Security Leftovers
-
LinuxSecurity ☛ Hackers Use SYSTEMBC Tool To Maintain Access To Compromised Network
Security researchers have identified a malicious tool called "SYSTEMBC" that hackers have been actively exploiting. This tool acts as a SOCKS5 proxy , providing threat actors with persistent access or a backdoor to compromised networks. The tool has been observed being used in various campaigns alongside different malware families .
-
SANS ☛ Facebook AdsManager Targeted by a Python Infostealer, (Thu, Jan 25th)
Classic collected data are: [...]
If some cookies are fascinating (ex: access to webmail, corporate services, …), what could be a practical example of abuse? Yesterday, I found another malicious Python script that behaves like an infostealer. It collects data from the following browsers:
Opera
Brave
Mozilla (Firefox)
Chrome
Edge
Coc Coc[1]
“Coc Coc” is a browser popular in Vietnam.
-
Security Week ☛ Orca Flags Dangerous Surveillance Giant Google Kubernetes Engine Misconfiguration
Attackers could take over a Kubernetes cluster if access privileges are granted to all authenticated users in Surveillance Giant Google Kubernetes Engine.