
Austin
@amartinsec
Pentesting stuff
ID: 1183420652780429313
http://blog.amartinsec.com 13-10-2019 16:34:15
64 Tweet
147 Followers
1,1K Following







Microsoft rolls back decision to block Office macros by default - Sergiu Gatlan bleepingcomputer.com/news/microsoft…


I found this in the process memory of a loaded Brute Ratel C4 samples reported by Unit42 Is that the org that leaked the framework or just an arbitrary UserAgent set by the threat actor? If it's the latter, I'd be sorry unit42.paloaltonetworks.com/brute-ratel-c4… Sample bazaar.abuse.ch/sample/d71dc7b…



In our latest blog post, we publish a MS "won't fix" unauthenticated SSRF to RCE in Microsoft Office Online Server mdsec.co.uk/2022/10/micros… by Manish Kishan Tanwar


From our headquarters underneath the Vatican, happy Halloween! Today we release the first edition of our new publication Black Mass. Special thanks to our Editor in Chief Helen (of Tor) for all of her hard work. papers.vx-underground.org/papers/Other/V…






