01/30

A Practical Guide to PrintNightmare in 2024 | itm4n's blog

https://itm4n.github.io/printnightmare-exploitation/
A Practical Guide to PrintNightmare in 2024 | itm4n's blog

URGENT: Upgrade GitLab - Critical Workspace Creation Flaw Allows File Overwrite

https://thehackernews.com/2024/01/urgent-upgrade-gitlab-critical.html
URGENT: Upgrade GitLab - Critical Workspace Creation Flaw Allows File Overwrite

2024 SANS SOC Survey

https://survey.sans.org/jfe/form/SV_2cuqQXXCpi4kO7Y
2024 SANS SOC Survey

New ZLoader Malware Variant Surfaces with 64-bit Windows Compatibility

https://thehackernews.com/2024/01/new-zloader-malware-variant-surfaces.html
New ZLoader Malware Variant Surfaces with 64-bit Windows Compatibility

Exclusive: US disabled Chinese hacking network targeting critical infrastructure | Reuters

https://www.reuters.com/world/us/us-disabled-chinese-hacking-network-targeting-critical-infrastructure-sources-2024-01-29/
Exclusive: US disabled Chinese hacking network targeting critical infrastructure | Reuters

Italian Data Protection Watchdog Accuses ChatGPT of Privacy Violations

https://thehackernews.com/2024/01/italian-data-protection-watchdog.html
Italian Data Protection Watchdog Accuses ChatGPT of Privacy Violations

Brazilian Feds Dismantle Grandoreiro Banking Trojan, Arresting Top Operatives

https://thehackernews.com/2024/01/brazilian-feds-dismantle-grandoreiro.html
Brazilian Feds Dismantle Grandoreiro Banking Trojan, Arresting Top Operatives

Juniper Networks Releases Urgent Junos OS Updates for High-Severity Flaws

https://thehackernews.com/2024/01/juniper-networks-releases-urgent-junos.html
Juniper Networks Releases Urgent Junos OS Updates for High-Severity Flaws

Fla. Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider – Krebs on Security

https://krebsonsecurity.com/2024/01/fla-man-charged-in-sim-swapping-spree-is-key-suspect-in-hacker-groups-oktapus-scattered-spider/
Fla. Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider – Krebs on Security

Microsoft Teams phishing pushes DarkGate malware via group chats

https://www.bleepingcomputer.com/news/security/microsoft-teams-phishing-pushes-darkgate-malware-via-group-chats/
Microsoft Teams phishing pushes DarkGate malware via group chats

China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz

https://thehackernews.com/2024/01/china-linked-hackers-target-myanmars.html
China-Linked Hackers Target Myanmar's Top Ministries with Backdoor Blitz

45k Jenkins servers exposed to RCE attacks using public exploits

https://www.bleepingcomputer.com/news/security/45k-jenkins-servers-exposed-to-rce-attacks-using-public-exploits/
45k Jenkins servers exposed to RCE attacks using public exploits

Project Zero: Analyzing a Modern In-the-wild Android Exploit

https://googleprojectzero.blogspot.com/2023/09/analyzing-modern-in-wild-android-exploit.html
Project Zero: Analyzing a Modern In-the-wild Android Exploit

Yearly Intel Trend Review: 2023 | RedSense Cyber Threat Intelligence

https://redsense.com/publications/yearly-intel-trend-review-2023/
Yearly Intel Trend Review: 2023 | RedSense Cyber Threat Intelligence

Automation Hacks: Unearthing a Critical RCE the Easy Way | by Asbawy | Jan, 2024 | Medium

https://asbawy.medium.com/automation-hacks-unearthing-a-critical-rce-the-easy-way-ad64f01a06a3?source=rss------bug_bounty-5
Automation Hacks: Unearthing a Critical RCE the Easy Way | by Asbawy | Jan, 2024 | Medium

Mercedes-Benz accidentally exposed sensitive data, including source code

https://securityaffairs.com/158306/data-breach/mercedes-benz-data-leak.html
Mercedes-Benz accidentally exposed sensitive data, including source code

Citibank sued over failure to defend customers against hacks, fraud

https://www.bleepingcomputer.com/news/technology/citibank-sued-over-failure-to-defend-customers-against-hacks-fraud/
Citibank sued over failure to defend customers against hacks, fraud

Welcome to DorkMe

https://www.dorkme.com/
Welcome to DorkMe

LEAKEY: checks and validates for leaked credentials

https://securityonline.info/leakey-checks-and-validates-for-leaked-credentials/
LEAKEY: checks and validates for leaked credentials

http://geospy.web.app

http://geospy.web.app

Juniper Networks Patches Vulnerabilities in Switches, Firewalls - SecurityWeek

https://www.securityweek.com/juniper-networks-patches-vulnerabilities-in-switches-firewalls/
Juniper Networks Patches Vulnerabilities in Switches, Firewalls - SecurityWeek

Police disrupt Grandoreiro banking malware operation, make arrests

https://www.bleepingcomputer.com/news/security/police-disrupt-grandoreiro-banking-malware-operation-make-arrests/
Police disrupt Grandoreiro banking malware operation, make arrests

APT_REPORT/summary/2024/Symantec_Ransomware_Threat_Landscape_2024.pdf at master · blackorbird/APT_REPORT · GitHub

https://github.com/blackorbird/APT_REPORT/blob/master/summary/2024/Symantec_Ransomware_Threat_Landscape_2024.pdf
APT_REPORT/summary/2024/Symantec_Ransomware_Threat_Landscape_2024.pdf at master · blackorbird/APT_REPORT · GitHub

US charges two more suspects with DraftKing account hacks

https://www.bleepingcomputer.com/news/security/us-charges-two-more-suspects-with-draftking-account-hacks/
US charges two more suspects with DraftKing account hacks

Akira Ransomware and exploitation of Cisco Anyconnect vulnerability CVE-2020-3259 ⋆ Truesec

https://www.truesec.com/hub/blog/akira-ransomware-and-exploitation-of-cisco-anyconnect-vulnerability-cve-2020-3259
Akira Ransomware and exploitation of Cisco Anyconnect vulnerability CVE-2020-3259 ⋆ Truesec

US Disrupted Chinese Hacking Operation Aimed at Critical Infrastructure: Report  - SecurityWeek

https://www.securityweek.com/us-disrupted-chinese-hacking-operation-aimed-at-critical-infrastructure-report/
US Disrupted Chinese Hacking Operation Aimed at Critical Infrastructure: Report  - SecurityWeek

oss-security - Out-of-bounds read & write in the glibc's qsort()

https://www.openwall.com/lists/oss-security/2024/01/30/7
oss-security - Out-of-bounds read & write in the glibc's qsort()

Schneider Electric Responding to Ransomware Attack, Data Breach  - SecurityWeek

https://www.securityweek.com/schneider-electric-division-responding-to-ransomware-attack-data-breach/
Schneider Electric Responding to Ransomware Attack, Data Breach  - SecurityWeek

Faction: Open-source pentesting report generation and collaboration framework - Help Net Security

https://www.helpnetsecurity.com/2024/01/30/faction-pentesting-report-generation-collaboration/
Faction: Open-source pentesting report generation and collaboration framework - Help Net Security

CVE-2024-0517 (Out of Bounds Write in V8)

https://h0meb0dy.me/entry/CVE-2024-0517-Out-of-Bounds-Write-in-V8
CVE-2024-0517 (Out of Bounds Write in V8)

FACT SHEET: Biden-Harris Administration Releases End of Year Report on Open-Source Software Security Initiative | ONCD | The White House

https://www.whitehouse.gov/oncd/briefing-room/2024/01/30/fact-sheet-biden-harris-administration-releases-end-of-year-report-on-open-source-software-security-initiative/
FACT SHEET: Biden-Harris Administration Releases End of Year Report on Open-Source Software Security Initiative | ONCD | The White House

Discord

https://discord.com/events/1091207023942696960/1201898501911609344
Discord

APT_REPORT/summary/2024/GRIT_Ransomware_Annual_Report_2023.pdf at master · blackorbird/APT_REPORT · GitHub

https://github.com/blackorbird/APT_REPORT/blob/master/summary/2024/GRIT_Ransomware_Annual_Report_2023.pdf
APT_REPORT/summary/2024/GRIT_Ransomware_Annual_Report_2023.pdf at master · blackorbird/APT_REPORT · GitHub

Hundreds of network operators’ credentials found circulating in Dark Web

https://securityaffairs.com/158329/cyber-crime/network-operators-credentials-found-in-dark-web.html
Hundreds of network operators’ credentials found circulating in Dark Web

Online ransomware decryptor helps recover partially encrypted files

https://www.bleepingcomputer.com/news/security/online-ransomware-decryptor-helps-recover-partially-encrypted-files/
Online ransomware decryptor helps recover partially encrypted files

Vastaamo hacker traced via ‘untraceable’ Monero transactions, police says

https://www.bleepingcomputer.com/news/security/vastaamo-hacker-traced-via-untraceable-monero-transactions-police-says/
Vastaamo hacker traced via ‘untraceable’ Monero transactions, police says

CVE-2023-40547 - avoid incorrectly trusting HTTP headers · rhboot/shim@0226b56 · GitHub

https://github.com/rhboot/shim/commit/0226b56513b2b8bd5fd281bce77c40c9bf07c66d
CVE-2023-40547 - avoid incorrectly trusting HTTP headers · rhboot/shim@0226b56 · GitHub

US Lawmakers Introduce Farm and Food Cybersecurity Act - SecurityWeek

https://www.securityweek.com/us-lawmakers-introduce-farm-and-food-cybersecurity-act/
US Lawmakers Introduce Farm and Food Cybersecurity Act - SecurityWeek

APT_REPORT/summary/2024/2023 RESEARCH REPORT.pdf at master · blackorbird/APT_REPORT · GitHub

https://github.com/blackorbird/APT_REPORT/blob/master/summary/2024/2023%20RESEARCH%20REPORT.pdf
APT_REPORT/summary/2024/2023 RESEARCH REPORT.pdf at master · blackorbird/APT_REPORT · GitHub

750M Indian mobile subscribers' data offered for sale on dark web

https://securityaffairs.com/158349/data-breach/750m-indian-mobile-subscribers-dark-web.html
750M Indian mobile subscribers' data offered for sale on dark web