Výsledky hledání

téma: identita× v celém archivu zrušit filtry

221 karet z 233 položek · strana 4 z 4 CZ · EN/orig

2

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

In this article The CaptiveCrunch campaignStorm-2945 and Midnight BlizzardCaptiveCrunch tradecraft and toolingHow to protect against CaptiveCrunch activityMicrosoft Defender detections and hunting guidanceIndicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some…

Microsoft veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: identita tp: špionáž

· Microsoft Security Blog · CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

Hugging Face reconstructed more than 17,000 attacker events from a July 2026 intrusion driven by an autonomous artificial intelligence (AI) agent. The path was familiar: untrusted dataset content abused a processing worker (file disclosure, then code execution), credential harvest, then multi-cluster lateral movement. Production Elastic Defend behavior rules and Elastic Security detection (SIEM) rules already watch those types of behaviors. This post maps each stage to detections you can enable…

Hugging Face OpenAI Elastic US

tg: incident tg: rozbor tg: propagace tp: únik dat tp: AI tp: identita

· Elastic Security · Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend

2

You were onto something with “It’s the Climb,” Miley

Welcome to this week’s edition of the Threat Source newsletter. For my fianceé’s 30th birthday, I took her on a weekend trip to Shenandoah National Park – a favorite of ours since we went to a wedding there several years back. We’ve done several incredible hikes over the years, but one in particular had always loomed over my head: Old Rag, a 9.3 mile circuit hike that’s largely considered the most difficult in Virginia. I've always been warned that at the beginning and end, you hate Old Rag.…

zdravotnictví veřejná správa US

tg: rozbor tg: přehled tp: phishing tp: ransomware tp: identita

· Cisco Talos · You were onto something with “It’s the Climb,” Miley

​​​​What’s new in Microsoft Security: July 2026

Every organization needs security that protects end to end with the speed and scale of AI. Microsoft’s vision is simple: security should be ambient and autonomous, just like the AI it protects. As organizations scale AI and expand across environments, security teams need protection that covers every surface. This month’s updates help security and IT teams secure their AI environments, use AI to defend at speed and scale, and strengthen the foundations that AI-powered operations depend on.…

Microsoft US

tg: novinka v produktu tg: propagace tp: AI tp: identita

· Microsoft Security Blog · ​​​​What’s new in Microsoft Security: July 2026

2

The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches

Key Takeaways Two real-world cloud attacks reached meaningful impact in less than ten minutes despite pursuing entirely different objectives. Both attackers treated the environment as a connected system, using existing permissions and relationships to expand their reach. Reconnaissance increasingly focuses on understanding access and capability rather than discovering vulnerable assets. AI is compressing the gap between discovery, decision-making, and execution for cloud attackers. The interval…

Amazon Web Services US

tg: incident tg: rozbor tg: propagace tp: podvod tp: AI tp: identita

· Qualys · The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches

1

New North Korean campaign uses fake coding interviews to steal developer credentials

Elastic Security Labs found a new Contagious Interview campaign, tracked as REF9403, hiding malware inside SVG image files using steganography. To our knowledge, this specific infection chain has not been previously documented. We found it after the DPRK-aligned group targeted our own community Slack workspace with a fake job posting and a "coding challenge" project. Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet…

US

tg: varování tg: rozbor tp: malware tp: phishing tp: identita tp: špionáž

· Elastic Security · New North Korean campaign uses fake coding interviews to steal developer credentials

1

The Risk of Exposed Cloud Functions and How to Harden

Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RFI) Command Injection Successful exploitation of these vulnerabilities can…

Google US

tg: rozbor tg: návod tp: identita

· Mandiant / Google TI · The Risk of Exposed Cloud Functions and How to Harden

1

1

1

1

1

1

SPOJENO PŘES CVE VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products

[VDE-2026-046] Vulnerable components expose sensitive information to unauthorized actors through an unsecured configuration interface. Vulnerable firmware releases contain an unsecured configuration interface that allows retrieval of sensitive information such as hashed credentials. It was found that users with no or low rights can access information from devices that should not be available to them. An attacker can use this information to impersonate authorized users.

EPSS 0.00 CVE-2026-3323 VEGA DE

tg: zranitelnost tp: identita tp: průmyslové systémy

· CERT@VDE · VEGA: Missing Authentication for critical function in VEGAPULS two- and four-wire products

2

1

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

AAD Graph Activity Logs are now ingestible into Elastic and usable for threat detection within the SIEM/XDR solution. That sentence shouldn't be exciting, but it is. For most of the past decade, this slice of telemetry simply didn't exist as a customer-accessible log stream. Microsoft Graph Activity Logs (the modern graph.microsoft.com surface) went GA in April 2024. The legacy graph.windows.net surface, the one adversary tooling actually hits, stayed dark until early 2026. This post walks the…

Microsoft Elastic US

tg: rozbor tg: novinka v produktu tg: návod tp: identita

· Elastic Security · Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

1

CODESYS Control - Incorrect Authorization

[Advisory2026-08_VDE-2026-056] The CODESYS Control runtime system provides a user management mechanism with multiple privilege groups including the visualization administrators group, which is intended solely to manage visualization users. Due to insufficient authorization checks an authenticated remote user with low-privileged visualization administrator access can delete higher-privileged accounts. However, independent mechanisms protect the deletion of the last remaining device admin user,…

EPSS 0.00 CVE-2026-8046 CODESYS DE

tg: zranitelnost tp: identita tp: průmyslové systémy

· CERT@VDE · CODESYS Control - Incorrect Authorization

1

1

1

1

1

Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

Tycoon 2FA is currently the most prolific Phishing-as-a-Service (PhaaS) platform among AiTM phishing kits. First observed in August 2023 and attributed to Storm-1747 (per Microsoft Threat Intelligence), the kit provides turnkey adversary-in-the-middle (AiTM) capabilities that bypass multi-factor authentication and steal authenticated session tokens from Microsoft 365 and Google Workspace accounts. At its peak, Tycoon 2FA accounted for roughly 62% of phishing attempts blocked by Microsoft,…

Microsoft Google US

tg: varování tg: rozbor tp: phishing tp: identita

· Elastic Security · Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

1

CODESYS Visualization - Insufficiently Protected Credentials

[Advisory2026-07_VDE-2026-052] A vulnerability in the CODESYS Visualization login dialog has been identified. During logins within the CODESYS Visualization, authentication data may not be sufficiently isolated when multiple users perform login operations concurrently. As a result, an authenticated visualization user may be able to obtain credentials entered by another visualization user. The issue affects only login operations within an active visualization session and can be triggered via…

EPSS 0.00 CVE-2026-0393 CODESYS DE

tg: zranitelnost tp: identita tp: průmyslové systémy

· CERT@VDE · CODESYS Visualization - Insufficiently Protected Credentials

1

1

Supply Chain Attack: rilevata nuova ondata di compromissione pacchetti NPM

Rilevata una campagna su larga scala di compromissione della supply chain nell'ecosistema npm, denominata "Mini Shai-Hulud". L'attacco sfrutta un malware di tipo worm per infiltrarsi negli ambienti di sviluppo e nelle pipeline di Continuous Integration/Continuous Deployment (CI/CD). L'obiettivo primario è l'esfiltrazione di credenziali sensibili e la successiva propagazione automatizzata attraverso la pubblicazione di versioni malevole di pacchetti legittimi.

npm IT

tg: varování tp: malware tp: dodavatelský řetězec tp: identita

· CSIRT Itálie (ACN) · Supply Chain Attack: rilevata nuova ondata di compromissione pacchetti NPM

1

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

Executive Summary SentinelLABS has identified PCPJack, a credential theft framework that worms across exposed cloud infrastructure and removes artifacts associated with TeamPCP, a threat actor persona who claimed several high-profile supply chain intrusions throughout early 2026. The toolset harvests credentials from cloud, container, developer, productivity, and financial services, then exfiltrates the data through attacker-controlled infrastructure while attempting to spread to additional…

Docker Kubernetes Redis MongoDB US

tg: varování tg: rozbor tp: malware tp: podvod tp: identita

· SentinelLabs · PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

2

Know who to watch before the incident finds you

Elastic Security v9.4 introduces Entity Analytics Watchlists, a new capability in the Entity Analytics suite that lets security teams create named, weighted lists of users, hosts, and services and feed that context directly into the platform's risk scoring pipeline. The gap this closes isn't awareness, as most security teams already know which entities deserve elevated scrutiny. The gap is that SIEMs have had no way to express that organizational knowledge as a risk signal. Watchlists do that…

Elastic US

tg: novinka v produktu tg: propagace tp: identita

· Elastic Security · Know who to watch before the incident finds you

Your UEBA is lying to you: Why entity record quality decides everything

There's an uncomfortable truth in security analytics that nobody talks about at conferences: The quality of your detections, alerts, and investigations is only as good as the entity records that represent the users, hosts, and services in your environment. Not the machine learning models. Not the anomaly detection algorithms. Not the risk scoring engine. The entities: the foundations to teach your system about the data and protect it. Get the entities wrong, and everything downstream is…

Elastic US

tg: názor tg: propagace tp: identita

· Elastic Security · Your UEBA is lying to you: Why entity record quality decides everything

1

Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities

TrendAI™ Research breaks down Quasar Linux (QLNX), a previously undocumented sophisticated Linux RAT with low detection rates. In this blog, we examine a full-featured Linux threat incorporating a rootkit, a PAM backdoor, credential harvesting, and more, revealing how this malware enables stealthy access, persistence, and potential supply-chain attacks.

JP

tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Trend Micro · Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities

1

CI/CD pipeline abuse: the problem no one is watching

Preamble In 2025 and 2026, we watched a pattern play out across the industry. Attackers stopped going after production servers directly and started targeting the automation that deploys to them. Compromised developer credentials, a modified workflow file, and suddenly every secret in a CI/CD environment is streaming to an attacker-controlled endpoint. We saw this play out across incidents involving major open-source projects, Fortune 500 companies, and critical infrastructure tooling. The…

GitHub GitLab Microsoft US

tg: rozbor tg: novinka v produktu tp: dodavatelský řetězec tp: AI tp: identita

· Elastic Security · CI/CD pipeline abuse: the problem no one is watching

1

1

1

Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting

Key Takeaways We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and OpenClaw were embedded in the operator’s day-to-day workflow, supporting troubleshooting, orchestration, and refinement of the collection pipeline. This AI-assisted workflow resulted in the modular platform Bissa scanner […] The post Bissa Scanner Exposed: AI-Assisted Mass Exploitation and…

US

tg: varování tg: zneužíváno tg: rozbor tp: AI tp: identita

· The DFIR Report · Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting

1

1

1

1

1

1

1