03/16

Browser In The Browser (BITB) Attack | mr.d0x

https://mrd0x.com/browser-in-the-browser-phishing-attack/
Browser In The Browser (BITB) Attack | mr.d0x

Have Your Cake and Eat it Too? An Overview of UNC2891 | Mandiant

https://www.mandiant.com/resources/unc2891-overview
Have Your Cake and Eat it Too? An Overview of UNC2891 | Mandiant

Facebook Hit With $18.6 Million GDPR Fine Over 12 Data Breaches in 2018

https://thehackernews.com/2022/03/facebook-hit-with-186-million-gdpr-fine.html
Facebook Hit With $18.6 Million GDPR Fine Over 12 Data Breaches in 2018

Five Individuals Charged Variously with Stalking, Harassing and Spying on U.S. Residents on Behalf of the PRC Secret Police | OPA | Department of Justice

https://www.justice.gov/opa/pr/five-individuals-charged-variously-stalking-harassing-and-spying-us-residents-behalf-prc-0
Five Individuals Charged Variously with Stalking, Harassing and Spying on U.S. Residents on Behalf of the PRC Secret Police | OPA | Department of Justice

New Linux botnet exploits Log4J, uses DNS tunneling for comms

https://www.bleepingcomputer.com/news/security/new-linux-botnet-exploits-log4j-uses-dns-tunneling-for-comms/
New Linux botnet exploits Log4J, uses DNS tunneling for comms

Top 10 CICD Security Risks - Cider Security Site

https://www.cidersecurity.io/top-10-cicd-security-risks/
Top 10 CICD Security Risks - Cider Security Site

The Discovery and Exploitation of CVE-2022-25636 · Nick Gregory

https://nickgregory.me/linux/security/2022/03/12/cve-2022-25636/
The Discovery and Exploitation of CVE-2022-25636 · Nick Gregory

| Job Preference

http://www.jobpreference.com
| Job Preference

Multiple Flaws Uncovered in ClickHouse OLAP Database System for Big Data

https://thehackernews.com/2022/03/multiple-flaws-uncovered-in-clickhouse.html
Multiple Flaws Uncovered in ClickHouse OLAP Database System for Big Data

URLhaus | Browse

https://urlhaus.abuse.ch/browse.php?search=www[.]arkpp[.]com
URLhaus | Browse

Microsoft Defender tags Office updates as ransomware activity

https://www.bleepingcomputer.com/news/security/microsoft-defender-tags-office-updates-as-ransomware-activity/
Microsoft Defender tags Office updates as ransomware activity

CVE-2022-22616 - YouTube

https://www.youtube.com/watch?v=S5moPnXnvaE
CVE-2022-22616 - YouTube

From XSS to RCE (dompdf 0day) | Positive Security

https://positive.security/blog/dompdf-rce
From XSS to RCE (dompdf 0day) | Positive Security

Tweet / Twitter

https://twitter.com/leonard_effort/status/1504056654010142730
Tweet / Twitter

New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems

https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware
New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems

Offensive_tools/PostDump at main · post-cyberlabs/Offensive_tools · GitHub

https://github.com/post-cyberlabs/Offensive_tools/tree/main/PostDump
Offensive_tools/PostDump at main · post-cyberlabs/Offensive_tools · GitHub

Unpatched RCE Bug in dompdf Project Affects HTML to PDF Converters

https://thehackernews.com/2022/03/unpatched-rce-bug-in-dompdf-project.html
Unpatched RCE Bug in dompdf Project Affects HTML to PDF Converters

FBI, CISA Warn of Russian Hackers Exploiting MFA and PrintNightmare Bug

https://thehackernews.com/2022/03/fbi-cisa-warn-of-russian-hackers.html
FBI, CISA Warn of Russian Hackers Exploiting MFA and PrintNightmare Bug

Technical Advisory – Apple macOS XAR – Arbitrary File Write (CVE-2022-22582) – NCC Group Research

https://research.nccgroup.com/2022/03/15/technical-advisory-apple-macos-xar-arbitrary-file-write-cve-2022-22582/
Technical Advisory – Apple macOS XAR – Arbitrary File Write (CVE-2022-22582) – NCC Group Research