November 8, 2023 at 05:32PM

■■■■■ DuckDuckC2: A proof-of-concept C2 channel through DuckDuckGo’s image proxy service. The provided example can be extended multiple ways to achieve different deployments. https://github.com/nopcorn/DuckDuckC2 https://nopcorn.github.io/2023/09/25/duckduckgo-as-c2 https://t.me/cKure/13201

November 8, 2023 at 05:26PM

■■■■□ CVE-2023-22518: Improper Authorization Vulnerability in Confluence Data Center and Server. A critical vulnerability in Atlassian Confluence Data Center and Server. The vulnerability could potentially allow unauthenticated attackers with network access to the Confluence Instance to restore the database of the Confluence instance and eventually execute arbitrary system commands. https://github.com/ForceFledgling/CVE-2023-22518 https://t.me/cKure/13199

November 8, 2023 at 05:19PM

■□□□□ Cyber-Attack on Qatari Ecommerce Government by a group calling themselves ‘Indian Cyber Force’. It was a DoS attack. Target – https://ecommerce.gov.qa/ Check Host – https://check-host.net/check-report/130d6715kb0d Duration: 2 hours (as per the group). https://t.me/cKure/13198

November 7, 2023 at 02:35AM

GCR – Google Calendar RAT Google Calendar RAT is a PoC of Command&Control (C2) over Google Calendar Events, This tool has been developed for those circumstances where it is difficult to create an entire red teaming infrastructure. To use GRC, only a Gmail account is required. The script creates a ‘Covert Channel’ by exploiting the…