This report delves into the evolving threat of Registered Domain Generation Algorithms (RDGAs), highlighting how these advanced mechanisms allow threat actors to register numerous domains quickly, complicating detection efforts. It features the implications of…
Tag: THREAT HUNTING
Summary: The content discusses the cybersecurity threats faced by the Paris 2024 Olympic Games and the increase in cybersecurity services spending to defend against these threats. Threat Actor: Cybercriminals | Cybercriminals Victim: Paris 2024 Olympic Games | Paris 2024 Olympic Games Key Point : Th…
Threat actors are increasingly using fileless code execution through the Windows registry to evade traditional AV/EDR detections. The article shows real-world examples (STEADY#URSA/SUBTLE#PAWS, GOOTLOADER, COOKBOX, Qakbot) and outlines practical detection appr…
Threat Intelligence, or just TI, is sometimes criticized for possibly being inaccurate or outdated. However, there are compelling reasons to incorporate it into your cybersecurity defense strategy. Let’s present some ways to use TI effectively as part of your security operations lifecycle.
CISA warned chemical facilities that its Chemical Security Assessment Tool (CSAT) environment was compromised in January. CISA warns chemical facilities that its Chemical Security Assessment Tool (CSAT) environment was breached in January. In March, the Recorded Future News first reported that the US Cybersecurity and Infrastructure Security Agency (CISA) agency was hacked…
SELKS: Open-source Suricata IDS/IPS, network security monitoring, threat hunting – Help Net Security
Summary: This content discusses SELKS, a free and open-source solution for network intrusion detection and protection, network security monitoring, and threat hunting. Threat Actor: N/A Victim: N/A Key Point : SELKS is a turnkey solution developed by Stamus Networks for small and medium-sized organi…
Summary: This content discusses the importance of process mapping in cybersecurity and how it can revolutionize understanding and managing the security landscape. Threat Actor: N/A Victim: N/A Key Point : Cybersecurity is not just about firewalls and antivirus, but also about understanding how defen…
Summary: Permiso has developed YetiHunter, a tool that allows companies to detect and investigate threats in their Snowflake environments. Threat Actor: N/A Victim: Snowflake customers Key Point : Permiso’s YetiHunter is a threat detection and hunting tool designed specifically for Snowflake environ…
Summary: The notorious Scattered Spider cybercrime group has become an affiliate of the RansomHub ransomware-as-a-service (RaaS) operator, leading to the emergence of a new RaaS model in the cybercrime landscape. Threat Actor: Scattered Spider | Scattered Spider Victim: Change Healthcare | Change He…
Summary: The content discusses the rise of AI-powered cyber threats and the impact on cybersecurity strategies, with a focus on prevention capabilities. Threat Actor: AI-powered cyber threats | AI-powered cyber threats Victim: Organizations | organizations Key Point : 75% of security professionals h…
Mandiant assesses with high confidence that Russia poses the most significant threat to the Paris Olympics, including cyber espionage, disruptive and destructive operations, and information operations. Organizations should update threat profiles, conduct secur…
This time, we’re not revealing a new cyber threat investigation or analysis, but I want to share some insights about the team behind all Sekoia Threat Intelligence and Detection Engineering reports. Let me introduce you to the Sekoia TDR team. TL;DR Sekoia Threat Detection & Research (TDR) is a…
In the modern Internet society, one can easily obtain information on devices all over the world connected to the Internet using network and device search engines such as Shodan. Threat actors can use these search engines to engage in malicious behaviors such as collecting information on attack targets or performing port…
AT&T has split its cybersecurity services business to form a new company called LevelBlue. It includes AT&T’s managed security services business, cybersecurity consulting business, and assets from the acquisition of AlienVault in 2018….
The Top 10 Malware in Q1 2024 changed slightly from the previous quarter. Here’s what the CIS Cyber Threat Intelligence team observed….