November 1, 2023 at 05:13PM

■■■■□ Lazarus infect blockchain engineers with novel macOS malware. Elastic Security Labs exposes an attempt by the DPRK to infect blockchain engineers with novel macOS malware. https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn https://t.me/cKure/13162

November 1, 2023 at 12:22PM

■■□□□ memdlopen: dlopen() filelessly a shared object or even a program (and run it). This is an implementation of the technique developed in the paper Remote Library Injection published at Nologin. There’s another implementation which has a severe problem: code signatures, which is precisely what I have fixed. https://github.com/arget13/memdlopen https://t.me/cKure/13161

November 1, 2023 at 03:30AM

■■■□□ Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability. Atlassian warns that a critical vulnerability in Confluence Data Center and Server could lead to significant data loss if exploited. https://www.securityweek.com/atlassian-ciso-urges-quick-action-to-protect-confluence-instances-from-critical-vulnerability/ https://t.me/cKure/13159

November 1, 2023 at 03:30AM

■■■■■ Massive Data-Breach t national card of India: Aadhaar data of 815m Indians in dark web, says cyber security firm. The hacker was willing to sell the entire Aadhaar and Indian passport dataset for $80,000 when contacted by Resecurity. https://m.rediff.com/news/report/aadhaar-data-of-815m-indians-in-dark-web-says-cyber-security-firm/20231031.htm https://t.me/cKure/13157

November 1, 2023 at 03:30AM

■■■■□ United States-Russia Cyber-War: Russian Hackers Breached 632,000 DOJ And Pentagon Email Addresses In Massive MOVEit Cyberattack, Report Says. https://www.forbes.com/sites/tylerroush/2023/10/30/russian-hackers-breached-632000-doj-and-pentagon-email-addresses-in-massive-moveit-cyberattack-report-says/ https://t.me/cKure/13156

November 1, 2023 at 03:30AM

■■□□□ United States: Hardware store empire felled by cyberattack. US outfit scrambles to repair operations, restore processing of online orders. https://www.theregister.com/2023/10/31/ace_hardware_cyberattack/ https://t.me/cKure/13158