malwr

Can't Join? t.me/malwr

subscribers number

9 335

subscribers

Malware News

Updated: Oct 6, 2024


The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

Contact: @SirMalware

Country Rank 880 ↓1
Country United States
Language English

Latest Posts

malwr

August 15, 2024, 7:32

Writing a PE Loader for the Xbox in 2024 | lander's posts
Adventures in reinventing the wheel. Also: I hate thread-local storage.

https://landaire.net/reflective-pe-loader-for-xbox/


🎖@malwr

malwr

August 15, 2024, 7:28

Iranian backed group steps up phishing campaigns against Israel, U.S.

Google’s Threat Analysis Group shares insights on APT42, an Iranian government-backed threat actor.

https://blog.google/threat-analysis-group/iranian-backed-group-steps-up-phishing-campaigns-against-israel-us/


🎖@malwr

malwr

August 14, 2024, 18:33

Abusing AV/EDR Exclusions to Evade Detections | by Arun Nair | SEERcurity Spotlight | Aug, 2024 | Medium
Long time dear readers. In this blog post we’ll see how to abuse a common feature in Antivirus and EDRs that’s not often talked about. I will be using Windows Defender AV, as that’s common and often…

https://medium.com/seercurity-spotlight/abusing-av-edr-exclusions-to-evade-detections-21fe31d7ed49


🎖@malwr

malwr

August 14, 2024, 14:24

Server-Side Template Injection: Transforming Web Applications from Assets to Liabilities

https://research.checkpoint.com/2024/server-side-template-injection-transforming-web-applications-from-assets-to-liabilities/


🎖@malwr

malwr

August 14, 2024, 11:06

CVE-2024-38112: Void Banshee Targets Windows Users Through Zombie Internet Explorer in Zero-Day Attacks

Our threat hunters discovered CVE-2024-38112, which was used as a zero-day by APT group Void Banshee, to access and execute files through the disabled Internet Explorer using MSHTML. We promptly identified and reported this zero-day vulnerability to Microsoft, and it has been patched.

https://www.trendmicro.com/en_us/research/24/g/CVE-2024-38112-void-banshee.html


🎖@malwr

malwr

August 14, 2024, 2:48

ASLRn’t: How memory alignment broke library ASLR - zolutal’s blog
As it turns out, on recent Ubuntu, Arch, Fedora, and likely other distro’s releases, with kernel versions >=5.18, library ASLR is literally broken for 32-bit libraries of at least 2MB in size, on certain filesystems. Also, ASLR’s entropy on 64-bit libraries that are at least 2MB is significantly reduced, 28 bits -> 19 bits, on certain filesystems.

https://zolutal.github.io/aslrnt/


🎖@malwr

malwr

August 13, 2024, 15:07

Extension Trojan Malware Campaign | ReasonLabs
This research article intends to highlight a specific ongoing threat and the larger issue: malicious web extensions. The ReasonLabs Research Team has identified a new widespread polymorphic malware campaign that forcefully installs extensions on endpoints.

https://reasonlabs.com/research/new-widespread-extension-trojan-malware-campaign


🎖@malwr

malwr

August 13, 2024, 15:05

captainzero93/Protect-Images-from-AI-PixelGuard: PixelGuard protects images from AI scraping and unauthorized use in AI training, such as facial recognition models or style transfer algorithms. It employs multiple invisible protection techniques that mostly imperceptible to the eye but can interfere with AI processing.

https://github.com/captainzero93/Protect-Images-from-AI-PixelGuard


🎖@malwr

malwr

August 13, 2024, 15:01

captainzero93/security_harden_linux: Semi-automated bash scripts that provide security hardening for Linux, Debian based, 2024

https://github.com/captainzero93/security_harden_linux/


🎖@malwr