06/16

DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach | Volexity

https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach/
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach | Volexity

Police Linked to Hacking Campaign to Frame Indian Activists | WIRED

https://www.wired.com/story/modified-elephant-planted-evidence-hacking-police/
Police Linked to Hacking Campaign to Frame Indian Activists | WIRED

AIVD disrupts activities of Russian intelligence officer targeting the International Criminal Court | News item | AIVD

https://english.aivd.nl/latest/news/2022/06/16/aivd-disrupts-activities-of-russian-intelligence-officer-targeting-the-international-criminal-court
AIVD disrupts activities of Russian intelligence officer targeting the International Criminal Court | News item | AIVD

Obeleu - Google マップ

https://goo.gl/maps/7oCnRZJDzhLscao49
Obeleu - Google マップ

Shadow Credentials - Red Teaming Experiments

https://www.ired.team/offensive-security-experiments/active-directory-kerberos-abuse/shadow-credentials
Shadow Credentials - Red Teaming Experiments

Guide to Reversing and Exploiting iOS binaries Part 2: ARM64 ROP Chains

https://www.inversecos.com/2022/06/guide-to-reversing-and-exploiting-ios.html
Guide to Reversing and Exploiting iOS binaries Part 2: ARM64 ROP Chains

fred's notes – Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu

https://fredericb.info/2022/06/breaking-secure-boot-on-google-nest-hub-2nd-gen-to-run-ubuntu.html
fred's notes – Breaking Secure Boot on Google Nest Hub (2nd Gen) to run Ubuntu

VirusTotal - File - 2bc598361c057879174a09c0833ef223225124d6745df5615a7a1a9c6d273f4c

https://www.virustotal.com/gui/file/2bc598361c057879174a09c0833ef223225124d6745df5615a7a1a9c6d273f4c/detection
VirusTotal - File - 2bc598361c057879174a09c0833ef223225124d6745df5615a7a1a9c6d273f4c

VirusTotal - File - 6ddab79a6d836f9c1ed9ab3bbe28a074c0c93bd87f55144ed62b23c0032715d1

https://www.virustotal.com/gui/file/6ddab79a6d836f9c1ed9ab3bbe28a074c0c93bd87f55144ed62b23c0032715d1/detection
VirusTotal - File - 6ddab79a6d836f9c1ed9ab3bbe28a074c0c93bd87f55144ed62b23c0032715d1

2277 - XNU: Flow Divert Race Condition Use After Free - project-zero

https://bugs.chromium.org/p/project-zero/issues/detail?id=2277
2277 - XNU: Flow Divert Race Condition Use After Free - project-zero

Hang Fire: Challenging our Mental Model of Initial Access | by Matt Hand | Jun, 2022 | Posts By SpecterOps Team Members

https://posts.specterops.io/hang-fire-challenging-our-mental-model-of-initial-access-513c71878767
Hang Fire: Challenging our Mental Model of Initial Access | by Matt Hand | Jun, 2022 | Posts By SpecterOps Team Members

Hatching Triage | Behavioral Report

https://tria.ge/220616-npjddseefk/behavioral1
Hatching Triage | Behavioral Report

CISA’s Easterly Calls for Closing the Cyber Gender Gap | FedTech Magazine

https://fedtechmagazine.com/article/2022/06/cisas-easterly-calls-closing-cyber-gender-gap
CISA’s Easterly Calls for Closing the Cyber Gender Gap | FedTech Magazine

GitHub - ufrisk/MemProcFS: MemProcFS

https://github.com/ufrisk/MemProcFS
GitHub - ufrisk/MemProcFS: MemProcFS

High-Severity RCE Vulnerability Reported in Popular Fastjson Library

https://thehackernews.com/2022/06/high-severity-rce-vulnerability.html
High-Severity RCE Vulnerability Reported in Popular Fastjson Library

The Android kernel mitigations obstacle race | The GitHub Blog

https://github.blog/2022-06-16-the-android-kernel-mitigations-obstacle-race/
The Android kernel mitigations obstacle race | The GitHub Blog

SANS Ransomware Summit 2022, Can You Detect This?

https://thedfirreport.com/2022/06/16/sans-ransomware-summit-2022-can-you-detect-this/
SANS Ransomware Summit 2022, Can You Detect This?

SANS-Ransomware-Summit-2022-Can-You-Detect-This.pdf

https://thedfirreport.com/wp-content/uploads/2022/06/SANS-Ransomware-Summit-2022-Can-You-Detect-This.pdf
SANS-Ransomware-Summit-2022-Can-You-Detect-This.pdf

MaliBot: A New Android Banking Trojan Spotted in the Wild

https://thehackernews.com/2022/06/malibot-new-android-banking-trojan.html
MaliBot: A New Android Banking Trojan Spotted in the Wild

MalwareBazaar | SHA256 2d8740ea16e9457a358ebea73ad377ff75f7aa9bdf748f0d801f5a261977eda4 (Matanbuchus)

https://bazaar.abuse.ch/sample/2d8740ea16e9457a358ebea73ad377ff75f7aa9bdf748f0d801f5a261977eda4/
MalwareBazaar | SHA256 2d8740ea16e9457a358ebea73ad377ff75f7aa9bdf748f0d801f5a261977eda4 (Matanbuchus)

New cloud-based Microsoft Defender for home now generally available

https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-for-individuals-now-generally-available/
New cloud-based Microsoft Defender for home now generally available

MalwareBazaar | SHA256 cc08642ddbbb8f735a3263180164cda6cf3b73a490fc742d5c3e31130504e97c (Matanbuchus)

https://bazaar.abuse.ch/sample/cc08642ddbbb8f735a3263180164cda6cf3b73a490fc742d5c3e31130504e97c/
MalwareBazaar | SHA256 cc08642ddbbb8f735a3263180164cda6cf3b73a490fc742d5c3e31130504e97c (Matanbuchus)

PoC/mikrotik_jailbreak.py at master · pedrib/PoC · GitHub

https://github.com/pedrib/PoC/blob/master/tools/mikrotik_jailbreak.py
PoC/mikrotik_jailbreak.py at master · pedrib/PoC · GitHub

VirusTotal - File - ea937d8090b79f5cf3cc068ad868bcee54efd94ad35fea28999433868aec1c3e

https://www.virustotal.com/gui/file/ea937d8090b79f5cf3cc068ad868bcee54efd94ad35fea28999433868aec1c3e
VirusTotal - File - ea937d8090b79f5cf3cc068ad868bcee54efd94ad35fea28999433868aec1c3e

Akamai Blog | Panchan’s Mining Rig: New Golang Peer-to-Peer Botnet Says “Hi!”

https://www.akamai.com/blog/security/new-p2p-botnet-panchan
Akamai Blog | Panchan’s Mining Rig: New Golang Peer-to-Peer Botnet Says “Hi!”