Microsoft blocked Office macros in 2022. Attackers moved to ISO files. Microsoft fixed ISO files. Attackers moved to LNK and OneNote. Microsoft closed those too. By mid-2024 attackers had landed on MSC files, the administrative console files used by IT teams to manage Windows systems. GrimResource exploits a cross-site scripting vulnerability in apds.dll that was reported in 2018 and never patched. The sample that exposed the technique was a red team payload accidentally uploaded to VirusTotal by a blue team analyst who picked it up during an assessment. When it first landed on VirusTotal on June 6 2024, zero antivirus engines flagged it.
New blog is out! Digging into TAG-150โs evolving tradecraft across #DinDoor, #DenoRAT, and #NightshadeC2.
We break down the infection chain from ClickFix/MSI โ AI-generated PowerShell โ DinDoor โ DenoRAT, which ultimately executes NightshadeC2 in memory via a Python loader that invokes reflective PE injection shellcode.
https://t.co/c9DM0BALZC
Weโve received notice that the Department of Commerce has lifted export controls on Claude Fable 5 and Mythos 5.
We'll begin restoring access tomorrow, and will share an update soon.
Weโre grateful to our users for their patience, and to everyone who worked with us on redeploying the models.
Microsoft Sentinel just leveled up with Sentinel Data Lake:
โ Powered by Microsoft Fabric OneLake
โ Native support for KQL and PySpark
โ Analyze hot, archived, and long-term logs (no rehydration)
โ Break free from ingestion based SIEM cost models
This changes how we do security at scale
https://t.co/WRN7hCtPfd
A few weeks ago, I was responding to a cybersecurity incident - $500,000 have been stolen from a #blockchain developer. The infected operating system was freshly installed, and the victim was vigilant about cybersecurity. How could this happen? New supply chain attack? [1/6]
@SuperSmada Accountability is the main issue mixed with lack morals and thuggery from top to bottom. Mind you citizens are not excluded, they're also part of the problem