10/30

Exploiting Ghost SPNs and Kerberos Reflection for SMB Privilege Elevation

https://www.semperis.com/blog/exploiting-ghost-spns-and-kerberos-reflection-for-smb-server-privilege-elevation/
Exploiting Ghost SPNs and Kerberos Reflection for SMB Privilege Elevation

Yet Another DCOM Object for Command Execution Part 1

https://sud0ru.ghost.io/yet-another-dcom-object-for-command-execution-part-1/
Yet Another DCOM Object for Command Execution Part 1

Canada Says Hackers Tampered With ICS at Water Facility, Oil and Gas Firm - SecurityWeek

https://www.securityweek.com/canada-says-hackers-tampered-with-ics-at-water-facility-oil-and-gas-firm/
Canada Says Hackers Tampered With ICS at Water Facility, Oil and Gas Firm - SecurityWeek

Edit fiddle - JSFiddle - Code Playground

https://jsfiddle.net/yo0a24dj/
Edit fiddle - JSFiddle - Code Playground

New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL

https://thehackernews.com/2025/10/new-brash-exploit-crashes-chromium.html
New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL

LinkedIn phishing targets finance execs with fake board invites

https://www.bleepingcomputer.com/news/security/linkedin-phishing-targets-finance-execs-with-fake-board-invites/
LinkedIn phishing targets finance execs with fake board invites

PhantomRaven Malware Found in 126 npm Packages Stealing GitHub Tokens From Devs

https://thehackernews.com/2025/10/phantomraven-malware-found-in-126-npm.html
PhantomRaven Malware Found in 126 npm Packages Stealing GitHub Tokens From Devs

BPO giant Conduent confirms data breach impacts 10.5 million people

https://www.bleepingcomputer.com/news/security/bpo-giant-conduent-confirms-data-breach-impacts-105-million-people/
BPO giant Conduent confirms data breach impacts 10.5 million people

PhantomRaven: NPM Malware Hidden in Invisible Dependencies | Koi Blog

https://www.koi.ai/blog/phantomraven-npm-malware-hidden-in-invisible-dependencies
PhantomRaven: NPM Malware Hidden in Invisible Dependencies | Koi Blog

Ex-L3Harris Cyber Boss Pleads Guilty to Selling Trade Secrets to Russian Firm | WIRED

https://www.wired.com/story/peter-williams-trenchant-trade-secrets-theft-russian-firm/
Ex-L3Harris Cyber Boss Pleads Guilty to Selling Trade Secrets to Russian Firm | WIRED

Former US defense contractor employee pleads guilty to selling hacking tools to buyer in Russia | CNN Politics

https://edition.cnn.com/2025/10/29/politics/defense-contractor-hacking-tools-russia
Former US defense contractor employee pleads guilty to selling hacking tools to buyer in Russia | CNN Politics

Radically improving Nix/NixOS security with Fil-C - Development - NixOS Discourse

https://discourse.nixos.org/t/radically-improving-nix-nixos-security-with-fil-c/71476
Radically improving Nix/NixOS security with Fil-C - Development - NixOS Discourse

Data Leak Outs Students of Iran's MOIS Training Academy

https://www.darkreading.com/threat-intelligence/data-leak-students-iran-mois-training-academy
Data Leak Outs Students of Iran's MOIS Training Academy