Malicious Python packages caught stealing Discord tokens, installing shells
https://therecord.media/malicious-python-packages-caught-stealing-discord-tokens-installing-shells/
Some notes about Microsoft Exchange Deserialization RCE (CVE-2021–42321) | by Peterjson | Medium
https://peterjson.medium.com/some-notes-about-microsoft-exchange-deserialization-rce-cve-2021-42321-110d04e8852
Project Zero: Using Kerberos for Authentication Relay Attacks
https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html
11 Malicious PyPI Python Libraries Caught Stealing Discord Tokens and Installing Shells
https://thehackernews.com/2021/11/11-malicious-pypi-python-libraries.html
FBI - Tips
http://tips.fbi.gov
Fall of the machines: Exploiting the Qualcomm NPU (neural processing unit) kernel driver | GitHub Security Lab
https://securitylab.github.com/research/qualcomm_npu
[CONTI] Ransomware Group In-Depth Analysis - PRODAFT
https://www.prodaft.com/resource/detail/conti-ransomware-group-depth-analysis
Cobalt Strike: Decrypting Obfuscated Traffic – Part 4 – NVISO Labs
https://blog.nviso.eu/2021/11/17/cobalt-strike-decrypting-obfuscated-traffic-part-4/
TPM sniffing – Sec Team Blog
https://blog.scrt.ch/2021/11/15/tpm-sniffing/
https://dl.packetstormsecurity.net/2111-exploits/gitlab13102reverse-exec.txt
https://dl.packetstormsecurity.net/2111-exploits/gitlab13102reverse-exec.txt
HackSys Extreme Vulnerable Driver — Arbitrary Write NULL (New Solution) | by w4fz5uck5 | Medium
https://wafzsucks.medium.com/hacksys-extreme-vulnerable-driver-arbitrary-write-null-new-solution-7d45bfe6d116
Unzip, 6 more - CyberChef
https://tinyurl.com/zexbjxcd
FDIC: FIL-74-2021: Computer-Security Incident Notification Final Rule
https://www.fdic.gov/news/financial-institution-letters/2021/fil21074.html
Capitol Violence — FBI
https://fbi.gov/wanted/capitol-violence
𝕯𝖒𝖎𝖙𝖗𝖞 𝕾𝖒𝖎𝖑𝖞𝖆𝖓𝖊𝖙𝖘 on Twitter: "#Conti #Ransomware https://t.co/cWfGfRHd2b" / Twitter
https://twitter.com/ddd1ms/status/1461813586154635268
herrcore on Twitter: "🚨Live on Twitch Join us as we speed run RE a static config extractor for #Emotet 👾🍹#REandChat https://t.co/qmFXpiGGcX" / Twitter
https://twitter.com/herrcore/status/1461486204076052486
Triple Threat: North Korea-Aligned TA406 Scams, Spies, and Steals | Proofpoint US
https://www.proofpoint.com/us/blog/threat-insight/triple-threat-north-korea-aligned-ta406-scams-spies-and-steals
GitHub - binref/refinery: High Octane Triage Analysis
https://github.com/binref/refinery/
PRODAFT on Twitter: "PRODAFT Threat Intelligence (PTI) team has issued a new report on the inner workings of the notorious #Conti ransomware group which is currently recognized as the most dangerous #ransomware operation in terms of its revenue and target selection. https://t.co/EcqR8sgCxX" / Twitter
https://twitter.com/PRODAFT/status/1461336459231866892
Malware-Traffic-Analysis.net - 2021-11-18 (Thursday) - Emotet epoch 4 activity (emails/malware/pcap)
https://www.malware-traffic-analysis.net/2021/11/18/index.html
Space / Twitter
https://twitter.com/i/spaces/1mnxedbBOyPJX
Intelligence Insights: November 2021
https://redcanary.com/blog/intelligence-insights-november-2021/
Insurers run from ransomware cover as losses mount | Reuters
https://www.reuters.com/markets/europe/insurers-run-ransomware-cover-losses-mount-2021-11-19/
New Side Channel Attacks Re-Enable Serious DNS Cache Poisoning Attacks
https://thehackernews.com/2021/11/new-side-channel-attacks-re-enable.html
Sponsor @FuzzySecurity on GitHub Sponsors · GitHub
https://github.com/sponsors/FuzzySecurity
Bsides Chile 2021 - Versión QUARANTINE - YouTube
https://youtu.be/YwhioxWlUWo
GitHub - oXis/GPUSleep: Move CS beacon to GPU memory when sleeping
https://github.com/oXis/GPUSleep
Cobalt Strike: Using Known Private Keys To Decrypt Traffic – Part 1 – NVISO Labs
https://blog.nviso.eu/2021/10/21/cobalt-strike-using-known-private-keys-to-decrypt-traffic-part-1/
The Pitfall of Threat Intelligence Whitelisting: Specter Botnet is 'taking over' Top Legit DNS Domains By Using ClouDNS Service
https://blog.netlab.360.com/the-pitfall-of-threat-intelligence-whitelisting-specter-botnet-is-taking-over-top-legit-dns-domains-by-using-cloudns-service/
Cobalt Strike: Using Process Memory To Decrypt Traffic – Part 3 – NVISO Labs
https://blog.nviso.eu/2021/11/03/cobalt-strike-using-process-memory-to-decrypt-traffic-part-3/
Experts Expose Secrets of Conti Ransomware Group That Made 25 Million from Victims
https://thehackernews.com/2021/11/experts-expose-secrets-of-conti.html
GitHub's commitment to npm ecosystem security | The GitHub Blog
https://github.blog/2021-11-15-githubs-commitment-to-npm-ecosystem-security/