12/15

Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html
Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

Tweet / Twitter

https://twitter.com/TinkerSec/status/1471128734010945542
Tweet / Twitter

log4j memes

https://log4jmemes.com/
log4j memes

Log4Shell Update: Second log4j Vulnerability Published (CVE-2021-44228 + CVE-2021-45046) | LunaTrace

https://www.lunasec.io/docs/blog/log4j-zero-day-update-on-cve-2021-45046/
Log4Shell Update: Second log4j Vulnerability Published (CVE-2021-44228 + CVE-2021-45046) | LunaTrace

Process Injection Update in Cobalt Strike 4.5 | Cobalt Strike

https://www.cobaltstrike.com/blog/process-injection-update-in-cobalt-strike-4-5/
Process Injection Update in Cobalt Strike 4.5 | Cobalt Strike

Weixin Official Accounts Platform

https://mp.weixin.qq.com/s/7y-iyMMZAoN4B2dGvCFvXg
Weixin Official Accounts Platform

Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability - Microsoft Security Blog

https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/
Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability - Microsoft Security Blog

Log4j – Apache Log4j Security Vulnerabilities

https://logging.apache.org/log4j/2.x/security.html
Log4j – Apache Log4j Security Vulnerabilities

Dan Kaminsky - Internet Hall of Fame

https://www.internethalloffame.org/inductees/dan-kaminsky
Dan Kaminsky - Internet Hall of Fame

Speakers | OffensiveCon

https://www.offensivecon.org/speakers/
Speakers | OffensiveCon

New Blueprint to protect UK from Cyber Threats - GOV.UK

https://www.gov.uk/government/news/new-blueprint-to-protect-uk-from-cyber-threats
New Blueprint to protect UK from Cyber Threats - GOV.UK

U.S. lawmakers call for sanctions against Israel's NSO, other spyware firms | Reuters

https://www.reuters.com/world/us/exclusive-us-lawmakers-call-sanctions-against-israels-nso-other-spyware-firms-2021-12-15/
U.S. lawmakers call for sanctions against Israel's NSO, other spyware firms | Reuters

Owowa: the add-on that turns your OWA into a credential stealer and remote access panel | Securelist

https://securelist.com/owowa-credential-stealer-and-remote-access/105219/
Owowa: the add-on that turns your OWA into a credential stealer and remote access panel | Securelist

Quantum computing will lead to new risks for cyber security | World Economic Forum

https://www.weforum.org/global_future_councils/gfc-on-quantum-computing/articles/in-a-quantum-future-our-economy-needs-to-be-protected-a-cybersecurity-expert-explains-why
Quantum computing will lead to new risks for cyber security | World Economic Forum

Azure Run Command for Dummies | Mandiant

https://www.mandiant.com/resources/azure-run-command-dummies
Azure Run Command for Dummies | Mandiant

Nation State Threat Group Targets Airline with Aclip Backdoor

https://securityintelligence.com/posts/nation-state-threat-group-targets-airline-aclip-backdoor/
Nation State Threat Group Targets Airline with Aclip Backdoor

Log4Shell attacks expand to nation-state groups from China, Iran, North Korea, and Turkey

https://therecord.media/log4shell-attacks-expand-to-nation-state-groups-from-china-iran-north-korea-and-turkey/
Log4Shell attacks expand to nation-state groups from China, Iran, North Korea, and Turkey

Huawei documents show Chinese tech giant’s involvement in surveillance programs - The Washington Post

https://www.washingtonpost.com/world/2021/12/14/huawei-surveillance-china/
Huawei documents show Chinese tech giant’s involvement in surveillance programs - The Washington Post

Second Log4j Vulnerability (CVE-2021-45046) Discovered — New Patch Released

https://thehackernews.com/2021/12/second-log4j-vulnerability-cve-2021.html
Second Log4j Vulnerability (CVE-2021-45046) Discovered — New Patch Released

Defeat the Castle – Bypass AV & Advanced XDR solutions. -

https://0xsp.com/security%20research%20&%20development%20(SRD)/defeat-the-castle-bypass-av-advanced-xdr-solutions
Defeat the Castle – Bypass AV & Advanced XDR solutions. -

CyberSlide - The Cyber Startup Observatory

https://cyberstartupobservatory.com/resources-cyberslide/
CyberSlide - The Cyber Startup Observatory

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/82444084da0460b71a625154ca0bc815d7920137bbdb3463ee174b8efb234637/
MalwareBazaar | Browse Checking your browser

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/f604ca55de802f334064610d65e23890ab81906cdac3f8a5c7c25126176289c8/
MalwareBazaar | Browse Checking your browser

DarkWatchman: A new evolution in fileless techniques. - Prevailion

https://www.prevailion.com/darkwatchman-new-fileness-techniques/
DarkWatchman: A new evolution in fileless techniques. - Prevailion

PrivChat #6 - Privacy is a human right - YouTube

https://www.youtube.com/watch?v=ttQiA_GfI6s
PrivChat #6 - Privacy is a human right - YouTube

Shadowserver Special Reports – Vulnerable Log4j Servers | The Shadowserver Foundation

https://www.shadowserver.org/news/shadowserver-special-reports-vulnerable-log4j-servers/
Shadowserver Special Reports – Vulnerable Log4j Servers | The Shadowserver Foundation

Microsoft Issues Windows Update to Patch 0-Day Used to Spread Emotet Malware

https://thehackernews.com/2021/12/microsoft-issues-windows-update-to.html
Microsoft Issues Windows Update to Patch 0-Day Used to Spread Emotet Malware

Facebook to Pay Hackers for Reporting Data Scraping Bugs and Scraped Datasets

https://thehackernews.com/2021/12/facebook-to-pay-hackers-for-reporting.html
Facebook to Pay Hackers for Reporting Data Scraping Bugs and Scraped Datasets

New ransomware now being deployed in Log4Shell attacks

https://www.bleepingcomputer.com/news/security/new-ransomware-now-being-deployed-in-log4shell-attacks/
New ransomware now being deployed in Log4Shell attacks