01/21

Parag Agrawal Shakes Up Twitter's Security Team - The New York Times

https://www.nytimes.com/2022/01/21/technology/twitter-security-team.html
Parag Agrawal Shakes Up Twitter's Security Team - The New York Times

Windows Drivers Reverse Engineering Methodology - VoidSec

https://voidsec.com/windows-drivers-reverse-engineering-methodology/
Windows Drivers Reverse Engineering Methodology - VoidSec

MoonBounce: the dark side of UEFI firmware | Securelist

https://securelist.com/moonbounce-the-dark-side-of-uefi-firmware/105468/
MoonBounce: the dark side of UEFI firmware | Securelist

Anticipating Cyber Threats as the Ukraine Crisis Escalates | Mandiant

https://www.mandiant.com/resources/ukraine-crisis-cyber-threats
Anticipating Cyber Threats as the Ukraine Crisis Escalates | Mandiant

End-to-end encryption protects children, says UK information watchdog | Chat and messaging apps | The Guardian

https://www.theguardian.com/technology/2022/jan/21/end-to-end-encryption-protects-children-says-uk-information-watchdog
End-to-end encryption protects children, says UK information watchdog | Chat and messaging apps | The Guardian

PSBits/AppLockerBypass at master · gtworek/PSBits · GitHub

https://github.com/gtworek/PSBits/tree/master/AppLockerBypass
PSBits/AppLockerBypass at master · gtworek/PSBits · GitHub

Hackers Were in Ukraine Systems Months Before Deploying Wiper

https://zetter.substack.com/p/hackers-were-in-ukraine-systems-months
Hackers Were in Ukraine Systems Months Before Deploying Wiper

Return of Pseudo Ransomware

https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/return-of-pseudo-ransomware.html
Return of Pseudo Ransomware

McAfee Agent bug lets hackers run code with Windows SYSTEM privileges

https://www.bleepingcomputer.com/news/security/mcafee-agent-bug-lets-hackers-run-code-with-windows-system-privileges/
McAfee Agent bug lets hackers run code with Windows SYSTEM privileges

Merck wins cyber-insurance lawsuit related to NotPetya attack - The Record from Recorded Future News

https://therecord.media/merck-wins-cyber-insurance-lawsuit-related-to-notpetya-attack/
Merck wins cyber-insurance lawsuit related to NotPetya attack - The Record from Recorded Future News

Tweet / Twitter

https://twitter.com/kateconger/status/1484413889408225280
Tweet / Twitter

Over 90 WordPress themes, plugins backdoored in supply chain attack

https://www.bleepingcomputer.com/news/security/over-90-wordpress-themes-plugins-backdoored-in-supply-chain-attack/
Over 90 WordPress themes, plugins backdoored in supply chain attack

Microsoft disables Excel 4.0 macros by default to block malware

https://www.bleepingcomputer.com/news/microsoft/microsoft-disables-excel-40-macros-by-default-to-block-malware/
Microsoft disables Excel 4.0 macros by default to block malware

A deeper UEFI dive into MoonBounce

https://www.binarly.io/posts/A_deeper_UEFI_dive_into_MoonBounce/index.html
A deeper UEFI dive into MoonBounce

404 Page not found | STAR Labs

https://starlabs.sg/blog/2022/01/the-cat-escaped-from-the-chrome-sandbox/
404 Page not found | STAR Labs

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/7efc216f28686df549f764bc60f19eb50e86540cbedc4bac5e03df650579fa40/
MalwareBazaar | Browse Checking your browser

VirusTotal - File - 1eede29007619d207842ddcaadf41b17b47a456004df43189d1f6cf54a3b785b

https://www.virustotal.com/gui/file/1eede29007619d207842ddcaadf41b17b47a456004df43189d1f6cf54a3b785b
VirusTotal - File - 1eede29007619d207842ddcaadf41b17b47a456004df43189d1f6cf54a3b785b

Read the never-issued Trump order that would have seized voting machines - POLITICO

https://www.politico.com/news/2022/01/21/read-the-never-issued-trump-order-that-would-have-seized-voting-machines-527572
Read the never-issued Trump order that would have seized voting machines - POLITICO

Cisco Issues Patch for Critical RCE Vulnerability in RCM for StarOS Software

https://thehackernews.com/2022/01/cisco-issues-patch-for-critical-rce.html
Cisco Issues Patch for Critical RCE Vulnerability in RCM for StarOS Software

Feodo Tracker | BazarLoader C&C: 144.217.50.242

https://feodotracker.abuse.ch/browse/host/144.217.50.242/
Feodo Tracker | BazarLoader C&C: 144.217.50.242

VMware vCenter Server Unauthenticated Log4Shell JNDI Injection Remote Code Execution ≈ Packet Storm

https://packetstormsecurity.com/files/165642/VMware-vCenter-Server-Unauthenticated-Log4Shell-JNDI-Injection-Remote-Code-Execution.html
VMware vCenter Server Unauthenticated Log4Shell JNDI Injection Remote Code Execution ≈ Packet Storm