04/15

Diving Deeper into WatchGuard Pre-Auth RCE - CVE-2022-26318 – Assetnote

https://blog.assetnote.io/2022/04/13/watchguard-firebox-rce/
Diving Deeper into WatchGuard Pre-Auth RCE - CVE-2022-26318 – Assetnote

Orion Threat Alert: Flight of the BumbleBee - Cynet

https://www.cynet.com/orion-threat-alert-flight-of-the-bumblebee/
Orion Threat Alert: Flight of the BumbleBee - Cynet

VirusTotal - File - d69665f56ddef7ad4e71971f06432e59f1510a7194386e5f0e8926aea7b88e00

https://www.virustotal.com/gui/file/d69665f56ddef7ad4e71971f06432e59f1510a7194386e5f0e8926aea7b88e00
VirusTotal - File - d69665f56ddef7ad4e71971f06432e59f1510a7194386e5f0e8926aea7b88e00

Google Releases Urgent Chrome Update to Patch Actively Exploited Zero-Day Flaw

https://thehackernews.com/2022/04/google-releases-urgent-chrome-update-to.html
Google Releases Urgent Chrome Update to Patch Actively Exploited Zero-Day Flaw

CVE-2022-26809 MS-RPC Vulnerability Analysis | SANS Webcast

https://www.sans.org/webcasts/cve-2022-26809-ms-rpc-vulnerability-analysis/
CVE-2022-26809 MS-RPC Vulnerability Analysis | SANS Webcast

How vx-underground is building a hacker's dream library - The Record by Recorded Future

https://therecord.media/how-vx-underground-is-building-a-hackers-dream-library/
How vx-underground is building a hacker's dream library - The Record by Recorded Future

Chrome Releases: Stable Channel Update for Desktop

https://chromereleases.googleblog.com/2022/04/stable-channel-update-for-desktop_14.html
Chrome Releases: Stable Channel Update for Desktop

Mysteries of the Registry – Pavel Yosifovich

http://scorpiosoftware.net/2022/04/15/mysteries-of-the-registry/
Mysteries of the Registry – Pavel Yosifovich

FBI - Tips

http://tips.fbi.gov
FBI - Tips

Critical Auth Bypass Bug Reported in Cisco Wireless LAN Controller Software

https://thehackernews.com/2022/04/critical-auth-bypass-bug-reported-in.html
Critical Auth Bypass Bug Reported in Cisco Wireless LAN Controller Software

Karakurt revealed as data extortion arm of Conti cybercrime syndicate

https://www.bleepingcomputer.com/news/security/karakurt-revealed-as-data-extortion-arm-of-conti-cybercrime-syndicate/
Karakurt revealed as data extortion arm of Conti cybercrime syndicate

Multiple Vulnerabilities in Cisco Expressway

https://firefart.at/post/multiple_vulnerabilities_cisco_expressway/
Multiple Vulnerabilities in Cisco Expressway

JekyllBot:5 Flaws Let Attackers Take Control of Aethon TUG Hospital Robots

https://thehackernews.com/2022/04/new-jekyllbot5-flaws-let-attackers-take.html
JekyllBot:5 Flaws Let Attackers Take Control of Aethon TUG Hospital Robots

Project Zero: CVE-2021-1782, an iOS in-the-wild vulnerability in vouchers

https://googleprojectzero.blogspot.com/2022/04/cve-2021-1782-ios-in-wild-vulnerability.html
Project Zero: CVE-2021-1782, an iOS in-the-wild vulnerability in vouchers

Haskers Gang Gives Away ZingoStealer Malware to Other Cybercriminals for Free

https://thehackernews.com/2022/04/haskers-gang-gives-away-zingostealer.html
Haskers Gang Gives Away ZingoStealer Malware to Other Cybercriminals for Free

(1) New Messages!

https://www.avertium.com/resources/threat-reports/in-depth-look-at-iranian-apt-muddywater
(1) New Messages!

Coercing NTLM Authentication from SCCM | by Chris Thompson | Posts By SpecterOps Team Members

https://posts.specterops.io/coercing-ntlm-authentication-from-sccm-e6e23ea8260a
Coercing NTLM Authentication from SCCM | by Chris Thompson | Posts By SpecterOps Team Members