10/19

Orange: A New Attack Surface on MS Exchange Part 4 - ProxyRelay!

https://blog.orange.tw/2022/10/proxyrelay-a-new-attack-surface-on-ms-exchange-part-4.html
Orange: A New Attack Surface on MS Exchange Part 4 - ProxyRelay!

A New Attack Surface on MS Exchange Part 4 - ProxyRelay! | DEVCORE

https://devco.re/blog/2022/10/19/a-new-attack-surface-on-MS-exchange-part-4-ProxyRelay/
A New Attack Surface on MS Exchange Part 4 - ProxyRelay! | DEVCORE

Microsoft Office Online Server Remote Code Execution - MDSec

https://www.mdsec.co.uk/2022/10/microsoft-office-online-server-remote-code-execution/
Microsoft Office Online Server Remote Code Execution - MDSec

PHP filters chain: What is it and how to use it

https://www.synacktiv.com/publications/php-filters-chain-what-is-it-and-how-to-use-it.html
PHP filters chain: What is it and how to use it

Defenders beware: A case for post-ransomware investigations - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/10/18/defenders-beware-a-case-for-post-ransomware-investigations/
Defenders beware: A case for post-ransomware investigations - Microsoft Security Blog

HTTP/3 connection contamination: an upcoming threat? | PortSwigger Research

https://portswigger.net/research/http-3-connection-contamination
HTTP/3 connection contamination: an upcoming threat? | PortSwigger Research

VirusTotal - File - 725ca9e0571a6651e1bcf7dcf5d921fb004e753d67bfd135bd61f178b8aa5e4c

https://www.virustotal.com/gui/file/725ca9e0571a6651e1bcf7dcf5d921fb004e753d67bfd135bd61f178b8aa5e4c/detection
VirusTotal - File - 725ca9e0571a6651e1bcf7dcf5d921fb004e753d67bfd135bd61f178b8aa5e4c

Guest Blog Post - Memory corruption vulnerabilities in Edge | Microsoft Browser Vulnerability Research

https://microsoftedge.github.io/edgevr/posts/memory-corruption-vulnerabilities-in-edge/
Guest Blog Post - Memory corruption vulnerabilities in Edge | Microsoft Browser Vulnerability Research

Hexacon - Conference – Speakers

https://2022.hexacon.fr/conference/speakers/
Hexacon - Conference – Speakers

Consortium led by Smartfin acquires leading cybersecurity software provider Hex-Rays - Smartfin

https://smartfinvc.com/news/smartfin-acquires-leading-cybersecurity-software-provider-hex-rays-together-with-sfpim-and-sriw/
Consortium led by Smartfin acquires leading cybersecurity software provider Hex-Rays - Smartfin

‘They said: aren’t you that porn star?’ The woman hunting down image-based abuse | Sexual harassment | The Guardian

https://www.theguardian.com/global-development/2022/oct/19/they-said-arent-you-that-porn-star-the-woman-hunting-down-image-based-abuse
‘They said: aren’t you that porn star?’ The woman hunting down image-based abuse | Sexual harassment | The Guardian

Verizon notifies prepaid customers their accounts were breached

https://www.bleepingcomputer.com/news/security/verizon-notifies-prepaid-customers-their-accounts-were-breached/
Verizon notifies prepaid customers their accounts were breached

23000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite | by h4x0r_dz | Oct, 2022 | Medium

https://medium.com/@h4x0r_dz/23000-for-authentication-bypass-file-upload-arbitrary-file-overwrite-2578b730a5f8
23000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite | by h4x0r_dz | Oct, 2022 | Medium

Researchers Detail Azure SFX Flaw That Could've Allowed Attackers to Gain Admin Access

https://thehackernews.com/2022/10/researchers-detail-azure-sfx-flaw-that.html
Researchers Detail Azure SFX Flaw That Could've Allowed Attackers to Gain Admin Access

Experts Warn of Stealthy PowerShell Backdoor Disguising as Windows Update

https://thehackernews.com/2022/10/experts-warn-of-stealthy-powershell.html
Experts Warn of Stealthy PowerShell Backdoor Disguising as Windows Update

Browser Exploitation: Firefox OOB to RCE • Vulndev

https://vulndev.io/2022/09/09/browser-exploitation-firefox-oob-to-rce/
Browser Exploitation: Firefox OOB to RCE • Vulndev

Changing memory protection using APC

https://blog.offensive.af/changing-memory-protection-using-apc
Changing memory protection using APC

Spyder Loader: Malware Seen in Recent Campaign Targeting Organizations in Hong Kong | Symantec Enterprise Blogs

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/spyder-loader-cuckoobees-hong-kong
Spyder Loader: Malware Seen in Recent Campaign Targeting Organizations in Hong Kong | Symantec Enterprise Blogs