10/02

(Research) Exploiting HTTP Parsers Inconsistencies

https://rafa.hashnode.dev/exploiting-http-parsers-inconsistencies
(Research) Exploiting HTTP Parsers Inconsistencies

BunnyLoader: New Malware-as-a-Service Threat Emerges in the Cybercrime Underground

https://thehackernews.com/2023/10/bunnyloader-new-malware-as-service.html
BunnyLoader: New Malware-as-a-Service Threat Emerges in the Cybercrime Underground

Zanubis Android Banking Trojan Poses as Peruvian Government App to Target Users

https://thehackernews.com/2023/10/zanubis-android-banking-trojan-poses-as.html
Zanubis Android Banking Trojan Poses as Peruvian Government App to Target Users

Silent Skimmer: A Year-Long Web Skimming Campaign Targeting Online Payment Businesses

https://thehackernews.com/2023/10/silent-skimmer-year-long-web-skimming.html
Silent Skimmer: A Year-Long Web Skimming Campaign Targeting Online Payment Businesses

OpenRefine's Zip Slip Vulnerability Could Let Attackers Execute Malicious Code

https://thehackernews.com/2023/10/openrefines-zip-slip-vulnerability.html
OpenRefine's Zip Slip Vulnerability Could Let Attackers Execute Malicious Code

[CVE-2023–38743] ManageEngine ADManager Command Injection | by Petrus Viet | Oct, 2023 | Medium

https://petrusviet.medium.com/cve-2023-38743-manageengine-admanager-command-injection-6afccbb196fe
[CVE-2023–38743] ManageEngine ADManager Command Injection | by Petrus Viet | Oct, 2023 | Medium

MalwareBazaar | SHA256 4c4a5c51dc3e8cf6b2a3f6fd54008593002daa180fe73489e93da5e0d152be4f

https://bazaar.abuse.ch/sample/4c4a5c51dc3e8cf6b2a3f6fd54008593002daa180fe73489e93da5e0d152be4f/
MalwareBazaar | SHA256 4c4a5c51dc3e8cf6b2a3f6fd54008593002daa180fe73489e93da5e0d152be4f

Tips and Tricks for Effective SQL Injection Testing using SQLMap Tamper Scripts | by Muhammad Daffa | Oct, 2023 | Medium

https://muhdaffa.medium.com/tips-and-tricks-for-effective-sql-injection-testing-using-sqlmap-tamper-scripts-ed4bfa5717e7
Tips and Tricks for Effective SQL Injection Testing using SQLMap Tamper Scripts | by Muhammad Daffa | Oct, 2023 | Medium

Practical Bug Bounty | TCM Security, Inc.

https://www.tcm.rocks/PracticalBugBounty
Practical Bug Bounty | TCM Security, Inc.

r-tec Blog | .NET Assembly Obfuscation for Memory Scanner Evasion - r-tec Cyber Security

https://www.r-tec.net/r-tec-blog-net-assembly-obfuscation-for-memory-scanner-evasion.html
r-tec Blog | .NET Assembly Obfuscation for Memory Scanner Evasion - r-tec Cyber Security

Thousands of GitHub Comments Leak Live API Keys - Truffle Security

https://trufflesecurity.com/blog/thousands-of-github-comments-leak-live-api-keys/
Thousands of GitHub Comments Leak Live API Keys - Truffle Security

FBI warns of surge in 'phantom hacker' scams impacting elderly

https://www.bleepingcomputer.com/news/security/fbi-warns-of-surge-in-phantom-hacker-scams-impacting-elderly/
FBI warns of surge in 'phantom hacker' scams impacting elderly

Recently Patched TeamCity Vulnerability Exploited to Hack Servers - SecurityWeek

https://www.securityweek.com/recently-patched-teamcity-vulnerability-exploited-to-hack-servers/
Recently Patched TeamCity Vulnerability Exploited to Hack Servers - SecurityWeek

Unpatched Exim Vulnerabilities Expose Many Mail Servers to Attacks  - SecurityWeek

https://www.securityweek.com/unpatched-exim-vulnerabilities-expose-many-mail-servers-to-attacks/
Unpatched Exim Vulnerabilities Expose Many Mail Servers to Attacks  - SecurityWeek

Using silent SMS to localize LTE users

https://mandomat.github.io/2023-09-21-localization-with-silent-SMS/
Using silent SMS to localize LTE users

Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw - SecurityWeek

https://www.securityweek.com/live-exploitation-underscores-urgency-to-patch-critical-ws-ftp-server-flaw/
Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw - SecurityWeek

APIs: Unveiling the Silent Killer of Cyber Security Risk Across Industries

https://thehackernews.com/2023/10/apis-unveiling-silent-killer-of-cyber.html
APIs: Unveiling the Silent Killer of Cyber Security Risk Across Industries

Singapore plans to scan your face instead of your passport • The Register

https://go.theregister.com/feed/www.theregister.com/2023/10/02/singapore_face_scan_passports/
Singapore plans to scan your face instead of your passport • The Register

Amazon sends Mastercard, Google Play gift card order emails by mistake

https://www.bleepingcomputer.com/news/security/amazon-sends-mastercard-google-play-gift-card-order-emails-by-mistake/
Amazon sends Mastercard, Google Play gift card order emails by mistake

Sign in to GitHub · GitHub

http://cs.github.com
Sign in to GitHub · GitHub

LUCR-3: Scattered Spider Getting SaaS-y in the Cloud

https://thehackernews.com/2023/10/lucr-3-scattered-spider-getting-saas-y.html
LUCR-3: Scattered Spider Getting SaaS-y in the Cloud

KubeHound: Identifying attack paths in Kubernetes clusters | Datadog Security Labs

https://securitylabs.datadoghq.com/articles/kubehound-identify-kubernetes-attack-paths/
KubeHound: Identifying attack paths in Kubernetes clusters | Datadog Security Labs

New Marvin attack revives 25-year-old decryption flaw in RSA

https://www.bleepingcomputer.com/news/security/new-marvin-attack-revives-25-year-old-decryption-flaw-in-rsa/
New Marvin attack revives 25-year-old decryption flaw in RSA

Arm warns of Mali GPU flaws likely exploited in targeted attacks

https://www.bleepingcomputer.com/news/security/arm-warns-of-mali-gpu-flaws-likely-exploited-in-targeted-attacks/
Arm warns of Mali GPU flaws likely exploited in targeted attacks

Number of Internet-Exposed ICS Drops Below 100,000: Report - SecurityWeek

https://www.securityweek.com/number-of-internet-exposed-ics-drops-below-100000-report/
Number of Internet-Exposed ICS Drops Below 100,000: Report - SecurityWeek

European Telecommunications Standards Institute Discloses Data Breach - SecurityWeek

https://www.securityweek.com/european-telecommunications-standards-institute-discloses-data-breach/
European Telecommunications Standards Institute Discloses Data Breach - SecurityWeek

Ben Wallace: Ukraine’s counteroffensive is succeeding. Give them the tools to finish the job

https://www.telegraph.co.uk/news/2023/10/01/ben-wallace-ukraine-counteroffensive-succeeding/
Ben Wallace: Ukraine’s counteroffensive is succeeding. Give them the tools to finish the job