01/28

Bypassing OGNL sandboxes for fun and charities | The GitHub Blog

https://github.blog/2023-01-27-bypassing-ognl-sandboxes-for-fun-and-charities/
Bypassing OGNL sandboxes for fun and charities | The GitHub Blog

SIP / VoIP - Pentester's Promiscuous Notebook

https://ppn.snovvcrash.rocks/pentest/infrastructure/networks/sip-voip#cisco-ip-phones
SIP / VoIP - Pentester's Promiscuous Notebook

Ukraine: Sandworm hackers hit news agency with 5 data wipers

https://www.bleepingcomputer.com/news/security/ukraine-sandworm-hackers-hit-news-agency-with-5-data-wipers/
Ukraine: Sandworm hackers hit news agency with 5 data wipers

APT_REPORT/2022-Blockchain-Security-and-AML-Analysis-Annual-Report(EN).pdf at master · blackorbird/APT_REPORT · GitHub

https://github.com/blackorbird/APT_REPORT/blob/master/summary/2023/2022-Blockchain-Security-and-AML-Analysis-Annual-Report(EN).pdf
APT_REPORT/2022-Blockchain-Security-and-AML-Analysis-Annual-Report(EN).pdf at master · blackorbird/APT_REPORT · GitHub

#GermanyRIP. Kremlin-loyal hacktivists wage DDoSes to retaliate for tank aid | Ars Technica

https://arstechnica.com/information-technology/2023/01/germanyrip-kremlin-loyal-hacktivists-wage-ddoses-to-retaliate-for-tank-aid/
#GermanyRIP. Kremlin-loyal hacktivists wage DDoSes to retaliate for tank aid | Ars Technica

The Week in Ransomware - January 27th 2023 - 'We hacked the hackers'

https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-january-27th-2023-we-hacked-the-hackers/
The Week in Ransomware - January 27th 2023 - 'We hacked the hackers'

Experts Uncover the Identity of Mastermind Behind Golden Chickens Malware Service

https://thehackernews.com/2023/01/experts-uncover-identity-of-mastermind.html
Experts Uncover the Identity of Mastermind Behind Golden Chickens Malware Service

A leaked internal message appears to show Elon Musk ordered Twitter staff to suspend a left-wing activist's account

https://www.msn.com/en-us/money/other/a-leaked-internal-message-appears-to-show-elon-musk-ordered-twitter-staff-to-suspend-a-left-wing-activist-s-account/ar-AA16NS0X?ocid=msedgntp&cvid=f468f8fa0e7544e098c70ac94e75aab9
A leaked internal message appears to show Elon Musk ordered Twitter staff to suspend a left-wing activist's account

ISC Releases Security Patches for New BIND DNS Software Vulnerabilities

https://thehackernews.com/2023/01/isc-releases-security-patches-for-new.html
ISC Releases Security Patches for New BIND DNS Software Vulnerabilities

GitHub - ReFirmLabs/binwalk: Firmware Analysis Tool

https://github.com/ReFirmLabs/binwalk
GitHub - ReFirmLabs/binwalk: Firmware Analysis Tool

At the Edge of Tier Zero: The Curious Case of the RODC | by Elad Shamir | Posts By SpecterOps Team Members

https://posts.specterops.io/at-the-edge-of-tier-zero-the-curious-case-of-the-rodc-ef5f1799ca06
At the Edge of Tier Zero: The Curious Case of the RODC | by Elad Shamir | Posts By SpecterOps Team Members

How US police use digital data to prosecute abortions | TechCrunch

https://techcrunch.com/2023/01/27/digital-data-roe-wade-reproductive-privacy/
How US police use digital data to prosecute abortions | TechCrunch

Massive Microsoft 365 outage caused by WAN router IP change

https://www.bleepingcomputer.com/news/microsoft/massive-microsoft-365-outage-caused-by-wan-router-ip-change/
Massive Microsoft 365 outage caused by WAN router IP change

Docguard | Detects suspicious files!

https://app.docguard.io/3de760cbd285be07260fc3ddb8e39504b8a602435a077c7f89a5782d8e050e99/results/dashboard
Docguard | Detects suspicious files!

RCE exploit for vRealize Log Insight coming next week, patch now

https://www.bleepingcomputer.com/news/security/rce-exploit-for-vrealize-log-insight-coming-next-week-patch-now/
RCE exploit for vRealize Log Insight coming next week, patch now

GitHub - garrettfoster13/pre2k

https://github.com/garrettfoster13/pre2k
GitHub - garrettfoster13/pre2k

Ransomware experts laud Hive takedown but question impact without arrests - The Record from Recorded Future News

https://therecord.media/ransomware-experts-laud-hive-takedown-but-question-impact-without-arrests/
Ransomware experts laud Hive takedown but question impact without arrests - The Record from Recorded Future News

Bypassing Cloudflare WAF: XSS via SQL Injection

https://www.ukusormus.com/bypassing-cloudflare-waf-xss-via-sql-injection/
Bypassing Cloudflare WAF: XSS via SQL Injection