December 23, 2023
December 23, 2023
Holiday gift for you. Ghidra 11.0 released! New BSim feature can find structurally similar functions in (potentially large) collections of binaries or object files. Initial support for Rust compiled binaries. Golang improved. +morehttps://t.co/08mFeYtGW3
— Rob Joyce (@NSA_CSDirector) December 22, 2023
Latest Ghidra has function similarity search built in, using feature vectors calculated by the decompiler. https://t.co/mrmvH8CJU1 pic.twitter.com/ywSesC7BCp
— Antti Tikkanen (@anttitikkanen) December 22, 2023
Dear folks running bounty programs, I have a holiday request: If I send you a full read XXE, consider it as RCE. That has been true for me, always, since 2012. I don't want to mess with your prod environment to change the CVSS from 9.6 to 9.8 or 10 but if, you ask, I will. Thanks
— Reginaldo Silva (@reginaldojsf) December 22, 2023
Predatory sparrows are still all up in the Iranian gas stations. Seems like they are banging the “signal” drum pretty hard on this one
با وجود اینکه چند روز از #هک سیستم #سوخت_رسانی گذشته اما هنوز #پمپ_بنزین ها کار نمیکنند، در اصل چون ما تصمیم نگرفتیم که کار کنند...
— Gonjeshke Darande (@darandegonjeshk) December 22, 2023
پس چه زمانی کار میکنند؟ هر وقت تصمیم بگیریم :) https://t.co/fqyOua0L1k
شرمنده #جمهوری_اسلامی منطقه را نا امن کرد
— Gonjeshke Darande (@darandegonjeshk) December 22, 2023
ما هم گفتیم یه واکنش مختصری بهشون بدیم
خلاصه خوشحال شدیم هنوز کار نمیکنه 😉
The #Islamic_republic destabilized the region with their #terror_proxies and we had to give them a small response. Happy out response is still "working" 😉 https://t.co/DlDvV6GSjN
I bet I could do some bad things in this hotel room🐸 pic.twitter.com/zFMEseM4wv
— Takwan (@CriticalTakwan) December 22, 2023
If I put this together, can I list server architect on my resume? pic.twitter.com/shIJGiW9hX
— InfoSec Artist (@infosecart) December 22, 2023
— EvilMog (@Evil_Mog) December 22, 2023
omg take away his keys https://t.co/YvuqREhT65
— Faux Pelini (@FauxPelini) December 22, 2023
One person has been arrested every hour since the start of December for drink or drug driving, according to gardaí https://t.co/UTVqeZwisF
— RTÉ News (@rtenews) December 21, 2023
Lot of noise to signal in here, but an interesting exploit. By combining a number of small low severity vulnerabilities spammers are able to achieve good results.
Google Search Overwhelmed By Massive Spam Attack
Google is apparently struggling to contain a spam attack that's been ongoing for days
— ettingermentum (@ettingermentum) December 22, 2023
when people recognize me irl they yell my tweets at me like “tom i always say GORSH when i nut now” or “my dick looks like a bald werewolf too” and i have to be like “thanks man... grandma this is FootFreak69 he’s my friend from the computer”
— old tom (@YuckyTom) August 12, 2018
BREAKING: President Joe Biden has announced he's issuing a federal pardon to every American who has used marijuana in the past, including those who were never arrested or prosecuted.
— unusual_whales (@unusual_whales) December 22, 2023
One cyber crime actor – Lace Tempest (and pretty much a single persona within that team) – has obtained and exploited 5 0days and 1 n-day without a public POC to deploy ransomware [CL0P]
— Nick Carr (@ItsReallyNick) December 21, 2023
1️⃣ Accellion FTA CVE-2021-27101 (+CVE-2021-27102/CVE-2021-27103/CVE-2021-27104)
2️⃣… https://t.co/ZomsUKOu5T
🔴 Lace Tempest (aka FIN11/TA505/DEV-0950) has used at least 1 n-day and 4 zero-day attacks as initial access (T1190) to deploy CL0P ransomware/extortion:
— Germán Fernández (@1ZRR4H) June 6, 2023
▪ Accellion FTA CVE-2021-27101 (+CVE-2021-27102/CVE-2021-27103/CVE-2021-27104)
▪ SolarWinds Serv-U CVE-2021-35211
▪… https://t.co/hDnYXljHBS pic.twitter.com/stQaMEi5aq
This week on the blog: How do we know how many people lived in ancient Greece or Rome? What methods do we use to make those estimates? Are they good enough to do big 'macro-history' with?
— Bret Devereaux (@BretDevereaux) December 23, 2023
Spoilers: the best we can do is not very reliable at all!https://t.co/YGkK1jax3u
Cyber-espionage group Cloud Atlas targets Russian companies with war-related phishing attackshttps://t.co/aIc8c4YdlE
— Dr. Dan Lomas (@Sandbagger_01) December 22, 2023