04/13

Coercing NTLM Authentication from SCCM | by Chris Thompson | Posts By SpecterOps Team Members

https://posts.specterops.io/coercing-ntlm-authentication-from-sccm-e6e23ea8260a
Coercing NTLM Authentication from SCCM | by Chris Thompson | Posts By SpecterOps Team Members

APT Cyber Tools Targeting ICS/SCADA Devices | CISA

https://www.cisa.gov/uscert/ncas/alerts/aa22-103a
APT Cyber Tools Targeting ICS/SCADA Devices | CISA

INCONTROLLER: New State-Sponsored Cyber Attack Tools Target Multiple Industrial Control Systems | Mandiant

https://www.mandiant.com/resources/incontroller-state-sponsored-ics-tool
INCONTROLLER: New State-Sponsored Cyber Attack Tools Target Multiple Industrial Control Systems | Mandiant

Dismantling ZLoader: How malicious ads led to disabled security tools and ransomware - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/04/13/dismantling-zloader-how-malicious-ads-led-to-disabled-security-tools-and-ransomware/
Dismantling ZLoader: How malicious ads led to disabled security tools and ransomware - Microsoft Security Blog

pocs/windows/spooler-splenumforms-iov at main · grigoritchy/pocs · GitHub

https://github.com/grigoritchy/pocs/tree/main/windows/spooler-splenumforms-iov
pocs/windows/spooler-splenumforms-iov at main · grigoritchy/pocs · GitHub

Bypassing Cortex XDR | mr.d0x

https://mrd0x.com/cortex-xdr-analysis-and-bypass/
Bypassing Cortex XDR | mr.d0x

CHERNOVITE's PIPEDREAM Targeting Industrial Control Systems (ICS)

https://www.dragos.com/blog/industry-news/chernovite-pipedream-malware-targeting-industrial-control-systems/
CHERNOVITE's PIPEDREAM Targeting Industrial Control Systems (ICS)

Volunteer Centre "Palyanytsya"

https://palyanycia.com/en/home-page/
Volunteer Centre "Palyanytsya"

Tarrask malware uses scheduled tasks for defense evasion - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/04/12/tarrask-malware-uses-scheduled-tasks-for-defense-evasion/
Tarrask malware uses scheduled tasks for defense evasion - Microsoft Security Blog

Akamai Blog | Critical Remote Code Execution Vulnerabilities in Windows RPC Runtime

https://www.akamai.com/blog/security/critical-remote-code-execution-vulnerabilities-windows-rpc-runtime
Akamai Blog | Critical Remote Code Execution Vulnerabilities in Windows RPC Runtime

NSA partners with DOE, CISA, and FBI to release advisory on APT Cyber Tools Targeting ICS/SCADA devices > National Security Agency/Central Security Service > Article

https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/2997885/nsa-partners-with-doe-cisa-and-fbi-to-release-advisory-on-apt-cyber-tools-targe/
NSA partners with DOE, CISA, and FBI to release advisory on APT Cyber Tools Targeting ICS/SCADA devices > National Security Agency/Central Security Service > Article

CVE-2022-24527: Microsoft Connected Cache Local Privilege Escalation (Fixed) | Rapid7 Blog

https://www.rapid7.com/blog/post/2022/04/12/cve-2022-24527-microsoft-connected-cache-local-privilege-escalation-fixed/
CVE-2022-24527: Microsoft Connected Cache Local Privilege Escalation (Fixed) | Rapid7 Blog

April 2022 outage update

https://www.atlassian.com/engineering/april-2022-outage-update
April 2022 outage update

Hackers exploit critical VMware CVE-2022-22954 bug, patch now

https://www.bleepingcomputer.com/news/security/hackers-exploiting-vmware-servers-with-public-rce-exploit/
Hackers exploit critical VMware CVE-2022-22954 bug, patch now

APT Cyber Tools Targeting ICS/SCADA Devices | CISA

https://us-cert.cisa.gov/ncas/alerts/aa22-103a
APT Cyber Tools Targeting ICS/SCADA Devices | CISA

Qakbot/Qakbot_AA_13.04.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_AA_13.04.2022.txt
Qakbot/Qakbot_AA_13.04.2022.txt at main · pr0xylife/Qakbot · GitHub

Twitter / Error

https://twitter.com/OphirHarpaz/status/1514358026668552197
Twitter / Error

Microsoft Exposes Evasive Chinese Tarrask Malware Attacking Windows Computers

https://thehackernews.com/2022/04/microsoft-exposes-evasive-chinese.html
Microsoft Exposes Evasive Chinese Tarrask Malware Attacking Windows Computers