Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
AhnLab ASEC details the WhiteLock ransomware variant that encrypts files one by one while also disabling remote access tools on compromised systems. The ransomware leaves a distinctive white padlock icon on encrypted files.
This article warns about a phishing campaign that sends emails disguised as official Kakao account transfer notifications. The emails create anxiety and urge recipients to click a 'Verify Account' link, which leads to credential theft.
If files start getting locked one by one and even remote access tools stop working, your system may already be infected with ransomware.
Google Cloud Security explores how active ADFS signing keys can be recovered through machine DPAPI, enabling the Golden SAML attack technique first described in 2017. The research highlights that this persistence method remains a significant threat to federated identity environments.
Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem.
This article details how manually rotated ADFS certificates can leave active signing keys exposed in Machine DPAPI, creating 'ghost' certificates. Attackers can exploit these to forge SAML tokens without touching LSASS or the live ADFS service.