🚨 #ShellTorch New CVSS: 9.8 vulnerability in #PyTorch model server TorchServe, threatens countless #AI users. Immediate action is required! >> https://t.co/BoBgpmTnUi
Today! At @AppSec Village, @gkpln3 and I will dive into open-source shadow vulnerabilities and shed light on an emerging vulnerability concept and our journey uncovering it. Be there! #defcon31@defcon.
https://t.co/oBJ15uRkX7
[1/7] Operation #ElectroRAT is a new campaign that takes sizable measures to steal crypto wallets. For more information about the operation - https://t.co/CWLnOevKir
The following is a technical analysis->
@IntezerLabs
Operation #ElectroRAT
Already thousands of crypto wallets stolen. Extensive campaign includes written from scratch RAT hidden in trojanized applications.
Windows, Linux and macOS samples undetected in VirusTotal
https://t.co/KyBqPhZ0jW
Here it is, proud to release the OST map.
A central location to track threat actor usage of open source offensive tools.
I have man people to thank for allowing me to speak with both sides of the debate to understand this issue deeply.
Enjoy! :)
My new blog post about TeamTNT abusing a legitimate tool to gain full control over victim servers, first time attackers use legitimate 3rd party software to target Linux and cloud infrastructure. Check it out:
https://t.co/MYg25rLrP2
TeamTNT is abusing a legitimate tool to gain full control over victim servers—essentially functioning as a backdoor. To our knowledge, this is the first time an attacker has used legitimate third party software to target cloud infrastructure https://t.co/9Tq7dfh0QP
I wrote a tutorial how to hunt for malware that uses OST libraries. It's a pretty advanced technique and I've been able to catch some low detected samples and track threat groups migrating to use new OST libraries using this technique. Hope you enjoy.
https://t.co/GUdmDqg8K2
Undetected Doki attack actively infecting vulnerable #Docker servers in the cloud. Attacker uses a novel Domain Generation Algorithm (DGA) based on a DogeCoin digital wallet to generate C&C domains. Research by @NicoleFishi19 and @kajilot https://t.co/CS1aK5DXjv
Huge discovery by our research team - #Docker servers in the cloud with exposed API are at risk of being hacked within a few hours with a fully undetected #Linux malware.
Payload with 0 detections in VT for months. Read the technical report here -
https://t.co/EsVixav3tP
My very first blog is out! As part of an ongoing attack on vulnerable Docker servers, a new undetected malware called Doki is dropped. It uses DogeCoin digital wallet to generate C&C domains. Check it out:
https://t.co/n6Qiqzg30V
[1/3]
🆕 Linux version of #Lazarus's #ManusCrypt variant F. Its PE version was reported by the @USCERT_gov in May 2020
https://t.co/Bejr1XJ4Ms
->>
My very first blog is now published! Part 1 out of a multi-part series that will provide you practical knowledge for #ELF malware analysis. Check it out https://t.co/TFz2gEirad
We just shared our Linux binaries map, which allows you to explore the code-sharing relationship between all binary files in a standard Azure Ubuntu cloud workload!
https://t.co/est4Q7Vich
Raw data available here - https://t.co/tv72iCAlWT
My new blog post about continued Ke3chang (APT15 🇨🇳) tool changes in 2020 and their new "Ketrum" tools.
https://t.co/0WVwAoWfpc
@zuzana_hromcova was very helpful with her previous documentation of the group's activities in 2019.