07/19

GitHub - chip-red-pill/MicrocodeDecryptor

https://github.com/chip-red-pill/MicrocodeDecryptor
GitHub - chip-red-pill/MicrocodeDecryptor

Better know a data source: Logon sessions

https://redcanary.com/blog/logon-sessions/
Better know a data source: Logon sessions

On Detection: Tactical to Functional | by Jared Atkinson | Jul, 2022 | Posts By SpecterOps Team Members

https://posts.specterops.io/on-detection-tactical-to-functional-d71da6505720
On Detection: Tactical to Functional | by Jared Atkinson | Jul, 2022 | Posts By SpecterOps Team Members

Russia Released a Ukrainian App for Hacking Russia That Was Actually Malware

https://www.vice.com/en/article/bvmnxd/russia-released-a-ukrainian-app-for-hacking-russia-that-was-actually-malware
Russia Released a Ukrainian App for Hacking Russia That Was Actually Malware

Continued cyber activity in Eastern Europe observed by TAG

https://blog.google/threat-analysis-group/continued-cyber-activity-in-eastern-europe-observed-by-tag/
Continued cyber activity in Eastern Europe observed by TAG

Several New Play Store Apps Spotted Distributing Joker, Facestealer and Coper Malware

https://thehackernews.com/2022/07/several-new-play-store-apps-spotted.html
Several New Play Store Apps Spotted Distributing Joker, Facestealer and Coper Malware

I see what you did there: A look at the CloudMensis macOS spyware | WeLiveSecurity

https://www.welivesecurity.com/2022/07/19/i-see-what-you-did-there-look-cloudmensis-macos-spyware/
I see what you did there: A look at the CloudMensis macOS spyware | WeLiveSecurity

Air-gapped systems leak data via SATA cable WiFi antennas

https://www.bleepingcomputer.com/news/security/air-gapped-systems-leak-data-via-sata-cable-wifi-antennas/
Air-gapped systems leak data via SATA cable WiFi antennas

Unit 42 Threat Group Naming Update

https://unit42.paloaltonetworks.com/unit-42-threat-group-naming-update/
Unit 42 Threat Group Naming Update

x86matthew - AddExeImport - Add a hardcoded DLL dependency to any EXE

https://www.x86matthew.com/view_post?id=add_exe_import
x86matthew - AddExeImport - Add a hardcoded DLL dependency to any EXE

CVE-2022-30526 (Fixed): Zyxel Firewall Local Privilege Escalation | Rapid7 Blog

https://www.rapid7.com/blog/post/2022/07/19/cve-2022-30526-fixed-zyxel-firewall-local-privilege-escalation/
CVE-2022-30526 (Fixed): Zyxel Firewall Local Privilege Escalation | Rapid7 Blog

Threat Hunting Series: The Threat Hunting Process | by Kostas | Jul, 2022 | Medium

https://kostas-ts.medium.com/threat-hunting-series-the-threat-hunting-process-f76583f2475b
Threat Hunting Series: The Threat Hunting Process | by Kostas | Jul, 2022 | Medium

EJS, Server side template injection RCE (CVE-2022-29078) - writeup | ~#whoami <Eslam Salem>

https://eslam.io/posts/ejs-server-side-template-injection-rce/
EJS, Server side template injection RCE (CVE-2022-29078) - writeup | ~#whoami <Eslam Salem>