When trusted sites turn. [Research Saturday]

When trusted sites turn. [Research Saturday]

Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researchers have identified a newly named threat actor, DriveSurge, which has compromised thousands of legitimate websites and uses ClickFix and fake browser update lures to distribute malware at scale through a pay-per-install operation. The group leverages a traffic distribution system called zTDS to silently redirect visitors from trusted websites to malicious payloads, while employing sophisticated infrastructure, obfuscation, and fingerprinting techniques to evade detection. The report also details how DriveSurge targets both Windows and macOS users and provides defenders with eight infrastructure fingerprints to help identify and disrupt the campaign. The research and executive brief can be found here: Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(3734)

Building a secure space internet. [T-Minus: Space-Cyber Briefing]

Building a secure space internet. [T-Minus: Space-Cyber Briefing]

As space infrastructure has continued to expand, developing secure space systems has become just as important as launching the spacecraft themselves. In this week's episode, host Maria Varmazis sits ...

23 Aug 24min

A RAT in the spreadsheet. [Research Saturday]

A RAT in the spreadsheet. [Research Saturday]

Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers hav...

22 Aug 29min

The guest nobody invited.

The guest nobody invited.

CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agen...

21 Aug 31min

The robots have gone bananas.

The robots have gone bananas.

Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat ...

20 Aug 31min

Hackers hiding in plain sight.

Hackers hiding in plain sight.

Medusa’s reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft ...

19 Aug 28min

Fake it till you exfiltrate it.

Fake it till you exfiltrate it.

A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware ...

18 Aug 28min

Please hold while we decide.

Please hold while we decide.

Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged e...

17 Aug 28min

Frontier models and the future of cyber defense. [Special Edition]

Frontier models and the future of cyber defense. [Special Edition]

In this special edition from Black Hat, Dave Bittner sits down with ⁠Clint Gibler⁠, Cyber Lead at ⁠OpenAI⁠, and ⁠Robby Winchester⁠, Chief Global Professional Services Officer at ⁠SpecterOps⁠, to explo...

16 Aug 28min

Populärt inom Politik & nyheter

aftonbladet-krim
p3-krim
aftonbladet-daily
rss-expressen-dok
svenska-fall
flashback-forever
rss-krimstad
rss-vad-fan-hande
motiv
rss-krimreportrarna
rss-sanning-konsekvens
svd-ledarredaktionen
spar
rss-frandfors-horna
rss-flodet
politiken
rss-aftonbladet-krim
fordomspodden
grans
krimmagasinet