« 2024 »

654 reports

2024-01-08 • Certi K

Project name: TerraPort Finance Date of exploit: Apr 10th, 2023 Asset loss: around $4M Vulnerability: Centralization Related Risk Date of audit report publishing: Dec 11th, 2023 Conclusion: Out of Audit Scope Terraport operates as a DeFi platform that use…

#Terraport
2024-01-08 • Whoisxmlapi

WhoisXML API examined a Kimsuky campaign using 13 AhnLab-published IOCs as pivots for DNS expansion. The source says Kimsuky shifted from its usual HWP or Microsoft Word spearphishing attachments toward compressed files and malicious links. The infrastruc…

#Kimsuky
2024-01-05 • 安恒信息

DBAPPSecurity's 2023 advanced threat landscape report says Lazarus was the most active APT group disclosed during the year, accounting for 12.7% of observed reporting, with Kimsuky and APT37 also among the most active East Asian groups at 9.3% and 6.5%. T…

#Trend
2024-01-05 • Phylum

Phylum reports that a crypto-themed npm package campaign first described in November remained active, with nearly two dozen additional packages identified through December 2023. The packages download a remote binary during installation, decrypt and execut…

#SupplyChain #NPM
2024-01-04 • Greg Lesewich

TA444, also known as Sapphire Sleet, BLUENOROFF, or STARDUST CHOLLIMA, is linked in the excerpt to CosmicRust, a Rust-based Mach-O backdoor described as less mature than RustBucket. The sample uses WebSockets for communications, carries an ad-hoc signatur…

#TA444 #YARA #CosmicRust