Quotidien Hebdomadaire Mensuel

Quotidien Shaarli

Tous les liens d'un jour sur une page.

March 31, 2025

Fake Zoom Ends in BlackSuit Ransomware

Key Takeaways The threat actor gained initial access by a fake Zoom installer that used d3f@ckloader and IDAT loader to drop SectopRAT. After nine days of dwell time, the SectopRAT malware dropped …

Les actions et projets futurs de l'OFCS pour renforcer la cybersécurité en Suisse

Depuis 2024, l'OFCS est un office fédéral indépendant au sein du Département fédéral de la défense, de la prot

ClickFix: Another Deceptive Social Engineering Technique

Discover ClickFix, a rising social engineering threat used to deliver malware and learn how to detect and respond against it with Logpoint.

Pulling the Threads on the Phish of Troy Hunt

Connecting a successful phishing attempt to Scattered Spider through Validin pivoting

TCCing is Believing

Apple finally adds TCC events to Endpoint Security!
Since the majority of macOS malware circumvents TCC through explicit user approval, it would be incredibly helpful for any security tool to detect this — and possibly override the user’s risky decision. Until now the best (only?) option was to ingest log messages generated by the TCC subsystem. This approach was implemented in a tool dubbed Kronos, written by Calum Hall Luke Roberts (now, of Phorion fame). Unfortunately, as they note, this approach did have it drawbacks:

Hidden Malware Strikes Again: Mu-Plugins Under Attack

Hidden malware strikes WordPress mu-plugins. Our latest findings reveal how to safeguard your site against these threats.

Ransomware crews add EDR killers to their arsenal

interview: Crims are disabling security tools early in attacks, Talos says