Plus récents

🇺🇦 Кіберполіція викрила хакерське угруповання на атаках іноземних компаній вірусом-шифрувальником

cyberpolice.gov.ua/news/kiberp

🇺🇦 СБУ викрила українців, які створили сервіс для хакерів і обікрали 50 іноземних компаній на мільйон доларів

ssu.gov.ua/novyny/sbu-vykryla-

Am 4. Januar 2022 wurde die Unfallkasse Thüringen (ukt.de) Opfer eines Cyberangriffes. Den Angreifern ist es gelungen über eine Ransomeware alle Server zu verschlüsseln.

ukt.de/unser-service/aktuelles

Imagine a future where moral and cognitive battles are waged with well-crafted narratives delivered and manipulated by an intricate web of simple and sophisticated cyber, information, electronic, and psychological warfare tools.

mwi.usma.edu/rethinking-man-tr

Security Alert - U.S. Embassy Kyiv, Ukraine (January 12, 2022)
The Department of State continues to advise U.S. citizens to reconsider travel to Ukraine due to increased threats from Russia.

ua.usembassy.gov/security-aler

ShadowCoerce - Coercing the domain controller machine account to authenticate to a host which is under the control of a threat actor could lead to domain compromise.

pentestlaboratories.com/2022/0

ShadowCoerce - Domain controllers which are running the VSS Agent Service could provide an opportunity for domain escalation.

youtube.com/watch?v=8ChZDeizjI

Un jeune allemand de 19 ans, David Colombo, spécialiste en sécurité informatique a discrètement piraté plusieurs Tesla situées à l'autre bout du monde. Résultat, il pouvait réaliser à distance tout un tas d'actions plus impressionnantes les unes que les autres.

iphonesoft.fr/2022/01/12/hacke

A teenage security researcher, David Colombo, claimed that he can remotely control various functions in 25 Teslas across 13 countries. Tesla

nasdaq.com/articles/teenage-re

Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory

github.com/optiv/Ivy

How to bypass EDR with Microsoft Teams ?

  • Copy payload into: %userprofile%\AppData\Local\Microsoft\Teams\current\

  • Then: %userprofile%\AppData\Local\Microsoft\Teams\Update.exe --processStart payload.exe --process-start-args "args"

Credit: Elli (IR)

ParseFortinetSerialNumber - A to parse products serial numbers, and detect the associated model and version.

github.com/p0dalirius/ParseFor

MirrorDump - Another LSASS dumping tool that uses a dynamically compiled LSA plugin to grab an lsass handle and API hooking for capturing the dump in memory.

github.com/snovvcrash/MirrorDu

[PDF] A comprehensive set of reverse engineering tutorials covers x86, x64 as well as 32-bit ARM and 64-bit architectures.

0xinfection.github.io/reversin

🇺🇸 The health information management services provider CIOX Health (cioxhealth.com) has suffered a data breach that has affected at least 32 healthcare providers. CIOX health started notifying affected healthcare provider clients about the breach on December 30, 2021. The security breach has been reported to the HHS' Office for Civil Rights by CIOX Health as affecting 12,493 individuals.

hipaajournal.com/over-30-healt

New Windows Server updates cause DC boot loops, break Hyper-V. The most serious issue introduced by these is that Windows Domain Controllers enter a boot loop, with servers getting into an endless cycle of starting and then rebooting after a few minutes. After installing Microsoft Updates, Resilient File System (ReFS) volumes are no longer accessible or are seen as RAW (unformatted) after installing the updates. In addition to the boot loops, Hyper-V no longer starts on the server. Microsoft released security updates to fix four different Hyper-V vulnerabilities yesterday (CVE-2022-21901, CVE-2022-21900, CVE-2022-21905, and CVE-2022-21847), which are likely causing this issue.

bleepingcomputer.com/news/micr

🇬🇧 Plus de 50 000 courriers envoyés par des banques et des collectivités locales indexées par Google suite à une erreur de la société de sous-traitance Virtual Mail Room (vmailroom.co.uk)

wired.co.uk/article/virtual-ma

Plus anciens