12/01

Project Zero: This shouldn't have happened: A vulnerability postmortem

https://googleprojectzero.blogspot.com/2021/12/this-shouldnt-have-happened.html
Project Zero: This shouldn't have happened: A vulnerability postmortem

Careers

https://target.wd5.myworkdayjobs.com/targetcareers/job/7000-Target-Pkwy-NNCD-0375-Brooklyn-ParkMN-55445/Cybersecurity-Analyst--CSIRT_R0000179554
Careers

Memory corruption in NSS via DER-encoded DSA and RSA-PSS signatures — Mozilla

https://www.mozilla.org/en-US/security/advisories/mfsa2021-51/
Memory corruption in NSS via DER-encoded DSA and RSA-PSS signatures — Mozilla

Jumping the air gap: 15 years of nation‑state effort | WeLiveSecurity

https://www.welivesecurity.com/2021/12/01/jumping-air-gap-15-years-nation-state-effort/
Jumping the air gap: 15 years of nation‑state effort | WeLiveSecurity

Microsoft Defender scares admins with Emotet false positives

https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-scares-admins-with-emotet-false-positives/
Microsoft Defender scares admins with Emotet false positives

Injection is the New Black: Novel RTF Template Inject Technique Poised for Widespread Adoption Beyond APT Actors  | Proofpoint US

https://www.proofpoint.com/us/blog/threat-insight/injection-new-black-novel-rtf-template-inject-technique-poised-widespread
Injection is the New Black: Novel RTF Template Inject Technique Poised for Widespread Adoption Beyond APT Actors  | Proofpoint US

Hackers Increasingly Using RTF Template Injection Technique in Phishing Attacks

https://thehackernews.com/2021/12/hackers-increasingly-using-rtf-template.html
Hackers Increasingly Using RTF Template Injection Technique in Phishing Attacks

Tracking a P2P network related to TA505 | NCC Group Research Blog | Making the world safer and more secure

https://research.nccgroup.com/2021/12/01/tracking-a-p2p-network-related-with-ta505/
Tracking a P2P network related to TA505 | NCC Group Research Blog | Making the world safer and more secure

APT groups from China, Russia, and India adopt novel attack technique

https://therecord.media/apt-groups-from-china-russia-and-india-adopt-novel-attack-technique/
APT groups from China, Russia, and India adopt novel attack technique

Tweet / Twitter

https://twitter.com/GossiTheDog/status/1465976334539231233
Tweet / Twitter

Smishing Botnets Going Viral in Iran - Check Point Research404 Not FoundBack ButtonSearch IconFilter Icon

https://research.checkpoint.com/2021/smishing-botnets-going-viral-in-iran/
Smishing Botnets Going Viral in Iran - Check Point Research404 Not FoundBack ButtonSearch IconFilter Icon

Tetrane - Automated Reverse Engineering Platform

https://url.tetrane.com/ZAc8Q/ac0e
Tetrane - Automated Reverse Engineering Platform

ProxyShell exploitation leads to BlackByte ransomware - Red Canary

https://redcanary.com/blog/blackbyte-ransomware/
ProxyShell exploitation leads to BlackByte ransomware - Red Canary

URLhaus | Checking your browser

https://urlhaus.abuse.ch/url/1838032/
URLhaus | Checking your browser

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/d25a928416c3614b40c4c57447023f53fa5cc4d4bd5dee5fc68a7e8cbc52d7cb/
MalwareBazaar | Browse Checking your browser

InfoSec Jupyterthon 2021 - Day 1 - YouTube

https://aka.ms/Jupyterthon2021Live1
InfoSec Jupyterthon 2021 - Day 1 - YouTube

https://bit.ly/3ChiQsE

https://bit.ly/3ChiQsE

Welcome! | VK

http://VK.com
Welcome! | VK

Lateral Movement with Managed Identities of Azure Virtual Machines | Microsoft 365 Security

https://m365internals.com/2021/11/30/lateral-movement-with-managed-identities-of-azure-virtual-machines/
Lateral Movement with Managed Identities of Azure Virtual Machines | Microsoft 365 Security

InfoSec Jupyterthon 2021 - Day 2 - YouTube

https://aka.ms/Jupyterthon2021Live2
InfoSec Jupyterthon 2021 - Day 2 - YouTube

FBI document shows what data can be obtained from encrypted messaging apps

https://therecord.media/fbi-document-shows-what-data-can-be-obtained-from-encrypted-messaging-apps/
FBI document shows what data can be obtained from encrypted messaging apps