Tag: Threat Hunting Content

CVE-2024-47575 Detection: FortiManager API Vulnerability Exploited in Zero-Day Attacks 4 min read CVEs CVE-2024-47575 Detection: FortiManager API Vulnerability Exploited in Zero-Day Attacks by Veronika Zahorulko UAC-0218 Attack Detection: Adversaries Steal Files Using HOMESTEEL Malware 3 min read CVEs UAC-0218 Attack Detection: Adversaries Steal Files Using HOMESTEEL Malware by Veronika Zahorulko MEDUZASTEALER Detection: Hackers Distribute Malware Masquerading the Sender as Reserve+ Technical Support via Telegram Messaging Service 3 min read CVEs MEDUZASTEALER Detection: Hackers Distribute Malware Masquerading the Sender as Reserve+ Technical Support via Telegram Messaging Service by Veronika Zahorulko UAC-0050 Attack Detection: russia-Backed APT Performs Cyber Espionage, Financial Crimes, and Disinformation Operations Against Ukraine 4 min read CVEs UAC-0050 Attack Detection: russia-Backed APT Performs Cyber Espionage, Financial Crimes, and Disinformation Operations Against Ukraine by Veronika Zahorulko Earth Simnavaz (aka APT34) Attack Detection: Iranian Hackers Leverage Windows Kernel Vulnerability to Target UAE and Gulf Region 3 min read CVEs Earth Simnavaz (aka APT34) Attack Detection: Iranian Hackers Leverage Windows Kernel Vulnerability to Target UAE and Gulf Region by Veronika Zahorulko Shrouded#Sleep Campaign Detection: North Korean Hackers Linked to the APT37 Group Use New VeilShell Malware Targeting Southeast Asia 4 min read CVEs Shrouded#Sleep Campaign Detection: North Korean Hackers Linked to the APT37 Group Use New VeilShell Malware Targeting Southeast Asia by Veronika Zahorulko SOC Prime Threat Bounty Digest — September 2024 Results 3 min read SOC Prime Platform SOC Prime Threat Bounty Digest — September 2024 Results by Alla Yurchenko Earth Baxia Attack Detection: China-Backed Hackers Use Spear-Phishing, Exploit the GeoServer Vulnerability (CVE-2024-36401), and Apply a New EAGLEDOOR Malware to Target APAC 4 min read CVEs Earth Baxia Attack Detection: China-Backed Hackers Use Spear-Phishing, Exploit the GeoServer Vulnerability (CVE-2024-36401), and Apply a New EAGLEDOOR Malware to Target APAC by Veronika Zahorulko CVE-2024-6670 and CVE-2024-6671 Detection: RCE Attacks Exploiting Critical SQL Injection Vulnerabilities in WhatsUp Gold  3 min read CVEs CVE-2024-6670 and CVE-2024-6671 Detection: RCE Attacks Exploiting Critical SQL Injection Vulnerabilities in WhatsUp Gold  by Veronika Zahorulko Celebrating Detection Engineering Excellence 4 min read SOC Prime Platform Celebrating Detection Engineering Excellence by Alla Yurchenko