3 Dec 2024, 16:29 UTC325 views3 reactionsread 8 August 2026 Novel phishing campaign uses corrupted Word documents to evade security
A novel phishing attack abuses Microsoft's Word file recovery feature by sending corrupted Word documents as email attachments, allowing them to bypass security software due to their damaged state but still be recoverable by the application.
https://www.bleepingcomputer.com/news/security/novel-phishing-campaign-uses-corrupted-word-documents-to-…
👍3
Signed
18 Nov 2024, 15:32 UTC159 views1 reactionsread 8 August 2026 Phishing emails increasingly use SVG attachments to evade detection
Threat actors increasingly use Scalable Vector Graphics (SVG) attachments to display phishing forms or deploy malware while evading detection.
Most images on the web are JPG or PNG files, which are made of grids of tiny squares called pixels. Each pixel has a specific color value, and together, these pixels form the entire image.
SVG, or Scalable …
👍1
Signed
3 Nov 2024, 15:49 UTC138 views1 reactionsread 8 August 2026 https://arstechnica.com/information-technology/2024/11/microsoft-warns-of-8000-strong-botnet-used-in-password-spraying-attacks/
The malicious network, made up almost entirely of TP-Link routers, was first documented in October 2023 by a researcher who named it Botnet-7777. The geographically dispersed collection of more than 16,000 compromised devices at its peak got its name because it exposes its malicious malwa…
👍1
Signed
31 Oct 2024, 09:47 UTC118 views2 reactionsread 8 August 2026 https://sharpsec.run/rce-vulnerability-in-qbittorrent/
👍2
Signed
11 Oct 2024, 07:17 UTC147 views1 reactionsread 8 August 2026 https://securelist.com/miner-campaign-misuses-open-source-siem-agent/114022/
👍1
Signed
9 Oct 2024, 11:06 UTC126 views1 reactionsread 8 August 2026 Photo
https://www.bleepingcomputer.com/news/security/european-govt-air-gapped-systems-breached-using-custom-malware/
🔥1
Signed
13 Sept 2024, 17:22 UTC158 views3 reactionsread 8 August 2026 Forwarded from @proxy_barVideo
LoL )))
reCAPTCHA Phish
😁2👎1
Signed
15 May 2024, 12:50 UTC257 viewsread 8 August 2026 https://isc.sans.edu/diary/30926
Дежурное напоминание о важности MFA на примере реальной ситуации
Signed
2 May 2024, 09:14 UTC235 views3 reactionsread 8 August 2026 https://blogs.infoblox.com/threat-intelligence/a-cunning-operator-muddling-meerkat-and-chinas-great-firewall/
👍2🔥1
Signed
29 Feb 2024, 08:44 UTC211 views2 reactionsread 8 August 2026 https://www.bleepingcomputer.com/news/technology/registrars-can-now-block-all-domains-that-resemble-brand-names/
Платная защита бренда от фишинговых доменов 😁 (результат не гарантирован)
👍1🔥1
Signed
15 Feb 2024, 07:12 UTC175 views2 reactionsread 8 August 2026 https://www.presseportal.de/pm/173495/5713546
👍2
Signed
3 Feb 2024, 10:10 UTC177 views2 reactionsread 8 August 2026 What did I say to make you stop talking to me?
[...] Attackers are interested in attempting to detect honeypots; over the years, we have seen various ways to do so. But so far, we have not done much to prevent this. We randomize some fo the parameters, but overall, we just run a "stock" cowrie install. There is however a relatively easy method to find out what gave the honeypot away after the attacker connected.
Mo…
👍2
Signed
Showing the 12 most recent of 20 posts we hold for @chtivvvo. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.