Click here to download all references as Bib-File.•
2022-07-29
⋅
RiskIQ
⋅
Falling Into a Nest of Vipers or: "Why'd it have to be snakes?" (Microsoft Threat Intelligence Brief) |
2022-07-28
⋅
SentinelOne
⋅
Living Off Windows Defender | LockBit Ransomware Sideloads Cobalt Strike Through Microsoft Security Tool Cobalt Strike LockBit |
2022-07-27
⋅
Microsoft
⋅
Untangling KNOTWEED: European private-sector offensive actor using 0-day exploits Subzero Denim Tsunami |
2022-07-26
⋅
Microsoft
⋅
Malicious IIS extensions quietly open persistent backdoors into servers CHINACHOPPER MimiKatz |
2022-07-14
⋅
Microsoft
⋅
North Korean threat actor (H0lyGh0st /DEV-0530) targets small and midsize businesses with H0lyGh0st ransomware SiennaBlue SiennaPurple Storm-0530 |
2022-07-13
⋅
Microsoft
⋅
Uncovering a macOS App Sandbox escape vulnerability: A deep dive into CVE-2022-26706 |
2022-07-12
⋅
Microsoft
⋅
From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud |
2022-07-06
⋅
Trend Micro
⋅
Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&C Server HavanaCrypt |
2022-07-05
⋅
Microsoft
⋅
Hive ransomware gets upgrades in Rust Hive |
2022-06-30
⋅
Microsoft
⋅
Using process creation properties to catch evasion techniques |
2022-06-30
⋅
Microsoft
⋅
Toll fraud malware: How an Android application can drain your wallet Joker |
2022-06-27
⋅
Netskope
⋅
Emotet: Still Abusing Microsoft Office Macros Emotet |
2022-06-23
⋅
InQuest
⋅
Follina, the Latest in a Long Chain of Microsoft Office Exploits |
2022-06-21
⋅
BleepingComputer
⋅
Microsoft Exchange servers hacked by new ToddyCat APT gang ToddyCat |
2022-06-16
⋅
ESET Research
⋅
How Emotet is changing tactics in response to Microsoft’s tightening of Office macro security Emotet |
2022-06-13
⋅
Microsoft
⋅
The many lives of BlackCat ransomware BlackCat Velvet Tempest |
2022-06-13
⋅
Microsoft
⋅
The many lives of BlackCat ransomware BlackCat |
2022-06-11
⋅
Twitter (@MsftSecIntel)
⋅
Tweet on DEV-0401, DEV-0234 exploiting Confluence RCE CVE-2022-26134 Kinsing Mirai Cobalt Strike Lilac Typhoon |
2022-06-03
⋅
Trustwave
⋅
Trustwave's Action Response: Microsoft zero-day CVE-2022-30190 (aka Follina) |
2022-06-02
⋅
Microsoft
⋅
Exposing POLONIUM activity and infrastructure targeting Israeli organizations POLONIUM |