November 29, 2021 at 10:18PM

■■□□□ Cyber-Attack by DPRK : ScarCruft surveilling North Korean defectors and human rights activists. https://securelist.com/scarcruft-surveilling-north-korean-defectors-and-human-rights-activists/105074/ https://t.me/cKure/10287

November 29, 2021 at 10:15PM

■■■■□ Unpatched Windows Zero-Day Allows Privileged File Access A temporary fix has been issued for CVE-2021-24084, which can be exploited using the LPE exploitation approach for the HiveNightmare/SeriousSAM bug. https://threatpost.com/unpatched-windows-zero-day-privileged-file-access/176609/ https://t.me/cKure/10286

November 29, 2021 at 10:11PM

■■■□□ Data-Leak from Japan : Japanese multinational conglomerate Panasonic disclosed a security breach after unknown threat actors gained access to servers on its network this month. https://www.bleepingcomputer.com/news/security/panasonic-discloses-data-breach-after-network-hack/ https://t.me/cKure/10284

November 29, 2021 at 03:56PM

■■■■□ Windows 11 password write in plain text. Finally had a moment to test Winlogon password leaking (a.k.a. notifying) on Windows 11. No big surprise.And the flow is:-user enters password-winlogon loads mpnotify.exe-mpnotify opens RPC channel-winlogon sends pass via RPC-mpnotify forwards to DLL-DLL stores it on disk pic.twitter.com/502qCao1BH — Grzegorz Tworek (@0gtweet) November 29, 2021 https://t.me/cKure/10281