06/08

Cisco fixes AnyConnect bug giving Windows SYSTEM privileges

https://www.bleepingcomputer.com/news/security/cisco-fixes-anyconnect-bug-giving-windows-system-privileges/
Cisco fixes AnyConnect bug giving Windows SYSTEM privileges

Nacos Hessian 反序列化 RCE - Y4er的博客

https://y4er.com/posts/nacos-hessian-rce/
Nacos Hessian 反序列化 RCE - Y4er的博客

Introducing Google’s Secure AI Framework

https://blog.google/technology/safety-security/introducing-googles-secure-ai-framework/
Introducing Google’s Secure AI Framework

http://redsiege.com/training

http://redsiege.com/training

Threat Intel Queries

https://embee-research.ghost.io/shodan-censys-queries/
Threat Intel Queries

Bypassing Defender with ThreatCheck & Ghidra - Offensive Defence

https://offensivedefence.co.uk/posts/threatcheck-ghidra/
Bypassing Defender with ThreatCheck & Ghidra - Offensive Defence

CL0P likes to MOVEit MOVEit

https://www.curatedintel.org/2023/06/cl0p-likes-to-moveit-moveit.html
CL0P likes to MOVEit MOVEit

Kimsuky Targets Think Tanks and News Media with Social Engineering Attacks

https://thehackernews.com/2023/06/kimsuky-targets-think-tanks-and-news.html
Kimsuky Targets Think Tanks and News Media with Social Engineering Attacks

Abusing undocumented features to spoof PE section headers | secret club

https://secret.club/2023/06/05/spoof-pe-sections.html
Abusing undocumented features to spoof PE section headers | secret club

域名售卖

http://subject.cn
域名售卖

Barracuda Urges Immediate Replacement of Hacked ESG Appliances

https://thehackernews.com/2023/06/barracuda-urges-immediate-replacement.html
Barracuda Urges Immediate Replacement of Hacked ESG Appliances

Fuzzing Android Native libraries with libFuzzer + QEMU 🦥 | fuzzing.science

https://fuzzing.science/blog/Fuzzing-Android-Native-libraries-with-libFuzzer-Qemu
Fuzzing Android Native libraries with libFuzzer + QEMU 🦥 | fuzzing.science

Royal ransomware gang adds BlackSuit encryptor to their arsenal

https://www.bleepingcomputer.com/news/security/royal-ransomware-gang-adds-blacksuit-encryptor-to-their-arsenal/
Royal ransomware gang adds BlackSuit encryptor to their arsenal

SSTIC2023 » Présentation » Deep Attack Surfaces, Shallow Bugs - Valentina Palmiotti

https://www.sstic.org/2023/presentation/deep_attack_surfaces_shallow_bugs/
SSTIC2023 » Présentation » Deep Attack Surfaces, Shallow Bugs - Valentina Palmiotti

20 cybersecurity projects on GitHub you should check out - Help Net Security

https://www.helpnetsecurity.com/2023/06/08/github-cybersecurity-projects/
20 cybersecurity projects on GitHub you should check out - Help Net Security

Stealth Soldier Backdoor Used in Targeted Espionage Attacks in North Africa - Check Point Research

https://research.checkpoint.com/2023/stealth-soldier-backdoor-used-in-targeted-espionage-attacks-in-north-africa/
Stealth Soldier Backdoor Used in Targeted Espionage Attacks in North Africa - Check Point Research

Common Vulnerability Scoring System

https://www.first.org/cvss/v4-0/
Common Vulnerability Scoring System

Barracuda Email Security Gateway Appliance (ESG) Vulnerability

https://www.barracuda.com/company/legal/esg-vulnerability
Barracuda Email Security Gateway Appliance (ESG) Vulnerability

Urgent Security Updates: Cisco and VMware Address Critical Vulnerabilities

https://thehackernews.com/2023/06/urgent-security-updates-cisco-and.html
Urgent Security Updates: Cisco and VMware Address Critical Vulnerabilities

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/browse/tag/balibumba1-com/
MalwareBazaar | Browse Checking your browser

Microsoft OneDrive down worldwide following claims of DDoS attacks

https://www.bleepingcomputer.com/news/microsoft/microsoft-onedrive-down-worldwide-following-claims-of-ddos-attacks/
Microsoft OneDrive down worldwide following claims of DDoS attacks