01/19

CVE-2022-47966 SAML ShowStopper

https://blog.viettelcybersecurity.com/saml-show-stopper/
CVE-2022-47966 SAML ShowStopper

Exploiting CVE-2021-3490 for Container Escapes | CrowdStrike

https://www.crowdstrike.com/blog/exploiting-cve-2021-3490-for-container-escapes/
Exploiting CVE-2021-3490 for Container Escapes | CrowdStrike

Project Zero: Exploiting null-dereferences in the Linux kernel

https://googleprojectzero.blogspot.com/2023/01/exploiting-null-dereferences-in-linux.html
Project Zero: Exploiting null-dereferences in the Linux kernel

CVE-2022-21587 (Oracle E-Business Suite Unauthenticated RCE)

https://blog.viettelcybersecurity.com/cve-2022-21587-oracle-e-business-suite-unauth-rce/
CVE-2022-21587 (Oracle E-Business Suite Unauthenticated RCE)

2022 Microsoft Teams RCE

https://blog.pksecurity.io/2023/01/16/2022-microsoft-teams-rce.html
2022 Microsoft Teams RCE

Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475) | Mandiant

https://www.mandiant.com/resources/blog/chinese-actors-exploit-fortios-flaw
Suspected Chinese Threat Actors Exploiting FortiOS Vulnerability (CVE-2022-42475) | Mandiant

Firefox在野0day分析

https://weiyiling.cn/one/firefox_0day_case_analysis
Firefox在野0day分析

Gamaredon (Ab)uses Telegram to Target Ukrainian Organizations

https://blogs.blackberry.com/en/2023/01/gamaredon-abuses-telegram-to-target-ukrainian-organizations
Gamaredon (Ab)uses Telegram to Target Ukrainian Organizations

PayPal accounts breached in large-scale credential stuffing attack

https://www.bleepingcomputer.com/news/security/paypal-accounts-breached-in-large-scale-credential-stuffing-attack/
PayPal accounts breached in large-scale credential stuffing attack

Malware-IOCs/2023-01-18 Redline IOCs at main · executemalware/Malware-IOCs · GitHub

https://github.com/executemalware/Malware-IOCs/blob/main/2023-01-18%20Redline%20IOCs
Malware-IOCs/2023-01-18 Redline IOCs at main · executemalware/Malware-IOCs · GitHub

MailChimp discloses new breach after employees got hacked

https://www.bleepingcomputer.com/news/security/mailchimp-discloses-new-breach-after-employees-got-hacked/
MailChimp discloses new breach after employees got hacked

Anh Chu on LinkedIn: #openforwork #layoff #womenintech #h1b | 809 comments

https://www.linkedin.com/posts/anhhchu_openforwork-layoff-womenintech-activity-7021577931734847488-t1kd
Anh Chu on LinkedIn: #openforwork #layoff #womenintech #h1b | 809 comments

(3) Ukrainians accuse Russian military hackers of disrupting press briefing on cyberattacks

https://www.cnn.com/europe/live-news/russia-ukraine-war-news-1-18-23/h_666a99949693d5bea317f9c8b6d259e4
(3) Ukrainians accuse Russian military hackers of disrupting press briefing on cyberattacks

Ransomware profits drop 40% in 2022 as victims refuse to pay

https://www.bleepingcomputer.com/news/security/ransomware-profits-drop-40-percent-in-2022-as-victims-refuse-to-pay/
Ransomware profits drop 40% in 2022 as victims refuse to pay

New 'Blank Image' attack hides phishing scripts in SVG files

https://www.bleepingcomputer.com/news/security/new-blank-image-attack-hides-phishing-scripts-in-svg-files/
New 'Blank Image' attack hides phishing scripts in SVG files

Ransomware attack hits nearly 300 fast food restaurants in UK, including KFC and Pizza Hut - The Record from Recorded Future News

https://therecord.media/ransomware-attack-hits-nearly-300-fast-food-restaurants-in-uk-including-kfc-and-pizza-hut/
Ransomware attack hits nearly 300 fast food restaurants in UK, including KFC and Pizza Hut - The Record from Recorded Future News

ManageEngine CVE-2022-47966 Technical Deep Dive – Horizon3.ai

https://www.horizon3.ai/manageengine-cve-2022-47966-technical-deep-dive/
ManageEngine CVE-2022-47966 Technical Deep Dive – Horizon3.ai