Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @bartblaze
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @bartblaze
-
Pinned Tweet
I've published my slides on the workshop I gave about Malware Analysis, Threat Intelligence and Reverse Engineering. Blog: https://bartblaze.blogspot.co.uk/2018/02/malware-analysis-threat-intelligence.html … Direct link:https://www.slideshare.net/bartblaze/malware-analysis-threat-intelligence-and-reverse-engineering …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
After testing another CVE-2021-40444 sample that works with html+cab payload on a remote web server, I can now confirm that "mhtml:" and "x-usc:" are not needed in the remote OLE URL for the exploit to work. But the double URL http:...!http:... seems required.https://twitter.com/decalage2/status/1436085507663056898 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Bart RetweetedThanks. Twitter will use this to make your timeline better. UndoUndo
-
Bart Retweeted
Kusto hunting query for the vulnerability in MSHTML, CVE-2021-40444: https://blog.nviso.eu/2021/09/09/kusto-hunting-query-for-cve-2021-40444/ …
#CVE202140444Thanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Chinese hackers have breached the internal networks of at least ten Indonesian government ministries and agencies, including computers from Indonesia’s primary intelligence service, the Badan Intelijen Negara (BIN) Only on
@TheRecord_Media https://therecord.media/indonesian-intelligence-agency-compromised-in-suspected-chinese-hack/ …pic.twitter.com/LhD22h8UQI
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Bad news about CVE-2021-40444 detection: after some tests, I can confirm that the remote object URL can be a simple URL, no need for mhtml, x-usc or even the double URL. So no way to detect CVE-2021-40444 just by looking at the URL, you need to get the remote object to find out.https://twitter.com/decalage2/status/1435640605149908992 …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Facebook sent reporters covering their glasses launch a list of supposed "third-party" privacy and consumer groups that it consulted for the product. So I did some digging. FB funds at least 4 of the 5 groups. Future of Privacy Forum is one.https://twitter.com/RMac18/status/1435998632767987714 …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Some context to that Fortinet VPN creds leak from Tuesday https://therecord.media/fortinet-warns-customers-after-hackers-leak-passwords-for-87000-vpns/ …pic.twitter.com/Cv1wxScc7Z
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
New blog post!

Title: Kusto hunting query for CVE-2021-40444
| by Bart Parys (@bartblaze) Link: https://blog.nviso.eu/2021/09/09/kusto-hunting-query-for-cve-2021-40444/ …#CVE202140444#kusto#MSHTML#infosec#netsec#hunting#blueteamThanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Tickling VMProtect with LLVM: Part 1-3 by
@fvrmatteohttps://secret.club/2021/09/08/vmprotect-llvm-lifting-1.html …Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Kusto hunting query for the vulnerability in MSHTML, CVE-2021-40444: https://blog.nviso.eu/2021/09/09/kusto-hunting-query-for-cve-2021-40444/ …
#CVE202140444Thanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Three great days in
#Lille
, at @FIC_eu , sharing@EU_Commission’s commitment in boosting#EU
#CyberSecurity capabilities and resilience. Thanks to the EU funded cyber community hosted in our booth:@Cybersec_ECCC@CyberSec4Europe@concordiah2020@ECHOcybersec@sparta_eupic.twitter.com/zslkaVuHh0Thanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Great to see CAPE's
#Hancitor config extraction showcased in 'Difesa e Sicurezza' today
Molte grazie a @JAMESWT_MHT e@FBussoletti
https://twitter.com/FBussoletti/status/1435872415670849537 …pic.twitter.com/wCEtqHekUe
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Some
#CVE-2021-40444 Samples uploaded to#Bazaar@abuse_ch
https://bazaar.abuse.ch/browse/tag/CVE-2021-40444/ …
pic.twitter.com/Wqa1tow08X
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Great blog post by
@0xThiebaut on the anatomy of Metasploit shellcode and how to abuse its import resolution:https://blog.nviso.eu/2021/09/02/anatomy-and-disruption-of-metasploit-shellcode/ …Thanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Three of the most common issues
#BloodHoundEnterprise finds, their impacts, and how you can use FOSS#BloodHound to find and fix these issues yourself, today:
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
oleobj (from
#oletools) can be used to detect CVE-2021-40444: if there is a remote OLE object with an URL starting with "mhtml:", it's probably an exploit for that vulnerability.https://twitter.com/ochsenmeier/status/1435619938153156624 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Not sure if Microsoft fixed this (my VM is unpatched). But it works in explorer preview mode via RTF: https://twitter.com/buffaloverflow/status/1435596990650503168 …pic.twitter.com/H5cdmL8tpX
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Popping calc with CVE-2021-40444 (MS Office exploit) Thanks to
@BouncyHat for collaborating
Not planning to release but my bet is with itw exploits, it won't be long..pic.twitter.com/1eVsUksMwjThanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
Microsoft identified a limited number of targeted attacks. To protect customers, please see https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 … for mitigation guidance.
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Bart Retweeted
This one is legit and is going to be worse than the Equation Editor CVEs (which make up almost all endpoint exploitation still), so strap in.https://twitter.com/ImposeCost/status/1435311131183271944 …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
