#ESETresearch discovered an #exploit targeting Firefox and Windows zero days, used in the wild by Russia-aligned #RomCom. Browsing a specially crafted web page runs arbitrary code with the privileges of the user, compromising the PC. @dmnsch & R.Dumont https://t.co/qugbteKlcE 1/7
#ESETresearch uncovered a new compromise that we attribute to #FrostyNeighbor, using links in malicious PDFs sent via spearphishing attachments to target governmental organizations in Ukraine. @dmnsch https://t.co/2x75QnEMIe 1/5
#ESETresearch has discovered a zero-day vulnerability in WinRAR, exploited in the wild by Russia-aligned #RomCom@dmnsch@cherepanov74
https://t.co/DjAaBJJa5O 1/7
📣 Oops!... They did it again!!!
61 Talks submitted and so many too good that, once again, we had to increase a bit the number of accepted talks. 🔥
#PIVOTcon25 Agenda is finally here, and the caliber is insane!!! Check it out ➡️ link below in second post
#CTI#ThreatIntel 1/19
🚨 Warning: A critical #vulnerability (CVE-2024-9680) in Firefox is being actively exploited.
Don’t wait—ensure your browsers are updated now to protect against potential remote code execution.
Learn more: https://t.co/Agj4ZbBBOB
#cybersecurity#hacking
#ESETresearch investigated two previously undocumented toolsets used by the #GoldenJackal APT group, both of which target air-gapped systems. https://t.co/oh9WPggwsQ 1/6
#ESETresearch’s @jiboutin and @matthieu_faou will be presenting at @labscon_io this Friday. Join them on site to hear about #Ebury - see the the full scale of a sophisticated Linux threat & about DigitalRecyclers, another member of the APT15 galaxy. https://t.co/r1W2xGUo8z
#ESETresearch has analyzed a single-click exploit for WPS Office for Windows being used in the wild by threat actor #APT-C-60. Analysis of the vendor’s silently released patch led to the discovery of another #vulnerability. 1/8 https://t.co/TgSgUroMm1
ESETresearch discovered a zero-day exploit of #Telegram for Android allowing attackers to share malicious payloads that appear as video files via chat. We named the vulnerability being exploited #EvilVideo. https://t.co/3tWy5ae7rX @lukasstefanko 1/4
#ESETresearch discovered a signed, vulnerable, ad-injecting driver from a mysterious Chinese company. This threat, which we dubbed HotPage, comes self-contained in an executable that installs its main driver and injects libraries into Chromium-based browsers. 1/7
Look Out for Common Email #Phishing Subjects! 🚨
Our recent analysis of #phishingemails reveals the most commonly used subjects by #threatactors:
💰 Invoices and Payments
⚠️ Urgent Requests
📦 Logistics and Shipping
🔒 Password Resets and Account Security
#SecureYourEmail
#ESETresearch has released its latest APT Activity Report covering October 2023 to March 2024 (Q4 2023 - Q1 2024). During this period, we observed a sharp increase in activity of 🇮🇷 Iran-aligned threat groups, which shifted their focus to more disruptive operations. 1/2
#ESETresearch has discovered a new campaign by 🇨🇳China-aligned #APT#EvasivePanda, leveraging the Monlam Festival to target Tibetans. The campaign included a targeted watering hole, compromised news website, and an additional supply-chain attack ... https://t.co/gkdmncTPER 1/7
If you are a threat intelligence/security researcher and you are looking for the fully translated: https://t.co/Mf7qBsEhgw dump.
@lys and I translated it all here: https://t.co/UVocE6xSR3
#ESETResearch has observed an alarming growth of deceptive Android loan apps offering personal loans designed to defraud users and gain their personal information. Many of these apps found their way to official marketplaces.
@LukasStefanko https://t.co/Dz0rn3bfxb 1/8