[go: up one dir, main page]
More Web Proxy on the site http://driver.im/ Skip to main content

Search

Items tagged with: AlienVault






Patch it up: Old vulnerabilities are everyone's problems

This analysis emphasizes the importance of addressing old vulnerabilities in software systems globally. It highlights the end of Windows 10 support in October 2025 and the risks associated with unpatched systems. The article discusses the relevance of vulnerabilities regardless of geographic location, citing examples like Log4j and NotPetya. It also mentions a recent CVE (CVE-2025-22224) that affected over 40,000 instances globally within a week of discovery. The article stresses the need for regular software updates and patching, regardless of nationality or location, to maintain robust cybersecurity.

Pulse ID: 67d379e0ce69380c331c2dda
Pulse Link: otx.alienvault.com/pulse/67d37…
Pulse Author: AlienVault
Created: 2025-03-14 00:35:44

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #InfoSec #Log4j #OTX #OpenThreatExchange #Windows #bot #AlienVault













Hundreds of thousands of rubles for your secrets: cyber spies disguise themselves as recruiters

Cybercriminals impersonating a real company are sending fake job descriptions to employees of targeted organizations. The attackers, known as Squid Werewolf, are offering substantial sums of money, potentially hundreds of thousands of rubles, in exchange for sensitive information. This sophisticated phishing campaign aims to exploit the trust associated with legitimate recruitment processes to gather confidential data from unsuspecting employees. The operation demonstrates the evolving tactics of cyber espionage groups, blending social engineering with financial incentives to compromise organizational security.

Pulse ID: 67d1758164fe4b799677296c
Pulse Link: otx.alienvault.com/pulse/67d17…
Pulse Author: AlienVault
Created: 2025-03-12 11:52:32

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #Espionage #ICS #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #Rust #SocialEngineering #bot #AlienVault








Analysis of Lazarus Group's Attack Targeting Windows Web Servers

The Lazarus group has been targeting Windows web servers, particularly in South Korea, installing webshells and C2 scripts to use compromised servers as proxies. The attacks involve multiple stages, including the use of LazarLoader malware and privilege escalation tools. The C2 scripts act as proxies between the malware and secondary C2 servers. Various webshells were identified, including RedHat Hacker and custom ASP shells. The LazarLoader downloader was used to fetch additional payloads, while a privilege escalation tool exploited UAC bypass techniques. The attackers aim to establish persistence and gain elevated access on compromised systems.

Pulse ID: 67d046ba5b8e5cade96959d8
Pulse Link: otx.alienvault.com/pulse/67d04…
Pulse Author: AlienVault
Created: 2025-03-11 14:20:42

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #InfoSec #Korea #Lazarus #Malware #OTX #OpenThreatExchange #SouthKorea #Windows #bot #AlienVault


Caution Against Watering Hole Attack and Malicious File Distribution Disguised as Unification Education Support Application

A watering hole attack targeting unification education program applicants has been discovered. The attackers uploaded malicious HWP document files to a notice board for an educational program. When opened, the file executes hidden malicious code through OLE objects. The malware creates persistence using scheduled tasks, downloads additional payloads, and communicates with a command and control server. Based on the techniques used, the attack is attributed to the North Korean Kimsuky group. Users are advised to exercise caution when downloading application forms from such websites.

Pulse ID: 67d046fb6d5b34c23aa7ac80
Pulse Link: otx.alienvault.com/pulse/67d04…
Pulse Author: AlienVault
Created: 2025-03-11 14:21:47

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #Education #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #UK #bot #AlienVault













Medusa Ransomware Activity Continues to Increase

Medusa ransomware attacks jumped by 42% between 2023 and 2024. This increase in activity continues to escalate, with almost twice as many Medusa attacks observed in January and February 2025 as in the first two months of 2024.

Pulse ID: 67ca228b1821bc391a93a04e
Pulse Link: otx.alienvault.com/pulse/67ca2…
Pulse Author: AlienVault
Created: 2025-03-06 22:32:42

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RansomWare #bot #AlienVault