GitHub - hugsy/recon_2024_windbg_workshop
https://github.com/hugsy/recon_2024_windbg_workshop
Apple Removes VPN Apps from Russian App Store Amid Government Pressure
https://thehackernews.com/2024/07/apple-removes-vpn-apps-from-russian-app.html
BlueSpy: PoC to record audio from a Bluetooth device
https://meterpreter.org/bluespy-poc-to-record-audio-from-a-bluetooth-device/
GitHub - ManuelBerrueta/FlowAnalyzer: FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).
https://github.com/ManuelBerrueta/FlowAnalyzer
Roblox vendor data breach exposes dev conference attendee info
https://www.bleepingcomputer.com/news/security/roblox-vendor-data-breach-exposes-dev-conference-attendee-info/
Turla: A Master of Deception
https://www.gdatasoftware.com/blog/2024/07/37977-turla-evasion-lnk-files
GitHub - TarlogicSecurity/BlueSpy
https://github.com/TarlogicSecurity/BlueSpy
DLL Sideloading for stable persistence - YouTube
https://www.youtube.com/watch?v=-FmTg2_ESsA
GitHub - enovella/TEE-reversing: A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices
https://github.com/enovella/TEE-reversing
Cisco Confirms Critical OpenSSH regreSSHion (CVE-2024-6387) Flaw in Multiple Products
https://securityonline.info/cisco-confirms-critical-openssh-regresshion-cve-2024-6387-flaw-in-multiple-products/
Live Recon: Hacking Tinder's Bug Bounty Program (with @Rhynorater) - YouTube
https://youtu.be/IWIchfPJUGo
Neiman Marcus data breach: 31 million email addresses found exposed
https://www.bleepingcomputer.com/news/security/neiman-marcus-data-breach-31-million-email-addresses-found-exposed/
Selfie-based ID raises eyebrows among infosec experts • The Register
https://go.theregister.com/feed/www.theregister.com/2024/07/08/selfie_authentication_security/
Critical Unpatched Flaws Disclosed in Popular Gogs Open-Source Git Service
https://thehackernews.com/2024/07/critical-vulnerabilities-disclosed-in.html
1. Kuba Gretzky: Keynote: A Smooth Sea Never Made a Skilled Phisherman - YouTube
https://www.youtube.com/watch?v=Nh99d3YnpI4
IAT tracer demo - YouTube
https://youtu.be/kGa_j-sALUg
New APT Group "CloudSorcerer" Targets Russian Government Entities
https://thehackernews.com/2024/07/new-apt-group-cloudsorcerer-targets.html
Attackers Exploiting Remote Code Execution Vulnerability in Ghostscript - SecurityWeek
https://www.securityweek.com/attackers-exploiting-remote-code-execution-vulnerability-in-ghostscript/
Notepad finally gets spellcheck, autocorrect for all Windows 11 users
https://www.bleepingcomputer.com/news/microsoft/notepad-finally-gets-spellcheck-autocorrect-for-all-windows-11-users/
Apple removed 25 VPN apps from the App Store in Russia
https://securityaffairs.com/165437/hacking/apple-removed-vpn-apps-from-app-store-in-russia.html
Shopify denies it was hacked, links stolen data to third-party app
https://www.bleepingcomputer.com/news/security/shopify-denies-it-was-hacked-links-stolen-data-to-third-party-app/
5 Key Questions CISOs Must Ask Themselves About Their Cybersecurity Strategy
https://thehackernews.com/2024/07/5-key-questions-cisos-must-ask.html
GitHub - hasherezade/ida_ifl: IFL - Interactive Functions List (plugin for IDA Pro)
https://github.com/hasherezade/ida_ifl
日本の組織を狙った攻撃グループKimsukyによる攻撃活動 - JPCERT/CC Eyes | JPCERTコーディネーションセンター公式ブログ
https://blogs.jpcert.or.jp/ja/2024/07/kimsuky.html
CISA adds Cisco NX-OS Command Injection bug to its Known Exploited Vulnerabilities catalog
https://securityaffairs.com/165415/security/cisa-adds-cisco-nx-os-command-injection-bug-known-exploited-vulnerabilities-catalog.html
Microsoft lets SwiftKey support site certificate expire • The Register
https://go.theregister.com/feed/www.theregister.com/2024/07/08/microsoft_swiftkeys_cert_expires/
Microsoft: Windows 11 22H2 reaches end of service in October
https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-11-22h2-reaches-end-of-service-in-october/
Experts Warn of Mekotio Banking Trojan Targeting Latin American Countries
https://thehackernews.com/2024/07/experts-warn-of-mekotio-banking-trojan.html
Avast releases free decryptor for DoNex ransomware and past variants
https://www.bleepingcomputer.com/news/security/avast-releases-free-decryptor-for-donex-ransomware-and-past-variants/
GitHub - bigb0x/CVE-2024-36991: POC for CVE-2024-36991: This exploit will attempt to read Splunk /etc/passwd file.
https://github.com/bigb0x/CVE-2024-36991
Supreme Court Ruling Threatens the Framework of Cybersecurity Regulation - SecurityWeek
https://www.securityweek.com/supreme-court-ruling-threatens-the-framework-of-cybersecurity-regulation/
Europol says Home Routing mobile encryption feature aids criminals
https://www.bleepingcomputer.com/news/security/europol-says-home-routing-mobile-encryption-feature-aids-criminals/