Code Execution in Chromium's V8 Heap Sandbox – Anvbis
https://anvbis.au/posts/code-execution-in-chromiums-v8-heap-sandbox/
WinDbg — the Fun Way: Part 1. A while ago WinDbg added support for a… | by Yarden Shafir | Medium
https://medium.com/@yardenshafir2/windbg-the-fun-way-part-1-2e4978791f9b
Newly discovered: BadSpace backdoor delivered by high-ranking websites
https://www.gdatasoftware.com/blog/2024/06/37947-badspace-backdoor
Police arrest Conti and LockBit ransomware crypter specialist
https://www.bleepingcomputer.com/news/security/police-arrest-conti-and-lockbit-ransomware-crypter-specialist/
Google warns of actively exploited Pixel firmware zero-day
https://www.bleepingcomputer.com/news/security/google-warns-of-actively-exploited-pixel-firmware-zero-day/
The Decompilation Wiki - Decompilation Wiki
https://decompilation.wiki/
Black Basta ransomware gang linked to Windows zero-day attacks
https://www.bleepingcomputer.com/news/security/black-basta-ransomware-gang-linked-to-windows-zero-day-attacks/
CVE-2024-29824 Deep Dive: Ivanti EPM SQL Injection Remote Code Execution Vulnerability – Horizon3.ai
https://www.horizon3.ai/attack-research/attack-blogs/cve-2024-29824-deep-dive-ivanti-epm-sql-injection-remote-code-execution-vulnerability/
Progressive Web Apps (PWAs) Phishing | mr.d0x
https://mrd0x.com/progressive-web-apps-pwa-phishing/
Microsoft deprecates Windows DirectAccess, recommends Always On VPN
https://www.bleepingcomputer.com/news/microsoft/microsoft-deprecates-windows-directaccess-recommends-always-on-vpn/
CISA warns of criminals impersonating its employees in phone calls
https://www.bleepingcomputer.com/news/security/cisa-warns-of-criminals-impersonating-its-employees-in-phone-calls/
Black Basta Ransomware May Have Exploited MS Windows Zero-Day Flaw
https://thehackernews.com/2024/06/black-basta-ransomware-may-have.html
Microsoft Issues Patches for 51 Flaws, Including Critical MSMQ Vulnerability
https://thehackernews.com/2024/06/microsoft-issues-patches-for-51-flaws.html
New Phishing Campaign Deploys WARMCOOKIE Backdoor Targeting Job Seekers
https://thehackernews.com/2024/06/new-phishing-campaign-deploys.html
GitHub - varwara/CVE-2024-26229: CWE-781: Improper Address Validation in IOCTL with METHOD_NEITHER I/O Control Code
https://github.com/varwara/CVE-2024-26229
UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion | Google Cloud Blog
https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion
Lateral Movement with the .NET Profiler | by Daniel Mayer | Jun, 2024 | Posts By SpecterOps Team Members
https://posts.specterops.io/lateral-movement-with-the-net-profiler-8772c86f9523
AWS adds passkeys support, warns root users must enable MFA
https://www.bleepingcomputer.com/news/security/aws-adds-passkeys-support-warns-root-users-must-enable-mfa/
Dipping into Danger: The WARMCOOKIE backdoor — Elastic Security Labs
https://www.elastic.co/security-labs/dipping-into-danger
Life360 says hacker tried to extort them after Tile data breach
https://www.bleepingcomputer.com/news/security/life360-says-hacker-tried-to-extort-them-after-tile-data-breach/
Pure Storage confirms data breach after Snowflake account hack
https://www.bleepingcomputer.com/news/security/pure-storage-confirms-data-breach-after-snowflake-account-hack/
GitHub - S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet: A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
https://github.com/S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet
Microsoft Patches Zero-Click Outlook Vulnerability That Could Soon Be Exploited - SecurityWeek
https://www.securityweek.com/microsoft-patches-zero-click-outlook-vulnerability-that-could-soon-be-exploited/
Fortinet Patches Code Execution Vulnerability in FortiOS - SecurityWeek
https://www.securityweek.com/fortinet-patches-code-execution-vulnerability-in-fortios/
CVE-2023-33127: .NET Cross-Session Privilege Escalation Exploit · GitHub
https://gist.github.com/bohops/c7bf35ee7ff593a3a76014f7f87abb30
China-Backed Hackers Exploit Fortinet Flaw, Infecting 20,000 Systems Globally
https://thehackernews.com/2024/06/china-backed-hackers-exploit-fortinet.html
Bypassing EDR NTDS.dit protection using BlueTeam tools. | by bilal al-qurneh | Jun, 2024 | Medium
https://medium.com/@0xcc00/bypassing-edr-ntds-dit-protection-using-blueteam-tools-1d161a554f9f
No AI training in newly distrusted Terms of Service, Adobe says | Malwarebytes
https://www.malwarebytes.com/blog/news/2024/06/no-ai-training-in-newly-distrusted-terms-of-service-adobe-says
Lessons from the Ticketmaster-Snowflake Breach
https://thehackernews.com/2024/06/lessons-from-ticketmaster-snowflake.html
Cryptojacking Campaign Targets Misconfigured Kubernetes Clusters
https://thehackernews.com/2024/06/cryptojacking-campaign-targets.html
SmokeLoader History | ThreatLabz
https://www.zscaler.com/blogs/security-research/brief-history-smokeloader-part-1
New phishing toolkit uses PWAs to steal login credentials
https://www.bleepingcomputer.com/news/security/new-phishing-toolkit-uses-pwas-to-steal-login-credentials/
Analysis of VirtualBox CVE-2023-21987 and CVE-2023-21991
https://qriousec.github.io/post/vbox-pwn2own-2023/
Effective strategies for conducting Mass Password Resets during cybersecurity incidents
https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/effective-strategies-for-conducting-mass-password-resets-during/ba-p/4159408
Phishing emails abuse Windows search protocol to push malicious scripts
https://www.bleepingcomputer.com/news/security/phishing-emails-abuse-windows-search-protocol-to-push-malicious-scripts/
Introduction to Azure Cloud Token Theft MindMap V1 | by rootsecdev | Jun, 2024 | Medium
https://rootsecdev.medium.com/introduction-to-azure-cloud-token-theft-mindmap-v1-22d015cb5ee8
Thousands of blood test samples set to be destroyed after NHS cyberattack | The Independent
https://www.independent.co.uk/news/health/nhs-cyberattack-london-gp-blood-tests-b2560450.html
Fly Phishing. How to Bypass SPAM Filters | by Forrest Kasler | Jun, 2024 | Medium
https://posts.specterops.io/fly-phishing-7d4fb56ac325
Google Warns of Pixel Firmware Zero-Day Under Limited, Targeted Exploitation - SecurityWeek
https://www.securityweek.com/google-warns-of-pixel-firmware-zero-day-under-limited-targeted-exploitation/