Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.

TerminalFix turns a fake CAPTCHA into a stealthy network tunnel

TerminalFix turns a fake CAPTCHA into a stealthy network tunnel
A new TerminalFix campaign is using counterfeit Cloudflare CAPTCHA pages to trick Windows users into pasting PowerShell commands that ultimately turn infected PCs into network pivot points. Instead of stopping at information theft, the multistage intrusion establishes persistence, maps Active Directory, and deploys an encrypted reverse tunnel capable of reaching internal systems.

Source

Entra ID CAE covers far fewer Microsoft 365 sign-ins than expected

Entra ID CAE covers far fewer Microsoft 365 sign-ins than expected
Microsoft’s Continuous Access Evaluation (CAE) can revoke access before a normal one-hour token expires, but its protection is far from universal across Microsoft 365. An analysis of 740 first-party resource tokens found that only 33 included the CAE claim, while some Microsoft clients still request ordinary tokens even when connecting to CAE-capable services.

Source

Fake software installers use msiexec to bypass defenses and persist on Windows

Fake software installers use msiexec to bypass defenses and persist on Windows
Microsoft is tracking an active fake software campaign that regenerates malicious archives behind familiar download filenames, then uses Windows components such as `msiexec.exe` to execute payloads from randomized public directories. The Silver Fox-linked activity has compromised organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education, particularly those with China-based operations or Chinese-speaking users.

Source

❌