09/21

Revealed: U.S. Military Bought Mass Monitoring Tool That Includes Internet Browsing, Email Data

https://www.vice.com/en/article/y3pnkw/us-military-bought-mass-monitoring-augury-team-cymru-browsing-email-data
Revealed: U.S. Military Bought Mass Monitoring Tool That Includes Internet Browsing, Email Data

x86matthew - Exploiting a Seagate service to create a SYSTEM shell (CVE-2022-40286)

https://www.x86matthew.com/view_post?id=windows_seagate_lpe
x86matthew - Exploiting a Seagate service to create a SYSTEM shell (CVE-2022-40286)

GitHub - 3xp0rt/LockBit-Black-Builder

https://github.com/3xp0rt/LockBit-Black-Builder
GitHub - 3xp0rt/LockBit-Black-Builder

Giving JuicyPotato a second chance: JuicyPotatoNG – Decoder's Blog

https://decoder.cloud/2022/09/21/giving-juicypotato-a-second-chance-juicypotatong
Giving JuicyPotato a second chance: JuicyPotatoNG – Decoder's Blog

Python for Defenders, Pt. 1 | The Taggart Institute

https://learn.taggart-tech.com/p/python-for-defenders-pt1
Python for Defenders, Pt. 1 | The Taggart Institute

Sign In | LinkedIn

https://www.linkedin.com/in/blenster/
Sign In | LinkedIn

Native function and Assembly Code Invocation - Check Point Research

https://research.checkpoint.com/2022/native-function-and-assembly-code-invocation/
Native function and Assembly Code Invocation - Check Point Research

New Windows 11 security features are designed for hybrid work - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/09/20/new-windows-11-security-features-are-designed-for-hybrid-work/
New Windows 11 security features are designed for hybrid work - Microsoft Security Blog

Blenster on Twitter: "Just got laid off. Lovely. Anybody hiring?" / Twitter

https://twitter.com/blenster/status/1572596103148871681
Blenster on Twitter: "Just got laid off. Lovely. Anybody hiring?" / Twitter

Out Of Band Update: Cobalt Strike 4.7.1 | Cobalt Strike

https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-1/
Out Of Band Update: Cobalt Strike 4.7.1 | Cobalt Strike

From Leaking TheHole to Chrome Renderer RCE | by Numen Cyber Labs | Numen Cyber Labs | Sep, 2022 | Medium

https://medium.com/numen-cyber-labs/from-leaking-thehole-to-chrome-renderer-rce-183dcb6f3078
From Leaking TheHole to Chrome Renderer RCE | by Numen Cyber Labs | Numen Cyber Labs | Sep, 2022 | Medium

Cobalt Strike Community Kit

https://cobalt-strike.github.io/community_kit/
Cobalt Strike Community Kit

SIM Swapper Abducted, Beaten, Held for $200k Ransom – Krebs on Security

https://krebsonsecurity.com/2022/09/sim-swapper-abducted-beaten-held-for-200k-ransom/
SIM Swapper Abducted, Beaten, Held for $200k Ransom – Krebs on Security

🦊 on Twitter: "Changing my teams name to https://t.co/1WUmGU7ckR" / Twitter

https://twitter.com/th3cyF0x/status/1551912736111706112
🦊 on Twitter: "Changing my teams name to https://t.co/1WUmGU7ckR" / Twitter

DEATHCon 0x0 2022

https://deathcon.io
DEATHCon 0x0 2022

Rewards plus: Fake mobile banking rewards apps lure users to install info-stealing RAT on Android devices - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/09/21/rewards-plus-fake-mobile-banking-rewards-apps-lure-users-to-install-info-stealing-rat-on-android-devices/
Rewards plus: Fake mobile banking rewards apps lure users to install info-stealing RAT on Android devices - Microsoft Security Blog

Over 39,000 Unauthenticated Redis Instances Found Exposed on the Internet

https://thehackernews.com/2022/09/over-39000-unauthenticated-redis.html
Over 39,000 Unauthenticated Redis Instances Found Exposed on the Internet

Critical Remote Hack Flaws Found in Dataprobe's Power Distribution Units

https://thehackernews.com/2022/09/critical-remote-hack-flaws-found-in.html
Critical Remote Hack Flaws Found in Dataprobe's Power Distribution Units

Unpatched 15-year old Python bug allows code execution in 350k projects

https://www.bleepingcomputer.com/news/security/unpatched-15-year-old-python-bug-allows-code-execution-in-350k-projects/
Unpatched 15-year old Python bug allows code execution in 350k projects

pe-bear/README.md at main · hasherezade/pe-bear · GitHub

https://github.com/hasherezade/pe-bear/blob/main/README.md
pe-bear/README.md at main · hasherezade/pe-bear · GitHub

Record DDoS Attack with 25.3 Billion Requests Abused HTTP/2 Multiplexing

https://thehackernews.com/2022/09/record-ddos-attack-with-253-billion.html
Record DDoS Attack with 25.3 Billion Requests Abused HTTP/2 Multiplexing