Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html
Ian Beer on Twitter: "Today we're publishing a detailed technical writeup of FORCEDENTRY, the zero-click iMessage exploit linked by Citizen Lab to the exploitation of journalists, activists and dissidents around the world. https://t.co/RYsqpTHF5j" / Twitter
https://twitter.com/i41nbeer/status/1471163195679252484
GitHub - cisagov/log4j-affected-db: A community sourced list of log4j-affected software
https://github.com/cisagov/log4j-affected-db
Tweet / Twitter
https://twitter.com/TinkerSec/status/1471128734010945542
log4j memes
https://log4jmemes.com/
Microsoft Security Intelligence on Twitter: "As we continue to monitor threats taking advantage of the CVE-2021-44228 Log4j 2 vulnerability, we’re seeing activity ranging from experimentation to exploitation from multiple groups, including nation-state actors and access brokers linked to ransomware: https://t.co/WWSxGvaiDy" / Twitter
https://twitter.com/MsftSecIntel/status/1470960102232444940
Log4Shell Update: Second log4j Vulnerability Published (CVE-2021-44228 + CVE-2021-45046) | LunaTrace
https://www.lunasec.io/docs/blog/log4j-zero-day-update-on-cve-2021-45046/
Cyber House Party - Festive Special 2021 - LIVE - YouTube
https://youtu.be/CEq7QV4sY3Q
Process Injection Update in Cobalt Strike 4.5 | Cobalt Strike
https://www.cobaltstrike.com/blog/process-injection-update-in-cobalt-strike-4-5/
Weixin Official Accounts Platform
https://mp.weixin.qq.com/s/7y-iyMMZAoN4B2dGvCFvXg
Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability - Microsoft Security Blog
https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/
Log4j – Apache Log4j Security Vulnerabilities
https://logging.apache.org/log4j/2.x/security.html
Dan Kaminsky - Internet Hall of Fame
https://www.internethalloffame.org/inductees/dan-kaminsky
Speakers | OffensiveCon
https://www.offensivecon.org/speakers/
New Blueprint to protect UK from Cyber Threats - GOV.UK
https://www.gov.uk/government/news/new-blueprint-to-protect-uk-from-cyber-threats
U.S. lawmakers call for sanctions against Israel's NSO, other spyware firms | Reuters
https://www.reuters.com/world/us/exclusive-us-lawmakers-call-sanctions-against-israels-nso-other-spyware-firms-2021-12-15/
Owowa: the add-on that turns your OWA into a credential stealer and remote access panel | Securelist
https://securelist.com/owowa-credential-stealer-and-remote-access/105219/
NEW MILLENIUM CONSULTING
http://nmcus.com
Quantum computing will lead to new risks for cyber security | World Economic Forum
https://www.weforum.org/global_future_councils/gfc-on-quantum-computing/articles/in-a-quantum-future-our-economy-needs-to-be-protected-a-cybersecurity-expert-explains-why
Azure Run Command for Dummies | Mandiant
https://www.mandiant.com/resources/azure-run-command-dummies
Nation State Threat Group Targets Airline with Aclip Backdoor
https://securityintelligence.com/posts/nation-state-threat-group-targets-airline-aclip-backdoor/
Guide: How To Detect and Mitigate the Log4Shell Vulnerability (CVE-2021-44228 & CVE-2021-45046) | LunaTrace
https://www.lunasec.io/docs/blog/log4j-zero-day-mitigation-guide/
Log4Shell attacks expand to nation-state groups from China, Iran, North Korea, and Turkey
https://therecord.media/log4shell-attacks-expand-to-nation-state-groups-from-china-iran-north-korea-and-turkey/
Huawei documents show Chinese tech giant’s involvement in surveillance programs - The Washington Post
https://www.washingtonpost.com/world/2021/12/14/huawei-surveillance-china/
Second Log4j Vulnerability (CVE-2021-45046) Discovered — New Patch Released
https://thehackernews.com/2021/12/second-log4j-vulnerability-cve-2021.html
Defeat the Castle – Bypass AV & Advanced XDR solutions. -
https://0xsp.com/security%20research%20&%20development%20(SRD)/defeat-the-castle-bypass-av-advanced-xdr-solutions
offensivecon on Twitter: "Real World 0-days: A Year-in-Review of 0-day Exploits Used In-the-Wild in 2021 by @maddiestone https://t.co/5tra7VhbZa" / Twitter
https://twitter.com/offensive_con/status/1471081609822715906
CyberSlide - The Cyber Startup Observatory
https://cyberstartupobservatory.com/resources-cyberslide/
Project Zero Bugs on Twitter: "A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution https://t.co/MUk90ClE80" / Twitter
https://twitter.com/ProjectZeroBugs/status/1471164401424080915
The Cyber Startup Observatory - The Global Cyber Innovation Network
https://cyberstartupobservatory.com
Malware-Traffic-Analysis.net - 2021-12-03 (Friday) - Contact Forms campaign BazarLoader with Cobalt Strike
https://www.malware-traffic-analysis.net/2021/12/03/index.html
MalwareBazaar | Browse Checking your browser
https://bazaar.abuse.ch/sample/82444084da0460b71a625154ca0bc815d7920137bbdb3463ee174b8efb234637/
MalwareBazaar | Browse Checking your browser
https://bazaar.abuse.ch/sample/f604ca55de802f334064610d65e23890ab81906cdac3f8a5c7c25126176289c8/
GitHub - specterops/at-ps: Adversary Tactics - PowerShell Training
https://github.com/specterops/at-ps
DarkWatchman: A new evolution in fileless techniques. - Prevailion
https://www.prevailion.com/darkwatchman-new-fileness-techniques/
PrivChat #6 - Privacy is a human right - YouTube
https://www.youtube.com/watch?v=ttQiA_GfI6s
GitHub - 0xInfection/LogMePwn: A fully automated, reliable, super-fast, mass scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.
https://github.com/0xInfection/LogMePwn
Shadowserver Special Reports – Vulnerable Log4j Servers | The Shadowserver Foundation
https://www.shadowserver.org/news/shadowserver-special-reports-vulnerable-log4j-servers/
Microsoft Issues Windows Update to Patch 0-Day Used to Spread Emotet Malware
https://thehackernews.com/2021/12/microsoft-issues-windows-update-to.html
Facebook to Pay Hackers for Reporting Data Scraping Bugs and Scraped Datasets
https://thehackernews.com/2021/12/facebook-to-pay-hackers-for-reporting.html
🇬🇧 APT31 Intrusion set campaign: description, countermeasures and code – CERT-FR
https://www.cert.ssi.gouv.fr/cti/CERTFR-2021-CTI-013/
New ransomware now being deployed in Log4Shell attacks
https://www.bleepingcomputer.com/news/security/new-ransomware-now-being-deployed-in-log4shell-attacks/