07/22

3 ways to get Remote Code Execution in Kafka UI - The GitHub Blog

https://github.blog/2024-07-22-3-ways-to-get-remote-code-execution-in-kafka-ui/
3 ways to get Remote Code Execution in Kafka UI - The GitHub Blog

Spain arrests three for using DDoSia hacktivist platform

https://www.bleepingcomputer.com/news/security/spain-arrests-three-for-using-ddosia-hacktivist-platform/
Spain arrests three for using DDoSia hacktivist platform

BruCON 2024 Training – BruCON 2024

https://www.brucon.org/2024/brucon-2024-training/
BruCON 2024 Training – BruCON 2024

Schedule

https://www.se.community/schedule/
Schedule

pwnat: Breakthrough NAT Traversal Without Port Forwarding

https://meterpreter.org/pwnat-breakthrough-nat-traversal-without-port-forwarding/
pwnat: Breakthrough NAT Traversal Without Port Forwarding

PINEAPPLE and FLUXROOT Hacker Groups Abuse Google Cloud for Credential Phishing

https://thehackernews.com/2024/07/pineapple-and-fluxroot-hacker-groups.html
PINEAPPLE and FLUXROOT Hacker Groups Abuse Google Cloud for Credential Phishing

New Play ransomware Linux version targets VMware ESXi VMs

https://www.bleepingcomputer.com/news/security/new-play-ransomware-linux-version-targets-vmware-esxi-vms/
New Play ransomware Linux version targets VMware ESXi VMs

Kevin Tellier lighting talk - YouTube

https://youtu.be/JTt0kXkw5s8
Kevin Tellier lighting talk - YouTube

US sanctions Russian hacktivists who breached water facilities

https://www.bleepingcomputer.com/news/security/us-sanctions-russian-hacktivists-who-breached-water-facilities/
US sanctions Russian hacktivists who breached water facilities

Zeroed.Tech

https://zeroed.tech/blog/viewstate-the-unpatchable-iis-forever-day-being-actively-exploited/
Zeroed.Tech

Microsoft releases Windows repair tool to remove CrowdStrike driver

https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-repair-tool-to-remove-crowdstrike-driver/
Microsoft releases Windows repair tool to remove CrowdStrike driver

SocGholish Malware Exploits BOINC Project for Covert Cyberattacks

https://thehackernews.com/2024/07/socgholish-malware-exploits-boinc.html
SocGholish Malware Exploits BOINC Project for Covert Cyberattacks

CrowdStrike Incident Leveraged for Malware Delivery, Phishing, Scams - SecurityWeek

https://www.securityweek.com/crowdstrike-incident-leveraged-for-malware-delivery-phishing-scams/
CrowdStrike Incident Leveraged for Malware Delivery, Phishing, Scams - SecurityWeek

Police infiltrates, takes down DigitalStress DDoS-for-hire service

https://www.bleepingcomputer.com/news/security/police-infiltrates-takes-down-digitalstress-ddos-for-hire-service/
Police infiltrates, takes down DigitalStress DDoS-for-hire service

GitHub - t94j0/adexplorersnapshot-rs

https://github.com/t94j0/adexplorersnapshot-rs
GitHub - t94j0/adexplorersnapshot-rs

Fake CrowdStrike updates target companies with malware, data wipers

https://www.bleepingcomputer.com/news/security/fake-crowdstrike-updates-target-companies-with-malware-data-wipers/
Fake CrowdStrike updates target companies with malware, data wipers

FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks - SentinelOne

https://www.sentinelone.com/labs/fin7-reboot-cybercrime-gang-enhances-ops-with-new-edr-bypasses-and-automated-attacks/
FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks - SentinelOne

Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android

https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/
Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android

Safety Equipment Giant Cadre Holdings Hit by Cyberattack - SecurityWeek

https://www.securityweek.com/safety-equipment-giant-cadre-holdings-hit-by-cyberattack/
Safety Equipment Giant Cadre Holdings Hit by Cyberattack - SecurityWeek

Two Members of LockBit Ransomware Group Plead Guilty in US Court - SecurityWeek

https://www.securityweek.com/two-members-of-lockbit-ransomware-group-plead-guilty-in-us-court/
Two Members of LockBit Ransomware Group Plead Guilty in US Court - SecurityWeek

2024 Blue Team Con Call for Volunteers

https://btcon.link/volunteers
2024 Blue Team Con Call for Volunteers

The Disclosure Dilemma and Ensuring Defense - YouTube

https://youtu.be/Cuhs4EJqxMw?si=YmHhEYzd8TEkw6X5
The Disclosure Dilemma and Ensuring Defense - YouTube

Experts Uncover Chinese Cybercrime Network Behind Gambling and Human Trafficking

https://thehackernews.com/2024/07/experts-uncover-chinese-cybercrime.html
Experts Uncover Chinese Cybercrime Network Behind Gambling and Human Trafficking

MalwareBazaar | 74-119-195-176

https://bazaar.abuse.ch/browse/tag/74-119-195-176/
MalwareBazaar | 74-119-195-176

New Linux Variant of Play Ransomware Targeting VMware ESXi Systems

https://thehackernews.com/2024/07/new-linux-variant-of-play-ransomware.html
New Linux Variant of Play Ransomware Targeting VMware ESXi Systems

Telegram zero-day allowed sending malicious Android APKs as videos

https://www.bleepingcomputer.com/news/security/telegram-zero-day-camouflaged-malicious-android-apks-as-videos/
Telegram zero-day allowed sending malicious Android APKs as videos

Heritage Foundation data breach containing personal data is available online | Malwarebytes

https://www.malwarebytes.com/blog/news/2024/07/heritage-foundation-data-breach-containing-personal-data-is-available-online
Heritage Foundation data breach containing personal data is available online | Malwarebytes