07/03

Microsoft finds Raspberry Robin worm in hundreds of Windows networks

https://www.bleepingcomputer.com/news/security/microsoft-finds-raspberry-robin-worm-in-hundreds-of-windows-networks/
Microsoft finds Raspberry Robin worm in hundreds of Windows networks

Release 5.3.0 - Operation C01NS · Porchetta-Industries/CrackMapExec · GitHub

https://github.com/Porchetta-Industries/CrackMapExec/releases/tag/v5.3.0
Release 5.3.0 - Operation C01NS · Porchetta-Industries/CrackMapExec · GitHub

Penetration-Testing-Tools/Handy-BloodHound-Cypher-Queries.md at master · mgeeky/Penetration-Testing-Tools · GitHub

https://github.com/mgeeky/Penetration-Testing-Tools/blob/master/red-teaming/bloodhound/Handy-BloodHound-Cypher-Queries.md
Penetration-Testing-Tools/Handy-BloodHound-Cypher-Queries.md at master · mgeeky/Penetration-Testing-Tools · GitHub

nday exploit: netgear orbi unauthenticated command injection (CVE-2020-27861) | hyprblog

https://blog.coffinsec.com/research/2022/07/02/orbi-nday-exploit-cve-2020-27861.html
nday exploit: netgear orbi unauthenticated command injection (CVE-2020-27861) | hyprblog

Rogue HackerOne employee steals bug reports to sell on the side

https://www.bleepingcomputer.com/news/security/rogue-hackerone-employee-steals-bug-reports-to-sell-on-the-side/
Rogue HackerOne employee steals bug reports to sell on the side

Verified Twitter accounts hacked to send fake suspension notices

https://www.bleepingcomputer.com/news/security/verified-twitter-accounts-hacked-to-send-fake-suspension-notices/
Verified Twitter accounts hacked to send fake suspension notices

NahamSec - Twitch

https://www.twitch.tv/nahamsec
NahamSec - Twitch

GitHub - Wh04m1001/IDiagnosticProfileUAC

https://github.com/Wh04m1001/IDiagnosticProfileUAC
GitHub - Wh04m1001/IDiagnosticProfileUAC

AMSI Unchained: Review of Known AMSI Bypass Techniques and Introducing a New One - Black Hat Asia 2022 | Briefings Schedule

https://www.blackhat.com/asia-22/briefings/schedule/#amsi-unchained-review-of-known-amsi-bypass-techniques-and-introducing-a-new-one-26120
AMSI Unchained: Review of Known AMSI Bypass Techniques and Introducing a New One - Black Hat Asia 2022 | Briefings Schedule

Did You Know Your Browser’s Autofill Credentials Could Be Stolen via Cross-Site Scripting (XSS) - GoSecure

https://www.gosecure.net/blog/2022/06/29/did-you-know-your-browsers-autofill-credentials-could-be-stolen-via-cross-site-scripting-xss/
Did You Know Your Browser’s Autofill Credentials Could Be Stolen via Cross-Site Scripting (XSS) - GoSecure