ESET Research on Twitter: "#ESETresearch discovered a trojanized IDA Pro installer, distributed by the #Lazarus APT group. Attackers bundled the original IDA Pro 7.5 software developed by @HexRaysSA with two malicious components. @cherepanov74 1/5 https://t.co/WEAJz4Gxpi" / Twitter
https://twitter.com/esetresearch/status/1458438155149922312
ReCertifying Active Directory
https://www.slideshare.net/harmj0y/recertifying-active-directory
Cyber-mercenary group Void Balaur has been hacking companies for years
https://therecord.media/cyber-mercenary-group-void-balaur-has-been-hacking-companies-for-years/
Microsoft Issues Patches for Actively Exploited Excel, Exchange Server 0-Day Bugs
https://thehackernews.com/2021/11/microsoft-issues-patches-for-actively.html
ChaosDB explained: Azure's Cosmos DB vulnerability walkthrough | Wiz Blog
https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-vulnerability-walkthrough
14 New Security Flaws Found in BusyBox Linux Utility for Embedded Devices
https://thehackernews.com/2021/11/14-new-security-flaws-found-in-busybox.html
Tweet / Twitter
https://twitter.com/browninfosecguy/status/1458039376693366784
Quakbot Strikes with QuakNightmare Exploitation
https://www.cynet.com/attack-techniques-hands-on/quakbot-strikes-with-quaknightmare-exploitation/
We're sorry, but something went wrong (500)
https://aka.ms/MSRC-Registration
Massive Zero-Day Hole Found in Palo Alto Security Appliances | Threatpost
https://threatpost.com/massive-zero-day-hole-found-in-palo-alto-security-appliances/176170/
home.account.msoffice.team - urlscan.io
https://urlscan.io/result/e85a1b75-f472-440c-b679-d7d28e5ea9c9
Exclusive: A Cyber Mercenary Is Hacking The Google And Telegram Accounts Of Presidential Candidates, Journalists And Doctors
https://www.forbes.com/sites/thomasbrewster/2021/11/10/rocket-hack-hacker-for-hire-targets-belrus-opposition-gmail-protonmail-and-telegram
Zero-Day Disclosure: PAN GlobalProtect CVE-2021-3064
https://www.randori.com/blog/cve-2021-3064
SITE NOT FOUND
http://bit.ly/3mSwsVv
Ricerca Security: ARMored CoreSight: Towards Efficient Binary-only Fuzzing
https://ricercasecurity.blogspot.com/2021/11/armored-coresight-towards-efficient.html
Tweet / Twitter
https://twitter.com/gossithedog/status/1458183749351485444
Installing TinyTracer on Windows 10 - YouTube
https://www.youtube.com/watch?v=iTtRoxO48kQ
Updating The Verge’s background policy - The Verge
https://www.theverge.com/press-room/22772113/the-verge-on-background-policy-update
TrickBot teams up with Shatak phishers for Conti ransomware attacks
https://www.bleepingcomputer.com/news/security/trickbot-teams-up-with-shatak-phishers-for-conti-ransomware-attacks/
Red Canary on Twitter: "New from @jsecurity101: MSRPC to ATT&CK is an encyclopedia of comprehensive context about specific Remote Procedure Call protocols. https://t.co/giieQZE4bs https://t.co/0lAJ0ECwG5" / Twitter
https://twitter.com/redcanary/status/1458505409724141572
CVE-2021-3064 PAN-OS: Memory Corruption Vulnerability in GlobalProtect Portal and Gateway Interfaces
https://security.paloaltonetworks.com/CVE-2021-3064
CVE-2021-42321 - Security Update Guide - Microsoft - Microsoft Exchange Server Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-42321
KB5008102—Active Directory Security Accounts Manager hardening changes (CVE-2021-42278) - Microsoft Support
https://support.microsoft.com/en-us/topic/kb5008102-active-directory-security-accounts-manager-hardening-changes-cve-2021-42278-5975b463-4c95-45e1-831a-d120004e258e
David Alicea on Twitter: "Here’s another one… https://t.co/C2WDiTMY2d" / Twitter
https://twitter.com/dayvee87/status/1458084680234852368
Careers at Thomson Reuters
https://thomsonreuters.wd5.myworkdayjobs.com/External_Career_Site/job/USA-San-Francisco-California-S/Cybersecurity-Correspondent--Level-1-Journalist-_JREQ151014
Robinhood Hackers Accessed Internal Tool for Removing Account Security Features, Screenshots Show
https://www.vice.com/en/article/epxdmn/robinhood-hackers-internal-tool-security-features
Webinar - Securing the future of Cloud Native Development
https://lp.traceable.ai/2021_11_CloudNative.html?utm_medium=org_social&utm_source=organic_search&utm_campaign=tb_mitppm_wrmlaunch_digmc_nord_us_en&utm_content=_free-trial
(1) New Messages!
https://www.cybereason.com/blog/threat-analysis-report-from-shatak-emails-to-the-conti-ransomware
Walking on APT31 infrastructure footprints - SEKOIA.IO
https://bit.ly/3wBiqfl
Ringzer0 - Offensive Security Training, Done Right
https://ringzer0.training/
Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond
https://www.intruder.io/research/practical-http-header-smuggling
Neutralize threats before Impact
http://SEKOIA.IO
Pagina non trovata – Exprivia
https://www.exprivia.it/it/cybersecurity-ottimizzare-gli-investimenti-andltbr-andgtper-ridurre-il-rischio-complessivo/6835/apulia-cybersecurity-forum-2021-andltbr-andgt2anddeg-edizione.php