04/19

Project Zero: The More You Know, The More You Know You Don’t Know

https://googleprojectzero.blogspot.com/2022/04/the-more-you-know-more-you-know-you.html
Project Zero: The More You Know, The More You Know You Don’t Know

CatalanGate: Extensive Mercenary Spyware Operation against Catalans Using Pegasus and Candiru - The Citizen Lab

https://citizenlab.ca/2022/04/catalangate-extensive-mercenary-spyware-operation-against-catalans-using-pegasus-candiru/
CatalanGate: Extensive Mercenary Spyware Operation against Catalans Using Pegasus and Candiru - The Citizen Lab

Resolving System Service Numbers using the Exception Directory - MDSec

https://www.mdsec.co.uk/2022/04/resolving-system-service-numbers-using-the-exception-directory/
Resolving System Service Numbers using the Exception Directory - MDSec

MalwareBazaar | SHA256 f0fc0e1700296e299a34707361b859d20a07b147da4b0c1c0401696d655fd605 (Quakbot)

https://bazaar.abuse.ch/sample/f0fc0e1700296e299a34707361b859d20a07b147da4b0c1c0401696d655fd605/
MalwareBazaar | SHA256 f0fc0e1700296e299a34707361b859d20a07b147da4b0c1c0401696d655fd605 (Quakbot)

When “secure” isn’t secure at all: High‑impact UEFI vulnerabilities discovered in Lenovo consumer laptops | WeLiveSecurity

https://www.welivesecurity.com/2022/04/19/when-secure-isnt-secure-uefi-vulnerabilities-lenovo-consumer-laptops/
When “secure” isn’t secure at all: High‑impact UEFI vulnerabilities discovered in Lenovo consumer laptops | WeLiveSecurity

Attack On Europe: Documenting Russian Equipment Losses During The 2022 Russian Invasion Of Ukraine - Oryx

https://oryxspioenkop.com/2022/02/attack-on-europe-documenting-equipment.html
Attack On Europe: Documenting Russian Equipment Losses During The 2022 Russian Invasion Of Ukraine - Oryx

Tweet / Twitter

https://twitter.com/jkass99/status/1516491976593469440
Tweet / Twitter

| Job Preference

http://www.jobpreference.com
| Job Preference

2274 - Linux: watch_queue filter OOB write (and other bugs) - project-zero

https://bugs.chromium.org/p/project-zero/issues/detail?id=2274
2274 - Linux: watch_queue filter OOB write (and other bugs) - project-zero

Emotet botnet switches to 64-bit modules, increases activity

https://www.bleepingcomputer.com/news/security/emotet-botnet-switches-to-64-bit-modules-increases-activity/
Emotet botnet switches to 64-bit modules, increases activity

Okta Concludes its Investigation Into the January 2022 Compromise | Okta

https://www.okta.com/blog/2022/04/okta-concludes-its-investigation-into-the-january-2022-compromise/
Okta Concludes its Investigation Into the January 2022 Compromise | Okta

Extracting Cobalt Strike from Windows Error Reporting — Blake's R&D

http://bmcder.com/blog/extracting-cobalt-strike-from-windows-error-reporting
Extracting Cobalt Strike from Windows Error Reporting — Blake's R&D

Orion Threat Alert: Flight of the BumbleBee - Cynet

https://www.cynet.com/orion-threat-alert-flight-of-the-bumblebee/
Orion Threat Alert: Flight of the BumbleBee - Cynet

Shameful: Insteon looks dead—just like its users’ smart homes | Ars Technica

https://arstechnica.com/gadgets/2022/04/shameful-insteon-looks-dead-just-like-its-users-smart-homes/
Shameful: Insteon looks dead—just like its users’ smart homes | Ars Technica

How to recover files encrypted by Yanluowang | Securelist

https://securelist.com/how-to-recover-files-encrypted-by-yanlouwang/106332/
How to recover files encrypted by Yanluowang | Securelist

Webinar Registration - Zoom

https://specterops.zoom.us/webinar/register/WN_9UZef0yUSQqR7Njqj2Cvbw
Webinar Registration - Zoom

PSBits/HideSnapshot at master · gtworek/PSBits · GitHub

https://github.com/gtworek/PSBits/tree/master/HideSnapshot
PSBits/HideSnapshot at master · gtworek/PSBits · GitHub

redpwn-empires.html · GitHub

https://gist.github.com/hkraw/07fea48adf2ad4978dbf3b498ab05dff
redpwn-empires.html · GitHub

LinkedIn brand takes lead as most impersonated in phishing attacks

https://www.bleepingcomputer.com/news/security/linkedin-brand-takes-lead-as-most-impersonated-in-phishing-attacks/
LinkedIn brand takes lead as most impersonated in phishing attacks

How Democracies Spy on Their Citizens | The New Yorker

https://www.newyorker.com/magazine/2022/04/25/how-democracies-spy-on-their-citizens
How Democracies Spy on Their Citizens | The New Yorker

From Patch To Exploit: CVE-2021-35029

https://blog.cys4.com/exploit/reverse-engineering/2022/04/18/From-Patch-To-Exploit_CVE-2021-35029.html
From Patch To Exploit: CVE-2021-35029