News:

Lab - Just Launched!

Main Menu

Recent posts

#61
IT News / Phoenix UEFI vulnerability imp...
Last post by ixsky -
Phoenix UEFI vulnerability impacts hundreds of Intel PC models

A newly discovered vulnerability in Phoenix SecureCore UEFI firmware tracked as CVE-2024-0762 impacts devices running numerous Intel CPUs, with Lenovo already releasing new firmware updates to resolve the flaw. [...]

Source: Phoenix UEFI vulnerability impacts hundreds of Intel PC models
#62
IT News / Sysinternals' Process Monitor ...
Last post by ixsky -
Sysinternals' Process Monitor Version 4 Released, (Sat, Jun 22nd)

Version 4.01 of Sysinternals' Process Monitor (procmon) was released (just one day after the release of version 4.0).

These releases bring improvements to performance and the user interface.



And a new event for the Process start was added.

This can now be displayed as a column:





And it can also be used as a filter, for example to filter out all process that started before the new process you want to analyze:



Didier Stevens
Senior handler
blog.DidierStevens.com

 
 (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Source: Sysinternals' Process Monitor Version 4 Released, (Sat, Jun 22nd)
#63
IT News / CosmicSting flaw impacts 75% o...
Last post by ixsky -
CosmicSting flaw impacts 75% of Adobe Commerce, Magento sites

A vulnerability dubbed "CosmicSting" impacting Adobe Commerce and Magento websites remains largely unpatched nine days after the security update has been made available, leaving millions of sites open to catastrophic attacks. [...]

Source: CosmicSting flaw impacts 75% of Adobe Commerce, Magento sites
#64
IT News / Linux version of RansomHub ran...
Last post by ixsky -
Linux version of RansomHub ransomware targets VMware ESXi VMs

The RansomHub ransomware operation is using a Linux encryptor designed specifically to encrypt VMware ESXi environments in corporate attacks. [...]

Source: Linux version of RansomHub ransomware targets VMware ESXi VMs
#65
IT News / ExCobalt Cyber Gang Targets Ru...
Last post by ixsky -
ExCobalt Cyber Gang Targets Russian Sectors with New GoRed Backdoor

Russian organizations have been targeted by a cybercrime gang called ExCobalt using a previously unknown Golang-based backdoor known as GoRed.
"ExCobalt focuses on cyber espionage and includes several members active since at least 2016 and presumably once part of the notorious Cobalt Gang," Positive Technologies researchers Vladislav Lunin and Alexander Badayev said in a technical report

Source: ExCobalt Cyber Gang Targets Russian Sectors with New GoRed Backdoor
#66
IT News / Warning: New Adware Campaign T...
Last post by ixsky -
Warning: New Adware Campaign Targets Meta Quest App Seekers

A new campaign is tricking users searching for the Meta Quest (formerly Oculus) application for Windows into downloading a new adware family called AdsExhaust.
"The adware is capable of exfiltrating screenshots from infected devices and interacting with browsers using simulated keystrokes," cybersecurity firm eSentire said in an analysis, adding it identified the activity earlier this month.
"

Source: Warning: New Adware Campaign Targets Meta Quest App Seekers
#67
IT News / UNC3886 hackers use Linux root...
Last post by ixsky -
UNC3886 hackers use Linux rootkits to hide on VMware ESXi VMs

A suspected Chinese threat actor tracked as UNC3886 uses publicly available open-source rootkits named 'Reptile' and 'Medusa' to remain hidden on VMware ESXi virtual machines, allowing them to conduct credential theft, command execution, and lateral movement. [...]

Source: UNC3886 hackers use Linux rootkits to hide on VMware ESXi VMs
#68
IT News / U.S. Treasury Sanctions 12 Kas...
Last post by ixsky -
U.S. Treasury Sanctions 12 Kaspersky Executives Amid Software Ban

The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) imposed sanctions against a dozen individuals serving executive and senior leadership roles at Kaspersky Lab, a day after the Russian company was banned by the Commerce Department.
The move "underscores our commitment to ensure the integrity of our cyber domain and to protect our citizens against malicious cyber

Source: U.S. Treasury Sanctions 12 Kaspersky Executives Amid Software Ban
#69
IT News / SolarWinds Serv-U path travers...
Last post by ixsky -
SolarWinds Serv-U path traversal flaw actively exploited in attacks

Threat actors are actively exploiting a SolarWinds Serv-U path-traversal vulnerability, leveraging publicly available proof-of-concept (PoC) exploits. [...]

Source: SolarWinds Serv-U path traversal flaw actively exploited in attacks
#70
IT News / CDK Global hacked again while ...
Last post by ixsky -
CDK Global hacked again while recovering from first cyberattack

Car dealership SaaS platform CDK Global suffered an additional breach Wednesday night as it was starting to restore systems shut down in an previous cyberattack. [...]

Source: CDK Global hacked again while recovering from first cyberattack