08/08

BumbleBee Roasts Its Way to Domain Admin – The DFIR Report

https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/
BumbleBee Roasts Its Way to Domain Admin – The DFIR Report

Microsoft Office to publish symbols starting August 2022 – Microsoft Security Response Center

https://msrc-blog.microsoft.com/2022/08/08/microsoft-office-to-publish-symbols-starting-august-2022/
Microsoft Office to publish symbols starting August 2022 – Microsoft Security Response Center

Incident Report: Employee and Customer Account Compromise - August 4, 2022

https://www.twilio.com/blog/august-2022-social-engineering-attack
Incident Report: Employee and Customer Account Compromise - August 4, 2022

GitHub - rad9800/TamperingSyscalls

https://github.com/rad9800/TamperingSyscalls
GitHub - rad9800/TamperingSyscalls

Unravelling a Mimikatz campaign

https://blog.bushidotoken.net/2022/08/unravelling-mimikatz-campaign.html
Unravelling a Mimikatz campaign

Congratulations to the MSRC 2022 Most Valuable Researchers! – Microsoft Security Response Center

https://msrc-blog.microsoft.com/2022/08/08/congratulations-to-the-msrc-2022-most-valuable-researchers/
Congratulations to the MSRC 2022 Most Valuable Researchers! – Microsoft Security Response Center

Zero Day Initiative — Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack

https://www.thezdi.com/blog/2022/7/25/looking-at-patch-gap-vulnerabilities-in-the-vmware-esxi-tcpip-stack
Zero Day Initiative — Looking at Patch Gap Vulnerabilities in the VMware ESXi TCP/IP Stack

Twilio hacked by phishing campaign targeting internet companies | TechCrunch

https://techcrunch.com/2022/08/08/twilio-breach-customer-data/
Twilio hacked by phishing campaign targeting internet companies | TechCrunch

Analyzing .NET Core Single File Samples (DUCKTAIL Case Study) | Tony Lambert

https://forensicitguy.github.io/analyzing-net-core-single-file-ducktail/
Analyzing .NET Core Single File Samples (DUCKTAIL Case Study) | Tony Lambert

metasploit-framework/manageengine_adaudit_plus_cve_2022_28219.rb at master · rapid7/metasploit-framework · GitHub

https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/manageengine_adaudit_plus_cve_2022_28219.rb
metasploit-framework/manageengine_adaudit_plus_cve_2022_28219.rb at master · rapid7/metasploit-framework · GitHub

Meet the team responsible for hacking Google

https://blog.google/technology/safety-security/meet-the-team-responsible-for-hacking-google/
Meet the team responsible for hacking Google

Meta Cracks Down on Cyber Espionage Operations in South Asia Abusing Facebook

https://thehackernews.com/2022/08/meta-cracks-down-on-cyber-espionage.html
Meta Cracks Down on Cyber Espionage Operations in South Asia Abusing Facebook

New Orchard Botnet Uses Bitcoin Founder's Account Info to Generate Malicious Domains

https://thehackernews.com/2022/08/new-orchard-botnet-uses-bitcoin.html
New Orchard Botnet Uses Bitcoin Founder's Account Info to Generate Malicious Domains

Chinese hackers use new Windows malware to backdoor govt, defense orgs

https://www.bleepingcomputer.com/news/security/chinese-hackers-use-new-windows-malware-to-backdoor-govt-defense-orgs/
Chinese hackers use new Windows malware to backdoor govt, defense orgs

BlueTeamVillage - Twitch

https://twitch.tv/blueteamvillage
BlueTeamVillage - Twitch

Justin Elze on Twitter: "CobaltStrikes are up!!! https://t.co/ek1ULO5aTr" / Twitter

https://twitter.com/HackingLZ/status/1555963075206868992
Justin Elze on Twitter: "CobaltStrikes are up!!! https://t.co/ek1ULO5aTr" / Twitter

MalwareBazaar | DLAWT

https://bazaar.abuse.ch/browse/tag/DLAWT/
MalwareBazaar | DLAWT