently patched in Infoblox s NetMRI have been made public. In particular an unauthenticated remote code execution issue should be considered critical.
https://rhinosecuritylabs.com/research/infoblox-multiple-cves/
vBulletin Exploits CVE-2025-48827, CVE-2025-48828
We do see exploit attempts for the vBulletin flaw disclosed about a week ago. The flaw is only exploitable if vBulltin is run on PHP 8.1, and was patched over a year ago. However, vBulltin never disclosed the type of vulnerability that was patched.
https://isc.sans.edu/diary/vBulletin%20Exploits%20%28CVE-2025-48827%2C%20CVE-2025-48828%29/32006
Google Chrome 0-Day Patched
Google released a security update for Google Chrome patching three flaws. One of these is already being exploited.
https://chromereleases.googleblog.com/
Roundcube Update
Roundcube patched a vulnerability that allows any authenticated user to execute arbitrary code.
https://roundcube.net/news/2025/06/01/security-updates-1.6.11-and-1.5.10
HP Vulnerabilities in StoreOnce
HP patched multiple vulnerabilities in StoreOnce. These issues could lead to remote code execution
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbst04847en_us&docLocale=en_US
Simple SSH Backdoor
Xavier came across a simple SSH backdoor taking advantage of the ssh client preinstalled on recent Windows systems. The backdoor is implemented via an SSH configuration file that instructs the SSH client to connect to a remote system and forward a shell on a random port. This will make the shell accessible to anybody able to connect to the C2 host.
https://isc.sans.edu/diary/Simple%20SSH%20Backdoor/32000
Google Chrome to Distrust CAs
Google Chrome will remove the Chunghwa Telecom and Netlock certificate authorities from its list of trusted CAs. Any certificates issued after July 31st will not be trusted. Certificates issued before the deadline will be trusted until they expire.
https://security.googleblog.com/2025/05/sustaining-digital-certificate-security-chrome-root-store-changes.html
Microsoft Emergency Update to Fix Crashes Caused by May Patch
Microsoft released an emergency update for a bug caused by one of the patches released in May. Due to the bug, systems may not restart after the patch is applied. This affects, first of all, virtual systems running in Azure and HyperV but apparently has also affected some physical systems.
https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23h2#kb5058405-might-fail-to-install-with-recovery-error-0xc0000098-in-acpi-sys
Qualcomm Adreno Graphics Processing Unit Patch (Exploited!)
Qualcomm released an update for the driver for its Adreno GPU. The patched vulnerability is already being exploited against Android devices.
https://docs.qualcomm.com/product/publicresources/securitybulletin/june-2025-bulletin.html
A PNG Image With an Embedded Gift
Xavier shows how Python code attached to a PNG image can be used to implement a command and control channel or a complete remote admin kit.
https://isc.sans.edu/diary/A+PNG+Image+With+an+Embedded+Gift/31998
Cisco IOS XE WLC Arbitrary File Upload Vulnerability (CVE-2025-20188) Analysis
Horizon3 analyzed a recently patched flaw in Cisco Wireless Controllers. This arbitrary file upload flaw can easily be used to execute arbitrary code.
https://horizon3.ai/attack-research/attack-blogs/cisco-ios-xe-wlc-arbitrary-file-upload-vulnerability-cve-2025-20188-analysis/
Don't Call That "Protected" Method: Dissecting an N-Day vBulletin RCE
A change in PHP 8.1 can expose methods previously expected to be safe . vBulletin fixed a related flaw about a year ago without explicitly highlighting the security impact of the fix. A blog post now exposed the flaw and provided exploit examples. We have seen exploit attempts against honeypots starting May 25th, two days after the blog was published.
https://karmainsecurity.com/dont-call-that-protected-method-vbulletin-rce
Alternate Data Streams: Adversary Defense Evasion and Detection
Good Primer of alternate data streams and how they are abused, as well as how to detect and defend against ADS abuse.
https://isc.sans.edu/diary/Alternate%20Data%20Streams%20%3F%20Adversary%20Defense%20Evasion%20and%20Detection%20%5BGuest%20Diary%5D/31990
Connectwise Breach Affects ScreenConnect Customers
Connectwise s ScreenConnect solution was compromised, leading to attacks against a small number of customers. This is yet another example of how attackers are taking advantage of remote access solutions.
https://www.connectwise.com/company/trust/advisories
Mark Your Calendar: APT41 Innovative Tactics
Google detected attacks leveraging Google s calendar solution as a command and control channel.
https://cloud.google.com/blog/topics/threat-intelligence/apt41-innovative-tactics
Webs of Deception: Using the SANS ICS Kill Chain to Flip the Advantage to the Defender
Defending a small Industrial Control System (ICS) against sophisticated threats can seem futile. The resource disparity between small ICS defenders and sophisticated attackers poses a significant security challenge.
https://www.sans.edu/cyber-research/webs-deception-using-sans-ics-kill-chain-flip-advantage-defender/
Exploring a Use Case of Artificial Intelligence Assistance with Understanding an Attack
Jennifer Wilson took a weird string found in a recent honeypot sample and worked with ChatGPT to figure out what it is all about.
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Exploring%20a%20Use%20Case%20of%20Artificial%20Intelligence%20Assistance%20with%20Understanding%20an%20Attack/31980
Ransomware Deployed via SimpleHelp Vulnerabilities
Ransomware actors are using vulnerabilities in SimpleHelp to gain access to victim s networks via MSPs. The exploited vulnerabilities were patched in January.
https://news.sophos.com/en-us/2025/05/27/dragonforce-actors-target-simplehelp-vulnerabilities-to-attack-msp-customers/
OS Command Injection in Everetz Equipment
Broadcast equipment manufactured by Everetz is susceptible to an OS command injection vulnerability. Everetz has not responded to researchers reporting the vulnerability so far and there is no patch available.
https://www.onekey.com/resource/security-advisory-remote-code-execution-on-evertz-svdn-cve-2025-4009
SSH authorized_keys File
One of the most common techniques used by many bots is to add rogue keys to the authorized_keys file, implementing an SSH backdoor. Managing these files and detecting unauthorized changes is not hard and should be done if you operate Unix systems.
https://isc.sans.edu/diary/Securing%20Your%20SSH%20authorized_keys%20File/31986
REMOTE COMMAND EXECUTION ON SMARTBEDDED METEOBRIDGE (CVE-2025-4008)
Weatherstation software Meteobridge suffers from an easily exploitable unauthenticated remote code execution vulnerability
https://www.onekey.com/resource/security-advisory-remote-command-execution-on-smartbedded-meteobridge-cve-2025-4008
https://forum.meteohub.de/viewtopic.php?t=18687
Manageengine ADAuditPlus SQL Injection
Zoho patched two SQL Injection vulnerabilities in its ManageEngine ADAuditPlus product
https://www.manageengine.com/products/active-directory-audit/cve-2025-41407.html
https://www.manageengine.com/products/active-directory-audit/cve-2025-36527.html
Dero Miner Infects Containers through Docker API
Kaspersky found yet another botnet infecting docker containers to spread crypto coin miners. The initial access happens via exposed docker APIs.
https://securelist.com/dero-miner-infects-containers-through-docker-api/116546/
SVG Steganography
Steganography is not only limited to pixel-based images but can be used to embed messages into vector-based formats like SVG.
https://isc.sans.edu/diary/SVG%20Steganography/31978
Fortinet Vulnerability Details CVE-2025-32756
Horizon3.ai shows how it was able to find the vulnerability in Fortinet s products, and how to possibly exploit this issue. The vulnerability is already being exploited in the wild and was patched May 13th
https://horizon3.ai/attack-research/attack-blogs/cve-2025-32756-low-rise-jeans-are-back-and-so-are-buffer-overflows/
Remote Prompt Injection in GitLab Duo Leads to Source Code Theft
An attacker may leave instructions (prompts) for GitLab Duo embedded in the source code. This could be used to exfiltrate source code and secrets or to inject malicious code into an application.
https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo
Resilient Secure Backup Connectivity for SMB/Home Users
Establishing resilient access to a home network via a second ISP may lead to unintended backdoors. Secure the access and make sure you have the visibility needed to detect abuse.
https://isc.sans.edu/diary/Resilient%20Secure%20Backup%20Connectivity%20for%20SMB%20Home%20Users/31972
BadSuccessor: Abusing dMSA to Escalate Privileges in Active Directory
An attacker with the ability to create service accounts may be able to manipulate these accounts to mark them as migrated accounts, inheriting all privileges the original account had access to.
https://www.akamai.com/blog/security-research/abusing-dmsa-for-privilege-escalation-in-active-directory
Flaw in samlify That Opens Door to SAML Single Sign-On Bypass CVE-2025-47949
The samlify Node.js library does not verify SAML assertions correctly. It will consider the entire assertion valid, not just the original one. An attacker may use this to obtain additional privileges or authenticate as a different user
https://www.endorlabs.com/learn/cve-2025-47949-reveals-flaw-in-samlify-that-opens-door-to-saml-single-sign-on-bypass
New Variant of Crypto Confidence Scam
Scammers are offering login credentials for what appears to be high value crypto coin accounts. However, the goal is to trick users into paying for expensive VIP memberships to withdraw the money.
https://isc.sans.edu/diary/New%20Variant%20of%20Crypto%20Confidence%20Scam/31968
Malicious Chrome Extensions
Malicious Chrome extensions mimick popular services like VPNs to trick users into installing them. Once installed, the extensions will exfiltrate browser secrets
https://dti.domaintools.com/dual-function-malware-chrome-extensions/
Malicious VS Code Extensions
Malicious Visual Studio Code extensions target crypto developers to trick them into installing them to exfiltrate developer secrets.
https://securitylabs.datadoghq.com/articles/mut-9332-malicious-solidity-vscode-extensions/#indicators-of-compromise
Researchers Scanning the Internet
A newish RFC, RFC 9511, suggests researchers identify themselves by adding strings to the traffic they send, or by operating web servers on machines from which the scan originates. We do offer lists of researchers and just added three new groups today
https://isc.sans.edu/diary/Researchers%20Scanning%20the%20Internet/31964
Cloudy with a change of Hijacking: Forgotten DNS Records
Organizations do not always remove unused CNAME records. An attacker may take advantage of this if an attacker is able to take possession of the now unused public cloud resource the name pointed to.
https://blogs.infoblox.com/threat-intelligence/cloudy-with-a-chance-of-hijacking-forgotten-dns-records-enable-scam-actor/
Message signature verification can be spoofed CVE-2025-47934
A vulnerability in openpgp.js may be used to spoof message signatures. openpgp.js is a popular library in systems implementing end-to-end encrypted browser applications.
https://github.com/openpgpjs/openpgpjs/security/advisories/GHSA-8qff-qr5q-5pr8
RAT Dropped By Two Layers of AutoIT Code
Xavier explains how AutoIT was used to install a remote admin tool (RAT) and how to analyse such a tool
https://isc.sans.edu/diary/RAT%20Dropped%20By%20Two%20Layers%20of%20AutoIT%20Code/31960
RVTools compromise confirmed
Robware.net, the site behind the popular tool RVTools now confirmed that it was compromised. The site is currently offline.
https://www.robware.net/readMore
Trojaned Version of Keepass used to install info stealer and Cobalt Strike beacon
A backdoored version of KeePass was used to trick victims into installing Cobalt Strike and other malware. In this case, Keepass itself was not compromised and the malicious version was advertised via search engine optimization tricks
https://labs.withsecure.com/publications/keepass-trojanised-in-advanced-malware-campaign
Procolored UV Printer Software Compromised
The official software offered by the makers of the Procolored UV printer has been compromised, and versions with malware were distributed for about half a year.
https://www.hackster.io/news/the-maker-s-toolbox-procolored-v11-pro-dto-uv-printer-review-680d491e17e3
https://www.gdatasoftware.com/blog/2025/05/38200-printer-infected-software-downloads
xorsearch.py: Python Functions
Didier s xorsearch tool now supports python functions to filter output
https://isc.sans.edu/diary/xorsearch.py%3A%20Python%20Functions/31858
Pwn2Own Berlin 2025
Last weeks Pwn2Own contest in Berlin allowed researchers to demonstrate a number of new exploits with a large focus on privilege escalation and virtual machine escape.
https://www.zerodayinitiative.com/blog/2025/5/17/pwn2own-berlin-2025-day-three-results
Senior US Officials Impersonated in Malicious Messaging Campaign
The FBI warns of senior US officials being impersonated in text and voice messages.
https://www.ic3.gov/PSA/2025/PSA250515
Scattered Spider: TTP Evolution in 2025
Pushscurity provided an update on how Scattered Spider evolved. One thing they noted was that Scattered Spider takes advantage of legit dynamic domain name systems to make detection more difficult
https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/
Web Scanning SonicWall for CVE-2021-20016 - Update
Scans for SonicWall increased by an order of magnitude over the last couple of weeks. Many of the attacks appear to originate from Global Host , a low-cost virtual hosting provider.
https://isc.sans.edu/diary/Web%20Scanning%20SonicWall%20for%20CVE-2021-20016%20-%20Update/31952
Google Update Patches Exploited Chrome Flaw
Google released an update for Chrome. The update fixes two specific flaws reported by external researchers, CVE-2025-4664 and CVE-2025-4609. The first flaw is already being exploited in the wild.
https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop_14.html
https://x.com/slonser_/status/1919439373986107814
RVTools Bumblebee Malware Attack
Zerodaylabs published its analysis of the RV-Tools Backdoor attack. It suggests that this may not be solely a search engine optimization campaign directing victims to the malicious installer, but that the RVTools distribution site was compromised.
https://zerodaylabs.net/rvtools-bumblebee-malware/
Operation RoundPress
ESET Security wrote up a report summarizing recent XSS attacks against open-source webmail systems
https://www.welivesecurity.com/en/eset-research/operation-roundpress/
Another day, another phishing campaign abusing google.com open redirects
Google s links from it s maps page to hotel listings do suffer from an open redirect vulnerability that is actively exploited to direct users to phishing pages.
https://isc.sans.edu/diary/Another%20day%2C%20another%20phishing%20campaign%20abusing%20google.com%20open%20redirects/31950
Adobe Patches
Adobe patched 12 different applications. Of particular interest is the update to ColdFusion, which fixes several arbitrary code execution and arbitrary file read problems.
https://helpx.adobe.com/security/security-bulletin.html
Samsung Patches magicInfo 9 Again
Samsung released a new patch for the already exploited magicInfo 9 CMS vulnerability. While the description is identical to the patch released last August, a new CVE number is used.
https://security.samsungtv.com/securityUpdates#SVP-MAY-2025
Ivanti Patches Critical Ivanti Neurons Flaw
Ivanti released a patch for Ivanti Neurons for ITSM (on-prem only) fixing a critical authentication bypass vulnerability. Ivanti also points to its guidance to secure the underlying IIS server to make exploitation of flaws like this more difficult
Microsoft Patch Tuesday
Microsoft patched 70-78 vulnerabilities (depending on how you count them). Five of these vulnerabilities are already being exploited. In particular, a remote code execution vulnerability in the scripting engine should be taken seriously. It requires the Microsoft Edge browser to run in Internet Explorer mode.
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20May%202025/31946
Security Advisory Ivanti Endpoint Manager Mobile (EPMM) May 2025 (CVE-2025-4427 and CVE-2025-4428)
Ivanti patched an authentication bypass vulnerability and a remote code execution vulnerability. The authentication bypass can exploit the remote code execution vulnerability without authenticating first.
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US
Fortinet Patches Exploited Vulnerability in API (CVE-2025-32756)
Fortinet patched an already exploited stack-based buffer overflow vulnerability in the API of multiple Fortinet products. The vulnerability is exploited via crafted HTTP requests.
https://fortiguard.fortinet.com/psirt/FG-IR-25-254
Apple Updates Everything
Apple patched all of its operating systems. This update ports a patch for a recently exploited vulnerability to older versions of iOS and macOS.
https://isc.sans.edu/diary/31942
It Is 2025, And We Are Still Dealing With Default IoT Passwords And Stupid 2013 Router Vulnerabilities
Versions of the Mirai botnet are attacking devices made by Unipi Technology. These devices are using a specific username and password combination. In addition, this version of the Mirai botnet will also attempt exploits against an old Netgear vulnerability.
https://isc.sans.edu/diary/It%20Is%202025%2C%20And%20We%20Are%20Still%20Dealing%20With%20Default%20IoT%20Passwords%20And%20Stupid%202013%20Router%20Vulnerabilities/31940
Output Messenger Vulnerability
The internal messenger application Output Messenger is currently used in sophisticated attacks. Attackers are exploiting a path traversal vulnerability that has not been fixed.
https://www.outputmessenger.com/cve-2025-27920/
Commvault Correction
Commvault s patch indeed fixes the recent vulnerability. The Pioneer Release Will Dormann used to experiment will only offer patches after it has been registered, which leads to an error when assessing the patch s efficacy.
https://www.darkreading.com/application-security/commvault-patch-works-as-intended
Steganography Challenge
Didier revealed the solution to last weekend s cryptography challenge. The image used the same encoding scheme as Didier described before, but the columns and rows were transposed.
https://isc.sans.edu/forums/diary/Steganography%20Challenge%3A%20My%20Solution/31912/
FBI Warns of End-of-life routers
The FBI is tracking larger botnets taking advantage of unpatched routers. Many of these routers are end-of-life, and no patches are available for the exploited vulnerabilities. The attackers are turning the devices into proxies, which are resold for various criminal activities.
https://www.ic3.gov/PSA/2025/PSA250507
ASUS Driverhub Vulnerability
ASUS Driverhub software does not properly check the origin of HTTP requests, allowing a CSRF attack from any website leading to arbitrary code execution.
https://mrbruh.com/asusdriverhub/
RV-Tools SEO Poisoning
Varonis Threat Labs observed SEO poisoning being used to trick system administrators into installing a malicious version of RV Tools. The malicious version includes a remote access tool leading to the theft of credentials
https://www.varonis.com/blog/seo-poisoning#initial-access-and-persistence
No Internet Access: SSH to the Rescue
If faced with restrictive outbound network access policies, a single inbound SSH connection can quickly be turned into a tunnel or a full-blown VPN
https://isc.sans.edu/diary/No%20Internet%20Access%3F%20SSH%20to%20the%20Rescue!/31932
SAMSUNG magicINFO 9 Server Flaw Still exploitable
The SAMSUNG magicINFO 9 Server Vulnerability we found being exploited last week is apparently still not completely patched, and current versions are vulnerable to the exploit observed in the wild.
https://www.huntress.com/blog/rapid-response-samsung-magicinfo9-server-flaw
Bring Your Own Installer: Bypassing SentinelOne Through Agent Version Change Interruption
SentinelOne s installer is vulnerable to an exploit allowing attackers to shut down the end point protection software
https://www.aon.com/en/insights/cyber-labs/bring-your-own-installer-bypassing-sentinelone
Commvault Still Exploitable
A recent patch for Commvault is apparently ineffective and the PoC exploit published by watchTowr is still working against up to date patched systems
https://infosec.exchange/@wdormann/114458913006792356
Example of Modular Malware
Xavier analyzes modular malware that downloads DLLs from GitHub if specific features are required. In particular, the webcam module is inspected in detail.
https://isc.sans.edu/diary/Example%20of%20%22Modular%22%20Malware/31928
Sysaid XXE Vulnerabilities
IT Service Management Software Sysaid patched a number of XXE vulnerabilities. Without authentication, an attacker is able to obtain confidential data and completely compromise the system. watchTowr published a detailed analysis of the flaws including exploit code.
https://labs.watchtowr.com/sysowned-your-friendly-rce-support-ticket/
Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability
Cisco Patched a vulnerability in its wireless controller software that may be used to not only upload files but also execute code as root without authentication.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-file-uplpd-rHZG9UfC
Unifi Protect Camera Vulnerability
Ubiquity patched a vulnerability in its Protect camera firmware fixing a buffer overflow flaw.
https://community.ui.com/releases/Security-Advisory-Bulletin-047-047/cef86c37-7421-44fd-b251-84e76475a5bc
Python InfoStealer with Embedded Phishing Webserver
Didier found an interesting infostealer that, in addition to implementing typical infostealer functionality, includes a web server suitable to create local phishing sites.
https://isc.sans.edu/diary/Python%20InfoStealer%20with%20Embedded%20Phishing%20Webserver/31924
Android Update Fixes Freetype 0-Day
Google released its monthly Android update. As part of the update, it patched a vulnerability in Freetype that is already being exploited. Android is not alone in using Freetype. Freetype is a very commonly used library to parse fonts like Truetype fonts.
https://source.android.com/docs/security/bulletin/2025-05-01
CISA Warns of Unsophistacted Cyber Actors
CISA released an interesting title report warning operators of operational technology networks of ubiquitous attacks by unsophisticated actors. It emphasizes how important it is to not forget basic security measures to defend against these attacks.
https://www.cisa.gov/news-events/alerts/2025/05/06/unsophisticated-cyber-actors-targeting-operational-technology
Mirai Now Exploits Samsung MagicINFO CMS CVE-2024-7399
The Mirai botnet added a new vulnerability to its arsenal. This vulnerability, a file upload and remote code execution vulnerability in Samsung s MagicInfo 9 CMS, was patched last August but attracted new attention last week after being mostly ignored so far.
https://isc.sans.edu/diary/Mirai+Now+Exploits+Samsung+MagicINFO+CMS+CVE20247399/31920
New Kali Linux Signing Key
The Kali Linux maintainers lost access to the secret key used to sign packages. Users must install a new key that will be used going forward.
https://www.kali.org/blog/new-kali-archive-signing-key/
The Risk of Default Configuration: How Out-of-the-Box Helm Charts Can Breach Your Cluster
Many out-of-the-box Helm charts for Kubernetes applications deploy vulnerable configurations with exposed ports and no authentication
https://techcommunity.microsoft.com/blog/microsoftdefendercloudblog/the-risk-of-default-configuration-how-out-of-the-box-helm-charts-can-breach-your/4409560
Steganography Challenge
Didier published a fun steganography challenge. A solution will be offered on Saturday.
https://isc.sans.edu/diary/Steganography+Challenge/31910
Microsoft Makes Passkeys Default Authentication Method
Microsoft is now encouraging new users to use Passkeys as the default and only login method, further moving away from passwords
https://www.microsoft.com/en-us/security/blog/2025/05/01/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins/
Microsoft Authenticator Autofill Changes
Microsoft will no longer support the use of Microsoft authenticator as a password safe. Instead, it will move users to the password prefill feature built into Microsoft Edge. This change will start in June and should be completed in August at which point you must have moved your credentials out of Microsoft Authenticator
https://support.microsoft.com/en-gb/account-billing/changes-to-microsoft-authenticator-autofill-09fd75df-dc04-4477-9619-811510805ab6
Backdoor found in popular e-commerce components
SANSEC identified several backdoored Magento e-commerce components. These backdoors were installed as far back as 2019 but only recently activated, at which point they became known. Affected vendors dispute any compromise at this point.
https://sansec.io/research/license-backdoor
Steganography Analysis With pngdump.py: Bitstreams
More details from Didiear as to how to extract binary content hidden inside images
https://isc.sans.edu/diary/Steganography%20Analysis%20With%20pngdump.py%3A%20Bitstreams/31904
Using Trusted Protocols Against You: Gmail as a C2 Mechanism
Attackers are using typosquatting to trick developers into installing malicious python packages. These python packages will use GMail as a command and control channel by sending email to hard coded GMail accounts
https://socket.dev/blog/using-trusted-protocols-against-you-gmail-as-a-c2-mechanism
Security Brief: French BEC Threat Actor Targets Property Payments
A French business email compromise threat actor is targeting property management firms to send emails to tenents tricking them into sending rent payments to fake bank accounts
https://www.proofpoint.com/us/blog/threat-insight/security-brief-french-bec-threat-actor-targets-property-payments
SANS.edu Research Journal
https://isc.sans.edu/j/research
Web Scanning for Sonicwall Vulnerabilities CVE-2021-20016
For the last week, scans for Sonicwall API login and domain endpoints have skyrocketed. These attacks may be exploiting an older vulnerability or just attempting to brute force credentials.
https://isc.sans.edu/diary/Web%20Scanning%20Sonicwall%20for%20CVE-2021-20016/31906
The Wizards APT Group SLAAC Spoofing Adversary in the Middle Attacks
ESET published an article with details regarding an IPv6-linked attack they have observed. Attackers use router advertisements to inject fake recursive DNS servers that are used to inject IP addresses for hostnames used to update software. This leads to the victim downloading malware instead of legitimate updates.
https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/
Windows RDP Access is Possible with Old Credentials
Credential caching may lead to Windows allowing RDP logins with old credentials.
https://arstechnica.com/security/2025/04/windows-rdp-lets-you-log-in-using-revoked-passwords-microsoft-is-ok-with-that/?comments-page=1#comments
More Scans for SMS Gateways and APIs
Attackers are not just looking for SMS Gateways like the scans we reported on last week, but they are also actively scanning for other ways to use APIs and add on tools to send messages using other people s credentials.
https://isc.sans.edu/diary/More%20Scans%20for%20SMS%20Gateways%20and%20APIs/31902
AirBorne: AirPlay Vulnerabilities
Researchers at Oligo revealed over 20 weaknesses they found in Apple s implementation of the AirPlay protocol. These vulnerabilities can be abused to execute code or launch denial-of-service attacks against affected devices. Apple patched the vulnerabilities in recent updates.
https://www.oligo.security/blog/airborne
SRUM-DUMP Version 3: Uncovering Malware Activity in Forensics
Mark Baggett released SRUM-DUMP Version 3. The tool simplifies data extraction from Widnows System Resource Usage Monitor (SRUM). This database logs how much resources software used for 30 days, and is invaluable to find out what software was executed when and if it sent or received network data.
https://isc.sans.edu/diary/SRUM-DUMP%20Version%203%3A%20Uncovering%20Malware%20Activity%20in%20Forensics/31896
Novel Universal Bypass For All Major LLMS
Hidden Layer discovered a new prompt injection technique that bypasses security constraints in large language models.
The technique uses an XML formatted prequel for a prompt, which appears to the LLM as a policy file. This Policy Puppetry can be used to rewrite some of the security policies configured for LLMs. Unlike other techniques, this technique works across multiple LLMs without changing the policy.
https://hiddenlayer.com/innovation-hub/novel-universal-bypass-for-all-major-llms/
CHOICEJACKING: Compromising Mobile Devices through Malicious Chargers like a Decade ago
The old Juice Jacking is back, at least if you do not run the latest version of Android or iOS. This issue may allow a malicious USB device, particularly a USB charger, to take control of a device connected to it.
https://pure.tugraz.at/ws/portalfiles/portal/89650227/Final_Paper_Usenix.pdf
SANS @RSA: https://www.sans.org/mlp/rsac/
Example of a Payload Delivered Through Steganography
Xavier and Didier published two diaries this weekend, building on each other. First, Xavier showed an example of an image being used to smuggle an executable past network defenses, and second, Didier showed how to use his tools to extract the binary.
https://isc.sans.edu/diary/Example%20of%20a%20Payload%20Delivered%20Through%20Steganography/31892
SAP Netweaver Exploited CVE-2025-31324
An arbitrary file upload vulnerability in SAP s Netweaver product is actively exploited to upload webshells. Reliaquest discovered the issue. Reliaquest reports that they saw it being abused to upload the Brute Ratel C2 framework. Users of Netweaver must turn off the developmentserver alias and disable visual composer, and the application was deprecated for about 10 years. SAP has released an emergency update for the issue.
https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/
https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
Any.Run Reports False Positive Uploads
Due to false positives caused by MS Defender XDR flagging Adobe Acrobat Cloud links as malicious, many users of Any.Run s free tier uploaded confidential documents to Any.Run. Anyrun blocked these uploads for now but reminded users to be cautious about what documents are being uploaded.
https://x.com/anyrun_app/status/1915429758516560190
Attacks against Teltonika Networks SMS Gateways
Attackers are actively scanning for SMS Gateways. These attacks take advantage of default passwords and other commonly used passwords.
https://isc.sans.edu/diary/Attacks%20against%20Teltonika%20Networks%20SMS%20Gateways/31888
Commvault Vulnerability CVE-2205-34028
Commvault, about a week ago, published an advisory and a fix for a vulnerability in its backup software. watchTowr now released a detailed writeup and exploit for the vulnerability
https://labs.watchtowr.com/fire-in-the-hole-were-breaching-the-vault-commvault-remote-code-execution-cve-2025-34028/
Exploitation Trends Q1 2025
Vulncheck published a summary of exploitation trends, pointing out that about a quarter of vulnerabilities are exploited a day after a patch is made available.
https://vulncheck.com/blog/exploitation-trends-q1-2025
inetpub directory issues
The inetpub directory introduced by Microsoft in its April patch may lead to a denial of service against applying patches on Windows if an attacker can create a junction for that location pointing to an existing system binary like Notepad.
https://doublepulsar.com/microsofts-patch-for-cve-2025-21204-symlink-vulnerability-introduces-another-symlink-vulnerability-9ea085537741
Honeypot Iptables Maintenance and DShield-SIEM Logging
In this diary, Jesse is talking about some of the tasks to maintain a honeypot, like keeping filebeats up to date and adjusting configurations in case your dynamic IP address changes
https://isc.sans.edu/diary/Honeypot%20Iptables%20Maintenance%20and%20DShield-SIEM%20Logging/31876
XRPL.js Compromised
An unknown actor was able to push malicious updates of the XRPL.js library to NPM. The library is officially recommended for writing Riple (RPL) cryptocurrency code. The malicious library exfiltrated secret keys to the attacker
https://www.aikido.dev/blog/xrp-supplychain-attack-official-npm-package-infected-with-crypto-stealing-backdoor
https://github.com/XRPLF/xrpl.js/security/advisories/GHSA-33qr-m49q-rxfx
Cisco Equipment Affected by Erlang/OTP SSH Vulnerability
Cisco published an advisory explaining which of its products are affected by the critical Erlang/OTP SSH library vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-erlang-otp-ssh-xyZZy
xorsearch.py: Ad Hoc YARA Rules
Adhoc YARA rules allow for easy searches using command line arguments without having to write complete YARA rules for simple use cases like string and regex searches
https://isc.sans.edu/diary/xorsearch.py%3A%20%22Ad%20Hoc%20YARA%20Rules%22/31856
Google Spoofed via DKIM Replay Attack
DKIM replay attacks are a known issue where the attacker re-uses a prior DKIM signature. This will work as long as the headers signed by the signature are unchanged. Recently, this attack has been successful against Google.
https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/
SSL.com E-Mail Validation Bug
SSL.com did not properly verify which domain a particular email address is authorized to receive certificates for. This could have been exploited against webmail providers.
https://bugzilla.mozilla.org/show_bug.cgi?id=1961406
It's 2025, so why are malicious advertising URLs still going strong?
Phishing attacks continue to take advantage of Google s advertising services. Sadly, this is still the case for obviously malicious links, even after various anti-phishing services flag the URL.
https://isc.sans.edu/diary/It%27s%202025...%20so%20why%20are%20obviously%20malicious%20advertising%20URLs%20still%20going%20strong%3F/31880
ChatGPT Fingerprinting Documents via Unicode
ChatGPT apparently started leaving fingerprints in texts, which it creates by adding invisible Unicode characters like non-breaking spaces.
https://www.rumidocs.com/newsroom/new-chatgpt-models-seem-to-leave-watermarks-on-text
Asus AI Cloud Security Advisory
Asus warns of a remote code execution vulnerability in its routers. The vulnerability is related to the AI Cloud feature. If your router is EoL, disabling the feature will mitigate the vulnerability
https://www.asus.com/content/asus-product-security-advisory/
PyTorch Vulnerability
PyTorch fixed a remote code execution vulnerability exploitable if a malicious model was loaded. This issue was exploitable even with the weight_only=True" setting selected
https://github.com/pytorch/pytorch/security/advisories/GHSA-53q9-r3pm-6pq6
Microsoft Entra User Lockout
Multiple organizations reported widespread alerts and account lockouts this weekend from Microsoft Entra. The issue is caused by a new feature Microsoft enabled. This feature will lock accounts if Microsoft believes that the password for the account was compromised.
https://www.bleepingcomputer.com/news/microsoft/widespread-microsoft-entra-lockouts-tied-to-new-security-feature-rollout/
https://learn.microsoft.com/en-us/entra/identity/authentication/feature-availability
Erlang/OTP SSH Exploit
An exploit was published for the Erlang/OTP SSH vulnerability. The vulnerability is easy to exploit, and the exploit and a Metasploit module allow for easy remote code execution.
https://github.com/exa-offsec/ssh_erlangotp_rce/blob/main/ssh_erlangotp_rce.rb
Sonicwall Exploited
An older command injection vulnerability is now exploited on Sonicwall devices after initially gaining access by brute-forcing credentials.
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0022
Unpatched Vulnerability in Bubble.io
An unpatched vulnerability in the no-code platform bubble.io can be used to access any project hosted on the site.
https://github.com/demon-i386/pop_n_bubble
RedTail: Remnux and Malware Management
A description showing how to set up a malware analysis in the cloud with Remnux and Kasm. RedTail is a sample to illustrate how the environment can be used.
https://isc.sans.edu/diary/RedTail%2C%20Remnux%20and%20Malware%20Management%20%5BGuest%20Diary%5D/31868
Critical Erlang/OTP SSH Vulnerability
Researchers identified a critical vulnerability in the Erlang/OTP SSH library. Due to this vulnerability, SSH servers written in Erlang/OTP allow arbitrary remote code execution without prior authentication
https://www.openwall.com/lists/oss-security/2025/04/16/2
Brickstorm Analysis
An analysis of a recent instance of the Brickstorm backdoor. This backdoor used to be more known for infecting Linux systems, but now it also infects Windows.
https://www.nviso.eu/blog/nviso-analyzes-brickstorm-espionage-backdoor
https://blog.nviso.eu/wp-content/uploads/2025/04/NVISO-BRICKSTORM-Report.pdf
OpenAI GPT 4.1 Controversy
OpenAI released its latest model, GPT 4.1, without a safety report and guardrails to prevent malware creation.
https://opentools.ai/news/openai-stirs-controversy-with-gpt-41-release-lacking-safety-report
Apple Updates
Apple released updates for iOS, iPadOS, macOS, and VisionOS. The updates fix two vulnerabilities which had already been exploited against iOS.
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/31866
Oracle Updates
Oracle released it quarterly critical patch update. The update addresses 378 security vulnerabilities. Many of the critical updates are already known vulnerabilities in open-source software like Apache and Nginx ingress.
https://www.oracle.com/security-alerts/cpuapr2025.html
Oracle Breach Guidance
CISA released guidance for users affected by the recent Oracle cloud breach. The guidance focuses on the likely loss of passwords.
https://www.cisa.gov/news-events/alerts/2025/04/16/cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise
Google Chrome Update
A Google Chrome update released today fixes two security vulnerabilities. One of the vulnerabilities is rated as critical.
https://chromereleases.googleblog.com/2025/04/stable-channel-update-for-desktop_15.html
CVE Updates
CISA extended MITRE s funding to operate the CVE numbering scheme. However, a number of other organizations announced that they may start alternative vulnerability registers.
https://euvd.enisa.europa.eu/
https://gcve.eu/
https://www.thecvefoundation.org/
Online Services Again Abused to Exfiltrate Data
Attackers like to abuse free online services that can be used to exfiltrate data. From the originals , like pastebin,
to past favorites like anonfiles.com. The latest example is gofile.io. As a defender, it is important to track these services to detect exfiltration early
https://isc.sans.edu/diary/Online%20Services%20Again%20Abused%20to%20Exfiltrate%20Data/31862
OpenSSH 10.0 Released
OpenSSH 10.0 was released. This release adds quantum-safe ciphers and the separation of authentication services into a separate binary to reduce the authentication attack surface.
https://www.openssh.com/releasenotes.html#10.0p1
Apache Roller Vulnerability
Apache Roller addressed a vulnerability. Its CVSS score of 10.0 appears inflated, but it is still a vulnerability you probably want to address.
https://lists.apache.org/thread/4j906k16v21kdx8hk87gl7663sw7lg7f
CVE Funding Changes
Mitre s government contract to operate the CVE system may run out tomorrow. This could lead to a temporary disruption of services, but the system is backed by a diverse board of directors representing many large companies. It is possible that non-government funding sources may keep the system afloat for now.
https://www.cve.org/
xorsearch Update
Diedier updated his "xorsearch" tool. It is now a python script, not a compiled binary, and supports Yara signatures. With Yara support also comes support for regular expressions.
https://isc.sans.edu/diary/xorsearch.py%3A%20Searching%20With%20Regexes/31854
Shorter Lived Certificates
The CA/Brower Forum passed an update to reduce the maximum livetime of
certificates. The reduction will be implemented over the next four years. EFF also released an update to certbot introducing profiles that can be used to request shorter lived certificates.
https://www.eff.org/deeplinks/2025/04/certbot-40-long-live-short-lived-certs
https://groups.google.com/a/groups.cabforum.org/g/servercert-wg/c/bvWh5RN6tYI
New Malware Harvesting Data from USB drives and infecting them.
Kaspersky is reporting that they identified new malware that not only harvests data from USB drives, but also spread via USB drives by replacing existing documents with malicious files.
https://securelist.com/goffee-apt-new-attacks/116139/
Exploit Attempts for Recent Langflow AI Vulnerability (CVE-2025-3248)
After spotting individaul attempts to exploit the recent Langflow vulnerability late last weeks, we now see more systematic internet wide scans attempting to verify the vulnerability.
https://isc.sans.edu/forums/diary/Exploit+Attempts+for+Recent+Langflow+AI+Vulnerability+CVE20253248/31850/
Fortinet Analysis of Threat Actor Activity
Fortinet oberved recent vulnerablities in its devices being used to add a symlink to ease future compromise. The symlink is not removed by prior patches, and Fortinet released additional updates to detect and remove this attack artifact.
https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity
MSFT Inetpub
Microsoft clarrified that its April patches created the inetpub directory on purpose. Users should not remove it.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21204#exploitability
SANSFIRE
https://isc.sans.edu/j/sansfire
Network Infraxploit
Our undergraduate intern, Matthew Gorman, wrote up a walk through of
CVE-2018-0171, an older Cisco vulnerability, that is still actively being
exploited. For example, VOLT TYPHOON recently exploited this problem.
https://isc.sans.edu/diary/Network+Infraxploit+Guest+Diary/31844
Windows Update Issues / Windows 10 Update
Microsoft updated its "Release Health" notes with details regarding issues
users experiences with Windows Hello, Citrix, and Roblox. Microsoft also released an emergency update for Office 2016 which has stability problems after applying the most recent update.
https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3521
https://support.microsoft.com/en-us/topic/april-10-2025-update-for-office-2016-kb5002623-d60c1f31-bb7c-4426-b8f4-69186d7fc1e5
Dell Updates
Dell releases critical updates for it's Powerscale One FS product. In particular, it fixes a default password problem.
https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities
Langflow Vulnerablity (possible exploit scans sighted) CVE-2025-3248
Langflow addressed a critical vulnerability end of March. This writeup by Horizon3 demonstrates how the issue is possibly exploited. We have so far seen one "hit" in our honeypot logs for the vulnerable API endpoint URL.
https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/
Getting Past PyArmor
PyArmor is a python obfuscation tool used for malicious and non-malicious software. Xavier is taking a look at a sample to show what can be learned from these obfuscated samples with not too much work.
https://isc.sans.edu/diary/Obfuscated%20Malicious%20Python%20Scripts%20with%20PyArmor/31840
CenterStack RCE CVE-2025-30406
Gladinet s CenterStack secure file-sharing software suffers from an inadequately protected machine key vulnerability that can be used to modify ViewState data. This vulnerability may lead to remote code execution, which is already exploited.
https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf
Google Patches two zero-day vulnerabilities CVE-2024-53150 CVE-2024-53197
Google released its monthly patches for Android. Two of the patched vulnerabilities are already exploited. One of them was used by Serbian law enforcement.
https://www.malwarebytes.com/blog/news/2025/04/google-fixes-two-actively-exploited-zero-day-vulnerabilities-in-android
Broadcom VMWare Tenzu Updates
Broadcom released updates for VMWare Tenzu. Many vulnerabilities affect the backup component and allow for arbitrary command execution.
https://support.broadcom.com/web/ecx/security-advisory?
Windows 11 April Update ads inetpub directory
The April Windows 11 update appears to create a new /inetpub directory. It is unclear why, and removing it appears to have no bad effects.
https://www.bleepingcomputer.com/news/microsoft/windows-11-april-update-unexpectedly-creates-new-inetpub-folder/
WhatsApp File Type Confusion/Spoofing
WhatsApp patched a file type confusion vulnerability. A victim may be tricked into downloading n
https://www.whatsapp.com/security/advisories/2025/
SANS Critical AI Security Guidelines
https://www.sans.org/mlp/critical-ai-security-guidelines
Microsoft Patch Tuesday
Microsoft patched over 120 vulnerabilities this month. 11 of these were rated critical, and one vulnerability is already being exploited.
https://isc.sans.edu/diary/Microsoft%20April%202025%20Patch%20Tuesday/31838
Adobe Updates
Adobe released patches for 12 different products. In particular important are patches for Coldfusion addressing several remote code execution vulnerabilities. Adobe Commercse got patches as well, but none of the vulnerabilities are rated critical.
https://helpx.adobe.com/security/security-bulletin.html
OpenSSL 3.5 Released
OpenSSL 3.5 was released with support to post quantum ciphers. This is a long term support release.
https://groups.google.com/a/openssl.org/g/openssl-project/c/9ZYdIaExmIA
Fortiswitch Update
Fortinet released an update for Fortiswitch addressing a vulnerability that may be used to reset a password without verification.
https://fortiguard.fortinet.com/psirt/FG-IR-24-435
XORsearch: Searching With Regexes
Didier explains a workaround to use his tool XORsearch to search for regular expressions instead of simple strings.
https://isc.sans.edu/diary/XORsearch%3A%20Searching%20With%20Regexes/31834
MCP Security Notification: Tool Poisoning Attacks
Invariant labs summarized a critical weakness in the Model Context Protocol (MCP) that allows for "Tool Poisoning Attacks." Many major providers such as Anthropic and OpenAI, workflow automation systems like Zapier, and MCP clients like Cursor are susceptible to this attack
https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks
Making :visited more private
Google Chrome changed how links are marked as visited . This new partitioning scheme was introduced to improve privacy. Instead of marking a link as visited on any page where it is displayed, it is only marked as visited if the user clicks on the link while visiting the particular site where the link is displayed.
https://developer.chrome.com/blog/visited-links
New SSH Username Report
A new ssh/telnet username reports makes it easier to identify new usernames attackers are using against our telnet and ssh honeypots
https://isc.sans.edu/diary/New%20SSH%20Username%20Report/31830
Quickshell Sharing is Caring: About an RCE Attack Chain on Quick Share
The Google Quick Share protocol is susceptible to several vulnerabilities that have not yet been fully patched, allowing for some file overwrite issues that could lead to the accidental execution of malicious code.
https://www.blackhat.com/asia-25/briefings/schedule/index.html#quickshell-sharing-is-caring-about-an-rce-attack-chain-on-quick-share-43874
Apache Traffic Director Request Smuggling Vulnerability
https://www.openwall.com/lists/oss-security/2025/04/02/4
Exploring Statistical Measures to Predict URLs as Legitimate or Intrusive
Using frequency analysis, and training the model with honeypot data as well as log data from legitimate websites allows for a fairly simple and reliable triage of web server logs to identify possible malicious activity.
https://isc.sans.edu/diary/Exploring%20Statistical%20Measures%20to%20Predict%20URLs%20as%20Legitimate%20or%20Intrusive%20%5BGuest%20Diary%5D/31822
Critical Unexploitable Ivanti Vulnerability Exploited CVE-2025-22457
In February, Ivanti patched CVE-2025-22457. At the time, the vulnerability was not considered to be exploitable. Mandiant now published a blog disclosing that the vulnerability was exploited as soon as mid-march
https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability/
WinRAR MotW Vulnerability CVE-2025-31334
WinRAR patched a vulnerability that would not apply the Mark of the Web correctly if a compressed file included symlinks. This may make it easier to trick a victim into executing code downloaded from a website.
https://nvd.nist.gov/vuln/detail/CVE-2025-31334
Microsoft Warns of Tax-Related Scam
With the US personal income tax filing deadline only about a week out, Microsoft warns of commonly deployed scams that they are observing related to income tax filings
https://www.microsoft.com/en-us/security/blog/2025/04/03/threat-actors-leverage-tax-season-to-deploy-tax-themed-phishing-campaigns/
Oracle Breach Update
https://www.bloomberg.com/news/articles/2025-04-02/oracle-tells-clients-of-second-recent-hack-log-in-data-stolen
Surge in Scans for Juniper t128 Default User
Lasst week, we dedtect a significant surge in ssh scans for the username t128 . This user is used by Juniper s Session Smart Routing, a product they acquired from 128 Technologies which is the reason for the somewhat unusual username.
https://isc.sans.edu/diary/Surge%20in%20Scans%20for%20Juniper%20%22t128%22%20Default%20User/31824
Vulnerable Verizon API Allowed for Access to Call Logs
An API Verizon offered to users of its call filtering application suffered from an authentication bypass vulnerability allowing users to access any Verizon user s call history. While using a JWT to authenticate the user, the phone number used to retrieve the call history logs was passed in a not-authenticated header.
https://evanconnelly.github.io/post/hacking-call-records/
Google Offering End-to-End Encryption to G-Mail Business Users
Google will add an end-to-end encryption feature to commercial GMail users. However, for non GMail users to read the emails they first must click on a link and log in to Google.
https://workspace.google.com/blog/identity-and-security/gmail-easy-end-to-end-encryption-all-businesses
Apple Patches Everything
Apple released updates for all of its operating systems. Most were released on Monday with WatchOS patches released today on Tuesday. Two already exploited vulnerabilities, which were already patched in the latest iOS and macOS versions, are now patched for older operating systems as well. A total of 145 vulnerabilities were patched.
https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20March%2031st%202025%20Edition/31816
VMWare Workstation and Fusion update check broken
VMWare s automatic update check in its Workstation and Fusion products is currently broken due to a redirect added as part of the Broadcom transition
https://community.broadcom.com/vmware-cloud-foundation/question/certificate-error-is-occured-during-connecting-update-server
NIM Postgres Vulnerability
NIM Developers using prepared statements to send SQL queries to Postgres may expose themselves to a SQL injection vulnerability. NIM s Postgres library does not appear to use actual prepared statements; instead, it assembles the code and the user data as a string and passes them on to the database. This may lead to a SQL injection vulnerability
https://blog.nns.ee/2025/03/28/nim-postgres-vulnerability/
Apache Camel Exploit Attempt by Vulnerability Scans
A recently patched vulnerability in Apache Camel has been integrated into some vulnerability scanners, like for example OpenVAS. We do see some exploit attempts in our honeypots, but they appear to be part of internal vulnerablity scans
https://isc.sans.edu/diary/Apache%20Camel%20Exploit%20Attempt%20by%20Vulnerability%20Scan%20%28CVE-2025-27636%2C%20CVE-2025-29891%29/31814
New Security Requirements for Certificate Authorities
Starting in July, certificate authorities need to verify domain ownership data from multiple viewpoints around the internet. They will also have to use linters to verify certificate requests.
https://security.googleblog.com/2025/03/new-security-requirements-adopted-by.html
Possible Oracle Breach
Oracle still denies being the victim of a data berach as leaked data may show different.
https://doublepulsar.com/oracle-attempt-to-hide-serious-cybersecurity-incident-from-customers-in-oracle-saas-service-9231c8daff4a
https://www.theregister.com/2025/03/30/infosec_news_in_brief/
https://www.darkreading.com/cyberattacks-data-breaches/oracle-still-denies-breach-researchers-persist
A Tale of Two Phishing Sties
Two phishing sites may use very different backends, even if the site itself appears to be visually very similar. Phishing kits are often copied and modified, leading to sites using similar visual tricks on the user facing site, but very different backends to host the sites and reporting data to the miscreant.
https://isc.sans.edu/diary/A%20Tale%20of%20Two%20Phishing%20Sites/31810
A Phihsing Tale of DOH and DNS MX Abuse
Infoblox discovered a new variant of the Meerkat phishing kit that uses DoH in Javascript to discover MX records, and generate better customized phishing pages.
https://blogs.infoblox.com/threat-intelligence/a-phishing-tale-of-doh-and-dns-mx-abuse/
Using OpenID Connect for SSH
Cloudflare opensourced it's OPKSSH too. It integrates SSO systems supporting OpenID connect with SSH.
https://github.com/openpubkey/opkssh/
Sitecore "thumbnailsaccesstoken" Deserialization Scans (and some new reports) CVE-2025-27218
Our honeypots detected a deserialization attack against the CMS Sitecore using a thumnailaccesstoken header. The underlying vulnerability was patched in January, and security firm Searchlight Cyber revealed details about this vulnerability a couple of weeks ago.
https://isc.sans.edu/diary/Sitecore%20%22thumbnailsaccesstoken%22%20Deserialization%20Scans%20%28and%20some%20new%20reports%29%20CVE-2025-27218/31806
Blasting Past Webp
Google s Project Zero revealed details how the NSO BLASTPASS exploit took advantage of a Webp image parsing vulnerability in iOS. This zero-click attack was employed in targeted attack back in 2023 and Apple patched the underlying vulnerability in September 2023. But this is the first byte by byte description showing how the attack worked.
https://googleprojectzero.blogspot.com/2025/03/blasting-past-webp.html
Splunk Vulnerabilities
Splunk patched about a dozen of vulnerabilities. None of them are rated critical, but a vulnerability rated High allows authenticated users to execute arbitrary code.
https://advisory.splunk.com/
Firefox 0-day Patched
Mozilla patched a sandbox escape vulnerability that is already being exploited.
https://www.mozilla.org/en-US/security/advisories/mfsa2025-19/
Leveraging CNNs and Entropy-Based Feature Selection to Identify Potential Malware Artifacts of Interest
This diary explores a novel methodology for classifying malware by integrating entropy-driven feature selection with a specialized Convolutional Neural Network (CNN). Motivated by the increasing obfuscation tactics used by modern malware authors, we will focus on capturing high-entropy segments within files, regions most likely to harbor malicious functionality, and feeding these distinct byte patterns into our model.
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Leveraging%20CNNs%20and%20Entropy-Based%20Feature%20Selection%20to%20Identify%20Potential%20Malware%20Artifacts%20of%20Interest/31790
Malware found on npm infecting local package with reverse shell
Researchers at Reversinglabs found two malicious NPM packages, ethers-provider2, and ethers-providerz that patch the well known (and not malicious) ethers package to add a reverse shell and downloader.
https://www.reversinglabs.com/blog/malicious-npm-patch-delivers-reverse-shell
Google Patched Google Chrome 0-day
Google patched a vulnerability in Chrome that was already exploited in attacks against media and educational organizations in Russia
https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop_25.html
XWiki Search Vulnerablity Exploit Attempts (CVE-2024-3721)
Our honeypot detected an increase in exploit attempts for an XWiki command injection vulnerablity. The vulnerability was patched last April, but appears to be exploited more these last couple days. The vulnerability affects the search feature and allows the attacker to inject Groovy code templates.
https://isc.sans.edu/diary/X-Wiki%20Search%20Vulnerability%20exploit%20attempts%20%28CVE-2024-3721%29/31800
Correction: FBI Image Converter Warning
The FBI's Denver office warned of online file converters, not downloadable conversion tools
https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam
VMWare Vulnerability
Broadcom released a fix for a VMWare Tools vulnerability. The vulnerability allows users of a Windows virtual machine to escalate privileges within the machine.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25518
Draytek Reboots
Over the weekend, users started reporting Draytek routers rebooting and getting stuck in a reboot loop. Draytek now published advise as to how to fix the problem.
https://faq.draytek.com.au/docs/draytek-routers-rebooting-how-to-solve-this-issue/
Microsoft Managemnt Console Exploit CVE-2025-26633
TrendMicro released details showing how the MMC vulnerability Microsoft patched as part of its patch tuesday this month was exploited.
https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html
Privacy Aware Bots
A botnet is using privacy as well as CSRF prevention headers to better blend in with normal browsers. However, in the process they may make it actually easier to spot them.
https://isc.sans.edu/diary/Privacy%20Aware%20Bots/31796
Critical Ingress Nightmare Vulnerability
ingress-nginx fixed four new vulnerabilities, one of which may lead to a Kubernetes cluster compromise. Note that at the time I am making this live, not all of the URLs below are available yet, but I hope they will be available shortly after publishing this podcast
https://www.darkreading.com/application-security/critical-ingressnightmare-vulns-kubernetes-environments
https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities
https://kubernetes.io/blog/
FBI Warns of File Converter Scams
File converters may include malicious ad ons. Be careful where you get your software from.
https://www.fbi.gov/contact-us/field-offices/denver/news/fbi-denver-warns-of-online-file-converter-scam
VSCode Extension Includes Ransomware
https://x.com/ReversingLabs/status/1902355043065500145
Critical Next.js Vulnerability CVE-2025-29927
A critical vulnerability in how the x-middleware-subrequest header is verified may lead to bypassing authorization in Next.js applications.
https://zhero-web-sec.github.io/research-and-things/nextjs-and-the-corrupt-middleware
https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw
https://www.runzero.com/blog/next-js/
Microsoft Trust Signing Service Abused
Attackers abut the Microsoft Trust Signing Service, a service meant to help developers create signed software, to obtain short lived signatures for malware.
https://www.bleepingcomputer.com/news/security/microsoft-trust-signing-service-abused-to-code-sign-malware/
Some New Data Feeds and Little Incident
We started offering additional data feeds, and an SEO spamer attempted to make us change a link from an old podcast episode.
https://isc.sans.edu/diary/Some%20new%20Data%20Feeds%2C%20and%20a%20little%20%22incident%22./31786
Veeam Deserialization Vulnerability
Veeam released details regarding the latest vulnerablity in Veeam, pointing out the insufficient patch applied to a prior deserialization vulnerability.
https://labs.watchtowr.com/by-executive-order-we-are-banning-blacklists-domain-level-rce-in-veeam-backup-replication-cve-2025-23120/
IBM AIX Vulnerablity
The AIX NIM service is vulnerable to an unauthenticated remote code execution vulnerability
https://www.ibm.com/support/pages/node/7186621
thanks Chris Mosby for Spotify comment
Exploit Attempts for Cisco Smart Licensing Utility CVE-2024-20439 CVE-2024-20440
Attackers added last September's Cisco Smart Licensing Utility vulnerability to their toolset. These attacks orginate most likely from botnets and the same attackers are scanning for a wide range of additional vulnerabilities. The vulnerability is a static credential issue and trivial to exploit after the credentials were published last fall.
https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Cisco%20Smart%20Licensing%20Utility%20CVE-2024-20439%20and%20CVE-2024-20440/31782
Legacy Driver Exploitation Through Bypassing Certificate Verification
Ahnlab documented a new type of "bring your own vulnerable driver" vulnerability. In this case, an old driver used by an anit-malware and anti-rootkit system can be used to shut down arbitrary processeses, including security related processeses.
https://asec.ahnlab.com/en/86881/
Synology Vulnerability Updates
Synology updates some security advisories it release last year adding addition details and vulnerable systems.
https://www.synology.com/en-global/security/advisory/Synology_SA_24_20
https://www.synology.com/en-global/security/advisory/Synology_SA_24_24
Python Bot Delivered Through DLL Side-Loading
A "normal", but vulnerable to DLL side-loading PDF reader may be used to launch additional exploit code
https://isc.sans.edu/diary/Python%20Bot%20Delivered%20Through%20DLL%20Side-Loading/31778
Tomcat RCE Correction
To exploit the Tomcat RCE I mentioned yesterday, two non-default configuration options must be selected by the victim.
https://x.com/dkx02668274/status/1901893656316969308
SAML Roulette: The Hacker Always Wins
This Portswigger blog explains in detail how to exploit the ruby-saml vulnerablity against GitLab.
https://portswigger.net/research/saml-roulette-the-hacker-always-wins
Windows Shortcut Zero Day Exploit
Attackers are currently taking advantage of an unpatched vulnerability in how Windows displays Shortcut (.lnk file) details. Trendmicro explains how the attack works and provides PoC code. Microsoft is not planning to fix this issue
https://www.trendmicro.com/en_us/research/25/c/windows-shortcut-zero-day-exploit.html
Static Analysis of GUID Encoded Shellcode
Didier explains how to decode shell code embeded as GUIDs in malware, and how to feed the result to his tool 1768.py which will extract Cobal Strike configuration information from the code.
https://isc.sans.edu/diary/Static%20Analysis%20of%20GUID%20Encoded%20Shellcode/31774
SAMLStorm: Critical Authentication Bypass in xml-crypto and Node.js libraries
xml-crypto, a library use in Node.js applications to decode XML and support SAML, has found to parse comments incorrectly leading to several SAML vulnerabilities.
https://workos.com/blog/samlstorm
One PUT Request to Own Tomcat: CVE-2025-24813 RCE is in the Wild
A just made public deserialization vulnerablity in Tomcat is already being exploited. Contributing to the rapid exploit release is the similarity of this vulnerability to other Java deserializtion vulnerabilities.
https://lab.wallarm.com/one-put-request-to-own-tomcat-cve-2025-24813-rce-is-in-the-wild/ CVE-2025-24813
CSS Abuse for Evasion and Tracking
Attackers are using cascading stylesheets to evade detection and enable more stealthy tracking of users
https://blog.talosintelligence.com/css-abuse-for-evasion-and-tracking/
Mirai Bot Now Incorporating Malformed DrayTek Vigor Router Exploits
One of the many versions of the Mirai botnet added some new exploit strings attempting to take advantage of an old DrayTek Vigor Router vulnerability, but they got the URL wrong.
https://isc.sans.edu/diary/Mirai%20Bot%20now%20incroporating%20%28malformed%3F%29%20DrayTek%20Vigor%20Router%20Exploits/31770
Compromised GitHub Action
The popular GitHub action tj-actions/changed-files was compromised and leaks credentials via the action logs
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised
ruby-saml authentication bypass
A confusion in how to parse SAML messages between two XML parsers used by Ruby leads to an authentication bypass in saml-ruby.
https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/
GitHub Fake Security Alerts
Fake GitHub security alerts are used to trick package maintainers into adding OAUTH privileges to malicious apps.
https://www.bleepingcomputer.com/news/security/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/
File Hashes Analysis with Power BI
Guy explains in this diary how to analyze Cowrie honeypot file hashes using Microsoft's BI tool and what you may be able to discover using this tool.
https://isc.sans.edu/diary/File%20Hashes%20Analysis%20with%20Power%20BI%20from%20Data%20Stored%20in%20DShield%20SIEM/31764
Apache Camel Vulnerability
Apache released two patches for Camel in close succession. Initially, the vulnerability was only addressed for headers, but as Akamai discovered, it can also be exploited via query parameters. This vulnerability is trivial to exploit and leads to arbitrary code execution.
https://www.akamai.com/blog/security-research/march-apache-camel-vulnerability-detections-and-mitigations
Juniper Patches Junos Vulnerability
Juniper patches an already exploited vulnerability in JunOS. However, to exploit the vulnerability, and attacker already needs privileged access. By exploiting the vulnerability, an attacker may completely compromised the device.
https://supportportal.juniper.net/s/article/2025-03-Out-of-Cycle-Security-Bulletin-Junos-OS-A-local-attacker-with-shell-access-can-execute-arbitrary-code-CVE-2025-21590?language=en_US
AMI Security Advisory
AMI patched three vulnerabilities. One of the, an authentication bypass in Redfish, allows for a complete system compromise without authentication and is rated with a CVSS score of 10.0.
https://go.ami.com/hubfs/Security%20Advisories/2025/AMI-SA-2025003.pdf
Log4J Scans for VMWare Hyhbrid Cloud Extensions
An attacker is scanning various login pages, including the authentication feature in the VMWare HCX REST API for Log4j vulnerabilities. The attack submits the exploit string as username, hoping to trigger the vulnerability as Log4j logs the username
https://isc.sans.edu/diary/Scans%20for%20VMWare%20Hybrid%20Cloud%20Extension%20%28HCX%29%20API%20(Log4j%20-%20not%20brute%20forcing)/31762
Patch Tuesday Fallout
Yesterday's Apple patch may re-activate Apple Intelligence for users who earlier disabled it. Microsoft is offering support for users whos USB printers started printing giberish after a January patch was applies.
https://www.macrumors.com/2025/03/11/ios-18-3-2-apple-intelligence-auto-on/
https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22h2#usb-printers-might-print-random-text-with-the-january-2025-preview-update
Adobe Updates
Adobe updated seven different products, including Adobe Acrobat. The Acrobat vulnerability may lead to remote code execution and Adobe considers the vulnerablities critical.
https://helpx.adobe.com/security/security-bulletin.html
Medusa Ransomware
CISA and partner agencies released details about the Medusa Ransomware. The document includes many details useful to defenders.
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
Zoom Update
Zoom released a critical update fixing a number of remote code execution vulnerabilities.
https://www.zoom.com/en/trust/security-bulletin/
FreeType Library Vulnerability
https://www.facebook.com/security/advisories/cve-2025-27363
Microsoft Patch Tuesday
Microsoft Patched six already exploited vulnerabilities today. In addition, the patches included a critical patch for Microsoft's DNS server and about 50 additional patches.
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20March%202025/31756
Apple Updates iOS/macOS
Apple released an update to address a single, already exploited, vulnerability in WebKit. This vulnerability affects iOS, macOS and VisionOS.
https://support.apple.com/en-us/100100
Expressif Response to ESP32 Debug Commands
Expressif released a statement commenting on the recent release of a paper alledging "Backdoors" in ESP32 chipsets. According to Expressif, these commands are debug commands and not reachable directly via Bluetooth.
https://www.espressif.com/en/news/Response_ESP32_Bluetooth
Shellcode Encoded in UUIDs
Attackers are using UUIDs to encode Shellcode. The 128 Bit (or 16 Bytes) encoded in each UUID are converted to shell code to implement a cobalt strike beacon
https://isc.sans.edu/diary/Shellcode%20Encoded%20in%20UUIDs/31752
Moxa CVE-2024-12297 Expanded to PT Switches
Moxa in January first releast an update to address a fronted authorizaation logic disclosure vulnerability. It now updated the advisory and included the PT series switches as vulenrable.
https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241408-cve-2024-12297-frontend-authorization-logic-disclosure-vulnerability-identified-in-pt-switches
Opentext Insufficently Protected Credentials
https://portal.microfocus.com/s/article/KM000037455?language=en_US
Livewire Volt API vulnerability
https://github.com/livewire/volt/security/advisories/GHSA-v69f-5jxm-hwvv
Commonly Probed Webshell URLs
Many attackers deploy web shells to gain a foothold on vulnerable web servers. These webshells can also be taken over by parasitic exploits.
https://isc.sans.edu/diary/Commonly%20Probed%20Webshell%20URLs/31748
Undocumented ESP32 Commands
A recent conference presentation by Tarlogic revealed several "backdoors" or undocumented features in the commonly used ESP32 Chipsets. Tarlogic also released a toolkit to make it easier to audit chipsets and find these hiddent commands.
https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/
Camera Off: Akira deploys ransomware via Webcam
The Akira ransomware group was recently observed infecting a network with Ransomware by taking advantage of a webcam.
https://www.s-rminform.com/latest-thinking/camera-off-akira-deploys-ransomware-via-webcam
Latest Google Chrome Update Encourages UBlock Origin Removal
The latest update to Google Chrome not only disabled the UBlock Origin ad blocker, but also guides users to uninstall the extension instead of re-enabling it.
https://chromereleases.googleblog.com/2025/03/stable-channel-update-for-desktop.html
https://www.reddit.com/r/youtube/comments/1j2ec76/ublock_origin_is_gone/
Critical Kibana Update
Elastic published a critical Kibana update patching a prototype polution vulnerability that would allow arbitrary code execution for users with the "Viewer" role.
https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441
Certified PrePw0n3d Android TV Sticks
Wired is reporting of over a million Android TV sticks that were found to be pre-infected with adware
https://www.wired.com/story/android-tv-streaming-boxes-china-backdoor/
SANS.edu Research Paper
Advanced Persistent Threats (APTs) are among the most challenging to detect in enterprise environments, often mimicking authorized privileged access prior to their actions on objectives.
https://www.sans.edu/cyber-research/identifying-advanced-persistent-threat-activity-through-threat-informed-detection-engineering-enhancing-alert-visibility-enterprises/
DShield Traffic Analysis using ELK
The "DShield SIEM" includes an ELK dashboard as part of the Honeypot. Learn how to find traffic of interest with this tool.
https://isc.sans.edu/diary/DShield%20Traffic%20Analysis%20using%20ELK/31742
Zen and the Art of Microcode Hacking
Google released details, including a proof of concept exploit, showing how to take advantage of the recently patched AMD microcode vulnerability
https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking CVE-2024-56161
VIM Vulnerability
An attacker may execute arbitrary code by tricking a user to open a crafted tar file in VIM
https://github.com/vim/vim/security/advisories/GHSA-wfmf-8626-q3r3
Snil Mail Fake Ransom Note
A copy cat group is impersonating ransomware actors. The group sends snail mail to company executives claiming to have stolen company data and threatening to leak it unless a payment is made.
https://www.guidepointsecurity.com/blog/snail-mail-fail-fake-ransom-note-campaign-preys-on-fear/
Romanian Distillery Scanning for SMTP Credentials
A particular attacker expanded the scope of their leaked credential file scans. In addition to the usual ".env" style files, it is not looking for specific SMTP related credential files.
https://isc.sans.edu/diary/Romanian%20Distillery%20Scanning%20for%20SMTP%20Credentials/31736
Tool Updates: mac-robber.py
This update of mac-robber.py fixes issues with symlinks.
https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py/31738
CVE-2025-1723 Account takeover vulnerability in ADSelfService Plus
CVE-2025-1723 describes a vulnerability caused by session mishandling in ADSelfService Plus that could allow unauthorized access to user enrollment data when MFA was not enabled for ADSelfService Plus login.
https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-1723.html
Android March Update
Google released an update for Android addressing two already exploited vulnerabilities and several critical issues.
https://source.android.com/docs/security/bulletin/2025-03-01
PayPal's no-code-checkout Abuse
Attackers are using PayPal's no-code-checkout feature is being abused by scammers to host PayPal tech support scam pages right within the PayPal.com domain.
https://www.malwarebytes.com/blog/scams/2025/02/paypals-no-code-checkout-abused-by-scammers
Broadcom Fixes three VMWare VCenter Vulnerabilities
https://github.com/vmware/vcf-security-and-compliance-guidelines/tree/main/security-advisories/vmsa-2025-0004
Mark of the Web: Some Technical Details
Windows implements the "Mark of the Web" (MotW) as an alternate data stream that contains not just the "zoneid" of where the file came from, but may include other data like the exact URL and referrer.
https://isc.sans.edu/diary/Mark%20of%20the%20Web%3A%20Some%20Technical%20Details/31732
Havoc Sharepoint with Microsoft Graph API
A recent phishing attack observed by Fortinet uses a simple HTML email to trick a user into copy pasting powershell into their system to execute additional code. Most of the malware interaction uses a Sharepoint site via Microsoft's Graph API futher hiding the malicious traffic
https://www.fortinet.com/blog/threat-research/havoc-sharepoint-with-microsoft-graph-api-turns-into-fud-c2
Paragon Partition Manager Exploit
A vulnerable Paragon Partition Manager has been user recently to escalate privileges for ransomware deployment. Even if you to not have PAragon installed: An attacker may just "bring the vulnerable driver" to your system.
https://kb.cert.org/vuls/id/726882
Common Crawl includes Common Leaks
The "Common Crawl" dataset, a large dataset created by spidering website, contains as expected many API keys and other secrets. This data is often used to train large language models
https://trufflesecurity.com/blog/research-finds-12-000-live-api-keys-and-passwords-in-deepseek-s-training-data
Github Repositories Exposed by Copilot
As it is well known, Github's Copilot is using data from public GitHub repositories to train it's model. However, it appears that repositories who were briefly left open and later made private have been included as well, allowing Copilot users to retrieve files from these repositories.
https://www.lasso.security/blog/lasso-major-vulnerability-in-microsoft-copilot
MITRE Caldera Framework Allows Unauthenticated Code Execution
The MITRE Caldera adversary emulation framework allows for unauthenticted code execution by allowing attackers to specify compiler options
https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e
modsecurity Rule Bypass
Attackers may bypass the modsecurity web application firewall by prepending encoded characters with 0.
https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-42w7-rmv5-4x2j
Njrat Compaign Using Microsoft dev Tunnels:
A recent version of the Njrat remote admin tool is taking advantage of Microsoft's developer tunnels (devtunnels.ms) as a command and control channel.
https://isc.sans.edu/diary/Njrat%20Campaign%20Using%20Microsoft%20Dev%20Tunnels/31724
NrootTag Apple FindMy Abuse
Malware could use a weakness in the keys used for Apple FindMy to abuse it to track victims. Updates were released with iOS 18.2, but to solve the issue the vast majority of Apple users must update.
https://nroottag.github.io/
360XSS: Mass Website Exploitation via Virtual Tour Framework
The Krpano VR library which is often used to implement 3D virtual tours on real estate websites, is currently being abused to inject spam messages. The XSS vulnerabilty could allow attackers to inject even more malicious JavaScript.
https://olegzay.com/360xss/
SANS.edu Research: Proof is in the Pudding: EDR Configuration Versus Ransomware. Benjamin Powell
https://www.sans.edu/cyber-research/proof-pudding-edr-configuration-versus-ransomware/
Attacker of of Ephemeral Ports
Attackers often use ephermeral ports to reach out to download additional resources or exfiltrate data. This can be used, with care, to detect possible compromises.
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Malware%20Source%20Servers%3A%20The%20Threat%20of%20Attackers%20Using%20Ephemeral%20Ports%20as%20Service%20Ports%20to%20Upload%20Data/31710
Compromised Visal Studio Code Extension downloaded by Millions
Amit Assaraf identified a likely compromised Visual Studio Code theme that was installed by millions of potential victims. Amit did not disclose the exact malicious behaviour, but is asking for victims to contact them for details.
https://medium.com/@amitassaraf/a-wolf-in-dark-mode-the-malicious-vs-code-theme-that-fooled-millions-85ed92b4bd26
ByBit Theft Due to Compromised Developer Workstation
ByBit and Safe{Wallet} disclosed that the record breaking ethereum theft was due to a compromised Safe{Wallet} developer workstation. A replaced JavaScript file targeted ByBit and altered a transaction signed by ByBit.
https://x.com/benbybit/status/1894768736084885929
https://x.com/safe/status/1894768522720350673
PoC for NAKIVO Backup Replication Vulnerability
This vulnerability allows the compromise of NAKIVO backup systems. The vulnerability was patched silently in November, and never disclosed by NAKIVO. Instead, WatchTowr now disloses details including a proof of concept exploit.
https://labs.watchtowr.com/the-best-security-is-when-we-all-agree-to-keep-everything-secret-except-the-secrets-nakivo-backup-replication-cve-2024-48248/
OpenH264 Vulnerability
https://github.com/cisco/openh264/security/advisories/GHSA-m99q-5j7x-7m9x
rsync vulnerability exploited
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Massive Botnet Targets M365 with Password Spraying
A large botnet is targeting service accounts in M365 with credentials stolen by infostealer malware.
https://securityscorecard.com/wp-content/uploads/2025/02/MassiveBotnet-Report_022125_03.pdf
Mixing up Public and Private Keys in OpenID
The complex OpenID specificiation and the flexibility it supports enables careless administrators to publich private keys instead or in addition to public keys
https://blog.hboeck.de/archives/909-Mixing-up-Public-and-Private-Keys-in-OpenID-Connect-deployments.html
Healthcare Malware Hunt Part 1:
Medial images are often encoded in the DICOM format, an image format unique to medical imaging. Patients looking for viewers for DICOM images are tricked into downloading malware.
https://www.forescout.com/blog/healthcare-malware-hunt-part-1-silver-fox-apt-targets-philips-dicom-viewers/
Unfurl Update Released
Unfurl released an Update fixing a few bugs and adding support to decode BlueSky URLs.
https://isc.sans.edu/diary/Unfurl%20v2025.02%20released/31716
Google Confirms GMail To Ditch SMS Code Authentication
Google no longer considers SMS authentication save enough for GMail. Instead, it pushes users to use Passkeys, or QR code based app authentication
https://www.forbes.com/sites/daveywinder/2025/02/23/google-confirms-gmail-to-ditch-sms-code-authentication/
Beware of Paypal New Address Feature Abuse
Attackers are using "address change" e-mails to send links to phishing sites or trick users into calling fake tech support phone numbers. Attackers are just adding the malicious content as part of the address. The e-mail themselves are legitimate PayPal emails and will pass various spam and phishing filters.
https://www.bleepingcomputer.com/news/security/beware-paypal-new-address-feature-abused-to-send-phishing-emails/
Exim SQL Injection Vulnerability
Exim, with sqlite support and ETRN enabled, is vulnerable to a simple SQL injection exploit. A PoC has been released
https://www.exim.org/static/doc/security/CVE-2025-26794.txt
https://github.com/OscarBataille/CVE-2025-26794?
XMLlib patches
https://gitlab.gnome.org/GNOME/libxml2/-/issues/847
https://gitlab.gnome.org/GNOME/libxml2/-/issues/828
0-Day in Parallels
https://jhftss.github.io/Parallels-0-day/
Tool Update: Sigs.py
Jim updates sigs.py. The tool verifies hashes for files and automatically recognizes what hash is used.
https://isc.sans.edu/diary/Tool%20update%3A%20sigs.py%20-%20added%20check%20mode/31706
Google Announcing Quantum Safe Digital Signatures in Cloud KMS
Google announced the option to use quantum safe digital signatures for its
cloud key management system.
https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-digital-signatures-in-cloud-kms
Windows 11 Patch issues
The February Patch Tuesday appears to have caused issues with a number of Windows 11 systems. In particular the usability of the file manager appears to be affected.
https://www.windowslatest.com/2025/02/16/windows-11-kb5051987-breaks-file-explorer-install-fails-on-windows-11-24h2/
LTE/5G Vulnerabilities
Researchers at the university of Florida have identified a large number of vulnerabilities in 5G and LTE networks.
https://nathanielbennett.com/publications/ransacked.pdf
Using ES|QL In Kibana to Query DShield Honeypot Logs
Using the "Elastic Search Piped Query Language" to query DShield honeypot logs
https://isc.sans.edu/diary/Using%20ES%7CQL%20in%20Kibana%20to%20Queries%20DShield%20Honeypot%20Logs/31704
Mongoose Flaws Put MongoDB at risk
The Object Direct Mapping library Mongoose suffers from an injection vulnerability leading to the potenitial of remote code exeuction in MongoDB
https://www.theregister.com/2025/02/20/mongoose_flaws_mongodb/
U-Boot Vulnerabilities
The open source boot loader U-Boot does suffer from a number of issues allowing the bypass of its integrity checks. This may lead to the execution of malicious code on boot.
https://www.openwall.com/lists/oss-security/2025/02/17/2
Unifi Protect Camera Update
https://community.ui.com/releases/Security-Advisory-Bulletin-046-046/9649ea8f-93db-4713-a875-c3fd7614943f
XWorm Cocktail: A Mix of PE data with PowerShell Code
Quick analysis of an interesting XWrom sample with powershell code embedded inside an executable
https://isc.sans.edu/diary/XWorm+Cocktail+A+Mix+of+PE+data+with+PowerShell+Code/31700
Microsoft's Majorana 1 Chip Carves New Path for Quantum Computing
Microsoft announced a breack through in Quantum computing. Its new prototype Majorana 1 chip takes advantage of exotic majorana particles to implement a scalable low error rate solution to building quantum computers
https://news.microsoft.com/source/features/ai/microsofts-majorana-1-chip-carves-new-path-for-quantum-computing/
Russia Targeting Signal Messenger
Signal is well regarded as a secure end to end encrypted messaging platform. However, a user may be tricked into providing access to their account by scanning a QR code masquerading as a group channel invitation.
https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/
ModelScan: Protection Against Model Serialization Attacks
ModelScan is a tool to inspect AI models for deserialization attacks. The tool will detect suspect commands and warn the user.
https://isc.sans.edu/diary/ModelScan%20-%20Protection%20Against%20Model%20Serialization%20Attacks/31692
OpenSSH MitM and DoS Vulnerabilities
OpenSSH Patched two vulnerabilities discovered by Qualys. One may be used for MitM attack in specfic configurations of OpenSSH.
https://www.qualys.com/2025/02/18/openssh-mitm-dos.txt
Juniper Authentication Bypass
Juniper fixed an authentication bypass vulnerability that affects several prodcuts. The patch was released outside the normal patch schedule.
https://supportportal.juniper.net/s/article/2025-02-Out-of-Cycle-Security-Bulletin-Session-Smart-Router-Session-Smart-Conductor-WAN-Assurance-Router-API-Authentication-Bypass-Vulnerability-CVE-2025-21589?language=en_US
DELL BIOS Patches
DELL released BIOS updates fixing a privilege escalation issue. The update affects a large part of Dell's portfolio
https://www.dell.com/support/kbdoc/en-en/000258429/dsa-2025-021
My Very Personal Guidance and Strategies to Protect Network Edge Devices
A quick summary to help you secure edge devices. This may be a bit opinionated, but these are the strategies that I find work and are actionable.
https://isc.sans.edu/diary/My%20Very%20Personal%20Guidance%20and%20Strategies%20to%20Protect%20Network%20Edge%20Devices/31660
PostgreSQL SQL Injection
A followup to yesterday's segment about the PostgreSQL vulnerability. Rapid7 released a Metasploit module to exploit the vulnerability.
https://github.com/rapid7/metasploit-framework/pull/19877
Ivanti Connect Secure Exploited
The Japanese CERT observed exploitation of January's Connect Secure vulnerability
https://blogs.jpcert.or.jp/ja/2025/02/spawnchimera.html
WinZip Vulnerability
WinZip patched a buffer overflow vulenrability that may be triggered by malicious 7Z files
https://www.zerodayinitiative.com/advisories/ZDI-25-047/
Xerox Printer Patch
Xerox patched two vulnerabililites in its enterprise multifunction printers that may be exploited for lateral movement.
https://securitydocs.business.xerox.com/wp-content/uploads/2025/02/Xerox-Security-Bulletin-XRX25-003-for-Xerox-VersaLinkPhaser-and-WorkCentre.pdf
Fake BSOD Delivered by Malicious Python Script
Xavier found an odd malicious Python script that displays a blue screen of
death to users. The purpose isn't quite clear. It could be a teach support scam
tricking users into calling the 800 number displayed, or a simple
anti-reversing trick
https://isc.sans.edu/diary/Fake%20BSOD%20Delivered%20by%20Malicious%20Python%20Script/31686
The Danger of IP Volatility
Accounting for IP addresses is important, and if not done properly, may
lead to resources being exposed after IP addresses are released.
https://isc.sans.edu/diary/The%20Danger%20of%20IP%20Volatility/31688
PostgreSQL SQL Injection
Functions in PostgreSQL's libpq do not properly escape parameters which may
lead to SQL injection issues if the functions are used to create input for pqsql.
https://www.postgresql.org/support/security/CVE-2025-1094/
Multiple Russian Threat Actors Targeting Microsoft Device Code Auth
The OAUTH device code flow is used to attach devices with limited input capability to a user's account. However, this can be abused via phishing attacks.
https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/
DShield SIEM Docker Updates
Interested in learning more about the attacks hitting your honeypot?
Guy assembled a neat SIEM to create dashboards summarizing the attacks.
https://isc.sans.edu/diary/DShield%20SIEM%20Docker%20Updates/31680
PANOS Path Confusion Auth Bypass
Palo Alto Networks fixed a path confusion vulnerability introduced by the
overly complex midle box chain in PANOS.
https://slcyber.io/blog/nginx-apache-path-confusion-to-auth-bypass-in-pan-os/
https://www.theregister.com/2025/02/13/palo_alto_firewall/
China's Volt Typhoon Continues to use Cisco Vulns
Recorded Future wrote up some recent attacks of the Red Mike / Volt Typhoon groups going after telecom providers by compromissing Cisco systems via an older vulnerabilty
https://www.wired.com/story/chinas-salt-typhoon-spies-are-still-hacking-telecoms-now-by-exploiting-cisco-routers/
Crowdstrike Patches Linux Client
https://www.crowdstrike.com/security-advisories/cve-2025-1146/
An Ontology for Threats: Cybercrime and Digital Forensic Investigation on Smart City Infrastructure
Smart cities is a big topic for many local governments. With building these complex systems, attacks will follow.
https://isc.sans.edu/diary/An%20ontology%20for%20threats%2C%20cybercrime%20and%20digital%20forensic%20investigation%20on%20Smart%20City%20Infrastructure/31676
North Korean state actor tricking admins into executing PowerShell
North Korean state actors are spending quite a bit of effort setting up relationships with South Korean system administrators, culminating in them getting tricked into executing malicious PowerShell scripts.
https://x.com/MsftSecIntel/status/1889407814604296490
Wazuh Vulnerability
A deserialization vulnerability in Wazuh may lead to an unauthenticated remote code execution vulnerability
https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh
PAM PKCS11 Vulnerablity
Several vulnerabilities in the Linux PAM module processing smart card authentication can be used to bypass authentication
https://github.com/OpenSC/pam_pkcs11/releases/tag/pam_pkcs11-0.6.13
Ivanti Patches
Ivanti released its monhtly update, fixing a number of critical vulnerabilities in Connect Secure and other prodcuts
https://forums.ivanti.com/s/article/February-Security-Advisory-Ivanti-Connect-Secure-ICS-Ivanti-Policy-Secure-IPS-and-Ivanti-Secure-Access-Client-ISAC-Multiple-CVEs?language=en_US
Microsoft Patch Tuesday
Microsoft released patches for 55 vulnerabilities. Three of them are actagorized as critical, two are already exploited and another two have been publicly disclosed. The LDAP server vulnerability could become a huge deal, but it is not clear if an exploit will appear.
https://isc.sans.edu/diary/Microsoft%20February%202025%20Patch%20Tuesday/31674
Adobe Patches
Adobe released patches for seven products. Watch out in particular for the Adobe Commerce issues
https://helpx.adobe.com/security/security-bulletin.html
Fortinet Acknowledges Exploitation of Vulnerability
https://fortiguard.fortinet.com/psirt/FG-IR-24-535
Reminder: 7-Zip MoW
The MoW must be added to any files extracted from ZIP or other compound file formats. 7-Zip does not do so by default unless you alter the default configuration.
https://isc.sans.edu/diary/Reminder%3A%207-Zip%20%26%20MoW/31668
Apple Fixes 0-Day
Apple released updates to iOS and iPadOS fixing a bypass for USB Restricted Mode. The vulnerability is already being exploited.
https://support.apple.com/en-us/122174
AMD ZEN CPU Microcode Update
An attacker is able to replace microcode on some AMD CPUs. This may alter how the CPUs function and Google released a PoC showing how it can be used to manipulate the random number generator.
https://github.com/google/security-research/security/advisories/GHSA-4xq7-4mgh-gp6w
Trimble Cityworks Exploited
CISA added a recent Trimble Cityworks vulnerabliity to its list of exploited vulnerabilities.
https://learn.assetlifecycle.trimble.com/i/1532182-cityworks-customer-communication-2025-02-06-docx/0?
Google Tag Manager Skimmer Steals Credit Card Info
Sucuri released a blog post with updates to the mage cart campaign. The latest version is injecting malicious code as part of the google tag manager / analytics code.
https://blog.sucuri.net/2025/02/google-tag-manager-skimmer-steals-credit-card-info-from-magento-site.html
SSL 2.0 Turns 30 This Sunday
SSL was created in February 1995. However, back in 2005, only a year later, SSL 3.0 was released, and as of 2011, SSL 2.0 was deprecated, and support was removed from many crypto libraries. However, over 400k hosts are still exposed via SSL 2.0.
https://isc.sans.edu/diary/SSL%202.0%20turns%2030%20this%20Sunday...%20Perhaps%20the%20time%20has%20come%20to%20let%20it%20die%3F/31664
Deepseek News
Many articles cover various security shortcomings in the Chinese Deepseek AI model. Remember that some of these issues are not unique to Deepseek.
https://www.upguard.com/blog/deepseek-adoption
https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face
https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak
https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/
Crypto Wallet Scam Not For Free
Didier looked closer at the recent dual signature crypto scams. These wallets are not free; attackers must spend money to set them up.
https://isc.sans.edu/diary/Crypto+Wallet+Scam+Not+For+Free/31666
The Unbreakable Multi-Layer Anti-Debugging System
Xavier found a nice Python script that included what it calls the "Unbreakable Multi-Layer Anti-Debugging System". Leave it up to Xavier to tear it appart for you.
https://isc.sans.edu/diary/The%20Unbreakable%20Multi-Layer%20Anti-Debugging%20System/31658
Take my money: OCR crypto stealers in Google Play and App Store
Malware using OCR on screen shots was available not just via Google Play, but also the Apple App Store.
https://securelist.com/sparkcat-stealer-in-app-store-and-google-play-2/115385/
Threat Actors Still Leveraging Legit RMM Tool ScreenConnect
Unsurprisingly, threat actors still like to use legit remote admin tools, like ScreenConnect, as a command and control channel. Silent Push outlines the latest trends and IoCs they found
https://www.silentpush.com/blog/screenconnect/
Cisco Identity Services Engine Insecure Java Deserialization and Authorization Bypass Vulnerabilities
Java deserializing strikes again to allow arbitrary code execution. Cisco fixed this vulnerability and a authorization bypass issue in its Identity Services Engine
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multivuls-FTW9AOXF
F5 Update
F5 fixes an interesting authentication bypass problem affecting TLS client certificates
https://my.f5.com/manage/s/article/K000149173
Phishing via com- prefix domains
Every day, attackers are registering a few hunder domain names starting with com-. These are used in phishing e-mails, like for example "toll fee scams", to create more convincing phishing links.
https://isc.sans.edu/diary/Phishing%20via%20%22com-%22%20prefix%20domains/31654
Microsoft Windows 10 Extended Security Updates
Microsoft released pricing and additional details for the Windows 10 extended security updates. For the first year after official free updates stopped, security updates will be available for $61 for the first year.
https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates
Mozilla Enforcing Certificate Transparency
Mozilla is following the lead from other browsers, and will require certificates to include a certificate signature timestamp as proof of compliance with certificate transparency requirements.
https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/OagRKpVirsA/m/Q4c89XG-EAAJ
https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency#Enterprise_Policies
Veeam Update
Veeam's internal backup process may be used to execute arbitrary code by an attacker with a machine in the middle position.
https://www.veeam.com/kb4712
Netgear Unauthenticated RCE
https://kb.netgear.com/000066558/Security-Advisory-for-Unauthenticated-RCE-on-Some-WiFi-Routers-PSV-2023-0039
Some Updates to Our Data Feeds
We made some updates to the documentation for our data feeds, and added the neat Rosti Feed to our list as well as to our ipinfo page.
https://isc.sans.edu/diary/Some%20updates%20to%20our%20data%20feeds/31650
8 Million Request Later We Meade the Solarwindws Supply Chain Attack Look Amateur
While the title is a bit of watchTowr hyperbole, the problem of resurrecting dead S3 buckets back to live is real and needs to be addressed. Boring solutions will help not becoming an exciting headline.
https://labs.watchtowr.com/8-million-requests-later-we-made-the-solarwinds-supply-chain-attack-look-amateur/
Let's Encrypt Ending Expiration Emails
Let's Encrypt will no longer send emails for expiring certificates. They suggest other free services to send these emails for you
https://letsencrypt.org/2025/01/22/ending-expiration-emails/
Guidance and Strategies Protect Network Edge Edvices
CISA and other agencies created a guidance document outlining how to protect edge devices like firewalls, vpn concentrators and other similar devices.
https://www.cisa.gov/resources-tools/resources/guidance-and-strategies-protect-network-edge-devices
Crypto Wallet Scam
YouTube spam messages leak private keys to crypto wallets. However, these keys can not be used to withdraw funds. Victims are scammed into depositing "gas fees" which are then collected by the scammer.
https://isc.sans.edu/diary/Crypto%20Wallet%20Scam/31646
Mediatek Patches
Mediatek patched numerous vulnerabilities in its WLAN products. Some allow for unauthenticated arbitrary code execution
https://corp.mediatek.com/product-security-bulletin/February-2025
D-Link Vulnerability
D-Link disclosed a vulnerability in older routers that as of May no longer receive any updates. Your only option is to upgrade hardare.
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415
Microsoft Discontinues VPN Service
Microsoft is shutting down the VPN service that was included as part of Microsoft Defender
https://support.microsoft.com/en-au/topic/end-of-support-privacy-protection-vpn-in-microsoft-defender-for-individuals-8b503da5-732a-4472-833a-e2ddca53036a
To Simulate or Replicate: Crafting Cyber Ranges
Automating the creation of cyber ranges. This will be a multi part series and this part covers creating the DNS configuration in Windows
https://isc.sans.edu/diary/To%20Simulate%20or%20Replicate%3A%20Crafting%20Cyber%20Ranges/31642
Scammers Exploiting Deepseek Hype
Scammers are using the hype around Deepseek, and some of the confusion caused by it's site not being reachable, to scam users into installing malware. I am also including a link to a "jailbreak" of Deepseek (this part was not covered in the podcast).
https://www.welivesecurity.com/en/cybersecurity/scammers-exploiting-deepseek-hype/
https://lab.wallarm.com/jailbreaking-generative-ai/
PyPi Archived Status
PyPi introduced a new feature to mark repositories as archived. This implies that the author is no longer maintaining the particular package
https://blog.pypi.org/posts/2025-01-30-archival/
ICS Mecial Advisory: Comtec Patient Monitor Backdoor
And interested backdoor was found in a Comtech Patient Monitor.
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01
PCAPs or It Didn't Happen: Exposing an Old Netgear Vulnerability Still Active in 2025 [Guest Diary]
https://isc.sans.edu/diary/PCAPs%20or%20It%20Didn%27t%20Happen%3A%20Exposing%20an%20Old%20Netgear%20Vulnerability%20Still%20Active%20in%202025%20%5BGuest%20Diary%5D/31638
RCE Vulnerablity in AI Development Platform Lightning AI
Noma Security discovered a neat remote code execution vulnerability in Lightning AI. This vulnerability is exploitable by tricking a logged in user into clicking a simple link.
https://noma.security/noma-research-discovers-rce-vulnerability-in-ai-development-platform-lightning-ai/
Canon Laser Printers and Small Office Multifunctional Printer Vulnerabilities
Canon fixed three different vulnerablities affecting various laser and small office multifunctional printers. These vulnerabilities may lead to remote code execution, and there are some interesting exploit opportunities
https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers
Deepseek ClickHouse Database Leak
https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak
From PowerShell to a Python Obfuscation Race!
This information stealer not only emulates a PDF document convincingly, but also includes its own Python environment for Windows
https://isc.sans.edu/diary/From%20PowerShell%20to%20a%20Python%20Obfuscation%20Race!/31634
Alleged Active Exploit Sale of CVE-2024-55591 on Fortinet Devices
An exploit for this week's Fortinet vulnerability is for sale on russian forums. Fortinet also requires patching of devices without cloud license within seven days of patch release
https://x.com/MonThreat/status/1884577840185643345
https://community.fortinet.com/t5/Support-Forum/Firmware-upgrade-policy/td-p/373376
The Tainted Voyage: Uncovering Voyager's Vulnerabilities
Sonarcube identified vulnerabilities in the popular PHP package Voyager. One of them allows arbitrary file uploads.
https://www.sonarsource.com/blog/the-tainted-voyage-uncovering-voyagers-vulnerabilities/
Hackers exploit critical unpatched flaw in Zyxel CPE devices
A currently unpatches vulnerablity in Zyxel devices is actively exploited.
https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-unpatched-flaw-in-zyxel-cpe-devices/
VMSA-2025-0002: VMware Avi Load Balancer addresses an unauthenticated blind SQL Injection vulnerability (CVE-2025-22217)
VMWare released a patch for the AVI Load Balancer addressing an unauthenticated blink SQL injection vulnerability.
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/25346
Learn about fileless crypto stealers written in Python, the ongoing exploitation of recent SimpleHelp vulnerablities, new Apple Silicon Sidechannel attacks a Team Viewer Vulnerablity and an odd QR Code
Fileless Python InfoStealer Targeting Exodus
This Python script targets Exodus crypto wallet and password managers to steal crypto currencies. It does not save exfiltrated data in files, but keeps it in memory for exfiltration
https://isc.sans.edu/diary/Fileless%20Python%20InfoStealer%20Targeting%20Exodus/31630
Campaign Exploiting SimpleHelp Vulnerablity
Arcticwolf observed attacks exploiting SimpleHelp for initial access to networks. It has not been verified, but is assumed that vulnerabilities made public about a week ago are being exploited.
https://arcticwolf.com/resources/blog-uk/arctic-wolf-observes-campaign-exploiting-simplehelp-rmm-software-initial-access/
Two new Side Channel Vulnerabilities in Apple Silicon
SLAP (Data Speculation Attacks via Load Address Prediction): This attack exploits the Load Address Predictor in Apple CPUs starting with the M2/A15, allowing unauthorized access to sensitive data by mispredicting memory addresses. FLOP (Breaking the Apple M3 CPU via False Load Output Predictions): This attack targets the Load Value Predictor in Apple's M3/A17 CPUs, enabling attackers to execute arbitrary computations on incorrect data, potentially leaking sensitive information.
https://predictors.fail/
Teamviewer Security Bulletin
Teamviewer patched a privilege escalation vulnerability CVE-2025-0065
https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2025-1001/
Odd QR Code
A QR code may resolve to a different URL if looked at at an angle.
https://mstdn.social/@isziaui/113874436953157913
Limited Discount for SANS Baltimore
https://sans.org/u/1zQd
This episode shows how attackers are bypassing phishing filter by abusing the "shy" softhyphen HTML entitiy. We got an update from Apple fixing a 0-day vulnerability in addition to a number of other issues. watchTowr show how to exploit an interesting FortiOS vulnerability and we have patches for Github Desktop and Apache Solr
An unusal shy z-wasp phish
https://isc.sans.edu/diary/An%20unusual%20%22shy%20z-wasp%22%20phishing/31626
How the soft hyphen "shy" HTML entity can be abused to bypass e-mail filters
Apple Patches
https://support.apple.com/en-us/100100
Apple released patches for all of its operating systems, fixing a 0-day vulnerability among many others issues
Get Fortirekt I am the Super_admin now
https://labs.watchtowr.com/get-fortirekt-i-am-the-super_admin-now-fortios-authentication-bypass-cve-2024-55591/
Details about a recent FortiOS Vulnerability
GitHub Desktop Vulnerability
https://thehackernews.com/2025/01/github-desktop-vulnerability-risks.html
Apache Solr Vulnerability
https://solr.apache.org/security.html#cve-2024-52012-apache-solr-configset-upload-on-windows-allows-arbitrary-path-write-access
Guest Diary: How Access Brokers Maintain Persistence
Explore how cybercriminals utilize access brokers to persist within networks and the impact this has on organizational security.
https://isc.sans.edu/forums/diary/Guest+Diary+How+Access+Brokers+Maintain+Persistence/31600/
Critical Vulnerability in Meta's Llama Stack (CVE-2024-50050)
A deep dive into CVE-2024-50050, a critical vulnerability affecting Meta's Llama Stack, with exploitation details and mitigation strategies.
https://www.oligo.security/blog/cve-2024-50050-critical-vulnerability-in-meta-llama-llama-stack
ESXi Ransomware and SSH Tunneling Defense Strategies
Learn how to fortify your infrastructure against ransomware targeting ESXi environments, focusing on SSH tunneling and proactive measures.
https://www.sygnia.co/blog/esxi-ransomware-ssh-tunneling-defense-strategies/
Zyxel USG FLEX/ATP Series Application Signature Recovery Steps
Addressing issues with Zyxel s USG FLEX/ATP Series application signatures as of January 24, 2025, with a detailed recovery guide.
https://support.zyxel.eu/hc/en-us/articles/24159250192658-USG-FLEX-ATP-Series-Recovery-Steps-for-Application-Signature-Issue-on-January-24th-2025
Subaru Starlink Vulnerability Exposed Cars to Remote Hacking
Discussing how a vulnerability in Subaru s Starlink system left vehicles susceptible to remote exploitation and the steps taken to resolve it.
https://www.securityweek.com/subaru-starlink-vulnerability-exposed-cars-to-remote-hacking/
In today's episode, learn how an attacker attempted to exploit webmail XSS vulnerablities against us. Sonicwall released a critical patch fixing an already exploited vulnerability in its SMA 1000 appliance. Cisco fixed vulnerabilities in ClamAV and its Meeting Manager REST API. Learn from SANS.edu student Anthony Russo how to take advantage of AI for SOAR.
XSS Attempts via E-Mail
https://isc.sans.edu/diary/XSS%20Attempts%20via%20E-Mail/31620
An analysis of a recent surge in email-based XSS attack attempts targeting users and organizations. Learn the implications and mitigation techniques.
SonicWall PSIRT Advisory: CVE-2025-23006
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0002 CVE-2025-23006
Details of a critical vulnerability in SonicWall appliances (SNWLID-2025-0002) and what you need to do to secure your systems.
Cisco ClamAV Advisory: OLE2 Parsing Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-ole2-H549rphA
A DoS vulnerability in the popular open source anti virus engine ClamAV
Cisco CMM Privilege Escalation Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cmm-privesc-uy2Vf8pc
A patch of a privilege escalation flaw in Cisco s CMM module.
In today's episode, we start by talking about the PFSYNC protocol used to synchronize firewall states to support failover. Oracle released it's quarterly critical patch update. ESET is reporting about a critical VPN supply chain attack and CISA released guidance for victims of recent Ivanti related attacks.
Catching CARP: Fishing for Firewall States in PFSync Traffic
https://isc.sans.edu/diary/Catching%20CARP%3A%20Fishing%20for%20Firewall%20Stat%20es%20in%20PFSync%20Traffic/31616)
Discover how attackers exploit PFSync traffic to manipulate firewall states. This deep dive explores vulnerabilities and mitigation strategies in network defense.
Oracle Critical Patch Update January 2025
https://www.oracle.com/security-alerts/cpujan2025.html)
Oracle's January 2025 patch release addresses numerous critical vulnerabilities across their product suite. Learn about key updates and how to secure your systems.
PlushDaemon: Compromising the Supply Chain of a Korean VPN Service
https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-supply-chain-korean-vpn-service/
ESET Research uncovers PlushDaemon, a sophisticated supply chain attack targeting a Korean VPN provider. Understand the implications for supply chain security.
CISA Cybersecurity Advisory: AA25-022A
https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-022a
The latest advisory highlights active threats and mitigation strategies for critical infrastructure. Stay ahead with CISA s guidance on emerging cyber risks.
This episodes covers how Starlink users can be geolocated and how Cloudflare may help deanonymize users. The increased use of AI helpers leads to leaking data via careless prompts.
Geolocation and Starlink
https://isc.sans.edu/diary/Geolocation%20and%20Starlink/31612
Discover the potential geolocation risks associated with Starlink and how they might be exploited. This diary entry dives into new concerns for satellite internet users.
Deanonymizing Users via Cloudflare
https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117
Deanonymizing users by identifying which cloudflare server cashed particular content
Sage's AI Assistant and Customer Data Concerns
https://www.theregister.com/2025/01/20/sage_copilot_data_issue/
Examine how a Sage AI tool inadvertently exposed sensitive customer data, raising questions about AI governance and trust in business applications.
The Threat of Sensitive Data in Generative AI Prompts
https://www.darkreading.com/threat-intelligence/employees-sensitive-data-genai-prompts
Analyze how employees careless prompts to generative AI tools can lead to sensitive data breaches and the importance of awareness training.
Homebrew Phishing
https://x.com/ryanchenkie/status/1880730173634699393
In this episode, we talk about downloading and analyzing partial ZIP files, how legitimate remote access tools are used in recent compromises and how a research found an SSRF vulnerability in Azure DevOps
Partial ZIP File Downloads
A closer look at how attackers are leveraging partial ZIP file downloads to bypass file verification systems and plant malicious content.
https://isc.sans.edu/diary/Partial%20ZIP%20File%20Downloads/31608
Ukrainian CERT Advisory on AnyDesk Threat
The Ukrainian CERT provides detailed guidance on identifying and mitigating recent cyber threats exploiting AnyDesk for unauthorized access.
https://cert.gov.ua/article/6282069
Finding SSRFs in Azure DevOps
An in-depth analysis of how server-side request forgery (SSRF) vulnerabilities are discovered and exploited in Azure DevOps pipelines.
https://binarysecurity.no/posts/2025/01/finding-ssrfs-in-devops
In this episode, we cover how to use honeypot data to keep your offensive infrastructure alive longer, three critical vulnerabilities in SimpleHelp that must be patched now, and an interesting vulnerability affecting many systems allowing UEFI Secure Boot bypass.
Leveraging Honeypot Data for Offensive Security Operations [Guest Diary] A recent guest diary on the SANS Internet Storm Center discusses how offensive security professionals can utilize honeypot data to enhance their operations. The diary highlights the detection of scans from multiple IP addresses, emphasizing the importance of monitoring non-standard user-agent strings in web requests.
https://isc.sans.edu/diary/Leveraging%20Honeypot%20Data%20for%20Offensive%20Security%20Operations%20%5BGuest%20Diary%5D/31596
Security Vulnerabilities in SimpleHelp 5.5.7 and Earlier SimpleHelp has released version 5.5.8 to address critical security vulnerabilities present in versions 5.5.7 and earlier. Users are strongly advised to upgrade to the latest version to prevent potential exploits. Detailed information and upgrade instructions are available on SimpleHelp's official website.
https://simple-help.com/kb---security-vulnerabilities-01-2025#send-us-your-questions
Under the Cloak of UEFI Secure Boot: Introducing CVE-2024-7344 ESET researchers have identified a new vulnerability, CVE-2024-7344, that allows attackers to bypass UEFI Secure Boot on most UEFI-based systems. This flaw enables the execution of untrusted code during system boot, potentially leading to the deployment of malicious UEFI bootkits. Affected users should apply available patches to mitigate this risk.
https://www.welivesecurity.com/en/eset-research/under-cloak-uefi-secure-boot-introducing-cve-2024-7344/
In this episode, we explore the efficient storage of honeypot logs in databases, issues with Citrix's Session Recording Agent and Windows Update. Ivanti is having another interesting security event and our SANS.edu graduate student Rich Green talks about his research on Passkeys.
Extracting Practical Observations from Impractical Datasets: A SANS Internet Storm Center diary entry discusses strategies for analyzing complex datasets to derive actionable insights.
https://isc.sans.edu/diary/Extracting%20Practical%20Observations%20from%20Impractical%20Datasets/31582
Citrix Session Recording Agent Update Issue: Citrix reports that Microsoft's January security update fails or reverts on machines with the 2411 Session Recording Agent installed, providing guidance on addressing this issue.
https://support.citrix.com/s/article/CTX692505-microsofts-january-security-update-failsreverts-on-a-machine-with-2411-session-recording-agent?language=en_US
Ivanti Endpoint Manager Security Advisory: Ivanti releases a security advisory for Endpoint Manager versions 2024 and 2022 SU6, detailing vulnerabilities and recommended actions.
https://forums.ivanti.com/s/article/Security-Advisory-EPM-January-2025-for-EPM-2024-and-EPM-2022-SU6?language=en_US
Revolutionizing Enterprise Security: The Exciting Future of Passkeys Beyond Passwords: A SANS.edu research paper explores the shift from traditional passwords to passkeys, highlighting the benefits and challenges of adopting passwordless authentication methods.
https://www.sans.edu/cyber-research/revolutionizing-enterprise-security-exciting-future-passkeys-beyond-passwords/
Today's episode covers an odd 12 year old Netgear vulnerability that only received a proper CVE number last year. Learn about how to properly identify OpenID connect users and avoid domain name resue. Good old rsync turns out to be in need of patching and Fortinet: Not sure if it needs patching. Probably it does. Go ahead and patch it.
The Curious Case of a 12-Year-Old Netgear Router Vulnerability
Outdated Netgear routers remain a security risk, with attackers actively exploiting a 2013 vulnerability to deploy crypto miners. Learn how to protect your network by updating or replacing legacy hardware.
URL: https://isc.sans.edu/diary/The%20Curious%20Case%20of%20a%2012-Year-Old%20Netgear%20Router%20Vulnerability/31592
Millions at Risk Due to Google s OAuth Flaw
A flaw in Google s OAuth implementation enables attackers to exploit defunct domain accounts, exposing sensitive data. Tips on implementing MFA and domain monitoring to reduce risks.
URL: https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw
Rsync 3.4.0 Security Release
The latest rsync update fixes critical vulnerabilities, including buffer overflows and symbolic link issues. Upgrade immediately to protect your file synchronization processes.
URL: https://download.samba.org/pub/rsync/NEWS#3.4.0
Fortinet PSIRT Advisories: Stay Secure
Fortinet's latest advisories address vulnerabilities in FortiOS, FortiProxy, and more. Review and apply patches promptly to secure your perimeter defenses.
URL: https://www.fortiguard.com/psirt
Today, Microsoft Patch Tuesday headlines our news with Microsoft patching 209 vulnerabilities, some
of which have already been exploited. Fortinet suspects a so far unpatched Node.js authentication
bypass to be behind some recent exploits of FortiOS and FortiProxy devices.
Microsoft January 2025 Patch Tuesday
This month's Microsoft patch update addresses a total of 209 vulnerabilities, including 12 classified as critical. Among these, 3 vulnerabilities have been actively exploited in the wild, and 5 have been disclosed prior to the patch release, marking them as zero-days.
https://isc.sans.edu/diary/rss/31590
Fortinet Security Advisory FG-IR-24-535 CVE-2024-55591
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS and FortiProxy may allow a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
https://fortiguard.fortinet.com/psirt/FG-IR-24-535
PRTG Network Monitor Update:
Update for an already exploited XSS vulnerability in Paesler PRTG Network Monitor CVE-2024-12833
https://www.paessler.com/prtg/history/stable
Episode Summary:
This episode covers brute-force attacks on the password reset functionality of Hikvision devices, a macOS SIP bypass vulnerability, Linux rootkit malware, and a novel ransomware campaign targeting AWS S3 buckets.
Topics Covered:
Hikvision Password Reset Brute Forcing
URL: https://isc.sans.edu/diary/Hikvision%20Password%20Reset%20Brute%20Forcing/31586
Hikvision devices are being targeted using old brute-force attacks exploiting predictable password reset codes.
Analyzing CVE-2024-44243: A macOS System Integrity Protection Bypass
URL: https://www.microsoft.com/en-us/security/blog/2025/01/13/analyzing-cve-2024-44243-a-macos-system-integrity-protection-bypass-through-kernel-extensions/
Microsoft details a macOS vulnerability allowing attackers to bypass SIP using kernel extensions.
Rootkit Malware Controls Linux Systems Remotely
URL: https://cybersecuritynews.com/rootkit-malware-controls-linux-systems-remotely/
A sophisticated rootkit targeting Linux systems uses zero-day vulnerabilities for remote control.
Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C
URL: https://www.halcyon.ai/blog/abusing-aws-native-services-ransomware-encrypting-s3-buckets-with-sse-c
Attackers are using AWS s SSE-C encryption to lock S3 buckets during ransomware campaigns. We cover how the attack works and how to protect your AWS environment.
In today's episode, we cover the latest updates in cybersecurity:
Windows Defender Enhances Chrome Extension Detection
Microsoft's Defender now catalogs Chrome extensions to identify malicious ones. Learn how this improves enterprise security.
https://isc.sans.edu/diary/Windows%20Defender%20Chrome%20Extension%20Detection/31574
Multi-OLE Analysis in Malicious Documents
A look at how attackers embed OLE files in Office documents to evade detection and the tools to combat it.
https://isc.sans.edu/diary/Multi-OLE/31580
Ivanti Connect Secure RCE Vulnerability (CVE-2025-0282)
Details of a critical vulnerability affecting Ivanti products and the patching timelines.
https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/
Apple USB-C Controller Compromised
Researchers hacked Apple s ACE3 USB-C controller, highlighting hardware security challenges.
https://cybersecuritynews.com/apples-new-usb-c-controller-hacked/
IRS Pushes for IP PIN Enrollment
Protect yourself from tax-related identity theft by securing your IP PIN for the 2025 tax season.
https://www.irs.gov/newsroom/irs-encourages-all-taxpayers-to-sign-up-for-an-ip-pin-for-the-2025-tax-season
In this episode, we explore the following stories:
"Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics"
Overview of Redtail's multi-architecture cryptomining malware exploiting vulnerabilities and deploying persistence techniques.
URL: Examining Redtail: Analyzing a Sophisticated Cryptomining Malware and its Advanced Tactics
"Information Stealer Masquerades as LDAPNightmare PoC Exploit"
A malware disguised as a PoC exploit targets users seeking to test vulnerabilities like LDAPNightmare.
URL: Information Stealer Masquerades as LDAPNightmare PoC Exploit
"How Extensions Trick CWS Search"
Research reveals how malicious browser extensions manipulate Chrome Web Store search to appear legitimate.
URL: How Extensions Trick CWS Search
"Palo Alto Networks' Expedition Vulnerabilities (PAN-SA-2025-0001)"
Multiple vulnerabilities in the deprecated Expedition tool can expose credentials and lead to unauthorized file and command execution.
URL: Palo Alto Networks' Expedition Vulnerabilities (PAN-SA-2025-0001)
In this episode, we discuss critical vulnerabilities in Ivanti Connect Secure and Policy Secure, command injection risks in Aviatrix Network Controllers, and the risks posed by hijacked abandoned backdoors.
Episode Links and Topics:
More Governments Backdoors in Your Backdoors
https://labs.watchtowr.com/more-governments-backdoors-in-your-backdoors/
Researchers reveal how expired domains linked to abandoned backdoors can be hijacked, exposing systems to further compromise.
Security Update: Ivanti Connect Secure, Policy Secure, and Neurons for ZTA Gateways
https://www.ivanti.com/blog/security-update-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways
Ivanti addresses critical vulnerabilities (CVE-2025-0282, CVE-2025-0283) in their secure gateway products, with active exploitation in the wild.
CVE-2024-50603: Aviatrix Network Controller Command Injection Vulnerability
https://www.securing.pl/en/cve-2024-50603-aviatrix-network-controller-command-injection-vulnerability/
A command injection vulnerability in Aviatrix Network Controllers allows unauthenticated code execution, posing severe risks to network environments.
In this episode, we dive into active exploitation of a zero-day in SonicWall SSL-VPN, privilege escalation vulnerabilities in Moxa devices, and a BitLocker bypass in Windows 11. We also cover cryptocurrency mining malware hitting PHP servers and the White House's launch of the U.S. Cyber Trust Mark to secure connected devices.
Episode Links and Topics:
PacketCrypt Classic Cryptocurrency Miner on PHP Servers
https://isc.sans.edu/diary/PacketCrypt%20Classic%20Cryptocurrency%20Miner%20on%20PHP%20Servers/31564
Malware exploiting PHP servers to mine PacketCrypt Classic cryptocurrency.
SonicOS Affected By Multiple Vulnerabilities
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0003
A zero-day vulnerability in SonicWall SSL-VPN devices is under active attack.
Privilege Escalation and OS Command Injection Vulnerabilities in Moxa Devices
https://www.moxa.com/en/support/product-support/security-advisory/mpsa-241155-privilege-escalation-and-os-command-injection-vulnerabilities-in-cellular-routers,-secure-routers,-and-netwo
Critical vulnerabilities in Moxa routers and security appliances allow privilege escalation and OS command injection.
White House Launches U.S. Cyber Trust Mark
https://www.whitehouse.gov/briefing-room/statements-releases/2025/01/07/white-house-launches-u-s-cyber-trust-mark-providing-american-consumers-an-easy-label-to-see-if-connected-devices-are-cybersecure/
A new cybersecurity labeling program for connected devices aims to help consumers choose secure products.
Windows BitLocker: Screwed without a Screwdriver
https://media.ccc.de/v/38c3-windows-bitlocker-screwed-without-a-screwdriver#t=761
(video in English)
A two-year-old vulnerability in Windows 11 allows bypassing BitLocker encryption.
In this episode of the SANS Internet Storm Center's Stormcast, we cover critical vulnerabilities affecting OpenSSH, BeyondTrust, and Nuclei, including the newly discovered "RegreSSHion" flaw and a bypass vulnerability in Nuclei. We also discuss how malware evasion techniques can impact analysis environments and highlight the dangers of fake exploits targeting researchers. Tune in for insights on patching, mitigation strategies, and staying ahead of emerging threats.
Topics Covered:
Make Malware Happy
https://isc.sans.edu/diary/Make%20Malware%20Happy/31560
A look at how malware adapts and detects analysis environments, and why replicating operational settings is critical during malware analysis.
Nuclei Signature Verification Bypass (CVE-2024-43405)
https://www.wiz.io/blog/nuclei-signature-verification-bypass
A critical vulnerability in Nuclei allows malicious templates to bypass signature verification, risking arbitrary code execution.
Critical Vulnerability in BeyondTrust (CVE-2024-12356)
https://censys.com/cve-2024-12356/
A high-risk flaw in BeyondTrust products allows unauthenticated OS command execution, posing a significant threat to privileged access systems.
RegreSSHion Code Execution Vulnerability (CVE-2024-6387)
https://cybersecuritynews.com/regresshion-code-execution-vulnerability/
OpenSSH vulnerability "RegreSSHion" enables remote code execution, and fake exploits targeting security researchers are in circulation.
In this episode of the SANS Internet Storm Center's Stormcast, we cover the latest cybersecurity threats and defenses, including Python-delivered malware, goodware hash sets, SSL/TLS protocol updates, and critical vulnerabilities in ASUS routers and Paessler PRTG. Stay informed and secure your systems!
Full details and links to all stories:
SwaetRAT via Python: https://isc.sans.edu/diary/SwaetRAT%20Delivery%20Through%20Python/31554
Goodware Hash Sets: https://isc.sans.edu/diary/Goodware%20Hash%20Sets/31556
SSL/TLS Updates: https://isc.sans.edu/diary/Changes%20in%20SSL%20and%20TLS%20support%20in%202024/31550
Cyberhaven Extension Compromise: https://secureannex.com/blog/cyberhaven-extension-compromise/
PRTG Vulnerability: https://www.zerodayinitiative.com/advisories/ZDI-24-1736/
ASUS Router Vulnerabilities: https://cybersecuritynews.com/asus-router-vulnerabilities/
PHPUnit and Androxgh0st
https://isc.sans.edu/diary/Command%20Injection%20Exploit%20For%20PHPUnit%20before%204.8.28%20and%205.x%20before%205.6.3%20%5BGuest%20Diary%5D/31528
Mirai Attacks Session Smart Routers
https://supportportal.juniper.net/s/article/2024-12-Reference-Advisory-Session-Smart-Router-Mirai-malware-found-on-systems-when-the-default-password-remains-unchanged?language=en_US
FortiWLM Unauthenticated limited file read vulnerability
https://fortiguard.fortinet.com/psirt/FG-IR-23-144
https://securityonline.info/kaspersky-uncovers-active-exploitation-of-fortinet-vulnerability-cve-2023-48788/
Beyond Trust Security Advisory
https://www.beyondtrust.com/trust-center/security-advisories/bt24-10
BadBox Update
https://www.bitsight.com/blog/badbox-botnet-back
A Deep Dive into TeamTNT and Spinning YARN
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20A%20Deep%20Dive%20into%20TeamTNT%20and%20Spinning%20YARN/31530
Earth Koshchei Coopts Red Team Tools in Complex RDP Attacks
https://www.trendmicro.com/en_us/research/24/l/earth-koshchei.html
Okta Social Engineering Impersonation Report
https://sec.okta.com/articles/2024/okta-social-engineering-report-response-and-recommendation
US considers banning TP-Link routers over cybersecurity risks
https://www.bleepingcomputer.com/news/security/us-considers-banning-tp-link-routers-over-cybersecurity-risks/
CISA Releases Best Practice Guidance for Mobile Communications
https://www.cisa.gov/news-events/alerts/2024/12/18/cisa-releases-best-practice-guidance-mobile-communications
Python Delivering AnyDesk Client as RAT
https://isc.sans.edu/diary/Python+Delivering+AnyDesk+Client+as+RAT/31524/
Vishing via Microsoft Teams Facilitates DarkGate Malware Intrusion
https://www.trendmicro.com/en_us/research/24/l/darkgate-malware.html
SS7 Attacks
https://www.404media.co/email/ac709882-1e4b-42fc-bcca-cf7ce4793716/
CrushFTP Vulnerability
https://crushftp.com/crush11wiki/Wiki.jsp?page=Update
MUT-1244 Targeting Offensive Actors
https://securitylabs.datadoghq.com/articles/mut-1244-targeting-offensive-actors/
Golang Crypto Vulnerability
https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909
Meeten Malware: A Cross-Platform Threat to Crypto Wallets on macOS and Windows
https://www.cadosecurity.com/blog/meeten-malware-threat
Exploit Attempts Inspired by Recent Struts 2 File Upload Vulnerability
https://isc.sans.edu/diary/Exploit%20attempts%20inspired%20by%20recent%20Struts2%20File%20Upload%20Vulnerability%20%28CVE-2024-53677%2C%20CVE-2023-50164%29/31520
Citrix Netscaler Password Spraying Mitigation
https://www.citrix.com/blogs/2024/12/13/password-spraying-attacks-netscaler-december-2024/
Let's Encrypt Six Day Certifiates
https://letsencrypt.org/2024/12/11/eoy-letter-2024/
Devices in Germany Arrived Pre-Pw0n3d
https://cybersecuritynews.com/30000-devices-in-germany-discovered-with-pre-installed-malware-badbox/
Windows 11 and TPM
https://techcommunity.microsoft.com/blog/windows-itpro-blog/tpm-2-0-%E2%80%93-a-necessity-for-a-secure-and-future-proof-windows-11/4339066
https://www.forbes.com/sites/zakdoffman/2024/12/12/microsoft-warns-400-million-windows-users-do-not-update-your-pc/
Microsoft Azure MFA Bypass
https://www.oasis.security/resources/blog/oasis-security-research-team-discovers-microsoft-azure-mfa-bypass
Struts 2 Arbitrary File Upload CVE-2024-53677
https://cwiki.apache.org/confluence/display/WW/S2-067
Russian actor Secret Blizzard using tools of other groups to attack Ukraine
https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/
Vulnerability Symbiosis: vSphere's CVE-2024-38812 and CVE-2024-38813
https://isc.sans.edu/diary/Vulnerability%20Symbiosis%3A%20vSphere%3Fs%20CVE-2024-38812%20and%20CVE-2024-38813%20%5BGuest%20Diary%5D/31510
Apple Updates Everything (iOS, iPadOS, macOS, watchOS, tvOS, visionOS)
https://isc.sans.edu/diary/Apple+Updates+Everything+iOS+iPadOS+macOS+watchOS+tvOS+visionOS/31514/
Widespread exploitation of Cleo file transfer software (CVE-2024-50623)
https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild
https://labs.watchtowr.com/cleo-cve-2024-50623/
Microsoft Patch Tuesday December 2024
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%3A%20December%202024/31508
Ivanty Security Advisory
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Services-Application-CSA-CVE-2024-11639-CVE-2024-11772-CVE-2024-11773?language=en_US
Visual Studio Code Tunnels
https://www.sentinelone.com/labs/operation-digital-eye-chinese-apt-compromises-critical-digital-infrastructure-via-visual-studio-code-tunnels/
Mitigating NTLM Relay Attacks
https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/
CURLing for Crypto on Honeypots
https://isc.sans.edu/diary/CURLing%20for%20Crypto%20on%20Honeypots/31502
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/
Android Monthly Update
https://source.android.com/docs/security/bulletin/pixel/2024-12-01
RCS Not Always Encrypted
https://daringfireball.net/linked/2024/12/04/shame-on-google-messages
Bypassing WAFs with the Phantom Version Cookie
https://portswigger.net/research/bypassing-wafs-with-the-phantom-version-cookie
URL File NTLM Hash Disclosure
https://blog.0patch.com/2024/12/url-file-ntlm-hash-disclosure.html
Ultralytics Library Infected with Miner
https://github.com/ultralytics/ultralytics/issues/18027#issuecomment-2521578169
DaMAgeCard attack targets memory directly thru SD card reader
https://swarm.ptsecurity.com/new-dog-old-tricks-damagecard-attack-targets-memory-directly-thru-sd-card-reader/
Business E-Mail Compromise
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Business%20Email%20Compromise/31474
Where There s Smoke, There s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day
https://labs.watchtowr.com/where-theres-smoke-theres-fire-mitel-micollab-cve-2024-35286-cve-2024-41713-and-an-0day/
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-misa-2024-0029
Lorex 2K Indoor Wi-Fi Security Camera
https://www.rapid7.com/globalassets/_pdfs/research/pwn2own-iot-2024-lorex-2k-indoor-wi-fi-security-camera-research.pdf
https://www.lorex.com/products/2k-indoor-wi-fi-security-camera
HPE Aruba Vulnerabilities
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04761en_us&docLocale=en_US
Alan Paller Inducted into the Cybersecurity Hall of Fame
https://cybersecurityhalloffame.org/
Data Analysis: The Unsung Hero of Cybersecurity Expertise
https://isc.sans.edu/diary/Data%20Analysis%3A%20The%20Unsung%20Hero%20of%20Cybersecurity%20Expertise%20%5BGuest%20Diary%5D/31494
FBI Warns iPhone and Android Users Stop Sending Texts
https://www.forbes.com/sites/zakdoffman/2024/12/03/fbi-warns-iphone-and-android-users-stop-sending-texts/
IdentityIQ Improper Access Control Vulnerability CVE-2024-10905
https://www.sailpoint.com/security-advisories/identityiq-improper-access-control-vulnerability-cve-2024-10905
Solana web3.js Backdoor
https://socket.dev/blog/supply-chain-attack-solana-web3-js-library
Extracting Files Embedded Inside Word Documents
https://isc.sans.edu/diary/Extracting%20Files%20Embedded%20Inside%20Word%20Documents/31486
Korea arrests CEO for adding DDoS feature to satellite receivers
https://www.bleepingcomputer.com/news/security/korea-arrests-ceo-for-adding-ddos-feature-to-satellite-receivers/
Veeam Vulnerabilities
https://www.veeam.com/kb4679
WPTaskScheduler Presistence and CVE-2024-49039 PoC
https://github.com/je5442804/WPTaskScheduler_CVE-2024-49039
Credential Guard and Kerberos delegation
https://isc.sans.edu/diary/Credential%20Guard%20and%20Kerberos%20delegation/31488
The Day We Unveiled the Secret Rotation Illusion
https://www.clutch.security/blog/the-day-we-unveiled-the-secret-rotation-illusion
Corrupt Word Documents used in Phshing
https://x.com/anyrun_app/status/1861024182210900357
IBM Security Verify Access Appliance Vulnerabilities
https://www.ibm.com/support/pages/security-bulletin-multiple-security-vulnerabilities-were-found-ibm-security-verify-access-appliance-cve-2024-49803-cve-2024-49804-cve-2024-49805-cve-2024-49806
AWS DShield Sensor + DShield SIEM
https://isc.sans.edu/diary/SANS%20ISC%20Internship%20Setup%3A%20AWS%20DShield%20Sensor%20%2B%20DShield%20SIEM%20%5BGuest%20Diary%5D/31480
From a Regular Infostealer to its Obfuscated Version
https://isc.sans.edu/diary/From%20a%20Regular%20Infostealer%20to%20its%20Obfuscated%20Version/31484
Credit Card Skimmer Malware Targeting Magento Checkout Pages
https://blog.sucuri.net/2024/11/credit-card-skimmer-malware-targeting-magento-checkout-pages.html
LogoFAIL Exploited to Deploy Bootkitty, the first UEFI bootkit for Linux
https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux
Stickers:
https://isc.sans.edu/stickers.html (code PODCAST)
Using Zeek, Snort, and Grafana to Detect Crypto Mining Malware
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Using%20Zeek%2C%20Snort%2C%20and%20Grafana%20to%20Detect%20Crypto%20Mining%20Malware/31472
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access
https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/
Introducing NachoVPN: One VPN Server to Pwn Them All
https://blog.amberwolf.com/blog/2024/november/introducing-nachovpn---one-vpn-server-to-pwn-them-all/
Keycloak Patches
https://github.com/keycloak/keycloak/security/advisories/GHSA-93ww-43rr-79v3
Palo Alto Networks Global Protect App
https://security.paloaltonetworks.com/CVE-2024-5921
PHP Updates
https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff
Quick & Dirty Obfuscated JavaScript Analysis
https://isc.sans.edu/diary/Quick%20%26%20Dirty%20Obfuscated%20JavaScript%20Analysis/31468
Decrypting a PDF With a User Password
https://isc.sans.edu/diary/Decrypting%20a%20PDF%20With%20a%20User%20Password/31466
The strange case of disappearing Russian servers
https://isc.sans.edu/diary/The%20strange%20case%20of%20disappearing%20Russian%20servers/31476
QNAP Buggy Firmware Update
https://community.qnap.com/t/firmware-qts-5-2-2-2950-build-20241114-released/254
7-ZIP Zstandard Decompression Integer Underflow
https://www.zerodayinitiative.com/advisories/ZDI-24-1532/
https://7-zip.org/download.html
Increase In Phishing SVG Attachments
https://isc.sans.edu/diary/Increase%20In%20Phishing%20SVG%20Attachments/31456
Logging blind spot revealed in FortiClient VPN
https://pentera.io/blog/FortiClient-VPN_logging-blind-spot-revealed/
Needrestart Vulnerability
https://www.qualys.com/2024/11/19/needrestart/needrestart.txt
Apple Patches Two Exploited Vulnerabilities
https://isc.sans.edu/diary/Apple%20Fixes%20Two%20Exploited%20Vulnerabilities/31452
Oracle Patch for Agile Product Lifecycle Management CVE-2024-21287
https://www.oracle.com/security-alerts/alert-cve-2024-21287.html
OFBiz Patches CVE-2024-47208 CVE-2024-48962
https://nvd.nist.gov/vuln/detail/CVE-2024-47208
https://seclists.org/oss-sec/2024/q4/95
D-Link Warns of Vulnerability in EOL Devices
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10415
Detecting the Presence of a Debugger in Linux
https://isc.sans.edu/diary/Detecting%20the%20Presence%20of%20a%20Debugger%20in%20Linux/31450
Palo Alto Patches
https://security.paloaltonetworks.com/CVE-2024-0012
https://security.paloaltonetworks.com/CVE-2024-9474
VMware vCenter Server Attacks
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968e
Veritas Enterprise Vault Vulnerability
https://www.veritas.com/support/en_US/security/VTS24-014
Exploit attempts for unpatched Citrix vulnerability CVE-2024-8068/CVE-2024-8069
https://isc.sans.edu/diary/Exploit+attempts+for+unpatched+Citrix+vulnerability/31446
https://support.citrix.com/s/article/CTX691941-citrix-session-recording-security-bulletin-for-cve20248068-and-cve20248069?language=en_US
Microsoft Power Pages: Data Exposure Reviewed
https://appomni.com/ao-labs/microsoft-power-pages-data-exposure-reviewed/
Zohocorp ManageEngine ADAudit Plus Vulnerable To SQL Injection Attacks CVE-2024-49574
https://www.manageengine.com/products/active-directory-audit/cve-2024-49574.html
Ancient TP-Link Backdoor Discovered by Attackers
https://isc.sans.edu/diary/Ancient%20TP-Link%20Backdoor%20Discovered%20by%20Attackers/31442
GitHub Projects Targeted with Malicious Commits To Frame Researchers
https://www.bleepingcomputer.com/news/security/github-projects-targeted-with-malicious-commits-to-frame-researcher/
PaloAlto and Fortinet Vulnerabilities
https://labs.watchtowr.com/hop-skip-fortijump-fortijumphigher-cve-2024-23113-cve-2024-47575/
https://security.paloaltonetworks.com/PAN-SA-2024-0015
https://www.volexity.com/blog/2024/11/15/brazenbamboo-weaponizes-forticlient-vulnerability-to-steal-vpn-credentials-via-deepdata/
Microsoft November 2024 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20November%202024%20Patch%20Tuesday/31438
CISA Top Routinely Exploited Vulnerabilities
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a
APT Actors Embed Malware within macOS Flutter Applications
https://www.jamf.com/blog/jamf-threat-labs-apt-actors-embed-malware-within-macos-flutter-applications/
PDF Object Streams
https://isc.sans.edu/diary/PDF%20Object%20Streams/31430
Mazda Infotainment Vulnerabilities
https://www.zerodayinitiative.com/blog/2024/11/7/multiple-vulnerabilities-in-the-mazda-in-vehicle-infotainment-ivi-system
Ruby SAML CVE-2024-45409: As bad as it gets and hiding in plain sight
https://workos.com/blog/ruby-saml-cve-2024-45409
Veeam Backup Enterprise Manager Vulnerability
https://www.veeam.com/kb4682
Security Update for Dell Enterprise SONiC Distribution Vulnerabilities
https://www.dell.com/support/kbdoc/en-us/000245655/dsa-2024-449-security-update-for-dell-enterprise-sonic-distribution-vulnerabilities
Easy Access to Information for Conducting Fraudulent
Emergency Data Requests Impacts US-Based Companies
and Law Enforcement Agencies
https://www.ic3.gov/CSA/2024/241104.pdf
zipdump and pkzip records
https://isc.sans.edu/diary/zipdump%20%26%20PKZIP%20Records/31428
Am I Isolated
https://github.com/edera-dev/am-i-isolated
Locked iPhones Reboot
https://www.404media.co/police-freak-out-at-iphones-mysteriously-rebooting-themselves-locking-cops-out/
https://x.com/naehrdine/status/1854896392797360484
Palo Alto Networks Bulletin
https://security.paloaltonetworks.com/PAN-SA-2024-0015
D-Link Vulnerability
https://netsecfish.notion.site/Command-Injection-Vulnerability-in-name-parameter-for-D-Link-NAS-12d6b683e67c80c49ffcc9214c239a07
Steam Account Checker Poisoned with Infostealer
https://isc.sans.edu/diary/Steam%20Account%20Checker%20Poisoned%20with%20Infostealer/31420
Cisco Ultra Reliable Wireless Backhaul Vulnerability
https://www.cisco.com/site/us/en/products/networking/industrial-wireless/ultra-reliable-wireless-backhaul/index.html
Breaking Down Multipart Parsers: File upload validation bypass
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/
Evasive ZIP Concatenation: Trojan Targets Windows Users
https://perception-point.io/blog/evasive-concatenated-zip-trojan-targets-windows-users/
Veeam Backup Enterprise Manager Vulnerability (CVE-2024-40715)
https://www.veeam.com/kb4682
SANS Holiday Hack Challenge
https://www.sans.org/mlp/holiday-hack-challenge-2024
Insights from August Web Traffic Surge
https://isc.sans.edu/forums/diary/%5BGuest%20Diary%5D%20Insights%20from%20August%20Web%20Traffic%20Surge/31408/
Talkative Air Fryer
https://www.which.co.uk/policy-and-insight/article/why-is-my-air-fryer-spying-on-me-which-reveals-the-smart-devices-gathering-your-data-and-where-they-send-it-a9Fa24K6gY1c
Pygmy Goat Malware Report
https://www.ncsc.gov.uk/section/keep-up-to-date/malware-analysis-reports
Apple CVE-2024-44258 PoC Exploit
https://github.com/ifpdz/CVE-2024-44258
HPE Arruba vulnerabilities
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04722en_us&docLocale=en_US
Python RAT with a Nice Screensharing Feature
https://isc.sans.edu/diary/Python%20RAT%20with%20a%20Nice%20Screensharing%20Feature/31414
Android Security Bulletin November 2024
https://source.android.com/docs/security/bulletin/2024-11-01
Malware Delivered as Virtual Machine
https://www.securonix.com/blog/crontrap-emulated-linux-environments-as-the-latest-tactic-in-malware-staging/
Fake Docusign Invoices
https://lab.wallarm.com/attackers-abuse-docusign-api-to-send-authentic-looking-invoices-at-scale/
Analyzing an Encrypted Phishing PDF
https://isc.sans.edu/diary/Analyzing%20an%20Encrypted%20Phishing%20PDF/31404
Okta Verify Desktop MFA For Windows Password Less Login CVE-2024-9191
https://trust.okta.com/security-advisories/okta-verify-desktop-mfa-for-windows-passwordless-login-cve-2024-9191/
QNAP QuRouter Vulnerability and Patch
https://www.qnap.com/en/security-advisory/qsa-24-45
From Naptime to Big Sleep
https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html
Authenticated SQL injection vulnerability - ManageEngine ADManager Plus CVE-2024-48878
https://www.manageengine.com/products/ad-manager/admanager-kb/cve-2024-48878.html
October Activity with Username chenzilong
https://isc.sans.edu/diary/October%202024%20Activity%20with%20Username%20chenzilong/31400
qpdf Extracting PDF Streams
https://isc.sans.edu/diary/qpdf%3A%20Extracting%20PDF%20Streams/31406
Okta bcrypt issue
https://trust.okta.com/security-advisories/okta-ad-ldap-delegated-authentication-username/
https://medium.com/@rajat29gupta/how-bcrypts-limitations-contributed-to-okta-s-vulnerability-a-lesson-for-developers-39425c644ed5
Synology Vulnerabilities
https://www.synology.com/de-de/security/advisory/Synology_SA_24_19
https://www.synology.com/de-de/security/advisory/Synology_SA_24_18
Lastpass Fake Reviews
https://blog.lastpass.com/posts/fake-web-store-reviews-attempting-to-steal-customer-data
Scans for RDP Gateways
https://isc.sans.edu/diary/Scans%20for%20RDP%20Gateways/31398
CyberPanel Exploited
https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/
Windows Themes Files Spoofing CVE-2024-38030
https://blog.0patch.com/2024/10/we-patched-cve-2024-38030-found-another.html
QNAP Patches CVE-2024-50388, CVE-2024-50387
https://www.qnap.com/en/security-advisory/qsa-24-41
Facebook Malvertising
https://www.bitdefender.com/en-us/blog/labs/unmasking-the-sys01-infostealer-threat-bitdefender-labs-tracks-global-malvertising-campaign-targeting-meta-business-pages/
Critical RCE Vulnerabilty in Cyberpanel
https://dreyand.rs/code/review/2024/10/27/what-are-my-options-cyberpanel-v236-pre-auth-rce
Spring WebFlux Vulnerability
https://access.redhat.com/security/cve/cve-2024-38821
https://spring.io/security/cve-2024-38821
Inbound SMTP DANE with DNSSEC for Exchange Online
https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-general-availability-of-inbound-smtp-dane-with-dnssec/ba-p/4281292
HeptaX: Unauthorized RDP Connections for Cyberespionage Operations
https://cyble.com/blog/heptax-unauthorized-rdp-connections-for-cyberespionage-operations/
Apple Update Everything
https://isc.sans.edu/diary/Apple%20Updates%20Everything/31390
Selfcontained HTML Phishing Attachment Using Telegram to Exfiltrate Credentials
https://isc.sans.edu/diary/Selfcontained+HTML+phishing+attachment+using+Telegram+to+exfiltrate+stolen+credentials/31388/
ChatGPT-4o Guardrail Jailbreak: Hex Encoding for Writing CVE Exploits
https://0din.ai/blog/chatgpt-4o-guardrail-jailbreak-hex-encoding-for-writing-cve-exploits
Two currently (old) exploited Ivanti vulnerabilities
https://isc.sans.edu/diary/Two%20currently%20%28old%29%20exploited%20Ivanti%20vulnerabilities/31384
Arcadyan FMIMG51AX000J (WiFi Alliance) RCE CVE-2024-41992
https://ssd-disclosure.com/ssd-advisory-arcadyan-fmimg51ax000j-wifi-alliance-rce/
Okta iOS App Vulnerability CVE-2024-10327
https://trust.okta.com/security-advisories/okta-verify-for-ios-cve-2024-10327/
Threat Alert TeamTNT's docker gatling gun campaign
https://www.aquasec.com/blog/threat-alert-teamtnts-docker-gatling-gun-campaign/
Development Features Enabled in Production
https://isc.sans.edu/diary/Development%20Features%20Enabled%20in%20Prodcution/31380
Large-scale brute-force activity targeting VPNs, SSH services with commonly used login credentials
https://blog.talosintelligence.com/large-scale-brute-force-activity-targeting-vpns-ssh-services-with-commonly-used-login-credentials/
Cisco Secure Firewall Management Center Software Command Injection Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-v3AWDqN7
Exposing the Danger Within: Hardcoded Cloud Credentials in Popular Mobile Apps
https://www.security.com/threat-intelligence/exposing-danger-within-hardcoded-cloud-credentials-popular-mobile-apps
Everybody Loves Bash Scripts Including Attackers
https://isc.sans.edu/diary/Everybody%20Loves%20Bash%20Scripts.%20Including%20Attackers./31376
Fortimanager Exploited Vulnerability
https://www.fortiguard.com/psirt/FG-IR-24-423
Sharepoint Exploit
https://www.cisa.gov/news-events/alerts/2024/10/22/cisa-adds-one-known-exploited-vulnerability-catalog
https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC
OpenSSL Vulnerability
https://openssl-library.org/news/secadv/20241016.txt
Reduced Certificate Lifetime
https://github.com/cabforum/servercert/pull/553
How much HTTP (not HTTPS) Traffic is Traversing Your Perimeter?
https://isc.sans.edu/diary/How%20much%20HTTP%20%28not%20HTTPS%29%20Traffic%20is%20Traversing%20Your%20Perimeter%3F/31372
VMSA-2024-0019:VMware vCenter Server updates address heap-overflow and privilege escalation vulnerabilities (CVE-2024-38812, CVE-2024-38813)
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
Unifi Security Advisory Bulletin 043
https://community.ui.com/releases/Security-Advisory-Bulletin-043-043/28e45c75-314e-4f07-a4f3-d17f67bd53f7
Fake attachment. Roundcube mail server attacks exploit CVE-2024-37383 vulnerability.
https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/fake-attachment-roundcube-mail-server-attacks-exploit-cve-2024-37383-vulnerability
Atlassian Security Bulletin - October 15 2024
https://confluence.atlassian.com/security/security-bulletin-october-15-2024-1442910972.html
OneDev Arbitrary file reading for unauthenticated user
https://github.com/theonedev/onedev/security/advisories/GHSA-7wg5-6864-v489
A Network Nerd's Take on Emergency Preparedness
https://isc.sans.edu/diary/A%20Network%20Nerd%27s%20Take%20on%20Emergency%20Preparedness/31356
HM Surf Vulnerability Access to Camera Exploited CVE-2024-44133
https://www.microsoft.com/en-us/security/blog/2024/10/17/new-macos-vulnerability-hm-surf-could-lead-to-unauthorized-data-access/
Fortinet releases patches for undisclosed critical FortiManager vulnerability
https://www.helpnetsecurity.com/2024/10/21/fortimanager-critical-vulnerability/
ScienceLogic Vulnerability
https://rackspace.service-now.com/system_status?id=detailed_status&service=4dafca5a87f41610568b206f8bbb35a6
https://docs.sciencelogic.com/latest/Content/Web_Admin_and_Accounts/System_Administration/sys_admin_system_upgrade.htm
Microsoft 365: Partially incomplete log data due to monitoring agent issue
https://m365admin.handsontek.net/multiple-services-partially-incomplete-log-data-due-to-monitoring-agent-issue/
End-to-End Encrytped Cloud Storage in the Wild: A Broken Ecosystem
https://brokencloudstorage.info/paper.pdf
ESET Branded Malware
https://x.com/ESETresearch/status/1847192384448172387
Synology Update
https://www.synology.com/en-us/security/advisory/Synology_SA_24_17
Spring Framework Update CVe-2024-38819 CVE-2024-38820
https://spring.io/blog/2024/10/17/spring-framework-cve-2024-38819-and-cve-2024-38820-published
Grafana Security Release CVE-2024-9264
https://grafana.com/blog/2024/10/17/grafana-security-release-critical-severity-fix-for-cve-2024-9264/
Scanning Activity from Subnet 15.184.0.0/16.
https://isc.sans.edu/diary/Scanning%20Activity%20from%20Subnet%2015.184.0.0%2016/31362
Gatekeeper Bypass
/unit42.paloaltonetworks.com/gatekeeper-bypass-macos/
Oracle Critical Patch Update
https://www.oracle.com/security-alerts/cpuoct2024.html
Cisco ATA 190 Series Analog Telephone Adapter Firmware Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ata19x-multi-RDTEqRsy
SAP Vulnerability
https://redrays.io/blog/poc-sap-note-3433192-code-injection-vulnerability-in-sap-netweaver-as-java/
Dept. of Commerce Sites Advertising Medication
https://x.com/tliston/status/1833542884047654984
The Top 10 Not So Common SSH Usernames and Passwords
https://isc.sans.edu/diary/The%20Top%2010%20Not%20So%20Common%20SSH%20Usernames%20and%20Passwords/31360
CISA Product Security Bad Practices
https://www.cisa.gov/resources-tools/resources/product-security-bad-practices
Kubernetes Image Builder Vulnerability CVE-2024-9486 CVE-2024-9594
https://discuss.kubernetes.io/t/security-advisory-cve-2024-9486-and-cve-2024-9594-vm-images-built-with-kubernetes-image-builder-use-default-credentials/30119
Solarwinds Hardcoded Password Exploited CVE-2024-28987
https://www.bleepingcomputer.com/news/security/solarwinds-web-help-desk-flaw-is-now-exploited-in-attacks/
Bypassing noexec and executing arbitrary binaries
https://iq.thc.org/bypassing-noexec-and-executing-arbitrary-binaries
Workshop Website:
https://www.sansapi.com/
https://www.sansapi.com/docs
Angular-base64-upload Demo Script Exploited
https://isc.sans.edu/diary/Angular-base64-upload%20Demo%20Script%20Exploited%20%28CVE-2024-42640%29/31354
Quantum Annealing Public Key Cryptographic Attack Algorithm Based on D-Wave Advantage
http://cjc.ict.ac.cn/online/onlinepaper/wc-202458160402.pdf
EDRSilencer
https://github.com/netero1010/EDRSilencer
Synchronizing Passkeys
https://fidoalliance.org/specifications-credential-exchange-specifications/
Phishing Page Delivered Through a Blob URL
https://isc.sans.edu/diary/Phishing%20Page%20Delivered%20Through%20a%20%20Blob%20URL/31350
Fortinet Fortigate CVE 2024-23113 deep dive
https://labs.watchtowr.com/fortinet-fortigate-cve-2024-23113-a-super-complex-vulnerability-in-a-super-secure-appliance-in-2024/
This New Supply Chain Attack Technique Can Trojanize All Your CLI Commands
https://checkmarx.com/blog/this-new-supply-chain-attack-technique-can-trojanize-all-your-cli-commands/
Windows PPTP and L2TP Deprecation
https://techcommunity.microsoft.com/t5/windows-server-news-and-best/pptp-and-l2tp-deprecation-a-new-era-of-secure-connectivity/ba-p/4263956
BIG-IP LTM Systems Unencrypted Cookie Exploitation
https://www.cisa.gov/news-events/alerts/2024/10/10/best-practices-configure-big-ip-ltm-systems-encrypt-http-persistence-cookies
https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/
https://www.welivesecurity.com/en/eset-research/telekopye-hits-new-hunting-ground-hotel-booking-scams/
GPTHoney: A new class of honeypot
https://isc.sans.edu/diary/GPTHoney%3A%20A%20new%20class%20of%20honeypot%20%5BGuest%20Diary%5D/31342
Palo Alto Expedition: From N-Day to Full Compromise
https://www.horizon3.ai/attack-research/palo-alto-expedition-from-n-day-to-full-compromise/
Firefox 0-Day
https://www.mozilla.org/en-US/security/advisories/mfsa2024-51/
GitLab Vulnerabilities Patched
https://securityonline.info/cve-2024-9164-cvss-9-6-gitlab-users-urged-to-update-now/
From Perfctl to InfoStealer
https://isc.sans.edu/diary/From%20Perfctl%20to%20InfoStealer/31334
Wazuh Abused by Miner Campaign
https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/
USB Sticks Still Bridge Airgaps
https://www.welivesecurity.com/en/eset-research/mind-air-gap-goldenjackal-gooses-government-guardrails/
Fortigate Vulnerability now being exploited
https://nvd.nist.gov/vuln/detail/CVE-2024-23113
Microsoft Patch Tuesday - October 2024
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20October%202024/31336
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
The Disappearance of an Internet Domain
https://every.to/p/the-disappearance-of-an-internet-domain
macOS Sequoia: System/Network Admins, Hold On!
https://isc.sans.edu/diary/macOS%20Sequoia%3A%20System%20Network%20Admins%2C%20Hold%20On!/31330
Cisco Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-rv34x-privesc-rce-qE33TCms
Apple iTunes PoC
https://github.com/mbog14/CVE-2024-44193
Attackers used ISP's Wiretap System to Spy on Users
https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835
https://www.bleepingcomputer.com/news/security/atandt-verizon-reportedly-hacked-to-target-us-govt-wiretapping-platform/
Survey of CUPS exploit URLs
https://isc.sans.edu/diary/Survey%20of%20CUPS%20exploit%20attempts/31326
Exposed LDAP Servers
https://www.usenix.org/conference/usenixsecurity24/presentation/kaspereit
Exploiting Visual Studio via Dump Files
https://ynwarcs.github.io/exploiting-vs-dump-files
Apple Security Updates
https://support.apple.com/en-us/100100
Free API Security Workshop
https://www.sans.org/webcasts/aviata-solo-flight-challenge-cloud-security-workshop-chapter-7/
Kickstart Your DShield Honeypot
https://isc.sans.edu/diary/Kickstart%20Your%20DShield%20Honeypot%20%5BGuest%20Diary%5D/31320
CreanaKeeper Use of Cloud Services
https://www.welivesecurity.com/en/eset-research/separating-bee-panda-ceranakeeper-making-beeline-thailand/
Pixel Addressing Vulnerabilities in Cellular Modems
https://security.googleblog.com/2024/10/pixel-proactive-security-cellular-modems.html
Optigo Spectra Vulnerabilities
https://claroty.com/team82/disclosure-dashboard/cve-2024-41925
https://claroty.com/team82/disclosure-dashboard/cve-2024-45367
Security Related Docker Containers
https://isc.sans.edu/diary/Security%20related%20Docker%20containers/31318
CUPS DDoS Attack
https://www.akamai.com/blog/security-research/october-cups-ddos-threat
Draytek Vulnerabilities
https://www.forescout.com/resources/draybreak-draytek-research/
SANS Munich (free Community Night Tuesday October 15th)
https://www.sans.org/cyber-security-training-events/munich-october-2024/
Hurricane Helene Aftermath - Cyber Security Awareness Month
https://isc.sans.edu/diary/Hurricane%20Helene%20Aftermath%20-%20Cyber%20Security%20Awareness%20Month/31314
Zimbra - Remote Command Execution (CVE-2024-45519)
https://blog.projectdiscovery.io/zimbra-remote-code-execution/
Enhancing the security of Microsoft Edge extensions with the new Publish API
https://blogs.windows.com/msedgedev/2024/09/30/enhanced-security-for-extensions-with-new-publish-api/
CVE-2024-36435 Deep-Dive: The Year s Most Critical BMC Security Flaw
https://www.binarly.io/blog/cve-2024-36435-deep-dive-the-years-most-critical-bmc-security-flaw
Tool Update: mac-robber.py, le-hex-to-ip.py
https://isc.sans.edu/diary/Tool%20update%3A%20mac-robber.py%20and%20le-hex-to-ip.py/31310
Ransomware Attacks Expanding to Hybrid Cloud Environments
https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/
Update on Recall Security and Privacy Architecture
https://blogs.windows.com/windowsexperience/2024/09/27/update-on-recall-security-and-privacy-architecture/
Detecting Ransomware in Windows Event Logs
https://blogs.jpcert.or.jp/en/2024/09/windows.html
Progress WhatsUp Gold Update
https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-September-2024?popup=true&overview
Singapore Class
https://jbu.me/singapore
CUPS Vulnerability
https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302
PHP Updates
https://www.php.net/ChangeLog-8.php#8.1.30
DNS And Big Chinese Firewall
https://www.assetnote.io/resources/research/insecurity-through-censorship-vulnerabilities-caused-by-the-great-firewall
https://isc.sans.edu/diary/Are+You+Piratebay+thepiratebayorg+Resolving+to+Various+Hosts/19175
HPE Aruba Networking Vulnerabilities
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04712en_us&docLocale=en_US
Patch for Critical CUPS vulnerability: Don't Panic
https://isc.sans.edu/diary/Patch%20for%20Critical%20CUPS%20vulnerability%3A%20Don%27t%20Panic/31302
DNS Reflection Update and Corrupted DNS Requests
https://isc.sans.edu/diary/DNS%20Reflection%20Update%20and%20Odd%20Corrupted%20DNS%20Requests/31296
CVE-2024-28987 Solarwinds Web Help Desk Hardcoded Credentials Vulnerability
https://www.horizon3.ai/attack-research/cve-2024-28987-solarwinds-web-help-desk-hardcoded-credential-vulnerability-deep-dive/ cve-2024-28987
Watchguard Unauthenticated and Unencrypted SSO Protocol
https://www.redteam-pentesting.de/en/advisories/rt-sa-2024-006/
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014
Infostealers Overcome Chrome's App Bound Encryption
https://securityonline.info/infostealers-overcome-chromes-app-bound-encryption-threatening-user-data-security/
Exploitation of RAISECOM Gateway Devices CVE-2024-7120
https://isc.sans.edu/diary/Exploitation%20of%20RAISECOM%20Gateway%20Devices%20Vulnerability%20CVE-2024-7120/31292
Cellopoint Vulnerability CVE-2024-9043
https://www.twcert.org.tw/en/cp-139-8103-b0568-2.html
Cisco Smart Licensing Vulnerability Details
https://starkeblog.com/cve-wednesday/cisco/2024/09/20/cve-wednesday-cve-2024-20439.html
Ivanti Virtual Traffic Manager Exploited
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
GNU Linux Systems Possible Critical Vulnerability
https://securityonline.info/severe-unauthenticated-rce-flaw-cvss-9-9-in-gnu-linux-systems-awaiting-full-disclosure/
Phishing Links With @ Sign
https://isc.sans.edu/diary/Phishing%20links%20with%20%40%20sign%20and%20the%20need%20for%20effective%20security%20awareness%20building/31288
Kaspersky Deletes Itself Installs UltraAV Antivirus Without Warning
https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/
Microchip ASF tinydhcp Vulnerability
https://kb.cert.org/vuls/id/138043
Windows Server Update Services Deprecation
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-server-update-services-wsus-deprecation/ba-p/4250436
Windows Server 2025 Hotpatches
https://techcommunity.microsoft.com/t5/windows-server-news-and-best/now-in-preview-hotpatch-for-windows-server-2025/ba-p/4248296
Google Suggests Not Using WHOIS for Certificate Validation
https://lists.cabforum.org/pipermail/servercert-wg/2024-September/004821.html
Versa Director Vulnerability
https://security-portal.versa-networks.com/emailbulletins/66e4a8ebda545d61ec2b1ab9
Apache Hugegraph Vulnerability Exploited
https://nvd.nist.gov/vuln/detail/CVE-2024-27348
Fake GitHub Site Targeting Developers
https://isc.sans.edu/diary/Fake%20GitHub%20Site%20Targeting%20Developers/31282
Ivanti CSA 4.6 Advisory
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US
German Police Deanonymizes Tor User
https://blog.torproject.org/tor-is-still-safe/
Ever wonder how crooks get the credentials to unlock stolen phones?
https://arstechnica.com/security/2024/09/cops-bust-website-crooks-used-to-unlock-1-2-million-stolen-mobile-phones/
Python Infostealer Patching Windows Exodus App
https://isc.sans.edu/diary/Python%20Infostealer%20Patching%20Windows%20Exodus%20App/31276
Service Now Knoledge Bases Data Exposures
https://appomni.com/ao-labs/servicenow-knowledge-bases-data-exposures-uncovered/
Gitlab Patch
https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/
Aruba Patch
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&docLocale=en_US
23:59, Time to Exfiltrate!
https://isc.sans.edu/diary/23%3A59%2C%20Time%20to%20Exfiltrate!/31272
Critical VMWare VCenter Vulnerability
https://blogs.vmware.com/cloud-foundation/2024/09/17/vmsa-2024-0019-questions-answers/
Zero-Click Calendar invite - Critical zero-click vulnerability chain in macOS
https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b
Google Adds Latest Post Quantum Encryption Standard to Chrome
https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html
Managing PE Files with Overlays
https://isc.sans.edu/forums/diary/Managing%20PE%20Files%20With%20Overlays/31268/
Apple Updates
https://support.apple.com/en-us/100100
Ivanti EOL Cloud Service Appliances
https://www.cisa.gov/news-events/alerts/2024/09/13/ivanti-releases-security-update-cloud-services-appliance
Microsoft Revises September Update
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-43461
DLink Vulnerabilities
https://www.twcert.org.tw/en/cp-139-8081-3fb39-2.html
https://www.twcert.org.tw/en/cp-139-8091-bcd52-2.html
https://www.twcert.org.tw/en/cp-139-8089-32df6-2.html
Finding Honeypot Clusters Using DBSCAN
https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%202/31194
Auto IT Credential Flusher
https://research.openanalysis.net/credflusher/kiosk/stealer/stealc/amadey/autoit/2024/09/11/cred-flusher.html
Ivanti Patches
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Cloud-Service-Appliance-CSA-CVE-2024-8190?language=en_US
https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29847-deep-dive-ivanti-endpoint-manager-agentportal-deserialization-of-untrusted-data-remote-code-execution-vulnerability/
File Sender Vulnerability
https://filesender.org/vulnerability-in-filesender-versions-below-2-49-and-3-x-beta/
Docker Patches
https://docs.docker.com/desktop/release-notes/#4342
Compromise of old hostname .mobi whois server
https://labs.watchtowr.com/we-spent-20-to-achieve-rce-and-accidentally-became-the-admins-of-mobi/
Microsoft Reconsidering Security Tool API
https://blogs.windows.com/windowsexperience/2024/09/12/taking-steps-that-drive-resiliency-and-security-for-windows-customers/
Microsoft implents PQC in SymCrypt
https://techcommunity.microsoft.com/t5/security-compliance-and-identity/microsoft-s-quantum-resistant-cryptography-is-here/ba-p/4238780
GitLab Patch
https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job
Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20September%202024%20Patch%20Tuesday/31254
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Ivanti Patches
https://forums.ivanti.com/s/article/Security-Advisory-EPM-September-2024-for-EPM-2024-and-EPM-2022?language=en_US
Critical Loadmaster Security Vulnerability
https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591
HA Proxy Patch
https://www.mail-archive.com/haproxy%40formilux.org/msg45280.html
Akira Ransomware Campaign Targeting Sonicwall SSLVPN Accounts
https://arcticwolf.com/resources/blog/arctic-wolf-observes-akira-ransomware-campaign-targeting-sonicwall-sslvpn-accounts/
Kibana Deserializatio Vulnerability
https://discuss.elastic.co/t/kibana-8-15-1-security-update-esa-2024-27-esa-2024-28/366119
Stately Taurus Abuses VSCode
https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/
Password Cracking Energy: More Details
https://isc.sans.edu/diary/Password%20Cracking%20%26%20Energy%3A%20More%20Dedails/31242
Python Notpad ++
https://isc.sans.edu/diary/Python%20%26%20Notepad%2B%2B/31240
Fake LinkedIn Job Ads
https://cloud.google.com/blog/topics/threat-intelligence/examining-web3-heists/
Android Crypto Passphrase Stealer with OCR
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-android-spyagent-campaign-steals-crypto-credentials-via-image-recognition/
Sextortion Scam Now use Your Chating Spouses Name as a Lure
https://www.bleepingcomputer.com/news/security/sextortion-scam-now-use-your-cheating-spouses-name-as-a-lure/
Enrichment Data: Keeping it Fresh
https://isc.sans.edu/diary/Enrichment%20Data%3A%20Keeping%20it%20Fresh/31236
Veeam Update
https://www.veeam.com/kb4649
New OFBiz Vulnerabilities
https://www.rapid7.com/blog/post/2024/09/05/cve-2024-45195-apache-ofbiz-unauthenticated-remote-code-execution-fixed/
Cisco Smart License Manager Patches
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cslu-7gHMzWmw
Scans for Moodle Learning Platform Following Recent Update
https://isc.sans.edu/diary/Scans+for+Moodle+Learning+Platform+Following+Recent+Update/31230
PyPi Rivival HiJack
https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/
Android Updates
https://source.android.com/docs/security/bulletin/2024-09-01
Mediatec WAPPD PoC Exploit
https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html#wrapping-up
Protected OOXML Text Documents
https://isc.sans.edu/diary/Protected%20OOXML%20Text%20Documents/31078
Sextortion E-Mails with Photos
https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/
Zyxel OS Command Injection Vulnerability
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-os-command-injection-vulnerability-in-aps-and-security-router-devices-09-03-2024
D-Link DIR-846W Unpatched RCE Vulnerabilities
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10411
VMWare Priviledge Escalation Vulnerability CVe-2024-38811
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24939
YubiKey Sidechannel Attack
https://ninjalab.io/wp-content/uploads/2024/09/20240903_eucleak.pdf
https://www.yubico.com/support/security-advisories/ysa-2024-03/
Wireshark 4.4: Converting Display Filters to BPF Capture Filters
https://isc.sans.edu/diary/Wireshark+44+Converting+Display+Filters+to+BPF+Capture+Filters/31224
GitHub Comments Used to Spread Malware
https://www.reddit.com/r/Malware/comments/1f2n1h4/comment/lkbi5gi/
Voldemort Malware Curses Orgs Using Global Tax Authorities
https://www.darkreading.com/threat-intelligence/voldemort-malware-curses-orgs-global-tax-authorities
Analysis of CVE-2024-43044 From file read to RCE in Jenkins through agents
https://blog.convisoappsec.com/en/analysis-of-cve-2024-43044/
Live Patching DLLs with Python
https://isc.sans.edu/diary/Live%20Patching%20DLLs%20with%20Python/31218
Global Protect Phishing
https://www.trendmicro.com/en_us/research/24/h/threat-actors-target-middle-east-using-fake-tool.html
BlackByte Ransomware Update
https://blog.talosintelligence.com/blackbyte-blends-tried-and-true-tradecraft-with-newly-disclosed-vulnerabilities-to-support-ongoing-attacks/
The Risks Lurking in Publicly Exposed GenAI Development Services
https://www.legitsecurity.com/blog/the-risks-lurking-in-publicly-exposed-genai-development-services
Finding Lateral Movement of Adversaries Through the Noise of Systems Administration
https://www.sans.edu/cyber-research/finding-lateral-movement-adversaries-through-noise-systems-administration/
YouTube Channel: https://www.youtube.com/c/CyberAttackDefense
Vega-Lite With Kibana To Parse and Display IP Activity Over Time
https://isc.sans.edu/diary/Vega-Lite%20with%20Kibana%20to%20Parse%20and%20Display%20IP%20Activity%20over%20Time/31210
Attack tool update impairs Windows computers
https://news.sophos.com/en-us/2024/08/27/burnt-cigar-2/
Iran-based Cyber Actors Enabling Ransomware Attacks on US Organizations
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a
Confluence Vulnerabilty Exploited for Crypto Miners
https://www.trendmicro.com/en_us/research/24/h/cve-2023-22527-cryptomining.html
Fortra FileCatalyst Workflow Hard Coded HSQLDB Credentials
https://www.fortra.com/security/advisories/product-security/fi-2024-011
Why is Python so Popular to Infect Windows Hosts
https://isc.sans.edu/diary/Why%20Is%20Python%20so%20Popular%20to%20Infect%20Windows%20Hosts%3F/31208
OFBiz Vulnerability Update
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
https://nvd.nist.gov/vuln/detail/CVE-2024-38856
Versa Directory Vulnerability Exploited
https://versa-networks.com/blog/versa-security-bulletin-update-on-cve-2024-39717-versa-director-dangerous-file-type-upload-vulnerability/
Google Chrome Vulnerability Exploited
https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html
SGX Key Leak
https://x.com/_markel___/status/1828112469010596347
From Highly Obfuscated Batch File to XWorm and Redline
https://isc.sans.edu/diary/From%20Highly%20Obfuscated%20Batch%20File%20to%20XWorm%20and%20Redline/31204
CVE-2024-38063 Windows IPv6 Issue PoC Exploit
https://github.com/ynwarcs/CVE-2024-38063
Not a vulnerability
https://github.com/juwenyi/CVE-2024-42992
Pandas Erros: What encoding are my logs in?
https://isc.sans.edu/diary/Pandas%20Errors%3A%20What%20encoding%20are%20my%20logs%20in%3F/31200
Crowdstrike Performance Issues
https://www.reddit.com/r/sysadmin/comments/1eyfex6/at_least_its_not_on_a_friday/
CopyBara Malware
https://www.zscaler.com/blogs/security-research/technical-analysis-copybara#conclusion
SonicWall Vulnerability
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0015
OpenAI Scans Honeypots
https://isc.sans.edu/diary/OpenAI%20Scans%20for%20Honeypots.%20Artificially%20Malicious%3F%20Action%20Abuse%3F/31196
Broken Linux Boot Partitions after August Microsoft Update
https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-23H2#3377msgdesc
Google Fixes Chrome 0-day
https://chromereleases.googleblog.com/2024/08/stable-channel-update-for-desktop_21.html
Cisco Zero Day Exploited (now Patched)
https://www.sygnia.co/blog/china-threat-group-velvet-ant-cisco-zero-day/
Solar Winds Helpdesk Backdoor
https://support.solarwinds.com/SuccessCenter/s/article/SolarWinds-Web-Help-Desk-12-8-3-Hotfix-2
Securing the Future: How Memory-Safe Programming Languages Impact Industry Safety (Christopher Ross)
https://www.sans.edu/cyber-research/securing-future-how-memory-safe-programming-languages-impact-industry-safety/
Mapping Threats wiht DNSTwist and the Internet Storm Center
https://isc.sans.edu/diary/Mapping%20Threats%20with%20DNSTwist%20and%20the%20Internet%20Storm%20Center%20%5BGuest%20Diary%5D/31188
Slack AI Prompt Injection
https://promptarmor.substack.com/p/slack-ai-data-exfiltration-from-private
Phishing in PWA Applications
https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/
QNAP Ransomware Security Center
https://www.qnap.com/en/news/2024/qnap-officially-releases-qts-5-2-introducing-security-center-for-active-file-activity-monitoring-elevated-security-and-data-protection
Where are we with CVE-2024-38063: Microsoft IPv6 Vulnerability
https://isc.sans.edu/diary/Where+are+we+with+CVE202438063+Microsoft+IPv6+Vulnerability/31186
Microsoft August Update Prevents Linux from Booting
https://community.frame.work/t/sbat-verification-error-booting-linux-after-windows-update/56354
PHP CGI Vulnerability Exploited CVE-2024-4577
https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns
F5 Updates
https://my.f5.com/manage/s/article/K000140111
https://my.f5.com/manage/s/article/K000140108
Do you like donuts? Here is a donut Shellcode Delivered Through PowerShell Python
https://isc.sans.edu/diary/Do%20you%20Like%20Donuts%3F%20Here%20is%20a%20Donut%20Shellcode%20Delivered%20Through%20PowerShell%20Python/31182
How Vulnerabilities in Microsoft Apps for MacOS allow Stealing Permissions
https://blog.talosintelligence.com/how-multiple-vulnerabilities-in-microsoft-apps-for-macos-pave-the-way-to-stealing-permissions/
Digital Wallet Security Loophole
https://www.umass.edu/news/article/new-study-reveals-loophole-digital-wallet-security-even-if-rightful-cardholder-doesnt
Microsoft IPv6 Vulnerability CVE-2024-38063
https://x.com/f4rmpoet/status/1825472703223992323
YouTube Video (going live 10am ET)
https://www.youtube.com/watch?v=miBb1llFOYQ
Summarizing Web Honeypot Logs
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%207%20minutes%20and%204%20steps%20to%20a%20quick%20win%3A%20A%20write-up%20on%20custom%20tools/31170
Large Scale Cloud Extortion Operation
https://unit42.paloaltonetworks.com/large-scale-cloud-extortion-operation/
Chrome Redacting Credit Cards and Passwords when you share Android Screens
https://www.bleepingcomputer.com/news/google/chrome-will-redact-credit-cards-passwords-when-you-share-android-screen/
Google Products Targeted by Search Ad Scammers
https://www.malwarebytes.com/blog/scams/2024/08/dozens-of-google-products-targeted-by-scammers-via-malicious-search-ads
MakeShift: Security Analysis of Shimano Di2 Wireless Gear Shifting in Bicyles
https://www.usenix.org/system/files/woot24-motallebighomi.pdf
Wireshark 4.4.0 rc 1 Custom Columns
https://isc.sans.edu/diary/Wireshark%204.4.0rc1%27s%20Custom%20Columns/31174
Github Repo Artifact Leak Tokens
https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/
BitLocker Security Feature Bypass Vulnerability
https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-38058
Solarwindws Hotfix
https://support.solarwinds.com/SuccessCenter/s/article/WHD-12-8-3-Hotfix-1
Ed Skoudis, Paul Maurer: The Code of Honor
https://cybercodeofhonor.com/
MSI Malware
https://isc.sans.edu/diary/Multiple%20Malware%20Dropped%20Through%20MSI%20Package/31168
Microsoft IPv6 Vulnerablity CVE-2024-38063
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38063
https://x.com/XiaoWei___/status/1823532146679799993/photo/1
Critical Ivanti Virtual Traffic Manager Patch CVE-2024-7593
https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2024-7593?language=en_US
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Microsoft August 2024 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20August%202024%20Patch%20Tuesday/31164
NIST Finalizes Post Quantum Encryption Standards
https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
Zabbix Network Monitoring Updates
https://support.zabbix.com/browse/ZBX-25016
https://support.zabbix.com/browse/ZBX-25013
(and others)
QuickShell: Sharing is Caring about an RCE Attack Chain on Quick Share
https://www.safebreach.com/blog/rce-attack-chain-on-quick-share
Chrome, Edge users beset by malicious extensions that can t be easily removed
https://www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/
AMD Guest Memory Vulnerabilities
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html
CORS/SameOrigin Video
https://isc.sans.edu/forums/diary/Video%3A%20Same%20Origin%2C%20CORS%2C%20DNS%20Rebinding%20and%20Localhost/31158/
Splitting the email atom: exploiting parsers to bypass access controls
https://portswigger.net/research/splitting-the-email-atom#parser-discrepancies
Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
https://blog.orange.tw/2024/08/confusion-attacks-en.html
GL-Inet Patches
https://www.gl-inet.com/security-updates/security-advisories-vulnerabilities-and-cves-aug-1-2024/
Microsoft Office Spoofing Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38200
Exploring Anti-Phishing Measures in Microsoft 365
https://certitude.consulting/blog/en/o365-anti-phishing-measures/
SSHamble Security Testing Tool
https://www.runzero.com/blog/sshamble-unexpected-exposures-in-the-secure-shell/
macOS Sequoia Weekly Permission Prompts
https://9to5mac.com/2024/08/06/macos-sequoia-screen-recording-privacy-prompt/
.internal domain
https://www.icann.org/en/public-comment/proceeding/proposed-top-level-domain-string-for-private-use-24-01-2024
0.0.0.0 Day Exploiting Localhost APIs from the Browser
https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser
Apple Hardens Gatekeeper
https://developer.apple.com/news/?id=saqachfa
Downgrade Attacks Using Windows Updates
https://www.safebreach.com/blog/downgrade-attacks-using-windows-updates/
A Survey of Scans For GeoServer Vulnerabilities
https://isc.sans.edu/diary/A%20Survey%20of%20Scans%20for%20GeoServer%20Vulnerabilities/31148
Crowdstrike Root Cause Analysis
https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/
Kibana Vulnerability
https://discuss.elastic.co/t/kibana-8-14-2-7-17-23-security-update-esa-2024-22/364424
Android August 2024 Bulletin
https://source.android.com/docs/security/bulletin/2024-08-01
Ubiquity Amplication Attack Vulnerability Update
https://blog.checkpoint.com/research/over-20000-ubiquiti-cameras-and-routers-are-vulnerable-to-amplification-attacks-and-privacy-risks/
Script Obfuscation Using Multiple Instances of the Same Function
https://isc.sans.edu/diary/Script%20obfuscation%20using%20multiple%20instances%20of%20the%20same%20function/31144
Disclosure of key technical details of CrowdStrike's large-scale blue screen
https://mp.weixin.qq.com/s/uD7mhzyRSX1dTW-TMg4UhQ
New OFBiz Vulnerability
https://issues.apache.org/jira/browse/OFBIZ-13128
https://www.youtube.com/watch?v=J_IxCBjd4Pw
Roundcube XSS Vulnerabilities
https://securityonline.info/roundcube-webmail-releases-security-updates-to-patch-multiple-vulnerabilities/
Current Secure Boot Certifiate Authority Expires in 2026
https://isc.sans.edu/diary/Even+Linux+users+should+take+a+look+at+this+Microsoft+KB+article/31140
OOXML Spreadsheets Protected by Verifier Hashes
https://isc.sans.edu/diary/OOXML%20Spreadsheets%20Protected%20By%20Verifier%20Hashes/31072
StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms
https://www.volexity.com/blog/2024/08/02/stormbamboo-compromises-isp-to-abuse-insecure-software-update-mechanisms/
DARPA TRACTOR Program for Translating C to Rust
https://www.darpa.mil/news-events/2024-07-31a
Tracking Proxy Scans with IPv4.Games
https://isc.sans.edu/diary/Tracking%20Proxy%20Scans%20with%20IPv4.Games/31136
Threat Actor Impersonates Google via Fake Ad For Authenticator
https://www.malwarebytes.com/blog/news/2024/07/threat-actor-impersonates-google-via-fake-ad-for-authenticator
Who Knew? Domain Hijacking is so easy
https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/
Increased Activity Against Apache OFBiz CVS-2024-32113
https://isc.sans.edu/diary/Increased%20Activity%20Against%20Apache%20OFBiz%20CVE-2024-32113/31132
Digicert Certificate Revocation Incident
https://www.digicert.com/support/certificate-revocation-incident
Microsoft Azure Outage
https://azure.status.microsoft/en-us/status/history/
Improving Security of Chrome Cookies
https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html
Apple Updates Everything: July 2024 Edition
https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20July%202024%20Edition/31128
VMWare ESXi Vulnerability Actively Exploited CVE-2024-37085
https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/
Weak VoWiFi Encryption CVE-2024-22064
https://idw-online.de/en/news837652
CrowdStrike Outage Themed Maldoc
https://isc.sans.edu/diary/CrowdStrike%20Outage%20Themed%20Maldoc/31116
HotJar XSS Puts OAuth at Risk
https://salt.security/blog/over-1-million-websites-are-at-risk-of-sensitive-information-leakage---xss-is-dead-long-live-xss
Proofpoint Echospoofing
https://labs.guard.io/echospoofing-a-massive-phishing-campaign-exploiting-proofpoints-email-protection-to-dispatch-3dd6b5417db6
ExelaStealer Delivered "From Russia With Love"
https://isc.sans.edu/diary/31118
Create Your Own BSOD: NotMyFault
https://isc.sans.edu/diary/Create%20Your%20Own%20BSOD%3A%20NotMyFault/31120
PKFail Vulnerability
https://pk.fail/
CrowdStrike Recovery
https://arstechnica.com/information-technology/2024/07/97-of-crowdstrike-systems-are-back-online-microsoft-suggests-windows-changes/
X-Worm Hidden With Process Hollowing
https://isc.sans.edu/diary/XWorm%20Hidden%20With%20Process%20Hollowing/31112
Anyone Can Access Deleted and Private Repo Data on GitHub
https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github
Google Chrome Scanning Encrypted Files
https://arstechnica.com/security/2024/07/google-overhauls-chromes-safe-browsing-protection-to-scan-password-protected-files/
"Mouse Logger" Malicious Python Script
https://isc.sans.edu/diary/%22Mouse%20Logger%22%20Malicious%20Python%20Script/31106
Crowdstrike Preliminary Post Incident Review
https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/
How a North Korean Fake IT Worker Tried to Infiltrate Us
https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us
New Exploit Variation Against D-Link NAS Devices
https://isc.sans.edu/diary/New%20Exploit%20Variation%20Against%20D-Link%20NAS%20Devices%20%28CVE-2024-3273%29/31102
APKs Masquerading as Videos on Telegram
https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/
Goodbye Attackers can Bypass Windows Hello Strong Authentication
https://www.darkreading.com/endpoint-security/goodbye-attackers-can-bypass-windows-hello-strong-authentication
Let's Encrypt Intends to End OCSP Service
https://letsencrypt.org/2024/07/23/replacing-ocsp-with-crls.html
Google Third-Party Cookies are hanging around
https://privacysandbox.com/intl/en_us/news/privacy-sandbox-update/
CrowdStrike Update
https://isc.sans.edu/diary/CrowdStrike%3A%20The%20Monday%20After/31098
https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/
Keynote Recording
https://www.sans.org/services/video-player/?key=1goL2vPrltnj
Widespread Windows Crashes Due to Crowdstrike Updates
https://isc.sans.edu/diary/Widespread%20Windows%20Crashes%20Due%20to%20Crowdstrike%20Updates/31094
https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/
https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/
https://techcommunity.microsoft.com/t5/intune-customer-success/new-recovery-tool-to-help-with-crowdstrike-issue-impacting/ba-p/4196959
Oracle Quarterly Critical Patch Update
https://www.oracle.com/security-alerts/cpujul2024.html
Exchange Online Implementing Inbound SMTP DANE with DNSSEC
https://techcommunity.microsoft.com/t5/exchange-team-blog/announcing-public-preview-of-inbound-smtp-dane-with-dnssec-for/ba-p/4155257
VPN Port Shadowing Vulnerability
https://petsymposium.org/popets/2024/popets-2024-0070.pdf
Who You Gonna Call: Androx Gh0st Busters!
https://isc.sans.edu/diary/Who%20You%20Gonna%20Call%3F%20AndroxGh0st%20Busters!%20%5BGuest%20Diary%5D/31086
Cisco Smart Software Manager Vulnerability CVE-2024-20419
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-auth-sLw3uhUy
Critical Security Flaw in Cisco Secure Email Gateway: CVE-2024-20401
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-afw-bGG2UsjH
Microsoft Introducing Checkpoint Updates
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/introducing-windows-11-checkpoint-cumulative-updates/ba-p/4182552
GeoServer Patches
https://github.com/geoserver/geoserver/security/advisories/GHSA-6jj6-gm7p-fcvv
Reply Chain Phishing With a Twist
https://isc.sans.edu/diary/%22Reply-chain%20phishing%22%20with%20a%20twist/31084
Claroty TP-Link and Synology IP Camera Exploits
https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera
https://claroty.com/team82/research/pwn2own-wan-to-lan-exploit-showcase
Cosmic Sting Hits Adobe Commerce Stores
https://sansec.io/research/cosmicsting-hitting-major-stores
Protected OOXML Spreadsheets
https://isc.sans.edu/diary/Protected%20OOXML%20Spreadsheets/31070
Leaked PyPi Secret Token Revealed in Binary
https://jfrog.com/blog/leaked-pypi-secret-token-revealed-in-binary-preventing-suppy-chain-attack/
Microsoft 365 Defender Affected by June Update
https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#network-data-reporting-from-microsoft-365-defender-may-be-interrupted
16-Bit Hash Collisions in XLS Spreadsheets
https://isc.sans.edu/diary/16-bit%20Hash%20Collisions%20in%20.xls%20Spreadsheets/31066
Attacks against the "Nette" PHP framework CVE-2020-15227
https://isc.sans.edu/forums/diary/Attacks+against+the+Nette+PHP+framework+CVE202015227/31076/
Squarespace Hijacked Domains
https://github.com/security-alliance/advisories/blob/main/2024-07-squarespace.pdf
Understanding SSH Honeypot Logs: Attackers Fingerprinting Honeypots
https://isc.sans.edu/diary/Understanding%20SSH%20Honeypot%20Logs%3A%20Attackers%20Fingerprinting%20Honeypots/31064
Patch or Peril: A Veeam Vulnerability Incident
https://www.group-ib.com/blog/estate-ransomware/
Juniper Patches
https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&f:ctype=[Security%20Advisories]
VMWare Aria Automation SQL Injection Vuln;
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24598
Leaked SMS Messages
https://www.ccc.de/de/updates/2024/2fa-sms
Finding Honeypot Data Clusters Using DBSCAN Part 1
https://isc.sans.edu/diary/Finding%20Honeypot%20Data%20Clusters%20Using%20DBSCAN%3A%20Part%201/31050
Second RegreSSHion Like OpenSSH Vulnerability
https://lwn.net/ml/all/20240708162106.GA4920@openwall.com/
Resurrecting Internet Explorer: Threat Actors Using Zero-Day Tricks in Internet Shortcut File CVE-2024-38112
https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/
SharePoint Proof of Concept Exploit CVE-2024-38094 CVE-2024-38024 CVE-2024-38023
https://github.com/testanull/MS-SharePoint-July-Patch-RCE-PoC/blob/main/poc_filtered.py
Citrix Netscaler, Agent and SDX Security Bulletin CVE-2024-6235 CVE-2024-6236
https://support.citrix.com/article/CTX677998/netscaler-console-agent-and-sdx-security-bulletin-for-cve20246235-and-cve20246236
OpenVPN Updates
https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/
Microsoft Patch Tuesday July 2024
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20July%202024/31058
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
RADIUS protocol susceptible to forgery attacks
https://kb.cert.org/vuls/id/456537
https://www.inkbridgenetworks.com/blastradius/faq
Kunai: Keep an Eye on your Linux Hosts Activity
https://isc.sans.edu/diary/Kunai%3A%20Keep%20an%20Eye%20on%20your%20Linux%20Hosts%20Activity/31054
Decryptor for DoNex Ransomware
https://decoded.avast.io/threatresearch/decrypted-donex-ransomware-and-its-predecessors/
Shelltorch Explained: Multiple Vulnerabilities in Pytorch Model Server (Torchserve)
https://www.oligo.security/blog/shelltorch-explained-multiple-vulnerabilities-in-pytorch-model-server
Exim Bypass Attachment Inspection
https://bugs.exim.org/show_bug.cgi?id=3099#c4
Toshiba/Sharp Printer vulnerabilities
https://pierrekim.github.io/blog/2024-06-27-toshiba-mfp-40-vulnerabilities.html
https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html
OpenSSH RegreSSHion Vulnerability
https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
https://isc.sans.edu/diary/SSH%20%22regreSSHion%22%20Remote%20Code%20Execution%20Vulnerability%20in%20OpenSSH./31046
Overlooked Domain Name Resliency Issues: Registrar Communications
https://isc.sans.edu/diary/Overlooked%20Domain%20Name%20Resiliency%20Issues%3A%20Registrar%20Communications/31048
Cloudflare 1.1.1.1 incident on Juine 27th 2024
https://blog.cloudflare.com/cloudflare-1111-incident-on-june-27-2024
What Setting Live Traps For Cybercriminals Taught Me About Security
https://isc.sans.edu/diary/What%20Setting%20Live%20Traps%20for%20Cybercriminals%20Taught%20Me%20About%20Security%20%5BGuest%20Diary%5D/31038
TeamViewer Compromise
https://www.teamviewer.com/en-us/resources/trust-center/statement/
Fortra File Catalyst Vulnerability and PoC
https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability-YmYwYWY4OTYtNTUzMi1lZjExLTg0MGEtNjA0NWJkMDg3MDA0
https://www.tenable.com/security/research/tra-2024-25
GitLab Critical Update
https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/
When Prompts Go Rogue: Analyzing a Prompt Injection Code Execution in Vanna.AI
https://jfrog.com/blog/prompt-injection-attack-code-execution-in-vanna-ai-cve-2024-5565/
Critical Progress MOVEit Authentication Bypass Vulnerability
https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/
https://community.progress.com/s/article/MOVEit-Transfer-Product-Security-Alert-Bulletin-June-2024-CVE-2024-5806
Polyfill.io Supply Chain Attack
https://cside.dev/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack
Apple AirPods Firmware Update
https://support.apple.com/en-us/HT214111
TCP Latency Sidechannel
https://www.snailload.com/snailload.pdf
Microsoft Management Console for Intial Access and Evasion
https://www.elastic.co/security-labs/grimresource
Wyze Camera Vulnerabilities
https://forums.wyze.com/t/security-advisory/289256
Configuration Scans Expand
https://isc.sans.edu/diary/Configuration%20Scanners%20Adding%20Java%20Specific%20Configuration%20Files/31032
SQL Server Emergency Fix
https://support.microsoft.com/en-us/topic/june-20-2024-kb5041054-os-build-20348-2529-out-of-band-b746ffbd-934e-42ac-9c66-ed0636edf7f1
Juniper Security Analytics Update
https://supportportal.juniper.net/s/article/On-Demand-JSA-Series-Multiple-vulnerabilities-resolved-in-Juniper-Secure-Analytics-in-7-5-0-UP8-IF03?language=en_US
MacOS/iOS XNU Buffer Overflow Exploit CVE-2024-27815
https://jprx.io/cve-2024-27815/
Sysinternals Process Monitor Version 4 Released
https://isc.sans.edu/diary/Sysinternals%27%20Process%20Monitor%20Version%204%20Released/31026
Kaspersky Sanctions
https://home.treasury.gov/news/press-releases/jy2420
Phoenix UEFI Buffer Overflow Affects Wide Range of Systems
https://eclypsium.com/blog/ueficanhazbufferoverflow-widespread-impact-from-vulnerability-in-popular-pc-and-server-firmware/
Ghostscript Update
https://ghostscript.readthedocs.io/en/gs10.03.1/News.html
js2py vulnerability
https://github.com/Marven11/CVE-2024-28397-js2py-Sandbox-Escape
No Excuses: Free Tools to Help Secure Authentication in Ubuntu
https://isc.sans.edu/diary/No%20Excuses%2C%20Free%20Tools%20to%20Help%20Secure%20Authentication%20in%20Ubuntu%20Linux%20%5BGuest%20Diary%5D/31024
Handling BOM MIME Files
https://isc.sans.edu/diary/Handling+BOM+MIME+Files/31022
Atlasiun Confluence Data Center and Server Vuln
https://confluence.atlassian.com/security/security-bulletin-june-18-2024-1409286211.html
Beyond the @ Symbol: Exploiting the Flexibility of Email Addresses For Offensive Purposes
https://modzero.com/en/blog/beyond_the_at_symbol/
VMWare Patches
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24453
New NetSupport Campaign Deleivered Through MSIX Packages
https://isc.sans.edu/diary/New%20NetSupport%20Campaign%20Delivered%20Through%20MSIX%20Packages/31018
D-Link Router Backdoor
https://www.twcert.org.tw/en/cp-139-7880-629f5-2.html
https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10398
iTerm2 Vulnerablity
https://vin01.github.io/piptagole/escape-sequences/iterm2/rce/2024/06/16/iterm2-rce-window-title-tmux-integration.html
NextCloud Vulnerability
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9v72-9xv5-3p7c
Overview of My Tools That Handle JSON Data
https://isc.sans.edu/diary/Overview%20of%20My%20Tools%20That%20Handle%20JSON%20Data/31012
Python Serialization and "Sleepy Pickle"
https://x.com/MarkBaggett/status/1801732554740969561
Detecting Headless Chrome
https://deviceandbrowserinfo.com/learning_zone/articles/detecting-headless-chrome-puppeteer-2024
Detecting Malicious VS Code Extensions
https://medium.com/@amitassaraf/4-6-introducing-extensiontotal-how-to-assess-risk-in-vs-code-extensions-3ac5bfd83fb1
ASUS Router Critical Vulnerability
https://www.asus.com/content/asus-product-security-advisory/
The Art of JQ and Command-Line Fu
https://isc.sans.edu/diary/The%20Art%20of%20JQ%20and%20Command-line%20Fu%20%5BGuest%20Diary%5D/31006
Microsoft Outlook Vulnerablity Details
https://blog.morphisec.com/cve-2024-30103-microsoft-outlook-vulnerability
Keeping our Outlook Personal Email Users Safe
https://techcommunity.microsoft.com/t5/outlook-blog/keeping-our-outlook-personal-email-users-safe-reinforcing-our/ba-p/4164184
Exploiting ML models with pickle file attacks
https://blog.trailofbits.com/2024/06/11/exploiting-ml-models-with-pickle-file-attacks-part-1/
MSMQ Packets
https://isc.sans.edu/diary/Port%201801%20Traffic%3A%20Microsoft%20Message%20Queue/31004
Adobe Updates
https://helpx.adobe.com/security/products/magento/apsb24-40.html
Black Basta Exploited CVE-2024-26169 Prior to Patch
https://symantec-enterprise-blogs.security.com/threat-intelligence/black-basta-ransomware-zero-day
Pixel Phone 0-Day Patched
https://source.android.com/docs/security/bulletin/pixel/2024-06-01
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20June%202024/31000
JetBrains IntelliJ Based IDE GitHub Plugin Vulnerability
https://blog.jetbrains.com/security/2024/06/updates-for-security-issue-affecting-intellij-based-ides-2023-1-and-github-plugin/
Veeam Recovery Orchestrator (VRO) vulnerability CVE-2024-29855
https://www.veeam.com/kb4585
Precor Threadmill Vulnerablity
https://securityintelligence.com/x-force/internet-connected-treadmill-vulnerabilities-discovered/
Veeam Exploit CVE-2024-29849
https://summoning.team/blog/veeam-enterprise-manager-cve-2024-29849-auth-bypass/
SORBS Shutdown
https://www.theregister.com/2024/06/07/sorbs_closed/
Rogue Cell Tower Shut Down in London
https://www.cityoflondon.police.uk/news/city-of-london/news/2024/june/two-people-arrested-in-connection-with-investigation-into-homemade-mobile-antenna-used-to-send-thousands-of-smishing-text-messages-to-the-public/
Malicious Comfyui Modules
https://www.youtube.com/watch?v=ntwGHjBCbeQ
PHP Unicode Remote Code Execution Exploit
https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/
PyTorch Distributed RPC Framework Remote Code Execution
https://huntr.com/bounties/39811836-c5b3-4999-831e-46fee8fcade3
https://www.cve.org/CVERecord?id=CVE-2024-5480
Malicious VSCode Extensions Used by Researchers
https://www.bleepingcomputer.com/news/security/malicious-visual-studio-code-extensions-with-millions-of-installs-discovered/
Malicious Python Script with a "Best Before" Date
https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20%22Best%20Before%22%20Date/30988
FBI Obtained 7,000 LockBit Ransomware Keys
https://www.fbi.gov/news/speeches/fbi-cyber-assistant-director-bryan-vorndran-s-remarks-at-the-2024-boston-conference-on-cyber-security
Apple Guarantees 5 Years of Security Updates
https://www.androidauthority.com/iphone-software-support-commitment-3449135/
FCC Proposes New Rule for Security Routing
https://www.fcc.gov/document/fcc-proposes-internet-routing-security-reporting-requirements
WatchGuard VPN Brutefording
https://isc.sans.edu/diary/Brute%20Force%20Attacks%20Against%20Watchguard%20VPN%20Endpoints/30984
TotalRecall Tool To Extract Data from Microsoft Recall
https://github.com/xaitax/TotalRecall
WebEx Flaw
https://www.helpnetsecurity.com/2024/06/05/cisco-webex-cloud-vulnerability/
https://netzbegruenung.de/blog/netzbegruenung-findet-schwachstellen-auch-im-cisco-webex-clouddienst-behoerden-und-unternehmen-in-ganz-europa-betroffen/ (in german)
No Defender Yes Defender
https://isc.sans.edu/diary/No-Defender%2C%20Yes-Defender/30980
Fake Job Ads Lead to Stolen Crypto Currency
https://www.ic3.gov/Media/Y2024/PSA240604
Zyxel NAS Vulnerabilities
https://outpost24.com/blog/zyxel-nas-critical-vulnerabilities/
A Wireshark Lua Dissector for Fixed Field Length Protocols
https://isc.sans.edu/diary/A%20Wireshark%20Lua%20Dissector%20for%20Fixed%20Field%20Length%20Protocols/30976
COX Cable Modem Admin API Weakness
https://samcurry.net/hacking-millions-of-modems
Malicous Stack Overflow Answers
https://www.bleepingcomputer.com/news/security/cybercriminals-pose-as-helpful-stack-overflow-users-to-push-malware/
Atlasian Confluence Data Center and SErver Remote Code Execution Vuln CVE-2024-21683
https://blog.sonicwall.com/en-us/2024/05/confluence-data-center-and-server-remote-code-execution-vulnerability/
K1w1 Infostealer Uses gofile.io for Exfiltration
https://isc.sans.edu/diary/%22K1w1%22%20InfoStealer%20Uses%20gofile.io%20for%20Exfiltration/30972
Kaspersky Linux Malware Scanner
https://www.kaspersky.com/blog/kvrt-for-linux/51375/
Snowflake Incident
https://www.helpnetsecurity.com/2024/06/01/snowflake-breach-data-theft/
HuggingFace Space Secrets Leak
https://huggingface.co/blog/space-secrets-disclosure
Feeding MISP with OSSEC
https://isc.sans.edu/diary/Feeding%20MISP%20with%20OSSEC/30968
Checkpoint VPN
https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/
The Pumpkin Eclipse
https://blog.lumen.com/the-pumpkin-eclipse/
Michael Dunking: Detecting Cypher Injection with Open-Source Network Intrusion Detection
https://www.sans.edu/cyber-research/detecting-cypher-injection-with-open-source-network-intrusion-detection/
Is that It? Finding the Unknown: Correlations Between Honeypot Logs and PCAPs
https://isc.sans.edu/diary/Is%20that%20It%3F%20%20Finding%20the%20Unknown%3A%20Correlations%20Between%20Honeypot%20Logs%20%26%20PCAPs%20%5BGuest%20Diary%5D/30962
Checkpoint 0-Day
https://blog.checkpoint.com/security/enhance-your-vpn-security-posture
Okta warns of Credential Stuffing Against Customer Identity Cloud
https://sec.okta.com/articles/2024/05/detecting-cross-origin-authentication-credential-stuffing-attacks
Brute Forcing Old Bitcoin Wallet Password
https://www.youtube.com/watch?v=o5IySpAkThg
Preventing SQL Injection with Python
https://www.youtube.com/watch?v=1cQy9N1Xndk
PoC Exploit for CVE-2024-23108 in Fortinet FortiSIEM
https://www.horizon3.ai/attack-research/cve-2024-23108-fortinet-fortisiem-2nd-order-command-injection-deep-dive/
ShrinkLocker: Turning BitLocker into ransomware
https://securelist.com/ransomware-abuses-bitlocker/112643/
iconv buffer overflow PoC 2024-2961
https://github.com/ambionics/cnext-exploits/
PoC for Apple Priv. Escalation bug CVE-2024-27842
https://github.com/wangtielei/POCs/tree/main/CVE-2024-27842
https://x.com/WangTielei
Files with TGZ Extension used as malspam attachements
https://isc.sans.edu/diary/Files%20with%20TXZ%20extension%20used%20as%20malspam%20attachments/30958
Google 0-Day
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_23.html
Google Stops Trusting Globaltrust CA
https://groups.google.com/a/ccadb.org/g/public/c/wRs-zec8w7k/m/G_9QprJ2AQAJ
Checkpoint warns of password bruteforcing
https://blog.checkpoint.com/security/enhance-your-vpn-security-posture?campaign=checkpoint&eid=guvrs&advisory=1
SEC522: Defending Web Applications
isc.sans.edu/j/sec522
Analysis of 'redtail' file uploads to ISC Honeypot
https://isc.sans.edu/diary/Analysis%20of%20%3Fredtail%3F%20File%20Uploads%20to%20ICS%20Honeypot%2C%20a%20Multi-Architecture%20Coin%20Miner%20%5BGuest%20Diary%5D/30950
Veeam Vulnerablity
https://www.veeam.com/kb4581
C-Root Server Lost Touch With Peers
https://arstechnica.com/security/2024/05/dns-glitch-that-threatened-internet-stability-fixed-cause-remains-unclear/
Ivanti Vulnerabilities
https://forums.ivanti.com/s/article/Avalanche-6-4-3-602-additional-security-hardening-and-CVE-fixed?language=en_US
Justice AV Solutions Software Backdoor
https://www.rapid7.com/blog/post/2024/05/23/cve-2024-4978-backdoored-justice-av-solutions-viewer-software-used-in-apparent-supply-chain-attack/
NMAP Scanning Without Scanning - The ipinfo API
https://isc.sans.edu/diary/NMAP%20Scanning%20without%20Scanning%20%28Part%202%29%20-%20The%20ipinfo%20API/30948
Why Your WiFi Router Doubles As An Apple Airtag
https://krebsonsecurity.com/2024/05/why-your-wi-fi-router-doubles-as-an-apple-airtag/#more-67551
https://account.microsoft.com/privacy/location-services-opt-out
https://answers.microsoft.com/en-us/windows/forum/all/wifi-sense-my-ssid-includes-optout-why-do-windows/1453142a-755a-476f-aa48-56d05b89e33c
https://www.computerworld.com/article/1484722/here-s-how-to-opt-out-of-google-s-wi-fi-snooping.html
https://www.privacy.org.nz/publications/commissioner-inquiries/google-s-collection-of-wifi-information-during-street-view-filming/
Scanning without Scanning with nmap
https://isc.sans.edu/diary/Scanning%20without%20Scanning%20with%20NMAP%20%28APIs%20FTW%29/30944
iTerm2 Vulnerablities
https://vin01.github.io/piptagole/escape-sequences/iterm2/hyper/url-handlers/code-execution/2024/05/21/arbitrary-url-schemes-terminal-emulators.html
GitHub Enterprise Vulnerablity CVE-2024-4985
https://nvd.nist.gov/vuln/detail/CVE-2024-4985
BitBucket Pipelines Leaking Secrets
https://cloud.google.com/blog/topics/threat-intelligence/bitbucket-pipeline-leaking-secrets
Microsoft Recall Privacy
https://www.microsoft.com/en-us/windows/copilot-plus-pcs?r=1#faq1
Analyzing MSG Files
https://isc.sans.edu/diary/Analyzing%20MSG%20Files/30940
Linguistic Lumberjack: Fluent Bit Vulnerability CVE-2024-4323
https://www.tenable.com/blog/linguistic-lumberjack-attacking-cloud-services-via-logging-endpoints-fluent-bit-cve-2024-4323
Fortinet FortiSIEM Command Injection Deep-Dive CVE-2023-23992
https://www.horizon3.ai/attack-research/cve-2023-34992-fortinet-fortisiem-command-injection-deep-dive/
Git Vulnerability CVE-2024-32002 PoC
https://amalmurali.me/posts/git-rce/
Google Chrome CVE-2024-4947 PoC
https://buptsb.github.io/blog/post/CVE-2024-4947-%20v8%20incorrect%20AccessInfo%20for%20module%20namespace%20object%20causes%20Maglev%20type%20confusion.html
Another PDF Streams Example: Extracting JPEGs
https://isc.sans.edu/diary/Another%20PDF%20Streams%20Example%3A%20Extracting%20JPEGs/30924
QNAP QTS QNAPping At the Wheel
https://labs.watchtowr.com/qnap-qts-qnapping-at-the-wheel-cve-2024-27130-and-friends/
May 2024 Security Update Problems with Windows 2019
https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-1809-and-windows-server-2019#3299msgdesc
Dlink Vulnerabilities Exploited
https://www.cisa.gov/news-events/alerts/2024/05/16/cisa-adds-three-known-exploited-vulnerabilities-catalog
Ivanti PoC Exploit CVE 2024-22026
https://www.redlinecybersecurity.com/blog/exploiting-cve-2024-22026-rooting-ivanti-epmm-mobileiron-core
Why yq? Adventurs in XML
https://isc.sans.edu/diary/Why%20yq%3F%20%20Adventures%20in%20XML/30930
Black Basta Uses Quick Assist
https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/
Various Chrome 0-Day Vulnerabilities
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_15.html
Android Theft Protection Improvement
https://blog.google/products/android/android-theft-protection/
Critical Git Update
https://github.blog/2024-05-14-securing-git-addressing-5-new-vulnerabilities/
Got MFA? If not, now is the time!
https://isc.sans.edu/diary/Got%20MFA%3F%20%20If%20not%2C%20Now%20is%20the%20Time!/30926
SSID Confusion: Making Wi-Fi Clients Connect to the Wrong Network CVE-2023-52424
https://www.top10vpn.com/assets/2024/05/Top10VPN-x-Vanhoef-SSID-Confusion.pdf
FIDO2 MitM Session Hijacking
https://www.silverfort.com/blog/using-mitm-to-bypass-fido2/?web_view=true#but-first-some-background
Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20May%202024%20Patch%20Tuesday/30920
Detecting Bluetooth Trackers
https://security.googleblog.com/2024/05/google-and-apple-deliver-support-for.html
Adobe Patches
https://helpx.adobe.com/security/products/acrobat/apsb24-29.html
VMWare Updates
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24280
Revoking Vulnerability Windows Boot Managers
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/revoking-vulnerable-windows-boot-managers/ba-p/4121735
Apple Updates Everything
https://isc.sans.edu/diary/Apple%20Patches%20Everything%3A%20macOS%2C%20iOS%2C%20iPadOS%2C%20watchOS%2C%20tvOS%20updated./30916
Juniper OpenSSH Update
https://supportportal.juniper.net/s/article/2024-05-Reference-Advisory-Junos-OS-and-Junos-OS-Evolved-Multiple-CVEs-reported-in-OpenSSH?language=en_US
Malicious Go Binary Delivered via Steganography in PyPi
https://blog.phylum.io/malicious-go-binary-delivered-via-steganography-in-pypi/
DNS Suffixes on Windows
https://isc.sans.edu/diary/DNS%20Suffixes%20on%20Windows/30912
Black Basta Ransomware Advisory
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a
Possible Exploitation of Arcserve Unified Data Protection Vuln
https://digital.nhs.uk/cyber-alerts/2024/cc-4487
Chrome Patches 0-Day
https://chromereleases.googleblog.com/2024/05/stable-channel-update-for-desktop_9.html
Solarwinds ARM Vulnerablities
https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-4_release_notes.htm
Analyzing PDF Streams
https://isc.sans.edu/diary/Analyzing%20PDF%20Streams/30908
F5 Next Central Manager Vulnerabilities
https://eclypsium.com/blog/big-vulnerabilities-in-next-gen-big-ip/
Veeam Patches
https://www.veeam.com/kb4441
https://www.veeam.com/kb4509
Citrix Hypervisor Security Update CVE-2024-31497
https://support.citrix.com/article/CTX633416/citrix-hypervisor-security-update-for-cve202431497
Analzying Synology Disks
https://isc.sans.edu/diary/Analyzing%20Synology%20Disks%20on%20Linux/30904
RSA Panel
https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About
SANS.edu Research Journal
https://www.sans.edu/cyber-security-research
Detecting XFinity/Comcast DNS Spoofing
https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898
Weblogic PoC CVE-2024-21006
https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/
https://github.com/momika233/CVE-2024-21006
PDF.js React PDF Vulnerablity
https://securityonline.info/cve-2024-4367-cve-2024-34342-javascript-flaw-threatens-millions-of-pdf-js-and-react-pdf-users/
Tinyproxy Response
https://github.com/tinyproxy/tinyproxy/issues/533
DHCP Based VPN Routing Leaks
https://www.leviathansecurity.com/blog/tunnelvision
Mullvad VPN DNS Traffic Leak
https://mullvad.net/en/blog/dns-traffic-can-leak-outside-the-vpn-tunnel-on-android
Tiny Proxy Vulnerability
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1889
DNS Debugging with nslookup
https://isc.sans.edu/diary/nslookups+Debug+Options/30894/
Microsoft Plans DNS Lockdown
https://techcommunity.microsoft.com/t5/networking-blog/announcing-zero-trust-dns-private-preview/ba-p/4110366
Microsoft Graph API Abuse
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/graph-api-threats
SANSFIRE SEC522 Defending Web Applications
https://www.sans.org/cyber-security-training-events/sansfire-2024/
https://isc.sans.edu/diary/Scans%20Probing%20for%20LB-Link%20and%20Vinga%20WR-AC1200%20routers%20CVE-2023-24796/30890
Scans Probing for LB-Link and Vinga WR-AC1200 routers CVE-2023-24796
Buffer Overflow Vulnerabilities in ArubaOS
https://www.arubanetworks.com/support-services/security-bulletins/
The Cuttlefish Malware
https://blog.lumen.com/eight-arms-to-hold-you-the-cuttlefish-malware/
Linux Trojan - Xorddos with Filename eyshcjdmzg
https://isc.sans.edu/diary/Linux%20Trojan%20-%20Xorddos%20with%20Filename%20eyshcjdmzg/30880
AWS S3 Denial of Wallet Amplification Attack
https://medium.com/@maciej.pocwierz/how-an-empty-s3-bucket-can-make-your-aws-bill-explode-934a383cb8b1
https://blog.limbus-medtec.com/the-aws-s3-denial-of-wallet-amplification-attack-bc5a97cc041d
EU iOS Safari Allows User Tracking
https://www.mysk.blog/2024/04/28/safari-tracking/
BentoML Critical Deserialization Vuln CVE-2024-2912
https://nvd.nist.gov/vuln/detail/CVE-2024-2912
Another Day, Another NAS: Attacks against Zyxel NAS326 Devices CVE-2023-4473, CVE-2023-4474
https://isc.sans.edu/diary/Another%20Day%2C%20Another%20NAS%3A%20Attacks%20against%20Zyxel%20NAS326%20devices%20CVE-2023-4473%2C%20CVE-2023-4474/30884
R-Bitrary Code Execution: Vulnearbility in R's Deserialization
https://hiddenlayer.com/research/r-bitrary-code-execution/
Coordinated Docker Hub Attacks using Malicious Repositories
https://jfrog.com/blog/attacks-on-docker-with-millions-of-malicious-repositories-spread-malware-and-phishing-scams/
NVMe-oF/TCP Vulnerabilities
https://www.cyberark.com/resources/threat-research-blog/your-nvme-had-been-syzed-fuzzing-nvme-of-tcp-driver-for-linux-with-syzkaller
DLink NAS Exploit Variation
https://www.qnap.com/en/security-advisory/qsa-24-09
Muddling Meerkat DNS Abuse
https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/
Android TV Data Leakage
https://www.youtube.com/watch?v=QiyBXXO8QpA
https://www.404media.co/android-tvs-can-expose-user-email-inboxes/
SEC522: SANSFIRE
https://www.sans.org/cyber-security-courses/application-security-securing-web-apps-api-microservices/
SEC522 Demo (requires free account):
https://www.sans.org/ondemand/get-demo/316
Okta warns of increase in credential stuffing
https://sec.okta.com/blockanonymizers
Fake payment cards used by Police in Japan
https://twitter.com/vxunderground/status/1783522097425211887
Phishing Campaigns Targeting USPS
https://www.akamai.com/blog/security-research/phishing-usps-malicious-domains-traffic-equal-to-legitimate-traffic
Chrome 124 Breaks TLS Handshake
https://www.reddit.com/r/sysadmin/comments/1carvpd/chrome_124_breaks_tls_handshake/
Does it matter if iptables isn't running on my honeypot?
https://isc.sans.edu/forums/diary/Does%20it%20matter%20if%20iptables%20isn't%20running%20on%20my%20honeypot%3F/30862/
Unplugging PlugX: Singholing the PlugX USB worm botnet
https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/
pfSense Updates
https://docs.netgate.com/advisories/index.html
GitLab Updates
https://about.gitlab.com/releases/2024/04/24/patch-release-gitlab-16-11-1-released/
Matthew Alan Vorhees: Prevention Strategies for Modern Living Off the Land Usage
https://www.sans.edu/cyber-research/prevention-strategies-modern-living-off-land-usage/
API Rug Pull - The NIST NVD Database and API
https://isc.sans.edu/diary/API%20Rug%20Pull%20-%20The%20NIST%20NVD%20Database%20and%20API%20%28Part%204%20of%203%29/30868
Cisco Patches Vulnerabilities and Discovers Arcane Backdoor
https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/
Vulnerabilities across keyboard apps reveal keystrokes to network eavesdroppers
https://citizenlab.ca/2024/04/vulnerabilities-across-keyboard-apps-reveal-keystrokes-to-network-eavesdroppers/
MySQL2: Dangers of User-Defined Database Connections
https://blog.slonser.info/posts/mysql2-attacker-configuration/
Netgear Nighthawk Vulnerabilities
https://jvn.jp/en/vu/JVNVU91883072/
Struts2 devmode Still a Problem Ten Years Later
https://isc.sans.edu/forums/diary/Struts%20%22devmode%22%3A%20Still%20a%20problem%20ten%20years%20later%3F/30866/
Analyzing Forest Blizard's Custom Post-Compromise Tool for exploiting CVE-2022-38028
https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/
April 2024 Exchange Server Hotfix Update
https://techcommunity.microsoft.com/t5/exchange-team-blog/released-april-2024-exchange-server-hotfix-updates/ba-p/4120536
CVE-2024-2389: Command Injection Vulnerability in Progress Flowmon
https://rhinosecuritylabs.com/research/cve-2024-2389-in-progress-flowmon/
GuptiMiner: Hijacking Antivirus Updates for Distributing Backdoors and Casual Mining
https://decoded.avast.io/janrubin/guptiminer-hijacking-antivirus-updates-for-distributing-backdoors-and-casual-mining/
Number of Industrial Devices Accessible From Internet Up 30 Thousand over three years
https://isc.sans.edu/diary/It%20appears%20that%20the%20number%20of%20industrial%20devices%20accessible%20from%20the%20internet%20has%20risen%20by%2030%20thousand%20over%20the%20past%20three%20years/30860
Evil XDR: Turning an XDR into an Offensive Tool
https://www.darkreading.com/application-security/evil-xdr-researcher-turns-palo-alto-software-into-perfect-malware
GitLab Comment Bug
https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/
SEC522 Demo: https://www.sans.org/ondemand/get-demo/316
The CVE's They are A-Changing
https://isc.sans.edu/diary/The%20CVE%27s%20They%20are%20A-Changing!/30850
CrushFTP 0-Day Vulnerability
https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update
https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/
GitHub Comment Bug Used to Distribute Malware
https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/
YubiKey Manager Privilege Escalation
https://www.yubico.com/support/security-advisories/ysa-2024-01/
Palo Alto Networks GlobalProtect Update
https://security.paloaltonetworks.com/CVE-2024-3400
Delinea Secret Server Authn Authz Bypass
https://straightblast.medium.com/all-your-secrets-are-belong-to-us-a-delinea-secret-server-authn-authz-bypass-adc26c800ad3
Ivanti Avalanche Poc/Details
https://www.tenable.com/security/research/tra-2024-10
Advanced Phishing Campaign
https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit
Hashicorp go-getter update CVE-2024-3817
https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040
OfflRouter Virus
https://blog.talosintelligence.com/offlrouter-virus-causes-upload-confidential-documents-to-virustotal/
Malicious PDF File As Delivery Mechanism
https://isc.sans.edu/diary/Malicious%20PDF%20File%20Used%20As%20Delivery%20Mechanism/30848
Updated Palo Alto Networks GlobalProtect Guidance
https://security.paloaltonetworks.com/CVE-2024-3400
Coordinated Social Engineering Takeovers of Open Source Projects;
https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/
OpenMetaData Attacks
https://www.microsoft.com/en-us/security/blog/2024/04/17/attackers-exploiting-new-critical-openmetadata-vulnerabilities-on-kubernetes-clusters/
Palo Alto Networks GlobalProtect exploit public and widely exploited CVE-2024-3400
https://isc.sans.edu/forums/diary/Palo%20Alto%20Networks%20GlobalProtect%20exploit%20public%20and%20widely%20exploited%20CVE-2024-3400/30844/
Putty Private Key Recovery
https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html
Oracle Critical Patch Update
https://www.oracle.com/security-alerts/cpuapr2024.html
Ivanti Avalanche MDM Patches
https://forums.ivanti.com/s/article/Avalanche-6-4-3-Security-Hardening-and-CVEs-addressed?language=en_US
Quick Palo Alto Networks Global Protect Vulnerablity Update CVE-2024-3400
https://isc.sans.edu/diary/30838
Delinea patches critical vulnerability in secret manager
https://trust.delinea.com/?tcuUid=17aaf4ef-ada9-46d5-bf97-abd3b07daae3
Lancom Windows Setup Assistant May Reset Password
https://www.lancom-systems.com/service-support/general-security-information
PHP Patches
https://seclists.org/oss-sec/2024/q2/113
Duo SMS and VoiP Logs Leaked
https://app.securitymsp.cisco.com/e/es?e=2785&eid=opguvrs&elq=bd1c1886a59e40c09915b029a74be94e
Lastpass Stops Deepfake Attack
https://blog.lastpass.com/posts/2024/04/attempted-audio-deepfake-call-targets-lastpass-employee
Palo Alto Networks GlobalProtect 0-Day CVE-2024-3400
https://security.paloaltonetworks.com/CVE-2024-3400
https://www.volexity.com/blog/2024/04/12/zero-day-exploitation-of-unauthenticated-remote-code-execution-vulnerability-in-globalprotect-cve-2024-3400/#RespondingToCompromise
BatBadBut: You can't securely execute commands on Windows
https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/
FortiClient Linux Remote Code Execution
https://www.fortiguard.com/psirt/FG-IR-23-087
Apple Threat Notifications and Protecting Against Mercenary Spyware
https://support.apple.com/en-us/102174
New Technique to Trick Developers Detected in an Open Source Supply Chain Attack
https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/
Rust Command API code execution vulnerability CVE-2024-24576
https://blog.rust-lang.org/2024/04/09/cve-2024-24576.html
Adobe Updates: Magento Adobe Commerce CVE-2024-20759 CVE-2024-20758
https://helpx.adobe.com/security/products/magento/apsb24-18.html
https://helpx.adobe.com/security.html
Fortinet FortiOS And FortiProxy Vulnerability CVE-2023-41677
https://www.fortiguard.com/psirt/FG-IR-23-493
Smoke and Screen Mirrors Signed Backdoor CVE-2024-26234
https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/
Microsoft Patches
https://isc.sans.edu/forums/diary/April%202024%20Microsoft%20Patch%20Tuesday%20Summary/30822/
D-Link NAS Backdoor
https://github.com/netsecfish/dlink
LG SmartTV Vulnerabilities
https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/
A Use Case for Adding Threat Hunting to Your Security Operations Team.
https://isc.sans.edu/diary/30816
Notepad++ Parasite Site
https://notepad-plus-plus.org/news/help-to-take-down-parasite-site/
Hugging Face Pickle File Vulnerablities
https://huggingface.co/blog/hugging-face-wiz-security-blog
Google Considers V8 Sandbox no longer experimental
https://v8.dev/blog/sandbox
Heartbleed 10th Anniversary
https://heartbleed.com/
Possible Libarchive Backdoor Vulnerability
https://github.com/libarchive/libarchive/pull/1609
Magento XML Backdoor
https://sansec.io/research/magento-xml-backdoor
Google Public DNS's approach to fight against cache poisoning attacks
https://security.googleblog.com/2024/03/google-public-dnss-approach-to-fight.html
Remote code execution (RCE)vulnerability in Brocade Fabric OS (CVE-2023-3454)
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23215
SANS London April Evening Talk
https://sans.zoom.us/webinar/register/WN_ZLLnQKCCQCywLGm-CM4xQg#/registration
Slicing up DoNex with Binary Ninja
https://isc.sans.edu/diary/Slicing%20up%20DoNex%20with%20Binary%20Ninja/30812
HTTP/2 Continuation Flood
https://nowotarski.info/http2-continuation-flood-technical-details/
Dangers of CSS in HTML Email
https://lutrasecurity.com/en/articles/kobold-letters/
Dan Mazella: Infostealers in Automotive Headunits
https://www.sans.edu/cyber-research/exploring-infostealer-malware-techniques-automotive-head-units/
Playing with xzbot: Some things you can learn from SSH traffic
https://isc.sans.edu/forums/diary/Some%20things%20you%20can%20learn%20from%20SSH%20traffic/30808/
Google Proposes Device Bound Session Credentials (DBSC)
https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html
Four More Ivanti Vulnerabilities
https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
Google Pixel Zero Day
https://source.android.com/docs/security/bulletin/pixel/2024-04-01
Chrome Incognito Mode Settlement
https://www.wired.com/story/google-chrome-incognito-mode-data-deletion-settlement/
Google E-Mail Sender Guidelines FAQ
https://support.google.com/a/answer/14229414?hl=en&fl=1&sjid=2270464422796374445-NC
Cisco Updates and VPN Best Practices
https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221806-password-spray-attacks-impacting-custome.html
https://sec.cloudapps.cisco.com/security/center/publicationListing.x
Apache Pulsar Vulnerability
https://pulsar.apache.org/security/CVE-2024-29834/
Progress Flowmon Network Monitoring Tool Vulnerability CVE-2024-2389
https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability
Wait Just an Infosec Episode with Bojan Zdrnja: Thursday April 4th 2024 10:00 EDST
https://isc.sans.edu/j/xzutils (link will redirect once episode is live)
The amazingly scary xz sshd backdoor
https://isc.sans.edu/diary/The%20amazingly%20scary%20xz%20sshd%20backdoor/30802
The xz-utils backdoor in security advisories by national CSIRTs
https://isc.sans.edu/diary/The+xzutils+backdoor+in+security+advisories+by+national+CSIRTs/30800
Checking CSV Files
https://isc.sans.edu/diary/Checking%20CSV%20Files/30796
Infostealers Pose Threat to macOS
https://www.jamf.com/blog/infostealers-pose-threat-to-macos/
xz-utils Backdoor CVE-2024-3094
https://www.openwall.com/lists/oss-security/2024/03/29/4
https://tukaani.org/xz-backdoor/
https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27
Backdoor reverse analysis
https://bsky.app/profile/did:plc:x2nsupeeo52oznrmplwapppl/post/3kowjkx2njy2b
YARA Rule
https://github.com/byinarie/CVE-2024-3094-info/blob/main/CVE-2024-3094.yar
Social Engineering Attempts to Include Backdoor in Distros
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067708
https://news.ycombinator.com/item?id=39866275
Github Repo (now disabled)
https://github.com/tukaani-project/xz
Statements from Distributions
https://www.kali.org/blog/about-the-xz-backdoor/
https://archlinux.org/news/the-xz-package-has-been-backdoored/
https://access.redhat.com/security/cve/CVE-2024-3094
https://bugs.gentoo.org/928134
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024
From JavaScript to AsyncRAT
https://isc.sans.edu/diary/From%20JavaScript%20to%20AsyncRAT/30788
TeamCity Patches
https://www.jetbrains.com/privacy-security/issues-fixed/?product=TeamCity&version=2024.03
Okta Verify for Windows Auto-update Arbitrary Code Execution CVE-2024-0980
https://trust.okta.com/security-advisories/okta-verify-windows-auto-update-arbitrary-code-execution-cve-2024-0980/
Google Zero Day Report
https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Year_in_Review_of_ZeroDays.pdf
Scans for Apache OfBiz
https://isc.sans.edu/diary/Scans%20for%20Apache%20OfBiz/30784
Wall-Escape (CVE-2024-28085)
https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txt
Recent "MFA Bombing" Attacks Targeting Apple Users
https://krebsonsecurity.com/2024/03/recent-mfa-bombing-attacks-targeting-apple-users/
New tool: linux-pkgs.sh
https://isc.sans.edu/forums/diary/New%20tool%3A%20linux-pkgs.sh/30774/
Suspicious NuGet package grabs data from industrial systems
https://www.reversinglabs.com/blog/suspicious-nuget-package-grabs-data-from-industrial-systems
Preventing Cross Service UDP Loops in QUIC
https://bughunters.google.com/blog/5960150648750080/preventing-cross-service-udp-loops-in-quic
ShadowRay Attacks AI Workloads Actively Exploited in the Wild
https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild
TheMoon Malware Infects 6,000 ASUS Routers in 72 Hours for Proxy Service
https://www.bleepingcomputer.com/news/security/themoon-malware-infects-6-000-asus-routers-in-72-hours-for-proxy-service/
Tool updates: le-hex-to-ip.py and sigs.py
https://isc.sans.edu/diary/Tool%20updates%3A%20le-hex-to-ip.py%20and%20sigs.py/30772
Apple Updates for MacOS, iOS/iPadOS, visionOS;
https://isc.sans.edu/diary/Apple%20Updates%20for%20MacOS%2C%20iOS%20iPadOS%20and%20visionOS/30778
Fake Python Infrastructure
https://checkmarx.com/blog/over-170k-users-affected-by-attack-using-fake-python-infrastructure/
OpenVPN Update
https://openvpn.net/community-downloads/
1768.py's Experimental Mode
https://isc.sans.edu/diary/1768.py%27s%20Experimental%20Mode/30770
CISCP Advisory on Application-Layer Loop DoS
https://docs.google.com/document/d/1KByZzrdwQhrXGPPCf9tUzERZyRzg0xOpGbWoDURZxTI/edit
Fixes for Windows Server LSASS Memory Leak
https://www.catalog.update.microsoft.com/Search.aspx?q=2024-03%20Cumulative%20Update
Geofeed
https://isc.sans.edu/forums/diary/Whois%20%22geofeed%22%20Data/30766/
Apple Updates
https://support.apple.com/en-us/HT201222
Apple Bug
https://gofetch.fail/
GitHub Copilot AutoFix
https://github.blog/2024-03-20-found-means-fixed-introducing-code-scanning-autofix-powered-by-github-copilot-and-codeql/
Fortinet PoC
https://www.horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/
Ivanti Standalone Sentry
https://forums.ivanti.com/s/article/KB-CVE-2023-41724-Remote-Code-Execution-for-Ivanti-Standalone-Sentry?language=en_US
Scans for the Fortinet FortiOS CVE-2024-21762 Vulnerability
https://isc.sans.edu/diary/Scans%20for%20Fortinet%20FortiOS%20and%20the%20CVE-2024-21762%20vulnerability/30762
Microsoft Reminder: It is Tax Season (at least in the US)
https://www.theregister.com/2024/03/20/its_tax_season_and_scammers/
Abusing DHCP Administrators Group for Privilege Escalation in Windows Domains;
https://www.akamai.com/blog/security-research/abusing-dhcp-administrators-group-for-privilege-escalation-in-windows-domains
Attacker Hunting Firewalls
https://isc.sans.edu/diary/Attacker%20Hunting%20Firewalls/30758
Fortigate Vulnerability Exploit Available
https://github.com/h4x0r-dz/CVE-2024-21762
IC3 Annual Report 2023
https://www.ic3.gov/Media/PDF/AnnualReport/2023_IC3Report.pdf
Issues with macOS 14.4 Update
https://www.macrumors.com/2024/03/18/do-not-update-macos-sonoma-14-4/
Microsoft announced deprecation of 1024 bit RSA Keys
https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#deprecated-features
Chrome Real-Time Safe Browsing Protection
https://blog.google/products/chrome/google-chrome-safe-browsing-real-time/
Fortra FileCatalyst Vulnerability CVE-2024-25153
https://www.fortra.com/security/advisory/fi-2024-002
Spring Security CVE-2024-22257
https://spring.io/security/cve-2024-22257/
TrendNet TWEW-827DRU Router Vulnerability CVE-2024-28353 CVE-2024-28354
https://warp-desk-89d.notion.site/TEW-827DRU-5c40fb20572148f0b00f329d69273791
5GHoul Revisted: Thress Months Later
https://isc.sans.edu/diary/5Ghoul%20Revisited%3A%20Three%20Months%20Later/30746
Obfuscated Hexadecimal Payload
https://isc.sans.edu/diary/Obfuscated%20Hexadecimal%20Payload/30750
ChatGPT Related OAUTH Issues
https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data?utm_source=social&utm_medium=reddit
RedCanary Threat Detection Report
https://redcanary.com/threat-detection-report/
CRL/OCSP Changes
https://github.com/cabforum/servercert/blob/main/docs/BR.md
Increase in the number of phishing messages pointing to IPFS and to R2 buckets
https://isc.sans.edu/diary/Increase%20in%20the%20number%20of%20phishing%20messages%20pointing%20to%20IPFS%20and%20to%20R2%20buckets/30744
Fortinet New Vulnerabilities
https://www.horizon3.ai/attack-research/attack-blogs/fortiwlm-the-almost-story-for-the-forti-forty/
Fortinet Updates
https://www.helpnetsecurity.com/2024/03/14/cve-2023-48788-poc/
Arcserve UDP Vulnerability and PoC
https://www.tenable.com/security/research/tra-2024-07
Michael Holcomb: Mode Matters: Monitoring PLCs for Detecting Potential ICS/OT Incidents
https://www.sans.edu/cyber-research/mode-matters-monitoring-plcs-for-detecting-potential-ics-ot-incidents/
Using ChatGPT to Deofuscate Malicious Scripts
https://isc.sans.edu/diary/Using%20ChatGPT%20to%20Deobfuscate%20Malicious%20Scripts/30740
Critical Fortinet Vulnerabilities
https://fortiguard.fortinet.com/psirt
Adobe Security Bulletins
https://helpx.adobe.com/security/security-bulletin.html
Kubernetes Local Volumes Command Injection Vulnerability
https://www.akamai.com/blog/security-research/kubernetes-local-volumes-command-injection-vulnerability-rce-system-privileges
Microsoft Patch Tuesday March 2024
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20-%20March%202024/30736
Death Knell of NVD
https://resilientcyber.substack.com/p/death-knell-of-the-nvd
Unrestricted file upload vulnerability in ManageEngine Desktop Central
https://www.incibe.es/en/incibe-cert/notices/aviso/unrestricted-file-upload-vulnerability-manageengine-desktop-central
Siemens Fire Protection System Updates
https://cert-portal.siemens.com/productcert/html/ssa-225840.html
What happens when you accidentially leak your AWS API Keys
https://isc.sans.edu/diary/What%20happens%20when%20you%20accidentally%20leak%20your%20AWS%20API%20keys%3F%20%5BGuest%20Diary%5D/30730
How Crypto Imposters are using Calendly to infect Macs with Malware
https://cyberguy.com/news/how-crypto-imposters-are-using-calendly-to-infect-macs-with-malware/
https://krebsonsecurity.com/2024/02/calendar-meeting-links-used-to-spread-mac-malware/
Misconfiguration Manager: Overlooked and Overprivileged
https://posts.specterops.io/misconfiguration-manager-overlooked-and-overprivileged-70983b8f350d
Attack Wrangles Thousands of Web Users into a Password Cracking Botnet
https://arstechnica.com/security/2024/03/attack-wrangles-thousands-of-web-users-into-a-password-cracking-botnet
Cisco VPN Client Vuln
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-secure-client-crlf-W43V4G7
Fortinet Vulnerability Exploited
https://bishopfox.com/blog/cve-2024-21762-vulnerability-scanner-for-fortigate-firewalls
pgAdmin Path Traversal
https://www.shielder.com/advisories/pgadmin-path-traversal_leads_to_unsafe_deserialization_and_rce/
Font Vulnerabilities
https://www.canva.dev/blog/engineering/fonts-are-still-a-helvetica-of-a-problem/
QNAP Flaws
https://securityonline.info/cve-2024-21899-cvss-9-8-critical-qnap-flaw-opens-door-to-hackers/
AWS Deploymnet Risks - Configuration and Credential File Targeting
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20AWS%20Deployment%20Risks%20-%20Configuration%20and%20Credential%20File%20Targeting/30722
Apple Updates
https://isc.sans.edu/diary/MacOS%20Patches%20%28and%20Safari%2C%20TVOS%2C%20VisionOS%2C%20WatchOS%29/30726
NSA/CISA Secure Cloud Guides
https://media.defense.gov/2024/Mar/07/2003407866/-1/-1/0/CSI-CloudTop10-Identity-Access-Management.PDF
https://media.defense.gov/2024/Mar/07/2003407858/-1/-1/0/CSI-CloudTop10-Key-Management.PDF
https://media.defense.gov/2024/Mar/07/2003407859/-1/-1/0/CSI-CloudTop10-Managed-Service-Providers.PDF
https://media.defense.gov/2024/Mar/07/2003407862/-1/-1/0/CSI-CloudTop10-Secure-Data.PDF
https://media.defense.gov/2024/Mar/07/2003407861/-1/-1/0/CSI-CloudTop10-Network-Segmentation.PDF
Scanning and Abusing the QUIC Protocol
https://isc.sans.edu/diary/Scanning%20and%20abusing%20the%20QUIC%20protocol/30720
Google Chrome Update
https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html
Spinning YARN
https://www.cadosecurity.com/spinning-yarn-a-new-linux-malware-campaign-targets-docker-apache-hadoop-redis-and-confluence/
Teamcity Exploited
https://twitter.com/leak_ix/status/1765460190621581347
iOS/iPadOS Updates with Zero Day Fixes
https://isc.sans.edu/diary/Apple%20Releases%20iOS%20iPadOS%20Updates%20with%20Zero%20Day%20Fixes./30716
Why Your Firewall Will Kill You
https://isc.sans.edu/diary/Why+Your+Firewall+Will+Kill+You/30714/
QEMU Tunnel
https://securelist.com/network-tunneling-with-qemu/111803/
VMware Vulnerabilities Patched
https://www.vmware.com/security/advisories/VMSA-2024-0006.html
Capturing DShield Packets with a LAN Tap
https://isc.sans.edu/diary/Capturing%20DShield%20Packets%20with%20a%20LAN%20Tap%20%5BGuest%20Diary%5D/30708
Additional Critical Security Issues Affecting Teamcity
https://blog.jetbrains.com/teamcity/2024/03/additional-critical-security-issues-affecting-teamcity-on-premises-cve-2024-27198-and-cve-2024-27199-update-to-2023-11-4-now/
GitHub Push Protection Now On By Default
https://github.blog/2024-02-29-keeping-secrets-out-of-public-repositories/
Android Updates
https://source.android.com/docs/security/bulletin/2024-03-01
Linksys E-2000 Vulnerablity
https://warp-desk-89d.notion.site/Linksys-E-2000-efcd532d8dcf4710a4af13fca131a5b8
Scanning for Confluence CVE-2022-26134
https://isc.sans.edu/diary/Scanning%20for%20Confluence%20CVE-2022-26134/30704
Exploiting CSP Wildcards for Google Domains
https://attackshipsonfi.re/p/exploiting-csp-wildcards-for-google
Silver SAML: Golden SAML in the Cloud
https://www.semperis.com/blog/meet-silver-saml/
Dissecting DarkGate: Module Malware Delivery and Persistence as a Service
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Dissecting%20DarkGate%3A%20Modular%20Malware%20Delivery%20and%20Persistence%20as%20a%20Service./30700
Ivanti Incident Response Update
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060b
Github Flooded with Infected Repos
https://apiiro.com/blog/malicious-code-campaign-github-repo-confusion-attack
Security Flaws in NoName Doorbell Cameras
https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/
Exploit Attempts for Unknown Password Reset Vulnerability
https://isc.sans.edu/diary/Exploit%20Attempts%20for%20Unknown%20Password%20Reset%20Vulnerability/30698
StopRansomware: Updated ALPHV Blackcat Advisory
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a
GlobalBlock Service To Prevent Trademark abuse
https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/
Take Downs and the Rest of Us: Do they matter?
https://isc.sans.edu/diary/Take%20Downs%20and%20the%20Rest%20of%20Us%3A%20Do%20they%20matter%3F/30694
Joint Cybersecurity Advisory
https://www.ic3.gov/Media/News/2024/240227.pdf
SVR Cyber Actors Adapt Tactics for Initial Cloud Access
https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access
Data Scientists Targeted by Malicious Hugging Face ML Models with Silent Backdoor
https://jfrog.com/blog/data-scientists-targeted-by-malicious-hugging-face-ml-models-with-silent-backdoor/
Utilizing the VirusTotal API to Query Files Uploaded to the DShield Honeypot
https://isc.sans.edu/diary/Utilizing%20the%20VirusTotal%20API%20to%20Query%20Files%20Uploaded%20to%20DShield%20Honeypot%20%5BGuest%20Diary%5D/30688
New WiFi Authentication Vulnerabilities Discovered
https://www.top10vpn.com/research/wifi-vulnerabilities/
Subdomain Takeover Spam
https://labs.guard.io/subdomailing-thousands-of-hijacked-major-brand-subdomains-found-bombarding-users-with-millions-a5e5fb892935
Update MGLNDD * Scans
https://isc.sans.edu/forums/diary/Update%3A%20MGLNDD_*%20Scans/30686/
Simple Anti-Sandbox Technique: Where's the Mouse
https://isc.sans.edu/diary/Simple%20Anti-Sandbox%20Technique%3A%20Where%27s%20The%20Mouse%3F/30684
Security Vulnerabilities in Apex Code Could Leak Salesforce Data
https://www.varonis.com/blog/apex-code-vulnerabilities
IBM Operation Decision Manager Exploit CVE-2024-22319 CVE-2024-22320
https://labs.watchtowr.com/double-k-o-rce-in-ibm-operation-decision-manager/
Linux Kernel TLS Vulnerability CVE-2024-26582
https://lore.kernel.org/linux-cve-announce/2024022139-spruce-prelude-c358@gregkh/
Friend, Foe or Something In Between
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Friend%2C%20foe%20or%20something%20in%20between%3F%20The%20grey%20area%20of%20%27security%20research%27/30670
Large AT&T Wireless Network Outage
https://isc.sans.edu/diary/Large%20AT%26T%20Wireless%20Network%20Outage%20%23att%20%23outage/30680
Connect Wise Screenconnect Userd by LockBit
https://www.bleepingcomputer.com/news/security/screenconnect-servers-hacked-in-lockbit-ransomware-attacks/
SSH Snake Abused in the Wild
https://github.com/MegaManSec/SSH-Snake
Phishing Pages Hosted on Archive.org
https://isc.sans.edu/forums/diary/Phishing%20pages%20hosted%20on%20archive.org/30676/
ScreenConnect Authentication Bypass Exploit CVE-2024-1709 CVE-2024-1708)
https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass
iMessage with PQ3
https://security.apple.com/blog/imessage-pq3/
Old Mirai New Exploits
https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658
KeyTrap PoC Exploit
https://github.com/knqyf263/CVE-2023-50387
Google Open Sources Magika File ID System
https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html
Exploiting Unsynchronised Clocks
https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks
Old Mirai New Exploits
https://isc.sans.edu/diary/Mirai-Mirai%20On%20The%20Wall...%20%5BGuest%20Diary%5D/30658
KeyTrap PoC Exploit
https://github.com/knqyf263/CVE-2023-50387
Google Open Sources Magika File ID System
https://opensource.googleblog.com/2024/02/magika-ai-powered-fast-and-efficient-file-type-identification.html
Exploiting Unsynchronised Clocks
https://attackshipsonfi.re/p/exploiting-unsynchonised-clocks
SolarWinds Security Advisories
https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-3_release_notes.htm
Google Chrome Adds Private Network Checks
https://chromestatus.com/feature/4869685172764672
Gold Factory iOS Trojan
https://www.group-ib.com/blog/goldfactory-ios-trojan/
USPS Anchors Snowballing Smishing Campaigns
https://www.sentinelone.com/labs/sns-sender-active-campaigns-unleash-messaging-spam-through-the-cloud/
Linux Issuing CVEs
http://www.kroah.com/log/blog/2024/02/13/linux-is-a-cna/
Analyzing Pulse Secure Firmware and Bypassing Integrity Checking
https://eclypsium.com/blog/flatlined-analyzing-pulse-secure-firmware-and-bypassing-integrity-checking/
Jennifer Walker: Detecting Rogue Ethernet Switches Using Layer 1 Techniques
https://www.sans.edu/cyber-research/detecting-rogue-ethernet-switches-using-layer-1-techniques/
Guest Diary: Learning by Doing An Interative Adventure in Troubleshooting
https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20Learning%20by%20doing%3A%20Iterative%20adventures%20in%20troubleshooting/30648
Snap Trap: The Hidden Dangers within Ubuntu's Package Suggestion System
https://www.aquasec.com/blog/snap-trap-the-hidden-dangers-within-ubuntus-package-suggestion-system/
The Risks of the Monikerlink Bug in Microsoft Outlook
https://research.checkpoint.com/2024/the-risks-of-the-monikerlink-bug-in-microsoft-outlook-and-the-big-picture/
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
AMD Patches
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7009.html
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20February%202024%20Patch%20Tuesday/30646
DNSSEC DoS Vulnerability CVE-2023-50387
https://www.presseportal.de/pm/173495/5713546
Zoom Desktop Client Vuln
https://www.zoom.com/en/trust/security-bulletin
QNAP Vulnerablity
https://www.qnap.com/de-de/security-advisory/qsa-23-57
https://unit42.paloaltonetworks.com/qnap-qts-firmware-cve-2023-50358/
Exploit Against Unnamed BYTEVALUE Router Vulnerablity Included in Mirai
https://isc.sans.edu/diary/Exploit%20against%20Unnamed%20%22Bytevalue%22%20router%20vulnerability%20included%20in%20Mirai%20Bot/30642
Senior Executives Targeted in Ongoing Azure Account Takeover
https://www.darkreading.com/cloud-security/senior-executives-targeted-ongoing-azure-account-takeover
CISA Parners With OpenSSF To Secure Software Repositories
https://www.cisa.gov/news-events/alerts/2024/02/08/cisa-partners-openssf-securing-software-repositories-working-group-release-principles-package
PostgreSQL Vulnerability
https://www.postgresql.org/support/security/CVE-2024-0985/
Microsoft Defender Bypass via Comma
https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt
MSIX With Heaviliy Obfuscated PowerShell Script
https://isc.sans.edu/diary/MSIX%20With%20Heavily%20Obfuscated%20PowerShell%20Script/30636
Too Many Honeypots
https://vulncheck.com/blog/too-many-honeypots
ClamAV Command Injection Vulnerability CVE-2024-20328
https://amitschendel.github.io/vulnerabilites/CVE-2024-20328/
ExpressVPN DNS Leaks
https://www.expressvpn.com/blog/windows-app-dns-requests/
A Python MP3 Player With Builtin Keylogger Capability
https://isc.sans.edu/diary/A%20Python%20MP3%20Player%20with%20Builtin%20Keylogger%20Capability/30632
Fake LastPass App in Apple App Store
https://blog.lastpass.com/2024/02/warning-fraudulent-app-impersonating-lastpass-currently-available-in-apple-app-store/
Ivanti XXE Vulnerability
https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure
FortiOS sslvpnd vulnerability
https://www.fortiguard.com/psirt/FG-IR-24-015
Anybody knows what this URL is about? Maybe Balena API request?
https://isc.sans.edu/forums/diary/Anybody%20knows%20that%20this%20URL%20is%20about%3F%20Maybe%20Balena%20API%20request%3F/30628/
Critical shim vulnerability and patch
https://github.com/rhboot/shim/releases/tag/15.8
Volt Typhoon Lessons Learned
https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques
Computer viruses are celebrating their 40th birthday (well, 54th, really)
https://isc.sans.edu/diary/Computer%20viruses%20are%20celebrating%20their%2040th%20birthday%20%28well%2C%2054th%2C%20really%29/30624
Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
https://www.tomshardware.com/networking/three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages
Critical Security Issue Affecting TeamCity On-Premises CVE-2024-23917
https://blog.jetbrains.com/teamcity/2024/02/critical-security-issue-affecting-teamcity-on-premises-cve-2024-23917/
Resume Looters
https://www.group-ib.com/blog/resumelooters/
Facebook Advertising Spreads Novel Malware Variant
https://www.trustwave.com/hubfs/Web/Library/Documents_pdf/FaceBook_Ad_Spreads_Novel_Malware.pdf
Public Information and Email Spam
https://isc.sans.edu/diary/Public+Information+and+Email+Spam/30620/
Anydesk Update
https://www.bleepingcomputer.com/news/security/anydesk-says-hackers-breached-its-production-servers-reset-passwords/
https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-213655-1032.pdf
Ivanti POC For CVE-2024-21893
https://attackerkb.com/topics/FGlK1TVnB2/cve-2024-21893/rapid7-analysis
Deepfake Exploits
https://www.scmp.com/news/hong-kong/law-and-crime/article/3250851/everyone-looked-real-multinational-firms-hong-kong-office-loses-hk200-million-after-scammers-stage
https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/
DShield Sensor Log Collection with Elasticsearch
https://isc.sans.edu/forums/diary/DShield%20Sensor%20Log%20Collection%20with%20Elasticsearch/30616/
Anydesk Breach
https://anydesk.com/en/public-statement
Leaky Vessels
https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/
What is a Top Level Domain
https://isc.sans.edu/forums/diary/What%20is%20a%20%22Top%20Level%20Domain%22%3F/30612/
Updated CISA Ivanti Policy
https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure
Cloudflare Publishes Breach Details
https://blog.cloudflare.com/thanksgiving-2023-security-incident
Vision Pro Update
https://support.apple.com/en-us/HT214070
The Fun and Dangers of Top Level Domains (TLDs)
https://isc.sans.edu/diary/The%20Fun%20and%20Dangers%20of%20Top%20Level%20Domains%20%28TLDs%29/30608
Ivanti Releases Patches and New Vulnerabilities
https://forums.ivanti.com/s/article/CVE-2024-21888-Privilege-Escalation-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US
glibc syslog() vulnerablity
https://www.qualys.com/2024/01/30/cve-2023-6246/syslog.txt
modsecurity WAF bypass
https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30
What did I say to make you stop talking to me
https://isc.sans.edu/diary/What%20did%20I%20say%20to%20make%20you%20stop%20talking%20to%20me%3F/30604
Identification of a top-level domain for private use
https://itp.cdn.icann.org/en/files/root-system/identification-tld-private-use-24-01-2024-en.pdf
Juniper Patches Patching
https://supportportal.juniper.net/s/article/2024-01-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-have-been-addressed?language=en_US
https://www.theregister.com/2024/01/30/juniper_networks_vulnerabilities/
Chat GPT Leaking Conversations Again
https://arstechnica.com/security/2024/01/ars-reader-reports-chatgpt-is-sending-him-conversations-from-unrelated-ai-users/
Exploit Flare Up Against Older Atlassian Confluence Vulnerability
https://isc.sans.edu/diary/Exploit%20Flare%20Up%20Against%20Older%20Altassian%20Confluence%20Vulnerability/30600
Malicious Python Packages install Infostealer
https://www.fortinet.com/blog/threat-research/info-stealing-packages-hidden-in-pypi
Linux ICMPv6 Router Adv. RCE
https://access.redhat.com/security/cve/cve-2023-6200
A Batch File With Multiple Payloads
https://isc.sans.edu/diary/A%20Batch%20File%20With%20Multiple%20Payloads/30592
fritz.box domain used to advertise NFTs
https://www.heise.de/news/Verwirrend-Internet-Domain-fritz-box-zeigt-NFT-Galerie-statt-Router-Verwaltung-9610149.html
Jenkins CVE-2024-23897 PoC
https://github.com/gquere/pwn_jenkins/blob/master/README.md#jenkins-cli-arbitrary-read-cve-2024-23897-applies-to-versions-below-2442-and-lts-24263
Malicious Google Ads Target Chinese Users
https://www.malwarebytes.com/blog/threat-intelligence/2024/01/malicious-ads-for-restricted-messaging-applications-target-chinese-users
Fecebook AdsManager Targeted by a Python Infostealer
https://isc.sans.edu/diary/Facebook%20AdsManager%20Targeted%20by%20a%20Python%20Infostealer/30590
Privacy Concerns about Apple Push Notifications
https://twitter.com/mysk_co/status/1750502700112916504
https://www.youtube.com/watch?v=4ZPTjGG9t7s
Inside a Global Phone Spy Tool Monitoring Billions
https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/
How Bad User Interfaces Make Security Tools Harmful
https://isc.sans.edu/diary/How%20Bad%20User%20Interfaces%20Make%20Security%20Tools%20Harmful/30586
Sys:All Loophole Alloed Us to Penetrate GKE Clusters in Production
https://orca.security/resources/blog/sys-all-google-kubernetes-engine-risk-example/
Automotive Pwn2Own
https://www.zerodayinitiative.com/blog/2024/1/23/pwn2own-automotive-2024-the-full-schedule
Android Keystroke Injection Vulnerability Exploit
https://www.mobile-hacker.com/2024/01/23/exploiting-0-click-android-bluetooth-vulnerability-to-inject-keystrokes-without-pairing/
CVE-2024-0769 D-Link DIR-859
https://securityonline.info/cve-2024-0769-the-vulnerability-d-link-wont-fix-in-dir-859-router/
SANS.edu Dean's List
https://www.sans.edu/students/awards
Update on Atlassian Exploit Activity
https://isc.sans.edu/forums/diary/Update%20on%20Atlassian%20Exploit%20Activity%20/30582/
POC For Fortra GoAnywhere MFT Authentication Bypass CVE-2024-0204
https://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/
Baracuda Web Application Firewall
https://campus.barracuda.com/product/webapplicationfirewall/doc/102888530/security-advisory/
GitGot: GitHub leveraged by cybercriminals to store stolen data
https://www.reversinglabs.com/blog/gitgot-cybercriminals-using-github-to-store-stolen-data
Apple Updates Everything
https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20-%20New%200%20Day%20in%20WebKit/30578/
Atlassian Confluence RCE Vulnerability Exploits CVE-2023-22527
https://isc.sans.edu/forums/diary/Scans%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20RCE%20Vulnerability%20CVE-2023-22527/30576/
Updated Ivanti Mitigation Advise
https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
Czech Republic Sets IPv6 Shutdown date
https://konecipv4.cz/en/
macOS Python Script Replacing Walling Applications with Rogue Apps
https://isc.sans.edu/diary/macOS%20Python%20Script%20Replacing%20Wallet%20Applications%20with%20Rogue%20Apps/30572
Microsoft Breach
https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/
Juniper Vulnerabilities
https://labs.watchtowr.com/the-second-wednesday-of-the-first-month-of-every-quarter-juniper-0day-revisited/
Brave Removing Strict Fingerprint Mode
https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/
More Scans for Ivanti Connect "Secure" VPN. Exploits Public
https://isc.sans.edu/diary/More%20Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN.%20Exploits%20Public/30568
Ivanti Endpoint Manager Mobile / MobileIron Core Vuln exploited CVE-2023-35082
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Attacks against Exposed Databases
https://twitter.com/fasterthanlime/status/1741935393413402739
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes
https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes
Number Usage in Passwords
https://isc.sans.edu/diary/Number%20Usage%20in%20Passwords/30540
A Lightweight Method to Detect Potential iOS Malware
https://securelist.com/shutdown-log-lightweight-ios-malware-detection-method/111734/
CISA and FBI Release Known IOCs Associated with Androxgh0st Malware
https://www.cisa.gov/news-events/alerts/2024/01/16/cisa-and-fbi-release-known-iocs-associated-androxgh0st-malware
Ivanti Vulnerability Widespread Scanning
https://isc.sans.edu/diary/Scans%20for%20Ivanti%20Connect%20%22Secure%22%20VPN%20%20Vulnerability%20%28CVE-2023-46805%2C%20CVE-2024-21887%29/30562
https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/
Citrix Patches Already Exploited Vulnerability
https://support.citrix.com/article/CTX584986/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20236548-and-cve20236549
Atlassian Confluence Remote Code Execution Vulnerability
https://confluence.atlassian.com/security/cve-2023-22527-rce-remote-code-execution-vulnerability-in-confluence-data-center-and-confluence-server-1333990257.html
macOS Infostealers
https://www.sentinelone.com/blog/the-many-faces-of-undetected-macos-infostealers-keysteal-atomic-cherrypie-continue-to-adapt/
Google Chrome 0-day
https://chromereleases.googleblog.com/2024/01/stable-channel-update-for-desktop_16.html
GitHub Key Rotation
https://www.bleepingcomputer.com/news/security/github-rotates-keys-to-mitigate-impact-of-credential-exposing-flaw/
One File, Two Payloads
https://isc.sans.edu/diary/One%20File%2C%20Two%20Payloads/30558
Ivanti Vulnerability Updates
https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/
NVidia DGX H100 and A100 Updates
https://nvidia.custhelp.com/app/answers/detail/a_id/5510
GitLab Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2023-7028
Timeline to Remove DSA Support in OpenSSH
https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-January/000156.html
Juniper Patches
https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&numberOfResults=50&f:ctype=[Security%20Advisories]
ManageEngine ADSelfService Plus Patch CVE-2024-0252
https://www.manageengine.com/products/self-service-password/advisory/CVE-2024-0252.html
Atomic Stealer for Mac Update
https://www.malwarebytes.com/blog/threat-intelligence/2024/01/atomic-stealer-rings-in-the-new-year-with-updated-version
Jenkins Brute Force Scans
https://isc.sans.edu/diary/Jenkins%20Brute%20Force%20Scans/30546
Ivanti Connect Security VPN Vulnerability Exploited
https://www.volexity.com/blog/2024/01/10/active-exploitation-of-two-zero-day-vulnerabilities-in-ivanti-connect-secure-vpn/
Zoom Privilege Escalation Vulnerability
https://www.zoom.com/en/trust/security-bulletin/ZSB-24001/
Apache Applictions Targeted by Stealthy Attacker
https://blog.aquasec.com/threat-alert-apache-applications-targeted-by-stealthy-attacker
Infosec Toolshed
https://youtu.be/qDK1PQ1OZjk?si=_vTpHqlovD2Hjd4M
Microsoft January 2024 Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+January+2024+Patch+Tuesday/30548/
Adobe Vulnerabilities
https://helpx.adobe.com/security/products/substance3d_stager/apsb24-06.html
CVE-2023-50916: Authentication Coercion Vulnerablity in Kyocera Device Manager
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/cve-2023-50916-authentication-coercion-vulnerability-in-kyocera-device-manager/
Network Connected Wrenches Used in Factories can be hacked
https://arstechnica.com/security/2024/01/network-connected-wrenches-used-in-factories-can-be-hacked-for-sabotage-or-ransomware/
What is That User Agent
https://isc.sans.edu/diary/What%20is%20that%20User%20Agent%3F/30536
KyberSlash Vulnerability
https://kyberslash.cr.yp.to/faq.html
Netfilter DoS Vulnerability CVE-2024-0193
https://access.redhat.com/security/cve/CVE-2024-0193
Cacti Vulnerability
https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp
Netstat But Better and in PowerShell
https://isc.sans.edu/diary/Netstat%2C%20but%20Better%20and%20in%20PowerShell/30532
Double Phishing Submission
https://isc.sans.edu/diary/Are%20you%20sure%20of%20your%20password%3F/30534
Suspicious Prometei Botnet Activity
https://isc.sans.edu/diary/Suspicious%20Prometei%20Botnet%20Activity/30538
Spectral Blur Mac Malware
https://g-les.github.io/yara/2024/01/03/100DaysofYARA_SpectralBlur.html
Google Malware Abusing API is Standard Token Theft not an API Issue
https://www.bleepingcomputer.com/news/security/google-malware-abusing-api-is-standard-token-theft-not-an-api-issue/
Wireshark Updates
https://isc.sans.edu/diary/Wireshark%20updates/30528
Android Updates
https://source.android.com/docs/security/bulletin/2024-01-01
Ivanti Critical Vulnerability
https://forums.ivanti.com/s/article/SA-2023-12-19-CVE-2023-39336?language=en_US
Malicious PyPi Packages
https://www.fortinet.com/blog/threat-research/malicious-pypi-packages-deploy-coinminer-on-linux-devices
Everything npm package
https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/
Interesting large and small malspam attachments from 2023
https://isc.sans.edu/diary/Interesting%20large%20and%20small%20malspam%20attachments%20from%202023/30524
Orange Spain RIPE Account Compromise
https://www.bleepingcomputer.com/news/security/hacker-hijacks-orange-spain-ripe-account-to-cause-bgp-havoc/
Bitwarden Heist
https://blog.redteam-pentesting.de/2024/bitwarden-heist/
Apple iOS PoC Exploits
https://github.com/felix-pb/kfd/blob/main/writeups/smith.md
https://github.com/felix-pb/kfd/blob/main/writeups/landa.md
Fingerprinting SSH Identification Strings
https://isc.sans.edu/diary/Fingerprinting%20SSH%20Identification%20Strings/30520
Google OAUTH2 Exploited by Malware
https://www.cloudsek.com/blog/compromising-google-accounts-malwares-exploiting-undocumented-oauth2-functionality-for-session-hijacking
TsuKing DNS Amplification
https://lixiang521.com/publication/ccs23/ccs23-xu-tsuking.pdf
Shall We Play a Game
https://isc.sans.edu/diary/Shall+We+Play+a+Game/30510
Mailtrap.io Exfiltration
https://isc.sans.edu/diary/Python%20Keylogger%20Using%20Mailtrap.io/30512
Pi Hole Docker
https://isc.sans.edu/forums/diary/Pi-Hole%20Pi4%20Docker%20Deployment/30516/
Mirai Update
https://isc.sans.edu/diary/Unveiling%20the%20Mirai%3A%20Insights%20into%20Recent%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30514
Barracuda 0-Day Vulnerability
https://www.barracuda.com/company/legal/esg-vulnerability
Apache OFBiz 0-Day Exploited against Atlassian (and possibly others)
https://blog.sonicwall.com/en-us/2023/12/sonicwall-discovers-critical-apache-ofbiz-zero-day-authbiz/
Securing Web Servers
https://isc.sans.edu/diary/How%20to%20Protect%20your%20Webserver%20from%20Directory%20Enumeration%20Attack%20%3F%20Apache2%20%5BGuest%20Diary%5D/30504
Chrome 0-Day (last one for the year?)
https://chromereleases.googleblog.com/2023/12/stable-channel-update-for-desktop_20.html
Note that there will be no daily stormcast for the rest of the year. Returning January 2nd
SANS Cloud Defender 2024
https://www.sans.org/cyber-security-training-events/cloud-defender-2024-live-online/
Increase in Exploit Attempts for Atlassian Confluence Server (CVE-2023-22518)
https://isc.sans.edu/diary/Increase%20in%20Exploit%20Attempts%20for%20Atlassian%20Confluence%20Server%20%28CVE-2023-22518%29/30502
Fake F5 BigIP Update
https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/
Google OAUTH Problems
https://trufflesecurity.com/blog/google-oauth-is-broken-sort-of/
Remembering Adrien de Beaupre
https://www.hpmcgarry.ca/memorials/ernest-adrien-de-beaupre/5344136/index.php
What are they looking for? Scans for OpenID Connect Configuration
https://isc.sans.edu/diary/What%20are%20they%20looking%20for%3F%20Scans%20for%20OpenID%20Connect%20Configuration%20%28Update%3A%20CitrixBleed%29/30498
Terrapin Attack Against SSH
https://terrapin-attack.com/TerrapinAttack.pdf
ALPHV/Blackcat Ransomware Disrupted and Decryptor Available
https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant
SMTP Smuggling - Spoofing E-Mails Worldwide
https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/
Ledger Supply Chain Attack
https://www.ledger.com/blog/a-letter-from-ledger-chairman-ceo-pascal-gauthier-regarding-ledger-connect-kit-exploit
December Windows 11 Patch Breacks Wi-Fi Connectivity
https://www.bleepingcomputer.com/news/microsoft/decembers-windows-11-kb5033375-update-breaks-wi-fi-connectivity/
An Example of a RocketMQ Exploit Scanner
https://isc.sans.edu/diary/An%20Example%20of%20RocketMQ%20Exploit%20Scanner/30492
C# Payload Phoning to a Cobalt Strike Server
https://isc.sans.edu/diary/CSharp%20Payload%20Phoning%20to%20a%20CobaltStrike%20Server/30490
3CX SQL Injection Vulnerability
https://www.3cx.com/blog/news/sql-database-integration/
QNAP Viostor 0-Day Vulnerablity
https://www.akamai.com/blog/security-research/qnap-viostor-zero-day-vulnerability-spreading-mirai-patched
PFSense Vulnerability
https://www.sonarsource.com/blog/pfsense-vulnerabilities-sonarcloud/
SANS Holiday Hack Challenge
https://sans.org/holidayhack
T-shooting Terraform for DShield Honeypot in Azure
https://isc.sans.edu/diary/T-shooting%20Terraform%20for%20DShield%20Honeypot%20in%20Azure%20%5BGuest%20Diary%5D/30484
Ubiquity Unifi Cameras Visible in Wrong Account
https://community.ui.com/questions/Bug-Fix-Cloud-Access-Misconfiguration/fe8d4479-e187-4471-bf95-b2799183ceb7
Zoom Vulnerabilities and VISS
https://viss.zoom.com/specifications
https://www.zoom.com/en/trust/security-bulletin/
Squid Denial of Service Vulnerability
https://www.zoom.com/en/trust/security-bulletin/
Malicious Python Script with a TCL/TK GUI
https://isc.sans.edu/diary/Malicious%20Python%20Script%20with%20a%20TCL%20TK%20GUI/30478
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
TeamCity Exploited
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-347a
Sophos Firewall Exploit for EOL Devices CVE-2022-3236
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20December%202023/30480
Microsoft Warns of Malicious OAUTH Applications
https://www.microsoft.com/en-us/security/blog/2023/12/12/threat-actors-misuse-oauth-applications-to-automate-financially-driven-attacks/
Apache Struts2 Exploit CVE-2023-50164
https://xz.aliyun.com/t/13172
What is Sitemap.xml and Why a Pentester Should Care
https://isc.sans.edu/diary/What%20is%20sitemap.xml%2C%20and%20Why%20a%20Pentester%20Should%20Care/30472
Apple Patches Everything
https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything/30474/
Android Password Manager Auto Spill
https://i.blackhat.com/EU-23/Presentations/EU-23-Gangwal-AutoSpill-Zero-Effort-Credential-Stealing.pdf
IPv4 Mapped IPv6 Addresses
https://isc.sans.edu/diary/IPv4-mapped%20IPv6%20Address%20Used%20For%20Obfuscation/30466
Honeypots From the Skeptical Beginner to the Tactical Enthusiast
https://isc.sans.edu/diary/Honeypots%3A%20From%20the%20Skeptical%20Beginner%20to%20the%20Tactical%20Enthusiast/30468
Bluetooth Weakness CVE-2023-45866
https://github.com/skysafe/reblog/tree/main/cve-2023-45866
Syrus 4 IoT Gateway Vulnerability CVE-2023-6248
https://socradar.io/syrus4-iot-gateway-vulnerability-could-allow-code-execution-on-thousands-of-vehicles-simultaneously-cve-2023-6248/
Microsoft Edge Vulnerability CVE-2023-35618
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnotes-security#december-7-2023
5G Vulnerabilities
https://isc.sans.edu/diary/5Ghoul%3A%20Impacts%2C%20Implications%20and%20Next%20Steps/30462
Revealing the hidden Risks of QR Codes
https://isc.sans.edu/diary/Revealing%20the%20Hidden%20Risks%20of%20QR%20Codes%20%5BGuest%20Diary%5D/30458
Window 10 End of Support
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/plan-for-windows-10-eos-with-windows-11-windows-365-and-esu/ba-p/4000414
Apache Struts 2 Vulnerability CVE-2023-50164
https://cwiki.apache.org/confluence/display/WW/S2-066
Whose packet is is anyway: a new RFC for attribution of internet probes
https://isc.sans.edu/forums/diary/Whose%20packet%20is%20it%20anyway%3A%20a%20new%20RFC%20for%20attribution%20of%20internet%20probes/30456/
MLFlow Vulnerability
https://www.contrastsecurity.com/security-influencers/discovering-mlflow-framework-zero-day-vulnerability-machine-language-model-security-contrast-security
https://mlflow.org/category/news/index.html
Abusing STS Tokens
https://redcanary.com/blog/aws-sts/
Atlasian Vulnerabilities
https://confluence.atlassian.com/security/security-advisories-bulletins-1236937381.html
Holiday Hack Challenge
https://www.sans.org/mlp/holiday-hack-challenge-2023/
Cobalt Strike's "Runtime Configuration"
https://isc.sans.edu/diary/Cobalt%20Strike%27s%20%22Runtime%20Configuration%22/30426
Adobe ColdFusion Exploit Abused
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a
Atos Unify OpenScape Vulnerability
https://sec-consult.com/vulnerability-lab/advisory/argument-injection-vulnerability-in-multiple-atos-unify-openscape-products/
ExtremeXOS Vulnerabilities
https://rhinosecuritylabs.com/research/extreme-networks-extremexos-vulnerabilities/
Zarya Hacktivists: More than just Sharepoint
https://isc.sans.edu/diary/Zarya%20Hacktivists%3A%20More%20than%20just%20Sharepoint./30450
ICANN Registration Data Request Service (RDRS)
https://rdrs.icann.org/
Android Updates
https://source.android.com/docs/security/bulletin/2023-12-01
GitLab Patches
https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/
UEFI Exploit via Boot Image
https://binarly.io/posts/The_Far_Reaching_Consequences_of_LogoFAIL/index.html
Fake Phishing Scan Tricks Users into Installing Backdoor Plugin
https://www.wordfence.com/blog/2023/12/psa-fake-cve-2023-45124-phishing-scam-tricks-users-into-installing-backdoor-plugin/
Qlik Sense Exploited by Cactus Ransomware
https://arcticwolf.com/resources/blog/qlik-sense-exploited-in-cactus-ransomware-campaign/
https://www.praetorian.com/blog/qlik-sense-technical-exploit/
VMWare Vulnerability Patched
https://www.vmware.com/security/advisories/VMSA-2023-0026.html
Apple Updates
https://isc.sans.edu/diary/Apple+Patches+Exploited+WebKit+Vulnerabilitiues+in+iOSiPadOSmacOS/30444
Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today
https://isc.sans.edu/forums/diary/Prophetic+Post+by+Intern+on+CVE20231389+Foreshadows+Mirai+Botnet+Expansion+Today/30442/
Zyxel Vulnerabilities
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-authentication-bypass-and-command-injection-vulnerabilities-in-nas-products
Solarwinds Update
https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-4_release_notes.htm#link3
DNS Looking Glass
https://isc.sans.edu/tools/dnslookup/
Decoding the Patterns: Analzying DShield Honeypot Activity
https://isc.sans.edu/diary/Decoding%20the%20Patterns%3A%20Analyzing%20DShield%20Honeypot%20Activity%20%5BGuest%20Diary%5D/30428
Arcserve Unified Data Protection Multiple Vulnerabilities
https://www.tenable.com/security/research/tra-2023-37
Hikvision Vulnerabilities
https://www.hikvision.com/hk/support/cybersecurity/security-advisory/security-vulnerability-in-some-hikvision-products/
Assessing Prompt Injection Risks in 200+ Custom GPTs
https://arxiv.org/pdf/2311.11538.pdf
Pro-Russian Attackers Scanning for Sharepoint Servers to Exploit CVE-2023-29357
https://isc.sans.edu/diary/Pro%20Russian%20Attackers%20Scanning%20for%20Sharepoint%20Servers%20to%20Exploit%20CVE-2023-29357/30436
Microsoft Deprecates Microsoft Defender Application Guard for Office
https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features
Synology Vulnerability
https://www.synology.com/en-global/security/advisory/Synology_SA_23_16
Apache Tomcat Request Smuggling Vulnerability CVE-2023-46589
https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxr
Scans for ownCloud Vulnerability (CVE-2023-49103)
https://isc.sans.edu/diary/Scans%20for%20ownCloud%20Vulnerability%20%28CVE-2023-49103%29/30432
Windows Hello Fingerprint Reader Weakness
https://blackwinghq.com/blog/posts/a-touch-of-pwn-part-i/
DShield Birthday
https://isc.sans.edu/diary/Happy%20Birthday%20DShield/30420
Mirai uses CVE-2023-1389
https://isc.sans.edu/diary/CVE-2023-1389%3A%20A%20New%20Means%20to%20Expand%20Botnets/30418
More Mirai Vulnerabilities
https://www.akamai.com/blog/security-research/new-rce-botnet-spreads-mirai-via-zero-days
Analyzing OVA Files
https://isc.sans.edu/diary/OVA%20Files/30424
Static Code Injections in OpenCart (CVE-2023-47444)
https://github.com/opencart/opencart/issues/12947
Holiday Hackchallenge
https://www.sans.org/mlp/holiday-hack-challenge-2023/
Beyond -n: Optimizign tcpdump performance
https://isc.sans.edu/forums/diary/Beyond%20-n%3A%20Optimizing%20tcpdump%20performance/30408/
Zimbra 0-day used to target international government organizations
https://blog.google/threat-analysis-group/zimbra-0-day-used-to-target-international-government-organizations/
FortiSIEM OS command injection in Report Server
https://www.fortiguard.com/psirt/FG-IR-23-135
AI Exploit Collection
https://github.com/protectai/ai-exploits
CrushFTP Remote Code Execution
https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/
Scott Poley: The Cyber Date Paradox: Storing Less, Discovering More
https://www.sans.edu/cyber-research/cyber-data-paradox-storing-less-discovering-more/
Redline Dropped Through MSIX Package
https://isc.sans.edu/diary/Redline%20Dropped%20Through%20MSIX%20Package/30404
ChatGPT Code Interpreter Security Hole
https://www.tomshardware.com/news/chatgpt-code-interpreter-security-hole
Directory Traversal in Reactor Netty CVE-2023-34062
https://spring.io/security/cve-2023-34062
Aruba Networking Product Vulnerabilities
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt
HARArmor
https://harmor.dev/
Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20Patch%20Tuesday%20November%202023/30400
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
Intel CPU Glitch State Patch
https://lock.cmpxchg8b.com/reptar.html
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00950.html
Noticing command control channels by reviewing DNS protocols
https://isc.sans.edu/diary/Noticing%20command%20and%20control%20channels%20by%20reviewing%20DNS%20protocols/30396
Passive SSH Key Compromise via Lattices
https://eprint.iacr.org/2023/1711.pdf
Juniper Vulnerabilities Exploited
https://supportportal.juniper.net/s/article/2023-08-Out-of-Cycle-Security-Bulletin-Junos-OS-SRX-Series-and-EX-Series-Multiple-vulnerabilities-in-J-Web-can-be-combined-to-allow-a-preAuth-Remote-Code-Execution?language=en_US
Routers Targeted for Gafgyt Botnet
https://isc.sans.edu/forums/diary/Routers%20Targeted%20for%20Gafgyt%20Botnet%20%5BGuest%20Diary%5D/30390/
ScreenConnect used to Attack Healthcare
https://www.huntress.com/blog/third-party-pharmaceutical-vendor-linked-to-pharmacy-and-health-clinic-cyberattack
Fake Skills Assessment Portals Associated with Sapphire Sleet
https://twitter.com/MsftSecIntel/status/1722316019920728437
OpenVPN Access Server Vulnerabilities
https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/
Visual Examples of Code Injection
https://isc.sans.edu/diary/Visual%20Examples%20of%20Code%20Injection/30388
SysAid Exploited by Cl0p Ransomware (CVE-2023-47246)
https://www.sysaid.com/blog/service-desk/on-premise-software-security-vulnerability-notification
WS_FTP Server Update CVE-2023-42659
https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2023
Malvertiser copies PC news site to delivery infostealer
https://www.malwarebytes.com/blog/threat-intelligence/2023/11/malvertiser-copies-pc-news-site-to-deliver-infostealer
pyArrow/Apache Arrow Vulnerability
https://lists.apache.org/thread/yhy7tdfjf9hrl9vfrtzo8p2cyjq87v7n
Example of a Phishing Campaing Project File
https://isc.sans.edu/diary/Example%20of%20Phishing%20Campaign%20Project%20File/30384
Cryptomining with Microsoft Azure Automation Services
https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure
Windows 11 Insider Changing Firewall Behaviour
https://blogs.windows.com/windows-insider/2023/11/08/announcing-windows-11-insider-preview-build-25992-canary-channel/
CISA Adds SLP Vulnerability to Known Exploited Vulnerabilty List
https://www.cisa.gov/news-events/alerts/2023/11/08/cisa-adds-one-known-exploited-vulnerability-catalog
What's Normal: New uses of DNS, Discovery of Designated Resolvers (DDR)
https://isc.sans.edu/diary/What%27s%20Normal%3A%20New%20uses%20of%20DNS%2C%20Discovery%20of%20Designated%20Resolvers%20%28DDR%29/30380
BlueNoroff macOS Malware
https://www.jamf.com/blog/bluenoroff-strikes-again-with-new-macos-malware/
Emphasizing Security by Default wiht Advanced Microsoft Authenticator Features
https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/emphasizing-security-by-default-with-advanced-microsoft/ba-p/3773130
Confluence CVe-2023-22518 Exploited
https://isc.sans.edu/diary/Exploit%20Activity%20for%20CVE-2023-22518%2C%20Atlassian%20Confluence%20Data%20Center%20and%20Server/30376
Google Threat Horizons Report
https://services.google.com/fh/files/blogs/gcat_threathorizons_full_oct2023.pdf
https://www.sans.edu/cyber-research/bookmark-bruggling-novel-data-exfiltration-with-brugglemark/
Veeam Update
https://www.veeam.com/kb4508
QNAP Update
https://www.qnap.com/de-de/security-advisory/qsa-23-35
New Microsoft Exchange Zero Days
https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/
StripedFly: Perennially Flying under the Radar
https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/
Send My: Sending Data over Apple's Find My Network
https://github.com/positive-security/send-my
New Microsoft Exchange Zero Days
https://www.bleepingcomputer.com/news/microsoft/new-microsoft-exchange-zero-days-allow-rce-data-theft-attacks/
StripedFly: Perennially Flying under the Radar
https://securelist.com/stripedfly-perennially-flying-under-the-radar/110903/
Send My: Sending Data over Apple's Find My Network
https://github.com/positive-security/send-my
Quick Tip for Artificially Inflated PE Files
https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370
Apache ActiveMQ Flaw Exploited
https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt
https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/
Critical Firepower Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN
Dozens of npm Packages Caught Attempting to Deploy Reverse Shell
https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/
Quick Tip for Artificially Inflated PE Files
https://isc.sans.edu/diary/Quick%20Tip%20For%20Artificially%20Inflated%20PE%20Files/30370
Apache ActiveMQ Flaw Exploited
https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt
https://www.rapid7.com/blog/post/2023/11/01/etr-suspected-exploitation-of-apache-activemq-cve-2023-46604/
Critical Firepower Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-cmd-inj-29MP49hN
Dozens of npm Packages Caught Attempting to Deploy Reverse Shell
https://blog.phylum.io/dozens-of-npm-packages-caught-attempting-to-deploy-reverse-shell/
Malware Dropped Through a ZPAQ Archive
https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/
CVSS 4.0 Now Official
https://www.first.org/cvss/v4-0/index.html
MOZI Botnet Killswitch
https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/
URL Shorteners in .us
https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/
Impersonating Slack Users
https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html
Malware Dropped Through a ZPAQ Archive
https://isc.sans.edu/forums/diary/Malware%20Dropped%20Through%20a%20ZPAQ%20Archive/30366/
CVSS 4.0 Now Official
https://www.first.org/cvss/v4-0/index.html
MOZI Botnet Killswitch
https://www.welivesecurity.com/en/eset-research/who-killed-mozi-finally-putting-the-iot-zombie-botnet-in-its-grave/
URL Shorteners in .us
https://securityonline.info/infoblox-uncovers-malicious-wave-in-us-domain-registrations/
Impersonating Slack Users
https://falconspy.org/redteam/tradecraft/2023/10/05/2023-10-05-Slack-Impersonation.html
Multiple Layers of Anti-Sandboxing Techniques
https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362
CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server
https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html
Malvertisement Promotes Malicious PyCharm Version
https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza
Thorn SFTP Gateway Java Deserialization RCE CVE-2016-1000027 CVE-2023-47174
https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/
Multiple Layers of Anti-Sandboxing Techniques
https://isc.sans.edu/diary/Multiple%20Layers%20of%20Anti-Sandboxing%20Techniques/30362
CVE-2023-22518 Improper Authorization Vulnerability in Confluence Data Center and Server
https://confluence.atlassian.com/security/cve-2023-22518-improper-authorization-vulnerability-in-confluence-data-center-and-server-1311473907.html
Malvertisement Promotes Malicious PyCharm Version
https://www.malwarebytes.com/blog/threat-intelligence/2023/10/malvertising-via-dynamic-search-ads-delivers-malware-bonanza
Thorn SFTP Gateway Java Deserialization RCE CVE-2016-1000027 CVE-2023-47174
https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/
Flying under the Radar: The Privacy Impact of Mulicast DNS
https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/
Kubernetes ingress-nginx vulnerability
https://github.com/kubernetes/ingress-nginx/issues/10571
Google Chrome HTTPS Upgrade
https://github.com/dadrian/https-upgrade/blob/main/explainer.md
Wordpad POC CVE-2023-36563
https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/
Flying under the Radar: The Privacy Impact of Mulicast DNS
https://isc.sans.edu/forums/diary/Flying%20under%20the%20Radar%3A%20The%20Privacy%20Impact%20of%20multicast%20DNS/30358/
Kubernetes ingress-nginx vulnerability
https://github.com/kubernetes/ingress-nginx/issues/10571
Google Chrome HTTPS Upgrade
https://github.com/dadrian/https-upgrade/blob/main/explainer.md
Wordpad POC CVE-2023-36563
https://www.dillonfrankesecurity.com/posts/cve-2023-36563-wordpad-analysis/
Size Matters for Many Security Controls
https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352
Spam or Phishing? Looking for Credentials and Passwords
https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354
iOS Leaks MAC Address
https://www.youtube.com/watch?v=T3XABxNogTA
Zero Day Initiative Pwn2Own Summary
https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results
https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results
https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results
Microsoft Octo Tempest Writeup
https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/
Size Matters for Many Security Controls
https://isc.sans.edu/diary/Size%20Matters%20for%20Many%20Security%20Controls/30352
Spam or Phishing? Looking for Credentials and Passwords
https://isc.sans.edu/diary/Spam%20or%20Phishing%3F%20Looking%20for%20Credentials%20%26%20Passwords/30354
iOS Leaks MAC Address
https://www.youtube.com/watch?v=T3XABxNogTA
Zero Day Initiative Pwn2Own Summary
https://www.zerodayinitiative.com/blog/2023/10/24/pwn2own-toronto-2023-day-one-results
https://www.zerodayinitiative.com/blog/2023/10/25/pwn2own-toronto-2023-day-two-results
https://www.zerodayinitiative.com/blog/2023/10/26/pwn2own-toronto-2023-day-three-results
Microsoft Octo Tempest Writeup
https://www.microsoft.com/en-us/security/blog/2023/10/25/octo-tempest-crosses-boundaries-to-facilitate-extortion-encryption-and-destruction/
Adventures in Validating IPv4 Addresses
https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/
BIG-IP Configuration Utility Unauthenticated Remote Code Execution
https://my.f5.com/manage/s/article/K000137353
https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/
iLeakage Vulnerability
https://ileakage.com/
Adventures in Validating IPv4 Addresses
https://isc.sans.edu/forums/diary/Adventures%20in%20Validating%20IPv4%20Addresses/30348/
BIG-IP Configuration Utility Unauthenticated Remote Code Execution
https://my.f5.com/manage/s/article/K000137353
https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/
iLeakage Vulnerability
https://ileakage.com/
Apple Updates
https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344
Confluence Server Scans CVE-2023-22515
https://isc.sans.edu/diary/30342
Critical VMVware vCenter Patch CVE-2023-34048
https://www.vmware.com/security/advisories/VMSA-2023-0023.html
Apple Updates
https://isc.sans.edu/diary/Apple%20Patches%20Everything.%20Releases%20iOS%2017.1%2C%20MacOS%2014.1%20and%20updates%20for%20older%20versions%20fixing%20exploited%20vulnerability/30344
Confluence Server Scans CVE-2023-22515
https://isc.sans.edu/diary/30342
Critical VMVware vCenter Patch CVE-2023-34048
https://www.vmware.com/security/advisories/VMSA-2023-0023.html
Samsung Messages and Samsung Wallet briefly marked as 'harmful' by Google
https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/
OAuth Hijacking
https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts
Microsoft Exchange Server CVe-2023-36745 PoC
https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/
Citrix Bleed PoC CVe-2023-4966
https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966
VMWare VRealize Exploit CVE-2023-34051 CVE0-2023-34052
https://www.vmware.com/security/advisories/VMSA-2023-0021.html
Samsung Messages and Samsung Wallet briefly marked as 'harmful' by Google
https://9to5google.com/2023/10/23/samsung-messages-wallet-harmful-app-google/
OAuth Hijacking
https://salt.security/blog/oh-auth-abusing-oauth-to-take-over-millions-of-accounts
Microsoft Exchange Server CVe-2023-36745 PoC
https://n1k0la-t.github.io/2023/10/24/Microsoft-Exchange-Server-CVE-2023-36745/
Citrix Bleed PoC CVe-2023-4966
https://www.assetnote.io/resources/research/citrix-bleed-leaking-session-tokens-with-cve-2023-4966
VMWare VRealize Exploit CVE-2023-34051 CVE0-2023-34052
https://www.vmware.com/security/advisories/VMSA-2023-0021.html
Apple TV IPv6 DoS
https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336
Squid Patches
https://github.com/squid-cache/squid/security/advisories
Critical Citrix Update
https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/
Cisco Vulnerablity Updates CVE-2023-20198
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z
Apple TV IPv6 DoS
https://isc.sans.edu/diary/How%20an%20AppleTV%20may%20take%20down%20your%20%28%23IPv6%29%20network/30336
Squid Patches
https://github.com/squid-cache/squid/security/advisories
Critical Citrix Update
https://www.netscaler.com/blog/news/cve-2023-4966-critical-security-update-now-available-for-netscaler-adc-and-netscaler-gateway/
Cisco Vulnerablity Updates CVE-2023-20198
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z
base64dump.py Handles More Encodings Than Just BASE64
https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332
Stealing OAuth Tokens via Open Redirects
https://eval.blog/research/microsoft-account-token-leaks-in-harvest/
VMWare Patches
https://www.vmware.com/security/advisories.html
Solarwinds Patches
https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm
base64dump.py Handles More Encodings Than Just BASE64
https://isc.sans.edu/diary/base64dump.py%20Handles%20More%20Encodings%20Than%20Just%20BASE64/30332
Stealing OAuth Tokens via Open Redirects
https://eval.blog/research/microsoft-account-token-leaks-in-harvest/
VMWare Patches
https://www.vmware.com/security/advisories.html
Solarwinds Patches
https://documentation.solarwinds.com/en/success_center/arm/content/release_notes/arm_2023-2-1_release_notes.htm
Honeypot Update
https://github.com/DShield-ISC/dshield/blob/main/README.md
Malicious Keepass Ads
https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website
Malicious JavaScript in Smart Contracts
https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16
Honeypot Update
https://github.com/DShield-ISC/dshield/blob/main/README.md
Malicious Keepass Ads
https://www.malwarebytes.com/blog/threat-intelligence/2023/10/clever-malvertising-attack-uses-punycode-to-look-like-legitimate-website
Malicious JavaScript in Smart Contracts
https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16
Hiding in Hex
https://isc.sans.edu/diary/Hiding%20in%20Hex/30322
Oracle Quarterly Critical Patch Update
https://www.oracle.com/security-alerts/cpuoct2023.html
Citrix Vulnerability Exploited CVE-2023-4966
https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966
Exposed Jupyter Notebooks Exploited
https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/
Hiding in Hex
https://isc.sans.edu/diary/Hiding%20in%20Hex/30322
Oracle Quarterly Critical Patch Update
https://www.oracle.com/security-alerts/cpuoct2023.html
Citrix Vulnerability Exploited CVE-2023-4966
https://www.mandiant.com/resources/blog/remediation-netscaler-adc-gateway-cve-2023-4966
Exposed Jupyter Notebooks Exploited
https://www.cadosecurity.com/qubitstrike-an-emerging-malware-campaign-targeting-jupyter-notebooks/
Changes to SMS Delivery and How it Effects MFA and Phishing
https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320
Fake Traffic Tickets with QR Code
https://twitter.com/polizeiberlin/status/1713867011837567411
Synology NAS DSM Account Takeover: Not Random Randomnumbers
https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure
Milesight Routers CVe-2023-43261
https://github.com/win3zz/CVE-2023-43261
Changes to SMS Delivery and How it Effects MFA and Phishing
https://isc.sans.edu/diary/Changes%20to%20SMS%20Delivery%20and%20How%20it%20Effects%20MFA%20and%20Phishing/30320
Fake Traffic Tickets with QR Code
https://twitter.com/polizeiberlin/status/1713867011837567411
Synology NAS DSM Account Takeover: Not Random Randomnumbers
https://claroty.com/team82/research/synology-nas-dsm-account-takeover-when-random-is-not-secure
Milesight Routers CVe-2023-43261
https://github.com/win3zz/CVE-2023-43261
Are Typos Still relevant As An Indicator of Phishing
https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316
Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln
https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/
Mail traffic to cancelled domain names
https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names
SAMBA Update
https://www.samba.org/samba/history/security.html
Are Typos Still relevant As An Indicator of Phishing
https://isc.sans.edu/diary/Are+typos+still+relevant+as+an+indicator+of+phishing/30316
Active Exploitation of Cisco ISO XE Software Web Management User Interface Vuln
https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/
Mail traffic to cancelled domain names
https://www.sidn.nl/en/nl-domain-name/mail-traffic-to-cancelled-domain-names
SAMBA Update
https://www.samba.org/samba/history/security.html
What's Normal: Odd Mac Addresses
https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/
Domain Name Used as Password Captured by DShield Sensor
https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/
PoC Exploit for CVE-2023-41993
https://github.com/po6ix/POC-for-CVE-2023-41993
AvosLocker Ransomware Details
https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf
DarkGate Spreading via Skype and Teams
https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html
What's Normal: Odd Mac Addresses
https://isc.sans.edu/forums/diary/What's%20Normal%3A%20MAC%20Addresses/30310/
Domain Name Used as Password Captured by DShield Sensor
https://isc.sans.edu/forums/diary/Domain%20Name%20Used%20as%20Password%20Captured%20by%20DShield%20Sensor/30312/
PoC Exploit for CVE-2023-41993
https://github.com/po6ix/POC-for-CVE-2023-41993
AvosLocker Ransomware Details
https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf
DarkGate Spreading via Skype and Teams
https://www.trendmicro.com/en_ph/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html
SeroXen RAT in Typosquatted NuGet Packages
https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/
Hexadecimal IP Addresses
https://asec.ahnlab.com/en/57635/
Juniper Vulnerabilities
https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&numberOfResults=50&f:ctype=[Security%20Advisories]
Unpatched Squid Vulnerabilities
https://joshua.hu/squid-security-audit-35-0days-45-exploits
BSIDES Jacksonville
https://bsidesjax.org
SeroXen RAT in Typosquatted NuGet Packages
https://blog.phylum.io/phylum-discovers-seroxen-rat-in-typosquatted-nuget-package/
Hexadecimal IP Addresses
https://asec.ahnlab.com/en/57635/
Juniper Vulnerabilities
https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=%40sfcec_community_publish_date_formula__c%20descending&numberOfResults=50&f:ctype=[Security%20Advisories]
Unpatched Squid Vulnerabilities
https://joshua.hu/squid-security-audit-35-0days-45-exploits
BSIDES Jacksonville
https://bsidesjax.org
CVE-2023-22515 Activately Exploited
https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html
curl SOCKS5 oversized hostname vulnerability CVe-2023-38545
https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304
Adobe Acrobat Vulnerablity Actively Exploited CVE-2023-21608
https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog
Google Makes Passkey the Default
https://blog.google/technology/safety-security/passkeys-default-google-accounts/
VBScript Deprecated from Windows
https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features
CVE-2023-22515 Activately Exploited
https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html
curl SOCKS5 oversized hostname vulnerability CVe-2023-38545
https://isc.sans.edu/diary/CVE-2023-38545%3A%20curl%20SOCKS5%20oversized%20hostname%20vulnerability.%20How%20bad%20is%20it%3F/30304
Adobe Acrobat Vulnerablity Actively Exploited CVE-2023-21608
https://www.cisa.gov/news-events/alerts/2023/10/10/cisa-adds-five-known-vulnerabilities-catalog
Google Makes Passkey the Default
https://blog.google/technology/safety-security/passkeys-default-google-accounts/
VBScript Deprecated from Windows
https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features
http2 rapid reset
https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
microsoft patch tuesday
https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300
http2 rapid reset
https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
microsoft patch tuesday
https://isc.sans.edu/diary/October%202023%20Microsoft%20Patch%20Tuesday%20Summary/30300
ZIP's DOSTIME and DOSDATE Formats
https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296
New Magecart Campaign Abusing 404 Pages
https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer
Sophos Effected by Exim Flaw
https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln
Turn OFF This WatchGuard Feature: GuardLapse
https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/
ZIP's DOSTIME and DOSDATE Formats
https://isc.sans.edu/diary/ZIP%27s%20DOSTIME%20%26%20DOSDATE%20Formats/30296
New Magecart Campaign Abusing 404 Pages
https://www.akamai.com/blog/security-research/magecart-new-technique-404-pages-skimmer
Sophos Effected by Exim Flaw
https://www.sophos.com/en-us/security-advisories/sophos-sa-20231005-exim-vuln
Turn OFF This WatchGuard Feature: GuardLapse
https://projectblack.io/blog/turn-off-this-watchguard-feature-guardlapse/
Binary IPv6 Address Conversion
https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290
Wireshark Updates
https://www.wireshark.org/
Improved GitHub Secret Scanning
https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/
Prerooted Android Devices
https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/
curl update
https://github.com/curl/curl/discussions/12026
Binary IPv6 Address Conversion
https://isc.sans.edu/diary/Binary%20IPv6%20Addresses/30290
Wireshark Updates
https://www.wireshark.org/
Improved GitHub Secret Scanning
https://github.blog/2023-10-04-introducing-secret-scanning-validity-checks-for-major-cloud-services/
Prerooted Android Devices
https://arstechnica.com/security/2023/10/thousands-of-android-devices-come-with-unkillable-backdoor-preinstalled/
curl update
https://github.com/curl/curl/discussions/12026
New tool: le-hex-to-ip.py
https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284
Cisco Emergency Responder Static Credentials Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9
Loony Tunables PoC CVE-2023-4911
https://haxx.in/files/gnu-acme.py
Malicious Python Packages
https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/
Supermicro BMC Vulnerability
https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html
New tool: le-hex-to-ip.py
https://isc.sans.edu/diary/New%20tool%3A%20le-hex-to-ip.py/30284
Cisco Emergency Responder Static Credentials Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cer-priv-esc-B9t3hqk9
Loony Tunables PoC CVE-2023-4911
https://haxx.in/files/gnu-acme.py
Malicious Python Packages
https://checkmarx.com/blog/the-evolutionary-tale-of-a-persistent-python-threat/
Supermicro BMC Vulnerability
https://binarly.io/posts/Binarly_REsearch_Uncovers_Major_Vulnerabilities_in_Supermicro_BMCs/index.html
Normal Connections
https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/
Apple Patches
https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280
Looney Tunables Linux Privilege Escalation
https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so
Atlasian Confluence Server Vulnerability
https://jira.atlassian.com/browse/CONFSERVER-92475
Normal Connections
https://isc.sans.edu/diary/Whats+Normal+Connection+Sizes/30278/
Apple Patches
https://isc.sans.edu/diary/Apple%20fixes%20vulnerabilities%20in%20iOS%20and%20iPadOS./30280
Looney Tunables Linux Privilege Escalation
https://blog.qualys.com/vulnerabilities-threat-research/2023/10/03/cve-2023-4911-looney-tunables-local-privilege-escalation-in-the-glibcs-ld-so
Atlasian Confluence Server Vulnerability
https://jira.atlassian.com/browse/CONFSERVER-92475
Are Local LLMs Useful in Incident Response?
https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274
Pytorch Vulnerability
https://github.com/advisories/GHSA-4mqg-h5jf-j9m7
BING Reads Captchas
https://twitter.com/literallydenis/status/1708283962399846459
Evilproxy vs. Microsoft 365
https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/
Are Local LLMs Useful in Incident Response?
https://isc.sans.edu/diary/Are%20Local%20LLMs%20Useful%20in%20Incident%20Response%3F/30274
Pytorch Vulnerability
https://github.com/advisories/GHSA-4mqg-h5jf-j9m7
BING Reads Captchas
https://twitter.com/literallydenis/status/1708283962399846459
Evilproxy vs. Microsoft 365
https://www.menlosecurity.com/blog/evilproxy-phishing-attack-strikes-indeed/
Friendly Reminder: ZIP Metadata is Not Encrypted
https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268
EXIM New Version Released
https://www.exim.org/static/doc/security/CVE-2023-zdi.txt
Mail GPU Kernel Driver Allows Improper GPU Memory Processing Operations
https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
Bing AI Serves Malicous Ads
https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot
Google Announces Robots.txt Ad-Restrictions
https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android
Friendly Reminder: ZIP Metadata is Not Encrypted
https://isc.sans.edu/diary/Friendly%20Reminder%3A%20ZIP%20Metadata%20is%20Not%20Encrypted/30268
EXIM New Version Released
https://www.exim.org/static/doc/security/CVE-2023-zdi.txt
Mail GPU Kernel Driver Allows Improper GPU Memory Processing Operations
https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
Bing AI Serves Malicous Ads
https://www.malwarebytes.com/blog/threat-intelligence/2023/09/malicious-ad-served-inside-bing-ai-chatbot
Google Announces Robots.txt Ad-Restrictions
https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers#adsbot-mobile-web-android
Analyzing MIME Files: a Quick Tip
https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266
Infostealers Looking for Password Files
https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/
Simple Netcat Backdoor
https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/
EXIM Response to the ZDI Release
https://exim.org/static/doc/security/CVE-2023-zdi.txt
Exploit for WS_FTP Vulnerability
https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044
Analyzing MIME Files: a Quick Tip
https://isc.sans.edu/diary/Analyzing%20MIME%20Files%3A%20a%20Quick%20Tip/30266
Infostealers Looking for Password Files
https://isc.sans.edu/diary/Are+You+Still+Storing+Passwords+In+Plain+Text+Files/30262/
Simple Netcat Backdoor
https://isc.sans.edu/diary/Simple+Netcat+Backdoor+in+Python+Script/30264/
EXIM Response to the ZDI Release
https://exim.org/static/doc/security/CVE-2023-zdi.txt
Exploit for WS_FTP Vulnerability
https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-iis-http-modules-cve-2023-40044
IPv4 Addresses in Little Endian Decimal Format
https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256
Chrome Update fixes 0-day Vulnerability
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html
Unpatched EXIM Vulnerabilities
https://www.zerodayinitiative.com/advisories/ZDI-23-1469/
WS_FTP Vulnerabilities
https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023
IPv4 Addresses in Little Endian Decimal Format
https://isc.sans.edu/diary/IPv4%20Addresses%20in%20Little%20Endian%20Decimal%20Format/30256
Chrome Update fixes 0-day Vulnerability
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html
Unpatched EXIM Vulnerabilities
https://www.zerodayinitiative.com/advisories/ZDI-23-1469/
WS_FTP Vulnerabilities
https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023
GPU Sidechannel Attack
https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf
Router Firmware Compromised for Persistent Access
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a
More libwebp vulnerability confusion
https://www.cve.org/CVERecord?id=CVE-2023-5129
https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/
Fake Dependabot Commits
https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/
GPU Sidechannel Attack
https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf
Router Firmware Compromised for Persistent Access
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csa-cyber-report-sept-2023
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-270a
More libwebp vulnerability confusion
https://www.cve.org/CVERecord?id=CVE-2023-5129
https://arstechnica.com/security/2023/09/google-quietly-corrects-previously-submitted-disclosure-for-critical-webp-0-day/
Fake Dependabot Commits
https://checkmarx.com/blog/surprise-when-dependabot-contributes-malicious-code/
A new spint on the ZeroFont phishing technique
https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248
macOS Sonoma Updates
https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252
A new spint on the ZeroFont phishing technique
https://isc.sans.edu/diary/A%20new%20spin%20on%20the%20ZeroFont%20phishing%20technique/30248
macOS Sonoma Updates
https://isc.sans.edu/diary/Apple%20Releases%20MacOS%20Sonoma%20Including%20Numerous%20Security%20Patches/30252
LuaJIT Malware
https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/
NPM systeminformation flaw
https://systeminformation.io/security.html
Team City Authentication Bypass
https://twitter.com/ptswarm/status/1706223917008834748
LuaJIT Malware
https://www.sentinelone.com/labs/sandman-apt-a-mystery-group-targeting-telcos-with-a-luajit-toolkit/
NPM systeminformation flaw
https://systeminformation.io/security.html
Team City Authentication Bypass
https://twitter.com/ptswarm/status/1706223917008834748
Scanning for Laravel - a PHP Framework for Web Artisants
https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/
Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT
https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/
Unmasking a Sophistiacted Phishing Campaign That Targets Hotel Guests
https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality
BSides JAX October 14th
https://www.bsidesjax.org/
tickets: https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator
Scanning for Laravel - a PHP Framework for Web Artisants
https://isc.sans.edu/forums/diary/Scanning%20for%20Laravel%20-%20a%20PHP%20Framework%20for%20Web%20Artisants/30242/
Fake CVE-2023-40477 Proof of Concept Leads to VenomRAT
https://unit42.paloaltonetworks.com/fake-cve-2023-40477-poc-hides-venomrat/
Unmasking a Sophistiacted Phishing Campaign That Targets Hotel Guests
https://www.akamai.com/blog/security-research/sophisticated-phishing-campaign-targeting-hospitality
BSides JAX October 14th
https://www.bsidesjax.org/
tickets: https://www.eventbrite.com/e/bsides-jacksonville-2023-registration-566463807497?aff=oddtdtcreator
Apple Patches Three 0-Days
https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238
WebP Vulnerability
https://blog.isosceles.com/the-webp-0day/
MOVEit Transfer Service Pack
https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023
Improved Passkey Support in Windows 11
https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/
Apple Patches Three 0-Days
https://isc.sans.edu/diary/Apple+Patches+Three+New+0Day+Vulnerabilities+Affecting+iOSiPadOSwatchOSmacOS/30238
WebP Vulnerability
https://blog.isosceles.com/the-webp-0day/
MOVEit Transfer Service Pack
https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-September-2023
Improved Passkey Support in Windows 11
https://www.microsoft.com/en-us/security/blog/2023/09/21/new-microsoft-security-tools-to-protect-families-and-businesses/
What's Normal: DNS TTL Values
https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/
CISA Highlights Snatch Ransomware
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a
npm packages caught exfiltrating Kubernetes config, SSH keys
https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys
Nagios XI Vulnerabilities
https://outpost24.com/blog/nagios-xi-vulnerabilities/
What's Normal: DNS TTL Values
https://isc.sans.edu/forums/diary/What's%20Normal%3F%20DNS%20TTL%20Values/30234/
CISA Highlights Snatch Ransomware
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a
npm packages caught exfiltrating Kubernetes config, SSH keys
https://blog.sonatype.com/npm-packages-caught-exfiltrating-kubernetes-config-ssh-keys
Nagios XI Vulnerabilities
https://outpost24.com/blog/nagios-xi-vulnerabilities/
Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities
https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230
Trend Micro Apex One 0-day
https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US
SprySOCKS Backdoor
https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html
GitLab Patches
https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/
Obfuscated Scans For Older Adobe Experience Manager Vulnerabilities
https://isc.sans.edu/diary/Obfuscated%20Scans%20for%20Older%20Adobe%20Experience%20Manager%20Vulnerabilities/30230
Trend Micro Apex One 0-day
https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US
SprySOCKS Backdoor
https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html
GitLab Patches
https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/
Internet Wide Multi VPN Search from Single /24 Network
https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226
iOS/iPadOS/tvOS/WatchOS Updates
https://support.apple.com/en-us/HT201222
Juniper Vuln Details/Exploit CVE-2023-36845
https://vulncheck.com/blog/juniper-cve-2023-36845
Internet Wide Multi VPN Search from Single /24 Network
https://isc.sans.edu/diary/Internet%20Wide%20Multi%20VPN%20Search%20From%20Single%20%2024%20Network/30226
iOS/iPadOS/tvOS/WatchOS Updates
https://support.apple.com/en-us/HT201222
Juniper Vuln Details/Exploit CVE-2023-36845
https://vulncheck.com/blog/juniper-cve-2023-36845
When MFA isn't actually MFA
https://retool.com/blog/mfa-isnt-mfa/
QNAP Patches
https://www.qnap.com/en/security-advisories?ref=security_advisory_details
Chrome able to use Apple Keychain Passkeys
https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/
Fortinet XSS
https://fortiguard.fortinet.com/psirt/FG-IR-23-106
vBulletin XSS
https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c
When MFA isn't actually MFA
https://retool.com/blog/mfa-isnt-mfa/
QNAP Patches
https://www.qnap.com/en/security-advisories?ref=security_advisory_details
Chrome able to use Apple Keychain Passkeys
https://9to5google.com/2023/09/14/chrome-118-icloud-passkey/
Fortinet XSS
https://fortiguard.fortinet.com/psirt/FG-IR-23-106
vBulletin XSS
https://gist.github.com/GiongfNef/8fe658dce4c7fcf3a7b4e6387e50141c
DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G
https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216
Uncursing the ncurses memory corruption vulnerabilities
https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/
Arbitrary code execution via Windows Themes (CVE-2023-38146)
https://exploits.forsale/themebleed/
3AM Ransomware used if LockBit Fails
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit
DShield and eqmu Sitting in a Tree: L-O-G-G-I-N-G
https://isc.sans.edu/diary/DShield%20and%20qemu%20Sitting%20in%20a%20Tree%3A%20L-O-G-G-I-N-G/30216
Uncursing the ncurses memory corruption vulnerabilities
https://www.microsoft.com/en-us/security/blog/2023/09/14/uncursing-the-ncurses-memory-corruption-vulnerabilities-found-in-library/
Arbitrary code execution via Windows Themes (CVE-2023-38146)
https://exploits.forsale/themebleed/
3AM Ransomware used if LockBit Fails
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/3am-ransomware-lockbit
Backdoored Free DownloadManager
https://securelist.com/backdoored-free-download-manager-linux-malware/110465/
Foxit PDF Reader Updates
https://www.foxit.com/support/security-bulletins.html
macOS MetaStealer: New Family of Obfuscated Go Infostealers
https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/
Windows 11 to Support Blocking SMB NTLM Hashes
https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206
Backdoored Free DownloadManager
https://securelist.com/backdoored-free-download-manager-linux-malware/110465/
Foxit PDF Reader Updates
https://www.foxit.com/support/security-bulletins.html
macOS MetaStealer: New Family of Obfuscated Go Infostealers
https://www.sentinelone.com/blog/macos-metastealer-new-family-of-obfuscated-go-infostealers-spread-in-targeted-attacks/
Windows 11 to Support Blocking SMB NTLM Hashes
https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-ntlm-blocking-now-supported-in-windows-insider/ba-p/3916206
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214
OpenSSL 1.1.1 End of Life
https://www.openssl.org/blog/blog/2023/09/11/eol-111/
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20September%202023%20Patch%20Tuesday/30214
OpenSSL 1.1.1 End of Life
https://www.openssl.org/blog/blog/2023/09/11/eol-111/
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
Apple Patches Older Operating Systems
https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210
Wi-Fi Enabled Practical Keystroke Eavesdropping
https://arxiv.org/pdf/2309.03492.pdf
Phishing via Google Looker Studio
https://blog.checkpoint.com/security/phishing-via-google-looker-studio
HPE One View Authentication Bypass
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04530en_us
Apple Patches Older Operating Systems
https://isc.sans.edu/diary/Apple%20fixes%200-Day%20Vulnerability%20in%20Older%20Operating%20Systems/30210
Wi-Fi Enabled Practical Keystroke Eavesdropping
https://arxiv.org/pdf/2309.03492.pdf
Phishing via Google Looker Studio
https://blog.checkpoint.com/security/phishing-via-google-looker-studio
HPE One View Authentication Bypass
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=hpesbgn04530en_us
Augmenting Honeypot Logs
https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204
More details about Apple 0-day
https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs
Odd Password Solution
https://notpickard.com/@rdp/111009868239846779
Augmenting Honeypot Logs
https://isc.sans.edu/diary/%3FAnyone%20get%20the%20ASN%20of%20the%20Truck%20that%20Hit%20Me%3F!%3F%3A%20Creating%20a%20PowerShell%20Function%20to%20Make%203rd%20Party%20API%20Calls%20for%20Extending%20Honeypot%20Information%20%5BGuest%20Diary%5D/30204
More details about Apple 0-day
https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Remote Access VPN Unauthorized Access Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ravpn-auth-8LyfCkeC#fs
Odd Password Solution
https://notpickard.com/@rdp/111009868239846779
Apple Patches 0-Days
https://isc.sans.edu/diary/30200
https://support.apple.com/en-us/HT201222
iOS Fleezeware/Scareware
https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198
Aruba Vulnerabilities
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt
TP Link Vulnerabilities
https://jvn.jp/en/vu/JVNVU99392903/
Apple Patches 0-Days
https://isc.sans.edu/diary/30200
https://support.apple.com/en-us/HT201222
iOS Fleezeware/Scareware
https://isc.sans.edu/diary/Fleezeware%20Scareware%20Advertised%20via%20Facebook%20Tags%3B%20Available%20in%20Apple%20App%20Store/30198
Aruba Vulnerabilities
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt
TP Link Vulnerabilities
https://jvn.jp/en/vu/JVNVU99392903/
Security Related DNS Records
https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194
Microsoft Reveleas Details about Key Loss
https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/
September Android Updates
https://source.android.com/docs/security/bulletin/2023-09-01
Google Chrome Update
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html
Atlas VPN Tunnel Termination Vulnerability
https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/
Security Related DNS Records
https://isc.sans.edu/diary/Security%20Relevant%20DNS%20Records/30194
Microsoft Reveleas Details about Key Loss
https://msrc.microsoft.com/blog/2023/09/results-of-major-technical-investigations-for-storm-0558-key-acquisition/
September Android Updates
https://source.android.com/docs/security/bulletin/2023-09-01
Google Chrome Update
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop.html
Atlas VPN Tunnel Termination Vulnerability
https://www.reddit.com/r/cybersecurity/comments/167f16e/atlasvpn_linux_client_103_remote_disconnect/
Common Usernames Submitted to Honeypots
https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188
TPM LUKS Bypass
https://pulsesecurity.co.nz/advisories/tpm-luks-bypass
Cross Tenant Impersonation Prevention and Detection
https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection
Common Usernames Submitted to Honeypots
https://isc.sans.edu/diary/Common%20usernames%20submitted%20to%20honeypots/30188
TPM LUKS Bypass
https://pulsesecurity.co.nz/advisories/tpm-luks-bypass
Cross Tenant Impersonation Prevention and Detection
https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection
What is the Origin of Passwords Submitted to Honeypots
https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182
Creating a YARA Rule to Detect Obfuscated Strings
https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186
VMware Aria Operations for Networks Hardcoded Keys 2023-34039
https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/
https://github.com/sinsinology/CVE-2023-34039/
Windows will Disable TLS 1.0/1.1
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center
What is the Origin of Passwords Submitted to Honeypots
https://isc.sans.edu/diary/What%20is%20the%20origin%20of%20passwords%20submitted%20to%20honeypots%3F/30182
Creating a YARA Rule to Detect Obfuscated Strings
https://isc.sans.edu/diary/Creating%20a%20YARA%20Rule%20to%20Detect%20Obfuscated%20Strings/30186
VMware Aria Operations for Networks Hardcoded Keys 2023-34039
https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-34039/
https://github.com/sinsinology/CVE-2023-34039/
Windows will Disable TLS 1.0/1.1
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center
The low, low cost of (committing) cybercrime
https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/
Unpinnable Github Actions
https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/
Exploitation of Cisco ASA SSL VPNs
https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/
Splunk Vulnerabilities
https://advisory.splunk.com/advisories
Top Level Domain Issues
https://blog.talosintelligence.com/whats-in-a-name/
The low, low cost of (committing) cybercrime
https://isc.sans.edu/forums/diary/The%20low%2C%20low%20cost%20of%20%28committing%29%20cybercrime/30176/
Unpinnable Github Actions
https://www.paloaltonetworks.com/blog/prisma-cloud/unpinnable-actions-github-security/
Exploitation of Cisco ASA SSL VPNs
https://www.rapid7.com/blog/post/2023/08/29/under-siege-rapid7-observed-exploitation-of-cisco-asa-ssl-vpns/
Splunk Vulnerabilities
https://advisory.splunk.com/advisories
Top Level Domain Issues
https://blog.talosintelligence.com/whats-in-a-name/
Home Office/Small Business Hurricane Prep
https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166
Notepad++ Vulnerabilities
https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/
7-Zip Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-23-1164/
BGP Error Handling Issues
https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
Home Office/Small Business Hurricane Prep
https://isc.sans.edu/diary/Home%20Office%20%20%20Small%20Business%20Hurricane%20Prep/30166
Notepad++ Vulnerabilities
https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/
7-Zip Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-23-1164/
BGP Error Handling Issues
https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
Survival Time for Web Sites
https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170
PDF/ActiveMime Polyglot Maldocs
https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html
https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/
RocketMQ Vulnerability Exploited
https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability
ManageEngine Vulnerabilty
https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html
Survival Time for Web Sites
https://isc.sans.edu/diary/Survival%20time%20for%20web%20sites/30170
PDF/ActiveMime Polyglot Maldocs
https://blogs.jpcert.or.jp/en/2023/08/maldocinpdf.html
https://blog.didierstevens.com/2023/08/29/quickpost-pdf-activemime-maldocs-yara-rule/
RocketMQ Vulnerability Exploited
https://blogs.juniper.net/en-us/threat-research/dreambus-botnet-resurfaces-targets-rocketmq-vulnerability
ManageEngine Vulnerabilty
https://www.manageengine.com/security/advisory/CVE/CVE-2023-35785.html
Analysis of RAR Exploit Files (CVE-2023-38831)
https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164
Juniper Exploit CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847
https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/
Microsoft Will Enabled Extended Protection for Exchange Server by Default
https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849
Rust Malware Stages on Crates.io
https://blog.phylum.io/rust-malware-staged-on-crates-io/
Analysis of RAR Exploit Files (CVE-2023-38831)
https://isc.sans.edu/diary/Analysis+of+RAR+Exploit+Files+CVE202338831/30164
Juniper Exploit CVE-2023-36844 , CVE-2023-36845 , CVE-2023-36846 , CVE-2023-36847
https://labs.watchtowr.com/cve-2023-36844-and-friends-rce-in-juniper-firewalls/
Microsoft Will Enabled Extended Protection for Exchange Server by Default
https://techcommunity.microsoft.com/t5/exchange-team-blog/coming-soon-enabling-extended-protection-on-exchange-server-by/ba-p/3911849
Rust Malware Stages on Crates.io
https://blog.phylum.io/rust-malware-staged-on-crates-io/
SANS Community Night London Signup
https://www.sans.org/mlp/community-night-cloud-security-london-september-2023
Python Malware Using Postgresql for C2 Communications
https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158
macOS: Who is Behind This Network Connection?
https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160
CVE-2020-19909 Is Everything that is Wrong with CVEs
https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/
Windows Certificate Confusion
https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/
NPM E-Mail Validator Package Malware
https://blog.phylum.io/npm-emails-validator-package-malware/
Python Malware Using Postgresql for C2 Communications
https://isc.sans.edu/diary/Python%20Malware%20Using%20Postgresql%20for%20C2%20Communications/30158
macOS: Who is Behind This Network Connection?
https://isc.sans.edu/diary/macOS%3A%20Who%3Fs%20Behind%20This%20Network%20Connection%3F/30160
CVE-2020-19909 Is Everything that is Wrong with CVEs
https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-everything-that-is-wrong-with-cves/
Windows Certificate Confusion
https://arstechnica.com/security/2023/08/a-renegade-certificate-is-removed-from-windows-then-it-returns-confusion-ensues/
NPM E-Mail Validator Package Malware
https://blog.phylum.io/npm-emails-validator-package-malware/
How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT
https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152
FBI Warns of Persistent Barracuda Backdoors
https://www.ic3.gov/Media/News/2023/230823.pdf
Ivanti Sentry Athentication Bypass Deep Diver CVE-2023-38035
https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/
Smoke Loader Drops Whiffy Recon WiFi Scanning and Geolocation Malware
https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware
How I made a "QWERTY" Keyboard Walk Password Generator with ChatGPT
https://isc.sans.edu/diary/How%20I%20made%20a%20qwerty%20%3Fkeyboard%20walk%3F%20password%20generator%20with%20ChatGPT%20%20%5BGuest%20Diary%5D/30152
FBI Warns of Persistent Barracuda Backdoors
https://www.ic3.gov/Media/News/2023/230823.pdf
Ivanti Sentry Athentication Bypass Deep Diver CVE-2023-38035
https://www.horizon3.ai/ivanti-sentry-authentication-bypass-cve-2023-38035-deep-dive/
Smoke Loader Drops Whiffy Recon WiFi Scanning and Geolocation Malware
https://www.secureworks.com/blog/smoke-loader-drops-whiffy-recon-wi-fi-scanning-and-geolocation-malware
More Exotic Excel Files Dropping AgentTesla
https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150
CVE-2023-38831 WinRAR Vulnerability Exploited
https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/
Aruba Vulnerabilities
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt
More Exotic Excel Files Dropping AgentTesla
https://isc.sans.edu/diary/More%20Exotic%20Excel%20Files%20Dropping%20AgentTesla/30150
CVE-2023-38831 WinRAR Vulnerability Exploited
https://www.group-ib.com/blog/cve-2023-38831-winrar-zero-day/
Aruba Vulnerabilities
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt
Fernet Encryption in Malware
https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/
Malware Triage With Inotify Tools
https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/
Adobe Coldfusion Exploited
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Openfire Admin Console Vulnerability Exploited
https://vulncheck.com/blog/openfire-cve-2023-32315
XLoader Mac Malware Updates
https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/
Fernet Encryption in Malware
https://isc.sans.edu/forums/diary/Have%20You%20Ever%20Heard%20of%20the%20Fernet%20Encryption%20Algorithm%3F/30146/
Malware Triage With Inotify Tools
https://isc.sans.edu/diary/Quick+Malware+Triage+With+Inotify+Tools/30142/
Adobe Coldfusion Exploited
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Openfire Admin Console Vulnerability Exploited
https://vulncheck.com/blog/openfire-cve-2023-32315
XLoader Mac Malware Updates
https://www.sentinelone.com/blog/xloaders-latest-trick-new-macos-variant-disguised-as-signed-officenote-app/
SystemBC Scans and ProxyNation
https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138
https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware
Exchange Server Security Update Re-Release
https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025
Ivanti Sentry Vulnerability Exploited
https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US
DUO Security Outage
https://status.duo.com/incidents/rw7g0q7ztj8f
mTLS Vulnerabilities
https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/
SystemBC Scans and ProxyNation
https://isc.sans.edu/diary/SystemBC%20Malware%20Activity%20/30138
https://cybersecurity.att.com/blogs/labs-research/proxynation-the-dark-nexus-between-proxy-apps-and-malware
Exchange Server Security Update Re-Release
https://techcommunity.microsoft.com/t5/exchange-team-blog/re-release-of-august-2023-exchange-server-security-update/ba-p/3900025
Ivanti Sentry Vulnerability Exploited
https://forums.ivanti.com/s/article/CVE-2023-38035-API-Authentication-Bypass-on-Sentry-Administrator-Interface?language=en_US
DUO Security Outage
https://status.duo.com/incidents/rw7g0q7ztj8f
mTLS Vulnerabilities
https://github.blog/2023-08-17-mtls-when-certificate-authentication-is-done-wrong/
From a Zalando Phish to a RAT
https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136
RARLAB WinRAR Recovery Volume Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-23-1152/
Hotmail SPF Record Error Leads to spam false positives
https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/
Chinese Entanglement | DLL Hijacking in the Asian Gambling Sector
https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/
Google Chrome to Warn Users of Malicious Extensions
https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/
From a Zalando Phish to a RAT
https://isc.sans.edu/diary/From%20a%20Zalando%20Phishing%20to%20a%20RAT/30136
RARLAB WinRAR Recovery Volume Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-23-1152/
Hotmail SPF Record Error Leads to spam false positives
https://www.bleepingcomputer.com/news/microsoft/hotmail-email-delivery-fails-after-microsoft-misconfigures-dns/
Chinese Entanglement | DLL Hijacking in the Asian Gambling Sector
https://www.sentinelone.com/labs/chinese-entanglement-dll-hijacking-in-the-asian-gambling-sector/
Google Chrome to Warn Users of Malicious Extensions
https://betanews.com/2023/08/17/google-chrome-to-warn-users-about-problematic-extensions/
Command Line Parsing - Are These Really Unique Strings?
https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126
iOS 16 Fake Airplane Mode
https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/
LinkedIn Attacks
https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/
Robot Vacuum Privacy Issues
https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf
https://dontvacuum.me/
Command Line Parsing - Are These Really Unique Strings?
https://isc.sans.edu/diary/Command%20Line%20Parsing%20-%20Are%20These%20Really%20Unique%20Strings%3F/30126
iOS 16 Fake Airplane Mode
https://www.jamf.com/blog/fake-airplane-mode-a-mobile-tampering-technique-to-maintain-connectivity/
LinkedIn Attacks
https://cyberint.com/blog/research/linkedin-accounts-under-attack-how-to-protect-yourself/
Robot Vacuum Privacy Issues
https://dontvacuum.me/talks/DEFCON31/DEFCON31-vacuum-robots-final.pdf
https://dontvacuum.me/
PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks
https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks
Windows Random Time Issues
https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/
Energy Company Targeted in QR Code Campaign
https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/
New Citrix Scanner from Mandiant
https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner
PowerShell Gallery Prone to Typosqatting, Other Sypply Chain Attacks
https://www.darkreading.com/application-security/powershell-gallery-prone-to-typosquatting-other-supply-chain-attacks
Windows Random Time Issues
https://arstechnica.com/security/2023/08/windows-feature-that-resets-system-clocks-based-on-random-data-is-wreaking-havoc/
Energy Company Targeted in QR Code Campaign
https://cofense.com/blog/major-energy-company-targeted-in-large-qr-code-campaign/
New Citrix Scanner from Mandiant
https://www.mandiant.com/resources/blog/citrix-adc-vulnerability-ioc-scanner
macOS Background Task Manager Bypass
https://www.wired.com/story/apple-mac-background-task-management-flaw/
Ivanti Avalanche Vulnerability
https://www.tenable.com/security/research/tra-2023-27
Exploiting Synology NAS Cloud Connectivity
https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition
Fake Crypto Currency Apps Offered as "Beta" versions
https://www.ic3.gov/Media/Y2023/PSA230814
macOS Background Task Manager Bypass
https://www.wired.com/story/apple-mac-background-task-management-flaw/
Ivanti Avalanche Vulnerability
https://www.tenable.com/security/research/tra-2023-27
Exploiting Synology NAS Cloud Connectivity
https://claroty.com/team82/research/a-pain-in-the-nas-exploiting-cloud-connectivity-to-pwn-your-nas-synology-ds920-edition
Fake Crypto Currency Apps Offered as "Beta" versions
https://www.ic3.gov/Media/Y2023/PSA230814
PDFiD False Positives Revisited
https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122
CVE-2023-32019 Fix Enabled by Default;
https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080
CyberPower and Dataprobe Vulnerabilities
https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html
Ford WiFi Driver Vulnerability
https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&ref_url=https%253A%252F%252Fmedia.ford.com%252F
PDFiD False Positives Revisited
https://isc.sans.edu/diary/PDFiD%3A%20False%20Positives%20Revisited/30122
CVE-2023-32019 Fix Enabled by Default;
https://support.microsoft.com/en-us/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080
CyberPower and Dataprobe Vulnerabilities
https://www.trellix.com/en-us/about/newsroom/stories/research/the-threat-lurking-in-data-centers.html
Ford WiFi Driver Vulnerability
https://www.ti.com/lit/er/swra773/swra773.pdf?ts=1691717352391&ref_url=https%253A%252F%252Fmedia.ford.com%252F
Show Me All Your Windows
https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116
Zero Touch Pwn
https://blog.syss.com/posts/zero-touch-pwn/
Maginot DNS Spoofing Attack
https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang
Show Me All Your Windows
https://isc.sans.edu/diary/Show%20me%20All%20Your%20Windows!/30116
Zero Touch Pwn
https://blog.syss.com/posts/zero-touch-pwn/
Maginot DNS Spoofing Attack
https://www.usenix.org/conference/usenixsecurity23/presentation/li-xiang
Some things never change, such as SQL Authentication "Encryption"
https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112
Defender Pretender: When Windows Defender Updates Become a Security Risk
https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706
Dell Compellent Hardcoded Key
https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities
Vulnerabilities in Sogou Keyboard
https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/
Some things never change, such as SQL Authentication "Encryption"
https://isc.sans.edu/diary/Some%20things%20never%20change%20%3F%20such%20as%20SQL%20Authentication%20%3Fencryption%3F/30112
Defender Pretender: When Windows Defender Updates Become a Security Risk
https://www.blackhat.com/us-23/briefings/schedule/#defender-pretender-when-windows-defender-updates-become-a-security-risk-32706
Dell Compellent Hardcoded Key
https://www.dell.com/support/kbdoc/en-us/000216615/dsa-2023-282-security-update-for-dell-storage-integration-tools-for-vmware-dsitv-vulnerabilities
Vulnerabilities in Sogou Keyboard
https://citizenlab.ca/2023/08/vulnerabilities-in-sogou-keyboard-encryption/
Tunnelcrack VPN Vulnerability
https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf
Mozilla VPN Vulnerablity
https://www.openwall.com/lists/oss-security/2023/08/03/1
Non English Exchange Server Patch Issues
https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true
VSCode Token Security
https://cycode.com/blog/exposing-vscode-secrets/
Weekly Updates for Google Chrome
https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html
Tunnelcrack VPN Vulnerability
https://papers.mathyvanhoef.com/usenix2023-tunnelcrack.pdf
Mozilla VPN Vulnerablity
https://www.openwall.com/lists/oss-security/2023/08/03/1
Non English Exchange Server Patch Issues
https://techcommunity.microsoft.com/t5/exchange-team-blog/released-august-2023-exchange-server-security-updates/bc-p/3894481/highlight/true
VSCode Token Security
https://cycode.com/blog/exposing-vscode-secrets/
Weekly Updates for Google Chrome
https://security.googleblog.com/2023/08/an-update-on-chrome-security-updates.html
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20August%202023%20Patch%20Tuesday/30106
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
Update: Researchers Scanning the Internet
https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102
Malicious OpenBullet Configuration Files
https://www.kasada.io/threat-intel-openbullet-malware/
Abusing Cloudflare Tunnels
https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/
Update: Researchers Scanning the Internet
https://isc.sans.edu/diary/Update%3A%20Researchers%20scanning%20the%20Internet/30102
Malicious OpenBullet Configuration Files
https://www.kasada.io/threat-intel-openbullet-malware/
Abusing Cloudflare Tunnels
https://www.guidepointsecurity.com/blog/tunnel-vision-cloudflared-abused-in-the-wild/
Are Leaked Credential Dumps Used by Attackers?
https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098
New PaperCut RCE Vulnerability
https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/
Microsoft mitigates Power Platform Custom Code information disclosure vulnerability
https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/
Microsoft Publishes Token theft Playbook
https://learn.microsoft.com/en-us/security/operations/token-theft-playbook
Are Leaked Credential Dumps Used by Attackers?
https://isc.sans.edu/diary/Are%20Leaked%20Credentials%20Dumps%20Used%20by%20Attackers%3F/30098
New PaperCut RCE Vulnerability
https://www.horizon3.ai/cve-2023-39143-papercut-path-traversal-file-upload-rce-vulnerability/
Microsoft mitigates Power Platform Custom Code information disclosure vulnerability
https://msrc.microsoft.com/blog/2023/08/microsoft-mitigates-power-platform-custom-code-information-disclosure-vulnerability/
Microsoft Publishes Token theft Playbook
https://learn.microsoft.com/en-us/security/operations/token-theft-playbook
From small LNK to large malicious BAT file with zero VT score
https://isc.sans.edu/diary/From%20small%20LNK%20to%20large%20malicious%20BAT%20file%20with%20zero%20VT%20score/30094
Social Engineering via Microsoft Teams
https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/
Automating the Search for LOLBAS
https://pentera.io/resources/whitepapers/the-lolbas-odyssey-finding-new-lolbas-and-how-you-can-too/
Sneaky Versioning Used to Bypass Scanners
https://thehackernews.com/2023/08/malicious-apps-use-sneaky-versioning.html
Aruba Patches
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txt
Mitel Patches
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008
From small LNK to large malicious BAT file with zero VT score
https://isc.sans.edu/diary/From%20small%20LNK%20to%20large%20malicious%20BAT%20file%20with%20zero%20VT%20score/30094
Social Engineering via Microsoft Teams
https://www.microsoft.com/en-us/security/blog/2023/08/02/midnight-blizzard-conducts-targeted-social-engineering-over-microsoft-teams/
Automating the Search for LOLBAS
https://pentera.io/resources/whitepapers/the-lolbas-odyssey-finding-new-lolbas-and-how-you-can-too/
Sneaky Versioning Used to Bypass Scanners
https://thehackernews.com/2023/08/malicious-apps-use-sneaky-versioning.html
Aruba Patches
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txt
Mitel Patches
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0008
Zeek and Defender Endpoint
https://isc.sans.edu/diary/Zeek%20and%20Defender%20Endpoint/30088
New Ivanti MobileIron Core Vulnerability
https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older?language=en_US
Salesforce Phishing
https://labs.guard.io/phishforce-vulnerability-uncovered-in-salesforces-email-services-exploited-for-phishing-32024ad4b5fa
Abusing the Amazon Web Services SSM Agent as a Remote Access Trojan
https://www.mitiga.io/blog/abusing-the-amazon-web-services-ssm-agent-as-a-remote-access-trojan
Zeek and Defender Endpoint
https://isc.sans.edu/diary/Zeek%20and%20Defender%20Endpoint/30088
New Ivanti MobileIron Core Vulnerability
https://forums.ivanti.com/s/article/CVE-2023-35082-Remote-Unauthenticated-API-Access-Vulnerability-in-MobileIron-Core-11-2-and-older?language=en_US
Salesforce Phishing
https://labs.guard.io/phishforce-vulnerability-uncovered-in-salesforces-email-services-exploited-for-phishing-32024ad4b5fa
Abusing the Amazon Web Services SSM Agent as a Remote Access Trojan
https://www.mitiga.io/blog/abusing-the-amazon-web-services-ssm-agent-as-a-remote-access-trojan
DNS Over HTTPS Summary
https://isc.sans.edu/diary/Summary%20of%20DNS%20over%20HTTPS%20requests%20against%20our%20honeypots./30084
Malware Infects Airgapped Networks
https://usa.kaspersky.com/about/press-releases/2023_kaspersky-uncovers-malware-for-targeted-data-exfiltration-from-air-gapped-environments
Google Deleting Inactive Accounts
https://support.google.com/accounts/answer/12418290?visit_id=638264210155158507-1346504535&p=inactive_account_policy_blog&rd=1
Google AMP Service Used for Phishing
https://cofense.com/blog/google-amp-the-newest-of-evasive-phishing-tactic/
DNS Over HTTPS Summary
https://isc.sans.edu/diary/Summary%20of%20DNS%20over%20HTTPS%20requests%20against%20our%20honeypots./30084
Malware Infects Airgapped Networks
https://usa.kaspersky.com/about/press-releases/2023_kaspersky-uncovers-malware-for-targeted-data-exfiltration-from-air-gapped-environments
Google Deleting Inactive Accounts
https://support.google.com/accounts/answer/12418290?visit_id=638264210155158507-1346504535&p=inactive_account_policy_blog&rd=1
Google AMP Service Used for Phishing
https://cofense.com/blog/google-amp-the-newest-of-evasive-phishing-tactic/
Ivanti End Point Manager 2nd Zero Day
https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US
New Redis Malware Uses Unknown Initial Access Vector
https://www.cadosecurity.com/redis-p2pinfect/
https://unit42.paloaltonetworks.com/peer-to-peer-worm-p2pinfect/
Google Android 0-Day Summary
https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html
Wiping Sensitive Data from Printers
https://psirt.canon/advisory-information/cp2023-003/
Ivanti End Point Manager 2nd Zero Day
https://forums.ivanti.com/s/article/CVE-2023-35081-Arbitrary-File-Write?language=en_US
New Redis Malware Uses Unknown Initial Access Vector
https://www.cadosecurity.com/redis-p2pinfect/
https://unit42.paloaltonetworks.com/peer-to-peer-worm-p2pinfect/
Google Android 0-Day Summary
https://security.googleblog.com/2023/07/the-ups-and-downs-of-0-days-year-in.html
Wiping Sensitive Data from Printers
https://psirt.canon/advisory-information/cp2023-003/
USPS Phishing Scam Targeting iOS Users
https://isc.sans.edu/forums/diary/USPS+Phishing+Scam+Targeting+iOS+Users/30078/
Do Attackers Pay More Attention to IPv6
https://isc.sans.edu/diary/Do%20Attackers%20Pay%20More%20Attention%20to%20IPv6%3F/30076
Shell Code in Images
https://isc.sans.edu/diary/ShellCode%20Hidden%20with%20Steganography/30074
Ivanti Mobileiron Exploit Public
https://github.com/vchan-in/CVE-2023-35078-Exploit-POC/blob/main/cve_2023_35078_poc.py
USPS Phishing Scam Targeting iOS Users
https://isc.sans.edu/forums/diary/USPS+Phishing+Scam+Targeting+iOS+Users/30078/
Do Attackers Pay More Attention to IPv6
https://isc.sans.edu/diary/Do%20Attackers%20Pay%20More%20Attention%20to%20IPv6%3F/30076
Shell Code in Images
https://isc.sans.edu/diary/ShellCode%20Hidden%20with%20Steganography/30074
Ivanti Mobileiron Exploit Public
https://github.com/vchan-in/CVE-2023-35078-Exploit-POC/blob/main/cve_2023_35078_poc.py
Ubuntu OverlayFS Vulnerability
https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability
CISA Warns of Insecure Direct Option Reference Vulnerabilities
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-208a
Sophos UTM Patch
https://docs.sophos.com/releasenotes/index.html?productGroupID=nsg&productID=utm&versionID=9.7
Aruba Patches
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-009.txt
Ubuntu OverlayFS Vulnerability
https://www.wiz.io/blog/ubuntu-overlayfs-vulnerability
CISA Warns of Insecure Direct Option Reference Vulnerabilities
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-208a
Sophos UTM Patch
https://docs.sophos.com/releasenotes/index.html?productGroupID=nsg&productID=utm&versionID=9.7
Aruba Patches
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-009.txt
Suspicious IP Addresses Avoided By Malware Samples
https://isc.sans.edu/diary/Suspicious%20IP%20Addresses%20Avoided%20by%20Malware%20Samples/30068
Messaging Layer Security (MLS) Protocol
https://datatracker.ietf.org/doc/html/rfc9420
PySecDB: Security Commit Dataset in Python
https://github.com/SunLab-GMU/PySecDB
MacOS Infostealer
https://www.sentinelone.com/blog/apple-crimeware-massive-rust-infostealer-campaign-aiming-for-macos-sonoma-ahead-of-public-release/
Suspicious IP Addresses Avoided By Malware Samples
https://isc.sans.edu/diary/Suspicious%20IP%20Addresses%20Avoided%20by%20Malware%20Samples/30068
Messaging Layer Security (MLS) Protocol
https://datatracker.ietf.org/doc/html/rfc9420
PySecDB: Security Commit Dataset in Python
https://github.com/SunLab-GMU/PySecDB
MacOS Infostealer
https://www.sentinelone.com/blog/apple-crimeware-massive-rust-infostealer-campaign-aiming-for-macos-sonoma-ahead-of-public-release/
Ivanti Patches Endpoint Manager Mobile
https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US
Atlassian Patches
https://confluence.atlassian.com/security/security-bulletin-july-18-2023-1251417643.html
AMD Zen-2 Vulnerability
https://lock.cmpxchg8b.com/zenbleed.html
VMWare CVE-2023-20891
https://socradar.io/vmwares-response-to-the-critical-cve-2023-20891-vulnerability-exposing-cf-api-admin-credentials/
Ivanti Patches Endpoint Manager Mobile
https://forums.ivanti.com/s/article/CVE-2023-35078-Remote-unauthenticated-API-access-vulnerability?language=en_US
Atlassian Patches
https://confluence.atlassian.com/security/security-bulletin-july-18-2023-1251417643.html
AMD Zen-2 Vulnerability
https://lock.cmpxchg8b.com/zenbleed.html
VMWare CVE-2023-20891
https://socradar.io/vmwares-response-to-the-critical-cve-2023-20891-vulnerability-exposing-cf-api-admin-credentials/
Apple Updates
https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20%28again%29/30062/
https://support.apple.com/en-us/HT201222
Parsing Data with jq
https://isc.sans.edu/diary/JQ%3A%20Another%20Tool%20We%20Thought%20We%20Knew/30060
TETRA Radio Backdoor
https://www.wired.com/story/tetra-radio-encryption-backdoor/
Apple Updates
https://isc.sans.edu/forums/diary/Apple%20Updates%20Everything%20%28again%29/30062/
https://support.apple.com/en-us/HT201222
Parsing Data with jq
https://isc.sans.edu/diary/JQ%3A%20Another%20Tool%20We%20Thought%20We%20Knew/30060
TETRA Radio Backdoor
https://www.wired.com/story/tetra-radio-encryption-backdoor/
Shodan's API for the (Recon) Win!
https://isc.sans.edu/diary/Shodan%27s%20API%20For%20The%20%28Recon%29%20Win!/30050
Stolen Microsoft Key May Have Opened Up a lot more than US Government E-Mail Inboxes
https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr
https://www.theregister.com/2023/07/21/microsoft_key_skeleton/
Okta Logs Decoded
https://www.rezonate.io/blog/okta-logs-decoded-unveiling-identity-threats-through-threat-hunting/
Threat Actors Exploiting Citrix CVE-2023-3519
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-201a
https://github.com/securekomodo/citrixInspector
Shodan's API for the (Recon) Win!
https://isc.sans.edu/diary/Shodan%27s%20API%20For%20The%20%28Recon%29%20Win!/30050
Stolen Microsoft Key May Have Opened Up a lot more than US Government E-Mail Inboxes
https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr
https://www.theregister.com/2023/07/21/microsoft_key_skeleton/
Okta Logs Decoded
https://www.rezonate.io/blog/okta-logs-decoded-unveiling-identity-threats-through-threat-hunting/
Threat Actors Exploiting Citrix CVE-2023-3519
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-201a
https://github.com/securekomodo/citrixInspector
Deobfuscation of Malware Delivered Through a .bat File
https://isc.sans.edu/diary/Deobfuscation%20of%20Malware%20Delivered%20Through%20a%20.bat%20File/30048
Citrix CVE-2023-3519 Indicators of Compromise
https://www.deyda.net/index.php/en/2023/07/19/checklist-for-citrix-adc-cve-2023-3519/
ssh-agent vulnerability
https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt
Spring Security: WebFlux Security Bypass with Un-Prefixed Double Wildcard Pattern
https://spring.io/security/cve-2023-34034
American Megatrends (AMI) MegaRAC BMC Vulnerabilities
https://eclypsium.com/research/bmcc-lights-out-forever/
Deobfuscation of Malware Delivered Through a .bat File
https://isc.sans.edu/diary/Deobfuscation%20of%20Malware%20Delivered%20Through%20a%20.bat%20File/30048
Citrix CVE-2023-3519 Indicators of Compromise
https://www.deyda.net/index.php/en/2023/07/19/checklist-for-citrix-adc-cve-2023-3519/
ssh-agent vulnerability
https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt
Spring Security: WebFlux Security Bypass with Un-Prefixed Double Wildcard Pattern
https://spring.io/security/cve-2023-34034
American Megatrends (AMI) MegaRAC BMC Vulnerabilities
https://eclypsium.com/research/bmcc-lights-out-forever/
Citrix ADC Vulneraiblity CVE-2023-3519, CVE-2023-3466, CVE-2023-3467
https://isc.sans.edu/forums/diary/Citrix%20ADC%20Vulnerability%20CVE-2023-3519%2C%203466%20and%203467%20-%20Patch%20Now!/30044/
HAM Radio Enigma Machine Challenge
https://isc.sans.edu/diary/HAM%20Radio%20%2B%20Enigma%20Machine%20Challenge/30042
Oracle Critical Patch Update
https://www.oracle.com/security-alerts/cpujul2023.html
Microsoft Expanding Cloud Logging
https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/
Citrix ADC Vulneraiblity CVE-2023-3519, CVE-2023-3466, CVE-2023-3467
https://isc.sans.edu/forums/diary/Citrix%20ADC%20Vulnerability%20CVE-2023-3519%2C%203466%20and%203467%20-%20Patch%20Now!/30044/
HAM Radio Enigma Machine Challenge
https://isc.sans.edu/diary/HAM%20Radio%20%2B%20Enigma%20Machine%20Challenge/30042
Oracle Critical Patch Update
https://www.oracle.com/security-alerts/cpujul2023.html
Microsoft Expanding Cloud Logging
https://www.microsoft.com/en-us/security/blog/2023/07/19/expanding-cloud-logging-to-give-customers-deeper-security-visibility/
Exploit Attempts for "Stagil navigation for Jira Menus & Themes"
https://isc.sans.edu/diary/Exploit%20Attempts%20for%20%22Stagil%20navigation%20for%20Jira%20Menus%20%26%20Themes%22%20CVE-2023-26255%20and%20CVE-2023-26256/30038
Citrix Vulnerabilities
https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467
Google Cloud Build Service Vulnerability
https://orca.security/resources/blog/bad-build-google-cloud-build-potential-supply-chain-attack-vulnerability
Exploit Attempts for "Stagil navigation for Jira Menus & Themes"
https://isc.sans.edu/diary/Exploit%20Attempts%20for%20%22Stagil%20navigation%20for%20Jira%20Menus%20%26%20Themes%22%20CVE-2023-26255%20and%20CVE-2023-26256/30038
Citrix Vulnerabilities
https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467
Google Cloud Build Service Vulnerability
https://orca.security/resources/blog/bad-build-google-cloud-build-potential-supply-chain-attack-vulnerability
Zimbra Vulnerability Exploited
https://blog.zimbra.com/2023/07/security-update-for-zimbra-collaboration-suite-version-8-8-15
Woocommerce Vulnerability Actively Being Exploited
https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/
Adobe Coldfusion Flaws exploited
https://www.bleepingcomputer.com/news/security/adobe-warns-of-critical-coldfusion-rce-bug-exploited-in-attacks/
CISA Cloud Security Fact Sheet: Free Tools for Cloud Environments
https://www.cisa.gov/sites/default/files/2023-07/Free%20Tools%20for%20Cloud%20Environments_508c.pdf
JumpCloud Breach
https://arstechnica.com/security/2023/07/jumpcloud-says-nation-state-hacker-breach-targeted-some-of-its-customers/
Zimbra Vulnerability Exploited
https://blog.zimbra.com/2023/07/security-update-for-zimbra-collaboration-suite-version-8-8-15
Woocommerce Vulnerability Actively Being Exploited
https://www.rcesecurity.com/2023/07/patch-diffing-cve-2023-28121-to-compromise-a-woocommerce/
Adobe Coldfusion Flaws exploited
https://www.bleepingcomputer.com/news/security/adobe-warns-of-critical-coldfusion-rce-bug-exploited-in-attacks/
CISA Cloud Security Fact Sheet: Free Tools for Cloud Environments
https://www.cisa.gov/sites/default/files/2023-07/Free%20Tools%20for%20Cloud%20Environments_508c.pdf
JumpCloud Breach
https://arstechnica.com/security/2023/07/jumpcloud-says-nation-state-hacker-breach-targeted-some-of-its-customers/
Microsoft Driver Certs Details
https://blog.talosintelligence.com/old-certificate-new-signature/
Threads App Lures
https://www.helpnetsecurity.com/2023/07/14/threads-app-lure/
First Releases CVSS 4.0 Preview
https://www.first.org/cvss/
Microsoft Driver Certs Details
https://blog.talosintelligence.com/old-certificate-new-signature/
Threads App Lures
https://www.helpnetsecurity.com/2023/07/14/threads-app-lure/
First Releases CVSS 4.0 Preview
https://www.first.org/cvss/
DShield Honeypot Maintenance and Data Retention
https://isc.sans.edu/diary/DShield%20Honeypot%20Maintenance%20and%20Data%20Retention/30024
Enhanced Monitoring to Detect APT Activity Targeting Outlook Online
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-193a
PoC Exploit: Fake Proof of Concept with Backdoor Malware
https://www.uptycs.com/blog/new-poc-exploit-backdoor-malware
GhostScript CVE-2023-36664 PoC Exploit
https://www.kroll.com/en/insights/publications/cyber/ghostscript-cve-2023-36664-remote-code-execution-vulnerability
DShield Honeypot Maintenance and Data Retention
https://isc.sans.edu/diary/DShield%20Honeypot%20Maintenance%20and%20Data%20Retention/30024
Enhanced Monitoring to Detect APT Activity Targeting Outlook Online
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-193a
PoC Exploit: Fake Proof of Concept with Backdoor Malware
https://www.uptycs.com/blog/new-poc-exploit-backdoor-malware
GhostScript CVE-2023-36664 PoC Exploit
https://www.kroll.com/en/insights/publications/cyber/ghostscript-cve-2023-36664-remote-code-execution-vulnerability
Apple Re-Releases Rapid Security Update for iOS/MacOS
https://support.apple.com/HT201224
Loader Activity For Formbook "QM18"
https://isc.sans.edu/diary/Loader%20activity%20for%20Formbook%20%22QM18%22/30020
Adobe Patches
https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html
FortiOS/FortiProxy Stack Based Overflow
https://www.fortiguard.com/psirt/FG-IR-23-183
Citrix Secure Access Client for Ubuntu
https://support.citrix.com/article/CTX564169/citrix-secure-access-client-for-ubuntu-security-bulletin-for-cve202324492
Sonicwall Updates
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010
Apple Re-Releases Rapid Security Update for iOS/MacOS
https://support.apple.com/HT201224
Loader Activity For Formbook "QM18"
https://isc.sans.edu/diary/Loader%20activity%20for%20Formbook%20%22QM18%22/30020
Adobe Patches
https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html
FortiOS/FortiProxy Stack Based Overflow
https://www.fortiguard.com/psirt/FG-IR-23-183
Citrix Secure Access Client for Ubuntu
https://support.citrix.com/article/CTX564169/citrix-secure-access-client-for-ubuntu-security-bulletin-for-cve202324492
Sonicwall Updates
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/July%202023%20Microsoft%20Patch%20Update/30018/
https://blog.talosintelligence.com/old-certificate-new-signature/
Apple Withdraws Rapid Security Response Update
https://support.apple.com/en-us/HT213827
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/July%202023%20Microsoft%20Patch%20Update/30018/
https://blog.talosintelligence.com/old-certificate-new-signature/
Apple Withdraws Rapid Security Response Update
https://support.apple.com/en-us/HT213827
Apple Rapid Security Update Patches Three Exploited Vulnerabilities
https://isc.sans.edu/diary/Apple%20Rapid%20Security%20Update%20Patches%20Three%20Exploited%20Vulnerabilities/30012
Ubiquity Edgerouter and AirCube miniupnpd Heap Overflow
https://ssd-disclosure.com/ssd-advisory-edgerouters-and-aircube-miniupnpd-heap-overflow/
Mozilla Restricting Extensions on Quarantined Domains
https://support.mozilla.org/en-US/kb/quarantined-domains
https://www.mozilla.org/en-US/firefox/115.0/releasenotes/
https://lapcatsoftware.com/articles/2023/7/1.html
Apple Rapid Security Update Patches Three Exploited Vulnerabilities
https://isc.sans.edu/diary/Apple%20Rapid%20Security%20Update%20Patches%20Three%20Exploited%20Vulnerabilities/30012
Ubiquity Edgerouter and AirCube miniupnpd Heap Overflow
https://ssd-disclosure.com/ssd-advisory-edgerouters-and-aircube-miniupnpd-heap-overflow/
Mozilla Restricting Extensions on Quarantined Domains
https://support.mozilla.org/en-US/kb/quarantined-domains
https://www.mozilla.org/en-US/firefox/115.0/releasenotes/
https://lapcatsoftware.com/articles/2023/7/1.html
DSSuite Didier Toolbox Cokcer Image Update
https://isc.sans.edu/diary/DSSuite%20%28Didier%27s%20Toolbox%29%20Docker%20Image%20Update/30008
More MoveIT Flaws and new Service Pack
https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-July-2023
Cisco Nexus 9000 Flaw
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX
DSSuite Didier Toolbox Cokcer Image Update
https://isc.sans.edu/diary/DSSuite%20%28Didier%27s%20Toolbox%29%20Docker%20Image%20Update/30008
More MoveIT Flaws and new Service Pack
https://community.progress.com/s/article/MOVEit-Transfer-2020-1-Service-Pack-July-2023
Cisco Nexus 9000 Flaw
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX
IDS Comparisons with DShield Honeypot Data
https://isc.sans.edu/diary/IDS%20Comparisons%20with%20DShield%20Honeypot%20Data/30002
Truebot Exploits Netwrix Auditor
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-187a
Stackrot Linux Priviledge Escalation Vulnerability
https://www.openwall.com/lists/oss-security/2023/07/05/1
TeamsPhisher Exploit
https://github.com/Octoberfest7/TeamsPhisher
VMWare Update
https://www.vmware.com/security/advisories/VMSA-2023-0015.html
IDS Comparisons with DShield Honeypot Data
https://isc.sans.edu/diary/IDS%20Comparisons%20with%20DShield%20Honeypot%20Data/30002
Truebot Exploits Netwrix Auditor
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-187a
Stackrot Linux Priviledge Escalation Vulnerability
https://www.openwall.com/lists/oss-security/2023/07/05/1
TeamsPhisher Exploit
https://github.com/Octoberfest7/TeamsPhisher
VMWare Update
https://www.vmware.com/security/advisories/VMSA-2023-0015.html
DShield pfSense Client Update
https://isc.sans.edu/diary/DShield%20pfSense%20Client%20Update/29994
Exposed Industrial Control Systems
https://isc.sans.edu/diary/Controlling%20network%20access%20to%20ICS%20systems/30000
Analysis Method for Custom Encoding
https://isc.sans.edu/diary/Analysis%20Method%20for%20Custom%20Encoding/29946
SNAPPY: Detecting Rogue WiFi Access Points
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/snappy-detecting-rogue-and-fake-80211-wireless-access-points-through-fingerprinting-beacon-management-frames/
RUSTBUCKET Mac Malware
https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket
DShield pfSense Client Update
https://isc.sans.edu/diary/DShield%20pfSense%20Client%20Update/29994
Exposed Industrial Control Systems
https://isc.sans.edu/diary/Controlling%20network%20access%20to%20ICS%20systems/30000
Analysis Method for Custom Encoding
https://isc.sans.edu/diary/Analysis%20Method%20for%20Custom%20Encoding/29946
SNAPPY: Detecting Rogue WiFi Access Points
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/snappy-detecting-rogue-and-fake-80211-wireless-access-points-through-fingerprinting-beacon-management-frames/
RUSTBUCKET Mac Malware
https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket
GuLoader or BatLoader/Modiloader infection fro Remcos RAT
https://isc.sans.edu/diary/GuLoader-%20or%20DBatLoader%20ModiLoader-style%20infection%20for%20Remcos%20RAT/29990
CVE-2023-26258 Remote Code Execution in Arcserve UDP Backup
https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/
Sysmon Update
https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
https://medium.com/@olafhartong/sysmon-15-0-file-executable-detected-40fd64349f36
Drone Security and Fault Injection Attacks
https://labs.ioactive.com/2023/06/applying-fault-injection-to-firmware.html
GuLoader or BatLoader/Modiloader infection fro Remcos RAT
https://isc.sans.edu/diary/GuLoader-%20or%20DBatLoader%20ModiLoader-style%20infection%20for%20Remcos%20RAT/29990
CVE-2023-26258 Remote Code Execution in Arcserve UDP Backup
https://www.mdsec.co.uk/2023/06/cve-2023-26258-remote-code-execution-in-arcserve-udp-backup/
Sysmon Update
https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon
https://medium.com/@olafhartong/sysmon-15-0-file-executable-detected-40fd64349f36
Drone Security and Fault Injection Attacks
https://labs.ioactive.com/2023/06/applying-fault-injection-to-firmware.html
Kazkhastan: The world's last SSLv2 Super Power
https://isc.sans.edu/diary/Kazakhstan%20-%20the%20world%27s%20last%20SSLv2%20superpower...%20and%20a%20country%20with%20potentially%20vulnerable%20last-mile%20internet%20infrastructure/29988
npm manifest issues
https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem
Process Mockingjay: Echoing RWX In Userland To Achieve Code Execution
https://www.securityjoes.com/post/process-mockingjay-echoing-rwx-in-userland-to-achieve-code-execution
Kazkhastan: The world's last SSLv2 Super Power
https://isc.sans.edu/diary/Kazakhstan%20-%20the%20world%27s%20last%20SSLv2%20superpower...%20and%20a%20country%20with%20potentially%20vulnerable%20last-mile%20internet%20infrastructure/29988
npm manifest issues
https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem
Process Mockingjay: Echoing RWX In Userland To Achieve Code Execution
https://www.securityjoes.com/post/process-mockingjay-echoing-rwx-in-userland-to-achieve-code-execution
The Importance of Malware Triage
https://isc.sans.edu/diary/The+Importance+of+Malware+Triage/29984/
RowPress: Amplifying Read Disturbance in Modern DRAM Chips
https://dl.acm.org/doi/abs/10.1145/3579371.3589063
Dell BIOS Updates
https://www.dell.com/support/kbdoc/de-de/000214778/dsa-2023-174-dell-client-bios-security-update-for-an-out-of-bounds-write-vulnerability
Google Chrome Update
https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html
The Importance of Malware Triage
https://isc.sans.edu/diary/The+Importance+of+Malware+Triage/29984/
RowPress: Amplifying Read Disturbance in Modern DRAM Chips
https://dl.acm.org/doi/abs/10.1145/3579371.3589063
Dell BIOS Updates
https://www.dell.com/support/kbdoc/de-de/000214778/dsa-2023-174-dell-client-bios-security-update-for-an-out-of-bounds-write-vulnerability
Google Chrome Update
https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop_26.html
BlackLotus Mitigation Guide
https://media.defense.gov/2023/Jun/22/2003245723/-1/-1/0/CSI_BlackLotus_Mitigation_Guide.PDF
Camaro Dragon Infects USB Drives as well as Network Drives
https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/
Grafana Security Release
https://grafana.com/blog/2023/06/22/grafana-security-release-for-cve-2023-3128/
BlackLotus Mitigation Guide
https://media.defense.gov/2023/Jun/22/2003245723/-1/-1/0/CSI_BlackLotus_Mitigation_Guide.PDF
Camaro Dragon Infects USB Drives as well as Network Drives
https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/
Grafana Security Release
https://grafana.com/blog/2023/06/22/grafana-security-release-for-cve-2023-3128/
Email Spam With Modiloader Attached
https://isc.sans.edu/diary/Email%20Spam%20with%20Attachment%20Modiloader/29978
Word Document with an Online Attached Template
https://isc.sans.edu/diary/Word%20Document%20with%20an%20Online%20Attached%20Template/29976
Quakbot Activity Obama271 Distrubution Tag
https://isc.sans.edu/diary/Qakbot%20%28Qbot%29%20activity%2C%20obama271%20distribution%20tag/29968
Microsoft Teams External Tenant Confusion
https://labs.jumpsec.com/advisory-idor-in-microsoft-teams-allows-for-external-tenants-to-introduce-malware/
Free Smart Watches
https://www.darkreading.com/threat-intelligence/suspicious-smartwatches-mailed-us-army-personnel
Email Spam With Modiloader Attached
https://isc.sans.edu/diary/Email%20Spam%20with%20Attachment%20Modiloader/29978
Word Document with an Online Attached Template
https://isc.sans.edu/diary/Word%20Document%20with%20an%20Online%20Attached%20Template/29976
Quakbot Activity Obama271 Distrubution Tag
https://isc.sans.edu/diary/Qakbot%20%28Qbot%29%20activity%2C%20obama271%20distribution%20tag/29968
Microsoft Teams External Tenant Confusion
https://labs.jumpsec.com/advisory-idor-in-microsoft-teams-allows-for-external-tenants-to-introduce-malware/
Free Smart Watches
https://www.darkreading.com/threat-intelligence/suspicious-smartwatches-mailed-us-army-personnel
Apple Updates Already Exploited Vulnerabilities
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerabilities%20in%20iOS%20iPadOS%2C%20macOS%2C%20watchOS%20and%20Safari/29972
Heap Buffer Overflow in VMWare VCenter
https://www.vmware.com/security/advisories/VMSA-2023-0014.html
GitHub RepoJacking
https://blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking
Apple Updates Already Exploited Vulnerabilities
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerabilities%20in%20iOS%20iPadOS%2C%20macOS%2C%20watchOS%20and%20Safari/29972
Heap Buffer Overflow in VMWare VCenter
https://www.vmware.com/security/advisories/VMSA-2023-0014.html
GitHub RepoJacking
https://blog.aquasec.com/github-dataset-research-reveals-millions-potentially-vulnerable-to-repojacking
Analyzing a YouTube Sponsorship Phishing E-Mail
https://isc.sans.edu/diary/Analyzing%20a%20YouTube%20Sponsorship%20Phishing%20Mail%20and%20Malware%20Targeting%20Content%20Creators/29966
Malicious Code Can Be Anywhere
https://isc.sans.edu/diary/Malicious%20Code%20Can%20Be%20Anywhere/29964
Zyxel Vulnerability
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products
Huawei Vulnerability
https://www.huawei.com/en/psirt/security-advisories/2023/huawei-sa-thvihr-7015cbae-en
Asus Vulnerability
https://www.asus.com/content/asus-product-security-advisory/
VMWare Aria Vuln Exploited
https://www.vmware.com/security/advisories/VMSA-2023-0012.html
Analyzing a YouTube Sponsorship Phishing E-Mail
https://isc.sans.edu/diary/Analyzing%20a%20YouTube%20Sponsorship%20Phishing%20Mail%20and%20Malware%20Targeting%20Content%20Creators/29966
Malicious Code Can Be Anywhere
https://isc.sans.edu/diary/Malicious%20Code%20Can%20Be%20Anywhere/29964
Zyxel Vulnerability
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-pre-authentication-command-injection-vulnerability-in-nas-products
Huawei Vulnerability
https://www.huawei.com/en/psirt/security-advisories/2023/huawei-sa-thvihr-7015cbae-en
Asus Vulnerability
https://www.asus.com/content/asus-product-security-advisory/
VMWare Aria Vuln Exploited
https://www.vmware.com/security/advisories/VMSA-2023-0012.html
Formbook From Possible ModiLoaeder (DBatLoader)
https://isc.sans.edu/diary/Formbook%20from%20Possible%20ModiLoader%20%28DBatLoader%29%20/29958
Brute-Force ZIP Password Cracking with zipdump.py
https://isc.sans.edu/diary/Brute-Force%20ZIP%20Password%20Cracking%20with%20zipdump.py/29948
Malware Delivered Through .inf File
https://isc.sans.edu/diary/Malware%20Delivered%20Through%20.inf%20File/29960
FortiNAC - Just a few more RCEs
https://frycos.github.io/vulns4free/2023/06/18/fortinac.html
Formbook From Possible ModiLoaeder (DBatLoader)
https://isc.sans.edu/diary/Formbook%20from%20Possible%20ModiLoader%20%28DBatLoader%29%20/29958
Brute-Force ZIP Password Cracking with zipdump.py
https://isc.sans.edu/diary/Brute-Force%20ZIP%20Password%20Cracking%20with%20zipdump.py/29948
Malware Delivered Through .inf File
https://isc.sans.edu/diary/Malware%20Delivered%20Through%20.inf%20File/29960
FortiNAC - Just a few more RCEs
https://frycos.github.io/vulns4free/2023/06/18/fortinac.html
Supervision and Verfication in Vulnerability Management
https://isc.sans.edu/diary/Supervision%20and%20Verification%20in%20Vulnerability%20Management/29952
More MOVEit issues
https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-15June2023
Critical Citrix Sharefile Storagezones Controller
https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489
Chromeloader Malware Update
https://threatresearch.ext.hp.com/shampoo-a-new-chromeloader-campaign/
Bignum NPM Package Compromise
https://checkmarx.com/blog/hijacking-s3-buckets-new-attack-technique-exploited-in-the-wild-by-supply-chain-attackers
Supervision and Verfication in Vulnerability Management
https://isc.sans.edu/diary/Supervision%20and%20Verification%20in%20Vulnerability%20Management/29952
More MOVEit issues
https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-15June2023
Critical Citrix Sharefile Storagezones Controller
https://support.citrix.com/article/CTX559517/sharefile-storagezones-controller-security-update-for-cve202324489
Chromeloader Malware Update
https://threatresearch.ext.hp.com/shampoo-a-new-chromeloader-campaign/
Bignum NPM Package Compromise
https://checkmarx.com/blog/hijacking-s3-buckets-new-attack-technique-exploited-in-the-wild-by-supply-chain-attackers
Deobfuscating a VBS Script With Custom Encoding
https://isc.sans.edu/diary/Deobfuscating%20a%20VBS%20Script%20With%20Custom%20Encoding/29940
Every Signature is Broken: On the Insecurity of Microsoft Office s OOXML Signatures
https://www.usenix.org/conference/usenixsecurity23/presentation/rohlmann
How to Manage the Vulnerailbity Associated with CVE-2023-32019
https://support.microsoft.com/en-gb/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080
Fake Security Research GitHub Repos
https://vulncheck.com/blog/fake-repos-deliver-malicious-implant
Fortigate Vuln Details
https://blog.lexfo.fr/xortigate-cve-2023-27997.html
Zoom Updates
https://explore.zoom.us/en/trust/security/security-bulletin/
Deobfuscating a VBS Script With Custom Encoding
https://isc.sans.edu/diary/Deobfuscating%20a%20VBS%20Script%20With%20Custom%20Encoding/29940
Every Signature is Broken: On the Insecurity of Microsoft Office s OOXML Signatures
https://www.usenix.org/conference/usenixsecurity23/presentation/rohlmann
How to Manage the Vulnerailbity Associated with CVE-2023-32019
https://support.microsoft.com/en-gb/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080
Fake Security Research GitHub Repos
https://vulncheck.com/blog/fake-repos-deliver-malicious-implant
Fortigate Vuln Details
https://blog.lexfo.fr/xortigate-cve-2023-27997.html
Zoom Updates
https://explore.zoom.us/en/trust/security/security-bulletin/
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/June%202023%20Microsoft%20Patch%20Tuesday/29942/
VMWare 0-Day
https://www.mandiant.com/resources/blog/vmware-esxi-zero-day-bypass
https://www.vmware.com/security/advisories/VMSA-2023-0013.html
SAP Patches
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/June%202023%20Microsoft%20Patch%20Tuesday/29942/
VMWare 0-Day
https://www.mandiant.com/resources/blog/vmware-esxi-zero-day-bypass
https://www.vmware.com/security/advisories/VMSA-2023-0013.html
SAP Patches
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Geoserver Attack Details: More Cryptominers Against Unconfigured WebApps
https://isc.sans.edu/diary/Geoserver%20Attack%20Details%3A%20More%20Cryptominers%20against%20Unconfigured%20WebApps/29936
Fortinet Update CVE-2023-27997
https://www.fortiguard.com/psirt/FG-IR-23-097
Bitwarden Key Accessible By Low Privileged User
https://hackerone.com/reports/1874155
Western Digital SMART Flag Abuse
https://arstechnica.com/gadgets/2023/06/clearly-predatory-western-digital-sparks-panic-anger-for-age-shaming-hdds/
Geoserver Attack Details: More Cryptominers Against Unconfigured WebApps
https://isc.sans.edu/diary/Geoserver%20Attack%20Details%3A%20More%20Cryptominers%20against%20Unconfigured%20WebApps/29936
Fortinet Update CVE-2023-27997
https://www.fortiguard.com/psirt/FG-IR-23-097
Bitwarden Key Accessible By Low Privileged User
https://hackerone.com/reports/1874155
Western Digital SMART Flag Abuse
https://arstechnica.com/gadgets/2023/06/clearly-predatory-western-digital-sparks-panic-anger-for-age-shaming-hdds/
Undetected PowerShell Backdoor Disduigsed as a Profiled File
https://isc.sans.edu/diary/Undetected%20PowerShell%20Backdoor%20Disguised%20as%20a%20Profile%20File/29930
DShield Honeypot Activity for May 2023
https://isc.sans.edu/diary/DShield%20Honeypot%20Activity%20for%20May%202023%20/29932
Second MOVEit Vulnerability
https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability
Fortinet Patches CVE-2023-27997
https://twitter.com/cfreal_/status/1667852157536616451
Undetected PowerShell Backdoor Disduigsed as a Profiled File
https://isc.sans.edu/diary/Undetected%20PowerShell%20Backdoor%20Disguised%20as%20a%20Profile%20File/29930
DShield Honeypot Activity for May 2023
https://isc.sans.edu/diary/DShield%20Honeypot%20Activity%20for%20May%202023%20/29932
Second MOVEit Vulnerability
https://www.progress.com/security/moveit-transfer-and-moveit-cloud-vulnerability
Fortinet Patches CVE-2023-27997
https://twitter.com/cfreal_/status/1667852157536616451
Geoserver Scans
https://isc.sans.edu/diary/Ongoing%20scans%20for%20Geoserver/29926
Barracuda Recommends Replacing Compromised Devices
https://www.barracuda.com/company/legal/esg-vulnerability
Google improves Chrome Password Manager
https://www.msn.com/en-us/news/other/chrome-adds-windows-biometric-logins-to-its-password-powers/ar-AA1ciCCf
Minecraft Mods Include Malicious Code
https://www.bleepingcomputer.com/news/security/new-fractureiser-malware-used-curseforge-minecraft-mods-to-infect-windows-linux/
Trend Micro Service Pack
https://files.trendmicro.com/documentation/readme/Apex%20One/2020/apex_one_2019_win_cp_b12033_EN_Critical_Patch_Readme.html
Geoserver Scans
https://isc.sans.edu/diary/Ongoing%20scans%20for%20Geoserver/29926
Barracuda Recommends Replacing Compromised Devices
https://www.barracuda.com/company/legal/esg-vulnerability
Google improves Chrome Password Manager
https://www.msn.com/en-us/news/other/chrome-adds-windows-biometric-logins-to-its-password-powers/ar-AA1ciCCf
Minecraft Mods Include Malicious Code
https://www.bleepingcomputer.com/news/security/new-fractureiser-malware-used-curseforge-minecraft-mods-to-infect-windows-linux/
Trend Micro Service Pack
https://files.trendmicro.com/documentation/readme/Apex%20One/2020/apex_one_2019_win_cp_b12033_EN_Critical_Patch_Readme.html
DMARC in .co TLD
https://isc.sans.edu/diary/Management%20of%20DMARC%20control%20for%20email%20impersonation%20of%20domains%20in%20the%20.co%20TLD%20-%20part%202/29922
Three Vulnerabilities in VMWare Aria Operations for Networks
https://www.vmware.com/security/advisories/VMSA-2023-0012.html
SpinOK Spyware SDK found in Android Apps
https://vms.drweb.com/search/?q=Android.Spy.SpinOk&lng=en
https://www.cloudsek.com/threatintelligence/supply-chain-attack-infiltrates-android-apps-with-malicious-sdk
Cisco Anyconnect Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-csc-privesc-wx4U4Kw
RSA Webcast
https://www.rsaconference.com/library/webcast/149-sans-followup-2023
DMARC in .co TLD
https://isc.sans.edu/diary/Management%20of%20DMARC%20control%20for%20email%20impersonation%20of%20domains%20in%20the%20.co%20TLD%20-%20part%202/29922
Three Vulnerabilities in VMWare Aria Operations for Networks
https://www.vmware.com/security/advisories/VMSA-2023-0012.html
SpinOK Spyware SDK found in Android Apps
https://vms.drweb.com/search/?q=Android.Spy.SpinOk&lng=en
https://www.cloudsek.com/threatintelligence/supply-chain-attack-infiltrates-android-apps-with-malicious-sdk
Cisco Anyconnect Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-csc-privesc-wx4U4Kw
RSA Webcast
https://www.rsaconference.com/library/webcast/149-sans-followup-2023
Github Copilot vs Google: Which Code is More Secure
https://isc.sans.edu/forums/diary/Github%20Copilot%20vs.%20Google%3A%20Which%20code%20is%20more%20secure/29918/
Android Update
https://source.android.com/docs/security/bulletin/2023-06-01
Chrome Updates
https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.html
FBI Warns of Manipulated Photos and Videos For Sextortion
https://www.ic3.gov/Media/Y2023/PSA230605
Github Copilot vs Google: Which Code is More Secure
https://isc.sans.edu/forums/diary/Github%20Copilot%20vs.%20Google%3A%20Which%20code%20is%20more%20secure/29918/
Android Update
https://source.android.com/docs/security/bulletin/2023-06-01
Chrome Updates
https://chromereleases.googleblog.com/2023/06/stable-channel-update-for-desktop.html
FBI Warns of Manipulated Photos and Videos For Sextortion
https://www.ic3.gov/Media/Y2023/PSA230605
Brute Forcing Simple Archive Passwords
https://isc.sans.edu/diary/Brute%20Forcing%20Simple%20Archive%20Passwords/29914
KeePass 2.54 Released
https://keepass.info/news/n230603_2.54.html
Splunk Advisories
https://advisory.splunk.com/advisories
Malicious Google Chrome Extensions
https://palant.info/2023/05/31/more-malicious-extensions-in-chrome-web-store/
Symantec Updates
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/22217
Brute Forcing Simple Archive Passwords
https://isc.sans.edu/diary/Brute%20Forcing%20Simple%20Archive%20Passwords/29914
KeePass 2.54 Released
https://keepass.info/news/n230603_2.54.html
Splunk Advisories
https://advisory.splunk.com/advisories
Malicious Google Chrome Extensions
https://palant.info/2023/05/31/more-malicious-extensions-in-chrome-web-store/
Symantec Updates
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/22217
Critical Vulnerability in MoveIT Transfer Actively Exploited
https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023
https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/
https://www.mandiant.com/resources/blog/zero-day-moveit-data-theft
Atomic Wallet Compromise
https://www.bleepingcomputer.com/news/security/atomic-wallet-hacks-lead-to-over-35-million-in-crypto-stolen/
Magecart Update
https://www.akamai.com/blog/security-research/new-magecart-hides-behind-legit-domains
Critical Vulnerability in MoveIT Transfer Actively Exploited
https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023
https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/
https://www.mandiant.com/resources/blog/zero-day-moveit-data-theft
Atomic Wallet Compromise
https://www.bleepingcomputer.com/news/security/atomic-wallet-hacks-lead-to-over-35-million-in-crypto-stolen/
Magecart Update
https://www.akamai.com/blog/security-research/new-magecart-hides-behind-legit-domains
After 28 Years, SSLv2 is Still Not Gone
https://isc.sans.edu/forums/diary/After%2028%20years%2C%20SSLv2%20is%20still%20not%20gone%20from%20the%20internet...%20but%20we're%20getting%20there/29908/
Operation Triangulation: iOS Devices Targeted With Previously Unknown Malware
https://securelist.com/operation-triangulation/109842/
MOVEit Transfer Criticial Vulnerability
https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023
Code Injection Vulnerablity in Reportlab Python Library
https://github.com/c53elyas/CVE-2023-33733
After 28 Years, SSLv2 is Still Not Gone
https://isc.sans.edu/forums/diary/After%2028%20years%2C%20SSLv2%20is%20still%20not%20gone%20from%20the%20internet...%20but%20we're%20getting%20there/29908/
Operation Triangulation: iOS Devices Targeted With Previously Unknown Malware
https://securelist.com/operation-triangulation/109842/
MOVEit Transfer Criticial Vulnerability
https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023
Code Injection Vulnerablity in Reportlab Python Library
https://github.com/c53elyas/CVE-2023-33733
Apache NiFi Attacks
https://isc.sans.edu/diary/Your%20Business%20Data%20and%20Machine%20Learning%20at%20Risk%3A%20Attacks%20Against%20Apache%20NiFi/29900
Gigabyte App Center Backdoor;
https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
Salesforce Ghost Sites
https://www.varonis.com/blog/salesforce-ghost-sites
CVE-2023-34152: Shell Command Injection in ImageMagick
https://securityonline.info/cve-2023-34152-shell-command-injection-bug-affecting-imagemagick/
Apache NiFi Attacks
https://isc.sans.edu/diary/Your%20Business%20Data%20and%20Machine%20Learning%20at%20Risk%3A%20Attacks%20Against%20Apache%20NiFi/29900
Gigabyte App Center Backdoor;
https://eclypsium.com/blog/supply-chain-risk-from-gigabyte-app-center-backdoor/
Salesforce Ghost Sites
https://www.varonis.com/blog/salesforce-ghost-sites
CVE-2023-34152: Shell Command Injection in ImageMagick
https://securityonline.info/cve-2023-34152-shell-command-injection-bug-affecting-imagemagick/
Malspam Pushes ModiLoader Infection for Remocs Rat
https://isc.sans.edu/diary/Malspam%20pushes%20ModiLoader%20%28DBatLoader%29%20infection%20for%20Remcos%20RAT/29896
MacOS SIP Bypass
https://www.microsoft.com/en-us/security/blog/2023/05/30/new-macos-vulnerability-migraine-could-bypass-system-integrity-protection/
OpenSSL Update
https://www.openssl.org/news/secadv/20230530.txt
Barracuda Email Security Gateway Applicance Vulnerability Details
https://www.barracuda.com/company/legal/esg-vulnerability#:~:text=the%20section%20below.-,Endpoint%20IOCs,-Table%204%20lists
Void Rabisu RomCom Backdoor
https://www.trendmicro.com/en_us/research/23/e/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html
Nextcloud Vulnerability
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-mr7q-xf62-fw54
Zyxel NAS Vulnerability
https://sternumiot.com/iot-blog/ntp-textbox-vulnerability-in-zyxel-nas326-nas540-and-nas542-devices/
Wait Just An Infosec: Higher Ed
https://www.youtube.com/watch?v=ufEuo-096yc&list=PLtgaAEEmVe6B2kqkE9KdgPJdtbqNiaiOn&index=8
Malspam Pushes ModiLoader Infection for Remocs Rat
https://isc.sans.edu/diary/Malspam%20pushes%20ModiLoader%20%28DBatLoader%29%20infection%20for%20Remcos%20RAT/29896
MacOS SIP Bypass
https://www.microsoft.com/en-us/security/blog/2023/05/30/new-macos-vulnerability-migraine-could-bypass-system-integrity-protection/
OpenSSL Update
https://www.openssl.org/news/secadv/20230530.txt
Barracuda Email Security Gateway Applicance Vulnerability Details
https://www.barracuda.com/company/legal/esg-vulnerability#:~:text=the%20section%20below.-,Endpoint%20IOCs,-Table%204%20lists
Void Rabisu RomCom Backdoor
https://www.trendmicro.com/en_us/research/23/e/void-rabisu-s-use-of-romcom-backdoor-shows-a-growing-shift-in-th.html
Nextcloud Vulnerability
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-mr7q-xf62-fw54
Zyxel NAS Vulnerability
https://sternumiot.com/iot-blog/ntp-textbox-vulnerability-in-zyxel-nas326-nas540-and-nas542-devices/
Wait Just An Infosec: Higher Ed
https://www.youtube.com/watch?v=ufEuo-096yc&list=PLtgaAEEmVe6B2kqkE9KdgPJdtbqNiaiOn&index=8
Analyzing Office Documents Embedded Inside PowerPoint Files
https://isc.sans.edu/diary/Analyzing%20Office%20Documents%20Embedded%20Inside%20PPT%20%28PowerPoint%29%20Files/29894
DocuSign Themed Email Leads to Script-Based Infection
https://isc.sans.edu/diary/DocuSign-themed%20email%20leads%20to%20script-based%20infection/29888
File Archiver In The Browser
https://mrd0x.com/file-archiver-in-the-browser/
Securing PyPI accounts via Two-Factor Authentication
https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2fa/
Apache Casandra Vulnerabilities
https://lists.apache.org/thread/mwd02nrw2go8shg29rnp3o4hgompvkp5
MOXA MXsecurity Vulerabilities
https://www.moxa.com/en/support/product-support/security-advisory/mxsecurity-command-injection-and-hardcoded-credential-vulnerabilities
Analyzing Office Documents Embedded Inside PowerPoint Files
https://isc.sans.edu/diary/Analyzing%20Office%20Documents%20Embedded%20Inside%20PPT%20%28PowerPoint%29%20Files/29894
DocuSign Themed Email Leads to Script-Based Infection
https://isc.sans.edu/diary/DocuSign-themed%20email%20leads%20to%20script-based%20infection/29888
File Archiver In The Browser
https://mrd0x.com/file-archiver-in-the-browser/
Securing PyPI accounts via Two-Factor Authentication
https://blog.pypi.org/posts/2023-05-25-securing-pypi-with-2fa/
Apache Casandra Vulnerabilities
https://lists.apache.org/thread/mwd02nrw2go8shg29rnp3o4hgompvkp5
MOXA MXsecurity Vulerabilities
https://www.moxa.com/en/support/product-support/security-advisory/mxsecurity-command-injection-and-hardcoded-credential-vulnerabilities
IR Case/Alert Management
https://isc.sans.edu/diary/IR%20Case%20Alert%20Management/29880
Exploit for CVE-2023-2825 GitLab Vulnerability
https://github.com/Occamsec/CVE-2023-2825
Expo Framework OAUTH Vulnerability CVE-2023-28131
https://salt.security/blog/a-new-oauth-vulnerability-that-may-impact-hundreds-of-online-services
Mitel MiVoice Vulnerability CVE-2023-31457 CVE-2023-32748
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0004
D-Link Vulnerabilities
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10332
IR Case/Alert Management
https://isc.sans.edu/diary/IR%20Case%20Alert%20Management/29880
Exploit for CVE-2023-2825 GitLab Vulnerability
https://github.com/Occamsec/CVE-2023-2825
Expo Framework OAUTH Vulnerability CVE-2023-28131
https://salt.security/blog/a-new-oauth-vulnerability-that-may-impact-hundreds-of-online-services
Mitel MiVoice Vulnerability CVE-2023-31457 CVE-2023-32748
https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-23-0004
D-Link Vulnerabilities
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10332
More Data Enrichment for Cowrie Logs
https://isc.sans.edu/diary/More%20Data%20Enrichment%20for%20Cowrie%20Logs/29878
Volt Typhoon: Living of the Land
https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
Android App Breaking Bad
https://www.welivesecurity.com/2023/05/23/android-app-breaking-bad-legitimate-screen-recording-file-exfiltration/
Zyxel Updates
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls
Baracuda Email Security Gateway Vulnerability
https://status.barracuda.com/incidents/34kx82j5n4q9
Gitlab Patch
https://about.gitlab.com/releases/2023/05/23/critical-security-release-gitlab-16-0-1-released/
More Data Enrichment for Cowrie Logs
https://isc.sans.edu/diary/More%20Data%20Enrichment%20for%20Cowrie%20Logs/29878
Volt Typhoon: Living of the Land
https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
Android App Breaking Bad
https://www.welivesecurity.com/2023/05/23/android-app-breaking-bad-legitimate-screen-recording-file-exfiltration/
Zyxel Updates
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-multiple-buffer-overflow-vulnerabilities-of-firewalls
Baracuda Email Security Gateway Vulnerability
https://status.barracuda.com/incidents/34kx82j5n4q9
Gitlab Patch
https://about.gitlab.com/releases/2023/05/23/critical-security-release-gitlab-16-0-1-released/
Apache Nifi Scans
https://isc.sans.edu/diary/Help+us+figure+this+out+Scans+for+Apache+Nifi/29874/
Samsung Updates fix 0-Day
https://security.samsungmobile.com/securityUpdate.smsb
Lenovo All-In One Bricked by Windows Update
https://www.reddit.com/r/Lenovo/comments/136tatm/lenovo_firmware_10055_bricking_thinkcentre_v53024/
Dell VxRail Security Update
https://www.dell.com/support/kbdoc/en-us/000213011/dsa-2023-071-dell-vxrail-security-update-for-multiple-third-party-component-vulnerabilities-7-0-450
BrutePrint: Expose Smartphone Fingerprint Authentication to Brute-force Attack
https://arxiv.org/pdf/2305.10791.pdf
Apache Nifi Scans
https://isc.sans.edu/diary/Help+us+figure+this+out+Scans+for+Apache+Nifi/29874/
Samsung Updates fix 0-Day
https://security.samsungmobile.com/securityUpdate.smsb
Lenovo All-In One Bricked by Windows Update
https://www.reddit.com/r/Lenovo/comments/136tatm/lenovo_firmware_10055_bricking_thinkcentre_v53024/
Dell VxRail Security Update
https://www.dell.com/support/kbdoc/en-us/000213011/dsa-2023-071-dell-vxrail-security-update-for-multiple-third-party-component-vulnerabilities-7-0-450
BrutePrint: Expose Smartphone Fingerprint Authentication to Brute-force Attack
https://arxiv.org/pdf/2305.10791.pdf
Probes for recent ABUS Security Camera Vulnerability
https://isc.sans.edu/diary/Probes%20for%20recent%20ABUS%20Security%20Camera%20Vulnerability%3A%20Attackers%20keep%20an%20eye%20on%20everything./29870
.ZIP Domains Confuse Virustotal
https://twitter.com/imohanasundaram/status/1660678184977805316
Synology DSM 6.2 Patch
https://www.synology.com/en-global/security/advisory/Synology_SA_22_25
Jenkins Fixes Multiple Plugin Vulnerabilities
https://www.jenkins.io/security/advisory/2023-05-16/
PyPi Suspension Lifted
https://status.python.org/incidents/qy2t9mjjcc7g
Nissan Sylphy Classic Key Vulnerability
https://vulmon.com/vulnerabilitydetails?qid=CVE-2023-33281
Probes for recent ABUS Security Camera Vulnerability
https://isc.sans.edu/diary/Probes%20for%20recent%20ABUS%20Security%20Camera%20Vulnerability%3A%20Attackers%20keep%20an%20eye%20on%20everything./29870
.ZIP Domains Confuse Virustotal
https://twitter.com/imohanasundaram/status/1660678184977805316
Synology DSM 6.2 Patch
https://www.synology.com/en-global/security/advisory/Synology_SA_22_25
Jenkins Fixes Multiple Plugin Vulnerabilities
https://www.jenkins.io/security/advisory/2023-05-16/
PyPi Suspension Lifted
https://status.python.org/incidents/qy2t9mjjcc7g
Nissan Sylphy Classic Key Vulnerability
https://vulmon.com/vulnerabilitydetails?qid=CVE-2023-33281
Another Malicious HTA File Analysis - Part 3
https://isc.sans.edu/forums/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%203/29678/
When the Phisher Messes Up With Encoding
https://isc.sans.edu/diary/When%20the%20Phisher%20Messes%20Up%20With%20Encoding/29864
PyPi Suspends New Users and Projects
https://status.python.org/incidents/qy2t9mjjcc7g
PGP Signatures on PyPi: Worse than useless
https://blog.yossarian.net/2023/05/21/PGP-signatures-on-PyPI-worse-than-useless
RATs found hiding in the npm attic
https://www.reversinglabs.com/blog/rats-found-hiding-in-the-npm-attic
Another Malicious HTA File Analysis - Part 3
https://isc.sans.edu/forums/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%203/29678/
When the Phisher Messes Up With Encoding
https://isc.sans.edu/diary/When%20the%20Phisher%20Messes%20Up%20With%20Encoding/29864
PyPi Suspends New Users and Projects
https://status.python.org/incidents/qy2t9mjjcc7g
PGP Signatures on PyPi: Worse than useless
https://blog.yossarian.net/2023/05/21/PGP-signatures-on-PyPI-worse-than-useless
RATs found hiding in the npm attic
https://www.reversinglabs.com/blog/rats-found-hiding-in-the-npm-attic
Apple Updates Everything
https://isc.sans.edu/diary/Apple%20Updates%20Everything/29860
A Quick Survey of .zip Domains
https://isc.sans.edu/diary/A%20Quick%20Survey%20of%20.zip%20Domains%3A%20Your%20highest%20risk%20is%20running%20into%20Rick%20Astley./29858
Dell NetWorker Security Update
https://www.dell.com/support/kbdoc/en-us/000211267/dsa-2023-060-dell-networker-security-update-for-an-nsrcapinfo-vulnerability?lwp=rt
KeePass 2.X Master Password Dumper
https://github.com/vdohney/keepass-password-dumper
Apple Updates Everything
https://isc.sans.edu/diary/Apple%20Updates%20Everything/29860
A Quick Survey of .zip Domains
https://isc.sans.edu/diary/A%20Quick%20Survey%20of%20.zip%20Domains%3A%20Your%20highest%20risk%20is%20running%20into%20Rick%20Astley./29858
Dell NetWorker Security Update
https://www.dell.com/support/kbdoc/en-us/000211267/dsa-2023-060-dell-networker-security-update-for-an-nsrcapinfo-vulnerability?lwp=rt
KeePass 2.X Master Password Dumper
https://github.com/vdohney/keepass-password-dumper
Increase in Malicious RAR SFX Files
https://isc.sans.edu/forums/diary/Increase%20in%20Malicious%20RAR%20SFX%20files/29852/
FriendlyName Buffer Overflow in Wemo Smartplug
https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/
Wago License Page Exploit
https://onekey.com/blog/security-advisory-wago-unauthenticated-remote-command-execution/
Routers Turned Into Proxies
https://research.checkpoint.com/2023/the-dragon-who-sold-his-camaro-analyzing-custom-router-implant/
Increase in Malicious RAR SFX Files
https://isc.sans.edu/forums/diary/Increase%20in%20Malicious%20RAR%20SFX%20files/29852/
FriendlyName Buffer Overflow in Wemo Smartplug
https://sternumiot.com/iot-blog/mini-smart-plug-v2-vulnerability-buffer-overflow/
Wago License Page Exploit
https://onekey.com/blog/security-advisory-wago-unauthenticated-remote-command-execution/
Routers Turned Into Proxies
https://research.checkpoint.com/2023/the-dragon-who-sold-his-camaro-analyzing-custom-router-implant/
Signals Defense With Faraday Bags
https://isc.sans.edu/forums/diary/Signals%20Defense%20With%20Faraday%20Bags%20%26%20Flipper%20Zero/29840/
Microsoft Sharepoint Scans Password Protected Files
https://infosec.exchange/@threatresearch/110373860063222707#
Critical Sandbox Escape Vulnerability in VM2
https://github.com/patriksimek/vm2/security/advisories/GHSA-whpj-8f3w-67p5
Geacon Brings Cobalt Strike Capabilities to MacOS Threat Actors
https://www.sentinelone.com/blog/geacon-brings-cobalt-strike-capabilities-to-macos-threat-actors/
Signals Defense With Faraday Bags
https://isc.sans.edu/forums/diary/Signals%20Defense%20With%20Faraday%20Bags%20%26%20Flipper%20Zero/29840/
Microsoft Sharepoint Scans Password Protected Files
https://infosec.exchange/@threatresearch/110373860063222707#
Critical Sandbox Escape Vulnerability in VM2
https://github.com/patriksimek/vm2/security/advisories/GHSA-whpj-8f3w-67p5
Geacon Brings Cobalt Strike Capabilities to MacOS Threat Actors
https://www.sentinelone.com/blog/geacon-brings-cobalt-strike-capabilities-to-macos-threat-actors/
Ongoing Facebook Phishing campaign Without a Sender and (almost) without Links
https://isc.sans.edu/diary/Ongoing%20Facebook%20phishing%20campaign%20without%20a%20sender%20and%20%28almost%29%20without%20links/29848
Intel Microcode Updates Do Not Patch Vulnerability
https://www.theregister.com/2023/05/15/intel_mystery_microcode/
Fake Trezor Hardware Crypto Wallet
https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/
TP-Link Archer AX-21 Command Injection CVE-2023-1389 Exploited
https://www.fortiguard.com/threat-signal-report/5157/tp-link-archer-ax-21-command-injection-vulnerability-cve-2023-1389-exploited-in-the-wild
Ongoing Facebook Phishing campaign Without a Sender and (almost) without Links
https://isc.sans.edu/diary/Ongoing%20Facebook%20phishing%20campaign%20without%20a%20sender%20and%20%28almost%29%20without%20links/29848
Intel Microcode Updates Do Not Patch Vulnerability
https://www.theregister.com/2023/05/15/intel_mystery_microcode/
Fake Trezor Hardware Crypto Wallet
https://www.kaspersky.com/blog/fake-trezor-hardware-crypto-wallet/48155/
TP-Link Archer AX-21 Command Injection CVE-2023-1389 Exploited
https://www.fortiguard.com/threat-signal-report/5157/tp-link-archer-ax-21-command-injection-vulnerability-cve-2023-1389-exploited-in-the-wild
The .zip gTLD: Risks and Opportunities
https://isc.sans.edu/forums/diary/The+zip+gTLD+Risks+and+Opportunities/29838/
Brave Forgetful Browsing
https://brave.com/privacy-updates/25-forgetful-browsing/
Intel Mystery Microcode Patch
https://www.phoronix.com/news/Intel-12-May-2023-Microcode
Netgear Updates
https://kb.netgear.com/000065619/Security-Advisory-for-Multiple-Vulnerabilities-on-the-RAX30-PSV-2022-0348
Synology Updates
https://www.synology.com/en-global/security/advisory/Synology_SA_23_04
https://claroty.com/team82/research/chaining-five-vulnerabilities-to-exploit-netgear-nighthawk-rax30-routers-at-pwn2own-toronto-2022
The .zip gTLD: Risks and Opportunities
https://isc.sans.edu/forums/diary/The+zip+gTLD+Risks+and+Opportunities/29838/
Brave Forgetful Browsing
https://brave.com/privacy-updates/25-forgetful-browsing/
Intel Mystery Microcode Patch
https://www.phoronix.com/news/Intel-12-May-2023-Microcode
Netgear Updates
https://kb.netgear.com/000065619/Security-Advisory-for-Multiple-Vulnerabilities-on-the-RAX30-PSV-2022-0348
Synology Updates
https://www.synology.com/en-global/security/advisory/Synology_SA_23_04
https://claroty.com/team82/research/chaining-five-vulnerabilities-to-exploit-netgear-nighthawk-rax30-routers-at-pwn2own-toronto-2022
Geolocating IPs is Harder Than You Think
https://isc.sans.edu/diary/Geolocating%20IPs%20is%20harder%20than%20you%20think/29834
Pre-Infected Mobile Phones
https://www.theregister.com/2023/05/11/bh_asia_mobile_phones/
Dragos Breach
https://www.dragos.com/blog/deconstructing-a-cybersecurity-event/
AndoryuBot Targets Ruckus Admin RCE Vulnerability
https://www.fortinet.com/blog/threat-research/andoryubot-new-botnet-campaign-targets-ruckus-wireless-admin-remote-code-execution-vulnerability-cve-2023-25717
Geolocating IPs is Harder Than You Think
https://isc.sans.edu/diary/Geolocating%20IPs%20is%20harder%20than%20you%20think/29834
Pre-Infected Mobile Phones
https://www.theregister.com/2023/05/11/bh_asia_mobile_phones/
Dragos Breach
https://www.dragos.com/blog/deconstructing-a-cybersecurity-event/
AndoryuBot Targets Ruckus Admin RCE Vulnerability
https://www.fortinet.com/blog/threat-research/andoryubot-new-botnet-campaign-targets-ruckus-wireless-admin-remote-code-execution-vulnerability-cve-2023-25717
Exploratory Data Analysis with CISSM Cyber Attacks Database Part 2
https://isc.sans.edu/diary/Exploratory%20Data%20Analysis%20with%20CISSM%20Cyber%20Attacks%20Database%20-%20Part%202/29828
Microsoft Patched Outlook (actually Windows) vulnerability again
https://www.akamai.com/blog/security-research/important-outlook-vulnerability-bypass-windows-api
Law Enforcement and Intelligence Agencies Disable "Snake" Malware
https://media.defense.gov/2023/May/09/2003218554/-1/-1/1/JOINT_CSA_HUNTING_RU_INTEL_SNAKE_MALWARE_20230509.PDF
Fake System Update Drop Malware
https://www.malwarebytes.com/blog/threat-intelligence/2023/05/fake-system-update-drops-new-highly-evasive-loader
Exploratory Data Analysis with CISSM Cyber Attacks Database Part 2
https://isc.sans.edu/diary/Exploratory%20Data%20Analysis%20with%20CISSM%20Cyber%20Attacks%20Database%20-%20Part%202/29828
Microsoft Patched Outlook (actually Windows) vulnerability again
https://www.akamai.com/blog/security-research/important-outlook-vulnerability-bypass-windows-api
Law Enforcement and Intelligence Agencies Disable "Snake" Malware
https://media.defense.gov/2023/May/09/2003218554/-1/-1/1/JOINT_CSA_HUNTING_RU_INTEL_SNAKE_MALWARE_20230509.PDF
Fake System Update Drop Malware
https://www.malwarebytes.com/blog/threat-intelligence/2023/05/fake-system-update-drops-new-highly-evasive-loader
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20May%202023%20Patch%20Tuesday/29826
GitHub "Push Protection" now out of Beta
https://github.blog/2023-05-09-push-protection-is-generally-available-and-free-for-all-public-repositories/
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20May%202023%20Patch%20Tuesday/29826
GitHub "Push Protection" now out of Beta
https://github.blog/2023-05-09-push-protection-is-generally-available-and-free-for-all-public-repositories/
QR Codes Used in Fake Parking Tickets and Surveys
https://www.bleepingcomputer.com/news/security/qr-codes-used-in-fake-parking-tickets-surveys-to-steal-your-money/
Microsoft Edge Update
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel
Facebook Sees More Fake ChatGPT
https://about.fb.com/news/2023/05/metas-q1-2023-security-reports/
CyberGhost VPN Vulnerability
https://www.pentestpartners.com/security-blog/bullied-by-bugcrowd-over-kape-cyberghost-disclosure/
QR Codes Used in Fake Parking Tickets and Surveys
https://www.bleepingcomputer.com/news/security/qr-codes-used-in-fake-parking-tickets-surveys-to-steal-your-money/
Microsoft Edge Update
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-relnote-stable-channel
Facebook Sees More Fake ChatGPT
https://about.fb.com/news/2023/05/metas-q1-2023-security-reports/
CyberGhost VPN Vulnerability
https://www.pentestpartners.com/security-blog/bullied-by-bugcrowd-over-kape-cyberghost-disclosure/
Quickly Finding Encoded Payloads in Office Documents
https://isc.sans.edu/forums/diary/Quickly+Finding+Encoded+Payloads+in+Office+Documents/29818/
Exploratory Data Analysis with CISSM Cyber Attacks Database Part 1
https://isc.sans.edu/forums/diary/Exploratory+Data+Analysis+with+CISSM+Cyber+Attacks+Database+Part+1/29816/
Guildma is now Abusing Colorcpl.exe LOLBIN
https://isc.sans.edu/forums/diary/Guildma+is+now+abusing+colorcplexe+LOLBIN/29814/
Leaked MSI Keys
https://github.com/binarly-io/SupplyChainAttacks/blob/main/MSI/ImpactedDevices.md
https://twitter.com/matrosov/status/1654560343295934464
PHP Packages Compromised
https://blog.packagist.com/packagist-org-maintainer-account-takeover/
Quickly Finding Encoded Payloads in Office Documents
https://isc.sans.edu/forums/diary/Quickly+Finding+Encoded+Payloads+in+Office+Documents/29818/
Exploratory Data Analysis with CISSM Cyber Attacks Database Part 1
https://isc.sans.edu/forums/diary/Exploratory+Data+Analysis+with+CISSM+Cyber+Attacks+Database+Part+1/29816/
Guildma is now Abusing Colorcpl.exe LOLBIN
https://isc.sans.edu/forums/diary/Guildma+is+now+abusing+colorcplexe+LOLBIN/29814/
Leaked MSI Keys
https://github.com/binarly-io/SupplyChainAttacks/blob/main/MSI/ImpactedDevices.md
https://twitter.com/matrosov/status/1654560343295934464
PHP Packages Compromised
https://blog.packagist.com/packagist-org-maintainer-account-takeover/
Infostealer Embedded in a Word Document
https://isc.sans.edu/diary/Infostealer%20Embedded%20in%20a%20Word%20Document/29810
Cisco SPA-112 Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-unauth-upgrade-UqhyTWW
Fortinet May Updates
https://www.fortiguard.com/psirt?date=05-2023
PaperCut exploitation - A Different Path to Code Execution
https://vulncheck.com/blog/papercut-rce
Infostealer Embedded in a Word Document
https://isc.sans.edu/diary/Infostealer%20Embedded%20in%20a%20Word%20Document/29810
Cisco SPA-112 Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-spa-unauth-upgrade-UqhyTWW
Fortinet May Updates
https://www.fortiguard.com/psirt?date=05-2023
PaperCut exploitation - A Different Path to Code Execution
https://vulncheck.com/blog/papercut-rce
Increased Number of Configuration File Scans
https://isc.sans.edu/diary/Increased%20Number%20of%20Configuration%20File%20Scans/29806
Google Enabling Passkeys
https://blog.google/technology/safety-security/the-beginning-of-the-end-of-the-password/
Chrome to Drop Lock Icon from HTTPS
https://blog.chromium.org/2023/05/an-update-on-lock-icon.html
Attack Against AMD TPM Implementation
https://arxiv.org/abs/2304.14717
Increased Number of Configuration File Scans
https://isc.sans.edu/diary/Increased%20Number%20of%20Configuration%20File%20Scans/29806
Google Enabling Passkeys
https://blog.google/technology/safety-security/the-beginning-of-the-end-of-the-password/
Chrome to Drop Lock Icon from HTTPS
https://blog.chromium.org/2023/05/an-update-on-lock-icon.html
Attack Against AMD TPM Implementation
https://arxiv.org/abs/2304.14717
VBA Project References
https://isc.sans.edu/diary/VBA%20Project%20References/29800
BGP Message Parsing Vulnerabilities in FRRouting
https://www.forescout.com/blog/three-new-bgp-message-parsing-vulnerabilities-disclosed-in-frrouting-software/
JWT ECDSA Algorithm Confusion
https://blog.pentesterlab.com/exploring-algorithm-confusion-attacks-on-jwt-exploiting-ecdsa-23f7ff83390f
VBA Project References
https://isc.sans.edu/diary/VBA%20Project%20References/29800
BGP Message Parsing Vulnerabilities in FRRouting
https://www.forescout.com/blog/three-new-bgp-message-parsing-vulnerabilities-disclosed-in-frrouting-software/
JWT ECDSA Algorithm Confusion
https://blog.pentesterlab.com/exploring-algorithm-confusion-attacks-on-jwt-exploiting-ecdsa-23f7ff83390f
Passive Analysis of a Phishing Attachment
https://isc.sans.edu/diary/%22Passive%22%20analysis%20of%20a%20phishing%20attachment/29798
Apple Rapid Security Response
https://www.macrumors.com/2023/05/01/rapid-security-response-16-4-1/
Grafana Security Release
https://grafana.com/blog/2023/04/26/grafana-security-release-new-versions-of-grafana-with-security-fixes-for-cve-2023-28119-and-cve-2023-1387/
Illumina Vulnerability
https://www.fda.gov/medical-devices/letters-health-care-providers/illumina-cybersecurity-vulnerability-affecting-universal-copy-service-software-may-present-risks
Passive Analysis of a Phishing Attachment
https://isc.sans.edu/diary/%22Passive%22%20analysis%20of%20a%20phishing%20attachment/29798
Apple Rapid Security Response
https://www.macrumors.com/2023/05/01/rapid-security-response-16-4-1/
Grafana Security Release
https://grafana.com/blog/2023/04/26/grafana-security-release-new-versions-of-grafana-with-security-fixes-for-cve-2023-28119-and-cve-2023-1387/
Illumina Vulnerability
https://www.fda.gov/medical-devices/letters-health-care-providers/illumina-cybersecurity-vulnerability-affecting-universal-copy-service-software-may-present-risks
Quick IOC Scan With Docker
https://isc.sans.edu/diary/Quick%20IOC%20Scan%20With%20Docker/29788
Dobfuscation Scripts When Encodings Help
https://isc.sans.edu/diary/Deobfuscating%20Scripts%3A%20When%20Encodings%20Help/29792
Hackers Are Breaking Into AT&T Email Accounts To Steal Cryptocurrency
https://techcrunch.com/2023/04/26/hackers-are-breaking-into-att-email-accounts-to-steal-cryptocurrency/
Trheat Actor Selling New Atomic MacOS AMOS Stealer on Telegram
https://blog.cyble.com/2023/04/26/threat-actor-selling-new-atomic-macos-amos-stealer-on-telegram/
Zyxel Firewall Vulnerability
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
Quick IOC Scan With Docker
https://isc.sans.edu/diary/Quick%20IOC%20Scan%20With%20Docker/29788
Dobfuscation Scripts When Encodings Help
https://isc.sans.edu/diary/Deobfuscating%20Scripts%3A%20When%20Encodings%20Help/29792
Hackers Are Breaking Into AT&T Email Accounts To Steal Cryptocurrency
https://techcrunch.com/2023/04/26/hackers-are-breaking-into-att-email-accounts-to-steal-cryptocurrency/
Trheat Actor Selling New Atomic MacOS AMOS Stealer on Telegram
https://blog.cyble.com/2023/04/26/threat-actor-selling-new-atomic-macos-amos-stealer-on-telegram/
Zyxel Firewall Vulnerability
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-remote-command-injection-vulnerability-of-firewalls
Ransomware Gang Exploiting Unpatches Veeam Backup Products
https://www.computerweekly.com/news/365535586/Ransomware-gang-exploiting-unpatched-Veeam-backup-products
Google Authenticator Sync Encryption
https://security.googleblog.com/2023/04/google-authenticator-now-supports.html
Keycloak Vulnerability
https://out.reddit.com/t3_130km04?url=https%3A%2F%2Fwww.offensity.com%2Fen%2Fblog%2Fuser-impersonation-via-stolen-uuid-code-in-keycloak-cve-2023-0264%2F&token=AQAAjSdLZJTzQM37107hVzYY-tbz6ak81pMNqN9qv3m2SWXEOMIm&app_name=web2x&user_id=33629461&web_redirect=true
Ransomware Gang Exploiting Unpatches Veeam Backup Products
https://www.computerweekly.com/news/365535586/Ransomware-gang-exploiting-unpatched-Veeam-backup-products
Google Authenticator Sync Encryption
https://security.googleblog.com/2023/04/google-authenticator-now-supports.html
Keycloak Vulnerability
https://out.reddit.com/t3_130km04?url=https%3A%2F%2Fwww.offensity.com%2Fen%2Fblog%2Fuser-impersonation-via-stolen-uuid-code-in-keycloak-cve-2023-0264%2F&token=AQAAjSdLZJTzQM37107hVzYY-tbz6ak81pMNqN9qv3m2SWXEOMIm&app_name=web2x&user_id=33629461&web_redirect=true
Strolling Through Cyberspace and Hunting for Phishing Sites
https://isc.sans.edu/diary/Strolling%20through%20Cyberspace%20and%20Hunting%20for%20Phishing%20Sites/29780
RSA Panel: Five most dangerous new attack techniques
https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques
SANS.edu Research Journal
https://www.sans.edu/cyber-security-research
Strolling Through Cyberspace and Hunting for Phishing Sites
https://isc.sans.edu/diary/Strolling%20through%20Cyberspace%20and%20Hunting%20for%20Phishing%20Sites/29780
RSA Panel: Five most dangerous new attack techniques
https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques
SANS.edu Research Journal
https://www.sans.edu/cyber-security-research
Calculating CVSS Scores with ChatGPT
https://isc.sans.edu/diary/Calculating%20CVSS%20Scores%20with%20ChatGPT/29774
Amplifying SLP Traffic
https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp
Insecure Default Configuration in Apache Superset
https://www.horizon3.ai/cve-2023-27524-insecure-default-configuration-in-apache-superset-leads-to-remote-code-execution/ SLP Amplification; Apache Superset RCE;
PoC Exploit for Sophos Web Appliciance
https://github.com/W01fh4cker/CVE-2023-1671-POC
Calculating CVSS Scores with ChatGPT
https://isc.sans.edu/diary/Calculating%20CVSS%20Scores%20with%20ChatGPT/29774
Amplifying SLP Traffic
https://www.bitsight.com/blog/new-high-severity-vulnerability-cve-2023-29552-discovered-service-location-protocol-slp
Insecure Default Configuration in Apache Superset
https://www.horizon3.ai/cve-2023-27524-insecure-default-configuration-in-apache-superset-leads-to-remote-code-execution/ SLP Amplification; Apache Superset RCE;
PoC Exploit for Sophos Web Appliciance
https://github.com/W01fh4cker/CVE-2023-1671-POC
Aukill EDR Killer Malware Abuses Process Explorer Driver
https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/
Papercut Vulnerability Deep Dive
https://www.horizon3.ai/papercut-cve-2023-27350-deep-dive-and-indicators-of-compromise
Solarwinds Patches
https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-2_release_notes.htm
Schneider Electric Update
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-04&p_enDocType=Security%20and%20Safety%20Notice&p_File_Name=SEVD-2023-101-04.pdf
Virustotal Code Insight
https://blog.virustotal.com/2023/04/introducing-virustotal-code-insight.html
Aukill EDR Killer Malware Abuses Process Explorer Driver
https://news.sophos.com/en-us/2023/04/19/aukill-edr-killer-malware-abuses-process-explorer-driver/
Papercut Vulnerability Deep Dive
https://www.horizon3.ai/papercut-cve-2023-27350-deep-dive-and-indicators-of-compromise
Solarwinds Patches
https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2023-2_release_notes.htm
Schneider Electric Update
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-101-04&p_enDocType=Security%20and%20Safety%20Notice&p_File_Name=SEVD-2023-101-04.pdf
Virustotal Code Insight
https://blog.virustotal.com/2023/04/introducing-virustotal-code-insight.html
Management of DMARC control for email impersonation fo domains in the .co TLD
https://isc.sans.edu/forums/diary/Management+of+DMARC+control+for+email+impersonation+of+domains+in+the+co+TLD+part+1/29768/
X_Trader Supply Chain Attack Fallout
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain
Car Hacking with Old Nokia Phones
https://www.vice.com/en/article/v7beyj/car-thieves-tech-hidden-old-nokia-phones-bluetooth-speakers-emergency-engine-start-keyless
Dog Hunt Finding Decoy Dog Toolkit
https://blogs.infoblox.com/cyber-threat-intelligence/cyber-threat-advisory/dog-hunt-finding-decoy-dog-toolkit-via-anomalous-dns-traffic/
Management of DMARC control for email impersonation fo domains in the .co TLD
https://isc.sans.edu/forums/diary/Management+of+DMARC+control+for+email+impersonation+of+domains+in+the+co+TLD+part+1/29768/
X_Trader Supply Chain Attack Fallout
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain
Car Hacking with Old Nokia Phones
https://www.vice.com/en/article/v7beyj/car-thieves-tech-hidden-old-nokia-phones-bluetooth-speakers-emergency-engine-start-keyless
Dog Hunt Finding Decoy Dog Toolkit
https://blogs.infoblox.com/cyber-threat-intelligence/cyber-threat-advisory/dog-hunt-finding-decoy-dog-toolkit-via-anomalous-dns-traffic/
Taking a Bite Out of Password Expiry Helpdesk Calls
https://isc.sans.edu/diary/Taking%20a%20Bite%20Out%20of%20Password%20Expiry%20Helpdesk%20Calls/29758
3CX Software Supply Chain Compromise
https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise
Google Ghost Tokens
https://astrix.security/ghosttoken-exploiting-gcp-application-infrastructure-to-create-invisible-unremovable-trojan-app-on-google-accounts/
PyPi Trusted Publishers
https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/
Taking a Bite Out of Password Expiry Helpdesk Calls
https://isc.sans.edu/diary/Taking%20a%20Bite%20Out%20of%20Password%20Expiry%20Helpdesk%20Calls/29758
3CX Software Supply Chain Compromise
https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise
Google Ghost Tokens
https://astrix.security/ghosttoken-exploiting-gcp-application-infrastructure-to-create-invisible-unremovable-trojan-app-on-google-accounts/
PyPi Trusted Publishers
https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/
Yet Another Google Chrome 0-Day
https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html
Oracle Critical Patch Update April 2023
https://www.oracle.com/security-alerts/cpuapr2023.html
Github Provenance Action for npm Packages
https://www.theregister.com/2023/04/19/github_actions_npm_origins/
Microsoft Revises Threat Actor Naming
https://learn.microsoft.com/de-de/microsoft-365/security/intelligence/microsoft-threat-actor-naming
Yet Another Google Chrome 0-Day
https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html
Oracle Critical Patch Update April 2023
https://www.oracle.com/security-alerts/cpuapr2023.html
Github Provenance Action for npm Packages
https://www.theregister.com/2023/04/19/github_actions_npm_origins/
Microsoft Revises Threat Actor Naming
https://learn.microsoft.com/de-de/microsoft-365/security/intelligence/microsoft-threat-actor-naming
UDDIs Are Back: Attackers Rediscovering Old Exploits.
https://isc.sans.edu/diary/UDDIs%20are%20back%3F%20Attackers%20rediscovering%20old%20exploits./29754UDDIExplorer;
UDDIExplorer;
Russian Attacks against Routers
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108
Information Leakage on Discarded Routers
https://www.welivesecurity.com/2023/04/18/discarded-not-destroyed-old-routers-reveal-corporate-secrets/
UDDIs Are Back: Attackers Rediscovering Old Exploits.
https://isc.sans.edu/diary/UDDIs%20are%20back%3F%20Attackers%20rediscovering%20old%20exploits./29754UDDIExplorer;
UDDIExplorer;
Russian Attacks against Routers
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-108
Information Leakage on Discarded Routers
https://www.welivesecurity.com/2023/04/18/discarded-not-destroyed-old-routers-reveal-corporate-secrets/
The strange case of the Great Honeypot of China
https://isc.sans.edu/diary/The%20strange%20case%20of%20Great%20honeypot%20of%20China/29750
The LockBit ransomware (kinda) comes for macOS
https://objective-see.org/blog/blog_0x75.html
Google Cloud Used as C&C
https://thehackernews.com/2023/04/google-uncovers-apt41s-use-of-open.html
The strange case of the Great Honeypot of China
https://isc.sans.edu/diary/The%20strange%20case%20of%20Great%20honeypot%20of%20China/29750
The LockBit ransomware (kinda) comes for macOS
https://objective-see.org/blog/blog_0x75.html
Google Cloud Used as C&C
https://thehackernews.com/2023/04/google-uncovers-apt41s-use-of-open.html
Attack Campaing Tht Uses Fake Google Chrome Errors
https://insight-jp.nttsecurity.com/post/102icvb/attack-campaign-that-uses-fake-google-chrome-error-to-distribute-malware-from-com
Chromium Publishes Emergency Update
https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html
LAPS Update Errors
https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview
Manage Engine Vulnerability
https://hnd3884.github.io/posts/CVE-2023-29084-Command-injection-in-ManageEngine-ADManager-plus/
Attack Campaing Tht Uses Fake Google Chrome Errors
https://insight-jp.nttsecurity.com/post/102icvb/attack-campaign-that-uses-fake-google-chrome-error-to-distribute-malware-from-com
Chromium Publishes Emergency Update
https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html
LAPS Update Errors
https://learn.microsoft.com/en-us/windows-server/identity/laps/laps-overview
Manage Engine Vulnerability
https://hnd3884.github.io/posts/CVE-2023-29084-Command-injection-in-ManageEngine-ADManager-plus/
HTTP: What's Left of it and the OCSP Problem
https://isc.sans.edu/diary/HTTP%3A%20What%27s%20Left%20of%20it%20and%20the%20OCSP%20Problem/29744
NTP Vulnerability Update
https://github.com/spwpun/ntp-4.2.8p15-cves/issues/1#issuecomment-1506667321
SecurePoint UTM Vulnerability CVE-2023-22897
https://www.rcesecurity.com/2023/04/securepwn-part-1-bypassing-securepoint-utms-authentication-cve-2023-22620/
https://www.rcesecurity.com/2023/04/securepwn-part-2-leaking-remote-memory-contents-cve-2023-22897/
Google Cloud Assured Open Source Software Services
https://cloud.google.com/blog/products/identity-security/google-cloud-assured-open-source-software-service-now-ga
HTTP: What's Left of it and the OCSP Problem
https://isc.sans.edu/diary/HTTP%3A%20What%27s%20Left%20of%20it%20and%20the%20OCSP%20Problem/29744
NTP Vulnerability Update
https://github.com/spwpun/ntp-4.2.8p15-cves/issues/1#issuecomment-1506667321
SecurePoint UTM Vulnerability CVE-2023-22897
https://www.rcesecurity.com/2023/04/securepwn-part-1-bypassing-securepoint-utms-authentication-cve-2023-22620/
https://www.rcesecurity.com/2023/04/securepwn-part-2-leaking-remote-memory-contents-cve-2023-22897/
Google Cloud Assured Open Source Software Services
https://cloud.google.com/blog/products/identity-security/google-cloud-assured-open-source-software-service-now-ga
Recent IcedID (Bokbot) activity
https://isc.sans.edu/forums/diary/Recent%20IcedID%20%28Bokbot%29%20activity/29740/
Microsoft Message Queue Vulnerabilities Details
https://research.checkpoint.com/2023/queuejumper-critical-unauthorized-rce-vulnerability-in-msmq-service/
NTP Vulnerabilities
https://github.com/spwpun/ntp-4.2.8p15-cves
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0938
Recent IcedID (Bokbot) activity
https://isc.sans.edu/forums/diary/Recent%20IcedID%20%28Bokbot%29%20activity/29740/
Microsoft Message Queue Vulnerabilities Details
https://research.checkpoint.com/2023/queuejumper-critical-unauthorized-rce-vulnerability-in-msmq-service/
NTP Vulnerabilities
https://github.com/spwpun/ntp-4.2.8p15-cves
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2023-0938
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20April%202023%20Patch%20Tuesday/29736
Windows LAPS Available as part of Windows
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/by-popular-demand-windows-laps-available-now/ba-p/3788747
SAP Patches
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20April%202023%20Patch%20Tuesday/29736
Windows LAPS Available as part of Windows
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/by-popular-demand-windows-laps-available-now/ba-p/3788747
SAP Patches
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Another Malicious HTA File Analysis - Part 2
https://isc.sans.edu/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%202/29676
Apple Updates for Older Operating Systems
https://support.apple.com/en-us/HT201222
MSI Attack May Affect BIOS Updates
https://www.msi.com/news/detail/MSI-Statement-141688
KB5021130: How to manage the Netlogon protocol changes related to CVE-2022-38023
https://support.microsoft.com/en-us/topic/kb5021130-how-to-manage-the-netlogon-protocol-changes-related-to-cve-2022-38023-46ea3067-3989-4d40-963c-680fd9e8ee25
Another Malicious HTA File Analysis - Part 2
https://isc.sans.edu/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%202/29676
Apple Updates for Older Operating Systems
https://support.apple.com/en-us/HT201222
MSI Attack May Affect BIOS Updates
https://www.msi.com/news/detail/MSI-Statement-141688
KB5021130: How to manage the Netlogon protocol changes related to CVE-2022-38023
https://support.microsoft.com/en-us/topic/kb5021130-how-to-manage-the-netlogon-protocol-changes-related-to-cve-2022-38023-46ea3067-3989-4d40-963c-680fd9e8ee25
Detecting Suspicious API Usage with YARA Rules
https://isc.sans.edu/diary/Detecting%20Suspicious%20API%20Usage%20with%20YARA%20Rules/29724
Apple Patching Two 0-Day Vulnerabilities in iOS and macOS
https://isc.sans.edu/diary/Apple%20Patching%20Two%200-Day%20Vulnerabilities%20in%20iOS%20and%20macOS/29726
VM2 Sandbox Escape
https://github.com/patriksimek/vm2/security/advisories/GHSA-7jxr-cg7f-gpgv
https://gist.github.com/seongil-wi/2a44e082001b959bfe304b62121fb76d
Microsoft Netlogon: Potential Upcoming Impacts of CVE-2022-38023
https://isc.sans.edu/diary/Microsoft%20Netlogon%3A%20Potential%20Upcoming%20Impacts%20of%20CVE-2022-38023/29728
Detecting Suspicious API Usage with YARA Rules
https://isc.sans.edu/diary/Detecting%20Suspicious%20API%20Usage%20with%20YARA%20Rules/29724
Apple Patching Two 0-Day Vulnerabilities in iOS and macOS
https://isc.sans.edu/diary/Apple%20Patching%20Two%200-Day%20Vulnerabilities%20in%20iOS%20and%20macOS/29726
VM2 Sandbox Escape
https://github.com/patriksimek/vm2/security/advisories/GHSA-7jxr-cg7f-gpgv
https://gist.github.com/seongil-wi/2a44e082001b959bfe304b62121fb76d
Microsoft Netlogon: Potential Upcoming Impacts of CVE-2022-38023
https://isc.sans.edu/diary/Microsoft%20Netlogon%3A%20Potential%20Upcoming%20Impacts%20of%20CVE-2022-38023/29728
Self Extracting Archives
https://www.crowdstrike.com/blog/self-extracting-archives-decoy-files-and-their-hidden-payloads/
loldrivers
https://www.loldrivers.io
Trellix Privilege Escalation
https://kcm.trellix.com/corporate/index?page=content&id=SB10396
HP LaserJet Vuln.
https://support.hp.com/us-en/document/ish_7905330-7905358-16/hpsbpi03838
Self Extracting Archives
https://www.crowdstrike.com/blog/self-extracting-archives-decoy-files-and-their-hidden-payloads/
loldrivers
https://www.loldrivers.io
Trellix Privilege Escalation
https://kcm.trellix.com/corporate/index?page=content&id=SB10396
HP LaserJet Vuln.
https://support.hp.com/us-en/document/ish_7905330-7905358-16/hpsbpi03838
Exploration of DShield Cowrie Data with jq
https://isc.sans.edu/diary/Exploration%20of%20DShield%20Cowrie%20Data%20with%20jq/29714
NEXX Garage Door Vulnerability
https://medium.com/@samsabetan/the-uninvited-guest-idors-garage-doors-and-stolen-secrets-e4b49e02dadc
OneNote Changes
https://learn.microsoft.com/en-us/deployoffice/security/onenote-extension-block
MSFT Changes to Auto-Update
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3060
NPM Spam DDoS Attacks
https://www.helpnetsecurity.com/2023/04/05/flood-of-malicious-packages-results-in-npm-registry-dos/
Exploration of DShield Cowrie Data with jq
https://isc.sans.edu/diary/Exploration%20of%20DShield%20Cowrie%20Data%20with%20jq/29714
NEXX Garage Door Vulnerability
https://medium.com/@samsabetan/the-uninvited-guest-idors-garage-doors-and-stolen-secrets-e4b49e02dadc
OneNote Changes
https://learn.microsoft.com/en-us/deployoffice/security/onenote-extension-block
MSFT Changes to Auto-Update
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3060
NPM Spam DDoS Attacks
https://www.helpnetsecurity.com/2023/04/05/flood-of-malicious-packages-results-in-npm-registry-dos/
Analyzing the efile.com Malware
https://isc.sans.edu/diary/Analyzing+the+efilecom+Malware+efail/29712
ALPHV Ransomware Targets Backup Installations
https://www.mandiant.com/resources/blog/alphv-ransomware-backup
Sophos Web Appliance Vulnerability (and EoL)
https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce
Zimbra Exploited in Targeted Attacks
https://www.proofpoint.com/us/blog/threat-insight/exploitation-dish-best-served-cold-winter-vivern-uses-known-zimbra-vulnerability
Analyzing the efile.com Malware
https://isc.sans.edu/diary/Analyzing+the+efilecom+Malware+efail/29712
ALPHV Ransomware Targets Backup Installations
https://www.mandiant.com/resources/blog/alphv-ransomware-backup
Sophos Web Appliance Vulnerability (and EoL)
https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce
Zimbra Exploited in Targeted Attacks
https://www.proofpoint.com/us/blog/threat-insight/exploitation-dish-best-served-cold-winter-vivern-uses-known-zimbra-vulnerability
efile.com compromise
https://isc.sans.edu/forums/diary/Supply%20Chain%20Compromise%20or%20False%20Positive%3A%20The%20Intriguing%20Case%20of%20efile.com%20%5Bupdated%20-%20confirmed%20malicious%20code%5D/29708/
Western Digital MyCloud Breach
https://www.bleepingcomputer.com/news/security/western-digital-discloses-network-breach-my-cloud-service-down/
3CX Compromise Affected Cryptocoin Exchanges
https://securelist.com/gopuram-backdoor-deployed-through-3cx-supply-chain-attack/109344/
efile.com compromise
https://isc.sans.edu/forums/diary/Supply%20Chain%20Compromise%20or%20False%20Positive%3A%20The%20Intriguing%20Case%20of%20efile.com%20%5Bupdated%20-%20confirmed%20malicious%20code%5D/29708/
Western Digital MyCloud Breach
https://www.bleepingcomputer.com/news/security/western-digital-discloses-network-breach-my-cloud-service-down/
3CX Compromise Affected Cryptocoin Exchanges
https://securelist.com/gopuram-backdoor-deployed-through-3cx-supply-chain-attack/109344/
Use of X-Frame-Options and CSP frame-ancestors security headers
https://isc.sans.edu/diary/Use%20of%20X-Frame-Options%20and%20CSP%20frame-ancestors%20security%20headers%20on%201%20million%20most%20popular%20domains/29698
oledump supporting MSI Files
https://isc.sans.edu/diary/Update+oledump+MSI+Files/29700/
3CX Update
https://www.3cx.com/blog/news/chrome-blocks-latest-msi/
PinDuoDuo App shows anomalous behaviour
https://edition.cnn.com/2023/04/02/tech/china-pinduoduo-malware-cybersecurity-analysis-intl-hnk/index.html
Use of X-Frame-Options and CSP frame-ancestors security headers
https://isc.sans.edu/diary/Use%20of%20X-Frame-Options%20and%20CSP%20frame-ancestors%20security%20headers%20on%201%20million%20most%20popular%20domains/29698
oledump supporting MSI Files
https://isc.sans.edu/diary/Update+oledump+MSI+Files/29700/
3CX Update
https://www.3cx.com/blog/news/chrome-blocks-latest-msi/
PinDuoDuo App shows anomalous behaviour
https://edition.cnn.com/2023/04/02/tech/china-pinduoduo-malware-cybersecurity-analysis-intl-hnk/index.html
Malicious 3CX Dekstop App Update
Lifestream (Friday March 31st 1400 ET, 1800 UTC) https://www.youtube.com/watch?v=cCf3Km_j5bY
3CX Update: https://www.3cx.com/blog/news/desktopapp-security-alert/
SentinelOne: https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
Objective-See Blog Post: https://objective-see.org/blog/blog_0x73.html
Crowdstrike: https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/
Bypassing PowerShell Strong Obfuscation
https://isc.sans.edu/diary/Bypassing%20PowerShell%20Strong%20Obfuscation/29692
Malicious 3CX Dekstop App Update
Lifestream (Friday March 31st 1400 ET, 1800 UTC) https://www.youtube.com/watch?v=cCf3Km_j5bY
3CX Update: https://www.3cx.com/blog/news/desktopapp-security-alert/
SentinelOne: https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
Objective-See Blog Post: https://objective-see.org/blog/blog_0x73.html
Crowdstrike: https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/
Bypassing PowerShell Strong Obfuscation
https://isc.sans.edu/diary/Bypassing%20PowerShell%20Strong%20Obfuscation/29692
Extracting Multiple Streams From OLE Files
https://isc.sans.edu/diary/Extracting%20Multiple%20Streams%20From%20OLE%20Files/29688
3CXDesktop App Compromise
https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/
Microsoft Defender False Positives
https://twitter.com/MSFT365Status/status/1641048649525260289
https://admin.microsoft.com/Adminportal/Home?ref=/servicehealth/:/alerts/DZ534539 (requires login)
Active Exploitation of IBM Aspera Faspex CVE-2022-47986
https://www.rapid7.com/blog/post/2023/03/28/etr-active-exploitation-of-ibm-aspera-faspex-cve-2022-47986/
QNAP Patch for sudo vulnerablity
https://www.qnap.com/en/security-advisory/qsa-23-11
Extracting Multiple Streams From OLE Files
https://isc.sans.edu/diary/Extracting%20Multiple%20Streams%20From%20OLE%20Files/29688
3CXDesktop App Compromise
https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/
Microsoft Defender False Positives
https://twitter.com/MSFT365Status/status/1641048649525260289
https://admin.microsoft.com/Adminportal/Home?ref=/servicehealth/:/alerts/DZ534539 (requires login)
Active Exploitation of IBM Aspera Faspex CVE-2022-47986
https://www.rapid7.com/blog/post/2023/03/28/etr-active-exploitation-of-ibm-aspera-faspex-cve-2022-47986/
QNAP Patch for sudo vulnerablity
https://www.qnap.com/en/security-advisory/qsa-23-11
Network Data Collector Placement Makes a Difference
https://isc.sans.edu/diary/Network%20Data%20Collector%20Placement%20Makes%20a%20Difference/29664
Throttling and Blocking Email from Persistently Vulnerable Exchange Servers to Exchange Online
https://techcommunity.microsoft.com/t5/exchange-team-blog/throttling-and-blocking-email-from-persistently-vulnerable/ba-p/3762078
Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
https://papers.mathyvanhoef.com/usenix2023-wifi.pdf
Network Data Collector Placement Makes a Difference
https://isc.sans.edu/diary/Network%20Data%20Collector%20Placement%20Makes%20a%20Difference/29664
Throttling and Blocking Email from Persistently Vulnerable Exchange Servers to Exchange Online
https://techcommunity.microsoft.com/t5/exchange-team-blog/throttling-and-blocking-email-from-persistently-vulnerable/ba-p/3762078
Bypassing Wi-Fi Encryption by Manipulating Transmit Queues
https://papers.mathyvanhoef.com/usenix2023-wifi.pdf
Another Malicious HTA File Analysis Part 1
https://isc.sans.edu/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%201/29674
Apple Updates Everything
https://isc.sans.edu/diary/Apple%20Updates%20Everything%20%28including%20Studio%20Display%29/29682
MacStealer Malware Exfiltrates Mac Secrets
https://www.uptycs.com/blog/macstealer-command-and-control-c2-malware
Another Malicious HTA File Analysis Part 1
https://isc.sans.edu/diary/Another%20Malicious%20HTA%20File%20Analysis%20-%20Part%201/29674
Apple Updates Everything
https://isc.sans.edu/diary/Apple%20Updates%20Everything%20%28including%20Studio%20Display%29/29682
MacStealer Malware Exfiltrates Mac Secrets
https://www.uptycs.com/blog/macstealer-command-and-control-c2-malware
Update for Windows Snipping Tool
https://isc.sans.edu/diary/Microsoft%20Released%20an%20Update%20for%20Windows%20Snipping%20Tool%20Vulnerability/29670
GitHub Rotates SSH Keys
https://github.blog/2023-03-23-we-updated-our-rsa-ssh-host-key/
redis-py vulnerability leads to mixed up sessions, affects ChatGPT
https://openai.com/blog/march-20-chatgpt-outage
Linux Tech Tips YouTube Hack
https://www.theverge.com/2023/3/23/23653115/linus-tech-tips-youtube-hack-crypto-scam
https://isc.sans.edu/diary/Elon%20Musk%20Themed%20Crypto%20Scams%20Flooding%20YouTube%20Today/29434
CyberChef Update
https://github.com/gchq/CyberChef/wiki/Character-encoding,-EOL-separators,-and-editor-features
Update for Windows Snipping Tool
https://isc.sans.edu/diary/Microsoft%20Released%20an%20Update%20for%20Windows%20Snipping%20Tool%20Vulnerability/29670
GitHub Rotates SSH Keys
https://github.blog/2023-03-23-we-updated-our-rsa-ssh-host-key/
redis-py vulnerability leads to mixed up sessions, affects ChatGPT
https://openai.com/blog/march-20-chatgpt-outage
Linux Tech Tips YouTube Hack
https://www.theverge.com/2023/3/23/23653115/linus-tech-tips-youtube-hack-crypto-scam
https://isc.sans.edu/diary/Elon%20Musk%20Themed%20Crypto%20Scams%20Flooding%20YouTube%20Today/29434
CyberChef Update
https://github.com/gchq/CyberChef/wiki/Character-encoding,-EOL-separators,-and-editor-features
Cropping and Redacting Images Safely
https://isc.sans.edu/diary/Cropping%20and%20Redacting%20Images%20Safely/29666
Untitled Goose Tool
https://github.com/cisagov/untitledgoosetool
Veeam Vulnerability Details
https://www.horizon3.ai/veeam-backup-and-replication-cve-2023-27532-deep-dive/
Unicode Support in Python used to Evade Detection
https://blog.phylum.io/malicious-actors-use-unicode-support-in-python-to-evade-detection
Cropping and Redacting Images Safely
https://isc.sans.edu/diary/Cropping%20and%20Redacting%20Images%20Safely/29666
Untitled Goose Tool
https://github.com/cisagov/untitledgoosetool
Veeam Vulnerability Details
https://www.horizon3.ai/veeam-backup-and-replication-cve-2023-27532-deep-dive/
Unicode Support in Python used to Evade Detection
https://blog.phylum.io/malicious-actors-use-unicode-support-in-python-to-evade-detection
Windows Snipping Tool Privacy Bug: Inspecting PNG Files
https://isc.sans.edu/diary/Windows%2011%20Snipping%20Tool%20Privacy%20Bug%3A%20Inspecting%20PNG%20Files/29660
Acropalypse Detection and Sanitization Tools
https://github.com/infobyte/CVE-2023-21036
WooCommerce Skimmer Reveals Tampered Gateway Plugin
https://blog.sucuri.net/2023/03/woocommerce-skimmer-reveals-tampered-gateway-plugin.html
Netgear Orbi Router Vulnerable
https://blog.talosintelligence.com/vulnerability-spotlight-netgear-orbi-router-vulnerable-to-arbitrary-command-execution/
Windows Snipping Tool Privacy Bug: Inspecting PNG Files
https://isc.sans.edu/diary/Windows%2011%20Snipping%20Tool%20Privacy%20Bug%3A%20Inspecting%20PNG%20Files/29660
Acropalypse Detection and Sanitization Tools
https://github.com/infobyte/CVE-2023-21036
WooCommerce Skimmer Reveals Tampered Gateway Plugin
https://blog.sucuri.net/2023/03/woocommerce-skimmer-reveals-tampered-gateway-plugin.html
Netgear Orbi Router Vulnerable
https://blog.talosintelligence.com/vulnerability-spotlight-netgear-orbi-router-vulnerable-to-arbitrary-command-execution/
String Obfuscation: Character Pair Reversal
https://isc.sans.edu/diary/String%20Obfuscation%3A%20Character%20Pair%20Reversal/29654
Windows 11 Snipping Tool Privacy Bug
https://www.bleepingcomputer.com/news/microsoft/windows-11-snipping-tool-privacy-bug-exposes-cropped-image-content/
Malicious .Net Packages
https://jfrog.com/blog/attackers-are-starting-to-target-net-developers-with-malicious-code-nuget-packages/
Spring Framework Vulnerability
https://spring.io/blog/2023/03/20/spring-framework-6-0-7-and-5-3-26-fix-cve-2023-20860-and-cve-2023-20861
Snappy Vulnerability
https://github.com/KnpLabs/snappy/security/advisories/GHSA-gq6w-q6wh-jggc
String Obfuscation: Character Pair Reversal
https://isc.sans.edu/diary/String%20Obfuscation%3A%20Character%20Pair%20Reversal/29654
Windows 11 Snipping Tool Privacy Bug
https://www.bleepingcomputer.com/news/microsoft/windows-11-snipping-tool-privacy-bug-exposes-cropped-image-content/
Malicious .Net Packages
https://jfrog.com/blog/attackers-are-starting-to-target-net-developers-with-malicious-code-nuget-packages/
Spring Framework Vulnerability
https://spring.io/blog/2023/03/20/spring-framework-6-0-7-and-5-3-26-fix-cve-2023-20860-and-cve-2023-20861
Snappy Vulnerability
https://github.com/KnpLabs/snappy/security/advisories/GHSA-gq6w-q6wh-jggc
From Phishing Kit to Telegram ... or Not
https://isc.sans.edu/diary/From%20Phishing%20Kit%20To%20Telegram...%20or%20Not!/29650
Emotet uses OneNote
https://cofense.com/blog/emotet-sending-malicious-emails-after-three-month-hiatus/
WSUS Update
https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/plan/plan-your-wsus-deployment#uup-considerations
DOTRUNPEX .Net Injector
https://research.checkpoint.com/2023/dotrunpex-demystifying-new-virtualized-net-injector-used-in-the-wild/
From Phishing Kit to Telegram ... or Not
https://isc.sans.edu/diary/From%20Phishing%20Kit%20To%20Telegram...%20or%20Not!/29650
Emotet uses OneNote
https://cofense.com/blog/emotet-sending-malicious-emails-after-three-month-hiatus/
WSUS Update
https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/plan/plan-your-wsus-deployment#uup-considerations
DOTRUNPEX .Net Injector
https://research.checkpoint.com/2023/dotrunpex-demystifying-new-virtualized-net-injector-used-in-the-wild/
Old Backdoor, New Obfuscation
https://isc.sans.edu/diary/Old%20Backdoor%2C%20New%20Obfuscation/29646
Samsung Exynos Chip Vulnerability
https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html
Android Image Cropping Problem
https://twitter.com/ItsSimonTime/status/1636857478263750656/photo/1
https://acropalypse.app/
Bitwarden Pins
https://ambiso.github.io/bitwarden-pin/
Old Backdoor, New Obfuscation
https://isc.sans.edu/diary/Old%20Backdoor%2C%20New%20Obfuscation/29646
Samsung Exynos Chip Vulnerability
https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html
Android Image Cropping Problem
https://twitter.com/ItsSimonTime/status/1636857478263750656/photo/1
https://acropalypse.app/
Bitwarden Pins
https://ambiso.github.io/bitwarden-pin/
Simple Shellcode Dissection
https://isc.sans.edu/diary/Simple%20Shellcode%20Dissection/29642
Threat Actors Exploit Progress Telerik Vulnerablity
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-074a
Abusing Adobe Acrobat Sign to Distribute Malware
https://blog.avast.com/adobe-acrobat-sign-malware
Zoom Patches
https://explore.zoom.us/en/trust/security/security-bulletin/
Array Networks Advisory
https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf
Aruba Patches
https://www.arubanetworks.com/support-services/security-bulletins/
Simple Shellcode Dissection
https://isc.sans.edu/diary/Simple%20Shellcode%20Dissection/29642
Threat Actors Exploit Progress Telerik Vulnerablity
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-074a
Abusing Adobe Acrobat Sign to Distribute Malware
https://blog.avast.com/adobe-acrobat-sign-malware
Zoom Patches
https://explore.zoom.us/en/trust/security/security-bulletin/
Array Networks Advisory
https://support.arraynetworks.net/prx/001/http/supportportal.arraynetworks.net/documentation/FieldNotice/Array_Networks_Security_Advisory_for_Remote_Code_Execution_Vulnerability_AG.pdf
Aruba Patches
https://www.arubanetworks.com/support-services/security-bulletins/
IPFS Phishing and the need for correctly set HTTP security headers
https://isc.sans.edu/diary/IPFS%20phishing%20and%20the%20need%20for%20correctly%20set%20HTTP%20security%20headers/29638
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/
CVE-2023-23415 ICMP RCE
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23415
Chromium Certificate Proposals
https://www.chromium.org/Home/chromium-security/root-ca-policy/moving-forward-together/
IPFS Phishing and the need for correctly set HTTP security headers
https://isc.sans.edu/diary/IPFS%20phishing%20and%20the%20need%20for%20correctly%20set%20HTTP%20security%20headers/29638
Exploiting CVE-2023-23397: Microsoft Outlook Elevation of Privilege Vulnerability
https://www.mdsec.co.uk/2023/03/exploiting-cve-2023-23397-microsoft-outlook-elevation-of-privilege-vulnerability/
CVE-2023-23415 ICMP RCE
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23415
Chromium Certificate Proposals
https://www.chromium.org/Home/chromium-security/root-ca-policy/moving-forward-together/
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20March%202023%20Patch%20Tuesday/29634
Adobe Cold Fusion and Magento (Adobe Commerce) patches
https://helpx.adobe.com/security/products/magento/apsb23-17.html
https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html
SAP Patches
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Firefox Patches
https://www.mozilla.org/en-US/security/advisories/mfsa2023-09/
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20March%202023%20Patch%20Tuesday/29634
Adobe Cold Fusion and Magento (Adobe Commerce) patches
https://helpx.adobe.com/security/products/magento/apsb23-17.html
https://helpx.adobe.com/security/products/coldfusion/apsb23-25.html
SAP Patches
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Firefox Patches
https://www.mozilla.org/en-US/security/advisories/mfsa2023-09/
SVB Scams and New Domain Registrations
https://isc.sans.edu/diary/Incoming%20Silicon%20Valley%20Bank%20Related%20Scams/29630
CISA Adds Older PLEX and VMWare Vulnerablities to Known-Exploited List
https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-plex-bug-after-lastpass-breach/
FortiOS Vulnerability Exploited
https://www.fortiguard.com/psirt/FG-IR-22-369
SVB Scams and New Domain Registrations
https://isc.sans.edu/diary/Incoming%20Silicon%20Valley%20Bank%20Related%20Scams/29630
CISA Adds Older PLEX and VMWare Vulnerablities to Known-Exploited List
https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-plex-bug-after-lastpass-breach/
FortiOS Vulnerability Exploited
https://www.fortiguard.com/psirt/FG-IR-22-369
AsynRAT Trojan - Bill Payment (Pago de la factura)
https://isc.sans.edu/diary/AsynRAT+Trojan+Bill+Payment+Pago+de+la+factura/29626
Mirai Payload Generator
https://isc.sans.edu/diary/Overview%20of%20a%20Mirai%20Payload%20Generator/29624
Multi-Technology Script Leading to Browser Hijacking
https://isc.sans.edu/diary/Multi-Technology%20Script%20Leading%20to%20Browser%20Hijacking/29620
OneNote will warn users of embeded content
https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=OneNote%2CIn%20development&searchterms=122277
Google Removing Chrome Cleanup Tool
https://security.googleblog.com/2023/03/thank-you-and-goodbye-to-chrome-cleanup.html
AsynRAT Trojan - Bill Payment (Pago de la factura)
https://isc.sans.edu/diary/AsynRAT+Trojan+Bill+Payment+Pago+de+la+factura/29626
Mirai Payload Generator
https://isc.sans.edu/diary/Overview%20of%20a%20Mirai%20Payload%20Generator/29624
Multi-Technology Script Leading to Browser Hijacking
https://isc.sans.edu/diary/Multi-Technology%20Script%20Leading%20to%20Browser%20Hijacking/29620
OneNote will warn users of embeded content
https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=OneNote%2CIn%20development&searchterms=122277
Google Removing Chrome Cleanup Tool
https://security.googleblog.com/2023/03/thank-you-and-goodbye-to-chrome-cleanup.html
Suspected Chinese Campaign to Persist on SonicWall Devices
https://www.mandiant.com/resources/blog/suspected-chinese-persist-sonicwall
Old Cyber Gang Uses New Crypted - ScrubCrypt
https://www.fortinet.com/blog/threat-research/old-cyber-gang-uses-new-crypter-scrubcrypt
Home Assistant Supervisor Security Vulnerability
https://www.home-assistant.io/blog/2023/03/08/supervisor-security-disclosure/
Fake ChatGPT Chrome Extensions
https://www.helpnetsecurity.com/2023/03/09/fake-chatgpt-extension/
Criminals Steal Crytocurrency through Play-to-Earn Games
https://www.ic3.gov/Media/Y2023/PSA230309
Suspected Chinese Campaign to Persist on SonicWall Devices
https://www.mandiant.com/resources/blog/suspected-chinese-persist-sonicwall
Old Cyber Gang Uses New Crypted - ScrubCrypt
https://www.fortinet.com/blog/threat-research/old-cyber-gang-uses-new-crypter-scrubcrypt
Home Assistant Supervisor Security Vulnerability
https://www.home-assistant.io/blog/2023/03/08/supervisor-security-disclosure/
Fake ChatGPT Chrome Extensions
https://www.helpnetsecurity.com/2023/03/09/fake-chatgpt-extension/
Criminals Steal Crytocurrency through Play-to-Earn Games
https://www.ic3.gov/Media/Y2023/PSA230309
Increase in exploits against Joomla (CVE-2023-23752)
https://isc.sans.edu/diary/Increase%20in%20exploits%20agains%20Joomla%20%28CVE-2023-23752%29/29614
Jenkins RCE Vulnerability
https://blog.aquasec.com/jenkins-server-vulnerabilities
Bitwarden: The Curious Use-Case of Password Pilfering
https://flashpoint.io/blog/bitwarden-password-pilfering/
FortiOS Vulnerabilities
https://www.fortiguard.com/psirt/FG-IR-23-001
Veeam Backup Vulnerabilities
https://www.veeam.com/kb4245
Increase in exploits against Joomla (CVE-2023-23752)
https://isc.sans.edu/diary/Increase%20in%20exploits%20agains%20Joomla%20%28CVE-2023-23752%29/29614
Jenkins RCE Vulnerability
https://blog.aquasec.com/jenkins-server-vulnerabilities
Bitwarden: The Curious Use-Case of Password Pilfering
https://flashpoint.io/blog/bitwarden-password-pilfering/
FortiOS Vulnerabilities
https://www.fortiguard.com/psirt/FG-IR-23-001
Veeam Backup Vulnerabilities
https://www.veeam.com/kb4245
Hackers Love This VSCode Extension: What You Can Do to Stay Safe
https://isc.sans.edu/diary/Hackers%20Love%20This%20VSCode%20Extension%3A%20What%20You%20Can%20Do%20to%20Stay%20Safe/29610
Protecting Android Clipboard Content from Unintended Exposure
https://www.microsoft.com/en-us/security/blog/2023/03/06/protecting-android-clipboard-content-from-unintended-exposure/
SYS01 Stealer Targeting Facebook Accounts
https://blog.morphisec.com/sys01stealer-facebook-info-stealer
Hackers Love This VSCode Extension: What You Can Do to Stay Safe
https://isc.sans.edu/diary/Hackers%20Love%20This%20VSCode%20Extension%3A%20What%20You%20Can%20Do%20to%20Stay%20Safe/29610
Protecting Android Clipboard Content from Unintended Exposure
https://www.microsoft.com/en-us/security/blog/2023/03/06/protecting-android-clipboard-content-from-unintended-exposure/
SYS01 Stealer Targeting Facebook Accounts
https://blog.morphisec.com/sys01stealer-facebook-info-stealer
Scanning s3 Buckets
https://isc.sans.edu/diary/Scanning%20s3%20buckets/29606
HiatusRAT Router Malware
https://blog.lumen.com/new-hiatusrat-router-malware-covertly-spies-on-victims/
SonicWall Vulnerability
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0004
Windows Word RCE Proof-of-Concept
https://twitter.com/jduck/status/1632471544935923712
https://qoop.org/publications/cve-2023-21716-rtf-fonttbl.md
DBatLoader and Remcos RAT
https://www.sentinelone.com/blog/dbatloader-and-remcos-rat-sweep-eastern-europe/
Scanning s3 Buckets
https://isc.sans.edu/diary/Scanning%20s3%20buckets/29606
HiatusRAT Router Malware
https://blog.lumen.com/new-hiatusrat-router-malware-covertly-spies-on-victims/
SonicWall Vulnerability
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0004
Windows Word RCE Proof-of-Concept
https://twitter.com/jduck/status/1632471544935923712
https://qoop.org/publications/cve-2023-21716-rtf-fonttbl.md
DBatLoader and Remcos RAT
https://www.sentinelone.com/blog/dbatloader-and-remcos-rat-sweep-eastern-europe/
SANS.edu Commencement
https://www.linkedin.com/feed/update/urn:li:activity:7037794067266625536/
SCARLETEEL: Operation Leverating Terraform, Kubernetes and AWS for data theft
https://sysdig.com/blog/cloud-breach-terraform-data-theft/
Preventing Malicious OneNote Files
https://www.bleepingcomputer.com/news/security/how-to-prevent-microsoft-onenote-files-from-infecting-windows-with-malware/
Redis Miner Leverages Command Line File Hosting Service
https://www.cadosecurity.com/redis-miner-leverages-command-line-file-hosting-service/
SANS.edu Commencement
https://www.linkedin.com/feed/update/urn:li:activity:7037794067266625536/
SCARLETEEL: Operation Leverating Terraform, Kubernetes and AWS for data theft
https://sysdig.com/blog/cloud-breach-terraform-data-theft/
Preventing Malicious OneNote Files
https://www.bleepingcomputer.com/news/security/how-to-prevent-microsoft-onenote-files-from-infecting-windows-with-malware/
Redis Miner Leverages Command Line File Hosting Service
https://www.cadosecurity.com/redis-miner-leverages-command-line-file-hosting-service/
YARA: Detect the Unexpected
https://isc.sans.edu/diary/YARA%3A%20Detect%20The%20Unexpected%20.../29598
Drone Security and the Mysterious Case of DJI's DroneID
https://github.com/RUB-SysSec/DroneSecurity
Booking.com OAuth Flaw
https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com
SANS.edu Student Marco Gfeller: Lightweight Python-Based Malware Analysis Pipeline
https://www.sans.org/white-papers/lightweight-python-based-malware-analysis-pipeline/
YARA: Detect the Unexpected
https://isc.sans.edu/diary/YARA%3A%20Detect%20The%20Unexpected%20.../29598
Drone Security and the Mysterious Case of DJI's DroneID
https://github.com/RUB-SysSec/DroneSecurity
Booking.com OAuth Flaw
https://salt.security/blog/traveling-with-oauth-account-takeover-on-booking-com
SANS.edu Student Marco Gfeller: Lightweight Python-Based Malware Analysis Pipeline
https://www.sans.org/white-papers/lightweight-python-based-malware-analysis-pipeline/
Python Infostealer Targeting Gamers
https://isc.sans.edu/diary/Python%20Infostealer%20Targeting%20Gamers/29596
DNS Abuse Techniques Matrix
https://www.first.org/global/sigs/dns/DNS-Abuse-Techniques-Matrix_v1.1.pdf
BlackLotus UEFI Bootkit
https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/
TCG TPM2.0 implementations vulnerable to memory corruption
https://kb.cert.org/vuls/id/782720
Aruba Vulnerability
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-002.txt
Cisco VoIP Phone WebUI RCE
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP
Python Infostealer Targeting Gamers
https://isc.sans.edu/diary/Python%20Infostealer%20Targeting%20Gamers/29596
DNS Abuse Techniques Matrix
https://www.first.org/global/sigs/dns/DNS-Abuse-Techniques-Matrix_v1.1.pdf
BlackLotus UEFI Bootkit
https://www.welivesecurity.com/2023/03/01/blacklotus-uefi-bootkit-myth-confirmed/
TCG TPM2.0 implementations vulnerable to memory corruption
https://kb.cert.org/vuls/id/782720
Aruba Vulnerability
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-002.txt
Cisco VoIP Phone WebUI RCE
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ip-phone-cmd-inj-KMFynVcP
BB11 Distribution Qakbot (Qbot) activity
https://isc.sans.edu/diary/BB17%20distribution%20Qakbot%20%28Qbot%29%20activity/29592
LastPass Incident Details
https://support.lastpass.com/help/incident-1-additional-details-of-the-attack
https://support.lastpass.com/help/incident-2-additional-details-of-the-attack
CISA Red Team Shares Key Findings
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-059a
Jailbreak Chat
https://www.jailbreakchat.com
BB11 Distribution Qakbot (Qbot) activity
https://isc.sans.edu/diary/BB17%20distribution%20Qakbot%20%28Qbot%29%20activity/29592
LastPass Incident Details
https://support.lastpass.com/help/incident-1-additional-details-of-the-attack
https://support.lastpass.com/help/incident-2-additional-details-of-the-attack
CISA Red Team Shares Key Findings
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-059a
Jailbreak Chat
https://www.jailbreakchat.com
Phishing Again and Again
https://isc.sans.edu/diary/Phishing%20Again%20and%20Again/29588
Unlocked Phone Stealing
https://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a
More Fake Authenticator Apps
https://nakedsecurity.sophos.com/2023/02/27/beware-rogue-2fa-apps-in-app-store-and-google-play-dont-get-hacked/
Zoneminder Vulnerability
https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-72rg-h4vf-29gr
WebLogic Exploit (not verified) CVE-2023-21839
https://github.com/4ra1n/CVE-2023-21839/blob/master/cmd/main.go
Phishing Again and Again
https://isc.sans.edu/diary/Phishing%20Again%20and%20Again/29588
Unlocked Phone Stealing
https://www.wsj.com/articles/apple-iphone-security-theft-passcode-data-privacya-basic-iphone-feature-helps-criminals-steal-your-digital-life-cbf14b1a
More Fake Authenticator Apps
https://nakedsecurity.sophos.com/2023/02/27/beware-rogue-2fa-apps-in-app-store-and-google-play-dont-get-hacked/
Zoneminder Vulnerability
https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-72rg-h4vf-29gr
WebLogic Exploit (not verified) CVE-2023-21839
https://github.com/4ra1n/CVE-2023-21839/blob/master/cmd/main.go
URL Files and WebDav used for IcedId Bockbot Infection
https://isc.sans.edu/diary/URL%20files%20and%20WebDAV%20used%20for%20IcedID%20%28Bokbot%29%20infection/29578
oledump msi file plugin
https://isc.sans.edu/diary/oledump%20%26%20MSI%20Files/29584
Automatic Disruption of Ransomware and BEC attacks with Microsoft 365 Defender
https://techcommunity.microsoft.com/t5/microsoft-365-defender-blog/automatic-disruption-of-ransomware-and-bec-attacks-with/ba-p/3738294
Cisco Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-csrfv-DMx6KSwV
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-lldp-dos-ySCNZOpX
URL Files and WebDav used for IcedId Bockbot Infection
https://isc.sans.edu/diary/URL%20files%20and%20WebDAV%20used%20for%20IcedID%20%28Bokbot%29%20infection/29578
oledump msi file plugin
https://isc.sans.edu/diary/oledump%20%26%20MSI%20Files/29584
Automatic Disruption of Ransomware and BEC attacks with Microsoft 365 Defender
https://techcommunity.microsoft.com/t5/microsoft-365-defender-blog/automatic-disruption-of-ransomware-and-bec-attacks-with/ba-p/3738294
Cisco Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-capic-csrfv-DMx6KSwV
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-lldp-dos-ySCNZOpX
Updated Exchange AV Guidance
https://techcommunity.microsoft.com/t5/exchange-team-blog/update-on-the-exchange-server-antivirus-exclusions/ba-p/3751464
Best Practices for Securing Your Home Network
https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF
Attacks on Data Center Organizations
https://www.resecurity.com/blog/article/cyber-attacks-on-data-center-organizations
NPM Package Phishing
https://checkmarx.com/blog/how-npm-packages-were-used-to-spread-phishing-links/
Malicious PyPi Packages
https://www.fortinet.com/blog/threat-research/more-supply-chain-attacks-via-new-malicious-python-packages-in-pypi
Updated Exchange AV Guidance
https://techcommunity.microsoft.com/t5/exchange-team-blog/update-on-the-exchange-server-antivirus-exclusions/ba-p/3751464
Best Practices for Securing Your Home Network
https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF
Attacks on Data Center Organizations
https://www.resecurity.com/blog/article/cyber-attacks-on-data-center-organizations
NPM Package Phishing
https://checkmarx.com/blog/how-npm-packages-were-used-to-spread-phishing-links/
Malicious PyPi Packages
https://www.fortinet.com/blog/threat-research/more-supply-chain-attacks-via-new-malicious-python-packages-in-pypi
Internet Wide Scan Fingerprinting Confluence Servers
https://isc.sans.edu/diary/Internet%20Wide%20Scan%20Fingerprinting%20Confluence%20Servers/29574
Apple Updates Advisories
https://support.apple.com/en-us/HT213606
https://support.apple.com/en-us/HT213605
https://www.trellix.com/en-us/about/newsroom/stories/research/trellix-advanced-research-center-discovers-a-new-privilege-escalation-bug-class-on-macos-and-ios.html
Questionable two-factor Apps
https://twitter.com/mysk_co/status/1627097291063435264
VMWare Carbon Black App Control Vulnerability
https://www.vmware.com/security/advisories/VMSA-2023-0004.html
Internet Wide Scan Fingerprinting Confluence Servers
https://isc.sans.edu/diary/Internet%20Wide%20Scan%20Fingerprinting%20Confluence%20Servers/29574
Apple Updates Advisories
https://support.apple.com/en-us/HT213606
https://support.apple.com/en-us/HT213605
https://www.trellix.com/en-us/about/newsroom/stories/research/trellix-advanced-research-center-discovers-a-new-privilege-escalation-bug-class-on-macos-and-ios.html
Questionable two-factor Apps
https://twitter.com/mysk_co/status/1627097291063435264
VMWare Carbon Black App Control Vulnerability
https://www.vmware.com/security/advisories/VMSA-2023-0004.html
Phishing Page Branded with Your Corporate Website
https://isc.sans.edu/diary/Phishing%20Page%20Branded%20with%20Your%20Corporate%20Website/29570
Fortinet FortiNAC CVE-2022-39952 Deep-Dive and IOCs
https://www.horizon3.ai/fortinet-fortinac-cve-2022-39952-deep-dive-and-iocs/
Apache Commons FileUpload Vulnerability
https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy
VMWare Windows Server 2022 Fix
https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-esxi-70u3k-release-notes.html#resolvedissues
Phishing Page Branded with Your Corporate Website
https://isc.sans.edu/diary/Phishing%20Page%20Branded%20with%20Your%20Corporate%20Website/29570
Fortinet FortiNAC CVE-2022-39952 Deep-Dive and IOCs
https://www.horizon3.ai/fortinet-fortinac-cve-2022-39952-deep-dive-and-iocs/
Apache Commons FileUpload Vulnerability
https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy
VMWare Windows Server 2022 Fix
https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vsphere-esxi-70u3k-release-notes.html#resolvedissues
OneNote Suricata Rules
https://isc.sans.edu/diary/OneNote%20Suricata%20Rules/29564
New IIS Backdoor
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/frebniis-malware-iis
Outlook Spam
https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-flooded-with-spam-due-to-broken-email-filters/
Godaddy Breach and Website Redirects
https://aboutus.godaddy.net/newsroom/company-news/news-details/2023/Statement-on-recent-website-redirect-issues/default.aspx
OneNote Suricata Rules
https://isc.sans.edu/diary/OneNote%20Suricata%20Rules/29564
New IIS Backdoor
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/frebniis-malware-iis
Outlook Spam
https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-flooded-with-spam-due-to-broken-email-filters/
Godaddy Breach and Website Redirects
https://aboutus.godaddy.net/newsroom/company-news/news-details/2023/Statement-on-recent-website-redirect-issues/default.aspx
Phishing Emails to out Handlers Inbox
https://isc.sans.edu/diary/Spear%20Phishing%20Handlers%20for%20Username%20Password/29560
Twitter Alters 2FA
https://blog.twitter.com/en_us/topics/product/2023/an-update-on-two-factor-authentication-using-sms-on-twitter
Fortinet Updates
https://www.fortiguard.com/psirt-monthly-advisory/february-2023-vulnerability-advisories
https://twitter.com/Horizon3Attack/status/1626692778062237713
Cisco ClamAV Patches
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-q8DThCy
Phishing Emails to out Handlers Inbox
https://isc.sans.edu/diary/Spear%20Phishing%20Handlers%20for%20Username%20Password/29560
Twitter Alters 2FA
https://blog.twitter.com/en_us/topics/product/2023/an-update-on-two-factor-authentication-using-sms-on-twitter
Fortinet Updates
https://www.fortiguard.com/psirt-monthly-advisory/february-2023-vulnerability-advisories
https://twitter.com/Horizon3Attack/status/1626692778062237713
Cisco ClamAV Patches
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-q8DThCy
HTML Phishing Attachment with Browser-in-the-Browser Technique
https://isc.sans.edu/diary/HTML%20phishing%20attachment%20with%20browser-in-the-browser%20technique/29556
Windows Server 2022 Might Not Start Up After Updates
https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#windows-server-2022-might-not-start-up
New ESXiArgs Encryption Routing Outmaneuvers Recovery Methods
https://www.malwarebytes.com/blog/news/2023/02/new-esxiargs-encryption-routine-outmaneuvers-recovery-methods
PHP Updates
https://www.php.net
ClamAV Patches
https://blog.clamav.net/2023/02/clamav-01038-01052-and-101-patch.html
HTML Phishing Attachment with Browser-in-the-Browser Technique
https://isc.sans.edu/diary/HTML%20phishing%20attachment%20with%20browser-in-the-browser%20technique/29556
Windows Server 2022 Might Not Start Up After Updates
https://learn.microsoft.com/en-us/windows/release-health/status-windows-server-2022#windows-server-2022-might-not-start-up
New ESXiArgs Encryption Routing Outmaneuvers Recovery Methods
https://www.malwarebytes.com/blog/news/2023/02/new-esxiargs-encryption-routine-outmaneuvers-recovery-methods
PHP Updates
https://www.php.net
ClamAV Patches
https://blog.clamav.net/2023/02/clamav-01038-01052-and-101-patch.html
DNS Recon Redux
https://isc.sans.edu/diary/DNS%20Recon%20Redux%20-%20Zone%20Transfers%20%28plus%20a%20time%20machine%29%20for%20When%20You%20Can%27t%20do%20a%20Zone%20Transfer/29552
GitHub Copilot Update
https://github.blog/2023-02-14-github-copilot-now-has-a-better-ai-model-and-new-capabilities/
Hyundai Software Update
https://www.hyundaiantitheft.com
Citrix Patches CVE-2023-24486, CVE-2023-24484, CVE-2023-24485, and CVE-2023-24483
https://www.cisa.gov/uscert/ncas/current-activity/2023/02/14/citrix-releases-security-updates-workspace-apps-virtual-apps-and
HA Proxy Patch CVE-2023-25725
https://www.mail-archive.com/haproxy@formilux.org/msg43229.html
Firefox Patches
https://www.mozilla.org/en-US/security/advisories/mfsa2023-05/
DNS Recon Redux
https://isc.sans.edu/diary/DNS%20Recon%20Redux%20-%20Zone%20Transfers%20%28plus%20a%20time%20machine%29%20for%20When%20You%20Can%27t%20do%20a%20Zone%20Transfer/29552
GitHub Copilot Update
https://github.blog/2023-02-14-github-copilot-now-has-a-better-ai-model-and-new-capabilities/
Hyundai Software Update
https://www.hyundaiantitheft.com
Citrix Patches CVE-2023-24486, CVE-2023-24484, CVE-2023-24485, and CVE-2023-24483
https://www.cisa.gov/uscert/ncas/current-activity/2023/02/14/citrix-releases-security-updates-workspace-apps-virtual-apps-and
HA Proxy Patch CVE-2023-25725
https://www.mail-archive.com/haproxy@formilux.org/msg43229.html
Firefox Patches
https://www.mozilla.org/en-US/security/advisories/mfsa2023-05/
Microsoft February 2023 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20February%202023%20Patch%20Tuesday/29548
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Intel OpenBMC Vulnerabilities
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html
Microsoft February 2023 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20February%202023%20Patch%20Tuesday/29548
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Intel OpenBMC Vulnerabilities
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00737.html
Apple Patches Exploited Vulnerablity
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/29544
Venmo Phishing Abusing LinkedIn "slink"
https://isc.sans.edu/diary/Venmo+Phishing+Abusing+LinkedIn+slink/29542/
Malicious PyPi Packages Install Browser Extensions
https://blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack
Apple Patches Exploited Vulnerablity
https://isc.sans.edu/diary/Apple%20Patches%20Exploited%20Vulnerability/29544
Venmo Phishing Abusing LinkedIn "slink"
https://isc.sans.edu/diary/Venmo+Phishing+Abusing+LinkedIn+slink/29542/
Malicious PyPi Packages Install Browser Extensions
https://blog.phylum.io/phylum-discovers-revived-crypto-wallet-address-replacement-attack
Obfuscated Deactivation of Script Block Logging
https://isc.sans.edu/diary/Obfuscated%20Deactivation%20of%20Script%20Block%20Logging/29538
PCAP Data Analysis with Zeek
https://isc.sans.edu/diary/PCAP%20Data%20Analysis%20with%20Zeek/29530
Bing Chat Prompt Injection
https://arstechnica.com/information-technology/2023/02/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack/
More Malicious Python Packages
https://blog.sonatype.com/malicious-aptx-python-package-drops-meterpreter-shell-deletes-netstat
Obfuscated Deactivation of Script Block Logging
https://isc.sans.edu/diary/Obfuscated%20Deactivation%20of%20Script%20Block%20Logging/29538
PCAP Data Analysis with Zeek
https://isc.sans.edu/diary/PCAP%20Data%20Analysis%20with%20Zeek/29530
Bing Chat Prompt Injection
https://arstechnica.com/information-technology/2023/02/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack/
More Malicious Python Packages
https://blog.sonatype.com/malicious-aptx-python-package-drops-meterpreter-shell-deletes-netstat
A Backdoor with Smart Screenshot Capability
https://isc.sans.edu/diary/A%20Backdoor%20with%20Smart%20Screenshot%20Capability/29534
KeePass Patches Issue Allowing Password Export
https://keepass.info/news/n230109_2.53.html
AWS Phishing via Google Ads
https://www.sentinelone.com/blog/cloud-credentials-phishing-malicious-google-ads-target-aws-logins/
Apache Kafka Vulnerability
https://lists.apache.org/thread/vy1c7fqcdqvq5grcqp6q5jyyb302khyz
A Backdoor with Smart Screenshot Capability
https://isc.sans.edu/diary/A%20Backdoor%20with%20Smart%20Screenshot%20Capability/29534
KeePass Patches Issue Allowing Password Export
https://keepass.info/news/n230109_2.53.html
AWS Phishing via Google Ads
https://www.sentinelone.com/blog/cloud-credentials-phishing-malicious-google-ads-target-aws-logins/
Apache Kafka Vulnerability
https://lists.apache.org/thread/vy1c7fqcdqvq5grcqp6q5jyyb302khyz
Simple HTML Phishing via Telegram Bot
https://isc.sans.edu/forums/diary/Simple%20HTML%20Phishing%20via%20Telegram%20Bot/29528/
Recovering from ESXiArgs Ransomware
https://www.cisa.gov/uscert/ncas/alerts/aa23-039a
NIST Standardizes Lightweight Cryptography
https://csrc.nist.gov/Projects/lightweight-cryptography
Sonicwall Web Content Filtering on Windows 11 22H2
https://www.sonicwall.com/support/product-notification/limitation-with-web-content-filtering-on-windows-11-22h2/230208075107457/
Google Chrome Release Changes
https://developer.chrome.com/blog/early-stable/
Simple HTML Phishing via Telegram Bot
https://isc.sans.edu/forums/diary/Simple%20HTML%20Phishing%20via%20Telegram%20Bot/29528/
Recovering from ESXiArgs Ransomware
https://www.cisa.gov/uscert/ncas/alerts/aa23-039a
NIST Standardizes Lightweight Cryptography
https://csrc.nist.gov/Projects/lightweight-cryptography
Sonicwall Web Content Filtering on Windows 11 22H2
https://www.sonicwall.com/support/product-notification/limitation-with-web-content-filtering-on-windows-11-22h2/230208075107457/
Google Chrome Release Changes
https://developer.chrome.com/blog/early-stable/
A Survey of Bluetooth Vulnerabilities Trends
https://isc.sans.edu/diary/A%20Survey%20of%20Bluetooth%20Vulnerabilities%20Trends%20%282023%20Edition%29/29522
OpenSSL Vulnerabilities / Patches
https://www.openssl.org/news/secadv/20230207.txt
Packet Tuesday: Most Frequent DNS Query ID / DNS Notify
https://www.youtube.com/watch?v=QgCuE_zKyMY
GoAnywhere MFT Patch Available (and PoC)
https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html
https://my.goanywhere.com/webclient/Dashboard.xhtml
Qakbot Mechanizes Distribution of Malicous OneNote Notebooks
https://news.sophos.com/en-us/2023/02/06/qakbot-onenote-attacks/
A Survey of Bluetooth Vulnerabilities Trends
https://isc.sans.edu/diary/A%20Survey%20of%20Bluetooth%20Vulnerabilities%20Trends%20%282023%20Edition%29/29522
OpenSSL Vulnerabilities / Patches
https://www.openssl.org/news/secadv/20230207.txt
Packet Tuesday: Most Frequent DNS Query ID / DNS Notify
https://www.youtube.com/watch?v=QgCuE_zKyMY
GoAnywhere MFT Patch Available (and PoC)
https://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html
https://my.goanywhere.com/webclient/Dashboard.xhtml
Qakbot Mechanizes Distribution of Malicous OneNote Notebooks
https://news.sophos.com/en-us/2023/02/06/qakbot-onenote-attacks/
Earthquake Scams
https://isc.sans.edu/diary/Earthquake%20in%20Turkey%20and%20Syria%3A%20Be%20Aware%20of%20Possible%20Donation%20Scams/29518
APIs Used By Bots to Detect Public IP Addresses
https://isc.sans.edu/diary/APIs+Used+by+Bots+to+Detect+Public+IP+address/29516/
OpenSSH Vulnerablity Details CVE 2023-25136
https://blog.qualys.com/vulnerabilities-threat-research/2023/02/03/cve-2023-25136-pre-auth-double-free-vulnerability-in-openssh-server-9-1
A Novel State-of-the-Art Redis Malware
https://blog.aquasec.com/headcrab-attacks-servers-worldwide-with-novel-state-of-art-redis-malware?&web_view=true
Earthquake Scams
https://isc.sans.edu/diary/Earthquake%20in%20Turkey%20and%20Syria%3A%20Be%20Aware%20of%20Possible%20Donation%20Scams/29518
APIs Used By Bots to Detect Public IP Addresses
https://isc.sans.edu/diary/APIs+Used+by+Bots+to+Detect+Public+IP+address/29516/
OpenSSH Vulnerablity Details CVE 2023-25136
https://blog.qualys.com/vulnerabilities-threat-research/2023/02/03/cve-2023-25136-pre-auth-double-free-vulnerability-in-openssh-server-9-1
A Novel State-of-the-Art Redis Malware
https://blog.aquasec.com/headcrab-attacks-servers-worldwide-with-novel-state-of-art-redis-malware?&web_view=true
Assemblyline as a Malware Analysis Sandbox
https://isc.sans.edu/diary/Assemblyline%20as%20a%20Malware%20Analysis%20Sandbox/29510
GoAnywhere MFT zero-day Exploited
https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/
Ransomware targeting VMware ESXi
https://blog.ovhcloud.com/ransomware-targeting-vmware-esxi/
Jira Service Managment Server and Data Center Advisory CVE-2023-22501
https://confluence.atlassian.com/jira/jira-service-management-server-and-data-center-advisory-cve-2023-22501-1188786458.html
OpenSSH Update
https://www.openssh.com/releasenotes.html
F5 BigIP Vulnerability CVE-2023-22374
https://my.f5.com/manage/s/article/K000130415
Assemblyline as a Malware Analysis Sandbox
https://isc.sans.edu/diary/Assemblyline%20as%20a%20Malware%20Analysis%20Sandbox/29510
GoAnywhere MFT zero-day Exploited
https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/
Ransomware targeting VMware ESXi
https://blog.ovhcloud.com/ransomware-targeting-vmware-esxi/
Jira Service Managment Server and Data Center Advisory CVE-2023-22501
https://confluence.atlassian.com/jira/jira-service-management-server-and-data-center-advisory-cve-2023-22501-1188786458.html
OpenSSH Update
https://www.openssh.com/releasenotes.html
F5 BigIP Vulnerability CVE-2023-22374
https://my.f5.com/manage/s/article/K000130415
Rotating Packet Captures with pfSense
https://isc.sans.edu/diary/Rotating%20Packet%20Captures%20with%20pfSense/29500
BEC Group Incorporates Secondary Impersonated Personas
https://intelligence.abnormalsecurity.com/blog/firebrick-ostrich-third-party-reconnaissance-attacks
MalVirt .Net Virtualization Thrives in Malvertising Attacks
https://www.sentinelone.com/labs/malvirt-net-virtualization-thrives-in-malvertising-attacks/
Cisco Remote Code Execution with Persistence
https://www.trellix.com/en-us/about/newsroom/stories/research/when-pwning-cisco-persistence-is-key-when-pwning-supply-chain-cisco-is-key.html
Rotating Packet Captures with pfSense
https://isc.sans.edu/diary/Rotating%20Packet%20Captures%20with%20pfSense/29500
BEC Group Incorporates Secondary Impersonated Personas
https://intelligence.abnormalsecurity.com/blog/firebrick-ostrich-third-party-reconnaissance-attacks
MalVirt .Net Virtualization Thrives in Malvertising Attacks
https://www.sentinelone.com/labs/malvirt-net-virtualization-thrives-in-malvertising-attacks/
Cisco Remote Code Execution with Persistence
https://www.trellix.com/en-us/about/newsroom/stories/research/when-pwning-cisco-persistence-is-key-when-pwning-supply-chain-cisco-is-key.html
Detecting Malicious OneNote Files
https://isc.sans.edu/diary/Detecting%20%28Malicious%29%20OneNote%20Files/29494
Microsoft Defender Device Isolation for Linux
https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-device-isolation-support-for-linux/ba-p/3676400
SH1MMER Exploit for Chromebooks
https://sh1mmer.me
DOMPDF SVG Parsing Vulnerability
https://github.com/dompdf/dompdf/security/advisories/GHSA-3cw5-7cxw-v5qg
Detecting Malicious OneNote Files
https://isc.sans.edu/diary/Detecting%20%28Malicious%29%20OneNote%20Files/29494
Microsoft Defender Device Isolation for Linux
https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/announcing-device-isolation-support-for-linux/ba-p/3676400
SH1MMER Exploit for Chromebooks
https://sh1mmer.me
DOMPDF SVG Parsing Vulnerability
https://github.com/dompdf/dompdf/security/advisories/GHSA-3cw5-7cxw-v5qg
DShield Honeypot Setup with pfSense
https://isc.sans.edu/diary/DShield%20Honeypot%20Setup%20with%20pfSense/29490
Threat Actors Abusing Microsoft's "Verified Publisher" Status
https://www.proofpoint.com/us/blog/cloud-security/dangerous-consequences-threat-actors-abusing-microsofts-verified-publisher
PoS Malware Can Block Contactless Payments
https://securelist.com/prilex-modification-now-targeting-contactless-credit-card-transactions/108569/
Detecting Files Exempt from Anti Malware Scans
https://github.com/bananabr/TimeException
DShield Honeypot Setup with pfSense
https://isc.sans.edu/diary/DShield%20Honeypot%20Setup%20with%20pfSense/29490
Threat Actors Abusing Microsoft's "Verified Publisher" Status
https://www.proofpoint.com/us/blog/cloud-security/dangerous-consequences-threat-actors-abusing-microsofts-verified-publisher
PoS Malware Can Block Contactless Payments
https://securelist.com/prilex-modification-now-targeting-contactless-credit-card-transactions/108569/
Detecting Files Exempt from Anti Malware Scans
https://github.com/bananabr/TimeException
Decoding DNS over HTTP(s) Requests
https://isc.sans.edu/diary/Decoding%20DNS%20over%20HTTP%28s%29%20Requests/29488
Action Needed for GitHub Desktop and Atom Users
https://github.blog/2023-01-30-action-needed-for-github-desktop-and-atom-users/
GitHub Checksum Mismatches for .tar.gz Files
https://github.com/orgs/community/discussions/45830
Facebook 2FA Bypass
https://medium.com/pentesternepal/two-factor-authentication-bypass-on-facebook-3f4ac3ea139c
Fortinet Exploit
https://wzt.ac.cn/2022/12/15/CVE-2022-42475/
QNAP Vulnerability
https://www.qnap.com/en/security-advisory/qsa-23-01
Decoding DNS over HTTP(s) Requests
https://isc.sans.edu/diary/Decoding%20DNS%20over%20HTTP%28s%29%20Requests/29488
Action Needed for GitHub Desktop and Atom Users
https://github.blog/2023-01-30-action-needed-for-github-desktop-and-atom-users/
GitHub Checksum Mismatches for .tar.gz Files
https://github.com/orgs/community/discussions/45830
Facebook 2FA Bypass
https://medium.com/pentesternepal/two-factor-authentication-bypass-on-facebook-3f4ac3ea139c
Fortinet Exploit
https://wzt.ac.cn/2022/12/15/CVE-2022-42475/
QNAP Vulnerability
https://www.qnap.com/en/security-advisory/qsa-23-01
Microsoft Tips to Patch Your Exchange Servers
https://techcommunity.microsoft.com/t5/exchange-team-blog/protect-your-exchange-servers/ba-p/3726001
FCC Treatens to Take Action Against Twilio over Robocalls
https://www.fcc.gov/document/fcc-takes-mortgage-scam-robocall-campaign-targeting-homeowners
PlugX Variant Spreads via USB
https://unit42.paloaltonetworks.com/plugx-variants-in-usbs/
Adware in Google Play Store
https://news.drweb.com/show/review/?lng=en&i=14652
Tails 5.9 Update
https://tails.boum.org/news/version_5.9/index.de.html
Microsoft Tips to Patch Your Exchange Servers
https://techcommunity.microsoft.com/t5/exchange-team-blog/protect-your-exchange-servers/ba-p/3726001
FCC Treatens to Take Action Against Twilio over Robocalls
https://www.fcc.gov/document/fcc-takes-mortgage-scam-robocall-campaign-targeting-homeowners
PlugX Variant Spreads via USB
https://unit42.paloaltonetworks.com/plugx-variants-in-usbs/
Adware in Google Play Store
https://news.drweb.com/show/review/?lng=en&i=14652
Tails 5.9 Update
https://tails.boum.org/news/version_5.9/index.de.html
Live Linux IR with UAC
https://isc.sans.edu/diary/Live%20Linux%20IR%20with%20UAC/29480
Bitwarden Phishing
https://community.bitwarden.com/t/phishing-website-bitwardenlogin-com/49704
https://www.reddit.com/r/Bitwarden/comments/10k2aj5/google_search_ads_showing_fake_bitwarden_web/
PY#RATION Attack Campaign Leverages Fernet Encyrption and Websockets
https://www.securonix.com/blog/security-advisory-python-based-pyration-attack-campaign/
Skyhigh Security Secure Web Gateway: XSS in Single Sign On Plugin
https://www.redteam-pentesting.de/en/advisories/rt-sa-2022-002/-skyhigh-security-secure-web-gateway-cross-site-scripting-in-single-sign-on-plugin
Windows Crypto API Vuln PoC
https://github.com/akamai/akamai-security-research/tree/main/PoCs/CVE-2022-34689
BIND Patches
https://kb.isc.org/docs/cve-2022-3094
Live Linux IR with UAC
https://isc.sans.edu/diary/Live%20Linux%20IR%20with%20UAC/29480
Bitwarden Phishing
https://community.bitwarden.com/t/phishing-website-bitwardenlogin-com/49704
https://www.reddit.com/r/Bitwarden/comments/10k2aj5/google_search_ads_showing_fake_bitwarden_web/
PY#RATION Attack Campaign Leverages Fernet Encyrption and Websockets
https://www.securonix.com/blog/security-advisory-python-based-pyration-attack-campaign/
Skyhigh Security Secure Web Gateway: XSS in Single Sign On Plugin
https://www.redteam-pentesting.de/en/advisories/rt-sa-2022-002/-skyhigh-security-secure-web-gateway-cross-site-scripting-in-single-sign-on-plugin
Windows Crypto API Vuln PoC
https://github.com/akamai/akamai-security-research/tree/main/PoCs/CVE-2022-34689
BIND Patches
https://kb.isc.org/docs/cve-2022-3094
First Malicious OneNote Document
https://isc.sans.edu/diary/A%20First%20Malicious%20OneNote%20Document/29470
Guidance for Securing Remote Monitoring and Management Software
https://media.defense.gov/2023/Jan/25/2003149873/-1/-1/0/JOINT_CSA_RMM.PDF
Microsoft Azure-Based Kerberos Attacks Crack Open Cloud Accounts
https://www.darkreading.com/cloud/microsoft-azure-kerberos-attacks-open-cloud-accounts
Microsoft Blocking XLL Files Downloaded From Internet
https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=115485
Lexmark Vulnerablities
https://publications.lexmark.com/publications/security-alerts/CVE-2023-23560.pdf
VMware VRealize Update
https://www.vmware.com/security/advisories/VMSA-2023-0001.html
First Malicious OneNote Document
https://isc.sans.edu/diary/A%20First%20Malicious%20OneNote%20Document/29470
Guidance for Securing Remote Monitoring and Management Software
https://media.defense.gov/2023/Jan/25/2003149873/-1/-1/0/JOINT_CSA_RMM.PDF
Microsoft Azure-Based Kerberos Attacks Crack Open Cloud Accounts
https://www.darkreading.com/cloud/microsoft-azure-kerberos-attacks-open-cloud-accounts
Microsoft Blocking XLL Files Downloaded From Internet
https://www.microsoft.com/en-us/microsoft-365/roadmap?filters=&searchterms=115485
Lexmark Vulnerablities
https://publications.lexmark.com/publications/security-alerts/CVE-2023-23560.pdf
VMware VRealize Update
https://www.vmware.com/security/advisories/VMSA-2023-0001.html
Apple Patch Summary
https://isc.sans.edu/forums/diary/Apple%20Updates%20%28almost%29%20Everything%3A%20Patch%20Overview/29472/
ManageEngine News;
https://github.com/vonahisec/CVE-2022-47966-Scan
KSMBD Vulnerability
https://sysdig.com/blog/cve-2023-0210-linux-kernel-unauthenticated-remote-heap-overflow/
BitWarden Server Side Iterations
https://palant.info/2023/01/23/bitwarden-design-flaw-server-side-iterations/
Packet Tuesday: Neighbor Advertisements
https://www.youtube.com/watch?v=CoaZjuuY1do
Apple Patch Summary
https://isc.sans.edu/forums/diary/Apple%20Updates%20%28almost%29%20Everything%3A%20Patch%20Overview/29472/
ManageEngine News;
https://github.com/vonahisec/CVE-2022-47966-Scan
KSMBD Vulnerability
https://sysdig.com/blog/cve-2023-0210-linux-kernel-unauthenticated-remote-heap-overflow/
BitWarden Server Side Iterations
https://palant.info/2023/01/23/bitwarden-design-flaw-server-side-iterations/
Packet Tuesday: Neighbor Advertisements
https://www.youtube.com/watch?v=CoaZjuuY1do
Who's Resolving This Domain
https://isc.sans.edu/forums/diary/Who's%20Resolving%20This%20Domain%3F/29462/
Apple Updates Everything
https://support.apple.com/en-us/HT201222
NSA IPv6 Security Guidance
https://media.defense.gov/2023/Jan/18/2003145994/-1/-1/0/CSI_IPV6_SECURITY_GUIDANCE.PDF
Roaming Mantis Implements new DNS Changer in tis malicious mobile app
https://thehackernews.com/2023/01/roaming-mantis-spreading-mobile-malware.html
Who's Resolving This Domain
https://isc.sans.edu/forums/diary/Who's%20Resolving%20This%20Domain%3F/29462/
Apple Updates Everything
https://support.apple.com/en-us/HT201222
NSA IPv6 Security Guidance
https://media.defense.gov/2023/Jan/18/2003145994/-1/-1/0/CSI_IPV6_SECURITY_GUIDANCE.PDF
Roaming Mantis Implements new DNS Changer in tis malicious mobile app
https://thehackernews.com/2023/01/roaming-mantis-spreading-mobile-malware.html
Imortance of Signing in Windows Environments
https://isc.sans.edu/diary/Importance%20of%20signing%20in%20Windows%20environments/29456
FanDuel Discloses Data Breach Caused by Recent Mailchimp Hack
https://www.bleepingcomputer.com/news/security/fanduel-discloses-data-breach-caused-by-recent-mailchimp-hack/
OneNote Documents Used to Embed Malicious Office Documents
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
Cisco Unified Communications Manager SQL Injection
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-sql-rpPczR8n
Possible KeePass Vulnerability
https://twitter.com/vomanc/status/1617135599030530054
Imortance of Signing in Windows Environments
https://isc.sans.edu/diary/Importance%20of%20signing%20in%20Windows%20environments/29456
FanDuel Discloses Data Breach Caused by Recent Mailchimp Hack
https://www.bleepingcomputer.com/news/security/fanduel-discloses-data-breach-caused-by-recent-mailchimp-hack/
OneNote Documents Used to Embed Malicious Office Documents
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/trojanized-onenote-document-leads-to-formbook-malware/
Cisco Unified Communications Manager SQL Injection
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-sql-rpPczR8n
Possible KeePass Vulnerability
https://twitter.com/vomanc/status/1617135599030530054
SPF and DMARC use on 100k most popular domains
https://isc.sans.edu/diary/SPF%20and%20DMARC%20use%20on%20100k%20most%20popular%20domains/29452
Sysmon Exploit Released CVE-2022-41120, CVE-2022-44704
https://github.com/Wh04m1001/SysmonEoP
ManageEngine CVE-2022-47966 Technical Deep Dive
https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/
Netcomm Router Vulnerablities
https://kb.cert.org/vuls/id/986018
Microsoft Pushes Outdated Office Install Check
https://www.bleepingcomputer.com/news/microsoft/microsoft-pushes-kb5021751-to-check-for-outdated-office-installs/
SPF and DMARC use on 100k most popular domains
https://isc.sans.edu/diary/SPF%20and%20DMARC%20use%20on%20100k%20most%20popular%20domains/29452
Sysmon Exploit Released CVE-2022-41120, CVE-2022-44704
https://github.com/Wh04m1001/SysmonEoP
ManageEngine CVE-2022-47966 Technical Deep Dive
https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/
Netcomm Router Vulnerablities
https://kb.cert.org/vuls/id/986018
Microsoft Pushes Outdated Office Install Check
https://www.bleepingcomputer.com/news/microsoft/microsoft-pushes-kb5021751-to-check-for-outdated-office-installs/
Malicious Google Ads for Fake Notepad++ Lead to Aurora Stealer
https://isc.sans.edu/diary/Malicious%20Google%20Ad%20--%3E%20Fake%20Notepad%2B%2B%20Page%20--%3E%20Aurora%20Stealer%20malware/29448
Oracle Critical Patch Update
https://www.oracle.com/security-alerts/cpujan2023.html
QT QML Vulnerability
https://blog.talosintelligence.com/vulnerability-spotlight-integer-and-buffer-overflow-vulnerabilities-found-in-qt-qml/
sudo sudoedit vulnerablity
https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf
Malicious Google Ads for Fake Notepad++ Lead to Aurora Stealer
https://isc.sans.edu/diary/Malicious%20Google%20Ad%20--%3E%20Fake%20Notepad%2B%2B%20Page%20--%3E%20Aurora%20Stealer%20malware/29448
Oracle Critical Patch Update
https://www.oracle.com/security-alerts/cpujan2023.html
QT QML Vulnerability
https://blog.talosintelligence.com/vulnerability-spotlight-integer-and-buffer-overflow-vulnerabilities-found-in-qt-qml/
sudo sudoedit vulnerablity
https://www.synacktiv.com/sites/default/files/2023-01/sudo-CVE-2023-22809.pdf
Finding that one GPO setting in a pool of hundreds of GPOs
https://isc.sans.edu/diary/Finding%20that%20one%20GPO%20Setting%20in%20a%20Pool%20of%20Hundreds%20of%20GPOs/29442
GIT Code Audit
https://x41-dsec.de/security/research/news/2023/01/17/git-security-audit-ostif/
Azure SSRF Flaws
https://orca.security/resources/blog/ssrf-vulnerabilities-in-four-azure-services/
SMB Insecure Guest Auth Off By Default In Windows 11 Pro
https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-insecure-guest-auth-now-off-by-default-in-windows-insider/ba-p/3715014
Packet Tuesday: IPv6 Router Advertisements
https://www.youtube.com/watch?v=uRWpB_lYIZ8
Finding that one GPO setting in a pool of hundreds of GPOs
https://isc.sans.edu/diary/Finding%20that%20one%20GPO%20Setting%20in%20a%20Pool%20of%20Hundreds%20of%20GPOs/29442
GIT Code Audit
https://x41-dsec.de/security/research/news/2023/01/17/git-security-audit-ostif/
Azure SSRF Flaws
https://orca.security/resources/blog/ssrf-vulnerabilities-in-four-azure-services/
SMB Insecure Guest Auth Off By Default In Windows 11 Pro
https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb-insecure-guest-auth-now-off-by-default-in-windows-insider/ba-p/3715014
Packet Tuesday: IPv6 Router Advertisements
https://www.youtube.com/watch?v=uRWpB_lYIZ8
PSA: Why you must run an ad blocker when using Google
https://isc.sans.edu/diary/PSA%3A%20Why%20you%20must%20run%20an%20ad%20blocker%20when%20using%20Google/29438
NortonLifeLock Password Manager Bruteforcing
https://webcache.googleusercontent.com/search?q=cache%3A91Bmx_jTJIkJ%3Ahttps%3A%2F%2Fago.vermont.gov%2Fwp-content%2Fuploads%2F2023%2F01%2F2023-01-09-NortonLifeLock-Gen-Digital-Data-Breach-Notice-to-Consumers.pdf&cd=3&hl=de&ct=clnk≷=de
CVE-2023-0179 Linux kernel stack buffer overflow in nftables: PoC and writeup
https://seclists.org/oss-sec/2023/q1/20
MSI (in)Secure Boot
https://dawidpotocki.com/en/2023/01/13/msi-insecure-boot/
PSA: Why you must run an ad blocker when using Google
https://isc.sans.edu/diary/PSA%3A%20Why%20you%20must%20run%20an%20ad%20blocker%20when%20using%20Google/29438
NortonLifeLock Password Manager Bruteforcing
https://webcache.googleusercontent.com/search?q=cache%3A91Bmx_jTJIkJ%3Ahttps%3A%2F%2Fago.vermont.gov%2Fwp-content%2Fuploads%2F2023%2F01%2F2023-01-09-NortonLifeLock-Gen-Digital-Data-Breach-Notice-to-Consumers.pdf&cd=3&hl=de&ct=clnk≷=de
CVE-2023-0179 Linux kernel stack buffer overflow in nftables: PoC and writeup
https://seclists.org/oss-sec/2023/q1/20
MSI (in)Secure Boot
https://dawidpotocki.com/en/2023/01/13/msi-insecure-boot/
Elon Musk Themed Crypto Scams Flooding YouTube Today
https://isc.sans.edu/diary/Elon%20Musk%20Themed%20Crypto%20Scams%20Flooding%20YouTube%20Today/29434
Microsoft Text to Speech Synthesizer
https://arxiv.org/pdf/2301.02111.pdf
Missing Windows Start Menu
https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#2998msgdesc
Elon Musk Themed Crypto Scams Flooding YouTube Today
https://isc.sans.edu/diary/Elon%20Musk%20Themed%20Crypto%20Scams%20Flooding%20YouTube%20Today/29434
Microsoft Text to Speech Synthesizer
https://arxiv.org/pdf/2301.02111.pdf
Missing Windows Start Menu
https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22H2#2998msgdesc
Prowler v3: AWS & Azure security assessments
https://isc.sans.edu/diary/Prowler%20v3%3A%20AWS%20%26%20Azure%20security%20assessments/29430
Certified Pre-Pw0ned Android TV
https://github.com/DesktopECHO/T95-H616-Malware
Revolte Attack
https://revolte-attack.net
NGFW Data Exfiltration
https://cymulate.com/blog/data-exfiltration-firewall/
Prowler v3: AWS & Azure security assessments
https://isc.sans.edu/diary/Prowler%20v3%3A%20AWS%20%26%20Azure%20security%20assessments/29430
Certified Pre-Pw0ned Android TV
https://github.com/DesktopECHO/T95-H616-Malware
Revolte Attack
https://revolte-attack.net
NGFW Data Exfiltration
https://cymulate.com/blog/data-exfiltration-firewall/
Passive Detection of Internet-Connected Systems Affected by Exploited Vulnerabilities
https://isc.sans.edu/diary/Passive%20detection%20of%20internet-connected%20systems%20affected%20by%20vulnerabilities%20from%20the%20CISA%20KEV%20catalog/29426
Unauthenticed Remote DoS in ksmbd NTLMv2 Authentication
https://seclists.org/oss-sec/2023/q1/4
Cisco RV Series Vulnerabilities CVE-2023-20025
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5
Zoom Updates
https://explore.zoom.us/en/trust/security/security-bulletin/
Gootkit Abusing VLC
https://www.trendmicro.com/en_us/research/23/a/gootkit-loader-actively-targets-the-australian-healthcare-indust.html
Passive Detection of Internet-Connected Systems Affected by Exploited Vulnerabilities
https://isc.sans.edu/diary/Passive%20detection%20of%20internet-connected%20systems%20affected%20by%20vulnerabilities%20from%20the%20CISA%20KEV%20catalog/29426
Unauthenticed Remote DoS in ksmbd NTLMv2 Authentication
https://seclists.org/oss-sec/2023/q1/4
Cisco RV Series Vulnerabilities CVE-2023-20025
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sbr042-multi-vuln-ej76Pke5
Zoom Updates
https://explore.zoom.us/en/trust/security/security-bulletin/
Gootkit Abusing VLC
https://www.trendmicro.com/en_us/research/23/a/gootkit-loader-actively-targets-the-australian-healthcare-indust.html
Microsoft January 2023 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20January%202023%20Patch%20Tuesday/29420
Cacti Unauthenticated Remote Code Execution
https://www.sonarsource.com/blog/cacti-unauthenticated-remote-code-execution/
On the Security Vulnerabilities of Text-to-SQL Models
https://arxiv.org/pdf/2211.15363.pdf
Microsoft January 2023 Patch Tuesday
https://isc.sans.edu/diary/Microsoft%20January%202023%20Patch%20Tuesday/29420
Cacti Unauthenticated Remote Code Execution
https://www.sonarsource.com/blog/cacti-unauthenticated-remote-code-execution/
On the Security Vulnerabilities of Text-to-SQL Models
https://arxiv.org/pdf/2211.15363.pdf
New Year Old Tricks: Hunting for CircleCI Configuration Files
https://isc.sans.edu/diary/New%20year%2C%20old%20tricks%3A%20Hunting%20for%20CircleCI%20configuration%20files/29416
Amazon S3 Encrypts New Objects By Default
https://aws.amazon.com/blogs/aws/amazon-s3-encrypts-new-objects-by-default/
MatrixSSL Buffer Overflow
https://github.com/matrixssl/matrixssl/security/advisories/GHSA-fmwc-gwc5-2g29
Auth0 JsonWebToken Vulnerability CVE-2022-23529
https://unit42.paloaltonetworks.com/jsonwebtoken-vulnerability-cve-2022-23529/
New Year Old Tricks: Hunting for CircleCI Configuration Files
https://isc.sans.edu/diary/New%20year%2C%20old%20tricks%3A%20Hunting%20for%20CircleCI%20configuration%20files/29416
Amazon S3 Encrypts New Objects By Default
https://aws.amazon.com/blogs/aws/amazon-s3-encrypts-new-objects-by-default/
MatrixSSL Buffer Overflow
https://github.com/matrixssl/matrixssl/security/advisories/GHSA-fmwc-gwc5-2g29
Auth0 JsonWebToken Vulnerability CVE-2022-23529
https://unit42.paloaltonetworks.com/jsonwebtoken-vulnerability-cve-2022-23529/
Reversing AutoIT Scripts
https://isc.sans.edu/diary/AutoIT%20Remains%20Popular%20in%20the%20Malware%20Landscape/29408
Can You Trust Your VSCode Extensions
https://blog.aquasec.com/can-you-trust-your-vscode-extensions
A Deep Dive Into Powerat
https://blog.phylum.io/a-deep-dive-into-powerat-a-newly-discovered-stealer/rat-combo-polluting-pypi
Reversing AutoIT Scripts
https://isc.sans.edu/diary/AutoIT%20Remains%20Popular%20in%20the%20Malware%20Landscape/29408
Can You Trust Your VSCode Extensions
https://blog.aquasec.com/can-you-trust-your-vscode-extensions
A Deep Dive Into Powerat
https://blog.phylum.io/a-deep-dive-into-powerat-a-newly-discovered-stealer/rat-combo-polluting-pypi
More Brazil Malspam Pushing Astaroth (Guildma) in January 2023
https://isc.sans.edu/forums/diary/More%20Brazil%20malspam%20pushing%20Astaroth%20%28Guildma%29%20in%20January%202023/29404/
CircleCI Breach
https://circleci.com/blog/january-4-2023-security-alert/
Twitter Leak
https://www.bleepingcomputer.com/news/security/200-million-twitter-users-email-addresses-allegedly-leaked-online/
Slack Source Code Leak
https://slack.com/blog/news/slack-security-update
Control Web Panel Patch CVE-2022-44877
https://github.com/numanturle/CVE-2022-44877
Turla: A Galaxy of Opportunity
https://www.mandiant.com/resources/blog/turla-galaxy-opportunity
More Brazil Malspam Pushing Astaroth (Guildma) in January 2023
https://isc.sans.edu/forums/diary/More%20Brazil%20malspam%20pushing%20Astaroth%20%28Guildma%29%20in%20January%202023/29404/
CircleCI Breach
https://circleci.com/blog/january-4-2023-security-alert/
Twitter Leak
https://www.bleepingcomputer.com/news/security/200-million-twitter-users-email-addresses-allegedly-leaked-online/
Slack Source Code Leak
https://slack.com/blog/news/slack-security-update
Control Web Panel Patch CVE-2022-44877
https://github.com/numanturle/CVE-2022-44877
Turla: A Galaxy of Opportunity
https://www.mandiant.com/resources/blog/turla-galaxy-opportunity
Update to RTRBK - Diff and File Dates in PowerShell
https://isc.sans.edu/diary/Update%20to%20RTRBK%20-%20Diff%20and%20File%20Dates%20in%20PowerShell/29400
Google Chrome Sunsetting Legacy Windows Support
https://support.google.com/chrome/thread/185534985/sunsetting-support-for-windows-7-8-8-1-in-early-2023?hl=en
SHC used to compile cryptominer malware
https://asec.ahnlab.com/en/45182/
ManageEngine Password Manager Pro SQL Injection
https://pitstop.manageengine.com/portal/en/community/topic/manageengine-security-advisory important-security-fix-released-for-manageengine-password-manager-pro-2-1-2023#:~:text=critical%20security%20vulnerability
ForiADC Command Injection in Web Interface
https://www.fortiguard.com/psirt/FG-IR-22-061
Raspberry Robin Developments
https://www.securityjoes.com/post/raspberry-robin-detected-itw-targeting-insurance-financial-institutes-in-europe
Update to RTRBK - Diff and File Dates in PowerShell
https://isc.sans.edu/diary/Update%20to%20RTRBK%20-%20Diff%20and%20File%20Dates%20in%20PowerShell/29400
Google Chrome Sunsetting Legacy Windows Support
https://support.google.com/chrome/thread/185534985/sunsetting-support-for-windows-7-8-8-1-in-early-2023?hl=en
SHC used to compile cryptominer malware
https://asec.ahnlab.com/en/45182/
ManageEngine Password Manager Pro SQL Injection
https://pitstop.manageengine.com/portal/en/community/topic/manageengine-security-advisory important-security-fix-released-for-manageengine-password-manager-pro-2-1-2023#:~:text=critical%20security%20vulnerability
ForiADC Command Injection in Web Interface
https://www.fortiguard.com/psirt/FG-IR-22-061
Raspberry Robin Developments
https://www.securityjoes.com/post/raspberry-robin-detected-itw-targeting-insurance-financial-institutes-in-europe
NTP Fingerprinting
https://isc.sans.edu/diary/Its%20about%20time%3A%20OS%20Fingerprinting%20using%20NTP/29394
Misc Car Vulnerabilities
https://samcurry.net/web-hackers-vs-the-auto-industry/
Flipper Zero Phishing
https://twitter.com/AlvieriD/status/1609945425871609858
Trend Micro Patch
https://helpcenter.trendmicro.com/en-us/article/TMKA-11252
Packet Tuesday: IP Options
https://www.youtube.com/watch?v=HldNL3SLLwM
NTP Fingerprinting
https://isc.sans.edu/diary/Its%20about%20time%3A%20OS%20Fingerprinting%20using%20NTP/29394
Misc Car Vulnerabilities
https://samcurry.net/web-hackers-vs-the-auto-industry/
Flipper Zero Phishing
https://twitter.com/AlvieriD/status/1609945425871609858
Trend Micro Patch
https://helpcenter.trendmicro.com/en-us/article/TMKA-11252
Packet Tuesday: IP Options
https://www.youtube.com/watch?v=HldNL3SLLwM
Kyverno's container image signature verification bypass
https://www.armosec.io/blog/cve-2022-47633-kyvernos-container-image-signature-verification/
Google Smart Spaeker Vulnerability
https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html
Verizon Decomissions 3G CDMA Network
https://www.fiercewireless.com/wireless/verizon-tells-3g-customers-upgrade-they-lose-service
EarSpy: Spying Caller Speech and Identity Through Speaker Vibrations
https://arxiv.org/pdf/2212.12151.pdf
Kyverno's container image signature verification bypass
https://www.armosec.io/blog/cve-2022-47633-kyvernos-container-image-signature-verification/
Google Smart Spaeker Vulnerability
https://downrightnifty.me/blog/2022/12/26/hacking-google-home.html
Verizon Decomissions 3G CDMA Network
https://www.fiercewireless.com/wireless/verizon-tells-3g-customers-upgrade-they-lose-service
EarSpy: Spying Caller Speech and Identity Through Speaker Vibrations
https://arxiv.org/pdf/2212.12151.pdf
SPF and DMARC use on GOV domains in different ccTLDs
https://isc.sans.edu/forums/diary/SPF+and+DMARC+use+on+GOV+domains+in+different+ccTLDs/29384/
CVE-2022-47939 ksmbd Vulnerability
https://ubuntu.com/security/CVE-2022-47939
Netgear Vulnerabilities
https://kb.netgear.com/000065495/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Routers-PSV-2019-0208
PyTorch Malicious Dependency
https://pytorch.org/blog/compromised-nightly-dependency/
SPF and DMARC use on GOV domains in different ccTLDs
https://isc.sans.edu/forums/diary/SPF+and+DMARC+use+on+GOV+domains+in+different+ccTLDs/29384/
CVE-2022-47939 ksmbd Vulnerability
https://ubuntu.com/security/CVE-2022-47939
Netgear Vulnerabilities
https://kb.netgear.com/000065495/Security-Advisory-for-Pre-Authentication-Buffer-Overflow-on-Some-Routers-PSV-2019-0208
PyTorch Malicious Dependency
https://pytorch.org/blog/compromised-nightly-dependency/
Exchange OWASSRF Exploited for Remote Code Execution
https://isc.sans.edu/forums/diary/Exchange%20OWASSRF%20Exploited%20for%20Remote%20Code%20Execution/29374/
ksmbd Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-22-1690/
LastPass Incident Update
https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/
Exchange OWASSRF Exploited for Remote Code Execution
https://isc.sans.edu/forums/diary/Exchange%20OWASSRF%20Exploited%20for%20Remote%20Code%20Execution/29374/
ksmbd Vulnerability
https://www.zerodayinitiative.com/advisories/ZDI-22-1690/
LastPass Incident Update
https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/
Quick NTP Measurement
https://isc.sans.edu/diary/Can%20you%20please%20tell%20me%20what%20time%20it%20is%3F%20Adventures%20with%20public%20NTP%20servers./29368
FBI Favors Ad Blockers
https://www.ic3.gov/Media/Y2022/PSA221221
Hidden Costs of Parental Control Apps
https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/
ProxyNotShell Mitigtation Bypass
https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/
Quick NTP Measurement
https://isc.sans.edu/diary/Can%20you%20please%20tell%20me%20what%20time%20it%20is%3F%20Adventures%20with%20public%20NTP%20servers./29368
FBI Favors Ad Blockers
https://www.ic3.gov/Media/Y2022/PSA221221
Hidden Costs of Parental Control Apps
https://sec-consult.com/blog/detail/the-hidden-costs-of-parental-control-apps/
ProxyNotShell Mitigtation Bypass
https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/
Linux File System Monitoring and Actions
https://isc.sans.edu/diary/Linux%20File%20System%20Monitoring%20%26%20Actions/29362
Feed of NTP Server IP Addresses
https://isc.sans.edu/api/threatlist/ntpservers?json
Feed of Mastodon Server IP Addresses
https://isc.sans.edu/api/threatlist/mastodon?json
Packet Tuesday TLS Server Hello
https://www.youtube.com/watch?v=2HymU4dxWEQ
Android Preparing Support for Updatable Root Certificates
https://blog.esper.io/android-14-updatable-certificates/
Elastic IP Hijacking
https://www.mitiga.io/blog/elastic-ip-hijacking-a-new-attack-vector-in-aws
Microsoft Fixes HyperV issues With Latest Patch
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#2988
Linux File System Monitoring and Actions
https://isc.sans.edu/diary/Linux%20File%20System%20Monitoring%20%26%20Actions/29362
Feed of NTP Server IP Addresses
https://isc.sans.edu/api/threatlist/ntpservers?json
Feed of Mastodon Server IP Addresses
https://isc.sans.edu/api/threatlist/mastodon?json
Packet Tuesday TLS Server Hello
https://www.youtube.com/watch?v=2HymU4dxWEQ
Android Preparing Support for Updatable Root Certificates
https://blog.esper.io/android-14-updatable-certificates/
Elastic IP Hijacking
https://www.mitiga.io/blog/elastic-ip-hijacking-a-new-attack-vector-in-aws
Microsoft Fixes HyperV issues With Latest Patch
https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#2988
Hunting for Mastodon Servers
https://isc.sans.edu/diary/Hunting%20for%20Mastodon%20Servers/29358
KB5021233 Blue Screen
https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22H2#2986msgdesc
Edge Update will disable Internet Explorer in February
https://learn.microsoft.com/en-us/deployedge/edge-learnmore-neededge
Gatekeeper's Achilles heel: Unearthin a macOS vulnerability
https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/
Corsair Bug not causing keystroke logging
https://arstechnica.com/gadgets/2022/12/corsair-says-bug-not-keylogger-behind-some-k100-keyboards-creepy-behavior/
SentinelSneak: Malicious PyPi module poses as security software development kit
Hunting for Mastodon Servers
https://isc.sans.edu/diary/Hunting%20for%20Mastodon%20Servers/29358
KB5021233 Blue Screen
https://learn.microsoft.com/en-us/windows/release-health/status-windows-10-22H2#2986msgdesc
Edge Update will disable Internet Explorer in February
https://learn.microsoft.com/en-us/deployedge/edge-learnmore-neededge
Gatekeeper's Achilles heel: Unearthin a macOS vulnerability
https://www.microsoft.com/en-us/security/blog/2022/12/19/gatekeepers-achilles-heel-unearthing-a-macos-vulnerability/
Corsair Bug not causing keystroke logging
https://arstechnica.com/gadgets/2022/12/corsair-says-bug-not-keylogger-behind-some-k100-keyboards-creepy-behavior/
SentinelSneak: Malicious PyPi module poses as security software development kit
Infostealer Malware with Double Extension
https://isc.sans.edu/diary/Infostealer%20Malware%20with%20Double%20Extension/29354
Client Side Encryption For GMail
https://workspaceupdates.googleblog.com/2022/12/client-side-encryption-for-gmail-beta.html
Google Releases OSV Scanner
https://github.com/google/osv-scanner/releases/tag/v1.0.1
Samba Security Patches
https://thehackernews.com/2022/12/samba-issues-security-updates-to-patch.html
Zyxel Router Buffer Overflow
https://sec-consult.com/blog/detail/enemy-within-unauthenticated-buffer-overflows-zyxel-routers/
Infostealer Malware with Double Extension
https://isc.sans.edu/diary/Infostealer%20Malware%20with%20Double%20Extension/29354
Client Side Encryption For GMail
https://workspaceupdates.googleblog.com/2022/12/client-side-encryption-for-gmail-beta.html
Google Releases OSV Scanner
https://github.com/google/osv-scanner/releases/tag/v1.0.1
Samba Security Patches
https://thehackernews.com/2022/12/samba-issues-security-updates-to-patch.html
Zyxel Router Buffer Overflow
https://sec-consult.com/blog/detail/enemy-within-unauthenticated-buffer-overflows-zyxel-routers/
Google ads lead to fake software pages pushing IcedID (Bokbot)
https://isc.sans.edu/diary/Google%20ads%20lead%20to%20fake%20software%20pages%20pushing%20IcedID%20%28Bokbot%29/29344
HTML smugglers turn to SVG images
https://blog.talosintelligence.com/html-smugglers-turn-to-svg-images/
GitHub Improvements
https://github.blog/2022-12-14-raising-the-bar-for-software-security-next-steps-for-github-com-2fa/
NIST Retires SHA-1
https://www.nist.gov/news-events/news/2022/12/nist-retires-sha-1-cryptographic-algorithm
Google ads lead to fake software pages pushing IcedID (Bokbot)
https://isc.sans.edu/diary/Google%20ads%20lead%20to%20fake%20software%20pages%20pushing%20IcedID%20%28Bokbot%29/29344
HTML smugglers turn to SVG images
https://blog.talosintelligence.com/html-smugglers-turn-to-svg-images/
GitHub Improvements
https://github.blog/2022-12-14-raising-the-bar-for-software-security-next-steps-for-github-com-2fa/
NIST Retires SHA-1
https://www.nist.gov/news-events/news/2022/12/nist-retires-sha-1-cryptographic-algorithm
Microsoft Patch Issues:
https://support.microsoft.com/en-us/topic/december-13-2022-kb5021249-os-build-20348-1366-d5fe7608-bc9d-4055-a88c-fb2fd3d5fd45
https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/so-you-say-your-dc-s-memory-is-getting-all-used-up-after/ba-p/3696318
Critical Remote Code Execution Vulneraiblity in SPNEGO Extended Negotiation Security Mechanism
https://securityintelligence.com/posts/critical-remote-code-execution-vulnerability-spnego-extended-negotiation-security-mechanism/
VMWare EHCI Controller Vulnerability CVE-2022-31705
https://www.vmware.com/security/advisories/VMSA-2022-0033.html
Veem Vulnerability now Exploited
https://www.veeam.com/kb4288
nuget / npm / pypi used to host phishing pages
https://checkmarx.com/blog/how-140k-nuget-npm-and-pypi-packages-were-used-to-spread-phishing-links/
Microsoft Patch Issues:
https://support.microsoft.com/en-us/topic/december-13-2022-kb5021249-os-build-20348-1366-d5fe7608-bc9d-4055-a88c-fb2fd3d5fd45
https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/so-you-say-your-dc-s-memory-is-getting-all-used-up-after/ba-p/3696318
Critical Remote Code Execution Vulneraiblity in SPNEGO Extended Negotiation Security Mechanism
https://securityintelligence.com/posts/critical-remote-code-execution-vulnerability-spnego-extended-negotiation-security-mechanism/
VMWare EHCI Controller Vulnerability CVE-2022-31705
https://www.vmware.com/security/advisories/VMSA-2022-0033.html
Veem Vulnerability now Exploited
https://www.veeam.com/kb4288
nuget / npm / pypi used to host phishing pages
https://checkmarx.com/blog/how-140k-nuget-npm-and-pypi-packages-were-used-to-spread-phishing-links/
Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20December%202022%20Patch%20Tuesday/29336
Apple Patches
https://isc.sans.edu/diary/Apple%20Updates%20Everything/29338
Citrix Patches
https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/
Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20December%202022%20Patch%20Tuesday/29336
Apple Patches
https://isc.sans.edu/diary/Apple%20Updates%20Everything/29338
Citrix Patches
https://www.citrix.com/blogs/2022/12/13/critical-security-update-now-available-for-citrix-adc-citrix-gateway/
Quickie: CyberChef Sorting By String Length
https://isc.sans.edu/diary/Quickie%3A%20CyberChef%20Sorting%20By%20String%20Length/29328
FortiOS Buffer Overlow
https://www.fortiguard.com/psirt/FG-IR-22-398
A Custom Python Backdoor for VMWare ESXi Servers
https://blogs.juniper.net/en-us/threat-research/a-custom-python-backdoor-for-vmware-esxi-servers
Fuzzing Ping
https://tlakh.xyz/fuzzing-ping.html
Quickie: CyberChef Sorting By String Length
https://isc.sans.edu/diary/Quickie%3A%20CyberChef%20Sorting%20By%20String%20Length/29328
FortiOS Buffer Overlow
https://www.fortiguard.com/psirt/FG-IR-22-398
A Custom Python Backdoor for VMWare ESXi Servers
https://blogs.juniper.net/en-us/threat-research/a-custom-python-backdoor-for-vmware-esxi-servers
Fuzzing Ping
https://tlakh.xyz/fuzzing-ping.html
Fast Port Scanning in Powershell
https://isc.sans.edu/diary/Port%20Scanning%20in%20Powershell%20Redux%3A%20Speeding%20Up%20the%20Results%20%28challenge%20accepted!%29/29324
Bypassing WAFs with JSON
https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf
Invisbile npm malware evading security checks
https://jfrog.com/blog/invisible-npm-malware-evading-security-checks-with-crafted-versions/
PCI Secre Software Standard V 1.2
https://docs-prv.pcisecuritystandards.org/Software%20Security/Standard/PCI-Secure-Software-Standard-v1_2.pdf
VMWare/VCenter Patches
https://www.vmware.com/security/advisories/VMSA-2022-0030.html
Fast Port Scanning in Powershell
https://isc.sans.edu/diary/Port%20Scanning%20in%20Powershell%20Redux%3A%20Speeding%20Up%20the%20Results%20%28challenge%20accepted!%29/29324
Bypassing WAFs with JSON
https://claroty.com/team82/research/js-on-security-off-abusing-json-based-sql-to-bypass-waf
Invisbile npm malware evading security checks
https://jfrog.com/blog/invisible-npm-malware-evading-security-checks-with-crafted-versions/
PCI Secre Software Standard V 1.2
https://docs-prv.pcisecuritystandards.org/Software%20Security/Standard/PCI-Secure-Software-Standard-v1_2.pdf
VMWare/VCenter Patches
https://www.vmware.com/security/advisories/VMSA-2022-0030.html
Finding Gaps in Syslog
https://isc.sans.edu/diary/Finding%20Gaps%20in%20Syslog%20-%20How%20to%20find%20when%20nothing%20happened/29314
Internet Explorer Vulnerabilty used in Malicious Word Document
https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/
Zombinder Obfuscation Service used by Ermac
https://www.threatfabric.com/blogs/zombinder-ermac-and-desktop-stealers.html
Cisco IP Phone Vulnerability CVE-2022-20968
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipp-oobwrite-8cMF5r7U
daloRADIUS Vulnerablity CVE-2022-23475
https://securityonline.info/cve-2022-23475-account-take-over-flaw-in-open-source-radius-web-management-app/
SANS Holiday Hack Challenge
https://www.sans.org/mlp/holiday-hack-challenge/
Finding Gaps in Syslog
https://isc.sans.edu/diary/Finding%20Gaps%20in%20Syslog%20-%20How%20to%20find%20when%20nothing%20happened/29314
Internet Explorer Vulnerabilty used in Malicious Word Document
https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/
Zombinder Obfuscation Service used by Ermac
https://www.threatfabric.com/blogs/zombinder-ermac-and-desktop-stealers.html
Cisco IP Phone Vulnerability CVE-2022-20968
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ipp-oobwrite-8cMF5r7U
daloRADIUS Vulnerablity CVE-2022-23475
https://securityonline.info/cve-2022-23475-account-take-over-flaw-in-open-source-radius-web-management-app/
SANS Holiday Hack Challenge
https://www.sans.org/mlp/holiday-hack-challenge/
ZeroBot / WSZero IoT Botnet
https://www.fortinet.com/blog/threat-research/zerobot-new-go-based-botnet-campaign-targets-multiple-vulnerabilities
https://blog.netlab.360.com/new-ddos-botnet-wszeor/
Cacti Vulnerability CVE-2022-46169
https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf
Wireshark Updates
https://www.wireshark.org/docs/relnotes/wireshark-4.0.2.html
Apple iCloud Security Improvements
https://www.apple.com/newsroom/2022/12/apple-advances-user-security-with-powerful-new-data-protections/
ZeroBot / WSZero IoT Botnet
https://www.fortinet.com/blog/threat-research/zerobot-new-go-based-botnet-campaign-targets-multiple-vulnerabilities
https://blog.netlab.360.com/new-ddos-botnet-wszeor/
Cacti Vulnerability CVE-2022-46169
https://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf
Wireshark Updates
https://www.wireshark.org/docs/relnotes/wireshark-4.0.2.html
Apple iCloud Security Improvements
https://www.apple.com/newsroom/2022/12/apple-advances-user-security-with-powerful-new-data-protections/
Mirai Botnet and Gafgyt DDoS Team Up
https://isc.sans.edu/forums/diary/Mirai%20Botnet%20and%20Gafgyt%20DDoS%20Team%20Up%20Against%20SOHO%20Routers./29304/Gafgyt/Mirai Sample; Packet Tuesday;
Packet Tuesday Episode 4: TLS Client Hello
https://www.youtube.com/playlist?list=PLs4eo9Tja8biVteSW4a3GHY8qi0t1lFLL
Defcon Skimming: A new batch of Web Skimming attacks
https://blog.jscrambler.com/defcon-skimming-a-new-batch-of-web-skimming-attacks
Fake D-Link Vulnerability used by Moobot
https://vulncheck.com/blog/moobot-uses-fake-vulnerability
Android Patches CVE-2022-20411
https://source.android.com/docs/security/bulletin/2022-12-01?hl=en
Mirai Botnet and Gafgyt DDoS Team Up
https://isc.sans.edu/forums/diary/Mirai%20Botnet%20and%20Gafgyt%20DDoS%20Team%20Up%20Against%20SOHO%20Routers./29304/Gafgyt/Mirai Sample; Packet Tuesday;
Packet Tuesday Episode 4: TLS Client Hello
https://www.youtube.com/playlist?list=PLs4eo9Tja8biVteSW4a3GHY8qi0t1lFLL
Defcon Skimming: A new batch of Web Skimming attacks
https://blog.jscrambler.com/defcon-skimming-a-new-batch-of-web-skimming-attacks
Fake D-Link Vulnerability used by Moobot
https://vulncheck.com/blog/moobot-uses-fake-vulnerability
Android Patches CVE-2022-20411
https://source.android.com/docs/security/bulletin/2022-12-01?hl=en
VLCs Check For Updates No Updates
https://isc.sans.edu/diary/VLCs+Check+For+Updates+No+Updates/29300
AMI MegaRAC Baseboard Managment Controller Vulnerabilities
https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/
Netgear IPv6 Firewall Misconfiguration
https://medium.com/tenable-techblog/netgear-router-network-misconfiguration-70ac695c81a6
Veritas NetBackup Patch
https://www.veritas.com/content/support/en_US/security/VTS22-019
VLCs Check For Updates No Updates
https://isc.sans.edu/diary/VLCs+Check+For+Updates+No+Updates/29300
AMI MegaRAC Baseboard Managment Controller Vulnerabilities
https://eclypsium.com/2022/12/05/supply-chain-vulnerabilities-put-server-ecosystem-at-risk/
Netgear IPv6 Firewall Misconfiguration
https://medium.com/tenable-techblog/netgear-router-network-misconfiguration-70ac695c81a6
Veritas NetBackup Patch
https://www.veritas.com/content/support/en_US/security/VTS22-019
QBot Update
https://isc.sans.edu/forums/diary/obama224%20distribution%20Qakbot%20tries%20.vhd%20%28virtual%20hard%20disk%29%20images/29294/
Living of the Land: Unix tools in Windows
https://isc.sans.edu/diary/Linux%20LOLBins%20Applications%20Available%20in%20Windows/29296
https://isc.sans.edu/forums/diary/Fingerexe+LOLBin/29298/
CVE-2022-44721 Crowdstrike Falcon Uninstaller
https://github.com/purplededa/CVE-2022-44721-CsFalconUninstaller
Android Platform Key Leak
https://twitter.com/MishaalRahman/status/1598426974594433025
GitHub Pipeline Vulnerability
https://www.legitsecurity.com/blog/artifact-poisoning-vulnerability-discovered-in-rust
QBot Update
https://isc.sans.edu/forums/diary/obama224%20distribution%20Qakbot%20tries%20.vhd%20%28virtual%20hard%20disk%29%20images/29294/
Living of the Land: Unix tools in Windows
https://isc.sans.edu/diary/Linux%20LOLBins%20Applications%20Available%20in%20Windows/29296
https://isc.sans.edu/forums/diary/Fingerexe+LOLBin/29298/
CVE-2022-44721 Crowdstrike Falcon Uninstaller
https://github.com/purplededa/CVE-2022-44721-CsFalconUninstaller
Android Platform Key Leak
https://twitter.com/MishaalRahman/status/1598426974594433025
GitHub Pipeline Vulnerability
https://www.legitsecurity.com/blog/artifact-poisoning-vulnerability-discovered-in-rust
Quarkus Java Framework Vulnerability CVE-2022-4116
https://www.contrastsecurity.com/security-influencers/localhost-attack-against-quarkus-developers-contrast-security
https://access.redhat.com/security/cve/CVE-2022-4116
FreeBSD Ping RCE CVE-2022-23093
https://www.freebsd.org/security/advisories/FreeBSD-SA-22:15.ping.asc
NVidia GPU Display Driver Vulnerablities CVE-2022-34669
https://nvidia.custhelp.com/app/answers/detail/a_id/5415
TrustCor CA Revoked
https://www.washingtonpost.com/technology/2022/11/30/trustcor-internet-authority-mozilla/
Android Platform Certificates Used to Sign Malware
https://bugs.chromium.org/p/apvi/issues/detail?id=100
Quarkus Java Framework Vulnerability CVE-2022-4116
https://www.contrastsecurity.com/security-influencers/localhost-attack-against-quarkus-developers-contrast-security
https://access.redhat.com/security/cve/CVE-2022-4116
FreeBSD Ping RCE CVE-2022-23093
https://www.freebsd.org/security/advisories/FreeBSD-SA-22:15.ping.asc
NVidia GPU Display Driver Vulnerablities CVE-2022-34669
https://nvidia.custhelp.com/app/answers/detail/a_id/5415
TrustCor CA Revoked
https://www.washingtonpost.com/technology/2022/11/30/trustcor-internet-authority-mozilla/
Android Platform Certificates Used to Sign Malware
https://bugs.chromium.org/p/apvi/issues/detail?id=100
What is the deal wtih these router vulnerabilities
https://isc.sans.edu/diary/Whats+the+deal+with+these+router+vulnerabilities/29288/
Apple Updates
https://support.apple.com/en-us/HT201222
VLC Media Player Updates CVE-2022-41325
https://www.videolan.org/security/sb-vlc3018.html
VIN used to authenticate to Sirius XM Connected Vehicle Services
https://www.theregister.com/2022/11/30/siriusxm_connected_cars_hacking/
What is the deal wtih these router vulnerabilities
https://isc.sans.edu/diary/Whats+the+deal+with+these+router+vulnerabilities/29288/
Apple Updates
https://support.apple.com/en-us/HT201222
VLC Media Player Updates CVE-2022-41325
https://www.videolan.org/security/sb-vlc3018.html
VIN used to authenticate to Sirius XM Connected Vehicle Services
https://www.theregister.com/2022/11/30/siriusxm_connected_cars_hacking/
LinkedIn Bots
https://isc.sans.edu/diary/Identifying%20Groups%20of%20%22Bot%22%20Accounts%20on%20LinkedIn/29282
Oracle Fusion Middle Ware Exploited CVE-2021-35587
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Windows IKE Flaw Exploited CVE-2022-34721
https://www.cyfirma.com/outofband/windows-internet-key-exchange-ike-remote-code-execution-vulnerability-analysis/
Anker Eufy Cameras Sending Images to Cloud even if asked not to
https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/
Packet Tuesday
https://packettuesday.com
SANS Holiday Hack Challenge Sign Up
https://www.sans.org/mlp/holiday-hack-challenge/
LinkedIn Bots
https://isc.sans.edu/diary/Identifying%20Groups%20of%20%22Bot%22%20Accounts%20on%20LinkedIn/29282
Oracle Fusion Middle Ware Exploited CVE-2021-35587
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Windows IKE Flaw Exploited CVE-2022-34721
https://www.cyfirma.com/outofband/windows-internet-key-exchange-ike-remote-code-execution-vulnerability-analysis/
Anker Eufy Cameras Sending Images to Cloud even if asked not to
https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/
Packet Tuesday
https://packettuesday.com
SANS Holiday Hack Challenge Sign Up
https://www.sans.org/mlp/holiday-hack-challenge/
Ukraine Themed Twitter Spam Pushing iOS Scareware
https://isc.sans.edu/diary/Ukraine%20Themed%20Twitter%20Spam%20Pushing%20iOS%20Scareware/29276
Google Maps Privacy Issues
https://garrit.xyz/posts/2022-11-24-smart-move-google
ACER UEFI BIOS Vulnerabilities
https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings
OpenSSL Usage in UEFI Firmware Exposes Weakness in SBOMs
https://www.binarly.io/posts/OpenSSL_Usage_in_UEFI_Firmware_Exposes_Weakness_in_SBOMs/index.html
Ukraine Themed Twitter Spam Pushing iOS Scareware
https://isc.sans.edu/diary/Ukraine%20Themed%20Twitter%20Spam%20Pushing%20iOS%20Scareware/29276
Google Maps Privacy Issues
https://garrit.xyz/posts/2022-11-24-smart-move-google
ACER UEFI BIOS Vulnerabilities
https://community.acer.com/en/kb/articles/15520-security-vulnerability-regarding-vulnerability-that-may-allow-changes-to-secure-boot-settings
OpenSSL Usage in UEFI Firmware Exposes Weakness in SBOMs
https://www.binarly.io/posts/OpenSSL_Usage_in_UEFI_Firmware_Exposes_Weakness_in_SBOMs/index.html
Log4Shell campaigns are using Nashorn to get reverse shell on victim's machines
https://isc.sans.edu/diary/Log4Shell%20campaigns%20are%20using%20Nashorn%20to%20get%20reverse%20shell%20on%20victim%27s%20machines/29266
Attackers Keep Phishing Victms Under Stress
https://isc.sans.edu/diary/Attackers%20Keep%20Phishing%20Victims%20Under%20Stress/29270
Vulnerable SDK components lead to supply chian risks in IoT and OT environments
https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/
Google Chrome Patches 0-Day
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html
Hacking Smartwatches for Spear Phishing
https://cybervelia.com/?p=1380
Log4Shell campaigns are using Nashorn to get reverse shell on victim's machines
https://isc.sans.edu/diary/Log4Shell%20campaigns%20are%20using%20Nashorn%20to%20get%20reverse%20shell%20on%20victim%27s%20machines/29266
Attackers Keep Phishing Victms Under Stress
https://isc.sans.edu/diary/Attackers%20Keep%20Phishing%20Victims%20Under%20Stress/29270
Vulnerable SDK components lead to supply chian risks in IoT and OT environments
https://www.microsoft.com/en-us/security/blog/2022/11/22/vulnerable-sdk-components-lead-to-supply-chain-risks-in-iot-and-ot-environments/
Google Chrome Patches 0-Day
https://chromereleases.googleblog.com/2022/11/stable-channel-update-for-desktop_24.html
Hacking Smartwatches for Spear Phishing
https://cybervelia.com/?p=1380
Lessons Learned from Automatic Failover
https://isc.sans.edu/diary/Lessons%20Learned%20from%20Automatic%20Failover%3A%20When%208.8.8.8%20%22disappears%22.%20IPv6%20to%20the%20Rescue%3F/29260
Bitbucket Server and Data Center Vulnerability
https://jira.atlassian.com/browse/BSERV-13522
Amazon RDS Snapshot Leaks
https://www.mitiga.io/blog/how-mitiga-found-pii-in-exposed-amazon-rds-snapshots
Adobe Commerce merchants to be hit with TrojanOrders this season
https://sansec.io/research/trojanorder-magento
SANS EDU Research: Detecting and Mitigating the GateKeeper User Override on macOS in an Enterprise Environment; Antonio Piazza
https://www.sans.edu/cyber-research/detecting-and-mitigating-the-gatekeeper-user-override-on-macos-in-an-enterprise-environment/
Lessons Learned from Automatic Failover
https://isc.sans.edu/diary/Lessons%20Learned%20from%20Automatic%20Failover%3A%20When%208.8.8.8%20%22disappears%22.%20IPv6%20to%20the%20Rescue%3F/29260
Bitbucket Server and Data Center Vulnerability
https://jira.atlassian.com/browse/BSERV-13522
Amazon RDS Snapshot Leaks
https://www.mitiga.io/blog/how-mitiga-found-pii-in-exposed-amazon-rds-snapshots
Adobe Commerce merchants to be hit with TrojanOrders this season
https://sansec.io/research/trojanorder-magento
SANS EDU Research: Detecting and Mitigating the GateKeeper User Override on macOS in an Enterprise Environment; Antonio Piazza
https://www.sans.edu/cyber-research/detecting-and-mitigating-the-gatekeeper-user-override-on-macos-in-an-enterprise-environment/
Evil Maid Attacks - Remediation for the Cheap
https://isc.sans.edu/diary/Evil%20Maid%20Attacks%20-%20Remediation%20for%20the%20Cheap/29256
F5 Big IP CVE-2022-41622 and CVE-2022-41800 Vulnerability Details
https://www.rapid7.com/blog/post/2022/11/16/cve-2022-41622-and-cve-2022-41800-fixed-f5-big-ip-and-icontrol-rest-vulnerabilities-and-exposures/
Details about iPad/iOS Neural Engine Vulnerability CVE-2022-32899
https://github.com/0x36/weightBufs/
Disneyland Malware Team: It's a Puny World After All
https://krebsonsecurity.com/2022/11/disneyland-malware-team-its-a-puny-world-after-all/#more-61870
Evil Maid Attacks - Remediation for the Cheap
https://isc.sans.edu/diary/Evil%20Maid%20Attacks%20-%20Remediation%20for%20the%20Cheap/29256
F5 Big IP CVE-2022-41622 and CVE-2022-41800 Vulnerability Details
https://www.rapid7.com/blog/post/2022/11/16/cve-2022-41622-and-cve-2022-41800-fixed-f5-big-ip-and-icontrol-rest-vulnerabilities-and-exposures/
Details about iPad/iOS Neural Engine Vulnerability CVE-2022-32899
https://github.com/0x36/weightBufs/
Disneyland Malware Team: It's a Puny World After All
https://krebsonsecurity.com/2022/11/disneyland-malware-team-its-a-puny-world-after-all/#more-61870
Packet Tuesday
https://packettuesday.com
Stealing Passwords From Infosec Mastodon - Without Bypassing CSP
https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
SQLi and Access Flaws in Zendesk
https://www.varonis.com/blog/zendesk-sql-injection-and-access-flaws
Electric Vehicle Charging Infrastructure
https://newsreleases.sandia.gov/ev_security/
Packet Tuesday
https://packettuesday.com
Stealing Passwords From Infosec Mastodon - Without Bypassing CSP
https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
SQLi and Access Flaws in Zendesk
https://www.varonis.com/blog/zendesk-sql-injection-and-access-flaws
Electric Vehicle Charging Infrastructure
https://newsreleases.sandia.gov/ev_security/
Extracting "HTTP CONNECT" Requests with Python
https://isc.sans.edu/diary/Extracting%20%27HTTP%20CONNECT%27%20Requests%20with%20Python/29246
Windows Kerberos Authentication Breaks After November Updates
https://www.bleepingcomputer.com/news/microsoft/windows-kerberos-authentication-breaks-after-november-updates/
https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22h2#2953msgdesc
Cookies for MFA Bypass Gain Traction Among Cyberattackers
https://www.darkreading.com/threat-intelligence/cookies-mfa-bypass-cyberattackers
Extracting "HTTP CONNECT" Requests with Python
https://isc.sans.edu/diary/Extracting%20%27HTTP%20CONNECT%27%20Requests%20with%20Python/29246
Windows Kerberos Authentication Breaks After November Updates
https://www.bleepingcomputer.com/news/microsoft/windows-kerberos-authentication-breaks-after-november-updates/
https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-22h2#2953msgdesc
Cookies for MFA Bypass Gain Traction Among Cyberattackers
https://www.darkreading.com/threat-intelligence/cookies-mfa-bypass-cyberattackers
Extracting Information From "logfmt" Files with CyberChef
https://isc.sans.edu/diary/Extracting%20Information%20From%20%22logfmt%22%20Files%20With%20CyberChef/29244
Soccer Worldcup Risks
https://www.theregister.com/2022/11/11/world_cup_security/
https://www.welivesecurity.com/2022/11/11/fifa-world-cup-2022-scams-fake-lotteries-ticket-fraud/
Mysterious Company With Government Ties Plays Key Internet Role
https://www.washingtonpost.com/technology/2022/11/08/trustcor-internet-addresses-government-connections/
Extortion Scams Hit Website Owners
https://www.bleepingcomputer.com/news/security/new-extortion-scam-threatens-to-damage-sites-reputation-leak-data/
Extracting Information From "logfmt" Files with CyberChef
https://isc.sans.edu/diary/Extracting%20Information%20From%20%22logfmt%22%20Files%20With%20CyberChef/29244
Soccer Worldcup Risks
https://www.theregister.com/2022/11/11/world_cup_security/
https://www.welivesecurity.com/2022/11/11/fifa-world-cup-2022-scams-fake-lotteries-ticket-fraud/
Mysterious Company With Government Ties Plays Key Internet Role
https://www.washingtonpost.com/technology/2022/11/08/trustcor-internet-addresses-government-connections/
Extortion Scams Hit Website Owners
https://www.bleepingcomputer.com/news/security/new-extortion-scam-threatens-to-damage-sites-reputation-leak-data/
Do you collect "Observables" or "IOCs"
https://isc.sans.edu/diary/Do%20you%20collect%20%22Observables%22%20or%20%22IOCs%22%3F/29238
Android Update fixes Lock Screen Bypass
https://source.android.com/docs/security/bulletin/2022-11-01
https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/
libxml Vulnerability Details
https://gitlab.gnome.org/GNOME/libxml2/-/issues/381
CVE-2022-45063: xterm remote code execution vulnerability
https://www.openwall.com/lists/oss-security/2022/11/10/1
Do you collect "Observables" or "IOCs"
https://isc.sans.edu/diary/Do%20you%20collect%20%22Observables%22%20or%20%22IOCs%22%3F/29238
Android Update fixes Lock Screen Bypass
https://source.android.com/docs/security/bulletin/2022-11-01
https://bugs.xdavidhu.me/google/2022/11/10/accidental-70k-google-pixel-lock-screen-bypass/
libxml Vulnerability Details
https://gitlab.gnome.org/GNOME/libxml2/-/issues/381
CVE-2022-45063: xterm remote code execution vulnerability
https://www.openwall.com/lists/oss-security/2022/11/10/1
Another Script-Based Ransomware
https://isc.sans.edu/diary/Another%20Script-Based%20Ransomware/29234
Apple Security Updates
https://support.apple.com/en-us/HT201222
Lenovo UEFI Patch
https://www.welivesecurity.com/2022/04/19/when-secure-isnt-secure-uefi-vulnerabilities-lenovo-consumer-laptops/
FoxIT Update
https://www.foxit.com/support/security-bulletins.html
SAP Update
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
Another Script-Based Ransomware
https://isc.sans.edu/diary/Another%20Script-Based%20Ransomware/29234
Apple Security Updates
https://support.apple.com/en-us/HT201222
Lenovo UEFI Patch
https://www.welivesecurity.com/2022/04/19/when-secure-isnt-secure-uefi-vulnerabilities-lenovo-consumer-laptops/
FoxIT Update
https://www.foxit.com/support/security-bulletins.html
SAP Update
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20November%202022%20Patch%20Tuesday/29230
VMWare Workspace One Updates CVE-2022-31686, CVE-2022-31687, CVE-2022-31688
https://www.vmware.com/security/advisories/VMSA-2022-0028.html
Citrix Gateway / Citrix ADC Vulnerabilities CVE-2022-27510
https://support.citrix.com/article/CTX463706/citrix-gateway-and-citrix-adc-security-bulletin-for-cve202227510-cve202227513-and-cve202227516
Microsoft Exchange Updates
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
https://techcommunity.microsoft.com/t5/exchange-team-blog/released-november-2022-exchange-server-security-updates/ba-p/3669045
Microsoft Patches
https://isc.sans.edu/diary/Microsoft%20November%202022%20Patch%20Tuesday/29230
VMWare Workspace One Updates CVE-2022-31686, CVE-2022-31687, CVE-2022-31688
https://www.vmware.com/security/advisories/VMSA-2022-0028.html
Citrix Gateway / Citrix ADC Vulnerabilities CVE-2022-27510
https://support.citrix.com/article/CTX463706/citrix-gateway-and-citrix-adc-security-bulletin-for-cve202227510-cve202227513-and-cve202227516
Microsoft Exchange Updates
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
https://techcommunity.microsoft.com/t5/exchange-team-blog/released-november-2022-exchange-server-security-updates/ba-p/3669045
IPv4 Address Representations
https://isc.sans.edu/diary/IPv4%20Address%20Representations/29224
Azure AD Certificate-based Authentication (CBA) on Mobile
https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/azure-ad-certificate-based-authentication-cba-on-mobile/ba-p/2365672
Twitter Scams
https://nakedsecurity.sophos.com/2022/11/04/twitter-blue-badge-email-scams-dont-fall-for-them/
Facebook Personal Information Removal
https://www.facebook.com/contacts/removal
RSA Conference Finds Unencrypted Confidential Data in WiFi Traffic
https://www.darkreading.com/remote-workforce/unencrypted-traffic-weak-e-mail-passwords-still-undermining-wifi-security
IPv4 Address Representations
https://isc.sans.edu/diary/IPv4%20Address%20Representations/29224
Azure AD Certificate-based Authentication (CBA) on Mobile
https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad-blog/azure-ad-certificate-based-authentication-cba-on-mobile/ba-p/2365672
Twitter Scams
https://nakedsecurity.sophos.com/2022/11/04/twitter-blue-badge-email-scams-dont-fall-for-them/
Facebook Personal Information Removal
https://www.facebook.com/contacts/removal
RSA Conference Finds Unencrypted Confidential Data in WiFi Traffic
https://www.darkreading.com/remote-workforce/unencrypted-traffic-weak-e-mail-passwords-still-undermining-wifi-security
Remcos Downloader With Unicode Obfuscation
https://isc.sans.edu/diary/Remcos%20Downloader%20with%20Unicode%20Obfuscation/29220
Windows Malware With VHD Extension
https://isc.sans.edu/diary/Windows%20Malware%20with%20VHD%20Extension/29222
PyPi Packages Attempting to Deliver w4sp Stealer
https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack
Remcos Downloader With Unicode Obfuscation
https://isc.sans.edu/diary/Remcos%20Downloader%20with%20Unicode%20Obfuscation/29220
Windows Malware With VHD Extension
https://isc.sans.edu/diary/Windows%20Malware%20with%20VHD%20Extension/29222
PyPi Packages Attempting to Deliver w4sp Stealer
https://blog.phylum.io/phylum-discovers-dozens-more-pypi-packages-attempting-to-deliver-w4sp-stealer-in-ongoing-supply-chain-attack
Breakpoints in Burp
https://isc.sans.edu/forums/diary/Breakpoints%20in%20Burp/29214/
TA569 Supply Chain Attack Injects JavaScript
https://twitter.com/threatinsight/status/1587865920130752515
https://www.darkreading.com/application-security/supply-chain-attack-pushes-out-malware-to-more-than-250-media-websites
Link to old story similar to the above JavaScript injection
https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/
Hitachi Infrastructure Analytics Advisor
https://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2022-134/index.html
FortiNet Patches
https://fortiguard.fortinet.com/psirt?date=11-2022
Nessus Patches
https://www.tenable.com/security/tns-2022-24
Breakpoints in Burp
https://isc.sans.edu/forums/diary/Breakpoints%20in%20Burp/29214/
TA569 Supply Chain Attack Injects JavaScript
https://twitter.com/threatinsight/status/1587865920130752515
https://www.darkreading.com/application-security/supply-chain-attack-pushes-out-malware-to-more-than-250-media-websites
Link to old story similar to the above JavaScript injection
https://unit42.paloaltonetworks.com/web-skimmer-video-distribution/
Hitachi Infrastructure Analytics Advisor
https://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2022-134/index.html
FortiNet Patches
https://fortiguard.fortinet.com/psirt?date=11-2022
Nessus Patches
https://www.tenable.com/security/tns-2022-24
Who Put the "Dark" in DarkVNC?
https://isc.sans.edu/forums/diary/Who+put+the+Dark+in+DarkVNC/29210
sigstore General Availability
https://openssf.org/press-release/2022/10/25/sigstore-announces-general-availability-at-sigstorecon/
https://github.blog/2022-10-25-why-were-excited-about-the-sigstore-general-availability/
URLScan.io's SOAR Spot: Chatty Security Tools Leaking Private Data
https://positive.security/blog/urlscan-data-leaks
Checkmk: Remote Code Execution by Chaining Multiple Bugs
https://blog.sonarsource.com/checkmk-rce-chain-1/
Who Put the "Dark" in DarkVNC?
https://isc.sans.edu/forums/diary/Who+put+the+Dark+in+DarkVNC/29210
sigstore General Availability
https://openssf.org/press-release/2022/10/25/sigstore-announces-general-availability-at-sigstorecon/
https://github.blog/2022-10-25-why-were-excited-about-the-sigstore-general-availability/
URLScan.io's SOAR Spot: Chatty Security Tools Leaking Private Data
https://positive.security/blog/urlscan-data-leaks
Checkmk: Remote Code Execution by Chaining Multiple Bugs
https://blog.sonarsource.com/checkmk-rce-chain-1/
OpenSSL 3.0 Punycode Vulnerability Fix
https://isc.sans.edu/forums/diary/Critical+OpenSSL+30+Update+Released+Patches+CVE20223786+CVE20223602/29208
https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/
OpenSSL 3.0 Punycode Vulnerability Fix
https://isc.sans.edu/forums/diary/Critical+OpenSSL+30+Update+Released+Patches+CVE20223786+CVE20223602/29208
https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/
NMAP without NMAP - Port Testing and Scanning with PowerShell
https://isc.sans.edu/diary/NMAP+without+NMAP+Port+Testing+and+Scanning+with+PowerShell/29202
ConnectWise Recover and R1Soft Server Backup Critical Vulnerability
https://www.connectwise.com/company/trust/security-bulletins/r1soft-and-recover-security-bulletin
Google Chrome 0-Day Patch
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html
LODEINFO 2022 Abusing Security Software
https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/
Spring Security Vulnerability
https://tanzu.vmware.com/security/cve-2022-31692
NMAP without NMAP - Port Testing and Scanning with PowerShell
https://isc.sans.edu/diary/NMAP+without+NMAP+Port+Testing+and+Scanning+with+PowerShell/29202
ConnectWise Recover and R1Soft Server Backup Critical Vulnerability
https://www.connectwise.com/company/trust/security-bulletins/r1soft-and-recover-security-bulletin
Google Chrome 0-Day Patch
https://chromereleases.googleblog.com/2022/10/stable-channel-update-for-desktop_27.html
LODEINFO 2022 Abusing Security Software
https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/
Spring Security Vulnerability
https://tanzu.vmware.com/security/cve-2022-31692
Supersizing you DUO and 365 Integration
https://isc.sans.edu/forums/diary/Supersizing%20your%20DUO%20and%20365%20Integration/29194/
TCP/IP Vulnerability CVE-2022 34718 PoC Restoration and Analysis
https://medium.com/numen-cyber-labs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf
Juniper SSLVON / JunOS RCE Vulnerabilities
https://octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/
Raspberry Robin Update
https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/
Supersizing you DUO and 365 Integration
https://isc.sans.edu/forums/diary/Supersizing%20your%20DUO%20and%20365%20Integration/29194/
TCP/IP Vulnerability CVE-2022 34718 PoC Restoration and Analysis
https://medium.com/numen-cyber-labs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf
Juniper SSLVON / JunOS RCE Vulnerabilities
https://octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/
Raspberry Robin Update
https://www.microsoft.com/en-us/security/blog/2022/10/27/raspberry-robin-worm-part-of-larger-ecosystem-facilitating-pre-ransomware-activity/
Upcoming Critical OpenSSL Vulnerability: What will be Affected?
https://isc.sans.edu/forums/diary/Upcoming+Critical+OpenSSL+Vulnerability+What+will+be+Affected/29192
Apple Updates
https://support.apple.com/en-us/HT201222
Fodcha Botnet Reaches 1Tbps
https://blog.netlab.360.com/ddosmonster_the_return_of__fodcha_cn/
https://www.bleepingcomputer.com/news/security/fodcha-ddos-botnet-reaches-1tbps-in-power-injects-ransoms-in-packets/
Upcoming Critical OpenSSL Vulnerability: What will be Affected?
https://isc.sans.edu/forums/diary/Upcoming+Critical+OpenSSL+Vulnerability+What+will+be+Affected/29192
Apple Updates
https://support.apple.com/en-us/HT201222
Fodcha Botnet Reaches 1Tbps
https://blog.netlab.360.com/ddosmonster_the_return_of__fodcha_cn/
https://www.bleepingcomputer.com/news/security/fodcha-ddos-botnet-reaches-1tbps-in-power-injects-ransoms-in-packets/
Why is My Cat Using Baidu And Other IoT DNS Oddities
https://isc.sans.edu/forums/diary/Why+is+My+Cat+Using+Baidu+And+Other+IoT+DNS+Oddities/29188
OpenSSL Critical Flaw to Be Patched
https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html
MacOS Ventura Blocks Security Tools
https://www.wired.com/story/apple-macos-ventura-bug-security-tools/
Critical VMWare Security Tools
https://www.vmware.com/security/advisories/VMSA-2022-0027.html
Why is My Cat Using Baidu And Other IoT DNS Oddities
https://isc.sans.edu/forums/diary/Why+is+My+Cat+Using+Baidu+And+Other+IoT+DNS+Oddities/29188
OpenSSL Critical Flaw to Be Patched
https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html
MacOS Ventura Blocks Security Tools
https://www.wired.com/story/apple-macos-ventura-bug-security-tools/
Critical VMWare Security Tools
https://www.vmware.com/security/advisories/VMSA-2022-0027.html
Massing Cryptomining Operation via Github Actions
https://sysdig.com/blog/massive-cryptomining-operation-github-actions/
Daixin Team Ransomware Targeting Healthcare Providers
https://www.ic3.gov/Media/News/2022/221021.pdf
Cisco Anyconnect Client Exploited in the Wild
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj
SQLite Vulnerability Details
https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/
Massing Cryptomining Operation via Github Actions
https://sysdig.com/blog/massive-cryptomining-operation-github-actions/
Daixin Team Ransomware Targeting Healthcare Providers
https://www.ic3.gov/Media/News/2022/221021.pdf
Cisco Anyconnect Client Exploited in the Wild
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-anyconnect-dll-F26WwJW
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ac-win-path-traverse-qO4HWBsj
SQLite Vulnerability Details
https://blog.trailofbits.com/2022/10/25/sqlite-vulnerability-july-2022-library-api/
C2 Communications Through Outlook.com
https://isc.sans.edu/forums/diary/C2+Communications+Through+outlookcom/29180
Apple Patches Everything October 2022 Edition
https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything%3A%20October%202022%20Edition/29182/
Cisco ISE Patch
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-Dz5dpzyM
Dormant Colors Live Campaign With Over 1m Data Stealing Extensions Installed
https://guardiosecurity.medium.com/dormant-colors-live-campaign-with-over-1m-data-stealing-extensions-installed-9a9a459b5849
C2 Communications Through Outlook.com
https://isc.sans.edu/forums/diary/C2+Communications+Through+outlookcom/29180
Apple Patches Everything October 2022 Edition
https://isc.sans.edu/forums/diary/Apple%20Patches%20Everything%3A%20October%202022%20Edition/29182/
Cisco ISE Patch
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-path-trav-Dz5dpzyM
Dormant Colors Live Campaign With Over 1m Data Stealing Extensions Installed
https://guardiosecurity.medium.com/dormant-colors-live-campaign-with-over-1m-data-stealing-extensions-installed-9a9a459b5849
Sczriptzzbn Inject Pushes Malware for NetSupport RAT
https://isc.sans.edu/forums/diary/sczriptzzbn%20inject%20pushes%20malware%20for%20NetSupport%20RAT/29170/
rtfdump find options
https://isc.sans.edu/forums/diary/rtfdumps+Find+Option/29174
Exploited Windows Zero Day Lets JavaScript Files Bypass Security Warnings
https://www.bleepingcomputer.com/news/security/exploited-windows-zero-day-lets-javascript-files-bypass-security-warnings/
A study of malicious CVE proof of concept exploits in GitHub
https://arxiv.org/pdf/2210.08374.pdf
F5 Patches
https://support.f5.com/csp/article/K11830089
https://support.f5.com/csp/article/K30425568
Synology Updates
https://www.synology.com/en-global/security/advisory/Synology_SA_22_17
Sczriptzzbn Inject Pushes Malware for NetSupport RAT
https://isc.sans.edu/forums/diary/sczriptzzbn%20inject%20pushes%20malware%20for%20NetSupport%20RAT/29170/
rtfdump find options
https://isc.sans.edu/forums/diary/rtfdumps+Find+Option/29174
Exploited Windows Zero Day Lets JavaScript Files Bypass Security Warnings
https://www.bleepingcomputer.com/news/security/exploited-windows-zero-day-lets-javascript-files-bypass-security-warnings/
A study of malicious CVE proof of concept exploits in GitHub
https://arxiv.org/pdf/2210.08374.pdf
F5 Patches
https://support.f5.com/csp/article/K11830089
https://support.f5.com/csp/article/K30425568
Synology Updates
https://www.synology.com/en-global/security/advisory/Synology_SA_22_17
Forensic Value of Prefetch
https://isc.sans.edu/forums/diary/Forensic%20Value%20of%20Prefetch/29168/
Microsoft TLS Fix
https://support.microsoft.com/en-us/topic/october-17-2022-kb5020435-os-builds-19042-2132-19043-2132-and-19044-2132-out-of-band-243f34de-2f44-4015-a224-1b68a4132ca5
CISA Releases ScubaGear to Audit M365
https://github.com/cisagov/ScubaGear
HTTP/3 Connection Contamination
https://portswigger.net/research/http-3-connection-contamination
Forensic Value of Prefetch
https://isc.sans.edu/forums/diary/Forensic%20Value%20of%20Prefetch/29168/
Microsoft TLS Fix
https://support.microsoft.com/en-us/topic/october-17-2022-kb5020435-os-builds-19042-2132-19043-2132-and-19044-2132-out-of-band-243f34de-2f44-4015-a224-1b68a4132ca5
CISA Releases ScubaGear to Audit M365
https://github.com/cisagov/ScubaGear
HTTP/3 Connection Contamination
https://portswigger.net/research/http-3-connection-contamination
Are Internet Scanning Services Good or Bad for You?
https://isc.sans.edu/forums/diary/Are+Internet+Scanning+Services+Good+or+Bad+for+You/29164
FBI Warns of Student Loan Foregiveness Scams
https://www.ic3.gov/Media/Y2022/PSA221018
Fully Undetectable Powershell Backdoor
https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor/
Are Internet Scanning Services Good or Bad for You?
https://isc.sans.edu/forums/diary/Are+Internet+Scanning+Services+Good+or+Bad+for+You/29164
FBI Warns of Student Loan Foregiveness Scams
https://www.ic3.gov/Media/Y2022/PSA221018
Fully Undetectable Powershell Backdoor
https://www.safebreach.com/resources/blog/safebreach-labs-researchers-uncover-new-fully-undetectable-powershell-backdoor/
Python Obfuscation for Dummies
https://isc.sans.edu/forums/diary/Python%20Obfuscation%20for%20Dummies/29160/
Oracle October 2022 Critical Patch Update
https://www.oracle.com/security-alerts/cpuoct2022.html
Weak Encryption in Microsoft Office 365
https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation
Tesla 3 Hack
https://www.synacktiv.com/sites/default/files/2022-10/tesla_hexacon.pdf
Python Obfuscation for Dummies
https://isc.sans.edu/forums/diary/Python%20Obfuscation%20for%20Dummies/29160/
Oracle October 2022 Critical Patch Update
https://www.oracle.com/security-alerts/cpuoct2022.html
Weak Encryption in Microsoft Office 365
https://labs.withsecure.com/advisories/microsoft-office-365-message-encryption-insecure-mode-of-operation
Tesla 3 Hack
https://www.synacktiv.com/sites/default/files/2022-10/tesla_hexacon.pdf
Fileless Powershell Dropper
https://isc.sans.edu/forums/diary/Fileless%20Powershell%20Dropper/29156/
Apache Commons Text Vulnerablity
https://www.openwall.com/lists/oss-security/2022/10/13/4
How a Microsoft Blunder Opened Millions of PCs to Potent Malware Attacks
https://arstechnica.com/information-technology/2022/10/how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks/
Fileless Powershell Dropper
https://isc.sans.edu/forums/diary/Fileless%20Powershell%20Dropper/29156/
Apache Commons Text Vulnerablity
https://www.openwall.com/lists/oss-security/2022/10/13/4
How a Microsoft Blunder Opened Millions of PCs to Potent Malware Attacks
https://arstechnica.com/information-technology/2022/10/how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks/
Horizon3 Publishes FortiOS Vulnerablity Details and Exploit
https://www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/
More Exchange Vulnerability Workaround Bypasses
https://twitter.com/wdormann/status/1576922677675102208
Analysis of a Malicious HTML File and QBot
https://isc.sans.edu/forums/diary/Analysis+of+a+Malicious+HTML+File+QBot/29146
End of Life VMWare ESXi Versions
https://www.lansweeper.com/eol/vmware-esxi-end-of-life/
Horizon3 Publishes FortiOS Vulnerablity Details and Exploit
https://www.horizon3.ai/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684/
More Exchange Vulnerability Workaround Bypasses
https://twitter.com/wdormann/status/1576922677675102208
Analysis of a Malicious HTML File and QBot
https://isc.sans.edu/forums/diary/Analysis+of+a+Malicious+HTML+File+QBot/29146
End of Life VMWare ESXi Versions
https://www.lansweeper.com/eol/vmware-esxi-end-of-life/
Alchimist Offensive Framework
https://blog.talosintelligence.com/2022/10/alchimist-offensive-framework.html#more
VM2 Sandbox Vulnerability
https://www.oxeye.io/blog/vm2-sandbreak-vulnerability-cve-2022-36067
private npm package disclosure
https://blog.aquasec.com/private-packages-disclosed-via-timing-attack-on-npm
Zimbra Updates
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P27#Security_Fixes
Alchimist Offensive Framework
https://blog.talosintelligence.com/2022/10/alchimist-offensive-framework.html#more
VM2 Sandbox Vulnerability
https://www.oxeye.io/blog/vm2-sandbreak-vulnerability-cve-2022-36067
private npm package disclosure
https://blog.aquasec.com/private-packages-disclosed-via-timing-attack-on-npm
Zimbra Updates
https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P27#Security_Fixes
Adobe October Patch Tuesday
https://helpx.adobe.com/sa_en/security/security-bulletin.html
Fortinet Guidance
https://www.horizon3.ai/fortinet-iocs-cve-2022-40684/
https://isc.sans.edu/forums/diary/Scans+for+old+Fortigate+Vulnerability+Building+Target+Lists/29142
Android VPN Issues
https://mullvad.net/en/blog/2022/10/10/android-leaks-connectivity-check-traffic/
iOS VPN Issues
https://9to5mac.com/2022/10/12/ios-vpn-apps-2/
Aruba Patches
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-015.txt
Adobe October Patch Tuesday
https://helpx.adobe.com/sa_en/security/security-bulletin.html
Fortinet Guidance
https://www.horizon3.ai/fortinet-iocs-cve-2022-40684/
https://isc.sans.edu/forums/diary/Scans+for+old+Fortigate+Vulnerability+Building+Target+Lists/29142
Android VPN Issues
https://mullvad.net/en/blog/2022/10/10/android-leaks-connectivity-check-traffic/
iOS VPN Issues
https://9to5mac.com/2022/10/12/ios-vpn-apps-2/
Aruba Patches
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-015.txt
Microsoft October 2022 Patches
https://isc.sans.edu/forums/diary/October%202022%20Microsoft%20Patch%20Tuesday/29138/
SAP Patchday
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
Top CVEs Actively Exploited By People s Republic of China State-Sponsored Cyber Actors
https://www.cisa.gov/uscert/ncas/alerts/aa22-279a
Microsoft October 2022 Patches
https://isc.sans.edu/forums/diary/October%202022%20Microsoft%20Patch%20Tuesday/29138/
SAP Patchday
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
Top CVEs Actively Exploited By People s Republic of China State-Sponsored Cyber Actors
https://www.cisa.gov/uscert/ncas/alerts/aa22-279a
Wireshark Display Filter Update
https://isc.sans.edu/forums/diary/Wireshark+Specifying+a+Protocol+Stack+Layer+in+Display+Filters/29130
Fortinet Vulnerablity Update
https://twitter.com/Horizon3Attack/status/1579285863108087810
BazarCall Social Engineering Tactics
https://www.trellix.com/en-us/about/newsroom/stories/research/evolution-of-bazarcall-social-engineering-tactics.html
RPKI Rate Limiting
https://www.usenix.org/system/files/sec22-hlavacek.pdf
Wireshark Display Filter Update
https://isc.sans.edu/forums/diary/Wireshark+Specifying+a+Protocol+Stack+Layer+in+Display+Filters/29130
Fortinet Vulnerablity Update
https://twitter.com/Horizon3Attack/status/1579285863108087810
BazarCall Social Engineering Tactics
https://www.trellix.com/en-us/about/newsroom/stories/research/evolution-of-bazarcall-social-engineering-tactics.html
RPKI Rate Limiting
https://www.usenix.org/system/files/sec22-hlavacek.pdf
Fortinet Update
https://docs.fortinet.com/document/fortigate/7.2.2/fortios-release-notes/760203/introduction-and-supported-models
Zimbra Vulnerability
https://twitter.com/iagox86/status/1578084484720734209
https://attackerkb.com/topics/1DDTvUNFzH/cve-2022-41352/rapid7-analysis?referrer=activityFeed
Microsoft Exchange Workaround Improved Again
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
Ikea Smart Bulb Exploit
https://www.synopsys.com/blogs/software-security/cyrc-advisory-ikea-tradfri-smart-lighting/
Fortinet Update
https://docs.fortinet.com/document/fortigate/7.2.2/fortios-release-notes/760203/introduction-and-supported-models
Zimbra Vulnerability
https://twitter.com/iagox86/status/1578084484720734209
https://attackerkb.com/topics/1DDTvUNFzH/cve-2022-41352/rapid7-analysis?referrer=activityFeed
Microsoft Exchange Workaround Improved Again
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
Ikea Smart Bulb Exploit
https://www.synopsys.com/blogs/software-security/cyrc-advisory-ikea-tradfri-smart-lighting/
Infosec Calendar
https://isc.sans.edu/forums/diary/What+is+in+your+Infosec+Calendar/29118
OnionPoison: infected Tor Browser installer distributed through popular YouTube channel
https://securelist.com/onionpoison-infected-tor-browser-installer-youtube/107627/
MacOS Architve Utility Vulnerability Details
https://www.jamf.com/blog/jamf-threat-labs-macos-archive-utility-vulnerability/
Infosec Calendar
https://isc.sans.edu/forums/diary/What+is+in+your+Infosec+Calendar/29118
OnionPoison: infected Tor Browser installer distributed through popular YouTube channel
https://securelist.com/onionpoison-infected-tor-browser-installer-youtube/107627/
MacOS Architve Utility Vulnerability Details
https://www.jamf.com/blog/jamf-threat-labs-macos-archive-utility-vulnerability/
Credential Harvesting with Telegram
https://isc.sans.edu/forums/diary/Credential%20Harvesting%20with%20Telegram%20API/29112/
Updated Microsoft Exchange Fix
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
Impacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization
https://www.cisa.gov/uscert/ncas/alerts/aa22-277a
A New Supply Chain Attack on PHP
https://blog.sonarsource.com/securing-developer-tools-a-new-supply-chain-attack-on-php/
Credential Harvesting with Telegram
https://isc.sans.edu/forums/diary/Credential%20Harvesting%20with%20Telegram%20API/29112/
Updated Microsoft Exchange Fix
https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
Impacket and Exfiltration Tool Used to Steal Sensitive Information from Defense Industrial Base Organization
https://www.cisa.gov/uscert/ncas/alerts/aa22-277a
A New Supply Chain Attack on PHP
https://blog.sonarsource.com/securing-developer-tools-a-new-supply-chain-attack-on-php/
Microsoft Exchange Vulnerability Fix Bypassed
https://twitter.com/testanull/status/1576774007826718720
Schneider Electric UMAS Patch Bypass
https://securelist.com/the-secrets-of-schneider-electrics-umas-protocol/107435/
Supply Chain Attack via Trojanized Comm100 Chat Installer
https://www.crowdstrike.com/blog/new-supply-chain-attack-leverages-comm100-chat-installer/
Microsoft Exchange Vulnerability Fix Bypassed
https://twitter.com/testanull/status/1576774007826718720
Schneider Electric UMAS Patch Bypass
https://securelist.com/the-secrets-of-schneider-electrics-umas-protocol/107435/
Supply Chain Attack via Trojanized Comm100 Chat Installer
https://www.crowdstrike.com/blog/new-supply-chain-attack-leverages-comm100-chat-installer/
Microsoft Exchange 0-Day Update
https://isc.sans.edu/forums/diary/Exchange+Server+0Day+Actively+Exploited/29106
https://microsoft.github.io/CSS-Exchange/Security/EOMTv2/
CISA Adds Atlasian Bitbucket Vulnerability to Exploited List
https://www.cisa.gov/uscert/ncas/current-activity/2022/09/30/cisa-adds-three-known-exploited-vulnerabilities-catalog
Every unsandboxed app has Full Disk Access if Terminal Does
https://lapcatsoftware.com/articles/FullDiskAccess.html
Microsoft Exchange 0-Day Update
https://isc.sans.edu/forums/diary/Exchange+Server+0Day+Actively+Exploited/29106
https://microsoft.github.io/CSS-Exchange/Security/EOMTv2/
CISA Adds Atlasian Bitbucket Vulnerability to Exploited List
https://www.cisa.gov/uscert/ncas/current-activity/2022/09/30/cisa-adds-three-known-exploited-vulnerabilities-catalog
Every unsandboxed app has Full Disk Access if Terminal Does
https://lapcatsoftware.com/articles/FullDiskAccess.html
PNG Analysis with pngdump.py
https://isc.sans.edu/forums/diary/PNG%20Analysis/29100/
Possible Exchange Server 0-Day Vulnerability
https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html
https://success.trendmicro.com/dcx/s/solution/000291651?language=en_US
Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors
https://www.mandiant.com/resources/blog/esxi-hypervisors-malware-persistence
PNG Analysis with pngdump.py
https://isc.sans.edu/forums/diary/PNG%20Analysis/29100/
Possible Exchange Server 0-Day Vulnerability
https://www.gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html
https://success.trendmicro.com/dcx/s/solution/000291651?language=en_US
Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors
https://www.mandiant.com/resources/blog/esxi-hypervisors-malware-persistence
10 Years Later: Attacker re-discovering old VTiger CRM Vulnerability
https://isc.sans.edu/forums/diary/10+Years+Later+Attacker+rediscovering+old+VTiger+CRM+Vulnerability/29098
IRS Reports Significant Increase in Texting Scams
https://www.irs.gov/newsroom/irs-reports-significant-increase-in-texting-scams-warns-taxpayers-to-remain-vigilant
Cloudflare Releases Turnsitle, a user-friendly, privacy-preserving CAPTCHA alternative
https://blog.cloudflare.com/turnstile-private-captcha-alternative/
Cisco Patches
https://kb.cert.org/vuls/id/855201
Chrome 106 Release
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html?m=1
10 Years Later: Attacker re-discovering old VTiger CRM Vulnerability
https://isc.sans.edu/forums/diary/10+Years+Later+Attacker+rediscovering+old+VTiger+CRM+Vulnerability/29098
IRS Reports Significant Increase in Texting Scams
https://www.irs.gov/newsroom/irs-reports-significant-increase-in-texting-scams-warns-taxpayers-to-remain-vigilant
Cloudflare Releases Turnsitle, a user-friendly, privacy-preserving CAPTCHA alternative
https://blog.cloudflare.com/turnstile-private-captcha-alternative/
Cisco Patches
https://kb.cert.org/vuls/id/855201
Chrome 106 Release
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop_27.html?m=1
DNS Option 15 and Debugging DNSSEC Errors
https://isc.sans.edu/forums/diary/DNS+Option+15+Debugging+DNSSEC+Errors/29094
Yari: A New Era of Yara Debugging
https://engineering.avast.io/yari-a-new-era-of-yara-debugging/
HTTP Archive Almanac
https://almanac.httparchive.org/en/2022/security
DNS Option 15 and Debugging DNSSEC Errors
https://isc.sans.edu/forums/diary/DNS+Option+15+Debugging+DNSSEC+Errors/29094
Yari: A New Era of Yara Debugging
https://engineering.avast.io/yari-a-new-era-of-yara-debugging/
HTTP Archive Almanac
https://almanac.httparchive.org/en/2022/security
Easy Python Sandbox Detection
https://isc.sans.edu/forums/diary/Easy+Python+Sandbox+Detection/29090
Hackers use PowerPoint Files for "Mouseover" Malware Delivery
https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/
Redis 7.0 XAUTOCLAIM Heap Overflow
https://github.com/redis/redis/security/advisories/GHSA-5gc4-76rx-22c9
Scoreboard Hacking
https://maxwelldulin.com/BlogPost?post=7118102528
Easy Python Sandbox Detection
https://isc.sans.edu/forums/diary/Easy+Python+Sandbox+Detection/29090
Hackers use PowerPoint Files for "Mouseover" Malware Delivery
https://blog.cluster25.duskrise.com/2022/09/23/in-the-footsteps-of-the-fancy-bear-powerpoint-graphite/
Redis 7.0 XAUTOCLAIM Heap Overflow
https://github.com/redis/redis/security/advisories/GHSA-5gc4-76rx-22c9
Scoreboard Hacking
https://maxwelldulin.com/BlogPost?post=7118102528
Kids Like Cookies and Malware Likes them Too
https://isc.sans.edu/forums/diary/Kids+Like+Cookies+Malware+Too/29082
Downloading Files from Removed Domains
https://isc.sans.edu/forums/diary/Downloading%20Samples%20From%20Takendown%20Domains/29086/
WhatsApp Security Updates
https://www.whatsapp.com/security/advisories/2022/
Sophos RCE Flaw
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce
CircleCI Phishing Attacks Used to Access GitHub Accounts
https://discuss.circleci.com/t/circleci-security-alert-warning-phishing-attempt-for-login-credentials/45408
Kids Like Cookies and Malware Likes them Too
https://isc.sans.edu/forums/diary/Kids+Like+Cookies+Malware+Too/29082
Downloading Files from Removed Domains
https://isc.sans.edu/forums/diary/Downloading%20Samples%20From%20Takendown%20Domains/29086/
WhatsApp Security Updates
https://www.whatsapp.com/security/advisories/2022/
Sophos RCE Flaw
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220923-sfos-rce
CircleCI Phishing Attacks Used to Access GitHub Accounts
https://discuss.circleci.com/t/circleci-security-alert-warning-phishing-attempt-for-login-credentials/45408
RAT Delivered Through FODHelper
https://isc.sans.edu/forums/diary/RAT+Delivered+Through+FODHelper/29078
Microsoft Endpoint Configuration Manager Spoofing Vulnerability
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-37972
New Fuzzing Tool: cifuzz
https://github.com/CodeIntelligenceTesting/cifuzz
No Security Updates from Apple
https://support.apple.com/en-us/HT201222
RAT Delivered Through FODHelper
https://isc.sans.edu/forums/diary/RAT+Delivered+Through+FODHelper/29078
Microsoft Endpoint Configuration Manager Spoofing Vulnerability
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-37972
New Fuzzing Tool: cifuzz
https://github.com/CodeIntelligenceTesting/cifuzz
No Security Updates from Apple
https://support.apple.com/en-us/HT201222
Phishing Campaigns Use Free Only Resources
https://isc.sans.edu/forums/diary/Phishing%20Campaigns%20Use%20Free%20Online%20Resources/29074/
Insecure use of tarfile.extract in Python
https://bugs.python.org/issue1044#msg55464
Twitter Failed to Logout Users After Password Reset
https://privacy.twitter.com/en/blog/2022/an-issue-impacting-password-resets
Phishing Campaigns Use Free Only Resources
https://isc.sans.edu/forums/diary/Phishing%20Campaigns%20Use%20Free%20Online%20Resources/29074/
Insecure use of tarfile.extract in Python
https://bugs.python.org/issue1044#msg55464
Twitter Failed to Logout Users After Password Reset
https://privacy.twitter.com/en/blog/2022/an-issue-impacting-password-resets
Chainsaw: Hunt, search and extract event log records
https://isc.sans.edu/diary/Chainsaw%3A+Hunt%2C+search%2C+and+extract+event+log+records/29066
PDU Exploits past NAT
https://claroty.com/team82/research/jumping-nat-to-shut-down-electric-devices
Tamper Protection will be turned on for all Enterprise Customers
https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/tamper-protection-will-be-turned-on-for-all-enterprise-customers/ba-p/3616478
Chainsaw: Hunt, search and extract event log records
https://isc.sans.edu/diary/Chainsaw%3A+Hunt%2C+search%2C+and+extract+event+log+records/29066
PDU Exploits past NAT
https://claroty.com/team82/research/jumping-nat-to-shut-down-electric-devices
Tamper Protection will be turned on for all Enterprise Customers
https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/tamper-protection-will-be-turned-on-for-all-enterprise-customers/ba-p/3616478
Preventing ISO Malware
https://isc.sans.edu/diary/Preventing+ISO+Malware+/29062
State of Emotet
https://www.advintel.io/post/advintel-s-state-of-emotet-aka-spmtools-displays-over-million-compromised-machines-through-2022
Undermining Microsoft Teams Security by Mining Tokens
https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens
Preventing ISO Malware
https://isc.sans.edu/diary/Preventing+ISO+Malware+/29062
State of Emotet
https://www.advintel.io/post/advintel-s-state-of-emotet-aka-spmtools-displays-over-million-compromised-machines-through-2022
Undermining Microsoft Teams Security by Mining Tokens
https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens
Word Maldoc With CustomXML and Renamed VBAProject.bin
https://isc.sans.edu/diary/Word+Maldoc+With+CustomXML+and+Renamed+VBAProject.bin/29056
2FA on Lock Screens
https://www.bbc.com/news/uk-england-london-62809151
Chrome and Edge Enhances Spellcheck Features Expose PII, Even Your Password
https://www.otto-js.com/news/article/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords
Reconstructing Content Reflected in Glasses
https://arxiv.org/abs/2205.03971
Word Maldoc With CustomXML and Renamed VBAProject.bin
https://isc.sans.edu/diary/Word+Maldoc+With+CustomXML+and+Renamed+VBAProject.bin/29056
2FA on Lock Screens
https://www.bbc.com/news/uk-england-london-62809151
Chrome and Edge Enhances Spellcheck Features Expose PII, Even Your Password
https://www.otto-js.com/news/article/chrome-and-edge-enhanced-spellcheck-features-expose-pii-even-your-passwords
Reconstructing Content Reflected in Glasses
https://arxiv.org/abs/2205.03971
Malicous Word Document With a Frameset
https://isc.sans.edu/diary/Malicious+Word+Document+with+a+Frameset/29052
CVE-2022-34721 Exploit
https://github.com/78ResearchLab/PoC/tree/main/CVE-2022-34721
Trojaned Putty Used in Attacks
https://www.mandiant.com/resources/blog/dprk-whatsapp-phishing
Lenovo BIOS Updates
https://support.lenovo.com/us/en/product_security/LEN-94953#Desktop
Malicous Word Document With a Frameset
https://isc.sans.edu/diary/Malicious+Word+Document+with+a+Frameset/29052
CVE-2022-34721 Exploit
https://github.com/78ResearchLab/PoC/tree/main/CVE-2022-34721
Trojaned Putty Used in Attacks
https://www.mandiant.com/resources/blog/dprk-whatsapp-phishing
Lenovo BIOS Updates
https://support.lenovo.com/us/en/product_security/LEN-94953#Desktop
Easy Process Injection within Python
https://isc.sans.edu/diary/Easy+Process+Injection+within+Python/29048
Queen Elizabeth Related Phishing
https://twitter.com/threatinsight/status/1570092339984584705
Microsoft 365 Auto Updates Apps on Locked or Idle Devices
https://techcommunity.microsoft.com/t5/microsoft-365-blog/update-under-lock-improved-update-experience-for-microsoft-365/ba-p/3618901
Easy Process Injection within Python
https://isc.sans.edu/diary/Easy+Process+Injection+within+Python/29048
Queen Elizabeth Related Phishing
https://twitter.com/threatinsight/status/1570092339984584705
Microsoft 365 Auto Updates Apps on Locked or Idle Devices
https://techcommunity.microsoft.com/t5/microsoft-365-blog/update-under-lock-improved-update-experience-for-microsoft-365/ba-p/3618901
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+September+2022+Patch+Tuesday/29044/
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Magento Vendor Fishpig Hacked, Backdoors Added
https://sansec.io/research/rekoobe-fishpig-magento
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+September+2022+Patch+Tuesday/29044/
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Magento Vendor Fishpig Hacked, Backdoors Added
https://sansec.io/research/rekoobe-fishpig-magento
VirusTotal Result Comparisons for Honeypot Malware
https://isc.sans.edu/diary/VirusTotal+Result+Comparisons+for+Honeypot+Malware/29040
Apple Patches
https://support.apple.com/en-us/HT201222
Lorenz Ransomware Group Cracks MiVoice and Calls Back For Free
https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in/
VirusTotal Result Comparisons for Honeypot Malware
https://isc.sans.edu/diary/VirusTotal+Result+Comparisons+for+Honeypot+Malware/29040
Apple Patches
https://support.apple.com/en-us/HT201222
Lorenz Ransomware Group Cracks MiVoice and Calls Back For Free
https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in/
Malware Abusing File Exchange Site
https://isc.sans.edu/diary/Phishing+Word+Documents+with+Suspicious+URL/29034
Bypassing GitHub Required Reviewers to Submit Malicious Code
https://www.legitsecurity.com/blog/bypassing-github-required-reviewers-to-submit-malicious-code
Crimeware Trends: Ransomware Developers Turn to Intermittent Encryption
https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection/
Lets Encrypt Reviving Certificate Revocation Lists
https://letsencrypt.org/2022/09/07/new-life-for-crls.html
Malware Abusing File Exchange Site
https://isc.sans.edu/diary/Phishing+Word+Documents+with+Suspicious+URL/29034
Bypassing GitHub Required Reviewers to Submit Malicious Code
https://www.legitsecurity.com/blog/bypassing-github-required-reviewers-to-submit-malicious-code
Crimeware Trends: Ransomware Developers Turn to Intermittent Encryption
https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection/
Lets Encrypt Reviving Certificate Revocation Lists
https://letsencrypt.org/2022/09/07/new-life-for-crls.html
Analyzing Obfuscated VBS with CyberChef
https://isc.sans.edu/diary/Analyzing+Obfuscated+VBS+with+CyberChef/2902
pfBlockerNG Unauthenticated RCE
https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/
GifShell attack creates reverse shell using microsoft teams gifs
https://www.bleepingcomputer.com/news/security/gifshell-attack-creates-reverse-shell-using-microsoft-teams-gifs/
Analyzing Obfuscated VBS with CyberChef
https://isc.sans.edu/diary/Analyzing+Obfuscated+VBS+with+CyberChef/2902
pfBlockerNG Unauthenticated RCE
https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/
GifShell attack creates reverse shell using microsoft teams gifs
https://www.bleepingcomputer.com/news/security/gifshell-attack-creates-reverse-shell-using-microsoft-teams-gifs/
PHP Deserialization Exploit Attempt
https://isc.sans.edu/diary/PHP+Deserialization+Exploit+attempt/29024
TA505 Group's TeslaGun In-Depth Analysis
https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis
Cisco publishes unpatched Small Business Router Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-vpnbypass-Cpheup9O
Shikitega - New stealthy malware targeting Linux
https://thehackernews.com/2022/09/new-stealthy-shikitega-malware.html
PHP Deserialization Exploit Attempt
https://isc.sans.edu/diary/PHP+Deserialization+Exploit+attempt/29024
TA505 Group's TeslaGun In-Depth Analysis
https://www.prodaft.com/resource/detail/ta505-ta505-groups-tesla-gun-depth-analysis
Cisco publishes unpatched Small Business Router Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv-vpnbypass-Cpheup9O
Shikitega - New stealthy malware targeting Linux
https://thehackernews.com/2022/09/new-stealthy-shikitega-malware.html
Analysis of an Encoded Cobalt Strike Beacon
https://isc.sans.edu/diary/Analysis+of+an+Encoded+Cobalt+Strike+Beacon/29014
EvilProxy Phishing-As-A-Service with MFA Bypass
https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web
Zyxel Patches RCE Vulnerability
https://www.zyxel.com/support/Zyxel-security-advisory-for-format-string-vulnerability-in-NAS.shtml
Moobot Going after D-Link Devices
https://unit42.paloaltonetworks.com/moobot-d-link-devices/
Analysis of an Encoded Cobalt Strike Beacon
https://isc.sans.edu/diary/Analysis+of+an+Encoded+Cobalt+Strike+Beacon/29014
EvilProxy Phishing-As-A-Service with MFA Bypass
https://resecurity.com/blog/article/evilproxy-phishing-as-a-service-with-mfa-bypass-emerged-in-dark-web
Zyxel Patches RCE Vulnerability
https://www.zyxel.com/support/Zyxel-security-advisory-for-format-string-vulnerability-in-NAS.shtml
Moobot Going after D-Link Devices
https://unit42.paloaltonetworks.com/moobot-d-link-devices/
James Webb JPEG With Malware
https://isc.sans.edu/diary/James+Webb+JPEG+With+Malware/29010
Windows Defender False Positive
https://www.theregister.com/2022/09/05/windows_defender_chrome_false_positive/
Google Chrome 0-Day
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html
Sharkbot Android Infostealer in Google Play Store
https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play/
Nmap 7.93 - 25th Anniversary Release
https://seclists.org/nmap-announce/2022/1
James Webb JPEG With Malware
https://isc.sans.edu/diary/James+Webb+JPEG+With+Malware/29010
Windows Defender False Positive
https://www.theregister.com/2022/09/05/windows_defender_chrome_false_positive/
Google Chrome 0-Day
https://chromereleases.googleblog.com/2022/09/stable-channel-update-for-desktop.html
Sharkbot Android Infostealer in Google Play Store
https://blog.fox-it.com/2022/09/02/sharkbot-is-back-in-google-play/
Nmap 7.93 - 25th Anniversary Release
https://seclists.org/nmap-announce/2022/1
Jolokie Scans: Possible Hunt for Vulnerable Apache Geode Servers
https://isc.sans.edu/diary/Jolokia+Scans%3A+Possible+Hunt+for+Vulnerable+Apache+Geode+Servers+%28CVE-2022-37021%29/29006
Microsoft Basic Authentication Deprecation in Exchange Online
https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-deprecation-in-exchange-online-september/ba-p/3609437
Mobile App Supply Chain Vulnerabilities Could Endanger Sensitive Business Information
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mobile-supply-chain-aws
Gitlab Update
https://about.gitlab.com/releases/2022/08/30/critical-security-release-gitlab-15-3-2-released/#brute-force-attack-may-guess-a-password-even-when-2fa-is-enabled
Jolokie Scans: Possible Hunt for Vulnerable Apache Geode Servers
https://isc.sans.edu/diary/Jolokia+Scans%3A+Possible+Hunt+for+Vulnerable+Apache+Geode+Servers+%28CVE-2022-37021%29/29006
Microsoft Basic Authentication Deprecation in Exchange Online
https://techcommunity.microsoft.com/t5/exchange-team-blog/basic-authentication-deprecation-in-exchange-online-september/ba-p/3609437
Mobile App Supply Chain Vulnerabilities Could Endanger Sensitive Business Information
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/mobile-supply-chain-aws
Gitlab Update
https://about.gitlab.com/releases/2022/08/30/critical-security-release-gitlab-15-3-2-released/#brute-force-attack-may-guess-a-password-even-when-2fa-is-enabled
Underscores and DNS: The Privacy Story
https://isc.sans.edu/diary/Underscores+and+DNS%3A+The+Privacy+Story/29002
iOS 12.5.6 Update
https://support.apple.com/en-us/HT201222
Malware Disguised as Google Translate Desktop App
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications/
Apache Geode Deserialization Flaw
https://lists.apache.org/thread/qrvhmytsshsk5xcb68pwccw3y6m8o8nr
Foxit PDF Reader Update
https://sec-consult.com/vulnerability-lab/advisory/outdated-javascript-engine-leads-to-rce-in-foxit-pdf-reader/
Underscores and DNS: The Privacy Story
https://isc.sans.edu/diary/Underscores+and+DNS%3A+The+Privacy+Story/29002
iOS 12.5.6 Update
https://support.apple.com/en-us/HT201222
Malware Disguised as Google Translate Desktop App
https://research.checkpoint.com/2022/check-point-research-detects-crypto-miner-malware-disguised-as-google-translate-desktop-and-other-legitimate-applications/
Apache Geode Deserialization Flaw
https://lists.apache.org/thread/qrvhmytsshsk5xcb68pwccw3y6m8o8nr
Foxit PDF Reader Update
https://sec-consult.com/vulnerability-lab/advisory/outdated-javascript-engine-leads-to-rce-in-foxit-pdf-reader/
Two things that will never die: bash scripts and irc
https://isc.sans.edu/diary/Two+things+that+will+never+die%3A+bash+scripts+and+IRC%21/28998
Malware using James Webb Telescope images
https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems/
Malicious Chrome Extensions
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-cookie-stuffing-chrome-extensions-with-1-4-million-users/
Chromium Based Browsers Allow Access to Clipboard
https://bugs.chromium.org/p/chromium/issues/detail?id=1334203
Two things that will never die: bash scripts and irc
https://isc.sans.edu/diary/Two+things+that+will+never+die%3A+bash+scripts+and+IRC%21/28998
Malware using James Webb Telescope images
https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems/
Malicious Chrome Extensions
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/malicious-cookie-stuffing-chrome-extensions-with-1-4-million-users/
Chromium Based Browsers Allow Access to Clipboard
https://bugs.chromium.org/p/chromium/issues/detail?id=1334203
Update: VBA Malcode & UTF7 (APT-C-35)
https://isc.sans.edu/diary/Update%3A+VBA+Maldoc+%26+UTF7+%28APT-C-35%29/28994
Twilio Breach used to access 2FA Tokens
https://sec.okta.com/scatterswine
Popular PDF Reader Adware
https://www.malwarebytes.com/blog/news/2022/08/adware-found-on-google-play-pdf-reader-servicing-up-full-screen-ads
Google changing its VPN Ad Blocker Policy
https://support.google.com/googleplay/android-developer/answer/12253906?hl=en
Update: VBA Malcode & UTF7 (APT-C-35)
https://isc.sans.edu/diary/Update%3A+VBA+Maldoc+%26+UTF7+%28APT-C-35%29/28994
Twilio Breach used to access 2FA Tokens
https://sec.okta.com/scatterswine
Popular PDF Reader Adware
https://www.malwarebytes.com/blog/news/2022/08/adware-found-on-google-play-pdf-reader-servicing-up-full-screen-ads
Google changing its VPN Ad Blocker Policy
https://support.google.com/googleplay/android-developer/answer/12253906?hl=en
Dealing With False Positives when Scanning Memory Dumps for Cobalt Strike Beacons
https://isc.sans.edu/diary/Dealing+With+False+Positives+when+Scanning+Memory+Dumps+for+Cobalt+Strike+Beacons/28990
HTTP2 Packet Analysis with Wireshark
https://isc.sans.edu/diary/HTTP2+Packet+Analysis+with+Wireshark/28986
Paypal Phishing/Coinbase in One Image
https://isc.sans.edu/diary/Paypal+PhishingCoinbase+in+One+Image/28984
Sysinternals Updates: Sysmon v14.0 and ZoomIt v6.01
https://isc.sans.edu/diary/Sysinternals+Updates%3A+Sysmon+v14.0+and+ZoomIt+v6.01/28988
eth.link domain at risk
https://www.coindesk.com/tech/2022/08/26/web3-domain-name-service-could-lose-its-web-address-because-programmer-who-can-renew-it-sits-in-jail/
Dealing With False Positives when Scanning Memory Dumps for Cobalt Strike Beacons
https://isc.sans.edu/diary/Dealing+With+False+Positives+when+Scanning+Memory+Dumps+for+Cobalt+Strike+Beacons/28990
HTTP2 Packet Analysis with Wireshark
https://isc.sans.edu/diary/HTTP2+Packet+Analysis+with+Wireshark/28986
Paypal Phishing/Coinbase in One Image
https://isc.sans.edu/diary/Paypal+PhishingCoinbase+in+One+Image/28984
Sysinternals Updates: Sysmon v14.0 and ZoomIt v6.01
https://isc.sans.edu/diary/Sysinternals+Updates%3A+Sysmon+v14.0+and+ZoomIt+v6.01/28988
eth.link domain at risk
https://www.coindesk.com/tech/2022/08/26/web3-domain-name-service-could-lose-its-web-address-because-programmer-who-can-renew-it-sits-in-jail/
Taking Apart URL Shorteners
https://isc.sans.edu/diary/Taking+Apart+URL+Shorteners/28980
Python Developers Phished for PyPi Credentials
https://twitter.com/pypi/status/1562442188285308929
Group IB Connects Twilio and Cloudflare Phishing attacks to others
https://www.helpnetsecurity.com/2022/08/25/0ktapus-twilio-cloudflare-phishers-targets/
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
LastPass Security Incident
https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/
Bitbucket Vulnerability
https://securityonline.info/cve-2022-36804-bitbucket-server-and-data-center-command-injection-vulnerability/
Taking Apart URL Shorteners
https://isc.sans.edu/diary/Taking+Apart+URL+Shorteners/28980
Python Developers Phished for PyPi Credentials
https://twitter.com/pypi/status/1562442188285308929
Group IB Connects Twilio and Cloudflare Phishing attacks to others
https://www.helpnetsecurity.com/2022/08/25/0ktapus-twilio-cloudflare-phishers-targets/
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
LastPass Security Incident
https://blog.lastpass.com/2022/08/notice-of-recent-security-incident/
Bitbucket Vulnerability
https://securityonline.info/cve-2022-36804-bitbucket-server-and-data-center-command-injection-vulnerability/
Monster Libra -> IcedID -> Cobalt Strike and DarkVNC
https://isc.sans.edu/forums/diary/VNC/28974/
Is Tox the New C&C Method for Coinminers?
https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers
Carbon Black Blue Screens
https://community.carbonblack.com/t5/Knowledge-Base/Endpoint-Standard-Sudden-Blue-Screens-on-Windows-Devices-23rd/ta-p/114369
Gitlab Vulnerability
https://about.gitlab.com/releases/2022/08/22/critical-security-release-gitlab-15-3-1-released/#Remote%20Command%20Execution%20via%20Github%20import
Monster Libra -> IcedID -> Cobalt Strike and DarkVNC
https://isc.sans.edu/forums/diary/VNC/28974/
Is Tox the New C&C Method for Coinminers?
https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers
Carbon Black Blue Screens
https://community.carbonblack.com/t5/Knowledge-Base/Endpoint-Standard-Sudden-Blue-Screens-on-Windows-Devices-23rd/ta-p/114369
Gitlab Vulnerability
https://about.gitlab.com/releases/2022/08/22/critical-security-release-gitlab-15-3-1-released/#Remote%20Command%20Execution%20via%20Github%20import
Who's Looking at Your security.txt File
https://isc.sans.edu/diary/Who%27s+Looking+at+Your+security.txt+File%3F/28972
Assessing Python Malware Detectors with a Benchmark Dataset
https://blog.chainguard.dev/taming-python-malware-scanners/
New Iranian APT Data Extraction Tool
https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool/
Firefox Update
https://www.mozilla.org/en-US/security/advisories/mfsa2022-33/
IBM MQ Update
https://www.ibm.com/support/pages/node/6613021
Who's Looking at Your security.txt File
https://isc.sans.edu/diary/Who%27s+Looking+at+Your+security.txt+File%3F/28972
Assessing Python Malware Detectors with a Benchmark Dataset
https://blog.chainguard.dev/taming-python-malware-scanners/
New Iranian APT Data Extraction Tool
https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool/
Firefox Update
https://www.mozilla.org/en-US/security/advisories/mfsa2022-33/
IBM MQ Update
https://www.ibm.com/support/pages/node/6613021
32 or 64 Bits Malware
https://isc.sans.edu/diary/32+or+64+bits+Malware%3F/28968
Proxies and Configurations Used for Credential Stuffing Attacks
https://www.ic3.gov/Media/News/2022/220818.pdf
DirtyCred Linux Privilege Escalation Vulnerablity
https://www.blackhat.com/us-22/briefings/schedule/#cautious-a-new-exploitation-method-no-pipe-but-as-nasty-as-dirty-pipe-27169
Fake DDos Pages on WordPress Sites Lead to Drive-By-Downloads
https://blog.sucuri.net/2022/08/fake-ddos-pages-on-wordpress-lead-to-drive-by-downloads.html
32 or 64 Bits Malware
https://isc.sans.edu/diary/32+or+64+bits+Malware%3F/28968
Proxies and Configurations Used for Credential Stuffing Attacks
https://www.ic3.gov/Media/News/2022/220818.pdf
DirtyCred Linux Privilege Escalation Vulnerablity
https://www.blackhat.com/us-22/briefings/schedule/#cautious-a-new-exploitation-method-no-pipe-but-as-nasty-as-dirty-pipe-27169
Fake DDos Pages on WordPress Sites Lead to Drive-By-Downloads
https://blog.sucuri.net/2022/08/fake-ddos-pages-on-wordpress-lead-to-drive-by-downloads.html
Brazil malspam pushes Astaroth (Guildma) malware
https://isc.sans.edu/diary/Brazil+malspam+pushes+Astaroth+%28Guildma%29+malware/28962
Android Ring App XSS
https://checkmarx.com/blog/amazon-quickly-fixed-a-vulnerability-in-ring-android-app-that-could-expose-users-camera-recordings/
iOS in App Browser Security Issues
https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser
iOS in-App Browser Issues
https://krausefx.com/blog/ios-privacy-instagram-and-facebook-can-track-anything-you-do-on-any-website-in-their-in-app-browser
https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser
Brazil malspam pushes Astaroth (Guildma) malware
https://isc.sans.edu/diary/Brazil+malspam+pushes+Astaroth+%28Guildma%29+malware/28962
Android Ring App XSS
https://checkmarx.com/blog/amazon-quickly-fixed-a-vulnerability-in-ring-android-app-that-could-expose-users-camera-recordings/
iOS in App Browser Security Issues
https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser
iOS in-App Browser Issues
https://krausefx.com/blog/ios-privacy-instagram-and-facebook-can-track-anything-you-do-on-any-website-in-their-in-app-browser
https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser
Honeypot Attack Summaries with Python
https://isc.sans.edu/diary/Honeypot+Attack+Summaries+with+Python/28956
TP-Link Vulnerability
https://blog.viettelcybersecurity.com/1day-to-0day-on-tl-link-tl-wr841n/
Safari Update
https://support.apple.com/en-us/HT213414
iOS VPN Leaks
https://www.michaelhorowitz.com/VPNs.on.iOS.are.scam.php
Janet Jackson Hard Drive DDoS
https://devblogs.microsoft.com/oldnewthing/20220816-00/?p=106994
Honeypot Attack Summaries with Python
https://isc.sans.edu/diary/Honeypot+Attack+Summaries+with+Python/28956
TP-Link Vulnerability
https://blog.viettelcybersecurity.com/1day-to-0day-on-tl-link-tl-wr841n/
Safari Update
https://support.apple.com/en-us/HT213414
iOS VPN Leaks
https://www.michaelhorowitz.com/VPNs.on.iOS.are.scam.php
Janet Jackson Hard Drive DDoS
https://devblogs.microsoft.com/oldnewthing/20220816-00/?p=106994
A Quick VoIP Experiment
https://isc.sans.edu/diary/A+Quick+VoIP+Experiment/28950
Apple Patches Two Exploited Vulnerabilities
https://isc.sans.edu/diary/Apple+Patches+Two+Exploited+Vulnerabilities/28952
Google Chrome Update
https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.html
Cisco staystaystay exploit tool
https://www.youtube.com/watch?v=ySgbHClk9HE
A Quick VoIP Experiment
https://isc.sans.edu/diary/A+Quick+VoIP+Experiment/28950
Apple Patches Two Exploited Vulnerabilities
https://isc.sans.edu/diary/Apple+Patches+Two+Exploited+Vulnerabilities/28952
Google Chrome Update
https://chromereleases.googleblog.com/2022/08/stable-channel-update-for-desktop_16.html
Cisco staystaystay exploit tool
https://www.youtube.com/watch?v=ySgbHClk9HE
VBA Maldoc and UTF7 (APT-C-35)
https://isc.sans.edu/diary/VBA+Maldoc+%26+UTF7+%28APT-C-35%29/28946
Disrupting SEABORGIUM's Ongoing Phishing Operations
https://www.microsoft.com/security/blog/2022/08/15/disrupting-seaborgiums-ongoing-phishing-operations/
UWB Real Time Location Systems: How Secure Radio Communcations May Fail in Practice.
VBA Maldoc and UTF7 (APT-C-35)
https://isc.sans.edu/diary/VBA+Maldoc+%26+UTF7+%28APT-C-35%29/28946
Disrupting SEABORGIUM's Ongoing Phishing Operations
https://www.microsoft.com/security/blog/2022/08/15/disrupting-seaborgiums-ongoing-phishing-operations/
UWB Real Time Location Systems: How Secure Radio Communcations May Fail in Practice.
Realtek CVE-2022-27255 Followup (snort signature and presentation)
https://isc.sans.edu/diary/Realtek+SDK+SIP+ALG+Vulnerability%3A+A+Big+Deal%2C+but+not+much+you+can+do+about+it.+CVE+2022-27255/28940
MacOS Privilege Escalation
https://sector7.computest.nl/post/2022-08-process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability/
Zoom Update
https://explore.zoom.us/en/trust/security/security-bulletin/
Microsoft Block Vulnerable Bootloaders
https://eclypsium.com/2022/08/11/vulnerable-bootloaders-2022/
HPE Integrated Lights Out 5 Vulnerablities
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=emr_na-hpesbhf04333en_us
Realtek CVE-2022-27255 Followup (snort signature and presentation)
https://isc.sans.edu/diary/Realtek+SDK+SIP+ALG+Vulnerability%3A+A+Big+Deal%2C+but+not+much+you+can+do+about+it.+CVE+2022-27255/28940
MacOS Privilege Escalation
https://sector7.computest.nl/post/2022-08-process-injection-breaking-all-macos-security-layers-with-a-single-vulnerability/
Zoom Update
https://explore.zoom.us/en/trust/security/security-bulletin/
Microsoft Block Vulnerable Bootloaders
https://eclypsium.com/2022/08/11/vulnerable-bootloaders-2022/
HPE Integrated Lights Out 5 Vulnerablities
https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=emr_na-hpesbhf04333en_us
Realtek eCOS SDK SIP ALG Vulnerability
https://isc.sans.edu/diary/Realtek+SDK+SIP+ALG+Vulnerability%3A+A+Big+Deal%2C+but+not+much+you+can+do+about+it.+CVE+2022-27255/28940
Phishing HTML Attachment as Voicemail Audio Transcription
https://isc.sans.edu/diary/Phishing+HTML+Attachment+as+Voicemail+Audio+Transcription/28938
CVE-2022-0028 PAN-OS: Reflected Amplification Denial-of-Service Vulnerability
https://security.paloaltonetworks.com/CVE-2022-0028
Realtek eCOS SDK SIP ALG Vulnerability
https://isc.sans.edu/diary/Realtek+SDK+SIP+ALG+Vulnerability%3A+A+Big+Deal%2C+but+not+much+you+can+do+about+it.+CVE+2022-27255/28940
Phishing HTML Attachment as Voicemail Audio Transcription
https://isc.sans.edu/diary/Phishing+HTML+Attachment+as+Voicemail+Audio+Transcription/28938
CVE-2022-0028 PAN-OS: Reflected Amplification Denial-of-Service Vulnerability
https://security.paloaltonetworks.com/CVE-2022-0028
InfoStealer Script Based on Curl and NSudo
https://isc.sans.edu/diary/InfoStealer+Script+Based+on+Curl+and+NSudo/28932
Cisco Breach Details
https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html
Ivanti Pulse Connect Secure Privilege Escalation Vulnerability
https://gist.github.com/JGarciaSec/2060ec1c8efc1d573a1ddb754c6b4f84
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerablity
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-rsa-key-leak-Ms7UEfZz
InfoStealer Script Based on Curl and NSudo
https://isc.sans.edu/diary/InfoStealer+Script+Based+on+Curl+and+NSudo/28932
Cisco Breach Details
https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html
Ivanti Pulse Connect Secure Privilege Escalation Vulnerability
https://gist.github.com/JGarciaSec/2060ec1c8efc1d573a1ddb754c6b4f84
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software RSA Private Key Leak Vulnerablity
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-rsa-key-leak-Ms7UEfZz
And Here They Come Again: DNS Reflection Attacks
https://isc.sans.edu/diary/And+Here+They+Come+Again%3A+DNS+Reflection+Attacks/28928
Rapid 7 Defaultinator
https://defaultinator.com
Zimbra Mass Compromise
https://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/
VMWare vRealize Vulnerability
https://www.vmware.com/security/advisories/VMSA-2022-0022.html
Microsoft Vulnerability and IPS/Snort
https://community.meraki.com/t5/Meraki-Service-Notices/Microsoft-vulnerability-and-IPS-SNORT/ba-p/156649
And Here They Come Again: DNS Reflection Attacks
https://isc.sans.edu/diary/And+Here+They+Come+Again%3A+DNS+Reflection+Attacks/28928
Rapid 7 Defaultinator
https://defaultinator.com
Zimbra Mass Compromise
https://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/
VMWare vRealize Vulnerability
https://www.vmware.com/security/advisories/VMSA-2022-0022.html
Microsoft Vulnerability and IPS/Snort
https://community.meraki.com/t5/Meraki-Service-Notices/Microsoft-vulnerability-and-IPS-SNORT/ba-p/156649
Microsoft August 2022 Patch Tuesday
https://isc.sans.edu/diary/Microsoft+August+2022+Patch+Tuesday/28924
AEPIC Leak
https://aepicleak.com
Adobe security bulletins
https://helpx.adobe.com/security/security-bulletin.html
Microsoft August 2022 Patch Tuesday
https://isc.sans.edu/diary/Microsoft+August+2022+Patch+Tuesday/28924
AEPIC Leak
https://aepicleak.com
Adobe security bulletins
https://helpx.adobe.com/security/security-bulletin.html
JSON All the Logs!
https://isc.sans.edu/diary/JSON+All+the+Logs%21/28920
Microsoft Edge Enhanced Security
https://docs.microsoft.com/en-us/deployedge/microsoft-edge-security-browse-safer
Malicious Python Packages
https://www.darkreading.com/application-security/10-malicious-packages-slither-pypi-registry
New Orchard Botnet
https://blog.netlab.360.com/a-new-botnet-orchard-generates-dga-domains-with-bitcoin-transaction-information/
JSON All the Logs!
https://isc.sans.edu/diary/JSON+All+the+Logs%21/28920
Microsoft Edge Enhanced Security
https://docs.microsoft.com/en-us/deployedge/microsoft-edge-security-browse-safer
Malicious Python Packages
https://www.darkreading.com/application-security/10-malicious-packages-slither-pypi-registry
New Orchard Botnet
https://blog.netlab.360.com/a-new-botnet-orchard-generates-dga-domains-with-bitcoin-transaction-information/
Exim Vulnerability Silently Patched
https://github.com/ivd38/exim_overflow
DuckDuckGo Stopping Microsoft Tracking Code
https://spreadprivacy.com/more-privacy-and-transparency/
Emergency Broadcast Messaging System Vulnerabilities
https://content.govdelivery.com/accounts/USDHSFEMA/bulletins/3263326
Slack Leaks Hashed Passwords
https://slack.com/intl/en-in/blog/news/notice-about-slack-password-resets
Zimbra Flaw Exploited
https://nvd.nist.gov/vuln/detail/CVE-2022-27924
Exim Vulnerability Silently Patched
https://github.com/ivd38/exim_overflow
DuckDuckGo Stopping Microsoft Tracking Code
https://spreadprivacy.com/more-privacy-and-transparency/
Emergency Broadcast Messaging System Vulnerabilities
https://content.govdelivery.com/accounts/USDHSFEMA/bulletins/3263326
Slack Leaks Hashed Passwords
https://slack.com/intl/en-in/blog/news/notice-about-slack-password-resets
Zimbra Flaw Exploited
https://nvd.nist.gov/vuln/detail/CVE-2022-27924
TLP 2.0 is Here
https://isc.sans.edu/diary/TLP+2.0+is+here/28914
Hijacking email with Cloudflare Email Routing
https://albertpedersen.com/blog/hijacking-email-with-cloudflare-email-routing/
rsync arbitrary file write vulnerablity
https://www.openwall.com/lists/oss-security/2022/08/02/1
Local privilege escalation in Kaspersky VPN
https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/
TLP 2.0 is Here
https://isc.sans.edu/diary/TLP+2.0+is+here/28914
Hijacking email with Cloudflare Email Routing
https://albertpedersen.com/blog/hijacking-email-with-cloudflare-email-routing/
rsync arbitrary file write vulnerablity
https://www.openwall.com/lists/oss-security/2022/08/02/1
Local privilege escalation in Kaspersky VPN
https://www.synopsys.com/blogs/software-security/cyrc-advisory-kasperksy-vpn-microsoft-windows/
l9explore and LeakIX Internet Wide Recon Scans
https://isc.sans.edu/diary/l9explore+and+LeakIX+Internet+wide+recon+scans./28910
Arris / Arris Variant DSL/Fiber Router Critical Vulnerability
http://derekabdine.com/blog/2022-arris-advisory
35,000 Malicious Repo Forks Flood GitHub
https://www.bleepingcomputer.com/news/security/35-000-code-repos-not-hacked-but-clones-flood-github-to-serve-malware/
Palo Alto Master Key
https://twitter.com/rqu50/status/1554566757704089600#m
Laravel Unserialize RCE
https://github.com/beicheng-maker/vulns/issues/1
Unuathenticated Remote Code Execution in DrayTek Vigor Routers
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/rce-in-dratyek-routers.html
l9explore and LeakIX Internet Wide Recon Scans
https://isc.sans.edu/diary/l9explore+and+LeakIX+Internet+wide+recon+scans./28910
Arris / Arris Variant DSL/Fiber Router Critical Vulnerability
http://derekabdine.com/blog/2022-arris-advisory
35,000 Malicious Repo Forks Flood GitHub
https://www.bleepingcomputer.com/news/security/35-000-code-repos-not-hacked-but-clones-flood-github-to-serve-malware/
Palo Alto Master Key
https://twitter.com/rqu50/status/1554566757704089600#m
Laravel Unserialize RCE
https://github.com/beicheng-maker/vulns/issues/1
Unuathenticated Remote Code Execution in DrayTek Vigor Routers
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/rce-in-dratyek-routers.html
Increase in Chinese "Hacktivism" Attacks
https://isc.sans.edu/diary/Increase+in+Chinese+%22Hacktivism%22+Attacks/28906
Zoho Password Manager Exploit
https://xz.aliyun.com/t/11578
VMWare Updates
https://www.vmware.com/security/advisories/VMSA-2022-0021.html
https://twitter.com/VietPetrus
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html
Increase in Chinese "Hacktivism" Attacks
https://isc.sans.edu/diary/Increase+in+Chinese+%22Hacktivism%22+Attacks/28906
Zoho Password Manager Exploit
https://xz.aliyun.com/t/11578
VMWare Updates
https://www.vmware.com/security/advisories/VMSA-2022-0021.html
https://twitter.com/VietPetrus
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html
A Little DDoS in the Morning
https://isc.sans.edu/diary/A+Little+DDoS+In+the+Morning/28900
Exposed Twitter API Keys
https://cloudsek.com/whitepapers_reports/how-leaked-twitter-api-keys-can-be-used-to-build-a-bot-army/
TCL LinkHub Serialization Issues
https://blog.talosintelligence.com/2022/08/vulnerability-spotlight-how-misusing.html
Jenkins Plugin Updates
https://www.jenkins.io/security/advisory/2022-07-27/
A Little DDoS in the Morning
https://isc.sans.edu/diary/A+Little+DDoS+In+the+Morning/28900
Exposed Twitter API Keys
https://cloudsek.com/whitepapers_reports/how-leaked-twitter-api-keys-can-be-used-to-build-a-bot-army/
TCL LinkHub Serialization Issues
https://blog.talosintelligence.com/2022/08/vulnerability-spotlight-how-misusing.html
Jenkins Plugin Updates
https://www.jenkins.io/security/advisory/2022-07-27/
PDF Analysis Introduction and OpenActions Entries
https://isc.sans.edu/diary/PDF+Analysis+Intro+and+OpenActions+Entries/28894
IPFS The New Hotbed of Phishing
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/ipfs-the-new-hotbed-of-phishing/
Mail Stealing Browser Extension
https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/
Lofylife Malicious NPM Packages
https://securelist.com/lofylife-malicious-npm-packages/107014/
IP Camera Vulnerability
https://www.nozominetworks.com/blog/vulnerability-in-dahua-s-onvif-implementation-threatens-ip-camera-security/
Nuki Smart Lock Vulnerabilities
https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/
Foxit PDF Reader
https://www.foxit.com/support/security-bulletins.html
PDF Analysis Introduction and OpenActions Entries
https://isc.sans.edu/diary/PDF+Analysis+Intro+and+OpenActions+Entries/28894
IPFS The New Hotbed of Phishing
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/ipfs-the-new-hotbed-of-phishing/
Mail Stealing Browser Extension
https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/
Lofylife Malicious NPM Packages
https://securelist.com/lofylife-malicious-npm-packages/107014/
IP Camera Vulnerability
https://www.nozominetworks.com/blog/vulnerability-in-dahua-s-onvif-implementation-threatens-ip-camera-security/
Nuki Smart Lock Vulnerabilities
https://research.nccgroup.com/2022/07/25/technical-advisory-multiple-vulnerabilities-in-nuki-smart-locks-cve-2022-32509-cve-2022-32504-cve-2022-32502-cve-2022-32507-cve-2022-32503-cve-2022-32510-cve-2022-32506-cve-2022-32508-cve-2/
Foxit PDF Reader
https://www.foxit.com/support/security-bulletins.html
Exfiltrating Data with Bookmarks
https://isc.sans.edu/diary/Exfiltrating+Data+With+Bookmarks/28890
Critical Samba Bug Could Let Anyone Become Domain Admin
https://nakedsecurity.sophos.com/2022/07/27/critical-samba-bug-could-let-anyone-become-domain-admin-patch-now/
Apple IP Address Range Hijacked by Rostelecom
https://www.manrs.org/2022/07/for-12-hours-was-part-of-apple-engineerings-network-hijacked-by-russias-rostelecom/
Veritas Patches
https://www.veritas.com/content/support/en_US/security/VTS22-004#c1
IBM Patches
https://www.ibm.com/support/pages/node/6606251
https://www.ibm.com/support/pages/node/6607135
Exfiltrating Data with Bookmarks
https://isc.sans.edu/diary/Exfiltrating+Data+With+Bookmarks/28890
Critical Samba Bug Could Let Anyone Become Domain Admin
https://nakedsecurity.sophos.com/2022/07/27/critical-samba-bug-could-let-anyone-become-domain-admin-patch-now/
Apple IP Address Range Hijacked by Rostelecom
https://www.manrs.org/2022/07/for-12-hours-was-part-of-apple-engineerings-network-hijacked-by-russias-rostelecom/
Veritas Patches
https://www.veritas.com/content/support/en_US/security/VTS22-004#c1
IBM Patches
https://www.ibm.com/support/pages/node/6606251
https://www.ibm.com/support/pages/node/6607135
IcedID (BokBot) with Dark VNC and Cobalt Strike
https://isc.sans.edu/diary//28884
Web Assembly Crypto Miners
https://blog.sucuri.net/2022/07/cryptominers-webassembly-in-website-malware.html
Subzero and Knotweed
https://www.microsoft.com/security/blog/2022/07/27/untangling-knotweed-european-private-sector-offensive-actor-using-0-day-exploits/
IcedID (BokBot) with Dark VNC and Cobalt Strike
https://isc.sans.edu/diary//28884
Web Assembly Crypto Miners
https://blog.sucuri.net/2022/07/cryptominers-webassembly-in-website-malware.html
Subzero and Knotweed
https://www.microsoft.com/security/blog/2022/07/27/untangling-knotweed-european-private-sector-offensive-actor-using-0-day-exploits/
How is Your macOS Security Posture
https://isc.sans.edu/diary/How+is+Your+macOS+Security+Posture%3F/28882
Registry file with Executable Payload
https://www.x86matthew.com/view_post?id=embed_exe_reg
Targeted Phishing of Facebook Business Users
https://labs.withsecure.com/assets/BlogFiles/Publications/WithSecure_Research_DUCKTAIL.pdf
Forwarding Address is Hard
https://www.synacktiv.com/publications/cve-2022-31813-forwarding-addresses-is-hard.html
How is Your macOS Security Posture
https://isc.sans.edu/diary/How+is+Your+macOS+Security+Posture%3F/28882
Registry file with Executable Payload
https://www.x86matthew.com/view_post?id=embed_exe_reg
Targeted Phishing of Facebook Business Users
https://labs.withsecure.com/assets/BlogFiles/Publications/WithSecure_Research_DUCKTAIL.pdf
Forwarding Address is Hard
https://www.synacktiv.com/publications/cve-2022-31813-forwarding-addresses-is-hard.html
PowerShell Script with Fileless Capability
https://isc.sans.edu/diary/PowerShell+Script+with+Fileless+Capability/28878
With Management Comes Risk: Finding Flaws in Filewave MDM
https://claroty.com/2022/07/25/blog-research-with-management-comes-risk-finding-flaws-in-filewave-mdm/
CosmicStrand: the discovery of a sophisticated UEFI firmware rootkit
https://securelist.com/cosmicstrand-uefi-firmware-rootkit/106973/
PowerShell Script with Fileless Capability
https://isc.sans.edu/diary/PowerShell+Script+with+Fileless+Capability/28878
With Management Comes Risk: Finding Flaws in Filewave MDM
https://claroty.com/2022/07/25/blog-research-with-management-comes-risk-finding-flaws-in-filewave-mdm/
CosmicStrand: the discovery of a sophisticated UEFI firmware rootkit
https://securelist.com/cosmicstrand-uefi-firmware-rootkit/106973/
An Analysis of a Discerning Phishing Website
https://isc.sans.edu/diary/An+Analysis+of+a+Discerning+Phishing+Website+/28870
Sonicwall Vulnerability
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0007
Sh*load Exploids Episdoe V: Return of the Error
https://dellfer.com/shload-exploits-episode-v-return-of-the-error/
An Analysis of a Discerning Phishing Website
https://isc.sans.edu/diary/An+Analysis+of+a+Discerning+Phishing+Website+/28870
Sonicwall Vulnerability
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0007
Sh*load Exploids Episdoe V: Return of the Error
https://dellfer.com/shload-exploits-episode-v-return-of-the-error/
Maldoc with non-ASCII VBA Identifiers
https://isc.sans.edu/diary/Maldoc%3A+non-ASCII+VBA+Identifiers/28866
Cisco Security Updates
https://tools.cisco.com/security/center/publicationListing.x?
Outlook 365 Odd Supicious Login Attempt Warnings
https://www.theregister.com/2022/07/21/outlook_sign_ins/
Windows RDP Brute Force Protection
https://twitter.com/dwizzzleMSFT/status/1549870156771340288
Microsoft resuming blocking macros
https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805
Maldoc with non-ASCII VBA Identifiers
https://isc.sans.edu/diary/Maldoc%3A+non-ASCII+VBA+Identifiers/28866
Cisco Security Updates
https://tools.cisco.com/security/center/publicationListing.x?
Outlook 365 Odd Supicious Login Attempt Warnings
https://www.theregister.com/2022/07/21/outlook_sign_ins/
Windows RDP Brute Force Protection
https://twitter.com/dwizzzleMSFT/status/1549870156771340288
Microsoft resuming blocking macros
https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805
Malicious Python Script Behaving Like a Rubber Ducky
https://isc.sans.edu/diary/Malicious+Python+Script+Behaving+Like+a+Rubber+Ducky/28860
Apple Patches Everything
https://isc.sans.edu/diary/Apple+Patches+Everything+Day/28862
Confluence Atlasian Hard Coded Password
https://confluence.atlassian.com/doc/questions-for-confluence-security-advisory-2022-07-20-1142446709.html
Zyxel Vulnerablity
https://www.zyxel.com/support/Zyxel-security-advisory-authenticated-directory-traversal-vulnerabilities-of-firewalls.shtml
DNS over HTTP/3
https://security.googleblog.com/2022/07/dns-over-http3-in-android.html
Malicious Python Script Behaving Like a Rubber Ducky
https://isc.sans.edu/diary/Malicious+Python+Script+Behaving+Like+a+Rubber+Ducky/28860
Apple Patches Everything
https://isc.sans.edu/diary/Apple+Patches+Everything+Day/28862
Confluence Atlasian Hard Coded Password
https://confluence.atlassian.com/doc/questions-for-confluence-security-advisory-2022-07-20-1142446709.html
Zyxel Vulnerablity
https://www.zyxel.com/support/Zyxel-security-advisory-authenticated-directory-traversal-vulnerabilities-of-firewalls.shtml
DNS over HTTP/3
https://security.googleblog.com/2022/07/dns-over-http3-in-android.html
Beacon Request
https://isc.sans.edu/diary/Requests+For+beacon.http-get.+Help+Us+Figure+Out+What+They+Are+Looking+For/28856
Oracle July 2022 CPU
https://www.oracle.com/security-alerts/cpujul2022.html
CloudMensis MacOS Spyware
https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/
GPS Tracker Vulnerabilities
https://www.bitsight.com/sites/default/files/2022-07/MiCODUS-GPS-Report-Final.pdf
Beacon Request
https://isc.sans.edu/diary/Requests+For+beacon.http-get.+Help+Us+Figure+Out+What+They+Are+Looking+For/28856
Oracle July 2022 CPU
https://www.oracle.com/security-alerts/cpujul2022.html
CloudMensis MacOS Spyware
https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/
GPS Tracker Vulnerabilities
https://www.bitsight.com/sites/default/files/2022-07/MiCODUS-GPS-Report-Final.pdf
Adding Your Own Keywords to My PDF Tools
https://isc.sans.edu/diary/Adding+Your+Own+Keywords+To+My+PDF+Tools/28852
Tor Improvements
https://blog.torproject.org/new-release-tor-browser-115/
Trojan Horse Malware Password Cracker
https://www.dragos.com/blog/the-trojan-horse-malware-password-cracking-ecosystem-targeting-industrial-operators/
CVE-2022-33891 Apache Spark Shell Command Injection Vulnerability
https://securityonline.info/cve-2022-33891-apache-spark-shell-command-injection-vulnerability/
Juniper Junos Vulnerabilities
https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=date%20descending&f:ctype=[Security%20Advisories]
Adding Your Own Keywords to My PDF Tools
https://isc.sans.edu/diary/Adding+Your+Own+Keywords+To+My+PDF+Tools/28852
Tor Improvements
https://blog.torproject.org/new-release-tor-browser-115/
Trojan Horse Malware Password Cracker
https://www.dragos.com/blog/the-trojan-horse-malware-password-cracking-ecosystem-targeting-industrial-operators/
CVE-2022-33891 Apache Spark Shell Command Injection Vulnerability
https://securityonline.info/cve-2022-33891-apache-spark-shell-command-injection-vulnerability/
Juniper Junos Vulnerabilities
https://supportportal.juniper.net/s/global-search/%40uri?language=en_US#sort=date%20descending&f:ctype=[Security%20Advisories]
Python: Files in Use By Another Process
https://isc.sans.edu/diary/Python%3A+Files+In+Use+By+Another+Process/28848
Google Removing App Permissions List for Data Safety
https://twitter.com/MishaalRahman/status/1547307555407421443
Google Play Malware
https://twitter.com/IngraoMaxime/status/1547164768401858560
Faking Github Metadata
https://checkmarx.com/blog/unverified-commits-are-you-unknowingly-trusting-attackers-code/
Python: Files in Use By Another Process
https://isc.sans.edu/diary/Python%3A+Files+In+Use+By+Another+Process/28848
Google Removing App Permissions List for Data Safety
https://twitter.com/MishaalRahman/status/1547307555407421443
Google Play Malware
https://twitter.com/IngraoMaxime/status/1547164768401858560
Faking Github Metadata
https://checkmarx.com/blog/unverified-commits-are-you-unknowingly-trusting-attackers-code/
Debugging Broadcast Storms
https://isc.sans.edu/diary/A+%22DHCP+is+Broken%22+story%2C+and+a+Blast+from+the+Past+%28or+should+I+say+%22Storm%22+from+the+past%29/28844
Targeted Deanonymization via Side Channel Attacks
https://leakuidatorplusteam.github.io/preprint.pdf
Cookie Theft to BEC
https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/
VMWare Patch
https://www.vmware.com/security/advisories/VMSA-2021-0025.html
Debugging Broadcast Storms
https://isc.sans.edu/diary/A+%22DHCP+is+Broken%22+story%2C+and+a+Blast+from+the+Past+%28or+should+I+say+%22Storm%22+from+the+past%29/28844
Targeted Deanonymization via Side Channel Attacks
https://leakuidatorplusteam.github.io/preprint.pdf
Cookie Theft to BEC
https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/
VMWare Patch
https://www.vmware.com/security/advisories/VMSA-2021-0025.html
Using Referrers to Detect Phishing Attacks
https://isc.sans.edu/diary/Using+Referers+to+Detect+Phishing+Attacks/28836
Callback Phishing Campaigns Impersonating Security Companies
https://www.crowdstrike.com/blog/callback-malware-campaigns-impersonate-crowdstrike-and-other-cybersecurity-companies/
Retbleed Spectre Attack
https://comsec.ethz.ch/wp-content/files/retbleed_sec22.pdf
Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-26706
https://www.microsoft.com/security/blog/2022/07/13/uncovering-a-macos-app-sandbox-escape-vulnerability-a-deep-dive-into-cve-2022-26706/
Buffer Overflow Vulnerabilities in UEFI firmware of several Lenovo Notebook
https://twitter.com/ESETresearch/status/1547166334651334657
Using Referrers to Detect Phishing Attacks
https://isc.sans.edu/diary/Using+Referers+to+Detect+Phishing+Attacks/28836
Callback Phishing Campaigns Impersonating Security Companies
https://www.crowdstrike.com/blog/callback-malware-campaigns-impersonate-crowdstrike-and-other-cybersecurity-companies/
Retbleed Spectre Attack
https://comsec.ethz.ch/wp-content/files/retbleed_sec22.pdf
Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-26706
https://www.microsoft.com/security/blog/2022/07/13/uncovering-a-macos-app-sandbox-escape-vulnerability-a-deep-dive-into-cve-2022-26706/
Buffer Overflow Vulnerabilities in UEFI firmware of several Lenovo Notebook
https://twitter.com/ESETresearch/status/1547166334651334657
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft+July+2022+Patch+Tuesday/28838
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
SAP Patches
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
IBM Patches
https://www.ibm.com/support/pages/node/6602255
https://www.ibm.com/support/pages/node/6602259
https://www.ibm.com/support/pages/node/6602251
Microsoft Patch Tuesday
https://isc.sans.edu/diary/Microsoft+July+2022+Patch+Tuesday/28838
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
SAP Patches
https://dam.sap.com/mac/app/e/pdf/preview/embed/ucQrx6G?ltr=a&rc=10
IBM Patches
https://www.ibm.com/support/pages/node/6602255
https://www.ibm.com/support/pages/node/6602259
https://www.ibm.com/support/pages/node/6602251
Rogers Outage
https://about.rogers.com/news-ideas/a-message-from-rogers-president-and-ceo/
Rolling Pwn
https://rollingpwn.github.io/rolling-pwn/
GitHub Runners mine Cryptocoins
https://www.trendmicro.com/en_us/research/22/g/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html
SANSFIRE Keynote Stream
https://www.sans.org/webcasts/the-internet-storm-center-how-to-use-and-how-to-contribute-data/
Rogers Outage
https://about.rogers.com/news-ideas/a-message-from-rogers-president-and-ceo/
Rolling Pwn
https://rollingpwn.github.io/rolling-pwn/
GitHub Runners mine Cryptocoins
https://www.trendmicro.com/en_us/research/22/g/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html
SANSFIRE Keynote Stream
https://www.sans.org/webcasts/the-internet-storm-center-how-to-use-and-how-to-contribute-data/
SANSFIRE Keynote Stream
https://www.sans.org/webcasts/the-internet-storm-center-how-to-use-and-how-to-contribute-data/
Extracting URLs from Emotet with Cyberchef
https://isc.sans.edu/forums/diary/Excel%204%20Emotet%20Maldoc%20Analysis%20using%20CyberChef/28830/
Microsoft rolling Back Macro Policy Change
https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805
Checkmate Ransomware Affected Poorly Configured QNAP NAS
https://www.qnap.com/en/security-advisory/QSA-22-21
PyPi Requires 2FA for critical packages
https://pypi.org/security-key-giveaway/
SANSFIRE Keynote Stream
https://www.sans.org/webcasts/the-internet-storm-center-how-to-use-and-how-to-contribute-data/
Extracting URLs from Emotet with Cyberchef
https://isc.sans.edu/forums/diary/Excel%204%20Emotet%20Maldoc%20Analysis%20using%20CyberChef/28830/
Microsoft rolling Back Macro Policy Change
https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805
Checkmate Ransomware Affected Poorly Configured QNAP NAS
https://www.qnap.com/en/security-advisory/QSA-22-21
PyPi Requires 2FA for critical packages
https://pypi.org/security-key-giveaway/
How Many SANs are Insane
https://isc.sans.edu/forums/diary/How+Many+SANs+are+Insane/28820/
Fortinet July Updates
https://fortiguard.fortinet.com/psirt?date=07-2022
Phishing Attacks Getting Trickier
https://www.sans.org/newsletters/ouch/phishing-attacks-getting-trickier
Quantum Safe Ciphers
https://csrc.nist.gov/News/2022/pqc-candidates-to-be-standardized-and-round-4
Apple Proposes Lockdown Mode
https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/
How Many SANs are Insane
https://isc.sans.edu/forums/diary/How+Many+SANs+are+Insane/28820/
Fortinet July Updates
https://fortiguard.fortinet.com/psirt?date=07-2022
Phishing Attacks Getting Trickier
https://www.sans.org/newsletters/ouch/phishing-attacks-getting-trickier
Quantum Safe Ciphers
https://csrc.nist.gov/News/2022/pqc-candidates-to-be-standardized-and-round-4
Apple Proposes Lockdown Mode
https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/
EternalBlue 5 Years After WannaCry and NotPetya
https://isc.sans.edu/forums/diary/EternalBlue+5+years+after+WannaCry+and+NotPetya/28816/
OpenSSL Patches Two Vulnerabilities
https://www.openssl.org/news/secadv/20220705.txt
Iconburst NPM Software Supply Chain Attack
https://blog.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites
EternalBlue 5 Years After WannaCry and NotPetya
https://isc.sans.edu/forums/diary/EternalBlue+5+years+after+WannaCry+and+NotPetya/28816/
OpenSSL Patches Two Vulnerabilities
https://www.openssl.org/news/secadv/20220705.txt
Iconburst NPM Software Supply Chain Attack
https://blog.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites
7Zip Mark of the Web For Office Files
https://isc.sans.edu/forums/diary/7Zip+MoW+For+Office+files/28812/
SessionManager Backdoor Seen with IIS
https://securelist.com/the-sessionmanager-iis-backdoor/106868/
Googe Chrome Stable Channel Update
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html
7Zip Mark of the Web For Office Files
https://isc.sans.edu/forums/diary/7Zip+MoW+For+Office+files/28812/
SessionManager Backdoor Seen with IIS
https://securelist.com/the-sessionmanager-iis-backdoor/106868/
Googe Chrome Stable Channel Update
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html
Case Study: Cobalt Strike Server Lives on After its Domain is Suspended
https://isc.sans.edu/forums/diary/Case+Study+Cobalt+Strike+Server+Lives+on+After+Its+Domain+Is+Suspended/28804/
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
https://www.horizon3.ai/red-team-blog-cve-2022-28219/
CWE Top 25 Update
https://cwe.mitre.org/top25/archive/2022/2022_cwe_top25.html#analysis
Case Study: Cobalt Strike Server Lives on After its Domain is Suspended
https://isc.sans.edu/forums/diary/Case+Study+Cobalt+Strike+Server+Lives+on+After+Its+Domain+Is+Suspended/28804/
CVE-2022-28219: Unauthenticated XXE to RCE and Domain Compromise in ManageEngine ADAudit Plus
https://www.horizon3.ai/red-team-blog-cve-2022-28219/
CWE Top 25 Update
https://cwe.mitre.org/top25/archive/2022/2022_cwe_top25.html#analysis
Its New Phone Day: Time to Migrate Your MFA
https://isc.sans.edu/forums/diary/Its+New+Phone+Day+Time+to+migrate+your+MFA/28800/
Managing Human Risk Security Awareness Report
https://go.sans.org/lp-wp-2022-sans-security-awareness-report
Microsoft Azure Service Fabric Container Elevation of Privilege Vulnerability
https://unit42.paloaltonetworks.com/fabricscape-cve-2022-30137/#The-Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30137
Zimbra RCE Vulnerability
https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/
FBI Warns of Deep Fakes Beeing Used in Job Interviews
https://www.ic3.gov/Media/Y2022/PSA220628
Its New Phone Day: Time to Migrate Your MFA
https://isc.sans.edu/forums/diary/Its+New+Phone+Day+Time+to+migrate+your+MFA/28800/
Managing Human Risk Security Awareness Report
https://go.sans.org/lp-wp-2022-sans-security-awareness-report
Microsoft Azure Service Fabric Container Elevation of Privilege Vulnerability
https://unit42.paloaltonetworks.com/fabricscape-cve-2022-30137/#The-Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30137
Zimbra RCE Vulnerability
https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/
FBI Warns of Deep Fakes Beeing Used in Job Interviews
https://www.ic3.gov/Media/Y2022/PSA220628
Possible Scans for HiByMusic Devices
https://isc.sans.edu/forums/diary/Possible+Scans+for+HiByMusic+Devices/28796/
OpenSSL Heap Overflow
https://guidovranken.com/2022/06/27/notes-on-openssl-remote-memory-corruption/
https://github.com/openssl/openssl/issues/18625#issuecomment-1165012549
ZuoRat MalwareHijacking Home Office Routers
https://blog.lumen.com/zuorat-hijacks-soho-routers-to-silently-stalk-networks/
Possible Scans for HiByMusic Devices
https://isc.sans.edu/forums/diary/Possible+Scans+for+HiByMusic+Devices/28796/
OpenSSL Heap Overflow
https://guidovranken.com/2022/06/27/notes-on-openssl-remote-memory-corruption/
https://github.com/openssl/openssl/issues/18625#issuecomment-1165012549
ZuoRat MalwareHijacking Home Office Routers
https://blog.lumen.com/zuorat-hijacks-soho-routers-to-silently-stalk-networks/
Encrypted Client Hello: Anybody Using it Yet?
https://isc.sans.edu/forums/diary/Encrypted+Client+Hello+Anybody+Using+it+Yet/28792/
Jenkins Advisory
https://www.jenkins.io/security/advisory/2022-06-22/
Instagram Age Verification
https://about.fb.com/news/2022/06/new-ways-to-verify-age-on-instagram/
CodeSys V2 Vulnerability
https://github.com/ic3sw0rd/Codesys_V2_Vulnerability
Encrypted Client Hello: Anybody Using it Yet?
https://isc.sans.edu/forums/diary/Encrypted+Client+Hello+Anybody+Using+it+Yet/28792/
Jenkins Advisory
https://www.jenkins.io/security/advisory/2022-06-22/
Instagram Age Verification
https://about.fb.com/news/2022/06/new-ways-to-verify-age-on-instagram/
CodeSys V2 Vulnerability
https://github.com/ic3sw0rd/Codesys_V2_Vulnerability
Python Abusing the Windows GUI
https://isc.sans.edu/forums/diary/Python+abusing+The+Windows+GUI/28780/
Malicious Code Passed to PowerShell via the Clipboard
https://isc.sans.edu/forums/diary/Malicious+Code+Passed+to+PowerShell+via+the+Clipboard/28784/
Attacking With WebView2 Applications
https://mrd0x.com/attacking-with-webview2-applications/
Bronze Starlight Ransomware Operations Use Hui Loaders
https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader
Novel Exploit Detected in Mitel VoIP Appliance
https://www.crowdstrike.com/blog/novel-exploit-detected-in-mitel-voip-appliance/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29499
Python Abusing the Windows GUI
https://isc.sans.edu/forums/diary/Python+abusing+The+Windows+GUI/28780/
Malicious Code Passed to PowerShell via the Clipboard
https://isc.sans.edu/forums/diary/Malicious+Code+Passed+to+PowerShell+via+the+Clipboard/28784/
Attacking With WebView2 Applications
https://mrd0x.com/attacking-with-webview2-applications/
Bronze Starlight Ransomware Operations Use Hui Loaders
https://www.secureworks.com/research/bronze-starlight-ransomware-operations-use-hui-loader
Novel Exploit Detected in Mitel VoIP Appliance
https://www.crowdstrike.com/blog/novel-exploit-detected-in-mitel-voip-appliance/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29499
Malicious PowerShell Targeting Cryptocurrency Browser Extensions
https://isc.sans.edu/forums/diary/Malicious+PowerShell+Targeting+Cryptocurrency+Browser+Extensions/28772/
Keeping PowerShell: Security Measures to Use and Embrace
https://media.defense.gov/2022/Jun/22/2003021689/-1/-1/1/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF
Client-Side Magecart Attacks Still Around, But More Covert
https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert/
Chinese actor takes aim, armed with Nim Language and Bizarro AES
https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes/
Israeli Air Raid Sirens Hacked
https://twitter.com/Israel_Cyber/status/1538821467785265153
Malicious PowerShell Targeting Cryptocurrency Browser Extensions
https://isc.sans.edu/forums/diary/Malicious+PowerShell+Targeting+Cryptocurrency+Browser+Extensions/28772/
Keeping PowerShell: Security Measures to Use and Embrace
https://media.defense.gov/2022/Jun/22/2003021689/-1/-1/1/CSI_KEEPING_POWERSHELL_SECURITY_MEASURES_TO_USE_AND_EMBRACE_20220622.PDF
Client-Side Magecart Attacks Still Around, But More Covert
https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert/
Chinese actor takes aim, armed with Nim Language and Bizarro AES
https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes/
Israeli Air Raid Sirens Hacked
https://twitter.com/Israel_Cyber/status/1538821467785265153
Experimental New Domain / Domain Age API
https://isc.sans.edu/forums/diary/Experimental+New+Domain+Domain+Age+API/28770/
Forescout Vedere Labs Discovers 56 OT Vulnerabilities
https://www.forescout.com/resources/ot-icefall-report/
Cloudflare Outage
https://blog.cloudflare.com/cloudflare-outage-on-june-21-2022/
Does Acrobat Reader Unload Injection of Security Products
https://blog.minerva-labs.com/does-acrobat-reader-unload-injection-of-security-products
7-Zip Mark-of-the-Web Support
https://www.7-zip.org/history.txt
Experimental New Domain / Domain Age API
https://isc.sans.edu/forums/diary/Experimental+New+Domain+Domain+Age+API/28770/
Forescout Vedere Labs Discovers 56 OT Vulnerabilities
https://www.forescout.com/resources/ot-icefall-report/
Cloudflare Outage
https://blog.cloudflare.com/cloudflare-outage-on-june-21-2022/
Does Acrobat Reader Unload Injection of Security Products
https://blog.minerva-labs.com/does-acrobat-reader-unload-injection-of-security-products
7-Zip Mark-of-the-Web Support
https://www.7-zip.org/history.txt
Odd TCP Fast Open Packets
https://isc.sans.edu/forums/diary/Odd+TCP+Fast+Open+Packets+Anybody+understands+why/28766/
DFSCoerce NTLM Relay Attack
https://github.com/Wh04m1001/DFSCoerce
https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429
Windows Emergency Update Fixes Microsoft 365 Issues on ARM Devices
https://www.bleepingcomputer.com/news/microsoft/windows-emergency-update-fixes-microsoft-365-issues-on-arm-devices/
Safari Vulnerability Analysis
https://googleprojectzero.blogspot.com/2022/06/an-autopsy-on-zombie-in-wild-0-day.html
Internet Explorer Remnants Still an Issue
https://www.darkreading.com/vulnerabilities-threats/internet-explorer-will-likely-remain-an-attacker-target-for-some-time
Odd TCP Fast Open Packets
https://isc.sans.edu/forums/diary/Odd+TCP+Fast+Open+Packets+Anybody+understands+why/28766/
DFSCoerce NTLM Relay Attack
https://github.com/Wh04m1001/DFSCoerce
https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429
Windows Emergency Update Fixes Microsoft 365 Issues on ARM Devices
https://www.bleepingcomputer.com/news/microsoft/windows-emergency-update-fixes-microsoft-365-issues-on-arm-devices/
Safari Vulnerability Analysis
https://googleprojectzero.blogspot.com/2022/06/an-autopsy-on-zombie-in-wild-0-day.html
Internet Explorer Remnants Still an Issue
https://www.darkreading.com/vulnerabilities-threats/internet-explorer-will-likely-remain-an-attacker-target-for-some-time
Critical Vulnerability in Splunk Enterprise Deployment Server Functionality
https://isc.sans.edu/forums/diary/Critical+vulnerability+in+Splunk+Enterprises+deployment+server+functionality/28760/
Malspam Pushes Matanbuchus Malware Leads to Cobalt Strike
https://isc.sans.edu/forums/diary/Malspam+pushes+Matanbuchus+malware+leads+to+Cobalt+Strike/28752/
Proofpoint Discovers Potentially Dangerous Office 365 Functionality
https://www.proofpoint.com/us/blog/cloud-security/proofpoint-discovers-potentially-dangerous-microsoft-office-365-functionality
Critical Vulnerability in Splunk Enterprise Deployment Server Functionality
https://isc.sans.edu/forums/diary/Critical+vulnerability+in+Splunk+Enterprises+deployment+server+functionality/28760/
Malspam Pushes Matanbuchus Malware Leads to Cobalt Strike
https://isc.sans.edu/forums/diary/Malspam+pushes+Matanbuchus+malware+leads+to+Cobalt+Strike/28752/
Proofpoint Discovers Potentially Dangerous Office 365 Functionality
https://www.proofpoint.com/us/blog/cloud-security/proofpoint-discovers-potentially-dangerous-microsoft-office-365-functionality
Houdini is Back Delivered Through a JavaScript Dropper
https://isc.sans.edu/forums/diary/Houdini+is+Back+Delivered+Through+a+JavaScript+Dropper/28746/
Drifting Cloud: Zero-Day Sophos Firewall Exploitation
https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/
Exploiting a Heap Overflow in the FreeBSD Wi-Fi Stack
https://www.zerodayinitiative.com/blog/2022/6/15/cve-2022-23088-exploiting-a-heap-overflow-in-the-freebsd-wi-fi-stack
Cisco Email Security Appliance and Cisco Secure Email and Web Manager
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-esa-auth-bypass-66kEcxQD
Analyzing the Fastjson "Auto Type Bypass" RCE vulnerability
https://jfrog.com/blog/cve-2022-25845-analyzing-the-fastjson-auto-type-bypass-rce-vulnerability/
Houdini is Back Delivered Through a JavaScript Dropper
https://isc.sans.edu/forums/diary/Houdini+is+Back+Delivered+Through+a+JavaScript+Dropper/28746/
Drifting Cloud: Zero-Day Sophos Firewall Exploitation
https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/
Exploiting a Heap Overflow in the FreeBSD Wi-Fi Stack
https://www.zerodayinitiative.com/blog/2022/6/15/cve-2022-23088-exploiting-a-heap-overflow-in-the-freebsd-wi-fi-stack
Cisco Email Security Appliance and Cisco Secure Email and Web Manager
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-esa-auth-bypass-66kEcxQD
Analyzing the Fastjson "Auto Type Bypass" RCE vulnerability
https://jfrog.com/blog/cve-2022-25845-analyzing-the-fastjson-auto-type-bypass-rce-vulnerability/
Terraforming Honeypots: Using IaaC & Cloud to Attract Attacks
https://isc.sans.edu/forums/diary/Terraforming+Honeypots+Installing+DShield+Sensors+in+the+Cloud/28748/
Zimbra Email - Stealing Clear=Text Credenitals via Memcache Injection
https://blog.sonarsource.com/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/
Cloud Middleware Dataset
https://github.com/wiz-sec/cloud-middleware-dataset
CVE-2022-26937 Windows Network File System NLM Portmap Stack Buffer Overflow
https://www.zerodayinitiative.com/blog/2022/6/7/cve-2022-26937-microsoft-windows-network-file-system-nlm-portmap-stack-buffer-overflow
Citrix Application Delivery Management Security Bulletin
https://support.citrix.com/article/CTX460016/citrix-application-delivery-management-security-bulletin-for-cve202227511-and-cve202227512
Hardcoded Backdoor User and Outdated Software Components in Nexans FTTO GigaSwitch
https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/
Terraforming Honeypots: Using IaaC & Cloud to Attract Attacks
https://isc.sans.edu/forums/diary/Terraforming+Honeypots+Installing+DShield+Sensors+in+the+Cloud/28748/
Zimbra Email - Stealing Clear=Text Credenitals via Memcache Injection
https://blog.sonarsource.com/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/
Cloud Middleware Dataset
https://github.com/wiz-sec/cloud-middleware-dataset
CVE-2022-26937 Windows Network File System NLM Portmap Stack Buffer Overflow
https://www.zerodayinitiative.com/blog/2022/6/7/cve-2022-26937-microsoft-windows-network-file-system-nlm-portmap-stack-buffer-overflow
Citrix Application Delivery Management Security Bulletin
https://support.citrix.com/article/CTX460016/citrix-application-delivery-management-security-bulletin-for-cve202227511-and-cve202227512
Hardcoded Backdoor User and Outdated Software Components in Nexans FTTO GigaSwitch
https://sec-consult.com/vulnerability-lab/advisory/hardcoded-backdoor-user-outdated-software-components-nexans-ftto-gigaswitch/
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+June+2022+Patch+Tuesday/28742/
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
SynLapse Vulnerability
https://orca.security/resources/blog/synlapse-critical-azure-synapse-analytics-service-vulnerability/
Hertzbleed Attack
https://www.hertzbleed.com
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+June+2022+Patch+Tuesday/28742/
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
SynLapse Vulnerability
https://orca.security/resources/blog/synlapse-critical-azure-synapse-analytics-service-vulnerability/
Hertzbleed Attack
https://www.hertzbleed.com
Translating Saitama's DNS Tunneling
https://isc.sans.edu/forums/diary/Translating+Saitamas+DNS+tunneling+messages/28738/
Travis CI Logs Expose Users to Cyber Attacks
https://blog.aquasec.com/travis-ci-security
Linux Threat Hunting: "Syslogk" a kernel rootkit found under development in the wild
https://decoded.avast.io/davidalvarez/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild/
Mitel Desk Phone Backdoor
https://blog.syss.com/posts/rooting-mitel-desk-phones-through-the-backdoor/
Translating Saitama's DNS Tunneling
https://isc.sans.edu/forums/diary/Translating+Saitamas+DNS+tunneling+messages/28738/
Travis CI Logs Expose Users to Cyber Attacks
https://blog.aquasec.com/travis-ci-security
Linux Threat Hunting: "Syslogk" a kernel rootkit found under development in the wild
https://decoded.avast.io/davidalvarez/linux-threat-hunting-syslogk-a-kernel-rootkit-found-under-development-in-the-wild/
Mitel Desk Phone Backdoor
https://blog.syss.com/posts/rooting-mitel-desk-phones-through-the-backdoor/
EPSScall: An Exploit Prediction Scoring System App
https://isc.sans.edu/forums/diary/EPSScall+An+Exploit+Prediction+Scoring+System+App/28732/
PACMan Attack
https://pacmanattack.com
https://twitter.com/wdormann/status/1535245913857351680
Carrier LenelS2 HID Mercury access panel vulnerability
https://www.cisa.gov/uscert/ics/advisories/icsa-22-153-01
Malicious Python Modules
https://www.bleepingcomputer.com/news/security/pypi-package-keep-mistakenly-included-a-password-stealer/
EPSScall: An Exploit Prediction Scoring System App
https://isc.sans.edu/forums/diary/EPSScall+An+Exploit+Prediction+Scoring+System+App/28732/
PACMan Attack
https://pacmanattack.com
https://twitter.com/wdormann/status/1535245913857351680
Carrier LenelS2 HID Mercury access panel vulnerability
https://www.cisa.gov/uscert/ics/advisories/icsa-22-153-01
Malicious Python Modules
https://www.bleepingcomputer.com/news/security/pypi-package-keep-mistakenly-included-a-password-stealer/
TA570 QBot attempts to exploit CVE-2022-30190 (Follina)
https://isc.sans.edu/forums/diary/TA570+Qakbot+Qbot+tries+CVE202230190+Follina+exploit+msmsdt/28728/
Analysis of a Facebook Phishing Campaign
https://pixmsecurity.com/blog/blog/phishing-tactics-how-a-threat-actor-stole-1m-credentials-in-4-months/
Zyxel Security Advisory
https://www.zyxel.com/support/Zyxel-security-advisory-for-CRLF-injection-vulnerability-in-some-legacy-firewalls.shtml
Fujitsu Centricstor Vulnerability
https://research.nccgroup.com/2022/05/27/technical-advisory-fujitsu-centricstor-control-center-v8-1-unauthenticated-command-injection/
Meeting Owl Vulnerablities
https://www.modzero.com/static/meetingowl/Meeting_Owl_Pro_Security_Disclosure_Report_RELEASE.pdf
TA570 QBot attempts to exploit CVE-2022-30190 (Follina)
https://isc.sans.edu/forums/diary/TA570+Qakbot+Qbot+tries+CVE202230190+Follina+exploit+msmsdt/28728/
Analysis of a Facebook Phishing Campaign
https://pixmsecurity.com/blog/blog/phishing-tactics-how-a-threat-actor-stole-1m-credentials-in-4-months/
Zyxel Security Advisory
https://www.zyxel.com/support/Zyxel-security-advisory-for-CRLF-injection-vulnerability-in-some-legacy-firewalls.shtml
Fujitsu Centricstor Vulnerability
https://research.nccgroup.com/2022/05/27/technical-advisory-fujitsu-centricstor-control-center-v8-1-unauthenticated-command-injection/
Meeting Owl Vulnerablities
https://www.modzero.com/static/meetingowl/Meeting_Owl_Pro_Security_Disclosure_Report_RELEASE.pdf
SANS RSA Panel
(sorry, video no longer available)
Atlassian Confluence Attacks
https://isc.sans.edu/forums/diary/Atlassian+Confluence+Exploits+Seen+By+Our+Honeypots+CVE202226134/28722/
Fake CClenaer Malvertisements
https://blog.avast.com/fakecrack-campaign
Weakness in Verbatim Keypad Secure USB Drive
https://blog.syss.com/posts/hacking-usb-flash-drives-part-1/
SANS RSA Panel
(sorry, video no longer available)
Atlassian Confluence Attacks
https://isc.sans.edu/forums/diary/Atlassian+Confluence+Exploits+Seen+By+Our+Honeypots+CVE202226134/28722/
Fake CClenaer Malvertisements
https://blog.avast.com/fakecrack-campaign
Weakness in Verbatim Keypad Secure USB Drive
https://blog.syss.com/posts/hacking-usb-flash-drives-part-1/
The Trouble With Microsoft's Troubleshooters
https://irsl.medium.com/the-trouble-with-microsofts-troubleshooters-6e32fc80b8bd
QBot Uses Follina
https://twitter.com/threatinsight/status/1534227444915482625
Deadbolt Ransomware
https://www.trendmicro.com/en_us/research/22/f/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-mult.html
Google Android Updates
https://source.android.com/security/bulletin/2022-06-01?hl=en
The Trouble With Microsoft's Troubleshooters
https://irsl.medium.com/the-trouble-with-microsofts-troubleshooters-6e32fc80b8bd
QBot Uses Follina
https://twitter.com/threatinsight/status/1534227444915482625
Deadbolt Ransomware
https://www.trendmicro.com/en_us/research/22/f/closing-the-door-deadbolt-ransomware-locks-out-vendors-with-mult.html
Google Android Updates
https://source.android.com/security/bulletin/2022-06-01?hl=en
MS-MSDT RTF Maldocs Analysis oledump Plugins
https://isc.sans.edu/forums/diary/msmsdt+RTF+Maldoc+Analysis+oledump+Plugins/28718/
Cybercriminals Exploit Reverse Tunnel Services and URL Shorteners
https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/
Unpatched Horde Webmail Bug
https://blog.sonarsource.com/horde-webmail-rce-via-email/
Clickstudio (Passwordstate) Code Signing Cert Used by Follina Malware
https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/
MS-MSDT RTF Maldocs Analysis oledump Plugins
https://isc.sans.edu/forums/diary/msmsdt+RTF+Maldoc+Analysis+oledump+Plugins/28718/
Cybercriminals Exploit Reverse Tunnel Services and URL Shorteners
https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/
Unpatched Horde Webmail Bug
https://blog.sonarsource.com/horde-webmail-rce-via-email/
Clickstudio (Passwordstate) Code Signing Cert Used by Follina Malware
https://cloudsek.com/whitepapers_reports/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/
Sandbox Evasion... With Just a Filename!
https://isc.sans.edu/forums/diary/Sandbox+Evasion+With+Just+a+Filename/28708/
Atlassian Exploit Released
https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/
GitLab Critical Security Release
https://about.gitlab.com/releases/2022/06/01/critical-security-release-gitlab-15-0-1-released/
U-Boot Vulnerablities
https://research.nccgroup.com/2022/06/03/technical-advisory-multiple-vulnerabilities-in-u-boot-cve-2022-30790-cve-2022-30552/
Unisoc Baseband Chip Vulnerability
https://research.checkpoint.com/2022/vulnerability-within-the-unisoc-baseband/
Sandbox Evasion... With Just a Filename!
https://isc.sans.edu/forums/diary/Sandbox+Evasion+With+Just+a+Filename/28708/
Atlassian Exploit Released
https://www.rapid7.com/blog/post/2022/06/02/active-exploitation-of-confluence-cve-2022-26134/
GitLab Critical Security Release
https://about.gitlab.com/releases/2022/06/01/critical-security-release-gitlab-15-0-1-released/
U-Boot Vulnerablities
https://research.nccgroup.com/2022/06/03/technical-advisory-multiple-vulnerabilities-in-u-boot-cve-2022-30790-cve-2022-30552/
Unisoc Baseband Chip Vulnerability
https://research.checkpoint.com/2022/vulnerability-within-the-unisoc-baseband/
Quick Answers in Incident Response RECmd.exe
https://isc.sans.edu/forums/diary/Quick+Answers+in+Incident+Response+RECmdexe/28706/
Zero-Day Exploitation of Atlassian Confluence
https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/
https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html
Korenix Technology JetPort Backdoor
https://sec-consult.com/vulnerability-lab/advisory/backdoor-account-in-korenix-technology-jetport-series/
Elasticsearch Data Wiped
https://www.secureworks.com/blog/unsecured-elasticsearch-data-replaced-with-ransom-note
Quick Answers in Incident Response RECmd.exe
https://isc.sans.edu/forums/diary/Quick+Answers+in+Incident+Response+RECmdexe/28706/
Zero-Day Exploitation of Atlassian Confluence
https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/
https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html
Korenix Technology JetPort Backdoor
https://sec-consult.com/vulnerability-lab/advisory/backdoor-account-in-korenix-technology-jetport-series/
Elasticsearch Data Wiped
https://www.secureworks.com/blog/unsecured-elasticsearch-data-replaced-with-ransom-note
HTML Phishing Attachments - Now With Anti-Analysis Features
https://isc.sans.edu/forums/diary/HTML+phishing+attachments+now+with+antianalysis+features/28702/
Unofficial Patch for CVE-2022-30190 (Follina)
https://blog.0patch.com/2022/06/free-micropatches-for-follina-microsoft.html
Windows Search Vulnerability
https://www.bleepingcomputer.com/news/security/new-windows-search-zero-day-added-to-microsoft-protocol-nightmare/
Call Forwarding Used to Compromise WhatsApp Accounts
https://www.linkedin.com/posts/fb1h2s_beware-here-is-how-whatsapp-accounts-are-activity-6934386561048264704-NnFf/?utm_source=linkedin_share&utm_medium=member_desktop_web
Badkeys in Fuji Xerox and Canon Printers
https://fermatattack.secvuln.info
HTML Phishing Attachments - Now With Anti-Analysis Features
https://isc.sans.edu/forums/diary/HTML+phishing+attachments+now+with+antianalysis+features/28702/
Unofficial Patch for CVE-2022-30190 (Follina)
https://blog.0patch.com/2022/06/free-micropatches-for-follina-microsoft.html
Windows Search Vulnerability
https://www.bleepingcomputer.com/news/security/new-windows-search-zero-day-added-to-microsoft-protocol-nightmare/
Call Forwarding Used to Compromise WhatsApp Accounts
https://www.linkedin.com/posts/fb1h2s_beware-here-is-how-whatsapp-accounts-are-activity-6934386561048264704-NnFf/?utm_source=linkedin_share&utm_medium=member_desktop_web
Badkeys in Fuji Xerox and Canon Printers
https://fermatattack.secvuln.info
Follina Update
https://isc.sans.edu/forums/diary/First+Exploitation+of+Follina+Seen+in+the+Wild/28698/
https://isc.sans.edu/forums/diary/New+Microsoft+Office+Attack+Vector+via+msmsdt+Protocol+Scheme+CVE202230190/28694/
Open Automation Software Platform Vulnerability
https://blog.talosintelligence.com/2022/05/vuln-spotlight-open-automation-platform.html
Over 3.6 million MySQL servers found exposed on the Internet
https://www.bleepingcomputer.com/news/security/over-36-million-mysql-servers-found-exposed-on-the-internet/
Follina Update
https://isc.sans.edu/forums/diary/First+Exploitation+of+Follina+Seen+in+the+Wild/28698/
https://isc.sans.edu/forums/diary/New+Microsoft+Office+Attack+Vector+via+msmsdt+Protocol+Scheme+CVE202230190/28694/
Open Automation Software Platform Vulnerability
https://blog.talosintelligence.com/2022/05/vuln-spotlight-open-automation-platform.html
Over 3.6 million MySQL servers found exposed on the Internet
https://www.bleepingcomputer.com/news/security/over-36-million-mysql-servers-found-exposed-on-the-internet/
New Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme
https://isc.sans.edu/forums/diary/New+Microsoft+Office+Attack+Vector+via+msmsdt+Protocol+Scheme/28694/
New Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme
https://isc.sans.edu/forums/diary/New+Microsoft+Office+Attack+Vector+via+msmsdt+Protocol+Scheme/28694/
Huge Signed PE Files
https://isc.sans.edu/forums/diary/Huge+Signed+PE+File/28686/
VMWare Authentication Bypass PoC
https://www.horizon3.ai/vmware-authentication-bypass-vulnerability-cve-2022-22972-technical-deep-dive/
Quanta Server BMC Vulnerability
https://eclypsium.com/2022/05/26/quanta-servers-still-vulnerable-to-pantsdown/
Windows 11 and Server 2022 Update Prevent Trend Micro Ransomware Protection
https://success.trendmicro.com/dcx/s/solution/000291066?language=en_US
Nate Street: Advancing SIEM Log Management Strategies through Vendor-Agnostic Measurement
https://www.sans.edu/cyber-research/38685/
Huge Signed PE Files
https://isc.sans.edu/forums/diary/Huge+Signed+PE+File/28686/
VMWare Authentication Bypass PoC
https://www.horizon3.ai/vmware-authentication-bypass-vulnerability-cve-2022-22972-technical-deep-dive/
Quanta Server BMC Vulnerability
https://eclypsium.com/2022/05/26/quanta-servers-still-vulnerable-to-pantsdown/
Windows 11 and Server 2022 Update Prevent Trend Micro Ransomware Protection
https://success.trendmicro.com/dcx/s/solution/000291066?language=en_US
Nate Street: Advancing SIEM Log Management Strategies through Vendor-Agnostic Measurement
https://www.sans.edu/cyber-research/38685/
Using NMAP to Assess Hosts in Load Balanced Clusters
https://isc.sans.edu/forums/diary/Using+NMAP+to+Assess+Hosts+in+Load+Balanced+Clusters/28682/
Attacker Modifying Libraries Claims "Research"
https://www.bleepingcomputer.com/news/security/hacker-says-hijacking-libraries-stealing-aws-keys-was-ethical-research/
Heroku GitHub Integration Re-Enabled Again
https://blog.heroku.com/github-integration-update
Serious security vulnerablity in Tails 5.0
https://tails.boum.org/security/prototype_pollution/index.en.html
Google Chrome Update
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html
Using NMAP to Assess Hosts in Load Balanced Clusters
https://isc.sans.edu/forums/diary/Using+NMAP+to+Assess+Hosts+in+Load+Balanced+Clusters/28682/
Attacker Modifying Libraries Claims "Research"
https://www.bleepingcomputer.com/news/security/hacker-says-hijacking-libraries-stealing-aws-keys-was-ethical-research/
Heroku GitHub Integration Re-Enabled Again
https://blog.heroku.com/github-integration-update
Serious security vulnerablity in Tails 5.0
https://tails.boum.org/security/prototype_pollution/index.en.html
Google Chrome Update
https://chromereleases.googleblog.com/2022/05/stable-channel-update-for-desktop_24.html
ctx Python Library Updated with "Extra" Features
https://isc.sans.edu/forums/diary/ctx+Python+Library+Updated+with+Extra+Features/28678/
Zoom Updates
https://explore.zoom.us/en/trust/security/security-bulletin/
VMWare Exploit About to Be Released
https://twitter.com/Horizon3Attack/status/1528935531333177344
Zyxel Firewalls, AP Controllers, APs Patch
https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml
ctx Python Library Updated with "Extra" Features
https://isc.sans.edu/forums/diary/ctx+Python+Library+Updated+with+Extra+Features/28678/
Zoom Updates
https://explore.zoom.us/en/trust/security/security-bulletin/
VMWare Exploit About to Be Released
https://twitter.com/Horizon3Attack/status/1528935531333177344
Zyxel Firewalls, AP Controllers, APs Patch
https://www.zyxel.com/support/multiple-vulnerabilities-of-firewalls-AP-controllers-and-APs.shtml
Attacker Scanning for jQuery-File-Upload
https://isc.sans.edu/forums/diary/Attacker+Scanning+for+jQueryFileUpload/28674/
Oracle Security Alert Advisory - CVE-2022-21500
https://www.oracle.com/security-alerts/alert-cve-2022-21500.html
How to find NPM dependencies vulnerable to account hijacking
https://www.theregister.com/2022/05/23/npm_dependencies_vulnerable/
Pre-hijacked accounts
https://arxiv.org/pdf/2205.10174.pdf
Attacker Scanning for jQuery-File-Upload
https://isc.sans.edu/forums/diary/Attacker+Scanning+for+jQueryFileUpload/28674/
Oracle Security Alert Advisory - CVE-2022-21500
https://www.oracle.com/security-alerts/alert-cve-2022-21500.html
How to find NPM dependencies vulnerable to account hijacking
https://www.theregister.com/2022/05/23/npm_dependencies_vulnerable/
Pre-hijacked accounts
https://arxiv.org/pdf/2205.10174.pdf
A "Zip Bomb" to Bypass Security Controls & Sandboxes
https://isc.sans.edu/forums/diary/A+Zip+Bomb+to+Bypass+Security+Controls+Sandboxes/28670/
Cisco IOS XR Software Health Check Open Port Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-redis-ABJyE5xK
pwn2own Vancouver 2022 Results
https://www.zerodayinitiative.com/blog/2022/5/18/pwn2own-vancouver-2022-the-results#three
Malicious PyPi Packages Drop Cobalt Strike
https://blog.sonatype.com/new-pymafka-malicious-package-drops-cobalt-strike-on-macos-windows-linux
Security Advisory for BR200, BR500 and PSV-2021-0286
https://kb.netgear.com/000064712/Security-Advisory-for-Multiple-Security-Vulnerabilities-on-BR200-and-BR500-PSV-2021-0286
A "Zip Bomb" to Bypass Security Controls & Sandboxes
https://isc.sans.edu/forums/diary/A+Zip+Bomb+to+Bypass+Security+Controls+Sandboxes/28670/
Cisco IOS XR Software Health Check Open Port Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxr-redis-ABJyE5xK
pwn2own Vancouver 2022 Results
https://www.zerodayinitiative.com/blog/2022/5/18/pwn2own-vancouver-2022-the-results#three
Malicious PyPi Packages Drop Cobalt Strike
https://blog.sonatype.com/new-pymafka-malicious-package-drops-cobalt-strike-on-macos-windows-linux
Security Advisory for BR200, BR500 and PSV-2021-0286
https://kb.netgear.com/000064712/Security-Advisory-for-Multiple-Security-Vulnerabilities-on-BR200-and-BR500-PSV-2021-0286
Bumblebee Malware from TransferXL URLs
https://isc.sans.edu/forums/diary/Bumblebee+Malware+from+TransferXL+URLs/28664/
Microsoft Out-of-Band Update fixes Authentication Issues
https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#you-might-see-authentication-failures-on-the-server-or-client-for-services
Sonicwall Patch for SMA 1000
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0010
QNAP NAS Deadbolt Ransomware
https://www.qnap.com/en/security-news/2022/take-immediate-actions-to-secure-qnap-nas-and-update-qts-to-the-latest-available-version
380,000 open Kubernetes API Servers
https://www.shadowserver.org/news/over-380-000-open-kubernetes-api-servers/
Doj Annnounces New Polciy for Charging Cases under the Computer Fraud and Abuse Act
https://www.justice.gov/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act
Bumblebee Malware from TransferXL URLs
https://isc.sans.edu/forums/diary/Bumblebee+Malware+from+TransferXL+URLs/28664/
Microsoft Out-of-Band Update fixes Authentication Issues
https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#you-might-see-authentication-failures-on-the-server-or-client-for-services
Sonicwall Patch for SMA 1000
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0010
QNAP NAS Deadbolt Ransomware
https://www.qnap.com/en/security-news/2022/take-immediate-actions-to-secure-qnap-nas-and-update-qts-to-the-latest-available-version
380,000 open Kubernetes API Servers
https://www.shadowserver.org/news/over-380-000-open-kubernetes-api-servers/
Doj Annnounces New Polciy for Charging Cases under the Computer Fraud and Abuse Act
https://www.justice.gov/opa/pr/department-justice-announces-new-policy-charging-cases-under-computer-fraud-and-abuse-act
VMWare Flaws
https://core.vmware.com/vmsa-2022-0014-questions-answers-faq
https://blog.barracuda.com/2022/05/17/threat-spotlight-attempts-to-exploit-new-vmware-vulnerabilities/
Tesla BLE Proximity Authentication Vulnerable to Relay Attacks
https://research.nccgroup.com/2022/05/15/technical-advisory-ble-proximity-authentication-vulnerable-to-relay-attacks/
Credit Card Scraping via Malicious PHP Code
https://www.ic3.gov/Media/News/2022/220516.pdf
Microsoft updating Delegated Admin Privileges
https://docs.microsoft.com/en-gb/partner-center/announcements/2022-may#13
VMWare Flaws
https://core.vmware.com/vmsa-2022-0014-questions-answers-faq
https://blog.barracuda.com/2022/05/17/threat-spotlight-attempts-to-exploit-new-vmware-vulnerabilities/
Tesla BLE Proximity Authentication Vulnerable to Relay Attacks
https://research.nccgroup.com/2022/05/15/technical-advisory-ble-proximity-authentication-vulnerable-to-relay-attacks/
Credit Card Scraping via Malicious PHP Code
https://www.ic3.gov/Media/News/2022/220516.pdf
Microsoft updating Delegated Admin Privileges
https://docs.microsoft.com/en-gb/partner-center/announcements/2022-may#13
Use Your Browser Internal Password Vault... or Not?
https://isc.sans.edu/forums/diary/Use+Your+Browser+Internal+Password+Vault+or+Not/28658/
SQL Server Brute Forcing
https://twitter.com/MsftSecIntel/status/1526680337216114693
UpdateAgent Adapts Again
https://www.jamf.com/blog/updateagent-adapts-again/
Updated Exploited Vulnerabilities
https://www.cisa.gov/uscert/ncas/current-activity/2022/05/10/cisa-adds-one-known-exploited-vulnerability-catalog
Use Your Browser Internal Password Vault... or Not?
https://isc.sans.edu/forums/diary/Use+Your+Browser+Internal+Password+Vault+or+Not/28658/
SQL Server Brute Forcing
https://twitter.com/MsftSecIntel/status/1526680337216114693
UpdateAgent Adapts Again
https://www.jamf.com/blog/updateagent-adapts-again/
Updated Exploited Vulnerabilities
https://www.cisa.gov/uscert/ncas/current-activity/2022/05/10/cisa-adds-one-known-exploited-vulnerability-catalog
Apple Patches Everything
https://isc.sans.edu/forums/diary/Apple+Patches+Everything/28654/
Evil Never Sleeps: When Wireless Malware Stays on After Turning Off iPhones
https://arxiv.org/pdf/2205.06114.pdf
Third-Party Web Trackers Log What You Type Before Submitting
https://homes.esat.kuleuven.be/~asenol/leaky-forms/
Apple Patches Everything
https://isc.sans.edu/forums/diary/Apple+Patches+Everything/28654/
Evil Never Sleeps: When Wireless Malware Stays on After Turning Off iPhones
https://arxiv.org/pdf/2205.06114.pdf
Third-Party Web Trackers Log What You Type Before Submitting
https://homes.esat.kuleuven.be/~asenol/leaky-forms/
From 0-Day to Mirai: 7 days of BIG-IP Exploits
https://isc.sans.edu/forums/diary/From+0Day+to+Mirai+7+days+of+BIGIP+Exploits/28644/
Sonicwall Vulnerabilities Patched
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0009
Zonealarm Patch
https://www.zonealarm.com/software/extreme-security/release-history
Taking over npm account
https://thehackerblog.com/zero-days-without-incident-compromising-angular-via-expired-npm-publisher-email-domains-7kZplW4x/
From 0-Day to Mirai: 7 days of BIG-IP Exploits
https://isc.sans.edu/forums/diary/From+0Day+to+Mirai+7+days+of+BIGIP+Exploits/28644/
Sonicwall Vulnerabilities Patched
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0009
Zonealarm Patch
https://www.zonealarm.com/software/extreme-security/release-history
Taking over npm account
https://thehackerblog.com/zero-days-without-incident-compromising-angular-via-expired-npm-publisher-email-domains-7kZplW4x/
When Get-WebRequest Fails You
https://isc.sans.edu/forums/diary/When+GetWebRequest+Fails+You/28640/
HP PC BIOS Security Updates
https://support.hp.com/us-en/document/ish_6184733-6184761-16/hpsbhf03788
INTEL BIOS Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00601.html
Zyxel RCE Vulnerability
https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/
When Get-WebRequest Fails You
https://isc.sans.edu/forums/diary/When+GetWebRequest+Fails+You/28640/
HP PC BIOS Security Updates
https://support.hp.com/us-en/document/ish_6184733-6184761-16/hpsbhf03788
INTEL BIOS Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00601.html
Zyxel RCE Vulnerability
https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/
TA578 Using Thread-Hijacked Emails to Push ISO Files for Bumblebee Malware
https://isc.sans.edu/forums/diary/TA578+using+threadhijacked+emails+to+push+ISO+files+for+Bumblebee+malware/28636/
Google Drive Emerges as Top App for Malware Downloads
https://www.helpnetsecurity.com/2022/05/11/malicious-pdf-search-engines/
Vanity URL Abuse
https://www.varonis.com/blog/url-spoofing
npm Supply Chain Attack Turns Out to be Part of Penetration Test
https://jfrog.com/blog/npm-supply-chain-attack-targets-german-based-companies/
TA578 Using Thread-Hijacked Emails to Push ISO Files for Bumblebee Malware
https://isc.sans.edu/forums/diary/TA578+using+threadhijacked+emails+to+push+ISO+files+for+Bumblebee+malware/28636/
Google Drive Emerges as Top App for Malware Downloads
https://www.helpnetsecurity.com/2022/05/11/malicious-pdf-search-engines/
Vanity URL Abuse
https://www.varonis.com/blog/url-spoofing
npm Supply Chain Attack Turns Out to be Part of Penetration Test
https://jfrog.com/blog/npm-supply-chain-attack-targets-german-based-companies/
Microsoft May 2022 Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+May+2022+Patch+Tuesday/28632/
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
npm "foreach" package domain takeover
https://www.theregister.com/2022/05/10/security_npm_email/
Microsoft May 2022 Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+May+2022+Patch+Tuesday/28632/
Adobe Updates
https://helpx.adobe.com/security/security-bulletin.html
npm "foreach" package domain takeover
https://www.theregister.com/2022/05/10/security_npm_email/
Octopus Backdoor is Back with a New Embedded Obfuscated Bat File
https://isc.sans.edu/forums/diary/Octopus+Backdoor+is+Back+with+a+New+Embedded+Obfuscated+Bat+File/28628/#comments
CVE-2022-1388 (BIG-IP) Exploits
https://twitter.com/sans_isc/status/1523741896707043328
https://github.com/horizon3ai/CVE-2022-1388
Trend Micro False Positive Aftermath
https://success.trendmicro.com/dcx/s/solution/000290966?language=en_US
Microsoft Azure
https://orca.security/resources/blog/azure-synapse-analytics-security-advisory/
https://msrc-blog.microsoft.com/2022/05/09/vulnerability-mitigated-in-the-third-party-data-connector-used-in-azure-synapse-pipelines-and-azure-data-factory-cve-2022-29972/
Octopus Backdoor is Back with a New Embedded Obfuscated Bat File
https://isc.sans.edu/forums/diary/Octopus+Backdoor+is+Back+with+a+New+Embedded+Obfuscated+Bat+File/28628/#comments
CVE-2022-1388 (BIG-IP) Exploits
https://twitter.com/sans_isc/status/1523741896707043328
https://github.com/horizon3ai/CVE-2022-1388
Trend Micro False Positive Aftermath
https://success.trendmicro.com/dcx/s/solution/000290966?language=en_US
Microsoft Azure
https://orca.security/resources/blog/azure-synapse-analytics-security-advisory/
https://msrc-blog.microsoft.com/2022/05/09/vulnerability-mitigated-in-the-third-party-data-connector-used-in-azure-synapse-pipelines-and-azure-data-factory-cve-2022-29972/
F5 BIG-IP Unauthenticated RCE Vulnerability (CVE-2022-1388)
https://isc.sans.edu/forums/diary/F5+BIGIP+Unauthenticated+RCE+Vulnerability+CVE20221388/28624/
QNAP QVR Update
https://www.qnap.com/de-de/security-advisory/qsa-22-07
Raspberry Robin Worm
https://redcanary.com/blog/raspberry-robin/
rubygems CVE-2022-29176 explained
https://greg.molnar.io/blog/rubygems-cve-2022-29176/
What is the simples malware in the world?
https://isc.sans.edu/forums/diary/What+is+the+simplest+malware+in+the+world/28620/
F5 BIG-IP Unauthenticated RCE Vulnerability (CVE-2022-1388)
https://isc.sans.edu/forums/diary/F5+BIGIP+Unauthenticated+RCE+Vulnerability+CVE20221388/28624/
QNAP QVR Update
https://www.qnap.com/de-de/security-advisory/qsa-22-07
Raspberry Robin Worm
https://redcanary.com/blog/raspberry-robin/
rubygems CVE-2022-29176 explained
https://greg.molnar.io/blog/rubygems-cve-2022-29176/
What is the simples malware in the world?
https://isc.sans.edu/forums/diary/What+is+the+simplest+malware+in+the+world/28620/
Password-protected Excel Spreadsheet Pushes Remcos RAT
https://isc.sans.edu/forums/diary/Passwordprotected+Excel+spreadsheet+pushes+Remcos+RAT/28616/
Microsoft, Apple, Google Accelated FIDO Standard Implementation
https://www.theregister.com/2022/05/05/microsoft-apple-google-fido/
Heroku Admits Breach
https://status.heroku.com/incidents/2413
Password-protected Excel Spreadsheet Pushes Remcos RAT
https://isc.sans.edu/forums/diary/Passwordprotected+Excel+spreadsheet+pushes+Remcos+RAT/28616/
Microsoft, Apple, Google Accelated FIDO Standard Implementation
https://www.theregister.com/2022/05/05/microsoft-apple-google-fido/
Heroku Admits Breach
https://status.heroku.com/incidents/2413
Finding the Real "Last Patched" Day (Interim Version)
https://isc.sans.edu/forums/diary/Finding+the+Real+Last+Patched+Day+Interim+Version/28610/
Fake Windows Updates Install Ransomware
https://www.bleepingcomputer.com/news/security/fake-windows-10-updates-infect-you-with-magniber-ransomware/
Vulnerablities in Ransomware
https://www.malvuln.com
Heroku Forces Password Reset
https://status.heroku.com/incidents/2413
Cisco Patches Enterprise NFV Infrastructure Software
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-NFVIS-MUL-7DySRX9
Big-IP iControl REST Vulnerability
https://support.f5.com/csp/article/K23605346
Finding the Real "Last Patched" Day (Interim Version)
https://isc.sans.edu/forums/diary/Finding+the+Real+Last+Patched+Day+Interim+Version/28610/
Fake Windows Updates Install Ransomware
https://www.bleepingcomputer.com/news/security/fake-windows-10-updates-infect-you-with-magniber-ransomware/
Vulnerablities in Ransomware
https://www.malvuln.com
Heroku Forces Password Reset
https://status.heroku.com/incidents/2413
Cisco Patches Enterprise NFV Infrastructure Software
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-NFVIS-MUL-7DySRX9
Big-IP iControl REST Vulnerability
https://support.f5.com/csp/article/K23605346
Some Honeypot Updates
https://isc.sans.edu/forums/diary/Some+Honeypot+Updates/28608/
TLStorm 2 - NanoSSL TLS Library Misuse
https://www.armis.com/blog/tlstorm-2-nanossl-tls-library-misuse-leads-to-vulnerabilities-in-common-switches/
Unpatched DNS Bug in uClibc and uClibc-ng Library
https://www.nozominetworks.com/blog/nozomi-networks-discovers-unpatched-DNS-bug-in-popular-c-standard-library-putting-iot-at-risk/
Abusing Security Software to Sideload PlugX and ShadowPad
https://www.sentinelone.com/labs/moshen-dragons-triad-and-error-approach-abusing-security-software-to-sideload-plugx-and-shadowpad/
Microsoft Edge Update Triggers Trend Micro AV
https://success.trendmicro.com/forum/s/question/0D54T00001QDqzgSAD/we-are-getting-this-message-from-every-client-since-several-minutesis-it-a-false-positiv-error-or-do-we-have-a-real-trojaner-problem-
Some Honeypot Updates
https://isc.sans.edu/forums/diary/Some+Honeypot+Updates/28608/
TLStorm 2 - NanoSSL TLS Library Misuse
https://www.armis.com/blog/tlstorm-2-nanossl-tls-library-misuse-leads-to-vulnerabilities-in-common-switches/
Unpatched DNS Bug in uClibc and uClibc-ng Library
https://www.nozominetworks.com/blog/nozomi-networks-discovers-unpatched-DNS-bug-in-popular-c-standard-library-putting-iot-at-risk/
Abusing Security Software to Sideload PlugX and ShadowPad
https://www.sentinelone.com/labs/moshen-dragons-triad-and-error-approach-abusing-security-software-to-sideload-plugx-and-shadowpad/
Microsoft Edge Update Triggers Trend Micro AV
https://success.trendmicro.com/forum/s/question/0D54T00001QDqzgSAD/we-are-getting-this-message-from-every-client-since-several-minutesis-it-a-false-positiv-error-or-do-we-have-a-real-trojaner-problem-
Detecting VSTO Office Files with ExifTool
https://isc.sans.edu/forums/diary/Detecting+VSTO+Office+Files+With+ExifTool/28604/
The Gmail SMTP Relay Service Exploit
https://www.avanan.com/blog/the-gmail-smtp-relay-service-exploit
OpenSSF Package Analysis
https://openssf.org/blog/2022/04/28/introducing-package-analysis-scanning-open-source-packages-for-malicious-behavior/
M1 Prefetcher Data Leak
https://www.prefetchers.info
Detecting VSTO Office Files with ExifTool
https://isc.sans.edu/forums/diary/Detecting+VSTO+Office+Files+With+ExifTool/28604/
The Gmail SMTP Relay Service Exploit
https://www.avanan.com/blog/the-gmail-smtp-relay-service-exploit
OpenSSF Package Analysis
https://openssf.org/blog/2022/04/28/introducing-package-analysis-scanning-open-source-packages-for-malicious-behavior/
M1 Prefetcher Data Leak
https://www.prefetchers.info
Using Passive DNS Sources for Reconnaissance and Enumeration
https://isc.sans.edu/forums/diary/Using+Passive+DNS+sources+for+Reconnaissance+and+Enumeration/28596/
Microsoft Edge Secure Network
https://support.microsoft.com/en-gb/topic/use-the-microsoft-edge-secure-network-to-protect-your-browsing-885472e2-7847-4d89-befb-c80d3dda6318
Sina Weibo Making Users IPs and Location Public
https://www.theregister.com/2022/04/29/weibo_location_services_default/
https://weibo.com/u/1934183965?layerid=4763194269108760
SonicWall Global VPN Client DLL Search Order Hijacking
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0036
Zoom Updated
https://explore.zoom.us/en/trust/security/security-bulletin/
Using Passive DNS Sources for Reconnaissance and Enumeration
https://isc.sans.edu/forums/diary/Using+Passive+DNS+sources+for+Reconnaissance+and+Enumeration/28596/
Microsoft Edge Secure Network
https://support.microsoft.com/en-gb/topic/use-the-microsoft-edge-secure-network-to-protect-your-browsing-885472e2-7847-4d89-befb-c80d3dda6318
Sina Weibo Making Users IPs and Location Public
https://www.theregister.com/2022/04/29/weibo_location_services_default/
https://weibo.com/u/1934183965?layerid=4763194269108760
SonicWall Global VPN Client DLL Search Order Hijacking
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0036
Zoom Updated
https://explore.zoom.us/en/trust/security/security-bulletin/
A Day of SMB: What does our SMB/RPC Honeypot see? CVE-2022-26809
https://isc.sans.edu/forums/diary/A+Day+of+SMB+What+does+our+SMBRPC+Honeypot+see+CVE202226809/28594/
Azure PostgreSQL Privilege Escalation
https://www.wiz.io/blog/wiz-research-discovers-extrareplica-cross-account-database-vulnerability-in-azure-postgresql/
Security alert: Attack campaign involving stolen OAuth user tokens
https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens
Netatalk Vulnerability Affecting Synology, QNAP, Others?
https://www.synology.com/en-global/security/advisory/Synology_SA_22_06
A Day of SMB: What does our SMB/RPC Honeypot see? CVE-2022-26809
https://isc.sans.edu/forums/diary/A+Day+of+SMB+What+does+our+SMBRPC+Honeypot+see+CVE202226809/28594/
Azure PostgreSQL Privilege Escalation
https://www.wiz.io/blog/wiz-research-discovers-extrareplica-cross-account-database-vulnerability-in-azure-postgresql/
Security alert: Attack campaign involving stolen OAuth user tokens
https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens
Netatalk Vulnerability Affecting Synology, QNAP, Others?
https://www.synology.com/en-global/security/advisory/Synology_SA_22_06
MITRE ATT&CK v11
https://isc.sans.edu/forums/diary/MITRE+ATTCK+v11+a+small+update+that+can+help+not+just+with+detection+engineering/28590/
Microsoft Special Report: Ukraine
https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Vwwd
Linux Privilege Escalation Nimbuspwn
https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/
npm Package Planting
https://blog.aquasec.com/npm-package-planting
MITRE ATT&CK v11
https://isc.sans.edu/forums/diary/MITRE+ATTCK+v11+a+small+update+that+can+help+not+just+with+detection+engineering/28590/
Microsoft Special Report: Ukraine
https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE4Vwwd
Linux Privilege Escalation Nimbuspwn
https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/
npm Package Planting
https://blog.aquasec.com/npm-package-planting
WSO2 Vuln Exploited to Install Crypto Coin Miners
https://isc.sans.edu/forums/diary/WSO2+RCE+exploited+in+the+wild/28586/
Core Impact Backdoor Delivered Via VMware Vulnerablity
https://blog.morphisec.com/vmware-identity-manager-attack-backdoor
VirusTotal Exploit Update
https://twitter.com/bquintero/status/1518738072820670464
Emotet Experimenting With New Delivery Techniques
https://www.proofpoint.com/us/blog/threat-insight/emotet-tests-new-delivery-techniques
WSO2 Vuln Exploited to Install Crypto Coin Miners
https://isc.sans.edu/forums/diary/WSO2+RCE+exploited+in+the+wild/28586/
Core Impact Backdoor Delivered Via VMware Vulnerablity
https://blog.morphisec.com/vmware-identity-manager-attack-backdoor
VirusTotal Exploit Update
https://twitter.com/bquintero/status/1518738072820670464
Emotet Experimenting With New Delivery Techniques
https://www.proofpoint.com/us/blog/threat-insight/emotet-tests-new-delivery-techniques
Simple PDF Linking to Malicious Content
https://isc.sans.edu/forums/diary/Simple+PDF+Linking+to+Malicious+Content/28582/
VirusTotal Remote Code Execution
https://www.cysrc.com/blog/virus-total-blog
Apple's Private Relay can Cause the System to Ignore Firewall Rules
https://mullvad.net/en/blog/2022/4/25/apples-private-relay-can-cause-the-system-to-ignore-firewall-rules/
Emotet Breaks and Later Fixes Installer
https://www.bleepingcomputer.com/news/security/emotet-malware-infects-users-again-after-fixing-broken-installer/
Simple PDF Linking to Malicious Content
https://isc.sans.edu/forums/diary/Simple+PDF+Linking+to+Malicious+Content/28582/
VirusTotal Remote Code Execution
https://www.cysrc.com/blog/virus-total-blog
Apple's Private Relay can Cause the System to Ignore Firewall Rules
https://mullvad.net/en/blog/2022/4/25/apples-private-relay-can-cause-the-system-to-ignore-firewall-rules/
Emotet Breaks and Later Fixes Installer
https://www.bleepingcomputer.com/news/security/emotet-malware-infects-users-again-after-fixing-broken-installer/
Analyzing Word Phishing Document
https://isc.sans.edu/forums/diary/Analyzing+a+Phishing+Word+Document/28562/
Targeting Roku Streaming Devices
https://isc.sans.edu/forums/diary/Are+Roku+Streaming+Devices+Safe+from+Exploitation/28578/
JWT Null Signature Vulnerability PoC
https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/jwt-null-signature-vulnerable-app
Expat XML Vulnerabilities
https://www.ibm.com/support/pages/node/6573293
Jira Vulnerability
https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html
Analyzing Word Phishing Document
https://isc.sans.edu/forums/diary/Analyzing+a+Phishing+Word+Document/28562/
Targeting Roku Streaming Devices
https://isc.sans.edu/forums/diary/Are+Roku+Streaming+Devices+Safe+from+Exploitation/28578/
JWT Null Signature Vulnerability PoC
https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/jwt-null-signature-vulnerable-app
Expat XML Vulnerabilities
https://www.ibm.com/support/pages/node/6573293
Jira Vulnerability
https://confluence.atlassian.com/jira/jira-security-advisory-2022-04-20-1115127899.html
Multi Cryptocurrency Clipboard Swapper
https://isc.sans.edu/forums/diary/MultiCryptocurrency+Clipboard+Swapper/28574/
Amazong Fixes AWS log4j Fix
https://aws.amazon.com/security/security-bulletins/AWS-2022-006/
Cisco Fixes
https://tools.cisco.com/security/center/publicationListing.x
Psychic Signature PoC
https://github.com/khalednassar/CVE-2022-21449-TLS-PoC
ALAC Audio Decoder Bug
https://blog.checkpoint.com/2022/04/21/largest-mobile-chipset-manufacturers-used-vulnerable-audio-decoder-2-3-of-android-users-privacy-around-the-world-were-at-risk/
Multi Cryptocurrency Clipboard Swapper
https://isc.sans.edu/forums/diary/MultiCryptocurrency+Clipboard+Swapper/28574/
Amazong Fixes AWS log4j Fix
https://aws.amazon.com/security/security-bulletins/AWS-2022-006/
Cisco Fixes
https://tools.cisco.com/security/center/publicationListing.x
Psychic Signature PoC
https://github.com/khalednassar/CVE-2022-21449-TLS-PoC
ALAC Audio Decoder Bug
https://blog.checkpoint.com/2022/04/21/largest-mobile-chipset-manufacturers-used-vulnerable-audio-decoder-2-3-of-android-users-privacy-around-the-world-were-at-risk/
AA Distribution Quakbot (Qbot) infection siwth DarkVNC
https://isc.sans.edu/forums/diary/aa+distribution+Qakbot+Qbot+infection+with+DarkVNC+traffic/28568/
Java Psychic Signatures
https://neilmadden.blog/2022/04/19/psychic-signatures-in-java/
Snort DoS Vulnerability
https://claroty.com/2022/04/14/blog-research-blinding-snort-breaking-the-modbus-ot-preprocessor/
AA Distribution Quakbot (Qbot) infection siwth DarkVNC
https://isc.sans.edu/forums/diary/aa+distribution+Qakbot+Qbot+infection+with+DarkVNC+traffic/28568/
Java Psychic Signatures
https://neilmadden.blog/2022/04/19/psychic-signatures-in-java/
Snort DoS Vulnerability
https://claroty.com/2022/04/14/blog-research-blinding-snort-breaking-the-modbus-ot-preprocessor/
u-boot Password Reset
https://isc.sans.edu/forums/diary/Resetting+Linux+Passwords+with+UBoot+Bootloaders/28564/
Oracle CPU
https://www.oracle.com/security-alerts/cpuapr2022.html
MetaMask iCloud Phishing
https://www.bleepingcomputer.com/news/security/hackers-steal-655k-after-picking-metamask-seed-from-icloud-backup/
SMB1 Gone From Windows 11 Home
https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb1-now-disabled-by-default-for-windows-11-home-insiders-builds/ba-p/3289473
Lenovo UEFI/BIOS Vulnerability
https://support.lenovo.com/us/en/product_security/ps500483-lenovo-system-update-privilege-escalation-vulnerability
https://support.lenovo.com/de/de/product_security/LEN-84943
u-boot Password Reset
https://isc.sans.edu/forums/diary/Resetting+Linux+Passwords+with+UBoot+Bootloaders/28564/
Oracle CPU
https://www.oracle.com/security-alerts/cpuapr2022.html
MetaMask iCloud Phishing
https://www.bleepingcomputer.com/news/security/hackers-steal-655k-after-picking-metamask-seed-from-icloud-backup/
SMB1 Gone From Windows 11 Home
https://techcommunity.microsoft.com/t5/storage-at-microsoft/smb1-now-disabled-by-default-for-windows-11-home-insiders-builds/ba-p/3289473
Lenovo UEFI/BIOS Vulnerability
https://support.lenovo.com/us/en/product_security/ps500483-lenovo-system-update-privilege-escalation-vulnerability
https://support.lenovo.com/de/de/product_security/LEN-84943
Sysmon's ReigstryEvent (Value Set) and Binary Data
https://isc.sans.edu/forums/diary/Sysmons+RegistryEvent+Value+Set/28558/
Ukraine CERT Posts: IcedID and Zimbra Flaw
https://cert.gov.ua/article/39606
https://cert.gov.ua/article/39609
New NSO Pegasus Exploit Spotted in the Wild
https://citizenlab.ca/2022/04/catalangate-extensive-mercenary-spyware-operation-against-catalans-using-pegasus-candiru/
Unofficial Windows 11 Upgrade Delivers Spyware
https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/
Sysmon's ReigstryEvent (Value Set) and Binary Data
https://isc.sans.edu/forums/diary/Sysmons+RegistryEvent+Value+Set/28558/
Ukraine CERT Posts: IcedID and Zimbra Flaw
https://cert.gov.ua/article/39606
https://cert.gov.ua/article/39609
New NSO Pegasus Exploit Spotted in the Wild
https://citizenlab.ca/2022/04/catalangate-extensive-mercenary-spyware-operation-against-catalans-using-pegasus-candiru/
Unofficial Windows 11 Upgrade Delivers Spyware
https://www.bleepingcomputer.com/news/security/unofficial-windows-11-upgrade-installs-info-stealing-malware/
Office Now Protects You From Malicious ISO Files
https://isc.sans.edu/forums/diary/Office+Protects+You+From+Malicious+ISO+Files/28554/
Github Stolen OAUTH User Tokens
https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/
Git For Windows Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2022-24765
Cisco Wireless Controller Bug
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-auth-bypass-JRNhV4fF
Office Now Protects You From Malicious ISO Files
https://isc.sans.edu/forums/diary/Office+Protects+You+From+Malicious+ISO+Files/28554/
Github Stolen OAUTH User Tokens
https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/
Git For Windows Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2022-24765
Cisco Wireless Controller Bug
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-auth-bypass-JRNhV4fF
An Update on CVE-2022-26809 MSRPC Vulnerability - PATCH NOW
https://isc.sans.edu/forums/diary/An+Update+on+CVE202226809+MSRPC+Vulnerabliity+PATCH+NOW/28550/
Webcast: https://www.sans.org/webcasts/cve-2022-26809-ms-rpc-vulnerability-analysis/
https://twitter.com/splinter_code/status/1514653941304369153
Google Chrome 0-Day Patch
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html
Cisco Webex Phones Home Audio Telemetry
https://wiscprivacy.com/papers/vca_mute.pdf
Grafana Enterprise Vulnerabilty
https://grafana.com/blog/2022/04/12/grafana-enterprise-8.4.6-released-with-high-severity-security-fix/
An Update on CVE-2022-26809 MSRPC Vulnerability - PATCH NOW
https://isc.sans.edu/forums/diary/An+Update+on+CVE202226809+MSRPC+Vulnerabliity+PATCH+NOW/28550/
Webcast: https://www.sans.org/webcasts/cve-2022-26809-ms-rpc-vulnerability-analysis/
https://twitter.com/splinter_code/status/1514653941304369153
Google Chrome 0-Day Patch
https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html
Cisco Webex Phones Home Audio Telemetry
https://wiscprivacy.com/papers/vca_mute.pdf
Grafana Enterprise Vulnerabilty
https://grafana.com/blog/2022/04/12/grafana-enterprise-8.4.6-released-with-high-severity-security-fix/
How is Ukrainian Internet Holding Up During Russian Invasion
https://isc.sans.edu/forums/diary/How+is+Ukrainian+internet+holding+up+during+the+Russian+invasion/28546/
Update on Windows Patches and CVE-2022-26809
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26809
Adobe Updates
https://helpx.adobe.com/security/products/photoshop/apsb22-20.html
Apache Struts 2 Update
https://cwiki.apache.org/confluence/display/WW/S2-062
How is Ukrainian Internet Holding Up During Russian Invasion
https://isc.sans.edu/forums/diary/How+is+Ukrainian+internet+holding+up+during+the+Russian+invasion/28546/
Update on Windows Patches and CVE-2022-26809
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26809
Adobe Updates
https://helpx.adobe.com/security/products/photoshop/apsb22-20.html
Apache Struts 2 Update
https://cwiki.apache.org/confluence/display/WW/S2-062
Microsoft April 2022 Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+April+2022+Patch+Tuesday/28542/
NGINX Statement To LDAP Weakness
https://www.nginx.com/blog/addressing-security-weaknesses-nginx-ldap-reference-implementation/
Attacks on Ukrainian Power Grid
https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
Microsoft April 2022 Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+April+2022+Patch+Tuesday/28542/
NGINX Statement To LDAP Weakness
https://www.nginx.com/blog/addressing-security-weaknesses-nginx-ldap-reference-implementation/
Attacks on Ukrainian Power Grid
https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
Spring: It isn't just about Spring4Shell.
https://isc.sans.edu/forums/diary/Spring+It+isnt+just+about+Spring4Shell+Spring+Cloud+Function+Vulnerabilities+are+being+probed+too/28538/
Microsoft Windows Autopatch
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/get-current-and-stay-current-with-windows-autopatch/ba-p/3271839
More npm protestware
https://github.com/Yaffle/EventSource/commit/de137927e13d8afac153d2485152ccec48948a7a
Raspberry Pi Update
https://www.raspberrypi.com/news/raspberry-pi-bullseye-update-april-2022/
Spring: It isn't just about Spring4Shell.
https://isc.sans.edu/forums/diary/Spring+It+isnt+just+about+Spring4Shell+Spring+Cloud+Function+Vulnerabilities+are+being+probed+too/28538/
Microsoft Windows Autopatch
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/get-current-and-stay-current-with-windows-autopatch/ba-p/3271839
More npm protestware
https://github.com/Yaffle/EventSource/commit/de137927e13d8afac153d2485152ccec48948a7a
Raspberry Pi Update
https://www.raspberrypi.com/news/raspberry-pi-bullseye-update-april-2022/
Misc Spring4Shell Items
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67
https://www.trendmicro.com/en_us/research/22/d/cve-2022-22965-analyzing-the-exploitation-of-spring4shell-vulner.html
https://github.com/AgainstTheWest/NginxDay
Russian Certificate Authority Update
https://koen.engineer/russias-certificate-authority-for-sanctioned-organizations-645d61af8ac6
Conti Source Code Leak Leads to Copycats
https://www.bleepingcomputer.com/news/security/hackers-use-contis-leaked-ransomware-to-attack-russian-companies/
Misc Spring4Shell Items
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67
https://www.trendmicro.com/en_us/research/22/d/cve-2022-22965-analyzing-the-exploitation-of-spring4shell-vulner.html
https://github.com/AgainstTheWest/NginxDay
Russian Certificate Authority Update
https://koen.engineer/russias-certificate-authority-for-sanctioned-organizations-645d61af8ac6
Conti Source Code Leak Leads to Copycats
https://www.bleepingcomputer.com/news/security/hackers-use-contis-leaked-ransomware-to-attack-russian-companies/
What is BIMI
https://isc.sans.edu/forums/diary/What+is+BIMI+and+how+is+it+supposed+to+help+with+Phishing/28528/
Watchguard Vulnerability behind Cyclops Blink
https://techsearch.watchguard.com/KB?type=Article&SFDCID=kA16S000000SOCGSA4⟨=en_US
Malware Targeting Amazon Lambdas
https://www.cadosecurity.com/cado-discovers-denonia-the-first-malware-specifically-targeting-lambda/
Ashley Taylor: Doppelgaengers: Finding Job Scammers Who Steal Brand Identities
https://www.sans.edu/cyber-research/doppelgangers-finding-job-scammers-who-steal-brand-identities/
What is BIMI
https://isc.sans.edu/forums/diary/What+is+BIMI+and+how+is+it+supposed+to+help+with+Phishing/28528/
Watchguard Vulnerability behind Cyclops Blink
https://techsearch.watchguard.com/KB?type=Article&SFDCID=kA16S000000SOCGSA4⟨=en_US
Malware Targeting Amazon Lambdas
https://www.cadosecurity.com/cado-discovers-denonia-the-first-malware-specifically-targeting-lambda/
Ashley Taylor: Doppelgaengers: Finding Job Scammers Who Steal Brand Identities
https://www.sans.edu/cyber-research/doppelgangers-finding-job-scammers-who-steal-brand-identities/
Windows MetaStealer Malware
https://isc.sans.edu/forums/diary/Windows+MetaStealer+Malware/28522/
US Justice Depatment Takes Down Cyclops Blink Botnet
https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-botnet-controlled-russian-federation
VMWare Bugs
https://www.vmware.com/security/advisories.html
Palo Alto CVE-2022-0778
https://security.paloaltonetworks.com/CVE-2022-0778
Unpatched Apple Bug
https://www.intego.com/mac-security-blog/apple-neglects-to-patch-zero-day-wild-vulnerabilities-for-macos-big-sur-catalina/
Windows MetaStealer Malware
https://isc.sans.edu/forums/diary/Windows+MetaStealer+Malware/28522/
US Justice Depatment Takes Down Cyclops Blink Botnet
https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-botnet-controlled-russian-federation
VMWare Bugs
https://www.vmware.com/security/advisories.html
Palo Alto CVE-2022-0778
https://security.paloaltonetworks.com/CVE-2022-0778
Unpatched Apple Bug
https://www.intego.com/mac-security-blog/apple-neglects-to-patch-zero-day-wild-vulnerabilities-for-macos-big-sur-catalina/
WebLogic Crypto Miner Malware Disabling Alibaba Cloud Monitoring Tools
https://isc.sans.edu/forums/diary/WebLogic+Crypto+Miner+Malware+Disabling+Alibaba+Cloud+Monitoring+Tools/28520/
Cicada: Chinese APT Group Widens Targeting in Recent Espionage Activity
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-china-ngo-government-attacks
New Security Features for Windows 11
https://www.microsoft.com/security/blog/2022/04/05/new-security-features-for-windows-11-will-help-protect-hybrid-work/
Fin7 Power Hour: Adversary Archaeology and Evolution of FIN7
https://www.mandiant.com/resources/evolution-of-fin7
WebLogic Crypto Miner Malware Disabling Alibaba Cloud Monitoring Tools
https://isc.sans.edu/forums/diary/WebLogic+Crypto+Miner+Malware+Disabling+Alibaba+Cloud+Monitoring+Tools/28520/
Cicada: Chinese APT Group Widens Targeting in Recent Espionage Activity
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-china-ngo-government-attacks
New Security Features for Windows 11
https://www.microsoft.com/security/blog/2022/04/05/new-security-features-for-windows-11-will-help-protect-hybrid-work/
Fin7 Power Hour: Adversary Archaeology and Evolution of FIN7
https://www.mandiant.com/resources/evolution-of-fin7
Emptying the Phishtank: Are WordPress Sites the Mosquitoes of the Internet
https://isc.sans.edu/forums/diary/Emptying+the+Phishtank+Are+WordPress+sites+the+Mosquitoes+of+the+Internet/28516/
Mailchimp Breach Used to Target Trezor Users
https://www.bleepingcomputer.com/news/security/hackers-breach-mailchimps-internal-tools-to-target-crypto-customers/
Proactively Prevent Secret Leaks With GitHub Advanced Security Secret Scanning
https://github.blog/2022-04-04-push-protection-github-advanced-security/
TruffleHog v3
https://trufflesecurity.com/blog/introducing-trufflehog-v3
Russian Certificates (chinese article)
https://blog.netlab.360.com/review-revoke-russia-ssl-certificates/
Emptying the Phishtank: Are WordPress Sites the Mosquitoes of the Internet
https://isc.sans.edu/forums/diary/Emptying+the+Phishtank+Are+WordPress+sites+the+Mosquitoes+of+the+Internet/28516/
Mailchimp Breach Used to Target Trezor Users
https://www.bleepingcomputer.com/news/security/hackers-breach-mailchimps-internal-tools-to-target-crypto-customers/
Proactively Prevent Secret Leaks With GitHub Advanced Security Secret Scanning
https://github.blog/2022-04-04-push-protection-github-advanced-security/
TruffleHog v3
https://trufflesecurity.com/blog/introducing-trufflehog-v3
Russian Certificates (chinese article)
https://blog.netlab.360.com/review-revoke-russia-ssl-certificates/
GitLab Critical Security Release
https://about.gitlab.com/releases/2022/03/31/critical-security-release-gitlab-14-9-2-released/
ViaSat KA-SAT Network Cyber Attack
https://www.viasat.com/about/newsroom/blog/ka-sat-network-cyber-attack-overview/
MacOS Bug Enables Phishing
https://rambo.codes/posts/2022-03-15-how-a-macos-bug-could-have-allowed-for-a-serious-phishing-attack-against-users
PHP Supply Chain Attack on PEAR
https://blog.sonarsource.com/php-supply-chain-attack-on-pear
GitLab Critical Security Release
https://about.gitlab.com/releases/2022/03/31/critical-security-release-gitlab-14-9-2-released/
ViaSat KA-SAT Network Cyber Attack
https://www.viasat.com/about/newsroom/blog/ka-sat-network-cyber-attack-overview/
MacOS Bug Enables Phishing
https://rambo.codes/posts/2022-03-15-how-a-macos-bug-could-have-allowed-for-a-serious-phishing-attack-against-users
PHP Supply Chain Attack on PEAR
https://blog.sonarsource.com/php-supply-chain-attack-on-pear
Spring Vulnerability Update - Exploitation Attempts CVE-2022-22965
https://isc.sans.edu/forums/diary/Spring+Vulnerability+Update+Exploitation+Attempts+CVE202222965/28504/
Apple Patches 0 Day Vulnerability
https://isc.sans.edu/forums/diary/Apple+Patches+Actively+Exploited+Vulnerability+in+macOS+iOS+and+iPadOS/28506/
Wyze Cam Vulnerabilities
https://www.bitdefender.com/files/News/CaseStudies/study/413/Bitdefender-PR-Whitepaper-WCam-creat5991-en-EN.pdf
Zyxel Security Advisory
https://www.zyxel.com/support/forgery-vulnerabilities-of-select-Armor-home-routers.shtml
Spring Vulnerability Update - Exploitation Attempts CVE-2022-22965
https://isc.sans.edu/forums/diary/Spring+Vulnerability+Update+Exploitation+Attempts+CVE202222965/28504/
Apple Patches 0 Day Vulnerability
https://isc.sans.edu/forums/diary/Apple+Patches+Actively+Exploited+Vulnerability+in+macOS+iOS+and+iPadOS/28506/
Wyze Cam Vulnerabilities
https://www.bitdefender.com/files/News/CaseStudies/study/413/Bitdefender-PR-Whitepaper-WCam-creat5991-en-EN.pdf
Zyxel Security Advisory
https://www.zyxel.com/support/forgery-vulnerabilities-of-select-Armor-home-routers.shtml
Java Springtime Confusion: What Vulnerabilty are We Talking About
https://isc.sans.edu/forums/diary/Java+Springtime+Confusion+What+Vulnerability+are+We+Talking+About/28500/
Quickie: Parsing XLSB Documents
https://isc.sans.edu/forums/diary/Quickie+Parsing+XLSB+Documents/28496/
Pwning 3CX Phone Management Backends from the Internet
https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88
Java Springtime Confusion: What Vulnerabilty are We Talking About
https://isc.sans.edu/forums/diary/Java+Springtime+Confusion+What+Vulnerability+are+We+Talking+About/28500/
Quickie: Parsing XLSB Documents
https://isc.sans.edu/forums/diary/Quickie+Parsing+XLSB+Documents/28496/
Pwning 3CX Phone Management Backends from the Internet
https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88
More Fake/Typosquatting Twitter Accounts Asking for Ukraine Cryptocurrency Donations
https://isc.sans.edu/forums/diary/More+FakeTyposquatting+Twitter+Accounts+Asking+for+Ukraine+Crytocurrency+Donations/28492/
Mitigating Attacks Against Uninterruptible Power Supply Devices
https://www.cisa.gov/sites/default/files/publications/CISA-DOE_Insights-Mitigating_Vulnerabilities_Affecting_Uninterruptible_Power_Supply_Devices_Mar_29.pdf
MFA Bypass Attacks
https://blog.talosintelligence.com/2022/03/transparent-tribe-new-campaign.html
Google Advertises Mars Stealer
https://blog.morphisec.com/threat-research-mars-stealer
Hackers Gaining Power of Subpoena Via Fake "Emergency Data Requests"
https://krebsonsecurity.com/2022/03/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests/
More Fake/Typosquatting Twitter Accounts Asking for Ukraine Cryptocurrency Donations
https://isc.sans.edu/forums/diary/More+FakeTyposquatting+Twitter+Accounts+Asking+for+Ukraine+Crytocurrency+Donations/28492/
Mitigating Attacks Against Uninterruptible Power Supply Devices
https://www.cisa.gov/sites/default/files/publications/CISA-DOE_Insights-Mitigating_Vulnerabilities_Affecting_Uninterruptible_Power_Supply_Devices_Mar_29.pdf
MFA Bypass Attacks
https://blog.talosintelligence.com/2022/03/transparent-tribe-new-campaign.html
Google Advertises Mars Stealer
https://blog.morphisec.com/threat-research-mars-stealer
Hackers Gaining Power of Subpoena Via Fake "Emergency Data Requests"
https://krebsonsecurity.com/2022/03/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests/
BGP Hijacking of Twitter Prefix by RTComm.ru
https://isc.sans.edu/forums/diary/BGP+Hijacking+of+Twitter+Prefix+by+RTCommru/28488/
DDoS Against Sites in Ukraine
https://www.bleepingcomputer.com/news/security/hacked-wordpress-sites-force-visitors-to-ddos-ukrainian-targets/
Sophos Patches
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce
Sonicwall Patches
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003
opnsense CARP protocol routing error
https://medium.com/sensorfu/firewall-bypass-with-carp-in-packet-filter-c4ed70fb7dd7
BGP Hijacking of Twitter Prefix by RTComm.ru
https://isc.sans.edu/forums/diary/BGP+Hijacking+of+Twitter+Prefix+by+RTCommru/28488/
DDoS Against Sites in Ukraine
https://www.bleepingcomputer.com/news/security/hacked-wordpress-sites-force-visitors-to-ddos-ukrainian-targets/
Sophos Patches
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220325-sfos-rce
Sonicwall Patches
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0003
opnsense CARP protocol routing error
https://medium.com/sensorfu/firewall-bypass-with-carp-in-packet-filter-c4ed70fb7dd7
XLSB Files Because Binary is Stealthier Than XML
https://isc.sans.edu/forums/diary/XLSB+Files+Because+Binary+is+Stealthier+Than+XML/28476/
Dirty Pipe Container Escape PoC
https://www.datadoghq.com/blog/engineering/dirty-pipe-container-escape-poc/
PHP filter_var Shenanigans
https://pwning.systems/posts/php_filter_var_shenanigans/
OpenBSD slaacd vuln
https://blog.quarkslab.com/heap-overflow-in-openbsds-slaacd-via-router-advertisement.html
Google Chrome Update
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html
XLSB Files Because Binary is Stealthier Than XML
https://isc.sans.edu/forums/diary/XLSB+Files+Because+Binary+is+Stealthier+Than+XML/28476/
Dirty Pipe Container Escape PoC
https://www.datadoghq.com/blog/engineering/dirty-pipe-container-escape-poc/
PHP filter_var Shenanigans
https://pwning.systems/posts/php_filter_var_shenanigans/
OpenBSD slaacd vuln
https://blog.quarkslab.com/heap-overflow-in-openbsds-slaacd-via-router-advertisement.html
Google Chrome Update
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop_25.html
Malware Delivered Through Free Sharing Tool
https://isc.sans.edu/forums/diary/Malware+Delivered+Through+Free+Sharing+Tool/28474/
Western Digital PR4100 NAS Vulnerabilty
https://research.nccgroup.com/2022/03/24/remote-code-execution-on-western-digital-pr4100-nas-cve-2022-23121/
Crypto malware in patched wallets targeting Android and iOS devices
https://www.welivesecurity.com/2022/03/24/crypto-malware-patched-wallets-targeting-android-ios-devices/
Lapsus$ Arrest
https://www.bbc.com/news/technology-60864283
https://www.bloomberg.com/news/articles/2022-03-23/teen-suspected-by-cyber-researchers-of-being-lapsus-mastermind?sref=ylv224K8
Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide
https://www.justice.gov/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical
Malware Delivered Through Free Sharing Tool
https://isc.sans.edu/forums/diary/Malware+Delivered+Through+Free+Sharing+Tool/28474/
Western Digital PR4100 NAS Vulnerabilty
https://research.nccgroup.com/2022/03/24/remote-code-execution-on-western-digital-pr4100-nas-cve-2022-23121/
Crypto malware in patched wallets targeting Android and iOS devices
https://www.welivesecurity.com/2022/03/24/crypto-malware-patched-wallets-targeting-android-ios-devices/
Lapsus$ Arrest
https://www.bbc.com/news/technology-60864283
https://www.bloomberg.com/news/articles/2022-03-23/teen-suspected-by-cyber-researchers-of-being-lapsus-mastermind?sref=ylv224K8
Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide
https://www.justice.gov/opa/pr/four-russian-government-employees-charged-two-historical-hacking-campaigns-targeting-critical
Mars Stealer
https://isc.sans.edu/forums/diary/Arkei+Variants+From+Vidar+to+Mars+Stealer/28468/
Okta Update
https://www.okta.com/blog/2022/03/oktas-investigation-of-the-january-2022-compromise/
Microsoft Lapsus$ Update
https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/
npm Attack Targeting Azure Developers
https://jfrog.com/blog/large-scale-npm-attack-targets-azure-developers-with-malicious-packages/
Mars Stealer
https://isc.sans.edu/forums/diary/Arkei+Variants+From+Vidar+to+Mars+Stealer/28468/
Okta Update
https://www.okta.com/blog/2022/03/oktas-investigation-of-the-january-2022-compromise/
Microsoft Lapsus$ Update
https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/
npm Attack Targeting Azure Developers
https://jfrog.com/blog/large-scale-npm-attack-targets-azure-developers-with-malicious-packages/
Statement by President Biden: What you need to do (or not do)
https://isc.sans.edu/forums/diary/Statement+by+President+Biden+What+you+need+to+do+or+not+do/28466/
ASUS Cyclops Blink Advisory
https://www.asus.com/content/ASUS-Product-Security-Advisory/
HP Vulnerabilities
https://support.hp.com/us-en/document/ish_5948778-5949142-16/hpsbpi03780
Sophos UTM Updates
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220321-utm-9710
MacOS GIMMICK Malware
https://www.volexity.com/blog/2022/03/22/storm-cloud-on-the-horizon-gimmick-malware-strikes-at-macos/
Octa Breached By Lapsus
https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/
https://twitter.com/BillDemirkapi/status/1506107157124722690
Statement by President Biden: What you need to do (or not do)
https://isc.sans.edu/forums/diary/Statement+by+President+Biden+What+you+need+to+do+or+not+do/28466/
ASUS Cyclops Blink Advisory
https://www.asus.com/content/ASUS-Product-Security-Advisory/
HP Vulnerabilities
https://support.hp.com/us-en/document/ish_5948778-5949142-16/hpsbpi03780
Sophos UTM Updates
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220321-utm-9710
MacOS GIMMICK Malware
https://www.volexity.com/blog/2022/03/22/storm-cloud-on-the-horizon-gimmick-malware-strikes-at-macos/
Octa Breached By Lapsus
https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/
https://twitter.com/BillDemirkapi/status/1506107157124722690
Maldoc Cleaned by Anti-Virus
https://isc.sans.edu/forums/diary/Maldoc+Cleaned+by+AntiVirus/28460/
Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain
https://www.proofpoint.com/us/blog/threat-insight/serpent-no-swiping-new-backdoor-targets-french-entities-unique-attack-chain
IBM Spectrum Protect Update
https://www.ibm.com/support/pages/node/6564745
Lapsus$ May have Breached Microsoft
https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/
Statement by President Biden on our Nation's Cybersecurity
https://www.whitehouse.gov/briefing-room/statements-releases/2022/03/21/statement-by-president-biden-on-our-nations-cybersecurity/
Maldoc Cleaned by Anti-Virus
https://isc.sans.edu/forums/diary/Maldoc+Cleaned+by+AntiVirus/28460/
Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain
https://www.proofpoint.com/us/blog/threat-insight/serpent-no-swiping-new-backdoor-targets-french-entities-unique-attack-chain
IBM Spectrum Protect Update
https://www.ibm.com/support/pages/node/6564745
Lapsus$ May have Breached Microsoft
https://www.theregister.com/2022/03/21/microsoft_lapsus_breach_probe/
Statement by President Biden on our Nation's Cybersecurity
https://www.whitehouse.gov/briefing-room/statements-releases/2022/03/21/statement-by-president-biden-on-our-nations-cybersecurity/
Scans for Movable Type Vulnerability (CVE-2021-20837)
https://isc.sans.edu/forums/diary/Scans+for+Movable+Type+Vulnerability+CVE202120837/28454/
SolarWinds Advisory: Unauahtneticated Access in Web Help Desk (12.7.5)
https://isc.sans.edu/forums/diary/SolarWinds+Advisory+Unauthenticated+Access+in+Web+Help+Desk+1275/28456/
MGLNDD_* Scans
https://isc.sans.edu/forums/diary/MGLNDD+Scans/28458/
CAPTCHA Phishing
https://www.avanan.com/blog/using-captcha-forms-to-bypass-filters
Browser in the Browser Templates
https://mrd0x.com/browser-in-the-browser-phishing-attack/
Scans for Movable Type Vulnerability (CVE-2021-20837)
https://isc.sans.edu/forums/diary/Scans+for+Movable+Type+Vulnerability+CVE202120837/28454/
SolarWinds Advisory: Unauahtneticated Access in Web Help Desk (12.7.5)
https://isc.sans.edu/forums/diary/SolarWinds+Advisory+Unauthenticated+Access+in+Web+Help+Desk+1275/28456/
MGLNDD_* Scans
https://isc.sans.edu/forums/diary/MGLNDD+Scans/28458/
CAPTCHA Phishing
https://www.avanan.com/blog/using-captcha-forms-to-bypass-filters
Browser in the Browser Templates
https://mrd0x.com/browser-in-the-browser-phishing-attack/
npm Package Sabotaged for Belarus/Russian Users
https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/
President Zelensky Deepfakes
https://twitter.com/ngleicher/status/1504186935291506693
ATM Rootkit
https://www.mandiant.com/resources/unc2891-overview
Scanner for Backdoored Mikrotik Routers
https://github.com/microsoft/routeros-scanner
SANS.edu Student: Ron Grohman; Network Access Control and ICS: A Practical Guide
https://www.sans.edu/cyber-research/network-access-control-and-ics-a-practical-guide/
npm Package Sabotaged for Belarus/Russian Users
https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/
President Zelensky Deepfakes
https://twitter.com/ngleicher/status/1504186935291506693
ATM Rootkit
https://www.mandiant.com/resources/unc2891-overview
Scanner for Backdoored Mikrotik Routers
https://github.com/microsoft/routeros-scanner
SANS.edu Student: Ron Grohman; Network Access Control and ICS: A Practical Guide
https://www.sans.edu/cyber-research/network-access-control-and-ics-a-practical-guide/
Qakbot Infection With Cobalt Strike and VNC Activity
https://isc.sans.edu/forums/diary/Qakbot+infection+with+Cobalt+Strike+and+VNC+activity/28448/
Gh0stCringe RAT Being Distributed to Vulnerable Database Servers
https://asec.ahnlab.com/en/32572/
dompdf 0 day
https://positive.security/blog/dompdf-rce
OpenSSL DoS Vulnerability
https://www.openssl.org/news/secadv/20220315.txt
Qakbot Infection With Cobalt Strike and VNC Activity
https://isc.sans.edu/forums/diary/Qakbot+infection+with+Cobalt+Strike+and+VNC+activity/28448/
Gh0stCringe RAT Being Distributed to Vulnerable Database Servers
https://asec.ahnlab.com/en/32572/
dompdf 0 day
https://positive.security/blog/dompdf-rce
OpenSSL DoS Vulnerability
https://www.openssl.org/news/secadv/20220315.txt
Clean Binaries with Suspicious Behaviour
https://isc.sans.edu/forums/diary/Clean+Binaries+with+Suspicious+Behaviour/28444/
Misconfigured Multi-Factor Authentication Abused
https://www.cisa.gov/uscert/ncas/alerts/aa22-074a
German Office of Information Security Warns Kaspersky Users
https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2022/220315_Kaspersky-Warnung.html
Caddy Wiper Targeting Ukraine
https://www.welivesecurity.com/2022/03/15/caddywiper-new-wiper-malware-discovered-ukraine/
Fake Antivirus Targeting Ukraine
https://twitter.com/malwrhunterteam/status/1502302718140035080
B1txor20 DNS Tunnel Backdoor
https://blog.netlab.360.com/b1txor20-use-of-dns-tunneling_en/
Clean Binaries with Suspicious Behaviour
https://isc.sans.edu/forums/diary/Clean+Binaries+with+Suspicious+Behaviour/28444/
Misconfigured Multi-Factor Authentication Abused
https://www.cisa.gov/uscert/ncas/alerts/aa22-074a
German Office of Information Security Warns Kaspersky Users
https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2022/220315_Kaspersky-Warnung.html
Caddy Wiper Targeting Ukraine
https://www.welivesecurity.com/2022/03/15/caddywiper-new-wiper-malware-discovered-ukraine/
Fake Antivirus Targeting Ukraine
https://twitter.com/malwrhunterteam/status/1502302718140035080
B1txor20 DNS Tunnel Backdoor
https://blog.netlab.360.com/b1txor20-use-of-dns-tunneling_en/
Apple Updates Everything
https://isc.sans.edu/forums/diary/Apple+Updates+Everything+MacOS+123+XCode+133+tvOS+154+watchOS+85+iPadOS+154+and+more/28438/
Look Alike Accounts Used in Ukraine Dontation Scam Impersonating Olena Zelenska
https://isc.sans.edu/forums/diary/Look+Alike+Accounts+Used+in+Ukraine+Donation+Scam+impersonating+Olena+Zelenska/28440/
Curl on Windows
https://isc.sans.edu/forums/diary/Curl+on+Windows/28436/
Veeam Vulnerabilities
https://www.veeam.com/kb4288
Linux Netfilter Privilege Escalation
https://nickgregory.me/linux/security/2022/03/12/cve-2022-25636/
Apple Updates Everything
https://isc.sans.edu/forums/diary/Apple+Updates+Everything+MacOS+123+XCode+133+tvOS+154+watchOS+85+iPadOS+154+and+more/28438/
Look Alike Accounts Used in Ukraine Dontation Scam Impersonating Olena Zelenska
https://isc.sans.edu/forums/diary/Look+Alike+Accounts+Used+in+Ukraine+Donation+Scam+impersonating+Olena+Zelenska/28440/
Curl on Windows
https://isc.sans.edu/forums/diary/Curl+on+Windows/28436/
Veeam Vulnerabilities
https://www.veeam.com/kb4288
Linux Netfilter Privilege Escalation
https://nickgregory.me/linux/security/2022/03/12/cve-2022-25636/
Malware Using WebSockets For C&C
https://isc.sans.edu/forums/diary/Keep+an+Eye+on+WebSockets/28430/
Racoon Stealer leverages Telegram
https://decoded.avast.io/vladimirmartyanov/raccoon-stealer-trash-panda-abuses-telegram/
USAHERDS Hack
https://www.wired.com/story/china-apt41-hacking-usaherds-log4j/
YARA 4.2.0 Released
https://isc.sans.edu/forums/diary/YARA+420+Released/28432/
Malware Using WebSockets For C&C
https://isc.sans.edu/forums/diary/Keep+an+Eye+on+WebSockets/28430/
Racoon Stealer leverages Telegram
https://decoded.avast.io/vladimirmartyanov/raccoon-stealer-trash-panda-abuses-telegram/
USAHERDS Hack
https://www.wired.com/story/china-apt41-hacking-usaherds-log4j/
YARA 4.2.0 Released
https://isc.sans.edu/forums/diary/YARA+420+Released/28432/
Credential Leaks on Virustotal
https://isc.sans.edu/forums/diary/Credentials+Leaks+on+VirusTotal/28426/
GPS Issues Around Finish Rusian Border
https://www.straitstimes.com/world/europe/finland-detects-gps-disturbance-near-russias-kaliningrad
Russia Considering Internal Certificate Authority
https://www.gosuslugi.ru/tls
https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/
New Spectre Variant
https://www.vusec.net/projects/bhi-spectre-bhb/
Package Manager Vulnerabilities (yarn, pip, composer...)
https://blog.sonarsource.com/securing-developer-tools-package-managers
Credential Leaks on Virustotal
https://isc.sans.edu/forums/diary/Credentials+Leaks+on+VirusTotal/28426/
GPS Issues Around Finish Rusian Border
https://www.straitstimes.com/world/europe/finland-detects-gps-disturbance-near-russias-kaliningrad
Russia Considering Internal Certificate Authority
https://www.gosuslugi.ru/tls
https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/
New Spectre Variant
https://www.vusec.net/projects/bhi-spectre-bhb/
Package Manager Vulnerabilities (yarn, pip, composer...)
https://blog.sonarsource.com/securing-developer-tools-package-managers
Infostealer in a Batch File
https://isc.sans.edu/forums/diary/Infostealer+in+a+Batch+File/28422/
TP240PhoneHome reflection/amplification DDoS Attack Vector
https://blog.cloudflare.com/cve-2022-26143/
Malware Disguises as Pro Ukrainian Cybertools
https://blog.talosintelligence.com/2022/03/threat-advisory-cybercriminals.html#more
Russian Government Sites Hacked in Supply Chain Attack
https://www.bleepingcomputer.com/news/security/russian-government-sites-hacked-in-supply-chain-attack/
Third Party Vulnerabilities in RUGGEDCOM ROS
https://cert-portal.siemens.com/productcert/pdf/ssa-256353.pdf
Adobe Bulletins
https://helpx.adobe.com/security/security-bulletin.html
Infostealer in a Batch File
https://isc.sans.edu/forums/diary/Infostealer+in+a+Batch+File/28422/
TP240PhoneHome reflection/amplification DDoS Attack Vector
https://blog.cloudflare.com/cve-2022-26143/
Malware Disguises as Pro Ukrainian Cybertools
https://blog.talosintelligence.com/2022/03/threat-advisory-cybercriminals.html#more
Russian Government Sites Hacked in Supply Chain Attack
https://www.bleepingcomputer.com/news/security/russian-government-sites-hacked-in-supply-chain-attack/
Third Party Vulnerabilities in RUGGEDCOM ROS
https://cert-portal.siemens.com/productcert/pdf/ssa-256353.pdf
Adobe Bulletins
https://helpx.adobe.com/security/security-bulletin.html
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+March+2022+Patch+Tuesday/28418/
Critical APC UPS Vulnerability
https://www.armis.com/research/tlstorm/
Vulnerabilities in Firmware Affecting HP Devices
https://www.binarly.io/news/BinarlyDiscovers16NewHighImpactVulnerabilitiesinFirmwareAffectingHPEnterpriseDevices/index.html
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+March+2022+Patch+Tuesday/28418/
Critical APC UPS Vulnerability
https://www.armis.com/research/tlstorm/
Vulnerabilities in Firmware Affecting HP Devices
https://www.binarly.io/news/BinarlyDiscovers16NewHighImpactVulnerabilitiesinFirmwareAffectingHPEnterpriseDevices/index.html
Ukraine Scam Followup
https://isc.sans.edu/forums/diary/No+Bitcoin+No+Problem+Follow+Up+to+Last+Weeks+Donation+Scam/28412/
Dirty Pipe Linux Vulnerability
https://dirtypipe.cm4all.com
Mozilla Firefox and Thunderbird Vulnerability
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/
Azure AutoWarp
https://orca.security/resources/blog/autowarp-microsoft-azure-automation-service-vulnerability/
Terramaster TOS Vulnerability
https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiation/
https://forum.terra-master.com/en/viewtopic.php?f=28&t=3030
Ukraine Scam Followup
https://isc.sans.edu/forums/diary/No+Bitcoin+No+Problem+Follow+Up+to+Last+Weeks+Donation+Scam/28412/
Dirty Pipe Linux Vulnerability
https://dirtypipe.cm4all.com
Mozilla Firefox and Thunderbird Vulnerability
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/
Azure AutoWarp
https://orca.security/resources/blog/autowarp-microsoft-azure-automation-service-vulnerability/
Terramaster TOS Vulnerability
https://octagon.net/blog/2022/03/07/cve-2022-24990-terrmaster-tos-unauthenticated-remote-command-execution-via-php-object-instantiation/
https://forum.terra-master.com/en/viewtopic.php?f=28&t=3030
Ukraine Dontation Scam
https://isc.sans.edu/forums/diary/Scam+EMail+Impersonating+Red+Cross/28404/
Cogent Disconnects Russia
https://www.washingtonpost.com/technology/2022/03/04/russia-ukraine-internet-cogent-cutoff/
Russia DDoS Lists
https://safe-surf.ru/upload/ALRT/proxies.txt
https://safe-surf.ru/upload/ALRT/referer_http_header.txt
NVidia Stolen Certificates
https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/
https://twitter.com/cyb3rops/status/1499514240008437762
GitLab Vulnerabilities
https://about.gitlab.com/releases/2022/02/25/critical-security-release-gitlab-14-8-2-released/#unauthenticated-user-enumeration-on-graphql-api
Cisco Patches
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-87Q5YRk
Ukraine Dontation Scam
https://isc.sans.edu/forums/diary/Scam+EMail+Impersonating+Red+Cross/28404/
Cogent Disconnects Russia
https://www.washingtonpost.com/technology/2022/03/04/russia-ukraine-internet-cogent-cutoff/
Russia DDoS Lists
https://safe-surf.ru/upload/ALRT/proxies.txt
https://safe-surf.ru/upload/ALRT/referer_http_header.txt
NVidia Stolen Certificates
https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/
https://twitter.com/cyb3rops/status/1499514240008437762
GitLab Vulnerabilities
https://about.gitlab.com/releases/2022/02/25/critical-security-release-gitlab-14-8-2-released/#unauthenticated-user-enumeration-on-graphql-api
Cisco Patches
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-expressway-filewrite-87Q5YRk
Attackers Search For Exosed "LuCI" Folders
https://isc.sans.edu/diary/28400
Alexa Versus Alexa
https://arxiv.org/abs/2202.08619
Bypassing Google Cloud Armor
https://kloudle.com/blog/piercing-the-cloud-armor-the-8kb-bypass-in-google-cloud-platform-waf
Ukraine Updates
https://www.golem.de/news/ausfall-angriff-auf-ka-sat-satellit-ueber-gatewaystation-in-ukraine-2203-163614.html
https://www.crowdstrike.com/blog/how-to-decrypt-the-partyticket-ransomware-targeting-ukraine/
https://www.bleepingcomputer.com/news/security/ukraine-says-local-govt-sites-hacked-to-push-fake-capitulation-news/
Attackers Search For Exosed "LuCI" Folders
https://isc.sans.edu/diary/28400
Alexa Versus Alexa
https://arxiv.org/abs/2202.08619
Bypassing Google Cloud Armor
https://kloudle.com/blog/piercing-the-cloud-armor-the-8kb-bypass-in-google-cloud-platform-waf
Ukraine Updates
https://www.golem.de/news/ausfall-angriff-auf-ka-sat-satellit-ueber-gatewaystation-in-ukraine-2203-163614.html
https://www.crowdstrike.com/blog/how-to-decrypt-the-partyticket-ransomware-targeting-ukraine/
https://www.bleepingcomputer.com/news/security/ukraine-says-local-govt-sites-hacked-to-push-fake-capitulation-news/
The More Often Something is Repeated, the More True it Becomes
https://isc.sans.edu/forums/diary/The+More+Often+Something+is+Repeated+the+More+True+It+Becomes+Dealing+with+Social+Media/28396/
Fortinet Bug
https://www.fortiguard.com/psirt/FG-IR-21-028
IBM Updates
https://www.ibm.com/blogs/psirt/
Google Updates
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop.html
Conti Ransomware Leak
https://threatpost.com/conti-ransomware-decryptor-trickbot-source-code-leaked/178727/
Middle Box DDoS Attacks
https://www.akamai.com/blog/security/tcp-middlebox-reflection
The More Often Something is Repeated, the More True it Becomes
https://isc.sans.edu/forums/diary/The+More+Often+Something+is+Repeated+the+More+True+It+Becomes+Dealing+with+Social+Media/28396/
Fortinet Bug
https://www.fortiguard.com/psirt/FG-IR-21-028
IBM Updates
https://www.ibm.com/blogs/psirt/
Google Updates
https://chromereleases.googleblog.com/2022/03/stable-channel-update-for-desktop.html
Conti Ransomware Leak
https://threatpost.com/conti-ransomware-decryptor-trickbot-source-code-leaked/178727/
Middle Box DDoS Attacks
https://www.akamai.com/blog/security/tcp-middlebox-reflection
Geoblocking when you can't Geoblock
https://isc.sans.edu/forums/diary/Geoblocking+when+you+cant+Geoblock/28392/
IsaacWiper and HermeticWizard: New wiper and worm targeting Ukraine
https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/
Memory Corruption Vulnerabilities in PJSIP
https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/
Octa Patch for Advanced Server Access Client
https://trust.okta.com/security-advisories/okta-advanced-server-access-client-cve-2022-24295
ViaSat Outage
https://www.reuters.com/business/aerospace-defense/satellite-firm-viasat-probes-suspected-cyberattack-ukraine-elsewhere-2022-02-28/
Geoblocking when you can't Geoblock
https://isc.sans.edu/forums/diary/Geoblocking+when+you+cant+Geoblock/28392/
IsaacWiper and HermeticWizard: New wiper and worm targeting Ukraine
https://www.welivesecurity.com/2022/03/01/isaacwiper-hermeticwizard-wiper-worm-targeting-ukraine/
Memory Corruption Vulnerabilities in PJSIP
https://jfrog.com/blog/jfrog-discloses-5-memory-corruption-vulnerabilities-in-pjsip-a-popular-multimedia-library/
Octa Patch for Advanced Server Access Client
https://trust.okta.com/security-advisories/okta-advanced-server-access-client-cve-2022-24295
ViaSat Outage
https://www.reuters.com/business/aerospace-defense/satellite-firm-viasat-probes-suspected-cyberattack-ukraine-elsewhere-2022-02-28/
PHP Patches Code Injection Flaw
https://nvd.nist.gov/vuln/detail/CVE-2021-21708
https://bugs.php.net/bug.php?id=81708
Mozilla VPN Local Privilege Escalation
https://www.mozilla.org/en-US/security/advisories/mfsa2022-08/
Google Captcha Breaking
https://east-ee.com/2022/02/28/1367/
Samsung Encryption Vulnerability
https://eprint.iacr.org/2022/208.pdf
tshark Multiple IPs
https://isc.sans.edu/forums/diary/TShark+Multiple+IP+Addresses/28386/
PHP Patches Code Injection Flaw
https://nvd.nist.gov/vuln/detail/CVE-2021-21708
https://bugs.php.net/bug.php?id=81708
Mozilla VPN Local Privilege Escalation
https://www.mozilla.org/en-US/security/advisories/mfsa2022-08/
Google Captcha Breaking
https://east-ee.com/2022/02/28/1367/
Samsung Encryption Vulnerability
https://eprint.iacr.org/2022/208.pdf
tshark Multiple IPs
https://isc.sans.edu/forums/diary/TShark+Multiple+IP+Addresses/28386/
Ukraine Update
https://www.bleepingcomputer.com/news/security/ransomware-gangs-hackers-pick-sides-over-russia-invading-ukraine/
https://ddosecrets.com/wiki/Tetraedr
https://twitter.com/YourAnonOne/status/1496965766435926039
https://www.wired.com/story/ukraine-it-army-russia-war-cyberattacks-ddos/
Odd Windows Behaviour with Fixed Addresses
https://isc.sans.edu/forums/diary/Windows+Fixed+IPv4+Addresses+and+APIPA/28380/
Using Snort IDS Rules in NetWitness Packet Decoder
https://isc.sans.edu/forums/diary/Using+Snort+IDS+Rules+with+NetWitness+PacketDecoder/28382/
NVidia Breach
https://www.bloomberg.com/news/articles/2022-02-25/nvidia-is-investigating-cyber-attack-but-business-uninterrupted
Windows 11 Reset Not Removing All Data
https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#2783msgdesc
Ukraine Update
https://www.bleepingcomputer.com/news/security/ransomware-gangs-hackers-pick-sides-over-russia-invading-ukraine/
https://ddosecrets.com/wiki/Tetraedr
https://twitter.com/YourAnonOne/status/1496965766435926039
https://www.wired.com/story/ukraine-it-army-russia-war-cyberattacks-ddos/
Odd Windows Behaviour with Fixed Addresses
https://isc.sans.edu/forums/diary/Windows+Fixed+IPv4+Addresses+and+APIPA/28380/
Using Snort IDS Rules in NetWitness Packet Decoder
https://isc.sans.edu/forums/diary/Using+Snort+IDS+Rules+with+NetWitness+PacketDecoder/28382/
NVidia Breach
https://www.bloomberg.com/news/articles/2022-02-25/nvidia-is-investigating-cyber-attack-but-business-uninterrupted
Windows 11 Reset Not Removing All Data
https://docs.microsoft.com/en-us/windows/release-health/status-windows-11-21h2#2783msgdesc
Ukraine Update: Webcast
https://www.sans.org/webcasts/russian-cyber-attack-escalation-in-ukraine/
Other Ukraine Related Stories
https://isc.sans.edu/forums/diary/Ukraine+Russia+Situation+From+a+Domain+Names+Perspective/28376/
https://detection.watchguard.com
Zabbix Vulnerablity Exploited
https://www.cisa.gov/uscert/ncas/current-activity/2022/02/22/cisa-adds-two-known-exploited-vulnerabilities-catalog
https://support.zabbix.com/browse/ZBX-20350
Asustore Victim of Deadbolt Ransomware
https://forum.asustor.com/viewtopic.php?f=45&t=12630
Firepower Rule Update Failure After March 5th 2022
https://www.cisco.com/c/en/us/support/docs/field-notices/723/fn72332.html?emailclick=CNSemail
Social Media Takeover Malware Distrubeted Via Microsoft App Store
https://research.checkpoint.com/2022/new-malware-capable-of-controlling-social-media-accounts-infects-5000-machines-and-is-actively-being-distributed-via-gaming-applications-on-microsofts-official-store/
Ukraine Update: Webcast
https://www.sans.org/webcasts/russian-cyber-attack-escalation-in-ukraine/
Other Ukraine Related Stories
https://isc.sans.edu/forums/diary/Ukraine+Russia+Situation+From+a+Domain+Names+Perspective/28376/
https://detection.watchguard.com
Zabbix Vulnerablity Exploited
https://www.cisa.gov/uscert/ncas/current-activity/2022/02/22/cisa-adds-two-known-exploited-vulnerabilities-catalog
https://support.zabbix.com/browse/ZBX-20350
Asustore Victim of Deadbolt Ransomware
https://forum.asustor.com/viewtopic.php?f=45&t=12630
Firepower Rule Update Failure After March 5th 2022
https://www.cisco.com/c/en/us/support/docs/field-notices/723/fn72332.html?emailclick=CNSemail
Social Media Takeover Malware Distrubeted Via Microsoft App Store
https://research.checkpoint.com/2022/new-malware-capable-of-controlling-social-media-accounts-infects-5000-machines-and-is-actively-being-distributed-via-gaming-applications-on-microsofts-official-store/
New Sandworm Malware Cyclops Blink Replaces VPNFilter
https://www.ncsc.gov.uk/news/joint-advisory-shows-new-sandworm-malware-cyclops-blink-replaces-vpnfilter
Wiper Malware Seen Deployed Against Targets in the Ukraine
https://twitter.com/juanandres_gs/status/1496581710368358400
https://twitter.com/ESETresearch/status/1496581903205511181
The Rise and Fall of log4shell
https://isc.sans.edu/forums/diary/The+Rise+and+Fall+of+log4shell/28372/
pfsense authenticated RCE
https://www.shielder.it/advisories/pfsense-remote-command-execution/
BVP47 Backdoor
https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf
New Sandworm Malware Cyclops Blink Replaces VPNFilter
https://www.ncsc.gov.uk/news/joint-advisory-shows-new-sandworm-malware-cyclops-blink-replaces-vpnfilter
Wiper Malware Seen Deployed Against Targets in the Ukraine
https://twitter.com/juanandres_gs/status/1496581710368358400
https://twitter.com/ESETresearch/status/1496581903205511181
The Rise and Fall of log4shell
https://isc.sans.edu/forums/diary/The+Rise+and+Fall+of+log4shell/28372/
pfsense authenticated RCE
https://www.shielder.it/advisories/pfsense-remote-command-execution/
BVP47 Backdoor
https://www.pangulab.cn/files/The_Bvp47_a_top-tier_backdoor_of_us_nsa_equation_group.en.pdf
A Good Old Equation Editor Vulnerablity Deliverying Malware
https://www.welivesecurity.com/2022/02/22/teenage-cybercrime-stop-kids-wrong-path/
Horde Webmail 5.2.22 - Account Takeover via Email
https://blog.sonarsource.com/horde-webmail-account-takeover-via-email
NoVNC Phishing
https://mrd0x.com/bypass-2fa-using-novnc/
A Good Old Equation Editor Vulnerablity Deliverying Malware
https://www.welivesecurity.com/2022/02/22/teenage-cybercrime-stop-kids-wrong-path/
Horde Webmail 5.2.22 - Account Takeover via Email
https://blog.sonarsource.com/horde-webmail-account-takeover-via-email
NoVNC Phishing
https://mrd0x.com/bypass-2fa-using-novnc/
Sending an Email to an IPv4 Address
https://isc.sans.edu/forums/diary/Sending+an+Email+to+an+IPv4+Address/28362/
SMS Phone-Verified Account Services
https://www.trendmicro.com/en_us/research/22/b/sms-pva-services-use-of-infected-android-phones-reveals-flaws-in-sms-verification.html
Xenomorph Android Banking Trojan
https://www.threatfabric.com/blogs/xenomorph-a-newly-hatched-banking-trojan.html
Modified CryptBot Infostealer Going After Crypto Wallets
https://asec.ahnlab.com/en/31802/
Clarification for Adobe Magento Vulnerabilties
https://helpx.adobe.com/security/products/magento/apsb22-12.html
Sending an Email to an IPv4 Address
https://isc.sans.edu/forums/diary/Sending+an+Email+to+an+IPv4+Address/28362/
SMS Phone-Verified Account Services
https://www.trendmicro.com/en_us/research/22/b/sms-pva-services-use-of-infected-android-phones-reveals-flaws-in-sms-verification.html
Xenomorph Android Banking Trojan
https://www.threatfabric.com/blogs/xenomorph-a-newly-hatched-banking-trojan.html
Modified CryptBot Infostealer Going After Crypto Wallets
https://asec.ahnlab.com/en/31802/
Clarification for Adobe Magento Vulnerabilties
https://helpx.adobe.com/security/products/magento/apsb22-12.html
Remcos RAT Delivered Through Doube Compressed Archive
https://isc.sans.edu/forums/diary/Remcos+RAT+Delivered+Through+Double+Compressed+Archive/28354/
Cassandra User-Defined Functions Remote Code Execution
https://jfrog.com/blog/cve-2021-44521-exploiting-apache-cassandra-user-defined-functions-for-remote-code-execution/
Apple T2 Weakness
https://www.forensicfocus.com/news/passware-kit-forensic-t2-add-on-the-first-password-recovery-tool-for-macs-with-t2-chips/
snap priviledge escalation
https://www.qualys.com/2022/02/17/cve-2021-44731/oh-snap-more-lemmings.txt
Remcos RAT Delivered Through Doube Compressed Archive
https://isc.sans.edu/forums/diary/Remcos+RAT+Delivered+Through+Double+Compressed+Archive/28354/
Cassandra User-Defined Functions Remote Code Execution
https://jfrog.com/blog/cve-2021-44521-exploiting-apache-cassandra-user-defined-functions-for-remote-code-execution/
Apple T2 Weakness
https://www.forensicfocus.com/news/passware-kit-forensic-t2-add-on-the-first-password-recovery-tool-for-macs-with-t2-chips/
snap priviledge escalation
https://www.qualys.com/2022/02/17/cve-2021-44731/oh-snap-more-lemmings.txt
Hackers Attach Malicious .exe Files to Teams Conversations
https://www.avanan.com/blog/hackers-attach-malicious-.exe-files-to-teams-conversations
Thunderbird Patches
https://www.mozilla.org/en-US/security/advisories/mfsa2022-07/
Cisco Secure Email Gateway Update
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-dos-MxZvGtgU
GitHub Code Scanning Finds More Vulnerabilities Using Machine Learning
https://github.blog/2022-02-17-code-scanning-finds-vulnerabilities-using-machine-learning/
Exploit for Magento Vulnerability (CVE-2022-24086) Available
https://twitter.com/ptswarm/status/1494240197915123713
More Packet Fu With Zeek
https://isc.sans.edu/forums/diary/More+packet+fu+with+zeek/28350/
Hackers Attach Malicious .exe Files to Teams Conversations
https://www.avanan.com/blog/hackers-attach-malicious-.exe-files-to-teams-conversations
Thunderbird Patches
https://www.mozilla.org/en-US/security/advisories/mfsa2022-07/
Cisco Secure Email Gateway Update
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-dos-MxZvGtgU
GitHub Code Scanning Finds More Vulnerabilities Using Machine Learning
https://github.blog/2022-02-17-code-scanning-finds-vulnerabilities-using-machine-learning/
Exploit for Magento Vulnerability (CVE-2022-24086) Available
https://twitter.com/ptswarm/status/1494240197915123713
More Packet Fu With Zeek
https://isc.sans.edu/forums/diary/More+packet+fu+with+zeek/28350/
Astaroth (Guildma) Infection
https://isc.sans.edu/forums/diary/Astaroth+Guildma+infection/28346/
Atlassian Jira Updates
https://jira.atlassian.com/browse/CONFSERVER-66550
VMWare Updates
https://www.vmware.com/security/advisories/VMSA-2022-0004.html
FBI Warns of BEC Using Virtual Meeting Platforms
https://www.ic3.gov/Media/Y2022/PSA220216
Astaroth (Guildma) Infection
https://isc.sans.edu/forums/diary/Astaroth+Guildma+infection/28346/
Atlassian Jira Updates
https://jira.atlassian.com/browse/CONFSERVER-66550
VMWare Updates
https://www.vmware.com/security/advisories/VMSA-2022-0004.html
FBI Warns of BEC Using Virtual Meeting Platforms
https://www.ic3.gov/Media/Y2022/PSA220216
Who Are Those Bots?
https://isc.sans.edu/forums/diary/Who+Are+Those+Bots/28342/
SquirrelWaffle Adds a Twist of Fraud to Exchange Server Malspamming
https://news.sophos.com/en-us/2022/02/15/vulnerable-exchange-server-hit-by-squirrelwaffle-and-financial-fraud/
Details About Western Digital MyCloud Flaw
https://www.iot-inspector.com/blog/advisory-western-digital-my-cloud-pro-series-pr4100-rce/
Nooie Baby Monitor Vulnerabilities
https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-nooie-baby-monitor/
Who Are Those Bots?
https://isc.sans.edu/forums/diary/Who+Are+Those+Bots/28342/
SquirrelWaffle Adds a Twist of Fraud to Exchange Server Malspamming
https://news.sophos.com/en-us/2022/02/15/vulnerable-exchange-server-hit-by-squirrelwaffle-and-financial-fraud/
Details About Western Digital MyCloud Flaw
https://www.iot-inspector.com/blog/advisory-western-digital-my-cloud-pro-series-pr4100-rce/
Nooie Baby Monitor Vulnerabilities
https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-nooie-baby-monitor/
Reminder: Decoding TLS Client Hello to Non TLS Servers
https://isc.sans.edu/forums/diary/Reminder+Decoding+TLS+Client+Hellos+to+non+TLS+servers/28338/
Magento 2 Critical Vulnerability
https://sansec.io/research/magento-2-cve-2022-24086
BigSur/Catalina Mystery Update
https://support.apple.com/en-us/HT201222
MacOS Monterey Patch and Microsoft Defender
https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/mde-apparently-blocks-macos-monterey-12-1-12-2-upgrades/m-p/3078793
Google Chrome 0-Day Fixed
https://chromereleases.googleblog.com/2022/02/stable-channel-update-for-desktop_14.html
Moxa MXview Vulnerabilities and Patch
https://www.claroty.com/2022/02/10/blog-research-securing-network-management-systems-moxa-mxview/
Reminder: Decoding TLS Client Hello to Non TLS Servers
https://isc.sans.edu/forums/diary/Reminder+Decoding+TLS+Client+Hellos+to+non+TLS+servers/28338/
Magento 2 Critical Vulnerability
https://sansec.io/research/magento-2-cve-2022-24086
BigSur/Catalina Mystery Update
https://support.apple.com/en-us/HT201222
MacOS Monterey Patch and Microsoft Defender
https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/mde-apparently-blocks-macos-monterey-12-1-12-2-upgrades/m-p/3078793
Google Chrome 0-Day Fixed
https://chromereleases.googleblog.com/2022/02/stable-channel-update-for-desktop_14.html
Moxa MXview Vulnerabilities and Patch
https://www.claroty.com/2022/02/10/blog-research-securing-network-management-systems-moxa-mxview/
CinaRAT Delivered Through HTML ID Attributes
https://isc.sans.edu/forums/diary/CinaRAT+Delivered+Through+HTML+ID+Attributes/28330/
Windows Defender ASR Blocks LSASS Credential Stealing
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-credential-stealing-from-the-windows-local-security-authority-subsystem
Brave Blocking Credential Leaking Extension
https://www.theregister.com/2022/02/12/facebook_god_mode/
Project Zero Summary of Zero Day Bugs
https://googleprojectzero.blogspot.com/2022/02/a-walk-through-project-zero-metrics.html
CinaRAT Delivered Through HTML ID Attributes
https://isc.sans.edu/forums/diary/CinaRAT+Delivered+Through+HTML+ID+Attributes/28330/
Windows Defender ASR Blocks LSASS Credential Stealing
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-credential-stealing-from-the-windows-local-security-authority-subsystem
Brave Blocking Credential Leaking Extension
https://www.theregister.com/2022/02/12/facebook_god_mode/
Project Zero Summary of Zero Day Bugs
https://googleprojectzero.blogspot.com/2022/02/a-walk-through-project-zero-metrics.html
iOS/iPadOS/macOS/Safari 0-Day Vulnerability in WebKit
https://support.apple.com/en-us/HT213091
Zyxel Network Storage Devics Hunted By Mirai Variant
https://isc.sans.edu/forums/diary/Zyxel+Network+Storage+Devices+Hunted+By+Mirai+Variant/28324/
WMIC Removal
https://docs.microsoft.com/en-us/windows/deployment/planning/windows-10-deprecated-features
Zoom Uses Microphone after Meeting is Over
https://community.zoom.com/t5/Meetings/Why-is-the-Zoom-app-listening-on-my-microphone-when-not-in-a/td-p/29019
Evidence Planted to Implicate Innocent Activists
https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/
iOS/iPadOS/macOS/Safari 0-Day Vulnerability in WebKit
https://support.apple.com/en-us/HT213091
Zyxel Network Storage Devics Hunted By Mirai Variant
https://isc.sans.edu/forums/diary/Zyxel+Network+Storage+Devices+Hunted+By+Mirai+Variant/28324/
WMIC Removal
https://docs.microsoft.com/en-us/windows/deployment/planning/windows-10-deprecated-features
Zoom Uses Microphone after Meeting is Over
https://community.zoom.com/t5/Meetings/Why-is-the-Zoom-app-listening-on-my-microphone-when-not-in-a/td-p/29019
Evidence Planted to Implicate Innocent Activists
https://www.sentinelone.com/labs/modifiedelephant-apt-and-a-decade-of-fabricating-evidence/
Example of Cobalt Strike form Emotet Infection
https://isc.sans.edu/forums/diary/Example+of+Cobalt+Strike+from+Emotet+infection/28318/
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Intel Updates
https://www.intel.com/content/www/us/en/security-center/default.html
NaturalFreshMall: A Mass Store Attack
https://sansec.io/research/naturalfreshmall-mass-hack
Example of Cobalt Strike form Emotet Infection
https://isc.sans.edu/forums/diary/Example+of+Cobalt+Strike+from+Emotet+infection/28318/
Adobe Patches
https://helpx.adobe.com/security/security-bulletin.html
Intel Updates
https://www.intel.com/content/www/us/en/security-center/default.html
NaturalFreshMall: A Mass Store Attack
https://sansec.io/research/naturalfreshmall-mass-hack
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+February+2022+Patch+Tuesday/28316/
Google Cloud Virtual Machine Threat Detection
https://cloud.google.com/security-command-center/docs/concepts-vm-threat-detection-overview
Android Patches
https://source.android.com/security/bulletin/2022-02-01
SAP Patches
https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+February+2022
Podcast 13 Year Anniversary
https://isc.sans.edu/podcastdetail.html?id=25
Microsoft Patch Tuesday
https://isc.sans.edu/forums/diary/Microsoft+February+2022+Patch+Tuesday/28316/
Google Cloud Virtual Machine Threat Detection
https://cloud.google.com/security-command-center/docs/concepts-vm-threat-detection-overview
Android Patches
https://source.android.com/security/bulletin/2022-02-01
SAP Patches
https://wiki.scn.sap.com/wiki/display/PSR/SAP+Security+Patch+Day+-+February+2022
Podcast 13 Year Anniversary
https://isc.sans.edu/podcastdetail.html?id=25
web3 phishing via self-customizign landing pages
https://isc.sans.edu/forums/diary/web3+phishing+via+selfcustomizing+landing+pages/28312/
MSFT Blocking Office VBA Malcros
https://www.theverge.com/2022/2/7/22922032/microsoft-block-office-vba-macros-default-change
https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805
Acronis True Image Update
https://security-advisory.acronis.com/updates/UPD-2201-f76f-838c
Lockbit 2 IoCs
https://www.ic3.gov/Media/News/2022/220204.pdf
web3 phishing via self-customizign landing pages
https://isc.sans.edu/forums/diary/web3+phishing+via+selfcustomizing+landing+pages/28312/
MSFT Blocking Office VBA Malcros
https://www.theverge.com/2022/2/7/22922032/microsoft-block-office-vba-macros-default-change
https://techcommunity.microsoft.com/t5/microsoft-365-blog/helping-users-stay-safe-blocking-internet-macros-by-default-in/ba-p/3071805
Acronis True Image Update
https://security-advisory.acronis.com/updates/UPD-2201-f76f-838c
Lockbit 2 IoCs
https://www.ic3.gov/Media/News/2022/220204.pdf
Intuit warns of new phishing scams
https://security.intuit.com/security-notices
IRS working with ID.me
https://www.irs.gov/newsroom/new-identity-verification-process-to-access-certain-irs-online-tools-and-services
Argo CD Vulnerability
https://apiiro.com/blog/malicious-kubernetes-helm-charts-can-be-used-to-steal-sensitive-information-from-argo-cd-deployments/
https://github.com/argoproj/argo-cd/security/advisories/GHSA-63qx-x74g-jcr7
Thermal Imaging of PoE Devices
https://isc.sans.edu/forums/diary/Power+over+Ethernet+and+Thermal+Imaging/28308/
Intuit warns of new phishing scams
https://security.intuit.com/security-notices
IRS working with ID.me
https://www.irs.gov/newsroom/new-identity-verification-process-to-access-certain-irs-online-tools-and-services
Argo CD Vulnerability
https://apiiro.com/blog/malicious-kubernetes-helm-charts-can-be-used-to-steal-sensitive-information-from-argo-cd-deployments/
https://github.com/argoproj/argo-cd/security/advisories/GHSA-63qx-x74g-jcr7
Thermal Imaging of PoE Devices
https://isc.sans.edu/forums/diary/Power+over+Ethernet+and+Thermal+Imaging/28308/
Attack Surface Detection
https://isc.sans.edu/forums/diary/Keeping+Track+of+Your+Attack+Surface+for+Cheap/28304/
MFA News
https://www.proofpoint.com/us/blog/threat-insight/mfa-psa-oh-my
https://news.microsoft.com/wp-content/uploads/prod/sites/626/2022/02/Cyber-Signals-E-1.pdf
Zimbra Webmail 0-Day Exploited
https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/
Cisco RV Series Routers Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-mult-vuln-KA9PK6D
Attack Surface Detection
https://isc.sans.edu/forums/diary/Keeping+Track+of+Your+Attack+Surface+for+Cheap/28304/
MFA News
https://www.proofpoint.com/us/blog/threat-insight/mfa-psa-oh-my
https://news.microsoft.com/wp-content/uploads/prod/sites/626/2022/02/Cyber-Signals-E-1.pdf
Zimbra Webmail 0-Day Exploited
https://www.volexity.com/blog/2022/02/03/operation-emailthief-active-exploitation-of-zero-day-xss-vulnerability-in-zimbra/
Cisco RV Series Routers Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-smb-mult-vuln-KA9PK6D
Finding elFinder: Who is looking for your files?
https://isc.sans.edu/forums/diary/Finding+elFinder+Who+is+looking+for+your+files/28300/
IBM Spectrum Protect Plus Container Backup Vulnerabilities
https://www.ibm.com/support/pages/node/6540860
https://www.ibm.com/support/pages/node/6552188
Microsoft Update Connectivity
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/achieve-better-patch-compliance-with-update-connectivity-data/ba-p/3073356
UEFI Bios Vulnerabilities
https://www.insyde.com/security-pledge
Finding elFinder: Who is looking for your files?
https://isc.sans.edu/forums/diary/Finding+elFinder+Who+is+looking+for+your+files/28300/
IBM Spectrum Protect Plus Container Backup Vulnerabilities
https://www.ibm.com/support/pages/node/6540860
https://www.ibm.com/support/pages/node/6552188
Microsoft Update Connectivity
https://techcommunity.microsoft.com/t5/windows-it-pro-blog/achieve-better-patch-compliance-with-update-connectivity-data/ba-p/3073356
UEFI Bios Vulnerabilities
https://www.insyde.com/security-pledge
Windows Privilege Escalation Exploit CVE-2022-21882
https://github.com/KaLendsi/CVE-2022-21882
Fingerprinting Devices Via GPU
https://arxiv.org/pdf/2201.09956.pdf
SolarMarker Campaign used novel registry changes to establish persistence
https://news.sophos.com/en-us/2022/02/01/solarmarker-campaign-used-novel-registry-changes-to-establish-persistence/
Fake Job Ads
https://www.ic3.gov/Media/Y2022/PSA220201
Automation is Nice But Don't Replace Your Knowledge
https://isc.sans.edu/forums/diary/Automation+is+Nice+But+Dont+Replace+Your+Knowledge/28296/
Windows Privilege Escalation Exploit CVE-2022-21882
https://github.com/KaLendsi/CVE-2022-21882
Fingerprinting Devices Via GPU
https://arxiv.org/pdf/2201.09956.pdf
SolarMarker Campaign used novel registry changes to establish persistence
https://news.sophos.com/en-us/2022/02/01/solarmarker-campaign-used-novel-registry-changes-to-establish-persistence/
Fake Job Ads
https://www.ic3.gov/Media/Y2022/PSA220201
Automation is Nice But Don't Replace Your Knowledge
https://isc.sans.edu/forums/diary/Automation+is+Nice+But+Dont+Replace+Your+Knowledge/28296/
Be Careful with RPMSG Files
https://isc.sans.edu/forums/diary/Be+careful+with+RPMSG+files/28292/
QNAP Auto Update Clarification
https://www.qnap.com/en/security-news/2022/descriptions-and-explanations-of-the-qts-quts-hero-recommended-version-feature
Samba Vulnerability
https://kb.cert.org/vuls/id/119678
Exposed Datacenter Management
https://www.bleepingcomputer.com/news/security/over-20-000-data-center-management-systems-exposed-to-hackers/
Expat Vulnerability
https://github.com/libexpat/libexpat/blob/master/expat/Changes
Be Careful with RPMSG Files
https://isc.sans.edu/forums/diary/Be+careful+with+RPMSG+files/28292/
QNAP Auto Update Clarification
https://www.qnap.com/en/security-news/2022/descriptions-and-explanations-of-the-qts-quts-hero-recommended-version-feature
Samba Vulnerability
https://kb.cert.org/vuls/id/119678
Exposed Datacenter Management
https://www.bleepingcomputer.com/news/security/over-20-000-data-center-management-systems-exposed-to-hackers/
Expat Vulnerability
https://github.com/libexpat/libexpat/blob/master/expat/Changes
Malicious ISO Embedded in an HTML Page
https://isc.sans.edu/forums/diary/Malicious+ISO+Embedded+in+an+HTML+Page/28282/
YARA Console Module
https://isc.sans.edu/forums/diary/YARAs+Console+Module/28288/
Attackers Attaching Devices to Azure AD
https://www.microsoft.com/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/
QNAP Forced Updates
https://www.reddit.com/r/qnap/comments/sdsf02/i_just_suffered_what_i_believe_to_be_a_forced/huhfmjc/
Malicious ISO Embedded in an HTML Page
https://isc.sans.edu/forums/diary/Malicious+ISO+Embedded+in+an+HTML+Page/28282/
YARA Console Module
https://isc.sans.edu/forums/diary/YARAs+Console+Module/28288/
Attackers Attaching Devices to Azure AD
https://www.microsoft.com/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/
QNAP Forced Updates
https://www.reddit.com/r/qnap/comments/sdsf02/i_just_suffered_what_i_believe_to_be_a_forced/huhfmjc/
Technical Analysis of CVE-2022-22583
https://perception-point.io/technical-analysis-of-cve-2022-22583-bypassing-macos-system-integrity-protection/
https://isc.sans.edu/forums/diary/Apple+Patches+Everything/28280/
Little Snitch Firewall Bypass
https://rhinosecuritylabs.com/network-security/bypassing-little-snitch-firewall/
DazzleSpy Malware
https://www.welivesecurity.com/2022/01/25/watering-hole-deploys-new-macos-malware-dazzlespy-asia/
Geoffrey Parker: Building an Intelligent, Automated Tiered Phishing System
https://www.sans.edu/cyber-research/building-an-intelligent-automated-tiered-phishing-system-matching-the-message-level-to-user-ability/
Technical Analysis of CVE-2022-22583
https://perception-point.io/technical-analysis-of-cve-2022-22583-bypassing-macos-system-integrity-protection/
https://isc.sans.edu/forums/diary/Apple+Patches+Everything/28280/
Little Snitch Firewall Bypass
https://rhinosecuritylabs.com/network-security/bypassing-little-snitch-firewall/
DazzleSpy Malware
https://www.welivesecurity.com/2022/01/25/watering-hole-deploys-new-macos-malware-dazzlespy-asia/
Geoffrey Parker: Building an Intelligent, Automated Tiered Phishing System
https://www.sans.edu/cyber-research/building-an-intelligent-automated-tiered-phishing-system-matching-the-message-level-to-user-ability/
Over 20 Thousand Servers Have Their iLO Interfaces exposed to the Internet
https://isc.sans.edu/forums/diary/Over+20+thousand+servers+have+their+iLO+interfaces+exposed+to+the+internet+many+with+outdated+and+vulnerable+versions+of+FW/28276/
Apple Patches and Exploits
https://support.apple.com/en-us/HT201222
https://www.ryanpickren.com/safari-uxss
Let's Encrypt Fixes Problems and Revoces Certificates
https://community.letsencrypt.org/t/changes-to-tls-alpn-01-challenge-validation/170427
Over 20 Thousand Servers Have Their iLO Interfaces exposed to the Internet
https://isc.sans.edu/forums/diary/Over+20+thousand+servers+have+their+iLO+interfaces+exposed+to+the+internet+many+with+outdated+and+vulnerable+versions+of+FW/28276/
Apple Patches and Exploits
https://support.apple.com/en-us/HT201222
https://www.ryanpickren.com/safari-uxss
Let's Encrypt Fixes Problems and Revoces Certificates
https://community.letsencrypt.org/t/changes-to-tls-alpn-01-challenge-validation/170427
Local Privilege Escalation Vulnerablity in Polkit's pkexec (CVE-2021-4034)
https://isc.sans.edu/forums/diary/Local+privilege+escalation+vulnerability+in+polkits+pkexec+CVE20214034/28272/
Emotet Stops Using 0.0.0.0 in Spambot Traffic
https://isc.sans.edu/forums/diary/Emotet+Stops+Using+0000+in+Spambot+Traffic/28270/
VMWare Warns of Log4j Exploitation
https://www.vmware.com/security/advisories/VMSA-2021-0028.html
https://www.cynet.com/attack-techniques-hands-on/threats-looming-over-the-horizon/
Local Privilege Escalation Vulnerablity in Polkit's pkexec (CVE-2021-4034)
https://isc.sans.edu/forums/diary/Local+privilege+escalation+vulnerability+in+polkits+pkexec+CVE20214034/28272/
Emotet Stops Using 0.0.0.0 in Spambot Traffic
https://isc.sans.edu/forums/diary/Emotet+Stops+Using+0000+in+Spambot+Traffic/28270/
VMWare Warns of Log4j Exploitation
https://www.vmware.com/security/advisories/VMSA-2021-0028.html
https://www.cynet.com/attack-techniques-hands-on/threats-looming-over-the-horizon/
Moonbound UEFI Malware
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
Exploit of Sonicwall CVE-2021-20038
https://twitter.com/buffaloverflow/status/1485671824725786633
Dell EMC AppSync Vulnerability
https://www.dell.com/support/kbdoc/de-de/000195377/dsa-2022-003-dell-emc-appsync-security-update-for-multiple-vulnerabilities
Twitter API Keys Leaked in GitHub
https://incognitatech.medium.com/using-twitter-to-notify-careless-developers-the-unorthodox-way-d71478ad367a
Moonbound UEFI Malware
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
Exploit of Sonicwall CVE-2021-20038
https://twitter.com/buffaloverflow/status/1485671824725786633
Dell EMC AppSync Vulnerability
https://www.dell.com/support/kbdoc/de-de/000195377/dsa-2022-003-dell-emc-appsync-security-update-for-multiple-vulnerabilities
Twitter API Keys Leaked in GitHub
https://incognitatech.medium.com/using-twitter-to-notify-careless-developers-the-unorthodox-way-d71478ad367a
Obscure Wininet.dll Feature
https://isc.sans.edu/forums/diary/Obscure+Wininetdll+Feature/28262/
Mixed VBA and Excel 4 Macro in Targeted Excel Sheet
https://isc.sans.edu/forums/diary/Mixed+VBA+Excel4+Macro+In+a+Targeted+Excel+Sheet/28264/
https://techcommunity.microsoft.com/t5/excel-blog/excel-4-0-xlm-macros-now-restricted-by-default-for-customer/ba-p/3057905
F5 January 2022 Patches
https://support.f5.com/csp/article/K40084114
McAfee Privilege Escalation
https://kc.mcafee.com/corporate/index?page=content&id=SB10378
Obscure Wininet.dll Feature
https://isc.sans.edu/forums/diary/Obscure+Wininetdll+Feature/28262/
Mixed VBA and Excel 4 Macro in Targeted Excel Sheet
https://isc.sans.edu/forums/diary/Mixed+VBA+Excel4+Macro+In+a+Targeted+Excel+Sheet/28264/
https://techcommunity.microsoft.com/t5/excel-blog/excel-4-0-xlm-macros-now-restricted-by-default-for-customer/ba-p/3057905
F5 January 2022 Patches
https://support.f5.com/csp/article/K40084114
McAfee Privilege Escalation
https://kc.mcafee.com/corporate/index?page=content&id=SB10378
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Exchange E-Discovery Scans; Danabot Malspam; Weaponizing Middleboxes; COTS Encryption in Ransomware
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Microsoft Patches; Adobe Patches; cPanel Vulns; Firefox Update
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.
Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security.