Last Week in Security (LWiS) - 2025-03-17
过去一周网络安全领域值得关注的内容包括:Evilginx Pro正式发布、Cobalt Strike 4.11更新、密码复用问题严重、AI伪造GitHub仓库传播恶意软件、SAML解析器漏洞、Kentico CMS预认证RCE漏洞等工具与技术动态。 2025-3-18 08:9:48 Author: blog.badsectorlabs.com(查看原文) 阅读量:50 收藏

Evilginx Pro (@mrgretzky), Pre-auth RCE in a CMS (@chudyPB), GOAD ADCS (@M4yFly), YouTube email disclosure (@brutecat), SAML parser bug (@ulldma.bsky.social/@[email protected]), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2025-03-10 to 2025-03-17.

News

Techniques and Write-ups

Tools and Exploits

  • Xenon - A Mythic agent for Windows written in C. Read about the development here.
  • ludus_mythic_teamserver - Ludus role for deploying a Mythic Teamserver onto Linux servers.
  • truffleshow - A simple web viewer for TruffleHog JSON output.
  • checkm8 - bypassing intel txt's tboot integrity checks via coreboot shim.
  • SSH-Stealer - Smart keylogging capability to steal SSH Credentials including password & Private Key.
  • DSViper is a powerful tool designed to bypass Windows Defender's security mechanisms, enabling seamless execution of payloads on Windows systems without triggering security alerts. [Debatable - methods seem pretty simple and it's pretty sketchy to download the C++ files from github instead of package them in the repo]

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

  • The Security Conversation - Mudge, the creator of Cobalt Strike, is back! This non-technical post is about the importance of offensive security research and tooling, even if you don't like it. A more "raw" thread from Mudge is on bluesky.
  • cradle - CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taking, automated data linking, interactive visualizations, and robust access control. Enhance your CTI workflow from analysis to reporting—all in one secure space.
  • Snake_Apple - Articles and tools related to research in the Apple environment (mainly macOS).
  • TheTick - The Tick is the next evolution in covert access control system implants for simulating adversary-in-the-middle attacks.
  • scorpi - A Modern Hypervisor (for macOS).

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.


文章来源: https://blog.badsectorlabs.com/last-week-in-security-lwis-2025-03-17.html
如有侵权请联系:admin#unsafe.sh