North Korean Lazarus hackers abused recent Windows zero-day to obtain kernel-level access
Lazarus' shift to exploiting zero-day flaws represents a significant escalation from their previous methods.
Lazarus' shift to exploiting zero-day flaws represents a significant escalation from their previous methods.
The malicious activities range from ransomware deployment to data-stealing attacks.
The incident does not appear to have involved any customer, supplier or colleague information or data.
NIST has updated the CSF’s core guidance.
Since at least 2022, the group has used the botnet to conduct operations targeting governments, militaries and organizations worldwide.
The exploit primarily targeted users accessing Tornado Cash via IPFS gateways, like ipfs.io and cf-ipfs.com.
The attack compromised Change Healthcare's IT systems, leading to widespread disruptions in pharmacy services across the US.
While focusing their strategic efforts on entities in Ukraine, UAC-0184 seemingly aimed to broaden their scope to include further entities associated with Ukraine.
The threat actor employs methods such as CNAME hijacking and SPF record exploitation.
In the past year, APT29 has been observed pilfering system-issued access tokens to infiltrate victim accounts.
Showing elements 1661 - 1670