Search
Items tagged with: AlienVault
Patch it up: Old vulnerabilities are everyone's problems
This analysis emphasizes the importance of addressing old vulnerabilities in software systems globally. It highlights the end of Windows 10 support in October 2025 and the risks associated with unpatched systems. The article discusses the relevance of vulnerabilities regardless of geographic location, citing examples like Log4j and NotPetya. It also mentions a recent CVE (CVE-2025-22224) that affected over 40,000 instances globally within a week of discovery. The article stresses the need for regular software updates and patching, regardless of nationality or location, to maintain robust cybersecurity.
Pulse ID: 67d379e0ce69380c331c2dda
Pulse Link: otx.alienvault.com/pulse/67d37…
Pulse Author: AlienVault
Created: 2025-03-14 00:35:44
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Log4j #OTX #OpenThreatExchange #Windows #bot #AlienVault
LevelBlue - Open Threat Exchange
Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.LevelBlue Open Threat Exchange
Hundreds of thousands of rubles for your secrets: cyber spies disguise themselves as recruiters
Cybercriminals impersonating a real company are sending fake job descriptions to employees of targeted organizations. The attackers, known as Squid Werewolf, are offering substantial sums of money, potentially hundreds of thousands of rubles, in exchange for sensitive information. This sophisticated phishing campaign aims to exploit the trust associated with legitimate recruitment processes to gather confidential data from unsuspecting employees. The operation demonstrates the evolving tactics of cyber espionage groups, blending social engineering with financial incentives to compromise organizational security.
Pulse ID: 67d1758164fe4b799677296c
Pulse Link: otx.alienvault.com/pulse/67d17…
Pulse Author: AlienVault
Created: 2025-03-12 11:52:32
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #ICS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #Rust #SocialEngineering #bot #AlienVault
Analysis of Lazarus Group's Attack Targeting Windows Web Servers
The Lazarus group has been targeting Windows web servers, particularly in South Korea, installing webshells and C2 scripts to use compromised servers as proxies. The attacks involve multiple stages, including the use of LazarLoader malware and privilege escalation tools. The C2 scripts act as proxies between the malware and secondary C2 servers. Various webshells were identified, including RedHat Hacker and custom ASP shells. The LazarLoader downloader was used to fetch additional payloads, while a privilege escalation tool exploited UAC bypass techniques. The attackers aim to establish persistence and gain elevated access on compromised systems.
Pulse ID: 67d046ba5b8e5cade96959d8
Pulse Link: otx.alienvault.com/pulse/67d04…
Pulse Author: AlienVault
Created: 2025-03-11 14:20:42
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Korea #Lazarus #Malware #OTX #OpenThreatExchange #SouthKorea #Windows #bot #AlienVault
Caution Against Watering Hole Attack and Malicious File Distribution Disguised as Unification Education Support Application
A watering hole attack targeting unification education program applicants has been discovered. The attackers uploaded malicious HWP document files to a notice board for an educational program. When opened, the file executes hidden malicious code through OLE objects. The malware creates persistence using scheduled tasks, downloads additional payloads, and communicates with a command and control server. Based on the techniques used, the attack is attributed to the North Korean Kimsuky group. Users are advised to exercise caution when downloading application forms from such websites.
Pulse ID: 67d046fb6d5b34c23aa7ac80
Pulse Link: otx.alienvault.com/pulse/67d04…
Pulse Author: AlienVault
Created: 2025-03-11 14:21:47
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Education #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #UK #bot #AlienVault
Medusa Ransomware Activity Continues to Increase
Medusa ransomware attacks jumped by 42% between 2023 and 2024. This increase in activity continues to escalate, with almost twice as many Medusa attacks observed in January and February 2025 as in the first two months of 2024.
Pulse ID: 67ca228b1821bc391a93a04e
Pulse Link: otx.alienvault.com/pulse/67ca2…
Pulse Author: AlienVault
Created: 2025-03-06 22:32:42
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RansomWare #bot #AlienVault