Malware News
13K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
What is the primary purpose of Command and Control (C&C) servers in relation to malware?
Final Results
4%
To encrypt user data
2%
To block access to websites
4%
To increase internet speed
91%
To remotely control infected devices
New details on TinyTurla’s post-compromise activity reveal full kill chain

We now have new information on the entire kill chain this actor uses, including the tactics, techniques and procedures (TTPs) utilized to steal valuable information from their victims and propagate through their infected enterprises.

https://blog.talosintelligence.com/tinyturla-full-kill-chain/


πŸŽ–@malwr
Vulnerabilities in CDeX software

CERT Poland has received a report about three vulnerabilities (from CVE-2024-2463 to CVE-2024-2465) found in CDeX software.

https://cert.pl/en/posts/2024/03/CVE-2024-2463/


πŸŽ–@malwr
Borrower beware: Common loan scams and how to avoid them

Personal loan scams prey on your financial vulnerability and might even trap you in a vicious circle of debt. Here’s how to avoid being scammed when considering a loan.

https://www.welivesecurity.com/en/scams/borrower-beware-common-loan-scams/


πŸŽ–@malwr
Do you like to read security related tweets here? To read these tweets you should have twitter app.
Final Results
46%
I have twitter and I want to read these posts
54%
I don't have twitter and I can't read these posts
Violent Extremists Dox Executives, Enabling Physical Threats

Domestic violent extremists are increasingly doxing senior U.S. leaders β€” publishing their personally identifiable information without their consent and with malicious intent.

https://www.recordedfuture.com/violent-extremists-dox-executives-enabling-physical-threats


πŸŽ–@malwr
πŸ‘1
β€œCVE-2024-21388”- Microsoft Edge’s Marketing API Exploited for Covert Extension Installation | by Guardio | Mar, 2024 | Medium

At Guardio, making browsing safer is what we do best, with one of our key products being a browser extension that boosts users’ security on desktop browsers. Our expertise in this area led us to…

https://labs.guard.io/cve-2024-21388-microsoft-edges-marketing-api-exploited-for-covert-extension-installation-879fe5ad35ca


πŸŽ–@malwr
πŸ‘1
Uncovering Malicious Infrastructure with DNS Pivoting
Demonstrating DNS pivoting and analysis techniques for uncovering Malicious infrastructure

https://embee-research.ghost.io/infrastructure-analysis-with-dns-pivoting/


πŸŽ–@malwr