VXCON 2024 Workshop | Alisa Esage - Browser Exploitation Workshop - YouTube
https://www.youtube.com/live/b9OhamkAY2I
The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access | Volexity
https://www.volexity.com/blog/2024/11/22/the-nearest-neighbor-attack-how-a-russian-apt-weaponized-nearby-wi-fi-networks-for-covert-access/
Over 2,000 Palo Alto firewalls hacked using recently patched bugs
https://www.bleepingcomputer.com/news/security/over-2-000-palo-alto-firewalls-hacked-using-recently-patched-bugs/
EmbedPayloadInPng: Embed a payload inside a PNG file
https://meterpreter.org/embedpayloadinpng-embed-a-payload-inside-a-png-file/
Fortinet VPN design flaw hides successful brute-force attacks
https://www.bleepingcomputer.com/news/security/fortinet-vpn-design-flaw-hides-successful-brute-force-attacks/
Vulnerability Disclosure: Authentication Bypass in Vaultwarden versions < 1.32.5 - Insinuator.net
https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1-32-5/
US Takes Down Stolen Credit Card Marketplace PopeyeTools - SecurityWeek
https://www.securityweek.com/us-takes-down-stolen-credit-card-marketplace-popeyetools/
Obfuscating API Patches to Bypass New Windows Defender Behavior Signatures – Practical Security Analytics LLC
https://practicalsecurityanalytics.com/obfuscating-api-patches-to-bypass-new-windows-defender-behavior-signatures/
Thai Court Dismisses Activist’s Suit Against Israeli Spyware Producer Over Lack of Evidence - SecurityWeek
https://www.securityweek.com/thai-court-dismisses-activists-suit-against-israeli-spyware-producer-over-lack-of-evidence/
Leveraging An Order of Operations Bug to Achieve RCE in Sitecore 8.x - 10.x
https://www.assetnote.io/resources/research/leveraging-an-order-of-operations-bug-to-achieve-rce-in-sitecore-8-x---10-x
Haidar%20Kabibo,%20A%20journey%20into%20forgotten%20Null%20Session%20and%20MS-RPC%20interfaces.pdf
https://powerofcommunity.net/poc2024/Haidar%20Kabibo,%20A%20journey%20into%20forgotten%20Null%20Session%20and%20MS-RPC%20interfaces.pdf
[BSL2024] [KEYNOTE] AI WILL TAKE UR JOB! - Pedro Ribeiro - YouTube
https://youtu.be/0zAs7wjUhio
https://hire.jobvite.com/j?cj=ogZeZfwc&s=Campus_Event
https://hire.jobvite.com/j?cj=ogZeZfwc&s=Campus_Event
PrivEsc: Abusing the Service Control Manager for Stealthy & Persistent LPE - 0xv1n
https://0xv1n.github.io/posts/scmanager/
PyPI Attack: ChatGPT, Claude Impersonators Deliver JarkaStealer via Python Libraries
https://thehackernews.com/2024/11/pypi-attack-chatgpt-claude.html
MalwareBazaar | HellDown
https://bazaar.abuse.ch/browse/tag/HellDown/
Hackers breach US firm over Wi-Fi from Russia in 'Nearest Neighbor Attack'
https://www.bleepingcomputer.com/news/security/hackers-breach-us-firm-over-wi-fi-from-russia-in-nearest-neighbor-attack/