06/21

Dissecting TriangleDB, a Triangulation spyware implant | Securelist

https://securelist.com/triangledb-triangulation-implant/110050/
Dissecting TriangleDB, a Triangulation spyware implant | Securelist

GitHub - trustedsec/CS_COFFLoader

https://github.com/trustedsec/CS_COFFLoader/
GitHub - trustedsec/CS_COFFLoader

REcon - Home

https://recon.cx/
REcon - Home

UPS discloses data breach after exposed customer info used in SMS phishing

https://www.bleepingcomputer.com/news/security/ups-discloses-data-breach-after-exposed-customer-info-used-in-sms-phishing/
UPS discloses data breach after exposed customer info used in SMS phishing

New Report Exposes Operation Triangulation's Spyware Implant Targeting iOS Devices

https://thehackernews.com/2023/06/new-report-exposes-operation.html
New Report Exposes Operation Triangulation's Spyware Implant Targeting iOS Devices

Critical 'nOAuth' Flaw in Microsoft Azure AD Enabled Complete Account Takeover

https://thehackernews.com/2023/06/critical-noauth-flaw-in-microsoft-azure.html
Critical 'nOAuth' Flaw in Microsoft Azure AD Enabled Complete Account Takeover

Chinese Hacker Group 'Flea' Targets American Ministries with Graphican Backdoor

https://thehackernews.com/2023/06/chinese-hacker-group-flea-targets.html
Chinese Hacker Group 'Flea' Targets American Ministries with Graphican Backdoor

Shibuya.XSS techtalk #12 - connpass

https://shibuyaxss.connpass.com/event/287631/
Shibuya.XSS techtalk #12 - connpass

Chinese APT15 hackers resurface with new Graphican malware

https://www.bleepingcomputer.com/news/security/chinese-apt15-hackers-resurface-with-new-graphican-malware/
Chinese APT15 hackers resurface with new Graphican malware

Windows Native API… by Pavel Yosifovich [Leanpub PDF/iPad/Kindle]

https://leanpub.com/windowsnativeapiprogramming
Windows Native API… by Pavel Yosifovich [Leanpub PDF/iPad/Kindle]

Alert! Hackers Exploiting Critical Vulnerability in VMware's Aria Operations Networks

https://thehackernews.com/2023/06/alert-hackers-exploiting-critical.html
Alert! Hackers Exploiting Critical Vulnerability in VMware's Aria Operations Networks

New Condi Malware Hijacking TP-Link Wi-Fi Routers for DDoS Botnet Attacks

https://thehackernews.com/2023/06/new-condi-malware-hijacking-tp-link-wi.html
New Condi Malware Hijacking TP-Link Wi-Fi Routers for DDoS Botnet Attacks

VMware Confirms Live Exploits Hitting Just-Patched Security Flaw - SecurityWeek

https://www.securityweek.com/vmware-confirms-live-exploits-hitting-just-patched-security-flaw/
VMware Confirms Live Exploits Hitting Just-Patched Security Flaw - SecurityWeek

ScarCruft Hackers Exploit Ably Service for Stealthy Wiretapping Attacks

https://thehackernews.com/2023/06/scarcruft-hackers-exploit-ably-service.html
ScarCruft Hackers Exploit Ably Service for Stealthy Wiretapping Attacks

FTC: Amazon trapped millions into hard-to-cancel Prime memberships

https://www.bleepingcomputer.com/news/security/ftc-amazon-trapped-millions-into-hard-to-cancel-prime-memberships/
FTC: Amazon trapped millions into hard-to-cancel Prime memberships

Enphase Ignores CISA Request to Fix Remotely Exploitable Flaws - SecurityWeek

https://www.securityweek.com/enphase-ignores-cisa-request-to-fix-remotely-exploitable-flaws/
Enphase Ignores CISA Request to Fix Remotely Exploitable Flaws - SecurityWeek

한국내 macOS 이용자를 노린 APT37 공격 등장

https://www.genians.co.kr/blog/threat_intelligence_report_macos
한국내 macOS 이용자를 노린 APT37 공격 등장

New DOJ unit will focus on prosecuting nation-state cybercrime

https://therecord.media/doj-national-security-division-new-cybercrimes-section
New DOJ unit will focus on prosecuting nation-state cybercrime

New Condi malware builds DDoS botnet out of TP-Link AX21 routers

https://www.bleepingcomputer.com/news/security/new-condi-malware-builds-ddos-botnet-out-of-tp-link-ax21-routers/
New Condi malware builds DDoS botnet out of TP-Link AX21 routers

GitHub - lanleft/CVE2023-1829

https://github.com/lanleft/CVE2023-1829
GitHub - lanleft/CVE2023-1829

BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage Activities | Recorded Future

https://www.recordedfuture.com/bluedelta-exploits-ukrainian-government-roundcube-mail-servers
BlueDelta Exploits Ukrainian Government Roundcube Mail Servers to Support Espionage Activities | Recorded Future

APT_REPORT/group123/20230620_threat_inteligence_report_apt37_macos.pdf at master · blackorbird/APT_REPORT · GitHub

https://github.com/blackorbird/APT_REPORT/blob/master/group123/20230620_threat_inteligence_report_apt37_macos.pdf
APT_REPORT/group123/20230620_threat_inteligence_report_apt37_macos.pdf at master · blackorbird/APT_REPORT · GitHub

Photos: Infosecurity Europe 2023, part 2 - Help Net Security

https://www.helpnetsecurity.com/2023/06/21/photos-infosecurity-europe-2023-part-2/
Photos: Infosecurity Europe 2023, part 2 - Help Net Security

Password spraying and MFA bypasses in the modern security landscape | Sprocket Security

https://www.sprocketsecurity.com/resources/how-to-bypass-mfa-all-day
Password spraying and MFA bypasses in the modern security landscape | Sprocket Security