|
You are here |
lab52.io | ||
| | | | |
blog.talosintelligence.com
|
|
| | | | | * Cisco Talos has observed an unknown threat actor conducting a phishing campaign targeting Facebook business and advertising account users in Taiwan. * The decoy email and fake PDF filenames are designed to impersonate a company's legal department, attempting to lure the victim into downloading and executing malware. * This campaign abuses Google's | |
| | | | |
blog.eclecticiq.com
|
|
| | | | | EclecticIQ researchers continue to track a Chinese state-sponsored APT group called Mustang Panda. In December 2022, this group started targeting Europe with a new spearphishing campaign using a customized variant of the PlugX backdoor. | |
| | | | |
securityinaction.wordpress.com
|
|
| | | | | TL; DR In recent months threat actors have been leveraging alternative means of compromising Windows based systems in order to evade detection. Make certain to download and install software from legitimate sources and where possible make use of the Windows driver blocklist (further recommendations listed below). ==================== By employing techniques such as DLL sideloading (defined... | |
| | | | |
eapolsniper.github.io
|
|
| | | [AI summary] The blog post discusses a critical security vulnerability in Splunk Universal Forwarders, allowing attackers to exploit weak passwords and API access to gain SYSTEM or root privileges on networked systems. | ||