amsi (2)

31151147680?profile=RESIZE_400xCybersecurity researchers at Point Wild recently found a new way that cyber-attackers are gaining unauthorized access to computers.  The investigation, led by experts Kedar Shashikant Pandit, Prathamesh Shingare, and Amol Swami from the Lat61 Threat Intelligence Team, reveals that a common tool used by legitimate developers is being twisted by hackers to hide a nasty malware called XWorm.

Attack Details - The attack starts with a trick email or a fake software update, involving a harmless-lookin

13453722279?profile=RESIZE_400xCybercriminals are abusing a weakness in ASP.NET websites to remotely execute malicious code, according to Microsoft’s Threat Intelligence team, which has published an in-depth analysis of the new method.  In the article, Microsoft explained threat actors were injecting malicious code through a method called ViewState code injection attacks.

ViewState is a feature in ASP.NET websites that helps remember user input and page settings when the page is refreshed. It stores this information in a hidd