03/22

GitHub - TarlogicSecurity/BlueSpy

https://github.com/TarlogicSecurity/BlueSpy
GitHub - TarlogicSecurity/BlueSpy

Mozilla fixes two Firefox zero-day bugs exploited at Pwn2Own

https://www.bleepingcomputer.com/news/security/mozilla-fixes-two-firefox-zero-day-bugs-exploited-at-pwn2own/
Mozilla fixes two Firefox zero-day bugs exploited at Pwn2Own

Hackers earn $1,132,500 for 29 zero-days at Pwn2Own Vancouver

https://www.bleepingcomputer.com/news/security/hackers-earn-1-132-500-for-29-zero-days-at-pwn2own-vancouver/
Hackers earn $1,132,500 for 29 zero-days at Pwn2Own Vancouver

China-Linked Group Breaches Networks via Connectwise, F5 Software Flaws

https://thehackernews.com/2024/03/china-linked-group-breaches-networks.html
China-Linked Group Breaches Networks via Connectwise, F5 Software Flaws

Linux Page Cache for SRE | Viacheslav Biriukov

https://biriukov.dev/docs/page-cache/0-linux-page-cache-for-sre/
Linux Page Cache for SRE | Viacheslav Biriukov

Active Directory Enumeration for Red Teams - MDSec

https://www.mdsec.co.uk/2024/02/active-directory-enumeration-for-red-teams/
Active Directory Enumeration for Red Teams - MDSec

Unsaflok flaw can let hackers unlock millions of hotel doors

https://www.bleepingcomputer.com/news/security/unsaflok-flaw-can-let-hackers-unlock-millions-of-hotel-doors/
Unsaflok flaw can let hackers unlock millions of hotel doors

Russian Hackers May Have Targeted Ukrainian Telecoms with Upgraded 'AcidPour' Malware

https://thehackernews.com/2024/03/russian-hackers-target-ukrainian.html
Russian Hackers May Have Targeted Ukrainian Telecoms with Upgraded 'AcidPour' Malware

Security Vulnerabilities fixed in Firefox 124.0.1 — Mozilla

https://www.mozilla.org/en-US/security/advisories/mfsa2024-15/
Security Vulnerabilities fixed in Firefox 124.0.1 — Mozilla

Full Chain Baseband Exploits, Part 1 - taszk.io labs

https://labs.taszk.io/articles/post/full_chain_bb_part1/
Full Chain Baseband Exploits, Part 1 - taszk.io labs

GoFetch

https://gofetch.fail/
GoFetch

Saflok Lock Vulnerability Can Be Exploited to Open Millions of Doors - SecurityWeek

https://www.securityweek.com/saflok-lock-vulnerability-can-be-exploited-to-open-millions-of-doors/
Saflok Lock Vulnerability Can Be Exploited to Open Millions of Doors - SecurityWeek

AWS Patches Critical 'FlowFixation' Bug in Airflow Service to Prevent Session Hijacking

https://thehackernews.com/2024/03/aws-patches-critical-flowfixation-bug.html
AWS Patches Critical 'FlowFixation' Bug in Airflow Service to Prevent Session Hijacking

39,000 Websites Infected in 'Sign1' Malware Campaign - SecurityWeek

https://www.securityweek.com/39000-websites-infected-in-sign1-malware-campaign/
39,000 Websites Infected in 'Sign1' Malware Campaign - SecurityWeek

Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects

https://thehackernews.com/2024/03/massive-sign1-campaign-infects-39000.html
Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects

rev.ng

http://rev.ng
rev.ng

U.S. Justice Department Sues Apple Over Monopoly and Messaging Security

https://thehackernews.com/2024/03/us-justice-department-sues-apple-over.html
U.S. Justice Department Sues Apple Over Monopoly and Messaging Security

New GoFetch attack on Apple Silicon CPUs can steal crypto keys

https://www.bleepingcomputer.com/news/security/new-gofetch-attack-on-apple-silicon-cpus-can-steal-crypto-keys/
New GoFetch attack on Apple Silicon CPUs can steal crypto keys

Whois "geofeed" Data - SANS Internet Storm Center

https://isc.sans.edu/diary/Whois+geofeed+Data/30766
Whois "geofeed" Data - SANS Internet Storm Center

Malware-IOCs/2024-03-21 FakeUpdates_IOCs at main · executemalware/Malware-IOCs · GitHub

https://github.com/executemalware/Malware-IOCs/blob/main/2024-03-21%20FakeUpdates_IOCs
Malware-IOCs/2024-03-21 FakeUpdates_IOCs at main · executemalware/Malware-IOCs · GitHub

Streamline your static analysis triage with SARIF Explorer | Trail of Bits Blog

https://blog.trailofbits.com/2024/03/20/streamline-the-static-analysis-triage-process-with-sarif-explorer/
Streamline your static analysis triage with SARIF Explorer | Trail of Bits Blog

Evasive Sign1 malware campaign infects 39,000 WordPress sites

https://www.bleepingcomputer.com/news/security/evasive-sign1-malware-campaign-infects-39-000-wordpress-sites/
Evasive Sign1 malware campaign infects 39,000 WordPress sites

New StrelaStealer Phishing Attacks Hit Over 100 Organizations in E.U. and U.S.

https://thehackernews.com/2024/03/new-strelastealer-phishing-attacks-hit.html
New StrelaStealer Phishing Attacks Hit Over 100 Organizations in E.U. and U.S.

SMB Enumeration Cheatsheet | 0xdf hacks stuff

https://0xdf.gitlab.io/2024/03/21/smb-cheat-sheet.html
SMB Enumeration Cheatsheet | 0xdf hacks stuff

BKA - Listenseite für Pressemitteilungen 2024 - Illegaler Darknet-Marktplatz „Nemesis Market“ abgeschaltet

https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2024/Presse2024/240321_PM_Nemesis_Market.html
BKA - Listenseite für Pressemitteilungen 2024 - Illegaler Darknet-Marktplatz „Nemesis Market“ abgeschaltet

Mozilla Drops Onerep After CEO Admits to Running People-Search Networks – Krebs on Security

https://krebsonsecurity.com/2024/03/mozilla-drops-onerep-after-ceo-admits-to-running-people-search-networks/
Mozilla Drops Onerep After CEO Admits to Running People-Search Networks – Krebs on Security

New 'GoFetch' Apple CPU Attack Exposes Crypto Keys  - SecurityWeek

https://www.securityweek.com/new-gofetch-apple-cpu-attack-exposes-crypto-keys/
New 'GoFetch' Apple CPU Attack Exposes Crypto Keys  - SecurityWeek

Darknet marketplace Nemesis Market seized by German police

https://www.bleepingcomputer.com/news/security/darknet-marketplace-nemesis-market-seized-by-german-police/
Darknet marketplace Nemesis Market seized by German police

APT29 Uses WINELOADER to Target German Political Parties | Mandiant

https://www.mandiant.com/resources/blog/apt29-wineloader-german-political-parties
APT29 Uses WINELOADER to Target German Political Parties | Mandiant

Pwn2Own Vancouver 2024: participants earned $1,132,500 for 29 unique 0-days

https://securityaffairs.com/160901/hacking/pwn2own-vancouver-2024-final-result.html
Pwn2Own Vancouver 2024: participants earned $1,132,500 for 29 unique 0-days