SpoolFool: Windows Print Spooler Privilege Escalation (CVE-2022-21999) | by Oliver Lyak | Feb, 2022 | IFCR
https://research.ifcr.dk/spoolfool-windows-print-spooler-privilege-escalation-cve-2022-22718-bf7752b68d81
Ransomware dev releases Egregor, Maze master decryption keys
https://www.bleepingcomputer.com/news/security/ransomware-dev-releases-egregor-maze-master-decryption-keys/
Attack surface reduction rules reference | Microsoft Learn
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#:~:text=The%20default%20state,end%20user%20notifications
Top 10 web hacking techniques of 2021 | PortSwigger Research
https://portswigger.net/research/top-10-web-hacking-techniques-of-2021
Maze / Sekhmet / Egregor decryptor - Emsisoft: Free Ransomware Decryption Tools
https://www.emsisoft.com/ransomware-decryption-tools/maze-sekhmet-egregor
GitHub - fox-it/BloodHound.py: A Python based ingestor for BloodHound
https://github.com/fox-it/BloodHound.py
Radio station snafu in Seattle bricks some Mazda infotainment systems | Ars Technica
https://arstechnica.com/cars/2022/02/radio-station-snafu-in-seattle-bricks-some-mazda-infotainment-systems/
CISA, FBI, NSA and International Partners Issue Advisory on Ransomware Trends from 2021 > National Security Agency/Central Security Service > Article
https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/2928709/cisa-fbi-nsa-and-international-partners-issue-advisory-on-ransomware-trends-fro/
The Limited Edition BloodHound Shirt Custom Ink Fundraising
https://www.customink.com/fundraising/bloodhound-22
Ugg Boots 4 Sale: A Tale of Palestinian-Aligned Espionage | Proofpoint US
https://www.proofpoint.com/us/blog/threat-insight/ugg-boots-4-sale-tale-palestinian-aligned-espionage
CISA and SAP warn about major vulnerability - The Record from Recorded Future News
https://therecord.media/cisa-and-sap-warn-about-major-vulnerability/
GitHub - ly4k/SpoolFool: Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)
https://github.com/ly4k/SpoolFool
InfoSec Handlers Diary Blog - SANS Internet Storm Center
https://i5c.us/d28318
Shadow Chaser Group on Twitter: "Today our researchers have found sample which belongs to #SideCopy #APT group ITW:fc7343af5945ed5021a57cf235a7ae0c filename:Army-Cyber-Gp-Alt-Feb-2022. zip ITW:1e437d8cb03950655d38a310928de43c filename: Army-Cyber-Gp-Alt-Feb-2022.pdf.lnk https://t.co/ftWqP0MABD" / Twitter
https://twitter.com/ShadowChasing1/status/1490988027354648576
Two Arrested for Alleged Conspiracy to Launder $4.5 Billion in Stolen Cryptocurrency | OPA | Department of Justice
https://www.justice.gov/opa/pr/two-arrested-alleged-conspiracy-launder-45-billion-stolen-cryptocurrency
jack wagner on Twitter: "idk much about crypto security but this person shouldn’t have been able to steal 4.5 billion dollars of it https://t.co/i86nu7naKK" / Twitter
https://twitter.com/jackdwagner/status/1491140930090717184
x86matthew - StackScraper - Capturing sensitive data using real-time stack scanning against a remote process
https://www.x86matthew.com/view_post?id=stack_scraper
vx-underground on Twitter: "Heather Morgan, an individual alleged of laundering $4,500,000,000 in Bitcoin cryptocurrency, frequently uploaded videos of herself onto TikTok under the username "realrazzlekhan". She raps, "following rules is for fools, instead I work the edge case with my tools" https://t.co/bHbsf9QPGf" / Twitter
https://twitter.com/vxunderground/status/1491232763508568066
NaturalFreshMall: a Vulnerable Magento Extension and a Mass Hack – Sansec
https://sansec.io/research/naturalfreshmall-mass-hack
CVE-2022-21703: cross-origin request forgery against Grafana :: jub0bs.com
https://jub0bs.com/posts/2022-02-08-cve-2022-21703-writeup/
Site not found · GitHub Pages
https://elastic.github.io/security-research/whitepapers/2022/02/03.exploring-windows-uac-bypass-techniques-detection-strategies/article/
NCSC joins US and Australian partners to reveal latest... - NCSC.GOV.UK
https://www.ncsc.gov.uk/news/ncsc-joins-us-and-australian-partners-to-reveal-latest-ransomware-trends
CyberSlide - The Cyber Startup Observatory
https://cyberstartupobservatory.com/resources-cyberslide/
404 - File Not Found | CISA
http://go.usa.gov/xt79T
Microsoft and Other Major Software Firms Release February 2022 Patch Updates
https://thehackernews.com/2022/02/microsoft-and-other-major-software.html
eset_threat_report_t32021.pdf
https://www.welivesecurity.com/wp-content/uploads/2022/02/eset_threat_report_t32021.pdf
CISA warns admins to patch maximum severity SAP vulnerability
https://www.bleepingcomputer.com/news/security/cisa-warns-admins-to-patch-maximum-severity-sap-vulnerability/
Accidental CISO on Twitter: "Am I reading that second bullet point in the "Culture Fit" section correctly? I'm going to give @cybraryIT a big old "yikes" on that one. https://t.co/z9C9Mhgaog https://t.co/eJxNRDjbyv" / Twitter
https://twitter.com/AccidentalCISO/status/1491226702403739648
Distribution of Kimsuky Group's xRAT (Quasar RAT) Confirmed - ASEC BLOG
https://asec.ahnlab.com/en/31089/
Russian APT Hackers Used COVID-19 Lures to Target European Diplomats
https://thehackernews.com/2022/02/russian-apt-hackers-used-covid-19-lures.html
IcedID/icedID_09.02.2022.txt at main · pr0xylife/IcedID · GitHub
https://github.com/pr0xylife/IcedID/blob/main/icedID_09.02.2022.txt
V. Anand | வெ. ஆனந்த் on Twitter: "@thegrugq How to get caught? Delegate (your private keys to cloud storage) https://t.co/SPPZ6Ern6M" / Twitter
https://twitter.com/iam_anandv/status/1491256609846476800
Simple, Secure Identity Verification | ID.me
http://ID.me
The Cyber Startup Observatory - The Global Cyber Innovation Network
https://cyberstartupobservatory.com
Microsoft (MSFT) Considering Possible Deal For Mandiant (MNDT) - Bloomberg
https://www.bloomberg.com/news/articles/2022-02-08/microsoft-is-said-to-pursue-deal-for-cybersecurity-firm-mandiant
NSA Cyber on Twitter: "Ransomware incidents targeting critical infrastructure were on the rise in 2021. Protect against the threat using the joint cybersecurity guidance from @FBI, @CISAGov, @CyberGovAu, and @NCSC to help reduce the risk of compromise. Read more here: https://t.co/WUDLBiifhH https://t.co/ZSS9sPkHB8" / Twitter
https://twitter.com/NSACyber/status/1491417360556826634