11/23

Apple sues NSO Group to curb the abuse of state-sponsored spyware - Apple

https://www.apple.com/newsroom/2021/11/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware/
Apple sues NSO Group to curb the abuse of state-sponsored spyware - Apple

NSO was about to sell hacking tools to France. Now the Israeli spyware company is in crisis. | MIT Technology Review

https://www.technologyreview.com/2021/11/23/1040509/france-macron-nso-in-crisis-sanctions/
NSO was about to sell hacking tools to France. Now the Israeli spyware company is in crisis. | MIT Technology Review

New Windows zero-day with public exploit lets you become an admin

https://www.bleepingcomputer.com/news/microsoft/new-windows-zero-day-with-public-exploit-lets-you-become-an-admin/
New Windows zero-day with public exploit lets you become an admin

Tweet / Twitter

https://twitter.com/HowellONeill/status/1463127600344227845
Tweet / Twitter

https://gist.githubusercontent.com/plutooo/733318dbb57166d203c10d12f6c24e06/raw/15c5b2612ab62998243ce5e7877496466cabb77f/tsec.txt

https://gist.githubusercontent.com/plutooo/733318dbb57166d203c10d12f6c24e06/raw/15c5b2612ab62998243ce5e7877496466cabb77f/tsec.txt

GoDaddy says data breach exposed over a million user accounts | TechCrunch

https://techcrunch.com/2021/11/22/godaddy-breach-million-accounts/
GoDaddy says data breach exposed over a million user accounts | TechCrunch

Exploit released for Microsoft Exchange RCE bug, patch now

https://www.bleepingcomputer.com/news/security/exploit-released-for-microsoft-exchange-rce-bug-patch-now/
Exploit released for Microsoft Exchange RCE bug, patch now

Researchers Detail Privilege Escalation Bugs Reported in Oracle VirtualBox

https://thehackernews.com/2021/11/researchers-detail-privilege-escalation.html
Researchers Detail Privilege Escalation Bugs Reported in Oracle VirtualBox

Page not found · GitHub · GitHub

https://github.com/klinix5/InstallerFileTakeOver
Page not found · GitHub · GitHub

Attackers don\'t bother brute-forcing long passwords, Microsoft engineer says

https://therecord.media/attackers-dont-bother-brute-forcing-long-passwords-microsoft-engineer-says/
Attackers don\'t bother brute-forcing long passwords, Microsoft engineer says

Apple Sues Israeli Spyware Maker NSO Group - The New York Times

https://www.nytimes.com/2021/11/23/technology/apple-nso-group-lawsuit.html
Apple Sues Israeli Spyware Maker NSO Group - The New York Times

NVISO Technology Day - YouTube

https://www.youtube.com/watch?v=nB2JnQdJWZw
NVISO Technology Day - YouTube

Feodo Tracker | Blocklist

https://feodotracker.abuse.ch/blocklist/#ip-blocklist
Feodo Tracker | Blocklist

https://bit.ly/3ChiQsE

https://bit.ly/3ChiQsE

Ex-security chief: the government must prove its encryption plans work—or abandon them - Prospect Magazine

https://www.prospectmagazine.co.uk/science-and-technology/ex-security-chief-ciaran-martin-gchq-government-encryption-plans-facebook-apple
Ex-security chief: the government must prove its encryption plans work—or abandon them - Prospect Magazine

Document

https://www.sec.gov/Archives/edgar/data/1609711/000160971121000122/gddyblogpostnov222021.htm
Document

Lead Microsoft Engineer Kevin Sheldrake Brings Sysmon to Linux | Li...

https://linuxsecurity.com/features/lead-microsoft-engineer-kevin-sheldrake-brings-sysmon-to-linux
Lead Microsoft Engineer Kevin Sheldrake Brings Sysmon to Linux | Li...

End-to-end encryption: the (fruitless?) search for a compromise | Blavatnik School of Government

https://www.bsg.ox.ac.uk/research/publications/end-end-encryption-fruitless-search-compromise
End-to-end encryption: the (fruitless?) search for a compromise | Blavatnik School of Government

GoDaddy Breached - Plaintext Passwords - 1.2M Affected

https://www.wordfence.com/blog/2021/11/godaddy-breach-plaintext-passwords/
GoDaddy Breached - Plaintext Passwords - 1.2M Affected

Cobalt Strike Community Kit

https://cobalt-strike.github.io/community_kit/
Cobalt Strike Community Kit

CVE-2021-43557: Apache APISIX: Path traversal in request_uri variable - xvnpw personal blog

https://xvnpw.github.io/posts/cve_2021_43557_apache_apisix_path_traversal_in_request_uri_variable/
CVE-2021-43557: Apache APISIX: Path traversal in request_uri variable - xvnpw personal blog