11/02

Project Zero: Gregor Samsa: Exploiting Java's XML Signature Verification

https://googleprojectzero.blogspot.com/2022/11/gregor-samsa-exploiting-java-xml.html
Project Zero: Gregor Samsa: Exploiting Java's XML Signature Verification

SANS Difference Makers 2022 - community vote

https://survey.sans.org/jfe/form/SV_eXuwVrkCVdeoKMu
SANS Difference Makers 2022 - community vote

Emotet botnet starts blasting malware again after 5 month break

https://www.bleepingcomputer.com/news/security/emotet-botnet-starts-blasting-malware-again-after-5-month-break/
Emotet botnet starts blasting malware again after 5 month break

Dropbox discloses breach after hacker stole 130 GitHub repositories

https://www.bleepingcomputer.com/news/security/dropbox-discloses-breach-after-hacker-stole-130-github-repositories/
Dropbox discloses breach after hacker stole 130 GitHub repositories

405 Banned

https://urlhaus.abuse.ch/browse/tag/emotet/
405 Banned

How we handled a recent phishing incident that targeted Dropbox - Dropbox

https://dropbox.tech/security/a-recent-phishing-campaign-targeting-dropbox
How we handled a recent phishing incident that targeted Dropbox - Dropbox

VirusTotal - File - d07d1a4e7e5bac0eb9a34aaf4505742389e354808d5a73f1f5b6a41836a0d830

https://www.virustotal.com/gui/file/d07d1a4e7e5bac0eb9a34aaf4505742389e354808d5a73f1f5b6a41836a0d830
VirusTotal - File - d07d1a4e7e5bac0eb9a34aaf4505742389e354808d5a73f1f5b6a41836a0d830

New SandStrike spyware infects Android devices via malicious VPN app

https://www.bleepingcomputer.com/news/security/new-sandstrike-spyware-infects-android-devices-via-malicious-vpn-app/
New SandStrike spyware infects Android devices via malicious VPN app

Triage | Behavioral Report

https://tria.ge/221102-lh8zcsagb6/behavioral1
Triage | Behavioral Report

Chinese Hackers Using New Stealthy Infection Chain to Deploy LODEINFO Malware

https://thehackernews.com/2022/11/chinese-hackers-using-new-stealthy.html
Chinese Hackers Using New Stealthy Infection Chain to Deploy LODEINFO Malware

曝光!“海莲花”组织运营的物联网僵尸网络Torii

https://mp.weixin.qq.com/s/v2wiJe-YPG0ng87ffBB9FQ
曝光!“海莲花”组织运营的物联网僵尸网络Torii

Binary Defense Raises $36 Million From Invictus Growth Partners to Propel Rapid Expansion as the Most Trusted MDR Platform | Business Wire

https://www.businesswire.com/news/home/20221102005333/en/Binary-Defense-Raises-36-Million-From-Invictus-Growth-Partners-to-Propel-Rapid-Expansion-as-the-Most-Trusted-MDR-Platform
Binary Defense Raises $36 Million From Invictus Growth Partners to Propel Rapid Expansion as the Most Trusted MDR Platform | Business Wire

曝光!“海莲花”组织运营的物联网僵尸网络Torii

https://mp-weixin-qq-com.translate.goog/s/v2wiJe-YPG0ng87ffBB9FQ?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
曝光!“海莲花”组织运营的物联网僵尸网络Torii

GitHub - colmmacc/CVE-2022-3602

https://github.com/colmmacc/CVE-2022-3602
GitHub - colmmacc/CVE-2022-3602

Exploiting Static Site Generators: When Static Is Not Actually Static – Assetnote

https://blog.assetnote.io/2022/10/28/exploiting-static-site-generators/
Exploiting Static Site Generators: When Static Is Not Actually Static – Assetnote