Researchers have discovered that HollowGraph malware leverages Microsoft 365 calendars and Microsoft Graph APIs to establish covert command-and-control communications, exploiting legitimate cloud services to evade detection. The malware has been linked to the Cavern framework, indicating a coordinated approach to using cloud-based calendar systems as an alternative C2 infrastructure.
Automate Volatility 3 Memory Analysis with This Tool
13Cubed·2.8K views · 1 month ago
In this episode, we'll look at a tool that can run multiple Volatility 3 plugins simultaneously, automating your memory analysis and saving you valuable time during investigations.
*** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. ***
📖 Chapters
00:00 - Intro
02:18 - Demo
🛠 Resources
VolGolangWrapper:
Ernst & Young disclosed a data breach involving a compromised third-party IT support platform, with exposed support tickets potentially containing client documents and tax information. Check Point Research's weekly threat intelligence bulletin for July 20th covers this incident along with other significant cyber attacks and breaches discovered that week.
Two chiefs of UK policing agencies said the Transport for London prosecution demonstrates the need for Cybercrime Risk Orders
I got inside FIFA’s Secret World Cup Broadcast Network
NetworkChuck·513K views · 1 month ago
HackTheBox Logging
IppSec·8.4K views · 1 month ago
00:00 - Introduction
01:05 - Start of nmap
03:50 - Grabbing files off the open share, looking at logs and seeing an error message that contains an old credential
07:50 - Using BloodyAD to pull information from the account to see password last set, also running BloodHound
09:45 - Running Certipy, then using JQ to show me certificates with non-default groups/accounts in enrollment
12:25 - Going over Bloodhound, showing our SVC_RECOVERY can take over MSA_HEALTH$
16:30 - Showing BloodyAD to allow ourselves read access to the MSA_HEALTH$ password, could also do Shadow Credentials
20:30 - Getting on the box with WinRM, discovering Monitor.ps1 file. Use COM to look at scheduled task
24:30 - Using MSFVenom to create a malicious DLL, zip it up and upload wait for the scheduled task to execute it
32:40 - Got access to Jaylee Clifton, using Rubeus tgtdeleg to get us a Kerberos ticket so we can run commands as them on our box
38:45 - Using Certipy to confirm the server is vulnerable to ESC17
41:45 - Looking at WSUS Config, discover things are pointed to wsus.logging.htb which does not exist
46:10 - Using Certipy to create a certificate that can impersonate wsus.logging.htb
49:00 - Setting up WSUKS to push a malicious windows update
Google's Gemini AI assistant on Android devices can be exploited to send messages from a locked phone without authorization, potentially allowing anyone with physical access to impersonate the device owner. This vulnerability undermines the security protections that locked phones are designed to provide, creating a risk for message-based attacks and social engineering. The issue highlights the need for stricter authentication controls when AI assistants have access to sensitive device functions.
Microsoft Spying in 2026 is crazy and VPN can't help!
23andMe has agreed to an $18 million settlement with 42 US state attorneys general stemming from its 2023 data breach. The settlement includes mandatory enhancements to the company's data protection practices going forward. This action represents coordinated enforcement by state-level regulators against the genetic testing company for the security incident.
AI-powered MCP agents are accelerating penetration testing workflows by automating reconnaissance and vulnerability discovery across external, application, and cloud environments. In a real-world deployment, Bishop Fox leveraged this approach to uncover two information leaks comprising over 12 million records in a fraction of the traditional timeframe, demonstrating significant efficiency gains over conventional testing methodologies.
Unit 42 has published a technical analysis documenting three chained zero-day vulnerabilities affecting Siemens ROX II OT switches that can be exploited to achieve privilege escalation and maintain persistent root access. The vulnerability chain demonstrates a complete attack path through these industrial network devices, highlighting a significant threat to operational technology infrastructure.
CISA has mandated that US government agencies patch two critical Fortinet vulnerabilities by July 19 due to active exploitation in the wild. The urgent directive underscores the severity of these flaws and the immediate threat they pose to federal infrastructure.
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.
A widespread phishing campaign is using TrueType font files as a disguise to deliver a Lua-based loader, which subsequently deploys remote access trojans and information-stealing malware to compromised systems. This obfuscation technique leverages file type spoofing to evade detection while establishing a foothold for follow-on malicious payloads across multiple targets globally.
Cybersecurity researchers tested Open AI GPT 5.5’s offensive cyber capabilities – and the results showed how effective a frontier LLM can be for hackers
A new modular macOS stealer called ClickLock employs kill loops to lock victims out of their systems and coerce password entry. The malware forces users to surrender credentials by repeatedly terminating processes until they comply with the attacker's demands.
Two individuals responsible for the 2024 cyber-attack against Transport for London have been sentenced to five and a half years in prison after pleading guilty to Computer Misuse Act violations. According to the judge, the attackers were motivated by what was characterized as selfish bravado rather than ideological or financial objectives.