07/14

Supply Chain Attack Targeting Pakistani Government Delivers Shadowpad

https://www.trendmicro.com/en_us/research/23/g/supply-chain-attack-targeting-pakistani-government-delivers-shad.html
Supply Chain Attack Targeting Pakistani Government Delivers Shadowpad

Zimbra Warns of Critical Zero-Day Flaw in Email Software Amid Active Exploitation

https://thehackernews.com/2023/07/zimbra-warns-of-critical-zero-day-flaw.html
Zimbra Warns of Critical Zero-Day Flaw in Email Software Amid Active Exploitation

AIOS WordPress Plugin Faces Backlash for Storing User Passwords in Plain Text

https://thehackernews.com/2023/07/aios-wordpress-plugin-faces-backlash.html
AIOS WordPress Plugin Faces Backlash for Storing User Passwords in Plain Text

Critical Security Flaws Uncovered in Honeywell Experion DCS and QuickBlox Services

https://thehackernews.com/2023/07/critical-security-flaws-uncovered-in.html
Critical Security Flaws Uncovered in Honeywell Experion DCS and QuickBlox Services

TeamTNT's Cloud Credential Stealing Campaign Now Targets Azure and Google Cloud

https://thehackernews.com/2023/07/teamtnts-cloud-credential-stealing.html
TeamTNT's Cloud Credential Stealing Campaign Now Targets Azure and Google Cloud

Shutterfly says Clop ransomware attack did not impact customer data

https://www.bleepingcomputer.com/news/security/shutterfly-says-clop-ransomware-attack-did-not-impact-customer-data/
Shutterfly says Clop ransomware attack did not impact customer data

Colorado State University says data breach impacts students, staff

https://www.bleepingcomputer.com/news/security/colorado-state-university-says-data-breach-impacts-students-staff/
Colorado State University says data breach impacts students, staff

AVrecon malware infects 70,000 Linux routers to build botnet

https://www.bleepingcomputer.com/news/security/avrecon-malware-infects-70-0000-linux-routers-to-build-botnet/
AVrecon malware infects 70,000 Linux routers to build botnet

Infecting SSH Public Keys with backdoors

https://blog.thc.org/infecting-ssh-public-keys-with-backdoors
Infecting SSH Public Keys with backdoors

Streamlit

http://pi-recon.streamlit.app
Streamlit

The art of fuzzing: Windows Binaries - Bushido Security

https://bushido-sec.com/index.php/2023/06/25/the-art-of-fuzzing-windows-binaries/
The art of fuzzing: Windows Binaries - Bushido Security

Defend Against Insider Threats: Join this Webinar on SaaS Security Posture Management

https://thehackernews.com/2023/07/defend-against-insider-threats-join.html
Defend Against Insider Threats: Join this Webinar on SaaS Security Posture Management

BreachForums owner Pompompurin pleads guilty to hacking charges

https://www.bleepingcomputer.com/news/security/breachforums-owner-pompompurin-pleads-guilty-to-hacking-charges/
BreachForums owner Pompompurin pleads guilty to hacking charges

Spotify reportedly makes users' private playlists public

https://www.bleepingcomputer.com/news/technology/spotify-reportedly-makes-users-private-playlists-public/
Spotify reportedly makes users' private playlists public

Thread Priorities in Windows – Pavel Yosifovich

https://scorpiosoftware.net/2023/07/14/thread-priorities-in-windows/
Thread Priorities in Windows – Pavel Yosifovich

Source code for BlackLotus Windows UEFI malware leaked on GitHub

https://www.bleepingcomputer.com/news/security/source-code-for-blacklotus-windows-uefi-malware-leaked-on-github/
Source code for BlackLotus Windows UEFI malware leaked on GitHub

Rockwell warns of new APT RCE exploit targeting critical infrastructure

https://www.bleepingcomputer.com/news/security/rockwell-warns-of-new-apt-rce-exploit-targeting-critical-infrastructure/
Rockwell warns of new APT RCE exploit targeting critical infrastructure

A Deep Dive into Penetration Testing of macOS Applications (Part 1)

https://www.cyberark.com/resources/threat-research-blog/a-deep-dive-into-penetration-testing-of-macos-applications-part-1
A Deep Dive into Penetration Testing of macOS Applications (Part 1)

New SOHO Router Botnet AVrecon Spreads to 70,000 Devices Across 20 Countries

http://thehackernews.com/2023/07/new-soho-router-botnet-avrecon-spreads.html
New SOHO Router Botnet AVrecon Spreads to 70,000 Devices Across 20 Countries

Read memory dumps without a cat. | Powerseb

https://powerseb.github.io/posts/LSASS-parsing-without-a-cat/
Read memory dumps without a cat. | Powerseb