Opalsec :verified: · @Opalsec
163 followers · 76 posts · Server infosec.exchange

Find your Monday motivation with a recap of last week's infosec news - with vulnerabilities to patch and new research to read up on, there's plenty to help warm up the old noggin' before diving into another week:

opalsec.substack.com/p/soc-gou

have helpfully suggested patching a bunch of security exceptions it previously recommended making for earlier versions of , as they're no longer necessary and - oh yeah - because actors have also been actively abusing it to drop backdoors for years!

Stealc is a new, and in-demand Malware-as-a-Service offering on the Dark Web. The infostealer has received three major updates in the month since its release, and comes with all the major features a cyber crim could wish for to pilfer data and deliver additional stages.

A personal favourite from last week - realised a little too late that the Royal Mail negotiator had - in their words - "bamboozled" them throughout their extortion attempts. A real masterclass in how to handle a ransomware negotiation

VulnCheck have reported finding 7.5k instances on the internet that were vulnerable to a 2021 directory traversal vulnerability. This was lost in the hysteria around Log4Shell which emerged just days later, but can still be abused to write content to disk, or simply wipe the entire database altogether.

The vulnerability from the week before has come under widespread attack after a working exploit was released by researchers just two business days after the vulnerability was disclosed. Assume breach, patch, and hunt if you're not on top of this already.

For the , there's a cool BOF implementation of a Threadless process injection technique presented at Bsides Cyrus this year.

It's been a good week for the , with research and tools to help in detecting Cobalt Strike's Fork&Run procedure, a number of malware families and FOSS C2 frameworks, and more.

Good luck, and happy hunting!

opalsec.substack.com/p/soc-gou

#microsoft #exchange #lockbit #grafana #fortinac #redteam #blueteam #infosec #cyber #news #cybernews #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #soc #threatintel #threatintelligence #fortinet #cobaltstrike #darkweb

Last updated 3 years ago

Opalsec :verified: · @Opalsec
160 followers · 74 posts · Server infosec.exchange

Security research company Horizon3 released a proof-of-concept (PoC) exploit for a vulnerability in the Fortinet FortiNAC appliance, just two business days after the vendor notified customers of its existence.

The PoC allows an attacker to write arbitrary files to disk, and was seized upon by malicious actors who - just one day later - were seen deploying web shells on vulnerable appliances in-the-wild.

While security research is an undeniably important component of Cyber Security, its participants are often on the bleeding edge of offensive tradecraft, and need to be cautious that their research isn't abused by bad actors.

Allowing organisations just two business days to patch a vulnerability before releasing a fully-functional exploit into the wild does not meet that standard.

This isn't a criticism of Horizon3 themselves, but a reminder that organisations take time to discover and patch vulnerabilities, and security researchers need to be mindful of this - especially when publishing offensive tooling.

opalsec.substack.com/p/poc-lea

#infosec #cyber #news #cybernews #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #redteam #soc #threatintel #threatintelligence #poc #exploit #fortinet #fortinac #securityresearch

Last updated 3 years ago

securityaffairs · @securityaffairs
449 followers · 372 posts · Server infosec.exchange
Decio :mastodon: · @decio
91 followers · 248 posts · Server infosec.exchange
The Hacker News · @hackernews_bot
2150 followers · 1042 posts · Server social.platypush.tech

Referenced link: thehackernews.com/2023/02/fort
Discuss on discu.eu/q/https://thehackerne

Originally posted by The Hacker News / @TheHackersNews: nitter.platypush.tech/TheHacke

UPDATE: Heads up community!

Researchers has revealed PoC exploit for a critical security flaw in that can lead to remote code execution in the context of the root user.

Check out: thehackernews.com/2023/02/fort

#cybersecurity #fortinac

Last updated 3 years ago

securityaffairs · @securityaffairs
445 followers · 365 posts · Server infosec.exchange
Marco Ivaldi · @raptor
1715 followers · 976 posts · Server infosec.exchange
The Network DNA · @thenetworkdna
3 followers · 60 posts · Server mastodon.world
securityaffairs · @securityaffairs
438 followers · 354 posts · Server infosec.exchange