03/12

Patch Tuesday Diffing: CVE-2024-20696 - Windows Libarchive RCE | clearbluejar

https://clearbluejar.github.io/posts/patch-tuesday-diffing-cve-2024-20696-windows-libarchive-rce/
Patch Tuesday Diffing: CVE-2024-20696 - Windows Libarchive RCE | clearbluejar

Tor’s new WebTunnel bridges mimic HTTPS traffic to evade censorship

https://www.bleepingcomputer.com/news/security/tors-new-webtunnel-bridges-mimic-https-traffic-to-evade-censorship/
Tor’s new WebTunnel bridges mimic HTTPS traffic to evade censorship

Watch Out: These PyPI Python Packages Can Drain Your Crypto Wallets

https://thehackernews.com/2024/03/watch-out-these-pypi-python-packages.html
Watch Out: These PyPI Python Packages Can Drain Your Crypto Wallets

Malware Campaign Exploits Popup Builder WordPress Plugin to Infect 3,900+ Sites

https://thehackernews.com/2024/03/malware-campaign-exploits-popup-builder.html
Malware Campaign Exploits Popup Builder WordPress Plugin to Infect 3,900+ Sites

South Korean Citizen Detained in Russia on Cyber Espionage Charges

https://thehackernews.com/2024/03/south-korean-citizen-detained-in-russia.html
South Korean Citizen Detained in Russia on Cyber Espionage Charges

COM objects 101 | 30T4 Blog

https://30t4.me/posts/COM-Objects-101/
COM objects 101 | 30T4 Blog

Researchers expose Microsoft SCCM misconfigs usable in cyberattacks

https://www.bleepingcomputer.com/news/security/researchers-expose-microsoft-sccm-misconfigs-usable-in-cyberattacks/
Researchers expose Microsoft SCCM misconfigs usable in cyberattacks

Security Update Guide - Microsoft

https://msft.it/60119yPTS
Security Update Guide - Microsoft

Insurance scams via QR codes: how to recognise and defend yourself

https://securityaffairs.com/160392/cyber-crime/insurance-scams-via-qr-codes.html
Insurance scams via QR codes: how to recognise and defend yourself

The 2024 Sophos Threat Report: Cybercrime on Main Street – Sophos News

https://news.sophos.com/en-us/2024/03/12/2024-sophos-threat-report/
The 2024 Sophos Threat Report: Cybercrime on Main Street – Sophos News

Why Is 404 Media Included in a Fake Netflix Trailer Made by Russia?

https://www.404media.co/why-is-404-media-included-in-a-fake-netflix-trailer-made-by-russia/
Why Is 404 Media Included in a Fake Netflix Trailer Made by Russia?

Over 12 million auth secrets and keys leaked on GitHub in 2023

https://www.bleepingcomputer.com/news/security/over-12-million-auth-secrets-and-keys-leaked-on-github-in-2023/
Over 12 million auth secrets and keys leaked on GitHub in 2023

Patch Tuesday: Microsoft Flags Major Bugs in HyperV, Exchange Server  - SecurityWeek

https://www.securityweek.com/patch-tuesday-microsoft-flags-major-bugs-in-hyperv-exchange-server/
Patch Tuesday: Microsoft Flags Major Bugs in HyperV, Exchange Server  - SecurityWeek

EquiLend Ransomware Attack Leads to Data Breach  - SecurityWeek

https://www.securityweek.com/equilend-ransomware-attack-leads-to-data-breach/
EquiLend Ransomware Attack Leads to Data Breach  - SecurityWeek

Google Paid Out $10 Million via Bug Bounty Programs in 2023 - SecurityWeek

https://www.securityweek.com/google-paid-out-10-million-via-bug-bounty-programs-in-2023/
Google Paid Out $10 Million via Bug Bounty Programs in 2023 - SecurityWeek

Robots Dream of Root Shells

https://blog.isosceles.com/robots-dream-of-root-shells/
Robots Dream of Root Shells

Boeing whistleblower found dead in apparent suicide | The Hill

https://thehill.com/policy/transportation/4524968-boeing-whistleblower-found-dead-in-apparent-suicide/
Boeing whistleblower found dead in apparent suicide | The Hill

Ransomware review: January 2024

https://www.malwarebytes.com/blog/threat-intelligence/2024/03/ransomware-review-march-2024
Ransomware review: January 2024

Google's Threat model for Post-Quantum Cryptography - Google Bug Hunters

https://bughunters.google.com/blog/5108747984306176/google-s-threat-model-for-post-quantum-cryptography
Google's Threat model for Post-Quantum Cryptography - Google Bug Hunters

24SEC3.pdf

https://nebelwelt.net/files/24SEC3.pdf
24SEC3.pdf

Malware-IOCs/2024-03-11 Latrodectus IOCs at main · executemalware/Malware-IOCs · GitHub

https://github.com/executemalware/Malware-IOCs/blob/main/2024-03-11%20Latrodectus%20IOCs
Malware-IOCs/2024-03-11 Latrodectus IOCs at main · executemalware/Malware-IOCs · GitHub

Abusing Microsoft Access "Linked Table" Feature to Perform NTLM Forced Authentication Attacks - Check Point Research

https://research.checkpoint.com/2023/abusing-microsoft-access-linked-table-feature-to-perform-ntlm-forced-authentication-attacks/
Abusing Microsoft Access "Linked Table" Feature to Perform NTLM Forced Authentication Attacks - Check Point Research

US, Russia Accuse Each Other of Potential Election Cyberattacks - SecurityWeek

https://www.securityweek.com/us-russia-accuse-each-other-of-potential-election-cyberattacks/
US, Russia Accuse Each Other of Potential Election Cyberattacks - SecurityWeek

Stanford: Data of 27,000 people stolen in September ransomware attack

https://www.bleepingcomputer.com/news/security/stanford-data-of-27-000-people-stolen-in-september-ransomware-attack/
Stanford: Data of 27,000 people stolen in September ransomware attack

Whitepaper-A-technical-analysis-of-the-APT28s-backdoor-called-OCEANMAP.pdf

https://securityscorecard.com/wp-content/uploads/2024/03/Whitepaper-A-technical-analysis-of-the-APT28s-backdoor-called-OCEANMAP.pdf
Whitepaper-A-technical-analysis-of-the-APT28s-backdoor-called-OCEANMAP.pdf