home.social

#unc5174 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #unc5174, aggregated by home.social.

fetched live
  1. Federal agencies are racing to patch a VMware Tools flaw that lets hackers grab root access—Chinese state-backed group UNC5174 has been exploiting it. What does this mean for digital security? Read on for the full story.

    thedefendopsdiaries.com/vmware

    #vmwaretools
    #cve202541244
    #cybersecurity
    #cisa
    #unc5174
    #vulnerabilitymanagement
    #patching
    #infosec

  2. Podniesienie uprawnień w VMware – grupa UNC5174 powiązana z Chinami wykorzystuje lukę CVE-2025-41244

    29 września 2025 r. Broadcom poinformował o luce bezpieczeństwa CVE-2025-41244 w oprogramowaniu VMware Tools i VMware Aria, umożliwiającej lokalną eskalację uprawnień. Zgodnie z opinią badaczy z NVISO, luka była aktywnie wykorzystywana jako zero-day od co najmniej października 2024 roku. Za atakami stała grupa UNC5174 utożsamiana przez analityków z chińskim aparatem...

    #WBiegu #Chiny #Lpe #Unc5174 #Vmware #VmwareTools

    sekurak.pl/podniesienie-uprawn

  3. Podniesienie uprawnień w VMware – grupa UNC5174 powiązana z Chinami wykorzystuje lukę CVE-2025-41244

    29 września 2025 r. Broadcom poinformował o luce bezpieczeństwa CVE-2025-41244 w oprogramowaniu VMware Tools i VMware Aria, umożliwiającej lokalną eskalację uprawnień. Zgodnie z opinią badaczy z NVISO, luka była aktywnie wykorzystywana jako zero-day od co najmniej października 2024 roku. Za atakami stała grupa UNC5174 utożsamiana przez analityków z chińskim aparatem...

    #WBiegu #Chiny #Lpe #Unc5174 #Vmware #VmwareTools

    sekurak.pl/podniesienie-uprawn

  4. Podniesienie uprawnień w VMware – grupa UNC5174 powiązana z Chinami wykorzystuje lukę CVE-2025-41244

    29 września 2025 r. Broadcom poinformował o luce bezpieczeństwa CVE-2025-41244 w oprogramowaniu VMware Tools i VMware Aria, umożliwiającej lokalną eskalację uprawnień. Zgodnie z opinią badaczy z NVISO, luka była aktywnie wykorzystywana jako zero-day od co najmniej października 2024 roku. Za atakami stała grupa UNC5174 utożsamiana przez analityków z chińskim aparatem...

    #WBiegu #Chiny #Lpe #Unc5174 #Vmware #VmwareTools

    sekurak.pl/podniesienie-uprawn

  5. Podniesienie uprawnień w VMware – grupa UNC5174 powiązana z Chinami wykorzystuje lukę CVE-2025-41244

    29 września 2025 r. Broadcom poinformował o luce bezpieczeństwa CVE-2025-41244 w oprogramowaniu VMware Tools i VMware Aria, umożliwiającej lokalną eskalację uprawnień. Zgodnie z opinią badaczy z NVISO, luka była aktywnie wykorzystywana jako zero-day od co najmniej października 2024 roku. Za atakami stała grupa UNC5174 utożsamiana przez analityków z chińskim aparatem...

    #WBiegu #Chiny #Lpe #Unc5174 #Vmware #VmwareTools

    sekurak.pl/podniesienie-uprawn

  6. Podniesienie uprawnień w VMware – grupa UNC5174 powiązana z Chinami wykorzystuje lukę CVE-2025-41244

    29 września 2025 r. Broadcom poinformował o luce bezpieczeństwa CVE-2025-41244 w oprogramowaniu VMware Tools i VMware Aria, umożliwiającej lokalną eskalację uprawnień. Zgodnie z opinią badaczy z NVISO, luka była aktywnie wykorzystywana jako zero-day od co najmniej października 2024 roku. Za atakami stała grupa UNC5174 utożsamiana przez analityków z chińskim aparatem...

    #WBiegu #Chiny #Lpe #Unc5174 #Vmware #VmwareTools

    sekurak.pl/podniesienie-uprawn

  7. Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
    #SentinelOne discovered the campaign when they tried to hit the #security vendor's own servers
    In their report, they describe a series of intrusions between July 2024 and March 2025 involving #ShadowPad #malware and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as #APT15 and #UNC5174, And they're blaming #China.
    theregister.com/2025/06/09/chi

  8. Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
    #SentinelOne discovered the campaign when they tried to hit the #security vendor's own servers
    In their report, they describe a series of intrusions between July 2024 and March 2025 involving #ShadowPad #malware and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as #APT15 and #UNC5174, And they're blaming #China.
    theregister.com/2025/06/09/chi

  9. Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
    discovered the campaign when they tried to hit the vendor's own servers
    In their report, they describe a series of intrusions between July 2024 and March 2025 involving and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as and , And they're blaming .
    theregister.com/2025/06/09/chi

  10. Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
    #SentinelOne discovered the campaign when they tried to hit the #security vendor's own servers
    In their report, they describe a series of intrusions between July 2024 and March 2025 involving #ShadowPad #malware and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as #APT15 and #UNC5174, And they're blaming #China.
    theregister.com/2025/06/09/chi

  11. Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs
    #SentinelOne discovered the campaign when they tried to hit the #security vendor's own servers
    In their report, they describe a series of intrusions between July 2024 and March 2025 involving #ShadowPad #malware and post-exploitation espionage activity that SentinelOne has dubbed "#PurpleHaze", publicly reported as #APT15 and #UNC5174, And they're blaming #China.
    theregister.com/2025/06/09/chi

  12. UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell
    #UNC5174
    sysdig.com/blog/unc5174-chines

  13. UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell
    #UNC5174
    sysdig.com/blog/unc5174-chines

  14. UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell
    #UNC5174
    sysdig.com/blog/unc5174-chines

  15. UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell
    #UNC5174
    sysdig.com/blog/unc5174-chines

  16. UNC5174’s evolution in China’s ongoing cyber warfare: From SNOWLIGHT to VShell
    #UNC5174
    sysdig.com/blog/unc5174-chines

  17. Mandiant reported on the N-day exploitation of CVE-2023-46747 (9.8 critical, disclosed 26 October 2023 by F5, added to CISA KEV on 31 October 2023) unauthenticated RCE and ConnectWise CVE-2024-1709 (10.0 critical, disclosed 19 February 2024 by ConnectWise as exploited zero-day, in KEV) by the Chinese threat actor UNC5174, who they assess to be acting as a contractor for China's Ministry of State Security (MSS). Mandiant provides timeline and evidence of exploitation, post-exploitation tactics, custom malware and tooling. IOC and detection rules provided. 🔗 mandiant.com/resources/blog/in

    #UNC5174 #China #cyberespionage #threatintel #IOC #MSS #CVE_2023_46747 #CVE_2024_1709 #F5 #ConnectWise #ScreenConnect #eitw #activeexploitation #KEV

  18. Mandiant reported on the N-day exploitation of CVE-2023-46747 (9.8 critical, disclosed 26 October 2023 by F5, added to CISA KEV on 31 October 2023) unauthenticated RCE and ConnectWise CVE-2024-1709 (10.0 critical, disclosed 19 February 2024 by ConnectWise as exploited zero-day, in KEV) by the Chinese threat actor UNC5174, who they assess to be acting as a contractor for China's Ministry of State Security (MSS). Mandiant provides timeline and evidence of exploitation, post-exploitation tactics, custom malware and tooling. IOC and detection rules provided. 🔗 mandiant.com/resources/blog/in

    #UNC5174 #China #cyberespionage #threatintel #IOC #MSS #CVE_2023_46747 #CVE_2024_1709 #F5 #ConnectWise #ScreenConnect #eitw #activeexploitation #KEV

  19. Mandiant reported on the N-day exploitation of CVE-2023-46747 (9.8 critical, disclosed 26 October 2023 by F5, added to CISA KEV on 31 October 2023) unauthenticated RCE and ConnectWise CVE-2024-1709 (10.0 critical, disclosed 19 February 2024 by ConnectWise as exploited zero-day, in KEV) by the Chinese threat actor UNC5174, who they assess to be acting as a contractor for China's Ministry of State Security (MSS). Mandiant provides timeline and evidence of exploitation, post-exploitation tactics, custom malware and tooling. IOC and detection rules provided. 🔗 mandiant.com/resources/blog/in

    #UNC5174 #China #cyberespionage #threatintel #IOC #MSS #CVE_2023_46747 #CVE_2024_1709 #F5 #ConnectWise #ScreenConnect #eitw #activeexploitation #KEV

  20. Mandiant reported on the N-day exploitation of CVE-2023-46747 (9.8 critical, disclosed 26 October 2023 by F5, added to CISA KEV on 31 October 2023) unauthenticated RCE and ConnectWise CVE-2024-1709 (10.0 critical, disclosed 19 February 2024 by ConnectWise as exploited zero-day, in KEV) by the Chinese threat actor UNC5174, who they assess to be acting as a contractor for China's Ministry of State Security (MSS). Mandiant provides timeline and evidence of exploitation, post-exploitation tactics, custom malware and tooling. IOC and detection rules provided. 🔗 mandiant.com/resources/blog/in

    #UNC5174 #China #cyberespionage #threatintel #IOC #MSS #CVE_2023_46747 #CVE_2024_1709 #F5 #ConnectWise #ScreenConnect #eitw #activeexploitation #KEV

  21. Mandiant reported on the N-day exploitation of CVE-2023-46747 (9.8 critical, disclosed 26 October 2023 by F5, added to CISA KEV on 31 October 2023) unauthenticated RCE and ConnectWise CVE-2024-1709 (10.0 critical, disclosed 19 February 2024 by ConnectWise as exploited zero-day, in KEV) by the Chinese threat actor UNC5174, who they assess to be acting as a contractor for China's Ministry of State Security (MSS). Mandiant provides timeline and evidence of exploitation, post-exploitation tactics, custom malware and tooling. IOC and detection rules provided. 🔗 mandiant.com/resources/blog/in

    #UNC5174 #China #cyberespionage #threatintel #IOC #MSS #CVE_2023_46747 #CVE_2024_1709 #F5 #ConnectWise #ScreenConnect #eitw #activeexploitation #KEV