Výsledky hledání

výrobce: Microsoft× typ: varování× v celém archivu zrušit filtry

21 karet z 21 položek CZ · EN/orig

1

NightEagle targets Russian companies

Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign. Initial access In most incidents, the attackers used compromised valid…

KEV ✓ · ransomware EPSS 1.00 CVE-2019-0708 CVE-2020-0688 Microsoft RU

tg: varování tg: rozbor tp: malware tp: špionáž

· Securelist (Kaspersky) · NightEagle targets Russian companies

2

Upozornění na Device Code Phishing

Upozorňujeme na phishingovou kampaň zneužívající autentizační mechanismus Device Code Flow. Útočník pod záminkou připojení ke schůzce nebo videohovoru přes legitimní nástroje přiměje uživatele k autorizaci a přes kontrolovanou relaci dochází ke krádeži přístupového tokenu a následné kompromitaci uživatele.Device Code FlowDevice Code Flow je autentizační mechanismus navržený pro případy, kdy se uživatel přihlašuje na zařízení s omezenými možnostmi zadávání přihlašovacích údajů, například na…

Microsoft CZ

tg: varování tg: návod tp: phishing tp: identita

· NÚKIB · Upozornění na Device Code Phishing

The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

Elastic Security Labs has tracked REF9334, a Brazilian banking malware operation, since May 2025. Its toolkit is called KREMLIN (as named by the malware author, Kr3mlin4rt1st), though nothing about the operation is Russian. Lures impersonate twelve Brazilian banks; error messages and code comments are written in Portuguese, and the operators' Ethereum transactions cluster during São Paulo working hours. Over 15 months and seven campaigns, they built a malicious browser extension that installs…

Google Microsoft finance US

tg: varování tg: rozbor tp: malware tp: podvod

· Elastic Security · The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

1

3

Detect and disrupt AI-themed attacks with Microsoft Defender

Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude.1 The goal is to make phishing, search-driven malware campaigns, and malvertising—which is malicious advertising that uses online ads to lure users to harmful sites, downloads, or redirect…

Microsoft US

tg: varování tg: rozbor tg: propagace tp: malware tp: phishing tp: podvod tp: identita

· Microsoft Security Blog · Detect and disrupt AI-themed attacks with Microsoft Defender

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble. Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch your browser or restart your computer later can feel harmless. But a newly documented exploit kit called “BlueMoon” shows how quickly patching delays can become dangerous. Proofpoint Researchers found four espionage groups using the same exploit chain against Chrome browsers running…

Google Microsoft US

tg: varování tg: zneužíváno tg: rozbor tg: propagace tp: malware tp: phishing tp: špionáž

· Malwarebytes Labs · BlueMoon exploit kit turns Chrome and Windows flaws into attacks

SPOJENO PŘES CVE New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]

KEV ✓ EPSS 0.01 CVE-2026-85046 CVE-2026-85880 CVE-2026-87491 Microsoft Google US

tg: varování tg: zneužíváno tg: rozbor tp: malware tp: phishing tp: špionáž

· BleepingComputer · New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws · Volexity · Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

1

Passkey-themed social engineering leads to identity and cloud compromise

In this article Attack chain overviewAttributionMitigation and protection guidanceLearn more Microsoft Security Research is tracking active cloud-based intrusions spanning multiple accounts in which unusual sign-ins were followed by threat actor-added authentication methods, high-volume Microsoft Graph activity, SharePoint and OneDrive downloads, and email collection through REST APIs. Microsoft Security Research assesses that this sequence is consistent with automated collection from…

Microsoft US

tg: varování tg: rozbor tp: phishing tp: únik dat tp: identita

· Microsoft Security Blog · Passkey-themed social engineering leads to identity and cloud compromise

1

1

Angry Birds: Toy Ghouls’ new toys

Introduction We continue tracking the activity of Toy Ghouls (also known as Bearlyfy, Laboo.boo, and Feral Wolf), a financially motivated group that has been targeting Russian organizations since 2025. The attackers initially relied exclusively on tools pulled from public GitHub repositories along with leaked Babuk and LockBit ransomware builders, later shifting to their own custom ransomware, GenieLocker. In early July 2026, we observed the group using a custom backdoor for the first time. We…

Microsoft RU

tg: varování tg: rozbor tp: malware tp: ransomware

· Securelist (Kaspersky) · Angry Birds: Toy Ghouls’ new toys

2

ASCII smuggling crosses over from AI prompt injection to phishing evasion

In this article What is ASCII smuggling?Writing a practical ASCII-smuggling signatureWhat we observed: ASCII smuggling repurposed for phishingWhat is known and what is newIs there a detection gap?Mitigation and protection guidanceReferencesLearn More Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling. Instead of using these characters to hide instructions from people…

Microsoft finance US

tg: varování tg: rozbor tp: phishing tp: AI

· Microsoft Security Blog · ASCII smuggling crosses over from AI prompt injection to phishing evasion

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

In this article Risk to enterprise environmentsAttack chain overviewMitigation and response recommendationsLearn more Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session. Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI…

Microsoft US

tg: varování tg: rozbor tp: malware tp: phishing

· Microsoft Security Blog · Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

1

TerminalFix looks like ClickFix, but delivers a very different payload

Microsoft has published details about a Windows malware campaign it calls TerminalFix. The social engineering used to infect people is very similar to what we’ve seen in ClickFix campaigns. A website visitor is presented with a fake Cloudflare CAPTCHA which, when clicked, secretly copies a malicious command to their clipboard. Then they receive instructions on what they need to do to “prove they are human,” when in reality they are being instructed to execute the malicious command. After…

Microsoft US

tg: varování tg: rozbor tg: propagace tp: malware tp: phishing

· Malwarebytes Labs · TerminalFix looks like ClickFix, but delivers a very different payload

2

1

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

In this article Attack chain overviewMitigation and protection guidanceLearn more Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns…

Microsoft Cloudflare US

tg: varování tg: rozbor tp: malware tp: phishing

· Microsoft Security Blog · TerminalFix campaign deploys a reverse tunnel through multistage intrusion

1

SPOJENO PŘES CVE Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995)

CISA added CVE-2022-0995 to the Known Exploited Vulnerabilities catalog. Affected product: Linux Kernel. Remediation due date: 2026-09-09.

KEV ✓ EPSS 0.10 CVE-2022-0995 Linux Microsoft veřejná správa školství média US

tg: varování tg: rozbor tp: malware tp: podvod tp: únik dat tp: AI

· CISA KEV · Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995) · Cisco Talos · UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

1

41 deceptive download sites show a real link, then send you somewhere else

We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF. They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links. But the link you see…

Microsoft US

tg: varování tg: rozbor tp: podvod

· Malwarebytes Labs · 41 deceptive download sites show a real link, then send you somewhere else

1

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

In this article The CaptiveCrunch campaignStorm-2945 and Midnight BlizzardCaptiveCrunch tradecraft and toolingHow to protect against CaptiveCrunch activityMicrosoft Defender detections and hunting guidanceIndicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some…

Microsoft veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: identita tp: špionáž

· Microsoft Security Blog · CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

1

Lost in relocation: analysis of a new loader distributing CASTLESTEALER

A previously undocumented Windows loader tracked as OXLOADER is delivering the CASTLESTEALER infostealer via malicious Google Ads, with low detection rates across static engines and sandbox detonations. The loader uses several obfuscation layers (control-flow flattening, opaque predicates, mixed Boolean-Arithmetic), self-modifying decryption stubs, and abuses the Windows .reloc section to stage shellcode. Elastic Security Labs identified OXLOADER in an active campaign targeting one of our…

Microsoft Google US

tg: varování tg: rozbor tp: malware

· Elastic Security · Lost in relocation: analysis of a new loader distributing CASTLESTEALER

1

Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

Tycoon 2FA is currently the most prolific Phishing-as-a-Service (PhaaS) platform among AiTM phishing kits. First observed in August 2023 and attributed to Storm-1747 (per Microsoft Threat Intelligence), the kit provides turnkey adversary-in-the-middle (AiTM) capabilities that bypass multi-factor authentication and steal authenticated session tokens from Microsoft 365 and Google Workspace accounts. At its peak, Tycoon 2FA accounted for roughly 62% of phishing attempts blocked by Microsoft,…

Microsoft Google US

tg: varování tg: rozbor tp: phishing tp: identita

· Elastic Security · Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace