05/12

DEA Investigating Breach of Law Enforcement Data Portal – Krebs on Security

https://krebsonsecurity.com/2022/05/dea-investigating-breach-of-law-enforcement-data-portal/
DEA Investigating Breach of Law Enforcement Data Portal – Krebs on Security

CVE-2022-21972: Windows Server VPN Remote Kernel Use After Free Vulnerability (Part 1) - Nettitude Labs

https://labs.nettitude.com/blog/cve-2022-21972-windows-server-vpn-remote-kernel-use-after-free-vulnerability/
CVE-2022-21972: Windows Server VPN Remote Kernel Use After Free Vulnerability (Part 1) - Nettitude Labs

404 Page not found | STAR Labs

https://starlabs.sg/blog/2022/05/new-wine-in-old-bottle-microsoft-sharepoint-post-auth-deserialization-rce-cve-2022-29108/
404 Page not found | STAR Labs

BPFDoor: Stealthy Linux malware bypasses firewalls for remote access

https://www.bleepingcomputer.com/news/security/bpfdoor-stealthy-linux-malware-bypasses-firewalls-for-remote-access/
BPFDoor: Stealthy Linux malware bypasses firewalls for remote access

bloodyAD and CVE-2022-26923 | Total Recall

https://cravaterouge.github.io/ad/privesc/2022/05/11/bloodyad-and-CVE-2022-26923.html
bloodyAD and CVE-2022-26923 | Total Recall

CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection | Rapid7 Blog

https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/
CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection | Rapid7 Blog

Exploit for Active Directory Domain Privilege Escalation (CVE-2022–26923) · GitHub

https://gist.github.com/dmchell/478d83f369260bd4e4cd380712f6bb6e
Exploit for Active Directory Domain Privilege Escalation (CVE-2022–26923) · GitHub

How to Write YARA Rules That Minimize False Positives - Intezer

https://www.intezer.com/blog/threat-hunting/yara-rules-minimize-false-positives/
How to Write YARA Rules That Minimize False Positives - Intezer

Call For Papers - Wild West Hackin' Fest in Deadwood

https://wildwesthackinfest.com/deadwood/cfp/
Call For Papers - Wild West Hackin' Fest in Deadwood

APT34 targets Jordan Government using new Saitama backdoor

https://blog.malwarebytes.com/threat-intelligence/2022/05/apt34-targets-jordan-government-using-new-saitama-backdoor/
APT34 targets Jordan Government using new Saitama backdoor

iPhone Setup for Reversing and Debugging

https://naehrdine.blogspot.com/2022/05/iphone-setup-for-reversing-and-debugging.html
iPhone Setup for Reversing and Debugging

Where To Find Us | SpecterOps

https://ghst.ly/3vl6xtH
Where To Find Us | SpecterOps

CVE-2022-23270 - Windows Server VPN Remote Kernel Use After Free Vulnerability (Part 2) - Nettitude Labs

https://labs.nettitude.com/blog/cve-2022-23270-windows-server-vpn-remote-kernel-use-after-free-vulnerability/
CVE-2022-23270 - Windows Server VPN Remote Kernel Use After Free Vulnerability (Part 2) - Nettitude Labs

PPID Spoofing & BlockDLLs with NtCreateUserProcess - Offensive Defence

https://offensivedefence.co.uk/posts/ntcreateuserprocess/
PPID Spoofing & BlockDLLs with NtCreateUserProcess - Offensive Defence

‘I lost my life savings’: Terra Luna cryptocurrency collapses 98% overnight | The Independent

https://www.independent.co.uk/tech/terra-luna-ust-crypto-price-crash-b2076655.html
‘I lost my life savings’: Terra Luna cryptocurrency collapses 98% overnight | The Independent

MalwareBazaar | SHA256 df0d696632c25d7dc0f18b43ee985e7e4b4b7b7efb79ea0672d07e581c9bd561 (BumbleBee)

https://bazaar.abuse.ch/sample/df0d696632c25d7dc0f18b43ee985e7e4b4b7b7efb79ea0672d07e581c9bd561/
MalwareBazaar | SHA256 df0d696632c25d7dc0f18b43ee985e7e4b4b7b7efb79ea0672d07e581c9bd561 (BumbleBee)

Cisco Talos Intelligence Group - Comprehensive Threat Intelligence: Bitter APT adds Bangladesh to their targets

https://blog.talosintelligence.com/2022/05/bitter-apt-adds-bangladesh-to-their.html
Cisco Talos Intelligence Group - Comprehensive Threat Intelligence: Bitter APT adds Bangladesh to their targets

Joint statement by the President of the Republic and Prime Minister of Finland on Finland's NATO membership - Presidentti

https://www.presidentti.fi/en/press-release/joint-statement-by-the-president-of-the-republic-and-prime-minister-of-finland-on-finlands-nato-membership/
Joint statement by the President of the Republic and Prime Minister of Finland on Finland's NATO membership - Presidentti

Coinbase admits users may lose crypto if exchange goes bankrupt | Fortune

https://fortune.com/2022/05/11/coinbase-bankruptcy-crypto-assets-safe-private-key-earnings-stock/
Coinbase admits users may lose crypto if exchange goes bankrupt | Fortune

SEKTOR7 Institute

https://institute.sektor7.net/?coupon=ICE-SAINTS-19H
SEKTOR7 Institute

GitHub - warhorse/warhorse

https://github.com/warhorse/warhorse
GitHub - warhorse/warhorse

CVE-2022-0573: Artifactory Vulnerable to Deserialization of Untrusted Data - JFrog - JFrog Documentation

https://www.jfrog.com/confluence/display/JFROG/CVE-2022-0573%3A+Artifactory+Vulnerable+to+Deserialization+of+Untrusted+Data
CVE-2022-0573: Artifactory Vulnerable to Deserialization of Untrusted Data - JFrog - JFrog Documentation

#1350653 Remote kernel heap overflow

https://hackerone.com/reports/1350653
#1350653 Remote kernel heap overflow