Search:

Last Week in Security (LWiS) - 2025-01-27

0-click deanonymization (@hackermondev), Subaru hacks (@samwcyo + @infosec_au), 🍪 sandwitch (@d4d89704243), Entra Connect attacks (@hotnops), Kerberos relaying via HTTP (@croco_byte), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2025-01-20 to 2025-01-27.

News

Techniques and Write-ups

Tools and Exploits

  • WinVisor - WinVisor - A hypervisor-based emulator for Windows x64 user-mode executables using Windows Hypervisor Platform API. Full here WinVisor.
  • 7-Zip-CVE-2025-0411-POC - This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.
  • Draugr - BOF with Synthetic Stackframe.
  • gitC2 is a simple C2 POC that leverages a GitHub repository for executing commands through issues.
  • OdinLdr - Cobaltstrike Reflective Loader with Synthetic Stackframe.
  • speedloader - Rust template/library for implementing your own COFF loader.
  • slinger - An impacket-lite cli tool that combines many useful impacket functions using a single session.
  • rpeloader - use python on windows with full submodule support without installation.

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.