Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard | MSRC Blog | Microsoft Security Response Center
https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/
TeamViewer abused to breach networks in new ransomware attacks
https://www.bleepingcomputer.com/news/security/teamviewer-abused-to-breach-networks-in-new-ransomware-attacks/
Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software
https://thehackernews.com/2024/01/experts-warn-of-macos-backdoor-hidden.html
Ivanti Connect Secure Exploited to Install Cryptominers | GreyNoise Blog
https://www.greynoise.io/blog/ivanti-connect-secure-exploited-to-install-cryptominers
Chinese hackers exploit VMware bug as zero-day for two years
https://www.bleepingcomputer.com/news/security/chinese-hackers-exploit-vmware-bug-as-zero-day-for-two-years/
Russian threat group COLDRIVER expands its targeting of Western officials to include the use of malware
https://blog.google/threat-analysis-group/google-tag-coldriver-russian-phishing-malware/
VMware confirms critical vCenter flaw now exploited in attacks
https://www.bleepingcomputer.com/news/security/vmware-confirms-critical-vcenter-flaw-now-exploited-in-attacks/
Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package
https://thehackernews.com/2024/01/npm-trojan-bypasses-uac-installs.html
U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability
https://thehackernews.com/2024/01/us-cybersecurity-agency-warns-of.html
GitHub - YOLOP0wn/EchoDrv: Exploitation of echo_driver.sys
https://github.com/YOLOP0wn/EchoDrv
Security Brief: TA866 Returns with a Large Email Campaign | Proofpoint US
https://www.proofpoint.com/us/blog/threat-insight/security-brief-ta866-returns-large-email-campaign
Shodan Account
https://trends.shodan.io/search?query=%22BlackHunt+Ransomware%22#facet/overview
High Signal Detection and Exploitation of Ivanti's Pulse Connect Secure Auth Bypass & RCE
https://www.assetnote.io/resources/research/high-signal-detection-and-exploitation-of-ivantis-pulse-connect-secure-auth-bypass-rce
ShmooCon 2024 Day 1 One Track Mind - YouTube
http://Redact.link/shmoo24
VF Corp Says Data Breach Resulting From Ransomware Attack Impacts 35 Million - SecurityWeek
https://www.securityweek.com/vf-corp-says-data-breach-resulting-from-ransomware-attack-impacts-35-million/
FTC bans one more data broker from selling your location info
https://www.bleepingcomputer.com/news/security/ftc-bans-one-more-data-broker-from-selling-your-location-info/
Creating a Rootkit to Learn C - The Human Machine Interface
https://h0mbre.github.io/Learn-C-By-Creating-A-Rootkit/
Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution - Exodus Intelligence
https://blog.exodusintel.com/2024/01/19/google-chrome-v8-cve-2024-0517-out-of-bounds-write-code-execution/
VMware vCenter Server Vulnerability Exploited in Wild - SecurityWeek
https://www.securityweek.com/vmware-vcenter-server-vulnerability-exploited-in-wild/
US Gov Publishes Cybersecurity Guidance for Water and Wastewater Utilities - SecurityWeek
https://www.securityweek.com/us-gov-publishes-cybersecurity-guidance-for-water-and-wastewater-utilities/
Payoneer accounts in Argentina hacked in 2FA bypass attacks
https://www.bleepingcomputer.com/news/security/payoneer-accounts-in-argentina-hacked-in-2fa-bypass-attacks/
Outlook Vulnerability Discovery and New Ways to Leak NTLM Hashes
https://www.varonis.com/blog/outlook-vulnerability-new-ways-to-leak-ntlm-hashes
Google: Russian FSB hackers deploy new Spica backdoor malware
https://www.bleepingcomputer.com/news/security/google-russian-fsb-hackers-deploy-new-spica-backdoor-malware/
IT consultant in Germany fined for exposing shoddy security • The Register
https://go.theregister.com/feed/www.theregister.com/2024/01/19/germany_fine_security/
Top Official Says Kansas Courts Need at Least $2.6 Million to Recover From Cyberattack - SecurityWeek
https://www.securityweek.com/top-official-says-kansas-courts-need-at-least-2-6-million-to-recover-from-cyberattack/
Introducing HTTPQL: A new query language for hackers
https://blog.caido.io/introducing-httpql
Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating – NVISO Labs
https://blog.nviso.eu/2024/01/15/deobfuscating-android-arm64-strings-with-ghidra-emulating-patching-and-automating/