05/11

Certifried: Active Directory Domain Privilege Escalation (CVE-2022–26923) | by Oliver Lyak | IFCR

https://research.ifcr.dk/certifried-active-directory-domain-privilege-escalation-cve-2022-26923-9e098fe298f4
Certifried: Active Directory Domain Privilege Escalation (CVE-2022–26923) | by Oliver Lyak | IFCR

CYBERUK ONLINE - YouTube

https://www.youtube.com/c/CYBERUKONLINE
CYBERUK ONLINE - YouTube

APT34 targets Jordan Government using new Saitama backdoor

https://blog.malwarebytes.com/threat-intelligence/2022/05/apt34-targets-jordan-government-using-new-saitama-backdoor/
APT34 targets Jordan Government using new Saitama backdoor

Nerbian RAT Using COVID-19 Themes Features Sophisticated Evasion Techniques | Proofpoint US

https://www.proofpoint.com/us/blog/threat-insight/nerbian-rat-using-covid-19-themes-features-sophisticated-evasion-techniques
Nerbian RAT Using COVID-19 Themes Features Sophisticated Evasion Techniques | Proofpoint US

CVE-2022-21972: Windows Server VPN Remote Kernel Use After Free Vulnerability (Part 1) - Nettitude Labs

https://labs.nettitude.com/blog/cve-2022-21972-windows-server-vpn-remote-kernel-use-after-free-vulnerability/
CVE-2022-21972: Windows Server VPN Remote Kernel Use After Free Vulnerability (Part 1) - Nettitude Labs

Releases · hasherezade/mal_unpack

https://github.com/hasherezade/mal_unpack/releases
Releases · hasherezade/mal_unpack

Critical F5 BIG-IP vulnerability exploited to wipe devices

https://www.bleepingcomputer.com/news/security/critical-f5-big-ip-vulnerability-targeted-by-destructive-attacks/
Critical F5 BIG-IP vulnerability exploited to wipe devices

Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself/
Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself - Microsoft Security Blog

Releases · hasherezade/mal_unpack_drv · GitHub

https://github.com/hasherezade/mal_unpack_drv/releases
Releases · hasherezade/mal_unpack_drv · GitHub

Project Zero: Release of Technical Report into the AMD Security Processor

https://googleprojectzero.blogspot.com/2022/05/release-of-technical-report-into-amd.html
Project Zero: Release of Technical Report into the AMD Security Processor

Diving into pre-created computer accounts - TrustedSec

https://www.trustedsec.com/blog/diving-into-pre-created-computer-accounts/
Diving into pre-created computer accounts - TrustedSec

BPFDoor - An Evasive Linux Backdoor Technical Analysis

https://www.sandflysecurity.com/blog/bpfdoor-an-evasive-linux-backdoor-technical-analysis/
BPFDoor - An Evasive Linux Backdoor Technical Analysis

KB5014754: Certificate-based authentication changes on Windows domain controllers

https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16
KB5014754: Certificate-based authentication changes on Windows domain controllers

VXER.io

https://vxer.io/
VXER.io

Fighting child sexual abuse

https://ec.europa.eu/commission/presscorner/detail/en/ip_22_2976
Fighting child sexual abuse

Learning Linux kernel exploitation - Part 2 - CVE-2022-0847

https://0x434b.dev/learning-linux-kernel-exploitation-part-2-cve-2022-0847/
Learning Linux kernel exploitation - Part 2 - CVE-2022-0847

Some Top 100,000 Websites Collect Everything You Type—Before You Hit Submit | WIRED

https://www.wired.com/story/leaky-forms-keyloggers-meta-tiktok-pixel-study/
Some Top 100,000 Websites Collect Everything You Type—Before You Hit Submit | WIRED

Microsoft fixes new NTLM relay zero-day in all Windows versions

https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-new-ntlm-relay-zero-day-in-all-windows-versions/
Microsoft fixes new NTLM relay zero-day in all Windows versions

New IceApple exploit toolset deployed on Microsoft Exchange servers

https://www.bleepingcomputer.com/news/security/new-iceapple-exploit-toolset-deployed-on-microsoft-exchange-servers/
New IceApple exploit toolset deployed on Microsoft Exchange servers

The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF… | by Renwa | Medium

https://medium.com/@renwa/the-underrated-bugs-clickjacking-css-injection-drag-drop-xss-cookie-bomb-login-logout-csrf-84307a98fffa
The Underrated Bugs, Clickjacking, CSS Injection, Drag-Drop XSS, Cookie Bomb, Login+Logout CSRF… | by Renwa | Medium

Electron Shellcode Loader

https://barbellsandrootshells.com/electron-shellcode-loader
Electron Shellcode Loader

Microsoft Releases Fix for New Zero-Day with May 2022 Patch Tuesday Updates

https://thehackernews.com/2022/05/microsoft-releases-fix-for-new-zero-day.html
Microsoft Releases Fix for New Zero-Day with May 2022 Patch Tuesday Updates

GitHub - Pear1y/CVE-2022-26133: Atlassian Bitbucket Data Center RCE(CVE-2022-26133) verification.

https://github.com/Pear1y/CVE-2022-26133?fbclid=IwAR0kGMK6WaQGnXTXqKsfGvm1q62GVCMvs8ghQn81BZnEAOpgYDRKXD88NJI
GitHub - Pear1y/CVE-2022-26133: Atlassian Bitbucket Data Center RCE(CVE-2022-26133) verification.

Space / Twitter

https://twitter.com/i/spaces/1yoKMWVPjRNJQ
Space / Twitter