06/07

No Way, PHP Strikes Again! (CVE-2024-4577)

https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/?123=
No Way, PHP Strikes Again! (CVE-2024-4577)

No Way, PHP Strikes Again! (CVE-2024-4577)

https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/
No Way, PHP Strikes Again! (CVE-2024-4577)

Microsoft makes Windows Recall opt-in, secures data with Windows Hello

https://www.bleepingcomputer.com/news/microsoft/microsoft-makes-windows-recall-opt-in-secures-data-with-windows-hello/
Microsoft makes Windows Recall opt-in, secures data with Windows Hello

Phishing for Gold: Cyber Threats Facing the 2024 Paris Olympics | Google Cloud Blog

https://cloud.google.com/blog/topics/threat-intelligence/cyber-threats-2024-paris-olympics
Phishing for Gold: Cyber Threats Facing the 2024 Paris Olympics | Google Cloud Blog

SolarWinds Patches High-Severity Vulnerability Reported by NATO Pentester - SecurityWeek

https://www.securityweek.com/solarwinds-patches-high-severity-vulnerability-reported-by-nato-pentester/
SolarWinds Patches High-Severity Vulnerability Reported by NATO Pentester - SecurityWeek

PHP fixes critical RCE flaw impacting all versions for Windows

https://www.bleepingcomputer.com/news/security/php-fixes-critical-rce-flaw-impacting-all-versions-for-windows/
PHP fixes critical RCE flaw impacting all versions for Windows

Windows won’t take screenshots of everything you do after all — unless you opt in - The Verge

https://www.theverge.com/2024/6/7/24173499/microsoft-windows-recall-response-security-concerns
Windows won’t take screenshots of everything you do after all — unless you opt in - The Verge

Log in to X / X

https://twitter.com/rx
Log in to X / X

Security Alert: CVE-2024-4577 - PHP CGI Argument Injection Vulnerability | DEVCORE

https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/
Security Alert: CVE-2024-4577 - PHP CGI Argument Injection Vulnerability | DEVCORE

FUZZING'23 Workshop @ ISSTA

https://fuzzingworkshop.github.io/
FUZZING'23 Workshop @ ISSTA

FUZZING 2024

https://fuzzing24.hotcrp.com
FUZZING 2024

Windows Native API… by Pavel Yosifovich [Leanpub PDF/iPad/Kindle]

https://leanpub.com/windowsnativeapiprogramming
Windows Native API… by Pavel Yosifovich [Leanpub PDF/iPad/Kindle]

CVE-2024-27822: macOS PackageKit Privilege Escalation | Mykola’s blog

https://khronokernel.com/macos/2024/06/03/CVE-2024-27822.html
CVE-2024-27822: macOS PackageKit Privilege Escalation | Mykola’s blog

Pandabuy was extorted twice by the same threat actor

https://securityaffairs.com/164263/cyber-crime/pandabuy-extorted-again.html
Pandabuy was extorted twice by the same threat actor

CVE-2024-4577: Critical PHP Vulnerability Exposes Millions of Servers to RCE

https://securityonline.info/cve-2024-4577-critical-php-vulnerability-exposes-millions-of-servers-to-rce/
CVE-2024-4577: Critical PHP Vulnerability Exposes Millions of Servers to RCE

New Fog ransomware targets US education sector via breached VPNs

https://www.bleepingcomputer.com/news/security/new-fog-ransomware-targets-us-education-sector-via-breached-vpns/
New Fog ransomware targets US education sector via breached VPNs

https://pathonproject.com/zb/?30ea28505bb4a50b=#SzGZdzbJTstoRGgtNeQ8PneRuiMWZtesC5kPqsIGjzA=

https://pathonproject.com/zb/?30ea28505bb4a50b=#SzGZdzbJTstoRGgtNeQ8PneRuiMWZtesC5kPqsIGjzA=

LightSpy Spyware's macOS Variant Found with Advanced Surveillance Capabilities

https://thehackernews.com/2024/06/lightspy-spywares-macos-variant-found.html
LightSpy Spyware's macOS Variant Found with Advanced Surveillance Capabilities

Vercel Security Checkpoint

https://redteamrecipe.com/assembly-for-hackers
Vercel Security Checkpoint

Update on the Recall preview feature for Copilot+ PCs | Windows Experience Blog

https://blogs.windows.com/windowsexperience/2024/06/07/update-on-the-recall-preview-feature-for-copilot-pcs/
Update on the Recall preview feature for Copilot+ PCs | Windows Experience Blog

io (@iok) / X

https://twitter.com/iok
io (@iok) / X

Mozilla Launches 0Din Gen-AI Bug Bounty Program - SecurityWeek

https://www.securityweek.com/mozilla-launches-0din-gen-ai-bug-bounty-program/
Mozilla Launches 0Din Gen-AI Bug Bounty Program - SecurityWeek

LastPass says 12-hour outage caused by bad Chrome extension update

https://www.bleepingcomputer.com/news/security/lastpass-says-12-hour-outage-caused-by-bad-chrome-extension-update/
LastPass says 12-hour outage caused by bad Chrome extension update

Microsoft Bows to Public Pressure, Disables Controversial Windows Recall by Default - SecurityWeek

https://www.securityweek.com/microsoft-bows-to-public-pressure-disables-controversial-windows-recall-by-default/
Microsoft Bows to Public Pressure, Disables Controversial Windows Recall by Default - SecurityWeek

An AirTags Stalking Sting Operation

https://www.404media.co/email/ce4cec4d-51c3-4101-b2b4-2c9a64aee5e8/
An AirTags Stalking Sting Operation

SPECTR Malware Targets Ukraine Defense Forces in SickSync Campaign

https://thehackernews.com/2024/06/spectr-malware-targets-ukraine-defense.html
SPECTR Malware Targets Ukraine Defense Forces in SickSync Campaign

TargetCompany’s Linux Variant Targets ESXi Environments | Trend Micro (US)

https://www.trendmicro.com/en_us/research/24/f/targetcompany-s-linux-variant-targets-esxi-environments.html
TargetCompany’s Linux Variant Targets ESXi Environments | Trend Micro (US)

ransomware_notes/blackbasta/instructions_read_me.txt at main · threatlabz/ransomware_notes · GitHub

https://github.com/threatlabz/ransomware_notes/blob/main/blackbasta/instructions_read_me.txt
ransomware_notes/blackbasta/instructions_read_me.txt at main · threatlabz/ransomware_notes · GitHub