The MOVEit Transfer exploitation is not just SQL injection(👀)
We uncovered the very last stage of the attack chain to drop human2.aspx ultimately ends up gaining remote code execution ‼
We fully recreated the attack chain with a demo achieving a reverse shell & ransomware!
I asked GPT3 to rewrite one of my LPE exploits in Perl, Python, Rust and Fortran. It did a remarkably good job when the C code is clear and concise, original: https://t.co/Vo6bfwHh2i GPT3 in screens below.
Empire Ops: Tactics is a hands-on course at this year’s @defcon. We will teach how to recreate aspects of the #APT28 Prime Minister Attack while learning advanced #redteam techniques. #defcon30
Register: https://t.co/khUEbKUHxz
JPCERT/CC's @shu_tom writes about the Lazarus VSingle malware that has recently been updated to retrieve C2 server information from GitHub. https://t.co/vnGqyobPIk
Kicked off my "MalDev for Dummies" workshop successfully yesterday, which means the repo is now public! Slides, exercises, example code and resources to get you started on your malware development journey. C# and Nim supported for now. Enjoy!!
https://t.co/Z8aQ41QvHQ
Poking at my toy C2, godoh, I managed to add #cobaltstrike's external C2 support. This is a beacon staged using DNS-over-HTTPS. It's nothing novel, but I had fun gluing together TCP sockets and DoH.
Now you know that Mega is not really a privacy company. It’s important to understand that those who control the code can create backdoors to defeat encryption. I know the lead developers. They lack morality. I recommend not to use Mega for sensitive files: https://t.co/tLWnWIEqI3
A new version of the XLoader #botnet malware has been discovered that uses a probability-based approach to camouflage its command and control (C&C) infrastructure.
Read details: https://t.co/tHZihpFccF
#infosec#cybersecurity#hacking#malware
Intervista #esclusiva di @matricedigitale al gruppo hacker che ha attaccato l'Italia.
"Sono il fondatore di Killnet e di Legion. L’ho creato io, ma non voglio controllarlo. Stiamo formando migliaia di persone pronte a combattere la NATO in futuro."
https://t.co/tX6C4rYLIN