03/31

Project Zero: FORCEDENTRY: Sandbox Escape

https://googleprojectzero.blogspot.com/2022/03/forcedentry-sandbox-escape.html
Project Zero: FORCEDENTRY: Sandbox Escape

Spring Framework RCE, Early Announcement

https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement
Spring Framework RCE, Early Announcement

Turbocharging your security program with XDR | SANS Institute

https://www.sans.org/webcasts/turbocharging-your-security-program-with-xdr/
Turbocharging your security program with XDR | SANS Institute

Pwning 3CX Phone Management Backends from the Internet | by frycos | Medium

https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88
Pwning 3CX Phone Management Backends from the Internet | by frycos | Medium

Daughter + Dad: Coming out as transgender | Snyk

https://snyk.io/blog/daughter-dad-coming-transgender/
Daughter + Dad: Coming out as transgender | Snyk

Spring4Shell: Zero-Day Vulnerability in Spring Framework | Rapid7 Blog

https://www.rapid7.com/blog/post/2022/03/30/spring4shell-zero-day-vulnerability-in-spring-framework/
Spring4Shell: Zero-Day Vulnerability in Spring Framework | Rapid7 Blog

Tracking cyber activity in Eastern Europe

https://blog.google/threat-analysis-group/tracking-cyber-activity-eastern-europe/
Tracking cyber activity in Eastern Europe

I'm here and I'm human - Alyssa Miller

https://alyssasec.com/2022/03/im-here-and-im-human
I'm here and I'm human - Alyssa Miller

Emotet/e4_emotet_31.03.2022.txt at main · pr0xylife/Emotet · GitHub

https://github.com/pr0xylife/Emotet/blob/main/e4_emotet_31.03.2022.txt
Emotet/e4_emotet_31.03.2022.txt at main · pr0xylife/Emotet · GitHub

GreyNoise Trends

https://www.greynoise.io/viz/tag/spring-core-rce-attempt
GreyNoise Trends

GreyNoise Trends

https://www.greynoise.io/viz/tag/spring-cloud-function-spel-rce-attempt
GreyNoise Trends

Emotet/e5_emotet_31.03.2022.txt at main · pr0xylife/Emotet · GitHub

https://github.com/pr0xylife/Emotet/blob/main/e5_emotet_31.03.2022.txt
Emotet/e5_emotet_31.03.2022.txt at main · pr0xylife/Emotet · GitHub

Post Office Cops Used Social Media Surveillance Program Illegally

https://www.vice.com/en/article/n7nmaz/post-office-cops-used-social-media-surveillance-program-illegally
Post Office Cops Used Social Media Surveillance Program Illegally

Triage | Behavioral Report

https://tria.ge/220331-nzbfjafdfr/behavioral1
Triage | Behavioral Report

Login | Microsoft Careers

https://aka.ms/threat-hunter-role
Login | Microsoft Careers

qakbot_31_03_2022 - Pastebin.com

https://pastebin.com/mWbKWgrM
qakbot_31_03_2022 - Pastebin.com

'I can fight with a keyboard': How one Ukrainian IT specialist exposed a notorious Russian ransomware gang - CNNPolitics

https://www.cnn.com/2022/03/30/politics/ukraine-hack-russian-ransomware-gang/index.html
'I can fight with a keyboard': How one Ukrainian IT specialist exposed a notorious Russian ransomware gang - CNNPolitics

AcidRain | A Modem Wiper Rains Down on Europe - SentinelOne

https://www.sentinelone.com/labs/acidrain-a-modem-wiper-rains-down-on-europe/
AcidRain | A Modem Wiper Rains Down on Europe - SentinelOne

GitHub - snovvcrash/KeeThief at syscalls

https://github.com/snovvcrash/KeeThief/tree/syscalls
GitHub - snovvcrash/KeeThief at syscalls

Threat Alert: First Python Ransomware Attack Targeting Jupyter Notebooks

https://blog.aquasec.com/python-ransomware-jupyter-notebook
Threat Alert: First Python Ransomware Attack Targeting Jupyter Notebooks

Url: http://45.67.230.64/kinsing - AlienVault - Open Threat Exchange

https://otx.alienvault.com/indicator/url/http://45.67.230.64/kinsing
Url: http://45.67.230.64/kinsing - AlienVault - Open Threat Exchange

stuff.txt · GitHub

https://gist.github.com/esell/c9731a7e2c5404af7716a6810dc33e1a
stuff.txt · GitHub

Unpatched Java Spring Framework 0-Day RCE Bug Threatens Enterprise Web Apps Security

https://thehackernews.com/2022/03/unpatched-java-spring-framework-0-day.html
Unpatched Java Spring Framework 0-Day RCE Bug Threatens Enterprise Web Apps Security

Hackers Increasingly Using 'Browser-in-the-Browser' Technique in Ukraine Related Attacks

https://thehackernews.com/2022/03/hackers-increasingly-using-browser-in.html
Hackers Increasingly Using 'Browser-in-the-Browser' Technique in Ukraine Related Attacks

New Python-based Ransomware Targeting JupyterLab Web Notebooks

https://thehackernews.com/2022/03/new-python-based-ransomware-targeting.html
New Python-based Ransomware Targeting JupyterLab Web Notebooks

CSIRT

http://www.csirt.gob.cl
CSIRT

Spring Framework WebappClassLoader code execution CVE-2010-1622 Vulnerability Report

https://exchange.xforce.ibmcloud.com/vulnerabilities/59573
Spring Framework WebappClassLoader code execution CVE-2010-1622 Vulnerability Report

National Security Agency Employee Indicted for Willful Transmission and Retention of National Defense Information | OPA | Department of Justice

https://www.justice.gov/opa/pr/national-security-agency-employee-indicted-willful-transmission-and-retention-national
National Security Agency Employee Indicted for Willful Transmission and Retention of National Defense Information | OPA | Department of Justice

New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits

https://www.fortinet.com/blog/threat-research/deep-panda-log4shell-fire-chili-rootkits
New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits

ImpressCMS: from unauthenticated SQL injection to RCE | Karma(In)Security

http://karmainsecurity.com/impresscms-from-unauthenticated-sqli-to-rce
ImpressCMS: from unauthenticated SQL injection to RCE | Karma(In)Security