11 Dec 2024
Biztonsági szemle
VSCode Remote Tunnels exploited in suspected Chinese cyberespionage campaign
Threat actors behind the intrusions initially compromised internet-exposed apps and database servers with SQL injection before proceeding with PHPsert webshell distribution, reconnaissance, credential compromise, lateral movement, and custom Mimikatz injection for pass-the-hash intrusions, according to a joint report from SentinelOne SentinelLabs and Tinextra Cyber.
Read more