■□□□□ No Patch Available Yet for Critical SpringShell Bug. Workarounds can be made via SOC monitoring and firewall rules to dissuade scans with payloads. https://t.me/cKure/11090
All posts tagged hack
March 31, 2022 at 03:28PM
■■□□□ Mysterious disclosure of a zero-day RCE flaw Spring4Shell in Spring. An unauthenticated zero-day RCE vulnerability in the Spring Core Java framework called ‘Spring4Shell’ has been publicly disclosed. https://securityaffairs.co/wordpress/129644/hacking/spring-java-framework-rce-zero-day.html https://t.me/cKure/11089
March 31, 2022 at 11:59AM
■■□□□ The Morphisec Labs researchers analyzed a new malware, tracked as Mars stealer, which is based on the older Oski Stealer. https://securityaffairs.co/wordpress/129639/cyber-crime/mars-stealer-operation.html https://t.me/cKure/11088
March 31, 2022 at 11:57AM
■■□□□ Spring4Shell: Interesting thread! https://twitter.com/wdormann/status/1509372145394200579 https://t.me/cKure/11087
March 31, 2022 at 11:45AM
■■■■■ Zero-Day Vulnerability Discovered in Java Spring Framework. https://twitter.com/vxunderground/status/1509170582469943303 https://t.me/cKure/11086
March 31, 2022 at 11:42AM
■■■■■ Zero-Day: Unpatched Java Spring Framework 0-Day RCE Bug Threatens Enterprise Web Apps Security. https://thehackernews.com/2022/03/unpatched-java-spring-framework-0-day.html https://t.me/cKure/11085
March 31, 2022 at 11:18AM
■■■■■ Spring4Shell Details and Exploit Analysis. https://www.cyberkendra.com/2022/03/spring4shell-details-and-exploit-code.html https://t.me/cKure/11083
March 31, 2022 at 11:13AM
■■■■■ Zero-Day: Unauthenticated RCE on 3CX Phone Management systems. https://medium.com/@frycos/pwning-3cx-phone-management-backends-from-the-internet-d0096339dd88 https://t.me/cKure/11082
March 30, 2022 at 02:45PM
■■■□□ Cyber-Attack: A new campaign from the hacking group tracked as APT36, aka ‘Transparent Tribe’ or’ Mythic Leopard,’ has been discovered using new custom malware and entry vectors in attacks against the Indian government. https://www.bleepingcomputer.com/news/security/hackers-use-modified-mfa-tool-against-indian-govt-employees/ https://t.me/cKure/11081
March 30, 2022 at 02:44PM
■■□□□ Ten notorious ransomware strains put to the encryption speed test. https://www.bleepingcomputer.com/news/security/ten-notorious-ransomware-strains-put-to-the-encryption-speed-test/ https://t.me/cKure/11080
