08/10

Emerging Attacker Exploit: Microsoft Cross-Tenant Synchronization

https://thehackernews.com/2023/08/emerging-attacker-exploit-microsoft.html
Emerging Attacker Exploit: Microsoft Cross-Tenant Synchronization

New Statc Stealer Malware Emerges: Your Sensitive Data at Risk

https://thehackernews.com/2023/08/new-statc-stealer-malware-emerges-your.html
New Statc Stealer Malware Emerges: Your Sensitive Data at Risk

Cybercriminals Increasingly Using EvilProxy Phishing Kit to Target Executives

https://thehackernews.com/2023/08/cybercriminals-increasingly-using.html
Cybercriminals Increasingly Using EvilProxy Phishing Kit to Target Executives

New Attack Alert: Freeze[.]rs Injector Weaponized for XWorm Malware Attacks

https://thehackernews.com/2023/08/new-attack-alert-freezers-injector.html
New Attack Alert: Freeze[.]rs Injector Weaponized for XWorm Malware Attacks

Encryption Flaws in Popular Chinese Language App Put Users' Typed Data at Risk

https://thehackernews.com/2023/08/encryption-flaws-in-popular-chinese.html
Encryption Flaws in Popular Chinese Language App Put Users' Typed Data at Risk

Simplifying BOF Development: Debug, Test, and Save Your B(e)acon | Cobalt Strike

https://www.cobaltstrike.com/blog/simplifying-bof-development
Simplifying BOF Development: Debug, Test, and Save Your B(e)acon | Cobalt Strike

MoustachedBouncer hackers use AiTM attacks to spy on diplomats

https://www.bleepingcomputer.com/news/security/moustachedbouncer-hackers-use-aitm-attacks-to-spy-on-diplomats/
MoustachedBouncer hackers use AiTM attacks to spy on diplomats

Hackers use open source Merlin post-exploitation toolkit in attacks

https://www.bleepingcomputer.com/news/security/hackers-use-open-source-merlin-post-exploitation-toolkit-in-attacks/
Hackers use open source Merlin post-exploitation toolkit in attacks

Dell Compellent hardcoded key exposes VMware vCenter admin creds

https://www.bleepingcomputer.com/news/security/dell-compellent-hardcoded-key-exposes-vmware-vcenter-admin-creds/
Dell Compellent hardcoded key exposes VMware vCenter admin creds

CISA: New Whirlpool backdoor used in Barracuda ESG hacks

https://www.bleepingcomputer.com/news/security/cisa-new-whirlpool-backdoor-used-in-barracuda-esg-hacks/
CISA: New Whirlpool backdoor used in Barracuda ESG hacks

CVE-2023-38181 - Security Update Guide - Microsoft - Microsoft Exchange Server Spoofing Vulnerability

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-38181
CVE-2023-38181 - Security Update Guide - Microsoft - Microsoft Exchange Server Spoofing Vulnerability

Interpol Busts Phishing-as-a-Service Platform '16Shop,' Leading to 3 Arrests

https://thehackernews.com/2023/08/interpol-busts-phishing-as-service.html
Interpol Busts Phishing-as-a-Service Platform '16Shop,' Leading to 3 Arrests

Windows Defender-Pretender Attack Dismantles Flagship Microsoft EDR

https://www.darkreading.com/attacks-breaches/-researchers-detail-vuln-that-allowed-for-windows-defender-update-process-hijack
Windows Defender-Pretender Attack Dismantles Flagship Microsoft EDR

Detect FYI

http://Detect.FYI
Detect FYI

ICS Village DEFCON 31 Custom Ink Fundraising

https://www.customink.com/fundraising/ics-village-defcon-31
ICS Village DEFCON 31 Custom Ink Fundraising

Windows Internals: Day 4 (Pavel)

https://training.trainsec.net/windows-internals-day-4-pavel
Windows Internals: Day 4 (Pavel)

Focus on DroxiDat/SystemBC | Securelist

https://securelist.com/focus-on-droxidat-systembc/110302/
Focus on DroxiDat/SystemBC | Securelist

Microsoft Exchange updates pulled after breaking non-English installs

https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-updates-pulled-after-breaking-non-english-installs/
Microsoft Exchange updates pulled after breaking non-English installs

CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio  - SecurityWeek

https://www.securityweek.com/cisa-warns-organizations-of-exploited-vulnerability-in-net-visual-studio/
CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio  - SecurityWeek

Gafgyt malware exploits five-years-old flaw in EoL Zyxel router

https://www.bleepingcomputer.com/news/security/gafgyt-malware-exploits-five-years-old-flaw-in-eol-zyxel-router/
Gafgyt malware exploits five-years-old flaw in EoL Zyxel router

Minister defends safety law on messaging apps - BBC News

https://www.bbc.co.uk/news/technology-66455616
Minister defends safety law on messaging apps - BBC News

BSides London 2023 Notification

https://mailchi.mp/82de5c4e95a4/bsideslondon2023
BSides London 2023 Notification