Abusing Applint DLLs Registry: Detect This Behavior with Sigma Detection Rule

[vc_row][vc_column][vc_column_text]Dynamic-link libraries (DLLs) that are specified in the AppInit_DLLs value in the Registry keys: HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\CurrentVersion\Windows or HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows are loaded by user32.dll into every process that loads user32.dll With this sigma rule you can detect these behaviors:[/vc_column_text][/vc_column][/vc_row][vc_row css=”.vc_custom_1583061957730{background-color: #000000 !important;}”][vc_column css=”.vc_custom_1583061928491{background-color: #000000 !important;}”][vc_column_text css=”.vc_custom_1583061897720{background-color: #000000 !important;}”]title: Abusing Applint DLLs Registry Path description: DLLs values in…

Cisco vulnerabilities

Cisco Addresses High-Severity Vulnerabilities In Its Products

Cisco has issued security patches for vulnerabilities in its products, eight of which considered having a potentially high impact and the remainder rated medium. The vulnerabilities exist in Cisco products, including the Unified Computing System (UCS) software, Firepower firewall (FXOS), and the Nexus switch operating system (NX-OS) software.  “All six vulnerabilities have a Security Impact Rating (SIR)…

Cerberus android banking Trojan

Cerberus Android Banking Trojan Steals Google Authenticator’s 2FA Codes

“Cerberus” Android banking Trojan is now able to steal and exploit Google Authenticator’s one-time passcodes (OTP); these codes are generated for two-factor authentication (2FA) of many accounts. Google Authenticator app was launched in 2010 as the more secure alternative for SMS Authentication codes. The app works by providing six to eight-digits unique codes that users…


DoppelPaymer lanserar en webbplats för att läcka stulen information vid utebliven lösesumma

DoppelPaymer-operatörerna har lanserat webbplatsen “Dopple” för att läcka stulen information om offren som vägrar att betala en lösesumma. Operatörerna säger att de har skapat den här webbplatsen för att hota offren. Om de vägrar att betala kommer information såsom namn och viktiga företagsdata att läcka ut på webbplatsen. Operatörerna hävdar att webbplatsen för närvarande är…