Visualização normal

Antes de ontemStream principal
  • ✇ASEC BLOG
  • Attack Targeting MS‑SQL Servers to Deploy the ICE Cloud Scanner (Larva-26002) ATCP
    AhnLab SEcurity intelligence Center (ASEC) has confirmed that the Larva-26002 threat actor continues to target improperly managed MS-SQL servers in 2026. The Larva-26002 threat actor has distributed Trigona and Mimic ransomware in the past, and has since seized control of infected systems and installed scanners. The latest confirmed attack utilizes the ICE Cloud Client, a […]
     

Attack Targeting MS‑SQL Servers to Deploy the ICE Cloud Scanner (Larva-26002)

Por:ATCP
19 de Março de 2026, 12:00
AhnLab SEcurity intelligence Center (ASEC) has confirmed that the Larva-26002 threat actor continues to target improperly managed MS-SQL servers in 2026. The Larva-26002 threat actor has distributed Trigona and Mimic ransomware in the past, and has since seized control of infected systems and installed scanners. The latest confirmed attack utilizes the ICE Cloud Client, a […]
  • ✇The DFIR Report
  • Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware editor
    Key Takeaways The DFIR Report Services Table of Contents: Case Summary In late June 2024, an unpatched Confluence server was compromised via CVE-2023-22527, a template injection vulnerability, first from IP address 45.227.254[.]124, which just ran whoami and exited. Shortly thereafter, a different IP address used the same exploit, running curl to deploy a Metasploit payload […] The post Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware appeared first on The DFIR Report.
     

Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware

Por:editor
18 de Maio de 2025, 21:05

Key Takeaways The DFIR Report Services Table of Contents: Case Summary In late June 2024, an unpatched Confluence server was compromised via CVE-2023-22527, a template injection vulnerability, first from IP address 45.227.254[.]124, which just ran whoami and exited. Shortly thereafter, a different IP address used the same exploit, running curl to deploy a Metasploit payload […]

The post Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware appeared first on The DFIR Report.

❌
❌