#rdp — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #rdp, aggregated by home.social.
-
ФСТЭК описала периметр в 35 пунктах. 26 из них не стоят ни рубля
Читатель принёс мне в комментарии документ ФСТЭК как аргумент: длина пароля должна быть не менее 15 символов. Документ оказался настоящим, цифра в нём есть, но работает она не так, как её процитировали. Заодно выяснилось, что «Рекомендации по защите сетевого периметра информационных (автоматизированных) систем» лежат на сайте регулятора с 10 марта, в них 35 пунктов, и разбора этого документа нигде нет. Разбираю все 35: что запрещено прямым текстом, какие три пункта не выполнены почти нигде и сколько из них требуют денег. Спойлер: покупки требуют четыре пункта, ещё пять зависят от того, что уже стоит, а оставшиеся 26 закрываются регламентом и настройками.
https://habr.com/ru/articles/1072288/
#ФСТЭК #сетевой_периметр #межсетевой_экран #управление_уязвимостями #сегментация_сети #RDP #приказ_117
-
Hackers Hijack Thousands of WordPress Sites to Use as C2 Servers for StopAndProtect Malware
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/
Pulse ID: 6a848e9e0130217404ac4e13
Pulse Link: https://otx.alienvault.com/pulse/6a848e9e0130217404ac4e13
Pulse Author: CyberHunter_NL
Created: 2026-08-18 16:55:58Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #RDP #Word #Wordpress #bot #CyberHunter_NL
-
Selective Remote после первой статьи: как RDP-клиент для macOS вырос в рабочее место для RDP, SSH и SFTP
Selective Remote начинался как небольшой RDP-клиент для macOS, а к версии 0.22.0 вырос в рабочее пространство для RDP, SSH, SFTP и SSH-туннелей. Рассказываю, зачем SFTP понадобилась передача Server → Server, почему Drag & Drop пришлось спускать со SwiftUI на AppKit и как несколько отдельных экранов превратились в связанные Workspace.
https://habr.com/ru/articles/1071532/
#Selective_Remote #macOS #RDP #SSH #SFTP #SwiftUI #AppKit #FreeRDP #OpenSSH #open_source
-
::%16777216 — странный артефакт в логах RDP: история одного расследования
В логах RDP-подключений иногда встречается запись, которая выглядит как ::%16777216 — и это вместо привычного IP-адреса. Про такой артефакт пишут в отраслевых отчетах уже несколько лет. Он всплывает в описаниях атак с туннелированием RDP, и практически всегда авторы упоминают утилиту ngrok. Но при этом почти никто не объясняет, что это за значение, какова его природа и почему оно записано именно так. Складывается впечатление, что авторы либо не знают ответа, либо считают эту деталь слишком мелкой для пояснений. Я Константин Грищенко, в Positive Technologies я отвечаю за развитие технологий SOC. Работаю в этой сфере больше пяти лет, а всего в практической информационной безопасности — уже 23 года. В ноябре 2024 года в одном из докладов на конференции SOC Forum я в очередной раз увидел упоминание этого артефакта и решил все-таки попробовать разобраться в том, что это такое.
https://habr.com/ru/companies/pt/articles/1068878/
#cybersecurity #windows #rdp #ngrok #ioc #16777216
-
How the ErrTraffic Malware Campaign Uses ClickFix and EtherHiding
WatchGuard Threat Lab identified an active malware-as-a-service campaign leveraging ErrTraffic framework to distribute multiple threats through compromised WordPress websites. The operation employs ClickFix social engineering techniques and EtherHiding, which uses Polygon blockchain smart contracts to conceal command-and-control infrastructure dynamically. The campaign delivers various threats including Vidar infostealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader through multiple delivery methods such as DLL side-loading, process injection, and reflective loaders. Attackers exploit legitimate Windows binaries as LOLBINs, perform anti-analysis checks, create remote threads in browsers to bypass security features like Chrome's Application-Bound Encryption, and utilize various evasion techniques including code virtualization and RunPE. The framework is advertised by user LenAI on cybercrime forums and incorporates a Traffic Distribution System enabling affiliates to monetize victims...
Pulse ID: 6a7b3ff969397d537e5d24fa
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ff969397d537e5d24fa
Pulse Author: AlienVault
Created: 2026-08-11 15:30:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #Browser #Chrome #CyberCrime #CyberSecurity #Encryption #EtherHiding #InfoSec #InfoStealer #Malware #MalwareAsAService #OTX #Onion #OpenThreatExchange #RAT #RDP #SocialEngineering #Vidar #Windows #Word #Wordpress #bot #AlienVault
-
Abyssos RAT Includes RDPWrap-Related Module for Expanded Remote Access
Indicators extracted from public reporting. Source: https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-new-modular-rat
Pulse ID: 6a7ad5b8c169a9d5615a2bf2
Pulse Link: https://otx.alienvault.com/pulse/6a7ad5b8c169a9d5615a2bf2
Pulse Author: CyberHunter_NL
Created: 2026-08-11 07:56:40Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #Zscaler #bot #CyberHunter_NL
-
Researchers Build WordPress Exploit Using OpenAI's GPT
Indicators extracted from public reporting. Source: https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/
Pulse ID: 6a79a0e3fdd7e1a39099a924
Pulse Link: https://otx.alienvault.com/pulse/6a79a0e3fdd7e1a39099a924
Pulse Author: CyberHunter_NL
Created: 2026-08-10 09:58:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RDP #Word #Wordpress #bot #CyberHunter_NL
-
New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response
Indicators extracted from public reporting. Source: https://www.wordfence.com/blog/2026/08/psa-supply-chain-compromise-in-bdthemes-ecosystem-via-poisoned-api-response/
Pulse ID: 6a7975f91d2273d6abfcbc73
Pulse Link: https://otx.alienvault.com/pulse/6a7975f91d2273d6abfcbc73
Pulse Author: CyberHunter_NL
Created: 2026-08-10 06:55:53Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #RDP #SupplyChain #Word #Wordpress #bot #CyberHunter_NL
-
BdThemes Supply Chain Attack Compromises WordPress via Poisoned API
Pulse ID: 6a785c94a880b6c45e4905cd
Pulse Link: https://otx.alienvault.com/pulse/6a785c94a880b6c45e4905cd
Pulse Author: cryptocti
Created: 2026-08-09 10:55:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #SupplyChain #Word #Wordpress #bot #cryptocti
-
Analysis of a Phishing Email Attack Case
The Larva-24009 threat actor, also known as HeptaX, has been conducting phishing email campaigns since 2023, targeting Korean and global users to install malware. Active through 2026, the actor uses LNK files disguised as documents with topics like hospital surveys, blockchain, project proposals, and resumes to target enterprises. Upon execution, obfuscated PowerShell commands deploy backdoors and download additional scripts from command-and-control servers. The attack chain includes persistence mechanisms via Task Scheduler, remote access through QuasarRAT and UltraVNC, and information theft using NirSoft tools, custom keyloggers, and screenshot capabilities. The actor also creates backdoor RDP accounts and exfiltrates credentials, browser data, and user files. Version 2.1 of their Notifier malware utilizes Telegram API for status reporting. The campaigns demonstrate consistent tactics and infrastructure across multiple years of operation.
Pulse ID: 6a70c6f0d15cdde2874f628e
Pulse Link: https://otx.alienvault.com/pulse/6a70c6f0d15cdde2874f628e
Pulse Author: AlienVault
Created: 2026-08-03 16:50:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #BlockChain #Browser #CyberSecurity #Email #Hospital #ICS #InfoSec #InformationTheft #KeyLogger #Korea #LNK #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RDP #SMS #Telegram #VNC #bot #AlienVault
-
Caturday
https://ragtagcommunity.wordpress.com/2026/08/02/rdp-sunday-catfrontation/
a portmanteau storm of cattywampus
#blog #blogging #bloggingprompts #caturday #prompts #RagtagDailyPrompt #RDP #writingcommunity
washed up on a sandbox in Catmandu county
feline delectimus défectuepuss
concerning litterbox cattiquette
used by the tigerlilly tabby
with de rigueurpurr felid indifference
for the calicokittykat copycat
resulting in a catastrophic catfrontation -
4 Steps to Easily Access #RDP Remote Desktop with #Windows #VPS
Read this guide, "4 Steps to Easily Access RDP Remote Desktop with Windows VPS" to connect your Windows VPS to RDP (remote desktop protocol). RDP technology also fulfills other IT needs. For example, some computers, such as rack-mounted servers in data centers, don't have input ...
Continued 👉 https://blog.radwebhosting.com/access-rdp-remote-desktop-with-windows-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #vpsservers #remotedesktopprotocol #microsoftremotedesktop #vpsguide #rdpserver #windowsserver #vpsplatform -
Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core
Pulse ID: 6a698ece10f40a7a5f6c66d4
Pulse Link: https://otx.alienvault.com/pulse/6a698ece10f40a7a5f6c66d4
Pulse Author: Tr1sa111
Created: 2026-07-29 05:25:34Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #RDP #RemoteCodeExecution #Word #Wordpress #bot #Tr1sa111
-
Technical Advisory: wp2shell — Unauthenticated Remote Code Execution and Full Site Takeover in WordPress Core
Two chained vulnerabilities in WordPress Core enable unauthenticated remote code execution on installations running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1. The first flaw affects the REST API batch endpoint validation, while the second is a SQL injection in the post query layer. When exploited together, attackers achieve full administrator access and deploy webshells. Active exploitation has been confirmed with a public proof-of-concept available. Attackers conduct mass scanning followed by automated compromise sequences that create unauthorized administrator accounts with w2s_ prefixes, upload malicious plugins, and establish persistent remote access. Observed incidents show multiple exploitation attempts before successful compromise. Fixed versions 6.9.5 and 7.0.2 are available, with forced auto-updates deployed. Organizations should patch immediately or implement WAF rules blocking anonymous access to the batch endpoint.
Pulse ID: 6a6823754b2a6d2295eb3330
Pulse Link: https://otx.alienvault.com/pulse/6a6823754b2a6d2295eb3330
Pulse Author: AlienVault
Created: 2026-07-28 03:35:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #RAT #RCE #RDP #RemoteCodeExecution #SQL #Word #Wordpress #bot #AlienVault
-
RDP Проброс микрофона не работает из-за лицензирования (Windows Server)
Да, звучит странно, но заголовок - не кликбейт, а быстрый ответ, который возможно ты ищешь. Почему-то это ни где не описано и ChatGPT не знает. Я сам выяснил путём экспериментов.
-
Exploitation in the Wild of wp2shell
A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.
Pulse ID: 6a61c32bf83a8841dbf45852
Pulse Link: https://otx.alienvault.com/pulse/6a61c32bf83a8841dbf45852
Pulse Author: AlienVault
Created: 2026-07-23 07:30:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #Endpoint #InfoSec #OTX #OpenThreatExchange #PHP #RAT #RDP #RemoteCodeExecution #Vulnerability #Word #Wordpress #bot #AlienVault
-
4 Steps to Easily Access #RDP Remote Desktop with #Windows #VPS
Read this guide, "4 Steps to Easily Access RDP Remote Desktop with Windows VPS" to connect your Windows VPS to RDP (remote desktop protocol). RDP technology also fulfills other IT needs. For example, some computers, such as rack-mounted servers in data centers, don't have input ...
Continued 👉 https://blog.radwebhosting.com/access-rdp-remote-desktop-with-windows-vps/?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon.raddemo.host #vpsservers #vpsguide #windowsserver #microsoftremotedesktop #rdpserver #remotedesktopprotocol #vpsplatform -
Take a path
From Ragtag Daily Prompt, the prompt today is: Concrete Jungle
In the Concrete Jungle of downtown Minneapolis, where tall buildings and dark shadows reign, where strangers fear the intimacy of eye contact with others, where a phone demands attention to provide comfort, the trees need to reach out and introduce themselves.
Leave the jungle and step off the concrete path for just a moment.
Follow another path.
Look up.
Look around.
Breath.
#Concrete #ConcreteJungle #Downtown #DowntownMinneapolis #Fog #Minneapolis #MorningFog #Nature #Photography #Photos #RagtagDailyPrompt #RDP #Trees -
We've just released #FreeRDP 3.30.0 addressing a severe server side issue.
Update highly recommended.Check it out at https://freerdp.com
#security #rdp #CVE #remotedesktop #g-r-d #gnome-remote-desktop #krdp
-
🔒💻 FreeRDP 3.29 a fost lansat: O actualizare critică axată pe corectarea unor vulnerabilități majore de securitate
FreeRDP, cea mai populară și utilizată implementare open-source a protocolului Remote Desktop Protocol (RDP) de la Microsoft, a primit o nouă versiune de importanță majoră: FreeRDP 3.29. Această lansare este catalogată drept una critică pentru toți administratorii de sistem și utilizatorii care se bazează pe conexiuni la distanță, aducând un set masiv de patch-uri destinate să blocheze potențiale atacuri și să sporească stabilitatea generală a protocolului.
Iată principalele detalii și noutăți aduse de FreeRDP 3.29:
🔹 Corecții extinse de securitate (Vulnerability Fixes):
Obiectivul principal al acestei versiuni este securizarea canalelor de comunicare. FreeRDP 3.29 rezolvă mai multe vulnerabilități de securitate raportate recent, inclusiv probleme legate de:Out-of-bounds read/write: Au fost corectate erori în parsarea pachetelor de date primite, care puteau fi exploatate de un server sau client malițios pentru a provoca prăbușirea aplicației sau, în cazuri extreme, pentru a executa cod de la distanță (RCE).
Scurgeri de memorie (Memory Leaks): S-au eliminat numeroase scurgeri de resurse în gestionarea canalelor virtuale dinamice, asigurând o utilizare mult mai stabilă a memoriei în timpul sesiunilor lungi de utilizare.
🔹 Optimizări pentru clienții grafici xfreerdp și wlfreerdp:
Utilitarele de vizualizare au primit îmbunătățiri importante sub capotă:Wayland (wlfreerdp): A fost îmbunătățită sincronizarea clipboard-ului partajat și s-au rezolvat problemele de redimensionare dinamică a ferestrelor de pe desktopurile moderne Linux (cum ar fi GNOME sau KDE Plasma sub Wayland).
X11 (xfreerdp): S-a optimizat randarea grafică în modul ecran complet (fullscreen) pe configurațiile cu mai multe monitoare cu rezoluții mixte.
🔹 Redirecționare Smart Card mai sigură:
Sistemul de redirecționare a cititoarelor de carduri inteligente (Smart Cards), utilizat intens în mediile enterprise pentru autentificare securizată, a fost securizat suplimentar. S-au rezolvat problemele legate de deconectările neașteptate ale token-urilor de securitate și s-a îmbunătățit compatibilitatea cu standardele moderne de criptare.🔹 Compatibilitate îmbunătățită cu OpenSSL 3.x:
FreeRDP 3.29 își aliniază biblioteca internă la cele mai noi standarde și practici din OpenSSL 3.x. Acest lucru nu doar că îmbunătățește performanța conexiunilor securizate prin TLS, dar oferă și un plus de siguranță împotriva atacurilor de tip Man-in-the-Middle (MitM).Având în vedere numărul mare de vulnerabilități corectate în această versiune, administratorilor de sistem le este recomandat să actualizeze pachetele FreeRDP pe servere, stații de lucru și clienți subțiri (thin clients) cât mai curând posibil.
#OpenSource #FreeRDP #RemoteDesktop #RDP #CyberSecurity #LinuxTools #SysAdmin #TechNews #Linuxiac