WindowsMDMLPE - Windows 11 PoC
fileless-xec is enable to execute a remote binary on a local machine directly from memory without dropping them on disk #tools #informatique
🇺🇸 #Commerce Lists Entities Involved in the Support of 🇨🇳 Ch︀i︀na Military Quantum Computing Applications, 🇵🇰 Pakistani Nuclear and Missile Proliferation, and 🇷🇺 R︀ussi︀a's Military - The U.S Commerce Department's Bureau of Industry and Security (BIS) has issued a final rule adding 27 foreign entities and individuals to the Entity List for engaging in activities that are contrary to the national security or foreign policy interests of the 🇺🇸 United States. The 27 entities and individuals are located in the 🇨🇳 People's Republic of Ch︀i︀na (PRC), 🇯🇵 Japan, 🇵🇰 Pakistan and 🇸🇬 Singapore. One entity based in 🇷🇺 R︀ussi︀a was added to the Military End-User (MEU) list. #usa #cyber #threats #informatique
https://www.govinfo.gov/content/pkg/FR-2021-11-26/pdf/2021-25808.pdf
GPUSleep - How to makes your Cobalt Strike beacon disappear into GPU memory (and eventually come back) #tools #informatique
gsudo is a Linux sudo equivalent for #Windows users #tools #informatique
Point d'étape & plan d'action sur les travaux relatifs à la qualité de l'exploitation des réseaux fibre optique et aux raccordements finals #france #arcep #fibre #informatique
SQLRecon is a C# MS-SQL toolkit designed for offensive reconnaissance & post-exploitation #tools #informatique
Picky PPID Spoofing - Parent Process ID (PPID) Spoofing is one of the techniques employed by #Windows #malware authors to blend in the target system. #tools #informatique
https://captmeelo.com//redteam/maldev/2021/11/22/picky-ppid-spoofing.html
XpFibre (Altice, ex-SFR FttH) dans le collimateur de l'ARCEP, le gendarme des télécoms. La société et ses filiales ne respectent pas leur obligation de fournir aux opérateurs tiers, aux collectivités et aux usagers un accès satisfaisant à son réseau de fibre optique. Une enquête administrative est ouverte.
Filiales:
CheckCert is a small utility to request and parse the SSL certificate from a public or private web application #tools #informatique
We were able to retrieve the #Bitlocker key in a couple of days with a 49$ #FPGA module by only using tools available in #DIY stores and, cherry on the cake, without breaking the #computer. Bitlocker is the Full Disk Encryption (#FDE) solution offered by #Microsoft for its #Windows operating systems #crypto #informatique
3 bugs (CVE-2021-1940, CVE-2021-1968 & CVE-2021-1969) in #Qualcomm NPU exploited together enables me (Man Yue Mo) to execute arbitrary code in the kernel from an untrusted app with ease. I'll then use these primitives to create a reverse root shell with SELinux disabled on #Samsung devices #vuln #informatique
Oh365UserFinder was created as a successor of o365Creeper. This tool is used for identifying valid o365 accounts and domains without the risk of account lockouts. #tools #informatique
Sketch is a popular UI/UX design app for #Apple #macOS. This post covers a vulnerability in Sketch that I discovered back in July - CVE-2021-40531. In its simplest form, it is a macOS quarantine bypass, but in context it can be used for RCE #vuln #informatique
🕷 Decode, verify & generate JSON Web Tokens (JWT) #tools #informatique
Mots de passe : Comment créer des applications plus sécuritaires #dev #crypto #informatique
🇸🇪 #IKEA employees are told not to open the emails, regardless of who sent them, and to report them to the IT department immediately. The #Qbot and #Emotet trojans both lead to further #network compromise and ultimately the deployment of #ransomware on a breached network. Due to the severity of these infections and the likely compromise of their #Microsoft Exchange servers, IKEA is treating this security incident as a significant cyberattack that could potentially lead to a far more disruptive attack. #sweden #mail #cyber #botnet #threats #informatique
https://www.bleepingcomputer.com/news/security/ikea-email-systems-hit-by-ongoing-cyberattack/
9 hommes soupçonnés d'avoir pratiqué l'arnaque au « Allo », du nom d'une combine téléphonique, mis en examen ce jeudi 25 novembre 2021. Ces voyous d'une vingtaine d'années originaires de cités du sud de 🇫🇷 #Paris achetaient sur le #darknet des données personnelles volées à la suite de piratages informatiques puis ils usurpaient les numéros de #téléphone des agences bancaires des victimes et enfin ils téléphonaient aux victimes en se faisant passer pour les conseillers bancaires en prétextant une détection d'#achats frauduleux. Les victimes ainsi conditionnées donnaient purement et simplement leur n° de CB, dates de validité, cryptogramme,.. #france #police #justice #databreach #banking #spoofing #arnaques #internet #escroqueries #fraudes #cyber #threats #informatique
🇪🇸 Los Mossos de Tarragona detienen a una pareja que utilizaba teminales a la venta de El Corte Inglés y Mediamarkt para fabricar criptomonedas por control remoto #spain #cryptocurrency #cyber #threats #cryptocurrencies #informatique
https://www.lavanguardia.com/tecnologia/20211122/7879681/parasitando-ordenadores-exposicion.html
sc(r)apy | full metal packets
> We Are the Borg
> You Will be Assimilated
> Resistance is Futile