persistence

2 articles
sort: new top best
clear filter
0 4/10

Threat actor Storm-2561 uses SEO poisoning and spoofed VPN vendor websites to distribute fake VPN clients that capture credentials and deploy the Hyrax infostealer malware. The attack targets users of Ivanti, Cisco, Fortinet, Sophos, Sonicwall, Check Point, and WatchGuard VPN products by mimicking legitimate download pages and displaying fake login prompts.

Storm-2561 Ivanti Cisco Fortinet Sophos Sonicwall Check Point WatchGuard Hyrax Microsoft Taiyuan Lihua Near Information Technology Co., Ltd.
bleepingcomputer.com · Bill Toulas · 7 hours ago · details
0 8/10

A logic flaw in 2FA implementation across multiple platforms (Google, Microsoft, Instagram, Cloudflare) allows an attacker to maintain persistence after password recovery by exploiting session renewal in the 2FA page and leveraging the fact that disabled 2FA codes still validate, enabling account takeover without knowing the current password.

Google Microsoft Instagram Facebook Cloudflare Algolia GitHub LinkedIn Luke Berner HackerOne Bugcrowd
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details