Abusing mhyprotect to kill AVs / EDRs / XDRs / Protected Processes. https://github.com/zer0condition/mhydeath
Hashed and rehashed a tale of Goodware hashes https://dansec.medium.com/hashed-and-rehashed-a-tale-of-goodware-hashes-61da19c65528
Finding Deserialization Bugs in the Solarwind Platform https://www.zerodayinitiative.com/blog/2023/9/21/finding-deserialization-bugs-in-the-solarwind-platform
Bypassing UAC with SSPI Datagram Contexts https://splintercod3.blogspot.com/p/bypassing-uac-with-sspi-datagram.html?m=1
Nidhogg is an all-in-one simple to use rootkit for red teams. https://github.com/Idov31/Nidhogg/tree/dev
Modern Asian APT groups’ tactics, techniques and procedures (TTPs) https://securelist.com/modern-asia-apt-groups-ttp/111009/
Typical vulnerabilities in Proof of Stake protocols https://blog.decurity.io/typical-vulnerabilities-in-lsd-protocols-e52ffe4ee175
How Hackers Hide From Memory Scanners https://youtu.be/WYuhJzngfVc?si=KYvedCuIOsItE7sc
Process Injection - Avoiding Kernel Triggered Memory Scans https://www.r-tec.net/r-tec-blog-process-injection-avoiding-kernel-triggered-memory-scans.html
Netsupport Intrusion Results in Domain Compromise https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/
AI Exploits https://github.com/protectai/ai-exploits
Hypervisor Detection with SystemHypervisorDetailInformation https://medium.com/@matterpreter/hypervisor-detection-with-systemhypervisordetailinformation-26e44a57f80e
“MrTonyScam” — Botnet of Facebook Users Launch High-Intent Messenger Phishing Attack on Business Accounts https://labs.guard.io/mrtonyscam-botnet-of-facebook-users-launch-high-intent-messenger-phishing-attack-on-business-3182cfb12f4d
ShellTorch: Multiple Critical Vulnerabilities in PyTorch Model Server (TorchServe) (CVSS 9.9, CVSS 9.8) Threatens Countless AI Users - Immediate Action Required https://www.oligo.security/blog/shelltorch-torchserve-ssrf-vulnerability-cve-2023-43654
Defender Pretender: When Windows Defender Updates Become a Security Risk https://www.safebreach.com/blog/defender-pretender-when-windows-defender-updates-become-a-security-risk/
Chinese hackers have unleashed a never-before-seen Linux backdoor https://arstechnica.com/security/2023/09/never-before-seen-linux-backdoor-is-a-windows-malware-knockoff/
Persistence – Scheduled Task Tampering https://pentestlab.blog/2023/11/20/persistence-scheduled-task-tampering/
Reptar: an Intel Ice Lake CPU vulnerability, by Tavis Ormandy https://lock.cmpxchg8b.com/reptar.html
Process Injection - Avoiding Kernel Triggered Memory Scans https://www.r-tec.net/r-tec-blog-process-injection-avoiding-kernel-triggered-memory-scans.html
Court rules automakers can record and intercept owner text messages https://therecord.media/class-action-lawsuit-cars-text-messages-privacy