04/21

X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe | Symantec Enterprise Blogs

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain
X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe | Symantec Enterprise Blogs

Windows secrets extraction: a summary

https://www.synacktiv.com/publications/windows-secrets-extraction-a-summary
Windows secrets extraction: a summary

AppLocker Bypass – CreateRestrictedToken – Penetration Testing Lab

https://pentestlab.blog/2017/07/07/applocker-bypass-createrestrictedtoken/
AppLocker Bypass – CreateRestrictedToken – Penetration Testing Lab

Kubernetes RBAC Exploited in Large-Scale Campaign for Cryptocurrency Mining

https://thehackernews.com/2023/04/kubernetes-rbac-exploited-in-large.html
Kubernetes RBAC Exploited in Large-Scale Campaign for Cryptocurrency Mining

Exposed Web Panel Reveals Gamaredon Group's Automated Spear Phishing Campaigns

https://blog.eclecticiq.com/exposed-web-panel-reveals-gamaredon-groups-automated-spear-phishing-campaigns
Exposed Web Panel Reveals Gamaredon Group's Automated Spear Phishing Campaigns

Circumventing SRP and AppLocker to Create a New Process, By Design | Didier Stevens

https://blog.didierstevens.com/2011/01/25/circumventing-srp-and-applocker-to-create-a-new-process-by-design/
Circumventing SRP and AppLocker to Create a New Process, By Design | Didier Stevens

American Bar Association data breach hits 1.4 million members

https://www.bleepingcomputer.com/news/security/american-bar-association-data-breach-hits-14-million-members/
American Bar Association data breach hits 1.4 million members

N.K. Hackers Employ Matryoshka Doll-Style Cascading Supply Chain Attack on 3CX

https://thehackernews.com/2023/04/nk-hackers-employ-matryoshka-doll-style.html
N.K. Hackers Employ Matryoshka Doll-Style Cascading Supply Chain Attack on 3CX

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/5013cf8a7cf2e0e230f8c7149d2c9eb99c681cda6d754f58e2409d6f3db98c56/
MalwareBazaar | Browse Checking your browser

Cisco and VMware Release Security Updates to Patch Critical Flaws in their Products

https://thehackernews.com/2023/04/cisco-and-vmware-release-security.html
Cisco and VMware Release Security Updates to Patch Critical Flaws in their Products

GitHub - blasty/sonos

https://github.com/blasty/sonos
GitHub - blasty/sonos

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/sample/2bb49909ef6d4200d177dbaaa400ab01b185201c8e21b418c5bef53ce09e6cd5/
MalwareBazaar | Browse Checking your browser

GhostToken GCP flaw let attackers backdoor Google accounts

https://www.bleepingcomputer.com/news/security/ghosttoken-gcp-flaw-let-attackers-backdoor-google-accounts/
GhostToken GCP flaw let attackers backdoor Google accounts

3CX Breach Was a Double Supply Chain Compromise – Krebs on Security

https://krebsonsecurity.com/2023/04/3cx-breach-was-a-double-supply-chain-compromise/
3CX Breach Was a Double Supply Chain Compromise – Krebs on Security

YaraDBG v0.0.2

https://yaradbg.dev/
YaraDBG v0.0.2

University websites using MediaWiki, TWiki hacked to serve Fortnite spam

https://www.bleepingcomputer.com/news/security/university-websites-using-mediawiki-twiki-hacked-to-serve-fortnite-spam/
University websites using MediaWiki, TWiki hacked to serve Fortnite spam

Attackers use abandoned WordPress plugin to backdoor websites

https://www.bleepingcomputer.com/news/security/attackers-use-abandoned-wordpress-plugin-to-backdoor-websites/
Attackers use abandoned WordPress plugin to backdoor websites

Threat Advisory: Undetected North Korean Malware: A Looming Threat to Financial Institutions

https://www.bridewell.com/insights/news/detail/cti-advisory-undetected-nk-malware
Threat Advisory: Undetected North Korean Malware: A Looming Threat to Financial Institutions

Speak – BSides Belfast

https://bsidesbelfast.org/speak
Speak – BSides Belfast

GitHub - Orange-Cyberdefense/GOAD: game of active directory

https://github.com/Orange-Cyberdefense/GOAD
GitHub - Orange-Cyberdefense/GOAD: game of active directory

Mullvad VPN was subject to a search warrant. Customer data not compromised - Blog | Mullvad VPN

https://mullvad.net/blog/2023/4/20/mullvad-vpn-was-subject-to-a-search-warrant-customer-data-not-compromised/
Mullvad VPN was subject to a search warrant. Customer data not compromised - Blog | Mullvad VPN

Compromising Garmin's Sport Watches: A Deep Dive into GarminOS and its MonkeyC Virtual Machine - Anvil Secure

https://www.anvilsecure.com/blog/compromising-garmins-sport-watches-a-deep-dive-into-garminos-and-its-monkeyc-virtual-machine.html
Compromising Garmin's Sport Watches: A Deep Dive into GarminOS and its MonkeyC Virtual Machine - Anvil Secure

Xiaoqiying/Genesis Day Threat Actor Group Targets South Korea, Taiwan | Recorded Future

https://www.recordedfuture.com/xiaoqiying-genesis-day-threat-actor-group-targets-south-korea-taiwan
Xiaoqiying/Genesis Day Threat Actor Group Targets South Korea, Taiwan | Recorded Future

GhostToken Flaw Could Let Attackers Hide Malicious Apps in Google Cloud Platform

https://thehackernews.com/2023/04/ghosttoken-flaw-could-let-attackers.html
GhostToken Flaw Could Let Attackers Hide Malicious Apps in Google Cloud Platform

Fortra Sheds Light on GoAnywhere MFT Zero-Day Exploit Used in Ransomware Attacks

https://thehackernews.com/2023/04/fortra-sheds-light-on-goanywhere-mft.html
Fortra Sheds Light on GoAnywhere MFT Zero-Day Exploit Used in Ransomware Attacks

The Huge 3CX Breach Was Actually 2 Linked Supply Chain Attacks | WIRED

https://www.wired.com/story/3cx-supply-chain-attack-times-two/
The Huge 3CX Breach Was Actually 2 Linked Supply Chain Attacks | WIRED

Ransomware Attack Hits Marinette Marine Shipyard, Results in Short-Term Delay of Frigate, Freedom LCS Construction - USNI News

https://news.usni.org/2023/04/20/ransomware-attack-hits-marinette-marine-shipyard-results-in-short-term-delay-of-frigate-freedom-lcs-construction
Ransomware Attack Hits Marinette Marine Shipyard, Results in Short-Term Delay of Frigate, Freedom LCS Construction - USNI News

proxmox | Mayfly

https://mayfly277.github.io/categories/proxmox/
proxmox | Mayfly

Dropbox - Empire Wiki

https://bc-security.gitbook.io/empire-wiki/listeners/dropbox
Dropbox - Empire Wiki

'RustBucket' malware targets macOS

https://www.jamf.com/blog/bluenoroff-apt-targets-macos-rustbucket-malware/
'RustBucket' malware targets macOS

Release YARA v4.3.1 · VirusTotal/yara · GitHub

https://github.com/VirusTotal/yara/releases/tag/v4.3.1
Release YARA v4.3.1 · VirusTotal/yara · GitHub

CYBERWARCON - YouTube

https://youtube.com/@cyberwarcon
CYBERWARCON - YouTube