08/09

Cookieless DuoDrop: IIS Auth Bypass & App Pool Privesc in ASP.NET Framework (CVE-2023-36899) | Soroush Dalili (@irsdl) Blog

https://soroush.me/blog/2023/08/cookieless-duodrop-iis-auth-bypass-app-pool-privesc-in-asp-net-framework-cve-2023-36899/
Cookieless DuoDrop: IIS Auth Bypass & App Pool Privesc in ASP.NET Framework (CVE-2023-36899) | Soroush Dalili (@irsdl) Blog

A Message from Rapid7 CEO, Corey Thomas | Rapid7 Blog

https://www.rapid7.com/blog/post/2023/08/08/a-message-from-rapid7-ceo-corey-thomas/
A Message from Rapid7 CEO, Corey Thomas | Rapid7 Blog

r-tec Blog | Evade signature-based phishing detections - r-tec Cyber Security

https://www.r-tec.net/r-tec-blog-evade-signature-based-phishing-detections.html
r-tec Blog | Evade signature-based phishing detections - r-tec Cyber Security

EvilProxy phishing campaign targets 120,000 Microsoft 365 users

https://www.bleepingcomputer.com/news/security/evilproxy-phishing-campaign-targets-120-000-microsoft-365-users/
EvilProxy phishing campaign targets 120,000 Microsoft 365 users

Malicious Campaigns Exploit Weak Kubernetes Clusters for Crypto Mining

https://thehackernews.com/2023/08/malicious-campaigns-exploit-weak.html
Malicious Campaigns Exploit Weak Kubernetes Clusters for Crypto Mining

U.K. Electoral Commission Breach Exposes Voter Data of 40 Million Britons

https://thehackernews.com/2023/08/uk-electoral-commission-breach-exposes.html
U.K. Electoral Commission Breach Exposes Voter Data of 40 Million Britons

Collide+Power, Downfall, and Inception: New Side-Channel Attacks Affecting Modern CPUs

https://thehackernews.com/2023/08/collidepower-downfall-and-inception-new.html
Collide+Power, Downfall, and Inception: New Side-Channel Attacks Affecting Modern CPUs

Microsoft Releases Patches for 74 New Vulnerabilities in August Update

https://thehackernews.com/2023/08/microsoft-releases-patches-for-74-new.html
Microsoft Releases Patches for 74 New Vulnerabilities in August Update

Ghidralligator: Emulate and Fuzz the Embedded World - Airbus Defence and Space Cyber

https://www.cyber.airbus.com/ghidralligator_emulate_and_fuzz_the_embedded_world/
Ghidralligator: Emulate and Fuzz the Embedded World - Airbus Defence and Space Cyber

China-Linked Hackers Strike Worldwide: 17 Nations Hit in 3-Year Cyber Campaign

https://thehackernews.com/2023/08/china-linked-hackers-strike-worldwide.html
China-Linked Hackers Strike Worldwide: 17 Nations Hit in 3-Year Cyber Campaign

New Android 14 Security Feature: IT Admins Can Now Disable 2G Networks

https://thehackernews.com/2023/08/new-android-14-security-feature-it.html
New Android 14 Security Feature: IT Admins Can Now Disable 2G Networks

Google to fight hackers with weekly Chrome security updates

https://www.bleepingcomputer.com/news/google/google-to-fight-hackers-with-weekly-chrome-security-updates/
Google to fight hackers with weekly Chrome security updates

Rapid7 Announces Layoffs, Office Closings Under Restructuring Plan - SecurityWeek

https://www.securityweek.com/rapid7-announces-layoffs-office-closings-under-restructuring-plan/
Rapid7 Announces Layoffs, Office Closings Under Restructuring Plan - SecurityWeek

Popular open source project Moq criticized for quietly collecting data

https://www.bleepingcomputer.com/news/security/popular-open-source-project-moq-criticized-for-quietly-collecting-data/
Popular open source project Moq criticized for quietly collecting data

INTERPOL shutters ‘16shop’ phishing platform • The Register

https://www.theregister.com/2023/08/09/interpol_16shop_phishing_shutdown/
INTERPOL shutters ‘16shop’ phishing platform • The Register

August 2023 Security Updates - Release Notes - Security Update Guide - Microsoft

https://msrc.microsoft.com/update-guide/releaseNote/2023-Aug
August 2023 Security Updates - Release Notes - Security Update Guide - Microsoft

New Downfall attacks on Intel CPUs steal encryption keys, data

https://www.bleepingcomputer.com/news/security/new-downfall-attacks-on-intel-cpus-steal-encryption-keys-data/
New Downfall attacks on Intel CPUs steal encryption keys, data

GitHub - sensepost/hostapd-mana at hostapd-2.10

https://github.com/sensepost/hostapd-mana/tree/hostapd-2.10
GitHub - sensepost/hostapd-mana at hostapd-2.10

Northern Ireland police investigate second data breach after documents containing officers' names stolen | UK News | Sky News

https://news.sky.com/story/northern-ireland-police-investigate-second-data-breach-after-documents-containing-officers-names-stolen-12936808
Northern Ireland police investigate second data breach after documents containing officers' names stolen | UK News | Sky News

SAP Patches Critical Vulnerability in PowerDesigner Product - SecurityWeek

https://www.securityweek.com/sap-patches-critical-vulnerability-in-powerdesigner-product/
SAP Patches Critical Vulnerability in PowerDesigner Product - SecurityWeek

Novel 'Inception' Attack Exposes Sensitive Data in CPUs

https://www.hackread.com/novel-inception-attack-exposes-data-cpus/
Novel 'Inception' Attack Exposes Sensitive Data in CPUs

New Report Exposes Vice Society's Collaboration with Rhysida Ransomware

https://thehackernews.com/2023/08/new-report-exposes-vice-societys.html
New Report Exposes Vice Society's Collaboration with Rhysida Ransomware

BloodHound Community Edition: A New Era | by Andy Robbins | Aug, 2023 | Posts By SpecterOps Team Members

https://posts.specterops.io/bloodhound-community-edition-a-new-era-d64689806e90
BloodHound Community Edition: A New Era | by Andy Robbins | Aug, 2023 | Posts By SpecterOps Team Members

The Rhysida Ransomware: Activity Analysis and Ties to Vice Society - Check Point Research

https://research.checkpoint.com/2023/the-rhysida-ransomware-activity-analysis-and-ties-to-vice-society/
The Rhysida Ransomware: Activity Analysis and Ties to Vice Society - Check Point Research

Four tips to keep your GitHub Actions workflows secure - The GitHub Blog

https://github.blog/2023-08-09-four-tips-to-keep-your-github-actions-workflows-secure
Four tips to keep your GitHub Actions workflows secure - The GitHub Blog

MalwareBazaar | Browse Checking your browser

https://bazaar.abuse.ch/browse/tag/ftp-mgcpakistan-com/
MalwareBazaar | Browse Checking your browser

New BitForge cryptocurrency wallet flaws lets hackers steal crypto

https://www.bleepingcomputer.com/news/cryptocurrency/new-bitforge-cryptocurrency-wallet-flaws-lets-hackers-steal-crypto/
New BitForge cryptocurrency wallet flaws lets hackers steal crypto

URLhaus | Checking your browser

https://urlhaus.abuse.ch/url/2703195/
URLhaus | Checking your browser

Microsoft Visual Studio Code flaw lets extensions steal passwords

https://www.bleepingcomputer.com/news/security/microsoft-visual-studio-code-flaw-lets-extensions-steal-passwords/
Microsoft Visual Studio Code flaw lets extensions steal passwords

Rhysida ransomware behind recent attacks on healthcare

https://www.bleepingcomputer.com/news/security/rhysida-ransomware-behind-recent-attacks-on-healthcare/
Rhysida ransomware behind recent attacks on healthcare

Missouri warns that health info was stolen in IBM MOVEit data breach

https://www.bleepingcomputer.com/news/security/missouri-warns-that-health-info-was-stolen-in-ibm-moveit-data-breach/
Missouri warns that health info was stolen in IBM MOVEit data breach

LockBit threatens to leak medical data of cancer patients stolen from Varian Medical SystemsSecurity Affairs

https://securityaffairs.com/149307/cyber-crime/varian-medical-systems-lockbit-ransomware.html
LockBit threatens to leak medical data of cancer patients stolen from Varian Medical SystemsSecurity Affairs

Forging Tickets in 2023 - 0xdeaddood

https://0xdeaddood.rocks/2023/05/11/forging-tickets-in-2023/
Forging Tickets in 2023 - 0xdeaddood

Downfall: New Intel CPU Attack Exposing Sensitive Information - SecurityWeek

https://www.securityweek.com/downfall-new-intel-cpu-attack-exposing-sensitive-information/
Downfall: New Intel CPU Attack Exposing Sensitive Information - SecurityWeek

Webinar Registration - Zoom

https://ghst.ly/3Om0jDo
Webinar Registration - Zoom

Interpol takes down phishing-as-a-service platform used by 70,000 people

https://therecord.media/phishing-as-a-service-platform-taken-down-16shop-interpol
Interpol takes down phishing-as-a-service platform used by 70,000 people

CISA KEV: A Picture is Worth a Thousand Vulns

https://nucleussec.com/cisa-kev-art/
CISA KEV: A Picture is Worth a Thousand Vulns