ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal. Webworm is linked to other China-aligned APT groups such as SixLittleMonkeys and FishMonger. https://t.co/HlMeDfoOXP
The Exploiting Reversing Series (ERS) currently features 1051 pages of exploit development based on real-world targets:
[+] ERS 09: https://t.co/V0K5p1XvH9
[+] ERS 08: https://t.co/MPwYP7j8Qt
[+] ERS 07: https://t.co/h18hZC0azl
[+] ERS 06: https://t.co/Sh8pgB4bh8
[+] ERS 05: https://t.co/rdaPMOm4WM
[+] ERS 04: https://t.co/Vf0Fnwf0tc
[+] ERS 03: https://t.co/4lo5Hi0gnd
[+] ERS 02: https://t.co/6SNMK1tBkd
[+] ERS 01: https://t.co/YMTSBl59VC
Now is the time to take a break to dedicate all my energy and focus to security research and new projects that will be announced in the coming weeks and months.
Have a great day and enjoy reading.
#exploit #exploitation #windows #chrome #macOS #iOS #hypervisors #vulnerability #research
Trend Micro researchers examine the April 22 Checkmarx KICS and April 24 elementary-data incidents as part of a broader TeamPCP supply chain campaign. Across both cases, the actor abused trusted CI/CD and release workflows to steal credentials at scale. https://t.co/l3K2Ink7dZ
The DFIR Report reveals data from an intrusion where an EtherRAT was deployed via a fake Sysinternals MSI. The threat actor additionally used the TukTuk malware framework and the RMM GoTo Resolve and deployed The Gentlemen ransomware. https://t.co/NY5Px1Co58
Started Writing about top 100 malware family. It is just beginning, I will update when add new malware.
https://t.co/fHvwEtNBBe
Suggestion are welcome.
Two #0day exploits were used against targets in the Middle East, and led to the deployment of Candiru's #DevilsTongue spyware!
- Heap BOF in WebRTC, Chromium (CVE-2022-2294)
- LPE in a 3rd party driver
Great finding by the team @ @AvastThreatLabs!
https://t.co/03GtyS8Eno
>>
Fortinet's Cara Lin writes about a malicious document that exploited Follina, then downloaded Rozena to deploy a fileless attack and leverage the public Discord CDN attachment service. https://t.co/FyUNLL3VqT
Hive ransomware, already one of the most prevalent payloads in the ransomware-as-a-service (RaaS) ecosystem, has evolved. The latest variant has been transformed by a full code migration to Rust and new complex encryption methods: https://t.co/BKsobSD6mD
https://t.co/JFdfXicFPn researchers have published the second part of their analysis of Raccoon Stealer v2, covering the malware's functionalities and capabilities. https://t.co/0GrPoTVLrz
Avast researchers look at two browser exploit kits, MagnitudeEK & UnderminerEK, that are experimenting with exploit chains targeting unpatched users of Google Chrome & other Chromium-based browsers. https://t.co/yAe2fV6gKL
Cisco Talos's @CRaghuprasad & @vanjasvajcer write about Nanocore, Netwire & AsyncRAT campaigns that abuse public clouds. In this way threat actors can set up their infrastructure with minimal time/monetary commitments and detection is more difficult. https://t.co/t6Zz5K48nd
Sygnia’s Incident Response team identified a threat group dubbed 'Elephant Beetle' (or TG2003) siphoning off funds from businesses in the financial sector in Latin America https://t.co/xtBCTzdF8s