12/06

US military's hacking unit publicly acknowledges taking offensive action to disrupt ransomware operations | CNN Politics

https://www.cnn.com/2021/12/05/politics/us-cyber-command-disrupt-ransomware-operations/index.html
US military's hacking unit publicly acknowledges taking offensive action to disrupt ransomware operations | CNN Politics

GitHub - hasherezade/mal_unpack_drv: MalUnpack companion driver

https://github.com/hasherezade/mal_unpack_drv
GitHub - hasherezade/mal_unpack_drv: MalUnpack companion driver

NICKEL targeting government organizations across Latin America and Europe - Microsoft Security Blog

https://www.microsoft.com/security/blog/2021/12/06/nickel-targeting-government-organizations-across-latin-america-and-europe/
NICKEL targeting government organizations across Latin America and Europe - Microsoft Security Blog

uBlock, I exfiltrate: exploiting ad blockers with CSS | PortSwigger Research

https://portswigger.net/research/ublock-i-exfiltrate-exploiting-ad-blockers-with-css
uBlock, I exfiltrate: exploiting ad blockers with CSS | PortSwigger Research

SSRF vulnerability in AppSheet - Google VRP

https://nechudav.blogspot.com/2021/12/ssrf-vulnerability-in-appsheet-google.html
SSRF vulnerability in AppSheet - Google VRP

Project Zero: Windows Exploitation Tricks: Relaying DCOM Authentication

https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html
Project Zero: Windows Exploitation Tricks: Relaying DCOM Authentication

Red Sense- Intelligence Operations

https://www.advintel.io/post/corporate-loader-emotet-history-of-x-project-return-for-ransomware
Red Sense- Intelligence Operations

Services - The DFIR Report

http://thedfirreport.com/services
Services - The DFIR Report

Swiss tech company boss accused of selling mobile network access for spying — The Bureau of Investigative Journalism (en-GB)

https://www.thebureauinvestigates.com/stories/2021-12-06/swiss-tech-company-boss-accused-of-selling-mobile-network-access-for-spying
Swiss tech company boss accused of selling mobile network access for spying — The Bureau of Investigative Journalism (en-GB)

This Swiss Firm Exec Is Said To Have Operated A Secret Surveillance Operation - Bloomberg

https://www.bloomberg.com/news/articles/2021-12-06/this-swiss-tech-exec-is-said-to-have-operated-a-secret-surveillance-operation
This Swiss Firm Exec Is Said To Have Operated A Secret Surveillance Operation - Bloomberg

14 New XS-Leaks (Cross-Site Leaks) Attacks Affect All Modern Web Browsers

https://thehackernews.com/2021/12/14-new-xs-leaks-cross-site-leaks.html
14 New XS-Leaks (Cross-Site Leaks) Attacks Affect All Modern Web Browsers

2241 - runc/libcontainer: insecure handling of bind mount sources - project-zero

https://bugs.chromium.org/p/project-zero/issues/detail?id=2241
2241 - runc/libcontainer: insecure handling of bind mount sources - project-zero

PSBits/LookForLsassDumpInJournal.c at master · gtworek/PSBits · GitHub

https://github.com/gtworek/PSBits/blob/master/Misc/LookForLsassDumpInJournal.c
PSBits/LookForLsassDumpInJournal.c at master · gtworek/PSBits · GitHub

SPAR: Supermarket chain confirms ransomware attack has forced stores to close | Science & Tech News | Sky News

https://news.sky.com/story/supermarket-spar-forced-to-close-stores-due-to-cyber-attack-12488466
SPAR: Supermarket chain confirms ransomware attack has forced stores to close | Science & Tech News | Sky News

John Hultquist🌻 on Twitter: "https://t.co/SrzMigyW5Y" / Twitter

https://twitter.com/JohnHultquist/status/1467873277695692806
John Hultquist🌻 on Twitter: "https://t.co/SrzMigyW5Y" / Twitter

Warning: Yet Another Zoho ManageEngine Product Found Under Active Attacks

https://thehackernews.com/2021/12/warning-yet-another-zoho-manageengine.html
Warning: Yet Another Zoho ManageEngine Product Found Under Active Attacks

Malicious Excel XLL add-ins push RedLine password-stealing malware

https://www.bleepingcomputer.com/news/security/malicious-excel-xll-add-ins-push-redline-password-stealing-malware/
Malicious Excel XLL add-ins push RedLine password-stealing malware

Tweet / Twitter

https://twitter.com/jess_asli/status/1467626327297642501
Tweet / Twitter

bugbounty/403-bypass at main · aufzayed/bugbounty · GitHub

https://github.com/aufzayed/bugbounty/tree/main/403-bypass
bugbounty/403-bypass at main · aufzayed/bugbounty · GitHub

Hackers Steal $200 Million Worth of Cryptocurrency Tokens from BitMart Exchange

https://thehackernews.com/2021/12/hackers-steal-200-million-worth-of.html
Hackers Steal $200 Million Worth of Cryptocurrency Tokens from BitMart Exchange

Zoho warns of new zero-day vulnerability exploited in attacks

https://therecord.media/zoho-warns-of-new-zero-day-vulnerability-exploited-in-attacks/
Zoho warns of new zero-day vulnerability exploited in attacks