Výsledky hledání

výrobce: Cloudflare× v celém archivu zrušit filtry

15 karet z 15 položek CZ · EN/orig

1

1

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery…

Google Cloudflare NetSupport veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Cisco Talos · ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

1

1

1

Coder Module Registry Compromise Leads to Credential-Stealing Malware Distribution (Incident)

The attacker gained unauthorized access to Coder’s Cloudflare infrastructure and added attacker-controlled IP addresses to the pool serving Coder’s module registry. These servers hosted modified registry artifacts containing malicious code designed to discover credentials and ...

Coder Cloudflare US

tg: incident tg: rozbor tp: malware tp: dodavatelský řetězec tp: identita

· Wiz Research · Coder Module Registry Compromise Leads to Credential-Stealing Malware Distribution (Incident)

1

1

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

In this article Attack chain overviewMitigation and protection guidanceLearn more Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns…

Microsoft Cloudflare US

tg: varování tg: rozbor tp: malware tp: phishing

· Microsoft Security Blog · TerminalFix campaign deploys a reverse tunnel through multistage intrusion

1

1

10th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained the intrusion, but degraded systems caused delays while affected services were restored. Ryde, an electric scooter operator in…

EPSS 0.31 CVSS 10.0 CVE-2026-12537 CVE-2026-54316 CVE-2026-64638 Cloudflare Google Anthropic Cisco finance obchod obrana IL

· Check Point Research · 10th August – Threat Intelligence Report

2

Living off the coding agent: Two tales of tunnels and LaunchAgents

Coding agents such as Claude Code and Cursor are vendor-signed, used all day on developer laptops, and routinely open shells, call APIs, edit files, and install helpers. That makes GenAI-adjacent alerts challenging to investigate. The parent looks trusted, while the children can still look a lot like classic high-severity activity. This article walks through one of those windows. On a macOS endpoint, Elastic Security endpoint telemetry showed shells under Claude Code that scripted a login to an…

Cursor Apple Cloudflare US

tg: rozbor tp: AI tp: identita

· Elastic Security · Living off the coding agent: Two tales of tunnels and LaunchAgents

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

By Yarden Porat, Check Point Research Key Points Check Point Research analyzed Cloudflare Code Mode, a technique that changes how AI agents use MCP by turning tools into a TypeScript API the model can write code against. The research uncovered five vulnerabilities in workerd, the open-source runtime behind Code Mode and Cloudflare Workers. Two were rated Critical by Cloudflare. The blast radius is broad: by Cloudflare’s own numbers, Workers is built by millions of developers,[1] serves millions…

Cloudflare IL

· Check Point Research · When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

1

How legitimate cloud platforms enable phishers to bypass MFA

Threat actors are increasingly exploiting legitimate cloud services to evade detection and streamline the deployment of their scam infrastructure. Cloud hosting services and decentralized networks have become primary platforms for hosting phishing pages and sites. Throughout 2025 and 2026, we have observed phishing operators steadily migrate toward platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS. This post analyzes the mechanics of a real-life adversary-in-the-middle …

Cloudflare Vercel Netlify GitHub RU

· Securelist (Kaspersky) · How legitimate cloud platforms enable phishers to bypass MFA

1

VerdantBamboo: Just Another BRICKSTORM in the Firewall

In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The virtual machine was an Egnyte Storage Sync system, which is designed to facilitate syncing local on-premise files with the cloud. Volexity discovered that instead of connecting to a domain affiliated with Egnyte, the appliance was connecting to a threat-actor-controlled domain behind Cloudflare IP…

Egnyte Microsoft Synology Cloudflare US

· Volexity · VerdantBamboo: Just Another BRICKSTORM in the Firewall

1

1

Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response

Introduction Self-hosted services exposed through a reverse proxy inevitably attract automated scanners probing for misconfigurations, admin panels, and vulnerable endpoints. In this article, I show how to turn routine Traefik access logs into an active defensive control using Elastic Security and Cloudflare. I use an out-of-the-box ES|QL detection rule to identify web server discovery and fuzzing behavior. When suspicious probing patterns are detected, an automated workflow immediately blocks…

Elastic Cloudflare Traefik Labs US

tg: návod tg: propagace

· Elastic Security · Detecting Web Server Probing & Fuzzing in Traefik with Automated Cloudflare Response