08/11

Project Zero: The quantum state of Linux kernel garbage collection CVE-2021-0920 (Part I)

https://googleprojectzero.blogspot.com/2022/08/the-quantum-state-of-linux-kernel.html
Project Zero: The quantum state of Linux kernel garbage collection CVE-2021-0920 (Part I)

Mass Exploitation of (Un)authenticated Zimbra RCE: CVE-2022-27925 | Volexity

https://www.volexity.com/blog/2022/08/10/mass-exploitation-of-unauthenticated-zimbra-rce-cve-2022-27925/
Mass Exploitation of (Un)authenticated Zimbra RCE: CVE-2022-27925 | Volexity

Cyber Incident | Advanced

https://www.oneadvanced.com/cyber-incident/#updates
Cyber Incident | Advanced

Cisco hacked by Yanluowang ransomware gang, 2.8GB allegedly stolen

https://www.bleepingcomputer.com/news/security/cisco-hacked-by-yanluowang-ransomware-gang-28gb-allegedly-stolen/
Cisco hacked by Yanluowang ransomware gang, 2.8GB allegedly stolen

Concealed code execution: Techniques and detection

https://www.huntandhackett.com/blog/concealed-code-execution-techniques-and-detection
Concealed code execution: Techniques and detection

It Might Be Our Data, But It’s Not Our Breach – Krebs on Security

https://krebsonsecurity.com/2022/08/it-might-be-our-data-but-its-not-our-breach/
It Might Be Our Data, But It’s Not Our Breach – Krebs on Security

IAM Whoever I Say IAM :: Infiltrating VMWare Workspace ONE Access Using a 0-Click Exploit

https://srcincite.io/blog/2022/08/11/i-am-whoever-i-say-i-am-infiltrating-vmware-workspace-one-access-using-a-0-click-exploit.html
IAM Whoever I Say IAM :: Infiltrating VMWare Workspace ONE Access Using a 0-Click Exploit

Backdooring and hijacking Azure AD accounts by abusing external identities

https://dirkjanm.io/assets/raw/US-22-Mollema-Backdooring-and-hijacking-Azure-AD-accounts_final.pdf
Backdooring and hijacking Azure AD accounts by abusing external identities

GitHub - sourceincite/hekate

https://github.com/sourceincite/hekate/
GitHub - sourceincite/hekate

SMB RCE CVE-2022-35804的介绍 · VictorV的小博客

http://v-v.space/2022/08/11/CVE-2022-35804/
SMB RCE CVE-2022-35804的介绍 · VictorV的小博客

iOS Privacy: Instagram and Facebook can track anything you do on any website in their in-app browser · Felix Krause

https://krausefx.com/blog/ios-privacy-instagram-and-facebook-can-track-anything-you-do-on-any-website-in-their-in-app-browser
iOS Privacy: Instagram and Facebook can track anything you do on any website in their in-app browser · Felix Krause

“BazarCall” Advisory: Essential Guide to Attack Vector that Revolutionized Data Breaches

https://www.advintel.io/post/bazarcall-advisory-the-essential-guide-to-call-back-phishing-attacks-that-revolutionized-the-data
“BazarCall” Advisory: Essential Guide to Attack Vector that Revolutionized Data Breaches

Add download_file_types.asciipb entry for DIAGCAB · chromium/chromium@cd290e7 · GitHub

https://github.com/chromium/chromium/commit/cd290e7cbed7b2f95e4c2dc805e9d175f9161fc4
Add download_file_types.asciipb entry for DIAGCAB · chromium/chromium@cd290e7 · GitHub

HInvoke and avoiding PInvoke | drakonia’s blog

https://dr4k0nia.github.io/dotnet/coding/2022/08/10/HInvoke-and-avoiding-PInvoke.html
HInvoke and avoiding PInvoke | drakonia’s blog

Discord Desktop - Remote Code Execution | Electrovolt Blog

https://blog.electrovolt.io/posts/discord-rce/
Discord Desktop - Remote Code Execution | Electrovolt Blog