Talk With an Expert

Internet Storm Center Tech Corner

Bypassing PowerShell Strong Obfuscation

https://isc.sans.edu/diary/Bypassing+PowerShell+Strong+Obfuscation/29692

Network Data Collector Placement Makes a Difference

https://isc.sans.edu/diary/Network+Data+Collector+Placement+Makes+a+Difference/29664

Extracting Multiple Streams From OLE Files

https://isc.sans.edu/diary/Extracting+Multiple+Streams+From+OLE+Files/29688

Malicious 3CX Dekstop App Update

https://www.youtube.com/watch?v=cCf3Km_j5bY (livestream/recording)

https://www.3cx.com/blog/news/desktopapp-security-alert/

https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/

https://objective-see.org/blog/blog_0x73.html

https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/

3CXDesktop App Compromise

https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/

Microsoft Defender False Positives

https://twitter.com/MSFT365Status/status/1641048649525260289

https://admin.microsoft.com/Adminportal/Home?ref=/servicehealth/:/alerts/DZ534539 (requires login)

Active Exploitation of IBM Aspera Faspex CVE-2022-47986

https://www.rapid7.com/blog/post/2023/03/28/etr-active-exploitation-of-ibm-aspera-faspex-cve-2022-47986/

QNAP Patch for sudo vulnerability

https://www.qnap.com/en/security-advisory/qsa-23-11

Throttling and Blocking Email from Persistently Vulnerable Exchange Servers to Exchange Online

https://techcommunity.microsoft.com/t5/exchange-team-blog/throttling-and-blocking-email-from-persistently-vulnerable/ba-p/3762078

Bypassing Wi-Fi Encryption by Manipulating Transmit Queues

https://papers.mathyvanhoef.com/usenix2023-wifi.pdf

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive