Check out our latest research: Shady business of game server boosting powered by 0day exploits, malware family and fake game servers. Report: https://t.co/JWUGX4HPPu
#Breaking#ESETresearch releases a paper about Ebury, among the most advanced server-side Linux malware, which was deployed to 400,000 servers over the course of 15 years, primarily for financial gain. @marc_etienne_ https://t.co/R5yFdlTjqS 1/8
Some notes from analyzing the bash part obfuscation of the xz/liblzma part – link leads to the part I found most interesting – it was added in 5.6.1:
https://t.co/JzEzG5uNZZ
The video and slides of my talk "A 3-Year Tale of Hacking a Pwn2Own Target..." are out. Hope this presentation somehow could be another reference to your next research!
➡️ Video: https://t.co/A1bYtCT5dl
➡️ Slides: https://t.co/wMydKH0251
Android.Pandora trojans compromise Android TV boxes during firmware updates or when applications for viewing pirated video content are installed. This backdoor inherited its advanced DDoS-attack capabilities from the Linux.Mirai trojan.
https://t.co/mYrPqPDblv
When CS:GO clients connected to our server, they got more than a game. We found 3 RCE vulnerabilities to give clients an unexpected 'welcome'.
Ready for a deep-dive? 🎮🔧🎆
https://t.co/5hNvzHceVj #InfoSec#CSGO#Exploit
Demonstrating CVE-2022-37958 RCE Vuln. Reachable via any Windows application protocol that authenticates. Yes, that means RDP, SMB and many more. Please patch this one, it's serious!
https://t.co/ikOrTvQIJs
If you enjoy sailing the sea, beware! @MajorTomSec has found a critical security vulnerability in @RaftSurvivaGame, allowing 0-click RCE on any online player. The vendor has remained silent for 5 months, so here are the details: https://t.co/oqW4u4VIpM
#ESETResearch discovered that #LuckyMouse/#APT27 used a code-signing certificate belonging to VMPsoft, the developer of the VMProtect packer. The signed file is a loader for the SysUpdate backdoor (aka Soldier). We notified VMPSoft of this compromise 1/4
https://t.co/iCC221bwxw
We have just discovered two malicious PyPi packages masquerading as HTTP libraries: ‘ultrarequests’ and ‘pyquest’. The description of these packages is taken from the ‘requests’ package. The malicious code is in the class ‘HTTPError’ (‘exceptions[.]py’ file) [1/3]
I'm reading a blog post about a remote code execution within VirusTotal where I can not identify any VT machine. Some people confuse 3rd party machines with VT machines, it's not a new thing. Many partners and 3rd parties download and process VT feed to do their stuff.
ℹ️ Latest from our Threat Intelligence team: Spear phishing campaign targets Russian dissidents with Cobalt Strike and (new to us) RAT.
https://t.co/kXDu7VXMmg
Check out our new research on Calypso APT attack on a telecommunications company in Kazakhstan.
The attack mainly relied on BackDoor.Whitebird & BackDoor.PlugX backdoors along with Fast Reverse Proxy tool.
PDF: https://t.co/W4uD8g9LXU
IoCs: https://t.co/ZfvoG9Lwjz
#BREAKING#ESETresearch discovered an ongoing #MustangPanda campaign using new #Korplug variant deployed with elaborate custom loaders. Every stage of the deployment process uses anti-analysis techniques and control-flow obfuscation 1/6 @barberousse_bin https://t.co/ErrrFC76DM
CVE-2022-23812 undermines the global open source community and requires us to flag impacted versions of node-ipc as security vulnerabilities. Learn how to mitigate in the blog post. (2/2) https://t.co/hTf47SKgdP