04/17

GitHub - edwardzpeng/presentations

https://github.com/edwardzpeng/presentations
GitHub - edwardzpeng/presentations

Over 16,000 Fortinet devices compromised with symlink backdoor

https://www.bleepingcomputer.com/news/security/over-16-000-fortinet-devices-compromised-with-symlink-backdoor/
Over 16,000 Fortinet devices compromised with symlink backdoor

GitHub - harishsg993010/damn-vulnerable-MCP-server: Damn Vulnerable MCP Server

https://github.com/harishsg993010/damn-vulnerable-MCP-server
GitHub - harishsg993010/damn-vulnerable-MCP-server: Damn Vulnerable MCP Server

Control Flow Hijacking via Data Pointers | Legacyy

https://www.legacyy.xyz/defenseevasion/windows/2025/04/16/control-flow-hijacking-via-data-pointers.html
Control Flow Hijacking via Data Pointers | Legacyy

Windows NTLM hash leak flaw exploited in phishing attacks on governments

https://www.bleepingcomputer.com/news/security/windows-ntlm-hash-leak-flaw-exploited-in-phishing-attacks-on-governments/
Windows NTLM hash leak flaw exploited in phishing attacks on governments

Microsoft: Office 2016 and Office 2019 reach end of support in October

https://www.bleepingcomputer.com/news/microsoft/microsoft-office-2016-and-office-2019-reach-end-of-support-in-october/
Microsoft: Office 2016 and Office 2019 reach end of support in October

Ahold Delhaize confirms data theft after INC ransomware claims attack

https://www.bleepingcomputer.com/news/security/ahold-delhaize-confirms-data-theft-after-inc-ransomware-claims-attack/
Ahold Delhaize confirms data theft after INC ransomware claims attack

Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted Attacks

https://thehackernews.com/2025/04/apple-patches-two-actively-exploited.html
Apple Patches Two Actively Exploited iOS Flaws Used in Sophisticated Targeted Attacks

Call for Papers • BSidesNYC

https://bsidesnyc.org/cfp/
Call for Papers • BSidesNYC

Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware

https://unit42.paloaltonetworks.com/slow-pisces-new-custom-malware/
Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware

MITRE Hackers' Backdoor Has Targeted Windows for Years - SecurityWeek

https://www.securityweek.com/mitre-hackers-backdoor-has-targeted-windows-for-years/
MITRE Hackers' Backdoor Has Targeted Windows for Years - SecurityWeek

New Windows Server emergency updates fix container launch issue

https://www.bleepingcomputer.com/news/microsoft/new-windows-server-emergency-updates-fix-container-launch-issue/
New Windows Server emergency updates fix container launch issue

Chrome extensions with 6 million installs have hidden tracking code

https://www.bleepingcomputer.com/news/security/chrome-extensions-with-6-million-installs-have-hidden-tracking-code/
Chrome extensions with 6 million installs have hidden tracking code

Hooking Context Swaps with ETW | Archie’s reversing diary

https://archie-osu.github.io/etw/hooking/2025/04/09/hooking-context-swaps-with-etw.html
Hooking Context Swaps with ETW | Archie’s reversing diary

CISA warns of increased breach risks following Oracle Cloud leak

https://www.bleepingcomputer.com/news/security/cisa-warns-of-increased-breach-risks-following-oracle-cloud-leak/
CISA warns of increased breach risks following Oracle Cloud leak

State-Sponsored Hackers Weaponize ClickFix Tactic in Targeted Malware Campaigns

https://thehackernews.com/2025/04/state-sponsored-hackers-weaponize.html
State-Sponsored Hackers Weaponize ClickFix Tactic in Targeted Malware Campaigns

soc_chef | Security Operations Chef

https://mr-r3b00t.github.io/soc_chef/
soc_chef | Security Operations Chef

Mustang Panda Targets Myanmar With StarProxy, EDR Bypass, and TONESHELL Updates

https://thehackernews.com/2025/04/mustang-panda-targets-myanmar-with.html
Mustang Panda Targets Myanmar With StarProxy, EDR Bypass, and TONESHELL Updates

Krebs Exits SentinelOne After Security Clearance Pulled - SecurityWeek

https://www.securityweek.com/krebs-exits-sentinelone-after-security-clearance-pulled/
Krebs Exits SentinelOne After Security Clearance Pulled - SecurityWeek

New Windows Task Scheduler Bugs Let Attackers Bypass UAC and Tamper with Logs

https://thehackernews.com/2025/04/experts-uncover-four-new-privilege.html
New Windows Task Scheduler Bugs Let Attackers Bypass UAC and Tamper with Logs

Release Autopsy 4.22.1 · sleuthkit/autopsy · GitHub

https://github.com/sleuthkit/autopsy/releases/tag/autopsy-4.22.1
Release Autopsy 4.22.1 · sleuthkit/autopsy · GitHub

PowerShell for Hackers: Exploitation Essentials | hetmehta.com

https://hetmehta.com/posts/powershell-for-hackers/
PowerShell for Hackers: Exploitation Essentials | hetmehta.com

Mustang Panda: ToneShell and StarProxy | ThreatLabz

https://www.zscaler.com/blogs/security-research/latest-mustang-panda-arsenal-toneshell-and-starproxy-p1
Mustang Panda: ToneShell and StarProxy | ThreatLabz