06/25

Phishing Incident Report: Facts and Timeline  - ANY.RUN's Cybersecurity Blog

https://any.run/cybersecurity-blog/phishing-incident-report/
Phishing Incident Report: Facts and Timeline  - ANY.RUN's Cybersecurity Blog

llama.ttf

https://fuglede.github.io/llama.ttf/
llama.ttf

Auth. Bypass In (Un)Limited Scenarios - Progress MOVEit Transfer (CVE-2024-5806)

https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/
Auth. Bypass In (Un)Limited Scenarios - Progress MOVEit Transfer (CVE-2024-5806)

Polyfill.io

http://Polyfill.io
Polyfill.io

Polyfill.io JavaScript supply chain attack impacts over 100K sites

https://www.bleepingcomputer.com/news/security/polyfillio-javascript-supply-chain-attack-impacts-over-100k-sites/
Polyfill.io JavaScript supply chain attack impacts over 100K sites

Multiple WordPress Plugins Compromised: Hackers Create Rogue Admin Accounts

https://thehackernews.com/2024/06/multiple-wordpress-plugins-compromised.html
Multiple WordPress Plugins Compromised: Hackers Create Rogue Admin Accounts

P2PInfect botnet targets REdis servers with new ransomware module

https://www.bleepingcomputer.com/news/security/p2pinfect-botnet-targets-redis-servers-with-new-ransomware-module/
P2PInfect botnet targets REdis servers with new ransomware module

New attack uses MSC files and Windows XSS flaw to breach networks

https://www.bleepingcomputer.com/news/security/new-attack-uses-msc-files-and-windows-xss-flaw-to-breach-networks/
New attack uses MSC files and Windows XSS flaw to breach networks

Stop Using cdn.polyfill.io Now - Huli's blog

https://blog.huli.tw/2024/06/25/en/stop-using-polyfill-io/
Stop Using cdn.polyfill.io Now - Huli's blog

Monitor Cobalt Strike beacon for Windows tokens and gain Kerberos persistence | sokarepo

https://sokarepo.github.io/redteam/2024/04/18/monitor-cobaltstrike-windows-token-kerberos-persistence.html
Monitor Cobalt Strike beacon for Windows tokens and gain Kerberos persistence | sokarepo

FBI warns of fake law firms targeting crypto scam victims

https://www.bleepingcomputer.com/news/security/fbi-warns-of-fake-law-firms-targeting-crypto-scam-victims/
FBI warns of fake law firms targeting crypto scam victims

4 FIN9-linked Vietnamese Hackers Indicted in $71M U.S. Cybercrime Spree

https://thehackernews.com/2024/06/4-fin9-linked-vietnamese-hackers.html
4 FIN9-linked Vietnamese Hackers Indicted in $71M U.S. Cybercrime Spree

plORMbing your Django ORM

https://www.elttam.com/blog/plormbing-your-django-orm/
plORMbing your Django ORM

ACE Responder

http://ACEResponder.com
ACE Responder

IPC Fuzzing with Snapshots – Attack & Defense

https://blog.mozilla.org/attack-and-defense/2024/06/24/ipc-fuzzing-with-snapshots/
IPC Fuzzing with Snapshots – Attack & Defense

South Africa’s national health lab hit with ransomware attack amid mpox outbreak

https://therecord.media/south-africa-lab-ransomware-mpox-outbreak
South Africa’s national health lab hit with ransomware attack amid mpox outbreak

Operation Blotless攻撃キャンペーンに関する注意喚起

https://www.jpcert.or.jp/at/2024/at240013.html
Operation Blotless攻撃キャンペーンに関する注意喚起

New Medusa malware variants target Android users in seven countries

https://www.bleepingcomputer.com/news/security/new-medusa-malware-variants-target-android-users-in-seven-countries/
New Medusa malware variants target Android users in seven countries