The MITRE Corporation was a victim of a cyber attack in late December 2023. It exploited zero-day flaws in Ivanti Connect Secure and created rogue virtual machines (VMs) within the VMware environment. This maneuver enabled them to avoid detection while maintaining persistent access. The attackers also deployed a web shell to launch a Python-based tunneling tool. Effective countermeasures suggested include enabling secure boot and using certain scripts to identify potential threats.
Infostealers Dominate as Lumma Stealer Detections Soar by Almost 400%
Cybersecurity firm ESET reported a 369% increase in detections of the Lumma Stealer infostealer malware in the second half of 2024. The malware targets two-factor