12/29

Turning bad SSRF to good SSRF: Websphere Portal (CVE-2021-27748) – Assetnote

https://blog.assetnote.io/2021/12/26/chained-ssrf-websphere/
Turning bad SSRF to good SSRF: Websphere Portal (CVE-2021-27748) – Assetnote

Fintech firm hit by Log4j hack refuses to pay $5 million ransom

https://www.bleepingcomputer.com/news/security/fintech-firm-hit-by-log4j-hack-refuses-to-pay-5-million-ransom/
Fintech firm hit by Log4j hack refuses to pay $5 million ransom

LastPass users warned their master passwords are compromised

https://www.bleepingcomputer.com/news/security/lastpass-users-warned-their-master-passwords-are-compromised/
LastPass users warned their master passwords are compromised

JavaScript Engines Exploitation: a Jscript9 Case Study – Zero Day Engineering Research

https://zerodayengineering.com/research/javascript-engines-exploitation-jscript9.html
JavaScript Engines Exploitation: a Jscript9 Case Study – Zero Day Engineering Research

Iranian hackers behind Cox Media Group ransomware attack

https://therecord.media/iranian-hackers-behind-cox-media-group-ransomware-attack/
Iranian hackers behind Cox Media Group ransomware attack

Releases · hasherezade/mal_unpack_drv · GitHub

https://github.com/hasherezade/mal_unpack_drv/releases
Releases · hasherezade/mal_unpack_drv · GitHub

Implant.ARM.iLOBleed.a | Padvish Threats Database

https://threats.amnpardaz.com/en/2021/12/28/implant-arm-ilobleed-a/
Implant.ARM.iLOBleed.a | Padvish Threats Database

Download a Windows virtual machine - Windows app development | Microsoft Developer

https://developer.microsoft.com/en-us/windows/downloads/virtual-machines/
Download a Windows virtual machine - Windows app development | Microsoft Developer

Releases · hasherezade/mal_unpack

https://github.com/hasherezade/mal_unpack/releases
Releases · hasherezade/mal_unpack

New Apache Log4j Update Released to Patch Newly Discovered Vulnerability

https://thehackernews.com/2021/12/new-apache-log4j-update-released-to.html
New Apache Log4j Update Released to Patch Newly Discovered Vulnerability

en.pdf

https://news.amnpardaz.com/wp-content/uploads/sites/5/2021/12/en.pdf
en.pdf

CVE-2021-44832 - Apache Log4j 2.17.0 Arbitrary Code Execution via JDBCAppender DataSource Element | Checkmarx.com

https://checkmarx.com/blog/cve-2021-44832-apache-log4j-2-17-0-arbitrary-code-execution-via-jdbcappender-datasource-element/
CVE-2021-44832 - Apache Log4j 2.17.0 Arbitrary Code Execution via JDBCAppender DataSource Element | Checkmarx.com

Advisory: Websphere Portal SSRFs & Post Auth RCE - CVE-2021-27748 – Assetnote

https://blog.assetnote.io/2021/12/25/advisory-websphere-portal/
Advisory: Websphere Portal SSRFs & Post Auth RCE - CVE-2021-27748 – Assetnote

Exploits/Chains/Hydseven at main · forrest-orr/Exploits · GitHub

https://github.com/forrest-orr/Exploits/tree/main/Chains/Hydseven
Exploits/Chains/Hydseven at main · forrest-orr/Exploits · GitHub

Log4j – Apache Log4j Security Vulnerabilities

https://logging.apache.org/log4j/2.x/security.html
Log4j – Apache Log4j Security Vulnerabilities

Threat actor uses HP iLO rootkit to wipe servers

https://therecord.media/threat-actor-uses-hp-ilo-rootkit-to-wipe-servers/
Threat actor uses HP iLO rootkit to wipe servers

Another Log4j on the fire: Unifi | Sprocket Security

https://www.sprocketsecurity.com/blog/another-log4j-on-the-fire-unifi
Another Log4j on the fire: Unifi | Sprocket Security

Introduction · Reverse Engineering

https://0xinfection.github.io/reversing/
Introduction · Reverse Engineering

presentations/State of C2 Matrix - 2021 - GRIMMCon0x6.pdf at main · jorgeorchilles/presentations · GitHub

https://github.com/jorgeorchilles/presentations/blob/main/2021-GRIMMCon0x6/State%20of%20C2%20Matrix%20-%202021%20-%20GRIMMCon0x6.pdf
presentations/State of C2 Matrix - 2021 - GRIMMCon0x6.pdf at main · jorgeorchilles/presentations · GitHub

Tweet / Twitter

https://twitter.com/campuscodi/status/1476016845593493507
Tweet / Twitter