01/10

GitHub - blasty/lexmark

https://github.com/blasty/lexmark
GitHub - blasty/lexmark

www.localpotato.com

http://www.localpotato.com
www.localpotato.com

The OWASSRF + TabShell exploit chain

https://blog.viettelcybersecurity.com/tabshell-owassrf/
The OWASSRF + TabShell exploit chain

SCATTERED SPIDER Attempts to Avoid Detection with Bring-Your-Own-Driver Tactic

https://www.crowdstrike.com/blog/scattered-spider-attempts-to-avoid-detection-with-bring-your-own-driver-tactic/
SCATTERED SPIDER Attempts to Avoid Detection with Bring-Your-Own-Driver Tactic

Disclosing a New Vulnerability in JWT Secret Poisoning (CVE-2022-23529)

https://unit42.paloaltonetworks.com/jsonwebtoken-vulnerability-cve-2022-23529/
Disclosing a New Vulnerability in JWT Secret Poisoning (CVE-2022-23529)

entrat.exe (MD5: AA225301DD06B562ED9668DF7E742101) - Interactive analysis - ANY.RUN

https://app.any.run/tasks/9b362341-ab97-4999-97f5-62cdb04b1489
entrat.exe (MD5: AA225301DD06B562ED9668DF7E742101) - Interactive analysis - ANY.RUN

http://www.itcci.jp/

http://www.itcci.jp/

Auth0 fixes RCE flaw in JsonWebToken library used by 22,000 projects

https://www.bleepingcomputer.com/news/security/auth0-fixes-rce-flaw-in-jsonwebtoken-library-used-by-22-000-projects/
Auth0 fixes RCE flaw in JsonWebToken library used by 22,000 projects

StrongPity espionage campaign targeting Android users | WeLiveSecurity

https://www.welivesecurity.com/2023/01/10/strongpity-espionage-campaign-targeting-android-users/
StrongPity espionage campaign targeting Android users | WeLiveSecurity

Microsoft: Kubernetes clusters hacked in malware campaign via PostgreSQL

https://www.bleepingcomputer.com/news/security/microsoft-kubernetes-clusters-hacked-in-malware-campaign-via-postgresql/
Microsoft: Kubernetes clusters hacked in malware campaign via PostgreSQL