05/11

Nighthawk 0.2.4 - Taking Out The Trash - MDSec

https://www.mdsec.co.uk/2023/05/nighthawk-0-2-4-taking-out-the-trash/
Nighthawk 0.2.4 - Taking Out The Trash - MDSec

Uncovering RedStinger - Undetected APT cyber operations in Eastern Europe since 2020

https://www.malwarebytes.com/blog/threat-intelligence/2023/05/redstinger
Uncovering RedStinger - Undetected APT cyber operations in Eastern Europe since 2020

From One Vulnerability to Another: Outlook Patch Analysis Reveals Important Flaw in Windows API | Akamai

https://www.akamai.com/blog/security-research/important-outlook-vulnerability-bypass-windows-api
From One Vulnerability to Another: Outlook Patch Analysis Reveals Important Flaw in Windows API | Akamai

Babuk Source Code Sparks 9 Different Ransomware Strains Targeting VMware ESXi Systems

https://thehackernews.com/2023/05/babuk-source-code-sparks-9-new.html
Babuk Source Code Sparks 9 Different Ransomware Strains Targeting VMware ESXi Systems

AS-23-Landau-PPLdump-Is-Dead-Long-Live-PPLdump.pdf.pdf - Google ドライブ

https://drive.google.com/file/d/1Pj7hSvsj0qvegdIUvABa9KUEKOrLzu2p/view?usp=drivesdk
AS-23-Landau-PPLdump-Is-Dead-Long-Live-PPLdump.pdf.pdf - Google ドライブ

GitHub - mr-pmillz/gofireprox: FireProx written in Go

https://github.com/mr-pmillz/gofireprox
GitHub - mr-pmillz/gofireprox: FireProx written in Go

Inside the Italian Mafia’s Encrypted Phone of Choice

https://www.vice.com/en/article/88xgjz/inside-italian-mafias-encrypted-phone-no1bc
Inside the Italian Mafia’s Encrypted Phone of Choice

C2 and the Docker Dance: Mythic 3.0’s Marvelous Microservice Moves | by Cody Thomas | May, 2023 | Posts By SpecterOps Team Members

https://posts.specterops.io/c2-and-the-docker-dance-mythic-3-0s-marvelous-microservice-moves-f6e6e91356e2
C2 and the Docker Dance: Mythic 3.0’s Marvelous Microservice Moves | by Cody Thomas | May, 2023 | Posts By SpecterOps Team Members

conhost | LOLBAS

https://lolbas-project.github.io/lolbas/Binaries/Conhost/
conhost | LOLBAS

Regions (Windows GDI) - Win32 apps | Microsoft Learn

https://learn.microsoft.com/en-us/windows/win32/gdi/regions
Regions (Windows GDI) - Win32 apps | Microsoft Learn

eSentire | eSentire Threat Intelligence Malware Analysis: Vidar…

https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-vidar-stealer
eSentire | eSentire Threat Intelligence Malware Analysis: Vidar…

Qakbot/Qakbot_BB27_11.05.2023.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_BB27_11.05.2023.txt
Qakbot/Qakbot_BB27_11.05.2023.txt at main · pr0xylife/Qakbot · GitHub

FwHunt/IntelAlderLakeLeak.yml at main · binarly-io/FwHunt · GitHub

https://github.com/binarly-io/FwHunt/blob/main/rules/SupplyChain/IntelAlderLakeLeak.yml
FwHunt/IntelAlderLakeLeak.yml at main · binarly-io/FwHunt · GitHub

HITBAMS – Your Not so “Home” Office – Soho Hacking at Pwn2Own | NCC Group Research Blog | Making the world safer and more secure

https://research.nccgroup.com/2023/04/24/hitbams-your-not-so-home-office-soho-hacking-at-pwn2own/
HITBAMS – Your Not so “Home” Office – Soho Hacking at Pwn2Own | NCC Group Research Blog | Making the world safer and more secure

UK ‘increasingly concerned’ ransomware victims are keeping incidents secret

https://therecord.media/uk-increasingly-concerned-of-ransomware-victims-keeping-quiet-ncsc
UK ‘increasingly concerned’ ransomware victims are keeping incidents secret

SupplyChainAttacks/IntelKeysImpactedDevices.md at main · binarly-io/SupplyChainAttacks · GitHub

https://github.com/binarly-io/SupplyChainAttacks/blob/main/Lenovo:LCFC/IntelKeysImpactedDevices.md
SupplyChainAttacks/IntelKeysImpactedDevices.md at main · binarly-io/SupplyChainAttacks · GitHub

About Encrypted Direct Messages – DMs | Twitter Help

https://help.twitter.com/en/using-twitter/encrypted-direct-messages
About Encrypted Direct Messages – DMs | Twitter Help