Koh: The Token Stealer. Edit 07/13/22: After an awesome back… | by Will Schroeder | Jul, 2022 | Posts By SpecterOps Team Members
https://posts.specterops.io/koh-the-token-stealer-41ca07a40ed6
GitHub - GhostPack/Koh: The Token Stealer
https://github.com/GhostPack/Koh
This Is the Code the FBI Used to Wiretap the World
https://www.vice.com/en/article/v7veg8/anom-app-source-code-operation-trojan-shield-an0m
Automating binary vulnerability discovery with Ghidra and Semgrep - hn security
https://security.humanativaspa.it/automating-binary-vulnerability-discovery-with-ghidra-and-semgrep/
Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine
https://securityintelligence.com/posts/trickbot-group-systematically-attacking-ukraine/
Microsoft rolls back decision to block Office macros by default
https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-back-decision-to-block-office-macros-by-default/
Altiris Methods for Lateral Movement - MDSec
https://www.mdsec.co.uk/2022/07/altiris-methods-for-lateral-movement/
YamaBot Malware Used by Lazarus - JPCERT/CC Eyes | JPCERT Coordination Center official Blog
https://blogs.jpcert.or.jp/en/2022/07/yamabot.html
GitHub - p0dalirius/Coercer: A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 9 methods.
https://github.com/p0dalirius/Coercer
Apple expands commitment to protect users from mercenary spyware - Apple
https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/
GitHub - mandiant/route-sixty-sink: Link sources to sinks in C# applications.
https://github.com/mandiant/route-sixty-sink
2273 - Windows: Kerberos KerbRetrieveEncodedTicketMessage AppContainer EoP - project-zero
https://bugs.chromium.org/p/project-zero/issues/detail?id=2273
Researchers Warn of New OrBit Linux Malware That Hijacks Execution Flow
https://thehackernews.com/2022/07/researchers-warn-of-new-orbit-linux.html
Get Your Kicks on Route Sixty-Sink: Identifying Vulnerabilities Using Automated Static Analysis | Mandiant
https://www.mandiant.com/resources/route-sixty-sink-launch
PrivFu/SeBackupPrivilegePoC.cs at main · daem0nc0re/PrivFu · GitHub
https://github.com/daem0nc0re/PrivFu/blob/main/PrivilegedOperations/SeBackupPrivilegePoC/SeBackupPrivilegePoC.cs
GitHub - xforcered/BokuLoader: Cobalt Strike User-Defined Reflective Loader written in Assembly & C for advanced evasion capabilities.
https://github.com/xforcered/BokuLoader
ENISA Threat Landscape Methodology — ENISA
https://www.enisa.europa.eu/publications/enisa-threat-landscape-methodology
BleepingComputer on Twitter: "Microsoft rolls back decision to block Office macros by default - @serghei https://t.co/9BK0slNuEw" / Twitter
https://twitter.com/BleepinComputer/status/1545174259487621122
North Korean Maui Ransomware Actively Targeting U.S. Healthcare Organizations
https://thehackernews.com/2022/07/north-korean-maui-ransomware-actively.html
Account hijacking using "dirty dancing" in sign-in OAuth-flows - Detectify Labs
https://labs.detectify.com/2022/07/06/account-hijacking-using-dirty-dancing-in-sign-in-oauth-flows/
Hunting Zero Days in Embedded Devices (by Flashback Team)
http://training.flashback.sh
MalwareBazaar | SHA256 a7210d9c96813885238dcd4c7d6a6c08cb41220c65d7ce547ec17fde959d233e (Gozi)
https://bazaar.abuse.ch/sample/a7210d9c96813885238dcd4c7d6a6c08cb41220c65d7ce547ec17fde959d233e/
InfoSec Handlers Diary Blog - SANS Internet Storm Center
https://i5c.us/d28824
VirusTotal - File - 6d4e5e60b4f6cbc8a6e14343b59c406fe5c7f948aded16d23a0f6ed6984907c2
https://www.virustotal.com/gui/file/6d4e5e60b4f6cbc8a6e14343b59c406fe5c7f948aded16d23a0f6ed6984907c2
Rolling PWN
https://rollingpwn.github.io/rolling-pwn/
Quantum ransomware attack affects 657 healthcare orgs
https://www.bleepingcomputer.com/news/security/quantum-ransomware-attack-affects-657-healthcare-orgs/
OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow
https://www.intezer.com/blog/incident-response/orbit-new-undetected-linux-threat/
Polish PM claims Russia hacked, tweaked, leaked govt emails | AP News
https://apnews.com/article/russia-ukraine-poland-judiciary-warsaw-a4e37e00c14e337f853ec1c9384d4b26
VBA-macro-experiments/kerberoast.vba at main · Adepts-Of-0xCC/VBA-macro-experiments · GitHub
https://github.com/Adepts-Of-0xCC/VBA-macro-experiments/blob/main/kerberoast.vba
Gareth Heyes
https://garethheyes.co.uk
Over 1,200 NPM Packages Found Involved in "CuteBoi" Cryptomining Campaign
https://thehackernews.com/2022/07/over-1200-npm-packages-found-involved.html
Security advisory accidentally exposes vulnerable systems
https://www.bleepingcomputer.com/news/security/security-advisory-accidentally-exposes-vulnerable-systems/