03/26

Emotet malware distributed as fake W-9 tax forms from the IRS

https://www.bleepingcomputer.com/news/security/emotet-malware-distributed-as-fake-w-9-tax-forms-from-the-irs/
Emotet malware distributed as fake W-9 tax forms from the IRS

Utah social media law requires parental permission for kids : NPR

https://www.npr.org/2023/03/24/1165764450/utahs-new-social-media-law-means-children-will-need-approval-from-parents
Utah social media law requires parental permission for kids : NPR

GitHub - corkami/pics: Posters, drawings...

https://github.com/corkami/pics
GitHub - corkami/pics: Posters, drawings...

Guidance for investigating attacks using CVE-2023-23397 - Microsoft Security Blog

https://www.microsoft.com/en-us/security/blog/2023/03/24/guidance-for-investigating-attacks-using-cve-2023-23397/
Guidance for investigating attacks using CVE-2023-23397 - Microsoft Security Blog

Patch Tuesday -> Exploit Wednesday: Pwning Windows Ancillary Function Driver for WinSock (afd.sys) in 24 Hours

https://securityintelligence.com/posts/patch-tuesday-exploit-wednesday-pwning-windows-ancillary-function-driver-winsock/
Patch Tuesday -> Exploit Wednesday: Pwning Windows Ancillary Function Driver for WinSock (afd.sys) in 24 Hours

[QuickNote] Decrypting the C2 configuration of Warzone RAT | 0day in {REA_TEAM}

https://kienmanowar.wordpress.com/2023/03/25/quicknote-decrypting-the-c2-configuration-of-warzone-rat/
[QuickNote] Decrypting the C2 configuration of Warzone RAT | 0day in {REA_TEAM}

Untitled Goose Tool Aids Hunt and Incident Response in Azure, Azure Active Directory, and Microsoft 365 Environments | CISA

https://www.cisa.gov/news-events/alerts/2023/03/23/untitled-goose-tool-aids-hunt-and-incident-response-azure-azure-active-directory-and-microsoft-365
Untitled Goose Tool Aids Hunt and Incident Response in Azure, Azure Active Directory, and Microsoft 365 Environments | CISA

yara-rules/msil_susp_obf_xorstringsnet.yar at main · dr4k0nia/yara-rules · GitHub

https://github.com/dr4k0nia/yara-rules/blob/main/dotnet/msil_susp_obf_xorstringsnet.yar
yara-rules/msil_susp_obf_xorstringsnet.yar at main · dr4k0nia/yara-rules · GitHub

Triage | Behavioral Report

https://tria.ge/230326-sncxfagh98/behavioral2
Triage | Behavioral Report

Our Pwn2Own journey against time and randomness (part 1)

https://blog.quarkslab.com/our-pwn2own-journey-against-time-and-randomness-part-1.html
Our Pwn2Own journey against time and randomness (part 1)

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/1c9264473281f0d5144912a8c05d803697c7da8707cd5607017e6936d2fa1588/
MalwareBazaar | Browse Checking your browser

Apple Safari JavaScriptCore Inspector Type Confusion - SSD Secure Disclosure

https://ssd-disclosure.com/apple-safari-javascriptcore-inspector-type-confusion/
Apple Safari JavaScriptCore Inspector Type Confusion - SSD Secure Disclosure

Vibrator maker ordered to pay out C$4m for tracking users' sexual activity | Data protection | The Guardian

https://www.theguardian.com/technology/2017/mar/14/we-vibe-vibrator-tracking-users-sexual-habits
Vibrator maker ordered to pay out C$4m for tracking users' sexual activity | Data protection | The Guardian

Reversing UK mobile rail tickets

https://eta.st/2023/01/31/rail-tickets.html
Reversing UK mobile rail tickets

The SQL Injection Knowledge Base

https://www.websec.ca/kb/sql_injection
The SQL Injection Knowledge Base

#1865991 Open Redirect Vulnerability in Action Pack

https://hackerone.com/reports/1865991
#1865991 Open Redirect Vulnerability in Action Pack

grsecurity - Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse

https://grsecurity.net/exploiting_and_defending_against_same_type_object_reuse
grsecurity - Canary in the Kernel Mine: Exploiting and Defending Against Same-Type Object Reuse

Release TokenUniverse v0.3 · diversenok/TokenUniverse · GitHub

https://github.com/diversenok/TokenUniverse/releases/tag/v0.3
Release TokenUniverse v0.3 · diversenok/TokenUniverse · GitHub

h26forge.pdf

https://wrv.github.io/h26forge.pdf
h26forge.pdf

PoC-Malware-TTPs/PrintBrm-Impant-Exec at main · knight0x07/PoC-Malware-TTPs · GitHub

https://github.com/knight0x07/PoC-Malware-TTPs/tree/main/PrintBrm-Impant-Exec
PoC-Malware-TTPs/PrintBrm-Impant-Exec at main · knight0x07/PoC-Malware-TTPs · GitHub

#1265709 Lack of bruteforce protection for TOTP 2FA

https://hackerone.com/reports/1265709
#1265709 Lack of bruteforce protection for TOTP 2FA

Vice Society claims attack on Puerto Rico Aqueduct and Sewer AuthoritySecurity Affairs

https://securityaffairs.com/144022/hacking/puerto-rico-aqueduct-and-sewer-authority-attack.html
Vice Society claims attack on Puerto Rico Aqueduct and Sewer AuthoritySecurity Affairs

Week 13 – 2023 – This Week In 4n6

http://thisweekin4n6.com/2023/03/26/week-13-2023/
Week 13 – 2023 – This Week In 4n6

Exploit Pack

https://exploitpack.com
Exploit Pack

Breaking Pedersen Hashes in Practice – NCC Group Research

https://research.nccgroup.com/2023/03/22/breaking-pedersen-hashes-in-practice/
Breaking Pedersen Hashes in Practice – NCC Group Research