Mandiant links it to a known Chinese APT (UNC5221): cloud.google.com/blog/topics/...
Mandiant links it to a known Chinese APT (UNC5221): cloud.google.com/blog/topics/...
cloud.google.com/blog/topics/...
cloud.google.com/blog/topics/...
-Babuk2 gang linked to data broker Bjorka
-Stripe API abused for skimming
-Abuse of SVG redirects becomes mainstream
-UNC5221 deploys new Ivanti zero-day
-DrayTek reboot loops linked to pre-2020 bugs
-Five Eyes warns about fast flux networks
-Babuk2 gang linked to data broker Bjorka
-Stripe API abused for skimming
-Abuse of SVG redirects becomes mainstream
-UNC5221 deploys new Ivanti zero-day
-DrayTek reboot loops linked to pre-2020 bugs
-Five Eyes warns about fast flux networks
Here is the full report:
blog.eclecticiq.com/china-nexus-...
Here is the full report:
blog.eclecticiq.com/china-nexus-...
#SecurityLand #CyberWatch #CyberSecurity #ThreatIntelligence #APT #Brickstorm #Malware
#SecurityLand #CyberWatch #CyberSecurity #ThreatIntelligence #APT #Brickstorm #Malware
Peek the forecast—then subscribe for the follow-through. -> blog.alphahunt.io/will-unc5221...
#AlphaHunt #CyberSecurity #ZeroDay #UNC5221
Peek the forecast—then subscribe for the follow-through. -> blog.alphahunt.io/will-unc5221...
#AlphaHunt #CyberSecurity #ZeroDay #UNC5221
#BRICKSTORM #China #Mandiant #UNC5221 #CyberSecurity #Infosec #IPTheft therecord.media/china-linked...
#BRICKSTORM #China #Mandiant #UNC5221 #CyberSecurity #Infosec #IPTheft therecord.media/china-linked...
Beat the press release—subscribe for the final call.
blog.alphahunt.io/will-unc5221...
#AlphaHunt #CyberSecurity #ZeroDay
Beat the press release—subscribe for the final call.
blog.alphahunt.io/will-unc5221...
#AlphaHunt #CyberSecurity #ZeroDay
This is a known Chinese APT group that seems to be specialized in Ivanti and other Western enterprise products... they have a long list of past zero-days in their name
blog.eclecticiq.com/china-nexus-...
This is a known Chinese APT group that seems to be specialized in Ivanti and other Western enterprise products... they have a long list of past zero-days in their name
blog.eclecticiq.com/china-nexus-...
UNC5221として追跡されている中国のスパイグループが、Brickstormバックドアと、これまで記録されていなかったPlenetおよびAgentPSDというマルウェアを使用して、Microsoft 365環境にアクセスしていたことが明らかになった。
この事件の調査により、攻撃者は検出される少なくとも18ヶ月前には被害者のネットワークにアクセスしており、被害者組織のマネージドサービスプロバイダー(MSP)も侵害していたことが明らかになった。
UNC5221はVerdantBambooとし...
UNC5221として追跡されている中国のスパイグループが、Brickstormバックドアと、これまで記録されていなかったPlenetおよびAgentPSDというマルウェアを使用して、Microsoft 365環境にアクセスしていたことが明らかになった。
この事件の調査により、攻撃者は検出される少なくとも18ヶ月前には被害者のネットワークにアクセスしており、被害者組織のマネージドサービスプロバイダー(MSP)も侵害していたことが明らかになった。
UNC5221はVerdantBambooとし...
These initial attacks were linked to Chinese APT UNC5221, but it's unclear if DslogdRAT is their malware, or may belong to a different group
blogs.jpcert.or.jp/en/2025/04/d...
These initial attacks were linked to Chinese APT UNC5221, but it's unclear if DslogdRAT is their malware, or may belong to a different group
blogs.jpcert.or.jp/en/2025/04/d...
Read the forecast (then subscribe): blog.alphahunt.io/will-unc5221...
#AlphaHunt #CyberSecurity #ZeroDay #VMware
Read the forecast (then subscribe): blog.alphahunt.io/will-unc5221...
#AlphaHunt #CyberSecurity #ZeroDay #VMware
🔥 Subscribe for sharper forecasts—before the boom.
blog.alphahunt.io/by-dec-31-20...
#AlphaHunt #CyberSecurity #ZeroDay #APT
🔥 Subscribe for sharper forecasts—before the boom.
blog.alphahunt.io/by-dec-31-20...
#AlphaHunt #CyberSecurity #ZeroDay #APT