PaPPy's Avatar

PaPPy

@pappy.bsky.social

All around go to guy. Enjoy video games and cyber security

92 Followers  |  40 Following  |  25 Posts  |  Joined: 05.05.2023  |  2.0664

Latest posts by pappy.bsky.social on Bluesky

Google pushing out .zip as a TLD and then divesting their registrar business is the equivalent on pooping in the punch bowl as you leave a party

https://9to5google.com/2023/06/15/google-domains-squarespace/

15.06.2023 22:08 β€” πŸ‘ 11    πŸ” 6    πŸ’¬ 1    πŸ“Œ 2
Preview
Chinese hackers used VMware ESXi zero-day to backdoor VMs VMware patched today a VMware ESXi zero-day vulnerability exploited by a Chinese-sponsored hacking group to backdoor Windows and Linux virtual machines and steal data.

https://www.bleepingcomputer.com/news/security/chinese-hackers-used-vmware-esxi-zero-day-to-backdoor-vms/

13.06.2023 23:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Malvertising via brand impersonation is back again Ads containing the official website of an impersonated brand are running again, allowing fraudsters to scam users.

Great article on recent malvertising https://www.malwarebytes.com/blog/threat-intelligence/2023/05/malvertising-its-a-jungle-out-there

23.05.2023 15:35 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Onodo

Really cool initial access and malware graph https://onodo.org/visualizations/235067

13.05.2023 00:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@support.bsky.team how are the weekly invites granted? As I’m a week and an hour into this account and I do not have any invites. Thanks!

12.05.2023 15:23 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

It was trivial to come up with a POC for #CVE-2023-32243 thanks to @patchstackapp detailed write up. Already seeing it abused in the wild. #wordpress owners need to upgrade Essential Addons for Elementor plugin now and check for signs of intrusion.

12.05.2023 03:47 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
WordPress Elementor plugin bug let attackers hijack accounts on 1M sites One of WordPress's most popular Elementor plugins, "Essential Addons for Elementor," was found to be vulnerable to an unauthenticated privilege escalation that could allow remote attacks to gain administrator rights on the site.

This will lead to a lot of hacked WordPress sites I wonder if any of the link pits are running this plugin https://www.bleepingcomputer.com/news/security/wordpress-elementor-plugin-bug-let-attackers-hijack-accounts-on-1m-sites/

11.05.2023 17:23 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
eSentire Threat Intelligence Malware Analysis: Vidar Stealer Dive deeper into the technical details gathered during eSentire’s Threat Response Unit (TRU) team’s research and threat analysis of the Vidar Stealer malware.

Great research on the Vidar Stealer https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-vidar-stealer

11.05.2023 17:19 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Fake in-browser Windows updates push Aurora info-stealer malware A recently spotted malvertising campaign tricked users with an in-browser Windows update simulation to deliver the Aurora information stealing malware.

https://www.bleepingcomputer.com/news/security/fake-in-browser-windows-updates-push-aurora-info-stealer-malware/

11.05.2023 00:22 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
New Linux kernel NetFilter flaw gives attackers root privileges A new Linux NetFilter kernel flaw has been discovered, allowing unprivileged local users to escalate their privileges to root level, allowing complete control over a system.

Looking forward to seeing the POC on Monday for this LPE on Linux https://www.bleepingcomputer.com/news/security/new-linux-kernel-netfilter-flaw-gives-attackers-root-privileges/

10.05.2023 19:47 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Note that the update for CVE-2023-24932 does NOT actually fix anything. It gives you the option of applying the fix yourself. Read through ALL of https://tinyurl.com/mprmsext if you want to consider applying the protection. Feel free to cry a bit and/or consider a career change.

09.05.2023 19:15 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Spanish police dismantle phishing operation linked to crime ring The National Police of Spain have arrested two hackers, 15 members of a criminal organization, and another 23 people involved in illegal financial operations in Madrid and Seville for alleged bank scams.

Great work by the spanish police https://www.bleepingcomputer.com/news/security/spanish-police-dismantle-phishing-operation-linked-to-crime-ring/

09.05.2023 21:32 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Feds seize 13 more DDoS-for-hire platforms in ongoing international crackdown The DDoS whack-a-mole game between law enforcement and miscreants continues.

Great work taking down DDoS services https://arstechnica.com/information-technology/2023/05/feds-seize-13-more-ddos-for-hire-platforms-in-ongoing-international-crackdown/

09.05.2023 15:42 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Hunting Russian Intelligence β€œSnake” Malware | CISA

Nice article from CISA https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a

09.05.2023 15:16 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

7

09.05.2023 15:02 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
NextGen Healthcare says hackers accessed personal data of more than 1 million patients NextGen Healthcare has admitted to a data breach that saw hackers access the personal data of more than 1 million patients

Ouch https://techcrunch.com/2023/05/08/nextgen-healthcare-data-breach/

09.05.2023 00:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

That’s pretty funny #Microsoft #clippy

08.05.2023 21:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Reddit - Dive into anything

Seems legit… https://www.reddit.com/r/techsupport/comments/9gwwcj/windowsdefendervbs_on_cuserspubliclibraries_is/

08.05.2023 15:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Kenya is turning to spyware, again; African SIM cards and identities; Nigerian telcos want to be excluded from data regulation and more infosec stories from across Africa.

https://cybafrique.substack.com/p/kenya-is-turning-to-spyware-again

08.05.2023 03:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Massive malvertising campaign targets seniors via fake Weebly sites Scammers are buying ads on for the most common Google searches made by seniors and defrauding them with tech support scams.

Please educate y’all’s older folks https://www.malwarebytes.com/blog/threat-intelligence/2023/04/massive-malvertising-campaign-targets-seniors-via-fake-weebly-sites

07.05.2023 03:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
San Bernardino County pays $1.1M ransom after cyberattack disrupts Sheriff's Department systems The hackers encrypted San Bernardino County Sheriff's Department data, causing significant disruptions to operations.

https://abc7.com/san-bernardino-cyberattack-ransom-paid-hackers/13215833/

06.05.2023 14:44 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Stuff like this and the satellite network keep me up and employed https://www.darkreading.com/ics-ot/2-years-after-colonial-pipeline-attack-us-critical-infrastructure-remains-as-vulnerable-to-ransomware

06.05.2023 02:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Lol

05.05.2023 18:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Great post on bad practices in cyber security from CISA https://www.cisa.gov/news-events/news/bad-practices-0

05.05.2023 16:44 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If people haven’t upgraded their Papercut software now, this seems pretty bad https://thehackernews.com/2023/05/researchers-uncover-new-exploit-for.html

05.05.2023 15:23 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

What prevents this individual from just starting a new domain and running the same business again? #infosec https://krebsonsecurity.com/2023/05/10m-is-yours-if-you-can-get-this-guy-to-leave-russia/

05.05.2023 15:19 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Hello World! Happy to be here on #BlueSky instead of the dumpster fire!

05.05.2023 15:11 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@pappy is following 20 prominent accounts