home.social

#threatresearch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.

  1. New.

    "The chain uses two binaries. A dropper writes a shell script to the appliance's storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image."

    Rapid7: SMTP is the key: BPFDoor and AVERAT hitting the network edge rapid7.com/blog/post/tr-smtp-i @Rapid7Official #infosec #threatresearch #Linux

  2. New.

    "The chain uses two binaries. A dropper writes a shell script to the appliance's storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image."

    Rapid7: SMTP is the key: BPFDoor and AVERAT hitting the network edge rapid7.com/blog/post/tr-smtp-i @Rapid7Official #infosec #threatresearch #Linux

  3. New.

    "The chain uses two binaries. A dropper writes a shell script to the appliance's storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image."

    Rapid7: SMTP is the key: BPFDoor and AVERAT hitting the network edge rapid7.com/blog/post/tr-smtp-i @Rapid7Official #infosec #threatresearch #Linux

  4. New.

    "The chain uses two binaries. A dropper writes a shell script to the appliance's storage mount and executes it. The script stages both payloads into /sbin under the names ntpdate and udevds, launches them, and deletes each file ten seconds later while the processes continue running. One of those payloads is the dropper itself, re-executing as a resident watchdog, leaving both processes running without an on-disk image."

    Rapid7: SMTP is the key: BPFDoor and AVERAT hitting the network edge rapid7.com/blog/post/tr-smtp-i @Rapid7Official #infosec #threatresearch #Linux

  5. New.

    Socket: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX socket.dev/blog/glassworm-vsco @SocketSecurity #infosec #threatresearch #JavaScript #Git

  6. New.

    Socket: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX socket.dev/blog/glassworm-vsco @SocketSecurity #infosec #threatresearch #JavaScript #Git

  7. New.

    Socket: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX socket.dev/blog/glassworm-vsco @SocketSecurity #infosec #threatresearch #JavaScript #Git

  8. New.

    Socket: Pretty Themes, Hidden Loaders: GlassWorm-Linked Extensions Span VS Code Marketplace and Open VSX socket.dev/blog/glassworm-vsco @SocketSecurity #infosec #threatresearch #JavaScript #Git

  9. New, and an excellant timeline for this gang's activities and various shenanigans.

    Sekoia: Gotta breach 'em all! The journey of ShinyHunters sekoia.com/blog/gotta-breach-e @sekoia_io #infosec #ransomware #cybercrime #threatresearch

    @briankrebs

  10. New, and an excellant timeline for this gang's activities and various shenanigans.

    Sekoia: Gotta breach 'em all! The journey of ShinyHunters sekoia.com/blog/gotta-breach-e @sekoia_io #infosec #ransomware #cybercrime #threatresearch

    @briankrebs

  11. New, and an excellant timeline for this gang's activities and various shenanigans.

    Sekoia: Gotta breach 'em all! The journey of ShinyHunters sekoia.com/blog/gotta-breach-e @sekoia_io #infosec #ransomware #cybercrime #threatresearch

    @briankrebs

  12. New, and an excellant timeline for this gang's activities and various shenanigans.

    Sekoia: Gotta breach 'em all! The journey of ShinyHunters sekoia.com/blog/gotta-breach-e @sekoia_io #infosec #ransomware #cybercrime #threatresearch

    @briankrebs