06/12

Fortinet fixes critical RCE flaw in Fortigate SSL-VPN devices, patch now

https://www.bleepingcomputer.com/news/security/fortinet-fixes-critical-rce-flaw-in-fortigate-ssl-vpn-devices-patch-now/
Fortinet fixes critical RCE flaw in Fortigate SSL-VPN devices, patch now

CVExploits

https://cvexploits.io/
CVExploits

A Truly Graceful Wipe Out - The DFIR Report

https://thedfirreport.com/2023/06/12/a-truly-graceful-wipe-out/
A Truly Graceful Wipe Out - The DFIR Report

SteelCloverが使用する新たなマルウェアPowerHarborについて, Rintaro Koike

https://insight-jp.nttsecurity.com/post/102ignh/steelcloverpowerharbor
SteelCloverが使用する新たなマルウェアPowerHarborについて, Rintaro Koike

MSSQL linked servers: abusing ADSI for password retrieval

https://www.tarlogic.com/blog/linked-servers-adsi-passwords/
MSSQL linked servers: abusing ADSI for password retrieval

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/browse/tag/recupero%20crediti/
MalwareBazaar | Browse Checking your browser

GitHub - horizon3ai/CVE-2023-34362: MOVEit CVE-2023-34362

https://github.com/horizon3ai/CVE-2023-34362
GitHub - horizon3ai/CVE-2023-34362: MOVEit CVE-2023-34362

Apple's Safari Private Browsing Now Automatically Removes Tracking Parameters in URLs

https://thehackernews.com/2023/06/apples-safari-private-browsing-now.html
Apple's Safari Private Browsing Now Automatically Removes Tracking Parameters in URLs

Defeating Windows DEP With A Custom ROP Chain | NCC Group Research Blog | Making the world safer and more secure

https://research.nccgroup.com/2023/06/12/defeating-windows-dep-with-a-custom-rop-chain/
Defeating Windows DEP With A Custom ROP Chain | NCC Group Research Blog | Making the world safer and more secure

Cybercriminals Using Powerful BatCloak Engine to Make Malware Fully Undetectable

https://thehackernews.com/2023/06/cybercriminals-using-powerful-batcloak.html
Cybercriminals Using Powerful BatCloak Engine to Make Malware Fully Undetectable

Solarmarker: The Old is New – Squiblydoo.blog

https://squiblydoo.blog/2022/09/27/solarmarker-the-old-is-new/
Solarmarker: The Old is New – Squiblydoo.blog

REKCAH! Publishing – Spearphish General Store

https://spearphish-general-store.myshopify.com/collections/rekcah-publishing
REKCAH! Publishing – Spearphish General Store

Introduction to encryption for embedded Linux developers - sergioprado.blog

https://sergioprado.blog/introduction-to-encryption-for-embedded-linux-developers/
Introduction to encryption for embedded Linux developers - sergioprado.blog

Abusing undocumented features to spoof PE section headers | secret club

https://secret.club/2023/06/05/spoof-pe-sections.html
Abusing undocumented features to spoof PE section headers | secret club

Daily Cyber Briefing- Monday 12th June / Twitter

https://twitter.com/i/broadcasts/1lDxLngzvwmGm
Daily Cyber Briefing- Monday 12th June / Twitter

A More Complete Exploit for Fortinet CVE-2022-42475 | Bishop Fox

https://bishopfox.com/blog/exploit-cve-2022-42475?utm_campaign=awareness&utm_medium=social&utm_source=linkedin&utm_term=blog
A More Complete Exploit for Fortinet CVE-2022-42475 | Bishop Fox

Strava heatmap feature can be abused to find home addresses

https://www.bleepingcomputer.com/news/security/strava-heatmap-feature-can-be-abused-to-find-home-addresses/
Strava heatmap feature can be abused to find home addresses

Confidential data downloaded from UK regulator Ofcom in cyberattack

https://therecord.media/ofcom-cyberattack-uk-regulator-moveit-vulnerability
Confidential data downloaded from UK regulator Ofcom in cyberattack

Exploit released for MOVEit RCE bug used in data theft attacks

https://www.bleepingcomputer.com/news/security/exploit-released-for-moveit-rce-bug-used-in-data-theft-attacks/
Exploit released for MOVEit RCE bug used in data theft attacks

Microsoft: Azure Portal outage was caused by traffic “spike”

https://www.bleepingcomputer.com/news/microsoft/microsoft-azure-portal-outage-was-caused-by-traffic-spike-/
Microsoft: Azure Portal outage was caused by traffic “spike”

BHIS Seismograph Logo T-Shirt – Spearphish General Store

https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections/products/bhis-seismograph-logo-t-shirt
BHIS Seismograph Logo T-Shirt – Spearphish General Store

Mobile Pentesting 101 – How to Set Up Your iOS Environment – Security Café

https://securitycafe.ro/2023/06/12/mobile-pentesting-101-how-to-set-up-your-ios-environment/
Mobile Pentesting 101 – How to Set Up Your iOS Environment – Security Café