■■□□□ PowerShell’s Constrained Language (CLM) mode limits the functionality available to users to reduce the attack surface. It is meant to be used in conjunction with application control solutions like Device Guard User Mode Code Integrity. If CLM is enabled without proper application control settings, it is not an effective security solution. https://www.blackhillsinfosec.com/constrained-language-mode-bypass-when-pslockdownpolicy-is-used/ https://t.me/cKure/11824
All posts tagged cyber
September 29, 2022 at 09:11PM
■■■■■ Unconfirmed zero-day in Microsoft exchange. https://www.gteltsc.vn/blog/canh-bao-chien-dich-tan-cong-su-dung-lo-hong-zero-day-tren-microsoft-exchange-server-12714.html https://t.me/cKure/11823
September 29, 2022 at 09:00PM
● A zero-day in Microsoft exchange is circulating online. https://t.me/cKure/11822
September 29, 2022 at 02:13PM
■■■■□ New WhatsApp zero-day bug let hackers control the application remotely. CVE-2022-36934: Integer Overflow Bug CVE-2022-27492: Integer Underflow Bug https://cybersecuritynews.com/new-whatsapp-zero-day-bug/ https://t.me/cKure/11821
September 28, 2022 at 11:10PM
Interesting thread on malware. https://twitter.com/k3dg3/status/1575173131198558208 https://t.me/cKure/11819
September 28, 2022 at 12:05AM
■■■■□ CVE-2007-4559 (CVSS score: 6.8). As many as 350,000 open source projects are believed to be potentially vulnerable to exploitation as a result of a security flaw in a Python module that has remained unpatched for 15 years. https://thehackernews.com/2022/09/15-year-old-unpatched-python.html https://t.me/cKure/11818
September 28, 2022 at 12:00AM
■■■■□ Tool: Cpplumber is a static analysis tool that helps detecting and keeping track of C and C++ source code information that leaks into compiled executable files. https://github.com/ergrelet/cpplumber https://t.me/cKure/11816
September 27, 2022 at 11:58PM
■■■□□ Tool: CrackMapExec: Swiss army knife for pentesting networks. https://github.com/Porchetta-Industries/CrackMapExec https://t.me/cKure/11815
September 27, 2022 at 11:54PM
■■■■■ Cyber-attack on Pakistan Pakistan PM calls emergency meeting with military and ISI Chiefs after ISI bugging devices in his office were hacked into by an alleged Indian hacker and its audio files released on dark web for sale for 180 BTC. https://t.me/cKure/11814
September 27, 2022 at 02:52AM
■■■□□ iOS Native Code Obfuscation and Syscall Hooking. https://www.romainthomas.fr/post/22-09-ios-obfuscation-syscall-hooking/ https://t.me/cKure/11813
