12/14

404 Not Found

https://logging.apache.org/log4j/2.x/changes-report.html#a2.16.0
404 Not Found

CVE - CVE-2021-45046

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046
CVE - CVE-2021-45046

Owowa: the add-on that turns your OWA into a credential stealer and remote access panel | Securelist

https://securelist.com/owowa-credential-stealer-and-remote-access/105219/
Owowa: the add-on that turns your OWA into a credential stealer and remote access panel | Securelist

Phishing 2021 - A Year in Review - SteveD3.io

https://steved3.io/data/Phishing-2021-Year-In-Review/2021/12/14/
Phishing 2021 - A Year in Review - SteveD3.io

Restrict LDAP access via JNDI by rgoers · Pull Request #608 · apache/logging-log4j2 · GitHub

https://github.com/apache/logging-log4j2/pull/608#issuecomment-993542299
Restrict LDAP access via JNDI by rgoers · Pull Request #608 · apache/logging-log4j2 · GitHub

Cyber Santa Is Coming To Town - Hacking Party - YouTube

https://www.youtube.com/watch?v=Q-YxZaiqwBc
Cyber Santa Is Coming To Town - Hacking Party - YouTube

log4shell/software at main · NCSC-NL/log4shell · GitHub

https://github.com/NCSC-NL/log4shell/tree/main/software
log4shell/software at main · NCSC-NL/log4shell · GitHub

vx-underground

https://www.vx-underground.org/
vx-underground

Remote Deserialization Bug in Microsoft's RDP Client through Smart Card Extension (CVE-2021-38666)

https://thalium.github.io/blog/posts/deserialization-bug-through-rdp-smart-card-extension/
Remote Deserialization Bug in Microsoft's RDP Client through Smart Card Extension (CVE-2021-38666)

Chrome Releases: Stable Channel Update for Desktop

https://chromereleases.googleblog.com/2021/12/stable-channel-update-for-desktop_13.html
Chrome Releases: Stable Channel Update for Desktop

Hackers Exploit Log4j Vulnerability to Infect Computers with Khonsari Ransomware

https://thehackernews.com/2021/12/hackers-exploit-log4j-vulnerability-to.html
Hackers Exploit Log4j Vulnerability to Infect Computers with Khonsari Ransomware

eXploit – CVE-2021-42287/CVE-2021-42278 Weaponisation

https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html
eXploit – CVE-2021-42287/CVE-2021-42278 Weaponisation

KB5008380—Authentication updates (CVE-2021-42287) - Microsoft Support

https://support.microsoft.com/en-us/topic/kb5008380-authentication-updates-cve-2021-42287-9dafac11-e0d0-4cb8-959a-143bd0201041
KB5008380—Authentication updates (CVE-2021-42287) - Microsoft Support

[ANNOUNCE] Apache Log4j 2.16.0 Released-Apache Mail Archives

https://lists.apache.org/thread/d6v4r6nosxysyq9rvnr779336yf0woz4
[ANNOUNCE] Apache Log4j 2.16.0 Released-Apache Mail Archives

FBI - Tips

http://tips.fbi.gov
FBI - Tips

Elastic

http://log4shell.threatsearch.io
Elastic

BlueTeam CheatSheet * Log4Shell* | Last updated: 2021-12-20 2238 UTC · GitHub

https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592
BlueTeam CheatSheet * Log4Shell* | Last updated: 2021-12-20 2238 UTC · GitHub

Jobs at MoonPay

https://boards.greenhouse.io/moonpay/jobs/4784263003
Jobs at MoonPay

Update Google Chrome to Patch New Zero-Day Exploit Detected in the Wild

https://thehackernews.com/2021/12/update-google-chrome-to-patch-new-zero.html
Update Google Chrome to Patch New Zero-Day Exploit Detected in the Wild

Capitol Violence — FBI

https://fbi.gov/wanted/capitol-violence
Capitol Violence — FBI

Weixin Official Accounts Platform

https://mp.weixin.qq.com/s/7y-iyMMZAoN4B2dGvCFvXg
Weixin Official Accounts Platform

December 2021 Security Updates - Release Notes - Security Update Guide - Microsoft

https://msrc.microsoft.com/update-guide/releaseNote/2021-Dec
December 2021 Security Updates - Release Notes - Security Update Guide - Microsoft

Cobalt Strike 4.5: Fork&Run - You're "history" | Cobalt Strike

https://www.cobaltstrike.com/blog/cobalt-strike-4-5-fork-run-youre-history/
Cobalt Strike 4.5: Fork&Run - You're "history" | Cobalt Strike

ThreatFox | 45.146.164.160:1389

https://threatfox.abuse.ch/ioc/275541/
ThreatFox | 45.146.164.160:1389

Espionage Campaign Targets Telecoms Organizations across Middle East and Asia | Symantec Enterprise Blogs

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-campaign-telecoms-asia-middle-east
Espionage Campaign Targets Telecoms Organizations across Middle East and Asia | Symantec Enterprise Blogs

Tweet / Twitter

https://twitter.com/ncweaver/status/1470453024870912000
Tweet / Twitter

CVE - CVE-2021-44228

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44228
CVE - CVE-2021-44228

Log4j – Apache Log4j Security Vulnerabilities

https://logging.apache.org/log4j/2.x/security.html
Log4j – Apache Log4j Security Vulnerabilities

UnpacMe Results 2c568da9e5b57d99dd1934aa7dd4a463bc1d761c236ea89b171e58389ed1e2c9

https://www.unpac.me/results/380dee3a-053b-42f8-9b49-f31b5af77564
UnpacMe Results 2c568da9e5b57d99dd1934aa7dd4a463bc1d761c236ea89b171e58389ed1e2c9

Now You Serial, Now You Don’t — Systematically Hunting for Deserialization Exploits | Mandiant

https://www.mandiant.com/resources/hunting-deserialization-exploits
Now You Serial, Now You Don’t — Systematically Hunting for Deserialization Exploits | Mandiant

Log4Shell: Reconnaissance and post exploitation network detection – NCC Group Research

https://research.nccgroup.com/2021/12/12/log4shell-reconnaissance-and-post-exploitation-network-detection/
Log4Shell: Reconnaissance and post exploitation network detection – NCC Group Research

Latest Apple iOS Update Patches Remote Jailbreak Exploit for iPhones

https://thehackernews.com/2021/12/latest-apple-ios-update-patches-remote.html
Latest Apple iOS Update Patches Remote Jailbreak Exploit for iPhones

Tweet / Twitter

https://twitter.com/tinkersec/status/1470760062159360008
Tweet / Twitter

Microsoft fixes Windows AppX Installer zero-day used by Emotet

https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-appx-installer-zero-day-used-by-emotet/
Microsoft fixes Windows AppX Installer zero-day used by Emotet