A place to share links and articles that i have found helpful. This blog tends to be more offensive security minded. Basically it is a collection of notes that I will update periodically. None of this is set in stone, and I could very well be wrong on most of it. Just saying.
Holy Teamviewer Batman
https://www.symantec.com/blogs/threat-intelligence/buckeye-windows-zero-day-exploit
Windows zero day was exploited by Buckeye alongside Equation Group tools during 2016 attacks. Exploit and tools continued to be used after Buckeye's apparent disappearance in 2017.
Key Findings
- The Buckeye attack group was using Equation Group tools to gain persistent access to target organizations at least a year prior to the Shadow Brokers leak.
- Variants of Equation Group tools used by Buckeye appear to be different from those
released by Shadow Brokers, potentially indicating that they didn't originate from that leak. - Buckeye's use of Equation Group tools also involved the exploit of a previously unknown Windows zero-day vulnerability. This zero day was reported by Symantec to Microsoft in September 2018 and patched in March 2019.
- While Buckeye appeared to cease operations in mid-2017, the Equation Group tools it used continued to be used in attacks until late 2018. It is unknown who continued to use the tools. They may have been passed to another group or Buckeye may have continued operating longer than supposed.
Timehop has a turn now
Timehop Hacked — Hackers Stole Personal Data Of All 21 Million Users. This awesome probably includes the login details for all of these social media apps. Considering that those are now used to login to other sites, this breach is going to be bigger than first reported.
https://thehackernews.com/2018/07/timehop-data-breach.html
My Heritage breach
The IoT strikes
More on SEC breach
Here's The Latest About What The SEC Hackers Stole, but not a whole lot really
https://packetstormsecurity.com/news/view/28207/Heres-The-Latest-About-What-The-SEC-Hackers-Stole.html
Qatar state news agency hacked
GameStop breach
ASLR flaw
CIA Evidence of hacking kept secret
https://www.washingtonpost.com/posteverything/wp/2016/12/27/why-its-so-hard-to-prove-russia-was-behind-the-election-hacks/
Navy hacked through HP
http://mobile.reuters.com/article/idUSKBN13J001
Third party supplier strikes again. My guess is the was no FDE on the laptop.
New hacker bounty
not so new way to keylog
New data exfiltration method
Clever Attack Uses the Sound of a Computer’s Fan to Steal Data
https://www.wired.com/2016/06/clever-attack-uses-sound-computers-fan-steal-data/
Tactical Exploitation
Good to refer to every once and a while.
https://www.defcon.org/images/defcon-15/dc15-presentations/Moore_and_Valsmith/Whitepaper/dc-15-moore_and_valsmith-WP.pdf