Akamai researchers have discovered a new Magento campaign which we have dubbed "Xurum" in reference to the attacker's C2 server.
🔵 Evidence indicates Russian origin
🟠The login page masquerades as an error page containing a hidden form
Full write-up:
https://t.co/uL8LLoPfSB
#DanaBot kicking off the phishing and fraud season traditionally seen around year-end holidays with new tactics and techniques to steal money and sensitive information. New article by Ruby Cohen, @s0meGirlR3m, and @RoyXmos https://t.co/6yj07VQ4lF #trojan
[In Review] NSA's #EternalBlue is still kicking! Multi-vector campaign detected exploiting ThinkPHP, JBoss, & WebLogic spreads evasive #malware that replicates via SMB EternalBlue exploit. Packed using #VMProtect, it replaces a genuine Windows DLL & disguises itself as a service.
[IN REVIEW] A Chinese threat actor we track updated their arsenal with NSA exploits #EthernalBlue for #SMB and Esteemaudit for #RDP. Along with a compiled python scanner exploiting CVE-2017-10271 WebLogic #RCE which 1/66 AV are detecting.
[In Review] New campaign spotted spreading #XBash#malware via #Elastic Search CVE-2015-1427 vulnerability. #HFS exposes additional tools the attacker has but isn’t using for this attack.
[Article] "New #Golang#malware is spreading via multiple exploits to mine Monero" by Harsh Chawla, Remi Cohen and Andrey Shalnev: https://t.co/RvypjiIKcp
[In Review] New #cryptocurrency campaign targeting #Jenkins instances using Jenkins ACL Bypass and Metaprogramming RCE #vulnerability. Attempts to spread itself by scanning for Redis instances without authentication. CVE-2019-1003000 CVE-2019-1003001 CVE-2019-1003002
[In Review Update] Oracle addresses the #WebLogic zero-day vulnerability by allocating CVE-2019-2725 and releasing an out-of-band security update: https://t.co/REfFXoj2nh #0day