07/23

How a North Korean Fake IT Worker Tried to Infiltrate Us

https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us
How a North Korean Fake IT Worker Tried to Infiltrate Us

Fake CrowdStrike repair manual pushes new infostealer malware

https://www.bleepingcomputer.com/news/security/fake-crowdstrike-repair-manual-pushes-new-daolpu-infostealer-malware/
Fake CrowdStrike repair manual pushes new infostealer malware

Exploring malicious Windows drivers (Part 1): Introduction to the kernel and drivers

https://blog.talosintelligence.com/exploring-malicious-windows-drivers-part-1-introduction-to-the-kernel-and-drivers/
Exploring malicious Windows drivers (Part 1): Introduction to the kernel and drivers

Exploring malicious Windows drivers (Part 2): the I/O system, IRPs, stack locations, IOCTLs and more

https://blog.talosintelligence.com/exploring-malicious-windows-drivers-part-2/
Exploring malicious Windows drivers (Part 2): the I/O system, IRPs, stack locations, IOCTLs and more

Syllabus

https://maldevacademy.com/syllabus
Syllabus

Daggerfly: Espionage Group Makes Major Update to Toolset | Symantec Enterprise Blogs

https://symantec-enterprise-blogs.security.com/threat-intelligence/daggerfly-espionage-updated-toolset
Daggerfly: Espionage Group Makes Major Update to Toolset | Symantec Enterprise Blogs

Ukrainian Institutions Targeted Using HATVIBE and CHERRYSPY Malware

https://thehackernews.com/2024/07/ukrainian-institutions-targeted-using.html
Ukrainian Institutions Targeted Using HATVIBE and CHERRYSPY Malware

How a North Korean Fake IT Worker Tried to Infiltrate Us

https://blog-knowbe4-com.cdn.ampproject.org/c/s/blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us?hs_amp=true
How a North Korean Fake IT Worker Tried to Infiltrate Us

Verizon to pay $16 million in TracFone data breach settlement

https://www.bleepingcomputer.com/news/security/verizon-to-pay-16-million-in-tracfone-data-breach-settlement/
Verizon to pay $16 million in TracFone data breach settlement

An SQL injection issue related to the orderBy clause. · Advisory · 1Panel-dev/1Panel · GitHub

https://github.com/1Panel-dev/1Panel/security/advisories/GHSA-5grx-v727-qmq6
An SQL injection issue related to the orderBy clause. · Advisory · 1Panel-dev/1Panel · GitHub

Hackers abused swap files in e-skimming attacks on Magento sites

https://securityaffairs.com/166073/malware/threat-actors-abused-swap-files-e-skimming.html
Hackers abused swap files in e-skimming attacks on Magento sites

BreachForums v1 hacking forum data leak exposes members’ info

https://www.bleepingcomputer.com/news/security/breachforums-v1-hacking-forum-data-leak-exposes-members-info/
BreachForums v1 hacking forum data leak exposes members’ info

Google Will Keep Third-Party Cookies in Chrome - SecurityWeek

https://www.securityweek.com/google-will-keep-third-party-cookies-in-chrome/
Google Will Keep Third-Party Cookies in Chrome - SecurityWeek

Solving the 7777 Botnet enigma: A cybersecurity quest - Sekoia.io Blog

https://blog.sekoia.io/solving-the-7777-botnet-enigma-a-cybersecurity-quest/
Solving the 7777 Botnet enigma: A cybersecurity quest - Sekoia.io Blog

New ICS Malware 'FrostyGoop' Targeting Critical Infrastructure

https://thehackernews.com/2024/07/new-ics-malware-frostygoop-targeting.html
New ICS Malware 'FrostyGoop' Targeting Critical Infrastructure

Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android

https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/
Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android

Telegram Zero-Day Enabled Malware Delivery - SecurityWeek

https://www.securityweek.com/telegram-zero-day-enabled-malware-delivery/
Telegram Zero-Day Enabled Malware Delivery - SecurityWeek

Greece’s Land Registry agency breached in wave of 400 cyberattacks

https://www.bleepingcomputer.com/news/security/greeces-land-registry-agency-breached-in-wave-of-400-cyberattacks/
Greece’s Land Registry agency breached in wave of 400 cyberattacks

Magento Sites Targeted with Sneaky Credit Card Skimmer via Swap Files

https://thehackernews.com/2024/07/magento-sites-targeted-with-sneaky.html
Magento Sites Targeted with Sneaky Credit Card Skimmer via Swap Files

Meta Given Deadline to Address E.U. Concerns Over 'Pay or Consent' Model

https://thehackernews.com/2024/07/meta-given-deadline-to-address-eu.html
Meta Given Deadline to Address E.U. Concerns Over 'Pay or Consent' Model

What I learned from the ‘Microsoft global IT outage’ | by Kevin Beaumont | Jul, 2024 | DoublePulsar

https://doublepulsar.com/what-i-learned-from-the-microsoft-global-it-outage-d6138c06ebdb
What I learned from the ‘Microsoft global IT outage’ | by Kevin Beaumont | Jul, 2024 | DoublePulsar

FrostyGoop ICS Malware Left Ukrainian City's Residents Without Heating - SecurityWeek

https://www.securityweek.com/frostygoop-ics-malware-left-ukrainian-citys-residents-without-heating/
FrostyGoop ICS Malware Left Ukrainian City's Residents Without Heating - SecurityWeek

FrostyGoop malware attack cut off heat in Ukraine during winter

https://www.bleepingcomputer.com/news/security/frostygoop-malware-attack-cut-off-heat-in-ukraine-during-winter/
FrostyGoop malware attack cut off heat in Ukraine during winter

Chinese Hackers Target Taiwan and US NGO with MgBot Malware

https://thehackernews.com/2024/07/chinese-hackers-target-taiwan-and-us.html
Chinese Hackers Target Taiwan and US NGO with MgBot Malware