OpenSSL Product Security Update Advisory (CVE-2026-2673)

OpenSSL Product Security Update Advisory (CVE-2026-2673)

overview We have released security updates to address vulnerabilities in our OpenSSL products. users of affected products are encouraged to update to the latest version. affected products CVE-2026-2673 OpenSSL Version: 3.6OpenSSL version: 3.5 resolved vulnerabilities Key Exchange Group Negotiation Error Vulnerability in OpenSSL (CVE-2026-2673) vulnerability patches Vulnerability patches have been

IBM Product Security Update Advisory

IBM Product Security Update Advisory

overview We have released security updates that address vulnerabilities in IBM products. users of affected products are encouraged to update to the latest version. affected products Cve-2025-14031, cve-2026-1264 IBM Sterling B2B Integrator and IBM Sterling File Gateway versions: 6.1.0.0 or later and 6.1.2.7_2 or earlierIBM Sterling B2B Integrator and IBM

March 24, 2026

March 24, 2026 Hash 1c44795a067b06ace75723f371bd9d2a9 200849284a419703dec3b5da437617144 3d7a29a707dbb39b1aa4ab713fd9113ad URL 1http[:]//203[.]251[.]133[.]225/ 2http[:]//foodexkorea[.]com/ 3https[:]//sivetsa[.]com/ IP 1103[.]172[.]204[.]219 2118[.]193[.]33[.]3 345[.]249[.]247[.]124...

March 23, 2026

March 23, 2026 Hash 1d05c2a211d094b1bdf4dc3d219a6f984 2a04bccbab729c4c143073462205ea41c 321f143d9e23b2399591f139790bc4823 URL 1https[:]//www[.]roblox[.]re/ 2https[:]//otrojah[.]org/ 3http[:]//loadfor[.]me/ IP 1197[.]211[.]55[.]20 2211[.]20[.]14[.]156 3221[.]139[.]88[.]149...

March 22, 2026

March 22, 2026 Hash 119b1d6d2ef94ca3c7987f7f402df541c 28731be68d19b03fd95b5410dfcbc548e 38e35276f42c915846b806f91daa6bf23 URL 1https[:]//pelisflix1[.]homes/ 2http[:]//pl27549832[.]effectivegatecpm[.]com/ 3http[:]//110[.]37[.]3[.]227[:]56419/bin[.]sh IP 1103[.]250[.]11[.]156 2103[.]191[.]92[.]65 3207[.]154[.]254[.]44...

March 21, 2026

March 21, 2026 Hash 1d4a689ab2c54790d8d9ae9f879b94789 26098ebe696cd481df10c313cbcca9450 3fd45cc805a861bc3bf8a4c0a904fa6a5 URL 1http[:]//to[.]lk/setdvc 2http[:]//xmartind[.]com/ 3http[:]//i657261756174686c6574696373o636f6dz[.]oszar[.]com/ IP 1103[.]13[.]207[.]34 243[.]160[.]211[.]132 3103[.]63[.]108[.]25...

March 20, 2026

March 20, 2026 Hash 11be12a86a061cbf2b2267e31729fa88a 22df21063d5a8f52cb69cc87988352456 3f30ec68327f1310f0d859e489680ff6d URL 1https[:]//opt[.]listarmor[.]com/unsub/HADx3CsXgcV6BOtJaNkSZ9Kh 2http[:]//lasopaster751[.]weebly[.]com/ 3https[:]//arizonasewersolution[.]com/ IP 1185[.]213[.]175[.]140 296[.]246[.]230[.]97 3120[.]48[.]181[.]192...

Attack Targeting MS‑SQL Servers to Deploy the ICE Cloud Scanner (Larva-26002)

Attack Targeting MS‑SQL Servers to Deploy the ICE Cloud Scanner (Larva-26002)

AhnLab SEcurity intelligence Center (ASEC) has confirmed that the Larva-26002 threat actor continues to target improperly managed MS-SQL servers in 2026. The Larva-26002 threat actor has distributed Trigona and Mimic ransomware in the past, and has since seized control of infected systems and installed scanners. The latest confirmed attack utilizes

March 19, 2026

March 19, 2026 Hash 19638f919cc9ff937195358497bda5ba3 2434f17a18590fc94d5e64ae70090cc7e 316c6a1ed6955f7102611e833425bac49 URL 1https[:]//macromex[.]mx/2023/12/crazy-attila-mobile-monkey-recipe 2https[:]//casualluxuryoffsites[.]com/ 3http[:]//172[.]245[.]95[.]24/inverstorrneeepng[.]png IP 1120[.]71[.]149[.]30 2114[.]34[.]106[.]146 345[.]138[.]16[.]234...

February 2026 APT Attack Trends Report (South Korea)

February 2026 APT Attack Trends Report (South Korea)

Overview   AhnLab utilizes its infrastructure to monitor for Advanced Persistent Threat (APT) attacks in South Korea. This report covers the classification and statistics on APT attacks on South Korea targets identified during the month of February 2026, and introduces the features of each type.  Figure 1. Statistics on APT