Latest

6/recent/ticker-posts

Header Ads Widget

ChatGPT Vulnerability Against US Govt πŸ‡ΊπŸ‡Έ, SAML Roulette 🎲, Google Acquires Wiz πŸ€‘

Hackers exploited an SSRF vulnerability in ChatGPT's pictureproxy.php file, enabling unauthorized requests. There were over 10,000 attacks from an IP ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌  ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ 

TLDR

Together With ThreatSpike

TLDR Information Security 2025-03-19

Unlimited pentesting for $1,500 a month? Meet ThreatSpike (Sponsor)

As a 5 star rated, global certified CREST provider, ThreatSpike offers top-quality penetration testing at an unbeatable price. Get unlimited penetration testing for just $1,500 per month and ensure your business is always protected.

With ThreatSpike Red, you can:

…all led by a team of expert certified testers.

Your IT team will appreciate the simplicity and efficiency. Your auditors and management will value the comprehensive results.

Contact the team today for year-round peace of mind.

πŸ”“

Attacks & Vulnerabilities

New RAT Malware Used for Crypto Theft, Reconnaissance (3 minute read)

Microsoft Incident Response researchers report on a new RAT, StilachiRAT. This RAT can steal crypto wallet data, clipboard credentials, and Google Chrome local state files. It also features enhanced persistence, anti-forensics, and C2 command execution capabilities.
ChatGPT Vulnerability Exploited Against US Government Organizations (3 minute read)

Hackers exploited an SSRF vulnerability in ChatGPT's pictureproxy.php file, enabling unauthorized requests. There were over 10,000 attacks from one IP focused on the US government and financial institutions in a week.
South Korean Organizations Targeted by Cobalt Strike 'Cat' Delivered by a Rust Beacon (6 minute read)

Researchers found server hosting tools for cyber attacks on South Korean entities, notably using Cobalt Strike Cat. The attacker targeted government and commercial organizations with open-source tools like SQLMap and Web-SurvivalScan. The malware campaign utilized Rust-compiled loaders and a modified Cobalt Strike for post-exploitation.
🧠

Strategies & Tactics

Threat Modeling the TRAIL of Bits Way (7 minute read)

Trail of Bits' TRAIL (Threat and Risk Analysis Informed Lifecycle) is a threat modeling process that merges aspects of Mozilla's Rapid Risk Assessment, NIST SP 800-154, and NIST SP 800-53 to identify design-level security flaws. TRAIL constructs a model of system components and trust boundaries, documents threat scenarios of potential adversary exploitations, and generates actionable findings with short- and long-term mitigation recommendations. It addresses root causes at the architecture level, allowing clients to adapt their threat models as systems evolve and offering vital security insights throughout the software development lifecycle.
SAML roulette: the hacker always wins (8 minute read)

This blog explores how to exploit GitLab Enterprise through ruby-saml vulnerabilities using round-trip attacks and namespace confusion for unauthorized admin access. The technical details are provided for security education and understanding these attack vectors.
Defeating String Obfuscation in Obfuscated NodeJS Malware using AST (14 minute read)

This article describes how to defeat string obfuscation in Node.js malware through Abstract Syntax Tree (AST) parsing, focusing on the Nebula Stealer sample. It outlines a method using the Babel library to safely analyze, extract, and execute obfuscated code in a VM context while replacing obfuscated strings with their decoded values. The author includes code snippets for renaming variables, extracting code segments, executing parts of the code to reveal hidden strings, and enhancing readability.
πŸ§‘‍πŸ’»

Launches & Tools

AI SOC Analysts: What You Need to Know (Sponsor)

Businesses are cautiously optimistic about AI agents for SOC triage and investigation. This buyer's guide will help you understand what to look for in an AI SOC analyst, from a business and technical perspective. It also includes an RFP template that you can use as a starting point. Get a copy to your email
GitHub Actions Log Checker (GitHub Repo)

In the wake of the tj-actions and reviewdog supply chain attacks, this action scans GitHub Actions logs for exposed secrets and credentials.
AI HTTP Analyzer (Burp App)

AI HTTP Analyzer is a Burp App that provides an advanced security analysis assistant integrated into Burp Suite.
Dojo-101 (GitHub Repo)

Dojo-101 is a project for capturing experience and knowledge in cybersecurity.
🎁

Miscellaneous

Amazon RDS Now Provides Visibility Into IAM DB Authentication Metrics and Logs (2 minute read)

Amazon RDS IAM DB Authentication enables IAM principals to access RDS databases with their IAM credentials, eliminating the need for separate database credentials. It also reports IAM DB Auth error logs to CloudWatch and publishes authentication metrics automatically.
AWS WAF Adds JA4 Fingerprinting and Aggregation on JA3 and JA4 Fingerprints for Rate-Based Rules (2 minute read)

A JA4 TLS client fingerprint contains a 36-character fingerprint of the TLS Client Hello which can be used for identifying known bad actors. JA4 fingerprints are now supported in match statements in AWS WAF. Additionally, AWS WAF has added support for both JA3 and JA4 fingerprints to rate-based rules.
UK online safety law Musk hates kicks in today, and so far, Trump can't stop it (5 minute read)

The UK's Online Safety Act enforcement began, requiring tech platforms to remove dangerous content or face fines up to 10% of global turnover. Elon Musk hopes Trump will intervene to weaken the law, but UK officials insist it will remain intact and may even expand, particularly to combat AI-generated CSAM.

Quick Links

Google announces agreement to acquire Wiz (2 minute read)

Google has announced a definitive agreement to acquire cloud security platform Wiz, Inc. for $32 billion in cash.
OKX Web3: Taking a Stand Against Financial Crime (3 minute read)

OKX Web3 is addressing recent media attacks and taking action against financial crime, including a coordinated effort by the Lazarus group to abuse its services.
Infostealers fueled cyberattacks and snagged 2.1B credentials last year (3 minute read)

Cybercriminals used infostealers to steal 2.1 billion credentials last year, leading to ransomware attacks and data breaches.

Love TLDR? Tell your friends and get rewards!

Share your referral link below with friends to get free TLDR swag!
Track your referrals here.

Want to advertise in TLDR? πŸ“°

If your company is interested in reaching an audience of cybersecurity professionals and decision makers, you may want to advertise with us.

Want to work at TLDR? πŸ’Ό

Apply here or send a friend's resume to jobs@tldr.tech and get $1k if we hire them!

If you have any comments or feedback, just respond to this email!

Thanks for reading,
Prasanna Gautam, Eric Fernandez & Sammy Tbeile


Manage your subscriptions to our other newsletters on tech, startups, and programming. Or if TLDR Information Security isn't for you, please unsubscribe.

Post a Comment

0 Comments