BTC $61268.4851
ETH $3013.5712
BNB $571.5900
SOL $128.8916
stETH $3012.6804
XRP $0.4978
DOGE $0.1358
TON $5.1942
ADA $0.4322
AVAX $33.3191
TRX $0.1187
wstETH $3511.0861
WBTC $61287.2601
WETH $3014.0327
DOT $6.2811
BCH $438.1735
LINK $13.2360
MATIC $0.6651
UNI $7.1928
LTC $79.7723
ICP $12.6165
DAI $0.9999
FDUSD $0.9990
CAKE $2.5131
IMX $1.9662
RNDR $7.3377
NEAR $6.2471
ETC $25.6093
HBAR $0.0944
STX $2.2930
MNT $0.9595
FIL $5.6066
OKB $50.2572
PEPE $0.0000
VET $0.0367
ATOM $7.8045
KAS $0.1094
TAO $374.5752
WIF $2.4809
MKR $2658.3916
USDE $0.9987
GRT $0.2366
XMR $121.1078
AR $33.7602
FET $1.9776
XLM $0.1069
INJ $23.5717
BTC $61268.4851
ETH $3013.5712
BNB $571.5900
SOL $128.8916
stETH $3012.6804
XRP $0.4978
DOGE $0.1358
TON $5.1942
ADA $0.4322
AVAX $33.3191
TRX $0.1187
wstETH $3511.0861
WBTC $61287.2601
WETH $3014.0327
DOT $6.2811
BCH $438.1735
LINK $13.2360
MATIC $0.6651
UNI $7.1928
LTC $79.7723
ICP $12.6165
DAI $0.9999
FDUSD $0.9990
CAKE $2.5131
IMX $1.9662
RNDR $7.3377
NEAR $6.2471
ETC $25.6093
HBAR $0.0944
STX $2.2930
MNT $0.9595
FIL $5.6066
OKB $50.2572
PEPE $0.0000
VET $0.0367
ATOM $7.8045
KAS $0.1094
TAO $374.5752
WIF $2.4809
MKR $2658.3916
USDE $0.9987
GRT $0.2366
XMR $121.1078
AR $33.7602
FET $1.9776
XLM $0.1069
INJ $23.5717
  • Catalog
  • Blog
  • Tor Relay
  • Jabber
  • One-Time notes
  • Temp Email
  • What is TOR?
  • We are in tor
  • The APT29 group hacked into the network of European diplomatic institutions


    A vulnerability in the Credential Roaming function has become a weapon in the hands of attackers.

    The APT29 group used Credential Roaming after a successful phishing attack on an unnamed European diplomatic institution. This was reported by Mandiant experts, who discovered the use of Credential Roaming after hackers from APT29 visited the victim's network by executing many LDAP queries with atypical properties in the Active Directory system.

    Credential Roaming was first introduced in Windows Server 2003 Service Pack 1 (SP1) and is a mechanism that allows users to securely access their credentials (i.e. private keys and certificates) on different workstations in a Windows domain.

    After examining the internal mechanisms of the function, Mandiant discovered what the attackers took advantage of - the CVE-2022-30170 vulnerability, which allows hackers to write arbitrary files. This security flaw was fixed as part of the September Patch Tuesday, and to exploit it, an attacker would need to infiltrate the system under the guise of a user.

    According to the company's researchers, successful exploitation of the vulnerability allows an attacker to gain remote interactive login rights on a machine where the victim does not have such rights.

    Mandiant said the study "provides insight into why APT29 is actively querying the appropriate LDAP attributes in Active Directory" and urged organizations to apply the September fixes as soon as possible.

    Author DeepWeb
    The US has imposed a new package of sanctions against Tornado Cash
    New drama in the world of cryptocurrencies: why bitcoin sank below $16,000

    Comments 0

    Add comment