09/26

Attacking UNIX Systems via CUPS, Part I

https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/
Attacking UNIX Systems via CUPS, Part I

Red Teaming in the age of EDR: Evasion of Endpoint Detection Through Malware Virtualisation – Fox-IT International blog

https://blog.fox-it.com/2024/09/25/red-teaming-in-the-age-of-edr-evasion-of-endpoint-detection-through-malware-virtualisation/
Red Teaming in the age of EDR: Evasion of Endpoint Detection Through Malware Virtualisation – Fox-IT International blog

Shodan Search Engine

https://www.shodan.io/search/report?query=product%3Acups
Shodan Search Engine

Fake WalletConnect app on Google Play steals Android users’ crypto

https://www.bleepingcomputer.com/news/security/fake-walletconnect-app-on-google-play-steals-android-users-crypto/
Fake WalletConnect app on Google Play steals Android users’ crypto

Automattic blocks WP Engine’s access to WordPress resources

https://www.bleepingcomputer.com/news/security/automattic-blocks-wp-engines-access-to-wordpress-resources/
Automattic blocks WP Engine’s access to WordPress resources

Critical Nvidia Container Flaw Exposes Cloud AI Systems to Host Takeover - SecurityWeek

https://www.securityweek.com/critical-nvidia-container-flaw-exposes-cloud-ai-systems-to-host-takeover/
Critical Nvidia Container Flaw Exposes Cloud AI Systems to Host Takeover - SecurityWeek

A step-by-step guide to writing an iOS kernel exploit | Alfie CG

https://alfiecg.uk/2024/09/24/Kernel-exploit.html
A step-by-step guide to writing an iOS kernel exploit | Alfie CG

Eric Adams Told FBI He Forgot His Phone’s Passcode

https://www.404media.co/eric-adams-told-fbi-he-forgot-his-phones-passcode/
Eric Adams Told FBI He Forgot His Phone’s Passcode

Thread by @evilsocket on Thread Reader App – Thread Reader App

https://threadreaderapp.com/thread/1838169889330135132.html
Thread by @evilsocket on Thread Reader App – Thread Reader App

Watering Hole Attack on Kurdish Sites Distributing Malicious APKs and Spyware

https://thehackernews.com/2024/09/watering-hole-attack-on-kurdish-sites.html
Watering Hole Attack on Kurdish Sites Distributing Malicious APKs and Spyware

Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023

https://www.welivesecurity.com/en/eset-research/cyberespionage-gamaredon-way-analysis-toolset-used-spy-ukraine-2022-2023/
Cyberespionage the Gamaredon way: Analysis of toolset used to spy on Ukraine in 2022 and 2023

U.S. Indicts 2 Top Russian Hackers, Sanctions Cryptex – Krebs on Security

https://krebsonsecurity.com/2024/09/u-s-indicts-2-top-russian-hackers-sanctions-cryptex/
U.S. Indicts 2 Top Russian Hackers, Sanctions Cryptex – Krebs on Security

Kia dealer portal flaw could let attackers hack millions of cars

https://www.bleepingcomputer.com/news/security/kia-dealer-portal-flaw-could-let-attackers-hack-millions-of-cars/
Kia dealer portal flaw could let attackers hack millions of cars

Pwn2Own Stories - Ben McBride - YouTube

https://www.youtube.com/watch?v=j6jhzFgz_Xo
Pwn2Own Stories - Ben McBride - YouTube

Google Sees Drop in Memory Safety Bugs in Android as Code Matures - SecurityWeek

https://www.securityweek.com/google-sees-drop-in-memory-safety-bugs-in-android-as-code-matures/
Google Sees Drop in Memory Safety Bugs in Android as Code Matures - SecurityWeek

Tails OS merges with Tor Project for better privacy, security

https://www.bleepingcomputer.com/news/software/tails-os-merges-with-tor-project-for-better-privacy-security/
Tails OS merges with Tor Project for better privacy, security

CUPS flaws enable Linux remote code execution, but there’s a catch

https://www.bleepingcomputer.com/news/security/cups-flaws-enable-linux-remote-code-execution-but-theres-a-catch/
CUPS flaws enable Linux remote code execution, but there’s a catch

Meta halts routing via Deutsche Telekom over €20M peering fee

https://www.bleepingcomputer.com/news/technology/meta-halts-routing-via-deutsche-telekom-over-20m-peering-fee/
Meta halts routing via Deutsche Telekom over €20M peering fee

Chinese Hackers Infiltrate U.S. Internet Providers in Cyber Espionage Campaign

https://thehackernews.com/2024/09/chinese-hackers-infiltrate-us-internet.html
Chinese Hackers Infiltrate U.S. Internet Providers in Cyber Espionage Campaign

GitHub - WinampDesktop/winamp: Iconic media player

https://github.com/WinampDesktop/winamp
GitHub - WinampDesktop/winamp: Iconic media player

Hackers Could Have Remotely Controlled Kia Cars Using Only License Plates

https://thehackernews.com/2024/09/hackers-could-have-remotely-controlled.html
Hackers Could Have Remotely Controlled Kia Cars Using Only License Plates

US sanctions crypto exchanges used by Russian ransomware gangs

https://www.bleepingcomputer.com/news/security/us-sanctions-crypto-exchanges-used-by-russian-ransomware-gangs/
US sanctions crypto exchanges used by Russian ransomware gangs

Data of 3,191 congressional staffers leaked in the dark web

https://securityaffairs.com/168912/deep-web/3000-congressional-staffers-data-leaked-dark-web.html
Data of 3,191 congressional staffers leaked in the dark web

Shielder - Hunting for <del>Un</del>authenticated n-days in Asus Routers

https://shielder.com/blog/2024/01/hunting-for-~~un~~authenticated-n-days-in-asus-routers/
Shielder - Hunting for <del>Un</del>authenticated n-days in Asus Routers

Cloudflare Warns of India-Linked Hackers Targeting South and East Asian Entities

https://thehackernews.com/2024/09/cloudflare-warns-of-india-linked.html
Cloudflare Warns of India-Linked Hackers Targeting South and East Asian Entities

The Cloudflare Blog

https://blog.cloudflare.com/unraveling-sloppylemming-operations/
The Cloudflare Blog

China-linked APT group Salt Typhoon compromised some US ISPs

https://securityaffairs.com/168941/apt/salt-typhoon-china-linked-threat-actors-breached-us-isp.html
China-linked APT group Salt Typhoon compromised some US ISPs

N. Korean Hackers Deploy New KLogEXE and FPSpy Malware in Targeted Attacks

https://thehackernews.com/2024/09/n-korean-hackers-deploy-new-klogexe-and.html
N. Korean Hackers Deploy New KLogEXE and FPSpy Malware in Targeted Attacks

RansomHub’s EDR-Killer: How Zerologon and EDRKillShifter Exploit Networks Without Detection

https://securityonline.info/ransomhubs-edr-killer-how-zerologon-and-edrkillshifter-exploit-networks-without-detection/
RansomHub’s EDR-Killer: How Zerologon and EDRKillShifter Exploit Networks Without Detection