home.social

#wateringhole — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #wateringhole, aggregated by home.social.

fetched live
  1. Nowy wariant DarkSword — „P7” kradnie dane z Pęku kluczy i portfeli kryptowalutowych na iPhone’ach

    Firma iVerify opublikowała raport o P7 DarkSword — nowym, wcześniej nieznanym wariancie złośliwego oprogramowania powiązanego z łańcuchem exploitów DarkSword na iPhone’a, ujawnionym na początku tego roku — donosi redakcja 9to5Mac.

    Przypomnijmy kontekst, o którym pisaliśmy już wcześniej na iMagazine. Wiosną Google i iVerify ujawniły dwa zaawansowane narzędzia do włamań na iPhone’y — Coruna i DarkSword — łączące wiele luk w iOS w celu przejęcia urządzeń z nieaktualnymi wersjami systemu. Coruna celowała w iOS 13 do iOS 17.2.1, a DarkSword w iOS 18.4 do iOS 18.7. Apple wydało wtedy aktualizacje dla starszych wersji, w tym iOS 15.8.7, iOS 16.7.15 i iOS 18.7.7 — a nawet, co jest krokiem niezwykłym, udostępniło iOS 18.7.7 urządzeniom zdolnym do instalacji iOS 26, żeby osoby niechcące przechodzić na najnowszy system pozostały chronione. Google informowało wówczas, że DarkSword był wykorzystywany przez wielu komercyjnych dostawców oprogramowania szpiegującego i podejrzewanych aktorów państwowych, a ataki obserwowano m.in. w Arabii Saudyjskiej, Turcji, Malezji i na Ukrainie.

    iVerify natrafiło na P7 w sierpniu, badając infekcję na iPhonie pracownika instytucji finansowej. Nazwa pochodzi od prefiksu zmiennych p7_, którego autorzy użyli, modyfikując oryginalny kod DarkSword. Nowy wariant rozszerza zgodność do iOS 18.7 (poprzedni obsługiwał iOS 18.6), choć inne wdrożenia DarkSword obserwowane przez Google wspierały już iOS 18.7. Według iVerify operator rozprowadza P7 za pomocą złośliwych reklam w atakach typu watering-hole, więc ofiary niekoniecznie są celowane indywidualnie — wystarczy natknąć się na złośliwą lub przejętą treść w sieci.

    P7 poprawia wcześniejsze wersje w trzech obszarach: skrytości, stabilności i funkcjonalności. Ogranicza logowanie i liczbę wstrzyknięć do procesów, wykorzystuje pamięć przeglądarki, żeby nie atakować wielokrotnie tego samego urządzenia, i rozszerza możliwości kradzieży danych. Co najważniejsze, potrafi wyciągać dane z Pęku kluczy bezpośrednio na iPhonie, zanim wyśle je atakującym, zamiast kopiować całą bazę do przetworzenia gdzie indziej, oraz celuje w dane portfeli kryptowalutowych. Wprowadza też dwukierunkową komunikację z serwerem dowodzenia, dzięki której napastnicy mogą zlecać pobieranie dowolnych plików, wysyłanie zdjęć, inwentaryzację zainstalowanych aplikacji, dostęp do baz Notatek, zbieranie danych z kontenerów poszczególnych aplikacji i skanowanie systemu plików. Domyślnie spyware łączy się z serwerem co 15 sekund, a interwał można zmieniać zdalnie. iVerify podkreśla, że zmiany wyglądają na efekt sporej pracy operatorów, a nie prostych modyfikacji wspomaganych AI, a dawne wskaźniki infekcji (IOC) przestają być aktualne.

    Warto zaznaczyć, że P7 nie jest nową luką w iOS, ale nową wersją złośliwego oprogramowania instalowanego po udanym przejęciu przez DarkSword. iVerify nie podaje, jaka wersja iOS działała na urządzeniu, na którym znaleziono P7. Najprostsza ochrona pozostaje ta sama: aktualizacja systemu do najnowszej dostępnej wersji.

    Exploit DarkSword wykorzystuje luki w starszych wersjach iOS i iPadOS

    #aktualizacjaIOS #bezpieczeństwoIPhone #Coruna #DarkSword #iOS1877 #iVerify #P7DarkSword #PękKluczyKradzież #spywareIPhone #wateringHole
  2. Back at the wonderful #WateringHole. Friendly people and lovely #CraftBeer. #Tokyo #Japan Shin Oni-Gunsou IPA, Oni Densetsu Hokkaido & Kompas Fruit Season, Minoh Beer Osaka. #fcsp

  3. AhnLab's Operation Double Barrel report confirms the campaign has been running since 2025, injecting backdoors so deep the dungeon map is just a silhouette of a skeleton shrugging.

    Audit the compromised websites and patch vulnerabilities in Korean financial security software before the backdoors become permanent fixtures.

    Reward: You've received a Cursed Watering Flask. It's full. You don't want to know of what.

    #CyberSecurity #WateringHole #SouthKorea #APT #StateSponsored (2/2)

  4. 📰 Hackers Exploit Korean Security Software in Watering Hole Attacks

    State-sponsored hackers are exploiting South Korean security software 'AnySign4PC' in watering hole attacks. Compromised sites silently install backdoors (SIGNBT, COPPERHEDGE) on visitors' systems. Users urged to update now. #CyberAttack #WateringHole

    🔗 cyber.netsecops.io/articles/st

  5. 📰 Hackers Exploit Korean Security Software in Watering Hole Attacks

    State-sponsored hackers are exploiting South Korean security software 'AnySign4PC' in watering hole attacks. Compromised sites silently install backdoors (SIGNBT, COPPERHEDGE) on visitors' systems. Users urged to update now. #CyberAttack #WateringHole

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/st

  6. Photographers Spend Two Months in African Wildlife Hide Capturing Animals Close-Up

    Untamed Photo Safaris Two photographers spent an exhilarating couple of months at a wildlife conservancy in Kenya, capturing…
    #NewsBeep #News #Wildlife #africansafari #AU #Australia #hide #Kenya #naturehide #photohide #photosafari #safari #Science #wateringhole #wildlifephotography
    newsbeep.com/au/641963/

  7. Photographers Spend Two Months in African Wildlife Hide Capturing Animals Close-Up

    Untamed Photo Safaris Two photographers spent an exhilarating couple of months at a wildlife conservancy in Kenya, capturing…
    #NewsBeep #News #Wildlife #africansafari #hide #Kenya #naturehide #photohide #photosafari #Safari #Science #UK #UnitedKingdom #wateringhole #wildlifephotography
    newsbeep.com/uk/559495/

  8. Photographers Spend Two Months in African Wildlife Hide Capturing Animals Close-Up

    Untamed Photo Safaris Two photographers spent an exhilarating couple of months at a wildlife conservancy in Kenya, capturing…
    #NewsBeep #News #Wildlife #africansafari #CA #Canada #hide #Kenya #naturehide #photohide #photosafari #safari #Science #wateringhole #wildlifephotography
    newsbeep.com/ca/639207/

  9. "Google Threat Intelligence Group (GTIG) is tracking a long-running and adaptive cyber espionage campaign by APT24, a People's Republic of China (PRC)-nexus threat actor. Spanning three years, APT24 has been deploying BADAUDIO, a highly obfuscated first-stage downloader used to establish persistent access to victim networks.

    While earlier operations relied on broad strategic web compromises to compromise legitimate websites, APT24 has recently pivoted to using more sophisticated vectors targeting organizations in Taiwan. This includes the repeated compromise of a regional digital marketing firm to execute supply chain attacks and the use of targeted phishing campaigns.

    This report provides a technical analysis of the BADAUDIO malware, details the evolution of APT24's delivery mechanisms from 2022 to present, and offers actionable intelligence to help defenders detect and mitigate this persistent threat.

    As part of our efforts to combat serious threat actors, GTIG uses the results of our research to improve the safety and security of Google’s products and users. Upon discovery, all identified websites, domains, and files are added to the Safe Browsing blocklist in order to protect web users across major browsers. We also conducted a series of victim notifications with technical details to compromised sites, enabling affected organizations to secure their sites and prevent future infections."

    cloud.google.com/blog/topics/t

    #CyberSecurity #China #WateringHole #APT24 #Badaudio #Phishing #Taiwan #MultiVectorAttacks

  10. Day 6 of #30DaysWild

    Very little time to spare today, so I haven't managed to get outdoors. I have been thinking about #nature though; more specifically, how best to support my #hedgehog visitor(s).

    I'm going to go through the older crockery & those plant pots that moved home with me, and set up a mini #wildlife #wateringhole :)

    Y'all gotta drink!

  11. @r @torproject @m0xee @jeffcliff @thendrix @gabriel @sj_zero @Suiseiseki The last time Tor browser crapped itself INSTANTLY was shortly after i loaded this ARCHIVED VERSION OF this page (@internetarchive). Someone on fedi shared the, iirc, non-archived version of this link and i was curious.

    I made a note of the browser crash in october, i must've had JS enabled because my note says "reqJs"

    I have only just in the past few days had a chance to READ the note and revisit the page. As a part-time "coincidence suspector" I find it interesting that loading that page caused my browser to die instantly.... it doesn't now (not that that means much). If i had a chance to read it in october i'd have had a good few things to say about so-called "(#wateringHole) attacks". I feel a *cough* coming on....

    The following are mentioned in the atricle, as attacked sites (my notes in parenthesis):

    - #rojnews .news * COUGH* (#cloudflare (cf), not visited)
    - #hawarnews .com (cf, not visited)
    - #targetplatform .net (packed with youtube videos, seems westernized)

    I'd be VERY interested to know whether the sites above were cf during/before this attack but either way this is quite concerning, if the site was cf before the attack that could address HOW those sites were breached in the first place. If cf during the attack, then cf has failed in its mission to protect from the #cyberattack. If the sites became cf after, then we must ask do sites immediately become cf'd when a problem emerges? Would Kurdish outlets knowingly have a policy like that? Do the site owners EVEN KNOW the site is cf? This is not as silly a question as it sounds.

    Next i checked #kurdish news sites found in my own searches (with notes):

    - #kurditv .com * STILL COUGHING* (requires #google js(without integrity checks?!) to view videos!)
    - #kurdistanobserver .com (on googl servers, not visited)
    - #thekurdishproject .org (cf, not visited (NV))
    - #infopig .com (down at time of test)
    - #iranpressnews .com (cf, NV)
    - #ekurd .net (cf, NV)
    - #kurdpa .net (cf, NV)
    - #newslive .com (cf NV)
    - #kurdistan24 .net (cf NV)
    - #basnews .com (cf NV)
    - #kurdistantv .net (cf NV)
    - #zagrosnews .net (cf NV)
    - #kurdistanin .net (googl non-integrity checked js.... bunny, cf and amazon cloudfront resources)
    - #kurdistantribune .com (fetches non-integrity checked statcounter (cf) js, which is blocked by uBlockOrigin if u use TorBrowser in TailsOS. Uses youtube, feedburner (cf), #facebook and #twitter/ #fastly fetches snitch on the EXACT articles u read(!!!), with twitter js not being integrity checked)

    WATERING HOLE ATTACK RATING = EXTREME
    DIGITAL COLONIALISM INDEX = 99%?

    *END COUGH* (yeah i spent a few good hours coughing this up like a bad furball) :acat_chew:

    The article itself is not even very complete.... how are the supposed #APK files/apps getting manually(?) approved and installed on peoples' devices? .... @fdroidorg should be so lucky. Maybe the fdroid team need to take a feather from this hackers black hat? am i missing something here or does this story SMELL a bit?

    Thoughts?

  12. Powerful #Spyware #Exploits Enable a New String of 'Watering Hole' Attacks

    Suspected #Russian #hackers have compromised a series of websites to utilize sophisticated spyware exploits that are eerily similar to those created by #NSOGroup and #Intellexa.
    #privacy #security #wateringhole

    wired.com/story/russia-cozy-be

  13. Five years ago, I tented out on the savanna amongst wild elephants in Botswana. I saw hundreds and hundreds of elephants. They are beautiful animals. They also fart pretty much nonstop. #elephants #botswana #WateringHole #elephant

  14. When I once told someone that I am a #writer the answer was: "Such a beautiful life sitting at the pool and having ideas!" Well, meanwhile I am so rich #ironyAlarm that I have three inspiring (!) swimming pools: a very sophisticated one mainly for #wasps, the other ones for #birds, #insects, and #small #mammals. And I work hard as a pool girl to fill them during #heatwave and #drought. #biodiversity #ReconnectWithNature #water #gardening #naturelovers #birdbath #WateringHole

  15. This Week in Security: QueueJumper, JS VM2 Escape, and CAN Hacking - You may not be familiar with the Microsoft Message Queuing (MSMQ) service, a store... - hackaday.com/2023/04/14/this-w #thisweekinsecurity #securityhacks #softwarehacks #wateringhole #featured #can-bus #news

  16. Laut einem Bericht hat der Generalbundesanwalt Haftbefehl gegen einen russischen Hacker erwirkt, der unter anderem deutsche Energieversorger im Visier hatte.
    Russische Hackergruppe soll deutsche Energieversorger aufs Korn genommen haben
Share on Mastodon

Enter the server where you have an account.