06/20

Project Zero: Project Naptime: Evaluating Offensive Security Capabilities of Large Language Models

https://googleprojectzero.blogspot.com/2024/06/project-naptime.html
Project Zero: Project Naptime: Evaluating Offensive Security Capabilities of Large Language Models

T-Mobile denies it was hacked, links leaked data to vendor breach

https://www.bleepingcomputer.com/news/security/t-mobile-denies-it-was-hacked-links-leaked-data-to-vendor-breach/
T-Mobile denies it was hacked, links leaked data to vendor breach

Binary Ninja - Restructuring the Binary Ninja Decompiler

https://binary.ninja/2024/06/19/restructuring-the-decompiler.html
Binary Ninja - Restructuring the Binary Ninja Decompiler

SolarWinds Serv-U path traversal flaw actively exploited in attacks

https://www.bleepingcomputer.com/news/security/solarwinds-serv-u-path-traversal-flaw-actively-exploited-in-attacks/
SolarWinds Serv-U path traversal flaw actively exploited in attacks

An unpatched bug allows anyone to impersonate Microsoft corporate email accounts

https://securityaffairs.com/164675/hacking/expert-warns-of-a-spoofing-bug.html
An unpatched bug allows anyone to impersonate Microsoft corporate email accounts

Preauth RCE on NVIDIA Triton Server

https://sites.google.com/site/zhiniangpeng/blogs/Triton-RCE
Preauth RCE on NVIDIA Triton Server

CDK Global hacked again while recovering from first cyberattack

https://www.bleepingcomputer.com/news/security/cdk-global-hacked-again-while-recovering-from-first-cyberattack/
CDK Global hacked again while recovering from first cyberattack

TURPENTINE: CVE-2024-27815

https://jprx.io/cve-2024-27815/
TURPENTINE: CVE-2024-27815

Experts Uncover New Evasive SquidLoader Malware Targeting Chinese Organizations

https://thehackernews.com/2024/06/experts-uncover-new-evasive-squidloader.html
Experts Uncover New Evasive SquidLoader Malware Targeting Chinese Organizations

Analyzing Mutation-Coded - VM Protect and Alcatraz English | Keowu Blog's

https://keowu.re/posts/Analyzing-Mutation-Coded-VM-Protect-and-Alcatraz-English/
Analyzing Mutation-Coded - VM Protect and Alcatraz English | Keowu Blog's

Researchers Uncover UEFI Vulnerability Affecting Multiple Intel CPUs

https://thehackernews.com/2024/06/researchers-uncover-uefi-vulnerability.html
Researchers Uncover UEFI Vulnerability Affecting Multiple Intel CPUs

Sustained Campaign Using Chinese Espionage Tools Targets Telcos | Symantec Enterprise Blogs

https://symantec-enterprise-blogs.security.com/threat-intelligence/telecoms-espionage-asia
Sustained Campaign Using Chinese Espionage Tools Targets Telcos | Symantec Enterprise Blogs

Atlassian Patches High-Severity Vulnerabilities in Confluence, Crucible, Jira - SecurityWeek

https://www.securityweek.com/atlassian-patches-high-severity-vulnerabilities-in-confluence-crucible-jira/
Atlassian Patches High-Severity Vulnerabilities in Confluence, Crucible, Jira - SecurityWeek

Alleged researchers stole $3 million from Kraken exchange

https://securityaffairs.com/164694/hacking/kraken-zero-day-cyber-theft.html
Alleged researchers stole $3 million from Kraken exchange

Hundreds of PC, Server Models Possibly Affected by Serious Phoenix UEFI Vulnerability - SecurityWeek

https://www.securityweek.com/hundreds-of-pc-server-models-possibly-affected-by-serious-phoenix-uefi-vulnerability/
Hundreds of PC, Server Models Possibly Affected by Serious Phoenix UEFI Vulnerability - SecurityWeek

Reversing UK mobile rail tickets

https://eta.st/2023/01/31/rail-tickets.html
Reversing UK mobile rail tickets

TikTok facing fresh lawsuit in US over children's privacy | Malwarebytes

https://www.malwarebytes.com/blog/news/2024/06/tiktok-facing-fresh-lawsuit-in-us-over-childrens-privacy
TikTok facing fresh lawsuit in US over children's privacy | Malwarebytes

Russian spies' hacking campaign is 'endangering' French diplomatic interests

https://therecord.media/france-anssi-warning-russia-hacking-campaign-svr
Russian spies' hacking campaign is 'endangering' French diplomatic interests

How to break the token theft cyber-attack chain - Microsoft Community Hub

https://techcommunity.microsoft.com/t5/microsoft-entra-blog/how-to-break-the-token-theft-cyber-attack-chain/ba-p/4062700
How to break the token theft cyber-attack chain - Microsoft Community Hub

New Rust-based Fickle Malware Uses PowerShell for UAC Bypass and Data Exfiltration

https://thehackernews.com/2024/06/new-rust-based-fickle-malware-uses.html
New Rust-based Fickle Malware Uses PowerShell for UAC Bypass and Data Exfiltration

UNC3886 hackers use Linux rootkits to hide on VMware ESXi VMs

https://www.bleepingcomputer.com/news/security/unc3886-hackers-use-linux-rootkits-to-hide-on-vmware-esxi-vms/
UNC3886 hackers use Linux rootkits to hide on VMware ESXi VMs

KrebsOnSecurity Threatened with Defamation Lawsuit Over Fake Radaris CEO – Krebs on Security

https://krebsonsecurity.com/2024/06/krebsonsecurity-threatened-with-defamation-lawsuit-over-fake-radaris-ceo/
KrebsOnSecurity Threatened with Defamation Lawsuit Over Fake Radaris CEO – Krebs on Security

Exploiting CVE-2024-21378 – Remote Code Execution in Microsoft Outlook

https://www.netspi.com/blog/technical-blog/red-team-operations/microsoft-outlook-remote-code-execution-cve-2024-21378/
Exploiting CVE-2024-21378 – Remote Code Execution in Microsoft Outlook

Atlassian fixed six high-severity bugs in Confluence

https://securityaffairs.com/164743/security/atlassian-confluence-crucible-jira-flaws.html
Atlassian fixed six high-severity bugs in Confluence

Fickle Stealer Distributed via Multiple Attack Chain | FortiGuard Labs

https://www.fortinet.com/blog/threat-research/fickle-stealer-distributed-via-multiple-attack-chain
Fickle Stealer Distributed via Multiple Attack Chain | FortiGuard Labs

Linux version of RansomHub ransomware targets VMware ESXi VMs

https://www.bleepingcomputer.com/news/security/linux-version-of-ransomhub-ransomware-targets-vmware-esxi-vms/
Linux version of RansomHub ransomware targets VMware ESXi VMs

Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021

https://thehackernews.com/2024/06/chinese-cyber-espionage-targets-telecom.html
Chinese Cyber Espionage Targets Telecom Operators in Asia Since 2021

Decade-Long Cyber Assault on Asian Telecoms Traced to Chinese State Hackers - SecurityWeek

https://www.securityweek.com/long-running-chinese-espionage-campaign-targets-telecom-firms-in-asian-country/
Decade-Long Cyber Assault on Asian Telecoms Traced to Chinese State Hackers - SecurityWeek