North Korean hackers target defence industry with custom ThreatNeedle backdoor
The Lazarus group had been targeting the defense industry since early 2020.
The Lazarus group had been targeting the defense industry since early 2020.
The attack against the company was part of a broader campaign in which threat actors exploited multiple zero-day vulnerabilities in the Accellion FTA software.
NSDC says that the attack's goal was "the mass contamination of information resources of public authorities."
LazyScripter is not as sophisticated as other APT groups and mostly relies on open source and commercially available RATs.
CVE-2021-20016 is an SQL injection flaw that allows a remote attacker to execute arbitrary SQL queries in database.
The attacks exploited several vulnerabilities in Accellion’s FTA product in order to gain access and steal data.
The researchers uncovered two versions of the Silver Sparrow malware designed to target Intel x86_64 and Appe M1 ARM64 architectures.
A weekly vulnerability digest.
The agency said it has no evidence that any SSO accounts have been compromised.
Microsoft says it has completed the investigation into its SolarWinds breach.
Showing elements 3411 - 3420