05/14

Security Engineer, Mandiant, Google Cloud — Google Careers

https://www.google.com/about/careers/applications/jobs/results/85951836866912966-security-engineer-mandiant-google-cloud
Security Engineer, Mandiant, Google Cloud — Google Careers

New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation

https://thehackernews.com/2024/05/new-chrome-zero-day-vulnerability-cve.html
New Chrome Zero-Day Vulnerability CVE-2024-4761 Under Active Exploitation

AppleAVD | My interesting researches

https://r00tkitsmm.github.io/fuzzing/2024/05/14/anotherappleavd.html
AppleAVD | My interesting researches

My life as a Chinese spy: Secret police agent tells all - ABC News

https://www.abc.net.au/news/2024-05-13/china-spy-secret-police-agent-tells-all-four-corners/103826708
My life as a Chinese spy: Secret police agent tells all - ABC News

Microsoft Warns of Active Zero-Day Exploitation, Patches 60 Windows Vulnerabilities - SecurityWeek

https://www.securityweek.com/microsoft-patches-60-windows-vulns-warns-of-active-zero-day-exploitation/
Microsoft Warns of Active Zero-Day Exploitation, Patches 60 Windows Vulnerabilities - SecurityWeek

Ebury botnet malware infected 400,000 Linux servers since 2009

https://www.bleepingcomputer.com/news/security/ebury-botnet-malware-infected-400-000-linux-servers-since-2009/
Ebury botnet malware infected 400,000 Linux servers since 2009

CVE-2024-4761 v8 oob write

https://docs.google.com/document/d/e/2PACX-1vSpCvBik81OppzMXbPjb0uRlWTdn4I1kttNSlbHtNMCT3xZJJiyKAsCcUxzNBimlBdXoKxrktlgJjOZ/pub
CVE-2024-4761 v8 oob write

Google Chrome emergency update fixes 6th zero-day exploited in 2024

https://www.bleepingcomputer.com/news/security/google-chrome-emergency-update-fixes-6th-zero-day-exploited-in-2024/
Google Chrome emergency update fixes 6th zero-day exploited in 2024

Microsoft fixes Windows zero-day exploited in QakBot malware attacks

https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-zero-day-exploited-in-qakbot-malware-attacks/
Microsoft fixes Windows zero-day exploited in QakBot malware attacks

VMware makes Workstation Pro and Fusion Pro free for personal use

https://www.bleepingcomputer.com/news/software/vmware-makes-workstation-pro-and-fusion-pro-free-for-personal-use/
VMware makes Workstation Pro and Fusion Pro free for personal use

VMware Desktop Hypervisor Pro Apps Now Available for Personal Use - VMware Cloud Foundation (VCF) Blog

https://blogs.vmware.com/cloud-foundation/2024/05/14/vmware-desktop-hypervisor-pro-apps-now-available-for-personal-use/
VMware Desktop Hypervisor Pro Apps Now Available for Personal Use - VMware Cloud Foundation (VCF) Blog

CVE-2024-33006: Critical SAP Vulnerability Exposes Systems to Complete Takeover

https://securityonline.info/cve-2024-33006-critical-sap-vulnerability-exposes-systems-to-complete-takeover/
CVE-2024-33006: Critical SAP Vulnerability Exposes Systems to Complete Takeover

GraphQL Test Cases

https://anmolksachan.github.io/graphql/
GraphQL Test Cases

Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws

https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2024-patch-tuesday-fixes-3-zero-days-61-flaws/
Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws

Ongoing Campaign Bombards Enterprises with Spam Emails and Phone Calls

https://thehackernews.com/2024/05/ongoing-campaign-bombarded-enterprises.html
Ongoing Campaign Bombards Enterprises with Spam Emails and Phone Calls

Apple fixes Safari WebKit zero-day flaw exploited at Pwn2Own

https://www.bleepingcomputer.com/news/apple/apple-fixes-safari-webkit-zero-day-flaw-exploited-at-pwn2own/
Apple fixes Safari WebKit zero-day flaw exploited at Pwn2Own

Security Update Guide - Microsoft

https://msft.it/60119yPTS
Security Update Guide - Microsoft

BSides Nashville 2024 | Flickr

https://www.flickr.com/gp/200663524@N07/16A4CD246j
BSides Nashville 2024 | Flickr

FCC Warns of 'Royal Tiger' Robocall Scammers - SecurityWeek

https://www.securityweek.com/fcc-warns-of-royal-tiger-robocall-scammers/
FCC Warns of 'Royal Tiger' Robocall Scammers - SecurityWeek

Singing River Health System: Data of 895,000 stolen in ransomware attack

https://www.bleepingcomputer.com/news/security/singing-river-health-system-data-of-895-000-stolen-in-ransomware-attack/
Singing River Health System: Data of 895,000 stolen in ransomware attack

Apple and Google add alerts for unknown Bluetooth trackers to iOS, Android

https://www.bleepingcomputer.com/news/security/apple-and-google-add-alerts-for-unknown-bluetooth-trackers-to-ios-android/
Apple and Google add alerts for unknown Bluetooth trackers to iOS, Android

GitCaught: Threat Actor Leverages GitHub Repository for Malicious Infrastructure | Recorded Future

https://www.recordedfuture.com/gitcaught-threat-actor-leverages-github-repository-for-malicious-infrastructure
GitCaught: Threat Actor Leverages GitHub Repository for Malicious Infrastructure | Recorded Future

QakBot attacks with CVE-2024-30051 Windows zero-day | Securelist

https://securelist.com/cve-2024-30051/112618/
QakBot attacks with CVE-2024-30051 Windows zero-day | Securelist

Hackers use DNS tunneling for network scanning, tracking victims

https://www.bleepingcomputer.com/news/security/hackers-use-dns-tunneling-for-network-scanning-tracking-victims/
Hackers use DNS tunneling for network scanning, tracking victims

VMware Patches Severe Security Flaws in Workstation and Fusion Products

https://thehackernews.com/2024/05/vmware-patches-severe-security-flaws-in.html
VMware Patches Severe Security Flaws in Workstation and Fusion Products

Attackers Use DNS Tunneling to Track Victim Activity, Scan Networks - SecurityWeek

https://www.securityweek.com/attackers-use-dns-tunneling-to-track-victim-activity-scan-networks/
Attackers Use DNS Tunneling to Track Victim Activity, Scan Networks - SecurityWeek

Adobe Patches Critical Flaws in Reader, Acrobat - SecurityWeek

https://www.securityweek.com/adobe-patches-critical-flaws-in-reader-acrobat/
Adobe Patches Critical Flaws in Reader, Acrobat - SecurityWeek

Your Mental Health Matters - YouTube

https://youtu.be/-ljLIf-Pxl0
Your Mental Health Matters - YouTube

VMware Workstation Pro: Now Available Free for Personal Use - VMware Workstation Zealot

https://blogs.vmware.com/workstation/2024/05/vmware-workstation-pro-now-available-free-for-personal-use.html
VMware Workstation Pro: Now Available Free for Personal Use - VMware Workstation Zealot

SAP Patches Critical Vulnerabilities in CX Commerce, NetWeaver - SecurityWeek

https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-cx-commerce-netweaver/
SAP Patches Critical Vulnerabilities in CX Commerce, NetWeaver - SecurityWeek

Student, Personnel Information Stolen in City of Helsinki Cyberattack - SecurityWeek

https://www.securityweek.com/student-personnel-information-stolen-in-city-of-helsinki-cyberattack/
Student, Personnel Information Stolen in City of Helsinki Cyberattack - SecurityWeek

Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code

https://thehackernews.com/2024/05/critical-flaws-in-cacti-framework-could.html
Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code

Hooking System Calls in Windows 11 22H2 like Avast Antivirus. Research, analysis and bypass | the-deniss.github.io

https://the-deniss.github.io/posts/2022/12/08/hooking-system-calls-in-windows-11-22h2-like-avast-antivirus.html
Hooking System Calls in Windows 11 22H2 like Avast Antivirus. Research, analysis and bypass | the-deniss.github.io

Ebury is alive but unseen: 400k Linux servers compromised for cryptotheft and financial gain

https://www.welivesecurity.com/en/eset-research/ebury-alive-unseen-400k-linux-servers-compromised-cryptotheft-financial-gain/
Ebury is alive but unseen: 400k Linux servers compromised for cryptotheft and financial gain

Windows 10 KB5037768 update released with new features and 20 fixes

https://www.bleepingcomputer.com/news/microsoft/windows-10-kb5037768-update-released-with-new-features-and-20-fixes/
Windows 10 KB5037768 update released with new features and 20 fixes