06/24

FileFix - A ClickFix Alternative | mr.d0x

https://mrd0x.com/filefix-clickfix-alternative/
FileFix - A ClickFix Alternative | mr.d0x

APT-C-06(DarkHotel)利用BYOVD技术的最新攻击活动分析

https://mp.weixin.qq.com/s/m2G9oLHv504HJDW8mB5rDA
APT-C-06(DarkHotel)利用BYOVD技术的最新攻击活动分析

U.S. House Bans WhatsApp on Official Devices Over Security and Data Protection Issues

https://thehackernews.com/2025/06/us-house-bans-whatsapp-on-official.html
U.S. House Bans WhatsApp on Official Devices Over Security and Data Protection Issues

US Homeland Security warns of escalating Iranian cyberattack risks

https://www.bleepingcomputer.com/news/security/us-homeland-security-warns-of-escalating-iranian-cyberattack-risks/
US Homeland Security warns of escalating Iranian cyberattack risks

Canada says Salt Typhoon hacked telecom firm via Cisco flaw

https://www.bleepingcomputer.com/news/security/canada-says-salt-typhoon-hacked-telecom-firm-via-cisco-flaw/
Canada says Salt Typhoon hacked telecom firm via Cisco flaw

Researchers Find Way to Shut Down Cryptominer Campaigns Using Bad Shares and XMRogue

https://thehackernews.com/2025/06/researchers-find-way-to-shut-down.html
Researchers Find Way to Shut Down Cryptominer Campaigns Using Bad Shares and XMRogue

APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine

https://thehackernews.com/2025/06/apt28-uses-signal-chat-to-deploy.html
APT28 Uses Signal Chat to Deploy BEARDSHELL Malware and COVENANT in Ukraine

Four REvil ransomware crooks walk free after admitting guilt • The Register

https://go.theregister.com/feed/www.theregister.com/2025/06/24/four_revil_ransomware_suspects_time_served/
Four REvil ransomware crooks walk free after admitting guilt • The Register

US House bans WhatsApp on staff devices over security concerns

https://www.bleepingcomputer.com/news/security/us-house-bans-whatsapp-on-staff-devices-over-security-concerns/
US House bans WhatsApp on staff devices over security concerns

Automating MS-RPC vulnerability research | Incendium.rocks

https://www.incendium.rocks/posts/Automating-MS-RPC-Vulnerability-Research/
Automating MS-RPC vulnerability research | Incendium.rocks

Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via Keyloggers

https://thehackernews.com/2025/06/hackers-target-65-microsoft-exchange.html
Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via Keyloggers

Prometei Botnet Activity Spikes - SecurityWeek

https://www.securityweek.com/prometei-botnet-activity-spikes/
Prometei Botnet Activity Spikes - SecurityWeek

#OBTS v8.0: CFP

https://objectivebythesea.org/v8/cfp.html
#OBTS v8.0: CFP

New FileFix attack weaponizes Windows File Explorer for stealthy commands

https://www.bleepingcomputer.com/news/security/filefix-attack-weaponizes-windows-file-explorer-for-stealthy-powershell-commands/
New FileFix attack weaponizes Windows File Explorer for stealthy commands

China's Salt Typhoon Hackers Target Canadian Telecom Firms - SecurityWeek

https://www.securityweek.com/chinas-salt-typhoon-hackers-target-canadian-telecom-firms/
China's Salt Typhoon Hackers Target Canadian Telecom Firms - SecurityWeek

Hackers Exploit Misconfigured Docker APIs to Mine Cryptocurrency via Tor Network

https://thehackernews.com/2025/06/hackers-exploit-misconfigured-docker.html
Hackers Exploit Misconfigured Docker APIs to Mine Cryptocurrency via Tor Network

'Psylo browser' takes aim at digital fingerprinting • The Register

https://go.theregister.com/feed/www.theregister.com/2025/06/24/psylo_browser_privacy_tab_silos/
'Psylo browser' takes aim at digital fingerprinting • The Register

Profundis

http://Profundis.io
Profundis

Russia-linked APT28 use Signal chats to target Ukraine official with malware

https://securityaffairs.com/179288/apt/russia-linked-apt28-use-signal-chats-to-target-ukraine-official-with-malware.html
Russia-linked APT28 use Signal chats to target Ukraine official with malware

Trezor’s support platform abused in crypto theft phishing attacks

https://www.bleepingcomputer.com/news/security/trezors-support-platform-abused-in-crypto-theft-phishing-attacks/
Trezor’s support platform abused in crypto theft phishing attacks

Threat Intelligence - ANY.RUN

https://intelligence.any.run/analysis/lookup?utm_content=linktoti&utm_term=240625#%7B%2522query%2522:%2522threatName:%255C%2522%5Ephishing$%255C%2522%2522,%2522dateRange%2522:180%7D
Threat Intelligence - ANY.RUN

Critical Authentication Bypass Flaw Patched in Teleport - SecurityWeek

https://www.securityweek.com/critical-authentication-bypass-flaw-patched-in-teleport/
Critical Authentication Bypass Flaw Patched in Teleport - SecurityWeek

https://www.reddit.com/r/InfoSecNews/comments/1lio628/canada_says_salt_typhoon_hacked_telecom_firm_via/

https://www.reddit.com/r/InfoSecNews/comments/1lio628/canada_says_salt_typhoon_hacked_telecom_firm_via/