07/08

Microsoft rolls back decision to block Office macros by default

https://www.bleepingcomputer.com/news/microsoft/microsoft-rolls-back-decision-to-block-office-macros-by-default/
Microsoft rolls back decision to block Office macros by default

GitHub - GhostPack/Koh: The Token Stealer

https://github.com/GhostPack/Koh
GitHub - GhostPack/Koh: The Token Stealer

AstraLocker decryptor - Emsisoft: Free Ransomware Decryption Tools

https://www.emsisoft.com/ransomware-decryption-tools/astralocker
AstraLocker decryptor - Emsisoft: Free Ransomware Decryption Tools

MalwareBazaar | agencijazaregistraciju-rs

https://bazaar.abuse.ch/browse/tag/agencijazaregistraciju-rs/
MalwareBazaar | agencijazaregistraciju-rs

Acquisition News and Detection Updates

https://hatching.io/blog/acquisition-recorded-future/
Acquisition News and Detection Updates

Talks

https://o365blog.com/talks/
Talks

Microsoft Defender for Endpoint Internals 0x03 — MDE telemetry unreliability and log augmentation | by Olaf Hartong | FalconForce | Jul, 2022 | Medium

https://medium.com/falconforce/microsoft-defender-for-endpoint-internals-0x03-mde-telemetry-unreliability-and-log-augmentation-ec6e7e5f406f?source=friends_link&sk=568408658cb80770d2ed7ca8a415351c
Microsoft Defender for Endpoint Internals 0x03 — MDE telemetry unreliability and log augmentation | by Olaf Hartong | FalconForce | Jul, 2022 | Medium

Qakbot/Qakbot_obama199_08.07.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_obama199_08.07.2022.txt
Qakbot/Qakbot_obama199_08.07.2022.txt at main · pr0xylife/Qakbot · GitHub

MalwareBazaar | SHA256 1beb6f15f403fe31392012b506ce1bb38424482d3e8123f0f80ae439484fffe7 (Quakbot)

https://bazaar.abuse.ch/sample/1beb6f15f403fe31392012b506ce1bb38424482d3e8123f0f80ae439484fffe7/
MalwareBazaar | SHA256 1beb6f15f403fe31392012b506ce1bb38424482d3e8123f0f80ae439484fffe7 (Quakbot)

MalwareBazaar | SHA256 1a1cce1534108d04037119a579d9cd567d7308af65677234dce8e7a0b4b83eea (Quakbot)

https://bazaar.abuse.ch/sample/1a1cce1534108d04037119a579d9cd567d7308af65677234dce8e7a0b4b83eea/
MalwareBazaar | SHA256 1a1cce1534108d04037119a579d9cd567d7308af65677234dce8e7a0b4b83eea (Quakbot)

Automating binary vulnerability discovery with Ghidra and Semgrep - hn security

https://security.humanativaspa.it/automating-binary-vulnerability-discovery-with-ghidra-and-semgrep/
Automating binary vulnerability discovery with Ghidra and Semgrep - hn security

TrickBot Gang Shifted its Focus on "Systematically" Targeting Ukraine

https://thehackernews.com/2022/07/trickbot-malware-shifted-its-focus-on.html
TrickBot Gang Shifted its Focus on "Systematically" Targeting Ukraine

Free decryptor released for AstraLocker, Yashma ransomware victims

https://www.bleepingcomputer.com/news/security/free-decryptor-released-for-astralocker-yashma-ransomware-victims/
Free decryptor released for AstraLocker, Yashma ransomware victims

Tweet / Twitter

https://twitter.com/gossithedog/status/1545193161974218752
Tweet / Twitter