The Hotcobalt bugs can be exploited by registering fake beacons which help crash Cobalt Strike C2 servers, blocking C2 comms and new beacon deployments.
Law enforcement and researchers can also use Hotcobalt to take down malicious infrastructure.
Last month, @topotam77 discovered a new unauthenticated vector in the Microsoft Encrypting File System Remote Protocol (EFSRPC) API to perform Windows NTLM relay attacks. bleepingcomputer.com/news/microsoft…
It was quickly illustrated how easily these attacks could be conducted to take over a Windows domain.
@LawrenceAbrams Security researcher @jonasLyk is the one who discovered that Windows 10 and Windows 11 Registry files associated with the Security Account Manager (SAM) are accessible to users with low privileges.
Mimikatz creator @gentilkiwi told BleepingComputer that anyone can easily steal an elevated account's NTLM hashed password to gain higher privileges by taking advantage of the incorrect file permissions.
@LawrenceAbrams There's a new printer-related zero-day vulnerability that could let hackers gain administrative privileges on vulnerable Windows machines.
It was disclosed publicly by @gentilkiwi and can be exploited through a compromised remote print server
@LawrenceAbrams@gentilkiwi The exploit uses the 'Queue-Specific Files' feature of the Windows Point and Print capability.
Hackers can use it to download and run a malicious DLL with SYSTEM privileges when a client connects to the compromised remote print server
Ledger hardware wallet owners are receiving packages containing what appears to be new Ledger devices in convincing packaging.
The enclosed poorly written letter explains that the device was sent out after the customer's information was posted on the RaidForums hacking forum. bleepingcomputer.com/news/security/…
The National Police of Ukraine says the Clop gang is behind financial damages of $500 million.
Clop's Tor payment and data leak sites are still operational, so it looks like the Clop ransomware operation has not been completely shut down at this time.
If you're curious why Korean police were involved in the investigation: