home.social

#vnc — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vnc, aggregated by home.social.

  1. Threat Actors Weaponize Tiflux RMMs in Malspam Attacks

    Since late February, there has been an uptick in incidents involving Tiflux, a lesser-known Brazilian commercial remote management tool being weaponized by threat actors. The attack chain begins with phishing emails containing fake document lures that deliver a malicious MSI installer. Once executed, the installer deploys multiple remote access tools including UltraVNC, Splashtop, and ScreenConnect for persistent access. The Tiflux installer contains concerning components such as outdated VNC versions from 2014, expired certificates, hardcoded passwords, and a vulnerable HwRwDrv.sys driver known for privilege escalation abuse. The threat actors leverage these tools to establish persistence, capture screenshots, and collect system profiling information. This campaign exemplifies the continuing pattern of adversaries abusing legitimate remote management software for stealthy access to victim environments while chaining multiple tools together to maintain control.

    Pulse ID: 69fd4f31a337de81bfb907d5
    Pulse Link: otx.alienvault.com/pulse/69fd4
    Pulse Author: AlienVault
    Created: 2026-05-08 02:49:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CyberSecurity #Email #InfoSec #MalSpam #OTX #OpenThreatExchange #Password #Passwords #Phishing #ScreenConnect #Spam #VNC #Word #bot #AlienVault

  2. Threat Actors Weaponize Tiflux RMMs in Malspam Attacks

    Since late February, there has been an uptick in incidents involving Tiflux, a lesser-known Brazilian commercial remote management tool being weaponized by threat actors. The attack chain begins with phishing emails containing fake document lures that deliver a malicious MSI installer. Once executed, the installer deploys multiple remote access tools including UltraVNC, Splashtop, and ScreenConnect for persistent access. The Tiflux installer contains concerning components such as outdated VNC versions from 2014, expired certificates, hardcoded passwords, and a vulnerable HwRwDrv.sys driver known for privilege escalation abuse. The threat actors leverage these tools to establish persistence, capture screenshots, and collect system profiling information. This campaign exemplifies the continuing pattern of adversaries abusing legitimate remote management software for stealthy access to victim environments while chaining multiple tools together to maintain control.

    Pulse ID: 69fd4f31a337de81bfb907d5
    Pulse Link: otx.alienvault.com/pulse/69fd4
    Pulse Author: AlienVault
    Created: 2026-05-08 02:49:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CyberSecurity #Email #InfoSec #MalSpam #OTX #OpenThreatExchange #Password #Passwords #Phishing #ScreenConnect #Spam #VNC #Word #bot #AlienVault

  3. Threat Actors Weaponize Tiflux RMMs in Malspam Attacks

    Since late February, there has been an uptick in incidents involving Tiflux, a lesser-known Brazilian commercial remote management tool being weaponized by threat actors. The attack chain begins with phishing emails containing fake document lures that deliver a malicious MSI installer. Once executed, the installer deploys multiple remote access tools including UltraVNC, Splashtop, and ScreenConnect for persistent access. The Tiflux installer contains concerning components such as outdated VNC versions from 2014, expired certificates, hardcoded passwords, and a vulnerable HwRwDrv.sys driver known for privilege escalation abuse. The threat actors leverage these tools to establish persistence, capture screenshots, and collect system profiling information. This campaign exemplifies the continuing pattern of adversaries abusing legitimate remote management software for stealthy access to victim environments while chaining multiple tools together to maintain control.

    Pulse ID: 69fd4f31a337de81bfb907d5
    Pulse Link: otx.alienvault.com/pulse/69fd4
    Pulse Author: AlienVault
    Created: 2026-05-08 02:49:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CyberSecurity #Email #InfoSec #MalSpam #OTX #OpenThreatExchange #Password #Passwords #Phishing #ScreenConnect #Spam #VNC #Word #bot #AlienVault

  4. Threat Actors Weaponize Tiflux RMMs in Malspam Attacks

    Since late February, there has been an uptick in incidents involving Tiflux, a lesser-known Brazilian commercial remote management tool being weaponized by threat actors. The attack chain begins with phishing emails containing fake document lures that deliver a malicious MSI installer. Once executed, the installer deploys multiple remote access tools including UltraVNC, Splashtop, and ScreenConnect for persistent access. The Tiflux installer contains concerning components such as outdated VNC versions from 2014, expired certificates, hardcoded passwords, and a vulnerable HwRwDrv.sys driver known for privilege escalation abuse. The threat actors leverage these tools to establish persistence, capture screenshots, and collect system profiling information. This campaign exemplifies the continuing pattern of adversaries abusing legitimate remote management software for stealthy access to victim environments while chaining multiple tools together to maintain control.

    Pulse ID: 69fd4f31a337de81bfb907d5
    Pulse Link: otx.alienvault.com/pulse/69fd4
    Pulse Author: AlienVault
    Created: 2026-05-08 02:49:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CyberSecurity #Email #InfoSec #MalSpam #OTX #OpenThreatExchange #Password #Passwords #Phishing #ScreenConnect #Spam #VNC #Word #bot #AlienVault

  5. Threat Actors Weaponize Tiflux RMMs in Malspam Attacks

    Since late February, there has been an uptick in incidents involving Tiflux, a lesser-known Brazilian commercial remote management tool being weaponized by threat actors. The attack chain begins with phishing emails containing fake document lures that deliver a malicious MSI installer. Once executed, the installer deploys multiple remote access tools including UltraVNC, Splashtop, and ScreenConnect for persistent access. The Tiflux installer contains concerning components such as outdated VNC versions from 2014, expired certificates, hardcoded passwords, and a vulnerable HwRwDrv.sys driver known for privilege escalation abuse. The threat actors leverage these tools to establish persistence, capture screenshots, and collect system profiling information. This campaign exemplifies the continuing pattern of adversaries abusing legitimate remote management software for stealthy access to victim environments while chaining multiple tools together to maintain control.

    Pulse ID: 69fd4f31a337de81bfb907d5
    Pulse Link: otx.alienvault.com/pulse/69fd4
    Pulse Author: AlienVault
    Created: 2026-05-08 02:49:21

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Brazil #CyberSecurity #Email #InfoSec #MalSpam #OTX #OpenThreatExchange #Password #Passwords #Phishing #ScreenConnect #Spam #VNC #Word #bot #AlienVault

  6. People of #Android, I have decided to free you from the thrall of srccpy and scammy #RDP and #VNC servers for Android and make sure you can RDP to your phone, because… no good reason, really, other than I hate having 13 remote access apps:

  7. People of #Android, I have decided to free you from the thrall of srccpy and scammy #RDP and #VNC servers for Android and make sure you can RDP to your phone, because… no good reason, really, other than I hate having 13 remote access apps:

  8. People of #Android, I have decided to free you from the thrall of srccpy and scammy #RDP and #VNC servers for Android and make sure you can RDP to your phone, because… no good reason, really, other than I hate having 13 remote access apps:

  9. People of #Android, I have decided to free you from the thrall of srccpy and scammy #RDP and #VNC servers for Android and make sure you can RDP to your phone, because… no good reason, really, other than I hate having 13 remote access apps:

  10. People of #Android, I have decided to free you from the thrall of srccpy and scammy #RDP and #VNC servers for Android and make sure you can RDP to your phone, because… no good reason, really, other than I hate having 13 remote access apps:

  11. Cyberattacks Expose 1.8M RDP Servers Online

    A shocking 1.8 million RDP servers are currently vulnerable to cyberattacks, leaving them open to exploitation by opportunistic hackers. Canadian authorities have also cracked down on SMS blaster phishing, arresting three men and seizing a device that sent fake texts to unsuspecting phones.

    osintsights.com/cyberattacks-e

    #RemoteDesktop #Vnc #ExposedServers #Phishing #SmsBlaster

  12. iPhoneやiPadからMacを遠隔操作できるリモートデスクトップアプリ「Astropad Workbench」が英語以外の音声入力、バックグラウンド接続などをサポート。
    applech2.com/archives/20260429

    #applech2 #Astropad #AppStore #AstroHQ #iPad #iPhone #Mac #News #VNC #アプリ #サブスクリプション #有料

  13. iPhoneやiPadからMacを遠隔操作できるリモートデスクトップアプリ「Astropad Workbench」が英語以外の音声入力、バックグラウンド接続などをサポート。
    applech2.com/archives/20260429

    #applech2 #Astropad #AppStore #AstroHQ #iPad #iPhone #Mac #News #VNC #アプリ #サブスクリプション #有料

  14. iPhoneやiPadからMacを遠隔操作できるリモートデスクトップアプリ「Astropad Workbench」が英語以外の音声入力、バックグラウンド接続などをサポート。
    applech2.com/archives/20260429

    #applech2 #Astropad #AppStore #AstroHQ #iPad #iPhone #Mac #News #VNC #アプリ #サブスクリプション #有料

  15. iPhoneやiPadからMacを遠隔操作できるリモートデスクトップアプリ「Astropad Workbench」が英語以外の音声入力、バックグラウンド接続などをサポート。
    applech2.com/archives/20260429

    #applech2 #Astropad #AppStore #AstroHQ #iPad #iPhone #Mac #News #VNC #アプリ #サブスクリプション #有料

  16. Foxit Impersonation: Fake PDF Installer Deploys VNC

    Pulse ID: 69eaf846972c87c1f8b10f6d
    Pulse Link: otx.alienvault.com/pulse/69eaf
    Pulse Author: Tr1sa111
    Created: 2026-04-24 04:57:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #PDF #VNC #bot #Tr1sa111

  17. Foxit Impersonation: Fake PDF Installer Deploys VNC

    Pulse ID: 69eaf846972c87c1f8b10f6d
    Pulse Link: otx.alienvault.com/pulse/69eaf
    Pulse Author: Tr1sa111
    Created: 2026-04-24 04:57:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #PDF #VNC #bot #Tr1sa111

  18. Foxit Impersonation: Fake PDF Installer Deploys VNC

    Pulse ID: 69eaf846972c87c1f8b10f6d
    Pulse Link: otx.alienvault.com/pulse/69eaf
    Pulse Author: Tr1sa111
    Created: 2026-04-24 04:57:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #PDF #VNC #bot #Tr1sa111

  19. Foxit Impersonation: Fake PDF Installer Deploys VNC

    Pulse ID: 69eaf846972c87c1f8b10f6d
    Pulse Link: otx.alienvault.com/pulse/69eaf
    Pulse Author: Tr1sa111
    Created: 2026-04-24 04:57:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #PDF #VNC #bot #Tr1sa111

  20. Foxit Impersonation: Fake PDF Installer Deploys VNC

    Pulse ID: 69eaf846972c87c1f8b10f6d
    Pulse Link: otx.alienvault.com/pulse/69eaf
    Pulse Author: Tr1sa111
    Created: 2026-04-24 04:57:42

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #PDF #VNC #bot #Tr1sa111

  21. Foxit Impersonation: Fake PDF Installer Deploys VNC

    Attackers are leveraging the trusted reputation of Foxit PDF Reader, used by over 650 million people, to distribute malicious installers disguised as legitimate software. Rather than exploiting vulnerabilities, threat actors impersonate the vendor through fake installers with document-themed filenames that bypass user suspicion. When executed, these files display decoy passport images while downloading malicious MSI packages that deploy UltraVNC remote access tools disguised as GPU drivers. The attack establishes persistence through registry modifications and firewall exceptions, connecting to attacker-controlled infrastructure for complete remote system control. Telemetry indicates broad distribution across Germany, the United States, the United Kingdom, and Ukraine. This campaign demonstrates how brand impersonation combined with social engineering proves more effective than technical exploits, relying on user trust and behavioral patterns rather than software vulnerabilities.

    Pulse ID: 69e9e0346967ec306d0a2e2d
    Pulse Link: otx.alienvault.com/pulse/69e9e
    Pulse Author: AlienVault
    Created: 2026-04-23 09:02:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Germany #InfoSec #OTX #OpenThreatExchange #PDF #RAT #Rust #SocialEngineering #Troll #UK #Ukr #Ukraine #UnitedKingdom #UnitedStates #VNC #bot #AlienVault

  22. Foxit Impersonation: Fake PDF Installer Deploys VNC

    Attackers are leveraging the trusted reputation of Foxit PDF Reader, used by over 650 million people, to distribute malicious installers disguised as legitimate software. Rather than exploiting vulnerabilities, threat actors impersonate the vendor through fake installers with document-themed filenames that bypass user suspicion. When executed, these files display decoy passport images while downloading malicious MSI packages that deploy UltraVNC remote access tools disguised as GPU drivers. The attack establishes persistence through registry modifications and firewall exceptions, connecting to attacker-controlled infrastructure for complete remote system control. Telemetry indicates broad distribution across Germany, the United States, the United Kingdom, and Ukraine. This campaign demonstrates how brand impersonation combined with social engineering proves more effective than technical exploits, relying on user trust and behavioral patterns rather than software vulnerabilities.

    Pulse ID: 69e9e0346967ec306d0a2e2d
    Pulse Link: otx.alienvault.com/pulse/69e9e
    Pulse Author: AlienVault
    Created: 2026-04-23 09:02:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Germany #InfoSec #OTX #OpenThreatExchange #PDF #RAT #Rust #SocialEngineering #Troll #UK #Ukr #Ukraine #UnitedKingdom #UnitedStates #VNC #bot #AlienVault

  23. Foxit Impersonation: Fake PDF Installer Deploys VNC

    Attackers are leveraging the trusted reputation of Foxit PDF Reader, used by over 650 million people, to distribute malicious installers disguised as legitimate software. Rather than exploiting vulnerabilities, threat actors impersonate the vendor through fake installers with document-themed filenames that bypass user suspicion. When executed, these files display decoy passport images while downloading malicious MSI packages that deploy UltraVNC remote access tools disguised as GPU drivers. The attack establishes persistence through registry modifications and firewall exceptions, connecting to attacker-controlled infrastructure for complete remote system control. Telemetry indicates broad distribution across Germany, the United States, the United Kingdom, and Ukraine. This campaign demonstrates how brand impersonation combined with social engineering proves more effective than technical exploits, relying on user trust and behavioral patterns rather than software vulnerabilities.

    Pulse ID: 69e9e0346967ec306d0a2e2d
    Pulse Link: otx.alienvault.com/pulse/69e9e
    Pulse Author: AlienVault
    Created: 2026-04-23 09:02:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Germany #InfoSec #OTX #OpenThreatExchange #PDF #RAT #Rust #SocialEngineering #Troll #UK #Ukr #Ukraine #UnitedKingdom #UnitedStates #VNC #bot #AlienVault

  24. Foxit Impersonation: Fake PDF Installer Deploys VNC

    Attackers are leveraging the trusted reputation of Foxit PDF Reader, used by over 650 million people, to distribute malicious installers disguised as legitimate software. Rather than exploiting vulnerabilities, threat actors impersonate the vendor through fake installers with document-themed filenames that bypass user suspicion. When executed, these files display decoy passport images while downloading malicious MSI packages that deploy UltraVNC remote access tools disguised as GPU drivers. The attack establishes persistence through registry modifications and firewall exceptions, connecting to attacker-controlled infrastructure for complete remote system control. Telemetry indicates broad distribution across Germany, the United States, the United Kingdom, and Ukraine. This campaign demonstrates how brand impersonation combined with social engineering proves more effective than technical exploits, relying on user trust and behavioral patterns rather than software vulnerabilities.

    Pulse ID: 69e9e0346967ec306d0a2e2d
    Pulse Link: otx.alienvault.com/pulse/69e9e
    Pulse Author: AlienVault
    Created: 2026-04-23 09:02:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Germany #InfoSec #OTX #OpenThreatExchange #PDF #RAT #Rust #SocialEngineering #Troll #UK #Ukr #Ukraine #UnitedKingdom #UnitedStates #VNC #bot #AlienVault

  25. Foxit Impersonation: Fake PDF Installer Deploys VNC

    Attackers are leveraging the trusted reputation of Foxit PDF Reader, used by over 650 million people, to distribute malicious installers disguised as legitimate software. Rather than exploiting vulnerabilities, threat actors impersonate the vendor through fake installers with document-themed filenames that bypass user suspicion. When executed, these files display decoy passport images while downloading malicious MSI packages that deploy UltraVNC remote access tools disguised as GPU drivers. The attack establishes persistence through registry modifications and firewall exceptions, connecting to attacker-controlled infrastructure for complete remote system control. Telemetry indicates broad distribution across Germany, the United States, the United Kingdom, and Ukraine. This campaign demonstrates how brand impersonation combined with social engineering proves more effective than technical exploits, relying on user trust and behavioral patterns rather than software vulnerabilities.

    Pulse ID: 69e9e0346967ec306d0a2e2d
    Pulse Link: otx.alienvault.com/pulse/69e9e
    Pulse Author: AlienVault
    Created: 2026-04-23 09:02:44

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Germany #InfoSec #OTX #OpenThreatExchange #PDF #RAT #Rust #SocialEngineering #Troll #UK #Ukr #Ukraine #UnitedKingdom #UnitedStates #VNC #bot #AlienVault

  26. My homeserver went silent. DNS died. Router failover was useless as always — so I fixed it properly. keepalived floating IP, both AdGuards in parity, warm standby backups for Vaultwarden and Gitea. Also accidentally learned a lot about headless XRDP the hard way — LXQt, TigerVNC, rage quitting, and eventually XRDP and XFCE just working. Part 16!

    blog.ppb1701.com/dns-redundanc

    #nixos #adguardhome #dns #vnc #rdp #remoteaccess #redundency #homeserver #selfhosting #blog

  27. My homeserver went silent. DNS died. Router failover was useless as always — so I fixed it properly. keepalived floating IP, both AdGuards in parity, warm standby backups for Vaultwarden and Gitea. Also accidentally learned a lot about headless XRDP the hard way — LXQt, TigerVNC, rage quitting, and eventually XRDP and XFCE just working. Part 16!

    blog.ppb1701.com/dns-redundanc

    #nixos #adguardhome #dns #vnc #rdp #remoteaccess #redundency #homeserver #selfhosting #blog

  28. My homeserver went silent. DNS died. Router failover was useless as always — so I fixed it properly. keepalived floating IP, both AdGuards in parity, warm standby backups for Vaultwarden and Gitea. Also accidentally learned a lot about headless XRDP the hard way — LXQt, TigerVNC, rage quitting, and eventually XRDP and XFCE just working. Part 16!

    blog.ppb1701.com/dns-redundanc

    #nixos #adguardhome #dns #vnc #rdp #remoteaccess #redundency #homeserver #selfhosting #blog

  29. My homeserver went silent. DNS died. Router failover was useless as always — so I fixed it properly. keepalived floating IP, both AdGuards in parity, warm standby backups for Vaultwarden and Gitea. Also accidentally learned a lot about headless XRDP the hard way — LXQt, TigerVNC, rage quitting, and eventually XRDP and XFCE just working. Part 16!

    blog.ppb1701.com/dns-redundanc

    #nixos #adguardhome #dns #vnc #rdp #remoteaccess #redundency #homeserver #selfhosting #blog

  30. My homeserver went silent. DNS died. Router failover was useless as always — so I fixed it properly. keepalived floating IP, both AdGuards in parity, warm standby backups for Vaultwarden and Gitea. Also accidentally learned a lot about headless XRDP the hard way — LXQt, TigerVNC, rage quitting, and eventually XRDP and XFCE just working. Part 16!

    blog.ppb1701.com/dns-redundanc

    #nixos #adguardhome #dns #vnc #rdp #remoteaccess #redundency #homeserver #selfhosting #blog

  31. Lambda-Display-Upgrade auf V3: Was sich verbessert hat – und was nicht

    tl;dr: Gerade wurde bei uns das Display der Lambda EU08L-Wärmepumpe vom Steuerungsset 02 auf das neue Steuerungsset 03 getauscht. Die Hardware ist ein deutlicher Sprung – kapazitives Glas-Display, höhere Auflösung, spürbar schnellere Reaktionszeiten. Der Upgrade-Prozess selbst ist allerdings alles andere als komfortabel: Sämtliche Einstellungen gehen verloren und müssen manuell neu eingegeben werden. Kostenpunkt: bei uns rund 930 € inkl. allem – der Preis hängt vom jeweiligen […]

    hausbau.blog.dpesch.de/2026/04

  32. Lambda-Display-Upgrade auf V3: Was sich verbessert hat – und was nicht

    tl;dr: Gerade wurde bei uns das Display der Lambda EU08L-Wärmepumpe vom Steuerungsset 02 auf das neue Steuerungsset 03 getauscht. Die Hardware ist ein deutlicher Sprung – kapazitives Glas-Display, höhere Auflösung, spürbar schnellere Reaktionszeiten. Der Upgrade-Prozess selbst ist allerdings alles andere als komfortabel: Sämtliche Einstellungen gehen verloren und müssen manuell neu eingegeben werden. Kostenpunkt: bei uns rund 930 € inkl. allem – der Preis hängt vom jeweiligen […]

    hausbau.blog.dpesch.de/2026/04

  33. Mal ne Frage zu alter Hardware.
    Ich hab hier ein altes #ipad3 und wollte es als #homeassistant Dashboard benutzen, aber die Seite läd nicht. Und eine #vnc App aus dem Store kann ich nicht installieren weil die alte Version nicht mehr unterstützt wird...
    Hat dazu irgendwer eine Lösung?
    Danke

  34. Mal ne Frage zu alter Hardware.
    Ich hab hier ein altes #ipad3 und wollte es als #homeassistant Dashboard benutzen, aber die Seite läd nicht. Und eine #vnc App aus dem Store kann ich nicht installieren weil die alte Version nicht mehr unterstützt wird...
    Hat dazu irgendwer eine Lösung?
    Danke

  35. Mal ne Frage zu alter Hardware.
    Ich hab hier ein altes #ipad3 und wollte es als #homeassistant Dashboard benutzen, aber die Seite läd nicht. Und eine #vnc App aus dem Store kann ich nicht installieren weil die alte Version nicht mehr unterstützt wird...
    Hat dazu irgendwer eine Lösung?
    Danke