Last Week in Security (LWiS) - 2025-09-29
这篇文章总结了过去一周的网络安全动态,包括OmniProx多云IP旋转工具、Phantom Chrome扩展后门技术、FIDO跨设备钓鱼攻击、VMware Tools本地权限提升漏洞等安全事件和技术分析。此外还涉及捕获旗帜竞赛(CTF)、安全工具开发及漏洞利用等内容。 2025-9-30 03:59:0 Author: blog.badsectorlabs.com(查看原文) 阅读量:1 收藏

OmniProx (@ZephrFish), Phantom Chrome Extensions (Riadh Bouchahoua (@Synacktiv)), FIDO phishing (@dennis_kniep), VMWare Tools LPE (@0xThiebaut), MSI lateral movement (@werdhaihai), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2025-09-22 to 2025-09-29.

News

  • U.S. Secret Service dismantles imminent telecommunications threat in New York tristate area - A "nation-state threat actor" set up, "more than 300 co-located SIM servers and 100,000 SIM cards across multiple sites." The Secret Service claims this was to disrupt the United Nations general assembly happening in New York City. However, "within 35 miles" puts them really far away from the UN headquarters in NYC. It's probably just a standard SMS spam farm.
  • [LinkedIn] In 2024, we observed a Time-to-exploit of -1 - A paywalled report from Google Threat Intelligence shows that in 2024 vulnerabilities are being exploited before they are publicly known more often than after disclosure. Since the report is for customers only, it's not possible to know the methodology or sampling bias for this data unfortunately. Engagement bait?
  • Analysis of a Ransomware Breach - Mudge reflects on Kerberosting, the security conversation, and Senator Wyden's letter to the FTC (covered last week). If Microsoft had decided that Active Directory privilege escalation was a core issue in 2011, what would the cybersecurity industry look like today?
  • Join the Huntress Annual Capture the Flag - "Every October for Cybersecurity Awareness Month, thousands of defenders join our month-long Capture the Flag competition. Whether you’re new to cybersecurity or a seasoned pro, you’ll face daily puzzles and real-world attack simulations that sharpen your skills and keep you on your toes."
  • FlareOnOS v12.2 - "The Flare-On Challenge is the FLARE team's annual Capture-the-Flag (CTF) contest. It is a single-player series of Reverse Engineering puzzles that runs for every fall."

Techniques and Write-ups

Tools and Exploits

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.


文章来源: https://blog.badsectorlabs.com/last-week-in-security-lwis-2025-09-29.html
如有侵权请联系:admin#unsafe.sh