About
Activity
4K followers
Experience & Education
Licenses & Certifications
Publications
-
GoldenSpy Chapter 5 : Multiple GoldenSpy Uninstaller Variants Discovered
Trustwave
See publicationUnderstanding the attackers were watching our every move to help organizations impacted by GoldenSpy, we waited a period-of-time and quietly kept tracking with our threat hunting strategy. What we found is that they are continuing to push new GoldenSpy uninstallers – so far we have discovered five variants totalling 24 uninstaller files.
-
Microsoft Team arbitrary code execution
Trustwave
See publicationMy original finding allowed a malicious actor to use the MS Teams Updater to download any binary or payload they wish. This technique is typically known as Living Off the Land and is especially dangerous, as it uses known, common software to download malware.
-
GoldenSpy Chapter 4 - GoldenHelper
Trustwave
See publicationDirectly preceding GoldenSpy, another malware family was used to covertly access the networks of companies doing business in China. This is the story of GoldenHelper.
-
GoldenSpy Chapter 3
Trustwave
See publicationThis blog shows our analysis of a new binary, now being distributed by Intelligent Tax software, that is identical in operations to the original GoldenSpy Uninstallers, but specifically designed to evade detection by the YARA rule provided in our blog
-
Unsanitized file validation leads to Malicious payload download via Office binaries.
LOLBAS / LOLBINS
See publicationhttps://lolbas-project.github.io/lolbas/OtherMSBinaries/Excel/
https://lolbas-project.github.io/lolbas/OtherMSBinaries/Powerpnt/
https://lolbas-project.github.io/lolbas/OtherMSBinaries/Winword/ -
Vulnerability in Microsoft Teams - uncontrolled endpoint in nuget/squirrel packages
LOLBAS / LOLBINS
See publicationRemote download and execution of payload via Microsoft Teams
-
Vulnerability in Microsoft Teams - uncontrolled endpoint in nuget/squirrel packages
LOLBAS / LOLBINS
See publicationRemote download and execute of payload via Microsoft Teams
Honors & Awards
-
CVE-2020-0696 - Arbitrary code execution in Microsoft Outlook
Microsoft
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0696
-
FireEye Vulnerability Responsible Disclosure
FireEye
Email Security URL Evasion Techniques - https://www.fireeye.com/content/dam/fireeye-www/support/pdfs/2019-q4-security-advisory.pdf
-
Google Vulnerability Responsible Disclosure
Google
https://bughunter.withgoogle.com/profile/e89807f9-ff4f-4890-b32a-4c55c96c7246
-
ExpressVPN Vulnerability disclosure
ExpressVPN
https://www.expressvpn.com/blog/expressvpn-bug-bounty-rewards/
-
Listed 2nd time in security hall of fame of Facebook
Facebook
https://www.facebook.com/whitehat/thanks
-
Listed in security hall of fame of AT&T
AT&T
https://bugbounty.att.com/hof.php
-
Acknowledged by bitcoin.de for disclosing vulnerability
bitcoin.de
Acknowledged by bitcoin.de for disclosing multiple vulnerabilities
-
Listed in security hall of fame of Facebook
facebook.com
https://www.facebook.com/whitehat/thanks
One of my favourite bug,which compromises more than million account without victims knowledge,
Vulnerability: Reset any users password -
Listed in security hall of fame of acquia.com
acquia.com
https://www.acquia.com/how-report-security-issue
-
Listed in security hall of fame of crowdcurity.com
https://www.crowdcurity.com/
https://www.crowdcurity.com/hall-of-fame/all
-
Acknowledged by sherpany.com
sherpany.com
Acknowledged by sherpany.com for disclosing multiple vulnerabilities
-
Acknowledged by Asana.com
asana.com
Acknowledged by asana.com for disclosing security vulnerabilities
-
Acknowledged by magento.com
-
Acknowledged by magento.com for disclosing multiple vulnerabilities
-
Acknowledged by marktplaats.nl
marktplaats.nl
Acknowledged by marktplaats.nl for disclosing security vulnerabilities
-
Listed among with top security researchers
http://www.sakurity.com/
http://www.sakurity.com/hustlers
-
Listed in security hall of fame of Coinkite.com
Coinkite
https://coinkite.com/faq/responsible-disclosure
-
Listed in security hall of fame of Yahoo!
Yahoo!
http://bugbounty.yahoo.com/security_wall.html
-
Listed in security hall of fame of lookout.com
lookout.com
https://www.lookout.com/responsible-disclosure
-
Listed in security hall of fame of Coindrawer.com
coindrawer.com
https://www.coindrawer.com/whitehat/
-
Listed in security hall of fame of clojars.org
https://clojars.org/
https://clojars.org/security
-
Acknowledged by nomadesk.com
nomadesk.com
Acknowledged by nomadesk.com for disclosing multiple vulnerabilities
-
Acknowledged by polarssl.org for disclosing vulnerability
polarssl.org
Acknowledged by polarssl.org for disclosing vulnerability and making them secure
-
Listed in security hall of fame of atlassian.com
www.atlassian.com
https://www.atlassian.com/security/hall-of-fame
-
Listed in security hall of fame of shopify.com
shopify.com
https://www.shopify.com/security-response
-
Best Blogger
Norman Shark
-
Acknowledged by websecurify.com
websecurify.com
Acknowledged by websecurify.com for disclosing vulnerabilities
Recommendations received
-
LinkedIn User
12 people have recommended Reegun Richard
Join now to viewOther similar profiles
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More