#endpoint

2025-10-21

A view on a recent Salt Typhoon intrusion

Salt Typhoon, a China-linked cyber espionage group, has been observed targeting global infrastructure using stealthy techniques like DLL sideloading and zero-day exploits. Darktrace identified early-stage intrusion activity consistent with Salt Typhoon's tactics in a European telecommunications organization. The intrusion likely began with exploitation of a Citrix NetScaler Gateway appliance, followed by pivoting to Citrix VDA hosts. The threat actor delivered a SNAPPYBEE backdoor via DLL side-loading, used LightNode VPS endpoints for command and control, and attempted data exfiltration. Darktrace's anomaly-based detections played a key role in surfacing and neutralizing the threat before it could escalate further, highlighting the importance of proactive defense against sophisticated state-sponsored actors.

Pulse ID: 68f6536b549a38d68528a530
Pulse Link: otx.alienvault.com/pulse/68f65
Pulse Author: AlienVault
Created: 2025-10-20 15:21:15

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BackDoor #China #Citrix #CyberSecurity #Darktrace #Endpoint #Espionage #Europe #ICS #InfoSec #NetScaler #OTX #OpenThreatExchange #RAT #SideLoading #Telecom #Telecommunication #ZeroDay #bot #AlienVault

Waidler :mastodon:waidler@bayerwald.social
2025-10-16

Mit diesem Album teste ich gerade meinen neuen 3-Tier ROON Endpoint mit AudioLinux auf dem Raspberry Pi 4 als Diretta-Host und dem Raspberry Pi 5 als Diretta-Target. Stunning!

Arne Domnerus: „Jazz at the Pawnshop“
Das berühmte Stockholmer Konzert von 1976, aufgenommen von Gert Palmcrantz, zählt zu den audiophilen Dauerbrennern schlechthin. Es gibt Dutzende Versionen des Albums, das von vielen als eine der bestklingenden Jazz-Aufnahmen überhaupt gehandelt wird.

#roon #diretta #endpoint #jazz

TugaTech 🖥️tugatech@masto.pt
2025-10-14
Anupam MishraAnupam002
2025-10-07

admins! leads!

Your next breach could be a single rogue or a “harmless” file copy to an external drive.

Defend your data with Veltar:

- Create precise access rules for specific storage devices
- Enforce encryption so that only encrypted devices can connect
- Filter by type—, cards, external drives

Lock it down before someone else unlocks it for you.

Know more about -scalefusion.com/products/velta

2025-09-30

Disallow: /security-research? Crypto Phishing Sites' Failed Attempt to Block Investigators

An analysis of robots.txt files revealed over 60 cryptocurrency phishing pages impersonating hardware wallet brands Trezor and Ledger. The actor behind these pages attempted to block phishing reporting sites by including their endpoints in the robots.txt file, demonstrating a misunderstanding of its function. Most sites were hosted on Cloudflare Pages, with a few on custom domains. The campaign's unusual robots.txt pattern was also found in GitHub repositories containing crypto-themed spoof pages. Merge conflicts in README files suggest the actor may lack web development expertise. Various free web hosting providers were used for similar spoofed pages. The campaign highlights the ongoing targeting of cryptocurrency users and the potential effectiveness of even poorly executed phishing attempts.

Pulse ID: 68dc1d57df2b39428324e2b6
Pulse Link: otx.alienvault.com/pulse/68dc1
Pulse Author: AlienVault
Created: 2025-09-30 18:11:35

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Cloud #CyberSecurity #Edge #Endpoint #GitHub #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #bot #cryptocurrency #AlienVault

2025-09-24

Malicious Listener for Ivanti Endpoint Mobile Management Systems

An attack on a UK telecoms provider is being investigated by the UK Computer Security Agency (CSA) as part of its anti-virus programme, which aims to identify and prevent cyber-attacks.

Pulse ID: 68d3752f4586543730e22af1
Pulse Link: otx.alienvault.com/pulse/68d37
Pulse Author: Tr1sa111
Created: 2025-09-24 04:35:59

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #Endpoint #InfoSec #Ivanti #OTX #OpenThreatExchange #Telecom #UK #bot #Tr1sa111

Daniel Silverstonekinnison@flarn.net
2025-09-11

My new favourite uBlock Origin filter:

`www.youtube.com###endpoint[title=Shorts]`

Finally I can stop accidentally clicking that fucking awful thing.

Alexis | STR4T0TT0str4t0tt0
2025-08-21

Velociraptor spans the full attack lifecycle. It's delivering forensic insight into past compromise, enabling rapid triage now, and continuous detection for future threats.
A cohesive lens across all phases.

❀𝓪𝓵𝓬𝓮𝓪𖤐alcea@alceawis.com
2025-08-10
Oh nice.
Found another #pixiv #endpoint
https://embed.pixiv.net/artwork.php?illust_id=109256797

Kinda wish it'd relay the master img..
Ohwell
#repost •acws #acws
Anupam MishraAnupam002
2025-07-01

Your devices are either compliant—or they’re vulnerable.
With Veltar’s Automated Compliance, there’s no in-between.

✔️Enforce CIS standards at scale
✔️Auto-remediate policy violations
✔️Monitor real-time compliance posture
✔️Leverage 95+ rules

Read more: lnkd.in/dtgCahhH

Praveenpraveene27
2025-06-25

🚨 often starts at the — your laptop, desktop, or RDP. In Part 1 of our blog, learn how attacks begin, how they spread, and why local recovery fails.

🛡 Stay protected with BDRSuite.
🔗 bdrsuite.com/blog/endpoint-pro

aaron ~# :blinkingcursor:neuroexception@infosec.exchange
2025-06-10

I finally finished my #Fail2Ban setup and am quite happy with the result. I've got #discord and #email notifications, global IP banning (on all servers) and automatic reporting to #abuseipdb based on multiple factors. This is awesome.

I'm so happy that i took the time to set up #Authelia as it's a breeze to #protect a single #endpoint and cover 70-80% of all services.

#homelab #selfhosting #linux #security #sso #oidc #OpenIDConnect

2025-05-31

Giải pháp hiện đại bảo vệ thiết bị đầu cuối: Giới thiệu về phần mềm bảo mật Endpoint

Giải pháp hiện đại bảo vệ thiết bị đầu cuối: Giới thiệu về phần mềm bảo mật Endpoint Phần mềm bảo mật Endpoint đại diện cho một bước tiến quan trọng trong việc bảo vệ hệ thống máy tính và dữ liệu khỏi các mối đe dọa ngày càng tinh vi trong thời đại số.

maychu.top/2025/05/31/giai-pha

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst