05/09

Dell warns of data breach, 49 million customers allegedly affected

https://www.bleepingcomputer.com/news/security/dell-warns-of-data-breach-49-million-customers-allegedly-affected/
Dell warns of data breach, 49 million customers allegedly affected

Abusing MS Windows printing for C2 communication

https://diverto.hr/en/blog/2024-05-03-MS-Windows-Printing-C2/
Abusing MS Windows printing for C2 communication

Critical F5 Central Manager Vulnerabilities Allow Enable Full Device Takeover

https://thehackernews.com/2024/05/critical-f5-central-manager.html
Critical F5 Central Manager Vulnerabilities Allow Enable Full Device Takeover

Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery

https://thehackernews.com/2024/05/mirai-botnet-exploits-ivanti-connect.html
Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery

Go Binary Analysis with gftrace | 0xdf hacks stuff

https://0xdf.gitlab.io/2024/05/07/gftrace.html
Go Binary Analysis with gftrace | 0xdf hacks stuff

GitHub - cybersectroll/TrollDump

https://github.com/cybersectroll/TrollDump/
GitHub - cybersectroll/TrollDump

Modem on PinePhone

https://xnux.eu/devices/feature/modem-pp.html
Modem on PinePhone

Offensive IoT for Red Team Implants - Part 1 - Black Hills Information Security

https://www.blackhillsinfosec.com/offensive-iot-for-red-team-implants-part-1/
Offensive IoT for Red Team Implants - Part 1 - Black Hills Information Security

Digging for SSRF in NextJS apps

https://www.assetnote.io/resources/research/digging-for-ssrf-in-nextjs-apps
Digging for SSRF in NextJS apps

Custom Shellcode Creation in x64 | s4dbrd’s blog

https://s4dbrd.com/shellcode-creation-in-x64/
Custom Shellcode Creation in x64 | s4dbrd’s blog

University System of Georgia: 800K exposed in 2023 MOVEit attack

https://www.bleepingcomputer.com/news/security/university-system-of-georgia-800k-exposed-in-2023-moveit-attack/
University System of Georgia: 800K exposed in 2023 MOVEit attack

Zscaler takes "test environment" offline after rumors of a breach

https://www.bleepingcomputer.com/news/security/zscaler-says-it-was-not-hacked-after-rumors-circulate-online/
Zscaler takes "test environment" offline after rumors of a breach

New TunnelVision Attack Allows Hijacking of VPN Traffic via DHCP Manipulation

https://thehackernews.com/2024/05/new-tunnelvision-attack-allows.html
New TunnelVision Attack Allows Hijacking of VPN Traffic via DHCP Manipulation

Browser In The Browser (BITB) Attack | mr.d0x

https://mrd0x.com/browser-in-the-browser-phishing-attack/
Browser In The Browser (BITB) Attack | mr.d0x

The Five Most Dangerous New Attack Techniques You Need to Know About | RSA Conference

https://www.rsaconference.com/usa/agenda/session/The%20Five%20Most%20Dangerous%20New%20Attack%20Techniques%20You%20Need%20to%20Know%20About
The Five Most Dangerous New Attack Techniques You Need to Know About | RSA Conference

Zscaler Investigates Hacking Claims After Data Offered for Sale - SecurityWeek

https://www.securityweek.com/zscaler-investigates-hacking-claims-after-data-offered-for-sale/
Zscaler Investigates Hacking Claims After Data Offered for Sale - SecurityWeek

https://www.reddit.com/r/dataisbeautiful/comments/1cn7l7r/oc_most_common_4_digit_pin_numbers_from_an/

https://www.reddit.com/r/dataisbeautiful/comments/1cn7l7r/oc_most_common_4_digit_pin_numbers_from_an/

Citrix warns admins to manually mitigate PuTTY SSH client bug

https://www.bleepingcomputer.com/news/security/citrix-warns-admins-to-manually-mitigate-putty-ssh-client-bug/
Citrix warns admins to manually mitigate PuTTY SSH client bug

The Fundamentals of Cloud Security Stress Testing

https://thehackernews.com/2024/05/the-fundamentals-of-cloud-security.html
The Fundamentals of Cloud Security Stress Testing

F5 Patches Dangerous Vulnerabilities in BIG-IP Next Central Manager - SecurityWeek

https://www.securityweek.com/f5-patches-dangerous-vulnerabilities-in-big-ip-next-central-manager/
F5 Patches Dangerous Vulnerabilities in BIG-IP Next Central Manager - SecurityWeek

Transatlantic Cable podcast episode 346 | Kaspersky official blog

https://www.kaspersky.com/blog/transatlantic-cable-podcast-346/51210/
Transatlantic Cable podcast episode 346 | Kaspersky official blog

In interview, LockBItSupp says authorities outed the wrong guy

https://therecord.media/lockbitsupp-interview-ransomware-cybercrime-lockbit
In interview, LockBItSupp says authorities outed the wrong guy