05/13

The Hidden RCE Surfaces That Control the Droids - Speaker Deck

https://speakerdeck.com/flankerhqd/the-hidden-rce-surfaces-that-control-the-droids
The Hidden RCE Surfaces That Control the Droids - Speaker Deck

Syscall usage · S3cur3Th1sSh1t/SharpImpersonation@137e71d · GitHub

https://github.com/S3cur3Th1sSh1t/SharpImpersonation/commit/137e71d8fa93091f64234e7262b437e0eeb7cefd
Syscall usage · S3cur3Th1sSh1t/SharpImpersonation@137e71d · GitHub

SonicWall ‘strongly urges’ admins to patch SSLVPN SMA1000 bugs

https://www.bleepingcomputer.com/news/security/sonicwall-strongly-urges-admins-to-patch-sslvpn-sma1000-bugs/
SonicWall ‘strongly urges’ admins to patch SSLVPN SMA1000 bugs

| Job Preference

http://www.jobpreference.com
| Job Preference

Hunting evasive vulnerabilities | PortSwigger Research

https://portswigger.net/research/hunting-evasive-vulnerabilities
Hunting evasive vulnerabilities | PortSwigger Research

From Process Injection to Function Hijacking | CyberSecurity Blog

https://klezvirus.github.io/RedTeaming/AV_Evasion/FromInjectionToHijacking/
From Process Injection to Function Hijacking | CyberSecurity Blog

Operation RestyLink: APT campaign targeting Japanese companies, Ryu Hiyoshi

https://insight-jp.nttsecurity.com/post/102hojk/operation-restylink-apt-campaign-targeting-japanese-companies
Operation RestyLink: APT campaign targeting Japanese companies, Ryu Hiyoshi

PPID Spoofing & BlockDLLs with NtCreateUserProcess - Offensive Defence

https://offensivedefence.co.uk/posts/ntcreateuserprocess/
PPID Spoofing & BlockDLLs with NtCreateUserProcess - Offensive Defence

TheGlasshouseCtr - Twitch

https://twitch.tv/TheGlasshouseCtr
TheGlasshouseCtr - Twitch

WatchTower Flash Report | oRAT Malware

https://assets.sentinelone.com/customer-watchtower-white/orat-flash-wt
WatchTower Flash Report | oRAT Malware

a.exe (MD5: 5F53595BF1D56ECD376B76514AC8039E) - Interactive analysis - ANY.RUN

https://app.any.run/tasks/0f901eb5-4689-4fe0-9854-1c7eac8c64cd/#
a.exe (MD5: 5F53595BF1D56ECD376B76514AC8039E) - Interactive analysis - ANY.RUN

404 Page not found | STAR Labs

https://starlabs.sg/blog/2022/05/new-wine-in-old-bottle-microsoft-sharepoint-post-auth-deserialization-rce-cve-2022-29108/
404 Page not found | STAR Labs

Qakbot/Qakbot_AA_13.05.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_AA_13.05.2022.txt
Qakbot/Qakbot_AA_13.05.2022.txt at main · pr0xylife/Qakbot · GitHub

Eternity malware kit offers stealer, miner, worm, ransomware tools

https://www.bleepingcomputer.com/news/security/eternity-malware-kit-offers-stealer-miner-worm-ransomware-tools/
Eternity malware kit offers stealer, miner, worm, ransomware tools

New Saitama backdoor Targeted Official from Jordan's Foreign Ministry

https://thehackernews.com/2022/05/new-saitama-backdoor-targeted-official.html
New Saitama backdoor Targeted Official from Jordan's Foreign Ministry

Malware Analysis Series (MAS) – Article 4 – Exploit Reversing

https://exploitreversing.com/2022/05/12/malware-analysis-series-mas-article-4/
Malware Analysis Series (MAS) – Article 4 – Exploit Reversing

Hacking a Bank by Finding a 0day in DotCMS – Assetnote

https://blog.assetnote.io/2022/05/03/hacking-a-bank-using-dotcms-rce/
Hacking a Bank by Finding a 0day in DotCMS – Assetnote