


DefSecSentinel
616 posts

@DefSecSentinel
179CPT Cyber Operations Technician 170A @MOARNG




New DirtyFrag PoC is also detected by our previously released Linux privilege escalation detection👀 That’s the advantage of focusing on the underlying privilege escalation pattern instead of a single exploit. You can find the rule here: github.com/elastic/detect…




New blog post is up, exploring detection options for some recent In- the- Wild Windows LPE 0- days elastic.co/security-labs/…




We have identified a novel social engineering campaign abusing Obsidian, the popular note taking app, to deliver a previously undocumented RAT #PHANTOMPULSE and it’s loader #PHANTOMPULL targeting individuals in finance and crypto. The attack never exploits a vulnerability. It abuses Obsidian's own plugin ecosystem to execute code the moment a victim opens a shared vault. Full analysis: go.es.io/4cld0dB





ClickFix techniques are evolving. Instead of copy and paste instructions to Terminal, newer variants are using Script Editor to execute payloads on macOS. Read more about this delivery technique in our latest blog post. jamf.com/blog/clickfix-… #clickfix #malware #threathunting

ClickFix techniques are evolving. Instead of copy and paste instructions to Terminal, newer variants are using Script Editor to execute payloads on macOS. Read more about this delivery technique in our latest blog post. jamf.com/blog/clickfix-… #clickfix #malware #threathunting

Hello World!

