infoSource: SANS Internet Storm Center
AutoIT Payload Injector , (Tue, Jul 28th)
For a long time, AutoIT[ 1 ] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.
Read at the sourceSummary written for cymesh.dev. The full article lives at SANS Internet Storm Center.
Topics
Certificates expire quietly
cymesh.net watches your TLS and SSL certificates and warns you before one lapses.
monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks