08/06

ReVault flaws let hackers bypass Windows login on Dell laptops

https://www.bleepingcomputer.com/news/security/revault-flaws-let-hackers-bypass-windows-login-on-dell-laptops/
ReVault flaws let hackers bypass Windows login on Dell laptops

HTTP/1.1 Must Die

https://http1mustdie.com/
HTTP/1.1 Must Die

Hacker extradited to US for stealing $3.3 million from taxpayers

https://www.bleepingcomputer.com/news/security/hacker-extradited-to-us-for-stealing-33-million-from-taxpayers/
Hacker extradited to US for stealing $3.3 million from taxpayers

The Guest Who Could: Exploiting LPE in VMWare Tools – PT SWARM

https://swarm.ptsecurity.com/the-guest-who-could-exploiting-lpe-in-vmware-tools/
The Guest Who Could: Exploiting LPE in VMWare Tools – PT SWARM

New Ghost Calls tactic abuses Zoom and Microsoft Teams for C2 operations

https://www.bleepingcomputer.com/news/security/new-ghost-calls-tactic-abuses-zoom-and-microsoft-teams-for-c2-operations/
New Ghost Calls tactic abuses Zoom and Microsoft Teams for C2 operations

APT_REPORT/summary/2025/CrowdStrike 2025 Threat Hunting Report.pdf at master · blackorbird/APT_REPORT · GitHub

https://github.com/blackorbird/APT_REPORT/blob/master/summary/2025/CrowdStrike%202025%20Threat%20Hunting%20Report.pdf
APT_REPORT/summary/2025/CrowdStrike 2025 Threat Hunting Report.pdf at master · blackorbird/APT_REPORT · GitHub

National Bank of Canada online systems down due to 'technical issue'

https://www.bleepingcomputer.com/news/technology/national-bank-of-canada-online-systems-down-due-to-technical-issue/
National Bank of Canada online systems down due to 'technical issue'

PBS confirms data breach after employee info leaked on Discord servers

https://www.bleepingcomputer.com/news/security/pbs-confirms-data-breach-after-employee-info-leaked-on-discord-servers/
PBS confirms data breach after employee info leaked on Discord servers

BTV at DEF CON 33 – Blue Team Village

https://blueteamvillage.org/btv-at-def-con-33/
BTV at DEF CON 33 – Blue Team Village

WhatsApp adds new security feature to protect against scams

https://www.bleepingcomputer.com/news/security/whatsapp-adds-new-security-feature-to-protect-against-scams/
WhatsApp adds new security feature to protect against scams

Google suffers data breach in ongoing Salesforce data theft attacks

https://www.bleepingcomputer.com/news/security/google-suffers-data-breach-in-ongoing-salesforce-data-theft-attacks/
Google suffers data breach in ongoing Salesforce data theft attacks

ANY.RUN & Microsoft Sentinel: Catch Emerging Threats with Real-Time Threat Intelligence - ANY.RUN's Cybersecurity Blog

https://any.run/cybersecurity-blog/threat-intelligence-feeds-ms-sentinel-connector/
ANY.RUN & Microsoft Sentinel: Catch Emerging Threats with Real-Time Threat Intelligence - ANY.RUN's Cybersecurity Blog

KLM Confirms Customer Data Breach Linked to Third-Party System

https://hackread.com/klm-customer-data-breach-linked-third-party-system/
KLM Confirms Customer Data Breach Linked to Third-Party System

CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures

https://thehackernews.com/2025/08/cert-ua-warns-of-hta-delivered-c.html
CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures

Microsoft Launches Project Ire to Autonomously Classify Malware Using AI Tools

https://thehackernews.com/2025/08/microsoft-launches-project-ire-to.html
Microsoft Launches Project Ire to Autonomously Classify Malware Using AI Tools

Log in to X / X

https://x.com/iok
Log in to X / X

ThrottleStop driver abused to terminate AV processes | Securelist

https://securelist.com/av-killer-exploiting-throttlestop-sys/117026/
ThrottleStop driver abused to terminate AV processes | Securelist

superxss/README.md at main · yassinmohamed1111/superxss · GitHub

https://github.com/yassinmohamed1111/superxss/blob/main/README.md
superxss/README.md at main · yassinmohamed1111/superxss · GitHub

Getting Code Execution on Apache Spark SQL – muffSec

https://muffsec.com/blog/getting-code-execution-on-apache-spark-sql/
Getting Code Execution on Apache Spark SQL – muffSec

MalwareBazaar | SHA256 8b94f5fa94f35e5ba47ce260b009b34401c5c54042d7b7252c8c7d13bf8d9f05 (SalatStealer)

https://bazaar.abuse.ch/sample/8b94f5fa94f35e5ba47ce260b009b34401c5c54042d7b7252c8c7d13bf8d9f05/
MalwareBazaar | SHA256 8b94f5fa94f35e5ba47ce260b009b34401c5c54042d7b7252c8c7d13bf8d9f05 (SalatStealer)

A Full-Chain Exploit of an Unfused Qualcomm Device

https://hhj4ck.github.io/qualcomm/2025/08/06/secboot-off-qcm2150.html
A Full-Chain Exploit of an Unfused Qualcomm Device