Ingeniero de sistemas y seguridad.Gamer en los ratos libres.Quiero compartir con todo sobre el mundo de la tecnología de manera mas fácil de entender y acercarla cada vez mas.

Nuevos paquetes Trojanizados de npm revelan la táctica NullReceiver para ocultar las IPs del servidor C2 en Blockchain

Nuevos paquetes Trojanizados de npm revelan la táctica NullReceiver para ocultar las IPs del servidor C2 en Blockchain Introducción a la táctica NullReceiver Los investigadores en ciberseguridad han identificado una evolución sofisticada del mecanismo de comando y control (C2) EtherHiding dentro del ámbito del software malicioso. Este nuevo método, conocido como NullReceiver, utiliza un enfoque…

New Trojanized npm Packages Unveil NullReceiver Tactic for Concealing C2 Server IPs in Blockchain

New Trojanized npm Packages Unveil NullReceiver Tactic for Concealing C2 Server IPs in Blockchain Introduction to the NullReceiver Tactic Cybersecurity researchers have identified a sophisticated evolution of the EtherHiding command-and-control (C2) mechanism within the realm of malicious software. This new method, known as NullReceiver, utilizes a unique approach to obfuscate the C2 server’s IP address…

The Evolving Threat of TeamPCP: A Deeper Dive into Cybersecurity's Archenemy of Open-Source Software

The Evolving Threat of TeamPCP: A Deeper Dive into Cybersecurity’s Archenemy of Open-Source Software

The Evolving Threat of TeamPCP: A Deeper Dive into Cybersecurity’s Archenemy of Open-Source Software Background and Context The rise of open-source software has revolutionized the technology landscape, enabling rapid innovation and collaborative development. However, it has also attracted a new breed of cyber adversaries, with the group known as TeamPCP emerging as a significant threat.…

DOUBLECUP: A New Era in Malware Delivery Through ClickFix and Cached PNGs

DOUBLECUP: A New Era in Malware Delivery Through ClickFix and Cached PNGs

DOUBLECUP: A New Era in Malware Delivery Through ClickFix and Cached PNGs Background and Context In the ever-evolving landscape of cybersecurity, the emergence of new malware delivery systems poses an ongoing challenge for organizations and individual users alike. The recent discovery of a Russian loader-as-a-service (LaaS) known as DOUBLECUP highlights a sophisticated approach to malware…

CISA Señala una Vulnerabilidad de Alta Severidad en N-able N-central a Medida que Surgan Casos de Explotación

CISA Señala una Vulnerabilidad de Alta Severidad en N-able N-central a Medida que Surgan Casos de Explotación Introducción a la Vulnerabilidad La Agencia de Ciberseguridad e Infraestructura de EE. UU. (CISA) ha incluido recientemente una vulnerabilidad de seguridad crítica que afecta a N-able N-central en su base de datos de Vulnerabilidades Conocidas Explotadas (KEV). Esta…

CISA Flags High-Severity Flaw in N-able N-central as Exploitation Cases Surface

CISA Flags High-Severity Flaw in N-able N-central as Exploitation Cases Surface Introduction to the Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently included a critical security vulnerability affecting N-able N-central in its Known Exploited Vulnerabilities (KEV) database. This action follows verified instances of active exploitation, underscoring the urgency for organizations using this…