01/26

GitHub - Crusaders-of-Rust/CVE-2022-0185: CVE-2022-0185

https://github.com/Crusaders-of-Rust/CVE-2022-0185
GitHub - Crusaders-of-Rust/CVE-2022-0185: CVE-2022-0185

German govt warns of APT27 hackers backdooring business networks

https://www.bleepingcomputer.com/news/security/german-govt-warns-of-apt27-hackers-backdooring-business-networks/
German govt warns of APT27 hackers backdooring business networks

Human Rights Watch Among Pegasus Spyware Targets | Human Rights Watch

https://www.hrw.org/news/2022/01/26/human-rights-watch-among-pegasus-spyware-targets
Human Rights Watch Among Pegasus Spyware Targets | Human Rights Watch

Prime Minister’s Office Compromised: Details of Recent Espionage Campaign

https://www.trellix.com/en-gb/about/newsroom/stories/threat-labs/prime-ministers-office-compromised.html
Prime Minister’s Office Compromised: Details of Recent Espionage Campaign

CERT-UA

https://cert.gov.ua/article/18101
CERT-UA

PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec (CVE-2021-4034) | Qualys Security Blog

https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034
PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec (CVE-2021-4034) | Qualys Security Blog

New DeadBolt ransomware targets QNAP devices, asks 50 BTC for master key

https://www.bleepingcomputer.com/news/security/new-deadbolt-ransomware-targets-qnap-devices-asks-50-btc-for-master-key/
New DeadBolt ransomware targets QNAP devices, asks 50 BTC for master key

Jobs at GitHub

https://boards.greenhouse.io/github/jobs/3836182
Jobs at GitHub

VirusTotal - Sign in

https://www.virustotal.com/gui/collection/c40e02a6598ead021ab0013f825159a2caa8f1047ec228bfbf7f68a8ec6318b8
VirusTotal - Sign in

ID.me CEO backtracks on claims company doesn't use powerful facial recognition tech | CyberScoop

https://www.cyberscoop.com/id-me-ceo-backtracks-on-claims-company-doesnt-use-powerful-facial-recognition-tech/
ID.me CEO backtracks on claims company doesn't use powerful facial recognition tech | CyberScoop

Evolved phishing: Device registration trick adds to phishers’ toolbox for victims without MFA - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/01/26/evolved-phishing-device-registration-trick-adds-to-phishers-toolbox-for-victims-without-mfa/
Evolved phishing: Device registration trick adds to phishers’ toolbox for victims without MFA - Microsoft Security Blog

Watering hole deploys new macOS malware, DazzleSpy, in Asia | WeLiveSecurity

https://www.welivesecurity.com/2022/01/25/watering-hole-deploys-new-macos-malware-dazzlespy-asia/
Watering hole deploys new macOS malware, DazzleSpy, in Asia | WeLiveSecurity

A bug lurking for 12 years gives attackers root on most major Linux distros | Ars Technica

https://arstechnica.com/information-technology/2022/01/a-bug-lurking-for-12-years-gives-attackers-root-on-every-major-linux-distro/
A bug lurking for 12 years gives attackers root on most major Linux distros | Ars Technica

CRYPTOCVES

https://cryptocves.com/
CRYPTOCVES

Bypassing Little Snitch Firewall with Empty TCP Packets - Rhino Security Labs

https://rhinosecuritylabs.com/network-security/bypassing-little-snitch-firewall/
Bypassing Little Snitch Firewall with Empty TCP Packets - Rhino Security Labs

Doctor-style register planned for UK infosec professionals • The Register

https://www.theregister.com/2022/01/25/ukgov_cybersecurity_profession_regulation_ukcsc/
Doctor-style register planned for UK infosec professionals • The Register

Tweet / Twitter

https://twitter.com/campuscodi/status/1486132147354226690
Tweet / Twitter

A first look into how WinDbg works - YouTube

https://www.youtube.com/watch?v=QStC084UrgY
A first look into how WinDbg works - YouTube

Triage | Static Report

https://tria.ge/220126-k7ksdsbef9/static1
Triage | Static Report

GitHub - berdav/CVE-2021-4034: CVE-2021-4034 1day

https://github.com/berdav/CVE-2021-4034
GitHub - berdav/CVE-2021-4034: CVE-2021-4034 1day

Accidentally Graphing DLL Hijacks in Every Electron App :: [audible]blink

https://ctrl.red/posts/2022/01/accidentally-graphing-dll-hijacks-in-every-electron-app/
Accidentally Graphing DLL Hijacks in Every Electron App :: [audible]blink

Prime Minister’s Office Compromised: Details of Recent Espionage Campaign

https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/prime-ministers-office-compromised.html
Prime Minister’s Office Compromised: Details of Recent Espionage Campaign

Job details | Microsoft Careers

https://careers.microsoft.com/us/en/job/1245076/Senior-Threat-Analyst
Job details | Microsoft Careers

CyberSlide - The Cyber Startup Observatory

https://cyberstartupobservatory.com/resources-cyberslide/
CyberSlide - The Cyber Startup Observatory

Ukrainian government calls out false flag operation in recent data wiping attack - The Record from Recorded Future News

https://therecord.media/ukrainian-government-calls-out-false-flag-operation-in-recent-data-wiping-attack/
Ukrainian government calls out false flag operation in recent data wiping attack - The Record from Recorded Future News

Webcam Hacking (again) - Safari UXSS | Ryan Pickren

https://www.ryanpickren.com/safari-uxss
Webcam Hacking (again) - Safari UXSS | Ryan Pickren

https://haxx.in/files/blasty-vs-pkexec.c

https://haxx.in/files/blasty-vs-pkexec.c

argv silliness | ~ryiron

https://ryiron.wordpress.com/2013/12/16/argv-silliness/
argv silliness | ~ryiron

Initial Access Broker Involved in Log4Shell Attacks Against VMware Horizon Servers

https://thehackernews.com/2022/01/initial-access-broker-involved-in.html
Initial Access Broker Involved in Log4Shell Attacks Against VMware Horizon Servers

Jobs at GitHub

https://boards.greenhouse.io/github/jobs/3836183
Jobs at GitHub

Last Week in Security (LWiS) - 2022-01-25 | Bad Sector Labs Blog

https://blog.badsectorlabs.com/last-week-in-security-lwis-2022-01-25.html
Last Week in Security (LWiS) - 2022-01-25 | Bad Sector Labs Blog

White House clamps down on federal cybersecurity after big hacks | CNN Politics

https://www.cnn.com/2022/01/26/politics/white-house-cybersecurity-strategy/index.html
White House clamps down on federal cybersecurity after big hacks | CNN Politics

Pastebin.com - Not Found (#404)

https://pastebin.com/NLw2z0pK
Pastebin.com - Not Found (#404)

220126.pdf

https://www.ic3.gov/Media/News/2022/220126.pdf
220126.pdf

Wiper in Ukraine Used Code Repurposed From WhiteBlackCrypt Ransomware

https://zetter.substack.com/p/wiper-in-ukraine-used-code-repurposed
Wiper in Ukraine Used Code Repurposed From WhiteBlackCrypt Ransomware