Sys-Admin InfoSec
12.9K subscribers
244 photos
2 videos
104 files
4.6K links
News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Chat - @sysadm_in
* Job - @sysadm_in_job
* DNS - OpenBLD.net
* ? - @sysadminkz
Download Telegram
TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

Trojan that contains a dynamic infection chain with a heavy anti-analysis loading component that can deploy two embedded payloads (worm, banker). The observed infection chain bundles a malicious MSI installer inside a ZIP file. These MSI installer packages are abusing a signed Logitech program called Logi AI Prompt Builder..:

https://www.elastic.co/security-labs/tclbanker-brazilian-banking-trojan
PamDOORa: Analyzing a New Linux PAM-Based Backdoor for Sale on the Dark Web

https://flare.io/learn/resources/blog/pamdoora-new-linux-pam-based-backdoor-sale-dark-web
Forwarded from Sys-Admin Up (Yevgeniy Goncharov)
New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps

..The malware’s primary command-and-control channel has been migrated onto The Open Network (TON) using .adnl endpoints routed through an embedded local TON proxy..:

https://www.threatfabric.com/blogs/new-trickmo-variant-device-take-over-malware-targeting-banking-fintech-wallet-auth-app
AppSecFest 2026 - В эту пятницу в Алматы, Farabi Hub

Будут экспертные эксперты, тимлиды, специалисты, представители IT-индустрии, AppSec/DevSecOps-практики, инженеры по безопасности.

+ будет открытое CTF-соревнование от команды mimicats – где можно пропробовать свои скиллы в реальных задачах по ИБ (максимум практики, никакой теории)
+ Воркшопы с живое общением на темы AppSec, DevSecOps, инженерной культуры, процессы, и даже факапы

• Начало: 15 мая, 09:00, Farabi Hub

Все спикеры заслуживают внимания, многих знаю лично, все детали здесь: appsecfest.kz
Dead.Letter (CVE-2026-45185) How XBOW Found an Unauthenticated RCE on Exim

https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim
Forwarded from OpenBLD.net (Yevgeniy Goncharov)
DNS is not just about domains. It is about Trust.

Recent supply chain incidents are a strong reminder that modern attacks often start through tools and workflows developers already trust:

• npm packages and dependency updates
• compromised maintainer accounts
• VSCode extensions
• GitHub Actions workflows
• fake installers and update mechanisms

Several recent cases highlight this trend:

• Axios compromised on npm - malicious versions dropped a Remote Access Trojan >
• Compromised VSCode Nx Console >
• OpenAI TanStack npm supply chain attack >
• OpenAI Axios developer tool compromise >
• GitHub unauthorized access to internal repositories >

The key takeaway: supply chain attacks are becoming more relevant to every developer, engineering team, and company.

DNS security should not be treated as an optional layer.

It can provide visibility and control when malicious code attempts to:

• connect to C2 infrastructure
• reach phishing domains
• communicate with fake update servers
• exfiltrate data through suspicious endpoints

If malicious code has already entered the environment, visibility becomes critical...

At this point, the key questions are simple:

• Can you see where it is trying to connect?
• Can you understand whether that connection is expected?
• Can you react before the incident becomes bigger?

OpenBLD.net - Security starts earlier than incident response.

Watch yourself, your emails, your extensions, and your DNS. Peace ✌️
FortiBleed - Breach How 80,000+ Corporate= Firewalls Were Quietly Compromised

If your organization uses a Fortinet firewall or VPN product and appears in this dataset, treat your network perimeter as already compromised and act immediately. SOCRadar rates this campaign Critical..:

https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/
DuneSlide: Two Critical RCE vulnerabilities via Zero-Click Prompt Injection in Cursor IDE

https://www.catonetworks.com/blog/duneslide-two-critical-rce-vulnerabilities/
Vishing actors target Entra passkey enrollment (mimics the Microsoft passkey enrollment)

The threat actor registers domains that incorporate the word passkey as part of a voice-enabled phishing (“vishing”) scheme. The threat actor then calls targeted users on the phone in an attempt to persuade them that they need to register a new passkey.:

https://www.okta.com/en-au/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/
ClickLock Stealer: Paste Once, Lose Everything

Upon execution of the ClickFix command, the malicious script shows a terminal-based loading animation mimicking Cloudflare progress bar with browser verification flow..:

https://www.group-ib.com/blog/clicklock-stealer-macos-malware/