home.social

#rdp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #rdp, aggregated by home.social.

fetched live
  1. ФСТЭК описала периметр в 35 пунктах. 26 из них не стоят ни рубля

    Читатель принёс мне в комментарии документ ФСТЭК как аргумент: длина пароля должна быть не менее 15 символов. Документ оказался настоящим, цифра в нём есть, но работает она не так, как её процитировали. Заодно выяснилось, что «Рекомендации по защите сетевого периметра информационных (автоматизированных) систем» лежат на сайте регулятора с 10 марта, в них 35 пунктов, и разбора этого документа нигде нет. Разбираю все 35: что запрещено прямым текстом, какие три пункта не выполнены почти нигде и сколько из них требуют денег. Спойлер: покупки требуют четыре пункта, ещё пять зависят от того, что уже стоит, а оставшиеся 26 закрываются регламентом и настройками.

    habr.com/ru/articles/1072288/

    #ФСТЭК #сетевой_периметр #межсетевой_экран #управление_уязвимостями #сегментация_сети #RDP #приказ_117

  2. Hackers Hijack Thousands of WordPress Sites to Use as C2 Servers for StopAndProtect Malware

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/t

    Pulse ID: 6a848e9e0130217404ac4e13
    Pulse Link: otx.alienvault.com/pulse/6a848
    Pulse Author: CyberHunter_NL
    Created: 2026-08-18 16:55:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RDP #Word #Wordpress #bot #CyberHunter_NL

  3. Selective Remote после первой статьи: как RDP-клиент для macOS вырос в рабочее место для RDP, SSH и SFTP

    Selective Remote начинался как небольшой RDP-клиент для macOS, а к версии 0.22.0 вырос в рабочее пространство для RDP, SSH, SFTP и SSH-туннелей. Рассказываю, зачем SFTP понадобилась передача Server → Server, почему Drag & Drop пришлось спускать со SwiftUI на AppKit и как несколько отдельных экранов превратились в связанные Workspace.

    habr.com/ru/articles/1071532/

    #Selective_Remote #macOS #RDP #SSH #SFTP #SwiftUI #AppKit #FreeRDP #OpenSSH #open_source

  4. ::%16777216 — странный артефакт в логах RDP: история одного расследования

    В логах RDP-подключений иногда встречается запись, которая выглядит как ::%16777216 — и это вместо привычного IP-адреса. Про такой артефакт пишут в отраслевых отчетах уже несколько лет. Он всплывает в описаниях атак с туннелированием RDP, и практически всегда авторы упоминают утилиту ngrok. Но при этом почти никто не объясняет, что это за значение, какова его природа и почему оно записано именно так. Складывается впечатление, что авторы либо не знают ответа, либо считают эту деталь слишком мелкой для пояснений. Я Константин Грищенко, в Positive Technologies я отвечаю за развитие технологий SOC. Работаю в этой сфере больше пяти лет, а всего в практической информационной безопасности — уже 23 года. В ноябре 2024 года в одном из докладов на конференции SOC Forum я в очередной раз увидел упоминание этого артефакта и решил все-таки попробовать разобраться в том, что это такое.

    habr.com/ru/companies/pt/artic

    #cybersecurity #windows #rdp #ngrok #ioc #16777216

  5. How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding

    WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...

    Pulse ID: 6a7b3ff969397d537e5d24fa
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:30:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault

  6. Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access

    Indicators extracted from public reporting. Source: zscaler.com/blogs/security-res

    Pulse ID: 6a7ad5b8c169a9d5615a2bf2
    Pulse Link: otx.alienvault.com/pulse/6a7ad
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 07:56:40

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #Zscaler #bot #CyberHunter_NL

  7. Researchers Build WordPress Exploit Using OpenAI's GPT

    Indicators extracted from public reporting. Source: slcyber.io/research-center/wp2

    Pulse ID: 6a79a0e3fdd7e1a39099a924
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 09:58:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RDP #Word #Wordpress #bot #CyberHunter_NL

  8. New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response

    Indicators extracted from public reporting. Source: wordfence.com/blog/2026/08/psa

    Pulse ID: 6a7975f91d2273d6abfcbc73
    Pulse Link: otx.alienvault.com/pulse/6a797
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 06:55:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RDP #SupplyChain #Word #Wordpress #bot #CyberHunter_NL

  9. BdThemes Supply Chain Attack Compromises WordPress via Poisoned API

    Pulse ID: 6a785c94a880b6c45e4905cd
    Pulse Link: otx.alienvault.com/pulse/6a785
    Pulse Author: cryptocti
    Created: 2026-08-09 10:55:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #SupplyChain #Word #Wordpress #bot #cryptocti

  10. Analysis of a Phishing Email Attack Case

    The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.

    Pulse ID: 6a70c6f0d15cdde2874f628e
    Pulse Link: otx.alienvault.com/pulse/6a70c
    Pulse Author: AlienVault
    Created: 2026-08-03 16:50:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault

  11. Caturday

    https://ragtagcommunity.wordpress.com/2026/08/02/rdp-sunday-catfrontation/

    a portmanteau storm of cattywampus 
    washed up on a sandbox in Catmandu county
    feline delectimus défectuepuss
    concerning litterbox cattiquette
    used by the tigerlilly tabby
    with de rigueurpurr felid indifference
    for the calicokittykat copycat
    resulting in a catastrophic catfrontation

    #blog #blogging #bloggingprompts #caturday #prompts #RagtagDailyPrompt #RDP #writingcommunity
  12. 4 Steps to Easily Access #RDP Remote Desktop with #Windows #VPS

    Read this guide, "4 Steps to Easily Access RDP Remote Desktop with Windows VPS" to connect your Windows VPS to RDP (remote desktop protocol). RDP technology also fulfills other IT needs. For example, some computers, such as rack-mounted servers in data centers, don't have input ...
    Continued 👉 blog.radwebhosting.com/access- #vpsservers #remotedesktopprotocol #microsoftremotedesktop #vpsguide #rdpserver #windowsserver #vpsplatform

  13. Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core

    Pulse ID: 6a698ece10f40a7a5f6c66d4
    Pulse Link: otx.alienvault.com/pulse/6a698
    Pulse Author: Tr1sa111
    Created: 2026-07-29 05:25:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #RemoteCodeExecution #Word #Wordpress #bot #Tr1sa111

  14. Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core

    Two chained vulnerabilities in WordPress Core enable unauthenticated remote code execution on installations running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1. The first flaw affects the REST API batch endpoint validation, while the second is a SQL injection in the post query layer. When exploited together, attackers achieve full administrator access and deploy webshells. Active exploitation has been confirmed with a public proof-of-concept available. Attackers conduct mass scanning followed by automated compromise sequences that create unauthorized administrator accounts with w2s_ prefixes, upload malicious plugins, and establish persistent remote access. Observed incidents show multiple exploitation attempts before successful compromise. Fixed versions 6.9.5 and 7.0.2 are available, with forced auto-updates deployed. Organizations should patch immediately or implement WAF rules blocking anonymous access to the batch endpoint.

    Pulse ID: 6a6823754b2a6d2295eb3330
    Pulse Link: otx.alienvault.com/pulse/6a682
    Pulse Author: AlienVault
    Created: 2026-07-28 03:35:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #RemoteCodeExecution #SQL #Word #Wordpress #bot #AlienVault

  15. RDP Проброс микрофона не работает из-за лицензирования (Windows Server)

    Да, звучит странно, но заголовок - не кликбейт, а быстрый ответ, который возможно ты ищешь. Почему-то это ни где не описано и ChatGPT не знает. Я сам выяснил путём экспериментов.

    habr.com/ru/articles/1062498/

    #rdp #микрофон #проброс #windows

  16. Exploitation in the Wild of wp2shell

    A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.

    Pulse ID: 6a61c32bf83a8841dbf45852
    Pulse Link: otx.alienvault.com/pulse/6a61c
    Pulse Author: AlienVault
    Created: 2026-07-23 07:30:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #PHP #RAT #RDP #RemoteCodeExecution #Vulnerability #Word #Wordpress #bot #AlienVault

  17. 4 Steps to Easily Access #RDP Remote Desktop with #Windows #VPS

    Read this guide, "4 Steps to Easily Access RDP Remote Desktop with Windows VPS" to connect your Windows VPS to RDP (remote desktop protocol). RDP technology also fulfills other IT needs. For example, some computers, such as rack-mounted servers in data centers, don't have input ...
    Continued 👉 blog.radwebhosting.com/access- #vpsservers #vpsguide #windowsserver #microsoftremotedesktop #rdpserver #remotedesktopprotocol #vpsplatform

  18. Take a path

    From Ragtag Daily Prompt, the prompt today is: Concrete Jungle

    In the Concrete Jungle of downtown Minneapolis, where tall buildings and dark shadows reign, where strangers fear the intimacy of eye contact with others, where a phone demands attention to provide comfort, the trees need to reach out and introduce themselves.

    Leave the jungle and step off the concrete path for just a moment.

    Follow another path.

    Look up.

    Look around.

    Breath.

    #Concrete #ConcreteJungle #Downtown #DowntownMinneapolis #Fog #Minneapolis #MorningFog #Nature #Photography #Photos #RagtagDailyPrompt #RDP #Trees
  19. We've just released #FreeRDP 3.30.0 addressing a severe server side issue.
    Update highly recommended.

    Check it out at freerdp.com

    #security #rdp #CVE #remotedesktop #g-r-d #gnome-remote-desktop #krdp

  20. 🔒💻 FreeRDP 3.29 a fost lansat: O actualizare critică axată pe corectarea unor vulnerabilități majore de securitate

    FreeRDP, cea mai populară și utilizată implementare open-source a protocolului Remote Desktop Protocol (RDP) de la Microsoft, a primit o nouă versiune de importanță majoră: FreeRDP 3.29. Această lansare este catalogată drept una critică pentru toți administratorii de sistem și utilizatorii care se bazează pe conexiuni la distanță, aducând un set masiv de patch-uri destinate să blocheze potențiale atacuri și să sporească stabilitatea generală a protocolului.

    Iată principalele detalii și noutăți aduse de FreeRDP 3.29:

    🔹 Corecții extinse de securitate (Vulnerability Fixes):
    Obiectivul principal al acestei versiuni este securizarea canalelor de comunicare. FreeRDP 3.29 rezolvă mai multe vulnerabilități de securitate raportate recent, inclusiv probleme legate de:

    Out-of-bounds read/write: Au fost corectate erori în parsarea pachetelor de date primite, care puteau fi exploatate de un server sau client malițios pentru a provoca prăbușirea aplicației sau, în cazuri extreme, pentru a executa cod de la distanță (RCE).

    Scurgeri de memorie (Memory Leaks): S-au eliminat numeroase scurgeri de resurse în gestionarea canalelor virtuale dinamice, asigurând o utilizare mult mai stabilă a memoriei în timpul sesiunilor lungi de utilizare.

    🔹 Optimizări pentru clienții grafici xfreerdp și wlfreerdp:
    Utilitarele de vizualizare au primit îmbunătățiri importante sub capotă:

    Wayland (wlfreerdp): A fost îmbunătățită sincronizarea clipboard-ului partajat și s-au rezolvat problemele de redimensionare dinamică a ferestrelor de pe desktopurile moderne Linux (cum ar fi GNOME sau KDE Plasma sub Wayland).

    X11 (xfreerdp): S-a optimizat randarea grafică în modul ecran complet (fullscreen) pe configurațiile cu mai multe monitoare cu rezoluții mixte.

    🔹 Redirecționare Smart Card mai sigură:
    Sistemul de redirecționare a cititoarelor de carduri inteligente (Smart Cards), utilizat intens în mediile enterprise pentru autentificare securizată, a fost securizat suplimentar. S-au rezolvat problemele legate de deconectările neașteptate ale token-urilor de securitate și s-a îmbunătățit compatibilitatea cu standardele moderne de criptare.

    🔹 Compatibilitate îmbunătățită cu OpenSSL 3.x:
    FreeRDP 3.29 își aliniază biblioteca internă la cele mai noi standarde și practici din OpenSSL 3.x. Acest lucru nu doar că îmbunătățește performanța conexiunilor securizate prin TLS, dar oferă și un plus de siguranță împotriva atacurilor de tip Man-in-the-Middle (MitM).

    Având în vedere numărul mare de vulnerabilități corectate în această versiune, administratorilor de sistem le este recomandat să actualizeze pachetele FreeRDP pe servere, stații de lucru și clienți subțiri (thin clients) cât mai curând posibil.

    #OpenSource #FreeRDP #RemoteDesktop #RDP #CyberSecurity #LinuxTools #SysAdmin #TechNews #Linuxiac