OVERWATCH 2 GIVEAWAY
Saitama - Doomfist Legendary Bundle
How To Enter:
👊Follow @andrew_jrt
👊Like & Retweet
👊Tag your BFF
(Codes provided by Blizzard)
OVERWATCH 2 GIVEAWAY
Terrible Tornado - Kiriko Legendary Bundle
How To Enter:
👊Follow @andrew_jrt
👊Like & Retweet
👊Tag your BFF
(Codes provided by Blizzard)
New details on the 2nd LastPass incident are fun:
- got into Sr DevOp's home via vuln media software
- installed keylogger
- got master pass to corp vault (seemingly because it was being accessed from home computer)
Cool to see that LastPass is sharing this level of detail. Most companies are vulnerable to an attack like this.
Main post:
https://t.co/Qcyxpoh8xj
Incident 1 details:
https://t.co/LZYUJJ1Dhc
Incident 2 details:
https://t.co/GIuRP8RftR
I briefly analyzed #HermeticWiper to give an overview of its capabilities. I have deliberately omitted some details for better understanding. I'll update the graphic as my analysis progresses! Hope this will help you understand better the attack! #infosec#malware#cybersecurity
from @BlackHatEvents USA 2016:
A Journey From #JNDI/LDAP Manipulation to Remote Code Execution Dream Land by @pwntester and @olekmirosh
https://t.co/LbI7BTodtE
now the exploit vector presented in 2016 is the #log4jRCE.
attached slide #11 from the presentation below. :)
I made a small PoC. cs-mitm. py is a mitmproxy script that intercepts Cobalt Strike traffic, decrypts it and injects its own commands. In this video, a malicious beacon is terminated by sending it an exit command. The beacon uses one of the leaked private keys.
Recently I started working on a driver for mal_unpack ( a tool from #PEsieve family) - if anyone curious, I open-sourced the code: https://t.co/j6fD2eEjZE - please share what do you think