Bulletins d'actualité : Différence entre versions

De Docaposte Cyberdéfense
Aller à : navigation, rechercher
Ligne 15 : Ligne 15 :
 
<br>
 
<br>
 
<br>
 
<br>
−
<rss max=5 highlight="CVE">https://www.us-cert.gov/ncas/alerts.xml</rss>
+
<rss max=5 highlight="CVE">https://securelist.com/feed/</rss>

Version du 1 mars 2018 à 12:47

Classification


Edb-2015-theme-logo641.png

Offensive Security’s Exploit Database



Doc.png

MacSync under the microscope: new delivery methods and a new payload
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.

Doc.png

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.

Doc.png

The Odyssey and Trojans again: MovieReaper attacks users in multiple countries through compromised torrents
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as The Odyssey, and uses the Solana blockchain to hide its C2 infrastructure.

Doc.png

NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.

Doc.png

Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.