Cyber Morning Call - #571 - 26/06/2024
Listen now
Description
[Referências do Episódio] From Dormant to Dangerous: P2Pinfect Evolves to Deploy New Ransomware and Cryptominer - https://www.cadosecurity.com/blog/from-dormant-to-dangerous-p2pinfect-evolves-to-deploy-new-ransomware-and-cryptominer  New attack uses MSC files and Windows XSS flaw to breach networks - https://www.bleepingcomputer.com/news/security/new-grimresource-attack-uses-msc-files-and-windows-xss-flaw-to-breach-networks/  GrimResource -  Microsoft Management Console for initial access and evasion - https://www.elastic.co/security-labs/grimresource  페이스북과 MS관리콘솔을 활용한 Kimsuky APT 공격 발견 - https://www.genians.co.kr/blog/threat_intelligence/facebook  Polyfill supply chain attack hits 100K+ sites - https://sansec.io/research/polyfill-supply-chain-attack  Polyfill.io JavaScript supply chain attack impacts over 100K sites - https://www.bleepingcomputer.com/news/security/polyfillio-javascript-supply-chain-attack-impacts-over-100k-sites/  8220 Mining Gang's New Tool: k4spreader - https://blog.xlab.qianxin.com/8220-k4spreader-new-tool-en/  UAC-0184 Abuses Python in DLL Sideloading for XWORM Distribution - https://cyble.com/blog/uac-0184-abuses-python-in-dll-sideloading-for-xworm-distribution/  Roteiro e apresentação: Carlos Cabral e Bianca Oliveira Edição de áudio: Paulo Arruzzo Narração de encerramento: Bianca Garcia
More Episodes
[Referências do Episódio] Kimsuky deploys TRANSLATEXT to target South Korean academia - https://www.zscaler.com/blogs/security-research/kimsuky-deploys-translatext-target-south-korean-academia  MerkSpy: Exploiting CVE-2021-40444 to Infiltrate Systems -...
Published 06/28/24
[Referências do Episódio] Auth. Bypass In (Un)Limited Scenarios - Progress MOVEit Transfer (CVE-2024-5806) - https://labs.watchtowr.com/auth-bypass-in-un-limited-scenarios-progress-moveit-transfer-cve-2024-5806/  Fortra FileCatalyst Workflow Unauthenticated SQLi -...
Published 06/27/24
Published 06/27/24