08/19

iOS Privacy: Announcing InAppBrowser.com - see what JavaScript commands get injected through an in-app browser · Felix Krause

https://krausefx.com/blog/announcing-inappbrowsercom-see-what-javascript-commands-get-executed-in-an-in-app-browser
iOS Privacy: Announcing InAppBrowser.com - see what JavaScript commands get injected through an in-app browser · Felix Krause

You Can’t Audit Me: APT29 Continues Targeting Microsoft 365 | Mandiant

https://www.mandiant.com/resources/apt29-continues-targeting-microsoft
You Can’t Audit Me: APT29 Continues Targeting Microsoft 365 | Mandiant

GitHub - Markakd/DirtyCred

https://github.com/markakd/dirtycred
GitHub - Markakd/DirtyCred

DirtyCred-Zhenpeng.pdf

https://zplin.me/papers/DirtyCred-Zhenpeng.pdf
DirtyCred-Zhenpeng.pdf

GitHub - BC-SECURITY/Beginners-Guide-to-Obfuscation

https://github.com/BC-SECURITY/Beginners-Guide-to-Obfuscation
GitHub - BC-SECURITY/Beginners-Guide-to-Obfuscation

Zero Day Initiative — But You Told Me You Were Safe: Attacking the Mozilla Firefox Renderer (Part 1)

https://www.zerodayinitiative.com/blog/2022/8/17/but-you-told-me-you-were-safe-attacking-the-mozilla-firefox-renderer-part-1
Zero Day Initiative — But You Told Me You Were Safe: Attacking the Mozilla Firefox Renderer (Part 1)

JSSLoader: the shellcode edition

https://malwarebytes.com/blog/threat-intelligence/2022/08/jssloader-the-shellcode-edition
JSSLoader: the shellcode edition

Ransomware Summit 2022 - YouTube

https://www.youtube.com/playlist?list=PLtgaAEEmVe6AGQj2LhA4UnN0XolmeYw9_
Ransomware Summit 2022 - YouTube

1day to 0day(CVE-2022-30024) on TP-Link TL-WR841N

https://blog.viettelcybersecurity.com/1day-to-0day-on-tl-link-tl-wr841n/
1day to 0day(CVE-2022-30024) on TP-Link TL-WR841N

Rob Joyce on Twitter: "https://t.co/0EUokRZZSe" / Twitter

https://twitter.com/NSA_CSDirector/status/1560517798404579328
Rob Joyce on Twitter: "https://t.co/0EUokRZZSe" / Twitter

Exploiting WebKit JSPropertyNameEnumerator Out-of-Bounds Read (CVE-2021-1789) | STAR Labs

https://starlabs.sg/blog/2022/08-exploiting-webkit-jspropertynameenumerator-out-of-bounds-read-cve-2021-1789/
Exploiting WebKit JSPropertyNameEnumerator Out-of-Bounds Read (CVE-2021-1789) | STAR Labs

The head of GCHQ says Vladimir Putin is losing the information war in Ukraine | The Economist

https://www.economist.com/by-invitation/2022/08/18/the-head-of-gchq-says-vladimir-putin-is-losing-the-information-war-in-ukraine
The head of GCHQ says Vladimir Putin is losing the information war in Ukraine | The Economist

Rob Joyce on Twitter: "https://t.co/0EUokRZZSe" / Twitter

https://twitter.com/nsa_csdirector/status/1560517798404579328
Rob Joyce on Twitter: "https://t.co/0EUokRZZSe" / Twitter

AzureAD-Attack-Defense/ReplayOfPrimaryRefreshToken.md at main · Cloud-Architekt/AzureAD-Attack-Defense · GitHub

https://github.com/Cloud-Architekt/AzureAD-Attack-Defense/blob/main/ReplayOfPrimaryRefreshToken.md
AzureAD-Attack-Defense/ReplayOfPrimaryRefreshToken.md at main · Cloud-Architekt/AzureAD-Attack-Defense · GitHub