Quotidien Hebdomadaire Mensuel

Quotidien Shaarli

Tous les liens d'un jour sur une page.

January 27, 2025

Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware

Key Takeaways This intrusion began with the download and execution of a Cobalt Strike beacon that impersonated a Windows Media Configuration Utility. The threat actor used Rclone to exfiltrate data…

UnitedHealth updates number of data breach victims to 190 million

The 2024 ransomware attack on Change Healthcare exposed the data of about 190 million people, according to an update from parent company UnitedHealth Group.

Mysterious backdoor found on select Juniper routers

Someone has been quietly backdooring selected Juniper routers around the world in key sectors including semiconductor, energy, and manufacturing, since at least mid-2023.

The devices were infected with what appears to be a variant of cd00r, a publicly available "invisible backdoor" designed to operate stealthily on a victim's machine by monitoring network traffic for specific conditions before activating.

48,000+ internet-facing Fortinet firewalls still open to attack

Too many Fortinet firewalls vulnerable to attack via CVE-2024-55591 are still accessible from the Internet.

Sweden launches sabotage probe after another data cable damaged in Baltic Sea Europe

Another undersea data cable, this time connecting Sweden and Latvia, has been severed in the Baltic Sea, officials from both countries said Sunday. The incident prompted Sweden to launch a criminal probe into the matter and seize a "suspect vessel" vessel headed for Russia.

The J-Magic Show: Magic Packets and Where to find them - Lumen Blog

A backdoor tailored to Juniper routers that hides the activation signal in regular traffic using “Magic Packets” to give access to an attacker

HellCat and Morpheus | Two Brands, One Payload as Ransomware Affiliates Drop Identical Code

Analysis of payloads suggest affiliates may be using a shared codebase or common builder to deploy attacks under different RaaS brand names.

2024 macOS Malware Review | Infostealers, Backdoors, and APT Campaigns Targeting the Enterprise

Learn about the key macOS malware families from 2024, including tactics, IoCs, opportunities for detection, and links to further reading.