10/28

Project Zero: RC4 Is Still Considered Harmful

https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html
Project Zero: RC4 Is Still Considered Harmful

CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities – Blog | Octagon Networks

https://octagon.net/blog/2022/10/28/juniper-sslvpn-junos-rce-and-multiple-vulnerabilities/
CVE-2022-22241: Juniper SSLVPN / JunOS RCE and Multiple Vulnerabilities – Blog | Octagon Networks

Elon Musk on Twitter: "the bird is freed" / Twitter

https://twitter.com/elonmusk/status/1585841080431321088
Elon Musk on Twitter: "the bird is freed" / Twitter

OpenSSL warns of critical security vulnerability with upcoming patch | ZDNET

https://www.zdnet.com/article/openssl-warns-of-critical-security-vulnerability-with-upcoming-patch/
OpenSSL warns of critical security vulnerability with upcoming patch | ZDNET

Blog - Towards the next generation of XNU memory safety: kalloc_type - Apple Security Research

https://security.apple.com/blog/towards-the-next-generation-of-xnu-memory-safety/
Blog - Towards the next generation of XNU memory safety: kalloc_type - Apple Security Research

Elon Musk Twitter deal closes Thursday night - The Washington Post

https://www.washingtonpost.com/technology/2022/10/27/twitter-elon-musk/
Elon Musk Twitter deal closes Thursday night - The Washington Post

Overview - Apple Security Research

https://security.apple.com
Overview - Apple Security Research

Cranefly: Threat Actor Uses Previously Unseen Techniques and Tools in Stealthy Campaign | Symantec Enterprise Blogs

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/cranefly-new-tools-technique-geppei-danfuan
Cranefly: Threat Actor Uses Previously Unseen Techniques and Tools in Stealthy Campaign | Symantec Enterprise Blogs

Malwarebytes on Twitter: "An apology https://t.co/8A3UtccX5K" / Twitter

https://twitter.com/malwarebytes/status/1585748974862061570
Malwarebytes on Twitter: "An apology https://t.co/8A3UtccX5K" / Twitter

[CVE-2022-37969] | [Windows CLFS Zero-Day]

https://www.zscaler.com/blogs/security-research/technical-analysis-windows-clfs-zero-day-vulnerability-cve-2022-37969-part2-exploit-analysis
[CVE-2022-37969] | [Windows CLFS Zero-Day]

Google Issues Urgent Chrome Update to Patch Actively Exploited Zero-Day Vulnerability

https://thehackernews.com/2022/10/google-issues-urgent-chrome-update-to.html
Google Issues Urgent Chrome Update to Patch Actively Exploited Zero-Day Vulnerability

Forthcoming OpenSSL Releases

https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html
Forthcoming OpenSSL Releases

TCP/IP Vulnerability CVE-2022–34718 PoC Restoration and Analysis | by Numen Cyber Labs | Oct, 2022 | Medium

https://medium.com/@numencyberlabs/analysis-and-summary-of-tcp-ip-protocol-remote-code-execution-vulnerability-cve-2022-34718-8fcc28538acf
TCP/IP Vulnerability CVE-2022–34718 PoC Restoration and Analysis | by Numen Cyber Labs | Oct, 2022 | Medium

Blog - Apple Security Bounty. Upgraded. - Apple Security Research

https://security.apple.com/blog/apple-security-bounty-upgraded/
Blog - Apple Security Bounty. Upgraded. - Apple Security Research

Thomson Reuters leaked at least 3TB of sensitive data | Cybernews

https://cybernews.com/security/thomson-reuters-leaked-terabytes-sensitive-data/
Thomson Reuters leaked at least 3TB of sensitive data | Cybernews

So long and thanks for all the bits - NCSC.GOV.UK

https://www.ncsc.gov.uk/blog-post/so-long-thanks-for-all-the-bits
So long and thanks for all the bits - NCSC.GOV.UK

GitHub - numencyber/VulnerabilityPoC

https://github.com/numencyber/VulnerabilityPoC
GitHub - numencyber/VulnerabilityPoC

Welcome to hell, Elon - The Verge

https://www.theverge.com/2022/10/28/23428132/elon-musk-twitter-acquisition-problems-speech-moderation
Welcome to hell, Elon - The Verge

Incident Report: Employee and Customer Account Compromise - August 4, 2022

https://www.twilio.com/blog/august-2022-social-engineering-attack
Incident Report: Employee and Customer Account Compromise - August 4, 2022