Agregátor RSS
EasyAppointments 1.5.1 - Blind SQL Injection
Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global operations and resulted in stolen patient data, respectively. Medical-device maker Boston Scientific, whose IT systems were hacked by unknown intruders last week, said the cyberattack remains ongoing. It also noted that pacemakers and other heart devices implanted after the August 25 breach cannot provide remote monitoring and data transmission as intended. “New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated,” the medtech firm said in a late Friday update. This applies to all new cardiac rhythm management implants other than insertable cardiac monitors (ICM). ICM devices must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patients’ heart rhythms, the company added. Because of the cyberattack, “new ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app,” according to the update. The devices will still record any episodes, and patients can transmit these to the remote monitoring system by in-person transmission via the Clinic Assistant app. This is done by selecting the “interrogate” button, according to the company. Once its IT systems are back up and running, and the heart devices can pair with home monitoring equipment, they will again transmit recorded data to the remote systems. However, the company does not have a timeline for full restoration. “We are currently working on restoring affected functions and systems access,” Boston Scientific said on Saturday. The digital intrusion also affected the firm’s manufacturing, shipping, and ordering, it noted. “We are expeditiously working towards partial restoration for the shipping of some products this week,” according to a Sunday update. “Once we can demonstrate the restoration is fully operable, we anticipate ordering and shipping will ramp up to full capacity.” Boston Scientific has hired CrowdStrike to assist with the investigation and restoration efforts, and said the attack did not affect its cloud-based systems and apps - just “certain on-premise systems” - and added that it has seen no indication of unauthorized IT activity since August 25. The firm has repeatedly declined to answer The Register’s questions about the compromise, including whether it was a ransomware infection and which criminal crew is responsible. McKesson confirms breach as ShinyHunters claims responsibility Meanwhile, in another cybersecurity incident that has been very publicly claimed by the criminal perpetrator: pharmaceutical and medical supply giant McKesson over the weekend confirmed an intrusion after ShinyHunters on Friday told The Register it broke into the company’s Snowflake and Salesforce instances and stole millions of patients’ data. “Based on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we’ve confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units,” Francisco Fraga, McKesson executive VP, chief information officer and chief technology officer, said in a Saturday statement. The medical firm did not immediately respond to The Register’s questions, including how many patients were affected and what “certain data” was stolen. McKesson supports about 3,300 oncology providers in 29 states, according to its website. Fraga’s statement noted that distribution centers remain operational and McKesson continues to ship products. The firm has “reasonable assurance” that the digital intruders have been kicked out of the third-party environments and aren’t lurking around McKesson’s systems, he added. A ShinyHunters spokesperson told us that the notorious extortion group compromised more than 284 million records of patient data, and demanded McKesson pay $55.2 million or else they would leak the stolen data. However, as Have I Been Pwned boss Troy Hunt recently reminded everyone: Don’t confuse criminals’ claims with gospel truth, and “take headline numbers with a grain of salt unless you're confident in the processes of those making the claims." This was after Hunt’s HIBP service reported 12.9 million individuals affected by retailer Carhartt’s alleged breach. This number was around half of what ShinyHunters claimed when they leaked the company’s data earlier this month. The McKesson records, according to the ShinyHunters spokesperson, include patients’ full names, home and email addresses, phone numbers, dates of birth, Social Security numbers, appointment dates and notes, and sensitive illness details including cancer locations on people’s bodies. The group also claims to have swiped emails containing private information from doctors to patients. The spokesperson told us they accessed the company’s Snowflake and Salesforce instances by voice phishing “multiple employees.” This is a tried-and-true method popularized by the data-theft-and-extortion gang, which has victimized other medical providers in recent months. These include pacemaker manufacturer Medtronic in April, and cancer diagnostics business Exact Sciences in July. ®
Jak si s ohledem na školní prázdniny rozplánovat zbytek letošní dovolené, na kdy připadnou prázdniny v příštím roce a o jaké úlevy můžou rodiče školáků žádat v zaměstnání? Projděte si náš přehled.
Pozůstalá tvrdila, že část manželovy mzdy byla skrytá v cestovních náhradách a žádala proto vyšší rentu. Nejvyšší soud určil, kdo to musí prokázat.
Média slibují, že AI lékaře nahradí nebo vyřeší čekárny. V praxi ale jde hlavně o rozšířenou inteligenci: digitálního asistenta pro analýzu a dokumentaci, který stojí po lékařově boku.
Popíšeme si, jak je v programovacím jazyku Go implementována podpora pro SIMD (vektorové) operace. Do Go 1.26 totiž byly přidány experimentální balíčky s podporou SIMD.
Lidé stále častěji komunikuji s umělými inteligencemi v zákaznických službách. Sociální boti jsou stále chytřejší, empatičtější a stále více připomínají člověka, aby získali zákazníky. Podle nového výzkumu to může vést k zrcadlení jejich chování lidmi, kteří se pak stávají robolidskými.
Po odkladu GeForce RTX 5000 Super na neurčito se objevují obavy, zda podobný osud nečeká i GeForce RTX 6000. Ta samozřejmě vyjde, otázkou je kdy a v jaké podobě…
Delivered by injection, the drug transforms astrocytes into neurons. In an early study, mice modeling Alzheimer’s showed marked improvement compared to untreated peers.
The Alzheimer’s brain faces a double whammy. Toxic protein clumps build up inside and outside neurons to torpedo normal function and destroy delicate structures. Eventually, the cells die. The adult brain has an extremely limited ability to grow new neurons. Once gone, they’re rarely replaced. Over time, the brain withers, taking learning, memory, and cognition with it.
But there might be a sneaky workaround. The brain is packed with star-shaped cells called astrocytes that keep neurons healthy. They’re also shape-shifters. Under certain conditions, astrocytes can shed their identity and transform directly into mature neurons. In other words, they could be an abundant, untapped source of replacement neurons.
A team at the University of South Carolina has now taken advantage of this quirk. They engineered a tiny molecular cage and filled it with antibodies. Once inside astrocytes, the antibodies released a protein “brake” that normally keeps the cells’ identity stable. Free from this constraint, astrocytes in lab dishes and human brain organoids adopted the molecular signatures of neurons and eventually sparked with electrical activity.
In mice modeling Alzheimer’s disease, the treatment increased the number of neurons in the hippocampus, a brain region crucial for learning and memory and one of the first to falter in the disease. Treated mice resumed normal behavior and performed similarly to healthy mice on tests of learning and memory in a maze.
The approach fundamentally differs from existing methods and could “unlock previously inaccessible regenerative mechanisms,” wrote the team. If it proves safe and effective in clinical trials—and that’s a big if—the approach could one day tackle diseases beyond Alzheimer’s, such as Parkinson’s or amyotrophic lateral sclerosis (ALS).
Born Identity
The quest to treat Alzheimer’s has often been called the “graveyard of dreams.” The most common form of dementia, the disease affects roughly 24 million people worldwide and slowly eats away at thinking, memory, learning, and emotional regulation. Experts still debate Alzheimer’s root cause, but they largely agree that clumps of misshapen proteins called amyloid beta and tau exacerbate the disease.
Current FDA-approved treatments have had limited success. Antibodies that clear clumps offer only modest benefits to cognition and carry the risk of serious side effects. Other drugs, such as memantine, alter brain chemicals to protect damaged cells, rev up faltering brain circuits, and ease symptoms. But they don’t halt degeneration. As the disease progresses, benefits fade.
The central problem is frustratingly clear. Neurons die faster in Alzheimer’s than the brain can replace them. That’s why a landmark study nearly two decades ago made waves. Scientists once thought mature astrocytes were set in their fate. But the study showed the cells could be reprogrammed into neurons that generated electrical activity and formed connections with neighboring neurons in lab dishes to form working circuits.
Scientists later found a protein called PTBP1 that prevented this conversion. In 2020, a team injected an RNA-targeting form of CRISPR into the brains of mice modeling Parkinson’s disease. This reduced PTBP1 levels, which in turn, triggered the production of new neurons. The treatment restored the mice’s balance and motor skills, although some experts were skeptical.
While promising, CRISPR-based approaches can have unintended effects, and brain surgery is a tall order for any treatment. So, the team developed another way to release the PTBP1 brake.
Erase, Rewind
They turned to a duo of technologies that transport antibodies inside nanoparticle cages to degrade specific proteins inside cells. In this case, they used antibodies targeting PTBP1 and packaged the concoction in a biocompatible gel injected into the bloodstream.
Because of their large size, antibodies can’t usually cross the blood-brain barrier, a tightly sealed wall that keeps many molecules out of the brain. But the nanoparticle system helped ferry the antibodies across the blockade, nixing the need for brain surgery.
The team first tested the drug, called TN-PTBP1, on astrocytes grown in lab dishes. Within days, the cells lost their star shapes and began growing long, willowy branches characteristic of neurons. Their molecular profile also shifted, and the cells eventually burst with electrical signals.
The team recorded similar results in brain organoids, or “mini brains,” grown from human stem cells. Given a small electrical zap, the converted neurons responded in synchrony with neighboring neurons, suggesting they had integrated into existing neural circuits.
“The new neurons can become mature and survive,” said study author Peisheng Xu in a press release.
Next, they tested the drug in a mouse model of Alzheimer’s disease. By eight months, the mice showed clear signs of the disease. Their brains were highly inflamed and littered with toxic protein clumps. Neurons in the hippocampus had also substantially died off, similar to the loss seen in moderate to severe Alzheimer’s in humans.
The mice struggled with everyday behaviors, such as foraging for material to build nests. And they consistently performed poorly on a classic memory test where they had to find a location using visual cues (a bit like remembering where you parked your car).
Half the mice received TN-PTBP1 for two weeks; the others received saline. As expected, the drug reliably slashed PTBP1 levels in the brain. Over the course of the trial, treated mice increasingly improved on tests of cognition and memory, eventually performing at levels similar to healthy peers. Mice treated with saline showed no improvement.
“After just two injections, these mice became smarter,” said Xu. “Even after one injection, we already saw these mice’s behavior differ from that of the nontreated ones.”
The team found broader benefits too. The drug reduced inflammation and, surprisingly, the number of toxic protein clumps, suggesting it may have helped restore some of the brain’s ability to rid itself of waste. Neuron density also increased throughout the brain, and the treatment boosted production of proteins involved in maintaining the blood-brain barrier, which is often damaged in Alzheimer’s.
One unexpected, and welcome, effect was neurogenesis, the birth of new neurons in the hippocampus and another brain region. Neurogenesis declines with age, and whether it exists at all in adult humans is hotly debated. How TN-PTBP1 triggered it in mice remains a mystery. It’s also unknown how much the new neurons contributed to the animals’ recovery versus the direct conversion of astrocytes into neurons.
Still, it’s clear the drug boosted neuron numbers and “successfully reversed Alzheimer’s disease progression” in the mice, wrote the team.
The approach has a long road ahead. Many promising treatments in mice have failed in clinical trials. In the next few years, the team hopes to test the approach in monkeys, dial in the dose, and assess long-term safety. Astrocytes perform many tasks that keep the brain humming, and forcing them to abandon their identity could have unexpected consequences. There’s also the possibility newly converted neurons could scramble existing brain circuits rather than integrating safely, causing more harm than good.
But with rigorous testing, the drug could offer new hope.
The post This Drug Makes New Neurons in the Brain. Scientists Say It Reversed Alzheimer’s Symptoms in Mice. appeared first on SingularityHub.
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]
An eBPF security system can produce precise Linux telemetry while leaving a harder question unanswered: what happens if the eBPF layer itself is misconfigured, vulnerable, or trusted too broadly?
Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix.
Consultants say that this advisory raises a major concern in that it will train users to ignore critical alerts, which makes them far more susceptible to attacks.
The Microsoft release health dashboard update on the issue reported: “After installing the latest updates for Microsoft Defender Antivirus, notifications might appear stating that ‘Microsoft Defender Antivirus is turned off’ even though the antivirus is functioning correctly and all settings show it as active. These notifications can appear when Windows starts and intermittently afterward. They persist even if notification settings are turned off. This issue can be observed in any version of Windows or Windows Server with Microsoft Defender Antivirus running with the latest Defender updates.”
The post added: “We are working to release a resolution in a future Microsoft Defender Antivirus update and will provide more information when it is available.”
It then listed the various Windows client and server versions impacted: everything from the current Windows 11, version 26H1 and Windows Server 2025 back to Windows 10 Enterprise LTSC 2016 and Windows Server 2012.
Bad guidance
Industry observers said the suggestion that users ignore these alerts is concerning.
“Microsoft has just published guidance telling enterprises to ignore the exact signal that precedes a large share of ransomware detonations,” said Aman Mahapatra, chief strategy officer for technology consulting firm Tribeca Softtech, pointing out that disabling endpoint protection is standard tradecraft across virtually every ransomware affiliate playbook over the last five years.
“The alert Microsoft is telling people to disregard is the same alert an operator triggers minutes before encryption starts,” he said. “That is a genuine security regression created by a bug advisory and the open-ended timeline on a fix makes it worse.”
More disturbingly, he expects many security operations centers (SOCs) will create rules to suppress these alerts, which will make the problem even more severe.
“When a signal fires constantly and is known to be false, human response degrades in days, not weeks,” Mahapatra said. “A SOC seeing hundreds of these across a Windows fleet will write a suppression rule by next week, because the alternative is drowning [in false alerts], and that rule will outlive the bug by months. Nobody goes back to remove filters that are keeping the queue clean.”
Mahapatra also predicted that attackers will quickly leverage the bug to help in social engineering attacks.
“An attacker calling a help desk with ‘You’ll see Defender alerts on my machine, Microsoft says it’s the known bug, ignore it’ now has a corroborating vendor advisory backing the pretext,” Mahapatra said. “Help desks have been primed for exactly this issue. That is a working pretext with public documentation behind it, and it will get used.”
Lane Thames, team lead for cybersecurity R&D at Fortra, amplified Mahapatra’s concerns.
“IT teams need to be very careful about how they communicate this problem to users, and that communication should happen immediately,” Thames advised. “The message cannot simply be, ‘If Windows says Defender is turned off, ignore it.’ That is exactly the behavior we spend years teaching users not to adopt.”
“The better message is that Microsoft is currently experiencing a known notification issue with Microsoft Defender, but users should continue reporting security warnings through the normal help desk or security channel,” he said. “IT should verify Defender’s actual state rather than asking users to make that determination, otherwise, when the next warning is real, users may have already been trained to ignore it.”
This Microsoft alert “creates a perfect opportunity for a real attack to hide in the noise,” he added.
Degradation of trust
But Thames stressed that there is a bigger potential issue: degradation of trust.
“Security notifications only work when users believe them. If Windows repeatedly tells someone that their antivirus is disabled when IT tells them that it isn’t, eventually one of those sources loses credibility, if not both,” he said. “Microsoft needs to resolve this quickly, because false security warnings have a large consequence: they degrade the trust that security controls depend on.”
Tom Kellermann, VP of AI security and threat research at TrendAI, a division of TrendMicro, added that in the attacks his team has analyzed, roughly 67% leverage tampering with and disabling security software, something that is is usually a precursor to “a more systemic and intrusive campaign.”
The Microsoft advisory’s wording “is a poor example of crisis communications” and is “ridiculous,” he said. “Do not trust that advice [to ignore the alert]. Verify if it’s accurate and involve your threat hunting teams,” who can examine XDR telemetry.
Preserve the evidence
Noah Kenney, principal consultant at Digital 520, advised CISOs and CIOs to save evidence of this situation to prove insurance claims that will likely initially be denied.
“Six months from now, an insurer looking at a breached server won’t accept ‘Microsoft said there was a bug’ as proof that Defender was running. The popup says off. Microsoft says on. The company’s own telemetry has to break the tie,” he said. “That means time-stamped records of sensor check-ins, Defender versions, and any gaps in reporting. CISOs should save those records now. The patch will make the warning disappear, but it will not recreate evidence if the company failed to retain it.”
He noted that his greatest concern about the Microsoft alert is its wide impact on many Windows versions.
“Windows 11 26H1 and Windows Server 2012 are fourteen years apart, and Microsoft says this bug can hit both,” he said. “Companies separate desktops, servers, legacy systems, and critical infrastructure into different patch rings, but Defender runs through all of them. The popup will get patched, but that shared failure path through the Windows estate will still be there, and a bad update can produce the same wrong security signal everywhere at once.”
Linux interrupt maintainer Thomas Gleixner traced a Kernel Address Sanitizer report to incomplete regmap IRQ cleanup on Aug 30, 2026. The crash appeared while Linux was taking a CPU offline, but the stale pointer was created earlier when a device’s interrupt setup failed.
Jonghyuk Kim submitted a Linux Direct Rendering Manager scheduler patch series on Aug 28, 2026 that targets a use-after-free read shared by several GPU drivers. The proposed change caches a fence’s timeline name while its scheduler is still alive.
OpenClaw has unveiled what its makers call its largest ever update – large enough to earn a 2.0 moniker – with usability taking center stage, along with some security updates that critics are suggesting will be insufficient. The OpenClaw foundation announced the release of version 2.0 of its AI agent harness on Sunday, describing it as something with far more scope than they ever intended it to have. “This update touches every part of OpenClaw,” Foundation community manager Hannes Rudolph said of the update. “We started by simplifying installation and rebuilding the browser app as a first-class experience, but doing that properly meant carrying the cleanup through the rest of OpenClaw until it became OpenClaw 2.0.” It's those two features – the rebuilt installation experience and redesigned interface – that Rudolph dedicates most of his announcement to. OpenClaw is an open-source, self-hosted AI agent harness that allows users to build their own AI agents and connect them to whatever apps and services they want. OpenClaw went viral shortly after its launch due to its extensive capabilities, and helped launch the AI agent craze. But, by empowering AI models with agentic capabilities, it exposed numerous security problems with unrestrained automation. In version 2.0, the new installation process is designed to be simpler, ostensibly to get more people using OpenClaw. “We cut or simplified a lot of configuration and moved the rest out of initial setup, letting people get to a first conversation faster and finish setting up their Claw by talking to it,” Rudolph explained. As for the user experience, Rudolph explained that the OpenClaw browser app has been redesigned into “a first-class experience” where users can continue setup and interact with their agent. “The web-based experience in OpenClaw now feels more familiar to anyone who uses apps like ChatGPT, Claude, Gemini, or Perplexity, with conversations in the sidebar and the one you are working in at the centre instead of opening on a separate Overview page,” the patch notes for the release explains. In other words, OpenClaw’s basic interface now looks just like the chat interface for every other AI service you’ve likely used on the web. The last major feature update added in OpenClaw 2.0 is shared cloud sessions. Per the announcement, OpenClaw previously had no way to include multiple team members in a single instance without the Claw involved losing its memory. Shared cloud sessions correct that, enabling multiple people to interact with a single Claw while context is maintained across users and a continuous chat, giving OpenClaw feature parity with the agent harnesses offered by frontier labs like Anthropic and OpenAI, which allow collaboration for enterprise users. What about security? Since launching in November 2025, OpenClaw has deservedly earned its reputation as a complete security mess – not only in the code itself but for users and those who are unfortunate enough to come in contact with a Claw’s orders as well. Celebrity UK mathematician Professor Hannah Fry tested OpenClaw out earlier this year, finding it was ready and willing to share her private information when threatened. In another instance, an OpenClaw agent hacked a gym’s waiting list and forced its user into a full class, displacing other reservations, when simply asked to get him on the list. So, what is OpenClaw doing to improve on these risks as part of the update? Not that much, based on a reading of the patch notes. Shared sessions, for example, are a great way to introduce collaborative Claws at work, but the OpenClaw foundation states in the patch notes that the shared session controls “are not tenant isolation or a security boundary.” In other words, you’d better be sure there’s no need to isolate various OpenClaw instances. A new protected credentials feature has been added that allows users to share credentials with agents in shared environments without exposing them in chat. That’s great, and as explained in the patch notes it’s further secured in a local secret store that “separates Protected values from Agent-readable environment values.” What’s not great, on the other hand, is the fact that “Secret Store values are not encrypted at rest and depend on the filesystem permissions of OpenClaw's state directory.” A new sandbox for contributor-controlled code was also announced, with the patch notes referring to an environment for untrusted code isolation. Again, great – except sandboxing is turned off by default. In other words, this release is doing a lot to make installing and getting OpenClaw up and running for more people, but it’s not bringing security by default along with that accessibility. As we’ve warned before, granting a capable and potentially dangerous tool like this widespread access to your systems and credentials ought not be done lightly, fancy new wrapper or not. ®
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
Herní nábytek nemusí připomínat kokpit plný černého plastu a barevných světel. IKEA a Xbox společně připravily kolekci YXSTABY pro hráče, kteří konzoli nemají v samostatném herním doupěti, ale v běžném obývacím pokoji.
An unknown miscreant is using "TerminalFix" to trick unsuspecting users into running PowerShell commands that infect their computers with a reverse tunnel granting attackers access to their networks. Some of the malware is even hidden inside PNG graphics the PC downloads. TerminalFix is the latest variant of the wildly popular ClickFix initial access method for attackers. This type of social engineering technique tricks users into running malicious commands by promoting them with a phony fix or CAPTCHA verification. While traditional ClickFix attacks point victims to the Windows Run dialog, TerminalFix directs users to Windows Terminal or PowerShell, which increases the likelihood that they will unknowingly run multi-line scripts on their own computers, Redmond says. Plus, instead of delivering just one infostealer, this campaign kicks off a multi-stage attack chain that combines DLL sideloading, steganographic payload extraction, and Active Directory reconnaissance. It ultimately deploys a custom reverse tunnel on the infected machine that gives the attacker persistent, network-level proxy access through the compromised device. Microsoft declined to answer The Register’s questions, including how many organizations were targeted and victimized in this TerminalFix campaign, and which attacker or criminal crew is responsible for these attacks. The attack chain begins when the victim interacts with a phony overlay that spoofs the Cloudflare CAPTCHA “verify you are human” checkbox and includes a Cloudflare logo, causing a fake verification command to be copied to the clipboard before the victim pastes it into Windows Terminal or PowerShell. This command runs a hidden PowerShell script that prints a fake “Starting Cloudflare verification…” message and downloads a ZIP archive from an attacker-controlled server. It extracts the archive under C:\ProgramData and launches a batch file (1.bat) that silently executes LockScreenContentServer.exe. LockScreenContentServer.exe is a legitimate, signed Windows executable - and it acts as the DLL sideloading host for a second file: dui70.dll. This purports to be a “Windows DirectUI Engine,” but is actually the malicious payload, which executes a second-stage PowerShell script once it’s sideloaded. The second PowerShell script downloads additional payloads hidden inside PNG images - this is called steganography, and it makes file- and content-type inspection more difficult, and thus easier to hide malicious payloads. In an attempt to further obfuscate the payload and avoid being detected, the attacker split the payload into multiple PNGs. The PowerShell script downloads the three images, extracts an executable from the first image and two halves of the DLL from the second and third images, and then reassembles the components on disk. “After extraction, the source images are deleted to reduce forensic artifacts,” Microsoft researchers Sagar Patil, Suriyaraj Natarajan, and Parasharan Raghavan wrote. The malware establishes redundant persistence through both HKCU\…\Run registry keys and scheduled tasks that re-execute LockScreenContentServer.exe every 60 minutes to ensure it survives reboots. It then does reconnaissance on the compromised machine, scooping up system information across multiple language configurations including English, Spanish, and German. It also performs domain trust discovery, domain admin enumeration, and Active Directory user and computer searches, while pinging targeted, named servers. “The observed names correspond to common infrastructure roles, including domain controllers, databases, backup, gateways, and mail systems,” according to the threat hunters. “This probing could help an attacker identify accessible target systems for follow-on activity.” Next, the malware drops a persistent PowerShell file-watch loop that monitors a text file for new commands, executes them via Invoke-Expression, and writes results to an output file. This allows the attacker to execute additional PowerShell commands by writing them to the text file. And finally, the attacker deploys a custom, Python-based reverse-tunnel implant. The tunnel launches with no visible window via pythonw.exe, and it sets up a reverse WebSocket tunnel to gitnow[.]dev:443. This implant, combined with earlier reconnaissance data, gives the attacker SOCKS-style TCP proxy access through the victim’s network. Microsoft recommends organizations take several steps to avoid becoming a victim of this campaign. These include restricting PowerShell and Run dialog execution, and either blocking or auditing the Windows Run dialog (Win+R) if it’s not needed for daily work. Also, train employees on how to look for ClickFix tactics, like fake CAPTCHA verification pages that tell them to paste commands into Terminal or the Run dialog. ®
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.
The ongoing insider threat is part of what has been described as the IT worker scheme,
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.
The ongoing insider threat is part of what has been described as the IT worker scheme, Ravie Lakshmananhttp://www.blogger.com/profile/ [email protected]
|