07/24

North Korea Leverages SaaS Provider in a Targeted Supply Chain Attack | Mandiant

https://www.mandiant.com/resources/blog/north-korea-supply-chain
North Korea Leverages SaaS Provider in a Targeted Supply Chain Attack | Mandiant

New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection

https://thehackernews.com/2023/07/new-openssh-vulnerability-exposes-linux.html
New OpenSSH Vulnerability Exposes Linux Systems to Remote Command Injection

Apple fixes new zero-day used in attacks against iPhones, Macs

https://www.bleepingcomputer.com/news/apple/apple-fixes-new-zero-day-used-in-attacks-against-iphones-macs/
Apple fixes new zero-day used in attacks against iPhones, Macs

Clop now leaks data stolen in MOVEit attacks on clearweb sites

https://www.bleepingcomputer.com/news/security/clop-now-leaks-data-stolen-in-moveit-attacks-on-clearweb-sites/
Clop now leaks data stolen in MOVEit attacks on clearweb sites

Announcing Isosceles

https://blog.isosceles.com/announcing-isosceles/
Announcing Isosceles

Analysis of CVE-2023-3519 in Citrix ADC and NetScaler Gateway (Part 2) – Assetnote

https://blog.assetnote.io/2023/07/24/citrix-rce-part-2-cve-2023-3519/
Analysis of CVE-2023-3519 in Citrix ADC and NetScaler Gateway (Part 2) – Assetnote

Norwegian government IT systems hacked using zero-day flaw

https://www.bleepingcomputer.com/news/security/norwegian-government-it-systems-hacked-using-zero-day-flaw/
Norwegian government IT systems hacked using zero-day flaw

Google Messages Getting Cross-Platform End-to-End Encryption with MLS Protocol

https://thehackernews.com/2023/07/google-messages-getting-cross-platform.html
Google Messages Getting Cross-Platform End-to-End Encryption with MLS Protocol

Ivanti patches MobileIron zero-day bug exploited in attacks

https://www.bleepingcomputer.com/news/security/ivanti-patches-mobileiron-zero-day-bug-exploited-in-attacks/
Ivanti patches MobileIron zero-day bug exploited in attacks

BlackOfWorld · GitHub

https://github.com/BlackOfWorld
BlackOfWorld · GitHub

realhackhistory - YouTube

https://www.youtube.com/c/realhackhistory
realhackhistory - YouTube

Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation Attacks

https://thehackernews.com/2023/07/critical-zero-days-in-atera-windows.html
Critical Zero-Days in Atera Windows Installers Expose Users to Privilege Escalation Attacks

Pro-China influence campaign infiltrates U.S. news websites - The Washington Post

https://www.washingtonpost.com/politics/2023/07/24/pro-china-influence-campaign-infiltrates-us-news-websites/
Pro-China influence campaign infiltrates U.S. news websites - The Washington Post

Banking Sector Targeted in Open-Source Software Supply Chain Attacks

https://thehackernews.com/2023/07/banking-sector-targeted-in-open-source.html
Banking Sector Targeted in Open-Source Software Supply Chain Attacks

JumpCloud hack linked to North Korea after OPSEC mistake

https://www.bleepingcomputer.com/news/security/jumpcloud-hack-linked-to-north-korea-after-opsec-mistake/
JumpCloud hack linked to North Korea after OPSEC mistake

Lazarus hackers hijack Microsoft IIS servers to spread malware

https://www.bleepingcomputer.com/news/security/lazarus-hackers-hijack-microsoft-iis-servers-to-spread-malware/
Lazarus hackers hijack Microsoft IIS servers to spread malware

Flipper Zero now has its own app store for iOS, Android users

https://www.bleepingcomputer.com/news/security/flipper-zero-now-has-its-own-mobile-app-store-for-ios-android/
Flipper Zero now has its own app store for iOS, Android users

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/browse/tag/stores-anytime-at-ply-gg/
MalwareBazaar | Browse Checking your browser

http://varko.xyz/shadertoy_plus_plus_chrome_0day_sisu_statement.html

http://varko.xyz/shadertoy_plus_plus_chrome_0day_sisu_statement.html

Bridging the cybersecurity skills gap through cyber range training - Help Net Security

https://www.helpnetsecurity.com/2023/07/24/debbie-gordon-cyber-range-training/
Bridging the cybersecurity skills gap through cyber range training - Help Net Security

Ivanti schließt Zero-Day-Lücke in MobileIron | heise online

https://www.heise.de/news/Ivanti-schliesst-Zero-Day-Luecke-in-MobileIron-9225583.html
Ivanti schließt Zero-Day-Lücke in MobileIron | heise online

Debugging D-Link: Emulating firmware and hacking hardware

https://www.greynoise.io/blog/debugging-d-link-emulating-firmware-and-hacking-hardware
Debugging D-Link: Emulating firmware and hacking hardware

Analysis https://productkeyforfree.com Malicious activity - Interactive analysis ANY.RUN

https://app.any.run/tasks/484f9eee-5b39-4c44-b33d-06c0fb042717/
Analysis https://productkeyforfree.com Malicious activity - Interactive analysis ANY.RUN