04/05

Process Injection via Component Object Model (COM) IRundown::DoCallback() - MDSec

https://www.mdsec.co.uk/2022/04/process-injection-via-component-object-model-com-irundowndocallback/
Process Injection via Component Object Model (COM) IRundown::DoCallback() - MDSec

Unmanaged Code Execution with .NET Dynamic PInvoke – bohops

https://bohops.com/2022/04/02/unmanaged-code-execution-with-net-dynamic-pinvoke/
Unmanaged Code Execution with .NET Dynamic PInvoke – bohops

Learning Machine Learning Part 1: Introduction and Revoke-Obfuscation | by Will Schroeder | Posts By SpecterOps Team Members

https://posts.specterops.io/learning-machine-learning-part-1-introduction-and-revoke-obfuscation-c73033184f0
Learning Machine Learning Part 1: Introduction and Revoke-Obfuscation | by Will Schroeder | Posts By SpecterOps Team Members

Randomizing the KUSER_SHARED_DATA Structure on Windows – Microsoft Security Response Center

https://msrc-blog.microsoft.com/2022/03/30/randomizing-the-kuser_shared_data-structure-on-windows/
Randomizing the KUSER_SHARED_DATA Structure on Windows – Microsoft Security Response Center

FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7 | Mandiant

https://www.mandiant.com/resources/evolution-of-fin7
FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7 | Mandiant

Germany Shuts Down Russian Hydra Darknet Market; Seizes $25 Million in Bitcoin

https://thehackernews.com/2022/04/germany-shuts-down-russian-hydra.html
Germany Shuts Down Russian Hydra Darknet Market; Seizes $25 Million in Bitcoin

Cicada: Chinese APT Group Widens Targeting in Recent Espionage Activity | Broadcom Software Blogs

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cicada-apt10-china-ngo-government-attacks
Cicada: Chinese APT Group Widens Targeting in Recent Espionage Activity | Broadcom Software Blogs

BKA - Homepage - HTTP Status 404

https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2022/Presse2022/220405_PM_IllegalerDarknetMarktplatz.html?s=09
BKA - Homepage - HTTP Status 404

Making SMB Accessible with NTLMquic - TrustedSec

https://www.trustedsec.com/blog/making-smb-accessible-with-ntlmquic/
Making SMB Accessible with NTLMquic - TrustedSec

Germany takes down Hydra, world's largest darknet market

https://www.bleepingcomputer.com/news/legal/germany-takes-down-hydra-worlds-largest-darknet-market/
Germany takes down Hydra, world's largest darknet market

Bypassing Access Mask Auditing Strategies | by Jonathan Johnson | Medium

https://jsecurity101.medium.com/bypassing-access-mask-auditing-strategies-480fb641c158
Bypassing Access Mask Auditing Strategies | by Jonathan Johnson | Medium

MalwareBazaar | EnelEnergia

https://bazaar.abuse.ch/browse/tag/EnelEnergia/
MalwareBazaar | EnelEnergia

Researchers Trace Widespread Espionage Attacks Back to Chinese 'Cicada' Hackers

https://thehackernews.com/2022/04/researchers-trace-widespread-espionage.html
Researchers Trace Widespread Espionage Attacks Back to Chinese 'Cicada' Hackers

CVE-2021-38159: MOVEit Transfer SQL Injection Analysis

https://blog.viettelcybersecurity.com/moveit-transfer-cve/
CVE-2021-38159: MOVEit Transfer SQL Injection Analysis

Hackers Breach Mailchimp Email Marketing Firm to Launch Crypto Phishing Scams

https://thehackernews.com/2022/04/hackers-breach-mailchimp-email.html
Hackers Breach Mailchimp Email Marketing Firm to Launch Crypto Phishing Scams

CVE-2022-22639 - YouTube

https://www.youtube.com/watch?v=-vbkTLHh874
CVE-2022-22639 - YouTube

SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965 - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/04/04/springshell-rce-vulnerability-guidance-for-protecting-against-and-detecting-cve-2022-22965/
SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965 - Microsoft Security Blog

WhatsApp voice message phishing emails push info-stealing malware

https://www.bleepingcomputer.com/news/security/whatsapp-voice-message-phishing-emails-push-info-stealing-malware/
WhatsApp voice message phishing emails push info-stealing malware

SecurityZines

http://securityzines.com
SecurityZines

HD – Darknet Diaries

https://darknetdiaries.com/episode/114
HD – Darknet Diaries

UniCon 2022 - April 8

https://www.scythe.io/unicon2022
UniCon 2022 - April 8

Azure Active Directory Exposes Internal Information - Threat Analysis | Secureworks

https://www.secureworks.com/research/azure-active-directory-exposes-internal-information
Azure Active Directory Exposes Internal Information - Threat Analysis | Secureworks

Dead Lay Out in Bucha for Weeks, Refuting Russian Claim, Satellite Images Show - The New York Times

https://www.nytimes.com/2022/04/04/world/europe/bucha-ukraine-bodies.html
Dead Lay Out in Bucha for Weeks, Refuting Russian Claim, Satellite Images Show - The New York Times