> TODAY'S SUMMARY (13 articles)
Today's cybersecurity landscape highlights significant threats and trends. A vulnerability under attack, traced to a China-hosted IP, underscores the need for robust bug-hunting tools like Anthropic's Mythos. The Warlock group, also linked to China, is exploiting Microsoft SharePoint vulnerabilities to deploy ransomware, while the Technical University of Denmark has suffered a breach exposing data for 200,000 users. Additionally, critical vulnerabilities in Fortra's BoKS and GitLab's AI Gateway have been patched, emphasizing ongoing security challenges. New developments in AI, such as doxx.net's platform to prevent AI misadventures, indicate a growing focus on managing AI risks.
|
// AI-powered summary generated at 16:01
In the Deloitte poll, 50.2% of respondents said their organization is at risk of ‘harvest now, decrypt later’ attacks
An undisclosed number of people have been impacted
La Commission des valeurs mobilières de Hong Kong (SFC) a blâmé et sanctionné Six Fook Securities (ou Luk Fook Securities) pour des lacunes importantes dans ses mesures de cybersécurité. L'incident, une attaque par ransomware survenue en septembre 2022, a causé des perturbations majeures aux infrast...
Major phishing risk as personal details are compromised
Threat actor bombarded Uber contractor with 2FA requests
All about the new look for Hacking The Cloud v2.
On a network and need credentials? Try password spraying the domain controller directly.
A few years ago, I wrote this password spray tool called gospray that was used succesfully in a couple of engagements since. It does an LDAP bind directly against the domain controller to validate credentials. T...
It tried to trick victims into clicking on malicious files as part of a fake Amazon job assessment
Four of the CVEs posted are from 2013, and one is from 2010
In October 2019, a security researcher found a devastating vulnerability in Tornado.cash, a decentralized, non-custodial mixer on the Ethereum network. Tornado.cash uses zero-knowledge proofs (ZKPs) to allow its users to privately deposit and withdraw funds. The proofs are supposed to guarantee that...
US authorities indict and sanction in fresh crackdown
Attacker looks to have admin access to cloud accounts
En septembre 2022, Toulouse INP a été victime d'une cyberattaque avec le ransomware AvosLocker. L'attaque a été déclenchée via un compte étudiant compromis et a bloqué l'annuaire, les mécanismes d'authentification et les capacités d'accès physique aux bâtiments. Des mesures ont été prises pour rétab...
Most fake domains are registered in Russia
The group reportedly developed customized versions of Trochilus, Gh0st RAT and 9002 RAT
This week I learned about a design flaw with pip download, which allows an adversary to run arbitrary code.
I assumed that running pip install means anything could happen, but pip download seems a bit surprising.
Both seem useful for red teaming though.
Background This post from Yehuda Gelb named Au...
APT groups have leveraged Notepad++ plugins for nefarious purposes in the past
RedLine can steal usernames, passwords, cookies, bank card details and autofill data from browsers
Background If you haven’t done so yet, read my first Zix exploitation article: Spear Phishing with Zix: An Undisclosed Red Team Method for the Hungry APT, which established baselines to abuse the native organizational trust that Zix provides to perform spear phishing on the affected company. Shortly...
Experts urge the public not to fall for classic scams