11/01

CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows - OpenSSL Blog

https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/
CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows - OpenSSL Blog

https://www.openssl.org/news/secadv/20221101.txt

https://www.openssl.org/news/secadv/20221101.txt

Exploiting Static Site Generators: When Static Is Not Actually Static – Assetnote

https://blog.assetnote.io/2022/10/28/exploiting-static-site-generators/
Exploiting Static Site Generators: When Static Is Not Actually Static – Assetnote

Accused ‘Raccoon’ Malware Developer Fled Ukraine After Russian Invasion – Krebs on Security

https://krebsonsecurity.com/2022/10/accused-raccoon-malware-developer-fled-ukraine-after-russian-invasion/
Accused ‘Raccoon’ Malware Developer Fled Ukraine After Russian Invasion – Krebs on Security

NCSC Annual Review 2022 - NCSC.GOV.UK

https://www.ncsc.gov.uk/annual-review-2022
NCSC Annual Review 2022 - NCSC.GOV.UK

Hackers selling access to 576 corporate networks for $4 million

https://www.bleepingcomputer.com/news/security/hackers-selling-access-to-576-corporate-networks-for-4-million/
Hackers selling access to 576 corporate networks for $4 million

Maddie – Darknet Diaries

https://darknetdiaries.com/episode/127
Maddie – Darknet Diaries

CISA_CPG_CHECKLIST_508c.pdf

https://www.cisa.gov/sites/default/files/publications/CISA_CPG_CHECKLIST_508c.pdf
CISA_CPG_CHECKLIST_508c.pdf

Qakbot/Qakbot_BB05_01.11.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_BB05_01.11.2022.txt
Qakbot/Qakbot_BB05_01.11.2022.txt at main · pr0xylife/Qakbot · GitHub

Google ad for GIMP.org served info-stealing malware via lookalike site

https://www.bleepingcomputer.com/news/security/google-ad-for-gimporg-served-info-stealing-malware-via-lookalike-site/
Google ad for GIMP.org served info-stealing malware via lookalike site

OpenSSL-2022/README.md at main · NCSC-NL/OpenSSL-2022 · GitHub

https://github.com/NCSC-NL/OpenSSL-2022/blob/main/software/README.md
OpenSSL-2022/README.md at main · NCSC-NL/OpenSSL-2022 · GitHub

APT10: Tracking down LODEINFO 2022, part I | Securelist

https://securelist.com/apt10-tracking-down-lodeinfo-2022-part-i/107742/
APT10: Tracking down LODEINFO 2022, part I | Securelist

SANS Difference Makers 2022 - community vote

https://survey.sans.org/jfe/form/SV_eXuwVrkCVdeoKMu
SANS Difference Makers 2022 - community vote

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/614c3f36b2f32d43246a250bc12eeaeb5dfbed64f8cf5d1db72ab5f09c171ab3/
MalwareBazaar | Browse Checking your browser

Everything you need to know about the OpenSSL 3.0.7 Patch - MalwareTech

https://malwaretech.com/2022/11/everything-you-need-to-know-about-the-openssl-3-0-7-patch.html
Everything you need to know about the OpenSSL 3.0.7 Patch - MalwareTech

OpenSSL-2022/software at main · NCSC-NL/OpenSSL-2022 · GitHub

https://github.com/NCSC-NL/OpenSSL-2022/tree/main/software
OpenSSL-2022/software at main · NCSC-NL/OpenSSL-2022 · GitHub

Chinese Hackers Using New Stealthy Infection Chain to Deploy LODEINFO Malware

https://thehackernews.com/2022/11/chinese-hackers-using-new-stealthy.html
Chinese Hackers Using New Stealthy Infection Chain to Deploy LODEINFO Malware

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/592dc94d71effe762414d7d1ab10df18bf999340dd5851f0c132509d3f525dc2/
MalwareBazaar | Browse Checking your browser