12/20

Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africa | Symantec Enterprise Blogs

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/iran-apt-seedworm-africa-telecoms
Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africa | Symantec Enterprise Blogs

TrustedSec Impede

http://impede.ai
TrustedSec Impede

Alert: Chinese-Speaking Hackers Pose as UAE Authority in Latest Smishing Wave

https://thehackernews.com/2023/12/alert-chinese-hackers-pose-as-uae.html
Alert: Chinese-Speaking Hackers Pose as UAE Authority in Latest Smishing Wave

New phishing attack steals your Instagram backup codes to bypass 2FA

https://www.bleepingcomputer.com/news/security/new-phishing-attack-steals-your-instagram-backup-codes-to-bypass-2fa/
New phishing attack steals your Instagram backup codes to bypass 2FA

New Go-Based JaskaGO Malware Targeting Windows and macOS Systems

https://thehackernews.com/2023/12/new-go-based-jaskago-malware-targeting.html
New Go-Based JaskaGO Malware Targeting Windows and macOS Systems

Remote Encryption Attacks Surge: How One Vulnerable Device Can Spell Disaster

https://thehackernews.com/2023/12/remote-encryption-attacks-surge-how-one.html
Remote Encryption Attacks Surge: How One Vulnerable Device Can Spell Disaster

OilRig’s persistent attacks using cloud service-powered downloaders

https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/
OilRig’s persistent attacks using cloud service-powered downloaders

Malware-IOCs/2023-12-19 TA577 PikaBot IOCs at main · executemalware/Malware-IOCs · GitHub

https://github.com/executemalware/Malware-IOCs/blob/main/2023-12-19%20TA577%20PikaBot%20IOCs
Malware-IOCs/2023-12-19 TA577 PikaBot IOCs at main · executemalware/Malware-IOCs · GitHub

Phillip Wylie Show | Andy Robbins: The Evolution of Bloodhound

https://www.phillipwylieshow.com/episodes/andy-robbins-the-evolution-of-
Phillip Wylie Show | Andy Robbins: The Evolution of Bloodhound

Crypto scammers abuse X 'feature' to impersonate high-profile accounts

https://www.bleepingcomputer.com/news/security/crypto-scammers-abuse-x-feature-to-impersonate-high-profile-accounts/
Crypto scammers abuse X 'feature' to impersonate high-profile accounts

Behind the scenes: JaskaGO's coordinated strike on macOS and Windows

https://cybersecurity.att.com/blogs/labs-research/behind-the-scenes-jaskagos-coordinated-strike-on-macos-and-windows
Behind the scenes: JaskaGO's coordinated strike on macOS and Windows

3,500 Arrested in Global Operation HAECHI-IV Targeting Financial Criminals

https://thehackernews.com/2023/12/3500-arrested-in-global-operation.html
3,500 Arrested in Global Operation HAECHI-IV Targeting Financial Criminals

FBI: ALPHV ransomware raked in $300 million from over 1,000 victims

https://www.bleepingcomputer.com/news/security/fbi-alphv-ransomware-raked-in-300-million-from-over-1-000-victims/
FBI: ALPHV ransomware raked in $300 million from over 1,000 victims

German police takes down Kingdom Market cybercrime marketplace

https://www.bleepingcomputer.com/news/security/german-police-takes-down-kingdom-market-cybercrime-marketplace/
German police takes down Kingdom Market cybercrime marketplace

Interpol operation arrests 3,500 cybercriminals, seizes $300 million

https://www.bleepingcomputer.com/news/security/interpol-operation-arrests-3-500-cybercriminals-seizes-300-million/
Interpol operation arrests 3,500 cybercriminals, seizes $300 million

PagedOut_003_beta1.pdf

https://pagedout.institute/download/PagedOut_003_beta1.pdf
PagedOut_003_beta1.pdf

Mute the Sound: Chaining Vulnerabilities to Achieve RCE on Outlook: Pt 1 | Akamai

https://www.akamai.com/blog/security-research/2023/dec/chaining-vulnerabilities-to-achieve-rce-part-one
Mute the Sound: Chaining Vulnerabilities to Achieve RCE on Outlook: Pt 1 | Akamai

Ivanti releases patches for 13 critical Avalanche RCE flaws

https://www.bleepingcomputer.com/news/security/ivanti-releases-patches-for-13-critical-avalanche-rce-flaws/
Ivanti releases patches for 13 critical Avalanche RCE flaws

BlackCat Strikes Back: Ransomware Gang “Unseizes” Website, Vows No Limits on Targets - SecurityWeek

https://www.securityweek.com/blackcat-ransomware-group-responds-to-disruption-caused-by-law-enforcement/
BlackCat Strikes Back: Ransomware Gang “Unseizes” Website, Vows No Limits on Targets - SecurityWeek

NSA Blocked 10 Billion Connections to Malicious and Suspicious Domains - SecurityWeek

https://www.securityweek.com/nsa-blocked-10-billion-connections-to-malicious-and-suspicious-domains/
NSA Blocked 10 Billion Connections to Malicious and Suspicious Domains - SecurityWeek

Gaameradon Word/VBS IOCs 12/19/2023 · GitHub

https://gist.github.com/kirk-sayre-work/1dd6e5b08cf168a9b5f9281ce5c37ebb
Gaameradon Word/VBS IOCs 12/19/2023 · GitHub

How I Found SQL Injection worth of $4,000 bounty | by Roberto Nunes | Dec, 2023 | Medium

https://medium.com/@roberto99/how-i-found-sql-injection-worth-of-4-000-bounty-16ca09cbf8ec
How I Found SQL Injection worth of $4,000 bounty | by Roberto Nunes | Dec, 2023 | Medium

Xfinity Data Breach Impacts 36 Million Individuals - SecurityWeek

https://www.securityweek.com/xfinity-data-breach-impacts-36-million-individuals/
Xfinity Data Breach Impacts 36 Million Individuals - SecurityWeek

Introduction to the Scudo Allocator - Vectorize

https://vectorize.re/blog/internals/introduction-to-scudo/
Introduction to the Scudo Allocator - Vectorize

Fake F5 BIG-IP zero-day warning emails push data wipers

https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/
Fake F5 BIG-IP zero-day warning emails push data wipers

Lopseg | OSINT

https://www.lopseg.com.br/osint
Lopseg | OSINT

Developer Program | Microsoft 365 Dev Center

https://developer.microsoft.com/en-us/microsoft-365/dev-program
Developer Program | Microsoft 365 Dev Center