This Sparrow doesn't migrate. [Research Saturday]

This Sparrow doesn't migrate. [Research Saturday]

Martin Zugec, Technical Solutions Director at Bitdefender, discussing their work on "FamousSparrow APT Targets Azerbaijani Oil and Gas Industry." Bitdefender researchers uncovered a sustained cyber espionage campaign by the China-linked FamousSparrow group targeting an Azerbaijani oil and gas company, highlighting the growing focus on critical energy infrastructure in the South Caucasus. The attackers repeatedly exploited the same vulnerable Microsoft Exchange server over multiple months, deploying evolving versions of Deed RAT and Terndoor malware through sophisticated DLL sideloading techniques designed to evade detection and maintain persistence. The operation underscores FamousSparrow's adaptability and persistence, demonstrating how advanced threat actors continually refine their tooling and return to compromised environments until vulnerabilities are fully remediated and access is cut off. The research and executive brief can be found here: FamousSparrow APT Targets Azerbaijani Oil and Gas Industry

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(3734)

Building a secure space internet. [T-Minus: Space-Cyber Briefing]

Building a secure space internet. [T-Minus: Space-Cyber Briefing]

As space infrastructure has continued to expand, developing secure space systems has become just as important as launching the spacecraft themselves. In this week's episode, host Maria Varmazis sits ...

23 Aug 24min

A RAT in the spreadsheet. [Research Saturday]

A RAT in the spreadsheet. [Research Saturday]

Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers hav...

22 Aug 29min

The guest nobody invited.

The guest nobody invited.

CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agen...

21 Aug 31min

The robots have gone bananas.

The robots have gone bananas.

Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat ...

20 Aug 31min

Hackers hiding in plain sight.

Hackers hiding in plain sight.

Medusa’s reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft ...

19 Aug 28min

Fake it till you exfiltrate it.

Fake it till you exfiltrate it.

A fake consultancy fronts an alleged Chinese spy campaign. Meta heads to court over claims it hooked young users. Researchers crack the mystery behind the French EncroChat hack. CISA warns ransomware ...

18 Aug 28min

Please hold while we decide.

Please hold while we decide.

Internal policy conflicts hamper U.S. military AI leadership. Clop claims GE, Philips and Shell. Attackers actively probe internet-facing GeoServer instances. “The Hatman” offers millions of alleged e...

17 Aug 28min

Frontier models and the future of cyber defense. [Special Edition]

Frontier models and the future of cyber defense. [Special Edition]

In this special edition from Black Hat, Dave Bittner sits down with ⁠Clint Gibler⁠, Cyber Lead at ⁠OpenAI⁠, and ⁠Robby Winchester⁠, Chief Global Professional Services Officer at ⁠SpecterOps⁠, to explo...

16 Aug 28min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
forklart
aftenpodden-usa
popradet
stopp-verden
dine-penger-pengeradet
nokon-ma-ga
rss-gukild-johaug
det-store-bildet
rss-espen-lee-usensurert
hanna-de-heldige
lydartikler-fra-aftenposten
rss-ness
rss-penger-polser-og-politikk
aftenbla-bla
e24-podden
frokostshowet-pa-p5
rss-borsmorgen-okonominyhetene
grasoner-den-nye-kalde-krigen