101010.pl is one of the many independent Mastodon servers you can use to participate in the fediverse.
101010.pl czyli najstarszy polski serwer Mastodon. Posiadamy wpisy do 2048 znaków.

Server stats:

582
active users

#endpoint

0 posts0 participants0 posts today

Camera off: Akira deploys ransomware via webcam

Akira, a prominent ransomware group, accounted for 15% of incidents in 2024, showcasing novel evasion techniques. In a recent attack, Akira circumvented an Endpoint Detection and Response (EDR) tool by compromising an unsecured webcam to deploy ransomware. After initial detection, the group pivoted to exploit IoT devices, particularly a vulnerable webcam running Linux. This allowed them to execute their Linux ransomware variant without EDR interference. The incident highlights the importance of comprehensive security measures, including IoT device monitoring, network segmentation, and regular audits. Key takeaways include prioritizing patch management for all devices, adapting to evolving threat actor tactics, and ensuring proper EDR implementation.

Pulse ID: 67d046979aa7a5f6ddc6aa12
Pulse Link: otx.alienvault.com/pulse/67d04
Pulse Author: AlienVault
Created: 2025-03-11 14:20:07

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

I have now finally found the solution and cause to what stops deployment of IKEv2 VPN connections on #windows11 .
It took 6 months of pushing an issue through #Microsoft to finally solve the issue.
The background was that the deployment worked on some of our customers, but not on others. Everything worked if we sent a Powershell-script with same settings.

There WAS an undocumented limitation that all of the Child Security Association Parameters had to be configured. And we had some customer that didn't have PFS configured.
Microsoft has now fixed the documentation.

Current: learn.microsoft.com/en-us/mem/

Previous: web.archive.org/web/2023120605

learn.microsoft.comWindows 10/11 VPN settings in Microsoft IntuneLearn and read about all the available VPN settings in Microsoft Intune, what they're used for, and what they do. See the traffic rules, conditional access, and DNS and proxy settings for Windows 10/11 and Windows Holographic for Business devices.
#intune#msp#vpn

📨 Latest issue of my curated #cybersecurity and #infosec list of resources for week #38/2023 is out! It includes the following and much more:

🔓 ❌ TransUnion Denies #Breach After Hacker Publishes Allegedly Stolen Data
🔓 ⚖️ Hackers breached International Criminal Court’s systems last week
🔓 🤖 #Microsoft #AI researchers accidentally exposed terabytes of internal sensitive data
🦠 💸 #BlackCat #ransomware hits #Azure Storage with #Sphynx encryptor
🇮🇷 🇮🇱 Iranian Nation-State Actor OilRig Targets Israeli Organizations
🇮🇳 #India's biggest tech centers named as #cybercrime hotspots
🇫🇮 💊 Finnish Authorities Dismantle Notorious #PIILOPUOTI Dark Web Drug Marketplace
🇨🇦 🇷🇺 Canadian Government Targeted With #DDoS Attacks by Pro-#Russia Group
🇨🇳 🇺🇸 #China Accuses U.S. of Decade-Long #Cyberespionage Campaign Against #Huawei Servers
🇺🇸 🇨🇳 China's Malicious Cyber Activity Informing War Preparations, #Pentagon Says
🇨🇳 🦠 New #SprySOCKS Linux #malware used in cyber espionage attacks
🇬🇧 🔐 UK Minister Warns #Meta Over End-to-End Encryption
🇺🇸 🇷🇺 One of the #FBI’s most wanted hackers is trolling the U.S. government
🦠 🥸 Fake #WinRAR proof-of-concept exploit drops #VenomRAT malware
🦠 📈 #P2PInfect botnet activity surges 600x with stealthier malware variants
🦠 📡 Hackers backdoor #telecom providers with new HTTPSnoop malware
🦠 🐝 #Bumblebee malware returns in new attacks abusing #WebDAV folders
🔐 #GitHub launches #passkey support into general availability
☑️ 🐧 Free Download Manager releases script to check for #Linux malware
💬 🔐 #Signal adds quantum-resistant encryption to its #E2EE messaging protocol
🍏 🔐 #iOS 17 includes these new security and #privacy features
🩹 High-Severity Flaws Uncovered in #Atlassian Products and ISC BIND Server
🩹 😡 Incomplete disclosures by #Apple and #Google create “huge blindspot” for 0-day hunters
🍏 🩹 Apple emergency updates fix 3 new zero-days exploited in attacks
🩹 #TrendMicro fixes #endpoint protection zero-day used in attacks
🩹 #Fortinet Patches High-Severity #Vulnerabilities in FortiOS, FortiProxy, FortiWeb Products
🔓 Nearly 12,000 #Juniper #Firewalls Found Vulnerable to Recently Disclosed RCE Vulnerability

📚 This week's recommended reading is: "Future Crimes: Everything Is Connected, Everyone Is Vulnerable and What We Can Do About It" by Marc Goodman

Subscribe to the #infosecMASHUP newsletter to have it piping hot in your inbox every week-end ⬇️

infosec-mashup.santolaria.net/

X’s Infosec Newsletter · InfoSec MASHUP - Week 38/2023By Xavier «X» Santolaria

An interesting question for the haxors and slaxors here.

Given remote or physical access to an #endpoint with #authorization, what difference would a short (~30 minute) authorization window make in comparison to 8 hours?

Assume you don't get access to a refresh of the authorization but, come on, you usually do.