一般社団法人日本ハッカー協会 on Twitter: "2022年1月20日、最高裁判所において、Coinhive事件は逆転無罪判決となりました。これまでの皆様のご支援に深く感謝申し上げます。" / Twitter
https://twitter.com/japanhackera/status/1484054406694060040
MoonBounce: the dark side of UEFI firmware | Securelist
https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
vx-underground - Directory
https://samples.vx-underground.org/samples/Families/
Treasury Sanctions Russian-Backed Actors Responsible for Destabilization Activities in Ukraine | U.S. Department of the Treasury
https://home.treasury.gov/news/press-releases/jy0562
Windows Drivers Reverse Engineering Methodology - VoidSec
https://voidsec.com/windows-drivers-reverse-engineering-methodology/
Simple, Secure Identity Verification | ID.me
http://ID.me
The Cyber Startup Observatory - The Global Cyber Innovation Network
https://cyberstartupobservatory.com
VirusTotal - File - 694fb9d8ffeddf9988e6ae8946a50ee195ebb3021b0d0b0370f5246a497c4353
https://www.virustotal.com/gui/file/694fb9d8ffeddf9988e6ae8946a50ee195ebb3021b0d0b0370f5246a497c4353/community
Hackers Attempt to Exploit New SolarWinds Serv-U Bug in Log4Shell Attacks
https://thehackernews.com/2022/01/microsoft-hackers-exploiting-new.html
Zloader Installs Remote Access Backdoors and Delivers Cobalt Strike – Sophos News
https://news.sophos.com/en-us/2022/01/19/zloader-installs-remote-access-backdoors-and-delivers-cobalt-strike/
Google Details Two Zero-Day Bugs Reported in Zoom Clients and MMR Servers
https://thehackernews.com/2022/01/google-details-two-zero-day-bugs.html
Belarusian Government Officials Charged with Aircraft Piracy for Diverting Ryanair Flight 4978 to Arrest Dissident Journalist in May 2021 | OPA | Department of Justice
https://www.justice.gov/opa/pr/belarusian-government-officials-charged-aircraft-piracy-diverting-ryanair-flight-4978-arrest
Memorandum on Improving the Cybersecurity of National Security, Department of Defense, and Intelligence Community Systems - The White House
https://www.whitehouse.gov/briefing-room/presidential-actions/2022/01/19/memorandum-on-improving-the-cybersecurity-of-national-security-department-of-defense-and-intelligence-community-systems/
ryaagard on Twitter: "https://t.co/ffiFyHrakE :) https://t.co/Qvaw9dbus1" / Twitter
https://twitter.com/ryaagard/status/1483592308352294917
One Source to Rule Them All: Chasing AVADDON Ransomware | Mandiant
https://www.mandiant.com/resources/chasing-avaddon-ransomware
WMI for Script Kiddies - TrustedSec
https://hubs.la/Q012zm7n0
Mark Lechtik on Twitter: "[1/n] Today I'm sharing the details of a research done by @vaber_b, @legezo, Ilya Borisov and myself on a UEFI firmware implant found in the wild, dubbed #MoonBounce. We assess that this formerly unknown threat is the work of the infamous #APT41. A 🧵 https://t.co/YSa2R2RGJh" / Twitter
https://twitter.com/_marklech_/status/1484114943108603904
People Can’t See Some NFTs on Twitter, Crypto Wallets After OpenSea Goes Down
https://www.vice.com/en/article/g5qjej/people-cant-see-some-nfts-in-crypto-wallets-after-opensea-goes-down
oss-sec: Linux kernel: Heap buffer overflow in fs_context.c since version 5.1
https://seclists.org/oss-sec/2022/q1/54
blackorbird on Twitter: "#Oceanlotus .mht & .mhtml C2:glitch https://t.co/UYrEUxOWQJ https://t.co/NWi9E0cziL https://t.co/BRQWgsdfIB" / Twitter
https://twitter.com/blackorbird/status/1481527529475559427
The Real "F-Word": Understanding the Source of False Positives from EDR Systems & How to Ease the Pain | SANS Institute
https://www.sans.org/webcasts/the-real-f-word-understanding-the-source-of-false-positives-from-edr-systems-how-to-ease-the-pain/
SecurityZines
http://securityzines.com
GitHub - nyxgeek/onedrive_user_enum: onedrive user enumeration - pentest tool to enumerate valid o365 users
https://github.com/nyxgeek/onedrive_user_enum
Cisco bug gives remote attackers root privileges via debug mode
https://www.bleepingcomputer.com/news/security/cisco-bug-gives-remote-attackers-root-privileges-via-debug-mode/
Supply-Chain Risk Management: Doing More for Less - Infosecurity Magazine
https://www.infosecurity-magazine.com/webinars/supply-chain-risk-management/
EU wants to build its own DNS infrastructure with built-in filtering capabilities - The Record from Recorded Future News
https://therecord.media/eu-wants-to-build-its-own-dns-infrastructure-with-built-in-filtering-capabilities/
FBI links Diavol ransomware to the TrickBot cybercrime group
https://www.bleepingcomputer.com/news/security/fbi-links-diavol-ransomware-to-the-trickbot-cybercrime-group/
Pirates Spammed an Infamous Soviet Short-wave Radio Station with Memes
https://www.vice.com/en/article/y3vbjj/pirates-spammed-an-infamous-soviet-short-wave-radio-station-with-memes-uvb-76
GitHub - vletoux/pingcastle: PingCastle - Get Active Directory Security at 80% in 20% of the time
https://github.com/vletoux/pingcastle
Sean Lyngaas on Twitter: "New: @TalosSecurity says the attacker responsible for the data-wiping malware found on Ukrainian gov networks had access 2 those networks as far back as late summer. "The wiper malware was deployed several months after initial access was secured, depending on the network."-@kpyke" / Twitter
https://twitter.com/snlyngaas/status/1484275411597111303
Site not found · GitHub Pages
https://elastic.github.io/security-research/malware/2022/01/01.operation-bleeding-bear/article/
New BHUNT Password Stealer Malware Targeting Cryptocurrency Wallets
https://thehackernews.com/2022/01/new-bhunt-password-stealer-malware.html
Chris Wysopal on Twitter: "FireEye and McAfee brands are being retired. They will now be Trellix. Trellix plans to be the leader in XDR. "The company name is a reference to a garden trellis that supports plants as they grow—hence the notion of 'living' security." https://t.co/oKuLvXAAFf" / Twitter
https://twitter.com/WeldPond/status/1483805772928753666
test.mysmartlogon.com PingCastle 2023-02-20
https://pingcastle.com/PingCastleFiles/ad_hc_test.mysmartlogon.com.html