Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
https://www.nytimes.com/2019/05/06/us/politics/china-hacking-cyber.html
https://www.symantec.com/blogs/threat-intelligence/buckeye-windows-zero-day-exploit


Windows zero day was exploited by Buckeye alongside Equation Group tools during 2016 attacks. Exploit and tools continued to be used after Buckeye's apparent disappearance in 2017.

Key Findings

  • The Buckeye attack group was using Equation Group tools to gain persistent access to target organizations at least a year prior to the Shadow Brokers leak.
  • Variants of Equation Group tools used by Buckeye appear to be different from those
    released by Shadow Brokers, potentially indicating that they didn't originate from that leak.
  • Buckeye's use of Equation Group tools also involved the exploit of a previously unknown Windows zero-day vulnerability. This zero day was reported by Symantec to Microsoft in September 2018 and patched in March 2019.
  • While Buckeye appeared to cease operations in mid-2017, the Equation Group tools it used continued to be used in attacks until late 2018. It is unknown who continued to use the tools. They may have been passed to another group or Buckeye may have continued operating longer than supposed.

Hacker steals and shares unreleased TV shows

http://www.bbc.com/news/technology-39769428

Tinder Investigates After 40,000 Profile Pics Snatched

https://packetstormsecurity.com/news/view/27749/Tinder-Investigates-After-40-000-Profile-Pics-Snatched.html

Pwn2Own2017

Chrome Remains the Winner in Browser Security

https://securityzap.com/pwn2own-2017-chrome-remains-winner-browser-security/

Stegano 0.6.4

https://packetstormsecurity.com/files/140980/Stegano-0.6.4.tar.gz

Lynis Auditing Tool 2.4.1

Lynis Auditing Tool 2.4.1

https://packetstormsecurity.com/files/140981/lynis-2.4.1.tar.gz

Navy hacked through HP

http://mobile.reuters.com/article/idUSKBN13J001

Third party supplier strikes again. My guess is the was no FDE on the laptop.

not so new way to keylog

https://www.cyberpointllc.com/srt/posts/srt-logging-keystrokes-with-event-tracing-for-windows-etw.html

New mega-breach

http://thehackernews.com/2016/09/plaintext-passwords-leaked.html

a lot of money for nothing......

http://thehackernews.com/2016/04/fbi-unlock-iphone.html

Something tells me that the leak that nothing significant was gained form breaking into the famous iPhone is a ruse, or miss-direction. If you will. I am guessing they found some things, that can add a few pieces to the big puzzle, but nothing earth shattering.

Tactical Exploitation

was a nice quick read.
Good to refer to every once and a while.

https://www.defcon.org/images/defcon-15/dc15-presentations/Moore_and_Valsmith/Whitepaper/dc-15-moore_and_valsmith-WP.pdf