Hackers Amp Up COVID-19 IP Theft Attacks - In-depth report looks at how COVID-19 research has become as a juicy new target for organized cybe... https://threatpost.com/hackers-amp-up-covid-19-ip-theft-attacks/162634/ #u.s.departmentofhomelandsecurity #covid-19supplychain #vulnerabilities #government #darkhotel #covid-19 #cozybear #malware #moderna #breach #pfizer #hacks #apt29 #ebook
Hackers Amp Up COVID-19 IP Theft Attacks

In-depth report looks at how COVID-19 research has become as a juicy new target for organized cybercrime.

Threatpost - English - Global - threatpost.com
Группировка XDSpy более 9 лет похищала секреты властей восточноевропейских стран #ESET, #XDSpy, #DarkHotel https://www.securitylab.ru/news/512727.php https://twitter.com/SecurityLabnews/status/1312681377192697857/photo/1
Группировка XDSpy более 9 лет похищала секреты властей восточноевропейских стран

В основном целью XDSpy являются госорганы, включая военные ведомства и министерства внутренних дел, а также частные компании.

Le système Linux est-il invulnérable ?

Nos experts ont analysé les attaques sophistiquées et les campagnes APT qui s’en prennent à Linux et vous donnent quelques conseils de sécurité.

Daily - French - France - www.kaspersky.fr/blog
Fascinating new malware with very weak attribution to #DarkHotel steals files from air-gapped computers https://www.bleepingcomputer.com/news/security/new-ramsay-malware-steals-files-from-air-gapped-computers/ #northkorea #infosec
New Ramsay malware steals files from air-gapped computers

Malware analysts have found multiple samples of a new malware toolkit that can collect sensitive files from systems isolated from the internet. They call it Ramsay and there are few known victims to date.

Government VPN Servers Targeted in Zero-Day Attack - The attacks are being carried out against Chinese government interests worldwide, according to Qih... more: https://threatpost.com/government-vpn-servers-zero-day-attack/154472/ #advancedpersistentthreat #chinesegovernment #vulnerabilities #cloudsecurity #remoteworking #cyberattacks #coronavirus #government #vpnservers #aptattack #darkhotel #covid-19 #qihoo360 #hacks #china
Government VPN Servers Targeted in Zero-Day Attack

The attacks are being carried out against Chinese government interests worldwide, according to Qihoo 360.

Threatpost - English - Global - threatpost.com
"So viele Erfolge sind selten": DarkHotel hackte Nordkoreaner mustergültig

Steckt DarkHotel hinter der neusten Attacke auf nordkoreanische Ziele? Das behauptet Kaspersky und verweißt auf die Ausführung des Angriffs.

Tarnkappe

Evidence suggest that #DarkHotel group were aiming to achieve a foothold at the agency rather than just stealing information. They should be attempting to create a convincing website and email domains to leverage on the #covid19 fear and lure people into #Phishing attacks.
The group was first identified in 2014 #kaspersky, who believes the group to be active since at least 2007.

https://threatpost.com/who-attacked-possible-apt-covid-19-cyberattacks-double/154083/

WHO Targeted in Espionage Attempt, COVID-19 Cyberattacks Spike

The DarkHotel group could have been looking for information on tests, vaccines or trial cures.

Threatpost - English - Global - threatpost.com
WHO Targeted in Espionage Attempt, COVID-19 Cyberattacks Spike - The DarkHotel group could have been looking for information on tests, vaccines or trial cures. more: https://threatpost.com/who-attacked-possible-apt-covid-19-cyberattacks-double/154083/ #worldhealthorganization #criticalinfrastructure #impersonationattacks #websecurity #coronavirus #cyberattack #government #darkhotel #espionage #covid-19 #testing #vaccine #hacks #cure #apt
WHO Targeted in Espionage Attempt, COVID-19 Cyberattacks Spike

The DarkHotel group could have been looking for information on tests, vaccines or trial cures.

Threatpost - English - Global - threatpost.com
Microsoft Zero-Day Actively Exploited, Patch Forthcoming - CVE-2020-0674 is a critical flaw for most Internet Explorer versions, allowing remote code executi... more: https://threatpost.com/microsoft-zero-day-actively-exploited-patch/152018/ #securityvulnerability #remotecodeexecution #internetexplorer #vulnerabilities #cve-2020-0674 #websecurity #jscript.dll #aptattacks #workaround #darkhotel #microsoft #windows7 #zeroday #patch #bug
Microsoft Zero-Day Actively Exploited, Patch Forthcoming

CVE-2020-0674 is a critical flaw for most Internet Explorer versions, allowing remote code execution and complete takeover.

Threatpost - English - Global - threatpost.com
The #Darkhotel #APT #hacking group discovered to have used #vbscript #zeroday vulnerable in outdated #Windows installations which don't disable VBscript by default. Crikey long campaign by this group spanning many years. These DPRK supported guys are busier than a one armed brick layer in Baghdad
https://www.bleepingcomputer.com/news/security/zero-day-in-microsofts-vbscript-engine-used-by-darkhotel-apt/
Zero-Day In Microsoft's VBScript Engine Used By Darkhotel APT

A vulnerability in the VBScript engine has been used by hackers working for North Korea to compromise systems targeted by the Darkhotel operation.