ETW Forensics - Why use Event Tracing for Windows over EventLog? - - JPCERT/CC Eyes | JPCERT Coordination Center official Blog
https://blogs.jpcert.or.jp/en/2024/11/etw_forensics.html
Firefox Animation CVE-2024-9680 – Dimitri Fourny
https://dimitrifourny.github.io/2024/11/14/firefox-animation-cve-2024-9680.html
Hackers use macOS extended file attributes to hide malicious code
https://www.bleepingcomputer.com/news/security/hackers-use-macos-extended-file-attributes-to-hide-malicious-code/
POC2025 - We Trust a Power Of Community
https://powerofcommunity.net/2024.htm
Stealthy Attributes of APT Lazarus | Group-IB Blog
https://www.group-ib.com/blog/stealthy-attributes-of-apt-lazarus/
Update · community-scripts/ProxmoxVE · Discussion #237 · GitHub
https://github.com/community-scripts/ProxmoxVE/discussions/237
Experts Uncover 70,000 Hijacked Domains in Widespread 'Sitting Ducks' Attack Scheme
https://thehackernews.com/2024/11/experts-uncover-70000-hijacked-domains.html
US govt officials’ communications compromised in recent telecom hack
https://www.bleepingcomputer.com/news/security/chinese-hackers-compromised-us-government-officials-private-communications-in-recent-telecom-breach/
Piloting Edge Copilot - Speaker Deck
https://speakerdeck.com/shhnjk/piloting-edge-copilot
Hacker gets 10 years in prison for extorting US healthcare provider
https://www.bleepingcomputer.com/news/legal/hacker-gets-10-years-in-prison-for-extorting-us-healthcare-provider/
BeaconGate, Sleepmask... customizing Cobalt Strike after 4.10 | RWXStoned
https://rwxstoned.github.io/2024-11-13-Cobalt-Strike-customization/
nytimes.com
https://www.nytimes.com/2024/11/14/business/media/alex-jones-infowars-the-onion.html
BSides Nashville 2025 - A BSides Mid-TN Production: Call for Papers @ Sessionize.com
https://sessionize.com/bsides-nashville-2025-cfp/
Microsoft patches Windows zero-day exploited in attacks on Ukraine
https://www.bleepingcomputer.com/news/security/microsoft-patches-windows-zero-day-exploited-in-attacks-on-ukraine/
CISA, FBI Confirm China Hacked Telecoms Providers for Spying - SecurityWeek
https://www.securityweek.com/cisa-fbi-confirm-china-hacked-telecoms-providers-for-spying/
Pregnancy Tracking App ‘What to Expect’ Refuses to Fix Issue that Allows Full Account Takeover
https://www.404media.co/pregnancy-tracking-app-what-to-expect-refuses-to-fix-issue-that-allows-full-account-takeover-2/
Microsoft Power Pages Leak Millions of Private Records
https://www.darkreading.com/cybersecurity-operations/microsoft-power-pages-millions-private-records
APT-C-55(Kimsuky)组织利用GitHub作为载荷平台的攻击活动分析
https://mp.weixin.qq.com/s/GzMoR8jKjelzuj5BPhpJYA
NIST Explains Why It Failed to Clear CVE Backlog - SecurityWeek
https://www.securityweek.com/nist-explains-why-it-failed-to-clear-cve-backlog/
New Glove infostealer malware bypasses Chrome’s cookie encryption
https://www.bleepingcomputer.com/news/security/new-glove-stealer-malware-bypasses-chromes-cookie-encryption/
APT_REPORT/Exploit/Zero-day-cve-2024-4351-report.pdf at master · blackorbird/APT_REPORT · GitHub
https://github.com/blackorbird/APT_REPORT/blob/master/Exploit/Zero-day-cve-2024-4351-report.pdf
Two Men Charged For Hacking US Tax Preparation Firms - SecurityWeek
https://www.securityweek.com/two-men-charged-for-hacking-us-tax-preparation-firms/
Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails
https://thehackernews.com/2024/11/russian-hackers-exploit-new-ntlm-flaw.html
Crimeware and financial predictions for 2025 | Securelist
https://securelist.com/ksb-financial-and-crimeware-predictions-2025/114565/
Google Warns of Rising Cloaking Scams, AI-Driven Fraud, and Crypto Schemes
https://thehackernews.com/2024/11/google-warns-of-rising-cloaking-scams.html
GitHub - watchtowrlabs/Citrix-Virtual-Apps-XEN-Exploit: Citrix Virtual Apps and Desktops (XEN) Unauthenticated RCE
https://github.com/watchtowrlabs/Citrix-Virtual-Apps-XEN-Exploit
LOLRMM - Atera
https://lolrmm.io/tools/atera
Leaked info of 122 million linked to B2B data aggregator breach
https://www.bleepingcomputer.com/news/security/leaked-info-of-122-million-linked-to-b2b-data-aggregator-breach/