Entry Thumbnail

GachiLoader: Defeating Node.js Malware with API Tracing

Research by: **Sven Rath** ( **@eversinc33**), Jaromír Hořejší ( **@JaromirHorejsi**) ## Key Points – The YouTube Ghost Network is a malware distribution network that uses compromised accounts to promote malicious videos and spread malware, such as infostealers. – One of the observed campaigns uses a new, heavily obfuscated loader malware written in Node.js, which we […]

Posted by
Entry Thumbnail

Exploiting Anno 1404

# Exploiting Anno 1404 Anno 1404 is a strategy game developed by Related Designs and published by Ubisoft. It is a real-time strategy game that focuses on city management and construction. The Anno 1404: Venice expansion, released in 2010, includes an online and local area network multiplayer mode. During our […]

Posted by
Entry Thumbnail

Token Leak via Open Redirection and CSRF in the Callback Handler of cloudflare/workers-oauth-provider

**security-research** Public # Token Leak via Open Redirection and CSRF in the Callback Handler of cloudflare/workers-oauth-provider ## Package ## Affected versions ## Patched versions ## Description ### Summary Clients are required in the OAuth spec to prevent CSRF attacks at its Callback handler. The implementation in cloudflare/workers-oauth-provider doesn’t protect against […]

Posted by
Entry Thumbnail

A look at an Android ITW DNG exploit

Posted by Benoît Sevens, Google Threat Intelligence Group Introduction Between July 2024 and February 2025, 6 suspicious image files were uploaded to VirusTotal. Thanks to a lead from Meta, these samples came to the attention of Google Threat Intelligence Group. Investigation of these images showed that these images were DNG […]

Posted by