04/27

Encrypting our way to SSRF in VMWare Workspace One UEM (CVE-2021-22054) – Assetnote

https://blog.assetnote.io/2022/04/27/vmware-workspace-one-uem-ssrf/
Encrypting our way to SSRF in VMWare Workspace One UEM (CVE-2021-22054) – Assetnote

The hybrid war in Ukraine - Microsoft On the Issues

https://blogs.microsoft.com/on-the-issues/2022/04/27/hybrid-war-ukraine-russia-cyberattacks/
The hybrid war in Ukraine - Microsoft On the Issues

Assembling the Russian Nesting Doll: UNC2452 Merged into APT29 | Mandiant

https://www.mandiant.com/resources/unc2452-merged-into-apt29
Assembling the Russian Nesting Doll: UNC2452 Merged into APT29 | Mandiant

The chronicles of Bumblebee: The Hook, the Bee, and the Trickbot connection | by Eli Salem | Medium

https://elis531989.medium.com/the-chronicles-of-bumblebee-the-hook-the-bee-and-the-trickbot-connection-686379311056
The chronicles of Bumblebee: The Hook, the Bee, and the Trickbot connection | by Eli Salem | Medium

GitHub - trustedsec/CS-Remote-OPs-BOF

https://github.com/trustedsec/CS-Remote-OPs-BOF
GitHub - trustedsec/CS-Remote-OPs-BOF

Microsoft finds new elevation of privilege Linux vulnerability, Nimbuspwn - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/
Microsoft finds new elevation of privilege Linux vulnerability, Nimbuspwn - Microsoft Security Blog

CISA, FBI, NSA, and International Partners Warn Organizations of Top Routinely Exploited Cybersecurity Vulnerabilities > National Security Agency/Central Security Service > Article

https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/3011622/cisa-fbi-nsa-and-international-partners-warn-organizations-of-top-routinely-exp/
CISA, FBI, NSA, and International Partners Warn Organizations of Top Routinely Exploited Cybersecurity Vulnerabilities > National Security Agency/Central Security Service > Article

A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity | WeLiveSecurity

https://www.welivesecurity.com/2022/04/27/lookback-ta410-umbrella-cyberespionage-ttps-activity/
A lookback under the TA410 umbrella: Its cyberespionage TTPs and activity | WeLiveSecurity

U.S. Offers $10 Million Bounty for Information on 6 Russian Military Hackers

https://thehackernews.com/2022/04/us-offers-10-million-bounty-for.html
U.S. Offers $10 Million Bounty for Information on 6 Russian Military Hackers

Introduction to VirtualBox security research · Doyensec's Blog

https://blog.doyensec.com/2022/04/26/vbox-fuzzing.html
Introduction to VirtualBox security research · Doyensec's Blog

MalwareBazaar | SHA256 db4158ecdd18f5f5a706b12d2af93169199e02a6d53270acc3f233aa2d459ed2 (Gozi)

https://bazaar.abuse.ch/sample/db4158ecdd18f5f5a706b12d2af93169199e02a6d53270acc3f233aa2d459ed2/
MalwareBazaar | SHA256 db4158ecdd18f5f5a706b12d2af93169199e02a6d53270acc3f233aa2d459ed2 (Gozi)

US offers $10 million reward for tips on Russian Sandworm hackers

https://www.bleepingcomputer.com/news/security/us-offers-10-million-reward-for-tips-on-russian-sandworm-hackers/
US offers $10 million reward for tips on Russian Sandworm hackers

Azure Monitor – Malicious KQL Query – SecureCloudBlog

https://securecloud.blog/2022/04/27/azure-monitor-malicious-kql-query/
Azure Monitor – Malicious KQL Query – SecureCloudBlog

NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages

https://thehackernews.com/2022/04/npm-bug-allowed-attackers-to-distribute.html
NPM Bug Allowed Attackers to Distribute Malware as Legitimate Packages

4-Hour Time-to-Ransom Seen in Quantum Attack as Accelerated Ransomware Increasingly Common | SecurityWeek.Com

https://www.securityweek.com/4-hour-time-ransom-seen-quantum-attack-accelerated-ransomware-increasingly-common
4-Hour Time-to-Ransom Seen in Quantum Attack as Accelerated Ransomware Increasingly Common | SecurityWeek.Com

Redis, MongoDB, and Elastic: 2022’s top exposed databases

https://www.bleepingcomputer.com/news/security/number-of-publicly-exposed-database-instances-hits-new-record/
Redis, MongoDB, and Elastic: 2022’s top exposed databases

Fundraiser by Leonid Volkov : Join Navalny Team now!

https://www.gofundme.com/f/navalny-team
Fundraiser by Leonid Volkov : Join Navalny Team now!

Microsoft Discovers New Privilege Escalation Flaws in Linux Operating System

https://thehackernews.com/2022/04/microsoft-discovers-new-privilege.html
Microsoft Discovers New Privilege Escalation Flaws in Linux Operating System