12/13

Zero-Day Exploit Targeting Popular Java Library Log4j

https://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/
Zero-Day Exploit Targeting Popular Java Library Log4j

Diavol Ransomware

https://thedfirreport.com/2021/12/13/diavol-ransomware/
Diavol Ransomware

KB5008380—Authentication updates (CVE-2021-42287) - Microsoft Support

https://support.microsoft.com/en-us/topic/kb5008380-authentication-updates-cve-2021-42287-9dafac11-e0d0-4cb8-959a-143bd0201041
KB5008380—Authentication updates (CVE-2021-42287) - Microsoft Support

Now You Serial, Now You Don’t — Systematically Hunting for Deserialization Exploits | Mandiant

https://www.mandiant.com/resources/hunting-deserialization-exploits
Now You Serial, Now You Don’t — Systematically Hunting for Deserialization Exploits | Mandiant

eXploit – CVE-2021-42287/CVE-2021-42278 Weaponisation

https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html
eXploit – CVE-2021-42287/CVE-2021-42278 Weaponisation

Tweet / Twitter

https://twitter.com/TinkerSec/status/1470411644153233409
Tweet / Twitter

Log4Shell attacks began two weeks ago, Cisco and Cloudflare say

https://therecord.media/log4shell-attacks-began-two-weeks-ago-cisco-and-cloudflare-say/
Log4Shell attacks began two weeks ago, Cisco and Cloudflare say

Will Dormann on Twitter: "@Laughing_Mantis Well that's terrifying. https://t.co/Sy3R4suwGK" / Twitter

https://twitter.com/wdormann/status/1470409556303958017?t=UOruiPMQpKtObRhf-bckNA&s=19
Will Dormann on Twitter: "@Laughing_Mantis Well that's terrifying. https://t.co/Sy3R4suwGK" / Twitter

TryHackMe | Solar, exploiting log4j

https://tryhackme.com/room/solar
TryHackMe | Solar, exploiting log4j

Apache Log4j Vulnerability — Log4Shell — Widely Under Active Attack

https://thehackernews.com/2021/12/apache-log4j-vulnerability-log4shell.html
Apache Log4j Vulnerability — Log4Shell — Widely Under Active Attack

Arrest in Romania of a ransomware affiliate scavenging for sensitive data | Europol

https://www.europol.europa.eu/media-press/newsroom/news/arrest-in-romania-of-ransomware-affiliate-scavenging-for-sensitive-data
Arrest in Romania of a ransomware affiliate scavenging for sensitive data | Europol

ThreatFox | log4j

https://threatfox.abuse.ch/browse/tag/log4j/
ThreatFox | log4j

vx-underground

https://vx-underground.org
vx-underground

Ukraine arrests 51 for selling data of 300 million people in US, EU

https://www.bleepingcomputer.com/news/security/ukraine-arrests-51-for-selling-data-of-300-million-people-in-us-eu/
Ukraine arrests 51 for selling data of 300 million people in US, EU

FBI - Tips

http://tips.fbi.gov
FBI - Tips

Capitol Violence — FBI

https://fbi.gov/wanted/capitol-violence
Capitol Violence — FBI

Releases · Neo23x0/Fenrir

https://github.com/Neo23x0/Fenrir/releases
Releases · Neo23x0/Fenrir

GitHub’s response to Log4j vulnerability CVE-2021-44228 | The GitHub Blog

https://github.blog/2021-12-13-githubs-response-to-log4j-vulnerability-cve-2021-44228/
GitHub’s response to Log4j vulnerability CVE-2021-44228 | The GitHub Blog

Log4Shell Hell: anatomy of an exploit outbreak – Sophos News

https://news.sophos.com/en-us/2021/12/12/log4shell-hell-anatomy-of-an-exploit-outbreak/
Log4Shell Hell: anatomy of an exploit outbreak – Sophos News

504 Gateway Time-out

https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/
504 Gateway Time-out

Ransomware attack shuts down computer systems for Virginia legislative agencies

https://richmond.com/news/state-and-regional/govt-and-politics/ransomware-attack-shuts-down-computer-systems-for-virginia-legislative-agencies/article_1603183b-cc58-5f2e-bad9-99693582b79c.html#tracking-source=home-top-story
Ransomware attack shuts down computer systems for Virginia legislative agencies

sAMAccountName spoofing - The Hacker Recipes

https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing
sAMAccountName spoofing - The Hacker Recipes

Ransomware affiliate arrested in Romania

https://therecord.media/ransomware-affiliate-arrested-in-romania/
Ransomware affiliate arrested in Romania

Log4j (CVE-2021-44228) RCE Vulnerability Explained - YouTube

https://www.youtube.com/watch?v=0-abhd-CLwQ
Log4j (CVE-2021-44228) RCE Vulnerability Explained - YouTube

Error - PortSwigger

https://portswigger.net/bappstore/b011be53649346dd87276bca41ce8e8f
Error - PortSwigger

Hackers start pushing malware in worldwide Log4Shell attacks

https://www.bleepingcomputer.com/news/security/hackers-start-pushing-malware-in-worldwide-log4shell-attacks/
Hackers start pushing malware in worldwide Log4Shell attacks

Collection of WAF evasion payloads · GitHub

https://gist.github.com/ZephrFish/32249cae56693c1e5484888267d07d39
Collection of WAF evasion payloads · GitHub

Triage | Behavioral Report

https://tria.ge/211213-wjq52sead2/behavioral1
Triage | Behavioral Report

The #GCHQChristmasChallenge is here! - GCHQ.GOV.UK

https://www.gchq.gov.uk/news/christmas-card-2021
The #GCHQChristmasChallenge is here! - GCHQ.GOV.UK

Microsoft Details Building Blocks of Widely Active Qakbot Banking Trojan

https://thehackernews.com/2021/12/microsoft-details-building-blocks-of.html
Microsoft Details Building Blocks of Widely Active Qakbot Banking Trojan

Webinar Not Available

https://attendee.gotowebinar.com/register/5384784947517148427
Webinar Not Available

Log4Shell: Reconnaissance and post exploitation network detection – NCC Group Research

https://research.nccgroup.com/2021/12/12/log4shell-reconnaissance-and-post-exploitation-network-detection/
Log4Shell: Reconnaissance and post exploitation network detection – NCC Group Research