unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
Containers on fire: from container escapes to supply chain attacks
IntroductionModern infrastructures universally rely on containerization to deploy app...
2026-6-1 10:0:6 | 阅读: 44 |
收藏
|
Securelist - securelist.com
attacker
kubernetes
malicious
containers
privileges
OpenClaw security
OpenClaw, which was previously known as Clawdbot and Moltbot, is today one of the most...
2026-6-1 06:42:48 | 阅读: 11 |
收藏
|
Securelist - securelist.com
malicious
openclaw
skill
security
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
IntroductionContainerization using Docker has become firmly established in modern dev...
2026-5-29 07:0:51 | 阅读: 52 |
收藏
|
Securelist - securelist.com
pkp
privileges
security
attackers
Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years
IntroductionIn late April 2026, a client reached out to us for incident response supp...
2026-5-28 06:55:11 | 阅读: 50 |
收藏
|
Securelist - securelist.com
miner
malicious
privileges
payload
elevated
Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
In 2025, we observed pervasive SSH tunnel activity, which has remained active into 202...
2026-5-22 09:47:0 | 阅读: 36 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
windows
ssh
attackers
powershell
payload
How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
IntroductionExifTool is a widely adopted utility for reading and writing metadata in...
2026-5-20 09:2:31 | 阅读: 35 |
收藏
|
Securelist - securelist.com
exiftool
2026
IT threat evolution in Q1 2026. Mobile statistics
IT threat evolution in Q1 2026. Mobile statisticsIT threat evolution in Q1 2026. Non-...
2026-5-18 12:0:30 | 阅读: 31 |
收藏
|
Securelist - securelist.com
trojan
triada
mamont
banker
q1
IT threat evolution in Q1 2026. Non-mobile statistics
IT threat evolution in Q1 2026. Non-mobile statisticsIT threat evolution in Q1 2026....
2026-5-18 12:0:22 | 阅读: 28 |
收藏
|
Securelist - securelist.com
ransomware
q1
2026
territory
territories
Kimsuky targets organizations with PebbleDash-based tools
Over the past few months, we have conducted an in-depth analysis of specific activity...
2026-5-14 11:0:58 | 阅读: 39 |
收藏
|
Securelist - securelist.com
c2
appleseed
vscode
pebbledash
jse
State of ransomware in 2026
With International Anti-Ransomware Day taking place on May 12, Kaspersky presents its...
2026-5-12 07:0:4 | 阅读: 71 |
收藏
|
Securelist - securelist.com
ransomware
2026
encryption
extortion
security
CVE-2025-68670: discovering an RCE vulnerability in xrdp
Vulnerability reports...
2026-5-8 08:0:54 | 阅读: 57 |
收藏
|
Securelist - securelist.com
client
xrdp
wm
utf16
security
Exploits and vulnerabilities in Q1 2026
During Q1 2026, the exploit kits leveraged by threat actors to target user systems exp...
2026-5-7 10:0:43 | 阅读: 49 |
收藏
|
Securelist - securelist.com
2026
q1
security
c2
OceanLotus suspected of using PyPI to deliver ZiChatBot malware
IntroductionThrough our daily threat hunting, we noticed that, beginning in July 2025...
2026-5-6 13:0:34 | 阅读: 51 |
收藏
|
Securelist - securelist.com
zichatbot
malicious
library
colorinal
python
Websites with an undefined trust level: avoiding the trap
Executive summaryA suspicious website is a web resource that cannot be definitively...
2026-5-6 09:30:46 | 阅读: 53 |
收藏
|
Securelist - securelist.com
phishing
security
fraudulent
malicious
2026
“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security
IntroductionThe primary goal for attackers in a phishing campaign is to bypass email...
2026-5-4 10:0:23 | 阅读: 35 |
收藏
|
Securelist - securelist.com
phishing
attackers
security
bec
Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India
In December 2025, we detected a wave of malicious emails designed to look like officia...
2026-4-30 07:0:19 | 阅读: 37 |
收藏
|
Securelist - securelist.com
payload
loader
abcdoor
rustsl
fox
PhantomRPC: A new privilege escalation technique in Windows RPC
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内,并且不需要特定的开头。首先,我得仔细阅读用户提供的文章内容,了解其主要观点和关键信息。 文章主要讨论了Windows中的远程过程调用(RPC)机制及其潜在的安全漏洞。特别是,作者发现了一个新的漏洞,允许本地权限提升到SYSTEM级别。这个漏洞利用了RPC的架构弱点,攻击者可以在多个场景下进行攻击,比如通过模拟TermService或其他服务。 接下来,我需要提取关键点:RPC机制、漏洞、本地权限提升、攻击向量、检测和防御策略。同时,要注意字数限制,确保在100字以内简洁明了地表达这些内容。 然后,我会组织语言,确保信息准确且连贯。例如,开头提到RPC机制及其复杂性,接着说明漏洞如何导致权限提升,再提到多种攻击路径和防御措施。 最后,检查总结是否符合要求:没有使用特定的开头词,控制在100字以内,并且涵盖了文章的核心内容。 </think> Windows RPC机制存在架构性弱点,允许本地权限提升至SYSTEM级别。攻击者可利用此漏洞通过模拟合法RPC服务器实现权限 escalation。该漏洞影响所有Windows版本且未修复。研究展示了五种不同的攻击路径,并提供了检测和防御策略。...
2026-4-24 08:0:12 | 阅读: 43 |
收藏
|
Securelist - securelist.com
client
windows
attacker
security
FakeWallet crypto stealer spreading through iOS apps in the App Store
ReportsKaspersky researchers...
2026-4-20 09:31:14 | 阅读: 36 |
收藏
|
Over Security - Cybersecurity news aggregator - securelist.com
panda
bronze
president
mustang
honeymyte
FakeWallet crypto stealer spreading through iOS apps in the App Store
In March 2026, we uncovered more than twenty phishing apps in the Apple App Store masq...
2026-4-20 09:22:47 | 阅读: 36 |
收藏
|
Securelist - securelist.com
malicious
hxxps
phishing
ledger
mnemonics
FakeWallet crypto stealer spreading through iOS apps in the App Store
嗯,用户让我总结一下这篇文章的内容,控制在一百个字以内,而且不需要特定的开头。首先,我得通读整篇文章,抓住主要信息。 文章讲的是在2026年3月,发现了超过20个伪装成流行加密钱包的钓鱼应用在苹果应用商店里。这些应用一旦运行,就会重定向到看起来像应用商店的网页,并分发被感染的合法钱包版本。这些恶意软件专门设计用来劫持恢复短语和私钥。根据恶意软件的元数据,这个活动至少从2025年秋季就开始了。 然后,文章提到类似的事件在2022年发生过,当时研究人员发现被破坏的钱包通过钓鱼网站分发,并利用iOS配置文件安装恶意软件来窃取恢复短语。现在同样的加密盗窃计划再次出现,增加了新的恶意模块和更新的注入技术,并通过应用商店的钓鱼应用分发。 技术细节方面,这些钓鱼应用使用了占位符功能来显得真实,并通过恶意链接打开浏览器,利用配置文件安装被感染的钱包。恶意模块通过注入库或修改源代码来窃取恢复短语和私钥,并将数据加密后发送到攻击者的服务器。 受害者主要是中国用户,因为这些钓鱼应用主要在中国的应用商店出现,并且钓鱼页面也是中文的。然而,恶意模块本身没有地域限制,所以其他国家的用户也可能受到影响。 总结一下,文章描述了针对加密钱包用户的钓鱼攻击活动,利用苹果应用商店分发伪装的应用程序来窃取用户的敏感信息。 </think> 这篇文章揭示了一起针对加密钱包用户的钓鱼攻击活动。攻击者在苹果应用商店中发布了超过20个伪装成流行加密钱包的应用程序。这些应用程序一旦运行,会重定向用户到伪造的应用商店页面,并分发经过篡改的合法钱包版本。这些被感染的应用程序专门设计用于劫持用户的恢复短语和私钥。根据恶意软件的元数据,该活动至少从2025年秋季开始活跃。 攻击者利用iOS配置文件(包括企业配置描述文件)安装被感染的钱包应用程序到用户的设备上。这种技术不仅限于FakeWallet威胁;其他iOS威胁如SparkKitty也使用类似的方法。 恶意模块通过注入库或修改源代码来窃取用户的恢复短语和私钥。数据被加密后发送到攻击者的服务器进行处理。 受害者主要是中国用户,因为这些钓鱼应用程序主要在中国的应用商店中出现,并且钓鱼页面也是中文的。然而,恶意模块本身没有地域限制;由于部分变种会根据应用程序的语言自动调整钓鱼通知的内容,其他国家的用户也可能受到影响。 文章还指出了一些指标(IoC),包括受感染加密钱包IPA文件哈希、恶意动态链接库文件哈希、恶意React Native应用程序哈希、钓鱼HTML文件哈希、恶意Android文件哈希、恶意下载链接和C2地址等。 总之,这篇文章详细描述了FakeWallet威胁活动如何通过伪装成合法加密钱包的应用程序,在苹果应用商店中分发并窃取用户的敏感信息。...
2026-4-20 09:22:47 | 阅读: 34 |
收藏
|
Securelist - securelist.com
malicious
hxxps
phishing
ledger
mnemonics
Previous
2
3
4
5
6
7
8
9
Next