February 19, 2024
February 19, 2024
#threatintel
— 安坂星海 Azaka 🐼 VTuber (@AzakaSekai_) February 18, 2024
someone just leaked a bunch of internal Chinese government documents on GitHubhttps://t.co/BO8N64A7kF
Thread by @AzakaSekai_ on Thread Reader App – Thread Reader App
@AzakaSekai_: #threatintel someone just leaked a bunch of internal Chinese government documents on GitHub github.com/I-S00N/I-S00N/ From the looks of it, it looks like a bunch of spyware developed by the company 安洵信...…
Still: "#threathunting I'm currently doing a writeup on …" - Infosec Exchange
#threathunting I'm currently doing a writeup on the I-S00N Chinese government spyware data leak in real time over on the bird site. Buckle up there are a lot of juicy information. https://twitter.com/AzakaSekai_/status/1759326049262019025
GitHub - I-S00N/I-S00N
Contribute to I-S00N/I-S00N development by creating an account on GitHub.
Others:
1 My thoughts on the Chinese APT contractor leak 🇨🇳
— ✞ inversecos🩸 (@inversecos) February 19, 2024
Specifically, I want to talk about the leaked
- iOS Spyware
- Physical implantable devices
- Email surveillance system
Let's consider detection and how these would be installed. https://t.co/n5XGSp8veR
Thread by @inversecos on Thread Reader App – Thread Reader App
@inversecos: 1 My thoughts on the Chinese APT contractor leak 🇨🇳 Specifically, I want to talk about the leaked - iOS Spyware - Physical implantable devices - Email surveillance system Let's consider detection and h...…
This leak is interesting...
— mRr3b00t (@UK_Daniel_Card) February 19, 2024
also...
i-Soonhttps://t.co/xYOmAFDAyD https://t.co/1Bxu4h0mvw pic.twitter.com/5c0pswGcok
This July marks the 30th year anniversary of the publication of my PhD thesis on Reverse Compilation Techniques. In 1994, little did I know the impact this pioneering work would have on the security community that grew up in the 2000s. 🎉 Celebration events to be announced!
— Cristina Cifuentes (@criscifuentes) February 18, 2024
Ultimately, Starship Troopers fails as a parody because I personally identify with the thoughts and actions of all the characters the movie seems to be satirizing, and that can’t be right
— Fairy Gothmother, MD (@jenny2x4) February 18, 2024
Tools to search for people's contacts (free or trial free):https://t.co/tehgFwUF01https://t.co/AnDNX0CFBVhttps://t.co/PjmGFXOPPohttps://t.co/j29sITxSQEhttps://t.co/0gX9XkejU8https://t.co/d4H6YvAcRChttps://t.co/QewPJ7p9g6https://t.co/nd4d3VHtSmhttps://t.co/SONsxF5WvX pic.twitter.com/cWbwP3XQrd
— Cyber Detective💙💛 (@cyb_detective) February 18, 2024
⚠️ Update for CVE-2024-21413 💣
— Alex (@xaitax) February 18, 2024
Managed & confirmed Microsoft Outlook Remote Code Execution (RCE) but won't publish details (yet). pic.twitter.com/AdxMXgZIVa
Seems that folks successfully achieved working RCE w/ a previous RTF/Win exploit! This is expected as #MonikerLink is a powerful attack vector (delivering exp) on Outlook - it bypasses Protected View too!
— Haifei Li (@HaifeiLi) February 18, 2024
Now u have more reasons to PATCH & GET PROTECTED!https://t.co/esPv5KUJpd
Blog posts series on pwning the D-Link DIR-865L
— 0xor0ne (@0xor0ne) February 18, 2024
Credits @Coiffeur0x90
Remote Code Execution (pre-auth):https://t.co/Lbsif1Dvaf
Unsigned firmware upload:https://t.co/6v9TbblPGB
Memory corruptions:https://t.co/7obgalU13U#embedded #infosec pic.twitter.com/pop5h4FI3n
https://t.co/zLaTbRbzDv
— Cyber Detective💙💛 (@cyb_detective) February 18, 2024
Leaked databases search tool.
14 billion accounts + (emails and passwords)
Check yourself
Tip by @ManuelBot59 #ff#osint #leaks pic.twitter.com/TcHfjYIYr7
He's got a point :P pic.twitter.com/HjoDAsvBij
— Sos 🔜 DevGamm 🔜 GDC (@Sosowski) February 18, 2024
Forgotten moments in history: Count von Count's many contributions in WWII. It starts in 1939, as the then-known Contele von Compte, already well known for his math contributions to set construction, fearing the Molotov–Ribbentrop Pact's consequences, fled Romania by train. pic.twitter.com/5KWavqDzFL
— kaszeta (@kaszeta) February 17, 2024
1/11
— Cathal Mc Daid (@mcdaidc) February 15, 2024
Today, we’re releasing details of a small but interesting mobile #vulnerability called MMS Fingerprint, reportedly used by #NSOGroup.
How this might work, and how we found it, is a bit unusual.https://t.co/Lvg85E6IAF@EneaAB @josephfcox @rj_gallagher @campuscodi @lorenzofb
Thread by @mcdaidc on Thread Reader App â Thread Reader App
@mcdaidc: 1/11 Today, weâre releasing details of a small but interesting mobile #vulnerability called MMS Fingerprint, reportedly used by #NSOGroup. How this might work, and how we found it, is a bit unusual. @EneaAB...â¦
why don't linux, windows and Apple Mac's alert you in the gui (if you are logged in) if someone fails to sign in to an remote session? e.g. RDP, SSH, WINRM, SMB etc?
— mRr3b00t (@UK_Daniel_Card) February 18, 2024
it would be so useful if they did this (tm)
I knocked this up, i'll update it later to include failed etc but it's a really good idea and i'm dropping it into my linux build for KNux. https://t.co/XJYp4UTqdr
— Chono N (@Gyarbij) February 19, 2024