Apple expands commitment to protect users from mercenary spyware - Apple
https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/
Account hijacking using "dirty dancing" in sign-in OAuth-flows - Detectify Labs
https://labs.detectify.com/2022/07/06/account-hijacking-using-dirty-dancing-in-sign-in-oauth-flows/
2271 - Windows: Kerberos Redirected Logon Buffer EoP - project-zero
https://bugs.chromium.org/p/project-zero/issues/detail?id=2271
Abusing functionality to exploit a super SSRF in Jira Server (CVE-2022-26135) – Assetnote
https://blog.assetnote.io/2022/06/26/exploiting-ssrf-in-jira/
talks/unorthodox-lateral-movement.pdf at master · RiccardoAncarani/talks · GitHub
https://github.com/RiccardoAncarani/talks/blob/master/F-Secure/unorthodox-lateral-movement.pdf
Brute Ratel C4 Red Teaming Tool Being Abused by Malicious Actors
https://unit42.paloaltonetworks.com/brute-ratel-c4-tool/
GitHub - citronneur/pamspy: Credentials Dumper for Linux using eBPF
https://github.com/citronneur/pamspy
GitHub - xforcered/BokuLoader: Cobalt Strike User-Defined Reflective Loader written in Assembly & C for advanced evasion capabilities.
https://github.com/xforcered/BokuLoader
Game Of Active Directory v2 | Mayfly
https://mayfly277.github.io/posts/GOADv2/
Threat report: Maui ransomware - Stairwell
https://stairwell.com/news/threat-research-report-maui-ransomware/
A Diamond (Ticket) in the Ruff | Semperis
https://www.semperis.com/blog/a-diamond-ticket-in-the-ruff/
Reversing Malware How is APT 29 Successful w/ this Phishing Tech and BRc4 (Brute Ratel) opsec fails? - YouTube
https://www.youtube.com/watch?v=a7W6rhkpVSM
Hive Ransomware Upgrades to Rust for More Sophisticated Encryption Method
https://thehackernews.com/2022/07/hive-ransomware-upgrades-to-rust-for.html
Bitter APT Hackers Continue to Target Bangladesh Military Entities
https://thehackernews.com/2022/07/bitter-apt-hackers-continue-to-target.html
MalwareBazaar | SHA256 3bb0e8547e8c04387ae9cf9ea4beceb76efb5cc59fcdb750d25172b9b2efb6af (IcedID)
https://bazaar.abuse.ch/sample/3bb0e8547e8c04387ae9cf9ea4beceb76efb5cc59fcdb750d25172b9b2efb6af/
Hatching Triage | Behavioral Report
https://tria.ge/220706-wl7wkshgg2/behavioral1
OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow
https://www.intezer.com/blog/incident-response/orbit-new-undetected-linux-threat/
One I/O Ring to Rule Them All: A Full Read/Write Exploit Primitive on Windows 11 – Winsider Seminars & Solutions Inc.
https://windows-internals.com/one-i-o-ring-to-rule-them-all-a-full-read-write-exploit-primitive-on-windows-11/
Learn Node.js - Full Tutorial for Beginners - YouTube
https://www.youtube.com/watch?v=RLtyhwFtXQA
GitHub - romainthomas/the-poor-mans-obfuscator: Binary & scripts associated with "The Poor Man's Obfuscator" presentation
https://github.com/romainthomas/the-poor-mans-obfuscator
Malware Analysis and Reverse Engineering Workflow | Malware Hell
https://c3rb3ru5d3d53c.github.io/documents/malware-analysis-reversing-workflow/
Python Django Web Framework - Full Course for Beginners - YouTube
https://www.youtube.com/watch?v=F5mRW0jo-U4
Learn JavaScript - Full Course for Beginners - YouTube
https://www.youtube.com/watch?v=PkZNo7MFNFg
Learn Ruby on Rails - Full Course - YouTube
https://www.youtube.com/watch?v=fmyvWz5TUWg
PHP Programming Language Tutorial - Full Course - YouTube
https://www.youtube.com/watch?v=OK_JCtrrv-c
Chrome Releases: Stable Channel Update for Desktop
https://chromereleases.googleblog.com/2022/07/stable-channel-update-for-desktop.html
Apple Announces 'Extreme' Privacy Mode for Targets of Government Spyware
https://www.vice.com/en/article/88qnag/apple-announces-extreme-privacy-mode-for-targets-of-government-spyware
https://www.openssl.org/news/secadv/20220705.txt
https://www.openssl.org/news/secadv/20220705.txt
New RedAlert Ransomware targets Windows, Linux VMware ESXi servers
https://www.bleepingcomputer.com/news/security/new-redalert-ransomware-targets-windows-linux-vmware-esxi-servers/
OpenSSL Releases Patch for High-Severity Bug that Could Lead to RCE Attacks
https://thehackernews.com/2022/07/openssl-releases-patch-for-high.html
Security advisory accidentally exposes vulnerable systems
https://www.bleepingcomputer.com/news/security/security-advisory-accidentally-exposes-vulnerable-systems/
Romain Thomas
https://www.romainthomas.fr/publication/22-pst-the-poor-mans-obfuscator
ware70.pdf
https://csrc.nist.gov/csrc/media/publications/conference-paper/1998/10/08/proceedings-of-the-21st-nissc-1998/documents/early-cs-papers/ware70.pdf