Xortigate, or CVE-2023-27997 - The Rumoured RCE That Was
https://labs.watchtowr.com/xortigate-or-cve-2023-27997/
JWT authentication bypass via `X-HTTP-Method-Override` header · Advisory · GoogleCloudPlatform/esp-v2 · GitHub
https://github.com/GoogleCloudPlatform/esp-v2/security/advisories/GHSA-6qmp-9p95-fc5f
Malware-Traffic-Analysis.net - 30 days of Formbook: Day 8, Monday 2023-06-12 - "ee2q"
https://malware-traffic-analysis.net/2023/06/12/index.html
SAS 2023 is coming! - YouTube
https://youtu.be/yFdcNupjKU0
shubs on Twitter: "For a few months, @samwcyo, @bbuerhaus, @rhyselsmore and I focused on hacking EPP servers / ccTLD zones. We're disclosing our work today on the hackcompute blog: https://t.co/9ycLkH9sqp Our efforts in this space led to the ability to control the DNS zones of the following…" / Twitter
https://twitter.com/infosec_au/status/1668472363401515008
can I speak to your manager? hacking root EPP servers to take control of zones — hackcompute
https://hackcompute.com/hacking-epp-servers/
Pre-authenticated RCE in VMware vRealize Network Insight
https://summoning.team/blog/vmware-vrealize-network-insight-rce-cve-2023-20887/
フィッシング対策協議会 Council of Anti-Phishing Japan | ニュース | 緊急情報 | 総務省をかたるフィッシング (2023/06/13)
https://www.antiphishing.jp/news/alert/mic_20230613.html
Americans should prepare for cyber sabotage from Chinese hackers, US official warns | Reuters
https://www.reuters.com/world/americans-should-prepare-cyber-sabotage-chinese-hackers-us-official-warns-2023-06-12/
GitHub - sfewer-r7/CVE-2023-34362: CVE-2023-34362: MOVEit Transfer Unauthenticated RCE
https://github.com/sfewer-r7/CVE-2023-34362
PSIRT Advisories | FortiGuard
https://www.fortiguard.com/psirt/FG-IR-23-097
Beware: New DoubleFinger Loader Targets Cryptocurrency Wallets with Stealer
https://thehackernews.com/2023/06/beware-new-doublefinger-loader-targets.html
Special Offer for Asia Pacific Students | SANS Online Training
https://www.sans.org/u/1qIp
Public - Evading Logging in the Cloud: Disrupting and Bypassing AWS CloudTrail - Google スライド
http://frichetten.com/fwdcloudsec-2023
RDP honeypot targeted 3.5 million times in brute-force attacks
https://www.bleepingcomputer.com/news/security/rdp-honeypot-targeted-35-million-times-in-brute-force-attacks/
Reddit goes dark - by Casey Newton - Platformer
https://www.platformer.news/p/reddit-goes-dark
Bug Bounty Recon (Part-2). Previous Part… | by Aswin Thambi Panikulangara | Jun, 2023 | Medium
https://aswinthambipanik07.medium.com/bug-bounty-recon-part-2-6aa549ba63d5
SteelCloverが使用する新たなマルウェアPowerHarborについて, Rintaro Koike
https://insight-jp.nttsecurity.com/post/102ignh/steelcloverpowerharbor
Two Russian Nationals Charged for Masterminding Mt. Gox Crypto Exchange Hack
https://thehackernews.com/2023/06/two-russian-nationals-charged-for.html
Experts released PoC exploit for MOVEit Transfer CVE-2023-34362Security Affairs
https://securityaffairs.com/147404/hacking/moveit-transfer-poc.html
rhys on Twitter: "i recently teamed up with @infosec_au, @samwcyo, and @bbuerhaus to do some unspeakable things to some pretty hefty domain name infrastructure https://t.co/8H0HcRuOfj" / Twitter
https://twitter.com/rhyselsmore/status/1668472711247712257
An Illinois hospital links closure to ransomware attack
https://www.nbcnews.com/tech/security/illinois-hospital-links-closure-ransomware-attack-rcna85983
Bug Bounty Recon(Part-1) | by Aswin Thambi Panikulangara | May, 2023 | Medium
https://aswinthambipanik07.medium.com/bug-bounty-recon-part-1-dad7f86d1b0f
Analysis of CVE-2023-27997 and Clarifications on Volt Typhoon Campaign | Fortinet Blog
https://www.fortinet.com/blog/psirt-blogs/analysis-of-cve-2023-27997-and-clarifications-on-volt-typhoon-campaign
A Truly Graceful Wipe Out - The DFIR Report
https://thedfirreport.com/2023/06/12/a-truly-graceful-wipe-out/
Massive phishing campaign uses 6,000 sites to impersonate 100 brands
https://www.bleepingcomputer.com/news/security/massive-phishing-campaign-uses-6-000-sites-to-impersonate-100-brands/
New Loader Delivering Spyware via Image Steals Cryptocurrency Info
https://www.darkreading.com/attacks-breaches/new-loader-delivering-spyware-via-image-steals-cryptocurrency-info
Bug Bounty Recon (Part-3). Content Discovery using FFUF | by Aswin Thambi Panikulangara | Jun, 2023 | Medium
https://aswinthambipanik07.medium.com/bug-bounty-recon-part-3-ade14456e1ab