10/27

CVE-2023–4632: Local Privilege Escalation in Lenovo System Updater | by Matt Nelson | Oct, 2023 | Posts By SpecterOps Team Members

https://posts.specterops.io/cve-2023-4632-local-privilege-escalation-in-lenovo-system-updater-2762e9667120
CVE-2023–4632: Local Privilege Escalation in Lenovo System Updater | by Matt Nelson | Oct, 2023 | Posts By SpecterOps Team Members

France says Russian state hackers breached numerous critical networks

https://www.bleepingcomputer.com/news/security/france-says-russian-state-hackers-breached-numerous-critical-networks/
France says Russian state hackers breached numerous critical networks

Compromising F5 BIGIP with Request Smuggling -

https://www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/
Compromising F5 BIGIP with Request Smuggling -

A cascade of compromise: unveiling Lazarus' new campaign | Securelist

https://securelist.com/unveiling-lazarus-new-campaign/110888/
A cascade of compromise: unveiling Lazarus' new campaign | Securelist

F5 fixes BIG-IP auth bypass allowing remote code execution attacks

https://www.bleepingcomputer.com/news/security/f5-fixes-big-ip-auth-bypass-allowing-remote-code-execution-attacks/
F5 fixes BIG-IP auth bypass allowing remote code execution attacks

How Kaspersky obtained all stages of Operation Triangulation | Securelist

https://securelist.com/operation-triangulation-catching-wild-triangle/110916/
How Kaspersky obtained all stages of Operation Triangulation | Securelist

F5 Issues Warning: BIG-IP Vulnerability Allows Remote Code Execution

https://thehackernews.com/2023/10/f5-issues-warning-big-ip-vulnerability.html
F5 Issues Warning: BIG-IP Vulnerability Allows Remote Code Execution

N. Korean Lazarus Group Targets Software Vendor Using Known Flaws

https://thehackernews.com/2023/10/n-korean-lazarus-group-targets-software.html
N. Korean Lazarus Group Targets Software Vendor Using Known Flaws

“EtherHiding” — Hiding Web2 Malicious Code in Web3 Smart Contracts | by Guardio | Oct, 2023 | Medium

https://labs.guard.io/etherhiding-hiding-web2-malicious-code-in-web3-smart-contracts-65ea78efad16
“EtherHiding” — Hiding Web2 Malicious Code in Web3 Smart Contracts | by Guardio | Oct, 2023 | Medium

StripedFly malware framework infects 1 million Windows, Linux hosts

https://www.bleepingcomputer.com/news/security/stripedfly-malware-framework-infects-1-million-windows-linux-hosts/
StripedFly malware framework infects 1 million Windows, Linux hosts

How to Keep Your Business Running in a Contested Environment

https://thehackernews.com/2023/10/how-to-keep-your-business-running-in.html
How to Keep Your Business Running in a Contested Environment

Google Expands Its Bug Bounty Program to Tackle Artificial Intelligence Threats

https://thehackernews.com/2023/10/google-expands-its-bug-bounty-program.html
Google Expands Its Bug Bounty Program to Tackle Artificial Intelligence Threats

Lazarus hackers breached dev repeatedly to deploy SIGNBT malware

https://www.bleepingcomputer.com/news/security/lazarus-hackers-breached-dev-repeatedly-to-deploy-signbt-malware/
Lazarus hackers breached dev repeatedly to deploy SIGNBT malware

The Week in Ransomware - October 27th 2023 - Breaking Records

https://www.bleepingcomputer.com/news/security/the-week-in-ransomware-october-27th-2023-breaking-records/
The Week in Ransomware - October 27th 2023 - Breaking Records

Internet access severed in Gaza as IDF announces ‘expanding’ ground operation

https://therecord.media/internet-access-in-gaza-severed-israel
Internet access severed in Gaza as IDF announces ‘expanding’ ground operation

In Other News: Ex-NSA Employee Spying for Russia, EU Threat Landscape, Cyber Education Funding - SecurityWeek

https://www.securityweek.com/in-other-news-ex-nsa-employee-spying-for-russia-eu-threat-landscape-cyber-education-funding/
In Other News: Ex-NSA Employee Spying for Russia, EU Threat Landscape, Cyber Education Funding - SecurityWeek

Advanced 'StripedFly' Malware With 1 Million Infections Shows Similarities to NSA-Linked Tools - SecurityWeek

https://www.securityweek.com/advanced-stripedfly-malware-with-1-million-infections-shows-similarities-to-nsa-malware/
Advanced 'StripedFly' Malware With 1 Million Infections Shows Similarities to NSA-Linked Tools - SecurityWeek

Cloudflare sees surge in hyper-volumetric HTTP DDoS attacks

https://www.bleepingcomputer.com/news/security/cloudflare-sees-surge-in-hyper-volumetric-http-ddos-attacks/
Cloudflare sees surge in hyper-volumetric HTTP DDoS attacks

Critically close to zero (day): Exploiting Microsoft Kernel streaming service

https://securityintelligence.com/x-force/critically-close-to-zero-day-exploiting-microsoft-kernel-streaming-service/
Critically close to zero (day): Exploiting Microsoft Kernel streaming service

PE relocation Table | MalwareID Unpacking Guide

http://malwareid.in/unpack/unpacking-basics/pe-relocation-table
PE relocation Table | MalwareID Unpacking Guide

navgix: check for nginx alias traversal vulnerabilities

https://securityonline.info/navgix-check-for-nginx-alias-traversal-vulnerabilities/?expand_article=1
navgix: check for nginx alias traversal vulnerabilities

F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP - SecurityWeek

https://www.securityweek.com/f5-warns-of-critical-remote-code-execution-vulnerability-in-big-ip/
F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP - SecurityWeek

exploits/citrix/CVE-2023-4966/exploit.py at main · assetnote/exploits · GitHub

https://github.com/assetnote/exploits/blob/main/citrix/CVE-2023-4966/exploit.py
exploits/citrix/CVE-2023-4966/exploit.py at main · assetnote/exploits · GitHub

A gentle introduction to SMT-based program analysis | Fura Labs

https://furalabs.com/blog/2023/02/12/intro_to_smt_analysis
A gentle introduction to SMT-based program analysis | Fura Labs

Windows 11 KB5031455 preview update enables Moment 4 features by default

https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5031455-preview-update-enables-moment-4-features-by-default/
Windows 11 KB5031455 preview update enables Moment 4 features by default

Windows Exploit Mitigation Bypass - Isolated Heaps - YouTube

https://www.youtube.com/watch?v=5-F_IMpJfHc
Windows Exploit Mitigation Bypass - Isolated Heaps - YouTube

Process Injection using NtSetInformationProcess - RiskInsight

https://www.riskinsight-wavestone.com/en/2023/10/process-injection-using-ntsetinformationprocess/
Process Injection using NtSetInformationProcess - RiskInsight

Microsoft 365 users get workaround for ‘Something Went Wrong’ errors

https://www.bleepingcomputer.com/news/microsoft/microsoft-365-users-get-workaround-for-something-went-wrong-errors/
Microsoft 365 users get workaround for ‘Something Went Wrong’ errors