12/17

Log4j – Apache Log4j Security Vulnerabilities

https://logging.apache.org/log4j/2.x/security.html
Log4j – Apache Log4j Security Vulnerabilities

Red Sense- Intelligence Operations

https://www.advintel.io/post/ransomware-advisory-log4shell-exploitation-for-initial-access-lateral-movement
Red Sense- Intelligence Operations

[LOG4J2-3230] Certain strings can cause infinite recursion - ASF JIRA

https://issues.apache.org/jira/browse/LOG4J2-3230
[LOG4J2-3230] Certain strings can cause infinite recursion - ASF JIRA

Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html
Project Zero: A deep dive into an NSO zero-click iMessage exploit: Remote Code Execution

Pegasus vs. Predator: Dissident's Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware - The Citizen Lab

https://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/
Pegasus vs. Predator: Dissident's Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware - The Citizen Lab

Release v3.1.1.0 · lgandx/Responder · GitHub

https://github.com/lgandx/Responder/releases/tag/v3.1.1.0
Release v3.1.1.0 · lgandx/Responder · GitHub

Conti ransomware uses Log4j bug to hack VMware vCenter servers

https://www.bleepingcomputer.com/news/security/conti-ransomware-uses-log4j-bug-to-hack-vmware-vcenter-servers/
Conti ransomware uses Log4j bug to hack VMware vCenter servers

Tweet / Twitter

https://twitter.com/liamosaur/status/1471626232961716225
Tweet / Twitter

TellYouThePass ransomware via Log4Shell exploitation

https://www.curatedintel.org/2021/12/tellyouthepass-ransomware-via-log4shell.html
TellYouThePass ransomware via Log4Shell exploitation

Emergency Directive 22-02 (Closed) | CISA

http://cisa.gov/emergency-directive-22-02
Emergency Directive 22-02 (Closed) | CISA

New DarkHotel APT attack chain identified | Zscaler

https://www.zscaler.com/blogs/security-research/new-darkhotel-apt-attack-chain-identified
New DarkHotel APT attack chain identified | Zscaler

Log4Shell Update: Severity Upgraded 3.7 to 9.0 for Second log4j Vulnerability (CVE-2021-45046) | LunaTrace

https://www.lunasec.io/docs/blog/log4j-zero-day-severity-of-cve-2021-45046-increased/
Log4Shell Update: Severity Upgraded 3.7 to 9.0 for Second log4j Vulnerability (CVE-2021-45046) | LunaTrace

Conti ransomware group adopts Log4Shell exploit

https://therecord.media/conti-ransomware-group-adopts-log4shell-exploit/
Conti ransomware group adopts Log4Shell exploit

[#LOG4J2-3230] Certain strings can cause infinite recursion - ASF JIRA

https://issues.apache.org/jira/plugins/servlet/mobile#issue/LOG4J2-3230
[#LOG4J2-3230] Certain strings can cause infinite recursion - ASF JIRA

Apache Log4j Vulnerability Guidance | CISA

https://www.cisa.gov/uscert/apache-log4j-vulnerability-guidance
Apache Log4j Vulnerability Guidance | CISA

Chinese Spies Accused of Using Huawei in Secret Australian Telecom Hack - Bloomberg

https://www.bloomberg.com/news/articles/2021-12-16/chinese-spies-accused-of-using-huawei-in-secret-australian-telecom-hack
Chinese Spies Accused of Using Huawei in Secret Australian Telecom Hack - Bloomberg

The Web3 Fraud | USENIX

https://www.usenix.org/publications/loginonline/web3-fraud
The Web3 Fraud | USENIX

regex101: build, test, and debug regex

http://regex101.com/r/KqGG3W/3
regex101: build, test, and debug regex

New Phorpiex Botnet Variant Steals Half a Million Dollars in Cryptocurrency

https://thehackernews.com/2021/12/new-phorpiex-botnet-variant-steals-half.html
New Phorpiex Botnet Variant Steals Half a Million Dollars in Cryptocurrency

New PseudoManuscrypt Malware Infected Over 35,000 Computers in 2021

https://thehackernews.com/2021/12/new-pseudomanuscrypt-malware-infected.html
New PseudoManuscrypt Malware Infected Over 35,000 Computers in 2021

Google Online Security Blog: Understanding the Impact of Apache Log4j Vulnerability

https://security.googleblog.com/2021/12/understanding-impact-of-apache-log4j.html
Google Online Security Blog: Understanding the Impact of Apache Log4j Vulnerability

Sleep Mask Update in Cobalt Strike 4.5 | Cobalt Strike

https://www.cobaltstrike.com/blog/sleep-mask-update-in-cobalt-strike-4-5/
Sleep Mask Update in Cobalt Strike 4.5 | Cobalt Strike

Tweet / Twitter

https://twitter.com/jaxson_davidson/status/1470933731548356614
Tweet / Twitter

Tweet / Twitter

https://twitter.com/ncweaver/status/1471668214480334851
Tweet / Twitter

Log4j Vulnerability: Attackers Shift Focus From LDAP to RMI | Official Juniper Networks Blogs

https://blogs.juniper.net/en-us/threat-research/log4j-vulnerability-attackers-shift-focus-from-ldap-to-rmi
Log4j Vulnerability: Attackers Shift Focus From LDAP to RMI | Official Juniper Networks Blogs