Advertisement · 728 × 90

Posts by PaPPy

Google pushing out .zip as a TLD and then divesting their registrar business is the equivalent on pooping in the punch bowl as you leave a party

9to5google.com/2023/06/15/google-domain...

2 years ago 11 6 1 2
Preview
Chinese hackers used VMware ESXi zero-day to backdoor VMs VMware patched today a VMware ESXi zero-day vulnerability exploited by a Chinese-sponsored hacking group to backdoor Windows and Linux virtual machines and steal data.

www.bleepingcomputer.com/news/security/chinese-ha...

2 years ago 0 0 0 0
Preview
Malvertising via brand impersonation is back again Ads containing the official website of an impersonated brand are running again, allowing fraudsters to scam users.

Great article on recent malvertising www.malwarebytes.com/blog/threat-intelligence...

2 years ago 0 0 0 0
Onodo

Really cool initial access and malware graph https://onodo.org/visualizations/235067

2 years ago 0 0 0 0

@support.bsky.team how are the weekly invites granted? As I’m a week and an hour into this account and I do not have any invites. Thanks!

2 years ago 0 0 0 0

It was trivial to come up with a POC for #CVE-2023-32243 thanks to @patchstackapp detailed write up. Already seeing it abused in the wild. #wordpress owners need to upgrade Essential Addons for Elementor plugin now and check for signs of intrusion.

2 years ago 0 0 0 0
Preview
WordPress Elementor plugin bug let attackers hijack accounts on 1M sites One of WordPress's most popular Elementor plugins, "Essential Addons for Elementor," was found to be vulnerable to an unauthenticated privilege escalation that could allow remote attacks to gain administrator rights on the site.

This will lead to a lot of hacked WordPress sites I wonder if any of the link pits are running this plugin www.bleepingcomputer.com/news/security/wordpress-...

2 years ago 1 0 0 0
Preview
eSentire Threat Intelligence Malware Analysis: Vidar Stealer Dive deeper into the technical details gathered during eSentire’s Threat Response Unit (TRU) team’s research and threat analysis of the Vidar Stealer malware.

Great research on the Vidar Stealer www.esentire.com/blog/esentire-threat-int...

2 years ago 1 0 0 0
Preview
Fake in-browser Windows updates push Aurora info-stealer malware A recently spotted malvertising campaign tricked users with an in-browser Windows update simulation to deliver the Aurora information stealing malware.

www.bleepingcomputer.com/news/security/fake-in-br...

2 years ago 0 0 0 0
Advertisement
Preview
New Linux kernel NetFilter flaw gives attackers root privileges A new Linux NetFilter kernel flaw has been discovered, allowing unprivileged local users to escalate their privileges to root level, allowing complete control over a system.

Looking forward to seeing the POC on Monday for this LPE on Linux www.bleepingcomputer.com/news/security/new-linux-...

2 years ago 0 1 0 0

Note that the update for CVE-2023-24932 does NOT actually fix anything. It gives you the option of applying the fix yourself. Read through ALL of https://tinyurl.com/mprmsext if you want to consider applying the protection. Feel free to cry a bit and/or consider a career change.

2 years ago 0 1 0 0
Preview
Spanish police dismantle phishing operation linked to crime ring The National Police of Spain have arrested two hackers, 15 members of a criminal organization, and another 23 people involved in illegal financial operations in Madrid and Seville for alleged bank scams.

Great work by the spanish police www.bleepingcomputer.com/news/security/spanish-po...

2 years ago 1 0 0 0
Preview
Feds seize 13 more DDoS-for-hire platforms in ongoing international crackdown The DDoS whack-a-mole game between law enforcement and miscreants continues.

Great work taking down DDoS services arstechnica.com/information-technology/2...

2 years ago 1 1 0 0
Hunting Russian Intelligence “Snake” Malware | CISA

Nice article from CISA www.cisa.gov/news-events/cybersecurit...

2 years ago 0 0 0 0

7

2 years ago 1 0 0 0
Preview
NextGen Healthcare says hackers accessed personal data of more than 1 million patients NextGen Healthcare has admitted to a data breach that saw hackers access the personal data of more than 1 million patients

Ouch techcrunch.com/2023/05/08/nextgen-healt...

2 years ago 0 0 0 0
Advertisement
Post image

That’s pretty funny #Microsoft #clippy

2 years ago 0 0 0 0
Reddit - Dive into anything

Seems legit… www.reddit.com/r/techsupport/comments/9...

2 years ago 0 0 0 0
Preview
Kenya is turning to spyware, again; African SIM cards and identities; Nigerian telcos want to be excluded from data regulation and more infosec stories from across Africa.

cybafrique.substack.com/p/kenya-is-turning-to-sp...

2 years ago 0 0 0 0
Massive malvertising campaign targets seniors via fake Weebly sites Scammers are buying ads on for the most common Google searches made by seniors and defrauding them with tech support scams.

Please educate y’all’s older folks www.malwarebytes.com/blog/threat-intelligence...

2 years ago 0 0 0 0
Preview
San Bernardino County pays $1.1M ransom after cyberattack disrupts Sheriff's Department systems The hackers encrypted San Bernardino County Sheriff's Department data, causing significant disruptions to operations.

abc7.com/san-bernardino-cyberatta...

2 years ago 0 0 0 0

Stuff like this and the satellite network keep me up and employed www.darkreading.com/ics-ot/2-years-after-col...

2 years ago 0 0 0 0

Lol

2 years ago 0 0 0 0

Great post on bad practices in cyber security from CISA https://www.cisa.gov/news-events/news/bad-practices-0

2 years ago 0 0 0 0

If people haven’t upgraded their Papercut software now, this seems pretty bad thehackernews.com/2023/05/researchers-unco...

2 years ago 0 0 0 0

What prevents this individual from just starting a new domain and running the same business again? #infosec krebsonsecurity.com/2023/05/10m-is-yours-if-...

2 years ago 1 0 0 0
Advertisement

Hello World! Happy to be here on #BlueSky instead of the dumpster fire!

2 years ago 0 0 0 0