Alaid TechThread
578 subscribers
6 photos
1 video
81 files
1.3K links
Vulnerability discovery, threat intelligence, reverse engineering, AppSec
Download Telegram
Operation ‘Kremlin’
The file contains an obfuscated URL to a remote template which contains malicious VBA, eventually leading to the execution of VBS on the infected machine. The attack’s purpose is to stealthily exfiltrate information without running any external executables on the system.

https://www.clearskysec.com/operation-kremlin/
FuzzSplore: Visualizing Feedback-Driven Fuzzing Techniques.

https://arxiv.org/abs/2102.02527
malicious repositories can execute remote code while cloning

https://www.openwall.com/lists/oss-security/2021/03/09/3