Click here to download all references as Bib-File.•
| 2024-09-20
⋅
Trend Micro
⋅
How Ransomhub Ransomware Uses EDRKillShifter to Disable EDR and Antivirus Protections RansomHub Water Bakunawa |
| 2024-09-05
⋅
CISA
⋅
AA24-249A: Russian Military Cyber Actors Target US and Global Critical Infrastructure WhisperGate |
| 2024-07-30
⋅
Spamhaus
⋅
Too big to care? - Our disappointment with Cloudflare’s anti-abuse posture |
| 2024-07-29
⋅
Mandiant
⋅
UNC4393 Goes Gently into the SILENTNIGHT Black Basta QakBot sRDI SystemBC Zloader UNC3973 UNC4393 |
| 2024-07-26
⋅
Darktrace
⋅
Disarming the WarmCookie Backdoor: Darktrace’s Oven-Ready Solution WarmCookie |
| 2024-07-16
⋅
JPCERT/CC
⋅
MirrorFace Attack against Japanese Organisations LODEINFO NOOPDOOR |
| 2024-05-10
⋅
CISA
⋅
AA24-131A: #StopRansomware: Black Basta Black Basta Black Basta |
| 2024-04-10
⋅
0ffset Blog
⋅
Resolving Stack Strings with Capstone Disassembler & Unicorn in Python Conti |
| 2024-04-04
⋅
Mandiant
⋅
Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies UNC3569 UNC5266 UNC5291 UNC5330 UNC5337 UTA0178 |
| 2024-04-04
⋅
Mandiant
⋅
Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies TONERJAM |
| 2024-03-29
⋅
CISA
⋅
Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094 xzbot |
| 2024-03-20
⋅
CISA
⋅
Review of the Summer 2023 Microsoft Exchange Online Intrusion Storm-0558 |
| 2024-02-07
⋅
CISA
⋅
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure ScanLine |
| 2024-02-07
⋅
CISA
⋅
MAR-10448362-1.v1 Volt Typhoon ScanLine |
| 2024-01-15
⋅
Russian Panda Research Blog
⋅
From Russia With Code: Disarming Atomic Stealer AMOS |
| 2023-12-30
⋅
Rewterz Information Security
⋅
Rewterz Threat Alert – Widely Abused MSIX App Installer Disabled by Microsoft – Active IOCs EugenLoader POWERTRASH BATLOADER DarkGate FlawedGrace NetSupportManager RAT SectopRAT Storm-0506 |
| 2023-12-30
⋅
Rewterz Information Security
⋅
Rewterz Threat Alert – Widely Abused MSIX App Installer Disabled by Microsoft – Active IOCs HijackLoader Storm-1674 |
| 2023-12-15
⋅
⋅
Gatewatcher
⋅
Utilisation de faux profils Steam : Vidar Stealer prend les commandes Vidar |
| 2023-12-13
⋅
CISA
⋅
Russian Foreign Intelligence Service (SVR) Exploiting JetBrains TeamCity CVE Globally GraphDrop |
| 2023-11-16
⋅
CISA
⋅
Scattered Spider Ave Maria BlackCat Raccoon Vidar |