Zarya Hacktivists: More than just Sharepoint., (Mon, Dec 4th)

Last week, I wrote about a system associated with pro-Russian hacktivist scanning for vulnerable Sharepoint servers [1]. Thanks to @DonPasci on X for pointing me to an article by Radware about the same group using Mirai [2][3]. This group has been active for a while, using various low-hanging fruit exploits to hunt for defacement targets.

Continue reading Zarya Hacktivists: More than just Sharepoint., (Mon, Dec 4th)

Posted in Uncategorized

Apple Patches Exploited WebKit Vulnerabilities in iOS/iPadOS/macOS, (Thu, Nov 30th)

Apple today released patches for two WebKit vulnerabilities affecting macOS, iPadOS and iOS. I would expect standalone Safari updates for older macOS versions in the future. At this point, only the most recent operating system versions received patches.

Continue reading Apple Patches Exploited WebKit Vulnerabilities in iOS/iPadOS/macOS, (Thu, Nov 30th)

Posted in Uncategorized

Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today, (Thu, Nov 30th)

Last week, Jonah Latimer posted here about traffic he saw to his own EC2 web honeypot exploiting %%cve:2023-1389%%. I found this looking at new URL strings to our honepot network, and so for on 29 Nov 23, there have been about 300 detections for this vulnerability pulling a shell script from %%ip:45.95.146.26%% a quick little shell script that does little more than figure out the architecture of the victim device and then attempt to download a architecture-specific variant of Mirai.

Continue reading Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today, (Thu, Nov 30th)

Posted in Uncategorized