home.social

#qakbot — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #qakbot, aggregated by home.social.

  1. 🔥 Operation Endgame is BACK! This time targeting #BumbleBee, #Latrodectus, #DanaBot, #WarmCookie, #Qakbot and #Trickbot!

    Once again this is a HUGE win, with a truly international effort! 💪

    As with phase one of #OperationEndgame, Spamhaus are providing remediation support - those affected will be contacted in due course with steps to take.

    For more information, read our write-up here:
    👉 spamhaus.org/resource-hub/malw

  2. Трендовые уязвимости мая: лингвистический лесоруб и таинственный файл на ломаном английском

    Хабр, привет! Уже по традиции я, Александр Леонов, ведущий эксперт лаборатории PT Expert Security Center, рассказываю про трендовые уязвимости месяца. Всего их было четыре: 1️⃣ уязвимость, приводящая к удаленному выполнения кода в многоплатформенном опенсорсном инструменте для сбора и обработки журналов Fluent Bit (CVE-2024-4323); 2️⃣ уязвимость, приводящая к удаленному выполнения кода в корпоративной веб-вики Confluence (CVE-2024-21683); уязвимости Microsoft, связанные с 3️⃣ обходом функций безопасности в Windows MSHTML Platform (CVE-2024-30040) и 4️⃣ повышением привилегий в Windows DWM Core Library (CVE-2024-30051). Узнать самые опасные уязвимости мая

    habr.com/ru/companies/pt/artic

    #трендовые_уязвимости #cve #vulnerability_management #microsoft #эксплойт #confluence #dwm #qakbot #ole #патчи

  3. Mentioned Malware Families: Ryuk, Bashlite, QakBot

    Aliases for Ryuk: win.ryuk
    Malpedia link for Ryuk: malpedia.caad.fkie.fraunhofer.
    Aliases for Bashlite: elf.bashlite, gayfgt, Gafgyt, qbot, torlus, lizkebab
    Malpedia link for Bashlite: malpedia.caad.fkie.fraunhofer.
    Aliases for QakBot: win.qakbot, Oakboat, Pinkslipbot, Qbot, Quakbot
    Malpedia link for QakBot: malpedia.caad.fkie.fraunhofer.

    #Ryuk #Bashlite #QakBot

    Aliases provided by Malpedia.

  4. Mentioned Malware Families: Ryuk, Bashlite, QakBot

    Aliases for Ryuk: win.ryuk
    Malpedia link for Ryuk: malpedia.caad.fkie.fraunhofer.
    Aliases for Bashlite: elf.bashlite, gayfgt, Gafgyt, qbot, torlus, lizkebab
    Malpedia link for Bashlite: malpedia.caad.fkie.fraunhofer.
    Aliases for QakBot: win.qakbot, Oakboat, Pinkslipbot, Qbot, Quakbot
    Malpedia link for QakBot: malpedia.caad.fkie.fraunhofer.

    #Ryuk #Bashlite #QakBot

    Aliases provided by Malpedia.

  5. This week's wrap-up of infosec news is out, just in time for your morning commute: opalsec.substack.com/p/soc-gou

    #Qakbot have gotten in on the #OneNote action - turns out so too has every other threat actor under the sun.

    Iran's #OilRig/#APT34 has been caught in the act, abusing the legitimate Password Filters feature to siphon creds, and exfiltrating them via compromised mail channels.

    Some interesting techniques were observed in a recent #SocGholish campaign, including passively enumerating usera through event logs and disabling Restricted Admin mode to enable the theft of creds from memory.

    A series of vulnerabilities in the Fortran GoAnywhere MFT file transfer application, QNAP NAS appliances, and VMWare ESXi servers should be top of your list this morning - make sure you're not exposed!

    All that and much more, to help you shake off the cobwebs this Monday morning: opalsec.substack.com/p/soc-gou

    #infosec #CyberAttack #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #redteam #soc #threatintel #threatintelligence #vmware #poc