12/22

Apache Log4j bug: China’s industry ministry pulls support from Alibaba Cloud for not reporting flaw to government first | South China Morning Post

https://www.scmp.com/tech/big-tech/article/3160670/apache-log4j-bug-chinas-industry-ministry-pulls-support-alibaba-cloud
Apache Log4j bug: China’s industry ministry pulls support from Alibaba Cloud for not reporting flaw to government first | South China Morning Post

New Exploit Lets Malware Attackers Bypass Patch for Critical Microsoft MSHTML Flaw

https://thehackernews.com/2021/12/new-exploit-lets-malware-attackers.html
New Exploit Lets Malware Attackers Bypass Patch for Critical Microsoft MSHTML Flaw

China suspends deal with Alibaba for not sharing Log4j 0-day first with the government

https://thehackernews.com/2021/12/china-suspends-deal-with-alibaba-for.html
China suspends deal with Alibaba for not sharing Log4j 0-day first with the government

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/41e7cee6b5534a0e8633be51f8a3bb37d439f0ccd8893ed67dcbe6be7dda2e48/
MalwareBazaar | Browse Checking your browser

NimExamples/src/SysWhispers2 at main · ajpc500/NimExamples · GitHub

https://github.com/ajpc500/NimExamples/tree/main/src/SysWhispers2
NimExamples/src/SysWhispers2 at main · ajpc500/NimExamples · GitHub

US Army Creates Single Vaccine Against All COVID & SARS Variants, Researchers Say - Defense One

https://www.defenseone.com/technology/2021/12/us-army-creates-single-vaccine-effective-against-all-covid-sars-variants/360089/
US Army Creates Single Vaccine Against All COVID & SARS Variants, Researchers Say - Defense One

Active Directory Bugs Could Let hackers Take Over Windows Domain Controllers

https://thehackernews.com/2021/12/active-directory-bugs-could-let-hackers.html
Active Directory Bugs Could Let hackers Take Over Windows Domain Controllers

Mitigating Log4Shell and Other Log4j-Related Vulnerabilities | CISA

http://www.cisa.gov/uscert/ncas/alerts/aa21-356a
Mitigating Log4Shell and Other Log4j-Related Vulnerabilities | CISA

Tweet / Twitter

https://twitter.com/campuscodi/status/1473642105633488899
Tweet / Twitter

Laurent Gaffié blog: Responder and IPv6 attacks

https://g-laurent.blogspot.com/2021/12/responder-and-ipv6-attacks.html
Laurent Gaffié blog: Responder and IPv6 attacks

Your Full Map To Github Recon And Leaks Exposure | by Orwa Atyat | Medium

https://orwaatyat.medium.com/your-full-map-to-github-recon-and-leaks-exposure-860c37ca2c82
Your Full Map To Github Recon And Leaks Exposure | by Orwa Atyat | Medium

Tweet / Twitter

https://twitter.com/CioaraJeremy/status/1473647240384159748
Tweet / Twitter

MS Teams: 1 feature, 4 vulnerabilities | Positive Security

https://positive.security/blog/ms-teams-1-feature-4-vulns
MS Teams: 1 feature, 4 vulnerabilities | Positive Security

Canva

https://jobs.lever.co/canva?lever-via=hSaqlu7P0P
Canva

Hunting for samAccountName Spoofing (CVE-2021–42278) & Domain Controller Impersonation (CVE-2021–42287) | by Mauricio Velazco | Medium

https://medium.com/@mvelazco/hunting-for-samaccountname-spoofing-cve-2021-42287-and-domain-controller-impersonation-f704513c8a45
Hunting for samAccountName Spoofing (CVE-2021–42278) & Domain Controller Impersonation (CVE-2021–42287) | by Mauricio Velazco | Medium

BLISTER malware campaign discovered | Elastic

https://www.elastic.co/blog/elastic-security-uncovers-blister-malware-campaign
BLISTER malware campaign discovered | Elastic

Joint_CSA_Mitigating_Log4Shell_Other_Log4j_Vulnerabilities_20211222_FINAL.PDF

https://media.defense.gov/2021/Dec/22/2002913813/-1/-1/0/Joint_CSA_Mitigating_Log4Shell_Other_Log4j_Vulnerabilities_20211222_FINAL.PDF
Joint_CSA_Mitigating_Log4Shell_Other_Log4j_Vulnerabilities_20211222_FINAL.PDF

GitHub - FuzzySecurity/Sharp-Suite: Also known by Microsoft as Knifecoat

https://github.com/FuzzySecurity/Sharp-Suite#pickmansmodel
GitHub - FuzzySecurity/Sharp-Suite: Also known by Microsoft as Knifecoat

ThreatFox | Browse IOCs

https://threatfox.abuse.ch/ioc/277944/
ThreatFox | Browse IOCs