βοΈ CyberWeekly 13' July | Issue #5
βοΈ Evernote RCE, Windows Remoting, CVE-2021-40444, MSHTML, Pentesting AD, Reverse engineering .NET, WGU, Global AppSec 2024 Lisbon, Universal RCE, False File Immutability, EvilnoVNC, STOK, Polyfill(.)io
π https://hacklido.substack.com/p/cyberweekly-13-july-issue-5
βοΈ Evernote RCE, Windows Remoting, CVE-2021-40444, MSHTML, Pentesting AD, Reverse engineering .NET, WGU, Global AppSec 2024 Lisbon, Universal RCE, False File Immutability, EvilnoVNC, STOK, Polyfill(.)io
π https://hacklido.substack.com/p/cyberweekly-13-july-issue-5
π₯2
π Key Ransomeware Threats In 2024
π https://hacklido.com/blog/877-key-ransomeware-threats-in-2024
π https://hacklido.com/blog/877-key-ransomeware-threats-in-2024
HACKLIDO
Key Ransomeware Threats In 2024
In June, we wrote about Akira β a ransomware group using double extortion techniques to coerce victims after stealing and encrypting their sensitive data....
π4
π Pentesting Active Directory - Part 7 | Abusing Misconfigured Templates (ESC1)
π https://hacklido.com/blog/882-pentesting-active-directory-part-7-abusing-misconfigured-templates-esc1
π https://hacklido.com/blog/882-pentesting-active-directory-part-7-abusing-misconfigured-templates-esc1
HACKLIDO
Pentesting Active Directory - Part 7 | Abusing Misconfigured Templates (ESC1)
Active Directory Certificate Services ADCS is used for managing public key infrastructure in an Active Directory environment. Itβs commonly used in enter...
π The Rise Of Ransomeware As A Service
π https://hacklido.com/blog/879-the-rise-of-ransomeware-as-a-service
π https://hacklido.com/blog/879-the-rise-of-ransomeware-as-a-service
HACKLIDO
The Rise Of Ransomeware As A Service
Ransomware as a Service (RaaS) platforms continue to emerge, causing a significant impact across industries and organisations. Theyβre enabling inexperien...
π Why You Should Implement Post-Quantum Security Now
π https://hacklido.com/blog/878-why-you-should-implement-post-quantum-security-now
π https://hacklido.com/blog/878-why-you-should-implement-post-quantum-security-now
HACKLIDO
Why You Should Implement Post-Quantum Security Now
For years, quantum computing has been a vision of the future. Itβs a technology that has been far away β a distant promise of computing power far beyond ou...
βοΈ CyberWeekly 20' July | Issue #6
βοΈ Crowdstrike outage, healthcare ransmoware, HIPPA, Oracle bulk patch updates, Snort IPS, Active Directory pentesting, CVE-2024-27956 - SQLi, CVE-2024-40626 - XSS (Stored), RAG manipulation attacks, etc
π https://hacklido.substack.com/p/cyberweekly-20-july-issue-6
βοΈ Crowdstrike outage, healthcare ransmoware, HIPPA, Oracle bulk patch updates, Snort IPS, Active Directory pentesting, CVE-2024-27956 - SQLi, CVE-2024-40626 - XSS (Stored), RAG manipulation attacks, etc
π https://hacklido.substack.com/p/cyberweekly-20-july-issue-6
β€1π1π₯1π1
π How Much Ransome Are Cybercriminals Asking For?
π https://hacklido.com/blog/881-how-much-ransome-are-cybercriminals-asking-for
π https://hacklido.com/blog/881-how-much-ransome-are-cybercriminals-asking-for
HACKLIDO
How Much Ransome Are Cybercriminals Asking For?
Weβre focused onβ¦ How much money threat actors are asking for when they execute ransomware attacks. Ransom sums can vary wildly At time of writing, the...
π Getting started with SOC: Setting an Elastic Home SIEM lab
π https://hacklido.com/blog/891-getting-started-with-soc-setting-an-elastic-home-siem-lab
π https://hacklido.com/blog/891-getting-started-with-soc-setting-an-elastic-home-siem-lab
HACKLIDO
Getting started with SOC: Setting an Elastic Home SIEM lab
If you want to pursue your career as an SOC analyst, you can get hand- off experience for free by setting up your own SIEM labs. Hereβs how I did it. What is...
π3π1
π The Unpatchable Exploit: How Checkra1n bypasses iCloud Activation Locks
π https://hacklido.com/blog/899-the-unpatchable-exploit-how-checkra1n-bypasses-icloud-activation-locks
π https://hacklido.com/blog/899-the-unpatchable-exploit-how-checkra1n-bypasses-icloud-activation-locks
HACKLIDO
The Unpatchable Exploit: How Checkra1n bypasses iCloud Activation Locks
The Checkra1n jailbreak has revolutionised the landscape of iOS jailbreaking and security research. Leveraging the powerful checkm8 bootrom exploit, Checkr...
β€1π1
π How To Talk About Cybersecurity To People Who Don't [YET] Care
π https://hacklido.com/blog/898-how-to-talk-about-cybersecurity-to-people-who-dont-yet-care
π https://hacklido.com/blog/898-how-to-talk-about-cybersecurity-to-people-who-dont-yet-care
HACKLIDO
How To Talk About Cybersecurity To People Who Don't [YET] Care
Weβre focused onβ¦ How to talk to people who donβt care about cybersecurity. Why? Because weβre rolling out a new series of blog posts on the BHMEA cont...
π Machine Learning In Cybersecurity
π https://hacklido.com/blog/888-machine-learning-in-cybersecurity
π https://hacklido.com/blog/888-machine-learning-in-cybersecurity
HACKLIDO
Machine Learning In Cybersecurity
The emerging field of machine learning (ML) is driving transformations across industries. But while weβre still in these relatively early stages of the int...
π1
π Strengths and weaknesses of the new UN cybercrime convention
π https://hacklido.com/blog/902-strengths-and-weaknesses-of-the-new-un-cybercrime-convention
π https://hacklido.com/blog/902-strengths-and-weaknesses-of-the-new-un-cybercrime-convention
HACKLIDO
Strengths and weaknesses of the new UN cybercrime convention
On 8 August 2024, the draft text of the UN Convention Against Cybercrime was finalised. This has real implications for cybersecurity standards and resilien...
π A basic overview of Hypervisor Implants
π https://hacklido.com/blog/907-a-basic-overview-of-hypervisor-implants
π https://hacklido.com/blog/907-a-basic-overview-of-hypervisor-implants
HACKLIDO
A basic overview of Hypervisor Implants
Hypervisors are pieces of software used to manage VMs (Virtual Machines) or Guest machines on a Host machine. The main difference between a hypervisor an...
π The UN convention on cybercrime: What does it mean for you?
π https://hacklido.com/blog/904-the-un-convention-on-cybercrime-what-does-it-mean-for-you
π https://hacklido.com/blog/904-the-un-convention-on-cybercrime-what-does-it-mean-for-you
HACKLIDO
The UN convention on cybercrime: What does it mean for you?
Weβre focused onβ¦ The new UN convention on cybercrime. Why? Because the draft text of the UN Convention Against Cybercrime was finalised on 8 August 20...
π How do we measure the success of the UN cybercrime convention?
π https://hacklido.com/blog/903-how-do-we-measure-the-success-of-the-un-cybercrime-convention
π https://hacklido.com/blog/903-how-do-we-measure-the-success-of-the-un-cybercrime-convention
HACKLIDO
How do we measure the success of the UN cybercrime convention?
When we asked Betania Allo (Founder and Principal Consultant, BA Cyber Law & Policy) to share her perspective on the new UN Convention Against Cybercr...
π Why Cybersecurity Proffessionals Should Study Psychology
π https://hacklido.com/blog/897-why-cybersecurity-proffessionals-should-study-psychology
π https://hacklido.com/blog/897-why-cybersecurity-proffessionals-should-study-psychology
HACKLIDO
Why Cybersecurity Proffessionals Should Study Psychology
Weβre focused onβ¦ Being OK with making mistakes and not having all the answers. Why? Because we interviewed BHMEA Advisory Board member Jason Lau (CIS...
β€1π1
π The Way I Used to Find RCE (Remote Code Execution) via File Upload
π https://hacklido.com/blog/914-the-way-i-used-to-find-rce-remote-code-execution-via-file-upload
π https://hacklido.com/blog/914-the-way-i-used-to-find-rce-remote-code-execution-via-file-upload
HACKLIDO
The Way I Used to Find RCE (Remote Code Execution) via File Upload
Hello, Hacklido community! This is my first article, and Iβm excited to share one of my most significant vulnerability discoveries: Remote Code Execution (RC...
β€1
π Why cyber poverty is a serious problem in 2024
π https://hacklido.com/blog/916-why-cyber-poverty-is-a-serious-problem-in-2024
π https://hacklido.com/blog/916-why-cyber-poverty-is-a-serious-problem-in-2024
HACKLIDO
Why cyber poverty is a serious problem in 2024
In 2023, upcoming Black Hat MEA speaker Ramy Houssaini (Chief Cyber & Technology Risk Officer, & Group Privacy Officer, at BNP Paribas) was one of...
π What can we learn from the Crowdstrike IT outage?
π https://hacklido.com/blog/909-what-can-we-learn-from-the-crowdstrike-it-outage
π https://hacklido.com/blog/909-what-can-we-learn-from-the-crowdstrike-it-outage
HACKLIDO
What can we learn from the Crowdstrike IT outage?
The Crowdstrike global IT outage caused widespread disruption, with critical industries put at risk as some of their services stalled. Now, weβre seeing la...