Tell HN: Microsoft.com added 192.168.1.1 to their DNS record | Hacker News
https://news.ycombinator.com/item?id=38702783
Seedworm: Iranian Hackers Target Telecoms Orgs in North and East Africa | Symantec Enterprise Blogs
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/iran-apt-seedworm-africa-telecoms
TrustedSec Impede
http://impede.ai
Microsoft – クラウド、コンピューター、アプリ & ゲーム
http://Microsoft.com
Alert: Chinese-Speaking Hackers Pose as UAE Authority in Latest Smishing Wave
https://thehackernews.com/2023/12/alert-chinese-hackers-pose-as-uae.html
New phishing attack steals your Instagram backup codes to bypass 2FA
https://www.bleepingcomputer.com/news/security/new-phishing-attack-steals-your-instagram-backup-codes-to-bypass-2fa/
New Go-Based JaskaGO Malware Targeting Windows and macOS Systems
https://thehackernews.com/2023/12/new-go-based-jaskago-malware-targeting.html
Remote Encryption Attacks Surge: How One Vulnerable Device Can Spell Disaster
https://thehackernews.com/2023/12/remote-encryption-attacks-surge-how-one.html
OilRig’s persistent attacks using cloud service-powered downloaders
https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/
Malware-IOCs/2023-12-19 TA577 PikaBot IOCs at main · executemalware/Malware-IOCs · GitHub
https://github.com/executemalware/Malware-IOCs/blob/main/2023-12-19%20TA577%20PikaBot%20IOCs
Phillip Wylie Show | Andy Robbins: The Evolution of Bloodhound
https://www.phillipwylieshow.com/episodes/andy-robbins-the-evolution-of-
Crypto scammers abuse X 'feature' to impersonate high-profile accounts
https://www.bleepingcomputer.com/news/security/crypto-scammers-abuse-x-feature-to-impersonate-high-profile-accounts/
Behind the scenes: JaskaGO's coordinated strike on macOS and Windows
https://cybersecurity.att.com/blogs/labs-research/behind-the-scenes-jaskagos-coordinated-strike-on-macos-and-windows
SANS Security East New Orleans 2024 | Cyber Security Training
https://www.sans.org/u/1u4j
3,500 Arrested in Global Operation HAECHI-IV Targeting Financial Criminals
https://thehackernews.com/2023/12/3500-arrested-in-global-operation.html
FBI: ALPHV ransomware raked in $300 million from over 1,000 victims
https://www.bleepingcomputer.com/news/security/fbi-alphv-ransomware-raked-in-300-million-from-over-1-000-victims/
German police takes down Kingdom Market cybercrime marketplace
https://www.bleepingcomputer.com/news/security/german-police-takes-down-kingdom-market-cybercrime-marketplace/
Interpol operation arrests 3,500 cybercriminals, seizes $300 million
https://www.bleepingcomputer.com/news/security/interpol-operation-arrests-3-500-cybercriminals-seizes-300-million/
PagedOut_003_beta1.pdf
https://pagedout.institute/download/PagedOut_003_beta1.pdf
Mute the Sound: Chaining Vulnerabilities to Achieve RCE on Outlook: Pt 1 | Akamai
https://www.akamai.com/blog/security-research/2023/dec/chaining-vulnerabilities-to-achieve-rce-part-one
Ivanti releases patches for 13 critical Avalanche RCE flaws
https://www.bleepingcomputer.com/news/security/ivanti-releases-patches-for-13-critical-avalanche-rce-flaws/
BlackCat Strikes Back: Ransomware Gang “Unseizes” Website, Vows No Limits on Targets - SecurityWeek
https://www.securityweek.com/blackcat-ransomware-group-responds-to-disruption-caused-by-law-enforcement/
NSA Blocked 10 Billion Connections to Malicious and Suspicious Domains - SecurityWeek
https://www.securityweek.com/nsa-blocked-10-billion-connections-to-malicious-and-suspicious-domains/
Gaameradon Word/VBS IOCs 12/19/2023 · GitHub
https://gist.github.com/kirk-sayre-work/1dd6e5b08cf168a9b5f9281ce5c37ebb
How I Found SQL Injection worth of $4,000 bounty | by Roberto Nunes | Dec, 2023 | Medium
https://medium.com/@roberto99/how-i-found-sql-injection-worth-of-4-000-bounty-16ca09cbf8ec
Xfinity Data Breach Impacts 36 Million Individuals - SecurityWeek
https://www.securityweek.com/xfinity-data-breach-impacts-36-million-individuals/
Introduction to the Scudo Allocator - Vectorize
https://vectorize.re/blog/internals/introduction-to-scudo/
Fake F5 BIG-IP zero-day warning emails push data wipers
https://www.bleepingcomputer.com/news/security/fake-f5-big-ip-zero-day-warning-emails-push-data-wipers/
Lopseg | OSINT
https://www.lopseg.com.br/osint
Developer Program | Microsoft 365 Dev Center
https://developer.microsoft.com/en-us/microsoft-365/dev-program