06/14

Zimbra Email - Stealing Clear-Text Credentials via Memcache injection

https://blog.sonarsource.com/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/
Zimbra Email - Stealing Clear-Text Credentials via Memcache injection

Hertzbleed Attack

https://www.hertzbleed.com/
Hertzbleed Attack

Project Zero: An Autopsy on a Zombie In-the-Wild 0-day

https://googleprojectzero.blogspot.com/2022/06/an-autopsy-on-zombie-in-wild-0-day.html
Project Zero: An Autopsy on a Zombie In-the-Wild 0-day

Iranian Spear-Phishing Operation Targets Former Israeli and US High-Ranking Officials - Check Point Research

https://research.checkpoint.com/2022/check-point-research-exposes-an-iranian-phishing-campaign-targeting-former-israeli-foreign-minister-former-us-ambassador-idf-general-and-defense-industry-executives/
Iranian Spear-Phishing Operation Targets Former Israeli and US High-Ranking Officials - Check Point Research

The many lives of BlackCat ransomware - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/06/13/the-many-lives-of-blackcat-ransomware/
The many lives of BlackCat ransomware - Microsoft Security Blog

What caused B.C. power outage? | CTV News

https://bc.ctvnews.ca/single-beaver-caused-mass-internet-cell-service-outages-in-northern-b-c-1.5944697
What caused B.C. power outage? | CTV News

Unpatched Travis CI API Bug Exposes Thousands of Secret User Access Tokens

https://thehackernews.com/2022/06/unpatched-travis-ci-api-bug-exposes.html
Unpatched Travis CI API Bug Exposes Thousands of Secret User Access Tokens

BumbleBee: a new trendy loader for Initial Access Brokers - SEKOIA.IO Blog

https://blog.sekoia.io/bumblebee-a-new-trendy-loader-for-initial-access-brokers/
BumbleBee: a new trendy loader for Initial Access Brokers - SEKOIA.IO Blog

Bypassing CSP with dangling iframes | PortSwigger Research

https://portswigger.net/research/bypassing-csp-with-dangling-iframes
Bypassing CSP with dangling iframes | PortSwigger Research

CVE-2022-1040 Sophos XG Firewall Authentication bypass

https://blog.viettelcybersecurity.com/cve-2022-1040-sophos-xg-firewall-authentication-bypass/
CVE-2022-1040 Sophos XG Firewall Authentication bypass

UNITED STATES/ISRAEL : L3's plan to acquire Israeli cyber specialist NSO - 14/06/2022 - Intelligence Online

https://www.intelligenceonline.com/international-dealmaking/2022/06/14/l3-s-plan-to-acquire-israeli-cyber-specialist-nso,109791908-eve
UNITED STATES/ISRAEL : L3's plan to acquire Israeli cyber specialist NSO - 14/06/2022 - Intelligence Online

Malware Analysis CTF

https://cet.ctfd.io/register
Malware Analysis CTF

3 Key Components of Researcher Submission Templates | @Bugcrowd

https://www.bugcrowd.com/blog/3-key-components-of-researcher-submission-templates/
3 Key Components of Researcher Submission Templates | @Bugcrowd

IcedID_06_14_2022.txt · GitHub

https://gist.github.com/myrtus0x0/8a96d35196f0725101d4a47c27909a15
IcedID_06_14_2022.txt · GitHub

VirusTotal - File - 19408d64c6df49e57cc05ff83c79662eb7aa138823c32b1945cec79d823150ce

https://www.virustotal.com/gui/file/19408d64c6df49e57cc05ff83c79662eb7aa138823c32b1945cec79d823150ce/detection
VirusTotal - File - 19408d64c6df49e57cc05ff83c79662eb7aa138823c32b1945cec79d823150ce

Follina CVE-2022-30190 Detection with THOR and Aurora - Nextron Systems

https://www.nextron-systems.com/2022/06/13/follina-detection-with-thor-and-aurora/
Follina CVE-2022-30190 Detection with THOR and Aurora - Nextron Systems

IcedID_06_14_2022_2.txt · GitHub

https://gist.github.com/myrtus0x0/cdbf5318b878f88aeb6089866e6aea54
IcedID_06_14_2022_2.txt · GitHub

Hatching Triage | Behavioral Report

https://tria.ge/220614-kd2h2schfp/behavioral1
Hatching Triage | Behavioral Report

Hatching Triage | Behavioral Report

https://tria.ge/220614-wfjlssgcgq/behavioral1
Hatching Triage | Behavioral Report

Cyrill Gössi - YouTube

https://www.youtube.com/channel/UCp1rLlh9AQN9Pejzbg9dcAg/videos
Cyrill Gössi - YouTube

Russian hackers start targeting Ukraine with Follina exploits

https://www.bleepingcomputer.com/news/security/russian-hackers-start-targeting-ukraine-with-follina-exploits/
Russian hackers start targeting Ukraine with Follina exploits

Windows Updates Patch Actively Exploited 'Follina' Vulnerability | SecurityWeek.Com

https://www.securityweek.com/windows-updates-patch-actively-exploited-follina-vulnerability
Windows Updates Patch Actively Exploited 'Follina' Vulnerability | SecurityWeek.Com

abuse.ch | Introducing YARAify

https://abuse.ch/blog/introducing-yaraify/
abuse.ch | Introducing YARAify

IcedID_06_13_2022.txt · GitHub

https://gist.github.com/myrtus0x0/c7c49829affe8c88915b9590a38bbce0
IcedID_06_13_2022.txt · GitHub

AMFI Launch Constraints - First Quick Look · theevilbit blog

https://theevilbit.github.io/posts/amfi_launch_constraints/
AMFI Launch Constraints - First Quick Look · theevilbit blog

Coinbase Cuts Employees’ Access to Work Email, Docs Before Laying Them Off

https://www.vice.com/en/article/pkge7z/coinbase-cuts-employees-access-to-work-email-docs-before-laying-them-off
Coinbase Cuts Employees’ Access to Work Email, Docs Before Laying Them Off

Technical Details Released for 'SynLapse' RCE Vulnerability Reported in Microsoft Azure

https://thehackernews.com/2022/06/technical-details-released-for-synlapse.html
Technical Details Released for 'SynLapse' RCE Vulnerability Reported in Microsoft Azure

Metasploit 6.2.0 improves credential theft, SMB support features, more

https://www.bleepingcomputer.com/news/security/metasploit-620-improves-credential-theft-smb-support-features-more/
Metasploit 6.2.0 improves credential theft, SMB support features, more

New Syslogk Linux Rootkit Lets Attackers Remotely Command It Using "Magic Packets"

https://thehackernews.com/2022/06/new-syslogk-linux-rootkit-lets.html
New Syslogk Linux Rootkit Lets Attackers Remotely Command It Using "Magic Packets"

GitHub - abusech/YARAify: YARAify

https://github.com/abusech/YARAify
GitHub - abusech/YARAify: YARAify

HyperDbg’s One Thousand and One Nights | Rayanfam Blog

https://rayanfam.com/topics/hyperdbg-one-thousand-and-one-nights/
HyperDbg’s One Thousand and One Nights | Rayanfam Blog