⚠️Under Review⚠️
Закрытый канал
⚠️Right now this channel is completely under the Government. We are now investigating whether there is any illegal activities happened in this Channel or Not Due to some Anonymous Reports⚠️ User's Don't be Afraid, Just try to coperate in Investigation...
БольшеСтрана не указанаКатегория не указана
566
Подписчики
Нет данных24 часа
Нет данных7 дней
Нет данных30 дней
Архив постов
🔰𝗔𝗻𝘂𝗯𝗶𝘀 𝗕𝗼𝘁𝗻𝗲𝘁🔰
🔻Features :-
◾️Sms Stealer
◾️Credit Card Grabber
◾️Device Locker
◾️Contacts Stealer
◾️SMS Sender
◾️Run Apps
◾️Flood SMS
◾️Download apps in victim phone
◾️Inject Bank pages
◾️Notification 𝗦𝗲𝗻𝗱𝗲𝗿
📎𝗧𝘂𝘁𝗼𝗿𝗶𝗮𝗹 𝗜𝗻𝗰𝗹𝘂𝗱𝗲𝗱 + 𝗦𝗲𝘁𝘂𝗽 + 𝗣𝗮𝗻𝗲𝗹
𝗖𝗿𝗲𝗱𝗶𝘁 - @pradeepdhawan9870
Don't leech content
Download 👇
Repost from Shinchan Hack and Leaks ❤️🎉
Want This carding method
Free ❤️😁😁😁
Reaction 🔥 20
Join here 👇
https://t.me/+tquiqdDqckJiZDE9
Microsoft patches Outlook zero-day vulnerability used in attacks by Russian hackers
Microsoft has released a security patch to address a critical vulnerability (CVE-2023-23397) in Outlook that was exploited by a Russian hacking group to target government, military, energy, and transportation organizations in Europe. The group, which has been tracked as APT28, Sednit, and Fancy Bear, used malicious Outlook notes and tasks to steal NTLM hashes, which were then used to access victims’ networks and exfiltrate specific accounts.
The vulnerability can be exploited through low-complexity attacks by sending messages containing UNC paths to attacker-controlled SMB shares. Microsoft recommends immediate patching or temporary mitigation by adding users to the Protected Users group in Active Directory and blocking outbound SMB
Outlook versions affected
According to Microsoft, the vulnerability affects all supported versions of Outlook for Windows but not Outlook for Android, iOS, or macOS versions. Online services like Outlook on the web and Microsoft 365 do not support NTLM authentication, making them immune to attacks exploiting this NTLM relay vulnerability.
To help admins check if any users in their Exchange environment have been targeted using this Outlook vulnerability, Microsoft released a dedicated PowerShell script that checks Exchange messaging items for malicious UNC paths and allows modifying or deleting potentially malicious messages if they are found on the audited Exchange Server when run in Cleanup mode.
This critical elevation of privilege security flaw was first reported by the Computer Emergency Response Team for Ukraine (CERT-UA). Microsoft shared this information in a private threat analytics report available to customers with Microsoft 365 Defender, Microsoft Defender for Business, or Microsoft Defender for Endpoint Plan 2 subscriptions.
Mitigation
In addition to patching, Microsoft advises adding users to the Protected Users group in Active Directory and blocking outbound SMB to limit the impact of the attacks.
Microsoft urges its customers toMitigation
In addition to patching, Microsoft advises adding users to the Protected Users group in Active Directory and blocking outbound SMB to limit the impact of the attacks.
Microsoft urges its customers to take immediate action and patch their systems against CVE-2023-23397 or add users to the Protected Users group in Active Directory and block outbound SMB as a temporary mitigation to minimize the impact of the attacks. take immediate action and patch their systems against CVE-2023-23397 or add users to the Protected Users group in Active Directory and block outbound SMB as a temporary mitigation to minimize the impact of the attacks.
Russian hackers exploit Outlook zero-day vulnerability to target European organizations.
🔰𝗥𝗲𝘃𝗲𝗿𝘀𝗲 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗚𝘂𝗶𝗱𝗲🔰
📍𝗖𝗼𝘃𝗲𝗿𝘀 𝗮𝗹𝗹 𝗺𝗲𝘁𝗵𝗼𝗱
📍𝗧𝗲𝗮𝗰𝗵 𝗦𝗲𝗰𝗿𝗲𝘁 𝗧𝗲𝗰𝗵𝗻𝗶𝗾𝘂𝗲𝘀
📍𝗠𝗲𝗱𝗶𝘂𝗺 𝗙𝗿𝗶𝗲𝗻𝗱𝗹𝘆
𝗖𝗿𝗲𝗱𝗶𝘁 - @pradeepdhawan9870
𝗗𝗼𝗻'𝘁 𝗹𝗲𝗲𝗰𝗵 𝗰𝗼𝗻𝘁𝗲𝗻𝘁.
𝗗𝗼𝘄𝗻𝗹𝗼𝗮𝗱 👇
✅ • HACKING USING PDF EXPLOIT • ✅
~Tool used :- S.E.T
~What is a PDF exploit ❔
~Give reactions 💯❤️
~Enjoy the video👍
√ • Join : @TheDreadedArmy • √
HOW TO HACK ANY BROWSER USING XSS ATTACK
TOOL USED IN VIDEO :-
BeEf [Browser Exploitation Framework]
What is XSS ❓
XSS stands for Cross-site scripting (XSS) is a type of security vulnerability that can be found in some web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users.
Enjoy👍
☣ ᏀᎡᎬᎪͲ ᎻᎪᏟᏦᏆΝᏀ ᏟᎻᎪΝΝᎬᏞ ☣
🌸ՏᎻᎪᎡᎬ ᎪΝᎠ ՏႮᏢᏢϴᎡͲ ႮՏ🌸
What data is being stolen?
These malware steal sensitive information from computers, including passwords, credit card information, bank account numbers, and other confidential data.
How hackers are stealing the data?
These AI-generated videos ask users to download and install software from fake websites. When a user believes that the video is authentic, they go to those particular fake websites and download malicious software. Once installed on a system, these software steal information from the computer and upload it to the attacker's Command and Control server.
OpenAI to enable more customisations for enterprise and individual users
YouTube account takeover
YouTube has over 2.5 billion active monthly users and it is the go-to platform for people who look for tutorials. The platform also has regulations and a review process which make it difficult for threat actors to have long-term active accounts. Hence, these threat actors hack YouTube accounts with over 100,000 subscribers. After a few users have been affected, the video is usually taken down and the account is banned.
How hackers are using YouTube videos to steal user information
The narrative around how artificial intelligence (AI)-generated content is being used by hackers has gained momentum lately. Researchers have explained how AI image and voice generators can be a global security threat. On similar lines, a new report has claimed that threat actors are now using AI-generated videos on YouTube to spread stealer malware.
Increase in videos containing stealer malware
According to a report by IT security intelligence company CloudSEK, since November 2022, there has been a 200-300% month-on-month increase in videos on YouTube that contain links to stealer malware such as Vidar, RedLine, and Raccoon in their descriptions.
