04/04

Microsoft still unsure how hackers stole MSA key in 2023 Exchange attack

https://www.bleepingcomputer.com/news/security/microsoft-still-unsure-how-hackers-stole-msa-key-in-2023-exchange-attack/
Microsoft still unsure how hackers stole MSA key in 2023 Exchange attack

The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind | WIRED

https://www.wired.com/story/jia-tan-xz-backdoor/
The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind | WIRED

‘Lavender’: The AI machine directing Israel’s bombing spree in Gaza

https://www.972mag.com/lavender-ai-israeli-army-gaza/
‘Lavender’: The AI machine directing Israel’s bombing spree in Gaza

Hoya’s optics production and orders disrupted by cyberattack

https://www.bleepingcomputer.com/news/security/hoyas-optics-production-and-orders-disrupted-by-cyberattack/
Hoya’s optics production and orders disrupted by cyberattack

Vietnam-Based Hackers Steal Financial Data Across Asia with Malware

https://thehackernews.com/2024/04/vietnam-based-hackers-steal-financial.html
Vietnam-Based Hackers Steal Financial Data Across Asia with Malware

New HTTP/2 Vulnerability Exposes Web Servers to DoS Attacks

https://thehackernews.com/2024/04/new-http2-vulnerability-exposes-web.html
New HTTP/2 Vulnerability Exposes Web Servers to DoS Attacks

Ivanti Rushes Patches for 4 New Flaws in Connect Secure and Policy Secure

https://thehackernews.com/2024/04/ivanti-rushes-patches-for-4-new-flaw-in.html
Ivanti Rushes Patches for 4 New Flaws in Connect Secure and Policy Secure

Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies | Google Cloud Blog

https://cloud.google.com/blog/topics/threat-intelligence/ivanti-post-exploitation-lateral-movement
Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies | Google Cloud Blog

New HTTP/2 DoS attack can crash web servers with a single connection

https://www.bleepingcomputer.com/news/security/new-http-2-dos-attack-can-crash-web-servers-with-a-single-connection/
New HTTP/2 DoS attack can crash web servers with a single connection

Google Warns: Android Zero-Day Flaws in Pixel Phones Exploited by Forensic Companies

https://thehackernews.com/2024/04/google-warns-android-zero-day-flaws-in.html
Google Warns: Android Zero-Day Flaws in Pixel Phones Exploited by Forensic Companies

The Amazingly Scary XZ SSHD Backdoor - YouTube

https://www.youtube.com/live/HTNKS3tw3xk?si=GGCSWqIvjQjdop0Z
The Amazingly Scary XZ SSHD Backdoor - YouTube

VolWeb - A Centralized And Enhanced Memory Analysis Platform

https://www.kitploit.com/2024/04/volweb-centralized-and-enhanced-memory.html
VolWeb - A Centralized And Enhanced Memory Analysis Platform

🔴 Executive Offense Issue #12 -The Training Landscape Pt. 1

https://executiveoffense.beehiiv.com/p/cybersecurity-training-landscape-pt-1
🔴 Executive Offense Issue #12 -The Training Landscape Pt. 1

Pixel Phone Zero-Days Exploited by Forensic Firms - SecurityWeek

https://www.securityweek.com/pixel-phone-zero-days-exploited-by-forensic-firms/
Pixel Phone Zero-Days Exploited by Forensic Firms - SecurityWeek

Ivanti CEO Vows Cybersecurity Makeover After Zero-Day Blitz - SecurityWeek

https://www.securityweek.com/ivanti-ceo-vows-cybersecurity-makeover-after-zero-day-blitz/
Ivanti CEO Vows Cybersecurity Makeover After Zero-Day Blitz - SecurityWeek

New Phishing Campaign Targets Oil & Gas with Evolved Data-Stealing Malware

https://thehackernews.com/2024/04/new-phishing-campaign-targets-oil-gas.html
New Phishing Campaign Targets Oil & Gas with Evolved Data-Stealing Malware

Malware-IOCs/2024-04-02 XWorm IOCs at main · executemalware/Malware-IOCs · GitHub

https://github.com/executemalware/Malware-IOCs/blob/main/2024-04-02%20XWorm%20IOCs
Malware-IOCs/2024-04-02 XWorm IOCs at main · executemalware/Malware-IOCs · GitHub

Persistence – DLL Proxy Loading – Penetration Testing Lab

https://pentestlab.blog/2024/04/03/persistence-dll-proxy-loading/
Persistence – DLL Proxy Loading – Penetration Testing Lab

SA:CVE-2024-21894 (Heap Overflow), CVE-2024-22052 (Null Pointer Dereference), CVE-2024-22053 (Heap Overflow) and CVE-2024-22023 (XML entity expansion or XXE) for Ivanti Connect Secure and Ivanti Policy Secure Gateways

https://forums.ivanti.com/s/article/SA-CVE-2024-21894-Heap-Overflow-CVE-2024-22052-Null-Pointer-Dereference-CVE-2024-22053-Heap-Overflow-and-CVE-2024-22023-XML-entity-expansion-or-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US
SA:CVE-2024-21894 (Heap Overflow), CVE-2024-22052 (Null Pointer Dereference), CVE-2024-22053 (Heap Overflow) and CVE-2024-22023 (XML entity expansion or XXE) for Ivanti Connect Secure and Ivanti Policy Secure Gateways

US cancer center data breach exposes info of 827,000 patients

https://www.bleepingcomputer.com/news/security/us-cancer-center-data-breach-exposes-info-of-827-000-patients/
US cancer center data breach exposes info of 827,000 patients

Coding a trojan in Python - YouTube

https://www.youtube.com/watch?v=nLLeXRIOWLM
Coding a trojan in Python - YouTube