<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-04-19T19:19:41Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Zeljka Zorz</title>
  <author>
    <name>Zeljka Zorz</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1edx5uqm38yvesekvt9wvlwwt328gdpyrcnpn78w96rjamg2jlkcs5tqmkd.rss" />
  <link href="https://yabu.me/npub1edx5uqm38yvesekvt9wvlwwt328gdpyrcnpn78w96rjamg2jlkcs5tqmkd" />
  <id>https://yabu.me/npub1edx5uqm38yvesekvt9wvlwwt328gdpyrcnpn78w96rjamg2jlkcs5tqmkd</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/308/262/724/375/093/original/591b21dc5237c417.jpeg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/308/262/724/375/093/original/591b21dc5237c417.jpeg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqsydt53qp9zmh92r622wadzqxdp6s457vl6p8n9dxjkrkrnrqawl5qzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mzler4su</id>
    
      <title>Nostr event nevent1qqsydt53qp9zmh92r622wadzqxdp6s457vl6p8n9dxjkrkrnrqawl5qzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mzler4su</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsydt53qp9zmh92r622wadzqxdp6s457vl6p8n9dxjkrkrnrqawl5qzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mzler4su" />
    <content type="html">
      #Everything&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/709/478/867/217/811/original/95fa42e177573139.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-06-19T10:11:41Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfe6vkwk5fwfvl4x79d8w8zuuqv8ft3e66puqhylc9x6hp4dkmylgzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mz6qe5mq</id>
    
      <title type="html">Same.</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfe6vkwk5fwfvl4x79d8w8zuuqv8ft3e66puqhylc9x6hp4dkmylgzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mz6qe5mq" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsw7zkntj3p4mey4vggducp4jj90nzpwp80u46u9qfz4lcuw7nghfg37mvnc&#39;&gt;nevent1q…mvnc&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Same.
    </content>
    <updated>2025-02-18T08:00:58Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfutr8g2asnw4x7cagqk7vdycgnc9mcgexp9sw6358hsjvz4zdzcczyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mzg9zaf0</id>
    
      <title>Nostr event nevent1qqsfutr8g2asnw4x7cagqk7vdycgnc9mcgexp9sw6358hsjvz4zdzcczyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mzg9zaf0</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfutr8g2asnw4x7cagqk7vdycgnc9mcgexp9sw6358hsjvz4zdzcczyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mzg9zaf0" />
    <content type="html">
      &lt;a href=&#34;https://www.disruptionist.com/p/elon-musks-x-blocks-links-to-signal&#34;&gt;https://www.disruptionist.com/p/elon-musks-x-blocks-links-to-signal&lt;/a&gt;
    </content>
    <updated>2025-02-17T10:04:26Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9cnnpf8f036vfvsawnme05klg3hllxfdncjkqm8wkmeydt7jv2kczyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mzwkjf3v</id>
    
      <title type="html">Symantec says their protection bulletin was prompted by the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9cnnpf8f036vfvsawnme05klg3hllxfdncjkqm8wkmeydt7jv2kczyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mzwkjf3v" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy5x3u2zwl5qkmmankhx2jdfjgd4aey5f6qunfrgs4nz4q4q8cr7gkawxhf&#39;&gt;nevent1q…wxhf&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Symantec says their protection bulletin was prompted by the AhnLab blog post. &lt;br/&gt;&lt;br/&gt;I believe &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1qnsf2h37f0f4tm557xks235yrdyk7ws3qf62ee6u8dpck8yq9xxqlj7xrd&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;buherator&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1qns…7xrd&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; is right. Whether Microsoft found a continuation of the same campaign, with a slightly different approach / toolset, is impossible to tell.&lt;br/&gt;&lt;br/&gt;Judging by the capabilities provided by the Godzilla post-exploitation framework and the Godzilla webshell, I wold venture to say that they are one and the same, only Microsoft used that particular expression (and did not elaborate on it, which means they expect the readers to be familiar with it already - i.e., it&amp;#39;s known and documented).
    </content>
    <updated>2025-02-07T18:07:49Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxrc3eft7q8w7qxnlmrg7gvy0f8lyec2slqdu0a5k6qwk8c706zyqzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mz46keqg</id>
    
      <title type="html">Or ASEC: https://asec.ahnlab.com/en/85088/ They go in more ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxrc3eft7q8w7qxnlmrg7gvy0f8lyec2slqdu0a5k6qwk8c706zyqzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mz46keqg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8qfwhkwc9274rdx7telenzsmern8wzcseanc7jznj6u3symm33fgla9te5&#39;&gt;nevent1q…9te5&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Or ASEC: &lt;a href=&#34;https://asec.ahnlab.com/en/85088/&#34;&gt;https://asec.ahnlab.com/en/85088/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;They go in more detail, but mention ASP.NET environments with vulnerable configurations. &lt;br/&gt;&lt;br/&gt;Unfortunately, I don&amp;#39;t know enough about ASP.NET to make an educated guess whether these attacks could be related.
    </content>
    <updated>2025-02-07T11:50:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8qfwhkwc9274rdx7telenzsmern8wzcseanc7jznj6u3symm33fgzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mzjk4u6z</id>
    
      <title type="html">Is it possible that Broadcom/Symantec spotted these same attacks ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8qfwhkwc9274rdx7telenzsmern8wzcseanc7jznj6u3symm33fgzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mzjk4u6z" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdxk63xzuqqgpzl3qqnwjjmhxm7rumjzenyrfm525huqv2wxu0cmgmta3l8&#39;&gt;nevent1q…a3l8&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Is it possible that Broadcom/Symantec spotted these same attacks earlier?&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.broadcom.com/support/security-center/protection-bulletin/godzilla-webshell-deployment-campaign&#34;&gt;https://www.broadcom.com/support/security-center/protection-bulletin/godzilla-webshell-deployment-campaign&lt;/a&gt;
    </content>
    <updated>2025-02-07T11:02:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvc4k9u9dckg6dvd5t0ayt52pppgtsprhtftps9uvt4jm8p8msk7qzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mz30thpj</id>
    
      <title type="html">The Tor folks updated their post to say that: &amp;#34;An earlier ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvc4k9u9dckg6dvd5t0ayt52pppgtsprhtftps9uvt4jm8p8msk7qzyr956nsrwyu3nxrxe3v4enaeew9gap5ys0zvx0cachgwthdp2t7mz30thpj" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsw683rq84lgse4x4tn0dzmr0dgkqm5nranhl5l0xz43kfmqavnjkgk4exj9&#39;&gt;nevent1q…exj9&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The Tor folks updated their post to say that: &lt;br/&gt;&lt;br/&gt;&amp;#34;An earlier version of this blog post incorrectly stated that &amp;#39;Mozilla is aware of this attack being used in the wild against Tor Browser users.&amp;#39; This has been corrected to accurately reflect Mozilla&amp;#39;s official statement. To be clear, the Tor Project has no evidence that Tor Browser users were targeted specifically.&amp;#34;
    </content>
    <updated>2024-10-15T07:16:37Z</updated>
  </entry>

</feed>