LNK File Disguised as Certificate Distributing RokRAT Malware - ASEC BLOG
AhnLab Security Emergency response Center
https://asec.ahnlab.com/en/65076/
🎖@malwr
AhnLab Security Emergency response Center
https://asec.ahnlab.com/en/65076/
🎖@malwr
ASEC
LNK File Disguised as Certificate Distributing RokRAT Malware - ASEC
LNK File Disguised as Certificate Distributing RokRAT Malware ASEC
Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three — Elastic Security Labs
In previous articles in this multipart series, malware researchers on the Elastic Security Labs team dove into the REMCOS execution flow. In this article, you’ll learn more about REMCOS configuration structure and its C2 commands.
https://www.elastic.co/security-labs/dissecting-remcos-rat-part-three
🎖@malwr
In previous articles in this multipart series, malware researchers on the Elastic Security Labs team dove into the REMCOS execution flow. In this article, you’ll learn more about REMCOS configuration structure and its C2 commands.
https://www.elastic.co/security-labs/dissecting-remcos-rat-part-three
🎖@malwr
www.elastic.co
Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three — Elastic Security Labs
In previous articles in this multipart series, malware researchers on the Elastic Security Labs team dove into the REMCOS execution flow. In this article, you’ll learn more about REMCOS configuration structure and its C2 commands.
madhuakula/kubernetes-goat: Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
https://github.com/madhuakula/kubernetes-goat
🎖@malwr
https://github.com/madhuakula/kubernetes-goat
🎖@malwr
GitHub
GitHub - madhuakula/kubernetes-goat: Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes…
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀 - madhuakula/kubernetes-goat
From Spam to AsyncRAT: Tracking the Surge in Non-PE Cyber Threats
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/from-spam-to-asyncrat-tracking-the-surge-in-non-pe-cyber-threats/
🎖@malwr
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/from-spam-to-asyncrat-tracking-the-surge-in-non-pe-cyber-threats/
🎖@malwr
McAfee Blog
From Spam to AsyncRAT: Tracking the Surge in Non-PE Cyber Threats | McAfee Blog
Authored by Yashvi Shah and Preksha Saxena AsyncRAT, also known as "Asynchronous Remote Access Trojan," represents a highly sophisticated malware variant
JavaScript Debugging with Maglev Compiler | by VXRL | Medium
Other than fuzzing for vulnerabilities of our previous blogpost, it would be good to understand how Maglev compiler works via debugging. In the following article, we are going to briefly introduce…
https://vxrl.medium.com/javascript-debugging-with-maglev-compiler-6b2a26cb1a3a
🎖@malwr
Other than fuzzing for vulnerabilities of our previous blogpost, it would be good to understand how Maglev compiler works via debugging. In the following article, we are going to briefly introduce…
https://vxrl.medium.com/javascript-debugging-with-maglev-compiler-6b2a26cb1a3a
🎖@malwr
Medium
JavaScript Debugging with Maglev Compiler
Twitter: @Darkfloyd1014
CrowdStrike Enhances Cloud Asset Visualization to Accelerate Risk Prioritization
The massive increase in cloud adoption has driven adversaries to focus their efforts on cloud environments — a shift that led to cloud intrusions increasing by 75% in 2023, emphasizing the need for stronger cloud security. Larger scale leads to larger risk. As organizations increase their quantity of cloud assets, their attack surface grows. Each...
https://www.crowdstrike.com/blog/enhanced-cloud-asset-visualization/
🎖@malwr
The massive increase in cloud adoption has driven adversaries to focus their efforts on cloud environments — a shift that led to cloud intrusions increasing by 75% in 2023, emphasizing the need for stronger cloud security. Larger scale leads to larger risk. As organizations increase their quantity of cloud assets, their attack surface grows. Each...
https://www.crowdstrike.com/blog/enhanced-cloud-asset-visualization/
🎖@malwr
CrowdStrike.com
CrowdStrike Enhances Cloud Asset Visualization to Accelerate Risk Prioritization
We have enhanced CrowdStrike Falcon® Cloud Security capabilities so security analysts can easily visualize their cloud assets’ connections and better understand and prioritize risks.
Russia-Linked CopyCop Uses LLMs to Weaponize Influence Content at Scale
Insikt Group shares research on CopyCop: a Russian-linked network using AI for disinformation to influence US, UK, and French politics. Dive into the details.
https://www.recordedfuture.com/russia-linked-copycop-uses-llms-to-weaponize-influence-content-at-scale
🎖@malwr
Insikt Group shares research on CopyCop: a Russian-linked network using AI for disinformation to influence US, UK, and French politics. Dive into the details.
https://www.recordedfuture.com/russia-linked-copycop-uses-llms-to-weaponize-influence-content-at-scale
🎖@malwr
CVE-2024-21115: An Oracle VirtualBox LPE Used to Win Pwn2Own
https://www.thezdi.com/blog/2024/5/9/cve-2024-21115-an-oracle-virtualbox-lpe-used-to-win-pwn2own
🎖@malwr
https://www.thezdi.com/blog/2024/5/9/cve-2024-21115-an-oracle-virtualbox-lpe-used-to-win-pwn2own
🎖@malwr
Zero Day Initiative
Zero Day Initiative — CVE-2024-21115: An Oracle VirtualBox LPE Used to Win Pwn2Own
In this guest blog from Pwn2Own winner Cody Gallagher, he details CVE-2024-21115 – an Out-of-Bounds (OOB) Write that occurs in Oracle VirtualBox that can be leveraged for privilege escalation. This bug was recently patched by Oracle in April. Cody has…
zEus Stealer Distributed via Crafted Minecraft Source Pack | FortiGuard Labs
FortiGuard Labs analysis of a zEus batch stealer distributed via a crafted Minecraft source pack.
https://www.fortinet.com/blog/threat-research/zeus-stealer-distributed-via-crafted-minecraft-source-pack
🎖@malwr
FortiGuard Labs analysis of a zEus batch stealer distributed via a crafted Minecraft source pack.
https://www.fortinet.com/blog/threat-research/zeus-stealer-distributed-via-crafted-minecraft-source-pack
🎖@malwr
Fortinet Blog
zEus Stealer Distributed via Crafted Minecraft Source Pack
FortiGuard Labs analysis of a zEus batch stealer distributed via a crafted Minecraft source pack. Learn more.…
Fuel for thought: Can a driverless car get arrested?
What happens when problems caused by autonomous vehicles are not the result of errors, but the result of purposeful attacks?
https://www.welivesecurity.com/en/cybersecurity/fuel-thought-can-driverless-car-get-arrested/
🎖@malwr
What happens when problems caused by autonomous vehicles are not the result of errors, but the result of purposeful attacks?
https://www.welivesecurity.com/en/cybersecurity/fuel-thought-can-driverless-car-get-arrested/
🎖@malwr
Welivesecurity
Fuel for thought: Can a driverless car get arrested?
What happens when problems caused by autonomous vehicles are not the result of errors, but the result of purposeful attacks?
Coverage guided fuzzing for native Android libraries (Frida & Radamsa) - KnifeCoat
Coverage guided fuzzing for native Android libraries (Frida & Radamsa) - KnifeCoat
https://knifecoat.com/Posts/Coverage+guided+fuzzing+for+native+Android+libraries+(Frida+%26+Radamsa)
🎖@malwr
Coverage guided fuzzing for native Android libraries (Frida & Radamsa) - KnifeCoat
https://knifecoat.com/Posts/Coverage+guided+fuzzing+for+native+Android+libraries+(Frida+%26+Radamsa)
🎖@malwr
KnifeCoat
Coverage guided fuzzing for native Android libraries (Frida & Radamsa) - KnifeCoat
Intro Recently I have been getting into userland application testing on Android. I want to credit Iddo and Jacob for their excellent course on attacking IM Applications which I took at zer0con. As a …
2024-05-09: GootLoader activity
https://www.malware-traffic-analysis.net/2024/05/09/index.html
🎖@malwr
https://www.malware-traffic-analysis.net/2024/05/09/index.html
🎖@malwr
Telekopye: Chamber of Neanderthals’ secrets
Insight into groups operating Telekopye bots that scam people in online marketplaces
https://www.welivesecurity.com/en/eset-research/telekopye-chamber-neanderthals-secrets/
🎖@malwr
Insight into groups operating Telekopye bots that scam people in online marketplaces
https://www.welivesecurity.com/en/eset-research/telekopye-chamber-neanderthals-secrets/
🎖@malwr
Welivesecurity
Telekopye: Chamber of Neanderthals’ secrets
ESET research shares insights about groups operating Telekopye, Telegram bots that scam people in online marketplaces, their internal onboarding process, different tricks of trade that Neanderthals use, and more.
Doctor Web’s annual virus activity review for 2023
https://news.drweb.com/show/?i=14851&lng=en&c=5
🎖@malwr
https://news.drweb.com/show/?i=14851&lng=en&c=5
🎖@malwr
Exploring the Depths of SolarMarker's Multi-tiered Infrastructure
Uncover SolarMarker’s multi-tiered infrastructure and its impact on sectors like education, healthcare, and government. Learn more.
https://www.recordedfuture.com/exploring-the-depths-of-solarmarkers-multi-tiered-infrastructure
🎖@malwr
Uncover SolarMarker’s multi-tiered infrastructure and its impact on sectors like education, healthcare, and government. Learn more.
https://www.recordedfuture.com/exploring-the-depths-of-solarmarkers-multi-tiered-infrastructure
🎖@malwr
XWiki Remote Code Execution Vulnerability
Overview The SonicWall Capture Labs threat research team became aware of CVE-2024-31984, which is a code injection vulnerability in XWiki’s management of space titles and has a critical CVSS score of 9.9. After assessing the
https://blog.sonicwall.com/en-us/2024/05/xwiki-remote-code-execution-vulnerability/
🎖@malwr
Overview The SonicWall Capture Labs threat research team became aware of CVE-2024-31984, which is a code injection vulnerability in XWiki’s management of space titles and has a critical CVSS score of 9.9. After assessing the
https://blog.sonicwall.com/en-us/2024/05/xwiki-remote-code-execution-vulnerability/
🎖@malwr
Foxit PDF “Flawed Design” Exploitation
https://research.checkpoint.com/2024/foxit-pdf-flawed-design-exploitation/
🎖@malwr
https://research.checkpoint.com/2024/foxit-pdf-flawed-design-exploitation/
🎖@malwr
Check Point Research
Foxit PDF “Flawed Design” Exploitation - Check Point Research
Check Point Research has identified an unusual pattern of behavior involving PDF exploitation, mainly targeting users of Foxit Reader. This exploit triggers security warnings that could deceive unsuspecting users into executing harmful commands. Check Point…
GitCaught: Threat Actor Leverages GitHub Repository for Malicious Infrastructure
Discover how Russian-speaking hackers leverage GitHub to host malware disguised as legitimate software. Explore the campaign, implications, and protection strategies.
https://www.recordedfuture.com/gitcaught-threat-actor-leverages-github-repository-for-malicious-infrastructure
🎖@malwr
Discover how Russian-speaking hackers leverage GitHub to host malware disguised as legitimate software. Explore the campaign, implications, and protection strategies.
https://www.recordedfuture.com/gitcaught-threat-actor-leverages-github-repository-for-malicious-infrastructure
🎖@malwr
Remcos Is Pairing with PrivateLoader to Extend Its Capabilities
Overview This week, the SonicWall Capture Labs threat research team investigated a sample of the RemcosRAT that uses a PrivateLoader module to provide additional data and persistence on the victim’s machine. By installing VB scripts,
https://blog.sonicwall.com/en-us/2024/05/remcos-is-pairing-with-privateloader-to-extend-its-capabilities/
🎖@malwr
Overview This week, the SonicWall Capture Labs threat research team investigated a sample of the RemcosRAT that uses a PrivateLoader module to provide additional data and persistence on the victim’s machine. By installing VB scripts,
https://blog.sonicwall.com/en-us/2024/05/remcos-is-pairing-with-privateloader-to-extend-its-capabilities/
🎖@malwr
ESET APT Activity Report Q4 2023–Q1 2024
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2023 and Q1 2024
https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2023-q1-2024/
🎖@malwr
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2023 and Q1 2024
https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2023-q1-2024/
🎖@malwr
Welivesecurity
ESET APT Activity Report Q4 2023–Q1 2024
This report summarizes notable activities of selected advanced persistent threat (APT) groups that were documented by ESET researchers from October 2023 until the end of March 2024.
MICROSOFT SECURITY BULLETIN COVERAGE FOR MAY 2024
Overview Microsoft’s May 2024 Patch Tuesday has 59 vulnerabilities, 25 of which are Remote Code Execution vulnerabilities. The SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of
https://blog.sonicwall.com/en-us/2024/05/microsoft-security-bulletin-coverage-for-may-2024/
🎖@malwr
Overview Microsoft’s May 2024 Patch Tuesday has 59 vulnerabilities, 25 of which are Remote Code Execution vulnerabilities. The SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of
https://blog.sonicwall.com/en-us/2024/05/microsoft-security-bulletin-coverage-for-may-2024/
🎖@malwr