01/19

Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard | MSRC Blog | Microsoft Security Response Center

https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/
Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard | MSRC Blog | Microsoft Security Response Center

TeamViewer abused to breach networks in new ransomware attacks

https://www.bleepingcomputer.com/news/security/teamviewer-abused-to-breach-networks-in-new-ransomware-attacks/
TeamViewer abused to breach networks in new ransomware attacks

Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software

https://thehackernews.com/2024/01/experts-warn-of-macos-backdoor-hidden.html
Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software

Ivanti Connect Secure Exploited to Install Cryptominers | GreyNoise Blog

https://www.greynoise.io/blog/ivanti-connect-secure-exploited-to-install-cryptominers
Ivanti Connect Secure Exploited to Install Cryptominers | GreyNoise Blog

Chinese hackers exploit VMware bug as zero-day for two years

https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-vmware-bug-as-zero-day-for-two-years/
Chinese hackers exploit VMware bug as zero-day for two years

Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware

https://blog.google/threat-analysis-group/google-tag-coldriver-russian-phishing-malware/
Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware

VMware confirms critical vCenter flaw now exploited in attacks

https://www.bleepingcomputer.com/news/security/vmware-confirms-critical-vcenter-flaw-now-exploited-in-attacks/
VMware confirms critical vCenter flaw now exploited in attacks

Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package

https://thehackernews.com/2024/01/npm-trojan-bypasses-uac-installs.html
Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package

U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability

https://thehackernews.com/2024/01/us-cybersecurity-agency-warns-of.html
U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability

Security Brief: TA866 Returns with a Large Email Campaign  | Proofpoint US

https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta866-returns-large-email-campaign
Security Brief: TA866 Returns with a Large Email Campaign  | Proofpoint US

Shodan Account

https://trends.shodan.io/search?query=%22BlackHunt+Ransomware%22#facet/overview
Shodan Account

High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE

https://www.assetnote.io/resources/research/high-signal-detection-and-exploitation-of-ivantis-pulse-connect-secure-auth-bypass-rce
High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE

VF Corp Says Data Breach Resulting From Ransomware Attack Impacts 35 Million - SecurityWeek

https://www.securityweek.com/vf-corp-says-data-breach-resulting-from-ransomware-attack-impacts-35-million/
VF Corp Says Data Breach Resulting From Ransomware Attack Impacts 35 Million - SecurityWeek

FTC bans one more data broker from selling your location info

https://www.bleepingcomputer.com/news/security/ftc-bans-one-more-data-broker-from-selling-your-location-info/
FTC bans one more data broker from selling your location info

Creating a Rootkit to Learn C - The Human Machine Interface

https://h0mbre.github.io/Learn-C-By-Creating-A-Rootkit/
Creating a Rootkit to Learn C - The Human Machine Interface

Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution - Exodus Intelligence

https://blog.exodusintel.com/2024/01/19/google-chrome-v8-cve-2024-0517-out-of-bounds-write-code-execution/
Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution - Exodus Intelligence

VMware vCenter Server Vulnerability Exploited in Wild  - SecurityWeek

https://www.securityweek.com/vmware-vcenter-server-vulnerability-exploited-in-wild/
VMware vCenter Server Vulnerability Exploited in Wild  - SecurityWeek

US Gov Publishes Cybersecurity Guidance for Water and Wastewater Utilities - SecurityWeek

https://www.securityweek.com/us-gov-publishes-cybersecurity-guidance-for-water-and-wastewater-utilities/
US Gov Publishes Cybersecurity Guidance for Water and Wastewater Utilities - SecurityWeek

Payoneer accounts in Argentina hacked in 2FA bypass attacks

https://www.bleepingcomputer.com/news/security/payoneer-accounts-in-argentina-hacked-in-2fa-bypass-attacks/
Payoneer accounts in Argentina hacked in 2FA bypass attacks

Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes

https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes

Google: Russian FSB hackers deploy new Spica backdoor malware

https://www.bleepingcomputer.com/news/security/google-russian-fsb-hackers-deploy-new-spica-backdoor-malware/
Google: Russian FSB hackers deploy new Spica backdoor malware

IT consultant in Germany fined for exposing shoddy security • The Register

https://go.theregister.com/feed/www.theregister.com/2024/01/19/germany_fine_security/
IT consultant in Germany fined for exposing shoddy security • The Register

Top Official Says Kansas Courts Need at Least $2.6 Million to Recover From Cyberattack - SecurityWeek

https://www.securityweek.com/top-official-says-kansas-courts-need-at-least-2-6-million-to-recover-from-cyberattack/
Top Official Says Kansas Courts Need at Least $2.6 Million to Recover From Cyberattack - SecurityWeek

Introducing HTTPQL: A new query language for hackers

https://blog.caido.io/introducing-httpql
Introducing HTTPQL: A new query language for hackers

Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating – NVISO Labs

https://blog.nviso.eu/2024/01/15/deobfuscating-android-arm64-strings-with-ghidra-emulating-patching-and-automating/
Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating – NVISO Labs