March 3, 2023
“The Russians had a common crook, a thug, on their hands with an Estonian passport,” Alexander Toots, the deputy director of the Kapo, told Yahoo News. “This was too good an opportunity to pass up. So when they caught Danilov, they beat statements out of him, got him to say he was working for us. Then they tucked this ‘confession’ away for a rainy day, for when they wanted to pretend they caught a foreign agent. The FSB likes to scam their leadership and wider audience with these fake ‘spy cases’ to show they have domestic security under control. In this instance, however, they were too lazy to know or care that the guy they framed was currently sitting in our prison.”
-
Biden cybersecurity strategy document is out.
https://www.whitehouse.gov/briefing-room/statements-releases/2023/03/02/fact-sheet-biden-harris-administration-announces-national-cybersecurity-strategy/-
Redirection Roulette: Thousands of hijacked websites in East Asia redirecting visitors to other sites
Extensive network of malicious redirects that… seems to be adware/malvertising or something else financial
https://www.wiz.io/blog/redirection-roulette-
Operation HORIZON: A KGB Counterintelligence Operation against the West
https://www.wilsoncenter.org/blog-post/operation-horizon-kgb-counterintelligence-operation-against-west-
But what exactly is it, and why has panic grown about this group?-
-
-
-
-
-
Accessing the RAM of a QEMU Emulated System from another Process
$ qemu -M pc -nographic -m 512m \
-object memory-backend-file,id=pc.ram,size=512M,mem-path=/dev/shm/qemu-ram,share=on \
-machine memory-backend=pc.ram \
-smp cpus=2 -kernel ./bzImage_5.9 -drive file=./rootfs-target.img,if=ide -append "console=ttyS0 root=/dev/sda rw panic=1 earlyprintk=serial,ttyS0,115200"
This command will make the RAM available via the /dev/sim/qemu-ram file. Open it and mmap() it and you can RW the qemu RAM directly. Nice!
https://blog.reds.ch/?p=1379-