03/17

Embedding standards and pathways across the cyber profession by 2025 - GOV.UK

https://www.gov.uk/government/consultations/embedding-standards-and-pathways-across-the-cyber-profession-by-2025/embedding-standards-and-pathways-across-the-cyber-profession-by-2025
Embedding standards and pathways across the cyber profession by 2025 - GOV.UK

BIG sabotage: Famous npm package deletes files to protest Ukraine war

https://www.bleepingcomputer.com/news/security/big-sabotage-famous-npm-package-deletes-files-to-protest-ukraine-war/
BIG sabotage: Famous npm package deletes files to protest Ukraine war

From XSS to RCE (dompdf 0day) | Positive Security

https://positive.security/blog/dompdf-rce
From XSS to RCE (dompdf 0day) | Positive Security

Browser In The Browser (BITB) Attack | mr.d0x

https://mrd0x.com/browser-in-the-browser-phishing-attack/
Browser In The Browser (BITB) Attack | mr.d0x

Have Your Cake and Eat it Too? An Overview of UNC2891 | Mandiant

https://www.mandiant.com/resources/unc2891-overview
Have Your Cake and Eat it Too? An Overview of UNC2891 | Mandiant

Uncovering Trickbot’s use of IoT devices in command-and-control infrastructure - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/03/16/uncovering-trickbots-use-of-iot-devices-in-command-and-control-infrastructure/
Uncovering Trickbot’s use of IoT devices in command-and-control infrastructure - Microsoft Security Blog

Exposing initial access broker with ties to Conti

https://blog.google/threat-analysis-group/exposing-initial-access-broker-ties-conti/
Exposing initial access broker with ties to Conti

TryHackMe | One Million People Use TryHackMe!

https://tryhackme.com/resources/blog/one-million-users
TryHackMe | One Million People Use TryHackMe!

Exposing initial access broker with ties to Conti

https://blog.google/threat-analysis-group/exposing-initial-access-broker-ties-conti
Exposing initial access broker with ties to Conti

SOC Core Skills w/ John Strand - Antisyphon

https://www.antisyphontraining.com/soc-core-skills-w-john-strand/
SOC Core Skills w/ John Strand - Antisyphon

Tweet / Twitter

https://twitter.com/Bing_Chris/status/1504185317338845184
Tweet / Twitter

Abusing Azure Hybrid Workers for Privilege Escalation | Azure Penetration Testing

https://www.netspi.com/blog/technical/cloud-penetration-testing/abusing-azure-hybrid-workers-for-privilege-escalation/
Abusing Azure Hybrid Workers for Privilege Escalation | Azure Penetration Testing

New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems

https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware
New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems

cr8escape: New Vulnerability in CRI-O Container Engine (CVE-2022-0811)

https://www.crowdstrike.com/blog/cr8escape-new-vulnerability-discovered-in-cri-o-container-engine-cve-2022-0811/
cr8escape: New Vulnerability in CRI-O Container Engine (CVE-2022-0811)

Kleptocracy Asset Recovery Rewards Program | U.S. Department of the Treasury

https://home.treasury.gov/about/offices/terrorism-and-financial-intelligence/terrorist-financing-and-financial-crimes/kleptocracy-asset-recovery-rewards-program
Kleptocracy Asset Recovery Rewards Program | U.S. Department of the Treasury

New Vulnerability in CRI-O Engine Lets Attackers Escape Kubernetes Containers

https://thehackernews.com/2022/03/new-vulnerability-in-cri-o-engine-lets.html
New Vulnerability in CRI-O Engine Lets Attackers Escape Kubernetes Containers

Ukraine Secret Service Arrests Hacker Helping Russian Invaders

https://thehackernews.com/2022/03/ukraine-secret-service-arrests-hacker.html
Ukraine Secret Service Arrests Hacker Helping Russian Invaders

Microsoft Defender tags Office updates as ransomware activity

https://www.bleepingcomputer.com/news/security/microsoft-defender-tags-office-updates-as-ransomware-activity/
Microsoft Defender tags Office updates as ransomware activity