05/03

Hacking a Bank by Finding a 0day in DotCMS – Assetnote

https://blog.assetnote.io/2022/05/03/hacking-a-bank-using-dotcms-rce/
Hacking a Bank by Finding a 0day in DotCMS – Assetnote

Data Broker Is Selling Location Data of People Who Visit Abortion Clinics

https://www.vice.com/en/article/m7vzjb/location-data-abortion-clinics-safegraph-planned-parenthood
Data Broker Is Selling Location Data of People Who Visit Abortion Clinics

UNC3524: Eye Spy on Your Email | Mandiant

https://www.mandiant.com/resources/unc3524-eye-spy-email
UNC3524: Eye Spy on Your Email | Mandiant

AvosLocker Ransomware Variant Abuses Driver File to Disable Anti-Virus, Scans for Log4shell

https://www.trendmicro.com/en_us/research/22/e/avoslocker-ransomware-variant-abuses-driver-file-to-disable-anti-Virus-scans-log4shell.html
AvosLocker Ransomware Variant Abuses Driver File to Disable Anti-Virus, Scans for Log4shell

Supreme Court has voted to overturn abortion rights, draft opinion shows - POLITICO

https://www.politico.com/news/2022/05/02/supreme-court-abortion-draft-opinion-00029473
Supreme Court has voted to overturn abortion rights, draft opinion shows - POLITICO

CDC Tracked Millions of Phones to See If Americans Followed COVID Lockdown Orders

https://www.vice.com/en/article/m7vymn/cdc-tracked-phones-location-data-curfews
CDC Tracked Millions of Phones to See If Americans Followed COVID Lockdown Orders

Trello From the Other Side: Tracking APT29 Phishing Campaigns | Mandiant

https://www.mandiant.com/resources/tracking-apt29-phishing-campaigns
Trello From the Other Side: Tracking APT29 Phishing Campaigns | Mandiant

GitHub Says Recent Attack Involving Stolen OAuth Tokens Was "Highly Targeted"

https://thehackernews.com/2022/05/github-says-recent-attack-involving.html
GitHub Says Recent Attack Involving Stolen OAuth Tokens Was "Highly Targeted"

AvosLocker Ransomware Variant Using New Trick to Disable Antivirus Protection

https://thehackernews.com/2022/05/avoslocker-ransomware-variant-using-new.html
AvosLocker Ransomware Variant Using New Trick to Disable Antivirus Protection

Update on cyber activity in Eastern Europe

https://blog.google/threat-analysis-group/update-on-cyber-activity-in-eastern-europe
Update on cyber activity in Eastern Europe

| Job Preference

http://www.jobpreference.com
| Job Preference

REvil ransomware returns: New malware sample confirms gang is back

https://www.bleepingcomputer.com/news/security/revil-ransomware-returns-new-malware-sample-confirms-gang-is-back/
REvil ransomware returns: New malware sample confirms gang is back

Unpatched DNS Related Vulnerability Affects a Wide Range of IoT Devices

https://thehackernews.com/2022/05/unpatched-dns-related-vulnerability.html
Unpatched DNS Related Vulnerability Affects a Wide Range of IoT Devices

Update on cyber activity in Eastern Europe

https://blog.google/threat-analysis-group/update-on-cyber-activity-in-eastern-europe/
Update on cyber activity in Eastern Europe

What Your Period Tracker App Knows About You - Consumer Reports

https://www.consumerreports.org/health-privacy/what-your-period-tracker-app-knows-about-you-a8701683935/
What Your Period Tracker App Knows About You - Consumer Reports

(pub)TBHM App v1 - Google スライド

https://docs.google.com/presentation/d/1cMSRVlJJ5de6Pyv-09YgzOGS0OYrP6p7ggGl0f42wmw/edit?usp=sharing
(pub)TBHM App v1 - Google スライド

cocomelonc

https://cocomelonc.github.io/
cocomelonc

The Hermit Kingdom’s Ransomware Play

https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/the-hermit-kingdoms-ransomware-play.html
The Hermit Kingdom’s Ransomware Play

Cyber Warrior Studios Bio Links

https://cyberwarriorstudios.bio.link
Cyber Warrior Studios Bio Links

Chinese cyber-espionage group Moshen Dragon targets Asian telcos

https://www.bleepingcomputer.com/news/security/chinese-cyber-espionage-group-moshen-dragon-targets-asian-telcos/
Chinese cyber-espionage group Moshen Dragon targets Asian telcos

New Hacker Group Pursuing Corporate Employees Focused on Mergers and Acquisitions

https://thehackernews.com/2022/05/new-hacker-group-pursuing-corporate.html
New Hacker Group Pursuing Corporate Employees Focused on Mergers and Acquisitions

Chinese Hackers Caught Exploiting Popular Antivirus Products to Target Telecom Sector

https://thehackernews.com/2022/05/chinese-hackers-caught-exploiting.html
Chinese Hackers Caught Exploiting Popular Antivirus Products to Target Telecom Sector