06/22

Job Details - Google Careers

https://careers.google.com/jobs/results/93320137781715654/
Job Details - Google Careers

Exploit released for Cisco AnyConnect bug giving SYSTEM privileges

https://www.bleepingcomputer.com/news/security/exploit-released-for-cisco-anyconnect-bug-giving-system-privileges/
Exploit released for Cisco AnyConnect bug giving SYSTEM privileges

Advisory: IDOR in Microsoft Teams Allows for External Tenants to Introduce Malware | JUMPSEC LABS

https://labs.jumpsec.com/advisory-idor-in-microsoft-teams-allows-for-external-tenants-to-introduce-malware/
Advisory: IDOR in Microsoft Teams Allows for External Tenants to Introduce Malware | JUMPSEC LABS

APT37 hackers deploy new FadeStealer eavesdropping malware

https://www.bleepingcomputer.com/news/security/apt37-hackers-deploy-new-fadestealer-eavesdropping-malware/
APT37 hackers deploy new FadeStealer eavesdropping malware

Camaro Dragon Hackers Strike with USB-Driven Self-Propagating Malware

https://thehackernews.com/2023/06/camaro-dragon-hackers-strike-with-usb.html
Camaro Dragon Hackers Strike with USB-Driven Self-Propagating Malware

Critical Flaw Found in WordPress Plugin for WooCommerce Used by 30,000 Websites

https://thehackernews.com/2023/06/critical-flaw-found-in-wordpress-plugin.html
Critical Flaw Found in WordPress Plugin for WooCommerce Used by 30,000 Websites

VMware fixes vCenter Server bugs allowing code execution, auth bypass

https://www.bleepingcomputer.com/news/security/vmware-fixes-vcenter-server-bugs-allowing-code-execution-auth-bypass/
VMware fixes vCenter Server bugs allowing code execution, auth bypass

DuckDuckGo browser for Windows available for everyone as public beta

https://www.bleepingcomputer.com/news/security/duckduckgo-browser-for-windows-available-for-everyone-as-public-beta/
DuckDuckGo browser for Windows available for everyone as public beta

Military Satellite Access Sold on Russian Hacker Forum for $15,000

https://www.hackread.com/military-satellite-access-russian-hacker-forum/
Military Satellite Access Sold on Russian Hacker Forum for $15,000

MULTI#STORM Campaign Targets India and U.S. with Remote Access Trojans

https://thehackernews.com/2023/06/multistorm-campaign-targets-india-and.html
MULTI#STORM Campaign Targets India and U.S. with Remote Access Trojans

Microsoft: Hackers hijack Linux systems using trojanized OpenSSH version

https://www.bleepingcomputer.com/news/security/microsoft-hackers-hijack-linux-systems-using-trojanized-openssh-version/
Microsoft: Hackers hijack Linux systems using trojanized OpenSSH version

Malware-IOCs/2023-06-21 Qakbot (obama270) IOCs at main · executemalware/Malware-IOCs · GitHub

https://github.com/executemalware/Malware-IOCs/blob/main/2023-06-21%20Qakbot%20(obama270)%20IOCs
Malware-IOCs/2023-06-21 Qakbot (obama270) IOCs at main · executemalware/Malware-IOCs · GitHub

Alert: Million of GitHub Repositories Likely Vulnerable to RepoJacking Attack

https://thehackernews.com/2023/06/alert-million-of-github-repositories.html
Alert: Million of GitHub Repositories Likely Vulnerable to RepoJacking Attack

Mirai botnet targets 22 flaws in D-Link, Zyxel, Netgear devices

https://www.bleepingcomputer.com/news/security/mirai-botnet-targets-22-flaws-in-d-link-zyxel-netgear-devices/
Mirai botnet targets 22 flaws in D-Link, Zyxel, Netgear devices

GitHub - trustedsec/CS_COFFLoader

https://github.com/trustedsec/CS_COFFLoader/
GitHub - trustedsec/CS_COFFLoader

PoC Exploit Published for Cisco AnyConnect Secure Vulnerability - SecurityWeek

https://www.securityweek.com/poc-exploit-published-for-cisco-anyconnect-secure-vulnerability/
PoC Exploit Published for Cisco AnyConnect Secure Vulnerability - SecurityWeek

ESPboy walkie-talkie - YouTube

https://www.youtube.com/watch?v=v-oIQ5hdZ3Q
ESPboy walkie-talkie - YouTube

Stepping Insyde System Management Mode | NCC Group Research Blog | Making the world safer and more secure

https://research.nccgroup.com/2023/04/11/stepping-insyde-system-management-mode/
Stepping Insyde System Management Mode | NCC Group Research Blog | Making the world safer and more secure

US Military Personnel Targeted by Unsolicited Smartwatches Linked to Data Breaches

https://www.hackread.com/us-military-unsolicited-smartwatches-data-breach/
US Military Personnel Targeted by Unsolicited Smartwatches Linked to Data Breaches

Exploring Impersonation through the Named Pipe Filesystem Driver | by Jonathan Johnson | May, 2023 | Posts By SpecterOps Team Members

https://posts.specterops.io/exploring-impersonation-through-the-named-pipe-filesystem-driver-15f324dfbaf2
Exploring Impersonation through the Named Pipe Filesystem Driver | by Jonathan Johnson | May, 2023 | Posts By SpecterOps Team Members

Zero-Day Alert: Apple Releases Patches for Actively Exploited Flaws in iOS, macOS, and Safari

https://thehackernews.com/2023/06/zero-day-alert-apple-releases-patches.html
Zero-Day Alert: Apple Releases Patches for Actively Exploited Flaws in iOS, macOS, and Safari

Microsoft Teams users can now chat with any Teams user outside their organization - Microsoft Community Hub

https://techcommunity.microsoft.com/t5/microsoft-teams-blog/microsoft-teams-users-can-now-chat-with-any-teams-user-outside/ba-p/3070832
Microsoft Teams users can now chat with any Teams user outside their organization - Microsoft Community Hub

Kaspersky crimeware report: LockBit and phishing | Securelist

https://securelist.com/crimeware-report-lockbit-switchsymb/110068/
Kaspersky crimeware report: LockBit and phishing | Securelist

Researchers released a PoC exploit for CVE-2023-20178 flaw in Cisco AnyConnect SecureSecurity Affairs

https://securityaffairs.com/147744/hacking/cve-2023-20178-poc-exploit-code.html
Researchers released a PoC exploit for CVE-2023-20178 flaw in Cisco AnyConnect SecureSecurity Affairs

NSA shares tips on blocking BlackLotus UEFI malware attacks

https://www.bleepingcomputer.com/news/security/nsa-shares-tips-on-blocking-blacklotus-uefi-malware-attacks/
NSA shares tips on blocking BlackLotus UEFI malware attacks

HITB Armory

https://cfp.hackinthebox.org/events/hitb-armory-phuket2023
HITB Armory