Threat actors: “Please do not use Okta FastPass”
digicat @ digicat @infosec.pub Posts 270Comments 15Joined 2 yr. ago

From The Depths of the Shadows IRGC and Hacker Collectives Of The 12-Day War
Cyber Assessment Framework v4.0 released in response to growing threat - UK
yaraast: A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation
GRITREP: Observed Malicious Driver Use Associated with Akira SonicWall Campaign
Research: The Evolution of Chinese Smishing Syndicates and Digital Wallet Fraud
Disguises Zip Past Path Traversal - "Schizophrenic ZIP is an archive file that – after unzipping by two different software – may return two different files"
"Court Summons" Phishing Lure Used in Cyberattacks on Ukrainian Government and Defence Sector
Detection Engineering & Threat Hunting SIG (Special Interest Group) from FIRST
ft3: FT3: Fraud Tools, Tactics, and Techniques Framework - Fraud Tools, Tactics, and Techniques (FT3) is Stripe's adaptation of ATT&CK-style security frameworks
ITW CRITICAL SECURITY BULLETIN: Trend Micro Apex One™ (On-Premise) Management Console Command Injection RCE Vulnerabilities
Related https://www.jpcert.or.jp/english/at/2025/at250016.html