Metasploit Meterpreter Installed via Redis Server

Metasploit Meterpreter Installed via Redis Server

AhnLab SEcurity intelligence Center (ASEC) recently discovered that the Metasploit Meterpreter backdoor has been installed via the Redis service. Redis is an abbreviation of Remote Dictionary Server, which is an open-source in-memory data structure storage that is also used as a database. It is presumed that the threat actors abused

Util-linux Security Update Advisory (CVE-2024-28085)

Overview   We have released a security update to address a vulnerability in util-linux. users...

Google Android Family April 2024 Routine Security Update Advisory

Overview   Google(https://www.google.com) has released a security update that fixes vulnerabilities in the Android family...

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web cases  in March 2024

Security Issues in Korean & Global Financial Sector – Malware, Phishing, Deep Web & Dark Web cases in March 2024

Statistics on Malware Distributed to Financial Sectors   Statistics on Korean Accounts Exfiltrated Via Telegram by Industry   Phishing Email Distribution Cases Targeting the Financial Sector   Case 1. Targeting Korea Investment & Securities Co., Ltd. employees by disguising as a voice mail Impersonation target Voice mail How the Phishing

Linux Kernel Security Update Advisory (CVE-2024-1086)

Overview   The Linux Foundation has released a security update to address a vulnerability in...

Threat Actors Hack YouTube Channels to Distribute Infostealers (Vidar and LummaC2)

Threat Actors Hack YouTube Channels to Distribute Infostealers (Vidar and LummaC2)

AhnLab SEcurity intelligence Center (ASEC) recently found that there are a growing number of cases where threat actors use YouTube to distribute malware. The attackers do not simply create YouTube channels and distribute malware—they are stealing well-known channels that already exist to achieve their goal. In one of the cases,

XZ Utils Library Security Update Advisory (CVE-2024-3094)

Overview   We have released a security update to address a vulnerability in the XZ...