06/14

Chinese hackers use DNS-over-HTTPS for Linux malware communication

https://www.bleepingcomputer.com/news/security/chinese-hackers-use-dns-over-https-for-linux-malware-communication/
Chinese hackers use DNS-over-HTTPS for Linux malware communication

Fake zero-day PoC exploits on GitHub push Windows, Linux malware

https://www.bleepingcomputer.com/news/security/fake-zero-day-poc-exploits-on-github-push-windows-linux-malware/
Fake zero-day PoC exploits on GitHub push Windows, Linux malware

Severe Vulnerabilities Reported in Microsoft Azure Bastion and Container Registry

https://thehackernews.com/2023/06/severe-vulnerabilities-reported-in.html
Severe Vulnerabilities Reported in Microsoft Azure Bastion and Container Registry

CISA: LockBit ransomware extorted $91 million in 1,700 U.S. attacks

https://www.bleepingcomputer.com/news/security/cisa-lockbit-ransomware-extorted-91-million-in-1-700-us-attacks/
CISA: LockBit ransomware extorted $91 million in 1,700 U.S. attacks

New Golang-based Skuld Malware Stealing Discord and Browser Data from Windows PCs

https://thehackernews.com/2023/06/new-golang-based-skuld-malware-stealing.html
New Golang-based Skuld Malware Stealing Discord and Browser Data from Windows PCs

MOVEIt Transfer RCE Part Two (CVE-2023-34362) – Assetnote

https://blog.assetnote.io/2023/06/13/moveit-transfer-part-two/
MOVEIt Transfer RCE Part Two (CVE-2023-34362) – Assetnote

Etagを用いてTor Hidden Serviceを非匿名化する - Sh1ttyKids - Medium

https://sh1ttykids.medium.com/etag%E3%82%92%E7%94%A8%E3%81%84%E3%81%A6tor-hidden-service%E3%82%92%E9%9D%9E%E5%8C%BF%E5%90%8D%E5%8C%96%E3%81%99%E3%82%8B-24a32e677e56
Etagを用いてTor Hidden Serviceを非匿名化する - Sh1ttyKids - Medium

Fake Researcher Profiles Spread Malware through GitHub Repositories as PoC Exploits

https://thehackernews.com/2023/06/fake-researcher-profiles-spread-malware.html
Fake Researcher Profiles Spread Malware through GitHub Repositories as PoC Exploits

New ‘Shampoo’ Chromeloader malware pushed via fake warez sites

https://www.bleepingcomputer.com/news/security/new-shampoo-chromeloader-malware-pushed-via-fake-warez-sites/
New ‘Shampoo’ Chromeloader malware pushed via fake warez sites

Critical Security Vulnerability Discovered in WooCommerce Stripe Gateway Plugin

https://thehackernews.com/2023/06/critical-security-vulnerability.html
Critical Security Vulnerability Discovered in WooCommerce Stripe Gateway Plugin

Pirated Windows 10 ISOs install clipper malware via EFI partitions

https://www.bleepingcomputer.com/news/security/pirated-windows-10-isos-install-clipper-malware-via-efi-partitions/
Pirated Windows 10 ISOs install clipper malware via EFI partitions

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/browse/tag/aufierionformaticascom/
MalwareBazaar | Browse Checking your browser

China-linked APT UNC3886 used VMware ESXi Zero-DaySecurity Affairs

https://securityaffairs.com/147436/apt/unc3886-vmware-esxi-zero-day.html
China-linked APT UNC3886 used VMware ESXi Zero-DaySecurity Affairs

Chinese Hackers Exploit VMware Zero-Day to Backdoor Windows and Linux Systems

https://thehackernews.com/2023/06/chinese-hackers-exploit-vmware-zero-day.html
Chinese Hackers Exploit VMware Zero-Day to Backdoor Windows and Linux Systems

Microsoft Outs New Russian APT Linked to Wiper Attacks in Ukraine - SecurityWeek

https://www.securityweek.com/microsoft-outs-new-russian-apt-linked-to-wiper-attacks-in-ukraine/
Microsoft Outs New Russian APT Linked to Wiper Attacks in Ukraine - SecurityWeek

Microsoft links data wiping attacks to new Russian GRU hacking group

https://www.bleepingcomputer.com/news/security/microsoft-links-data-wiping-attacks-to-new-russian-gru-hacking-group/
Microsoft links data wiping attacks to new Russian GRU hacking group

Unveiling the Balada injector: a malware epidemic in WordPressSecurity Affairs

https://securityaffairs.com/147460/malware/balada-injector-malware-wordpress.html
Unveiling the Balada injector: a malware epidemic in WordPressSecurity Affairs

Cadet Blizzard emerges as a novel and distinct Russian threat actor | Microsoft Security Blog

https://www.microsoft.com/en-us/security/blog/2023/06/14/cadet-blizzard-emerges-as-a-novel-and-distinct-russian-threat-actor/
Cadet Blizzard emerges as a novel and distinct Russian threat actor | Microsoft Security Blog

Microsoft Releases Updates to Patch Critical Flaws in Windows and Other Software

https://thehackernews.com/2023/06/microsoft-releases-updates-to-patch.html
Microsoft Releases Updates to Patch Critical Flaws in Windows and Other Software

From One Vulnerability to Another: Outlook Patch Analysis Reveals Important Flaw in Windows API | Akamai

https://www.akamai.com/blog/security-research/important-outlook-vulnerability-bypass-windows-api
From One Vulnerability to Another: Outlook Patch Analysis Reveals Important Flaw in Windows API | Akamai