Tag: Threat Hunting Content

CVE-2024-47575 Detection: FortiManager API Vulnerability Exploited in Zero-Day Attacks 4 min read Latest Threats CVE-2024-47575 Detection: FortiManager API Vulnerability Exploited in Zero-Day Attacks by Veronika Telychko UAC-0218 Attack Detection: Adversaries Steal Files Using HOMESTEEL Malware 3 min read Latest Threats UAC-0218 Attack Detection: Adversaries Steal Files Using HOMESTEEL Malware by Veronika Telychko MEDUZASTEALER Detection: Hackers Distribute Malware Masquerading the Sender as Reserve+ Technical Support via Telegram Messaging Service 3 min read Latest Threats MEDUZASTEALER Detection: Hackers Distribute Malware Masquerading the Sender as Reserve+ Technical Support via Telegram Messaging Service by Veronika Telychko UAC-0050 Attack Detection: russia-Backed APT Performs Cyber Espionage, Financial Crimes, and Disinformation Operations Against Ukraine 4 min read Latest Threats UAC-0050 Attack Detection: russia-Backed APT Performs Cyber Espionage, Financial Crimes, and Disinformation Operations Against Ukraine by Veronika Telychko Earth Simnavaz (aka APT34) Attack Detection: Iranian Hackers Leverage Windows Kernel Vulnerability to Target UAE and Gulf Region 3 min read Latest Threats Earth Simnavaz (aka APT34) Attack Detection: Iranian Hackers Leverage Windows Kernel Vulnerability to Target UAE and Gulf Region by Veronika Telychko Shrouded#Sleep Campaign Detection: North Korean Hackers Linked to the APT37 Group Use New VeilShell Malware Targeting Southeast Asia 4 min read Latest Threats Shrouded#Sleep Campaign Detection: North Korean Hackers Linked to the APT37 Group Use New VeilShell Malware Targeting Southeast Asia by Veronika Telychko SOC Prime Threat Bounty Digest — September 2024 Results 3 min read SOC Prime Platform SOC Prime Threat Bounty Digest — September 2024 Results by Alla Yurchenko Earth Baxia Attack Detection: China-Backed Hackers Use Spear-Phishing, Exploit the GeoServer Vulnerability (CVE-2024-36401), and Apply a New EAGLEDOOR Malware to Target APAC 4 min read Latest Threats Earth Baxia Attack Detection: China-Backed Hackers Use Spear-Phishing, Exploit the GeoServer Vulnerability (CVE-2024-36401), and Apply a New EAGLEDOOR Malware to Target APAC by Veronika Telychko CVE-2024-6670 and CVE-2024-6671 Detection: RCE Attacks Exploiting Critical SQL Injection Vulnerabilities in WhatsUp Gold  3 min read Latest Threats CVE-2024-6670 and CVE-2024-6671 Detection: RCE Attacks Exploiting Critical SQL Injection Vulnerabilities in WhatsUp Gold  by Veronika Telychko Celebrating Detection Engineering Excellence 4 min read SOC Prime Platform Celebrating Detection Engineering Excellence by Alla Yurchenko