■■■□□ Golden GMSA: abusing Group Managed Service Accounts in Active Directory. https://github.com/Semperis/GoldenGMSA#usage https://t.me/cKure/11220
All posts tagged hack
April 15, 2022 at 02:56PM
■■■■□ SSOh-No: User enumeration and password spraying tool for testing Azure AD. https://github.com/optionalCTF/SSOh-No/releases https://t.me/cKure/11219
April 15, 2022 at 01:54PM
■■■■□ The analysis of a recent sample SunnyDay ransomware revealed some similarities with other ransomware, such as Ever101, Medusa Locker, Curator, and Payment45. https://seguranca-informatica.pt/analysis-of-the-sunnyday-ransomware/#.YlflF-jMIQ8 https://securityaffairs.co/wordpress/130204/malware/analysis-sunnyday-ransomware.html https://t.me/cKure/11218
April 15, 2022 at 12:56PM
■■■■□ Zero-Day: Google on Thursday shipped emergency patches to address two security issues in its Chrome web browser, one of which it says is being actively exploited in the wild. Tracked as CVE-2022-1364, the tech giant described the high-severity bug as a case of type confusion in the V8 JavaScript engine. Clément Lecigne of Google’s…
April 15, 2022 at 12:55PM
■■□□□ Tool: Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation. https://github.com/bonjourmalware/melody https://t.me/cKure/11216
April 15, 2022 at 11:37AM
■■■□□ Critical Apache Struts RCE vulnerability wasn’t fully fixed, patch now. https://www.bleepingcomputer.com/news/security/critical-apache-struts-rce-vulnerability-wasnt-fully-fixed-patch-now/ https://t.me/cKure/11215
April 15, 2022 at 02:10AM
■□□□□ Rarible NFT Market Vulnerability Authorized Attackers to Transfer Crypto Assets. https://t.me/cKure/11214
April 15, 2022 at 02:09AM
■■■■□ Privacy: Boffins at two US universities have found that muting popular native video-conferencing apps fails to disable device microphones – and that these apps have the ability to access audio data when muted, or actually do so. https://wiscprivacy.com/papers/vca_mute.pdf https://www.theregister.com/2022/04/14/muting_ciscos_webex_app_doesnt/ https://t.me/cKure/11213
April 15, 2022 at 01:14AM
■■■■■ Teaching Burp a new HTTP Transport Encoding. https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/ https://t.me/cKure/11212
April 15, 2022 at 12:57AM
■■■□□ CVE-2022-25165: Privilege Escalation to SYSTEM in AWS VPN Client. https://rhinosecuritylabs.com/aws/cve-2022-25165-aws-vpn-client/ https://t.me/cKure/11211
