11/15

Stealing passwords from infosec Mastodon - without bypassing CSP | PortSwigger Research

https://portswigger.net/research/stealing-passwords-from-infosec-mastodon-without-bypassing-csp
Stealing passwords from infosec Mastodon - without bypassing CSP | PortSwigger Research

It’s all in the details: The curious case of an lsass dumper gone undetected

https://dec0ne.github.io/research/2022-11-14-Undetected-Lsass-Dump-Workflow/
It’s all in the details: The curious case of an lsass dumper gone undetected

Top Zeus Botnet Suspect “Tank” Arrested in Geneva – Krebs on Security

https://krebsonsecurity.com/2022/11/top-zeus-botnet-suspect-tank-arrested-in-geneva/
Top Zeus Botnet Suspect “Tank” Arrested in Geneva – Krebs on Security

Researchers Say China State-backed Hackers Breached a Digital Certificate Authority

https://thehackernews.com/2022/11/researchers-say-china-state-backed.html
Researchers Say China State-backed Hackers Breached a Digital Certificate Authority

Varonis Threat Labs Discovers SQLi and Access Flaws in Zendesk

https://www.varonis.com/blog/zendesk-sql-injection-and-access-flaws
Varonis Threat Labs Discovers SQLi and Access Flaws in Zendesk

Indestructible G0thm0g - CrackMapExec ~ CME WIKI

https://wiki.porchetta.industries/news-2022/indestructible-g0thm0g
Indestructible G0thm0g - CrackMapExec ~ CME WIKI

Typhon Reborn With New Capabilities

https://unit42.paloaltonetworks.com/typhon-reborn-stealer/
Typhon Reborn With New Capabilities

Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries | Symantec Enterprise Blogs

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-governments-cert-authority
Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries | Symantec Enterprise Blogs

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/2cb8f04d41fe34706ff61cba06788faaaca87494721fcf8e86d20b897890a3b1/
MalwareBazaar | Browse Checking your browser

Chinese hackers target government agencies and defense orgs

https://www.bleepingcomputer.com/news/security/chinese-hackers-target-government-agencies-and-defense-orgs/
Chinese hackers target government agencies and defense orgs

Qakbot/Qakbot_BB05_15.11.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_BB05_15.11.2022.txt
Qakbot/Qakbot_BB05_15.11.2022.txt at main · pr0xylife/Qakbot · GitHub

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/440d84b5d539d7724898e4127df3d5f0d68cefb5bc14f09b13b2e657a3dc7a08/
MalwareBazaar | Browse Checking your browser

Internet disruptions registered as Russia moves in on Ukraine - NetBlocks

https://netblocks.org/reports/internet-disruptions-registered-as-russia-moves-in-on-ukraine-W80p4k8K
Internet disruptions registered as Russia moves in on Ukraine - NetBlocks

Google to Pay $391 Million Privacy Fine for Secretly Tracking Users' Location

https://thehackernews.com/2022/11/google-to-pays-391-million-privacy-fine.html
Google to Pay $391 Million Privacy Fine for Secretly Tracking Users' Location

Hacking Salesforce-backed WebApps - Hypn.za.net

https://www.hypn.za.net/blog/2022/11/12/Hacking-Salesforce-backed-WebApps/
Hacking Salesforce-backed WebApps - Hypn.za.net