09/30

Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server – Microsoft Security Response Center

https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/
Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server – Microsoft Security Response Center

GitHub - HavocFramework/Havoc: The Havoc Framework

https://github.com/HavocFramework/Havoc
GitHub - HavocFramework/Havoc: The Havoc Framework

ZDI-CAN-18333 aka ProxyNotShell— the story of the claimed zero day in Microsoft Exchange | by Kevin Beaumont | Sep, 2022 | DoublePulsar

https://doublepulsar.com/proxynotshell-the-story-of-the-claimed-zero-day-in-microsoft-exchange-5c63d963a9e9
ZDI-CAN-18333 aka ProxyNotShell— the story of the claimed zero day in Microsoft Exchange | by Kevin Beaumont | Sep, 2022 | DoublePulsar

Cảnh báo chiến dịch tấn công sử dụng lỗ hổng ZERO DAY trên Microsoft Exchange Server | Blog | GTSC - Cung cấp các dịch vụ bảo mật toàn diện

https://www.gteltsc.vn/blog/canh-bao-chien-dich-tan-cong-su-dung-lo-hong-zero-day-tren-microsoft-exchange-server-12714.html
Cảnh báo chiến dịch tấn công sử dụng lỗ hổng ZERO DAY trên Microsoft Exchange Server | Blog | GTSC - Cung cấp các dịch vụ bảo mật toàn diện

Warning: New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server | Blog | GTSC - Cung cấp các dịch vụ bảo mật toàn diện

https://gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html
Warning: New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server | Blog | GTSC - Cung cấp các dịch vụ bảo mật toàn diện

WARNING: New Unpatched Microsoft Exchange Zero-Day Under Active Exploitation

https://thehackernews.com/2022/09/warning-new-unpatched-microsoft.html
WARNING: New Unpatched Microsoft Exchange Zero-Day Under Active Exploitation

Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors | Mandiant

https://www.mandiant.com/resources/blog/esxi-hypervisors-malware-persistence
Bad VIB(E)s Part One: Investigating Novel Malware Persistence Within ESXi Hypervisors | Mandiant

Dismantling a Prolific Cybercriminal Empire: REvil Arrests and Reemergence

https://www.trellix.com/en-us/about/newsroom/stories/research/dismantling-a-prolific-cybercriminal-empire.html
Dismantling a Prolific Cybercriminal Empire: REvil Arrests and Reemergence

MalwareBazaar | SHA256 b9a1328f3107582e58d4fef064f2d3998b658ccc513f9e98a513f5606400d9be (Quakbot)

https://bazaar.abuse.ch/sample/b9a1328f3107582e58d4fef064f2d3998b658ccc513f9e98a513f5606400d9be/
MalwareBazaar | SHA256 b9a1328f3107582e58d4fef064f2d3998b658ccc513f9e98a513f5606400d9be (Quakbot)

MalwareBazaar | SHA256 af1692ced38f5fda305b35be66774822900a0b9617102db4b3da5f7c97f70e3e (Quakbot)

https://bazaar.abuse.ch/sample/af1692ced38f5fda305b35be66774822900a0b9617102db4b3da5f7c97f70e3e/
MalwareBazaar | SHA256 af1692ced38f5fda305b35be66774822900a0b9617102db4b3da5f7c97f70e3e (Quakbot)

Suspected Post-Authentication Zero-Day Vulnerabilities in Microsoft Exchange Server | Rapid7 Blog

https://www.rapid7.com/blog/post/2022/09/29/suspected-post-authentication-zero-day-vulnerabilities-in-microsoft-exchange-server/
Suspected Post-Authentication Zero-Day Vulnerabilities in Microsoft Exchange Server | Rapid7 Blog

Qakbot/Qakbot_BB_30.09.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_BB_30.09.2022.txt
Qakbot/Qakbot_BB_30.09.2022.txt at main · pr0xylife/Qakbot · GitHub

Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned) | by Jacopo Tediosi | Sep, 2022 | Medium

https://medium.com/@jacopotediosi/worldwide-server-side-cache-poisoning-on-all-akamai-edge-nodes-50k-bounty-earned-f97d80f3922b
Worldwide Server-side Cache Poisoning on All Akamai Edge Nodes ($50K+ Bounty Earned) | by Jacopo Tediosi | Sep, 2022 | Medium

Microsoft Confirms 2 New Exchange Zero-Day Flaws Being Used in the Wild

https://thehackernews.com/2022/09/microsoft-confirms-2-new-exchange-zero.html
Microsoft Confirms 2 New Exchange Zero-Day Flaws Being Used in the Wild

A glimpse into the shadowy realm of a Chinese APT: detailed analysis of a ShadowPad intrusion – NCC Group Research

https://research.nccgroup.com/2022/09/30/a-glimpse-into-the-shadowy-realm-of-a-chinese-apt-detailed-analysis-of-a-shadowpad-intrusion/
A glimpse into the shadowy realm of a Chinese APT: detailed analysis of a ShadowPad intrusion – NCC Group Research

GreyNoise | Microsoft Exchange ProxyNotShell 0-Day Vulnerability

https://www.greynoise.io/blog/microsoft-exchange-proxynotshell-vulnerability
GreyNoise | Microsoft Exchange ProxyNotShell 0-Day Vulnerability

Protecting vSphere From Specialized Malware | VMware

https://core.vmware.com/vsphere-esxi-mandiant-malware-persistence
Protecting vSphere From Specialized Malware | VMware

GitHub - jsa2/caOptics: CA Optics - Azure AD Conditional Access gap analyzer

https://github.com/jsa2/caOptics#ca-optics---azure-ad-conditional-access-gap-analyzer
GitHub - jsa2/caOptics: CA Optics - Azure AD Conditional Access gap analyzer

Hybrid + Identity Cyber Range

https://www.purplecloud.network
Hybrid + Identity Cyber Range

Germany arrests hacker for stealing €4 million via phishing attacks

https://www.bleepingcomputer.com/news/security/germany-arrests-hacker-for-stealing-4-million-via-phishing-attacks/
Germany arrests hacker for stealing €4 million via phishing attacks

GreyNoise Trends

https://viz.greynoise.io/tag/exchange-proxynotshell-vuln-check?days=3
GreyNoise Trends

Microsoft: Two New 0-Day Flaws in Exchange Server – Krebs on Security

https://krebsonsecurity.com/2022/09/microsoft-two-new-0-day-flaws-in-exchange-server/
Microsoft: Two New 0-Day Flaws in Exchange Server – Krebs on Security

Exploitation of Microsoft Exchange Servers seen in the wild – PwnDefend

https://www.pwndefend.com/2022/09/30/exploitation-of-microsoft-exchange-servers-seen-in-the-wild/
Exploitation of Microsoft Exchange Servers seen in the wild – PwnDefend

Microsoft confirms new Exchange zero-days are used in attacks

https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-new-exchange-zero-days-are-used-in-attacks/
Microsoft confirms new Exchange zero-days are used in attacks