🚨CISA warns of critical flaws in industrial control systems from Hitachi, mySCADA Technologies, Industrial Control Links & Nexx.
Top concern: CVE-2022-3682 (CVSS: 9.9) in Hitachi Energy's MicroSCADA.
Learn more: https://t.co/FVVGEPlpNN
#cybersecurity#informationsecurity
⚖️ #Microsoft takes legal action against cybercriminals misusing Cobalt Strike! Teaming up with Fortra & Health-ISAC, they aim to disrupt #malware distribution, including 🔒 #ransomware.
Learn more: https://t.co/HqRtPgM4VJ
#cybersecurity
⚒️ LOLDrivers
A curated list of Windows drivers used by adversaries to bypass security controls and carry out attacks.
https://t.co/lYhc2NJJAg
By @M_haggis#infosec#cybersecurity#dfir#hacking
Back in 2022, I found a (stupid) local privilege escalation vulnerability in QuickHeal's @Seqrite Endpoint Security (EPS) AV product. Today I'm dropping some vulnerability details and a PoC exploit for the LPE. CVE and blogpost soon! 😄
Exploit: https://t.co/DIhZN5V4Gc
When fuzzing for SQLI always try "%22" as an injection payload, just stumbled upon MariaDB fork that wouldn't show any verbose SQL errors otherwise.
https://t.co/E3JkVBOJa2' => 301
https://t.co/E3JkVBOJa2" => 301
https://t.co/LhEV2CEdvS => 301 with SQL error
#bugbountytips
Recently, I was doing some research on #Kubernetes and scanned the entire IPv4 space for vulnerable clusters. Published a blog detailing the results: https://t.co/HIgGRieJtn
Also releasing a tool to detect exposed components studied in the research: https://t.co/QY0hQYjOlY
After this clip, Assange was forced into asylum. Today he is locked in a dungeon -- and kept incommunicado.
Listen to this, then ask yourself why it was so important that he be silenced.
“They who can treat secretly of the affairs of a nation have it absolutely under their authority; and as they plot against the enemy in time of war, so do they against the citizens in time of peace.”
― Baruch Spinoza
https://t.co/24ycy31Lsk
Julian Assange, the publisher of @wikileaks, has been held in solitary confinement in a maximum security prison for 3 yrs. He has not been convicted of any crime. The UN says is being tortured. For telling the truth. While those who committed war crimes go free. #FreeAssange
#WhatsApp fixes two critical vulnerabilities that would have allowed attackers to remotely hack their victims' devices by simply calling them (CVE-2022-36934) or sending a video file (CVE-2022-27492).
Read: https://t.co/XeTBsw0RzY
#infosec
This is not how anyone should use OSINT. This "challenge" is meaningless platitude. This thread post lays out a playbook for others to abuse OSINT.
Please take a step back and consider what you’ve posted and all the different ways it could be misused.
Published a blog on an internet scale research around secrets exposed via the frontend of websites. Releasing a community version of the tool used for the study as well! :)
Blog: https://t.co/tsmr26VsVv
Tool: https://t.co/QnJIlVHJqk
Video: https://t.co/19DAXA2U1o
#DriftingCloud, a Chinese threat actor, used a zero-day exploit in Sophos Firewalls to breach an organization, add a webshell and a VPN account, conduct DNS MITM, and steal session cookies to further breach remotely hosted webservers. 😮#apt#dfir#exploit https://t.co/OZXVb9zDUm
MemProcFS 4.9 - fast easy memory forensics & analysis now with support for heaps, process SIDs, integrity levels and new APIs! https://t.co/inOM3l1GIF
We've updated the vx-underground Malware Analysis collection. We have added 35 new papers, all aggregated via @malpedia.
You can see the full list of additions in the attached images. Have a nice day and enjoy the weekend.
Check it out here: https://t.co/yQEAzfy3Rw