09/09

Offensive AI Researcher, X-Force Adversary Services - US | IBM

https://careers.ibm.com/job/20939619/offensive-ai-researcher-x-force-adversary-services-remote/?codes=WEB_SEARCH_NA
Offensive AI Researcher, X-Force Adversary Services - US | IBM

Chinese APT Abuses VSCode to Target Government in Asia

https://unit42.paloaltonetworks.com/stately-taurus-abuses-vscode-southeast-asian-espionage/
Chinese APT Abuses VSCode to Target Government in Asia

The Art of Exploiting Active Directory from Linux | Zavier

https://gatari.dev/posts/the-art-of-exploiting-ad-from-linux/
The Art of Exploiting Active Directory from Linux | Zavier

Payment gateway data breach affects 1.7 million credit card owners

https://www.bleepingcomputer.com/news/security/payment-gateway-data-breach-affects-17-million-credit-card-owners/
Payment gateway data breach affects 1.7 million credit card owners

Chinese Hackers Exploit Visual Studio Code in Southeast Asian Cyberattacks

https://thehackernews.com/2024/09/chinese-hackers-exploit-visual-studio.html
Chinese Hackers Exploit Visual Studio Code in Southeast Asian Cyberattacks

One Million US Kaspersky Customers Transferred to Pango's UltraAV - SecurityWeek

https://www.securityweek.com/one-million-us-kaspersky-customers-transferred-to-pangos-ultraav/
One Million US Kaspersky Customers Transferred to Pango's UltraAV - SecurityWeek

Meta fixes easily bypassed WhatsApp ‘View Once’ privacy feature

https://www.bleepingcomputer.com/news/security/meta-fixes-easily-bypassed-whatsapp-view-once-privacy-feature/
Meta fixes easily bypassed WhatsApp ‘View Once’ privacy feature

Progress Software fixed a maximum severity flaw in LoadMaster

https://securityaffairs.com/168192/uncategorized/progress-software-emergency-loadmaster-flaw.html
Progress Software fixed a maximum severity flaw in LoadMaster

Predator Spyware Resurfaces With Fresh Infrastructure - SecurityWeek

https://www.securityweek.com/predator-spyware-resurfaces-with-fresh-infrastructure/
Predator Spyware Resurfaces With Fresh Infrastructure - SecurityWeek

TIDRONE APT targets drone manufacturers in Taiwan

https://securityaffairs.com/168210/apt/tidrone-targets-organizations-taiwan.html
TIDRONE APT targets drone manufacturers in Taiwan

GitHub - dadevel/impacket-zsh-integration: ZSH integration for Impacket

https://github.com/dadevel/impacket-zsh-integration
GitHub - dadevel/impacket-zsh-integration: ZSH integration for Impacket

U.S. Offers $10 Million for Info on Russian Cadet Blizzard Hackers Behind Major Attacks

https://thehackernews.com/2024/09/us-offers-10-million-for-info-on.html
U.S. Offers $10 Million for Info on Russian Cadet Blizzard Hackers Behind Major Attacks

The (Anti-)EDR Compendium

https://blog.deeb.ch/posts/how-edr-works/
The (Anti-)EDR Compendium

Veeam Backup & Response - RCE With Auth, But Mostly Without Auth (CVE-2024-40711)

https://labs.watchtowr.com/veeam-backup-response-rce-with-auth-but-mostly-without-auth-cve-2024-40711-2/
Veeam Backup & Response - RCE With Auth, But Mostly Without Auth (CVE-2024-40711)

New Android SpyAgent Malware Uses OCR to Steal Crypto Wallet Recovery Keys

https://thehackernews.com/2024/09/new-android-spyagent-malware-uses-ocr.html
New Android SpyAgent Malware Uses OCR to Steal Crypto Wallet Recovery Keys

Remote Desktop Application vs MSTSC Forensics: RDP Artifacts You Might Be Missing | ZeroFox

https://www.zerofox.com/blog/remote-desktop-application-vs-mstsc-forensics-the-rdp-artifacts-you-might-be-missing/
Remote Desktop Application vs MSTSC Forensics: RDP Artifacts You Might Be Missing | ZeroFox

Arlo: I'm watching you

https://synacktiv.com/en/publications/arlo-im-watching-you
Arlo: I'm watching you

Two Indicted in US for Running Dark Web Marketplaces Offering Stolen Information - SecurityWeek

https://www.securityweek.com/two-indicted-in-us-for-running-dark-web-marketplaces-offering-stolen-information/
Two Indicted in US for Running Dark Web Marketplaces Offering Stolen Information - SecurityWeek

A half-hour to learn Rust

https://fasterthanli.me/articles/a-half-hour-to-learn-rust
A half-hour to learn Rust

Critical SonicWall Vulnerability Possibly Exploited in Ransomware Attacks - SecurityWeek

https://www.securityweek.com/critical-sonicwall-vulnerability-possibly-exploited-in-ransomware-attacks/
Critical SonicWall Vulnerability Possibly Exploited in Ransomware Attacks - SecurityWeek

MalwareBazaar | SHA256 915bc4d4e2670ce3cdb8833379578b2e6ade1446e5935d21d12ff25d9b496165

https://bazaar.abuse.ch/sample/915bc4d4e2670ce3cdb8833379578b2e6ade1446e5935d21d12ff25d9b496165/
MalwareBazaar | SHA256 915bc4d4e2670ce3cdb8833379578b2e6ade1446e5935d21d12ff25d9b496165

MalwareBazaar | COVERTCATCH

https://bazaar.abuse.ch/browse/tag/COVERTCATCH/
MalwareBazaar | COVERTCATCH

Windows DWM Core Library Elevation of Privilege Vulnerability (CVE-2024-30051)

https://www.coresecurity.com/core-labs/articles/windows-dwm-core-library-elevation-privilege-vulnerability-cve-2024-30051
Windows DWM Core Library Elevation of Privilege Vulnerability (CVE-2024-30051)

New RAMBO Attack Uses RAM Radio Signals to Steal Data from Air-Gapped Networks

https://thehackernews.com/2024/09/new-rambo-attack-uses-ram-radio-signals.html
New RAMBO Attack Uses RAM Radio Signals to Steal Data from Air-Gapped Networks

New RAMBO Attack Allows Air-Gapped Data Theft via RAM Radio Signals - SecurityWeek

https://www.securityweek.com/new-rambo-attack-allows-air-gapped-data-theft-via-ram-radio-signals/
New RAMBO Attack Allows Air-Gapped Data Theft via RAM Radio Signals - SecurityWeek