APT Security News
Advanced Persistent Threat (APT) groups: nation-state and highly resourced actors, their campaigns and attributed activity.
APT (Advanced Persistent Threat) groups are well-resourced, typically state-linked actors running long, targeted intrusion campaigns rather than opportunistic attacks. Newly attributed activity, campaign reports, and the tools and infrastructure researchers tie back to named groups all land here. Volume is lower than the commodity-crime feeds, but the targets are government bodies, critical infrastructure and high-value corporate networks.
Recent APT items
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection https://ift.tt/vPio6Nz
It turns out this goop someone sent me in a DM was state-sponsored malware designed to perform espionage on select groups on individuals in South America This malware campaign was attributed to APT-C-…
get dm > "smelly, is this goop?" (malware) > "i found it on x" > links GitHub > download > look inside > .net goop > didnt strip metadata > internally refers to itself as FunkyStar > internally does "…
Other topics
CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.