ARTICLES H ARTICLES ALERTS CONFERENCE MALWARE TRAFFICS UPDATE SOFTWARE BATTLEFIELD UKRAINE
|
DATE |
NAME |
INFO |
CATEGORY |
| 26.8.26 | Obfuscating IP Addresses as Hostnames | It is pretty obvious that hostnames can replace IP addresses. Pretty much any software accepting an IP address will also accept a hostname as an argument. Last week, | ARTICLES |
| 24.8.26 | DOUBLECUP's PNG Payload | New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up. It doesn't use real steganography: | ARTICLES |
| 21.8.26 | The invisible passenger in your car | While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary user app yet made no attempt to disguise itself as legitimate software: it had no user interface at all. | ARTICLES |
| 21.8.26 | Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays | One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise. | ARTICLES |
| 21.8.26 | Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting! | In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what's left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... | ARTICLES |
| 20.8.26 | Using Microsoft Graph and Powershell - Risk Detection Commands | Building on the last diary on Using MS Graph and Powershell, let's look at "Risky" logins. | ARTICLES |
| 20.8.26 | Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses | Microsoft Graph is a newer API that is meant to replace several others. OK, it's at version 2.3.9, so it's not all that new, but it's new enough that lots of folks (and commercial tools) aren't using it yet. It allows you to Get and Set info from/to M365, Entra Users and Entra managed | ARTICLES |
| 18.8.26 | Apple Patches iOS and macOS | Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS. | ARTICLES |
| 18.8.26 | Apple Screen Sharing Security | About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. | ARTICLES |
| 17.8.26 | UNISOC T612 LPE | UNISOC (Shanghai) Technologies Co., Ltd. is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT, and smart device chipsets. Formerly Spreadtrum, it serves major brands like Honor, realme, vivo, Samsung, and Motorola, with products in over 140 countries. | ARTICLES |
|
14.8.26 |
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit |
CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. |
ARTICLES |
|
13.8.26 |
In May 26, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. |
ARTICLES |
|
|
13.8.26 |
Using Gemma4 with Ollama - Testing File Hash Analysis and Recommendations with AI |
In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield sensor is collecting and tracking. |
ARTICLES |
|
13.8.26 |
A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash_history" and collecting meaningful additional data. |
ARTICLES |
|
|
10.8.26 |
The mobile section of the quarterly cyberthreat report includes statistics on malware, adware, and potentially unwanted software for Android, as well as descriptions of the most notable threats for Android and iOS discovered during the reporting period. |
ARTICLES |
|
|
10.8.26 |
Kaspersky products blocked nearly 400 million attacks that originated with various online resources. |
ARTICLES |
|
|
8.8.26 |
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of "modern" logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory |
ARTICLES |
|
|
6.8.26 |
On May 23, 26, a threat actor successfully authenticated to my Cowrie SSH honeypot using compromised credentials and, within 22 seconds, injected a backdoor SSH key, changed the root password, attempted to clear host-based access restrictions, and performed automated system reconnaissance. |
ARTICLES |
|
|
6.8.26 |
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm |
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle the cloud keys. That reflex has been correct in almost every supply-chain incident I have worked. |
ARTICLES |
|
4.8.26 |
This morning, I noticed specific sources "hunting" for vulnerabilities in URLs that I haven't noticed before. All of these URLs appear to be associated with diagnostic tools: |
ARTICLES |
|
|
3.8.26 |
Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor |
The Larva-24009 threat actor has been active since at least 2023, carrying out phishing email attacks targeting users both in Korea and globally to install malware. ASEC (AhnLab SEcurity intelligence Center (ASEC) has previously disclosed attack cases by this threat actor in 2024, and Subsequently, Cyble also identified this same attack campaign and named it “HeptaX.” |
ARTICLES |
|
2.8.26 |
This diary provides indicators from an Atomic MacOS (AMOS) stealer infection that I generated in my lab on July 31st, 26. |
ARTICLES |
|
|
1.8.26 |
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT. |
ARTICLES |