02/14

How Roblox ‘Beamers’ Get Rich Stealing from Children

https://www.vice.com/en/article/88gd4a/roblox-beaming-hackers
How Roblox ‘Beamers’ Get Rich Stealing from Children

Dropping Files on a Domain Controller Using CVE-2021-43893 | Rapid7 Blog

https://www.rapid7.com/blog/post/2022/02/14/dropping-files-on-a-domain-controller-using-cve-2021-43893/
Dropping Files on a Domain Controller Using CVE-2021-43893 | Rapid7 Blog

Eliminating Dangling Elastic IP Takeovers with Ghostbuster – Assetnote

https://blog.assetnote.io/2022/02/13/dangling-eips/
Eliminating Dangling Elastic IP Takeovers with Ghostbuster – Assetnote

Critical Magento 0-Day Vulnerability Under Active Exploitation — Patch Released

https://thehackernews.com/2022/02/critical-magento-0-day-vulnerability.html
Critical Magento 0-Day Vulnerability Under Active Exploitation — Patch Released

Jobs at SpecterOps

https://boards.greenhouse.io/specterops
Jobs at SpecterOps

WebKit RCE on ios 14.1 · GitHub

https://gist.github.com/ujin5/6b9a32eedc5a39d714a3a72f06efffe5
WebKit RCE on ios 14.1 · GitHub

PSBits/OfflineSAM at master · gtworek/PSBits · GitHub

https://github.com/gtworek/PSBits/tree/master/OfflineSAM
PSBits/OfflineSAM at master · gtworek/PSBits · GitHub

Just a moment...

https://www.bleepingcomputer.com/news/security/fbi-blackbyte-ransomware-breached-us-critical-infrastructure/
Just a moment...

Subscribers | hackers-arise

http://www.hackers-arise.com/hackers-arise-subscribers
Subscribers | hackers-arise

Invoke-HandleKatzInject.ps1 · GitHub

https://gist.github.com/S3cur3Th1sSh1t/9f328fc411ff103c0800294c523503e2
Invoke-HandleKatzInject.ps1 · GitHub

CyberSlide - The Cyber Startup Observatory

https://cyberstartupobservatory.com/resources-cyberslide/
CyberSlide - The Cyber Startup Observatory

Adversary Tactics: Tradecraft Analysis – SpecterOps

https://specterops.io/how-we-help/training-offerings/adversary-tactics-tradecraft-analysis
Adversary Tactics: Tradecraft Analysis – SpecterOps

Wazawaka Goes Waka Waka – Krebs on Security

https://krebsonsecurity.com/2022/02/wazawaka-goes-waka-waka/
Wazawaka Goes Waka Waka – Krebs on Security

UAC Bypass by Mocking Trusted Directories | by David Wells | Tenable TechBlog | Medium

https://medium.com/tenable-techblog/uac-bypass-by-mocking-trusted-directories-24a96675f6e
UAC Bypass by Mocking Trusted Directories | by David Wells | Tenable TechBlog | Medium

Ushi on Twitter: "Women being harassed is not “infosec drama.”" / Twitter

https://twitter.com/ush1c/status/1492538960777814019
Ushi on Twitter: "Women being harassed is not “infosec drama.”" / Twitter

Apache: Code execution in log4j2 · Advisory · google/security-research · GitHub

https://github.com/google/security-research/security/advisories/GHSA-ggmf-hg75-88gg
Apache: Code execution in log4j2 · Advisory · google/security-research · GitHub