12/08

Windows 10 RCE: The exploit is in the link | Positive Security

https://positive.security/blog/ms-officecmd-rce
Windows 10 RCE: The exploit is in the link | Positive Security

The hidden side of Seclogon part 2: Abusing leaked handles to dump LSASS memory

https://splintercod3.blogspot.com/p/the-hidden-side-of-seclogon-part-2.html
The hidden side of Seclogon part 2: Abusing leaked handles to dump LSASS memory

When old friends meet again: why Emotet chose Trickbot for rebirth - Check Point Research404 Not FoundBack ButtonSearch IconFilter Icon

https://research.checkpoint.com/2021/when-old-friends-meet-again-why-emotet-chose-trickbot-for-rebirth/
When old friends meet again: why Emotet chose Trickbot for rebirth - Check Point Research404 Not FoundBack ButtonSearch IconFilter Icon

Process Ghosting | Pentest Laboratories

https://pentestlaboratories.com/2021/12/08/process-ghosting/
Process Ghosting | Pentest Laboratories

GitHub - wavestone-cdt/EDRSandblast

https://github.com/wavestone-cdt/EdrSandblast
GitHub - wavestone-cdt/EDRSandblast

Dave Brown on Twitter: "... https://t.co/HSW2MkSr5n" / Twitter

https://twitter.com/dave_brown24/status/1468396443442552838
Dave Brown on Twitter: "... https://t.co/HSW2MkSr5n" / Twitter

Classe de vulnérabilités en environnement Active Directory – CERT-FR

https://www.cert.ssi.gouv.fr/dur/CERTFR-2021-DUR-001/
Classe de vulnérabilités en environnement Active Directory – CERT-FR

Google Disrupts Blockchain-based Glupteba Botnet; Sues Russian Hackers

https://thehackernews.com/2021/12/google-disrupts-blockchain-based.html
Google Disrupts Blockchain-based Glupteba Botnet; Sues Russian Hackers

Peeling away the layers of obfuscation from Excel VBA to dll | PC's Xcetra Support

https://pcsxcetrasupport3.wordpress.com/2021/12/07/peeling-away-the-layers-of-obfuscation-from-excel-vba-to-dll/
Peeling away the layers of obfuscation from Excel VBA to dll | PC's Xcetra Support

PSBits/IFilter at master · gtworek/PSBits · GitHub

https://github.com/gtworek/PSBits/tree/master/IFilter
PSBits/IFilter at master · gtworek/PSBits · GitHub

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/3f13e9bc8011c8bc8f3d7cb9a616ed6da1b6f16d9fcaa65d29d81caf2d5574d3/
MalwareBazaar | Browse Checking your browser

Emotet now drops Cobalt Strike, fast forwards ransomware attacks

https://www.bleepingcomputer.com/news/security/emotet-now-drops-cobalt-strike-fast-forwards-ransomware-attacks/
Emotet now drops Cobalt Strike, fast forwards ransomware attacks

Zero-Point Security

https://www.zeropointsecurity.co.uk/red-team-ops/purchase
Zero-Point Security

Warning: Yet Another Bitcoin Mining Malware Targeting QNAP NAS Devices

https://thehackernews.com/2021/12/warning-yet-another-bitcoin-mining.html
Warning: Yet Another Bitcoin Mining Malware Targeting QNAP NAS Devices

FIN13: A Cybercriminal Threat Actor Focused on Mexico | Mandiant

https://www.mandiant.com/resources/fin13-cybercriminal-mexico
FIN13: A Cybercriminal Threat Actor Focused on Mexico | Mandiant

Chinese State-Sponsored Cyber Espionage Activity Supports Expansion of Regional Power and Influence in Southeast Asia

https://www.recordedfuture.com/chinese-state-sponsored-cyber-espionage-expansion-power-influence-southeast-asia/
Chinese State-Sponsored Cyber Espionage Activity Supports Expansion of Regional Power and Influence in Southeast Asia

Hacking the US Government - Legally - GovInfoSecurity

https://www.govinfosecurity.com/hacking-us-government-legally-a-18076
Hacking the US Government - Legally - GovInfoSecurity

Grafana releases security patch after exploit for severe bug goes public

https://therecord.media/grafana-releases-security-patch-after-exploit-for-severe-bug-goes-public/
Grafana releases security patch after exploit for severe bug goes public

Ringzer0 - WORKSHOPS

https://ringzer0.training/workshops.html
Ringzer0 - WORKSHOPS

Moobot botnet spreading via Hikvision camera vulnerability

https://www.bleepingcomputer.com/news/security/moobot-botnet-spreading-via-hikvision-camera-vulnerability/
Moobot botnet spreading via Hikvision camera vulnerability

Resources for Retired Events Links | 6Connex Event Tech

https://securityweek.6connex.com/event/SecuritySummit/en-us#!/Auditorium/n1350713
Resources for Retired Events Links | 6Connex Event Tech

This Small Tech Company SpiffyTech May Actually Be a Ransomware Front Group

https://www.thedailybeast.com/this-small-tech-company-spiffytech-may-actually-be-a-ransomware-front-group
This Small Tech Company SpiffyTech May Actually Be a Ransomware Front Group