58 arrested in global cybercrime crackdown
The international operation, called Operation Jackal IV, focused on West African criminal networks, including the Black Axe cybercrime syndicate.
The international operation, called Operation Jackal IV, focused on West African criminal networks, including the Black Axe cybercrime syndicate.
Zimbra developer Synacor fixed the flaw in version 10.1.20, released on July 20.
The attackers used publicly known flaws to gain access and leveraged AI-powered tools for reconnaissance, exploit development, and other actions.
BTR_CLI can be used as an EDR/AV bypass technique, disabling security solutions using a trusted Windows driver, without relying on typical BYOVD techniques.
The attacks reportedly start with ZIP files that use shortcut (.LNK) files to begin the infection.
In brief: Threat actors are actively exploiting flaws in Apple, Microsoft, Zimbra, and other software; Russian hackers target defense and aerospace sectors in Europe and the US; and more.
The malware appears to have been developed mainly by human operators, but shows signs of AI-assisted development.
The indictment expands on a 2018 case and adds new defendants.
In the Dahua case, attacks involved a persistent backdoor account named p2pwn, paired with the password p2password.
TWINLOOT is a modular Python implant that keeps its C&C infrastructure inside trusted Microsoft services like SharePoint Online, Microsoft Graph API and Microsoft Teams TURN servers.
Showing elements 51 - 60