Výsledky hledání

sektor: veřejná správa v celém archivu

Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.

zrušit filtry CZ · EN/orig

118 karet z 119 položek · strana 2 z 2

19

1

1

One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

Executive Summary SentinelLABS has been tracking sustained cyberespionage activity against several Pakistani law enforcement organizations, taking place from February 2024 to April 2026. All these actors converged on Balochistan Police over this period, bringing both a partner and an adversary of Pakistan to the same police force in a province shaped by a separatist insurgency and the regional tensions it has drawn in. At Balochistan Police, the compromised assets included servers hosting web…

veřejná správa US

SentinelLabs ·

1

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and…

Microsoft veřejná správa US

Mandiant / Google TI ·

1

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Note: SysAid was not compromised, and no SysAid vulnerability was involved. The attacker had already gained access to the victim environment and abused a legitimate software-deployment feature to deploy malware onto another machine within it. Key Points Check Point Research (CPR) tracks ‘Cavern Manticore’ as an Iran-nexus threat actor operating against Israeli targets, with a focus on the government and IT sectors. Cavern Manticore shares technical overlaps with other Iranian MOIS (Ministry of…

Check Point veřejná správa telekomunikace IL

Check Point Research ·

2

22nd June – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment data were not affected.…

KEV ✓ EPSS 0.96 CVE-2026-20245 CVE-2026-33017 CVE-2026-34908 CVE-2026-34909 CVE-2026-34910 CVE-2026-41947 CVE-2026-41948 CVE-2026-55255 Cisco Ubiquiti Dify Langflow veřejná správa zdravotnictví finance IL

Check Point Research ·

1

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a revitalization of pro-Russia hacktivism at an unprecedented…

veřejná správa US

Mandiant / Google TI ·

1

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing…

Google veřejná správa obrana US

Mandiant / Google TI ·

1

Útočníci získali přístup k desítkám tisíc firewallů Fortinet

Bezpečnostní výzkumníci upozornili na rozsáhlou kampaň zaměřenou na firewally a VPN brány Fortinet, při níž mělo být kompromitováno téměř 74 000 zařízení ve 194 zemích. Útočníci podle zveřejněných informací automatizovaně vyhledávali veřejně dostupná administrační rozhraní, získávali konfigurace zařízení a následně offline prolamovali přístupové údaje. Mezi údajně zasaženými organizacemi jsou nadnárodní společnosti, státní instituce i provozovatelé kritické infrastruktury. Případ zároveň…

Fortinet veřejná správa energetika vodárenství telekomunikace CZ

CSIRT.CZ (CZ.NIC) ·

1

2

WEBINÁR: Praktické rady k používaniu JISKB (Jednotný informačný systém kybernetickej bezpečnosti)

V súvislosti so zavádzaním požiadaviek projektu NIS2 sme pre vás pripravili dva bezplatné webináre zamerané na praktické používanie JISKB – Jednotného informačného systému kybernetickej bezpečnosti. Počas 90-minútového online stretnutia získate prehľad o práci so systémom a priestor bude aj na vaše otázky. Obsah oboch termínov je rovnaký – vyberte si ten, ktorý vám viac vyhovuje.... The post WEBINÁR: Praktické rady k používaniu JISKB (Jednotný informačný systém kybernetickej bezpečnosti)…

veřejná správa SK

SK-CERT (NBÚ SR) ·

1

UNC1151/Ghostwriter phishing campaign targeting Gmail accounts

Recently, we have been observing attacks by the UNC1151/Ghostwriter group targeting Gmail accounts. This group has been regularly attacking the mailboxes of Polish citizens for several years, although in the past these attacks focused on other email providers. The techniques used evolve over time, but the core theme of the messages and their objective remain unchanged.

veřejná správa PL

CERT Polska ·

1

2026-007: Critical Vulnerability in Windows Netlogon

On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended updating affected Windows servers as soon as possible.

Microsoft veřejná správa EU

CERT-EU ·

4

2

Útočníci zneužívajú no-code platformu SOFTR na zber prihlasovacích údajov

Varovanie pred phishingovou kampaňou Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ varuje pred rozsiahlou phishingovou kampaňou zameranou primárne na súkromné firmy a štátne inštitúcie. Jej cieľom je vylákať od obetí prihlasovacie údaje k ich e-mailovým schránkam. Predmetná kampaň sa šíri prostredníctvom e-mailov s tematikou upozornení na vypršanie platnosti hesla k poštovej schránke a text správy používateľa vyzýva na reakciu. Útočníci... The post Útočníci zneužívajú no-code platformu…

SOFTR veřejná správa SK

SK-CERT (NBÚ SR) ·

1

LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine

In this LABScon 25 presentation, ESET researchers Matthieu Faou and Zoltán Rusnák present the first technical evidence that Gamaredon actively facilitated Turla’s access to high-value Ukrainian targets in Ukraine. Across incidents observed between February and June 2025, Gamaredon tooling, including PteroGraphin and PteroOdd, was used to deploy Turla’s Kazuar backdoor and, in at least one case, restore Turla’s access after the group appeared to have lost its foothold. The talk opens with a…

ESET SentinelOne veřejná správa US

SentinelLabs ·

1

1

Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense

On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices related to Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products. According to the update, the ArcaneDoor threat actor has developed a previously unknown persistence mechanism that is preserved across upgrading to the fixed releases that…

KEV ✓ EPSS 0.87 CVE-2025-20333 CVE-2025-20362 Cisco veřejná správa US

Cisco PSIRT ·

1

Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America

TrendAI™ Research has identified two emerging threat campaigns—SHADOW-AETHER-040 and SHADOW-AETHER-064—that use agentic AI to drive intrusion operations against government and financial organizations in Latin America, marking these among the first cases we have observed of AI agents executing attacks from initial access to data exfiltration.

Trend Micro veřejná správa finance JP

Trend Micro ·

1

2

3

1

1

1

1

1

1

1

1

1