Mount Point — pt.1
Mount Point — pt.1 🙂 Any investigation is an analysis of operating system artifacts. And to obtain them, you often have to work with virtual machine images, suc…
[ FEED // CHRONO // 267 ITEMS ]
Mount Point — pt.1 🙂 Any investigation is an analysis of operating system artifacts. And to obtain them, you often have to work with virtual machine images, suc…
PrevedMedved 👋 — it's Lumma Stealer again In mid-November, the PT ESC cyber threat intelligence team recorded a campaign distributing the malware Lumma Stealer…
Another stealer in Python?! 🫣 Since the beginning of September, we have been tracking attacks that at first glance could be attributed to the activity of the La…
📑 TaxOff: looks like you have… a backdoor In the third quarter, specialists from the TI department of the Positive Technologies Expert Security Center (PT Exper…
What exactly is wrong with this AES? ❔ Attackers often use encryption to obfuscate parts of malware samples that may be of greatest interest during research. Wh…
Through the blockchain to the data ⭐️ Researchers from Socket and Checkmarx have reported on an interesting malicious campaign in NPM. The attackers mimicked pl…
Not a Pwn2Own bug 🙂 CVE-2024-43641: a CWE-190 type error allowed overflowing the reference count on a _CM_KEY_SECURITY instance. The vulnerable code was located…
Over, over, can you hear us? 😲 Despite the fact that hackers have recently gotten lazy and increasingly don't develop anything of their own, original attack ide…
🔄 Major malware rules update Suricata I hope you remember that we have a public Suricata rules repository (we wrote about launching the resource in another post…
📲 Cloud services from the "MeHaFon" operator News from the field: the PT ESC team is observing a new campaign by the Cloud Atlas group targeting government orga…
APT-C-60, aka DarkHotel 💿 We once talked about the use of VHDX files in attacks and why it is convenient (no, this is not a call to action). You can find that p…
😏 Exclusively for Escalator, the ESC-VR team shares details about the vulnerability (CVE-2024-43629) that we found in the Desktop Window Manager component, allo…