#powershell

2025-12-17

A new campaign by the ForumTroll APT group

The ForumTroll APT group has launched a new targeted phishing campaign against Russian political scientists, exploiting plagiarism reports as bait. The attackers used sophisticated techniques, including a well-prepared domain and personalized emails, to deliver the Tuoni framework malware. This campaign follows their spring attacks, which targeted organizations using zero-day vulnerabilities. The fall campaign relied on social engineering, using emails posing as a scientific library to trick victims into downloading malicious archives. The final payload was delivered through a PowerShell script and established persistence using COM Hijacking. Despite being less technically sophisticated than the spring campaign, this operation demonstrates the group's continued focus on Russian and Belarusian targets.

Pulse ID: 6942a78ba8a16371e6ddd3cc
Pulse Link: otx.alienvault.com/pulse/6942a
Pulse Author: AlienVault
Created: 2025-12-17 12:52:27

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Belarus #CyberSecurity #Email #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #Russia #SocialEngineering #Troll #ZeroDay #bot #AlienVault

Matthew Dowstmdowst
2025-12-17

I just taught PowerShell to sing the 12 Days of Christmas with emojis and had to fight Unicode to do it. Come see how in the latest PoshBytes.

youtube.com/shorts/fDaaB0i7zXM

2025-12-17

BlindEagle Targets Colombian Government Agency with Caminho and DCRAT

A spear phishing campaign targeting a Colombian government agency under the Ministry of Commerce, Industry and Tourism was discovered in September 2025. The attack, attributed to BlindEagle, utilized a compromised email account within the organization to bypass security controls. The campaign employed a sophisticated multi-layer attack chain, including a fake web portal, nested JavaScript and PowerShell scripts, steganography, and the deployment of Caminho as a downloader for DCRAT. The attack leveraged legal-themed lures, in-memory execution, and abuse of legitimate services like Discord. BlindEagle's evolution in tactics and use of new tools like Caminho demonstrates their ongoing threat to Colombian institutions.

Pulse ID: 69421a1f3d6e9eac9a0ce057
Pulse Link: otx.alienvault.com/pulse/69421
Pulse Author: AlienVault
Created: 2025-12-17 02:49:03

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #DCRat #Discord #Email #Government #ICS #InfoSec #Java #JavaScript #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RCE #SpearPhishing #Steganography #bot #AlienVault

Le site de Korbenkorben.info@web.brid.gy
2025-12-17
<p>Bon, déjà si vous êtes sous Windows, je sais c'est dur la vie ^^. Mais si en plus vous êtes anti-IA, votre quotidien doit être encore plus difficile depuis que Microsoft a décidé de coller de l'intelligence artificielle partout dans son OS. Copilot par-ci, Recall par-là, des features IA dans Paint, dans le Bloc-notes, dans les paramètres... Bref, c'est l'invasion et y'a malheureusment pas vraiment de bouton &quot;OFF&quot; officiel pour tout virer d'un coup.</p>
<p>Hé bien figurez-vous qu'un développeur du nom de zoicware a créé un script PowerShell qui fait exactement ça. Ça s'appelle
<a href="https://github.com/zoicware/RemoveWindowsAI">RemoveWindowsAI</a>
et ça permet de dégager TOUTES les fonctionnalités IA de Windows 11 en quelques secondes. Aux chiottes Copilot, Recall, les suggestions de frappe, l'IA dans Paint, dans Edge, les effets vocaux... Tout y passe et c'est cool !</p>
<p>Et ce script ne se contente pas de désactiver des options dans les paramètres comme un vulgaire amateur puisqu'il modifie les clés de registre, supprime les packages Appx (même ceux marqués &quot;non supprimables&quot; par Microsoft), nettoie les fichiers cachés dans le Component-Based Servicing, et surtout il installe un bloqueur pour empêcher Windows Update de vous remettre tout ce bazar à la prochaine mise à jour. Parce que oui, Microsoft adore réinstaller ses trucs en douce...</p>
<img alt="" src="https://korben.info/cdn-cgi/image/width=1200,fit=scale-down,quality=90,f=avif/removewindows
2025-12-16
15 YEARS of ADMIN | ADMIN Network & Security News

Updated: Enable Natural Scrolling Using a Mouse or Touchpad

- Update GNOME version
- Add KDE Plasma 6

Step by step instructions of how to reverse or flip the mouse or touchpad scroll direction on Linux and Microsoft Windows 10/11 to a natural scroll.

adamsdesk.com/posts/enable-nat

#blog #linux #windows #GNOME #KDE #PowerShell

Jeff Hicks 🐶🎼🍷🖥️JeffHicks@techhub.social
2025-12-16

Have you finished spending a few months of lunches learning #PowerShell? Next on your plate should be one of the most comprehensive scripting books (jdhitsolutions.com/yourls/psto) written by the original PowerShell experts. Includes PowerShell 7 content.

Daniel Glenndanielglenn
2025-12-16

Ever need your files to just inherit permissions from a library and get rid of those unique perms? Here is your simple way to do it quickly!
t.co/FwBIyRBOXr

------
t.co/yIHYlXGa1W

— Daniel Glenn (@danielglenn)
Dec 16, 2025

2025-12-16

How To: XML-config для хранимых процедур MS SQL — создание, разбор, развёртывание

Всем привет! Меня зовут Александр Гаврилов, я архитектор баз данных и аналитических систем в GRI. Если вы когда-нибудь пытались выполнить одну и ту же операцию с похожими таблицами в разных базах, да ещё и на разных серверах, то знаете, насколько это может быть мучительно. В этой статье я покажу один из рабочих вариантов, как упростить такую задачу, и заодно расскажу про интересную функцию XQuery, которая может неожиданно помочь.

habr.com/ru/companies/gri/arti

#mssql #tsql #xml #запросы #XQuery #PowerShell #HowTo #deploy

2025-12-16

👾 Come non far andare in standby Windows con uno script PowerShell
Togliere la sospensione e l'attivazione automatica della schermata di blocco del PC senza installare programmi...

👉 selectallfromdual.com/blog/1708

#powershell #truccowin #truccowindows #windows

this is easy to do and a lot more complete than any of the anti- #AI #Windows11 stuff I've seen so far. Actually removes/deletes rather than just "turns off"

There's a command on that page, paste into #Powershell, run, then reboot. done.
github.com/zoicware/RemoveWind

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst