Τέσσερις ομάδες κατασκοπείας εκμεταλλεύονται κενά ασφαλείας σε Chrome και Windows

13 πηγές
  • Η Proofpoint ανακοίνωσε την Τετάρτη ότι ένα εργαλείο με την ονομασία BlueMoon συνδυάζει κενά ασφαλείας σε Chrome και Windows για να προσφέρει στους επιτιθέμενους πλήρη έλεγχο του συστήματος μέσω μηνυμάτων ηλεκτρονικού ψαρέματος (phishing).
  • Η πρώτη επιβεβαιωμένη χρήση προήλθε από την ομάδα APT31, που συνδέεται με την Κίνα, στις 28 Αυγούστου, με στόχο ΜΚΟ και εμπορικές εταιρείες στις ΗΠΑ. Τρεις ακόμη ομάδες υιοθέτησαν το εργαλείο μέσα σε λίγες ημέρες.
  • Οι ερευνητές εντόπισαν ενδείξεις ανάπτυξης exploits με τη βοήθεια τεχνητής νοημοσύνης, προειδοποιώντας ότι το εμπόδιο για την οπλοποίηση ευπαθειών σε προγράμματα περιήγησης ενδέχεται να μειώνεται.
Πηγές (13)
  1. 1 Once in a BlueMoon: Multiple State-Aligned Threat Actors ... www.proofpoint.com
  2. 2 Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week thehackernews.com
  3. 3 Multiple Chinese hacking groups seen using identical Chrome zero ... therecord.media
  4. 4 Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks cybersecuritynews.com
  5. 5 Novel Blue Moon kit targeting Chrome and Windows reflects new ... www.theregister.com
  6. 6 Chinese espionage groups swarm to exploit triple-link chain of zero ... cyberscoop.com
  7. 7 4 groups caught using the same Chrome and Windows exploit kit arstechnica.com
  8. 8 Chinese state-linked hackers exploit Chrome vulnerability - SC Media www.scworld.com
  9. 9 AI is collapsing the patch-gap window from weeks to days - Indoneo www.indoneo.com
  10. 10 New BlueMoon Exploit Kit Targets Chrome and Windows cyberwebspider.com
  11. 11 Cybersecurity Intelligence, News & Insights | Proofpoint US www.proofpoint.com
  12. 12 BlueMoon Exploit Kit Chains Chrome and Windows Flaws letsdatascience.com
  13. 13 RST Cloud (@rst_cloud) on X x.com