02/07

Critical RCE bug in Microsoft Outlook now exploited in attacks

https://www.bleepingcomputer.com/news/security/critical-rce-bug-in-microsoft-outlook-now-exploited-in-attacks/
Critical RCE bug in Microsoft Outlook now exploited in attacks

Perform a lsarlookupsids3 with a trust account, it uses netlogon as SSP (see [MS-NRPC] 3.3) (AES version) · GitHub

https://gist.github.com/ThePirateWhoSmellsOfSunflowers/cdf85b2c3b040f7c33b66d7001baf0ab
Perform a lsarlookupsids3 with a trust account, it uses netlogon as SSP (see [MS-NRPC] 3.3) (AES version) · GitHub

U.K. orders Apple to let it spy on users’ encrypted accounts - The Washington Post

https://www.washingtonpost.com/technology/2025/02/07/apple-encryption-backdoor-uk/
U.K. orders Apple to let it spy on users’ encrypted accounts - The Washington Post

Code injection attacks using publicly disclosed ASP.NET machine keys | Microsoft Security Blog

https://www.microsoft.com/en-us/security/blog/2025/02/06/code-injection-attacks-using-publicly-disclosed-asp-net-machine-keys/
Code injection attacks using publicly disclosed ASP.NET machine keys | Microsoft Security Blog

Shellcode Loaders! (Windows Malware Development) / X

https://x.com/i/broadcasts/1OdKrDEoaPnJX
Shellcode Loaders! (Windows Malware Development) / X

“Torrenting from a corporate laptop doesn’t feel right”: Meta emails unsealed - Ars Technica

https://arstechnica.com/tech-policy/2025/02/meta-torrented-over-81-7tb-of-pirated-books-to-train-ai-authors-say/
“Torrenting from a corporate laptop doesn’t feel right”: Meta emails unsealed - Ars Technica

DeepSeek App Transmits Sensitive User and Device Data Without Encryption

https://thehackernews.com/2025/02/deepseek-app-transmits-sensitive-user.html
DeepSeek App Transmits Sensitive User and Device Data Without Encryption

HPE notifies employees of data breach after Russian Office 365 hack

https://www.bleepingcomputer.com/news/security/hpe-notifies-employees-of-data-breach-after-russian-office-365-hack/
HPE notifies employees of data breach after Russian Office 365 hack

Researcher Outsmarts, Jailbreaks OpenAI's New o3-mini

https://www.darkreading.com/application-security/researcher-jailbreaks-openai-o3-mini
Researcher Outsmarts, Jailbreaks OpenAI's New o3-mini

Cloudflare outage caused by botched blocking of phishing URL

https://www.bleepingcomputer.com/news/security/cloudflare-outage-caused-by-botched-blocking-of-phishing-url/
Cloudflare outage caused by botched blocking of phishing URL

SF tech company worth $16B lays off staff after turning first profits

https://www.sfgate.com/tech/article/okta-layoffs-after-first-profits-20147418.php
SF tech company worth $16B lays off staff after turning first profits

ghidra/Ghidra/Configurations/Public_Release/src/global/docs/WhatsNew.md at Ghidra_11.3_build · NationalSecurityAgency/ghidra · GitHub

https://github.com/NationalSecurityAgency/ghidra/blob/Ghidra_11.3_build/Ghidra/Configurations/Public_Release/src/global/docs/WhatsNew.md#pyghidra
ghidra/Ghidra/Configurations/Public_Release/src/global/docs/WhatsNew.md at Ghidra_11.3_build · NationalSecurityAgency/ghidra · GitHub

Sign Up | LinkedIn

https://www.linkedin.com/in/arnauortega/
Sign Up | LinkedIn

India's RBI Introduces Exclusive "bank.in" Domain to Combat Digital Banking Fraud

https://thehackernews.com/2025/02/indias-rbi-introduces-exclusive-bankin.html
India's RBI Introduces Exclusive "bank.in" Domain to Combat Digital Banking Fraud