March 14, 2021 at 12:06AM

■■■■□ 15-year-old Linux kernel bugs let attackers gain root privileges. CVE-2021-27365: heap buffer overflow (Local Privilege Escalation, Information Leak, Denial of Service) CVE-2021-27363: kernel pointer leak (Information Leak) CVE-2021-27364: out-of-bounds read (Information Leak, Denial of Service) https://www.bleepingcomputer.com/news/security/15-year-old-linux-kernel-bugs-let-attackers-gain-root-privileges/ #Zeroday #0day https://t.me/cKure/7168

March 13, 2021 at 10:42PM

■■■□□ MS Exchange pre-auth RCE, Burp Crawler demystified & SSO security thesis. https://blog.intigriti.com/2021/03/10/bug-bytes-113-ms-exchange-pre-auth-rce-burp-crawler-demystified-sso-security-thesis/ https://t.me/cKure/7164

March 13, 2021 at 01:39PM

■■■■■ Google has released proof-of-concept code for conducting a Spectre-based attack against its Chrome browser to show how web developers can take steps to mitigate browser-based side-channel attacks. Exploit Code repo: https://github.com/google/security-research-pocs/tree/master/spectre.js https://www.theregister.com/2021/03/12/google_spectre_code/ https://t.me/cKure/7161

March 13, 2021 at 01:16PM

■■■■□ Another Google Chrome 0-Day Bug Found Actively Exploited In-the-Wild. https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop_12.html https://thehackernews.com/2021/03/another-google-chrome-0-day-bug-found.html #0day #Zeroday https://t.me/cKure/7160

March 13, 2021 at 01:12PM

■□□□□ #Israel based insurance company Shirbit suffered a #DataLeak last year (Q4 2020) and now the threat actors have given final warning and threatened to leak all data. https://t.me/cKure/7159

March 13, 2021 at 12:12AM

■■□□□ #Dridex spotted in #Poland . f67aaddc196878449d515e0c337828d8 Payload delivered from: /shahu66.com/rc62n0.rar c2: 162.241.44.26:9443 192.232.229.53:4443 77.220.64.34:443 193.90.12.121:3098 Source: https://mobile.twitter.com/pmmkowalczyk https://t.me/cKure/7158