https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
https://www.qualys.com/2024/07/01/cve-2024-6387/regresshion.txt
regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server | Qualys Security Blog
https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server
io (@iok) / X
https://twitter.com/iok
I SCANNED EVERY BUG BOUNTY PROGRAM - YouTube
https://youtu.be/Se_eYMSPMEU
Router maker's support portal hacked, replies with MetaMask phishing
https://www.bleepingcomputer.com/news/security/router-makers-support-portal-responds-with-metamask-phishing/
New OpenSSH Vulnerability Could Lead to RCE as Root on Linux Systems
https://thehackernews.com/2024/07/new-openssh-vulnerability-could-lead-to.html
CVE-2024-6387: Critical OpenSSH Unauthenticated RCE Flaw 'regreSSHion' Exposes Millions of Linux Systems
https://securityonline.info/cve-2024-6387-critical-openssh-unauthenticated-rce-flaw-regresshion-exposes-millions-of-linux-systems/
CapraRAT Spyware Disguised as Popular Apps Threatens Android Users
https://thehackernews.com/2024/07/caprarat-spyware-disguised-as-popular.html
Latest Intel CPUs impacted by new Indirector side-channel attack
https://www.bleepingcomputer.com/news/security/latest-intel-cpus-impacted-by-new-indirector-side-channel-attack/
New regreSSHion OpenSSH RCE bug gives root on Linux servers
https://www.bleepingcomputer.com/news/security/new-regresshion-openssh-rce-bug-gives-root-on-linux-servers/
Release v0.5.0 · VirusTotal/yara-x · GitHub
https://github.com/VirusTotal/yara-x/releases/tag/v0.5.0
Cisco warns of NX-OS zero-day exploited to deploy custom malware
https://www.bleepingcomputer.com/news/security/cisco-warns-of-nx-os-zero-day-exploited-to-deploy-custom-malware/
TeamViewer Hack Officially Attributed to Russian Cyberspies - SecurityWeek
https://www.securityweek.com/teamviewer-hack-officially-attributed-to-russian-cyberspies/
A Detection Engineer’s Guide to SCCM Misconfiguration Abuse | by Trenton Tait | Jun, 2024 | SnapAttack
https://blog.snapattack.com/a-detection-engineers-guide-to-sccm-misconfiguration-abuse-50fa059a446e
Add aux gather module for MOVEit Transfer SFTP auth bypass (CVE-2024-5806) by sfewer-r7 · Pull Request #19295 · rapid7/metasploit-framework · GitHub
https://github.com/rapid7/metasploit-framework/pull/19295
Microsoft tells more customers their emails have been stolen • The Register
https://go.theregister.com/feed/www.theregister.com/2024/07/01/infosec_in_brief/
CDK Global says all dealers will be back online by Thursday
https://www.bleepingcomputer.com/news/security/cdk-global-says-all-dealers-will-be-back-online-by-thursday/
元インターポール サイバー犯罪捜査官の福森⼤喜氏がGMOサイバーセキュリティ byイエラエに参画 | ニュース一覧 | 脆弱性診断(セキュリティ診断)のGMOサイバーセキュリティ byイエラエ
https://gmo-cybersecurity.com/news/20240701-2/
GitHub - zgzhang/cve-2024-6387-poc: a signal handler race condition in OpenSSH's server (sshd)
https://github.com/zgzhang/cve-2024-6387-poc
Police allege ‘evil twin’ in-flight Wi-Fi used to steal info • The Register
https://go.theregister.com/feed/www.theregister.com/2024/07/01/australia_evil_twin_wifi_airline_attack/
Securely design your applications and protect your sensitive data with VBS enclaves - Microsoft Community Hub
https://techcommunity.microsoft.com/t5/windows-os-platform-blog/securely-design-your-applications-and-protect-your-sensitive/ba-p/4179543
Critical Flaws in CocoaPods Expose iOS and macOS Apps to Supply Chain Attacks
https://thehackernews.com/2024/07/critical-flaws-in-cocoapods-expose-ios.html
TrustedSec Tech Brief - June 2024 Week 4 - YouTube
https://www.youtube.com/watch?v=hBDfCnvY4XU
https://www.openssh.com/txt/release-9.8
https://www.openssh.com/txt/release-9.8
oss-security - CVE-2024-6387: RCE in OpenSSH's server, on glibc-based Linux systems
https://www.openwall.com/lists/oss-security/2024/07/01/3
Google Offering $250,000 for Full VM Escape in New KVM Bug Bounty Program - SecurityWeek
https://www.securityweek.com/google-offering-250000-for-full-vm-escape-in-new-kvm-bug-bounty-program/
Creating a Rootkit to Learn C - The Human Machine Interface
https://h0mbre.github.io/Learn-C-By-Creating-A-Rootkit/
Millions of OpenSSH Servers Potentially Vulnerable to Remote regreSSHion Attack - SecurityWeek
https://www.securityweek.com/millions-of-openssh-servers-potentially-vulnerable-to-remote-regresshion-attack/
Australian charged for ‘Evil Twin’ WiFi attack on plane
https://www.bleepingcomputer.com/news/security/australian-charged-for-evil-twin-wifi-attack-on-plane/
Reversing Windows Container, episode II: Silo to Server Silo - Quarkslab's blog
https://blog.quarkslab.com/reversing-windows-container-part-ii-silo-to-server-silo.html
Indian Software Firm's Products Hacked to Spread Data-Stealing Malware
https://thehackernews.com/2024/07/indian-software-firms-products-hacked.html
Juniper Networks Releases Critical Security Update for Routers
https://thehackernews.com/2024/07/juniper-networks-releases-critical.html
Prudential Financial Data Breach Impacts 2.5 Million - SecurityWeek
https://www.securityweek.com/prudential-financial-data-breach-impacts-2-5-million/
RomHack - Buy Tickets
https://romhack.io/tickets
Kimsuky Deploys TRANSLATEXT Chrome Extension |ThreatLabz
https://www.zscaler.com/blogs/security-research/kimsuky-deploys-translatext-target-south-korean-academia