unit42.paloaltonetworks.com/solarstorm-supply-chain-attack-timeline/

 

SolarStorm Timeline: Details of the Software Supply-Chain Attack

The SolarStorm timeline summarized here is based on the information available to us and our direct experience defending against this threat.

unit42.paloaltonetworks.com

 

 

'News' 카테고리의 다른 글

twitter iOS News  (0) 2020.12.07
[News] DNS Cache Poisoning  (0) 2020.12.06
테슬라 모델X 전자 제어 장치 해킹 관련  (0) 2020.12.06
credit card PayPal forms  (0) 2020.12.06
supply chain attack  (0) 2020.11.19
블로그 이미지

wtdsoul

,

twitter iOS News

News 2020. 12. 7. 15:19

mobile.twitter.com/muirey03

 

Muirey03(@Muirey03) 님 | 트위터

@Muirey03 님 언뮤트하기 @Muirey03 님 뮤트하기 팔로우 @Muirey03 님 팔로우하기 팔로잉 @Muirey03 님 팔로우 중 언팔로우 @Muirey03 님 언팔로우하기 차단됨 @Muirey03 님이 차단됨 차단 해제 @Muirey03님 차단 해

mobile.twitter.com

 

 

'News' 카테고리의 다른 글

Solar Storm supply chain attack  (0) 2020.12.25
[News] DNS Cache Poisoning  (0) 2020.12.06
테슬라 모델X 전자 제어 장치 해킹 관련  (0) 2020.12.06
credit card PayPal forms  (0) 2020.12.06
supply chain attack  (0) 2020.11.19
블로그 이미지

wtdsoul

,

[News] DNS Cache Poisoning

News 2020. 12. 6. 16:41

thehackernews.com/2020/11/sad-dns-new-flaws-re-enable-dns-cache.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+TheHackersNews+%28The+Hackers+News+-+Cyber+Security+Blog%29

 

SAD DNS — New Flaws Re-Enable DNS Cache Poisoning Attacks

Critical flaws re-enabled DNS cache poisoning attack on Linux, Windows, macOS, and FreeBSD.

thehackernews.com

 

 

 

'News' 카테고리의 다른 글

Solar Storm supply chain attack  (0) 2020.12.25
twitter iOS News  (0) 2020.12.07
테슬라 모델X 전자 제어 장치 해킹 관련  (0) 2020.12.06
credit card PayPal forms  (0) 2020.12.06
supply chain attack  (0) 2020.11.19
블로그 이미지

wtdsoul

,

www.dailysecu.com/news/articleView.html?idxno=117327

 

(영상) 테슬라 모델X 전자 제어 장치 몇 분만에 해킹 - 데일리시큐

“우리는 테슬라 모델X의 열쇠 고리를 무선으로 손상시키고 이를 완전히 제어할 수 있었다. 이후 유효한 잠금 해제 메시지를 얻어 차의 잠금 장치를 풀 수 있었다.”테슬라 모델X의 전자 제어 장

www.dailysecu.com

 

'News' 카테고리의 다른 글

twitter iOS News  (0) 2020.12.07
[News] DNS Cache Poisoning  (0) 2020.12.06
credit card PayPal forms  (0) 2020.12.06
supply chain attack  (0) 2020.11.19
Researchers Publish PoC for Docker Escape Bug  (0) 2019.11.26
블로그 이미지

wtdsoul

,

credit card PayPal forms

News 2020. 12. 6. 16:15

www.bleepingcomputer.com/news/security/credit-card-skimmer-fills-fake-paypal-forms-with-stolen-order-info/

 

Credit card skimmer fills fake PayPal forms with stolen order info

A newly discovered credit card skimmer uses an innovative technique to inject highly convincing PayPal iframes and hijack the checkout process on compromised online stores.

www.bleepingcomputer.com

 

'News' 카테고리의 다른 글

[News] DNS Cache Poisoning  (0) 2020.12.06
테슬라 모델X 전자 제어 장치 해킹 관련  (0) 2020.12.06
supply chain attack  (0) 2020.11.19
Researchers Publish PoC for Docker Escape Bug  (0) 2019.11.26
Bad Binder: Android In-The-Wild Exploit  (0) 2019.11.25
블로그 이미지

wtdsoul

,

supply chain attack

News 2020. 11. 19. 10:59

www.welivesecurity.com/2020/11/16/lazarus-supply-chain-attack-south-korea/

 

Lazarus supply‑chain attack in South Korea | WeLiveSecurity

ESET research uncovers attempts to deploy Lazarus malware via a supply-chain attack that abuses genuine security software and stolen digital certificates.

www.welivesecurity.com

 

 

블로그 이미지

wtdsoul

,

https://www.infosecurity-magazine.com/news/researchers-public-poc-docker/

 

Researchers Public PoC for Docker Container Escape Bug

Researchers Public PoC for Docker Container Escape Bug. Flaw is patched in Docker version 19.03.1

www.infosecurity-magazine.com

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14271

 

CVE - CVE-2019-14271

20190725 Disclaimer: The entry creation date may reflect when the CVE ID was allocated or reserved, and does not necessarily indicate when this vulnerability was discovered, shared with the affected vendor, publicly disclosed, or updated in CVE.

cve.mitre.org

https://unit42.paloaltonetworks.com/breaking-docker-via-runc-explaining-cve-2019-5736/

 

Breaking out of Docker via runC – Explaining CVE-2019-5736

Last week (2019-02-11) a new vulnerability in runC was reported by its maintainers, originally found by Adam Iwaniuk and Borys Poplawski. Dubbed CVE-2019-5736, it affects Docker containers running in default settings and can be used by an attacker to gain

unit42.paloaltonetworks.com

 

 

 

 

'News' 카테고리의 다른 글

credit card PayPal forms  (0) 2020.12.06
supply chain attack  (0) 2020.11.19
Bad Binder: Android In-The-Wild Exploit  (0) 2019.11.25
IoT Device Search & Default Credential Scanner  (0) 2019.11.25
Microsoft Edge - Local File Disclosure and EoP  (0) 2019.11.21
블로그 이미지

wtdsoul

,

https://googleprojectzero.blogspot.com/2019/11/bad-binder-android-in-wild-exploit.html?m=1

 

Bad Binder: Android In-The-Wild Exploit

Posted by Maddie Stone, Project Zero Introduction On October 3, 2019, we disclosed issue 1942 (CVE-2019-2215), which is a use-afte...

googleprojectzero.blogspot.com

https://bugs.chromium.org/p/project-zero/issues/detail?id=1942

Issue 1942: Android: Use-After-Free in Binder driver

 

 

1942 - project-zero - Project Zero - Monorail

 

bugs.chromium.org

 

 

블로그 이미지

wtdsoul

,

https://www.e13olf.me/2019/11/i0t-pr0be-iot-device-search-default.html?m=1

 

[root@e13olf]# : i0t-pr0be - IoT Device Search & Default Credential Scanner

A Python 3 script to automate search via Shodan, save IoT device query results and also scan for their respective default credentials. The script utilizes two main APIs; Shodan & Python Selenium. Shodan Shodan membership allows you to get 100 query credits

www.e13olf.me

https://github.com/e13olf/i0t-pr0be

 

e13olf/i0t-pr0be

IoT device search and default credential scanner. Contribute to e13olf/i0t-pr0be development by creating an account on GitHub.

github.com

https://github.com/mozilla/geckodriver/releases

 

mozilla/geckodriver

WebDriver for Firefox. Contribute to mozilla/geckodriver development by creating an account on GitHub.

github.com

 

블로그 이미지

wtdsoul

,

https://leucosite.com/Edge-Local-File-Disclosure-and-EoP/?fbclid=IwAR2SNjX2wrwNSDx-U3rp-AL8lJSqvWMNWV_cRRYszb3R7KmqQx2t5EhqEeo

 

(CVE-2019-1356) Microsoft Edge - Local File Disclosure and Elevation of Privilege

Microsoft Edge - Local File Disclosure and EoP In this write up, I will be covering multiple bugs in the Edge (EdgeHTML) browser. The combination of these bugs will result in two distinct attacks, one being a local file disclosure and the other is an eleva

leucosite.com

 

In this write up, I will be covering multiple bugs in the Edge (EdgeHTML) browser. The combination of these bugs will result in two distinct attacks, one being a local file disclosure and the other is an elevation of privilege which is used to change any settings within 'about:flags'.

블로그 이미지

wtdsoul

,