06/15

Hertzbleed Attack

https://www.hertzbleed.com/
Hertzbleed Attack

Interpol seizes $50 million, arrests 2000 social engineers

https://www.bleepingcomputer.com/news/security/interpol-seizes-50-million-arrests-2000-social-engineers/
Interpol seizes $50 million, arrests 2000 social engineers

Zimbra Email - Stealing Clear-Text Credentials via Memcache injection

https://blog.sonarsource.com/zimbra-mail-stealing-clear-text-credentials-via-memcache-injection/
Zimbra Email - Stealing Clear-Text Credentials via Memcache injection

GreyNoise to expand its threat intel collection after securing $15M in funding | TechCrunch

https://techcrunch.com/2022/06/15/greynoise-threat-intel-funding/
GreyNoise to expand its threat intel collection after securing $15M in funding | TechCrunch

2277 - XNU: Flow Divert Race Condition Use After Free - project-zero

https://bugs.chromium.org/p/project-zero/issues/detail?id=2277
2277 - XNU: Flow Divert Race Condition Use After Free - project-zero

Pulling MikroTik into the Limelight | Margin Research

https://margin.re/blog/pulling-mikrotik-into-the-limelight.aspx
Pulling MikroTik into the Limelight | Margin Research

PSBits/NetstatWithTimestamps at master · gtworek/PSBits · GitHub

https://github.com/gtworek/PSBits/tree/master/NetstatWithTimestamps
PSBits/NetstatWithTimestamps at master · gtworek/PSBits · GitHub

Red Team Ops

https://training.zeropointsecurity.co.uk/courses/red-team-ops
Red Team Ops

DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach | Volexity

https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach | Volexity

Bypassing CSP with dangling iframes | PortSwigger Research

https://portswigger.net/research/bypassing-csp-with-dangling-iframes
Bypassing CSP with dangling iframes | PortSwigger Research

New Hertzbleed Side Channel Attack Affects All Modern AMD and Intel CPUs

https://thehackernews.com/2022/06/new-hertzbleed-side-channel-attack.html
New Hertzbleed Side Channel Attack Affects All Modern AMD and Intel CPUs

Ransomware gang creates site for employees to search for their stolen data

https://www.bleepingcomputer.com/news/security/ransomware-gang-creates-site-for-employees-to-search-for-their-stolen-data/
Ransomware gang creates site for employees to search for their stolen data

VirusTotal - File - c61fe40f46226d24f0f17c46acc4db6a0091c68abc6a3d995b3f6df1bbfcbb1e

https://www.virustotal.com/gui/file/c61fe40f46226d24f0f17c46acc4db6a0091c68abc6a3d995b3f6df1bbfcbb1e/detection
VirusTotal - File - c61fe40f46226d24f0f17c46acc4db6a0091c68abc6a3d995b3f6df1bbfcbb1e

IoCs/Troj-Miner-AED.csv at master · sophoslabs/IoCs · GitHub

https://github.com/sophoslabs/IoCs/blob/master/Troj-Miner-AED.csv
IoCs/Troj-Miner-AED.csv at master · sophoslabs/IoCs · GitHub

VirusTotal - File - 52b48c4b2f4a63fc6611dea7e9146a440d41e306143788ea20c56c3ab292cf00

https://www.virustotal.com/gui/file/52b48c4b2f4a63fc6611dea7e9146a440d41e306143788ea20c56c3ab292cf00/detection
VirusTotal - File - 52b48c4b2f4a63fc6611dea7e9146a440d41e306143788ea20c56c3ab292cf00

Research Paper | Emulating Phineas Phisher Attacks in Modern EDR Environments - SentinelOne

https://www.sentinelone.com/blog/research-paper-emulating-phineas-phisher-attacks-in-modern-edr-environments/
Research Paper | Emulating Phineas Phisher Attacks in Modern EDR Environments - SentinelOne

Akamai Blog | Panchan’s Mining Rig: New Golang Peer-to-Peer Botnet Says “Hi!”

https://www.akamai.com/blog/security/new-p2p-botnet-panchan
Akamai Blog | Panchan’s Mining Rig: New Golang Peer-to-Peer Botnet Says “Hi!”

Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup

https://doar-e.github.io/blog/2022/06/11/pwn2own-2021-canon-imageclass-mf644cdw-writeup/
Pwn2Own 2021 Canon ImageCLASS MF644Cdw writeup

Cisco Secure Email bug can let attackers bypass authentication

https://www.bleepingcomputer.com/news/security/cisco-secure-email-bug-can-let-attackers-bypass-authentication/
Cisco Secure Email bug can let attackers bypass authentication

Telerik UI exploitation leads to cryptominer, Cobalt Strike infections – Sophos News

https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections/
Telerik UI exploitation leads to cryptominer, Cobalt Strike infections – Sophos News

Zero Day Initiative — CVE-2022-26937: Microsoft Windows Network File System NLM Portmap Stack Buffer Overflow

https://www.zerodayinitiative.com/blog/2022/6/7/cve-2022-26937-microsoft-windows-network-file-system-nlm-portmap-stack-buffer-overflow
Zero Day Initiative — CVE-2022-26937: Microsoft Windows Network File System NLM Portmap Stack Buffer Overflow