Výsledky hledání

výrobce: Microsoft× typ: varování× v celém archivu zrušit filtry

7 karet z 7 položek CZ · EN/orig

2

ASCII smuggling crosses over from AI prompt injection to phishing evasion

In this article What is ASCII smuggling?Writing a practical ASCII-smuggling signatureWhat we observed: ASCII smuggling repurposed for phishingWhat is known and what is newIs there a detection gap?Mitigation and protection guidanceReferencesLearn More Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people…

Microsoft finance US

tg: varování tg: zneužíváno tp: phishing tp: identita

Microsoft Security Blog ·

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

In this article Risk to enterprise environmentsAttack chain overviewMitigation and response recommendationsLearn more Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session. Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI…

Microsoft US

tg: varování tg: rozbor tp: phishing tp: špionáž

Microsoft Security Blog ·

1

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

In this article Attack chain overviewCampaign scope and targetingMitigation and protection guidanceReferencesLearn more Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of…

Microsoft Razer Kaspersky zdravotnictví výroba a průmysl veřejná správa školství US

tg: varování tg: rozbor tp: malware

Microsoft Security Blog ·

1

TerminalFix looks like ClickFix, but delivers a very different payload

Microsoft has published details about a Windows malware campaign it calls TerminalFix. The social engineering used to infect people is very similar to what we’ve seen in ClickFix campaigns. A website visitor is presented with a fake Cloudflare CAPTCHA which, when clicked, secretly copies a malicious command to their clipboard. Then they receive instructions on what they need to do to “prove they are human,” when in reality they are being instructed to execute the malicious command. After…

Microsoft US

tg: varování tg: rozbor tp: malware tp: špionáž

Malwarebytes Labs ·

2

1

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

In this article Attack chain overviewMitigation and protection guidanceLearn more Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns…

Microsoft US

tg: varování tg: zneužíváno tp: malware tp: phishing

Microsoft Security Blog ·