hachyderm.io is one of the many independent Mastodon servers you can use to participate in the fediverse.
Hachyderm is a safe space, LGBTQIA+ and BLM, primarily comprised of tech industry professionals world wide. Note that many non-user account types have restrictions - please see our About page.

Administered by:

Server stats:

9.5K
active users

#crowdstrike

3 posts3 participants0 posts today

Microsoft тестирует Быстрое Машинное Восстановление позволяющее восстанавливать компьютер с ошибками при загрузке

Новая функция призвана предотвратить широкомасштабные сбои, подобные тому, который был вызван обновлением Crowdstrike.

tefida.com/microsoft-tests-qui

#microsoft #quickmachinerecovery #windows11 #61203653 #windowsinsiderpreview #crowdstrike #bsod #windowsupdate #itадминистраторы #новостиit #tefidacom

[Перевод] CrowdStrike — 2025 — Global Threat Report (Отчет о глобальных угрозах) — Введение

Введение из отчета по глобальным угрозам от CrowdStrike Отчет о глобальных угрозах CrowdStrike 2025 анализирует ключевые тенденции в киберугрозах за 2024 год, подчеркивая растущую сложность и организованность атак. Основное внимание уделяется концепции «предприимчивого противника», который использует передовые технологии, включая генеративный ИИ, для усиления атак.

habr.com/ru/articles/896276/

ХабрCrowdStrike — 2025 — Global Threat Report (Отчет о глобальных угрозах) — ВведениеПредисловие Не стоит недооценивать современных предприимчивых противников Посмотрите любую передачу о природе, и вы быстро поймете, что происходит с животными, которые...

Shedding light on the ABYSSWORKER driver

The ABYSSWORKER driver is a malicious tool used in conjunction with MEDUSA ransomware to disable anti-malware systems. It employs a HEARTCRYPT-packed loader and a revoked certificate-signed driver to target and silence EDR vendors. The driver imitates a legitimate CrowdStrike Falcon driver and uses obfuscation techniques to hinder analysis. It provides various functionalities including file manipulation, process and driver termination, and EDR system disabling. The driver's capabilities include removing callbacks, replacing driver functions, killing system threads, and detaching mini-filter devices. It uses unconventional methods like creating IRPs from scratch to perform file operations. The malware's sophisticated approach demonstrates the evolving tactics of cybercriminals in evading detection and disabling security measures.

Pulse ID: 67dc31a079ea6b0ac92136ae
Pulse Link: otx.alienvault.com/pulse/67dc3
Pulse Author: AlienVault
Created: 2025-03-20 15:17:52

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

LevelBlue Open Threat ExchangeLevelBlue - Open Threat ExchangeLearn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.
Replied in thread

@ceotech Only proof that people make mistakes, especially in stressful situations.

Did you know that there is an immense threat of making followup misyakes or REALLY getting #hacked while you're going through an incident? Saw that with #crowdstrike

#cybersecurity is about #people at least as much if not more so than it is about #tech

Also a good reason to use services like simplelogin.io or buy your own domain and set up a #catchall so you can use a different mail address for each account