🌸Spring (cyber) cleaning time! Here’s your checklist:
1. Update passwords
2. Enable multi-factor authentication
3. Back up your data
No technical background required. Visit NICCS for additional online safety tips: https://t.co/nspfhF4IQC
Palo Alto Networks has disclosed a severe zero-day vulnerability (CVE-2024-3400) affecting its market-leading firewall software, PAN-OS. This vulnerability carries a CVSS score of 10.0, indicating its critical severity
https://t.co/KXpW8bmji9
@whichbuffer@BushidoToken@Gi7w0rm They also talk about sstap
https://t.co/iCMsrzU7Il
SSTap, short for SOCKSTap, is used to “socksify” TCP and UDP connections at the network layer.
In the Trendmicro article they are also talking about SOCKS5 being used.
We saw new #Qbot#Qakbot "tchk07" from PDF > URLs today. MSI > AdobeAC.dll w/ export EditOwnerInfo.
This is still very low volume and targeted.
Huge shout out to our fantastic @Myrtus0x0 for the RE and config extraction. IOCs in original thread.
Samples:
https://t.co/XiykxirG6T
@tunnelgre@Cryptolaemus1 They use mail thread hijacking based on earlier send mail.
That way, they try to make users believe it is a valid mail. While this is not the case.
🆕 Top 10 Cyber Threats of 2023!
While you're rockin' around the TTPs 🎄 Grab a mince pie 🥧 and have a look back over the last year before we head into 2024 🎆
🔗 https://t.co/3ruXqhEUgy
#infosec#cybersecurity#cti#threatintel
hxxp[://]ec2-35-179-8-15[.]eu-west-2[.]compute[.]amazonaws[.]com/
hxxp[://]35[.]179[.]8[.]15/
AND
hxxps[://]app[.]alwasl[.]tn
#FAKEUPDATE Both have redirect to
hxxps[://]my[.]hoqer[.]com/temp/WebModuleBrowser[.]zip
👾Pivoting from the domain reveals an interesting small cluster....
🔓92.240.80.5 0/88 VT Score
🔓81.16.32.65 2/88 VT Score
🔓185.165.40.224 0/88 VT Score
🔓94.74.115.3 0/88 VT Score but Flagged by @Cybervrf
🔓188.165.219.33 2/88 VT Score
🔓161.97.185.178 0/88 VT Score
All hosting the update page on their active ports!
https://t.co/mwwYdum6kA
https://t.co/SmIzioABSC
#FAKEUPDATE #KryptoCTI #KryptoKloud #C2Engine