September 29, 2022 at 10:32PM

■■□□□ PowerShell’s Constrained Language (CLM) mode limits the functionality available to users to reduce the attack surface. It is meant to be used in conjunction with application control solutions like Device Guard User Mode Code Integrity. If CLM is enabled without proper application control settings, it is not an effective security solution. https://www.blackhillsinfosec.com/constrained-language-mode-bypass-when-pslockdownpolicy-is-used/ https://t.me/cKure/11824

September 29, 2022 at 02:13PM

■■■■□ New WhatsApp zero-day bug let hackers control the application remotely. CVE-2022-36934: Integer Overflow Bug CVE-2022-27492: Integer Underflow Bug https://cybersecuritynews.com/new-whatsapp-zero-day-bug/ https://t.me/cKure/11821

September 28, 2022 at 12:05AM

■■■■□ CVE-2007-4559 (CVSS score: 6.8). As many as 350,000 open source projects are believed to be potentially vulnerable to exploitation as a result of a security flaw in a Python module that has remained unpatched for 15 years. https://thehackernews.com/2022/09/15-year-old-unpatched-python.html https://t.me/cKure/11818

September 28, 2022 at 12:00AM

■■■■□ Tool: Cpplumber is a static analysis tool that helps detecting and keeping track of C and C++ source code information that leaks into compiled executable files. https://github.com/ergrelet/cpplumber https://t.me/cKure/11816

September 27, 2022 at 11:54PM

■■■■■ Cyber-attack on Pakistan Pakistan PM calls emergency meeting with military and ISI Chiefs after ISI bugging devices in his office were hacked into by an alleged Indian hacker and its audio files released on dark web for sale for 180 BTC. https://t.me/cKure/11814