Handler on Duty: Didier Stevens
Threat Level: green
Podcast Detail
CinaRAT via HTML IDs; Protecting LSASS; Blocking Facebook Credential Exposure
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/7878.mp3
My Next Class
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |
Interested in Internet Storm Center stickers? Check here if there are still some available for today.
CinaRAT Delivered Through HTML ID Attributes
https://isc.sans.edu/forums/diary/CinaRAT+Delivered+Through+HTML+ID+Attributes/28330/
Windows Defender ASR Blocks LSASS Credential Stealing
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-credential-stealing-from-the-windows-local-security-authority-subsystem
Brave Blocking Credential Leaking Extension
https://www.theregister.com/2022/02/12/facebook_god_mode/
Project Zero Summary of Zero Day Bugs
https://googleprojectzero.blogspot.com/2022/02/a-walk-through-project-zero-metrics.html
https://isc.sans.edu/forums/diary/CinaRAT+Delivered+Through+HTML+ID+Attributes/28330/
Windows Defender ASR Blocks LSASS Credential Stealing
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-credential-stealing-from-the-windows-local-security-authority-subsystem
Brave Blocking Credential Leaking Extension
https://www.theregister.com/2022/02/12/facebook_god_mode/
Project Zero Summary of Zero Day Bugs
https://googleprojectzero.blogspot.com/2022/02/a-walk-through-project-zero-metrics.html
Discussion
New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |
Network Monitoring and Threat Detection In-Depth | Baltimore | Mar 3rd - Mar 8th 2025 |
Application Security: Securing Web Apps, APIs, and Microservices | Orlando | Apr 13th - Apr 18th 2025 |