11/11

Tweet / Twitter

https://twitter.com/campuscodi/status/1458668057040097283
Tweet / Twitter

Alan Paller, Cyber Security Industry Titan and SANS Institute Founder, Passes Away | SANS Institute

https://www.sans.org/press/announcements/alan-paller-cyber-security-industry-titan-and-sans-institute-founder-passes-away/
Alan Paller, Cyber Security Industry Titan and SANS Institute Founder, Passes Away | SANS Institute

Zero-Day Disclosure: PAN GlobalProtect CVE-2021-3064

https://www.randori.com/blog/cve-2021-3064/
Zero-Day Disclosure: PAN GlobalProtect CVE-2021-3064

Analyzing a watering hole campaign using macOS exploits

https://blog.google/threat-analysis-group/analyzing-watering-hole-campaign-using-macos-exploits/
Analyzing a watering hole campaign using macOS exploits

The hunt for NOBELIUM, the most sophisticated nation-state attack in history - Microsoft Security Blog

https://www.microsoft.com/security/blog/2021/11/10/the-hunt-for-nobelium-the-most-sophisticated-nation-state-attack-in-history/
The hunt for NOBELIUM, the most sophisticated nation-state attack in history - Microsoft Security Blog

Tweet / Twitter

https://twitter.com/browninfosecguy/status/1458039376693366784
Tweet / Twitter

Zero-Day Disclosure: PAN GlobalProtect CVE-2021-3064

https://www.randori.com/blog/cve-2021-3064
Zero-Day Disclosure: PAN GlobalProtect CVE-2021-3064

HPE says hackers breached Aruba Central using stolen access key

https://www.bleepingcomputer.com/news/security/hpe-says-hackers-breached-aruba-central-using-stolen-access-key/
HPE says hackers breached Aruba Central using stolen access key

Secondary-Contexts - Google スライド

https://docs.google.com/presentation/d/1jqnpPe0A7L_cVuPe1V0XeW6LOHvMYg5PBqHd96SScJ8
Secondary-Contexts - Google スライド

The Kerberos Key List Attack: The return of the Read Only Domain Controllers – SecureAuth

https://www.secureauth.com/blog/the-kerberos-key-list-attack-the-return-of-the-read-only-domain-controllers/
The Kerberos Key List Attack: The return of the Read Only Domain Controllers – SecureAuth

2214 - Windows: WSAQuerySocketSecurity AppContainer EoP - project-zero

https://bugs.chromium.org/p/project-zero/issues/detail?id=2214
2214 - Windows: WSAQuerySocketSecurity AppContainer EoP - project-zero

Server Resolution Error 1001 - SDxCentral

https://www.sdxcentral.com/articles/news/women-in-cybersecurity-arent-unicorns-we-do-exist/2021/11/
Server Resolution Error 1001 - SDxCentral

Palo Alto Warns of Zero-Day Bug in Firewalls Using GlobalProtect Portal VPN

https://thehackernews.com/2021/11/palo-alto-warns-of-zero-day-bug-in.html
Palo Alto Warns of Zero-Day Bug in Firewalls Using GlobalProtect Portal VPN

Top Google Result for NFT Marketplace OpenSea Was a Phishing Site

https://www.vice.com/en/article/k7wakw/top-google-result-opensea-phishing-site
Top Google Result for NFT Marketplace OpenSea Was a Phishing Site

Cyber-mercenary group Void Balaur has been hacking companies for years

https://therecord.media/cyber-mercenary-group-void-balaur-has-been-hacking-companies-for-years/
Cyber-mercenary group Void Balaur has been hacking companies for years

Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond

https://www.intruder.io/research/practical-http-header-smuggling
Practical HTTP Header Smuggling: Sneaking Past Reverse Proxies to Attack AWS and Beyond

https://synthesis.to/2021/11/11/practical_mba_deobfuscation.html

https://synthesis.to/2021/11/11/practical_mba_deobfuscation.html

Google Caught Hackers Using a Mac Zero-Day Against Hong Kong Users

https://www.vice.com/en/article/93bw8y/google-caught-hackers-using-a-mac-zero-day-against-hong-kong-users
Google Caught Hackers Using a Mac Zero-Day Against Hong Kong Users

Hoe Booking een Amerikaanse spion in de eigen systemen ontdekte (en niets tegen de klanten zei) - NRC

https://www.nrc.nl/nieuws/2021/11/10/spion-andrew-zocht-bij-booking-uit-wie-naar-midden-oosten-reisde-2-a4065012
Hoe Booking een Amerikaanse spion in de eigen systemen ontdekte (en niets tegen de klanten zei) - NRC

American spy hacked Booking.com, company stayed silent - NRC

https://www.nrc.nl/nieuws/2021/11/10/american-spy-hacked-bookingcom-company-stayed-silent-a4065086
American spy hacked Booking.com, company stayed silent - NRC

Iran's Lyceum Hackers Target Telecoms, ISPs in Israel, Saudi Arabia, and Africa

https://thehackernews.com/2021/11/irans-lyceum-hackers-target-telecoms.html
Iran's Lyceum Hackers Target Telecoms, ISPs in Israel, Saudi Arabia, and Africa

Security Weekly Unlocked DIGITAL

https://events.securityweekly.com/unlocked2021
Security Weekly Unlocked DIGITAL