07/01

LOLBAS

http://LOLBAS-Project.github.io
LOLBAS

International Criminal Court hit by new 'sophisticated' cyberattack

https://www.bleepingcomputer.com/news/security/international-criminal-court-hit-by-new-sophisticated-cyberattack/
International Criminal Court hit by new 'sophisticated' cyberattack

Iran-linked hackers threaten to release Trump aides' emails | Reuters

https://www.reuters.com/legal/government/iran-linked-hackers-threaten-release-trump-aides-emails-2025-06-30/
Iran-linked hackers threaten to release Trump aides' emails | Reuters

New FileFix attack runs JScript while bypassing Windows MoTW alerts

https://www.bleepingcomputer.com/news/security/new-filefix-attack-runs-jscript-while-bypassing-windows-motw-alerts/
New FileFix attack runs JScript while bypassing Windows MoTW alerts

New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status

https://thehackernews.com/2025/07/new-flaw-in-ides-like-visual-studio.html
New Flaw in IDEs Like Visual Studio Code Lets Malicious Extensions Bypass Verified Status

MalwareBazaar | NetSupport

https://bazaar.abuse.ch/browse/tag/NetSupport/
MalwareBazaar | NetSupport

C2 - Pastebin.com

https://pastebin.com/YAXPGu2F
C2 - Pastebin.com

Microsoft Removes Password Management from Authenticator App Starting August 2025

https://thehackernews.com/2025/07/microsoft-removes-password-management.html
Microsoft Removes Password Management from Authenticator App Starting August 2025

AT&T rolls out "Wireless Lock" feature to block SIM swap attacks

https://www.bleepingcomputer.com/news/security/atandt-rolls-out-wireless-lock-feature-to-block-sim-swap-attacks/
AT&T rolls out "Wireless Lock" feature to block SIM swap attacks

PoC/CVE-2025-6554/poc.js at main · DarkNavySecurity/PoC · GitHub

https://github.com/DarkNavySecurity/PoC/blob/main/CVE-2025-6554/poc.js
PoC/CVE-2025-6554/poc.js at main · DarkNavySecurity/PoC · GitHub

Johnson Controls starts notifying people affected by 2023 breach

https://www.bleepingcomputer.com/news/security/johnson-controls-starts-notifying-people-affected-by-2023-breach/
Johnson Controls starts notifying people affected by 2023 breach

Kelly Benefits says 2024 data breach impacts 550,000 customers

https://www.bleepingcomputer.com/news/security/kelly-benefits-says-2024-data-breach-impacts-550-000-customers/
Kelly Benefits says 2024 data breach impacts 550,000 customers

Jasper Sleet: North Korean remote IT workers’ evolving tactics to infiltrate organizations | Microsoft Security Blog

https://www.microsoft.com/en-us/security/blog/2025/06/30/jasper-sleet-north-korean-remote-it-workers-evolving-tactics-to-infiltrate-organizations/
Jasper Sleet: North Korean remote IT workers’ evolving tactics to infiltrate organizations | Microsoft Security Blog

Microsoft open-sources VS Code Copilot Chat extension on GitHub

https://www.bleepingcomputer.com/news/security/microsoft-open-sources-vs-code-copilot-chat-extension-on-github/
Microsoft open-sources VS Code Copilot Chat extension on GitHub

Esse Health says recent data breach affects over 263,000 patients

https://www.bleepingcomputer.com/news/security/esse-health-says-recent-data-breach-affects-over-263-000-patients/
Esse Health says recent data breach affects over 263,000 patients

TA829 and UNK_GreenSec Share Tactics and Infrastructure in Ongoing Malware Campaigns

https://thehackernews.com/2025/07/ta829-and-unkgreensec-share-tactics-and.html
TA829 and UNK_GreenSec Share Tactics and Infrastructure in Ongoing Malware Campaigns

How we got persistent XSS on every AEM cloud site, thrice › Searchlight Cyber

https://slcyber.io/assetnote-security-research-center/how-we-got-persistent-xss-on-every-aem-cloud-site-thrice/
How we got persistent XSS on every AEM cloud site, thrice › Searchlight Cyber

Analysis of the threat case of kimsuky group using 'ClickFix' tactic

https://www.genians.co.kr/en/blog/threat_intelligence/suky-castle
Analysis of the threat case of kimsuky group using 'ClickFix' tactic

Cloudflare Puts a Default Block on AI Web Scraping - SecurityWeek

https://www.securityweek.com/cloudflare-puts-a-default-block-on-ai-web-scraping/
Cloudflare Puts a Default Block on AI Web Scraping - SecurityWeek

Profile / X

https://x.com/SuperQQ_Jean
Profile / X

U.S. Arrests Facilitator in North Korean IT Worker Scheme; Seizes 29 Domains and Raids 21 Laptop Farms

https://thehackernews.com/2025/07/us-arrests-key-facilitator-in-north.html
U.S. Arrests Facilitator in North Korean IT Worker Scheme; Seizes 29 Domains and Raids 21 Laptop Farms

Chrome Releases: Stable Channel Update for Desktop

https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.html
Chrome Releases: Stable Channel Update for Desktop

Chrome Zero-Day CVE-2025-6554 Under Active Attack — Google Issues Security Update

https://thehackernews.com/2025/07/google-patches-critical-zero-day-flaw.html
Chrome Zero-Day CVE-2025-6554 Under Active Attack — Google Issues Security Update

US disrupts North Korean IT worker "laptop farm" scheme in 16 states

https://www.bleepingcomputer.com/news/security/us-disrupts-north-korean-it-worker-laptop-farm-scheme-in-16-states/
US disrupts North Korean IT worker "laptop farm" scheme in 16 states

Hypervisors for Memory Introspection and Reverse Engineering | secret club

https://secret.club/2025/06/02/hypervisors-for-memory-introspection-and-reverse-engineering.html
Hypervisors for Memory Introspection and Reverse Engineering | secret club

Aeza Group sanctioned for hosting ransomware, infostealer servers

https://www.bleepingcomputer.com/news/security/aeza-group-sanctioned-for-hosting-ransomware-infostealer-servers/
Aeza Group sanctioned for hosting ransomware, infostealer servers

Google fixes fourth actively exploited Chrome zero-day of 2025

https://www.bleepingcomputer.com/news/security/google-fixes-fourth-actively-exploited-chrome-zero-day-of-2025/
Google fixes fourth actively exploited Chrome zero-day of 2025