[P2O Vancouver 2023] SharePoint Pre-Auth RCE chain (CVE-2023–29357 & CVE-2023–24955) | STAR Labs
https://starlabs.sg/blog/2023/09-sharepoint-pre-auth-rce-chain/![[P2O Vancouver 2023] SharePoint Pre-Auth RCE chain (CVE-2023–29357 & CVE-2023–24955) | STAR Labs](/image/screenshot/45b7f86a3f202b3c538673cf3adb88a4.png)
From ScreenConnect to Hive Ransomware in 61 hours - The DFIR Report
https://thedfirreport.com/2023/09/25/from-screenconnect-to-hive-ransomware-in-61-hours/
EvilBamboo Targets Mobile Devices in Multi-year Campaign | Volexity
https://www.volexity.com/blog/2023/09/22/evilbamboo-targets-mobile-devices-in-multi-year-campaign/
Call for Papers – ShmooCon
https://www.shmoocon.org/call-for-papers/
From Watering Hole to Spyware: EvilBamboo Targets Tibetans, Uyghurs, and Taiwanese
https://thehackernews.com/2023/09/from-watering-hole-to-spyware.html
Xenomorph Android malware now targets U.S. banks and crypto wallets
https://www.bleepingcomputer.com/news/security/xenomorph-android-malware-now-targets-us-banks-and-crypto-wallets/
Windows Hook Events – Pavel Yosifovich
https://scorpiosoftware.net/2023/09/24/windows-hook-events/
Ukrainian Military Targeted in Phishing Campaign Leveraging Drone Manuals
https://thehackernews.com/2023/09/ukrainian-military-targeted-in-phishing.html
Join the Mission to Prevent and Eradicate Cyberthreats - YouTube
https://www.youtube.com/watch?v=saRvhzZRgyc
COVID.gov/tests - Free at-home COVID-19 tests
http://covidtests.gov
Google is retiring its Gmail Basic HTML view in January 2024
https://www.bleepingcomputer.com/news/security/google-is-retiring-its-gmail-basic-html-view-in-january-2024/
BORN Ontario child registry data breach affects 3.4 million people
https://www.bleepingcomputer.com/news/security/born-ontario-child-registry-data-breach-affects-34-million-people/
How the Cult of the Dead Cow plans to save the internet | CyberScoop
https://cyberscoop.com/cult-of-the-dead-cow-veilid/
GitHub - google/bindiff: Quickly find differences and similarities in disassembled code
https://github.com/google/bindiff
Mixin Network suspends operations following $200 million hack
https://www.bleepingcomputer.com/news/security/mixin-network-suspends-operations-following-200-million-hack/
GitHub - embee-research/revengerat-config-extractor: config extractor for revenge rat
https://github.com/embee-research/revengerat-config-extractor
Sony Group Portal - Home
http://sony.com
Analysis 1695642270-1625ab19586f6660001-2uQ7HE.eml (MD5: B79EDD2EA5B3B8C559BC9116A262B3C2) Malicious activity - Interactive analysis ANY.RUN
https://app.any.run/tasks/d8906703-56da-446c-ad4c-a43c8885b666/
WTS API Wasteland — (Remote) Token Impersonation In Another Level | by Omri Baso | Sep, 2023 | Medium
https://medium.com/@omribaso/wts-api-wasteland-remote-token-impersonation-in-another-level-a23965e8227e
Release BinDiff 8 Open Source · google/bindiff · GitHub
https://github.com/google/bindiff/releases/tag/v8
Active-Directory-trust-attacks/presentations/BSidesCPH2022 at main · martinsohn/Active-Directory-trust-attacks · GitHub
https://github.com/martinsohn/Active-Directory-trust-attacks/tree/main/presentations/BSidesCPH2022
How Could a Self-XSS end with $$$$ | by Mahmoud Hamed | Sep, 2023 | Medium
https://7odamoo.medium.com/how-could-self-xss-end-with-b8342555cf3e
900 US Schools Impacted by MOVEit Hack at National Student Clearinghouse - SecurityWeek
https://www.securityweek.com/900-us-schools-impacted-by-moveit-hack-at-national-student-clearinghouse/
In-the-Wild Exploitation Expected for Critical TeamCity Flaw Allowing Server Takeover - SecurityWeek
https://www.securityweek.com/in-the-wild-exploitation-expected-for-critical-teamcity-flaw-allowing-server-takeover/
Trend Micro Patches Exploited Zero-Day Vulnerability in Endpoint Security Products - SecurityWeek
https://www.securityweek.com/trend-micro-patches-exploited-zero-day-vulnerability-in-endpoint-security-products/
Stealthy APT Gelsemium Seen Targeting Southeast Asian Government - SecurityWeek
https://www.securityweek.com/stealthy-apt-gelsemium-seen-targeting-southeast-asian-government/
‘Who Benefits?’ Inside the EU’s Fight over Scanning for Child Sex Content | Balkan Insight
https://balkaninsight.com/2023/09/25/who-benefits-inside-the-eus-fight-over-scanning-for-child-sex-content/
City of Dallas Details Ransomware Attack Impact, Costs - SecurityWeek
https://www.securityweek.com/city-of-dallas-details-ransomware-attack-impact-costs/
EDRaser - Tool For Remotely Deleting Access Logs, Windows Event Logs, Databases, And Other Files
http://www.kitploit.com/2023/09/edraser-tool-for-remotely-deleting.html
Predator Spyware Delivered to iOS, Android Devices via Zero-Days, MitM Attacks - SecurityWeek
https://www.securityweek.com/predator-spyware-delivered-to-ios-android-devices-via-zero-days-mitm-attacks/
Fantilator Page
https://onlyfans.web.cern.ch