Tageszusammenfassung - 08.11.2022

End-of-Day report

Timeframe: Montag 07-11-2022 18:00 - Dienstag 08-11-2022 18:00 Handler: Stephan Richter Co-Handler: Thomas Pribitzer


How to mimic Kerberos protocol transition using reflective RBCD

We know that a delegation is dangerous if an account allows delegating third-party user authentication to a privileged resource. In the case of constrained delegation, all it takes is to find a privileged account in one of the SPN (Service Principal Name) set in the msDS-AllowedToDelegateTo attribute of a compromised service account.


Azov-Malware zerstört Dateien in 666-Byte-Schritten

Der Windows-Schädling Azov ist ein Wiper und vernichtet Dateien unwiderruflich. Sicherheitsforscher beobachten ein erhöhtes Aufkommen.


Open Bug Bounty: Eine Million Sicherheitslücken im Web behoben

Eine offene Plattform für das Offenlegen von Sicherheitslücken im Web hat einen Meilenstein erreicht. Open Bug Bounty verzeichnet über 1,3 Mio. Entdeckungen.


Achtung Fake-Shop: marktstores.com gibt sich als Media Markt aus

Die Playstation 5 ist momentan überall ausverkauft. Vorsicht, wenn Sie im Internet dennoch einen Anbieter finden, der sie angeblich liefern kann. Dieser könnte sich als Fake-Shop herausstellen.


LockBit 3.0 Being Distributed via Amadey Bot

The ASEC analysis team has confirmed that attackers are using Amadey Bot to install LockBit. Amadey Bot, a malware that was first discovered in 2018, is capable of stealing information and installing additional malware by receiving commands from the attacker.


Prepare, respond & recover: Battling complex Cybersecurity threats with fundamentals

The cybersecurity industry has seen a lot of recent trends. For example, the proliferation of multifactor authentication (MFA) to fight against credential harvesting is a common thread.


Cracking 2.3M Attackers-Supplied Credentials: What Can We Learn from RDP Attacks

To study credentials attacks on RDP, we operate high-interaction honeypots on the Internet. We analyzed over 2.3 million connections that supplied hashed credentials and attempted to crack them.


DeimosC2: What SOC Analysts and Incident Responders Need to Know About This C&C Framework

This report provides defenders and security operations center teams with the technical details they need to know should they encounter the DeimosC2 C&C framework.



IBM Security Bulletins 2022-11-07

IBM Tivoli Monitoring, IBM App Connect Enterprise Certified Container, IBM Operations Analytics - Log Analysis


Siemens Security Advisories 2022-11-08

Siemens released 9 new and 8 updated Advisories. (CVSS Scores 5.3-9.9)


Patchday: Angreifer könnten Android-Geräte über Attacken lahmlegen

Google hat wichtige Sicherheitsupdates für Android 10 bis 13 veröffentlicht. Einige andere Hersteller bieten ebenfalls Patches an.


Security updates for Tuesday

Security updates have been issued by Debian (pixman and sudo), Fedora (mingw-binutils and mingw-gdb), Red Hat (bind, bind9.16, container-tools:3.0, container-tools:4.0, container-tools:rhel8, dnsmasq, dotnet7.0, dovecot, e2fsprogs, flatpak-builder, freetype, fribidi, gdisk, grafana, grafana-pcp, gstreamer1-plugins-good, httpd:2.4, kernel, kernel-rt, libldb, libreoffice, libtiff, libxml2, mingw-expat, mingw-zlib, mutt, nodejs:14, nodejs:18, openblas, openjpeg2, osbuild, pcs, php:7.4, php:8.0, [...]


ICS Patch Tuesday: Siemens Addresses Critical Vulnerabilities

Siemens and Schneider Electric have released their Patch Tuesday advisories for November 2022. Siemens has released nine new security advisories covering a total of 30 vulnerabilities, but Schneider has only published one new advisory.


Varnish HTTP/2 Request Forgery


Open Source Varnish Request Smuggling


PHOENIX CONTACT: Automationworx BCP File Parsing Vulnerabilities


Citrix Gateway and Citrix ADC Security Bulletin for CVE-2022-27510 CVE-2022-27513 and CVE-2022-27516


McAfee Total Protection: Update fixt Schwachstelle CVE-2022-43751
