APT40
China-Backed Threat Group Rapidly Exploits New Flaws: Agencies
APT40, a threat group backed by China's government, quickly adapts POC exploits of popular software like Microsoft Exchange and Log4j to attack corporate and government networks in the U.S., Australia, and elsewhere, ...
Security Boulevard
Nations come together to condemn China: APT31 and APT40
Gary Warner | | APT31, APT40, china, Hafnium, Kryptonite Panda, Leviathan, Ministry of State Security, MSS Hackers
On Monday (19JUL2021) President Biden announced that the US and its allies were joining together to condemn and expose that China was behind a set of unprecedented attacks exploiting vulnerabilities in Microsoft ...
Introducing RDP Inferences
Anthony Kasza | | Alert AA21-131A, Announcements, APT39, APT40, Corelight Labs, Crowbar, DarkSide ransomware, Duo, Emotet, encrypted traffic, encrypted traffic collection, JA3, Matrix ransomware, network detection response, Network Security, network security monitoring, network traffic analysis, network visibility, Palo Alto Networks, RDP, RDPBCGR, Richard Bejtlich, rsa, RSAConference, Vern Paxson, Zeek, Zscaler
By Anthony Kasza, Technical Director, Corelight Corelight recently released a new package, focused on RDP inferences, as part of our Encrypted Traffic Collection. This package runs on Corelight Sensors and provides network ...
Analyzing Encrypted RDP Connections
Anthony Kasza | | APT39, APT40, Corelight Labs, encryption, Microsoft, MITRE ATT&CK, MS-RDPBCGR, MS-RDPEUDP, MS-RDPEUDP2, open source, powershell, RDP, SharpRDP, SSH, TCP, TLS, Windows, Zeek
By Anthony Kasza, Corelight Security Researcher Microsoft’s Remote Desktop Protocol (RDP) is used to remotely administer systems within Windows environments. RDP is everywhere Windows is and is useful for conducting remote work ...
Cyber Security Roundup for February 2020
SecurityExpert | | adobe, APT40, brexit, cisco, Coalfire, cyber security roundup, cybercrime, Cybersecurity, Intel, LOC, Memty, Microsoft, nsa, patching, Ransomware, Regenix, Ryuk, Sodinokibi, sonos, Travelex
A roundup of UK focused cyber and information security news stories, blog posts, reports and threat intelligence from the previous calendar month, January 2020.After years of dither and delay the UK government ...