๐จ Research alert: Another npm supply chain attack is targeting developers.this time through popular packages in the keyv and cacheable ecosystems.
Check affected versions, IOCs, and mitigation steps ๐
https://t.co/nKRT04ACS0
Google just patched a serious โ ๏ธ vulnerability (CVE-2025-4664) that allows attackers to steal sensitive tokens (like OAuth or session IDs) when you simply visit a malicious site.
No clicking. No downloading. Just loading the page is enough.
What makes this so dangerous?
The bug lives in Chromeโs resource loading mechanism. It fails to apply origin policies correctly to Link headers, so attackers can trick your browser into sending full URLs โ including those juicy query strings with your login tokens โ to their server.
Imagine someone in HR or Finance clicking a phishing link. Suddenly their session tokens to SaaS tools (like payroll systems, admin panels, or customer databases) get exfiltrated without any interaction.
This isnโt remote code execution โ but in todayโs cloud-first, token-based authentication world, it might be worse.
So, yeah. I donโt post often about browser vulns. But this one is a no-go.
Update your Chrome. Right now.
Our talk from @defcon is now available! In the presented research, we document every EDR bypass technique used in the wild along with how to detect it using new memory forensics techniques and @volatility plugins. Feedback appreciated!
https://t.co/fWD57fzchj
#DFIR
Let's play a game! I'll share yet another #macOS stealer with a low detection rate on VT, and you try to find anything thatโs not a stealer! Honestly, I'd settle even for a good old-fashioned adware at this point xD https://t.co/scqy8hli7F
Yesterday the CUPS vulnerabilities were disclosed โ today, weโre showcasing our analysis of the POC and how Elastic Security can protect against it. Check it out: https://t.co/h8mkxOWCPt
#ElasticSecurityLabs#vulnerability#cybersecurity
I finished the promised article about System Integrity Protection #SIP, which introduces the #Apple idea of #rootless on #macOS. The article is for anyone interested in: #Programming#Re#Cybersecurity
https://t.co/9Qe2CIG6cQ
Enjoy reading!
The new publication from @DefSecSentinel explores the DPRKโs use of Python and social engineering for initial access. Check out the detailed breakdown here: https://t.co/PJyOr0vTMA
#ElasticSecurityLabs#DPRK#Python
#Lazarus#APT
The Lazarus group appears to be currently reaching out to targets via LinkedIn and spreading malware
https://t.co/OKtcMcZf2z
IOC :
https://t.co/YOrxCdZttj
We decided to share our #YARA rules to scan for indicators of the exploitation of CVE-2024-3400 in #PaloAlto's PAN-OS with the community and included some of the generic rules (detect similar attacks)
Three Steps
1. Generate a Tech Support file and extract it
https://t.co/ITPOvDtw7U
2. Download and extract THOR Lite
https://t.co/EVPjanmunk
3. Scan the extracted folder (tech support files)
thor64-lite.exe -a FileScan -p ..\2024XXXX_XXXX_techsupport.tgz_unpacked --intense --cross-platform --max-file-size 500MB
YARA Rules (already included in THOR Lite's signature package)
https://t.co/qMgto8kP9k
Evidence of exploitation and post-exploitation activity for #CVE20243400 can be found in log files on the FW in these locations:
/var/log/pan/gpsvc.log
/var/log/pan/md_out.log
/var/log/pan/device_telemetry_send.log
/var/log/syslog-system.log
/var/log/pan/mp-monitor.log
Pushed a new #KQL to search for vulnerable XZ devices (CVE-2024-3094). Since it seems related to SSH server compromise I also created a KQL query to list all inbound SSH connections to vulnerable XZ devices, you may want to review those.
https://t.co/89OPVeFhIN
๐Major Update: EDR Telemetry Project๐
I updated the EDR Telemetry Project to make the table accessible for color vision deficiencies, map all sub-categories to Mitre ATT&CK and more. (Read below๐)
Many thanks to all who contributed to this major update! Here are some changes:
โจ New EDR Additions:
โ Cortex EDR!
โ Symantec SES Complete!
๐ ๏ธ Enhancements and Fixes:
โข Color Accessibility Enhancements
โข Mitre ATT&CK Mapping (Thanks to @jamieantisocial and sorry it took so long ๐ฌ)
+ Elastic Telemetry Corrections
+ HarfangLab Telemetry Corrections
๐ฏNew Additions Coming Up:
๐ Sophos EDR
+Linux Telemetry Table (Started planning)
A huge shoutout to everyone who contributed! Your support and feedback are what drive this project forward. ๐
๐ GitHub Page: https://t.co/8DmXzffYVC
๐ Telemetry Table: https://t.co/6nvs6ymqof
Been slowly adding small programs that help me when teaching malware analysis - most programs in c/c++
๐ https://t.co/DXvS6Oqpha
Example, a program that implements the PEB-walking technique to resolve imports.
https://t.co/BMK1FADo8F
๐
I just published a detailed analysis about Stealc info stealer, a deep dive article about C/C++ stealer, the report involves
- in detailed code analysis
- config extractor
- yara rule
- IOCs
https://t.co/Daieg4YF1M
Uploaded all my Offensive Security & Reverse Engineering (OSRE) course labs (docx) to my repo found below. Most of them have very detailed instructions and should be great to get you started in Software Exploitation. 1/n
#Offsec#SoftwareExploitation#RE
https://t.co/D5oBtDNOnS
๐๐น๐ผ๐๐ฑ ๐ ๐ผ๐ป๐ถ๐๐ผ๐ฟ๐ถ๐ป๐ด ๐๐ต๐ฒ๐ฎ๐ ๐ฆ๐ต๐ฒ๐ฒ๐
Check out the Cloud Monitoring Cheat Sheet for all significant Cloud providers (AWS, GCP, Azure, and OCI).
When we talk about monitoring, we cover the following aspects:
๐น ๐๐ฎ๐๐ฎ ๐๐ผ๐น๐น๐ฒ๐ฐ๐๐ถ๐ผ๐ป: Gathering information from various sources to monitor the performance and health of cloud resources.
๐น๐๐ฎ๐๐ฎ ๐ฆ๐๐ผ๐ฟ๐ฎ๐ด๐ฒ: Storing the collected monitoring data in a repository or database for future reference and analysis.
๐น ๐๐ฎ๐๐ฎ ๐๐ป๐ฎ๐น๐๐๐ถ๐: Examining the stored monitoring data to identify patterns, anomalies, or insights about the cloud environment.
๐น ๐๐น๐ฒ๐ฟ๐๐ถ๐ป๐ด: Receiving notifications when specific conditions or thresholds are met or exceeded.
๐น ๐ฉ๐ถ๐๐๐ฎ๐น๐ถ๐๐ฎ๐๐ถ๐ผ๐ป: Representing monitoring data graphically, such as through charts or dashboards, to make it easier to understand.
๐น ๐ฅ๐ฒ๐ฝ๐ผ๐ฟ๐๐ถ๐ป๐ด ๐ฎ๐ป๐ฑ ๐๐ผ๐บ๐ฝ๐น๐ถ๐ฎ๐ป๐ฐ๐ฒ: Generating summaries or detailed monitoring data reports to ensure adherence to policies or regulations.
๐น ๐๐๐๐ผ๐บ๐ฎ๐๐ถ๐ผ๐ป: Using software to automatically perform tasks or actions based on monitoring data without manual intervention.
๐น ๐๐ป๐๐ฒ๐ด๐ฟ๐ฎ๐๐ถ๐ผ๐ป: Combining monitoring tools or data with other systems or applications to enhance functionality.
๐น ๐๐ฒ๐ฒ๐ฑ๐ฏ๐ฎ๐ฐ๐ธ ๐๐ผ๐ผ๐ฝ๐: Processes where the results or outcomes from monitoring are used to make improvements or adjustments to the cloud environment.
_______
If you want to expand your knowledge and personal growth, please follow me, @milan_milanovic, and hit the ๐ on my profile to get a notification for all my new posts.
#technology #softwareengineering #programming #techworldwithmilan #cloudcomputing