The Osint Cyber War 2023-05-29
The Osint Cyber War 2023-05-29
The Osint Cyber War 2023-05-29
Summary
Internet Storm Center Infocon Status
The intent of the 'Infocon' is to reflect changes in malicious traffic and the possibility of
disrupted connectivity. In particular important is the concept of "Change". Every host
connected to the Internet is subject to some amount of traffic caused by worms and viruses.
Interesting News
* Free Cyberforensics Training - CSI Linux Basics
Download the distro and take the course to learn what CSI Linux can add to your arsenal. This include a case
management solution, document templates (reports and legal docs), and more GUI options for gathering digital evidence
while storing it to the ongoing case.
https://training.csilinux.com/course/view.php?id=5
* * Our active Facebook group discusses the gambit of cyber security issues. Join the Cyber Secrets Facebook group here.
Index of Sections
Current News
* Packet Storm Security
* Krebs on Security
* Dark Reading
* The Hacker News
* Security Week
* Infosecurity Magazine
* KnowBe4 Security Awareness Training Blog
* ISC2.org Blog
* HackRead
* Koddos
* Naked Security
* Threat Post
* Null-Byte
* IBM Security Intelligence
* Threat Post
* C4ISRNET - Media for the Intelligence Age Military
The Hacker Corner:
* Security Conferences
* Google Zero Day Project
Cyber Range Content
* CTF Times Capture the Flag Event List
* Vulnhub
Tools & Techniques
* Packet Storm Security Latest Published Tools
* Kali Linux Tutorials
* GBHackers Analysis
InfoSec Media for the Week
* Black Hat Conference Videos
* Defcon Conference Videos
* Hak5 Videos
* Eli the Computer Guy Videos
* Security Now Videos
* Troy Hunt Weekly
* Intel Techniques: The Privacy, Security, & OSINT Show
Exploits and Proof of Concepts
* Packet Storm Security Latest Published Exploits
* CXSecurity Latest Published Exploits
* Exploit Database Releases
Cyber Crime & Malware Files/Links Latest Identified
* CyberCrime-Tracker
Advisories
* Hacked Websites
* Dark Web News
* US-Cert (Current Activity-Alerts-Bulletins)
* Zero Day Initiative Advisories
* Packet Storm Security's Latest List
Information Warfare Center Products
* CSI Linux
* Cyber Secrets Videos & Resoures
* Information Warfare Center Print & eBook Publications
Packet Storm Security
Krebs on Security
* New BrutePrint Attack Lets Attackers Unlock Smartphones with Fingerprint Brute-Force
* AceCryptor: Cybercriminals' Powerful Weapon, Detected in 240K+ Attacks
* 3 Challenges in Building a Continuous Threat Exposure Management (CTEM) Program and How to Beat
Them
* New GobRAT Remote Access Trojan Targeting Linux Routers in Japan
* Don't Click That ZIP File! Phishers Weaponizing .ZIP Domains to Trick Victims
* PyPI Implements Mandatory Two-Factor Authentication for Project Owners
* New Stealthy Bandit Stealer Targeting Web Browsers and Cryptocurrency Wallets
* Critical OAuth Vulnerability in Expo Framework Allows Account Hijacking
* Severe Flaw in Google Cloud's Cloud SQL Service Exposed Confidential Data
* Predator Android Spyware: Researchers Uncover New Data Theft Capabilities
* 5 Must-Know Facts about 5G Network Security and Its Cloud Benefits
* New COSMICENERGY Malware Exploits ICS Protocol to Sabotage Power Grids
* Barracuda Warns of Zero-Day Exploited to Breach Email Security Gateway Appliances
* Dark Frost Botnet Launches Devastating DDoS Attacks on Gaming Industry
* Zyxel Issues Critical Security Patches for Firewall and VPN Products
Security Week
Infosecurity Magazine
KnowBe4 Security Awareness Training Blog RSS Feed
* [Mastering Minds] China's Cognitive Warfare Ambitions Are Social Engineering At Scale
* Your KnowBe4 Fresh Content Updates from May 2023
* Verizon Sends New Smishing Warning
* [SEG Headache] More Than Half of Cybersecurity Leaders Say That Too Many Phishing Attacks Get
Through
* Financial Fraud Phishing Attacks Increase 72% In One Year; Financial Industry Takes the Brunt
* BatLoader Malware is Now Distributed in Drive-By Attacks
* More Than Half of all Email-Based Cyberattacks Bypass Legacy Security Filters
* [Hands-On Defense] Unpatched Software Causes 33% of Successful Attacks
* CyberheistNews Vol 13 #21 [Double Trouble] 78% of Ransomware Victims Face Multiple Extortions in Scar
* [Microsoft Warning] A 38% Spike In Business Email Compromise with new Cybercrime-as-a-Service
ISC2.org Blog
Unfortunately, at the time of this report, the ISC2 Blog resource was not availible.
HackRead
Koddos
Threat Post
Null-Byte
InfoWorld
* Unmanned program could suffer if Congress blocks F-22 retirements, Hunter says
* UK to test Sierra Nevada's high-flying spy balloons
* Babcock inks deals to pitch Israeli tech for British radar, air defense programs
* This infantry squad vehicle is getting a laser to destroy drones
* As Ukraine highlights value of killer drones, Marine Corps wants more
* Army Space, Cyber and Special Operations commands form 'triad' to strike anywhere, anytime
* Shell companies purchase radioactive materials, prompting push for nuclear licensing reform
* Marine regiment shows off capabilities at RIMPAC ahead of fall experimentation blitz
* Maxar to aid L3Harris in tracking missiles from space
* US Army's 'Lethality Task Force' looks to save lives with AI
The Hacker Corner
Conferences
CTF Time has links to a lot of current Capture the Flag competitions and information on past events. Below is
a list if CTFs they have on thier calendar.
* BxMCTF 2023
* DanteCTF 2023
* CyberSci Nationals 2023
* Break the Syntax CTF 2023
* justCTF 2023
* PwnMe Finals : "8 bits"
* HSCTF 10
* Ugra CTF Open 2023
* Season III: US Cyber Open CTF
* GPN CTF 2023
VulnHub Downloadable CTFs for your Cyber Range (Most use VirtualBox)
* Matrix-Breakout: 2 Morpheus
* Web Machine: (N7)
* The Planets: Earth
* Jangow: 1.0.1
* Red: 1
Tools & Techniques
Packet Storm Security Tools Links
GBHackers Analysis
Defcon Conference
* DEF CON 30 - Cesare Pizzi - Old Malware, New tools: Ghidra and Commodore 64
* DEF CON 30 BiC Village - Segun Olaniyan- Growth Systems for Cybersecurity Enthusiasts
* DEF CON 30 - Silk - DEF CON Memorial Interview
* DEF CON 30 Car Hacking Village - Evadsnibor - Getting Naughty on CAN bus with CHV Badge
Hak5
Security Now
* VCaaS - Voice Cloning as a Service - HP printer update, KeePass vulnerability, SpinRite bug
* Location Tracker Behavior - Diving deep into Google and Apple's tracker spec, SpinRite update
Troy Hunt
* 298-OSINT Maintenance
* 297-KYC, 2FA, macOS, & OSINT Updates
Proof of Concept (PoC) & Exploits
Packet Storm Security
CXSecurity
Kali has the Exploit-DB preinstalled and updates the database on a monthly basis. The tool that they have
added is called "SearchSploit". This can be installed on Linux, Mac, and Windows. Using the tool is also quite
simple. In the command line, type:
There is a second tool that uses searchsploit and a few other resources writen by 1N3 called "FindSploit". It is
also a command line (CLI) tool used to search for exploits, but it also requires online access.
Latest Hacked Websites
Published on Zone-h.org
http://ati.prefeitura.sp.gov.br
http://ati.prefeitura.sp.gov.br notified by nel00d
https://xpat-egov-mv.com
https://xpat-egov-mv.com notified by nel00d
http://metadata42.defensoria-nsjp.gob.mx
http://metadata42.defensoria-nsjp.gob.mx notified by Simsimi
http://metadata41.defensoria-nsjp.gob.mx
http://metadata41.defensoria-nsjp.gob.mx notified by Simsimi
http://metadata40.defensoria-nsjp.gob.mx
http://metadata40.defensoria-nsjp.gob.mx notified by Simsimi
http://metadata39.defensoria-nsjp.gob.mx
http://metadata39.defensoria-nsjp.gob.mx notified by Simsimi
http://metadata38.defensoria-nsjp.gob.mx
http://metadata38.defensoria-nsjp.gob.mx notified by Simsimi
http://metadata37.defensoria-nsjp.gob.mx
http://metadata37.defensoria-nsjp.gob.mx notified by Simsimi
http://metadata36.defensoria-nsjp.gob.mx
http://metadata36.defensoria-nsjp.gob.mx notified by Simsimi
http://metadata35.defensoria-nsjp.gob.mx
http://metadata35.defensoria-nsjp.gob.mx notified by Simsimi
http://metadata34.defensoria-nsjp.gob.mx
http://metadata34.defensoria-nsjp.gob.mx notified by Simsimi
http://metadata33.defensoria-nsjp.gob.mx
http://metadata33.defensoria-nsjp.gob.mx notified by Simsimi
http://metadata33.eastus.cloudapp.azure.com
http://metadata33.eastus.cloudapp.azure.com notified by Simsimi
http://www.machadinho.ro.gov.br/vz.txt
http://www.machadinho.ro.gov.br/vz.txt notified by aDriv4
http://www.coronavirus.apodaca.gob.mx/vz.txt
http://www.coronavirus.apodaca.gob.mx/vz.txt notified by aDriv4
http://tramites.apodaca.gob.mx/vz.txt
http://tramites.apodaca.gob.mx/vz.txt notified by aDriv4
http://tys.apodaca.gob.mx/vz.txt
http://tys.apodaca.gob.mx/vz.txt notified by aDriv4
Dark Web News
Darknet Live
RiskIQ
* Skimming for Sale: Commodity Skimming and Magecart Trends in Q1 2022
* RiskIQ Threat Intelligence Roundup: Phishing, Botnets, and Hijacked Infrastructure
* RiskIQ Threat Intelligence Roundup: Trickbot, Magecart, and More Fake Sites Targeting Ukraine
* RiskIQ Threat Intelligence Roundup: Campaigns Targeting Ukraine and Global Malware Infrastructure
* RiskIQ Threat Intelligence Supercharges Microsoft Threat Detection and Response
* RiskIQ Intelligence Roundup: Spoofed Sites and Surprising Infrastructure Connections
* RiskIQ Threat Intelligence Roundup: QBot, Magecart, Agent Tesla Headline Hijacked Infrastructure 
* RiskIQ Threat Intelligence Roundup: C2 and Nation-State Threat Infrastructure
* Jupyter Notebooks Make RiskIQ Data a Digital 'Mech Suit' for Threat Intelligence Analysts
* "Offshore" Shinjiru Provides Bulletproof Services to Cyberattackers
FireEye
* Fetch Payloads: A Shorter Path from Command Injection to Metasploit Session
* Healthcare Orgs: Do You Need an Outsourced SOC?
* VeloCON 2023: Submissions Wanted!
* Casting a Light on Shadow IT in Cloud Environments
* Metasploit Weekly Wrap-Up
* Introducing: 'Saved Filters' in InsightCloudSec
* Rapid7 Recognized as a Strong Performer in The Forrester Waveâ„¢ for MDR, Q2 2023
* CVE-2023-27350: Ongoing Exploitation of PaperCut Remote Code Execution Vulnerability
* Metasploit Wrap-up
* [The Lost Bots] S03E03. The Rise of The Machines
Advisories
US-Cert Alerts & bulletins
ZDI-CAN-21246: Adobe
A CVSS score 3.3 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) severity vulnerability discovered by 'Mat Powell of
Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2023-05-26, 3 days ago. The vendor is
given until 2023-09-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-21244: Adobe
A CVSS score 3.3 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) severity vulnerability discovered by 'Mat Powell of
Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2023-05-26, 3 days ago. The vendor is
given until 2023-09-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-21241: Adobe
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Mat Powell of
Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2023-05-26, 3 days ago. The vendor is
given until 2023-09-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-21243: Adobe
A CVSS score 3.3 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) severity vulnerability discovered by 'Mat Powell of
Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2023-05-26, 3 days ago. The vendor is
given until 2023-09-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-21242: Adobe
A CVSS score 3.3 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) severity vulnerability discovered by 'Mat Powell of
Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2023-05-26, 3 days ago. The vendor is
given until 2023-09-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-21245: Adobe
A CVSS score 3.3 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) severity vulnerability discovered by 'Mat Powell of
Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2023-05-26, 3 days ago. The vendor is
given until 2023-09-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-21240: Adobe
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Mat Powell of
Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2023-05-26, 3 days ago. The vendor is
given until 2023-09-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-21256: Foxit
A CVSS score 3.3 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) severity vulnerability discovered by 'Mat Powell of
Trend Micro Zero Day Initiative' was reported to the affected vendor on: 2023-05-26, 3 days ago. The vendor is
given until 2023-09-23 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-21118: Adobe
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Mark Vincent
Yason (@MarkYason)' was reported to the affected vendor on: 2023-05-24, 5 days ago. The vendor is given
until 2023-09-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-21122: Adobe
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Mark Vincent
Yason (@MarkYason)' was reported to the affected vendor on: 2023-05-24, 5 days ago. The vendor is given
until 2023-09-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-21063: Adobe
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Anonymous'
was reported to the affected vendor on: 2023-05-24, 5 days ago. The vendor is given until 2023-09-21 to
publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a
public advisory.
ZDI-CAN-21103: Adobe
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Mark Vincent
Yason (@MarkYason)' was reported to the affected vendor on: 2023-05-24, 5 days ago. The vendor is given
until 2023-09-21 to publish a fix or workaround. Once the vendor has created and tested a patch we will
coordinate the release of a public advisory.
ZDI-CAN-20977: Microsoft
A CVSS score 8.8 (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) severity vulnerability discovered by 'Anonymous'
was reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to
publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a
public advisory.
ZDI-CAN-21023: Foxit
A CVSS score 3.3 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N) severity vulnerability discovered by 'Anonymous'
was reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to
publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a
public advisory.
ZDI-CAN-20989: Microsoft
A CVSS score 6.4 (AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:H) severity vulnerability discovered by 'Anonymous'
was reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to
publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a
public advisory.
ZDI-CAN-21166: PDF-XChange
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Anonymous'
was reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to
publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a
public advisory.
ZDI-CAN-21060: Siemens
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Simon Janz
(@esj4y)' was reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until
2023-09-20 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate
the release of a public advisory.
ZDI-CAN-21051: Siemens
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Anonymous'
was reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to
publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a
public advisory.
ZDI-CAN-21225: Softing
A CVSS score 7.2 (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Pan ZhenPeng
(@Peterpan0927) & Li JianTao (@CurseRed) of STAR Labs SG Pte. Ltd. (@starlabs_sg)' was reported to the
affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to publish a fix or
workaround. Once the vendor has created and tested a patch we will coordinate the release of a public
advisory.
ZDI-CAN-21167: Apple
A CVSS score 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Anonymous'
was reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to
publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a
public advisory.
ZDI-CAN-21121: Fuji Electric
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'kimiya' was
reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to publish a
fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public
advisory.
ZDI-CAN-21041: Siemens
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Anonymous'
was reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to
publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a
public advisory.
ZDI-CAN-21054: Siemens
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'Anonymous'
was reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to
publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a
public advisory.
ZDI-CAN-20573: Kofax
A CVSS score 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) severity vulnerability discovered by 'rgod' was
reported to the affected vendor on: 2023-05-23, 6 days ago. The vendor is given until 2023-09-20 to publish a
fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public
advisory.
Packet Storm Security - Latest Advisories
The Cyber Weekl Awareness Report (WAR) is an Open Source Intelligence (AKA OSINT) resource centering
around an array of subjects ranging from Exploits, Advanced Persistent Threat, National Infrastructure, Dark
Web, Digital Forensics & Incident Response (DIFR), and the gambit of digital dangers.
Items that focus on cyber defense and DFIR usually spotlight capabilities in the CSI Linux environment. If
interested in helping evolve, please let us know. The Cyber Secrets publications rotates between odd quarters
issues focusing on Blue Team and the even issues on Red Team.