Buzzing on Christmas Eve: Trigona Ransomware in 3 Hours - The DFIR Report
https://thedfirreport.com/2024/01/29/buzzing-on-christmas-eve-trigona-ransomware-in-3-hours/
2024 SANS SOC Survey
https://survey.sans.org/jfe/form/SV_2cuqQXXCpi4kO7Y
GitHub - florylsk/ExecIT: Execute shellcode files with rundll32
https://github.com/florylsk/ExecIT
NSA Admits Secretly Buying Your Internet Browsing Data without Warrants
https://thehackernews.com/2024/01/nsa-admits-secretly-buying-your.html
Malicious PyPI Packages Slip WhiteSnake InfoStealer Malware onto Windows Machines
https://thehackernews.com/2024/01/malicious-pypi-packages-slip-whitesnake.html
Researchers Uncover How Outlook Vulnerability Could Leak Your NTLM Passwords
https://thehackernews.com/2024/01/researchers-uncover-outlook.html
Albabat, Kasseika, Kuiper: New Ransomware Gangs Rise with Rust and Golang
https://thehackernews.com/2024/01/albabat-kasseika-kuiper-new-ransomware.html
Ransomware payments drop to record low as victims refuse to pay
https://www.bleepingcomputer.com/news/security/ransomware-payments-drop-to-record-low-as-victims-refuse-to-pay/
Critical Alert: CVE-2023-6200 Exploits Linux Kernel with Code Execution Risk
https://securityonline.info/critical-alert-cve-2023-6200-exploits-linux-kernel-with-code-execution-risk/
DHS employees jailed for stealing data of 200K U.S. govt workers
https://www.bleepingcomputer.com/news/security/dhs-employees-jailed-for-stealing-data-of-200k-us-govt-workers/
Office of Public Affairs | One Iranian and Two Canadian Nationals Indicted in Murder-for-Hire Scheme | United States Department of Justice
https://www.justice.gov/opa/pr/one-iranian-and-two-canadian-nationals-indicted-murder-hire-scheme
Data Privacy Week 2024: The Definitive Roundup of Expert Quotes
https://solutionsreview.com/backup-disaster-recovery/data-privacy-week-2024-the-definitive-roundup-of-expert-quotes/
All my favorite tracing tools: eBPF, QEMU, Perfetto, new ones I built and more - Tristan Hume
https://thume.ca/2023/12/02/tracing-methods/
Compromised routers are still being exploited as malicious infrastructure to target government organizations in Europe and the Caucasus - HarfangLab EDR | Block cyberattacks.
https://harfanglab.io/en/insidethelab/compromised-routers-infrastructure-target-europe-caucasus/
CVE-2024-0517 (Out of Bounds Write in V8)
https://h0meb0dy.me/entry/CVE-2024-0517-Out-of-Bounds-Write-in-V8
SANS Las Vegas 2024 | Cyber Security Training
https://www.sans.org/u/1ukQ
GitHub - Cracked5pider/Stardust: A modern 64-bit position independent implant template
https://github.com/Cracked5pider/Stardust
GitHub - HyperDbg/HyperDbg: State-of-the-art native debugging tool
https://github.com/HyperDbg/HyperDbg
Microsoft says Outlook apps can’t connect to Outlook.com
https://www.bleepingcomputer.com/news/microsoft/microsoft-says-outlook-apps-cant-connect-to-outlookcom/
Top 10 web hacking techniques of 2023 - PortSwigger
https://portswigger.net/polls/top-10-web-hacking-techniques-2023
US Aid Office in Colombia Reports Its Facebook Page Was Hacked - SecurityWeek
https://www.securityweek.com/us-aid-office-in-colombia-reports-its-facebook-page-was-hacked/
AI Companies Will Need to Start Reporting Their Safety Tests to the US Government - SecurityWeek
https://www.securityweek.com/ai-companies-will-need-to-start-reporting-their-safety-tests-to-the-us-government/
750m Indian mobile subscribers’ info for sale on dark web • The Register
https://go.theregister.com/feed/www.theregister.com/2024/01/28/asia_tech_news_roundup/
Ivanti Struggling to Hit Zero-Day Patch Release Schedule - SecurityWeek
https://www.securityweek.com/ivanti-struggling-to-hit-zero-day-patch-release-schedule/
Microsoft Teams hit by second outage in three days
https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-hit-by-second-outage-in-three-days/
FBI: Tech support scams now use couriers to collect victims' money
https://www.bleepingcomputer.com/news/security/fbi-tech-support-scams-now-use-couriers-to-collect-victims-money/
Mshta | LOLBAS
https://lolbas-project.github.io/lolbas/Binaries/Mshta/
ZAP – Signing Requests using RSA Keys
https://www.zaproxy.org/blog/2024-01-29-signing-requests-using-rsa-keys/
Experts detailed Microsoft Outlook flaw that can leak NTLM v2 hashed passwords
https://securityaffairs.com/158287/hacking/microsoft-outlook-bug-leak-ntlm-v2-passwords.html
Outlook – free personal email and calendar from Microsoft
http://Outlook.com
The malware analyst’s guide to aPLib decompression
https://0xc0decafe.com/malware-analysts-guide-to-aplib-decompression
45k Jenkins servers exposed to RCE attacks using public exploits
https://www.bleepingcomputer.com/news/security/45k-jenkins-servers-exposed-to-rce-attacks-using-public-exploits/
Energy giant Schneider Electric hit by Cactus ransomware attack
https://www.bleepingcomputer.com/news/security/energy-giant-schneider-electric-hit-by-cactus-ransomware-attack/