07/21

Compromised Microsoft Key: More Impactful Than We Thought | Wiz Blog

https://www.wiz.io/blog/storm-0558-compromised-microsoft-key-enables-authentication-of-countless-micr
Compromised Microsoft Key: More Impactful Than We Thought | Wiz Blog

aa23-201a_csa_threat_actors_exploiting_citrix-cve-2023-3519_to_implant_webshells.pdf

https://www.cisa.gov/sites/default/files/2023-07/aa23-201a_csa_threat_actors_exploiting_citrix-cve-2023-3519_to_implant_webshells.pdf
aa23-201a_csa_threat_actors_exploiting_citrix-cve-2023-3519_to_implant_webshells.pdf

Shifting boundaries: Exploiting an Integer Overflow in Apple Safari - Exodus Intelligence

https://blog.exodusintel.com/2023/07/20/shifting-boundaries-exploiting-an-integer-overflow-in-apple-safari/
Shifting boundaries: Exploiting an Integer Overflow in Apple Safari - Exodus Intelligence

VirusTotal - File - 3b4b9f56d5bec5cf3cd3fd6b917d43b2ff8a0b1d22a00b577e8d2bcbb90f7418

https://www.virustotal.com/gui/file/3b4b9f56d5bec5cf3cd3fd6b917d43b2ff8a0b1d22a00b577e8d2bcbb90f7418/detection
VirusTotal - File - 3b4b9f56d5bec5cf3cd3fd6b917d43b2ff8a0b1d22a00b577e8d2bcbb90f7418

Netscaler ADC bug exploited to breach US critical infrastructure org

https://www.bleepingcomputer.com/news/security/cisa-citrix-rce-bug-exploited-to-breach-critical-infrastructure-org/
Netscaler ADC bug exploited to breach US critical infrastructure org

V8 Sandbox - Code Pointer Sandboxing - Google ドキュメント

https://docs.google.com/document/d/1CPs5PutbnmI-c5g7e_Td9CNGh5BvpLleKCqUnqmD82k/edit?usp=sharing
V8 Sandbox - Code Pointer Sandboxing - Google ドキュメント

Sophisticated BundleBot Malware Disguised as Google AI Chatbot and Utilities

https://thehackernews.com/2023/07/sophisticated-bundlebot-malware.html
Sophisticated BundleBot Malware Disguised as Google AI Chatbot and Utilities

HotRat: New Variant of AsyncRAT Malware Spreading Through Pirated Software

https://thehackernews.com/2023/07/hotrat-new-variant-of-asyncrat-malware.html
HotRat: New Variant of AsyncRAT Malware Spreading Through Pirated Software

Citrix NetScaler ADC and Gateway Devices Under Attack: CISA Urges Immediate Action

https://thehackernews.com/2023/07/citrix-netscaler-adc-and-gateway.html
Citrix NetScaler ADC and Gateway Devices Under Attack: CISA Urges Immediate Action

DDoS Botnets Hijacking Zyxel Devices to Launch Devastating Attacks

https://thehackernews.com/2023/07/ddos-botnets-hijacking-zyxel-devices-to.html
DDoS Botnets Hijacking Zyxel Devices to Launch Devastating Attacks

Amazon agrees to $25 million fine for Alexa children privacy violations

https://www.bleepingcomputer.com/news/technology/amazon-agrees-to-25-million-fine-for-alexa-children-privacy-violations/
Amazon agrees to $25 million fine for Alexa children privacy violations

PersonalStuff/http-vuln-cve2023-3519.nse at master · RootUp/PersonalStuff · GitHub

https://github.com/RootUp/PersonalStuff/blob/master/http-vuln-cve2023-3519.nse
PersonalStuff/http-vuln-cve2023-3519.nse at master · RootUp/PersonalStuff · GitHub

VirusTotal apologizes for data leak affecting 5,600 customers

https://www.bleepingcomputer.com/news/security/virustotal-apologizes-for-data-leak-affecting-5-600-customers/
VirusTotal apologizes for data leak affecting 5,600 customers

GitHub warns of Lazarus hackers targeting devs with malicious projects

https://www.bleepingcomputer.com/news/security/github-warns-of-lazarus-hackers-targeting-devs-with-malicious-projects/
GitHub warns of Lazarus hackers targeting devs with malicious projects

Writing your own RDI /sRDI loader using C and ASM

https://blog.malicious.group/writing-your-own-rdi-srdi-loader-using-c-and-asm/
Writing your own RDI /sRDI loader using C and ASM

How to Enhance Performance & Learning by Applying a Growth Mindset - Huberman Lab

https://hubermanlab.com/how-to-enhance-performance-and-learning-by-applying-a-growth-mindset/
How to Enhance Performance & Learning by Applying a Growth Mindset - Huberman Lab

Exploitation of Citrix Zero-Day by Possible Espionage Actors (CVE-2023-3519) | Mandiant

https://www.mandiant.com/resources/blog/citrix-zero-day-espionage
Exploitation of Citrix Zero-Day by Possible Espionage Actors (CVE-2023-3519) | Mandiant

Analysis of CVE-2023-3519 in Citrix ADC and NetScaler Gateway – Assetnote

https://blog.assetnote.io/2023/07/21/citrix-CVE-2023-3519-analysis/
Analysis of CVE-2023-3519 in Citrix ADC and NetScaler Gateway – Assetnote

Azure AD Token Forging Technique in Microsoft Attack Extends Beyond Outlook, Wiz Reports

https://thehackernews.com/2023/07/azure-ad-token-forging-technique-in.html
Azure AD Token Forging Technique in Microsoft Attack Extends Beyond Outlook, Wiz Reports

VirusTotal - File - e08dad3ba8f06e07fc4b18bac1f27360befb6fd1fd18a5b467ef8ee4f29735af

https://www.virustotal.com/gui/file/e08dad3ba8f06e07fc4b18bac1f27360befb6fd1fd18a5b467ef8ee4f29735af
VirusTotal - File - e08dad3ba8f06e07fc4b18bac1f27360befb6fd1fd18a5b467ef8ee4f29735af

Clop gang to earn over $75 million from MOVEit extortion attacks

https://www.bleepingcomputer.com/news/security/clop-gang-to-earn-over-75-million-from-moveit-extortion-attacks/
Clop gang to earn over $75 million from MOVEit extortion attacks

North Korean hackers targeted tech companies through JumpCloud and GitHub - Help Net Security

https://www.helpnetsecurity.com/2023/07/21/north-korean-hackers-github/
North Korean hackers targeted tech companies through JumpCloud and GitHub - Help Net Security