|
You are here |
www.welivesecurity.com | ||
| | | | |
blog.eclecticiq.com
|
|
| | | | | EclecticIQ researchers observed multiple weaponized phishing emails probably targeting the Security Service of Ukraine (SSU), NATO allies like Latvia, and private companies, Culver Aviation. | |
| | | | |
blog.talosintelligence.com
|
|
| | | | | Talos also discovered a new PowerShell command-line argument embedded in the LNK file to bypass anti-virus products and download the final payload into the victims' host. | |
| | | | |
www.cybereason.com
|
|
| | | | | Cybereason GSOC observed distribution of the Bumblebee Loader and post-exploitation activities including privilege escalation, reconnaissance and credential theft. Bumblebee operators use the Cobalt Strike framework throughout the attack and abuse credentials for privilege escalation to access Active Directory, as well as abusing a domain administrator account to move laterally, create local user accounts and exfiltrate data... | |
| | | | |
blog.eclecticiq.com
|
|
| | | This issue of the Analyst Prompt looks at IRIDUIM's ransomware campaign causing disruption in Ukraine and Poland, the continued use of log4shell by threats actors across the threat landscape, and Australia's new joint standing operation to disrupt and stop cybercriminal syndicates. | ||