05/30

Follina — a Microsoft Office code execution vulnerability | by Kevin Beaumont | DoublePulsar

https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e
Follina — a Microsoft Office code execution vulnerability | by Kevin Beaumont | DoublePulsar

VirusTotal - File - 4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784

https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection
VirusTotal - File - 4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784

The MS-MSDT 0-day Office RCE Proof-of-Concept Payload Building Process · GitHub

https://gist.github.com/tothi/66290a42896a97920055e50128c9f040
The MS-MSDT 0-day Office RCE Proof-of-Concept Payload Building Process · GitHub

Rapid Response: Microsoft Office RCE - “Follina” MSDT Attack

https://www.huntress.com/blog/microsoft-office-remote-code-execution-follina-msdt-bug
Rapid Response: Microsoft Office RCE - “Follina” MSDT Attack

Didier Stevens on Twitter: "FYI: https://t.co/t3ORRGaAnD" / Twitter

https://twitter.com/DidierStevens/status/1531033449561264128
Didier Stevens on Twitter: "FYI: https://t.co/t3ORRGaAnD" / Twitter

Watch Out! Researchers Spot New Microsoft Office Zero-Day Exploit in the Wild

https://thehackernews.com/2022/05/watch-out-researchers-spot-new.html
Watch Out! Researchers Spot New Microsoft Office Zero-Day Exploit in the Wild

New Microsoft Office zero-day used in attacks to execute PowerShell

https://www.bleepingcomputer.com/news/security/new-microsoft-office-zero-day-used-in-attacks-to-execute-powershell/
New Microsoft Office zero-day used in attacks to execute PowerShell

Space / Twitter

https://twitter.com/i/spaces/1ynJOZRDVrqGR
Space / Twitter

EnemyBot Linux Botnet Now Exploits Web Server, Android and CMS Vulnerabilities

https://thehackernews.com/2022/05/enemybot-linux-botnet-now-exploits-web.html
EnemyBot Linux Botnet Now Exploits Web Server, Android and CMS Vulnerabilities

New 'GoodWill' Ransomware Forces Victims to Donate Money and Clothes to the Poor

https://thehackernews.com/2022/05/new-goodwill-ransomware-forces-victims.html
New 'GoodWill' Ransomware Forces Victims to Donate Money and Clothes to the Poor

Bug Bounty Evolution: Not Your Grandson's Bug Bounty - Black Hat USA 2022 | Briefings Schedule

https://www.blackhat.com/us-22/briefings/schedule/#bug-bounty-evolution-not-your-grandsons-bug-bounty-27543
Bug Bounty Evolution: Not Your Grandson's Bug Bounty - Black Hat USA 2022 | Briefings Schedule

GitHub - Cracked5pider/KaynStrike: UDRL for CS

https://github.com/Cracked5pider/KaynStrike
GitHub - Cracked5pider/KaynStrike: UDRL for CS

MISP 2.4.159 released with many improvements including performance

https://www.misp-project.org/2022/05/30/MISP.2.4.159.released.html/
MISP 2.4.159 released with many improvements including performance

Troubleshooting: Allow users to access and run Troubleshooting Wizards

https://admx.help/?Category=Windows_10_2016&Policy=Microsoft.Policies.ScriptedDiagnostics::ScriptedDiagnosticsExecutionPolicy
Troubleshooting: Allow users to access and run Troubleshooting Wizards

SCYTHE Library: Breaking: Follina (MSDT) Vulnerability

https://www.scythe.io/library/breaking-follina-msdt-vulnerability
SCYTHE Library: Breaking: Follina (MSDT) Vulnerability