home.social

Search

1000 results for “alien”

  1. ufofeed.com/250809/response-fr Response from my backyard tree Big Homie to those Reddit friends who claimed trees are stupid not sentient and do not have consciousness as a statement of fact. Looks like a universal language #Alien #Aliens

  2. ufofeed.com/250809/response-fr Response from my backyard tree Big Homie to those Reddit friends who claimed trees are stupid not sentient and do not have consciousness as a statement of fact. Looks like a universal language #Alien #Aliens

  3. Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities

    Cisco Talos tracks active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager, allowing remote attackers to obtain administrative privileges. The exploitation is attributed to UAT-8616, a sophisticated threat actor previously involved in similar attacks. Additionally, multiple threat clusters have been exploiting CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 since March 2026, following public release of proof-of-concept code by ZeroZenX Labs. Post-compromise activities include deployment of various webshells, including XenShell, Godzilla, and Behinder variants, along with cryptocurrency miners, red team frameworks like Sliver and AdaptixC2, and credential stealers. Ten distinct threat clusters have been identified, each utilizing different malicious tooling and infrastructure. Affected systems require immediate patching and security measures.

    Pulse ID: 6a062c38dfdb5434bb2f0876
    Pulse Link: otx.alienvault.com/pulse/6a062
    Pulse Author: AlienVault
    Created: 2026-05-14 20:10:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cisco #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RAT #Sliver #Talos #Troll #Vulnerability #bot #cryptocurrency #AlienVault

  4. Kazuar: Anatomy of a nation-state botnet

    Kazuar is a sophisticated malware attributed to Russian state actor Secret Blizzard, having evolved from a traditional backdoor into a highly modular peer-to-peer botnet ecosystem. The malware comprises three distinct module types—Kernel, Bridge, and Worker—that distribute functionality across infected systems. A leadership election mechanism ensures only one Kernel module communicates externally, reducing detection opportunities. The architecture supports flexible configuration with over 150 options, multiple C2 channels including HTTP, WebSockets, and Exchange Web Services, and extensive data collection capabilities. Secret Blizzard primarily targets government, diplomatic, and defense organizations in Europe, Central Asia, and Ukraine to support Russian foreign policy and military intelligence objectives. The botnet maintains persistent access through sophisticated IPC mechanisms, staged data exfiltration during working hours, and comprehensive anti-analysis checks.

    Pulse ID: 6a062c383bdae760fc221b6f
    Pulse Link: otx.alienvault.com/pulse/6a062
    Pulse Author: AlienVault
    Created: 2026-05-14 20:10:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #CentralAsia #CyberSecurity #Europe #Government #HTTP #InfoSec #Kazuar #Malware #Military #NATO #OTX #OpenThreatExchange #RAT #Russia #SMS #UK #Ukr #Ukraine #bot #botnet #AlienVault

  5. Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files

    This analysis examines new obfuscation techniques employed by Gremlin stealer malware to conceal malicious payloads within embedded resources. A variant protected by sophisticated commercial packing utility uses instruction virtualization, transforming code into custom bytecode executed by a private virtual machine. The malware siphons sensitive information including payment card details, browser cookies, session tokens, cryptocurrency wallet data, and FTP/VPN credentials from compromised systems. It exfiltrates data to attacker-controlled servers at hxxp[:]194.87.92[.]109 for potential publication or sale. Recent iterations incorporate expanded Discord token extraction, active financial fraud through crypto clipper functionality that replaces cryptocurrency wallet addresses in real-time, and WebSocket-based session hijacking to bypass modern cookie protections. The malware employs advanced anti-analysis techniques including XOR-encoded payloads in .NET resource sections, identifier renaming, string encryp...

    Pulse ID: 6a073a73501adf1f890b1a5e
    Pulse Link: otx.alienvault.com/pulse/6a073
    Pulse Author: AlienVault
    Created: 2026-05-15 15:23:31

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CyberSecurity #Discord #FinancialFraud #ICS #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #RAT #RCE #Troll #VPN #bot #cryptocurrency #AlienVault