10/22

Exploited Windows zero-day lets JavaScript files bypass security warnings

https://www.bleepingcomputer.com/news/security/exploited-windows-zero-day-lets-javascript-files-bypass-security-warnings/
Exploited Windows zero-day lets JavaScript files bypass security warnings

Critical Flaw Reported in Move Virtual Machine Powering the Aptos Blockchain Network

https://thehackernews.com/2022/10/critical-flaw-reported-in-move-virtual.html
Critical Flaw Reported in Move Virtual Machine Powering the Aptos Blockchain Network

#StopRansomware: Daixin Team | CISA

https://www.cisa.gov/uscert/ncas/alerts/aa22-294a
#StopRansomware: Daixin Team | CISA

Smokeloader: The Pandora’s box of tricks, payloads and anti-analysis - BSides Portland 2022 - YouTube

https://www.youtube.com/watch?v=O69eMQ7NS8w&list=PLqdWoaf0o9zefFAO7wHFVp032cbX1IdfM&index=6
Smokeloader: The Pandora’s box of tricks, payloads and anti-analysis - BSides Portland 2022 - YouTube

grsecurity - Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse

https://grsecurity.net/exploiting_and_defending_against_same_type_object_reuse
grsecurity - Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/browse/tag/kbacloud-freeboxos-fr/
MalwareBazaar | Browse Checking your browser

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/browse/tag/XeonusWallet/
MalwareBazaar | Browse Checking your browser

VirusTotal - File - 73709989c2bc864eaac863974a65aa50a3e740e7796daaa726f96975a33b93c3

https://www.virustotal.com/gui/file/73709989c2bc864eaac863974a65aa50a3e740e7796daaa726f96975a33b93c3
VirusTotal - File - 73709989c2bc864eaac863974a65aa50a3e740e7796daaa726f96975a33b93c3

VirusTotal - File - 67b0763fa0c849e0fa4e9159f48cc8adf9684dd62a55a6379d5ff1a4215af87f

https://www.virustotal.com/gui/file/67b0763fa0c849e0fa4e9159f48cc8adf9684dd62a55a6379d5ff1a4215af87f
VirusTotal - File - 67b0763fa0c849e0fa4e9159f48cc8adf9684dd62a55a6379d5ff1a4215af87f

WarHawk: the New Backdoor in the Arsenal of the SideWinder APT Group | Zscaler

https://www.zscaler.com/blogs/security-research/warhawk-new-backdoor-arsenal-sidewinder-apt-group-0
WarHawk: the New Backdoor in the Arsenal of the SideWinder APT Group | Zscaler

Your Microsoft Exchange Server Is a Security Liability | WIRED

https://www.wired.com/story/microsoft-exchange-server-vulnerabilities/
Your Microsoft Exchange Server Is a Security Liability | WIRED

VirusTotal - File - 01ba4bb94394a834155724b06697fdb1c947adaee060a627658e70cb5e9a7e3e

https://www.virustotal.com/gui/file/01ba4bb94394a834155724b06697fdb1c947adaee060a627658e70cb5e9a7e3e
VirusTotal - File - 01ba4bb94394a834155724b06697fdb1c947adaee060a627658e70cb5e9a7e3e

New release - 0.8.0

http://www.hashview.io/releases/2022/10/21/release-0-8-0.html
New release - 0.8.0

Modern Binary/Patch Diffing! / Twitter

https://twitter.com/i/broadcasts/1nAKErNBVWRGL
Modern Binary/Patch Diffing! / Twitter

Fighting Golden Ticket Attacks with Privileged Attribute Certificate (PAC)

https://www.varonis.com/blog/pac_requestor-and-golden-ticket-attacks
Fighting Golden Ticket Attacks with Privileged Attribute Certificate (PAC)

Release Fuzzilli Version 0.9.2 · googleprojectzero/fuzzilli · GitHub

https://github.com/googleprojectzero/fuzzilli/releases/tag/v0.9.2
Release Fuzzilli Version 0.9.2 · googleprojectzero/fuzzilli · GitHub

Wholesale giant METRO hit by IT outage after cyberattack

https://www.bleepingcomputer.com/news/security/wholesale-giant-metro-hit-by-it-outage-after-cyberattack/
Wholesale giant METRO hit by IT outage after cyberattack

CSI_EMBRACING_ZT_SECURITY_MODEL_UOO115131-21.PDF

https://media.defense.gov/2021/Feb/25/2002588479/-1/-1/0/CSI_EMBRACING_ZT_SECURITY_MODEL_UOO115131-21.PDF
CSI_EMBRACING_ZT_SECURITY_MODEL_UOO115131-21.PDF

Malware development: persistence - part 7. Winlogon. Simple C++ example. - cocomelonc

https://cocomelonc.github.io/tutorial/2022/06/12/malware-pers-7.html
Malware development: persistence - part 7. Winlogon. Simple C++ example. - cocomelonc

BlackByte ransomware uses new data theft tool for double-extortion

https://www.bleepingcomputer.com/news/security/blackbyte-ransomware-uses-new-data-theft-tool-for-double-extortion/
BlackByte ransomware uses new data theft tool for double-extortion

Hackers Started Exploiting Critical "Text4Shell" Apache Commons Text Vulnerability

https://thehackernews.com/2022/10/hackers-started-exploiting-critical.html
Hackers Started Exploiting Critical "Text4Shell" Apache Commons Text Vulnerability

Android adware apps in Google Play downloaded over 20 million times

https://www.bleepingcomputer.com/news/security/android-adware-apps-in-google-play-downloaded-over-20-million-times/
Android adware apps in Google Play downloaded over 20 million times

CERT-UA

https://cert.gov.ua/article/2394117
CERT-UA

Reverse-engineering tcpip.sys: mechanics of a packet of the death (CVE-2021-24086)

https://doar-e.github.io/blog/2021/04/15/reverse-engineering-tcpipsys-mechanics-of-a-packet-of-the-death-cve-2021-24086
Reverse-engineering tcpip.sys: mechanics of a packet of the death (CVE-2021-24086)

VirusTotal - File - ca7f297dc04acad2fab04d5dc2de9475aed4186805f6c237c10b8f56b384cf30

https://www.virustotal.com/gui/file/ca7f297dc04acad2fab04d5dc2de9475aed4186805f6c237c10b8f56b384cf30/detection
VirusTotal - File - ca7f297dc04acad2fab04d5dc2de9475aed4186805f6c237c10b8f56b384cf30

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/browse/tag/srvdwnld-com/
MalwareBazaar | Browse Checking your browser

October 22, 2022 - by the grugq - The Info Op

https://grugq.substack.com/p/october-22-2022
October 22, 2022 - by the grugq - The Info Op

Utah SSG

https://softsec.cs.utah.edu/
Utah SSG

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/browse/tag/206-188-196-244/
MalwareBazaar | Browse Checking your browser

VirusTotal - File - f2779c63373e33fdbd001f336df36b01b0360cd6787c1cd29a6524cc7bcf1ffb

https://www.virustotal.com/gui/file/f2779c63373e33fdbd001f336df36b01b0360cd6787c1cd29a6524cc7bcf1ffb/detection
VirusTotal - File - f2779c63373e33fdbd001f336df36b01b0360cd6787c1cd29a6524cc7bcf1ffb

Winitor

http://www.winitor.com
Winitor