06/02

Confluence Security Advisory 2022-06-02 | Confluence Data Center and Server 7.19 | Atlassian Documentation

https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html
Confluence Security Advisory 2022-06-02 | Confluence Data Center and Server 7.19 | Atlassian Documentation

Zero-Day Exploitation of Atlassian Confluence | Volexity

https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/
Zero-Day Exploitation of Atlassian Confluence | Volexity

SideWinder.AntiBot.Script

https://blog.group-ib.com/sidewinder-antibot
SideWinder.AntiBot.Script

Using Python to unearth a goldmine of threat intelligence from leaked chat logs - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/06/01/using-python-to-unearth-a-goldmine-of-threat-intelligence-from-leaked-chat-logs/
Using Python to unearth a goldmine of threat intelligence from leaked chat logs - Microsoft Security Blog

WinDealer dealing on the side | Securelist

https://securelist.com/windealer-dealing-on-the-side/105946/
WinDealer dealing on the side | Securelist

New Windows Search zero-day added to Microsoft protocol nightmare

https://www.bleepingcomputer.com/news/security/new-windows-search-zero-day-added-to-microsoft-protocol-nightmare/
New Windows Search zero-day added to Microsoft protocol nightmare

Takedown of SMS-based FluBot spyware infecting Android phones | Europol

https://www.europol.europa.eu/media-press/newsroom/news/takedown-of-sms-based-flubot-spyware-infecting-android-phones
Takedown of SMS-based FluBot spyware infecting Android phones | Europol

CVE-2022-30190: Microsoft Support Diagnostic Tool (MSDT) RCE Vulnerability “Follina” | FortiGuard Labs 

https://www.fortinet.com/blog/threat-research/analysis-of-follina-zero-day
CVE-2022-30190: Microsoft Support Diagnostic Tool (MSDT) RCE Vulnerability “Follina” | FortiGuard Labs 

Exposing POLONIUM activity and infrastructure targeting Israeli organizations - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/06/02/exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/
Exposing POLONIUM activity and infrastructure targeting Israeli organizations - Microsoft Security Blog

WeLeakInfo.to and Related Domain Names Seized | USAO-DC | Department of Justice

https://www.justice.gov/usao-dc/pr/weleakinfoto-and-related-domain-names-seized
WeLeakInfo.to and Related Domain Names Seized | USAO-DC | Department of Justice

ExpressVPN Removes Servers in India After Refusing to Comply with Government Order

https://thehackernews.com/2022/06/expressvpn-removes-servers-in-india.html
ExpressVPN Removes Servers in India After Refusing to Comply with Government Order

Make JDBC Attacks Brilliant Again II

https://pyn3rd.github.io/2022/06/02/Make-JDBC-Attacks-Brilliant-Again/
Make JDBC Attacks Brilliant Again II

To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions | Mandiant

https://www.mandiant.com/resources/unc2165-shifts-to-evade-sanctions
To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions | Mandiant

Domain Seized

http://WeLeakInfo.to
Domain Seized

Clipminer malware gang stole $1.7M by hijacking crypto payments

https://www.bleepingcomputer.com/news/security/clipminer-malware-gang-stole-17m-by-hijacking-crypto-payments/
Clipminer malware gang stole $1.7M by hijacking crypto payments

ZDI-22-806 | Zero Day Initiative

https://www.zerodayinitiative.com/advisories/ZDI-22-806/
ZDI-22-806 | Zero Day Initiative

International Authorities Take Down Flubot Malware Network | Threatpost

https://threatpost.com/international-authorities-take-down-flubot-malware-network/179825/
International Authorities Take Down Flubot Malware Network | Threatpost

Enumeration and lateral movement in GCP environments | by Security Shenanigans | InfoSec Write-ups

https://securityshenanigans.medium.com/enumeration-and-lateral-movement-in-gcp-environments-c3b82d342794
Enumeration and lateral movement in GCP environments | by Security Shenanigans | InfoSec Write-ups

Researchers Demonstrate Ransomware for IoT Devices That Targets IT and OT Networks

https://thehackernews.com/2022/06/researchers-demonstrate-ransomware-for.html
Researchers Demonstrate Ransomware for IoT Devices That Targets IT and OT Networks

Foxconn confirms ransomware attack disrupted production in Mexico

https://www.bleepingcomputer.com/news/security/foxconn-confirms-ransomware-attack-disrupted-production-in-mexico/
Foxconn confirms ransomware attack disrupted production in Mexico

Binary Defense - Threat Researcher/Hunter (remote)

https://recruiting.paylocity.com/recruiting/jobs/Details/561129/Binary-Defense/Threat-ResearcherHunter-remote
Binary Defense - Threat Researcher/Hunter (remote)

DOJ Seizes 3 Web Domains Used to Sell Stolen Data and DDoS Services

https://thehackernews.com/2022/06/doj-seizes-3-web-domains-used-to-sell.html
DOJ Seizes 3 Web Domains Used to Sell Stolen Data and DDoS Services

Zero Day Initiative — Is exploiting a null pointer deref for LPE just a pipe dream?

https://www.zerodayinitiative.com/blog/2022/6/1/is-exploiting-a-null-pointer-deref-for-lpe-just-a-pipe-dream
Zero Day Initiative — Is exploiting a null pointer deref for LPE just a pipe dream?

Hatching Triage | Behavioral Report

https://tria.ge/220602-yjvvcabad9/behavioral4#report
Hatching Triage | Behavioral Report