04/28

Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707) | STAR Labs

https://starlabs.sg/blog/2023/04-microsoft-exchange-powershell-remoting-deserialization-leading-to-rce-cve-2023-21707/
Microsoft Exchange Powershell Remoting Deserialization leading to RCE (CVE-2023-21707) | STAR Labs

PSBits/ETW at master · gtworek/PSBits · GitHub

https://github.com/gtworek/PSBits/tree/master/ETW
PSBits/ETW at master · gtworek/PSBits · GitHub

Zyxel Firewall Devices Vulnerable to Remote Code Execution Attacks — Patch Now

https://thehackernews.com/2023/04/zyxel-firewall-devices-vulnerable-to.html
Zyxel Firewall Devices Vulnerable to Remote Code Execution Attacks — Patch Now

Stop the passing of the Online Safety Bill - Petitions

https://petition.parliament.uk/petitions/634725
Stop the passing of the Online Safety Bill - Petitions

Tonto Team Uses Anti-Malware File to Launch Attacks on South Korean Institutions

https://thehackernews.com/2023/04/tonto-team-uses-anti-malware-file-to.html
Tonto Team Uses Anti-Malware File to Launch Attacks on South Korean Institutions

Driver adventures for a 1999 webcam

https://blog.benjojo.co.uk/post/quickcam-usb-userspace-driver
Driver adventures for a 1999 webcam

Qakbot/Qakbot_obama258_28.04.2023.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_obama258_28.04.2023.txt
Qakbot/Qakbot_obama258_28.04.2023.txt at main · pr0xylife/Qakbot · GitHub

DOJ Detected SolarWinds Breach Months Before Public Disclosure | WIRED

https://www.wired.com/story/solarwinds-hack-public-disclosure/
DOJ Detected SolarWinds Breach Months Before Public Disclosure | WIRED

VirusTotal - File - a58da133b8aedcdca44489bf5bac98a1257f050af186620c8c0bae110f1e672b

https://www.virustotal.com/gui/file/a58da133b8aedcdca44489bf5bac98a1257f050af186620c8c0bae110f1e672b
VirusTotal - File - a58da133b8aedcdca44489bf5bac98a1257f050af186620c8c0bae110f1e672b

LastCall Injection PoC · GitHub

https://gist.github.com/Wra7h/0bfa02ccd236fa300f11ea656580381a
LastCall Injection PoC · GitHub

Finding XSS in a million websites (cPanel CVE-2023-29489) – Assetnote

https://blog.assetnote.io/2023/04/26/xss-million-websites-cpanel/
Finding XSS in a million websites (cPanel CVE-2023-29489) – Assetnote