Search:

Last Week in Security (LWiS) - 2025-06-09

Windows self-delete on 24H2 (@TKYNSEC), DNS rebinding (@yarlob), VSCode backdoor (@d1rkmtr), leak Google users' 📞# (@brutecat), Entra sync dumping (@hotnops), Delegations (@podalirius_), Chrome abuse for screenshots, mic, and camera access (@mrd0x), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2025-06-02 to 2025-06-09.

News

Techniques and Write-ups

Tools and Exploits

  • VSCode-Backdoor - Backdooring VSCode Projects.
  • srum-dump - A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.
  • SelfDeletion-Updated - Updated version of a long known self deletion technique to work with 24H2.
  • ECUtilities - Powershell and python utilities for Entra Connect.
  • JonMon-Lite is a research proof-of-concept "Remote Agentless EDR" that creates an ETW Trace Session through a Data Collector Set. This session can be created locally or remotely.
  • TrollRPC - a library to blind RPC calls based on UUID and OPNUM. A more surgical version of Ghosting-AMSI.
  • newtowner - Abuse trust-boundaries to bypass firewalls and network controls.
  • Delegations - A tool to work with all types of Kerberos delegations (unconstrained, constrained, and resource-based constrained delegations) in Active Directory.
  • VRDP-Training-Material - This repository contains the pre-joining training materials given to aspiring researchers on the Vulnerability Researcher Development Program.
  • kerbtool - A tool to interact with Kerberos to request, forge and convert various types of tickets in an Active Directory environment.
  • funcshenanigans - A bunch of shenanigans using functions, VEH and more.
  • SafeHarbor-BOF - Safe Harbor is a BOF that streamlines process reconnaissance for red team operations by identifying trusted, low-noise targets to maintain stealth and robust OPSEC.

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.