Chinese Backdoor for Telecom Systems
A while ago we showed the backdoor that the Chinese have been using to maintain persistence across telecom systems.
The backdoor attaches itself to a raw network socket and inspects incoming traffic. It sees packets before firewall rules have a chance to process them. So even if your firewall is configured correctly, the backdoor can still see traffic that should have been blocked.
To access the system hackers send a magic byte to get a reverse shell
We also showed how you can detect it
https://t.co/fBXtksn2Ju
@three_cube@_aircorridor #apt #redteam #blueteam
We’re happy to announce that our EDR Internals & Development training is now in its final stages of development.
Over the past several months, an enormous amount of work has gone into building this highly technical & detailed training. The course covers the internals of modern EDR from both user-mode and kernel-mode perspectives, including techniques like syscall hooking, filesystem minifilters, ETW telemetry, memory scanning, kernel callbacks, process instrumentation callbacks, call stack tracing, and anti-tampering mechanisms.
The course concludes with building a limited yet functional custom EDR agent and we test it against several malware techniques to gain practical experience with detection engineering and EDR internals.
This huge undertaking would not have been possible without @GigelV41464 who dedicated countless hours to analyzing different EDR products, building custom implementations, analyzing internal mechanisms, and documenting the techniques with excellent depth and clarity.
The official launch date is scheduled for June 15, 2026 but starting today, we're opening access to an early bird discount of 20% for a limited time.
EDR Internals & Development: https://t.co/oN6qcMjLr2
🚨 A new UNPATCHED Linux kernel “Dirty Frag” LPE flaw enables root access on Ubuntu, RHEL, Fedora and other distributions.
Researchers released a working proof-of-concept exploit capable of gaining root in a single command.
Details here: https://t.co/gxjVsS5pwo
🚨 Warning: Microsoft Defender is wrongly flagging some DigiCert certificates as Trojan:Win32/Cerdigent.A!dha, triggering widespread false positives on Windows systems.
Admins report certificates being removed from the Windows trust store after recent Defender signature updates.
What’s happening:
🔴 Two DigiCert root certificates flagged as malware
🔴 Some systems remove certs from the AuthRoot trust store
🔴 Detection added in April 30th Defender signature updates
Microsoft has released fixes in Security Intelligence updates version 1.449.430.0.
The issue comes shortly after a DigiCert breach where attackers gained access to support systems and code-signing certificates.
If you're seeing Trojan:Win32/Cerdigent.A!dha alerts, update Defender signatures immediately.
ATT&CK v19 is live! We've split Defense Evasion into Stealth and Defense Impairment, introduced Sub-Techniques to ICS ATT&CK, Detection Strategies to Mobile, and added some AI and Social Engineering to Enterprise. Check out all the details in our blog post https://t.co/XHzwGHZuNX
An update from NIST. Due to volume they’re only going to enrich CVEs that are meaningful to USG federal systems and critical software (some more nuance in the blog post). This means if you’re relying on the NVD data for your enterprise security program and use other software, your tools may not flag software you use as at risk. https://t.co/pI2o2XootK
ATT&CK v19 is coming 4/28! The biggest change this release is the replacement of the Defense Evasion tactic in Enterprise ATT&CK with new Stealth and Impair Defenses tactic. @coolestcatiknow talked more about what's changing back at ATT&CKcon 6.0 https://t.co/giWBDeDPTn.
🚨 Nation-state affiliated threat actors have compromised F5’s systems & downloaded portions of its BIG-IP source code—posing serious risk to FCEB agencies. Follow the guidance in ED 26-01 immediately to protect systems from potential exploits. 🔗 https://t.co/cXH0W4jGZo
🚨 Cyber threat actors are exploiting newly identified zero-day vulnerabilities in Cisco Adaptive Security Appliances via web services, posing significant risk. Federal agencies must act immediately and follow the guidance in Emergency Directive 25-03. 🔗 https://t.co/4DMWopRPtr
Chinese state-sponsored actors are targeting global telecommunications and other critical infrastructure orgs. We’ve joined others worldwide to call these actors out and publish hunting & mitigation guidance to reduce this ongoing threat. https://t.co/saq1a0sT8o