twp_zero's profile picture.

twp_zero

@twp_zero

twp_zero reposted

Samples which look like exploits for the recent MS Office vulnerability CVE-2026-21509 have been detected by CERT-UA and published today on MalwareBazaar. It turns out they can be detected by the olecheck tool I had released this week, and the last version of oletools: see below

Russian #APT28 carries out cyberattacks against Ukraine and EU countries using the CVE-2026-21509 exploit: cert.gov.ua/article/6287250 All mentioned samples collected and uploaded abuse.ch bazaar.abuse.ch/browse/tag/APT… bazaar.abuse.ch/browse/tag/CVE… Used #covenant DLL also…



twp_zero reposted

L’association @InterCERTFrance est à la recherche d’un responsable technique pour gérer l’infrastructure de services fournis à ses membres. Si vous voulez mettre un pied dans la cybersecurité opérationnelle et aider les entreprises 🇫🇷 à échanger 👇 linkedin.com/jobs/view/3773…

fr.linkedin.com

Offres d’emploi “29 Leader Price” - France

29 offres d’emploi Leader Price du jour (France). Bénéficiez de votre réseau professionnel et changez de travail ! De nouvelles offres d’emploi “Leader Price” sont ajoutées tous les jours.


twp_zero reposted

Webdav ftw🔥👍

Just confirmed that this works nicely over WebDAV - Microsoft's mitigation of blocking outbound 445 is insufficient, you can exploit this on any port as long as WebClient is running



twp_zero reposted

Minneapolis public schools says it is facing technical issues following an encryption event (meme #2)

vxunderground's tweet image. Minneapolis public schools says it is facing technical issues following an encryption event (meme #2)

twp_zero reposted

Just released a new list of #Raccoon v2 / #RecordBreaker #C2 Ips online as of today, 14.01.2023 github.com/Gi7w0rm/Malwar… Many changes have been observed since the first released list. Let's hope takedowns will continue :) Also thanks to @0xrb for the collaboration!


twp_zero reposted

And another #FOR610 session close to end! CTF running at full speed… Wanna play with #malware samples? Join me for another session in February, Munich (sans.org/cyber-security…)

xme's tweet image. And another #FOR610 session close to end! CTF running at full speed… Wanna play with #malware samples? Join me for another session in February, Munich (sans.org/cyber-security…)

twp_zero reposted

#Michelin CERT discovered several vulnerabilities on #IBM datapower. #CVE-2022-31776 describes a SSRF having RCE impact. Full advisory ibm.com/support/pages/… cc @maxenceschmitt #security #bugbounty


twp_zero reposted

Maybe something new going on with #Formbook/#Xloader here ? First image is "unknown" behaviour, second image the normal changes by #Formbook/Xloader

Wait a minute, this does some interesting changes to the registry... Maybe something less common here... #Formbook does similar things but usually not to IExplorer... @malwrhunterteam @fr3dhk @JRoosen Is this a new thing or am I missing something ?

Gi7w0rm's tweet image. Wait a minute, this does some interesting changes to the registry... Maybe something less common here...
#Formbook does similar things but usually not to IExplorer...
@malwrhunterteam @fr3dhk @JRoosen 
Is this a new thing or am I missing something ?
Gi7w0rm's tweet image. Wait a minute, this does some interesting changes to the registry... Maybe something less common here...
#Formbook does similar things but usually not to IExplorer...
@malwrhunterteam @fr3dhk @JRoosen 
Is this a new thing or am I missing something ?


twp_zero reposted

↑↑↓↓←→←→BA

Wait a minute, this does some interesting changes to the registry... Maybe something less common here... #Formbook does similar things but usually not to IExplorer... @malwrhunterteam @fr3dhk @JRoosen Is this a new thing or am I missing something ?

Gi7w0rm's tweet image. Wait a minute, this does some interesting changes to the registry... Maybe something less common here...
#Formbook does similar things but usually not to IExplorer...
@malwrhunterteam @fr3dhk @JRoosen 
Is this a new thing or am I missing something ?
Gi7w0rm's tweet image. Wait a minute, this does some interesting changes to the registry... Maybe something less common here...
#Formbook does similar things but usually not to IExplorer...
@malwrhunterteam @fr3dhk @JRoosen 
Is this a new thing or am I missing something ?


twp_zero reposted

The talks are available for replay there::passthesalt.ubicast.tv/channels/#2022 by @ubicast_video These people have still done great things, thank you to them for making accessible to us the inaccessible for some! #pts22


twp_zero reposted

After months of work, I'm proud to announce the release of DotDumper this August @BlackHatEvents' @ToolsWatch's Arsenal in Las Vegas! @Trellix allowed me to work tirelessly on this project to automatically unpack DotNet based malware! Check it out here: blackhat.com/us-22/arsenal/…

Libranalysis's tweet image. After months of work, I'm proud to announce the release of DotDumper this August @BlackHatEvents' @ToolsWatch's Arsenal in Las Vegas! @Trellix allowed me to work tirelessly on this project to automatically unpack DotNet based malware! Check it out here: blackhat.com/us-22/arsenal/…

twp_zero reposted

Madme Michue se déplace au #FIC2022 #FIC CORDIALEMENT MADAME MICHUE


twp_zero reposted

The third article in Malware Analysis Series (MAS) by Alexandre Borges, with a detailed analysis of a Trojan that uses many obfuscation techniques. A very well-written and enlightening read: exploitreversing.com/2022/05/05/mal…


twp_zero reposted

According to the FBI's 2021 Internet Crime Report (IC3 Statistics), Business E-Mail Compromise was responsible for more than 1/3rd of all cyber crime and yielded x49 more money than ransomware. Although the FBI notes ransomware is under reported. Ransomware: $49.2m BEC: $2.4b

vxunderground's tweet image. According to the FBI's 2021 Internet Crime Report (IC3 Statistics), Business E-Mail Compromise was responsible for more than 1/3rd of all cyber crime and yielded x49 more money than ransomware. Although the FBI notes ransomware is under reported.

Ransomware: $49.2m
BEC: $2.4b

twp_zero reposted

Pour les enquêteurs en culottes courtes à ne jamais oublié. l'article complet: futura-sciences.com/tech/actualite… Très intéressant sur la constitution de la preuve. #OSINT

Sebdraven's tweet image. Pour les enquêteurs en culottes courtes à ne jamais oublié.

l'article complet: futura-sciences.com/tech/actualite…

Très intéressant sur la constitution de la preuve.

#OSINT

twp_zero reposted

Vous savez quoi ? L'application de vidéo-conférence que vous utilisez vous écoute, même quand le micro est coupé (muted). wiscprivacy.com/publication/vc…


Un grand Merci aux 24 joueurs de notre #CTF #MicVox @michelin_eng // @#DevoxxFR J'espère que vous vous êtes bien amusé OR que vous avez appris plein de choses.


Loading...

Something went wrong.


Something went wrong.