02/03

Pre-Auth RCE in Aspera Faspex: Case Guide for Auditing Ruby on Rails – Assetnote

https://blog.assetnote.io/2023/02/02/pre-auth-rce-aspera-faspex/
Pre-Auth RCE in Aspera Faspex: Case Guide for Auditing Ruby on Rails – Assetnote

Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide

https://www.bleepingcomputer.com/news/security/massive-esxiargs-ransomware-attack-targets-vmware-esxi-servers-worldwide/
Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide

Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware | EclecticIQ

https://blog.eclecticiq.com/mustang-panda-apt-group-uses-european-commission-themed-lure-to-deliver-plugx-malware
Mustang Panda APT Group Uses European Commission-Themed Lure to Deliver PlugX Malware | EclecticIQ

Adobe Acrobat Reader - resetForm - CAgg UaF - RCE Exploit - CVE-2023-21608 - HackSys Inc

https://hacksys.io/blogs/adobe-reader-resetform-cagg-rce-cve-2023-21608
Adobe Acrobat Reader - resetForm - CAgg UaF - RCE Exploit - CVE-2023-21608 - HackSys Inc

Iran responsible for Charlie Hebdo attacks - Microsoft On the Issues

https://blogs.microsoft.com/on-the-issues/2023/02/03/dtac-charlie-hebdo-hack-iran-neptunium/
Iran responsible for Charlie Hebdo attacks - Microsoft On the Issues

Adobe Acrobat Reader - resetForm - CAgg UaF - RCE Exploit - CVE-2023-21608 - HackSys Inc

https://hacksys.io/blogs/adobe-reader-resetform-cagg-rce-CVE-2023-21608
Adobe Acrobat Reader - resetForm - CAgg UaF - RCE Exploit - CVE-2023-21608 - HackSys Inc

Atlassian's Jira Software Found Vulnerable to Critical Authentication Vulnerability

https://thehackernews.com/2023/02/atlassians-jira-software-found.html
Atlassian's Jira Software Found Vulnerable to Critical Authentication Vulnerability

North Korean hackers stole research data in two-month-long breach

https://www.bleepingcomputer.com/news/security/north-korean-hackers-stole-research-data-in-two-month-long-breach/
North Korean hackers stole research data in two-month-long breach

Iranian OilRig Hackers Using New Backdoor to Exfiltrate Data from Govt. Organizations

https://thehackernews.com/2023/02/iranian-oilrig-hackers-using-new.html
Iranian OilRig Hackers Using New Backdoor to Exfiltrate Data from Govt. Organizations

CISA Alert: Oracle E-Business Suite and SugarCRM Vulnerabilities Under Attack

https://thehackernews.com/2023/02/cisa-alert-oracle-e-business-suite-and.html
CISA Alert: Oracle E-Business Suite and SugarCRM Vulnerabilities Under Attack

New York attorney general orders stalkerware maker to notify hacked victims | TechCrunch

https://techcrunch.com/2023/02/03/new-york-stalkerware-notify-victims/
New York attorney general orders stalkerware maker to notify hacked victims | TechCrunch

Google ads push ‘virtualized’ malware made for antivirus evasion

https://www.bleepingcomputer.com/news/security/google-ads-push-virtualized-malware-made-for-antivirus-evasion/
Google ads push ‘virtualized’ malware made for antivirus evasion

Malware-IOCs/2023-01-31 Unknown Rust (likely) Stealer IOCs at main · executemalware/Malware-IOCs · GitHub

https://github.com/executemalware/Malware-IOCs/blob/main/2023-01-31%20Unknown%20Rust%20(likely)%20Stealer%20IOCs
Malware-IOCs/2023-01-31 Unknown Rust (likely) Stealer IOCs at main · executemalware/Malware-IOCs · GitHub

https://pathonproject.com/zb/?a2282305b884d3f8#MYGSdFNv+ZNZPvgP1jHuEdaXOd+DXZa/dZ9VYVS5XKo=

https://pathonproject.com/zb/?a2282305b884d3f8#MYGSdFNv+ZNZPvgP1jHuEdaXOd+DXZa/dZ9VYVS5XKo=