04/02

Bypassing DOMPurify with good old XML - Flatt Security Research

https://flatt.tech/research/posts/bypassing-dompurify-with-good-old-xml/
Bypassing DOMPurify with good old XML - Flatt Security Research

OffensiveCon24 :: pretalx

https://cfp.offensivecon.org/offensivecon24/cfp
OffensiveCon24 :: pretalx

research!rsc: Timeline of the xz open source attack

https://research.swtch.com/xz-timeline
research!rsc: Timeline of the xz open source attack

From OneNote to RansomNote: An Ice Cold Intrusion - The DFIR Report

https://thedfirreport.com/2024/04/01/from-onenote-to-ransomnote-an-ice-cold-intrusion/
From OneNote to RansomNote: An Ice Cold Intrusion - The DFIR Report

New Chrome feature aims to stop hackers from using stolen cookies

https://www.bleepingcomputer.com/news/security/new-chrome-feature-aims-to-stop-hackers-from-using-stolen-cookies/
New Chrome feature aims to stop hackers from using stolen cookies

Dark Wire by Joseph Cox | Hachette Book Group

https://www.hachettebookgroup.com/titles/joseph-cox/dark-wire/9781541702691/#preorder
Dark Wire by Joseph Cox | Hachette Book Group

India rescues 250 citizens enslaved by Cambodian cybercrime gang

https://www.bleepingcomputer.com/news/security/india-rescues-250-citizens-enslaved-by-cambodian-cybercrime-gang/
India rescues 250 citizens enslaved by Cambodian cybercrime gang

New XZ backdoor scanner detects implant in any Linux binary

https://www.bleepingcomputer.com/news/security/new-xz-backdoor-scanner-detects-implant-in-any-linux-binary/
New XZ backdoor scanner detects implant in any Linux binary

IBIS hotel check-in terminal keypad-code leakage | Pentagrid AG

https://www.pentagrid.ch/en/blog/ibis-hotel-check-in-terminal-keypad-code-leakage/
IBIS hotel check-in terminal keypad-code leakage | Pentagrid AG

Earth Freybug Uses UNAPIMON for Unhooking Critical APIs | Trend Micro (US)

https://www.trendmicro.com/en_us/research/24/d/earth-freybug.html
Earth Freybug Uses UNAPIMON for Unhooking Critical APIs | Trend Micro (US)

Microsoft FAQ and guidance for XZ Utils backdoor - Microsoft Community Hub

https://techcommunity.microsoft.com/t5/microsoft-defender-vulnerability/microsoft-faq-and-guidance-for-xz-utils-backdoor/ba-p/4101961
Microsoft FAQ and guidance for XZ Utils backdoor - Microsoft Community Hub

PandaBuy data breach allegedly impacted +1.3M customers

https://securityaffairs.com/161355/data-breach/pandabuy-data-breach.html
PandaBuy data breach allegedly impacted +1.3M customers

1311_05-08_mickens.pdf

https://www.usenix.org/system/files/1311_05-08_mickens.pdf
1311_05-08_mickens.pdf

China-linked Hackers Deploy New 'UNAPIMON' Malware for Stealthy Operations

https://thehackernews.com/2024/04/china-linked-hackers-deploy-new.html
China-linked Hackers Deploy New 'UNAPIMON' Malware for Stealthy Operations

Attacking an EDR - Part 3

https://her0ness.github.io/2023-11-07-Attacking-an-EDR-Part-3/
Attacking an EDR - Part 3

Maldev using AI - YouTube

https://www.youtube.com/watch?v=syKnjf9iVWk
Maldev using AI - YouTube

Massive Phishing Campaign Strikes Latin America: Venom RAT Targeting Multiple Sectors

https://thehackernews.com/2024/04/massive-phishing-campaign-strikes-latin.html
Massive Phishing Campaign Strikes Latin America: Venom RAT Targeting Multiple Sectors

ZAP – ZAP Updates - March 2024

https://www.zaproxy.org/blog/2024-04-02-zap-updates-march-2024/
ZAP – ZAP Updates - March 2024

Google now blocks spoofed emails for better phishing protection

https://www.bleepingcomputer.com/news/google/google-now-blocks-spoofed-emails-for-better-phishing-protection/
Google now blocks spoofed emails for better phishing protection

Google to delete search data of millions who used 'incognito' mode : NPR

https://www.npr.org/2024/04/01/1242019127/google-incognito-mode-settlement-search-history
Google to delete search data of millions who used 'incognito' mode : NPR

Russia charges suspects behind theft of 160,000 credit cards

https://www.bleepingcomputer.com/news/security/russia-charges-suspects-behind-theft-of-160-000-credit-cards/
Russia charges suspects behind theft of 160,000 credit cards

OWASP Data Breach Caused by Server Misconfiguration - SecurityWeek

https://www.securityweek.com/owasp-data-breach-caused-by-server-misconfiguration/
OWASP Data Breach Caused by Server Misconfiguration - SecurityWeek

NVD - CVE-2024-3094

https://nvd.nist.gov/vuln/detail/CVE-2024-3094
NVD - CVE-2024-3094

FTC: Americans lost $1.1 billion to impersonation scams in 2023

https://www.bleepingcomputer.com/news/security/ftc-americans-lost-11-billion-to-impersonation-scams-in-2023/
FTC: Americans lost $1.1 billion to impersonation scams in 2023

Google to Delete Billions of Browsing Records in 'Incognito Mode' Privacy Lawsuit Settlement

https://thehackernews.com/2024/04/google-to-delete-billions-of-browsing.html
Google to Delete Billions of Browsing Records in 'Incognito Mode' Privacy Lawsuit Settlement

TROOPERS24

https://troopers.de/students/
TROOPERS24

INC Ransom claims 'cyber incident' at UK city council • The Register

https://go.theregister.com/feed/www.theregister.com/2024/04/02/inc_ransom_leicester_council/
INC Ransom claims 'cyber incident' at UK city council • The Register