2024-12-28
Jaime flagging popular extensions here. My findings/thoughts: - 15ish fresh (this week) domains, each w/ their own extension tie-in. - Links back to early 2024 extensions, similar abuse, but focused on ad-blocking, AI, youtube, extensions. - VIBESINT = opportunistic scam. 🧵...
Reuters
Experts say hackers compromised several companies' Chrome browser extensions, including Cyberhaven's, in a series of intrusions dating back to mid-December
Hackers have compromised several different companies' Chrome browser extensions in a series of intrusions dating back to mid-December …
2023-12-07
Read what the merc doesn't want you to read: 👉 Story: https://web.archive.org/... 👉 Technical: https://www.sentinelone.com/ ...
Reuters
Reuters temporarily removes its article titled “How an Indian startup hacked the world” to comply with an Indian court order, and plans to appeal the decision
Reuters has temporarily removed the article “How an Indian startup hacked the world” to comply with a preliminary court order issued …
2023-08-07
Who is this NPO Mashinostroyeniya victim? ▪️ RU missile and military spacecrafts (incl. ICBMs and hypersonic missiles). ▪️ Sanctioned RU entity, subsidiary of JSC Tactical Missiles Corporation KTRV. ▪️ India is NPO's second largest customer after Russia. [image]
Reuters
Researchers: North Korean hackers placed backdoors at Russian rocket design bureau NPO Mashinostroyeniya for at least five months in 2022 to see emails and more
An elite group of North Korean hackers secretly breached computer networks at a major Russian missile developer for at least five months …
🇷🇺🇰🇵 Comrades in Arms? | North Korea Compromises Sanctioned Russian Missile Engineering Company. DPRK threat actors possibly aiding North Korea's contentious missile program. Here's what we found.. 🧵 https://www.sentinelone.com/ ... #threatintel
Reuters
Researchers: North Korean hackers placed backdoors at Russian rocket design bureau NPO Mashinostroyeniya for at least five months in 2022 to see emails and more
An elite group of North Korean hackers secretly breached computer networks at a major Russian missile developer for at least five months …
Links to Lazarus and ScarCruft/Inky Squid/APT37 —> two sets of internal activity. 🌶️ Compromised Linux Email server —> ScarCruft Infra. 🌶️ Internal spread of Lazarus OpenCarrot backdoor. More details and new IOCs from @milenkowski and I: https://www.sentinelone.com/ ... #ThreatIntel [image]
Reuters
Researchers: North Korean hackers placed backdoors at Russian rocket design bureau NPO Mashinostroyeniya for at least five months in 2022 to see emails and more
An elite group of North Korean hackers secretly breached computer networks at a major Russian missile developer for at least five months …