10/31

Follina Exploit Leads to Domain Compromise

https://thedfirreport.com/2022/10/31/follina-exploit-leads-to-domain-compromise/
Follina Exploit Leads to Domain Compromise

SensePost | Abusing windows’ tokens to compromise active directory without touching lsass

https://sensepost.com/blog/2022/abusing-windows-tokens-to-compromise-active-directory-without-touching-lsass/
SensePost | Abusing windows’ tokens to compromise active directory without touching lsass

Twitter to start charging $20 per month for verification - The Verge

https://www.theverge.com/2022/10/30/23431931/twitter-paid-verification-elon-musk-blue-monthly-subscription
Twitter to start charging $20 per month for verification - The Verge

New Azov data wiper tries to frame researchers and BleepingComputer

https://www.bleepingcomputer.com/news/security/new-azov-data-wiper-tries-to-frame-researchers-and-bleepingcomputer/
New Azov data wiper tries to frame researchers and BleepingComputer

Defender’s Guide – Posts By SpecterOps Team Members

https://posts.specterops.io/defenders-guide/home
Defender’s Guide – Posts By SpecterOps Team Members

Orion Threat Alert: Qakbot TTPs Arsenal and the Black Basta Ransomware - Cynet

https://www.cynet.com/blog/orion-threat-alert-qakbot-ttps-arsenal-and-the-black-basta-ransomware/
Orion Threat Alert: Qakbot TTPs Arsenal and the Black Basta Ransomware - Cynet

http://xss.ht

http://xss.ht

Spy agency embraces meme culture and the internet is here for it - CyberScoop

https://www.cyberscoop.com/nsa-memes-cybersecurity-awareness/
Spy agency embraces meme culture and the internet is here for it - CyberScoop

GitHub Repojacking Bug Could've Allowed Attackers to Takeover Other Users' Repositories

https://thehackernews.com/2022/10/github-repojacking-bug-couldve-allowed.html
GitHub Repojacking Bug Could've Allowed Attackers to Takeover Other Users' Repositories

XSS Hunter Deprecation FAQ - Google ドキュメント

https://docs.google.com/document/d/1HlkDOZhIxwgLWeFf4L8Vy3OIPAedeC3cMw0Jz4WORag/preview
XSS Hunter Deprecation FAQ - Google ドキュメント

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/24aec370771ad1208aeb54721067c9e3b139a368f13ab6b131dc7d6c13da5127/
MalwareBazaar | Browse Checking your browser

Qakbot/Qakbot_BB05_31.10.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_BB05_31.10.2022.txt
Qakbot/Qakbot_BB05_31.10.2022.txt at main · pr0xylife/Qakbot · GitHub

Safari is hot-linking images to semi-random websites | PortSwigger Research

https://portswigger.net/research/safari-is-hot-linking-images-to-semi-random-websites
Safari is hot-linking images to semi-random websites | PortSwigger Research

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/23dfa98dc0b37502bfc20df6154d83dc07d15c7a9980db8f0cf6d5963a997ee6/
MalwareBazaar | Browse Checking your browser

APT10: Tracking down LODEINFO 2022, part I | Securelist

https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/
APT10: Tracking down LODEINFO 2022, part I | Securelist

Backup Server Hacked - SUPPLY CHAIN Code Execution - YouTube

https://www.youtube.com/watch?v=HnS9o9E7rhY
Backup Server Hacked - SUPPLY CHAIN Code Execution - YouTube