04/21

CVE-2022-21449: Psychic Signatures in Java – Neil Madden

https://neilmadden.blog/2022/04/19/psychic-signatures-in-java/
CVE-2022-21449: Psychic Signatures in Java – Neil Madden

OffensiveCon22 - YouTube

https://www.youtube.com/playlist?list=PLYvhPWR_XYJnPvrhXE4RYvwZhV26nYTIp
OffensiveCon22 - YouTube

JSAC2022_workshop_macOS-forensic_en.pdf

https://jsac.jpcert.or.jp/archive/2022/pdf/JSAC2022_workshop_macOS-forensic_en.pdf
JSAC2022_workshop_macOS-forensic_en.pdf

Adventures with KernelCallbackTable Injection - Hack.Learn.Share

https://captmeelo.com/redteam/maldev/2022/04/21/kernelcallbacktable-injection.html
Adventures with KernelCallbackTable Injection - Hack.Learn.Share

Home - PowerofTenOnline.com

http://PowerofTenOnline.com
Home - PowerofTenOnline.com

security-labs-pocs/proof-of-concept-exploits/jwt-null-signature-vulnerable-app at main · DataDog/security-labs-pocs · GitHub

https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/jwt-null-signature-vulnerable-app
security-labs-pocs/proof-of-concept-exploits/jwt-null-signature-vulnerable-app at main · DataDog/security-labs-pocs · GitHub

Not found – 404 error

https://jobs.lever.co/dragos/511d10a2-7f5d-45fc-9060-33588a92cd39
Not found – 404 error

JBoss EAP/AS <= 6.* RCE - A little bit beyond \xAC\xED

https://jspin.re/jboss-eap-as-6-rce-a-little-bit-beyond-xac-xed/
JBoss EAP/AS <= 6.* RCE - A little bit beyond \xAC\xED

Attack On Europe: Documenting Russian Equipment Losses During The 2022 Russian Invasion Of Ukraine - Oryx

https://oryxspioenkop.com/2022/02/attack-on-europe-documenting-equipment.html
Attack On Europe: Documenting Russian Equipment Losses During The 2022 Russian Invasion Of Ukraine - Oryx

Criminals Abuse Apple Pay in Spending Sprees

https://www.vice.com/en/article/n7ngxm/apple-pay-fraud-spending-sprees-2fa-bots
Criminals Abuse Apple Pay in Spending Sprees

New Incident Report Reveals How Hive Ransomware Targets Organizations

https://thehackernews.com/2022/04/new-incident-report-reveals-how-hive.html
New Incident Report Reveals How Hive Ransomware Targets Organizations

Tweet / Twitter

https://twitter.com/uk_daniel_card/status/1517098575221694465
Tweet / Twitter

Cisco Umbrella default SSH key allows theft of admin credentials

https://www.bleepingcomputer.com/news/security/cisco-umbrella-default-ssh-key-allows-theft-of-admin-credentials/
Cisco Umbrella default SSH key allows theft of admin credentials

Malware-Traffic-Analysis.net - 2022-04-20 (Wednesday) - Emotet epoch4 activity

https://www.malware-traffic-analysis.net/2022/04/20/index.html
Malware-Traffic-Analysis.net - 2022-04-20 (Wednesday) - Emotet epoch4 activity

Emotet/e4_emotet_21.04.2022.txt at main · pr0xylife/Emotet · GitHub

https://github.com/pr0xylife/Emotet/blob/main/e4_emotet_21.04.2022.txt
Emotet/e4_emotet_21.04.2022.txt at main · pr0xylife/Emotet · GitHub

MalwareBazaar | solarmarker

https://bazaar.abuse.ch/browse/tag/solarmarker/
MalwareBazaar | solarmarker

Critical Chipset Bugs Open Millions of Android Devices to Remote Spying

https://thehackernews.com/2022/04/critical-chipset-bug-opens-millions-of.html
Critical Chipset Bugs Open Millions of Android Devices to Remote Spying

| Job Preference

http://www.jobpreference.com
| Job Preference

MalwareBazaar | SHA256 c3148c6c4b0ecce9c7d07ba57dea96e35acf5f2ef47396c48339bb9a3a07e390 (BumbleBee)

https://bazaar.abuse.ch/sample/c3148c6c4b0ecce9c7d07ba57dea96e35acf5f2ef47396c48339bb9a3a07e390/
MalwareBazaar | SHA256 c3148c6c4b0ecce9c7d07ba57dea96e35acf5f2ef47396c48339bb9a3a07e390 (BumbleBee)

MalwareBazaar | SHA256 3463f026ce1c325931e285b587b82f7f690db2e75929c7edd154df1e14f38c93 (BumbleBee)

https://bazaar.abuse.ch/sample/3463f026ce1c325931e285b587b82f7f690db2e75929c7edd154df1e14f38c93/
MalwareBazaar | SHA256 3463f026ce1c325931e285b587b82f7f690db2e75929c7edd154df1e14f38c93 (BumbleBee)

Qakbot/Qakbot_obama179_21.04.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_obama179_21.04.2022.txt
Qakbot/Qakbot_obama179_21.04.2022.txt at main · pr0xylife/Qakbot · GitHub