05/08

BPFDoor — an active Chinese global surveillance tool | by Kevin Beaumont | DoublePulsar

https://doublepulsar.com/bpfdoor-an-active-chinese-global-surveillance-tool-54b078f1a896
BPFDoor — an active Chinese global surveillance tool | by Kevin Beaumont | DoublePulsar

Hacking a Bank by Finding a 0day in DotCMS – Assetnote

https://blog.assetnote.io/2022/05/03/hacking-a-bank-using-dotcms-rce/
Hacking a Bank by Finding a 0day in DotCMS – Assetnote

Caramel credit card stealing service is growing in popularity

https://www.bleepingcomputer.com/news/security/caramel-credit-card-stealing-service-is-growing-in-popularity/
Caramel credit card stealing service is growing in popularity

A new secret stash for “fileless” malware | Securelist

https://securelist.com/a-new-secret-stash-for-fileless-malware/106393/
A new secret stash for “fileless” malware | Securelist

GitHub - FuzzySecurity/WWHF-WayWest-2022

https://github.com/FuzzySecurity/WWHF-WayWest-2022
GitHub - FuzzySecurity/WWHF-WayWest-2022

Introduction to VirtualBox security research · Doyensec's Blog

https://blog.doyensec.com/2022/04/26/vbox-fuzzing.html
Introduction to VirtualBox security research · Doyensec's Blog

SID filter as security boundary between domains? (Part 6) - Schema change trust attack - from child to parent — Improsec | improving security

https://improsec.com/tech-blog/sid-filter-as-security-boundary-between-domains-part-6-schema-change-trust-attack-from-child-to-parent
SID filter as security boundary between domains? (Part 6) - Schema change trust attack - from child to parent — Improsec | improving security