North Korea Hacked Him. So He Took Down Its Internet | WIRED
https://www.wired.com/story/north-korea-hacker-internet-outage/
How to start RE/malware analysis? | hasherezade's 1001 nights
https://hshrzd.wordpress.com/how-to-start/
Zero Day Initiative — CVE-2021-44142: Details on a Samba Code Execution Bug Demonstrated at Pwn2Own Austin
https://www.zerodayinitiative.com/blog/2022/2/1/cve-2021-44142-details-on-a-samba-code-execution-bug-demonstrated-at-pwn2own-austin
Site not found · GitHub Pages
https://elastic.github.io/security-research/whitepapers/2022/02/02.sandboxing-antimalware-products-for-fun-and-profit/article/
Critical Bug Found in WordPress Plugin for Elementor with Over a Million Installations
https://thehackernews.com/2022/02/critical-bug-found-in-wordpress-plugin.html
GitHub - mrd0x/EvilSelenium: EvilSelenium is a tool that weaponizes Selenium to attack Chromium based browsers.
https://github.com/mrd0x/EvilSelenium
Crypto.com: Ex-Hacker Who Worked for Controversial Spying Firm Won’t Join Company
https://www.vice.com/en/article/7kbezd/cryptocom-hires-ex-hacker-who-worked-for-company-that-spied-on-americans
Moodle: Blind SQL Injection (CVE-2021-36393) and Broken Access Control (CVE-2021-36397) - 0xkasper
https://0xkasper.com/articles/moodle-sql-injection-broken-access-control.html
MalwareBazaar | Browse Checking your browser
https://bazaar.abuse.ch/sample/3926e9fca7f160eb12b7fd9e4bd8ac9200d15c6103330fe4adb4dc85940e3593/
writeups/Hacking-Google-Drive-Integrations.md at main · httpvoid/writeups · GitHub
https://github.com/httpvoid/writeups/blob/main/Hacking-Google-Drive-Integrations.md
Malicious CSV text files used to install BazarBackdoor malware
https://www.bleepingcomputer.com/news/security/malicious-csv-text-files-used-to-install-bazarbackdoor-malware/
Password spraying and MFA bypasses in the modern security landscape | Sprocket Security
https://www.sprocketsecurity.com/blog/how-to-bypass-mfa-all-day#
UEFI firmware vulnerabilities affect at least 25 computer vendors
https://www.bleepingcomputer.com/news/security/uefi-firmware-vulnerabilities-affect-at-least-25-computer-vendors/
Mandiant Senior Principal Reverse Engineer | SmartRecruiters
https://jobs.smartrecruiters.com/Mandiant/743999802041669
Mars Stealer: Oski refactoring | 3xp0rt
https://3xp0rt.com/posts/mars-stealer
Dozens of Security Flaws Discovered in UEFI Firmware Used by Several Vendors
https://thehackernews.com/2022/02/dozens-of-security-flaws-discovered-in.html
Understanding Process Ghosting in Detail - Blog by Dosxuz
https://dosxuz.gitlab.io/post/processghosting/
MSDT DLL Hijack UAC bypass - Sevagas
https://blog.sevagas.com/?MSDT-DLL-Hijack-UAC-bypass
Notepad++ Plugins for Persistence - Offensive Defence
https://offensivedefence.co.uk/posts/notepad++/
JSAC2022_2_kobayashi_en.pdf
https://jsac.jpcert.or.jp/archive/2022/pdf/JSAC2022_2_kobayashi_en.pdf
New Malware Used by SolarWinds Attackers Went Undetected for Years
https://thehackernews.com/2022/02/new-malware-used-by-solarwinds.html
Max_Malyutin on Twitter: "#IcedID (#Bokbot) 🤖Excel > Regsvr32 MalDoc dropped DLLs x64: mse1.ocx 4343F6DE906B7993E1B923A0F472A06C mse2.ocx c624931fdb8a7c0d3daaa08cd12bd855 mse3.ocx 85314a61b806e07c69937bfe2e97da81 Path: C:\Rimta\mse[123].ocx Regsvr32 connection: 185.99.132[.]51 > hdtrenity[.]com https://t.co/Oo0V86ZeTq" / Twitter
https://twitter.com/Max_Mal_/status/1488643501545906184
Inside Trickbot, Russia’s Notorious Ransomware Gang | WIRED
https://www.wired.com/story/trickbot-malware-group-internal-messages/
BazarLoader/BazarLoader_02.02.2022.txt at main · pr0xylife/BazarLoader · GitHub
https://github.com/pr0xylife/BazarLoader/blob/main/BazarLoader_02.02.2022.txt
Cross-Site Scripting (XSS) Cheat Sheet - 2023 Edition | Web Security Academy
https://portswigger.net/web-security/cross-site-scripting/cheat-sheet#data-url-with-use-element-and-base64-encoded
A detailed analysis of Lazarus APT malware disguised as Notepad++ Shell Extension – CYBER GEEKS
https://cybergeeks.tech/a-detailed-analysis-of-lazarus-malware-disguised-as-notepad-shell-extension/
KP Snacks giant hit by Conti ransomware, deliveries disrupted
https://www.bleepingcomputer.com/news/security/kp-snacks-giant-hit-by-conti-ransomware-deliveries-disrupted/
Philippe Lagadec on Twitter: "@Tork_88 @jabreity @thegrugq @BushidoToken When a CSV file is opened in Excel, cells starting with = and other symbols are interpreted as formulas, and they can be used to launch commands via DDE. More info: https://t.co/NvWNxafXr1" / Twitter
https://twitter.com/decalage2/status/1488481984242462728