Content has been added to your Folio

Research, News, and Perspectives

Add Filters
Filter by:
Earth Lusca Uses KTLVdoor Backdoor for Multiplatform Intrusion
Malware

Earth Lusca Uses KTLVdoor Backdoor for Multiplatform Intrusion

While monitoring Earth Lusca, we discovered the threat group’s use of KTLVdoor, a highly obfuscated multiplatform backdoor, as part of a large-scale attack campaign.

September 04, 2024
Artificial Intelligence (AI)

Identifying Rogue AI

This is the third blog in an ongoing series on Rogue AI. Keep following for more technical guidance, case studies, and insights.

Expert Perspective Sep 19, 2024

Save to Folio

Expert Perspective Sep 19, 2024

Save to Folio

APT & Targeted Attacks

Earth Baxia Uses Spear-Phishing and GeoServer Exploit to Target APAC

We observed Earth Baxia carrying out targeted attacks against APAC countries that involved advanced techniques like spear-phishing and customized malware, with data suggesting that the group operates from China.

Sep 19, 2024

Save to Folio

Sep 19, 2024

Save to Folio

Exploits & Vulnerabilities

Vulnerabilities in Cellular Packet Cores Part IV: Authentication

Our research reveals two significant vulnerabilities in Microsoft Azure Private 5G Core (AP5GC), both of which have now been resolved and are discussed in this blog post.

Research Sep 18, 2024

Save to Folio

Research Sep 18, 2024

Save to Folio

Exploits & Vulnerabilities

Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities

In this blog entry, we provide an analysis of the recent remote code execution attacks related to Progress Software’s WhatsUp Gold that possibly abused the vulnerabilities CVE-2024-6670 and CVE-2024-6671.

Research Sep 12, 2024

Save to Folio

Research Sep 12, 2024

Save to Folio

Malware

Earth Preta Evolves its Attacks with New Malware and Strategies

In this blog entry, we discuss our analysis of Earth Preta’s enhancements in their attacks by introducing new tools, malware variants and strategies to their worm-based attacks and their time-sensitive spear-phishing campaign.

Research Sep 09, 2024

Save to Folio

Research Sep 09, 2024

Save to Folio

APT & Targeted Attacks

TIDRONE Targets Military and Satellite Industries in Taiwan

Our research reveals that an unidentified threat cluster we named TIDRONE have shown significant interest in military-related industry chains, particularly in the manufacturers of drones.

Research Sep 06, 2024

Save to Folio

Research Sep 06, 2024

Save to Folio

Artificial Intelligence (AI)

How AI Goes Rogue

This is the second blog in an ongoing series on Rogue AI. Keep following for more technical guidance, case studies, and insights.

Expert Perspective Sep 03, 2024

Save to Folio

Expert Perspective Sep 03, 2024

Save to Folio