<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>CIRCL publications</title>
    <link>https://www.circl.lu/pub/tr-38/</link>
    <description>The latest CIRCL technical reports and publications.</description>
    <language>en-us</language>
    <lastBuildDate>Thu, 01 Oct 2026 00:00:00 &#43;0000</lastBuildDate>
    <atom:link href="https://www.circl.lu/pub/tr-38/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Publications and Presentations</title>
      <link>https://www.circl.lu/pub/</link>
      <pubDate>Thu, 01 Oct 2026 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/</guid>
      <description>Publications Description Last update TR-100 - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway 27th September 2026 TR-99 - Phishing Campaign Targeting Hotel Customers in Luxembourg 1st June 2026 TR-98 - Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp;amp; CVE-2026-1340) - Active Exploitation 9 February 2026 TR-97 - Supply Chain Compromise Propagating Through the npm Ecosystem (Shai-Hulud) 28 November 2025 TR-96 - Multiple Vulnerabilities in F5 Devices and Products - Impact and Mitigation 15 October 2025 TR-95 - Critical vulnerability - Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. CVE-2025-53770 - CVE-2025-53771 20 July 2025 CIRCL AI Strategy 20 June 2025 TR-94 - Ongoing Phishing Campaigns Targeting Microsoft 365 Tenants Lacking Multi-Factor Authentication 22 May 2025 TR-93 - Financial transaction fraud after system compromise via Remote Management and Monitoring tools 26 February 2025 TR-93 (de) - Finanzbetrug nach Systemkompromittierung über Remote-Management- und Monitoring-Tools 26 February 2025 TR-93 (fr) - Fraude financière après compromission du système via des outils de gestion et de surveillance à distance 26 February 2025 TR-92 - Unused Domain Names and the Risks of Missing DNS SPF Records 22 January 2025 TR-91 - Vulnerability identified as CVE-2024-0012, affecting Palo Alto Networks PAN-OS software 20 December 2024 TR-90 - Vulnerability identified as CVE-2023-34990, affecting Fortinet FortiWLM 20 December 2024 TR-89 - Guidelines for Notifying CSIRT/CERT of Red Teaming and Penetration Testing Exercises 12 November 2024 TR-88 - Motivation, procedure and rationale for leaked credential notifications 30 August 2024 Learning from the Recent Windows/Falcon Sensor Outage: Causes and Potential Improvement Strategies in Linux Using Open Source Solutions 23rd July 2024 TR-87 - CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor 19th July 2024 TR-86 - Check Point VPN Information Disclosure (CVE-2024-24919) - Actively Exploited 31st May 2024 TR-85 - Three vulnerabilities in Cisco ASA software/appliance and FTD software being exploited 25th April 2024 TR-84 - PAN-OS (Palo Alto Networks) OS Command Injection Vulnerability in GlobalProtect Gateway - CVE-2024-3400 12th April 2024 TR-83 - Linux Boot Hardening HOWTO 3rd April 2024 TR-82 - backdoor discovered in xz-utils - CVE-2024-3094 30th March 2024 TR-81 - Critical FortiOS vulnerabilities in sslvpnd and fgfmd 9 February 2024 TR-80 - Targeted SMS and fake phone center call targeting financial/banking services 7 February 2024 TR-79 - AnyDesk Incident and Potential Associated Supply Chain Attack 5 February 2024 TR-78 - CVE-2023-46805 (Authentication Bypass) &amp;amp; CVE-2024-21887 (Command Injection) for Ivanti Connect Secure and Ivanti Policy Secure Gateways 11 January 2024 TR-77 - Spear phishing and voice call scams targeting corporate executives and their accounting department 30 August 2023 TR-76 - Multiple high severity vulnerabilities in CODESYS V3 SDK could lead to RCE or DoS 14 August 2023 TR-75 - Unauthenticated remote code execution vulnerability in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) - CVE-2023-3519 21 July 2023 TR-74 - A heap-based buffer overflow vulnerability (CWE-122) in FortiOS - CVE-2023-27997 5 July 2023 TR-73 - Ransomware FAQ 7 March 2023 TR-72 - Vulnerable Microsoft Exchange server metrics leading to alarming situation 21 February 2023 TR-71 - FortiOS - heap-based buffer overflow in sslvpnd (exploited) - FortiOS SSL-VPN - CVE-2022-42475 13 December 2022 TR-70 - Vulnerabilities in Microsoft Exchange CVE-2022-41040 - CVE-2022-41082 30 September 2022 TR-69 - How to choose an ICT supplier from a security perspective 13 June 2022 TR-68 - Best practices in times of tense geopolitical situations 28 February 2022 TR-67 - local privilege escalation vulnerability in polkit’s pkexec utility 26 January 2022 TR-66 - Webservers with mod_status like debug modules publicly available leak information 15 December 2021 TR-65 - Vulnerabilities and Exploitation of Log4j (Remote code injection in Log4j) 10 December 2021 TR-64 - Exploited Exchange Servers - Mails with links to malware from known/valid senders 10 November 2021 TR-63 - Vulnerabilities and Exploitation of Pulse Connect Secure 21 April 2021 TR-62 - Leak of Facebook Data from 533 Million Users 6 April 2021 TR-61 - Critical vulnerabilities in Microsoft Exchange 12 March 2021 TR-60 - Phishing - Effects and precautions 26 June 2020 TR-59 - Remote Work - In times of a crisis 18 March 2020 TR-58 - CVE-2020-0796 - Critical vulnerability in Microsoft SMBv3 - status and mitigation 11 March 2020 TR-57 - Ransomware - Effects and precautions 10 December 2019 TR-56 - HTTP Strict Transport Security 19 March 2019 TR-55 - SquashFu - an alternate Open Source Backup solution, resilient to Crypto Ransomware attacks 12 September 2018 TR-54 - Sextortion scam emails - I know your password 3 August 2018 TR-53 - Statement about WHOIS and GDPR 12 April 2018 TR-52 - Forensic Analysis of an HID Attack 5 February 2018 TR-51 - How to react to fraudulent acts of third party invoicing or requesting funds without showing any purchase order 23 November 2017 TR-50 - WPA2 handshake traffic can be manipulated to induce nonce and session key reuse 16 October 2017 TR-49 - CVE-2017-7494 - A critical vulnerability in Samba - remote code execution from a writable share 26 May 2017 TR-48 - Cyber-Threats Indicators Sharing, security-related actionable information and future of Personal Data Protection framework in the EU - MISP and GDPR 6 March 2017 TR-47 - Recommendations regarding Abuse handling for ISPs and registrars 23 February 2017 TR-46 - Information Leaks Affecting Luxembourg and Recommendations 17 February 2017 TR-45 - Data recovery techniques 12 May 2016 TR-44 - Information security - laws and specific rulings in the Grand Duchy of Luxembourg 15 March 2016 TR-43 - Installing MPSS 3.6.1 to use a Intel Xeon Phi Coprocessor on Ubuntu Trusty 14.04 LTS 11 January 2016 TR-42 - CVE-2015-7755 - CVE-2015-7756 - Critical vulnerabilities in Juniper ScreenOS 21 December 2015 TR-41 (de) - Crypto Ransomware - Vorsichtsmaßnahmen und Verhalten im Infektionsfall 19 May 2016 TR-41 (fr) - Crypto Ransomware - Défenses proactives et de réponse sur incident 19 May 2016 TR-41 - Crypto Ransomware - Proactive defenses and incident response 13 May 2017 TR-40 - Allaple worm activity in 2015 and long-term persistence of worm (malware) in Local Area Networks 24 September 2015 TR-39 - CIRCL-SOPs Standard Operational Procedures 30 July 2015 TR-38 - Attacks targeting enterprise banking solutions - recommendations and remediations 9 May 2017 TR-37 - VENOM / CVE-2015-3456 - Critical vulnerability in QEMU Floppy Disk Controller (FDC) emulation 14 May 2015 TR-36 - Example setup of WordPress with static export 28 April 2015 TR-34 - How to view and extract raw messages in common email clients 13 March 2015 TR-33 - Analysis - CTB-Locker / Critroni 17 February 2015 TR-32 - key-value store and NoSQL security recommendations 10 February 2015 TR-31 - GHOST / CVE-2015-0235 - glibc vulnerability - gethostbyname 29 January 2015 TR-30 - Acquisition Support Tools for Local Incident Response Teams (LIRT) 16 December 2020 TR-29 - NTP (Network Time Protocol) daemon - ntpd - critical vulnerabilities 2 January 2015 TR-28 - The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, are vulnerable to critical padding oracle attack - CVE-2014-3566 15 October 2014 TR-27 - GNU Bash Critical Vulnerability - CVE-2014-6271 - CVE-2014-7169 10 October 2014 TR-26 - Security Recommendations for Web Content Management Systems and Web Servers 28 April 2015 TR-25 - Analysis - Turla/Pfinet/Snake/Uroburos/Pfinet 10 July 2014 TR-24 - Analysis - Destory RAT family 3 June 2014 TR-23 - Analysis - NetWiredRC malware 26 November 2014 TR-22 - Practical Recommendations for Readiness to Handle Computer Security Incidents 15 December 2020 TR-21 - OpenSSL Heartbeat Critical Vulnerability 17 April 2014 TR-20 - Port evolution: a software to find the shady IP profiles in Netflow 18 February 2014 Training And Technical Courses Catalogue 2014 29 January 2014 TR-19 - UDP Protocols Security - Recommendations To Avoid or Limit DDoS amplification 8 July 2015 TR-18 - PBX and VoIP Security - Recommendations 19 February 2014 TR-17 - Java.Tomdep (Apache Tomcat Malware) - Information, Detection and Recommendation 22 November 2013 TR-16 - HoneyBot Services - Client Data Collection 14 October 2013 TR-15 - Hand of Thief/Hanthie Linux Malware - Detection and Remediation 29 August 2013 TR-14 - Analysis of a stage 3 Miniduke malware sample 3 July 2014 TR-13 - Malware analysis report of a Backdoor.Snifula variant 29 May 2013 TR-12 - Analysis of a PlugX malware variant used for targeted attacks 17 January 2014 TR-11 - Security Flaws in Universal Plug and Play (UPnP) 30 January 2013 TR-10 - Red October / Sputnik malware 16 January 2013 TR-09 - Malware Discovery and potential Removal (Windows 7) 31 August 2012 CIRCL 2011 trend report 29 August 2012 TR-08 - CIRCL automatic launch object detection for Mac OS X 23 January 2015 TR-07 - HOWTO find SMTP headers in common Email clients 13 March 2015 TR-06 - DigiNotar incident and general SSL/TLS security consequences 7 September 2011 TR-05 - SSL/TLS Security of Servers in Luxembourg 22 August 2011 Academic Publications Publication Authors Date Mapping CVEs to MITRE ATT&amp;amp;CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion (PDF) Cédric Bonhomme, Alexandre Dulaunoy 28 July 2026 GCVE: A Decentralized Model for Vulnerability Identification, Publication, and Operational Enrichment (PDF) Alexandre Dulaunoy 30 May 2026 Modeling Sparse and Bursty Vulnerability Sightings: Forecasting Under Data Constraints (PDF) Cédric Bonhomme, Alexandre Dulaunoy 17 April 2026 VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification (PDF) Cédric Bonhomme, Alexandre Dulaunoy 4 July 2025 Active and Passive Collection of SSH key material for cyber threat intelligence (PDF, DOI) Alexandre Dulaunoy, Jean-Louis Huynen, Aurélien Thirion 11 April 2022 Taxonomy driven indicator scoring in MISP threat intelligence platforms (PDF) Sami Mokaddem, Gérard Wagener, Alexandre Dulaunoy, András Iklódy 8 February 2019 Decaying Indicators of Compromise (PDF) András Iklódy, Gérard Wagener, Alexandre Dulaunoy, Sami Mokaddem, Cynthia Wagner 29 March 2018 MISP: The design and implementation of a collaborative threat intelligence sharing platform (PDF) Cynthia Wagner, Alexandre Dulaunoy, Gérard Wagener, András Iklódy 2016 Torinj: Automated Exploitation Malware Targeting Tor Users (PDF) Gérard Wagener, Alexandre Dulaunoy, Radu State 14 August 2012 Presentations Description Last update GCVE at Vulnopticon 2026 28th September 2026 GCVE Workshop before Vulnopticon 2026 - slides and materials 23rd September 2026 CSIRT Tooling: Best Practices in Developing, Maintaining and Distributing Open Source Tools 8th November 2018 Fail frequently to avoid disaster or how to organically build a threat intel sharing standard 7th December 2017 How to better understand DDoS attacks from a post-mortem analysis perspective using backscatter traffic Luxembourg Internet Days 2017 15th November 2017 DDoS and Attribution: Observations of Attacks against North Korea 15th November 2017 IoT dinosaurs - don’t die out 24 October 2017 An extended analysis of an IoT malware from a blackhole network 1st June 2017 Challenges for law firms: IT security threats and incidents for law firms - practical examples 12 May 2017 Honeypots Observations and Their Usefulness 15 March 2017 Introduction to Forensic at the #cybersecurity4success conference 3 October 2016 Data Mining in Incident Response - Challenges and Opportunities 13 May 2016 Experiences with Paste-Monitoring 18 March 2016 Four years of practical information sharing MISP &amp;amp; Threat Sharing 25th February 2016 Information Sharing and Taxonomies Practical Classification of Threat Indicators using MISP 26th January 2016 Improving Data Sharing to Increase Security Research Opportunities 2nd November 2015 cve-search - a free software to collect, search and analyse common vulnerabilities and exposures in software 9th October 2015 Protect your data, protect your life. Data Destruction Day 22nd September 2015 New ZeroMQ functionality in MISP 2nd July 2015 Sharing Threat Indicators and Security Ranking, an opportunity for the Internet Community 18 November 2014 Attackers benefit from sharing information. How can you benefit, too? at ICTSpring 4 July 2014 The void - An interesting place for network security monitoring Cynthia Wagner, Marc Stiefer (RESTENA), Alexandre Dulaunoy, Gérard Wagener (CIRCL) at TNC 2014 19 May 2014 Information Sharing Cornerstone in Incident Detection and Handling at DBIR presentation in Paris 15 May 2014 Darknet and Black Hole Monitoring a Journey into Typographic Errors at Honeynet Project Workshop in Warsaw 12 May 2014 An Overview of Security Incidents Targeting Citizen How the Attackers Are Deceiving Us? 15 March 2014 Passive DNS - Common Output Format 14 February 2014 Who targets the journalists? and how? A review of the attack surface in our digital society 7 February 2014 MISP or How to Share Efficiently IOCs Within a Country 26 July 2013 BGP Ranking Scoring ASNs Based on Their Potential Maliciousness 23 June 2013 ASMATRA: Ranking ASs Providing Transit Service to Malware Hosters 29 May 2013 Another Perspective to IP-Darkspace Analysis 29 January 2013 The Digital First Aid Kit The Digital First Aid Kit aims to provide preliminary support for people facing the most common types of digital threats. The Kit offers a set of self-diagnostic tools for citizen, human rights defenders, bloggers, activists and journalists fac ing attacks themselves, as well as providing guidelines for digital first responders to assist a person under threat.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="publications">Publications</h2>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Description</th>
					<th style="text-align: center">Last update</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><a href="./tr-100">TR-100 - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway</a></td>
					<td style="text-align: center">27th September 2026</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-99">TR-99 - Phishing Campaign Targeting Hotel Customers in Luxembourg</a></td>
					<td style="text-align: center">1st June 2026</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-98">TR-98 - Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp; CVE-2026-1340) - Active Exploitation</a></td>
					<td style="text-align: center">9 February 2026</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-97">TR-97 - Supply Chain Compromise Propagating Through the npm Ecosystem (Shai-Hulud)</a></td>
					<td style="text-align: center">28 November 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-96">TR-96 - Multiple Vulnerabilities in F5 Devices and Products - Impact and Mitigation</a></td>
					<td style="text-align: center">15 October 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-95">TR-95 - Critical vulnerability - Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. CVE-2025-53770 - CVE-2025-53771</a></td>
					<td style="text-align: center">20 July 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./ai-strategy/">CIRCL AI Strategy</a></td>
					<td style="text-align: center">20 June 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-94">TR-94 - Ongoing Phishing Campaigns Targeting Microsoft 365 Tenants Lacking Multi-Factor Authentication</a></td>
					<td style="text-align: center">22 May 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-93">TR-93 - Financial transaction fraud after system compromise via Remote Management and Monitoring tools</a></td>
					<td style="text-align: center">26 February 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-93/de/">TR-93 (de) - Finanzbetrug nach Systemkompromittierung über Remote-Management- und Monitoring-Tools</a></td>
					<td style="text-align: center">26 February 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-93/fr/">TR-93 (fr) - Fraude financière après compromission du système via des outils de gestion et de surveillance à distance</a></td>
					<td style="text-align: center">26 February 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-92">TR-92 - Unused Domain Names and the Risks of Missing DNS SPF Records</a></td>
					<td style="text-align: center">22 January 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-91">TR-91 - Vulnerability identified as CVE-2024-0012, affecting Palo Alto Networks PAN-OS software</a></td>
					<td style="text-align: center">20 December 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-90">TR-90 - Vulnerability identified as CVE-2023-34990, affecting Fortinet FortiWLM</a></td>
					<td style="text-align: center">20 December 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-89">TR-89 - Guidelines for Notifying CSIRT/CERT of Red Teaming and Penetration Testing Exercises</a></td>
					<td style="text-align: center">12 November 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-88">TR-88 - Motivation, procedure and rationale for leaked credential notifications</a></td>
					<td style="text-align: center">30 August 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./learning-from-falcon-sensor-outage/">Learning from the Recent Windows/Falcon Sensor Outage: Causes and Potential Improvement Strategies in Linux Using Open Source Solutions</a></td>
					<td style="text-align: center">23rd July 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-87">TR-87 - CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor</a></td>
					<td style="text-align: center">19th July 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-86">TR-86 - Check Point VPN Information Disclosure (CVE-2024-24919) - Actively Exploited</a></td>
					<td style="text-align: center">31st May 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-85">TR-85 - Three vulnerabilities in Cisco ASA software/appliance and FTD software being exploited</a></td>
					<td style="text-align: center">25th April 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-84">TR-84 - PAN-OS (Palo Alto Networks) OS Command Injection Vulnerability in GlobalProtect Gateway - CVE-2024-3400</a></td>
					<td style="text-align: center">12th April 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-83">TR-83 - Linux Boot Hardening HOWTO</a></td>
					<td style="text-align: center">3rd April 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-82">TR-82 - backdoor discovered in xz-utils - CVE-2024-3094</a></td>
					<td style="text-align: center">30th March 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-81">TR-81 - Critical FortiOS vulnerabilities in sslvpnd and fgfmd </a></td>
					<td style="text-align: center">9 February 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-80">TR-80 - Targeted SMS and fake phone center call targeting financial/banking services</a></td>
					<td style="text-align: center">7 February 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-79">TR-79 - AnyDesk Incident and Potential Associated Supply Chain Attack</a></td>
					<td style="text-align: center">5 February 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-78">TR-78 - CVE-2023-46805 (Authentication Bypass) &amp; CVE-2024-21887 (Command Injection) for Ivanti Connect Secure and Ivanti Policy Secure Gateways</a></td>
					<td style="text-align: center">11 January 2024</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-77">TR-77 - Spear phishing and voice call scams targeting corporate executives and their accounting department</a></td>
					<td style="text-align: center">30 August 2023</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-76">TR-76 - Multiple high severity vulnerabilities in CODESYS V3 SDK could lead to RCE or DoS</a></td>
					<td style="text-align: center">14 August 2023</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-75">TR-75 - Unauthenticated remote code execution vulnerability in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) - CVE-2023-3519</a></td>
					<td style="text-align: center">21 July 2023</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-74">TR-74 - A heap-based buffer overflow vulnerability (CWE-122) in FortiOS - CVE-2023-27997</a></td>
					<td style="text-align: center">5 July 2023</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-73">TR-73 - Ransomware FAQ</a></td>
					<td style="text-align: center">7 March 2023</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-72">TR-72 - Vulnerable Microsoft Exchange server metrics leading to alarming situation</a></td>
					<td style="text-align: center">21 February 2023</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-71">TR-71 - FortiOS - heap-based buffer overflow in sslvpnd (exploited) - FortiOS SSL-VPN - CVE-2022-42475</a></td>
					<td style="text-align: center">13 December 2022</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-70">TR-70 - Vulnerabilities in Microsoft Exchange CVE-2022-41040 - CVE-2022-41082</a></td>
					<td style="text-align: center">30 September 2022</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-69">TR-69 - How to choose an ICT supplier from a security perspective</a></td>
					<td style="text-align: center">13 June 2022</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-68">TR-68 - Best practices in times of tense geopolitical situations</a></td>
					<td style="text-align: center">28 February 2022</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-67">TR-67 - local privilege escalation vulnerability in polkit&rsquo;s pkexec utility</a></td>
					<td style="text-align: center">26 January 2022</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-66">TR-66 - Webservers with mod_status like debug modules publicly available leak information</a></td>
					<td style="text-align: center">15 December 2021</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-65">TR-65 - Vulnerabilities and Exploitation of Log4j (Remote code injection in Log4j)</a></td>
					<td style="text-align: center">10 December 2021</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-64">TR-64 - Exploited Exchange Servers - Mails with links to malware from known/valid senders</a></td>
					<td style="text-align: center">10 November 2021</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-63">TR-63 - Vulnerabilities and Exploitation of Pulse Connect Secure</a></td>
					<td style="text-align: center">21 April 2021</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-62">TR-62 - Leak of Facebook Data from 533 Million Users</a></td>
					<td style="text-align: center">6 April 2021</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-61">TR-61 - Critical vulnerabilities in Microsoft Exchange</a></td>
					<td style="text-align: center">12 March 2021</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-60">TR-60 - Phishing - Effects and precautions</a></td>
					<td style="text-align: center">26 June 2020</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-59">TR-59 - Remote Work - In times of a crisis</a></td>
					<td style="text-align: center">18 March 2020</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-58">TR-58 - CVE-2020-0796 - Critical vulnerability in Microsoft SMBv3 - status and mitigation</a></td>
					<td style="text-align: center">11 March 2020</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-57">TR-57 - Ransomware - Effects and precautions</a></td>
					<td style="text-align: center">10 December 2019</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-56">TR-56 - HTTP Strict Transport Security</a></td>
					<td style="text-align: center">19 March 2019</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-55">TR-55 - SquashFu - an alternate Open Source Backup solution, resilient to Crypto Ransomware attacks</a></td>
					<td style="text-align: center">12 September 2018</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-54">TR-54 - Sextortion scam emails - I know your password</a></td>
					<td style="text-align: center">3 August 2018</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-53">TR-53 - Statement about WHOIS and GDPR</a></td>
					<td style="text-align: center">12 April 2018</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-52">TR-52 - Forensic Analysis of an HID Attack</a></td>
					<td style="text-align: center">5 February 2018</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-51">TR-51 - How to react to fraudulent acts of third party invoicing or requesting funds without showing any purchase order</a></td>
					<td style="text-align: center">23 November 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-50">TR-50 - WPA2 handshake traffic can be manipulated to induce nonce and session key reuse</a></td>
					<td style="text-align: center">16 October 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-49">TR-49 - CVE-2017-7494 - A critical vulnerability in Samba - remote code execution from a writable share</a></td>
					<td style="text-align: center">26 May 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-48">TR-48 - Cyber-Threats Indicators Sharing, security-related actionable information and future of Personal Data Protection framework in the EU - MISP and GDPR</a></td>
					<td style="text-align: center">6 March 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-47">TR-47 - Recommendations regarding Abuse handling for ISPs and registrars</a></td>
					<td style="text-align: center">23 February 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-46">TR-46 - Information Leaks Affecting Luxembourg and Recommendations</a></td>
					<td style="text-align: center">17 February 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-45">TR-45 - Data recovery techniques</a></td>
					<td style="text-align: center">12 May 2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-44">TR-44 - Information security - laws and specific rulings in the Grand Duchy of Luxembourg</a></td>
					<td style="text-align: center">15 March 2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-43">TR-43 - Installing MPSS 3.6.1 to use a Intel Xeon Phi Coprocessor on Ubuntu Trusty 14.04 LTS</a></td>
					<td style="text-align: center">11 January 2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-42/">TR-42 - CVE-2015-7755 - CVE-2015-7756 - Critical vulnerabilities in Juniper ScreenOS</a></td>
					<td style="text-align: center">21 December 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-41/de/">TR-41 (de) - Crypto Ransomware - Vorsichtsmaßnahmen und Verhalten im Infektionsfall</a></td>
					<td style="text-align: center">19 May 2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-41/fr/">TR-41 (fr) - Crypto Ransomware - Défenses proactives et de réponse sur incident</a></td>
					<td style="text-align: center">19 May 2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-41/">TR-41 - Crypto Ransomware - Proactive defenses and incident response</a></td>
					<td style="text-align: center">13 May 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-40/">TR-40 - Allaple worm activity in 2015 and long-term persistence of worm (malware) in Local Area Networks</a></td>
					<td style="text-align: center">24 September 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-39">TR-39 - CIRCL-SOPs Standard Operational Procedures</a></td>
					<td style="text-align: center">30 July 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-38">TR-38 - Attacks targeting enterprise banking solutions - recommendations and remediations</a></td>
					<td style="text-align: center">9 May 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-37">TR-37 - VENOM / CVE-2015-3456 - Critical vulnerability in QEMU Floppy Disk Controller (FDC) emulation</a></td>
					<td style="text-align: center">14 May 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-36/">TR-36 - Example setup of WordPress with static export</a></td>
					<td style="text-align: center">28 April 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-34">TR-34 - How to view and extract raw messages in common email clients</a></td>
					<td style="text-align: center">13 March 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-33">TR-33 - Analysis - CTB-Locker / Critroni</a></td>
					<td style="text-align: center">17 February 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-32">TR-32 - key-value store and NoSQL security recommendations</a></td>
					<td style="text-align: center">10 February 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-31">TR-31 - GHOST / CVE-2015-0235 - glibc vulnerability - gethostbyname</a></td>
					<td style="text-align: center">29 January 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-30">TR-30 - Acquisition Support Tools for Local Incident Response Teams (LIRT)</a></td>
					<td style="text-align: center">16 December 2020</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-29">TR-29 - NTP (Network Time Protocol) daemon - ntpd - critical vulnerabilities</a></td>
					<td style="text-align: center">2 January 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-28">TR-28 - The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, are vulnerable to critical padding oracle attack - CVE-2014-3566</a></td>
					<td style="text-align: center">15 October 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-27">TR-27 - GNU Bash Critical Vulnerability - CVE-2014-6271 - CVE-2014-7169</a></td>
					<td style="text-align: center">10 October 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-26">TR-26 - Security Recommendations for Web Content Management Systems and Web Servers</a></td>
					<td style="text-align: center">28 April 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-25">TR-25 - Analysis - Turla/Pfinet/Snake/Uroburos/Pfinet</a></td>
					<td style="text-align: center">10 July 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-24">TR-24 - Analysis - Destory RAT family</a></td>
					<td style="text-align: center">3 June 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-23">TR-23 - Analysis - NetWiredRC malware</a></td>
					<td style="text-align: center">26 November 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-22">TR-22 - Practical Recommendations for Readiness to Handle Computer Security Incidents</a></td>
					<td style="text-align: center">15 December 2020</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-21">TR-21 - OpenSSL Heartbeat Critical Vulnerability</a></td>
					<td style="text-align: center">17 April 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-20/">TR-20 - Port evolution: a software to find the shady IP profiles in Netflow</a></td>
					<td style="text-align: center"> 18 February 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/circl-training-2014.pdf">Training And Technical Courses Catalogue 2014</a></td>
					<td style="text-align: center"> 29 January 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-19/">TR-19 - UDP Protocols Security - Recommendations To Avoid or Limit DDoS amplification</a></td>
					<td style="text-align: center"> 8 July 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-18/">TR-18 - PBX and VoIP Security - Recommendations</a></td>
					<td style="text-align: center"> 19 February 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-17/">TR-17 - Java.Tomdep (Apache Tomcat Malware) - Information, Detection and Recommendation</a></td>
					<td style="text-align: center"> 22 November 2013</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-16/">TR-16 - HoneyBot Services - Client Data Collection</a></td>
					<td style="text-align: center"> 14 October 2013</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-15/">TR-15 - Hand of Thief/Hanthie Linux Malware - Detection and Remediation</a></td>
					<td style="text-align: center"> 29 August 2013</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-14/">TR-14 - Analysis of a stage 3 Miniduke malware sample</a></td>
					<td style="text-align: center"> 3 July 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-13/">TR-13 - Malware analysis report of a Backdoor.Snifula variant</a></td>
					<td style="text-align: center">29 May 2013 </td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-12/">TR-12 - Analysis of a PlugX malware variant used for targeted attacks</a></td>
					<td style="text-align: center">17 January 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-11/">TR-11 - Security Flaws in Universal Plug and Play (UPnP)</a></td>
					<td style="text-align: center">30 January 2013</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-10/">TR-10 - Red October / Sputnik malware</a></td>
					<td style="text-align: center">16 January 2013</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-09/">TR-09 - Malware Discovery and potential Removal (Windows 7)</a></td>
					<td style="text-align: center">31 August 2012</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/CIRCL-trendreport-2011.pdf">CIRCL 2011 trend report</a></td>
					<td style="text-align: center">29 August 2012</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-08/">TR-08 - CIRCL automatic launch object detection for Mac OS X</a></td>
					<td style="text-align: center">23 January 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-07/">TR-07 - HOWTO find SMTP headers in common Email clients</a></td>
					<td style="text-align: center">13 March 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-06/">TR-06 - DigiNotar incident and general SSL/TLS security consequences</a></td>
					<td style="text-align: center">7 September 2011</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="./tr-05/">TR-05 - SSL/TLS Security of Servers in Luxembourg</a></td>
					<td style="text-align: center">22 August 2011</td>
			</tr>
	</tbody>
</table>
<h2 id="academic-publications">Academic Publications</h2>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Publication</th>
					<th style="text-align: left">Authors</th>
					<th style="text-align: center">Date</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><a href="https://arxiv.org/abs/2607.25572">Mapping CVEs to MITRE ATT&amp;CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion</a> (<a href="https://arxiv.org/pdf/2607.25572">PDF</a>)</td>
					<td style="text-align: left">Cédric Bonhomme, Alexandre Dulaunoy</td>
					<td style="text-align: center">28 July 2026</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="https://arxiv.org/abs/2606.00856">GCVE: A Decentralized Model for Vulnerability Identification, Publication, and Operational Enrichment</a> (<a href="https://arxiv.org/pdf/2606.00856">PDF</a>)</td>
					<td style="text-align: left">Alexandre Dulaunoy</td>
					<td style="text-align: center">30 May 2026</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="https://arxiv.org/abs/2604.16038">Modeling Sparse and Bursty Vulnerability Sightings: Forecasting Under Data Constraints</a> (<a href="https://arxiv.org/pdf/2604.16038">PDF</a>)</td>
					<td style="text-align: left">Cédric Bonhomme, Alexandre Dulaunoy</td>
					<td style="text-align: center">17 April 2026</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="https://arxiv.org/abs/2507.03607">VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification</a> (<a href="https://arxiv.org/pdf/2507.03607">PDF</a>)</td>
					<td style="text-align: left">Cédric Bonhomme, Alexandre Dulaunoy</td>
					<td style="text-align: center">4 July 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="https://arxiv.org/abs/2204.04922">Active and Passive Collection of SSH key material for cyber threat intelligence</a> (<a href="https://arxiv.org/pdf/2204.04922">PDF</a>, <a href="https://doi.org/10.1145/3491262">DOI</a>)</td>
					<td style="text-align: left">Alexandre Dulaunoy, Jean-Louis Huynen, Aurélien Thirion</td>
					<td style="text-align: center">11 April 2022</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="https://arxiv.org/abs/1902.03914">Taxonomy driven indicator scoring in MISP threat intelligence platforms</a> (<a href="https://arxiv.org/pdf/1902.03914">PDF</a>)</td>
					<td style="text-align: left">Sami Mokaddem, Gérard Wagener, Alexandre Dulaunoy, András Iklódy</td>
					<td style="text-align: center">8 February 2019</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="https://arxiv.org/abs/1803.11052">Decaying Indicators of Compromise</a> (<a href="https://arxiv.org/pdf/1803.11052">PDF</a>)</td>
					<td style="text-align: left">András Iklódy, Gérard Wagener, Alexandre Dulaunoy, Sami Mokaddem, Cynthia Wagner</td>
					<td style="text-align: center">29 March 2018</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="https://scholar.google.com/citations?view_op=view_citation&amp;hl=en&amp;user=SxxEvVMAAAAJ&amp;citation_for_view=SxxEvVMAAAAJ:XoXfffV-tXoC">MISP: The design and implementation of a collaborative threat intelligence sharing platform</a> (<a href="https://dl.acm.org/doi/pdf/10.1145/2994539.2994542">PDF</a>)</td>
					<td style="text-align: left">Cynthia Wagner, Alexandre Dulaunoy, Gérard Wagener, András Iklódy</td>
					<td style="text-align: center">2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="https://arxiv.org/abs/1208.2877">Torinj: Automated Exploitation Malware Targeting Tor Users</a> (<a href="https://arxiv.org/pdf/1208.2877">PDF</a>)</td>
					<td style="text-align: left">Gérard Wagener, Alexandre Dulaunoy, Radu State</td>
					<td style="text-align: center">14 August 2012</td>
			</tr>
	</tbody>
</table>
<h2 id="presentations">Presentations</h2>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Description</th>
					<th style="text-align: center">Last update</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><a href="https://gcve.eu/2026/09/28/gcve-at-vulnopticon-2026/">GCVE at Vulnopticon 2026</a></td>
					<td style="text-align: center">28th September 2026</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="https://gcve.eu/2026/09/23/gcve-workshop-before-vulnopticon-2026-slides-and-materials/">GCVE Workshop before Vulnopticon 2026 - slides and materials</a></td>
					<td style="text-align: center">23rd September 2026</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/csirt-tooling-policy.pdf">CSIRT Tooling: Best Practices in Developing, Maintaining and Distributing Open Source Tools</a></td>
					<td style="text-align: center">8th November 2018</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/20171207-FIRST-OASIS-CTI-Prague.pdf">Fail frequently to avoid disaster or how to organically build a threat intel sharing standard</a></td>
					<td style="text-align: center">7th December 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/20171115-LIDS-DDOS-workshop.pdf">How to better understand DDoS attacks from a post-mortem analysis perspective using backscatter traffic Luxembourg Internet Days 2017</a></td>
					<td style="text-align: center">15th November 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/20171115-LIDS-DDOS-NorthKorea.pdf">DDoS and Attribution: Observations of Attacks against North Korea</a></td>
					<td style="text-align: center">15th November 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/20171024-meetup-datascience.pdf">IoT dinosaurs - don’t die out</a></td>
					<td style="text-align: center">24 October 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/tnc17_paper_Fullpaper-IoTBlackholeCW.pdf">An extended analysis of an IoT malware from a blackhole network</a></td>
					<td style="text-align: center">1st June 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/files/20170512-Legalink.pdf">Challenges for law firms: IT security threats and incidents for law firms - practical examples</a></td>
					<td style="text-align: center">12 May 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/circl-isaca-lux-20170315.pdf">Honeypots Observations and Their Usefulness</a></td>
					<td style="text-align: center">15 March 2017</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/hamm-forensic-2016.pdf">Introduction to Forensic at the #cybersecurity4success conference</a></td>
					<td style="text-align: center">3 October 2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/circl-datamining-incidentresponse.pdf">Data Mining in Incident Response - Challenges and Opportunities</a></td>
					<td style="text-align: center">13 May 2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/201603owasp_circl.pdf">Experiences with Paste-Monitoring</a></td>
					<td style="text-align: center">18 March 2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/2016-FIRST-TC-Munich-MISP-Threat-Sharing.pdf">Four years of practical information sharing MISP &amp; Threat Sharing</a></td>
					<td style="text-align: center">25th February 2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/2016-FIRST-MISP-taxonomies.pdf">Information Sharing and Taxonomies Practical Classification of Threat Indicators using MISP</a></td>
					<td style="text-align: center">26th January 2016</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/circl-eupi-ncsra2015.pdf">Improving Data Sharing to Increase Security Research Opportunities</a></td>
					<td style="text-align: center">2nd November 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/brucon2015-cve-search.pdf">cve-search - a free software to collect, search and analyse common vulnerabilities and exposures in software</a></td>
					<td style="text-align: center">9th October 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/20150919-DataDestructionDay.pdf">Protect your data, protect your life. Data Destruction Day</a></td>
					<td style="text-align: center">22nd September 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/circl-misp-zmq.pdf">New ZeroMQ functionality in MISP</a></td>
					<td style="text-align: center">2nd July 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/InternetRanking.pdf">Sharing Threat Indicators and Security Ranking, an opportunity for the Internet Community</a></td>
					<td style="text-align: center">18 November 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/ictspring2014-attackers-infosharing.pdf">Attackers benefit from sharing information. How can you benefit, too?</a> at ICTSpring</td>
					<td style="text-align: center">4 July 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="http://www.terena.org/publications/tnc2014-proceedings/12-cynthia-wagner-Darkspace.pdf">The void - An interesting place for network security monitoring</a> Cynthia Wagner, Marc Stiefer (RESTENA), Alexandre Dulaunoy, Gérard Wagener (CIRCL) at <a href="http://www.terena.org/publications/tnc2014-proceedings/">TNC 2014</a></td>
					<td style="text-align: center">19 May 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/raphael-vinot-circl-DBIR-paris-20140515.pdf">Information Sharing Cornerstone in Incident Detection and Handling</a> at DBIR presentation in Paris</td>
					<td style="text-align: center">15 May 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/circl-blackhole-honeynetworkshop2014.pdf">Darknet and Black Hole Monitoring a Journey into Typographic Errors</a> at Honeynet Project Workshop in Warsaw</td>
					<td style="text-align: center">12 May 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/euparl-circl-march-2014.pdf">An Overview of Security Incidents Targeting Citizen How the Attackers Are Deceiving Us?</a></td>
					<td style="text-align: center">15 March 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/tfcsirt-zurich-passivedns-circl.pdf">Passive DNS - Common Output Format</a></td>
					<td style="text-align: center">14 February 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/circl-who-targets-the-journalists.pdf">Who targets the journalists? and how?  A review of the attack surface in our digital society</a></td>
					<td style="text-align: center">7 February 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/CIRCL-MISP.pdf">MISP or How to Share Efficiently IOCs Within a Country</a></td>
					<td style="text-align: center">26 July 2013</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/bgp-ranking-first2013.pdf">BGP Ranking Scoring ASNs Based on Their Potential Maliciousness</a></td>
					<td style="text-align: center">23 June 2013</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/im2013-bgpranking.pdf">ASMATRA: Ranking ASs Providing Transit Service to Malware Hosters</a></td>
					<td style="text-align: center">29 May 2013</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/assets/files/tf-csirt-first2013-circl-restena-blackhole.pdf">Another Perspective to IP-Darkspace Analysis</a></td>
					<td style="text-align: center">29 January 2013</td>
			</tr>
	</tbody>
</table>
<h2 id="the-digital-first-aid-kit">The Digital First Aid Kit</h2>
<p>The Digital First Aid Kit aims to provide preliminary support for people facing the most common types of digital threats.
The Kit offers a set of self-diagnostic tools for citizen, human rights defenders, bloggers, activists and journalists fac
ing attacks themselves, as well as providing guidelines for digital first responders to assist a person under threat.</p>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Description</th>
					<th style="text-align: center">Last update</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><a href="/pub/dfak/AccountHijacking/"><img src="/assets/images/dfak/LOGO-HIJACKING.png" alt="Digital First Aid Kit - Account Hijacking"></a></td>
					<td style="text-align: center">2nd September 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/pub/dfak/DDoSMitigation/"><img src="/assets/images/dfak/LOGO-DDOS.png" alt="Digital First Aid Kit - DDoS Mitigation"></a></td>
					<td style="text-align: center">2nd September 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/pub/dfak/DevicesSeized/"><img src="/assets/images/dfak/LOGO-LOST.png" alt="Digital First Aid Kit - Devices Lost? Stolen? Seized?"></a></td>
					<td style="text-align: center">2nd September 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/pub/dfak/Glossary/"><img src="/assets/images/dfak/LOGO-GLOSSARY.png" alt="Digital First Aid Kit - Glossary"></a></td>
					<td style="text-align: center">2nd September 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/pub/dfak/Malware/"><img src="/assets/images/dfak/LOGO-MALWARE.png" alt="Digital First Aid Kit - Malware"></a></td>
					<td style="text-align: center">2nd September 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/pub/dfak/SecureCommunication"><img src="/assets/images/dfak/LOGO-SECURE-COM.png" alt="Digital First Aid Kit - Secure Communication"></a></td>
					<td style="text-align: center">2nd September 2014</td>
			</tr>
	</tbody>
</table>
<h2 id="the-digital-first-aid-kit-german-edition">The Digital First Aid Kit (German Edition)</h2>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Description</th>
					<th style="text-align: center">Last update</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><a href="/pub/dfak/de/AccountHijacking/"><img src="/assets/images/dfak/LOGO-HIJACKING.png" alt="Digital First Aid Kit - Konto-Diebstahl "></a></td>
					<td style="text-align: center">18th March 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/pub/dfak/de/DevicesSeized/"><img src="/assets/images/dfak/LOGO-LOST.png" alt="Digital First Aid Kit - Devices Lost? Stolen? Seized?"></a></td>
					<td style="text-align: center">26th March 2015</td>
			</tr>
	</tbody>
</table>
<h2 id="security-advisories">Security Advisories</h2>
<p>The latest CIRCL security advisories are published by
<a href="https://vulnerability.circl.lu/">Vulnerability-Lookup</a>.</p>
<div class="advisory-feed" data-atom-feed="https://vulnerability.circl.lu/recent/gna-1.atom?date_sort=updated&amp;sort_order=desc" data-limit="5">
  <p class="advisory-feed-status" role="status">Loading the latest security advisories…</p>
  <ol class="advisory-feed-list" aria-label="Latest security advisories"></ol>
  <p class="advisory-feed-more"><a href="https://vulnerability.circl.lu/">Browse all vulnerabilities on Vulnerability-Lookup <span aria-hidden="true">↗</span></a></p>
</div>
<script src="/js/atom-reader.js" defer></script>
<h2 id="other-publications">Other publications</h2>
<table>
	<thead>
			<tr>
					<th style="text-align: left">Description</th>
					<th style="text-align: center">Last update</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><a href="/pub/coordinated-vulnerability-disclosure/">Coordinated Vulnerability Disclosure (CVD) Policy</a></td>
					<td style="text-align: center">18th June 2025</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/pub/taxonomy">CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection</a></td>
					<td style="text-align: center">15th March 2018</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/pub/responsible-vulnerability-disclosure/">Responsible Vulnerability Disclosure</a></td>
					<td style="text-align: center">10th January 2015</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/pub/traffic-light-protocol/">Traffic Light Protocol (TLP) - Classification and Sharing of Sensitive Information</a></td>
					<td style="text-align: center">March 2014</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/pub/request-for-proposals/">CIRCL - Request for Proposals</a></td>
					<td style="text-align: center">Regularly Updated</td>
			</tr>
	</tbody>
</table>
]]></content:encoded>
    </item>
    <item>
      <title>Operational Guidance for Incident Handling - Rulebooks</title>
      <link>https://www.circl.lu/pub/guidance/</link>
      <pubDate>Thu, 01 Oct 2026 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/guidance/</guid>
      <description>Operational guidance for incident handling Traffic Light Protocol (TLP): CLEAR&amp;#xA;Version: 1.0 (stable)&amp;#xA;Date: 28 September 2026&amp;#xA;Authors:&amp;#xA;Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI) Commission de Surveillance du Secteur Financier (CSSF) Computer Incident Response Center Luxembourg (CIRCL) Governmental Computer Security Incident Response Team (GovCERT) High Commission for National Protection (HCPN) Institut Luxembourgeois de Régulation (ILR) Disclaimer These rulebooks are solely intended to be used as a practical guidance by an entity facing a cybersecurity incident and looking for immediate assistance from the competent authorities and the Computer Security Incident Response Teams (“CSIRT”). They have been written by a joint team of experts of the High Commission for National Protection (“HCPN”), acting in its role as the Agence Nationale de la Sécurité des Systèmes d’Information (“ANSSI”) and as the Governmental Computer Security Incident Response Team (“GOVCERT.LU”), the Computer Incident Response Center Luxembourg (“CIRCL”), the Commission de Surveillance du Secteur Financier (“CSSF”), and of the Institut Luxembourgeois de Régulation (“ILR”), in the context of 14(5) of the Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité (“NIS2 Law”), and in accordance with the missions assigned to the HCPN in its role as ANSSI under Article 3, paragraph 1ter, of the Loi modifiée du 23 juillet 2016 portant création du Haut-Commissariat à la Protection nationale.&amp;#xA;</description>
      <content:encoded><![CDATA[<h1 id="operational-guidance-for-incident-handling">Operational guidance for incident handling</h1>
<p><strong>Traffic Light Protocol (TLP):</strong> CLEAR</p>
<p><strong>Version:</strong> 1.0 (stable)</p>
<p><strong>Date:</strong> 28 September 2026</p>
<p><strong>Authors:</strong></p>
<ul>
<li>Agence Nationale de la Sécurité des Systèmes d’Information (ANSSI)</li>
<li>Commission de Surveillance du Secteur Financier (CSSF)</li>
<li>Computer Incident Response Center Luxembourg (CIRCL)</li>
<li>Governmental Computer Security Incident Response Team (GovCERT)</li>
<li>High Commission for National Protection (HCPN)</li>
<li>Institut Luxembourgeois de Régulation (ILR)</li>
</ul>
<h2 id="disclaimer">Disclaimer</h2>
<p>These rulebooks are solely intended to be used as a practical guidance by an entity facing a cybersecurity incident and looking for immediate assistance from the competent authorities and the Computer Security Incident Response Teams (“CSIRT”). They have been written by a joint team of experts of the <em>High Commission for National Protection</em> (“HCPN”), acting in its role as the <em>Agence Nationale de la Sécurité des Systèmes d’Information</em> (“ANSSI”) and as <em>the Governmental Computer Security Incident Response Team</em> (“GOVCERT.LU”), the <em>Computer Incident Response Center Luxembourg</em> (“CIRCL”), the <em>Commission de Surveillance du Secteur Financier</em> (“CSSF”), and of the <em>Institut Luxembourgeois de Régulation</em> (“ILR”), in the context of 14(5) of the <em>Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité</em> (“NIS2 Law”), and in accordance with the missions assigned to the HCPN in its role as ANSSI under Article 3, paragraph 1<em>ter</em>, of the <em>Loi modifiée du 23 juillet 2016 portant création du Haut-Commissariat à la Protection nationale</em>.</p>
<p>These rulebooks must not be used as a substitute for any policies or procedures in force at the entities. Neither the HCPN, the CIRCL, the CSSF, nor the ILR can be held liable in the event of malfunction or unforeseen circumstances or for any damages resulting from the use of the guidance.</p>
<p>These rulebooks do not address the legal obligations to be fulfilled by the concerned entities (e.g., file a complaint, notification of incidents to the CSSF, the ILR, and the Commission Nationale pour la Protection des Données (CNPD), etc.).</p>
<h2 id="rulebook-0--triage--routing">Rulebook 0 – Triage &amp; Routing</h2>
<h3 id="context-and-objectives">Context and objectives</h3>
<p>This “rulebook 0” is intended to be used as a starting point for the entities suffering a cyber-security incident and looking for assistance.</p>
<p>The objectives of this “rulebook 0” are the following:</p>
<ul>
<li>
<p>Stabilize operations, safely collect key evidence, support forensic analysis, and route to appropriate playbooks.</p>
</li>
<li>
<p>Tick mandatory regulatory reporting clocks immediately (NIS2, DORA, sectoral rules as applicable).</p>
</li>
<li>
<p>Enable support for malicious cyber-attacks (human errors and system failures are out of scope of these rulebooks).</p>
</li>
</ul>
<p>The subsequent rulebooks, #1 to #8, follow a common chronological flow of steps that are traditionally used in incident resolution:</p>
<ul>
<li>
<p><strong>Typical initial detection</strong>: the observed artefacts that are relevant triggers for the specific rulebook (note that they are indicatives but not exhaustive, not all the artefacts must be encountered to launch a specific rulebook, and several rulebooks may be applicable to an individual incident).</p>
</li>
<li>
<p><strong>Immediate response (containment)</strong>: useful techniques to consider immediately, to prevent contagion and greater damage.</p>
</li>
<li>
<p><strong>Investigation steps</strong>: useful techniques to further investigate the incident, enabling to look for deeper infection and spot malicious artefacts.</p>
</li>
<li>
<p><strong>Remediation</strong>: useful techniques to move away from the incident situation and consider the entity to be back in a safe state.</p>
</li>
<li>
<p><strong>Evidence keeping</strong>: useful techniques to keep evidences for forensics analysis.</p>
</li>
<li>
<p><strong>Post-incident activity</strong>: useful points to consider when going through the “lessons learnt” process and seek for potential improvement.</p>
</li>
<li>
<p><strong>Communication</strong>: useful communication consideration, such as specific services to contact.</p>
</li>
<li>
<p><strong>Key watchpoints</strong>: useful tips to consider when handling the incident, especially for more sophisticated attacks.</p>
</li>
</ul>
<p>For reference, a traditional and complete framework for incident management is often represented in a cycle of 4 phases:</p>
<ul>
<li>
<p>Preparation,</p>
</li>
<li>
<p>Detection and Analysis</p>
</li>
<li>
<p>Containment, Eradication and Recovery</p>
</li>
<li>
<p>Post Incident Activity</p>
</li>
</ul>
<p>This set of rulebooks only covers parts of this cycle, addressing generic but still practical operational guidance.</p>
<h3 id="first-actions">First actions</h3>
<h4 id="assign-roles">Assign roles</h4>
<ul>
<li>
<p>Name the responsible people to be involved. For example: a leader, a secretary (for meeting minutes and evidence keeping), analysts and communicator.</p>
</li>
<li>
<p>Communication / reporting roles for timely and appropriate communication. This function is to be segregated from incident resolution teams (IT, security).</p>
</li>
<li>
<p>If a crisis situation is declared, create a secure war-room (physical or virtual). Track participation and decisions. Also, consider engaging the Business Continuity Management (BCM) lead immediately to assess potential business-critical impact.</p>
</li>
</ul>
<h4 id="look-at-the-first-indicators">Look at the first indicators</h4>
<ul>
<li>
<p>Use monitoring and logs to narrow the attack surface.</p>
</li>
<li>
<p>Classify: is the event likely human error, malicious, or uncertain?</p>
</li>
<li>
<p>Identify impacted assets, systems, users, and third parties.</p>
</li>
</ul>
<h4 id="staff-wellbeing">Staff wellbeing</h4>
<ul>
<li>
<p>Ensure teams are rotated for sustained incidents. Encourage breaks and provide psychological support as needed.</p>
</li>
<li>
<p>Keep clear, calm, factual communication to limit stress.</p>
</li>
</ul>
<h4 id="open-a-case-log--chain-of-custody">Open a case log &amp; chain of custody</h4>
<ul>
<li>
<p>Use incident management software if available or standardized template.</p>
</li>
<li>
<p>For every artifact: log who / what / when / how, compute hash (SHA-256), store originals read-only.</p>
</li>
<li>
<p>Secure all captured evidence in a dedicated, access-controlled repository.</p>
</li>
<li>
<p>Carefully consider that the entity’s infrastructure may be compromised and the reliance on out-of-band communication and storage may be a necessity.</p>
</li>
</ul>
<h3 id="fast-classification-to-route-to-the-proper-rulebooks">Fast classification to route to the proper rulebook(s)</h3>
<ul>
<li>
<p>Keep as much evidence as possible.</p>
</li>
<li>
<p>Onboard experts to assist you, either internally or externally: cyber experts, consultants, and legal counsel, as needed.</p>
</li>
<li>
<p>Keep track of all investigative hypotheses and keep them updated over time.</p>
</li>
<li>
<p>Frequently (re)assess the attack classification based on the information you collect over time, to ensure the invocation of the most relevant rulebook(s).</p>
</li>
<li>
<p>Based on the collected indicators, use the classification table below and invoke the most relevant rulebook(s):</p>
</li>
</ul>
<p><em>Note: The lists of indicators are non-exhaustive.</em></p>
<h4 id="rulebook-1---dos--ddos"><strong>Rulebook 1 - DoS &amp; DDoS</strong></h4>
<table class="guidance-classification">
  <thead>
    <tr>
      <th scope="col">Indicators of compromise</th>
      <th scope="col">Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>
        <ul>
          <li>Sudden or sustained service unavailability or severe latency reported by users or monitoring tools</li>
          <li>Saturated network traffic and connection timeouts</li>
          <li>Anomalies in network traffic, occurring at unusual pace (e.g., handshake failures, SYN/ACK reset or malformed packages, Web Application Firewall (WAF) origin timeouts, spikes in 4xx/5xx errors)</li>
          <li>Outstanding alerts from firewall, load balancer, or Internet Service Provider (ISP)</li>
          <li>Sudden drop in availability of external-facing services (Domain Name System (DNS), Virtual Private Network (VPN), email, web portals)</li>
          <li>Abnormal load on backend components (e.g., web servers or database servers), such as increased Central Processing Unit (CPU) consumption</li>
        </ul>
      </td>
      <td>
        <p>This rulebook covers all the kinds of DoS or DDoS attacks: including overflow or crash attacks, at either the network or application layers.</p>
      </td>
    </tr>
  </tbody>
</table>
<h4 id="rulebook-2--malware"><strong>Rulebook 2 – Malware</strong></h4>
<table class="guidance-classification">
  <thead>
    <tr>
      <th scope="col">Indicators of compromise</th>
      <th scope="col">Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>
        <ul>
          <li>Unusual file extensions (<code>.locked</code>, <code>.crypt</code>, etc.)</li>
          <li>Unintended file renaming observed</li>
          <li>Antivirus (AV) or Endpoint Detection and Response (EDR) alerts</li>
          <li>Suspicious process execution</li>
          <li>Outbound connections or beaconing activity to suspicious or known Command &amp; Control (C2)</li>
          <li>Persistence artifacts (services, tasks, Windows Management Instrumentation (WMI))</li>
          <li>Sudden inaccessibility of files or performance issues observed</li>
          <li>Ransom note discovered in end-user directories or shared drives</li>
          <li>Abnormal pop-ups or locked screens observed by users</li>
        </ul>
      </td>
      <td>
        <p>This rulebook applies to all kinds of malware, used for a variety of purposes, such as:</p>
        <ul>
          <li>Data theft and surveillance: infostealers, spyware, keyloggers, etc.</li>
          <li>Remote access and control: remote access trojans (RAT), backdoors, rootkits, abuse of RMM tools, etc.</li>
          <li>Destruction and extortion: ransomware, wipers, etc.</li>
          <li>Propagation and distribution: viruses, worms, trojans, botnets, etc.</li>
          <li>Resource exploitation: crypto miners, adware, logic bombs, etc.</li>
        </ul>
      </td>
    </tr>
  </tbody>
</table>
<h4 id="rulebook-3---exploitation-of-communication-channels-to-gain-access"><strong>Rulebook 3 - Exploitation of communication channels to gain access</strong></h4>
<table class="guidance-classification">
  <thead>
    <tr>
      <th scope="col">Indicators of compromise</th>
      <th scope="col">Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>
        <ul>
          <li>User reports a suspicious email or link</li>
          <li>User reports a suspicious SMS</li>
          <li>Anomalous email activity (auto-forwarding, mass mails)</li>
          <li>Alerts of credentials being re-used</li>
          <li>Reports from other entities, third parties, Computer Emergency Response Teams (CERTs), or Threat Intelligence feeds indicating an ongoing campaign targeting similar entities</li>
          <li>Detection from an email gateway or Security Information and Event Management (SIEM) showing indicators of exploitation of communication channels</li>
          <li>Reported fake websites or login portals imitating the entity's own websites or login portals</li>
        </ul>
      </td>
      <td>
        <p>This rulebook applies to all kinds of successful exploitation of communication channels, for instance: phishing, smishing (SMS phishing), vishing (voice phishing), quishing (QR code phishing), pretexting (e.g., CEO fraud), Business Email Compromise (BEC), etc.</p>
      </td>
    </tr>
  </tbody>
</table>
<h4 id="rulebook-4---credential-theft--account-compromise"><strong>Rulebook 4 - Credential theft &amp; account compromise</strong></h4>
<table class="guidance-classification">
  <thead>
    <tr>
      <th scope="col">Indicators of compromise</th>
      <th scope="col">Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>
        <ul>
          <li>Unusual login activity (geographic anomalies, impossible travel, unusual token usage)</li>
          <li>Unintended bypass of Multi-Factor Authentication (MFA)</li>
          <li>Privilege escalation alerts</li>
          <li>Unusual activities detected on mailboxes or cloud services, such as outstanding downloads, unintended permission changes, creation of new rules or delegates, or multiple failed logins or brute-force detections</li>
          <li>Alerts from other entities, Computer Emergency Response Teams (CERTs), or Threat Intelligence Feeds identifying compromised accounts in the entity's domains</li>
          <li>Suspicious OAuth or Application Programming Interfaces (API) token usage, in particular outside the corporate IP range</li>
        </ul>
      </td>
      <td>
        <p>This rulebook applies to all types of theft of credentials or compromise of accounts, including for instance: session hijacking, pass-the-hash attack, pass-the-ticket attack, brute forcing, password spraying, Kerberoasting, credential dumping (LSASS), etc.</p>
      </td>
    </tr>
  </tbody>
</table>
<h4 id="rulebook-5---vulnerability-exploitation"><strong>Rulebook 5 - Vulnerability exploitation</strong></h4>
<table class="guidance-classification">
  <thead>
    <tr>
      <th scope="col">Indicators of compromise</th>
      <th scope="col">Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>
        <ul>
          <li>Unusual behaviour of systems or applications (e.g., errors, crashes, defacement)</li>
          <li>Unusual Application Programming Interface (API) calls or access to data</li>
          <li>Unusual number of Web Application Firewall (WAF) or Security Information and Event Management (SIEM) alerts (e.g., spikes in 4xx/5xx error messages)</li>
          <li>Reverse or web shells observed or suspected to be in use</li>
          <li>Abnormal page volumetry (rendered page size / requests per IP)</li>
          <li>Abnormal behaviour in logs (e.g., access logs)</li>
        </ul>
      </td>
      <td>
        <p>This rulebook applies to all kinds of vulnerabilities: web application vulnerabilities, API exploitation, known exploited vulnerabilities (KEV), configuration-flaw exploitation, memory and binary exploitation, etc.</p>
      </td>
    </tr>
  </tbody>
</table>
<h4 id="rulebook-6---insider-threat"><strong>Rulebook 6 - Insider threat</strong></h4>
<table class="guidance-classification">
  <thead>
    <tr>
      <th scope="col">Indicators of compromise</th>
      <th scope="col">Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>
        <ul>
          <li>Unusual access to sensitive data</li>
          <li>Unusual large outbound traffic</li>
          <li>Unusual traffic outside working hours</li>
          <li>Complaints or warnings from the Human Resources (HR) department</li>
          <li>Unauthorized use of administrative tools or privilege-escalation attempts</li>
        </ul>
      </td>
      <td>
        <p>This rulebook applies to situations where an insider (e.g., employee or consultant), having genuine access to the entity's systems, leverages that granted access to perform malicious actions.</p>
      </td>
    </tr>
  </tbody>
</table>
<h4 id="rulebook-7---data-exfiltration"><strong>Rulebook 7 - Data exfiltration</strong></h4>
<table class="guidance-classification">
  <thead>
    <tr>
      <th scope="col">Indicators of compromise</th>
      <th scope="col">Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>
        <ul>
          <li>Unusual access to sensitive data</li>
          <li>Unusual large outbound traffic</li>
          <li>Unusual traffic outside working hours</li>
          <li>Suspicious (obfuscated) outbound traffic</li>
          <li>Alert from Endpoint Detection and Response (EDR) or threat intelligence resources</li>
          <li>Sudden large file transfers</li>
          <li>Long dwell time</li>
          <li>Data Loss Prevention (DLP) or proxy alerts indicating sensitive-data movement outside approved channels</li>
          <li>Data discovered outside traditional channels (e.g., Telegram, web forums, press, or other media)</li>
        </ul>
      </td>
      <td>
        <p>This rulebook applies to situations where an entity's data is exfiltrated without authorization.</p>
      </td>
    </tr>
  </tbody>
</table>
<h4 id="rulebook-8---package-compromission--supply-chain-attack"><strong>Rulebook 8 - Package compromission &amp; supply chain attack</strong></h4>
<table class="guidance-classification">
  <thead>
    <tr>
      <th scope="col">Indicators of compromise</th>
      <th scope="col">Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>
        <ul>
          <li>Unusual alerts following a software or firmware update, or the integration of a new third-party package</li>
          <li>Failures in hash validation or use of unexpected certificates used to sign packages</li>
          <li>Outbound traffic to abnormal domains</li>
          <li>Endpoint Detection and Response (EDR) alerts on newly updated binaries, installers or side-loaded Dynamic-Link Libraries (DLLs)</li>
          <li>Permission abuse of an application or integration (e.g., observed via unexpected OAuth / Single Sign On (SSO) consent or expanded scopes)</li>
          <li>Unusual requests originating from third-party services (e.g., API calls to unusual domains)</li>
          <li>Software behaviour not in line with the intended design (i.e., Software Bill of Materials (SBOM) drift)</li>
        </ul>
      </td>
      <td>
        <p>This rulebook applies to situations where an attack leverages third-party dependencies (e.g., software packages, libraries, open-source code, firmware, etc.) to compromise the entity's systems.</p>
      </td>
    </tr>
  </tbody>
</table>
<h3 id="general-guidance-and-watch-points">General guidance and watch points</h3>
<ul>
<li>
<p>Maintain timeline of actions (detection → response → containment → recovery).</p>
</li>
<li>
<p>Record all decisions and rationales.</p>
</li>
<li>
<p>Confirm that backup data is intact and isolated before any restoration.</p>
</li>
<li>
<p>Consider engaging external CSIRT/CERT or cyber-insurance provider early if contractual clauses exist.</p>
</li>
<li>
<p>After triage, continue reassessment: re-classify the incident as new evidence emerges.</p>
</li>
<li>
<p>Keep all internal and external communications factual, short, and go through legal review if needed.</p>
</li>
<li>
<p>After the incident is resolved and as part of the post-incident improvement, update your internal procedures, considering the lessons learnt.</p>
</li>
<li>
<p>Consider using external tools and procedures<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup> for the proper incident handling and evidence collection.</p>
</li>
</ul>
<h2 id="rulebook-1--denial-of-service-dos--distributed-denial-of-service-ddos">Rulebook 1 – Denial of Service (DoS) &amp; Distributed Denial of Service (DDoS)</h2>
<p>This rulebook covers all the kinds of DoS or DDoS attacks: including overflow or crash attacks, at either the network or application layers.</p>
<h3 id="typical-initial-detection">Typical initial detection</h3>
<ul>
<li>
<p>Sudden or sustained service unavailability or severe latency reported by users or monitoring tools</p>
</li>
<li>
<p>Saturated network traffic and connection timeouts</p>
</li>
<li>
<p>Anomalies in network traffic, occurring at unusual pace (e.g., handshake failures, SYN/ACK reset or malformed packages, Web Application Firewall (WAF) origin timeouts, spikes in 4xx/5xx errors)</p>
</li>
<li>
<p>Outstanding alerts from firewall, load balancer, or Internet Service Provider (ISP)</p>
</li>
<li>
<p>Sudden drop in availability of external-facing services (Domain Name System (DNS), Virtual Private Network (VPN), email, web portals)</p>
</li>
<li>
<p>Abnormal load on backend components (e.g., web servers or database servers), such as increased Central Processing Unit (CPU) consumption</p>
</li>
</ul>
<h3 id="immediate-response-containment">Immediate response (containment)</h3>
<ul>
<li>
<p>Immediately notify the Business Continuity Management (BCM) function and affected business owners</p>
</li>
<li>
<p>Identify the type of attack (i.e., volumetric or non-volumetric)</p>
</li>
<li>
<p>Contact the Internet Service Provider(s) (ISP) to turn on traffic filtering. If volumetric attack is already suspected, turn on anti-DDoS services that you subscribed (if any)</p>
</li>
<li>
<p>If identification is already done, block (or at least implement rate limits) attacking IP ranges, or geo-block</p>
</li>
<li>
<p>Mitigate impact on backend systems and critical services e.g., using for instance connection limits (“connections caps”), lower timeouts, or isolating affected systems</p>
</li>
<li>
<p>Divert traffic via Content Delivery Network (CDN) if available</p>
</li>
<li>
<p>Activate the crisis communication line if customer-facing portals are affected</p>
</li>
</ul>
<h3 id="investigation-steps">Investigation steps</h3>
<ul>
<li>
<p>Perform traffic analysis to determine the origin (geographic<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup> and logical) and nature of the traffic, collect indicators of compromise (IOCs), such as network packet captures (PCAP), edge logs, and patterns (e.g., User-Agent, URI, source ASNs)</p>
</li>
<li>
<p>Assess whether the attack is a distraction or part of a multi-vector campaign</p>
</li>
<li>
<p>Check if camouflage / obfuscation / data exfiltration techniques are employed at the same time of the attack; if yes, invoke other rulebooks as appropriate</p>
</li>
<li>
<p>Identify the business assets that are affected and the bottleneck devices</p>
</li>
</ul>
<h3 id="remediation">Remediation</h3>
<ul>
<li>
<p>Review web application firewall (WAF) configurations to mitigate protocol-based attacks, if relevant</p>
</li>
<li>
<p>Evaluate the business impact for any countermeasures proposed in response to the incident</p>
</li>
<li>
<p>Consider blocking based on geography, deny-lists or IP reputation lists</p>
</li>
<li>
<p>Consider blocking high-impact IPs and applying rate limits</p>
</li>
<li>
<p>Consider implementing challenge-response mechanisms (e.g., CAPTCHA)</p>
</li>
<li>
<p>Consider applying temporary cache rules</p>
</li>
<li>
<p>Check if backend services are affected by overload and take action as appropriate</p>
</li>
<li>
<p>Consider closely monitoring signs of network disruption to catch changes in the attack techniques (e.g., via Quality of Services (QoS) measures)</p>
</li>
<li>
<p>Once stable, gradually remove temporary blocks to validate that the service recovery is effective</p>
</li>
</ul>
<h3 id="evidence-keeping">Evidence keeping</h3>
<ul>
<li>
<p>NetFlow captures (e.g., short PCAP samples)</p>
</li>
<li>
<p>Logs from application servers, firewall, Intrusion Detection System (IDS), Intrusion Prevention System (IPS), Content Delivery Network (CDN), load-balancer and WAF</p>
</li>
<li>
<p>Maintain timeline and decisions in the incident case log</p>
</li>
</ul>
<h3 id="post-incident-activity">Post-incident activity</h3>
<ul>
<li>
<p>Identify and patch services that are prone to be leveraged during DDoS attacks (e.g., DNS, Network Time Protocol (NTP) or other amplification vulnerabilities)</p>
</li>
<li>
<p>Review your IT architecture to look for resiliency improvement opportunities</p>
</li>
<li>
<p>Consider deploying CDN with Anycast routing and caching capabilities, load balancers, multi-region redundancy, and separation of critical and non-critical services</p>
</li>
<li>
<p>Perform dependency mapping by identifying all public-facing services (web, Application Programming Interfaces (APIs)), entry points (public IPs and ports), as well as associated CDN, DNS, and authentication mechanisms</p>
</li>
<li>
<p>Review alert thresholds and monitoring dashboards for early detection</p>
</li>
<li>
<p>Consider subscribing to anti-DDoS services</p>
</li>
<li>
<p>If your external communication means were impacted, look for alternate solutions</p>
</li>
<li>
<p>Consider including DDoS attacks in your Business Continuity Plan (BCP) / Disaster Recovery Plan (DRP)</p>
</li>
</ul>
<h3 id="communication">Communication</h3>
<ul>
<li>
<p>Coordinate with ISP / hosting provider</p>
</li>
<li>
<p>Inform customers and business partners</p>
</li>
</ul>
<h3 id="key-watchpoints">Key watchpoints</h3>
<ul>
<li>
<p>Application-layer DoS may evade traditional detection mechanisms and volumetric defences may not be reliable</p>
</li>
<li>
<p>Attacks may occur on multiple layers (L3/L4 + L7) simultaneously</p>
</li>
<li>
<p>Techniques used by attackers shift rapidly and adapt to the defence responses (cat and mouse game)</p>
</li>
<li>
<p>Similar campaigns may reappear within days; keep monitoring heightened for a defined period</p>
</li>
<li>
<p>Confirm no persistent compromise remains once traffic stabilizes (e.g., injected web shell, backdoor)</p>
</li>
</ul>
<h2 id="rulebook-2--malware-1">Rulebook 2 – Malware</h2>
<p>This rulebook applies to all kinds of malware, used for a variety of purposes, such as:</p>
<ul>
<li>
<p>Data theft and surveillance: infostealers, spyware, keyloggers, etc.</p>
</li>
<li>
<p>Remote access and control: remote access trojans (RAT), backdoors, rootkits, abuses RMM tools, etc.</p>
</li>
<li>
<p>Destruction and extortion: ransomware, wipers, etc.</p>
</li>
<li>
<p>Propagation and distribution: viruses, worms, trojans, botnets, etc.</p>
</li>
<li>
<p>Resource exploitation: crypto miners, adware, logic bombs, etc.</p>
</li>
</ul>
<h3 id="typical-initial-detection-1">Typical initial detection</h3>
<ul>
<li>
<p>Unusual file extensions (.locked, .crypt, etc.)</p>
</li>
<li>
<p>Unintended files renaming observed</p>
</li>
<li>
<p>Antivirus (AV) or Endpoint Detection and Response (EDR) alerts</p>
</li>
<li>
<p>Suspicious process execution</p>
</li>
<li>
<p>Outbound connections or beaconing activity to suspicious or known Command &amp; Control (C2)</p>
</li>
<li>
<p>Persistence artifacts (services, tasks, Windows Management Instrumentation (WMI))</p>
</li>
<li>
<p>Sudden inaccessibility of files or performance issues observed</p>
</li>
<li>
<p>Ransom note discovered in end-user directories or shared drives</p>
</li>
<li>
<p>Abnormal pop-ups or locked screens observed by users</p>
</li>
</ul>
<h3 id="immediate-response-containment-1">Immediate response (containment)</h3>
<ul>
<li>
<p>Decide on the strategy based on the malware impact: either keep the system running or power off; knowing that keeping power on preserves memory for forensic analysis and <strong>may</strong> enable the extraction of the encryption key (in case of ransomware), while powering off <strong>may</strong> limit the immediate damage and <strong>may</strong> avoid propagation</p>
</li>
<li>
<p>Isolate affected systems from the network immediately (e.g., disconnect network cables, disable Wi-Fi, isolate at switch / Network Access Control (NAC) / hypervisor level)</p>
</li>
<li>
<p>In case a ransomware has already impacted the availability of infected systems, notify the Business Continuity Management (BCM) function for potential business impact</p>
</li>
<li>
<p>Block suspected domains and IPs</p>
</li>
<li>
<p>Change credentials used on infected devices and monitor accounts</p>
</li>
<li>
<p>Disable administrative shares and remote access (e.g., Server Message Block (SMB), Remote Desktop Protocol (RDP)) to limit lateral movement</p>
</li>
<li>
<p>Prevent spread by disabling scheduled tasks and tools usually used in lateral movement (e.g., PsExec)</p>
</li>
<li>
<p>If ransomware is suspected, disconnect backup systems from the network immediately and temporarily suspend automated backups to prevent encryption spread or tampering</p>
</li>
<li>
<p>Check integrity of offline copies</p>
</li>
</ul>
<h3 id="investigation-steps-1">Investigation steps</h3>
<ul>
<li>
<p>Create forensic copies for analysis: at first acquire key artifacts by relying on the EDR if available, and perform full disk acquisition (e.g., using “dd” tool) on critical workstations (entry point, domain controllers, attacker pivot)</p>
</li>
<li>
<p>Identify initial point of infection (e.g., specific end-user laptop) and initial vector (e.g., phishing, RDP access, exploited vulnerability, etc.)</p>
</li>
<li>
<p>In case of ransomware, determine encryption scope, identify ransomware strain (to check for decryptors) and persistence artifacts<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup></p>
</li>
<li>
<p>In case of ransomware, investigate the firewall logs to determine potential data exfiltration</p>
</li>
<li>
<p>Review logs for lateral movement, privilege escalation or indicators of persistence</p>
</li>
<li>
<p>Use threat-intelligence sources to look for known indicators (e.g., hashes, domains)</p>
</li>
<li>
<p>Assess if other rulebooks apply (e.g., <em>Rulebook 3 – Phishing</em> for initial infection, or <em>Rulebook 7 – Data Exfiltration</em> if leaks suspected)</p>
</li>
</ul>
<h3 id="remediation-1">Remediation</h3>
<ul>
<li>
<p>Entities should not pay the ransom (if any is requested) — it does not guarantee recovery and may breach sanctions law</p>
</li>
<li>
<p>Before restoring, apply latest patches / updates and perform Antivirus (AV) and Endpoint Detection and Response (EDR) scan</p>
</li>
<li>
<p>Restore infected systems from trusted sources (e.g., clean backups or gold images), and keep them disconnected from the network at first and check file integrity</p>
</li>
<li>
<p>Invalidate tokens cached on infected hosts</p>
</li>
<li>
<p>Although restoration is often the preferred option, it may not be always possible; in this situation, remove artifacts or tools (e.g., registry keys, tasks) used for persistence purpose</p>
</li>
<li>
<p>Re-enable network connectivity gradually, while monitoring for indicators of re-infection</p>
</li>
<li>
<p>Verify proper operation of restored systems before reintroducing them to production</p>
</li>
</ul>
<h3 id="evidence-keeping-1">Evidence keeping</h3>
<ul>
<li>
<p>Keep ransom note, a sample of encrypted files and a sample of the malware</p>
</li>
<li>
<p>Before wiping any system, create disk images</p>
</li>
<li>
<p>Collect logs (Windows Event Viewer, Sysmon, EDR, network captures), use automation for collection where possible</p>
</li>
<li>
<p>Collect volatile data (e.g., memory dumps) from infected machines before power-down (if feasible)</p>
</li>
<li>
<p>Document timeline of actions, decisions, and containment steps in the case log</p>
</li>
</ul>
<h3 id="post-incident-activity-1">Post-incident activity</h3>
<ul>
<li>
<p>Patch vulnerabilities and entry vectors used in the attack</p>
</li>
<li>
<p>Reset credentials (especially admin accounts)</p>
</li>
<li>
<p>Consider using “tiered credential rotation”</p>
</li>
<li>
<p>Consider reviewing the Group Policy Objects (GPOs) to harden endpoints</p>
</li>
<li>
<p>Consider reviewing the configuration of remote management tools (e.g., RDP) and look for potential security improvements</p>
</li>
<li>
<p>Consider enabling Multi-Factor Authentication (MFA) for all administrator and remote access</p>
</li>
<li>
<p>Consider reviewing endpoint security posture and look for security improvements</p>
</li>
<li>
<p>Consider segmenting the internal network</p>
</li>
<li>
<p>Consider improving the employees’ awareness</p>
</li>
<li>
<p>Consider deploying application whitelisting and EDR behavioural rules</p>
</li>
</ul>
<h3 id="communication-1">Communication</h3>
<ul>
<li>
<p>Alert IT and Security Operations Centre (SOC) teams immediately</p>
</li>
<li>
<p>Inform affected users if their accounts were involved</p>
</li>
</ul>
<h3 id="key-watchpoints-1">Key watchpoints</h3>
<ul>
<li>
<p>Beware of double extortion attacks (i.e., data theft and encryption)</p>
</li>
<li>
<p>Malware may act as dropper only, pre-positioning attackers for future malicious acts, so watch for dormant second-stage payloads (e.g., triggered scheduled tasks) or abnormal network traffic or system behaviour</p>
</li>
<li>
<p>Before recovery steps, validate all recovery sources as infections may re-trigger from persistent devices or offline backups</p>
</li>
<li>
<p>Cloud storage or synchronization services can re-propagate infected content if not sanitized</p>
</li>
<li>
<p>For ransomware attacks, consider referring to additional specialized guidance<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup></p>
</li>
</ul>
<h2 id="rulebook-3--exploitation-of-communication-channels-to-gain-access">Rulebook 3 – Exploitation of communication channels to gain access</h2>
<p>This rulebook applies to all kinds of successful exploitation of communication channels, for instance: phishing, smishing (SMS phishing), vishing (voice phishing), quishing (QR code phishing), pretexting (e.g., CEO fraud), Business Email Compromise (BEC), etc.</p>
<h3 id="typical-initial-detection-2">Typical initial detection</h3>
<ul>
<li>
<p>User reports suspicious email or link</p>
</li>
<li>
<p>User reports suspicious SMS</p>
</li>
<li>
<p>Anomalous email activity (auto-forwarding, mass mails)</p>
</li>
<li>
<p>Alerts of credentials being re-used</p>
</li>
<li>
<p>Reports from other entities, third-parties, Computer Emergency Response Teams (CERTs) or Threat Intelligence feeds indicating an ongoing campaign targeting similar entities</p>
</li>
<li>
<p>Detection from email gateway or Security Information and Event Management (SIEM) showing exploitation of communication channels indicators</p>
</li>
<li>
<p>Reported fake websites or login portals imitating the entity’s own websites or login portals</p>
</li>
</ul>
<h3 id="immediate-response-containment-2">Immediate response (containment)</h3>
<ul>
<li>
<p>Identify malicious domains and URLs and block them in proxy, email gateways and spam filters</p>
</li>
<li>
<p>Purge the email from all user mailboxes via administrative search-and-remove</p>
</li>
<li>
<p>Reset credentials of impacted user and invalidate active sessions (e.g., OAuth tokens, browser sessions)</p>
</li>
<li>
<p>Check for unintended auto-forwarding rules and remove them</p>
</li>
<li>
<p>Check endpoints of affected users for malware or credential stealers (run an Endpoint Detection and Response (EDR) scan)</p>
</li>
<li>
<p>If internal domains are spoofed, consider blocking the delivery from external sources using these spoofed internal domains</p>
</li>
<li>
<p>Keep evidence (e.g., copy of original emails and headers) before deletion</p>
</li>
<li>
<p>If multiple users reported identical messages, consider that a large-scale campaign is on-going and notify the Security Operations Centre (SOC) and the Management</p>
</li>
</ul>
<h3 id="investigation-steps-2">Investigation steps</h3>
<ul>
<li>
<p>Due to volume, investigations may not always be performed duly; keep processes simple and prioritised</p>
</li>
<li>
<p>Analyse the email headers to check sender authenticity, the message’s path and any trace of anomalies</p>
</li>
<li>
<p><strong>Don’t</strong> click on the payloads or URLs, however inspect them in a safe sandboxed environment to determine the malicious intent (e.g., credential harvesting, malware delivery, scam, OAuth token abuse).</p>
</li>
<li>
<p>Identify the users’ interactions (e.g., click, download, open) and the related impacts</p>
</li>
<li>
<p>Correlate Indicators of Compromise (IoCs) (e.g., IP, domain, hash, email subject) with other alerts and external sources (e.g., Threat Intelligence feeds, warning from CERTs)</p>
</li>
<li>
<p>Examine the phishing page<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup> to identify all involved parties, such as an initial redirector, or credentials posted to another website</p>
</li>
<li>
<p>Collect any artifacts you can fetch (e.g., phishing kit, Telegram ID/key, etc.)</p>
</li>
</ul>
<h3 id="remediation-2">Remediation</h3>
<ul>
<li>
<p>Check with external sources (e.g., Threat Intelligence feeds, warning from CERTs) if other similar phishing kits or campaigns are on-going and block them</p>
</li>
<li>
<p>Ensure that your email security settings (i.e., Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), Domain-based Message Authentication, Reporting &amp; Conformance (DMARC)) are in line with leading security practices</p>
</li>
<li>
<p>Reset or rotate credentials and tokens for all confirmed victims</p>
</li>
<li>
<p>Monitor post-incident activity on affected accounts for at least 72 hours, in particular check in logs if malicious downloads, macros or fileless payloads are executed</p>
</li>
</ul>
<h3 id="evidence-keeping-2">Evidence keeping</h3>
<ul>
<li>
<p>Keep the original malicious communication, including the headers</p>
</li>
<li>
<p>Collect mail server logs and user mailbox export</p>
</li>
<li>
<p>Screenshots of phishing pages<sup>6</sup>, if safely captured in a sandbox</p>
</li>
</ul>
<h3 id="post-incident-activity-2">Post-incident activity</h3>
<ul>
<li>
<p>Consider improving the user awareness on social engineering communication focusing on recognizing suspicious messages and reporting procedures</p>
</li>
<li>
<p>Strengthen email gateway rules, condition access/ Multi-Factor Authentication (MFA), OAuth and third-party app approval flows and sandboxing</p>
</li>
<li>
<p>Consider conducting a phishing campaign exercise for training evaluation</p>
</li>
<li>
<p>If a proxy is deployed, verify that SSL/TLS termination is enabled and that request methods are properly logged (the ability to identify “POST” requests is particularly valuable)</p>
</li>
<li>
<p>Evaluate the SPF configuration</p>
</li>
</ul>
<h3 id="communication-2">Communication</h3>
<ul>
<li>
<p>Notify impacted users promptly, explaining the steps they must take (password reset, token revocation, vigilance)</p>
</li>
<li>
<p>Escalate to Top Management if multiple users are targeted</p>
</li>
<li>
<p>Consider making a communication to all employees about an on-going deceptive/malicious communication campaign</p>
</li>
</ul>
<h3 id="key-watchpoints-2">Key watchpoints</h3>
<ul>
<li>
<p>Beware of phishing attempts looking to gather OAuth tokens, these may be used to bypass password resets</p>
</li>
<li>
<p>Attackers may collect compromise access now, and reuse later</p>
</li>
<li>
<p>Mobile users are increasingly targeted via SMS (i.e., smishing) or messaging applications (i.e., vishing)</p>
</li>
</ul>
<h2 id="rulebook-4--credential-theft--account-compromise">Rulebook 4 – Credential theft &amp; account compromise</h2>
<p>This rulebook applies to all the types of theft of credentials or compromise of accounts, including for instance: session hijacking, pass-the-hash attack, pass-the-ticket attack, brute forcing, password spraying, Kerberoasting, credential dumping (LSASS), etc.</p>
<h3 id="typical-initial-detection-3">Typical initial detection</h3>
<ul>
<li>
<p>Unusual login activity (geographic anomalies, impossible travel, unusual token usage)</p>
</li>
<li>
<p>Unintended bypass of Multi-Factor Authentication (MFA)</p>
</li>
<li>
<p>Privilege escalation alerts</p>
</li>
<li>
<p>Unusual activities detected on mailboxes or cloud services, such as outstanding downloads, unintended permission changes, creation of new rules/delegates, or multiple failed logins or brute-force detections</p>
</li>
<li>
<p>Alerts from other entities, Computer Emergency Response Teams (CERTs) or Threat Intelligence Feeds of identified compromised accounts in the entity’s domains</p>
</li>
<li>
<p>Suspicious OAuth or Application Programming Interfaces (API) token usage, in particular outside of the corporate IP range</p>
</li>
</ul>
<h3 id="immediate-response-containment-3">Immediate response (containment)</h3>
<ul>
<li>
<p>Force logoff and password reset of compromised accounts</p>
</li>
<li>
<p>Terminate compromised sessions and revoke associated tokens</p>
</li>
<li>
<p>Notify the Security Operations Centre (SOC) and the Identity and Access Management (IAM) team to monitor for potential reuse or reauthentication attempts, used in password spraying attacks</p>
</li>
</ul>
<h3 id="investigation-steps-3">Investigation steps</h3>
<ul>
<li>
<p>Identify entry vector (e.g., phishing, brute-force, token theft)</p>
</li>
<li>
<p>Review access logs</p>
</li>
<li>
<p>If MFA was by-passed, understand how (e.g., application-based attack or phishing relay) and determine whether the first rogue IP that logged in was also a phishing website</p>
</li>
<li>
<p>Check for lateral movements and privilege escalation</p>
</li>
<li>
<p>Check for persistence mechanisms, such as new MFA devices, new application accounts or passwords, tokens with long expiration date, unintended delegated mailbox access</p>
</li>
<li>
<p>Review logs of Endpoint Detection and Response (EDR) and affected components for credential dumping tools</p>
</li>
<li>
<p>Look for potential privilege-escalation events or newly created accounts</p>
</li>
<li>
<p>Look for unintended OAuth consents and API tokens, to detect potential unauthorized application integrations</p>
</li>
<li>
<p>Look for malicious mail rules</p>
</li>
</ul>
<h3 id="remediation-3">Remediation</h3>
<ul>
<li>
<p>Consider the scale of the impact and resetting passwords, API keys and tokens as appropriate</p>
</li>
<li>
<p>Consider implementing conditional access (e.g., MFA, geo-fencing), in particular for sensitive, administrator and remote access</p>
</li>
<li>
<p>Review the roles in the identity directory (e.g., Active Directory (AD)) and remove unauthorized privileges</p>
</li>
<li>
<p>Apply patches on affected components and/or apply mitigation measures to avoid new capture of credentials or tokens</p>
</li>
<li>
<p>Implement detection rules to detect ongoing or renewed attacker activity — such as repeated login attempts or the creation of new unauthorized sessions — even after credentials are changed</p>
</li>
<li>
<p>Primarily for cloud hosted email platforms, remove malicious application permissions and clean up mail forwarding/filtering rules</p>
</li>
</ul>
<h3 id="evidence-keeping-3">Evidence keeping</h3>
<ul>
<li>
<p>Authentication logs (e.g., Active Directory (AD), Identity Provider (IdP), Virtual Private Network (VPN))</p>
</li>
<li>
<p>Endpoint Detection and Response (EDR) logs</p>
</li>
</ul>
<h3 id="post-incident-activity-3">Post-incident activity</h3>
<ul>
<li>
<p>Consider hardening the password policy and enforcing MFA at large scale</p>
</li>
<li>
<p>Review the use of service accounts and Application Programming Interface (API) keys, and look for security improvement opportunities</p>
</li>
<li>
<p>Review and look for improvements in Identity and Access Management (IAM) policies and permissions</p>
</li>
<li>
<p>Consider raising awareness among users about phishing and credentials hygiene</p>
</li>
<li>
<p>Consider implementing detection use cases based on behavioural analytics and automated risk-based conditional access</p>
</li>
</ul>
<h3 id="communication-3">Communication</h3>
<ul>
<li>
<p>Notify impacted users promptly and advise them to verify their other accounts for reuse risks</p>
</li>
<li>
<p>Inform Security Operations Centre (SOC) and IT</p>
</li>
<li>
<p>Inform Management and legal / compliance departments if sensitive data was accessed, altered or exfiltrated</p>
</li>
</ul>
<h3 id="key-watchpoints-3">Key watchpoints</h3>
<ul>
<li>
<p>Token-based attacks may not be impacted by password reset attempts</p>
</li>
<li>
<p>Attackers often use automation for persistence (e.g., scheduled tasks)</p>
</li>
</ul>
<h2 id="rulebook-5--vulnerability-exploitation">Rulebook 5 – Vulnerability exploitation</h2>
<p>This rulebook applies to all kinds of vulnerabilities: web application vulnerabilities, API exploitation, known exploited vulnerabilities (KEV), configuration flaws exploitation, memory and binary exploitation, etc.</p>
<h3 id="typical-initial-detection-4">Typical initial detection</h3>
<ul>
<li>
<p>Unusual behaviour of systems or applications (e.g., error, crashes, defacement)</p>
</li>
<li>
<p>Unusual Application Programming Interface (API) calls or access to data</p>
</li>
<li>
<p>Unusual number of Web Application Firewall (WAF) or Security Information and Event Management (SIEM) alerts (e.g., spikes in 4xx/5xx error messages)</p>
</li>
<li>
<p>Reverse or web shells were observed or suspected to be used</p>
</li>
<li>
<p>Abnormal page volumetry (rendered page size / requests per IP)</p>
</li>
<li>
<p>Abnormal behaviour in logs (e.g., access logs)</p>
</li>
</ul>
<h3 id="immediate-response-containment-4">Immediate response (containment)</h3>
<ul>
<li>
<p>Isolate affected systems or applications</p>
</li>
<li>
<p>Identify the vulnerable path and kill-switch it</p>
</li>
<li>
<p>Consider disabling exposed API endpoints</p>
</li>
<li>
<p>Consider deploying or updating blocking WAF rules based on observed attack patterns</p>
</li>
<li>
<p>Notify the Business Continuity Management (BCM) function if critical systems or applications are affected</p>
</li>
<li>
<p>Keep logs and snapshots before patching or rebooting systems</p>
</li>
<li>
<p>Monitor for lateral movement from the web hosting systems to internal networks</p>
</li>
</ul>
<h3 id="investigation-steps-4">Investigation steps</h3>
<ul>
<li>
<p>To identify the exploited vulnerability, review web, API and systems access / error logs and reverse-proxy logs</p>
</li>
<li>
<p>Check if the vulnerability was introduced by a recent change, by checking the source code (e.g., use “<em>diff</em>” command between recent deploys)</p>
</li>
<li>
<p>Look for web shells (e.g., unusual server-side scripts (PHP, Python, Ruby, Node.js, ASP.NET (or other) files))</p>
</li>
<li>
<p>Inspect active network connections and running processes for signs of unauthorized outbound traffic or reverse shells</p>
</li>
<li>
<p>Check files integrity by comparing hashes with baseline (if available), and verify timestamps for unexpected modifications</p>
</li>
<li>
<p>Look for traces of persistence, such as new or modified scheduled tasks, system services or startup scripts</p>
</li>
<li>
<p>If possible, perform a memory analysis to detect fileless malware or injected code that does not exist on disk</p>
</li>
<li>
<p>Determine whether attackers accessed, altered or exfiltrated (sensitive) data (invoke Rulebook 7 – Data Exfiltration if suspected)</p>
</li>
</ul>
<h3 id="remediation-4">Remediation</h3>
<ul>
<li>
<p>Patch vulnerable components or, if not possible, consider disabling</p>
</li>
<li>
<p>Rotate secrets / credentials (e.g., tokens, API keys, database credentials)</p>
</li>
<li>
<p>Remove shells and implants</p>
</li>
<li>
<p>After cleaning steps, consider rebuilding the entire stack where the compromised application is hosted</p>
</li>
<li>
<p>Conduct a full vulnerability scan and validate remediation of exploited paths</p>
</li>
<li>
<p>Re-enable services progressively, under close monitoring</p>
</li>
</ul>
<h3 id="evidence-keeping-4">Evidence keeping</h3>
<ul>
<li>
<p>Full HTTP logs, access / error logs and WAF alerts</p>
</li>
<li>
<p>System and application layers logs (if any)</p>
</li>
<li>
<p>Keep images of the stack where the application is hosted (e.g., container, virtual machine)</p>
</li>
<li>
<p><em>“diffs</em>” of the system hosting the compromised application</p>
</li>
</ul>
<h3 id="post-incident-activity-4">Post-incident activity</h3>
<ul>
<li>
<p>Consider hardening the deployment pipeline and ensuring security review / security testing is part of the development lifecycle</p>
</li>
<li>
<p>Consider improving (or at the very least enabling) API authentication and rate-limits</p>
</li>
<li>
<p>Consider performing a full code review if custom development</p>
</li>
<li>
<p>Consider improving access and input validation controls</p>
</li>
<li>
<p>Consider implementing Server-Side Request Forgery (SSRF) and deserialization guards</p>
</li>
<li>
<p>Consider conducting improving the security review practice, such as regular penetration testing, vulnerability scans and source code reviews</p>
</li>
</ul>
<h3 id="communication-4">Communication</h3>
<ul>
<li>
<p>Alert the development team and/or infrastructure team accordingly to the attack vector</p>
</li>
<li>
<p>Notify business owners of any application downtime or user impact</p>
</li>
<li>
<p>Inform Management and legal / compliance departments if sensitive data was accessed, altered or exfiltrated</p>
</li>
</ul>
<h3 id="key-watchpoints-4">Key watchpoints</h3>
<ul>
<li>
<p>Exploits often lead to data theft: assume exfiltration until disproven</p>
</li>
<li>
<p>Attacks may exploit business logic flaws, not just technical bugs</p>
</li>
</ul>
<h2 id="rulebook-6--insider-threat">Rulebook 6 – Insider threat</h2>
<p>This rulebook applies to situations where an insider (e.g., employee, consultant), having genuine access to the entity’s systems, leverage the granted access to perform malicious actions.</p>
<h3 id="typical-initial-detection-5">Typical initial detection</h3>
<ul>
<li>
<p>Unusual access to sensitive data</p>
</li>
<li>
<p>Unusual large outbound traffic</p>
</li>
<li>
<p>Unusual traffic outside working hours</p>
</li>
<li>
<p>Complaints or warnings from Human Resources (HR) department</p>
</li>
<li>
<p>Unauthorized use of administrative tools or privilege escalation attempts</p>
</li>
</ul>
<h3 id="immediate-response-containment-5">Immediate response (containment)</h3>
<ul>
<li>
<p>Restrict user access thanks to need-to-know and least-privilege principles</p>
</li>
<li>
<p>Monitor ongoing activities, using approved tools and procedures, in respect of applicable laws and internal policies</p>
</li>
<li>
<p>Notify HR, legal, and third-party if affected</p>
</li>
<li>
<p>Suspend access (at least temporarily), if risk of data theft or sabotage is suspected</p>
</li>
</ul>
<h3 id="investigation-steps-5">Investigation steps</h3>
<ul>
<li>
<p>Collect access history, behavioural anomalies and recent changes in permissions or roles</p>
</li>
<li>
<p>Keep evidence, in respect of applicable laws and internal policies, for further (forensics) analysis</p>
</li>
<li>
<p>Use secure communication channels for inquiries with involved stakeholders</p>
</li>
<li>
<p>Perform intent analysis (e.g., looking at disciplinary sanctions, internal business changes, departures, etc.) and leverage threat intelligence</p>
</li>
</ul>
<h3 id="remediation-5">Remediation</h3>
<ul>
<li>
<p>Suspend or, at least, limit access if threat is confirmed</p>
</li>
<li>
<p>Use psychological support in case of internal conflict or distress</p>
</li>
<li>
<p>Change shared passwords and rotate Application Programming Interfaces (API) keys that the insider could have accessed</p>
</li>
</ul>
<h3 id="evidence-keeping-5">Evidence keeping</h3>
<ul>
<li>
<p>Collect end-user computer logs (e.g., email activity, file access), in respect of the Law</p>
</li>
<li>
<p>Communication with HR, legal, or management about the case</p>
</li>
<li>
<p>Role history within the entity</p>
</li>
<li>
<p>Maintain strict access control to investigative data (“need-to-know” principle)</p>
</li>
</ul>
<h3 id="post-incident-activity-5">Post-incident activity</h3>
<ul>
<li>
<p>Consider enhanced background screening procedures</p>
</li>
<li>
<p>Consider implementing user behaviour analytics (UBA)</p>
</li>
<li>
<p>Consider reviewing the Data Loss Prevention (DLP) policy and related measures</p>
</li>
<li>
<p>Consider enforcing stronger segmentation, based on need-to-know and least-privilege principles, and role-based access</p>
</li>
</ul>
<h3 id="communication-5">Communication</h3>
<ul>
<li>
<p>Continuously communicate with legal, compliance, HR, and management</p>
</li>
<li>
<p>Limit information sharing to those strictly required (“need to know” principle) to protect confidentiality</p>
</li>
</ul>
<h3 id="key-watchpoints-5">Key watchpoints</h3>
<ul>
<li>
<p>Do not confuse malicious acts with negligence</p>
</li>
<li>
<p>Personal motives are common</p>
</li>
</ul>
<h2 id="rulebook-7--data-exfiltration">Rulebook 7 – Data exfiltration</h2>
<p>This rulebook applies to situations where entity’s data is exfiltrated, without authorization.</p>
<h3 id="typical-initial-detection-6">Typical initial detection</h3>
<ul>
<li>
<p>Unusual access to sensitive data</p>
</li>
<li>
<p>Unusual large outbound traffic</p>
</li>
<li>
<p>Unusual traffic outside working hours</p>
</li>
<li>
<p>Suspicious (obfuscated) outbound traffic</p>
</li>
<li>
<p>Alert from Endpoint Detection and Response (EDR) or threat intelligence resources</p>
</li>
<li>
<p>Sudden large file transfers</p>
</li>
<li>
<p>Long dwell</p>
</li>
<li>
<p>Data Loss Prevention (DLP) or proxy alerts indicating sensitive data movement outside of approved channels</p>
</li>
<li>
<p>Data discovered outside traditional channels (e.g., Telegram, web forums, press, or other media)</p>
</li>
</ul>
<h3 id="immediate-response-containment-6">Immediate response (containment)</h3>
<ul>
<li>
<p>Decide on the strategy based on the sensitivity and leakage impact: either block or monitor</p>
</li>
<li>
<p>Monitor or isolate suspected compromised systems, ensuring forensic integrity is preserved</p>
</li>
<li>
<p>Limit or block suspected exfiltration channels (e.g., Secure File Transfer Protocol (SFTP) or Hypertext Transfer Protocol Secure (HTTPS) to unusual Autonomous System Numbers (ASNs) or cloud platform)</p>
</li>
<li>
<p>Disable remote access (e.g., Virtual Private Network (VPN), Secure Shell (SSH)) on suspect compromised accounts and machines</p>
</li>
<li>
<p>Monitor for Command and Control (C2) traffic</p>
</li>
<li>
<p>Perform full disk acquisition (e.g., using “dd” tool)</p>
</li>
</ul>
<h3 id="investigation-steps-6">Investigation steps</h3>
<ul>
<li>
<p>Check for persistence traces (e.g., scheduled tasks, web shells, “Living Off the Land” (LOTL) use)</p>
</li>
<li>
<p>Identify exfiltrated data and volume</p>
</li>
<li>
<p>Build a timeline</p>
</li>
<li>
<p>Determine dwell time and entry point (e.g., exploited vulnerability)</p>
</li>
<li>
<p>Look for locations used for data staging (e.g., temporary folders, shared drives, cloud synchronization directories)</p>
</li>
<li>
<p>Check systems that can be used for lateral communication (e.g., email, chat, and collaboration platforms)</p>
</li>
</ul>
<h3 id="remediation-6">Remediation</h3>
<ul>
<li>
<p>Remove attacker persistence (e.g., web shells, implants, scheduled tasks)</p>
</li>
<li>
<p>Consider restoring the whole IT infrastructure, or at least the part that is for sure compromised</p>
</li>
<li>
<p>Consider resetting all the credentials and tokens (i.e., user accounts, technical accounts, administrative accounts, etc.), including long-lived and cloud-integrated tokens</p>
</li>
<li>
<p>Consider using “tiered credential rotation”</p>
</li>
<li>
<p>Consider reviewing the Data Loss Prevention (DLP) policy and related measures</p>
</li>
<li>
<p>Consider segmenting access (e.g., Zero-Trust and least-privilege principles)</p>
</li>
</ul>
<h3 id="evidence-keeping-6">Evidence keeping</h3>
<ul>
<li>
<p>Network captures, proxy logs, system images</p>
</li>
<li>
<p>Any log evidencing a staged attack (e.g., relying on collaboration, chat or email)</p>
</li>
<li>
<p>DLP and Cloud Access Security Broker (CASB) alerts</p>
</li>
</ul>
<h3 id="post-incident-activity-6">Post-incident activity</h3>
<ul>
<li>
<p>Patch all entry vectors (e.g., VPN, email, apps)</p>
</li>
<li>
<p>Consider implementing a threat-hunting practice</p>
</li>
<li>
<p>Consider deploying detections mechanisms for LOTL and unusual outbound traffic</p>
</li>
</ul>
<h3 id="communication-6">Communication</h3>
<ul>
<li>
<p>Escalate to Top Management, legal, and compliance</p>
</li>
<li>
<p>Coordinate with Data-Protection Officer (DPO), if personal data was exfiltrated (c.f., General Data Protection Regulation (GDPR))</p>
</li>
</ul>
<h3 id="key-watchpoints-6">Key watchpoints</h3>
<ul>
<li>
<p>Exfiltration may be stealthy and encrypted (e.g., sent to common cloud services, and chunked in small packets)</p>
</li>
<li>
<p>Advanced attackers may use fileless techniques and hide in legitimate processes (LOTL)</p>
</li>
</ul>
<h2 id="rulebook-8--package-compromission--supply-chain-attack">Rulebook 8 – Package compromission &amp; supply chain attack</h2>
<p>This rulebook applies to situations where an attack leverages third-party dependencies (e.g., software packages, libraries, open-source codes, firmware, etc.) to compromise the entity’s systems.</p>
<h3 id="typical-initial-detection-7">Typical initial detection</h3>
<ul>
<li>
<p>Unusual alerts following a software or firmware update, or the integration of a new third-party package</p>
</li>
<li>
<p>Failures in hash validation or use of unexpected certificates used to sign packages</p>
</li>
<li>
<p>Outbound traffic to abnormal domains</p>
</li>
<li>
<p>Endpoint Detection and Response (EDR) alerts on newly updated binaries, installers or side-loaded Dynamic-Link Libraries (DLLs)</p>
</li>
<li>
<p>Permission abuse of an application or integration (e.g., observed via unexpected OAuth / Single Sign On (SSO) consent or expanded scopes)</p>
</li>
<li>
<p>Unusual requests originating from third-party services (e.g., API calls to unusual domains)</p>
</li>
<li>
<p>Software behaviour not in line with the intended design (i.e., Software Bill of Materials (SBOM) drift)</p>
</li>
</ul>
<h3 id="immediate-response-containment-7">Immediate response (containment)</h3>
<ul>
<li>
<p>For all the systems, freeze the deployments and disable the auto-updates</p>
</li>
<li>
<p>At network level, move affected hosts, containers and build agents (i.e., the worker machines that execute the Continuous Integration / Continuous Delivery (CI/CD) jobs) to quarantine</p>
</li>
<li>
<p>Block the observed Indicators of Compromise (IoCs) (e.g., domains, IP addresses, hashes, certificates)</p>
</li>
<li>
<p>Restrict the outbound traffic of affected systems to a small allowlist of trusted software-update endpoints</p>
</li>
<li>
<p>Revoke or rotate affected (or suspected to be affected) secrets and tokens</p>
</li>
<li>
<p>Disable suspicious OAuth and SSO integrations</p>
</li>
<li>
<p>Require an additional authentication challenge (beyond the initial login) for administrators</p>
</li>
<li>
<p>Inform the Security Operations Centre (SOC) and the Business Continuity Management (BCM) function of the incident, to seek for additional technical and business impact</p>
</li>
<li>
<p>Look for vendors or maintainers’ advice</p>
</li>
</ul>
<h3 id="investigation-steps-7">Investigation steps</h3>
<ul>
<li>
<p>Identify the compromised components; in particular note the affected versions and install times</p>
</li>
<li>
<p>List all the subsequent assets at risks, including those installed, updated, or used by the compromised components</p>
</li>
<li>
<p>Verify digital signatures and compare hashes with trusted sources</p>
</li>
<li>
<p>Validate certificate chain and revocation</p>
</li>
<li>
<p>Look for full process descendant chains (i.e., children processes, grandchildren processes, etc.) originating from affected installers</p>
</li>
<li>
<p>Review the CI/CD logs, the artifact repository records and SBOMs for potential traces of alteration</p>
</li>
<li>
<p>Audit logs to identify potential token abuse or data access</p>
</li>
<li>
<p>Hunt for traces of persistence (e.g., services, scheduled tasks, Windows Management Instrumentation (WMI), etc.)</p>
</li>
<li>
<p>Check for traces of lateral movement, privilege escalation and exfiltration</p>
</li>
<li>
<p>Verify the authenticity and integrity of upstream update channels and sources (e.g., golden images, Mobile Device Management (MDM) baselines, mirrors, update proxies like Windows Server Update Services (WSUS)) by validating signatures, certificate chains/revocation, and digests</p>
</li>
<li>
<p>Keep a timeline and take note of remediation decisions and actions</p>
</li>
</ul>
<h3 id="remediation-7">Remediation</h3>
<ul>
<li>
<p>Put the compromised packages in a blocklist and remove them from the registries and caches</p>
</li>
<li>
<p>Patch with clean updates or roll back to last know clean versions</p>
</li>
<li>
<p>Rebuild, or redeploy or replace the compromised components, using trusted sources</p>
</li>
<li>
<p>Recreate the impacted systems</p>
</li>
<li>
<p>Rotate or invalidate, as appropriate, the secrets, API keys, certificates, signing keys, SSH keys, SSO / OAuth refresh tokens, etc., potentially exposed to the attack</p>
</li>
<li>
<p>Remove the persistence artifacts (e.g., services, scheduled tasks, Windows Management Instrumentation (WMI), etc.)</p>
</li>
<li>
<p>Perform integrity checks, check packages execution in sandboxes and increase the monitoring sensitivity (temporarily)</p>
</li>
</ul>
<h3 id="evidence-keeping-7">Evidence keeping</h3>
<ul>
<li>
<p>Take snapshots of compromised Virtual Machines (VMs) and take capture of memory on key affected hosts</p>
</li>
<li>
<p>Keep copies of the malicious components (e.g., installers, packages, containers, certificate chains, etc.)</p>
</li>
<li>
<p>Keep a list of the instructions used to produce the malicious components (e.g., URL of repositories, applied patches, required packages, compiler, commands, etc.) and the traces of who / what built it and when</p>
</li>
<li>
<p>Keep logs of EDR, endpoints, CI/CD, artifact registries, proxies, access, etc.</p>
</li>
<li>
<p>Capture network traffic of key affected systems</p>
</li>
<li>
<p>Keep trace and a timeline of the communications with the vendors or the maintainers</p>
</li>
</ul>
<h3 id="post-incident-activity-7">Post-incident activity</h3>
<ul>
<li>
<p>Consider enforcing the source verifications, for instance via verified SBOMs and attestations</p>
</li>
<li>
<p>Consider implanting private registries and update proxies (rather than connecting directly to the Internet) together with a source allowlist</p>
</li>
<li>
<p>Consider using “tiered credential rotation” and reducing the lifetime of tokens for third-party access</p>
</li>
<li>
<p>Consider reviewing CI/CD hardening controls and look for potential improvements (e.g., only accept components with valid signatures, Multi-Factor Authentication (MFA) for privileged access to the pipeline, least privilege principle, enforce isolation for runners (i.e., not privileged, destroyed after each build, segregated as much as possible))</p>
</li>
<li>
<p>Consider implementing a careful strategy for deployments (e.g., “canary” releases and staged rollouts with rollback mechanisms)</p>
</li>
<li>
<p>Consider ongoing controls over third‑party components, verifying software authenticity with digital signatures, and limiting connections to known certificates only where appropriate</p>
</li>
<li>
<p>Consider improving the vendors and maintainers’ risk review, including contract security clauses and “kill-switch” rights (i.e., possibility to disable product, or update or data flow, on the entity’s end)</p>
</li>
<li>
<p>Consider monitoring exfiltration via tunnelling techniques</p>
</li>
</ul>
<h3 id="communication-7">Communication</h3>
<ul>
<li>
<p>Coordinate with the Security Operations Centre (SOC) and IT teams</p>
</li>
<li>
<p>Contact the vendors or the maintainers for IoCs, patches, advice and root cause analysis</p>
</li>
<li>
<p>Inform business owners and clients if appropriate</p>
</li>
</ul>
<h3 id="key-watchpoints-7">Key watchpoints</h3>
<ul>
<li>
<p>Beware of stolen certificates, which are commonly used, and prevent relying solely on code signing</p>
</li>
<li>
<p>Beware of auto-update feature that can lead to new infection</p>
</li>
<li>
<p>Third-party application may have excessive access rights</p>
</li>
<li>
<p>Beware of long dwell time and potential second‑stage payloads</p>
</li>
<li>
<p>Attackers often target build systems; therefore, isolation and monitoring are key</p>
</li>
<li>
<p>Offline and immutable backups are key to recover</p>
</li>
</ul>
<h2 id="glossary-generated-via-artificial-intelligence-tools">Glossary (generated via artificial intelligence tools)</h2>
<table>
	<thead>
			<tr>
					<th><strong>Acronym / expression</strong></th>
					<th><strong>Meaning</strong></th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td>AD</td>
					<td>Active Directory. A directory service developed by Microsoft for Windows domain networks that functions as a centralized database for network information. It stores data about network objects (users, computers, printers) and manages security policies, authentication, and authorization across the entire network infrastructure</td>
			</tr>
			<tr>
					<td>Adware</td>
					<td>Software that automatically displays or downloads advertising material (often unwanted) when a user is online</td>
			</tr>
			<tr>
					<td>ANSSI</td>
					<td>Agence Nationale de la Sécurité des Systèmes d’Information</td>
			</tr>
			<tr>
					<td>API</td>
					<td>Application Programming Interface. A set of defined rules and protocols that allows different software applications to communicate with each other, enabling them to exchange data and functionality without needing to understand each other’s internal code</td>
			</tr>
			<tr>
					<td>ASN</td>
					<td>Autonomous System Number. Unique number assigned to a network or group of IP prefixes under a single routing policy, used to identify it in BGP routing on the internet</td>
			</tr>
			<tr>
					<td>AV</td>
					<td>Antivirus. Software designed to detect, prevent, and remove malicious software (malware), such as viruses, worms, and Trojans</td>
			</tr>
			<tr>
					<td>Backdoor</td>
					<td>A covert method of bypassing normal authentication or encryption in a computer system, a product, or an embedded device</td>
			</tr>
			<tr>
					<td>BCM</td>
					<td>Business Continuity Management. A holistic management process that identifies potential threats to an organization and the impacts to business operations those threats, if realized, might cause</td>
			</tr>
			<tr>
					<td>BCP</td>
					<td>Business Continuity Plan. A document that outlines the processes and procedures an organization will follow to maintain essential functions during and after an unplanned event or disruption</td>
			</tr>
			<tr>
					<td>BGP</td>
					<td>Border Gateway Protocol. Standard exterior routing protocol that exchanges routing and reachability information between autonomous systems on the internet</td>
			</tr>
			<tr>
					<td>Botnet</td>
					<td>A network of private computers infected with malicious software and controlled as a group without the owners’ knowledge, often used to launch DDoS attacks, send spam, or spread malware</td>
			</tr>
			<tr>
					<td>Brute Forcing</td>
					<td>An attack method that involves systematically checking all possible combinations of passwords or keys until the correct one is found. It is a “trial-and-error” approach that can be time-consuming but effective against weak or short credentials</td>
			</tr>
			<tr>
					<td>C2</td>
					<td>Command and Control. The server infrastructure used by attackers to communicate with compromised systems, send commands, and exfiltrate data</td>
			</tr>
			<tr>
					<td>Canary</td>
					<td>Refers to “Canary Deployment” or “Canary Release”. A software release strategy where a new version of an application is rolled out to a small subset of users (the “canaries”) before being deployed to the entire user base. If the new version contains bugs or performance issues, only a small group is affected, and the rollout can be quickly reversed.<br>It can also refer to “Canary Tokens”, which are digital tripwires used to detect breaches</td>
			</tr>
			<tr>
					<td>CASB</td>
					<td>Cloud Access Security Broker. A security policy enforcement point (software or service) that sits between cloud service consumers (users) and cloud service providers. It allows organizations to extend their security policies into the cloud by providing visibility into cloud application usage, enforcing data security (like encryption and DLP), and detecting threats across cloud environments</td>
			</tr>
			<tr>
					<td>CDN</td>
					<td>Content Delivery Network. A geographically distributed group of servers that work together to provide fast delivery of Internet content</td>
			</tr>
			<tr>
					<td>CEO</td>
					<td>Chief Executive Officer</td>
			</tr>
			<tr>
					<td>CERT</td>
					<td>Computer Emergency Response Team. An expert group responsible for handling computer security incidents, including detection, response, and recovery</td>
			</tr>
			<tr>
					<td>CI/CD</td>
					<td>Continuous Integration/Continuous Delivery (or Deployment). A DevOps practice that automates the software development lifecycle.<br>CI (Continuous Integration): Developers frequently merge code changes into a central repository, where automated builds and tests run to detect bugs early.<br>CD (Continuous Delivery/Deployment): Automates the release process, ensuring code can be reliably released to production at any time (Delivery) or is automatically released to production after passing tests (Deployment)</td>
			</tr>
			<tr>
					<td>CIRCL</td>
					<td>Computer Incident Response Center Luxembourg</td>
			</tr>
			<tr>
					<td>CNPD</td>
					<td>Commission Nationale pour la Protection des Données</td>
			</tr>
			<tr>
					<td>Container</td>
					<td>A lightweight, standalone executable package that includes everything needed to run a piece of software, including the code, runtime, libraries, and system tools. Containers share the host OS kernel but run in isolated user spaces, offering a more efficient alternative to full virtual machines</td>
			</tr>
			<tr>
					<td>CPU</td>
					<td>Central Processing Unit. The primary component of a computer that acts as its “brain”, executing instructions and performing calculations necessary for software to run</td>
			</tr>
			<tr>
					<td>Credential Dumping</td>
					<td>The technique of extracting sensitive authentication data (like cleartext passwords, hashes, and Kerberos tickets) from the memory of the Local Security Authority Subsystem Service (LSASS) process on Windows. Tools like Mimikatz are commonly used to “dump” this memory, allowing attackers to steal credentials for privilege escalation and lateral movement</td>
			</tr>
			<tr>
					<td>Crypto miner</td>
					<td>Malware that uses a victim’s computer processing power to mine for cryptocurrencies without their consent or knowledge, often leading to significant performance degradation</td>
			</tr>
			<tr>
					<td>CSIRT</td>
					<td>Computer Security Incident Response Team. A specialized group of IT professionals responsible for managing, coordinating, and responding to cybersecurity incidents within an organization to minimize damage and ensure recovery.</td>
			</tr>
			<tr>
					<td>CSSF</td>
					<td>Commission de Surveillance du Secteur Financier</td>
			</tr>
			<tr>
					<td>DDoS</td>
					<td>Distributed Denial of Service. A type of cyberattack where multiple compromised systems (botnets) are used to target a single system or network, overwhelming it with traffic to render it unavailable</td>
			</tr>
			<tr>
					<td>DevOps</td>
					<td>Development and Operations. A collaborative software development methodology that bridges the gap between software developers (Dev) and IT operations teams (Ops)</td>
			</tr>
			<tr>
					<td>DKIM</td>
					<td>DomainKeys Identified Mail. An email security standard that adds a cryptographic digital signature to emails. This signature verifies that the email was indeed sent by the claimed domain and that its contents have not been altered in transit</td>
			</tr>
			<tr>
					<td>DLL</td>
					<td>Dynamic Link Library. A file format used in Microsoft Windows that contains shared code and data (such as functions or resources) which can be used by multiple programs simultaneously</td>
			</tr>
			<tr>
					<td>DLP</td>
					<td>Data Loss Prevention. A set of tools, strategies, and processes designed to ensure that sensitive data is not lost, misused, or accessed by unauthorized users</td>
			</tr>
			<tr>
					<td>DMARC</td>
					<td>Domain-based Message Authentication, Reporting, and Conformance. An email authentication protocol that builds on SPF and DKIM. It allows domain owners to publish a policy telling receiving servers what to do if an email fails authentication (e.g., reject it or mark it as spam) and provides reports on email activity</td>
			</tr>
			<tr>
					<td>DNS</td>
					<td>Domain Name System. The hierarchical naming system that translates human-readable domain names (like <a href="https://www.example.com">www.example.com</a>) into machine-readable IP addresses</td>
			</tr>
			<tr>
					<td>DORA</td>
					<td>Digital Operational Resilience Act</td>
			</tr>
			<tr>
					<td>DoS</td>
					<td>Denial of Service. A cyberattack that aims to make a machine, network, or service unavailable to its intended users by overwhelming it with excessive traffic or exploiting vulnerabilities to crash the system</td>
			</tr>
			<tr>
					<td>DPO</td>
					<td>Data Protection Officer</td>
			</tr>
			<tr>
					<td>Dropper</td>
					<td>A type of Trojan horse designed to “drop” (install) other malware onto a target system. Unlike a downloader that fetches malware from the internet, a dropper typically contains the malicious payload within itself, often encrypted or compressed to evade detection by antivirus software. Once executed, it extracts and installs the payload (such as ransomware or a backdoor) and may then delete itself to hide evidence of the infection</td>
			</tr>
			<tr>
					<td>DRP</td>
					<td>Disaster Recovery Plan. A documented, structured approach that describes how an organization can quickly resume work after an unplanned incident. A DRP is a subset of a Business Continuity Plan (BCP) and focuses specifically on restoring IT infrastructure and operations after a crisis</td>
			</tr>
			<tr>
					<td>EDR</td>
					<td>Endpoint Detection and Response. A cybersecurity technology that continuously monitors endpoint devices (like laptops and servers) to detect and respond to advanced threats that may bypass traditional antivirus solutions</td>
			</tr>
			<tr>
					<td>GDPR</td>
					<td>General Data Protection Regulation</td>
			</tr>
			<tr>
					<td>Geo-fencing</td>
					<td>A security mechanism that creates a virtual geographic boundary (“fence”) around a physical location</td>
			</tr>
			<tr>
					<td>GOVCERT.LU</td>
					<td>Governmental Computer Security Incident Response Team</td>
			</tr>
			<tr>
					<td>GPO</td>
					<td>Group Policy Object. A feature in Microsoft Windows Active Directory that allows administrators to define and control the working environment of users and computers. GPOs are used to enforce security settings and user configurations across a network</td>
			</tr>
			<tr>
					<td>Hash</td>
					<td>A fixed-size alphanumeric string generated from data of any size using a mathematical formula (hashing algorithm). Hashes are like “digital fingerprints”; if even a single bit of the original data changes, the resulting hash changes completely. They are used to verify data integrity and store passwords securely</td>
			</tr>
			<tr>
					<td>HCPN</td>
					<td>High Commission for National Protection</td>
			</tr>
			<tr>
					<td>HR</td>
					<td>Human Resources</td>
			</tr>
			<tr>
					<td>HTTP/HTTPS</td>
					<td>Hypertext Transfer Protocol (HTTP) is the fundamental protocol for transferring data (like webpages) over the internet. However, it transmits data in “plain text”, meaning anyone intercepting the traffic can read it.<br>HTTPS (HTTP Secure) is the secure version that adds an encryption layer using TLS (Transport Layer Security). It ensures that data exchanged between a user’s browser and the website is encrypted and authenticated, preventing attackers from eavesdropping, tampering with data, or impersonating the site</td>
			</tr>
			<tr>
					<td>Hypervisor</td>
					<td>Software, firmware, or hardware that creates and runs virtual machines (VMs) by separating a computer’s operating system and applications from the underlying physical hardware. From a security perspective, hypervisors provide isolation between VMs, but if compromised, an attacker could gain control over all guest systems</td>
			</tr>
			<tr>
					<td>IAM</td>
					<td>Identity and Access Management. A framework of policies and technologies that ensures the right individuals have the appropriate access to technology resources. It manages digital identities (like user accounts) and controls user access permissions to critical information and systems within an organization</td>
			</tr>
			<tr>
					<td>IdP</td>
					<td>Identity Provider. A system component or service that creates, maintains, and manages digital identity information for users and devices. It provides authentication services to other applications, allowing a user to log in once (Single Sign-On) and gain access to multiple different systems without creating new credentials for each one</td>
			</tr>
			<tr>
					<td>IDS</td>
					<td>Intrusion Detection System. A security tool that passively monitors network traffic or system events for suspicious activity and known threats, alerting administrators when potential breaches are detected without actively blocking them</td>
			</tr>
			<tr>
					<td>ILR</td>
					<td>Institut Luxembourgeois de Régulation</td>
			</tr>
			<tr>
					<td>Infostealer</td>
					<td>Malware designed specifically to find and exfiltrate sensitive information from a victim’s computer, such as login credentials, financial data, and personal documents</td>
			</tr>
			<tr>
					<td>IOC</td>
					<td>Indicator of Compromise. Forensic artifact or data point that indicates a system or network has likely been breached or is under malicious activity</td>
			</tr>
			<tr>
					<td>IP</td>
					<td>Internet Protocol. Network protocol that defines how data packets are addressed and routed between devices, using unique IP addresses to identify and locate each device on a network</td>
			</tr>
			<tr>
					<td>IPS</td>
					<td>Intrusion Prevention System. An active security control that sits in-line with network traffic to inspect packets in real-time, detecting malicious activity and automatically blocking or mitigating threats before they can damage the network</td>
			</tr>
			<tr>
					<td>ISP</td>
					<td>Internet Service Provider. A company or organization that provides customers with access to the internet and related services</td>
			</tr>
			<tr>
					<td>IT</td>
					<td>Information Technology</td>
			</tr>
			<tr>
					<td>Kerberoasting</td>
					<td>A post-exploitation attack targeting Active Directory service accounts. An authenticated attacker requests a Kerberos service ticket for a specific Service Principal Name (SPN). The returned ticket is encrypted with the service account’s password hash. The attacker then takes this ticket offline to crack the hash using brute force, revealing the service account’s plaintext password</td>
			</tr>
			<tr>
					<td>KEV</td>
					<td>Known Exploited Vulnerabilities</td>
			</tr>
			<tr>
					<td>Keylogger</td>
					<td>A type of spyware that records every keystroke made on a computer. This allows attackers to steal sensitive information such as usernames, passwords, and credit card numbers</td>
			</tr>
			<tr>
					<td>Kill-switch</td>
					<td>A security mechanism designed to immediately shut down or disconnect a system, application, or network connection in an emergency</td>
			</tr>
			<tr>
					<td>Lateral movement</td>
					<td>Techniques used by attackers after initial access to move from one compromised system to others within the same network, in order to discover, access, and control additional assets or sensitive data while evading detection</td>
			</tr>
			<tr>
					<td>Logic bomb</td>
					<td>A piece of malicious code intentionally inserted into a software system that will set off a malicious function when specified conditions are met</td>
			</tr>
			<tr>
					<td>LOTL</td>
					<td>Living Off the Land. A cyberattack technique where attackers use legitimate, pre-installed tools and features already present in the target system (such as PowerShell, WMI, or BASH) to conduct malicious activities. Because these tools are trusted and standard, the attack activity blends in with normal system operations, making it difficult for traditional security tools to detect</td>
			</tr>
			<tr>
					<td>LSASS</td>
					<td>Local Security Authority Subsystem Service. A critical Microsoft Windows system process (lsass.exe) responsible for enforcing security policies on the system. It verifies users logging on to a computer or server, handles password changes, and creates access tokens. Crucially for cybersecurity, LSASS stores sensitive credentials (like password hashes and Kerberos tickets) in its process memory to facilitate single sign-on. Because of this, it is a primary target for attackers using tools like Mimikatz to “dump” this memory and steal credentials for lateral movement</td>
			</tr>
			<tr>
					<td>MDM</td>
					<td>Mobile Device Management. A type of security software used by IT departments to monitor, manage, and secure mobile devices (smartphones, tablets, laptops) that access corporate data</td>
			</tr>
			<tr>
					<td>MFA</td>
					<td>Multi-Factor Authentication. A security method that requires users to provide two or more verification factors to gain access to a resource, such as an application or online account, adding a critical layer of security beyond just a password</td>
			</tr>
			<tr>
					<td>NAC</td>
					<td>Network Access Control. A security approach that restricts unauthorized users and devices from gaining access to corporate networks. NAC can enforce security policies on devices before they are allowed to connect</td>
			</tr>
			<tr>
					<td>NIS2 directive</td>
					<td>Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union</td>
			</tr>
			<tr>
					<td>NTP</td>
					<td>Network Time Protocol. A networking protocol used to synchronize clocks between computer systems over packet-switched, variable-latency data networks, ensuring devices maintain accurate and consistent time for logs, security certificates, and scheduled tasks</td>
			</tr>
			<tr>
					<td>OAuth</td>
					<td>Open Authorization. An open standard protocol that allows users to grant third-party websites or applications access to their information on other websites without sharing their passwords. It functions by exchanging tokens rather than credentials</td>
			</tr>
			<tr>
					<td>Pass-the-Hash Attack (PtH)</td>
					<td>A lateral movement technique where an attacker captures a hashed user credential (not the plaintext password) and uses it directly to authenticate to a remote server or service. This exploits authentication protocols that accept hashes for verification, allowing attackers to bypass the need for the actual password</td>
			</tr>
			<tr>
					<td>Pass-the-Ticket Attack (PtT)</td>
					<td>A post-exploitation technique where an attacker steals a valid Kerberos ticket (such as a Ticket Granting Ticket or TGT) from a compromised system and uses it to authenticate to network resources. This allows the attacker to move laterally across the network appearing as a legitimate user, often bypassing MFA</td>
			</tr>
			<tr>
					<td>Password Spraying</td>
					<td>A specific type of brute force attack where an attacker tries a single common password (e.g., “Winter2025!”) against many different user accounts. This “low-and-slow” approach is designed to avoid triggering account lockout policies that would normally block repeated failed login attempts on a single account</td>
			</tr>
			<tr>
					<td>Payload</td>
					<td>The component of a cyberattack or malware that executes the malicious activity. While the “delivery mechanism” (like a phishing email) gets the threat to the target, the payload is the cargo that performs the actual harm, such as encrypting files (ransomware), stealing data (spyware), or installing a backdoor</td>
			</tr>
			<tr>
					<td>PCAP</td>
					<td>Packet Capture. File or data format that stores raw network packets captured from a network interface for later analysis</td>
			</tr>
			<tr>
					<td>Privilege escalation</td>
					<td>A cyberattack technique where an attacker, having already gained initial low-level access to a system, exploits vulnerabilities, bugs, or misconfigurations to elevate their permissions</td>
			</tr>
			<tr>
					<td>PsExec</td>
					<td>A command-line tool from the Sysinternals suite that allows users to execute processes on remote systems with full interactivity. While a legitimate administrative tool, it is frequently abused by attackers for lateral movement and remote code execution within a compromised network</td>
			</tr>
			<tr>
					<td>QoS</td>
					<td>Quality of Service. A set of technologies and mechanisms that manage data traffic on a network to ensure reliability and performance for critical applications</td>
			</tr>
			<tr>
					<td>Ransomware</td>
					<td>Malware that encrypts a victim’s files or locks them out of their system, demanding a ransom payment, often in cryptocurrency, in exchange for the decryption key or access</td>
			</tr>
			<tr>
					<td>RAT</td>
					<td>Remote Access Trojan. A type of malware that provides an attacker with remote administrative control over an infected computer</td>
			</tr>
			<tr>
					<td>RDP</td>
					<td>Remote Desktop Protocol. A proprietary protocol developed by Microsoft that provides a user with a graphical interface to connect to another computer over a network connection</td>
			</tr>
			<tr>
					<td>Registry</td>
					<td>A hierarchical database in Microsoft Windows that stores low-level settings and configuration information for the operating system and for applications that opt to use it. It is a critical component for system function and a frequent target for malware, which may use it for persistence, configuration changes, or storing malicious data</td>
			</tr>
			<tr>
					<td>Reverse Shell</td>
					<td>A type of connection where the target machine (victim) actively initiates a network connection back to the attacker’s machine. This technique is used to bypass inbound firewall rules, which typically block outside connections but allow internal systems to connect out to the internet</td>
			</tr>
			<tr>
					<td>RMM</td>
					<td>Remote Monitoring and Management. Software platforms, often used legitimately by IT administrators, that allow for the remote management and monitoring of endpoints. However, attackers can abuse these tools to gain persistent access to a network, appearing as legitimate traffic to evade detection</td>
			</tr>
			<tr>
					<td>Rootkit</td>
					<td>A collection of malicious software tools that gives an unauthorized user privileged (“root”) access to and control over a computer system without being detected. Rootkits can hide their presence and other malware on a system</td>
			</tr>
			<tr>
					<td>SBOM</td>
					<td>Software Bill of Materials. A comprehensive inventory or “ingredients list” of all components, libraries, and dependencies that make up a piece of software. It is critical for supply chain security, allowing organizations to quickly identify if they are using vulnerable open-source components within their applications</td>
			</tr>
			<tr>
					<td>Session Hijacking</td>
					<td>A cyberattack method where an attacker intercepts or steals a valid session token (like a cookie) to impersonate a legitimate user. This allows the attacker to access the user’s active session and services without needing to know their username or password</td>
			</tr>
			<tr>
					<td>SFTP</td>
					<td>Secure File Transfer Protocol (or SSH File Transfer Protocol). A network protocol used for securely transferring files between systems over an encrypted connection. Unlike standard FTP, which sends data in plain text, SFTP uses the SSH (Secure Shell) protocol to encrypt both commands and data, protecting sensitive information from interception during transit</td>
			</tr>
			<tr>
					<td>SHA-256</td>
					<td>Secure Hash Algorithm 256-bit. A cryptographic function developed that converts data of any size into a fixed 256-bit string (hash).</td>
			</tr>
			<tr>
					<td>SIEM</td>
					<td>Security Information and Event Management. A security solution that provides real-time analysis of security alerts generated by applications and network hardware. It aggregates log data from various sources, identifies deviations from norms, and enables security teams to detect, investigate, and respond to threats more effectively</td>
			</tr>
			<tr>
					<td>SMB</td>
					<td>Server Message Block. A network file sharing protocol that allows applications on a computer to read and write to files and to request services from server programs in a computer network</td>
			</tr>
			<tr>
					<td>SMS</td>
					<td>Short Message Service</td>
			</tr>
			<tr>
					<td>Snapshot</td>
					<td>A record of the state of a system, disk volume, or file system at a specific point in time</td>
			</tr>
			<tr>
					<td>SOC</td>
					<td>Security Operations Centre. A centralized unit that deals with security issues on an organizational and technical level. A SOC is comprised of a team of cybersecurity professionals who monitor, analyse, and respond to cybersecurity incidents</td>
			</tr>
			<tr>
					<td>SPF</td>
					<td>Sender Policy Framework. An email authentication protocol that allows domain owners to specify which mail servers are authorized to send email on behalf of their domain. This helps prevent attackers from spoofing (impersonating) the domain in phishing emails</td>
			</tr>
			<tr>
					<td>SPN</td>
					<td>Service Principal Name. A unique identifier used in the Kerberos authentication protocol to identify a specific service instance (like a SQL server or HTTP service) running in an Active Directory environment. It maps a service to the account it is running under (a user or computer account), allowing the network to authenticate the service. Attackers often scan for SPNs to identify service accounts that can be targeted in “Kerberoasting” attacks to crack their passwords</td>
			</tr>
			<tr>
					<td>Spyware</td>
					<td>Malware that secretly observes the user’s computer activities without permission and reports it to the software’s author</td>
			</tr>
			<tr>
					<td>SSH</td>
					<td>Secure Shell. A network protocol that gives users, particularly system administrators, a secure way to access a computer over an unsecured network</td>
			</tr>
			<tr>
					<td>SSL</td>
					<td>Secure Sockets Layer. An older encryption protocol designed to secure communications over a computer network. While the term “SSL” is still widely used colloquially to refer to web encryption certificates, the protocol itself has been deprecated and replaced by the more secure TLS</td>
			</tr>
			<tr>
					<td>SSO</td>
					<td>Single Sign-On. An authentication process that allows a user to access multiple applications and services with one set of login credentials</td>
			</tr>
			<tr>
					<td>SSRF</td>
					<td>Server-Side Request Forgery. A web security vulnerability that allows an attacker to trick a server into sending requests to unintended locations. Attackers often use this to force the server to connect to internal-only services (like metadata services in cloud environments) to access sensitive data or credentials</td>
			</tr>
			<tr>
					<td>Supply chain attack</td>
					<td>A cyberattack that targets an organization by infiltrating a trusted third-party vendor, supplier, or partner in its supply chain. Instead of attacking the primary target directly (which may have strong defences), attackers compromise a less secure external provider – such as a software vendor, hardware manufacturer, or managed service provider – to gain access to the target’s network</td>
			</tr>
			<tr>
					<td>SYN/ACK</td>
					<td>Synchronize/Acknowledge. The second step in the TCP three-way handshake used to establish a reliable network connection</td>
			</tr>
			<tr>
					<td>Sysinternals</td>
					<td>A suite of free, advanced system utilities and technical resources designed to manage, diagnose, troubleshoot, and monitor Microsoft Windows environments. The suite includes a wide range of tools, many of which are essential for cybersecurity professionals for tasks like malware analysis, incident response, and performance troubleshooting. Popular tools in the suite include Process Explorer, Autoruns, Sysmon, and PsExec</td>
			</tr>
			<tr>
					<td>Sysmon</td>
					<td>A Windows service and device driver from the Sysinternals suite that provides advanced system monitoring. It logs detailed information about process creations, network connections, and changes to the file system to a dedicated event log, offering deeper visibility for threat hunting and incident response than standard Windows logs provide</td>
			</tr>
			<tr>
					<td>Threat Intelligence</td>
					<td>The process of collecting, analysing, and applying data about cyber threats, adversaries, and their methods. It transforms raw data into actionable insights, helping organizations understand threat actors’ motives and targets, and allowing them to shift from reactive defences to proactive strategies</td>
			</tr>
			<tr>
					<td>TLP</td>
					<td>Traffic Light Protocol</td>
			</tr>
			<tr>
					<td>TLS</td>
					<td>Transport Layer Security. The modern cryptographic protocol that provides end-to-end communications security over networks. It encrypts data sent between a client (like a web browser) and a server, ensuring privacy and data integrity, and is the standard technology behind secure HTTPS connections</td>
			</tr>
			<tr>
					<td>Token</td>
					<td>In authentication, a digital object (software or hardware) that provides a second factor of authentication or represents a user’s identity and permissions after they have logged in (e.g., a session token). This allows users to access resources without re-entering credentials for every request</td>
			</tr>
			<tr>
					<td>Trojan</td>
					<td>Malware that disguises itself as a legitimate program or file to trick a user into downloading and executing it. Unlike viruses and worms, Trojans do not self-replicate</td>
			</tr>
			<tr>
					<td>UBA</td>
					<td>User Behaviour Analytics. A cybersecurity process that uses machine learning and statistical analysis to establish a baseline of “normal” behaviour for users and devices on a network. By continuously monitoring activity, UBA detects anomalies – such as unusual login times, mass file downloads, or lateral movement – that may indicate a compromised account, insider threat, or cyberattack</td>
			</tr>
			<tr>
					<td>URI</td>
					<td>Uniform Resource Identifier. Text string that uniquely identifies a resource on a network, such as a document, image, or service (includes URLs as a subset)</td>
			</tr>
			<tr>
					<td>URL</td>
					<td>Uniform Resource Locator. Text string that specifies the address of a resource on a network and how to retrieve it, commonly used as a web address in browsers</td>
			</tr>
			<tr>
					<td>Virus</td>
					<td>A type of malicious code or program written to alter the way a computer operates and that is designed to spread from one computer to another by inserting its own code into other programs</td>
			</tr>
			<tr>
					<td>VM</td>
					<td>Virtual Machine. A software-based emulation of a physical computer that runs its own operating system and applications in an isolated environment, separated from the underlying physical hardware</td>
			</tr>
			<tr>
					<td>VPN</td>
					<td>Virtual Private Network. A technology that creates a secure, (often) encrypted connection (tunnel) over a less secure network, such as the public internet</td>
			</tr>
			<tr>
					<td>Vulnerability</td>
					<td>A weakness or flaw in a system’s design, implementation, or configuration that can be exploited by an attacker to compromise the system’s confidentiality, integrity, or availability</td>
			</tr>
			<tr>
					<td>WAF</td>
					<td>Web Application Firewall. A security system that filters, monitors, and blocks HTTP/HTTPS traffic to and from a web application</td>
			</tr>
			<tr>
					<td>Web Shell</td>
					<td>A malicious script or program uploaded to a compromised web server to give an attacker persistent remote administration capabilities. Once installed, it acts as a “backdoor”, allowing the attacker to execute system commands, modify files, and pivot deeper into the network through their web browser, often bypassing firewalls that allow standard HTTP/HTTPS traffic</td>
			</tr>
			<tr>
					<td>Windows Event Viewer</td>
					<td>A built-in Microsoft Windows tool that lets administrators and users view event logs generated by the operating system and applications</td>
			</tr>
			<tr>
					<td>Wiper</td>
					<td>A destructive form of malware designed to permanently erase or overwrite all data on a compromised system, rendering it unrecoverable</td>
			</tr>
			<tr>
					<td>WMI</td>
					<td>Windows Management Instrumentation. A core component of the Windows operating system that provides a standardized way for managing devices and applications on a network. Attackers can abuse WMI for lateral movement, code execution, and persistence within a compromised environment</td>
			</tr>
			<tr>
					<td>Worm</td>
					<td>Standalone malware that replicates itself to spread to other computers, often using a computer network to spread itself, relying on security vulnerabilities on the target system</td>
			</tr>
			<tr>
					<td>WSUS</td>
					<td>Windows Server Update Services. A Microsoft tool that allows IT administrators to manage and distribute Windows updates and patches to computers within a corporate network</td>
			</tr>
			<tr>
					<td>Zero-Trust</td>
					<td>A security framework based on the principle “never trust, always verify”. It assumes that no user, device, or network connection – whether inside or outside the corporate perimeter – should be trusted by default. Instead, every access request is continuously verified for identity, authorization, and device health before granting access to specific resources</td>
			</tr>
	</tbody>
</table>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p>Example: the CIRCL Standard Operational Procedures (SOP), available here: <a href="https://circl.lu/pub/tr-39">https://circl.lu/pub/tr-39</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p>Keep in mind limitations during reflective attacks&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p>External tools may assist in this task, such as: <a href="https://pandora.circl.lu">https://pandora.circl.lu</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p>Example: the CIRCL ransomware FAQ available here: <a href="https://circl.lu/pub/tr-73/">https://circl.lu/pub/tr-73/</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p>External tools may assist in this task, such as: <a href="https://lookyloo.circl.lu/">https://lookyloo.circl.lu/</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>
]]></content:encoded>
    </item>
    <item>
      <title>Operational guidance for incident handling</title>
      <link>https://www.circl.lu/pub/operational-guidance-for-incident-handling/</link>
      <pubDate>Mon, 28 Sep 2026 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/operational-guidance-for-incident-handling/</guid>
      <description>The High Commission for National Protection (“HCPN”), acting in its role as the Agence Nationale de la Sécurité des Systèmes d’Information (“ANSSI”) and as the Governmental Computer Security Incident Response Team (“GOVCERT.LU”), the Computer Incident Response Center Luxembourg (“CIRCL”), the Commission de Surveillance du Secteur Financier (“CSSF”), and the Institut Luxembourgeois de Régulation (“ILR”) are pleased to announce that a team of cyber security experts of the mentioned institutions jointly wrote a set of rulebooks related to operational guidance for incident handling.&amp;#xA;</description>
      <content:encoded><![CDATA[<p>The High Commission for National Protection (“HCPN”), acting in its role as the Agence Nationale de la Sécurité des Systèmes d’Information (“ANSSI”) and as the Governmental Computer Security Incident Response Team (“GOVCERT.LU”), the Computer Incident Response Center Luxembourg (“CIRCL”), the Commission de Surveillance du Secteur Financier (“CSSF”), and the Institut Luxembourgeois de Régulation (“ILR”) are pleased to announce that a team of cyber security experts of the mentioned institutions jointly wrote a set of rulebooks related to operational guidance for incident handling.</p>
<h2 id="why-were-these-rulebooks-developed">Why were these rulebooks developed?</h2>
<p>The <a href="/assets/files/operational-guidance-incident-handling.pdf">rulebooks</a> were developed in the context of Article 14(5) of the Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité (“NIS2 Act”).</p>
<p>Under Article 14(5), following receipt of an initial notification of a significant incident, the competent authority provides the notifying entity with an initial response and, at the entity’s request, guidance or operational advice on the implementation of possible mitigation measures. Such guidance is provided by the competent authority in cooperation with the relevant Computer Security Incident Response Team (“CSIRT”), which may also provide additional technical support at the entity’s request.</p>
<p>The rulebooks are intended to translate this operational guidance into practical and readily usable resources, helping entities facing a cybersecurity incident to rapidly identify and implement appropriate mitigation measures and to facilitate their interaction with the competent authority and the relevant CSIRT.</p>
<h2 id="who-are-they-intended-for">Who are they intended for?</h2>
<p>The rulebooks are primarily intended for public and private sector entities subject to the NIS2 Act. They provide operational guidance for handling cybersecurity incidents, in particular in the context of a significant incident notified to the competent authority in accordance with the notification mechanism established by the NIS2 Act.</p>
<p>They are especially relevant for technical teams, cybersecurity officers and other staff responsible for incident handling and response.</p>
<p>The rulebooks may also serve as a practical reference for other organisations facing a cybersecurity incident or seeking to prepare and improve their incident response procedures.</p>
<h2 id="what-do-the-rulebooks-provide">What do the rulebooks provide?</h2>
<p>The <a href="/assets/files/operational-guidance-incident-handling.pdf">rulebooks</a> provide practical, step-by-step guidance for handling specific types of cybersecurity incidents. Each rulebook addresses a particular incident scenario and structures the response across the main stages of incident handling.</p>
<p>Depending on the type of incident, the guidance covers:</p>
<ul>
<li>typical initial detection, including common signs, alerts and indicators that may reveal an incident;</li>
<li>immediate response and containment measures to limit the impact and prevent further compromise;</li>
<li>investigation steps to assess the scope, origin and consequences of the incident;</li>
<li>remediation measures to address the causes of the incident and restore a secure environment;</li>
<li>evidence keeping, including relevant information and technical artefacts that should be preserved;</li>
<li>post-incident activities to reduce the likelihood or impact of similar incidents in the future;</li>
<li>communication measures, including communication with affected users, management or other relevant parties; and</li>
<li>key watchpoints highlighting specific risks or issues requiring particular attention.</li>
</ul>
<p>The rulebooks are designed as practical reference guides that can be consulted during an incident, enabling technical and incident response teams to quickly identify relevant actions and measures for the specific situation they are facing.</p>
<h2 id="a-collaborative-and-evolving-resource">A collaborative and evolving resource</h2>
<p>The rulebooks were jointly developed by cybersecurity experts from the HCPN/ANSSI/GOVCERT.LU, CIRCL, CSSF and ILR.</p>
<p>To foster cyber security community feedback and ensure quality over time, the rulebooks are <a href="https://github.com/nis2-rulebooks/nis2-rulebooks/">hosted on GitHub</a> in addition to the <a href="/assets/files/operational-guidance-incident-handling.pdf">PDF document</a>. The contributions of cyber security professional are very welcomed and will be considered by the authors in future updates.</p>
<h2 id="disclaimer">Disclaimer</h2>
<p>These rulebooks are solely intended to be used as a practical guidance by an entity facing a cybersecurity incident and looking for immediate assistance from the competent authorities and the Computer Security Incident Response Teams (“CSIRT”). They have been written in the context of Article 14(5) of the Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité (“NIS2 Act”), and in accordance with the missions assigned to the HCPN in its role as ANSSI under Article 3, paragraph 1ter, of the Loi modifiée du 23 juillet 2016 portant création du Haut-Commissariat à la Protection nationale.</p>
<p>These rulebooks must not be used as a substitute for any policies or procedures in force at the entities. Neither the HCPN, the CIRCL, the CSSF, nor the ILR can be held liable in the event of malfunction or unforeseen circumstances or for any damages resulting from the use of the guidance.</p>
<p>These rulebooks do not address the legal obligations to be fulfilled by the concerned entities (e.g., file a complaint, notification of incidents to the CSSF, the ILR, and the Commission Nationale pour la Protection des Données (CNPD), etc.).</p>
]]></content:encoded>
    </item>
    <item>
      <title>TR-100 Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway</title>
      <link>https://www.circl.lu/pub/tr-100/</link>
      <pubDate>Sun, 27 Sep 2026 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-100/</guid>
      <description>Summary Multiple vulnerabilities have been disclosed in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).&amp;#xA;The vulnerabilities include unauthenticated remote code execution, memory corruption, HTTP request smuggling, security-policy bypass, denial of service and TCP Initial Sequence Number (ISN) prediction issues.&amp;#xA;Two vulnerabilities, CVE-2026-88771 and CVE-2026-88772, have a CVSS v4.0 base score of 9.5 and can result in remote code execution. According to Citrix and multiple observations from third-parties, exploitation of these vulnerabilities has been observed against unmitigated NetScaler deployments.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="summary">Summary</h2>
<p>Multiple vulnerabilities have been disclosed in <strong>Citrix NetScaler ADC</strong> (formerly Citrix ADC) and <strong>Citrix NetScaler Gateway</strong> (formerly Citrix Gateway).</p>
<p>The vulnerabilities include unauthenticated remote code execution, memory corruption, HTTP request smuggling, security-policy bypass, denial of service and TCP Initial Sequence Number (ISN) prediction issues.</p>
<p>Two vulnerabilities, <strong><a href="https://vulnerability.circl.lu/vuln/CVE-2026-88771">CVE-2026-88771</a></strong> and <strong><a href="https://vulnerability.circl.lu/vuln/CVE-2026-88772">CVE-2026-88772</a></strong>, have a CVSS v4.0 base score of <strong>9.5</strong> and can result in remote code execution. According to Citrix and multiple observations from third-parties, exploitation of these vulnerabilities has been observed against unmitigated NetScaler deployments.</p>
<p>Of particular concern, <strong>CVE-2026-88771 affects all vulnerable NetScaler ADC and NetScaler Gateway deployments, including appliances using the default configuration. No additional feature needs to be enabled for the vulnerability to be exposed.</strong></p>
<p>CIRCL strongly recommends administrators of affected NetScaler systems to <strong>upgrade without delay</strong> and to investigate potentially exposed systems for signs of compromise.</p>
<h2 id="affected-products">Affected Products</h2>
<p>The following supported versions are affected:</p>
<ul>
<li><strong>NetScaler ADC and NetScaler Gateway 14.1</strong> before <strong>14.1-73.37</strong></li>
<li><strong>NetScaler ADC and NetScaler Gateway 13.1</strong> before <strong>13.1-64.23</strong></li>
<li><strong>NetScaler ADC 14.1 FIPS</strong> before <strong>14.1-73.37 FIPS</strong></li>
<li><strong>NetScaler ADC 13.1 FIPS and NDcPP</strong> before <strong>13.1-37.279</strong></li>
</ul>
<p>Secure Private Access Hybrid deployments using NetScaler instances are also affected and the associated NetScaler appliances must be upgraded.</p>
<p>The vulnerabilities concern <strong>customer-managed NetScaler ADC and NetScaler Gateway appliances</strong>. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group.</p>
<h2 id="vulnerabilities">Vulnerabilities</h2>
<h3 id="cve-2026-88771--unauthenticated-remote-code-execution">CVE-2026-88771 — Unauthenticated Remote Code Execution</h3>
<p>A remote code execution vulnerability caused by improper input validation can allow an unauthenticated remote attacker to execute arbitrary commands.</p>
<p><strong>Precondition:</strong> None. All affected NetScaler ADC and NetScaler Gateway deployments are concerned, including default configurations.</p>
<ul>
<li><strong>CWE:</strong> CWE-20 — Improper Input Validation</li>
<li><strong>CVSS v4.0:</strong> 9.5</li>
<li><strong>Vector:</strong> <code>CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</code></li>
<li><strong>Exploitation:</strong> Observed in the wild</li>
</ul>
<p>This vulnerability should be considered the highest priority because exposure does not depend on an optional NetScaler feature being enabled.</p>
<h3 id="cve-2026-88772--memory-overflow-leading-to-rce-or-dos">CVE-2026-88772 — Memory Overflow Leading to RCE or DoS</h3>
<p>A memory overflow vulnerability can result in remote code execution or denial of service.</p>
<p><strong>Precondition:</strong> DTLS must be enabled. DTLS is enabled by default on VPN virtual servers unless explicitly disabled.</p>
<ul>
<li><strong>CWE:</strong> CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer</li>
<li><strong>CVSS v4.0:</strong> 9.5</li>
<li><strong>Vector:</strong> <code>CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H</code></li>
<li><strong>Exploitation:</strong> Observed in the wild</li>
</ul>
<h3 id="cve-2026-88773--http-request-smuggling">CVE-2026-88773 — HTTP Request Smuggling</h3>
<p>The vulnerability allows inconsistent interpretation of HTTP requests, resulting in an HTTP request smuggling condition.</p>
<p><strong>Precondition:</strong> HTTP functionality must be configured on the affected appliance. This includes Load Balancing, Content Switching, VPN or Authentication virtual servers using HTTP or SSL.</p>
<ul>
<li><strong>CWE:</strong> CWE-444 — Inconsistent Interpretation of HTTP Requests</li>
<li><strong>CVSS v4.0:</strong> 9.3</li>
<li><strong>Vector:</strong> <code>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N</code></li>
</ul>
<h3 id="cve-2026-88774--http-url-policy-bypass">CVE-2026-88774 — HTTP URL Policy Bypass</h3>
<p>Improper use or interpretation of HTTP URL-based expressions can allow configured security or feature policies to be bypassed.</p>
<p><strong>Precondition:</strong> An affected HTTP URL-based policy expression must be configured.</p>
<ul>
<li><strong>CWE:</strong> CWE-16 — Configuration</li>
<li><strong>CVSS v4.0:</strong> 7.0</li>
<li><strong>Vector:</strong> <code>CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N</code></li>
</ul>
<h3 id="cve-2026-88775--memory-overflow-in-gateway-or-aaa-configurations">CVE-2026-88775 — Memory Overflow in Gateway or AAA Configurations</h3>
<p>A memory overflow vulnerability can result in unpredictable behaviour or denial of service.</p>
<p><strong>Precondition:</strong> NetScaler must be configured as one of the following:</p>
<ul>
<li>
<p>Gateway:</p>
<ul>
<li>SSL VPN</li>
<li>ICA Proxy</li>
<li>CVPN</li>
<li>RDP Proxy</li>
</ul>
</li>
<li>
<p>AAA virtual server</p>
</li>
<li>
<p><strong>CWE:</strong> CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer</p>
</li>
<li>
<p><strong>CVSS v4.0:</strong> 8.8</p>
</li>
<li>
<p><strong>Vector:</strong> <code>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N</code></p>
</li>
</ul>
<h3 id="cve-2026-88776--memory-overflow-in-oracle-load-balancing">CVE-2026-88776 — Memory Overflow in Oracle Load Balancing</h3>
<p>A memory overflow vulnerability can lead to unpredictable behaviour or denial of service.</p>
<p><strong>Precondition:</strong> NetScaler must be configured with a Load Balancing virtual server of type Oracle.</p>
<ul>
<li><strong>CWE:</strong> CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer</li>
<li><strong>CVSS v4.0:</strong> 8.8</li>
<li><strong>Vector:</strong> <code>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N</code></li>
</ul>
<h3 id="cve-2026-88777--memory-overflow-in-non-http-l7-services">CVE-2026-88777 — Memory Overflow in Non-HTTP L7 Services</h3>
<p>A memory overflow vulnerability can result in unpredictable behaviour or denial of service.</p>
<p><strong>Precondition:</strong> NetScaler must be configured as an LB/CS or CGNAT-LSN/NAT64 device with a non-HTTP Layer 7 protocol feature enabled.</p>
<p>Potentially affected configurations include FTP, RTSP, DNS64 and NAT64 deployments.</p>
<ul>
<li><strong>CWE:</strong> CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer</li>
<li><strong>CVSS v4.0:</strong> 8.8</li>
<li><strong>Vector:</strong> <code>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N</code></li>
</ul>
<h3 id="cve-2026-88778--tcp-initial-sequence-number-prediction">CVE-2026-88778 — TCP Initial Sequence Number Prediction</h3>
<p>The TCP Initial Sequence Number generation mechanism can result in predictable values, potentially weakening assumptions about the integrity of TCP connections.</p>
<p><strong>Precondition:</strong> TCP functionality is enabled and Enhanced ISN Generation is disabled.</p>
<ul>
<li><strong>CWE:</strong> CWE-342 — Predictable Exact Value from Previous Values</li>
<li><strong>CVSS v4.0:</strong> 8.8</li>
<li><strong>Vector:</strong> <code>CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L</code></li>
</ul>
<h2 id="recommended-actions">Recommended Actions</h2>
<p>CIRCL recommends that administrators <strong>upgrade affected NetScaler appliances as soon as possible</strong>.</p>
<p>The following versions contain fixes:</p>
<table>
	<thead>
			<tr>
					<th>Product</th>
					<th>Fixed version</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td>NetScaler ADC / Gateway 14.1</td>
					<td><strong>14.1-73.37 or later</strong></td>
			</tr>
			<tr>
					<td>NetScaler ADC / Gateway 13.1</td>
					<td><strong>13.1-64.23 or later</strong></td>
			</tr>
			<tr>
					<td>NetScaler ADC 14.1 FIPS</td>
					<td><strong>14.1-73.37 FIPS or later</strong></td>
			</tr>
			<tr>
					<td>NetScaler ADC 13.1 FIPS / NDcPP</td>
					<td><strong>13.1-37.279 or later</strong></td>
			</tr>
	</tbody>
</table>
<p>Because exploitation of CVE-2026-88771 and CVE-2026-88772 has already been observed, <strong>upgrading should not be considered sufficient evidence that an appliance was not previously compromised</strong>.</p>
<p>For Internet-facing appliances that were running an affected version, administrators should also:</p>
<ol>
<li>preserve relevant logs and forensic evidence before making significant changes where operationally possible;</li>
<li>review NetScaler and external network/security logs for suspicious activity;</li>
<li>investigate unexpected configuration, filesystem or process changes;</li>
<li>review administrative and authentication activity;</li>
<li>review activity from the appliance towards internal infrastructure;</li>
<li>use the indicators and detection mechanisms provided by Citrix;</li>
<li>follow the organisation&rsquo;s incident response process if compromise is suspected.</li>
</ol>
<p>External forwarding of NetScaler logs to a SIEM or other independent logging infrastructure is strongly recommended, as it can provide evidence that remains available if the appliance itself is compromised.</p>
<h2 id="configuration-checks">Configuration Checks</h2>
<p>Administrators can use their NetScaler configuration to identify whether additional vulnerability-specific preconditions are met.</p>
<h3 id="cve-2026-88771">CVE-2026-88771</h3>
<p>No configuration check is required. <strong>All affected versions meet the vulnerability precondition.</strong></p>
<h3 id="cve-2026-88772">CVE-2026-88772</h3>
<p>Review VPN and virtual-server configurations for DTLS.</p>
<p>For example:</p>
<div class="highlight"><div style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;">
<table style="border-spacing:0;padding:0;margin:0;border:0;"><tr><td style="vertical-align:top;padding:0;margin:0;border:0;">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">1
</span></code></pre></td>
<td style="vertical-align:top;padding:0;margin:0;border:0;;width:100%">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE
</span></span></code></pre></td></tr></table>
</div>
</div><p>DTLS is enabled by default in this configuration.</p>
<p>An explicit:</p>
<div class="highlight"><div style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;">
<table style="border-spacing:0;padding:0;margin:0;border:0;"><tr><td style="vertical-align:top;padding:0;margin:0;border:0;">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">1
</span></code></pre></td>
<td style="vertical-align:top;padding:0;margin:0;border:0;;width:100%">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>-dtls OFF
</span></span></code></pre></td></tr></table>
</div>
</div><p>indicates that DTLS has been disabled for the VPN virtual server.</p>
<p>Also review explicitly configured DTLS virtual servers.</p>
<h3 id="cve-2026-88773">CVE-2026-88773</h3>
<p>Review HTTP/SSL Load Balancing, Content Switching, VPN and Authentication virtual servers:</p>
<div class="highlight"><div style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;">
<table style="border-spacing:0;padding:0;margin:0;border:0;"><tr><td style="vertical-align:top;padding:0;margin:0;border:0;">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">1
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">2
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">3
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">4
</span></code></pre></td>
<td style="vertical-align:top;padding:0;margin:0;border:0;;width:100%">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>add lb vserver &lt;vserver-name&gt; &lt;HTTP or SSL&gt;
</span></span><span style="display:flex;"><span>add cs vserver &lt;vserver-name&gt; &lt;HTTP or SSL&gt;
</span></span><span style="display:flex;"><span>add vpn vserver &lt;vserver-name&gt; &lt;HTTP or SSL&gt;
</span></span><span style="display:flex;"><span>add authentication vserver &lt;vserver-name&gt; &lt;HTTP or SSL&gt;
</span></span></code></pre></td></tr></table>
</div>
</div><h3 id="cve-2026-88775">CVE-2026-88775</h3>
<p>Relevant configuration entries include:</p>
<div class="highlight"><div style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;">
<table style="border-spacing:0;padding:0;margin:0;border:0;"><tr><td style="vertical-align:top;padding:0;margin:0;border:0;">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">1
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">2
</span></code></pre></td>
<td style="vertical-align:top;padding:0;margin:0;border:0;;width:100%">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>add vpn vserver .*
</span></span><span style="display:flex;"><span>add authentication vserver .*
</span></span></code></pre></td></tr></table>
</div>
</div><h3 id="cve-2026-88776">CVE-2026-88776</h3>
<p>Search for Oracle Load Balancing virtual servers:</p>
<div class="highlight"><div style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;">
<table style="border-spacing:0;padding:0;margin:0;border:0;"><tr><td style="vertical-align:top;padding:0;margin:0;border:0;">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">1
</span></code></pre></td>
<td style="vertical-align:top;padding:0;margin:0;border:0;;width:100%">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>add lb vserver.*ORACLE.*
</span></span></code></pre></td></tr></table>
</div>
</div><h3 id="cve-2026-88777">CVE-2026-88777</h3>
<p>Review configurations using non-HTTP Layer 7 protocols, including:</p>
<div class="highlight"><div style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;">
<table style="border-spacing:0;padding:0;margin:0;border:0;"><tr><td style="vertical-align:top;padding:0;margin:0;border:0;">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">1
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">2
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">3
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">4
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">5
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">6
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">7
</span><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">8
</span></code></pre></td>
<td style="vertical-align:top;padding:0;margin:0;border:0;;width:100%">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>add (lb|cs) vserver .* FTP
</span></span><span style="display:flex;"><span>add service .* FTP
</span></span><span style="display:flex;"><span>add lb monitor .* FTP
</span></span><span style="display:flex;"><span>add lb monitor .* FTP-EXTENDED
</span></span><span style="display:flex;"><span>set lsn group .* -rtspalg ENABLED
</span></span><span style="display:flex;"><span>add lb vserver .* DNS .* -dns64 ENABLED
</span></span><span style="display:flex;"><span>add dns policy64
</span></span><span style="display:flex;"><span>add nat64
</span></span></code></pre></td></tr></table>
</div>
</div><p>For LSN/CGNAT configurations, administrators should pay particular attention to FTP ALG configuration.</p>
<h3 id="cve-2026-88778">CVE-2026-88778</h3>
<p>Check whether Enhanced ISN Generation is disabled:</p>
<div class="highlight"><div style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;">
<table style="border-spacing:0;padding:0;margin:0;border:0;"><tr><td style="vertical-align:top;padding:0;margin:0;border:0;">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">1
</span></code></pre></td>
<td style="vertical-align:top;padding:0;margin:0;border:0;;width:100%">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-shell" data-lang="shell"><span style="display:flex;"><span>show ns tcpparam | grep <span style="color:#b44">&#34;Enhanced ISN Generation&#34;</span>
</span></span></code></pre></td></tr></table>
</div>
</div><p>A result containing:</p>
<div class="highlight"><div style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;">
<table style="border-spacing:0;padding:0;margin:0;border:0;"><tr><td style="vertical-align:top;padding:0;margin:0;border:0;">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code><span style="white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f">1
</span></code></pre></td>
<td style="vertical-align:top;padding:0;margin:0;border:0;;width:100%">
<pre tabindex="0" style="background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>Enhanced ISN Generation: DISABLED
</span></span></code></pre></td></tr></table>
</div>
</div><p>indicates that the vulnerable configuration precondition may be met when applicable TCP-based virtual servers are configured.</p>
<p>Administrators affected by CVE-2026-88778 should also apply the TCP configuration changes recommended by Citrix.</p>
<h2 id="incident-response-considerations">Incident Response Considerations</h2>
<p>Due to the reported exploitation of the two remote-code-execution vulnerabilities, CIRCL recommends treating vulnerable Internet-exposed NetScaler appliances with additional caution.</p>
<p>Where an appliance was exposed to untrusted networks while vulnerable, organisations should consider performing a compromise assessment rather than relying exclusively on successful installation of the security update.</p>
<p>In particular, successful patching prevents subsequent exploitation of the corrected vulnerabilities but does <strong>not</strong> remediate persistence or other changes potentially introduced before the update.</p>
<h2 id="references">References</h2>
<ul>
<li><a href="https://vulnerability.circl.lu/bundle/6d8bc6ad-f616-4600-9f2e-18a677efbaa6">CIRCL - Information Bundle</a></li>
<li><a href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&amp;articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778">Citrix Support</a></li>
<li><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772">CISA</a></li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 27th September 2026</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-99 - Phishing Campaign Targeting Hotel Customers in Luxembourg</title>
      <link>https://www.circl.lu/pub/tr-99/</link>
      <pubDate>Mon, 01 Jun 2026 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-99/</guid>
      <description>Executive Summary CIRCL and Horesca have been informed of a phishing campaign targeting customers of hotels in Luxembourg. A significant number of hotel guests have received fraudulent messages through different communication channels, including WhatsApp messages containing malicious URLs.&amp;#xA;The phishing messages are particularly convincing because they include information related to legitimate hotel bookings. This increases the likelihood that victims will trust the message and engage with the fraudulent website or communication channel.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>CIRCL and <a href="https://www.horesca.lu/actualites/8189-signalements-de-tentatives-de-phishing-visant-des-clients-dhotels">Horesca</a> have been informed of a phishing campaign targeting customers of hotels in Luxembourg. A significant number of hotel guests have received fraudulent messages through different communication channels, including WhatsApp messages containing malicious URLs.</p>
<p>The phishing messages are particularly convincing because they include information related to legitimate hotel bookings. This increases the likelihood that victims will trust the message and engage with the fraudulent website or communication channel.</p>
<p>The apparent objective of the campaign is to trick hotel customers into making payments to an actor-controlled account or payment infrastructure.</p>
<h2 id="observed-activity">Observed Activity</h2>
<p>Victims have reported receiving messages that appear to reference real hotel reservations. These messages may include booking-related information that is accurate or sufficiently close to a legitimate reservation to appear trustworthy.</p>
<p>The phishing messages typically contain a URL and encourage the recipient to take action, such as confirming a reservation, updating payment details, or completing a payment.</p>
<p>At this stage, CIRCL assesses that the information used in the phishing messages may originate from data associated with services operated by myLighthouse, a platform used in the hotel and hospitality sector.</p>
<p>The exact origin of the data exposure is currently unclear. Possible scenarios include, but are not limited to:</p>
<ul>
<li>a vulnerability affecting a service or integration;</li>
<li>abuse or compromise of one or more hotel accounts;</li>
<li>unauthorised access to or exfiltration of booking-related data;</li>
<li>misuse of legitimate access to hotel or booking-management systems.</li>
</ul>
<p>The investigation by Lighthouse has not yet clearly established the precise source of the data used in the phishing campaign.</p>
<h2 id="impact">Impact</h2>
<p>The campaign may affect hotel customers who have made legitimate bookings in Luxembourg (not limited) and who receive fraudulent communications referencing those bookings.</p>
<p>Potential impacts include:</p>
<ul>
<li>financial loss due to fraudulent payments;</li>
<li>disclosure of personal or payment-related information;</li>
<li>loss of trust in hotel communication channels;</li>
<li>increased workload for hotels, financial institutions, and incident response teams.</li>
</ul>
<h2 id="recommendations-for-hotel-owners-and-operators-using-mylighthouse">Recommendations for Hotel Owners and Operators Using myLighthouse</h2>
<p>CIRCL recommends that hotels using myLighthouse take the following actions as a priority:</p>
<ol>
<li>
<p><strong>Reset credentials</strong></p>
<ul>
<li>Reset passwords for all accounts associated with myLighthouse.</li>
<li>Ensure that passwords are unique and not reused across other services.</li>
</ul>
</li>
<li>
<p><strong>Enable and enforce multi-factor authentication</strong></p>
<ul>
<li>Enable MFA for all accounts where available.</li>
<li>Lighthouse has announced enforcement of MFA as of 1 June.</li>
<li>Hotels should verify that MFA is active for all relevant users and accounts.</li>
</ul>
</li>
<li>
<p><strong>Review account access</strong></p>
<ul>
<li>Review active users and remove accounts that are no longer required.</li>
<li>Check whether any unexpected or unauthorised accounts have access.</li>
<li>Review access rights and apply the principle of least privilege.</li>
</ul>
</li>
<li>
<p><strong>Inform customers about legitimate payment procedures</strong></p>
<ul>
<li>Clearly communicate the official payment methods used by the hotel.</li>
<li>Remind customers that unexpected payment requests received through WhatsApp, SMS, or unofficial channels should be treated with suspicion.</li>
<li>Provide customers with a trusted contact point to verify payment requests.</li>
</ul>
</li>
<li>
<p><strong>Monitor for suspicious activity</strong></p>
<ul>
<li>Monitor customer reports of phishing attempts.</li>
<li>Review logs, where available, for unusual access patterns.</li>
<li>Report suspicious URLs and related indicators to CIRCL.</li>
</ul>
</li>
</ol>
<h2 id="recommendations-for-victims-and-hotel-customers">Recommendations for Victims and Hotel Customers</h2>
<p>If you receive a message via WhatsApp, SMS, email, or another channel that refers to your hotel booking and asks you to click a link or make a payment, CIRCL recommends the following:</p>
<ol>
<li>
<p><strong>Do not click on the URL</strong></p>
<ul>
<li>Do not open links contained in suspicious or unexpected messages.</li>
<li>Do not enter personal, booking, or payment information on websites reached through such links.</li>
</ul>
</li>
<li>
<p><strong>Verify directly with the hotel</strong></p>
<ul>
<li>Contact the hotel using contact details obtained from the official hotel website or your original booking confirmation.</li>
<li>Do not rely on phone numbers, links, or contact details provided in the suspicious message.</li>
</ul>
</li>
<li>
<p><strong>If you interacted with the phishing site</strong></p>
<ul>
<li>Contact your bank or financial provider immediately.</li>
<li>Notify them that you may have been targeted by payment fraud.</li>
<li>Follow their instructions regarding card blocking, transaction monitoring, or chargeback procedures.</li>
<li>Notify the policy if you want to fill a complain.</li>
</ul>
</li>
<li>
<p><strong>Preserve evidence</strong></p>
<ul>
<li>Keep the suspicious message, phone number, URL, screenshots, and any payment details.</li>
<li>These elements can help incident responders and service providers limit the impact of the campaign.</li>
</ul>
</li>
</ol>
<h2 id="reporting-phishing-urls-to-circl">Reporting Phishing URLs to CIRCL</h2>
<p>CIRCL welcomes reports from users, victims, hotels, and service providers.</p>
<p>Phishing URLs can be submitted to Lookyloo at <a href="https://lookyloo.circl.lu/capture">https://lookyloo.circl.lu/capture</a></p>
<p>When submitting a URL, please mark the capture as phishing. This helps CIRCL and partners analyse the infrastructure, identify related campaigns, and support takedown or mitigation actions to reduce the impact on victims.</p>
<h2 id="indicators-of-compromise">Indicators of Compromise</h2>
<p>Indicators may vary depending on the hotel, the communication channel, and the infrastructure used by the threat actor.</p>
<p>A MISP event <a href="https://misppriv.circl.lu/events/view/10a94632-a0a1-4062-a3a5-95fe321ae045">https://misppriv.circl.lu/events/view/10a94632-a0a1-4062-a3a5-95fe321ae045</a> is available with all the indicators collected from the reported cases.</p>
<p>The threat actor appears to rotate phishing URLs frequently and also changes the phone numbers used to send WhatsApp messages, making static blocking and indicator-based detection more difficult.</p>
<p>Hotels and victims are encouraged to report phishing URLs and related artefacts to CIRCL for analysis.</p>
<h2 id="conclusion">Conclusion</h2>
<p>This phishing campaign is notable because it uses legitimate booking-related information to increase credibility and pressure victims into making fraudulent payments.</p>
<p>Hotels using myLighthouse should urgently reset credentials, ensure MFA is enabled and enforced, review access rights, and communicate clearly with customers about legitimate payment methods.</p>
<p>Customers who receive suspicious booking-related messages should not click on links, should verify requests directly with the hotel, and should contact their financial provider immediately if they engaged with the phishing site or made a payment.</p>
<p>CIRCL continues to collect reports and encourages the submission of phishing URLs through Lookyloo to support analysis and mitigation.</p>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 1st June 2026</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-98 - Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp;amp; CVE-2026-1340) - Active Exploitation</title>
      <link>https://www.circl.lu/pub/tr-98/</link>
      <pubDate>Mon, 09 Feb 2026 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-98/</guid>
      <description>Ivanti has released security updates for Endpoint Manager Mobile (EPMM) addressing two critical-severity vulnerabilities.&amp;#xA;Successful exploitation allows unauthenticated remote code execution. Active exploitation has been confirmed in the wild, both worldwide and in Luxembourg.&amp;#xA;CIRCL strongly recommends immediately initiating a full incident response procedure for all Ivanti EPMM instances, including compromise assessment and log review.&amp;#xA;As EPMM is a mobile endpoint management solution, a compromise of the EPMM server can result in severe impact, including full control over managed devices, lateral movements and access to sensitive data.&amp;#xA;</description>
      <content:encoded><![CDATA[<p>Ivanti has released security updates for Endpoint Manager Mobile (EPMM) addressing two critical-severity vulnerabilities.</p>
<p>Successful exploitation allows unauthenticated remote code execution. Active exploitation has been confirmed in the wild, both worldwide and in Luxembourg.</p>
<p>CIRCL strongly recommends immediately initiating a full incident response procedure for all Ivanti EPMM instances, including compromise assessment and log review.</p>
<p>As EPMM is a mobile endpoint management solution, a compromise of the EPMM server can result in severe impact, including full control over managed devices, lateral movements and access to sensitive data.</p>
<h2 id="affected-version">Affected Version</h2>
<table>
	<thead>
			<tr>
					<th>Product Name</th>
					<th>Affected Version(s)</th>
					<th>Affected CPE(s)</th>
					<th>Resolved Version(s)</th>
					<th>Patch Availability</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td>Ivanti Endpoint Manager Mobile</td>
					<td>12.5.0.0 and prior 12.6.0.0 and prior 12.7.0.0 and prior</td>
					<td>cpe:2.3:a:ivanti:endpoint_manager_mobile:12.7.0.0</td>
					<td>RPM 12.x.0.x</td>
					<td><a href="https://support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0S-5.noarch.rpm">https://support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0S-5.noarch.rpm</a></td>
			</tr>
			<tr>
					<td>Ivanti Endpoint Manager Mobile</td>
					<td>12.5.1.0 and prior 12.6.1.0 and prior</td>
					<td>cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.1.0 cpe:2.3:a:ivanti:endpoint_manager_mobile:12.6.1.0</td>
					<td>RPM 12.x.1.x</td>
					<td><a href="https://support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0L-5.noarch.rpm">https://support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0L-5.noarch.rpm</a></td>
			</tr>
	</tbody>
</table>
<p>Previous version under EoL might be also affected by the vulnerability.</p>
<h2 id="network-indicator">Network Indicator</h2>
<ul>
<li><a href="https://hub.ivanti.com/s/article/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US">Reviewing for post-exploit activity</a></li>
</ul>
<h2 id="detection-and-forensic">Detection and Forensic</h2>
<p>Ivanti published a detection script <a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US">Exploitation Detection RPM package</a>. We strongly recommend to do further detection and analysis beside the scripts provided by Ivanti.</p>
<h2 id="references">References</h2>
<ul>
<li><a href="https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US">Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp; CVE-2026-1340)</a></li>
<li><a href="https://hub.ivanti.com/s/article/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US">Analysis Guidance Ivanti Endpoint Manager Mobile (EPMM) CVE-2026-1281 &amp; CVE-2026-1340</a></li>
<li><a href="https://vulnerability.circl.lu/vuln/CVE-2026-1281">CVE-2026-1281</a></li>
<li><a href="https://vulnerability.circl.lu/vuln/CVE-2026-1340">CVE-2026-1340</a></li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 9th February 2025</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-97 - Supply Chain Compromise Propagating Through the npm Ecosystem (Shai-Hulud)</title>
      <link>https://www.circl.lu/pub/tr-97/</link>
      <pubDate>Fri, 28 Nov 2025 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-97/</guid>
      <description>The incident involves a self-replicating worm, publicly referred to as “Shai-Hulud”, which has infected more than 500 npm packages, with an even broader impact in a second wave (Shai-Hulud 2.0) that delivered a different payload.&amp;#xA;After gaining initial access, the malicious threat actor deployed malware designed to scan affected environments for sensitive credentials and exfiltrate these. The second version included a destructive payload capable of deleting the user’s home directory.&amp;#xA;</description>
      <content:encoded><![CDATA[<p>The incident involves a self-replicating worm, publicly referred to as “Shai-Hulud”, which has infected more than 500 npm packages, with an even broader impact in a second wave (Shai-Hulud 2.0) that delivered a different payload.</p>
<p>After gaining initial access, the malicious threat actor deployed malware designed to scan affected environments for sensitive credentials and exfiltrate these. The second version included a destructive payload capable of deleting the user’s home directory.</p>
<p>The threat actor specifically targeted GitHub Personal Access Tokens (PATs), API keys for major cloud service providers—including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure as well as credentials related to software distribution channels.</p>
<h2 id="detection">Detection</h2>
<ul>
<li>Review all the npm packages installed by reviewing <code>package-lock.json</code>, <code>yarn.lock</code> and similar files. Don&rsquo;t forget to search recursively.</li>
<li>A list of compromised package is available at <a href="https://github.com/wiz-sec-public/wiz-research-iocs/blob/main/reports/shai-hulud-2-packages.csv">https://github.com/wiz-sec-public/wiz-research-iocs/blob/main/reports/shai-hulud-2-packages.csv</a>.</li>
<li>Be careful with cached version in directory which could contain malicious packages.</li>
<li>Check for the hashes of the malware sample linked below.</li>
</ul>
<h2 id="remediation">Remediation</h2>
<ul>
<li>Immediately rotate all developer credentials and API keys.</li>
<li>Ensuring MFA is enabled on all developer having access to repositories and systems for software deployment.</li>
<li>Review access logs and CI pipelines if they have been modified.</li>
</ul>
<h2 id="malware-sample">Malware Sample</h2>
<ul>
<li><a href="https://www.virustotal.com/gui/file/62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0">62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0</a></li>
<li><a href="https://www.virustotal.com/gui/file/f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068">f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068</a></li>
<li><a href="https://www.virustotal.com/gui/file/a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a">a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a</a></li>
</ul>
<p>Network Indicator</p>
<hr>
<ul>
<li>http[:]//bun[.]sh/install[.]ps1</li>
</ul>
<h2 id="known-affected-software-in-luxembourg">Known affected software in Luxembourg</h2>
<p>We received notifications about affected users and GitHub repositories. To date, the impact has been minor, affecting only a limited number of organisations in Luxembourg. We are actively monitoring the situation.</p>
<h2 id="references">References</h2>
<ul>
<li>Datadog <a href="https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/">The Shai-Hulud 2.0 npm worm: analysis, and what you need to know</a></li>
<li>StepSecurity <a href="https://www.stepsecurity.io/blog/ctrl-tinycolor-and-40-npm-packages-compromised">Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages</a></li>
<li>Unit42 <a href="https://unit42.paloaltonetworks.com/npm-supply-chain-attack/">&ldquo;Shai-Hulud&rdquo; Worm Compromises npm Ecosystem in Supply Chain Attack (Updated November 26)</a></li>
<li>CISA <a href="https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem">Widespread Supply Chain Compromise Impacting npm Ecosystem</a></li>
<li>GitLab <a href="https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/">GitLab discovers widespread npm supply chain attack</a></li>
<li>WIZ <a href="https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack"></a></li>
<li>CIRCL <a href="https://vulnerability.circl.lu/recent#ossf_malicious_packages">Malicious Packages on vulnerability-lookup</a></li>
<li>CSSF <a href="https://www.cssf.lu/en/2025/11/supply-chain-attack-using-npm-packages/">Supply-chain attack using NPM packages</a></li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 28th November 2025</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-96 - Multiple Vulnerabilities in F5 Devices and Products - Impact and Mitigation</title>
      <link>https://www.circl.lu/pub/tr-96/</link>
      <pubDate>Wed, 15 Oct 2025 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-96/</guid>
      <description>A nation-state actor has breached F5’s systems and stolen proprietary files, including portions of the BIG-IP source code and vulnerability details. This access gives the attacker a significant advantage, enabling them to discover new flaws and develop targeted exploits for F5 devices and software.&amp;#xA;This TR applies to a wide range of F5 products, including BIG-IP iSeries and rSeries hardware, as well as BIG-IP (TMOS), Virtual Edition (VE), BIG-IP Next, and BIG-IQ software.&amp;#xA;</description>
      <content:encoded><![CDATA[<p>A <a href="https://my.f5.com/manage/s/article/K000154696">nation-state actor has breached F5&rsquo;s systems</a> and stolen proprietary files, including portions of the BIG-IP source code and vulnerability details. This access gives the attacker a significant advantage, enabling them to discover new flaws and develop targeted exploits for F5 devices and software.</p>
<p>This TR applies to a wide range of F5 products, including BIG-IP iSeries and rSeries hardware, as well as BIG-IP (TMOS), Virtual Edition (VE), BIG-IP Next, and BIG-IQ software.</p>
<p>We strongly recommend reviewing all your deployed BIG-IP products and applying the recommendations from the vendor as mentionned in <a href="https://my.f5.com/manage/s/article/K000156572">K000156572: Quarterly Security Notification (October 2025)</a>.</p>
<h2 id="known-affected-software-in-luxembourg">Known affected software in Luxembourg</h2>
<p>A significant number of BIG-IP devices were discovered in Luxembourg, and notifications have been sent to the ISPs and available contact points.</p>
<p>Based on the information available from the disclosure, we have not found any compromised or abused systems. Many of the vulnerabilities are related to potential Denial-of-Service (DoS) attacks, which should also be monitored. We also recommend looking closely at your logs.</p>
<h2 id="references">References</h2>
<ul>
<li>F5 - <a href="https://my.f5.com/manage/s/article/K000156572">K000156572: Quarterly Security Notification (October 2025)</a></li>
<li>CIRCL - <a href="https://vulnerability.circl.lu/bundle/834a30cc-c06c-49b3-9157-eb77f711c73f">F5 - K000156572: Quarterly Security Notification (October 2025 - CVE Allocated)</a></li>
<li>CIRCL - RULEZET.org - <a href="https://rulezet.org/bundle/detail/5">Threat Hunting Methodology: F5 Security Incident (K000154696)</a></li>
<li>CISA - <a href="https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices">ED 26-01: Mitigate Vulnerabilities in F5 Devices</a></li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.1 - TLP:CLEAR - Second version - 16th October 2025 - RULEZET bundle added</li>
<li>Version 1.0 - TLP:CLEAR - First version - 15th October 2025</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-95 - Critical vulnerability - Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. CVE-2025-53770 - CVE-2025-53771</title>
      <link>https://www.circl.lu/pub/tr-95/</link>
      <pubDate>Sun, 20 Jul 2025 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-95/</guid>
      <description>Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation. For more details about CVE-2025-53770 and CVE-2025-53771.&amp;#xA;</description>
      <content:encoded><![CDATA[<p>Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation. For more details about <a href="https://vulnerability.circl.lu/vuln/CVE-2025-53770">CVE-2025-53770</a> and <a href="https://vulnerability.circl.lu/vuln/CVE-2025-53771">CVE-2025-53771</a>.</p>
<p>These vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 is not impacted.</p>
<p>CIRCL advises initiating an incident response procedure, reviewing all logs, and especially scrutinizing any potential compromise to other internal infrastructure in addition to the Microsoft SharePoint Server.</p>
<h2 id="recommendations">Recommendations</h2>
<ul>
<li>Review the <a href="https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/">Microsoft Customer guidance for SharePoint vulnerability CVE-2025-53770</a></li>
<li>Assume the system has been compromised, because large‑scale exploitation occurred before the patch was released.</li>
<li>Rotate the current key materials on your exposed Microsoft SharePoint Server.</li>
<li>Trigger an incident response procedure, reviewing all logs, and especially scrutinizing any potential compromise to other internal infrastructure in addition to the Microsoft SharePoint Server.</li>
</ul>
<h2 id="impact">Impact</h2>
<p>It can result in the full compromise of the Microsoft SharePoint Server.</p>
<h2 id="exploitation">Exploitation</h2>
<p>Exploitation has been confirmed and has been seen worldwide, including in Luxembourg.</p>
<h2 id="detection">Detection</h2>
<p>Monitor and search logs for POSTs to <code>/_layouts/15/ToolPane.aspx?DisplayMode=Edit</code> which is the trigger for the known payload.</p>
<p>Review the Microsoft SharePoint Server for the presence of the <code>spinstall0.aspx</code> file.</p>
<p>A scanning approach (available as a bash script) and a set of indicators are detailed in an article from <a href="https://research.eye.security/sharepoint-under-siege/">eye.security</a>.</p>
<p>In addition, a set of indicators are available on the original article <a href="https://research.eye.security/sharepoint-under-siege/">https://research.eye.security/sharepoint-under-siege/</a>.</p>
<p>A MISP event with the indicators is also available with the following UUID: <code>d9da16a2-8444-45cb-8bb4-d27abf23a261</code> (CIRCL) and <code>59ed4725-5f2a-4844-8dc4-e6926dbcb5ce</code> (Microsoft) which includes detection rules for Microsoft Sentinel and Microsoft Defender XDR.</p>
<h2 id="affected-systems">Affected Systems</h2>
<ul>
<li>Microsoft - Microsoft SharePoint Enterprise Server 2016 - Version: N/A</li>
<li>Microsoft - Microsoft SharePoint Server 2019 - Version: 16.0.0   &lt; 16.0.10417.20037</li>
<li>Microsoft - Microsoft SharePoint Server Subscription Edition - Version: 16.0.0   &lt; 16.0.18526.20508</li>
</ul>
<h2 id="credits">Credits</h2>
<ul>
<li>Thanks to <a href="https://research.eye.security">https://research.eye.security</a> for the discovery.</li>
</ul>
<h2 id="references">References</h2>
<ul>
<li><a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49706">Original vulnerability - CVE-2025-49706</a></li>
<li><a href="https://vulnerability.circl.lu/vuln/CVE-2025-53770">CVE-2025-53770 (GCVE-0-2025-53770)</a> - Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.</li>
<li><a href="https://research.eye.security/sharepoint-under-siege/">SharePoint 0-day uncovered (CVE-2025-53770)</a></li>
<li>Scanning - <a href="https://github.com/righel/ms-sharepoint-version-nse">Nmap script to detect a Microsoft SharePoint instance version</a></li>
<li><a href="https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/">Disrupting active exploitation of on-premises SharePoint vulnerabilities</a></li>
</ul>
<h2 id="timeline">Timeline</h2>
<ul>
<li>2025-07-20 06:03 - <a href="https://vulnerability.circl.lu/bundle/7eb6b389-20dd-404f-90c4-314ed370fcc5">Customer guidance for SharePoint vulnerability CVE-2025-53770 MSRC Blog Microsoft Security Response Center</a></li>
<li>2025-07-18 18:00 - Initial discover of the ASPX payload by <a href="https://research.eye.security">https://research.eye.security</a>.</li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.3 - TLP:CLEAR - References updated</li>
<li>Version 1.2 - TLP:CLEAR - Clarification for key materials and links fixed - 22nd July 2025</li>
<li>Version 1.1 - TLP:CLEAR - Second version including updates and new scanning script - 21st July 2025</li>
<li>Version 1.0 - TLP:CLEAR - First version - 20th July 2025</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-94 - Ongoing Phishing Campaigns Targeting Microsoft 365 Tenants Lacking Multi-Factor Authentication</title>
      <link>https://www.circl.lu/pub/tr-94/</link>
      <pubDate>Thu, 22 May 2025 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-94/</guid>
      <description>Executive Summary This report details ongoing phishing campaigns specifically targeting organisations utilizing Microsoft 365, with a primary focus on Office 365 tenants where Multi-Factor Authentication (MFA) is not enforced. Attackers leverage sophisticated social engineering tactics and convincing phishing pages to harvest user credentials. Successful compromise of accounts without MFA allows attackers immediate access, leading to potential data exfiltration, business email compromise (BEC), internal spear-phishing, and deployment of further malicious payloads. This report outlines the attack methodology, observed indicators, potential impact, and critical mitigation strategies, emphasizing the urgent need for MFA deployment.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>This report details ongoing phishing campaigns specifically targeting organisations utilizing Microsoft 365, with a primary focus on Office 365 tenants where Multi-Factor Authentication (MFA) is not enforced. Attackers leverage sophisticated social engineering tactics and convincing phishing pages to harvest user credentials. Successful compromise of accounts without MFA allows attackers immediate access, leading to potential data exfiltration, business email compromise (BEC), internal spear-phishing, and deployment of further malicious payloads. This report outlines the attack methodology, observed indicators, potential impact, and critical mitigation strategies, emphasizing the urgent need for MFA deployment.</p>
<h2 id="attack-vector-and-methodology">Attack Vector and Methodology</h2>
<p>The primary attack vector is phishing emails, often crafted to bypass standard email security filters. The methodology typically follows these stages:</p>
<ol>
<li><strong>Reconnaissance (Optional but Common):</strong> Attackers may gather information about target organisations, including employee names, roles, and M365 usage, often from public sources like LinkedIn or company websites or just MX lookup on the targeted domain.</li>
<li><strong>Lure / Phishing Email:</strong>
<ul>
<li><strong>Themes:</strong> Common lures include fake security alerts (e.g., &ldquo;Unusual sign-in activity,&rdquo; &ldquo;Password expiry&rdquo;), notifications about shared documents, voicemail notifications, storage quota warnings, or urgent requests from &ldquo;IT support&rdquo; or &ldquo;management.&rdquo;</li>
<li><strong>Sender Spoofing:</strong> Attackers may spoof internal email addresses, trusted third-party services, or Microsoft itself.</li>
<li><strong>Content:</strong> Emails often contain urgent calls to action, instructing the recipient to click a link to verify their account, view a document, or prevent account suspension.</li>
</ul>
</li>
<li><strong>Phishing Page:</strong>
<ul>
<li>The link in the phishing email redirects the victim to a fake Microsoft 365 login page.</li>
<li>These pages are often pixel-perfect replicas of the legitimate Microsoft login portal, making them difficult for untrained users to distinguish.</li>
<li>Domains used for phishing pages are often typosquatted versions of legitimate domains or hosted on compromised websites.</li>
</ul>
</li>
<li><strong>Credential Harvesting:</strong>
<ul>
<li>The victim enters their M365 username and password into the fake login page.</li>
<li>These credentials are then captured by the attacker.</li>
</ul>
</li>
<li><strong>Account Access &amp; Exploitation (No MFA):</strong>
<ul>
<li>Since MFA is not enabled, the attacker can immediately use the harvested credentials to log into the victim&rsquo;s M365 account.</li>
<li>Common post-compromise activities include:
<ul>
<li><strong>Email Reconnaissance:</strong> Searching for sensitive information within emails and attachments.</li>
<li><strong>Setting up Mail Forwarding/Redirection Rules:</strong> To silently exfiltrate incoming emails or monitor communications.</li>
<li><strong>Business Email Compromise (BEC):</strong> Sending fraudulent emails from the compromised account (e.g., requesting wire transfers, changing payment details).</li>
<li><strong>Internal Spear-Phishing:</strong> Using the compromised account to send phishing emails to other employees or trusted contacts, leveraging the inherent trust.</li>
<li><strong>Data Exfiltration:</strong> Accessing and downloading files from OneDrive, SharePoint, and Teams.</li>
<li><strong>Further Compromise:</strong> Planting malware or attempting lateral movement (less common in pure credential phishing but possible).</li>
</ul>
</li>
</ul>
</li>
</ol>
<h2 id="observed-activity--indicators-of-compromise-iocs">Observed Activity / Indicators of Compromise (IoCs)</h2>
<p>Organisations should monitor for the following indicators:</p>
<p><strong>Email-based IoCs:</strong></p>
<ul>
<li>Emails with urgent subject lines or calls to action related to account security or document access.</li>
<li>Sender addresses that are slight variations of legitimate Microsoft or internal domains (e.g., <code>microsft.com</code>, <code>micosoftonline.com</code>, <code>company-support.com</code>).</li>
<li>Poor grammar or unusual phrasing in email content.</li>
<li>Hyperlinks that, when hovered over, reveal URLs not associated with Microsoft or the organisation.</li>
<li>Emails requesting direct credential entry on a linked page.</li>
</ul>
<p><strong>Login and Account Activity IoCs (within M365 Audit Logs):</strong></p>
<ul>
<li>Logins from unusual or geographically improbable IP addresses or countries.</li>
<li>Multiple failed login attempts from an IP followed by a successful login.</li>
<li>Logins using legacy authentication protocols (if not explicitly blocked).</li>
<li>Creation of unexpected mail forwarding rules or inbox rules (especially those that delete or move messages).</li>
<li>Changes to account recovery information (e.g., phone number, alternate email).</li>
<li>Unexpected sharing of files or folders from OneDrive or SharePoint.</li>
<li>Mass deletion of emails or files.</li>
<li>Sent items containing phishing emails or suspicious replies from the compromised account. We advise to closely monitor notification from partners receiving phishing emails from your domain name and existing Office365 accounts.</li>
</ul>
<p><strong>Network IoCs:</strong></p>
<ul>
<li>DNS lookups to known phishing domains or newly registered domains.</li>
<li>Outbound connections to suspicious IP addresses from user workstations after potential credential entry.</li>
</ul>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of M365 accounts without MFA can lead to severe consequences:</p>
<ul>
<li><strong>Data Breach:</strong> Unauthorized access to sensitive company data, customer information (PII), financial records, and intellectual property stored in emails, OneDrive, and SharePoint.</li>
<li><strong>Financial Loss:</strong> Through BEC attacks, invoice fraud, or unauthorized wire transfers.</li>
<li><strong>Reputational Damage:</strong> Loss of customer trust and damage to the organisation&rsquo;s brand.</li>
<li><strong>Operational Disruption:</strong> Interruption of business processes due to account lockout, data deletion, or system compromise.</li>
<li><strong>Compliance Violations:</strong> Potential breaches of data protection regulations (e.g., GDPR, HIPAA) leading to fines and legal action.</li>
<li><strong>Further Compromise:</strong> The compromised M365 account can be used as a launchpad for further attacks against internal systems or external partners.</li>
</ul>
<h2 id="mitigation--recommendations">Mitigation / Recommendations</h2>
<p>The most critical mitigation is the enforcement of Multi-Factor Authentication.</p>
<p><strong>Immediate and Essential Actions:</strong></p>
<ul>
<li><strong>Enforce MFA:</strong>
<ul>
<li><strong>Prioritize enabling and enforcing MFA for ALL M365 accounts, especially administrative accounts.</strong> Use strong MFA methods like authenticator apps (e.g., Microsoft Authenticator) or FIDO2 security keys. Avoid SMS-based MFA if possible due to susceptibility to SIM swapping.</li>
<li>Utilize Microsoft Entra ID (formerly Azure AD) Conditional Access policies to enforce MFA based on risk, location, or device compliance.</li>
</ul>
</li>
<li><strong>User Training and Awareness:</strong>
<ul>
<li>Conduct regular phishing awareness training for all employees.</li>
<li>Train users to identify suspicious emails, verify sender addresses, and scrutinize URLs before clicking.</li>
<li>Establish a clear procedure for reporting suspected phishing emails.</li>
</ul>
</li>
</ul>
<p><strong>Technical Controls and Best Practices:</strong></p>
<ul>
<li><strong>Disable Legacy Authentication:</strong> Protocols like POP3, IMAP, SMTP AUTH are often targeted as they may bypass MFA. Block legacy authentication protocols via Conditional Access policies or per-protocol settings.</li>
<li><strong>Review and Harden M365 Security Settings:</strong>
<ul>
<li>Regularly review M365 audit logs for suspicious activities.</li>
<li>Configure alerts for critical events (e.g., suspicious sign-ins, creation of mail forwarding rules).</li>
<li>Implement M365 Advanced Threat Protection (ATP) / Microsoft Defender for Office 365 for enhanced email filtering and link protection (Safe Links, Safe Attachments).</li>
</ul>
</li>
<li><strong>Password Policies:</strong> Enforce strong, unique passwords for all accounts. Encourage the use of password managers.</li>
<li><strong>Email Security Gateways:</strong> Utilize robust email security solutions with anti-phishing capabilities.</li>
<li><strong>Implement DMARC, DKIM, and SPF:</strong> To help prevent email spoofing of your domain.</li>
<li><strong>Principle of Least Privilege:</strong> Ensure users and administrators only have the permissions necessary for their roles. Regularly review privileged accounts.</li>
<li><strong>Incident Response Plan:</strong> Have a well-defined incident response plan for handling compromised accounts and data breaches. This should include steps for isolating affected accounts, investigating the breach, and remediation.</li>
</ul>
<h2 id="examples">Examples</h2>
<p>Here we will present some anonymized samples. All the name and company details abused by the attackers are valid and the emails come from the real email addresses from your contacts. This is why this attacks are so extremely dangerous.</p>
<h3 id="examples-emails-with-a-phishing-link">Examples: Emails with a Phishing Link</h3>
<pre tabindex="0"><code>Subject: #L125673547: &lt;Company Name&gt;

Content:
&lt;Phishing Link&gt;
Sincères salutations, mat beschte Gréiss, Best regards,
</code></pre><pre tabindex="0"><code>Subject: Votre facture - Compte 30031798047374-3772733 Architect &lt;Company Name&gt; vom 06.03.25

Content:
&lt;Phishing Link&gt;
Cordialement,
&lt;Name &amp; Company Address&gt;
</code></pre><h3 id="examples-emails-with-a-rmm-tool-link">Examples: Emails with a RMM Tool Link</h3>
<pre tabindex="0"><code>Subject: MISE EN DEMEURE

Content:
Madame, Monsieur

Je me permets de vous écrire en ma qualité d&#39;avocat représentant les intérêts de mon client, qui m&#39;a mandaté pour défendre ses droits à l&#39;encontre de votre société concernant des impayées.
Malgré plusieurs relances, la somme due pour les services rendus conformément au contrat n&#39;a toujours pas été effectuée.

Par la présente, Nous vous prions de bien vouloir prendre connaissance de la mise en demeure ci-jointe et procéder au règlement intégral à la réception de ce courrier, à défaut de quoi nous serons contraints d&#39;engager toutes les procédures judiciaires nécessaires à la défense des droits de mon client.

&lt;Link: Download RMM Tool&gt;

Cordialement.
Avocat à la Cour
</code></pre><pre tabindex="0"><code>Subject: ATTENTION - FACTURE IMPAYEE

Content:
Bonjour Monsieur, Madame,

Sauf erreur de notre part, après consultations de nos comptes, nous constatons que nous n&#39;avons toujours pas reçu le paiement de la facture ci-jointe malgré nos relances.

&lt;Link: Download RMM Tool&gt;

Nous vous prions de bien vouloir effectuer le paiement dans les meilleurs délais.

Cordialement
&lt;Name &amp; Company Address&gt;
</code></pre><h2 id="conclusion">Conclusion</h2>
<p>Phishing attacks targeting Microsoft 365 tenants remain a persistent and evolving threat. Microsoft is still not enforcing by default the multi-factor authentication. Organisations that have not implemented Multi-Factor Authentication are at significantly higher risk of account compromise, leading to potentially devastating consequences. The immediate enforcement of MFA, coupled with robust security practices and ongoing user education, is paramount to defending against these attacks and safeguarding organisational assets. Ignoring this critical security layer is no longer an option in the current threat landscape.</p>
<h2 id="8-references-optional">8. References (Optional)</h2>
<ul>
<li>Microsoft: <a href="https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication">Set up multifactor authentication for users</a></li>
<li>Microsoft: <a href="https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/responding-to-a-compromised-email-account">How to investigate a compromised email account</a></li>
</ul>
<h2 id="significance-for-luxembourg">Significance for Luxembourg</h2>
<p>We observed more than 48 organisations with M365 account compromised in the past 7 days starting from 21st May 2025.</p>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 21st May 2025</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-93 - Fraude financière après compromission du système via des outils de gestion et de surveillance à distance</title>
      <link>https://www.circl.lu/pub/tr-93/fr/</link>
      <pubDate>Wed, 26 Feb 2025 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-93/fr/</guid>
      <description>Résumé Ce document décrit une attaque de type Malspam ciblant les entreprises via des e-mails frauduleux exploitant des outils de gestion et de surveillance à distance (Remote Monitoring &amp;amp; Management - RMM). Les attaquants trompent les destinataires en leur faisant cliquer sur un lien malveillant, déguisé en facture, qui installe un outil RMM sur leur système. Comme ces outils sont des applications légitimes, ils contournent les antivirus et permettent aux attaquants d’obtenir un accès distant complet.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="résumé">Résumé</h2>
<p>Ce document décrit une attaque de type <strong>Malspam</strong> ciblant les entreprises via des e-mails frauduleux exploitant des outils de <strong>gestion et de surveillance à distance (Remote Monitoring &amp; Management - RMM)</strong>. Les attaquants trompent les destinataires en leur faisant cliquer sur un lien malveillant, déguisé en facture, qui installe un <strong>outil RMM sur leur système</strong>. Comme ces outils sont des applications légitimes, ils contournent les antivirus et permettent aux attaquants d&rsquo;obtenir un <strong>accès distant complet</strong>.</p>
<p>Une fois l&rsquo;accès établi, les attaquants renforcent leur contrôle en installant des outils RMM supplémentaires, en diffusant des e-mails malveillants et en modifiant les paramètres du système. Leur objectif principal est d’exploiter les stations de travail compromises – souvent celles des comptables ou responsables financiers – pour <strong>intercepter les codes PIN des cartes à puce</strong> et exécuter des <strong>transferts frauduleux</strong>, entraînant des pertes financières considérables.</p>
<p>Ce document propose une analyse détaillée du mode opératoire, des risques encourus et des mesures de protection recommandées pour se prémunir contre ces attaques.</p>
<h2 id="impact-au-luxembourg">Impact au Luxembourg</h2>
<p>Ces dernières semaines, plusieurs organisations et particuliers nous ont signalé des demandes inhabituelles de leurs banques, telles que :</p>
<ul>
<li><em>« Voulez-vous vraiment effectuer 10 transactions pour un total de 30.000 EUR vers l&rsquo;étranger ? »</em></li>
<li><em>« Voulez-vous vraiment exécuter un virement de 1.000.000 EUR vers l&rsquo;étranger ? »</em></li>
</ul>
<p>Ces transactions sont <strong>réelles et ont été initiées par des attaquants</strong>, qui ont pris le contrôle du système bancaire de la victime en installant des <strong>outils de gestion et de surveillance à distance (RMM)</strong>.<br>
L’infection initiale se fait par des <strong>attaques de phishing et de spear-phishing</strong>, comme décrit ci-dessous.</p>
<h2 id="mode-opératoire">Mode opératoire</h2>
<ol>
<li>L&rsquo;attaquant envoie un <strong>e-mail frauduleux</strong> contenant une fausse facture en pièce jointe.</li>
<li>La pièce jointe est en réalité <strong>un lien</strong> qui télécharge un <strong>outil RMM</strong> sur l’ordinateur de la victime.</li>
<li>Si la victime clique sur le lien, l’outil RMM est installé sur son système.</li>
<li><strong>L&rsquo;antivirus ne détecte pas l&rsquo;outil RMM comme malveillant</strong>, car il s&rsquo;agit d&rsquo;une application légitime.</li>
<li>L&rsquo;attaquant obtient un <strong>accès distant total</strong> au système et peut capturer le <strong>code PIN des cartes à puce</strong> utilisées pour l’authentification bancaire.</li>
<li>L’attaquant exécute ensuite les actions suivantes :
<ul>
<li><strong>Installation d’autres outils RMM</strong> pour assurer un accès persistant.</li>
<li>Envoi d’e-mails frauduleux aux contacts du carnet d’adresses de la victime.</li>
<li>Analyse approfondie du système compromis.</li>
<li>Modification des paramètres système pour atteindre ses objectifs.</li>
<li><strong>Exécution de transactions financières frauduleuses.</strong></li>
</ul>
</li>
</ol>
<h3 id="exemples-récents">Exemples récents</h3>
<pre tabindex="0"><code>Objet : Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024

Monsieur, Madame,

La présente communication concerne la facture no FACT#032024 et FACT#042024 au montant total de 32.857€ qui Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024. Vous trouverez en annexe une copie de la facture pertinente.

Comme vous le savez, nous vous avons fourni le delai de recouvrement du dossier R1184521. Or, malgré le rappel effectué le 15/06/2024 à laquelle une lettre de relance a été envoyée, nous constatons que la facture demeure impayée, et ce, bien que nous ayons rempli toutes nos obligations.

Ainsi, nous vous prions de nous faire parvenir un chèque certifié au montant de 32.857€ à l’ordre de notre entreprise dans les 10 jours de la réception de la présente mise en demeure. Le chèque devra être transmis au notre adresse. À défaut, une demande en justice pourrait être déposée contre vous, sans autre avis ni délai.

Soyez avisé que nous considérerons de bonne foi tout mode alternatif de règlement proposé. Nous sommes d’avis qu’il est dans l’intérêt de tous que cette situation puisse être réglée à l’amiable. En ce sens, nous vous invitons à communiquer avec nous si vous désirez discuter de la présente mise en demeure.

Nous vous invitons à ignorer la présente lettre si le paiement a été effectué avant la date de réception de cette communication.

VEUILLEZ AGIR EN CONSÉQUENCE.                                 
</code></pre><h2 id="mesures-de-protection">Mesures de protection</h2>
<p>Pour prévenir ces <strong>attaques de type Malspam</strong> (e-mails malveillants contenant des liens menant à des logiciels indésirables), une <strong>approche de sécurité multicouche</strong> est indispensable. Voici quelques <strong>mesures efficaces</strong> :</p>
<h3 id="1-sécurisation-des-e-mails">1. Sécurisation des e-mails</h3>
<ul>
<li><strong>Filtres avancés</strong> – Utilisation de <strong>passerelles sécurisées</strong> et de <strong>filtres anti-spam</strong>.</li>
<li><strong>Désactivation du téléchargement automatique des pièces jointes</strong>.</li>
<li><strong>Analyse et sandboxing des liens</strong> – Vérification des URL en temps réel.</li>
<li>CIRCL propose un <strong>service en ligne gratuit pour analyser les pièces jointes des e-mails</strong>: <a href="https://pandora.circl.lu">pandora</a></li>
</ul>
<h3 id="2-sensibilisation-et-formation-des-utilisateurs">2. Sensibilisation et formation des utilisateurs</h3>
<ul>
<li><strong>Campagnes de sensibilisation</strong> – Former les employés à <strong>ne pas cliquer sur des liens suspects</strong>.</li>
<li><strong>Survol des liens avant de cliquer</strong> pour vérifier leur destination.</li>
<li><strong>Simulations de phishing</strong> – Tests réguliers pour entraîner les employés à détecter les e-mails frauduleux.</li>
<li>CIRCL propose un <strong>service en ligne gratuit pour l&rsquo;analyse des URL</strong>: <a href="https://lookyloo.circl.lu">lookyloo</a></li>
</ul>
<h3 id="3-protection-des-postes-de-travail-et-du-réseau">3. Protection des postes de travail et du réseau</h3>
<ul>
<li><strong>Filtrage des URL malveillantes</strong> – Blocage des domaines frauduleux via un proxy ou un outil de sécurité.</li>
<li><strong>Whitelisting des applications</strong> – Seules les applications autorisées peuvent s’exécuter.</li>
<li><strong>Solutions avancées de détection (EDR/NGAV)</strong> – Surveillance et blocage des comportements malveillants.</li>
</ul>
<h3 id="4-authentification-et-protection-contre-lusurpation-didentité">4. Authentification et protection contre l’usurpation d’identité</h3>
<ul>
<li><strong>Mise en place de DMARC, DKIM et SPF</strong> – Protection contre le <strong>spoofing d&rsquo;e-mail</strong>.</li>
<li><strong>Surveillance des noms de domaine</strong> – Enregistrement de variantes pour prévenir l’usurpation.</li>
<li><strong>Configuration correcte du DNS</strong> - voir <a href="/pub/tr-92/">TR-92</a>.</li>
</ul>
<h3 id="5-gestion-des-accès-et-principe-du-moindre-privilège">5. Gestion des accès et principe du moindre privilège</h3>
<ul>
<li><strong>Restriction des droits utilisateur</strong> – Pas de droits administrateurs sans nécessité.</li>
<li><strong>Authentification renforcée</strong> – Vérification des actions sensibles.</li>
<li><strong>Désactivation des macros et de l&rsquo;exécution automatique des scripts</strong>.</li>
</ul>
<h3 id="6-autres-bonnes-pratiques">6. Autres bonnes pratiques</h3>
<ul>
<li><strong>Mises à jour régulières des logiciels et du système d’exploitation</strong>.</li>
<li><strong>Désactivation des extensions de navigateur non essentielles</strong>.</li>
</ul>
<h3 id="7-surveillance-et-réponse-aux-incidents">7. Surveillance et réponse aux incidents</h3>
<ul>
<li><strong>Surveillance via SIEM</strong> – Détection des comportements anormaux.</li>
<li><strong>Plan de réponse aux incidents</strong> – Isolement rapide des appareils compromis.</li>
</ul>
<h2 id="que-faire-en-cas-de-compromission-">Que faire en cas de compromission ?</h2>
<ul>
<li><strong>Déconnecter immédiatement l’ordinateur compromis du réseau (y compris le Wi-Fi !)</strong>.</li>
<li><strong>Contacter votre équipe de réponse aux incidents ou CIRCL</strong>.</li>
<li><strong>Informer l’équipe IT</strong> pour une surveillance renforcée.</li>
<li><strong>Identifier d’autres systèmes potentiellement touchés</strong>.</li>
<li><strong>Avertir vos contacts</strong> de ne pas ouvrir de liens provenant de votre entreprise.</li>
<li><strong>Former le personnel</strong> à détecter ces attaques.</li>
<li><strong>Déclarer la violation à la CNPD dans les 72 heures</strong> si des données personnelles sont compromises.</li>
</ul>
<h2 id="contre-mesures-efficaces">Contre-mesures efficaces</h2>
<h3 id="les-solutions-inefficaces-proposées-par-certains-prestataires-it"><strong>Les solutions inefficaces proposées par certains prestataires IT</strong></h3>
<p>Un simple scan antivirus est <strong>insuffisant</strong>, car :</p>
<ul>
<li><strong>Les outils RMM légitimes ne sont pas détectés comme malveillants</strong>.</li>
<li><strong>Des portes dérobées peuvent rester actives</strong>.</li>
<li><strong>L&rsquo;attaquant peut rétablir son accès rapidement</strong>.</li>
</ul>
<h3 id="les-bonnes-pratiques-à-adopter"><strong>Les bonnes pratiques à adopter</strong></h3>
<ul>
<li><strong>Déployer une solution EDR</strong> et mettre en place une <strong>liste blanche des outils RMM</strong>.</li>
<li><strong>Utilisez LuxTrust Mobile ou LuxTrust Scan</strong> au lieu d&rsquo;une carte à puce pour vous authentifier (voir la <a href="https://www.multiline.lu/wp-content/uploads/2019/12/Utilisation-du-LuxTrust-Scan-et-du-LuxTrust-Mobile-dans-MultiLineV4.pdf">documentation LuxTrust</a>)</li>
<li><strong>Retirer la carte à puce du lecteur lorsqu’elle n’est pas utilisée</strong>.</li>
<li><strong>Mettre en place une validation à deux personnes pour les transactions bancaires</strong>.</li>
<li><strong>Activer des facteurs d’authentification supplémentaires</strong>.</li>
<li><strong>Choisir une banque qui effectue une vérification des bénéficiaires</strong>.</li>
</ul>
<h2 id="récupération-après-compromission">Récupération après compromission</h2>
<ul>
<li><strong>Contacter immédiatement la banque</strong> pour tenter de bloquer les transactions frauduleuses.</li>
<li><strong>Déposer une plainte auprès de la police</strong>.</li>
<li><strong>Contacter CIRCL</strong> pour une analyse approfondie.</li>
<li><strong>Réinstaller complètement le système compromis</strong>.</li>
<li><strong>Surveiller les accès à distance (RDP, VPN, etc.)</strong>.</li>
<li><strong>Réinitialiser tous les mots de passe</strong>.</li>
<li><strong>Activer l’authentification à deux facteurs (2FA)</strong>.</li>
<li><strong>Renforcer la formation des employés</strong>.</li>
</ul>
<h2 id="conclusion">Conclusion</h2>
<p>Un simple scan antivirus <strong>ne suffit pas</strong>. Pour une récupération complète, il est nécessaire de <strong>réinstaller totalement le système affecté</strong>.</p>
<h2 id="ioc">IoC</h2>
<p>Voir l&rsquo;événement MISP UUID 5f7819de-5656-4063-a76a-a39253ee5154, disponible sur l&rsquo;instance <a href="https://misppriv.circl.lu/events/view/278450">MISP pour le secteur privé</a>.</p>
<h2 id="classification-du-document">Classification du document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> – Diffusion libre sous réserve du respect des droits d’auteur.</p>
<h2 id="révision">Révision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - Première version - 26 février 2025</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-93 - Finanzbetrug nach Systemkompromittierung über Remote-Management- und Monitoring-Tools</title>
      <link>https://www.circl.lu/pub/tr-93/de/</link>
      <pubDate>Wed, 26 Feb 2025 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-93/de/</guid>
      <description>Zusammenfassung Dieses Dokument beschreibt eine Malspam-Attacke, die sich gegen Unternehmen richtet, indem betrügerische E-Mails versendet werden, die Remote-Monitoring &amp;amp; Management (RMM)-Tools ausnutzen. Die Angreifer täuschen die Empfänger dazu, auf einen schädlichen Link zu klicken, der als Rechnung getarnt ist und ein RMM-Tool auf ihrem System installiert. Da diese Tools legitime Anwendungen sind, umgehen sie Antiviren-Erkennungen und ermöglichen den Angreifern vollständigen Fernzugriff.&amp;#xA;Sobald der Zugriff erlangt ist, eskalieren die Angreifer ihre Kontrolle, indem sie zusätzliche RMM-Tools zur Persistenz installieren, Malware über E-Mails verbreiten und Systemeinstellungen ändern. Besonders kritisch ist, dass sie kompromittierte Arbeitsstationen – oft von Buchhaltern oder Finanzverantwortlichen – ausnutzen, um Smartcard-PINs abzufangen und betrügerische Überweisungen auszuführen, was zu erheblichen finanziellen Verlusten führt.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="zusammenfassung">Zusammenfassung</h2>
<p>Dieses Dokument beschreibt eine Malspam-Attacke, die sich gegen Unternehmen richtet, indem betrügerische E-Mails versendet werden, die Remote-Monitoring &amp; Management (RMM)-Tools ausnutzen. Die Angreifer täuschen die Empfänger dazu, auf einen schädlichen Link zu klicken, der als Rechnung getarnt ist und ein RMM-Tool auf ihrem System installiert. Da diese Tools legitime Anwendungen sind, umgehen sie Antiviren-Erkennungen und ermöglichen den Angreifern vollständigen Fernzugriff.</p>
<p>Sobald der Zugriff erlangt ist, eskalieren die Angreifer ihre Kontrolle, indem sie zusätzliche RMM-Tools zur Persistenz installieren, Malware über E-Mails verbreiten und Systemeinstellungen ändern. Besonders kritisch ist, dass sie kompromittierte Arbeitsstationen – oft von Buchhaltern oder Finanzverantwortlichen – ausnutzen, um Smartcard-PINs abzufangen und betrügerische Überweisungen auszuführen, was zu erheblichen finanziellen Verlusten führt.</p>
<p>Dieses Dokument bietet eine detaillierte Analyse des Modus Operandi, der Risiken und der empfohlenen Schutzmaßnahmen zur Abwehr solcher Angriffe.</p>
<h2 id="bedeutung-für-luxemburg">Bedeutung für Luxemburg</h2>
<p>In den letzten Wochen haben wir mehrere Berichte von Organisationen und Einzelpersonen erhalten, die verdächtige Anfragen von ihren Banken gemeldet haben, wie zum Beispiel:</p>
<ul>
<li><em>„Möchten Sie wirklich 10 Transaktionen im Gesamtwert von ca. 30.000 EUR ins Ausland ausführen?“</em></li>
<li><em>„Möchten Sie wirklich eine Transaktion über 1.000.000 EUR ins Ausland ausführen?“</em></li>
</ul>
<p>Diese Transaktionen sind <strong>echt und wurden von Angreifern ausgeführt</strong>, die Zugriff auf das Bankensystem des Opfers erlangt haben, indem sie <strong>legitime Remote-Management- und Monitoring-Tools (RMM)</strong> installiert haben.<br>
Die Erstinfektion erfolgt über Phishing- und Spear-Phishing-Angriffe, wie unten beschrieben.</p>
<h2 id="modus-operandi">Modus Operandi</h2>
<ol>
<li>Der Angreifer sendet eine betrügerische geschäftliche E-Mail mit einer gefälschten Rechnung als Anhang.</li>
<li>Der Anhang ist tatsächlich ein Link, der ein Remote-Monitoring- &amp; Management-Tool (RMM) herunterlädt.</li>
<li>Wenn das Opfer den Link anklickt, wird das RMM-Tool auf seinem System installiert.</li>
<li><strong>Antivirus-Software erkennt das RMM-Tool nicht als bösartig, da es sich um legitime Anwendungen handelt.</strong></li>
<li>Das RMM-Tool gewährt dem Angreifer vollständigen Fernzugriff auf den Computer des Opfers, wodurch er die <strong>mehrstufige Smartcard-PIN</strong> erfassen kann.</li>
<li>Der Angreifer führt dann folgende Aktionen durch:
<ul>
<li><strong>Installation weiterer legitimer RMM-Tools</strong> zur Aufrechterhaltung des Zugriffs.</li>
<li>Versenden infizierter E-Mails an Kontakte im Adressbuch des Opfers.</li>
<li>Analyse des kompromittierten Systems.</li>
<li>Modifikation von Systemeinstellungen zur Erreichung seiner Ziele.</li>
<li><strong>Durchführung betrügerischer Finanztransaktionen.</strong></li>
</ul>
</li>
</ol>
<h3 id="aktuelle-beispiele-französisch">Aktuelle Beispiele (Französisch)</h3>
<pre tabindex="0"><code>Objet : Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024

Monsieur, Madame,

La présente communication concerne la facture no FACT#032024 et FACT#042024 au montant total de 32.857€ qui Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024. Vous trouverez en annexe une copie de la facture pertinente.

Comme vous le savez, nous vous avons fourni le delai de recouvrement du dossier R1184521. Or, malgré le rappel effectué le 15/06/2024 à laquelle une lettre de relance a été envoyée, nous constatons que la facture demeure impayée, et ce, bien que nous ayons rempli toutes nos obligations.

Ainsi, nous vous prions de nous faire parvenir un chèque certifié au montant de 32.857€ à l’ordre de notre entreprise dans les 10 jours de la réception de la présente mise en demeure. Le chèque devra être transmis au notre adresse. À défaut, une demande en justice pourrait être déposée contre vous, sans autre avis ni délai.

Soyez avisé que nous considérerons de bonne foi tout mode alternatif de règlement proposé. Nous sommes d’avis qu’il est dans l’intérêt de tous que cette situation puisse être réglée à l’amiable. En ce sens, nous vous invitons à communiquer avec nous si vous désirez discuter de la présente mise en demeure.

Nous vous invitons à ignorer la présente lettre si le paiement a été effectué avant la date de réception de cette communication.

VEUILLEZ AGIR EN CONSÉQUENCE.                                 
</code></pre><h2 id="schutzmaßnahmen">Schutzmaßnahmen</h2>
<p>Die Verhinderung solcher <strong>Malspam-Angriffe</strong> (bösartige Spam-Mails mit Links zum Herunterladen von Malware) erfordert einen <strong>mehrschichtigen Sicherheitsansatz</strong>. Nachfolgend effektive <strong>Schutzmaßnahmen</strong>:</p>
<h3 id="1-e-mail-sicherheitsmaßnahmen">1. E-Mail-Sicherheitsmaßnahmen</h3>
<ul>
<li><strong>Erweiterte E-Mail-Filter</strong> – Nutzen Sie <strong>sichere E-Mail-Gateways</strong> und <strong>Spam-Filter</strong>, um Malspam-E-Mails zu blockieren.</li>
<li><strong>Automatisches Herunterladen von Anhängen deaktivieren</strong> – Verhindern Sie, dass E-Mail-Clients verlinkte Dateien automatisch herunterladen.</li>
<li><strong>Link-Sandboxing &amp; URL-Analyse</strong> – Implementieren Sie Sicherheitslösungen, die Links in Echtzeit analysieren.</li>
<li>CIRCL bietet einen <strong>kostenlosen Online-Dienst zur Analyse von E-Mail-Anhängen</strong> an: <a href="https://pandora.circl.lu">pandora</a></li>
</ul>
<h3 id="2-benutzerbewusstsein--schulung">2. Benutzerbewusstsein &amp; Schulung</h3>
<ul>
<li><strong>Sensibilisierungskampagnen</strong> – Schulen Sie Mitarbeiter darin, <strong>keine unbekannten Links zu klicken</strong>.</li>
<li><strong>Links vor dem Klicken überprüfen</strong> – Mitarbeiter sollten Links vor dem Klicken mit der Maus überfahren.</li>
<li><strong>Phishing-Simulationen</strong> – Regelmäßige Tests zur Erkennung verdächtiger E-Mails.</li>
<li>CIRCL bietet einen <strong>kostenlosen Online-Dienst zur Untersuchung von URLs</strong> an: <a href="https://lookyloo.circl.lu">lookyloo</a></li>
</ul>
<h3 id="3-endpunktschutz--netzwerksicherheit">3. Endpunktschutz &amp; Netzwerksicherheit</h3>
<ul>
<li><strong>URL-Blockierung &amp; Web-Filter</strong> – Einsatz von Web-Proxies und Sicherheitstools zum Blockieren bösartiger Domains.</li>
<li><strong>Anwendungs-Whitelisting</strong> – Nur genehmigte Anwendungen dürfen ausgeführt werden.</li>
<li><strong>Erweiterter Endpunktschutz (EDR/NGAV)</strong> – Erkennung und Blockierung von Malware.</li>
</ul>
<h3 id="4-e-mail-authentifizierung--schutz-vor-spoofing">4. E-Mail-Authentifizierung &amp; Schutz vor Spoofing</h3>
<ul>
<li><strong>DMARC, DKIM und SPF implementieren</strong> – Schutz gegen <strong>E-Mail-Spoofing</strong>.</li>
<li><strong>Markenschutz &amp; Domain-Monitoring</strong> – Registrierung ähnlicher Domains zur Phishing-Prävention.</li>
<li><strong>Korrekte DNS-Konfiguration</strong> - siehe <a href="/pub/tr-92/">TR-92</a></li>
</ul>
<h3 id="5-zugriffskontrolle--prinzip-der-minimalen-rechte">5. Zugriffskontrolle &amp; Prinzip der minimalen Rechte</h3>
<ul>
<li><strong>Einschränkung von Benutzerrechten</strong> – Keine Admin-Rechte ohne triftigen Grund.</li>
<li><strong>Zusätzliche Authentifizierung</strong> – Verifikation für externe Links oder Downloads.</li>
<li><strong>Deaktivierung von Makros &amp; Skript-Autoausführung</strong>.</li>
</ul>
<h3 id="6-allgemeine-sicherheitsmaßnahmen">6. Allgemeine Sicherheitsmaßnahmen</h3>
<ul>
<li><strong>Regelmäßige Software- und OS-Updates</strong>.</li>
<li><strong>Unnötige Browser-Plugins deaktivieren</strong>.</li>
</ul>
<h3 id="7-reaktion-auf-vorfälle--monitoring">7. Reaktion auf Vorfälle &amp; Monitoring</h3>
<ul>
<li><strong>SIEM-Überwachung</strong> – Erkennung ungewöhnlicher Aktivitäten.</li>
<li><strong>Vorfallreaktionsplan</strong> – Infizierte Geräte schnell isolieren.</li>
</ul>
<h2 id="maßnahmen-bei-einer-kompromittierung">Maßnahmen bei einer Kompromittierung</h2>
<ul>
<li>Sofortige Trennung des betroffenen PCs vom Netzwerk (auch WLAN!).</li>
<li>Kontaktieren Sie Ihr Incident-Response-Team oder CIRCL.</li>
<li>IT-Team zur verstärkten Überwachung informieren.</li>
<li>Untersuchung möglicher weiterer betroffener Systeme.</li>
<li>Warnung an Kontakte, keine Links aus E-Mails Ihres Unternehmens zu öffnen.</li>
<li>Schulung der Mitarbeiter zur Wachsamkeit.</li>
<li><strong>Meldung an die CNPD innerhalb von 72 Stunden bei Datenpannen</strong>.</li>
</ul>
<h2 id="effektive-gegenmaßnahmen">Effektive Gegenmaßnahmen</h2>
<h3 id="unwirksame-lösungen-durch-it-dienstleister"><strong>Unwirksame Lösungen durch IT-Dienstleister</strong></h3>
<p>Ein mehrfacher Virenscan reicht <strong>nicht</strong> aus, da:</p>
<ul>
<li><strong>Legitime RMM-Tools</strong> nicht erkannt werden.</li>
<li><strong>Versteckte Hintertüren</strong> oft unentdeckt bleiben.</li>
<li><strong>Angreifer schnell wieder Zugriff erlangen</strong>.</li>
</ul>
<h3 id="erfolgreiche-maßnahmen"><strong>Erfolgreiche Maßnahmen</strong></h3>
<ul>
<li><strong>EDR-Lösung implementieren</strong> und RMM-Tools auf eine <strong>Allowlist</strong> setzen.</li>
<li><strong>Verwenden Sie LuxTrust Mobile oder LuxTrust Scan</strong> anstelle einer Smartcard zur Authentifizierung (siehe <a href="https://www.multiline.lu/wp-content/uploads/2019/09/Verwendung-von-LuxTrust-Scan-und-LuxTrust-Mobile-in-MultiLineV4.pdf">LuxTrust-Dokumentation</a>)</li>
<li><strong>Smartcard aus dem Leser entfernen</strong>, wenn sie nicht benutzt wird.</li>
<li><strong>4-Augen-Prinzip bei Überweisungen einführen</strong>.</li>
<li><strong>Zusätzliche Authentifizierungsfaktoren aktivieren</strong>.</li>
<li>Eine <strong>Bank wählen, die Empfänger prüft</strong>.</li>
</ul>
<h2 id="wiederherstellung-nach-einer-kompromittierung">Wiederherstellung nach einer Kompromittierung</h2>
<ul>
<li><strong>Sofort die Bank kontaktieren</strong>, um betrügerische Überweisungen zu stoppen.</li>
<li><strong>Strafanzeige bei der Polizei erstatten</strong>.</li>
<li><strong>CIRCL kontaktieren</strong>, falls IT-Sicherheitsberatung benötigt wird.</li>
<li><strong>Das kompromittierte System vollständig neu installieren</strong>.</li>
<li><strong>RDP-Zugriff überwachen</strong>.</li>
<li><strong>Alle Passwörter zurücksetzen</strong>.</li>
<li><strong>Zwei-Faktor-Authentifizierung (2FA) aktivieren</strong>.</li>
<li><strong>Mitarbeiter sensibilisieren</strong>.</li>
</ul>
<h2 id="fazit">Fazit</h2>
<p>Ein einfacher Virenscan <strong>löst das Problem nicht</strong>. Zur vollständigen Bereinigung muss das betroffene System <strong>komplett neu installiert</strong> werden.</p>
<h2 id="ioc">IoC</h2>
<p>Siehe MISP-Ereignis UUID 5f7819de-5656-4063-a76a-a39253ee5154, verfügbar auf <a href="https://misppriv.circl.lu/events/view/278450">MISP für den privaten Sektor</a>.</p>
<h2 id="dokumentklassifikation">Dokumentklassifikation</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> – Freie Verbreitung unter Beachtung des Urheberrechts.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - Erste Version - 26. Februar 2025</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-93 - Financial transaction fraud after system compromise via Remote Management and Monitoring tools</title>
      <link>https://www.circl.lu/pub/tr-93/</link>
      <pubDate>Wed, 26 Feb 2025 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-93/</guid>
      <description>Executive Summary This document outlines a malspam attack targeting businesses through fraudulent emails that exploit Remote Monitoring &amp;amp; Management (RMM) tools. The attackers deceive recipients into clicking a malicious link disguised as an invoice, which installs an RMM tool on their system. Since these tools are legitimate applications, they evade antivirus detection, granting attackers full remote access.&amp;#xA;Once access is gained, the attackers escalate their control by installing additional RMM tools for persistence, spreading malware via email, and modifying system settings. Critically, they exploit the compromised workstation—often belonging to accountants or financial officers—to capture smart card PINs and execute fraudulent wire transfers, resulting in significant financial losses.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>This document outlines a malspam attack targeting businesses through fraudulent emails that exploit Remote Monitoring &amp; Management (RMM) tools. The attackers deceive recipients into clicking a malicious link disguised as an invoice, which installs an RMM tool on their system. Since these tools are legitimate applications, they evade antivirus detection, granting attackers full remote access.</p>
<p>Once access is gained, the attackers escalate their control by installing additional RMM tools for persistence, spreading malware via email, and modifying system settings. Critically, they exploit the compromised workstation—often belonging to accountants or financial officers—to capture smart card PINs and execute fraudulent wire transfers, resulting in significant financial losses.</p>
<p>This document provides a detailed breakdown of the modus operandi, risks, and recommended preventative measures to mitigate the threat posed by such attacks.</p>
<h2 id="significance-for-luxembourg">Significance for Luxembourg</h2>
<p>Over the past few weeks, we have received multiple reports from organizations and individuals regarding suspicious inquiries from their banks, such as:</p>
<ul>
<li><em>&ldquo;Do you really want to execute 10 transactions totaling approximately 30,000 EUR abroad?&rdquo;</em></li>
<li><em>&ldquo;Do you really want to execute a transaction of 1,000,000 EUR abroad?&rdquo;</em></li>
</ul>
<p>These transactions are <strong>real and executed by attackers</strong> who have gained access to the victim’s banking system by installing <strong>legitimate Remote Monitoring and Management (RMM) tools</strong>.<br>
The initial infection occurs through phishing and spear-phishing attacks, as detailed below.</p>
<h2 id="modus-operandi">Modus Operandi</h2>
<ol>
<li>The attacker sends a fraudulent business email containing a fake invoice as an attachment.</li>
<li>The attachment is actually a link that downloads a Remote Monitoring &amp; Management (RMM) tool.</li>
<li>If the victim clicks the link, the RMM tool is installed on their system.</li>
<li><strong>Antivirus software does not detect the RMM tool as malicious since these are legitimate applications.</strong></li>
<li>The RMM tool grants the attacker full remote access to the victim’s computer, allowing them to capture the <strong>multiline smart card PIN</strong>.</li>
<li>The attacker then:
<ul>
<li><strong>Installs multiple other legitimate RMM tools</strong> for persistence.</li>
<li>Sends infected emails to contacts in the victim’s address book.</li>
<li>Analyzes the compromised system.</li>
<li>Modifies system configurations to achieve their objectives.</li>
<li><strong>Executes fraudulent financial transactions.</strong></li>
</ul>
</li>
</ol>
<h3 id="recent-examples-french">Recent Examples (French)</h3>
<pre tabindex="0"><code>Objet : Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024

Monsieur, Madame,

La présente communication concerne la facture no FACT#032024 et FACT#042024 au montant total de 32.857€ qui Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024. Vous trouverez en annexe une copie de la facture pertinente.

Comme vous le savez, nous vous avons fourni le delai de recouvrement du dossier R1184521. Or, malgré le rappel effectué le 15/06/2024 à laquelle une lettre de relance a été envoyée, nous constatons que la facture demeure impayée, et ce, bien que nous ayons rempli toutes nos obligations.

Ainsi, nous vous prions de nous faire parvenir un chèque certifié au montant de 32.857€ à l’ordre de notre entreprise dans les 10 jours de la réception de la présente mise en demeure. Le chèque devra être transmis au notre adresse. À défaut, une demande en justice pourrait être déposée contre vous, sans autre avis ni délai.

Soyez avisé que nous considérerons de bonne foi tout mode alternatif de règlement proposé. Nous sommes d’avis qu’il est dans l’intérêt de tous que cette situation puisse être réglée à l’amiable. En ce sens, nous vous invitons à communiquer avec nous si vous désirez discuter de la présente mise en demeure.

Nous vous invitons à ignorer la présente lettre si le paiement a été effectué avant la date de réception de cette communication.

VEUILLEZ AGIR EN CONSÉQUENCE.                                 
</code></pre><h2 id="prevention-strategies">Prevention Strategies</h2>
<p>Preventing such <strong>malspam attacks</strong> (malicious spam containing hyperlinks to download malware) in a corporate environment requires a <strong>multi-layered security approach</strong>. Below are effective <strong>prevention strategies</strong>:</p>
<h3 id="1-email-security-measures">1. Email Security Measures</h3>
<ul>
<li><strong>Advanced Email Filtering</strong> – Use <strong>secure email gateways</strong> and <strong>spam filters</strong> to detect and block malspam emails before they reach inboxes.</li>
<li><strong>Disable Auto-Download of Attachments</strong> – Prevent email clients from automatically downloading linked files.</li>
<li><strong>Link Sandboxing &amp; URL Analysis</strong> – Implement email security solutions that scan and analyze hyperlinks in real-time before users click them.</li>
<li>CIRCL proposes <strong>a free online service for scanning email attachments</strong>: <a href="https://pandora.circl.lu">pandora</a></li>
</ul>
<h3 id="2-user-awareness--training">2. User Awareness &amp; Training</h3>
<ul>
<li><strong>Security Awareness Campaigns</strong> – Educate employees on <strong>not clicking unknown or unexpected links</strong>, even from seemingly trusted sources.</li>
<li><strong>Hover Over Links Before Clicking</strong> – Teach employees to hover over hyperlinks to preview URLs before clicking.</li>
<li><strong>Phishing Simulation Training</strong> – Conduct regular phishing tests to train employees on recognizing suspicious links.</li>
<li>CIRCL proposes <strong>a free online service for investigating urls</strong>: <a href="https://lookyloo.circl.lu">lookyloo</a></li>
</ul>
<h3 id="3-endpoint-protection--network-security">3. Endpoint Protection &amp; Network Security</h3>
<ul>
<li><strong>URL Blocking &amp; Web Filtering</strong> – Use web proxies and security tools to block known malicious domains.</li>
<li><strong>Application Whitelisting</strong> – Restrict the execution of unapproved applications to prevent malware from running.</li>
<li><strong>Endpoint Protection Software</strong> – Deploy <strong>next-gen antivirus (NGAV) and Endpoint Detection &amp; Response (EDR)</strong> to identify and block malware from executing.</li>
</ul>
<h3 id="4-email-authentication--domain-protection">4. Email Authentication &amp; Domain Protection</h3>
<ul>
<li><strong>Implement DMARC, DKIM, and SPF</strong> – These email authentication protocols help prevent <strong>email spoofing</strong> and domain impersonation.</li>
<li><strong>Brand Protection &amp; Domain Monitoring</strong> – Monitor for domain spoofing attempts and <strong>register similar domains</strong> to prevent phishing.</li>
<li><strong>Correct DNS configuration</strong> - see <a href="/pub/tr-92/">TR-92</a></li>
</ul>
<h3 id="5-access-control--least-privilege-principle">5. Access Control &amp; Least Privilege Principle</h3>
<ul>
<li><strong>Restrict User Privileges</strong> – Users should not have <strong>admin rights</strong> unless absolutely necessary.</li>
<li><strong>Additional Authentication</strong> – Enforce authentication and verification for accessing external links or downloading software.</li>
<li><strong>Disable Macros &amp; Auto-Execution of Scripts</strong> – Prevent execution of <strong>malicious scripts</strong> embedded in documents.</li>
</ul>
<h3 id="6-general-secure-software--patch-management">6. General: Secure Software &amp; Patch Management</h3>
<ul>
<li><strong>Regular Software &amp; OS Updates</strong> – Ensure all systems, browsers, and email clients are patched to prevent exploitation.</li>
<li><strong>Disable Unnecessary Browser Plugins</strong> – Reduce attack surface by removing unneeded browser extensions.</li>
</ul>
<h3 id="7-incident-response--monitoring">7. Incident Response &amp; Monitoring</h3>
<ul>
<li><strong>SIEM (Security Information and Event Management)</strong> – Implement <strong>real-time monitoring</strong> to detect unusual email traffic patterns.</li>
<li><strong>Incident Response Plan</strong> – Have a response <strong>team</strong> and <strong>strategy</strong> ready if employees fall victim to malspam, including <strong>isolating infected devices</strong> and <strong>removing malware</strong>.</li>
</ul>
<h2 id="actions-during-a-compromise">Actions during a Compromise</h2>
<ul>
<li>Disconnect the affected PC from the network immediatly (Don&rsquo;t forget WiFi).</li>
<li>Talk to your local incident response team.</li>
<li>If this doesn&rsquo;t exist, do not hesitate to <strong>contact CIRCL</strong> to <strong>discuss the case</strong> and be prepared to <strong>receive an action plan</strong>.</li>
<li>Inform your IT team to increase monitoring and the vigilance level.</li>
<li>Investigate for potential other PC affected.</li>
<li>Warn all you contacts, clients, customers and alike to not click on links in emails send by your organization.</li>
<li>Teach all your staff about the issue and make them vigilant</li>
<li>There are legal obligations in case of compromised infrastructure, e.g. to inform CNPD within 72 hours and any victims of a data breach. CIRCL will give you recommendations if necessary.</li>
</ul>
<h2 id="mitigation-strategies">Mitigation Strategies</h2>
<h3 id="ineffective-solutions-from-ict-providers-what-does-not-fix-the-problem"><strong>Ineffective Solutions from ICT Providers: What Does NOT Fix the Problem</strong></h3>
<p>Some service providers attempt to mitigate the issue by running multiple antivirus scans on the infected system. If no further malware is detected, they conclude that the system is clean.</p>
<p>However, this approach is ineffective because:</p>
<ul>
<li>Attackers install <strong>legitimate RMM tools</strong> that antivirus software does not flag.</li>
<li>It is nearly impossible to detect all backdoors left by the attackers.</li>
<li>If this approach is followed, attackers will <strong>regain access quickly</strong> and continue fraudulent activity.</li>
</ul>
<h3 id="effective-mitigation-steps"><strong>Effective Mitigation Steps</strong></h3>
<ul>
<li>Implement an <strong>Endpoint Detection and Response (EDR) solution</strong> and enforce an <strong>allowlist for RMM tools</strong> used within the organization.</li>
<li>Use <strong>LuxTrust Mobile or LuxTrust Scan instead of a smart card to authenticate</strong> (see <a href="https://multiline.lu/wp-content/uploads/2019/09/Using-LuxTrust-Scan-and-LuxTrust-Mobile-in-MultiLineV4.pdf">luxtrust documentation</a>).</li>
<li><strong>Remove the multiline smart card from the reader</strong> when not in use.</li>
<li>Use <strong>4-eyes principles</strong> for wire transfers.</li>
<li><strong>Enable additional authentication factors</strong> for multiline banking (e.g., phone-based authentication).</li>
<li>Select a <strong>bank</strong> that actually <strong>checks</strong> wire transfer recipients.</li>
</ul>
<h2 id="remediation-after-a-compromise">Remediation After a Compromise</h2>
<p>If an organization falls victim to this attack, the following actions must be taken:</p>
<ul>
<li>Contact immediately the bank of your organisation and the destination bank to block the fraudulent wire transfer.</li>
<li>File a complaint with the local police or the “service de police judiciaire”.</li>
<li>Contact CIRCL if you need technical support or advice related to IT security incidents.</li>
<li><strong>Reinstall the compromised system from scratch.</strong></li>
<li><strong>Monitor Remote Desktop access.</strong> Attackers may exploit existing RDP access to escalate privileges or move
laterally within a network. Evidence of such activity can often be found in Event Logs.</li>
<li>In severe cases, <strong>all systems within the organization may need to be reinstalled.</strong></li>
<li><strong>Revoke and reissue all banking certificates.</strong></li>
<li><strong>Reset all passwords.</strong></li>
<li><strong>Implement Two-Factor Authentication (2FA) wherever possible.</strong></li>
<li><strong>Educate employees</strong> on cybersecurity best practices to prevent future incidents.</li>
</ul>
<h2 id="conclusion">Conclusion</h2>
<p>A simple virus scan <strong>does not resolve this issue</strong>. To fully mitigate the attack, the affected system must be <strong>completely reinstalled</strong>.</p>
<p>Organizations should <strong>closely monitor their ICT service providers</strong> to ensure proper remediation is performed.</p>
<h2 id="ioc">IoC</h2>
<p>See MISP event uuid 5f7819de-5656-4063-a76a-a39253ee5154, available on <a href="https://misppriv.circl.lu/events/view/278450">MISP for the private sector</a>.</p>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 26th February 2025</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-92 - Unused Domain Names and the Risks of Missing DNS SPF Records</title>
      <link>https://www.circl.lu/pub/tr-92/</link>
      <pubDate>Wed, 22 Jan 2025 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-92/</guid>
      <description>Executive Summary Many organizations maintain a broad portfolio of domain names, acquired for branding, strategic planning, or defensive purposes. However, a significant portion of these domains often remains unused or lacks proper DNS configurations, leaving them vulnerable to exploitation. One particularly critical oversight is the absence of DNS SPF (Sender Policy Framework) TXT records, which are essential to controlling the sources from which emails for a domain can be legitimately sent. This document highlights the risks associated with improperly configured domains and provides actionable recommendations to mitigate such vulnerabilities.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Many organizations maintain a broad portfolio of domain names, acquired for branding, strategic planning, or defensive purposes. However, a significant portion of these domains often remains unused or lacks proper DNS configurations, leaving them vulnerable to exploitation. One particularly critical oversight is the absence of DNS SPF (Sender Policy Framework) TXT records, which are essential to controlling the sources from which emails for a domain can be legitimately sent. This document highlights the risks associated with improperly configured domains and provides actionable recommendations to mitigate such vulnerabilities.</p>
<p>Unused domains can refer to domains registered by an organization but not actively used. They can also include domains that are utilized for other services, such as HTTP/web services, without the need to send emails.</p>
<h2 id="problem-statement">Problem Statement</h2>
<p>Attackers frequently exploit domains without SPF records or other DNS-based email authentication mechanisms. These misconfigured or dormant domains can become avenues for phishing, spamming, or distributing malware under the guise of legitimate organizational communication. Recipients, seeing a recognizable domain, may trust the malicious email, leading to financial losses, reputational damage, and compromised security for both the recipient and the originating organization.</p>
<h3 id="recent-examples">Recent Examples</h3>
<p>In recent incidents, attackers have exploited unused or poorly configured domains belonging to various organizations. Common scenarios include:</p>
<ol>
<li>Sending phishing emails that appear to originate from legitimate-looking email addresses tied to the organization.</li>
<li>Targeting partners, suppliers, or customers with malicious links or fraudulent invoices.</li>
<li>Compromising recipients’ systems by leveraging the trust associated with the recognizable domain name.</li>
</ol>
<p>These examples demonstrate the importance of ensuring that all domains in an organization’s portfolio are properly secured and configured, regardless of their current usage status.</p>
<h2 id="understanding-spf-records">Understanding SPF Records</h2>
<p>SPF records are a type of DNS TXT record that specifies which mail servers are authorized to send emails on behalf of a domain. For example, the following SPF record:</p>
<pre tabindex="0"><code>v=spf1 include:mail.example.com -all
</code></pre><ul>
<li><strong><code>v=spf1</code></strong>: Indicates the SPF version being used.</li>
<li><strong><code>include:mail.example.com</code></strong>: Specifies the authorized mail server(s).</li>
<li><strong><code>-all</code></strong>: Indicates that all other servers are unauthorized.</li>
</ul>
<p>If a domain lacks an SPF record, any mail server can claim to send emails on its behalf, making it susceptible to spoofing.</p>
<h2 id="recommendations">Recommendations</h2>
<p>To safeguard your organization’s domain portfolio and reduce the risk of abuse, follow these best practices:</p>
<ol>
<li>
<p><strong>Inventory All Domains</strong></p>
<ul>
<li>Maintain an updated inventory of all domains owned by the organization, including inactive and defensive registrations.</li>
</ul>
</li>
<li>
<p><strong>Implement SPF Records</strong></p>
<ul>
<li>Configure SPF records for all domains, even those not actively in use.</li>
<li>Example for a domain with no legitimate email traffic:
<pre tabindex="0"><code>v=spf1 -all
</code></pre>This record explicitly denies any mail servers from sending emails on behalf of the domain.</li>
</ul>
</li>
<li>
<p><strong>Extend Protections with DKIM and DMARC</strong></p>
<ul>
<li>Use <strong>DKIM (DomainKeys Identified Mail)</strong> to sign emails, ensuring their integrity.</li>
<li>Implement <strong>DMARC (Domain-based Message Authentication, Reporting, and Conformance)</strong> to provide instructions on handling authentication failures.
Example DMARC policy:
<pre tabindex="0"><code>v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com
</code></pre></li>
</ul>
</li>
<li>
<p><strong>Monitor DNS Configurations</strong></p>
<ul>
<li>Regularly audit DNS records for accuracy and completeness.</li>
<li>Utilize tools or managed services to detect and mitigate unauthorized use of domains.</li>
</ul>
</li>
<li>
<p><strong>Educate Stakeholders</strong></p>
<ul>
<li>Raise awareness among IT staff and decision-makers about the importance of securing all domains.</li>
<li>Include DNS management in your organization’s cybersecurity training and policies.</li>
</ul>
</li>
</ol>
<h2 id="references">References</h2>
<ul>
<li><strong>RFC 7208</strong>: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1. <a href="https://datatracker.ietf.org/doc/html/rfc7208">Available here</a></li>
<li><strong>RFC 6376</strong>: DomainKeys Identified Mail (DKIM) Signatures. <a href="https://datatracker.ietf.org/doc/html/rfc6376">Available here</a></li>
<li><strong>RFC 7489</strong>: Domain-based Message Authentication, Reporting, and Conformance (DMARC). <a href="https://datatracker.ietf.org/doc/html/rfc7489">Available here</a></li>
</ul>
<h2 id="conclusion">Conclusion</h2>
<p>Unused or misconfigured domains represent a significant security risk for organizations. By proactively managing your domain portfolio and implementing robust email authentication mechanisms like SPF, DKIM, and DMARC, you can prevent attackers from exploiting your domains and protect your organization’s reputation and stakeholders. Addressing these issues is not just a technical necessity but a critical component of responsible cybersecurity management.</p>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.1 - TLP:CLEAR - Updated version to clarify the meaning of unused domains - 23rd January 2025</li>
<li>Version 1.0 - TLP:CLEAR - First version - 21st January 2025</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-91 - Vulnerability identified as CVE-2024-0012, affecting Palo Alto Networks PAN-OS software</title>
      <link>https://www.circl.lu/pub/tr-91/</link>
      <pubDate>Fri, 20 Dec 2024 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-91/</guid>
      <description>An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges. This allows the attacker to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474.&amp;#xA;The risk is greatly reduced if access to the management web interface is restricted to trusted internal IP addresses, adhering to best practice deployment guidelines.&amp;#xA;</description>
      <content:encoded><![CDATA[<p>An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges. This allows the attacker to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like <a href="https://security.paloaltonetworks.com/CVE-2024-9474">CVE-2024-9474</a>.</p>
<p>The risk is greatly reduced if access to the management web interface is restricted to trusted internal IP addresses, adhering to <a href="https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431">best practice deployment guidelines</a>.</p>
<p>This issue impacts PAN-OS versions 10.2, 11.0, 11.1, and 11.2. Cloud NGFW and Prisma Access are not affected.</p>
<h2 id="impact">Impact</h2>
<ul>
<li><strong>CAPEC ID:</strong> CAPEC-115</li>
<li><strong>CAPEC Description:</strong> Authentication Bypass</li>
</ul>
<h2 id="exploitation">Exploitation</h2>
<p>Palo Alto Networks observed threat activity exploiting this vulnerability against exposed management web interfaces.</p>
<h3 id="problem-type">Problem Type</h3>
<ul>
<li><strong>CWE ID:</strong> CWE-306</li>
<li><strong>CWE Description:</strong> Missing Authentication for Critical Function</li>
</ul>
<h2 id="affected-systems">Affected Systems</h2>
<h3 id="palo-alto-networks-products">Palo Alto Networks Products</h3>
<ul>
<li><strong>Cloud NGFW:</strong> Not Affected, All versions unaffected.</li>
<li><strong>PAN-OS:</strong>
<ul>
<li><strong>Affected Versions:</strong></li>
<li>10.2.0 versions up to but not including 10.2.12-h2</li>
<li>11.0.0 versions up to but not including 11.0.6-h1</li>
<li>11.1.0 versions up to but not including 11.1.5-h1</li>
<li>11.2.0 versions up to but not including 11.2.4-h1</li>
<li><strong>Unaffected Versions:</strong> 10.1.0 and all versions that include the fix. (See solution section)</li>
</ul>
</li>
<li><strong>Prisma Access:</strong> Not Affected, All versions unaffected.</li>
</ul>
<h2 id="mitigation-and-solutions">Mitigation and Solutions</h2>
<h3 id="workarounds">Workarounds</h3>
<p>The primary mitigation is to restrict access to the management interface to only trusted internal IP addresses. Review these resources for more information:</p>
<ul>
<li>Palo Alto Networks LIVEcommunity article: <a href="https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431">https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431</a></li>
<li>Palo Alto Networks official documentation: <a href="https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices">https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices</a></li>
</ul>
<p>If you have a Threat Prevention subscription, you can block attacks using Threat IDs 95746, 95747, 95752, 95753, 95759, and 95763 (Applications and Threats content version 8915-9075 or later).</p>
<h3 id="solutions">Solutions</h3>
<p>The issue is fixed in:</p>
<ul>
<li>PAN-OS 10.2.12-h2</li>
<li>PAN-OS 11.0.6-h1</li>
<li>PAN-OS 11.1.5-h1</li>
<li>PAN-OS 11.2.4-h1</li>
<li>All later PAN-OS versions</li>
</ul>
<p>Additional fixes are available for other commonly deployed maintenance releases, including:</p>
<ul>
<li>PAN-OS 11.2: 11.2.0-h1, 11.2.1-h1, 11.2.2-h2, 11.2.3-h3</li>
<li>PAN-OS 11.1: 11.1.0-h4, 11.1.1-h2, 11.1.2-h15, 11.1.3-h11, 11.1.4-h7</li>
<li>PAN-OS 11.0: 11.0.0-h4, 11.0.1-h5, 11.0.2-h5, 11.0.3-h13, 11.0.4-h6, 11.0.5-h2</li>
<li>PAN-OS 10.2: 10.2.0-h4, 10.2.1-h3, 10.2.2-h6, 10.2.3-h14, 10.2.4-h32, 10.2.5-h9, 10.2.6-h6, 10.2.7-h18, 10.2.8-h15, 10.2.9-h16, 10.2.10-h9, 10.2.11-h6</li>
</ul>
<h2 id="cvss-metrics">CVSS Metrics</h2>
<h3 id="cvss-v40-highest-risk-scenario">CVSS v4.0 (Highest Risk Scenario)</h3>
<ul>
<li><strong>Vector String:</strong> CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Red</li>
<li><strong>Base Score:</strong> 9.3</li>
<li><strong>Base Severity:</strong> CRITICAL</li>
<li><strong>Scenario</strong>: The risk is highest when you allow access to the management interface from external IP addresses on the internet.</li>
</ul>
<h3 id="cvss-v40-restricted-access-scenario">CVSS v4.0 (Restricted Access Scenario)</h3>
<ul>
<li><strong>Vector String:</strong> CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Red</li>
<li><strong>Base Score:</strong> 5.9</li>
<li><strong>Base Severity:</strong> MEDIUM</li>
<li><strong>Scenario</strong>:  If you configure restricted access to a jump box that is the only system allowed to access the management interface, you greatly reduce the risk of exploitation because attacks would require privileged access using only those IP addresses.</li>
</ul>
<h2 id="credits">Credits</h2>
<ul>
<li>Palo Alto Networks thanks our Deep Product Security Research Team for discovering this issue internally from threat activity.</li>
</ul>
<h2 id="references">References</h2>
<ul>
<li><a href="https://vulnerability.circl.lu/vuln/cve-2024-0012">CVE-2024-0012</a> and <a href="https://vulnerability.circl.lu/vuln/cve-2024-9474">CVE-2024-9474</a></li>
<li><a href="https://vulnerability.circl.lu/bundle/d6006baf-209a-4a38-8a58-394ea67eab2a">Palo Alto - Privilege Escalation (PE) Vulnerability in the Web Management Interface versus : Authentication Bypass in the Management Web Interface</a></li>
<li><a href="https://security.paloaltonetworks.com/CVE-2024-0012">Palo Alto Networks Advisory</a></li>
<li><a href="https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/">WatchTowr Labs Analysis</a></li>
<li><a href="https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/">Unit 42 Analysis</a></li>
</ul>
<h2 id="timeline">Timeline</h2>
<ul>
<li><strong>2024-11-18T14:20:00.000Z:</strong> CVE-2024-0012 assigned, vulnerability identified and fixed.</li>
<li><strong>2024-11-15T22:00:00.000Z:</strong> FAQ about indicators of compromise answered.</li>
<li><strong>2024-11-14T22:18:00.000Z:</strong> Severity of PAN-SA-2024-0015 bulletin raised due to observed threat activity.</li>
<li><strong>2024-11-11T01:03:00.000Z:</strong> Added instructions to find devices with an internet-facing management interface discovered in scans.</li>
<li><strong>2024-11-08T13:00:00.000Z:</strong> Initially published as PAN-SA-2024-0015.</li>
</ul>
<h2 id="additional-information">Additional Information</h2>
<h3 id="configuration-notes">Configuration Notes</h3>
<p>The risk is highest if the management interface is configured to enable access from the internet or untrusted networks either:</p>
<ul>
<li>Directly or,</li>
<li>Through a data plane interface that includes a management interface profile</li>
</ul>
<p>The risk is greatly reduced by limiting access to the management interface to only trusted internal IP addresses.</p>
<p>Use the following steps to identify recently detected devices:</p>
<ol>
<li>Visit the Assets section of Customer Support Portal at <a href="https://support.paloaltonetworks.com">https://support.paloaltonetworks.com</a> (Products → Assets → All Assets → Remediation Required).</li>
<li>Devices with an internet-facing management interface discovered in scans are tagged with PAN-SA-2024-0015. A last seen timestamp is shown in UTC. If no such devices are listed, scans did not find any devices with an internet-facing management interface within the last three days.</li>
</ol>
<h3 id="cisa-adp-information">CISA ADP Information</h3>
<ul>
<li>
<p><strong>CISA Known Exploited Vulnerabilities (KEV):</strong></p>
<ul>
<li><strong>Date Added:</strong> 2024-11-18</li>
<li><strong>Reference:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2024-0012">https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2024-0012</a></li>
</ul>
</li>
<li>
<p><strong>SSVC Metrics</strong>:</p>
<ul>
<li><strong>Timestamp:</strong> 2024-11-19T04:55:47.202753Z</li>
<li><strong>ID:</strong> CVE-2024-0012</li>
<li><strong>Options:</strong> Exploitation: active, Automatable: yes, Technical Impact: total</li>
<li><strong>Role:</strong> CISA Coordinator</li>
<li><strong>Version:</strong> 2.0.3</li>
</ul>
</li>
</ul>
<h3 id="nvd-information">NVD Information</h3>
<ul>
<li>
<p><strong>NVD Description</strong>: An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like  CVE-2024-9474.
The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines.
This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.</p>
</li>
<li>
<p><strong>NVD CVSS v3.1 Metrics:</strong></p>
<ul>
<li><strong>Vector String:</strong> CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</li>
<li><strong>Base Score:</strong> 9.8</li>
<li><strong>Base Severity:</strong> CRITICAL</li>
</ul>
</li>
</ul>
<h3 id="linked-csaf-documents">Linked CSAF Documents</h3>
<ul>
<li><strong>CISA:</strong></li>
<li><a href="https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-02">ICSA-24-338-02</a> - Siemens RUGGEDCOM APE1808 devices</li>
<li><strong>NCSC-NL:</strong></li>
<li><a href="https://advisories.ncsc.nl/advisory?id=NCSC-2024-0451">ncsc-2024-0451</a> - Kwetsbaarheden verholpen in Palo Alto PAN-OS</li>
</ul>
<h3 id="github-advisory">GitHub Advisory</h3>
<ul>
<li><a href="https://github.com/advisories/GHSA-mw9x-2qwv-599p">GHSA-mw9x-2qwv-599p</a></li>
</ul>
<h3 id="vulnerability-lookup-bundles">Vulnerability Lookup Bundles</h3>
<ul>
<li><strong>Palo Alto - <a href="https://vulnerability.circl.lu/bundle/d6006baf-209a-4a38-8a58-394ea67eab2a">Privilege Escalation (PE) Vulnerability in the Web Management Interface versus : Authentication Bypass in the Management Web Interface</a></strong>
<ul>
<li>Description: This bundle highlights the relationship between CVE-2024-0012 and CVE-2024-9474. It notes they are often used in a chain to gain superuser access to PAN-OS systems</li>
<li>Related Vulnerabilities: CVE-2024-0012, CVE-2024-9474</li>
</ul>
</li>
</ul>
<h3 id="vulnerability-sightings">Vulnerability Sightings</h3>
<p>The <a href="https://vulnerability.circl.lu/bundle/d6006baf-209a-4a38-8a58-394ea67eab2a">vulnerability has been observed and discussed in various sources</a>, including:</p>
<ul>
<li>Infosec.exchange user posts (multiple)</li>
<li><a href="https://github.com/projectdiscovery/nuclei-templates/tree/main/http/cves/2024/CVE-2024-0012.yaml">Projectdiscovery Nuclei Template</a></li>
<li>MISP Instance (MISP/3c19819c-1dac-4ef2-bfed-be5efa7e0123)</li>
<li>Feedsin.space (<a href="https://feedsin.space/feed/CISAKevBot/items/2704493">https://feedsin.space/feed/CISAKevBot/items/2704493</a>)</li>
<li>Mastodon posts (multiple)</li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 20th December 2024</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-90 - Vulnerability identified as CVE-2023-34990, affecting Fortinet FortiWLM</title>
      <link>https://www.circl.lu/pub/tr-90/</link>
      <pubDate>Fri, 20 Dec 2024 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-90/</guid>
      <description>A relative path traversal vulnerability has been discovered in Fortinet FortiWLM versions 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4. This vulnerability allows an attacker to execute unauthorized code or commands by sending specially crafted web requests.&amp;#xA;Affected Products Vendor: Fortinet Product: FortiWLM Versions: 8.6.0 through 8.6.5 (inclusive) 8.5.0 through 8.5.4 (inclusive) Vulnerability Class CWE-23: Relative Path Traversal CWE-94: Improper Control of Generation of Code (‘Code Injection’) Impact Successful exploitation of this vulnerability could lead to the execution of arbitrary code or commands on the affected system.&amp;#xA;</description>
      <content:encoded><![CDATA[<p>A relative path traversal vulnerability has been discovered in Fortinet FortiWLM versions 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4. This vulnerability allows an attacker to execute unauthorized code or commands by sending specially crafted web requests.</p>
<h2 id="affected-products">Affected Products</h2>
<ul>
<li><strong>Vendor:</strong> Fortinet</li>
<li><strong>Product:</strong> FortiWLM</li>
<li><strong>Versions:</strong>
<ul>
<li>8.6.0 through 8.6.5 (inclusive)</li>
<li>8.5.0 through 8.5.4 (inclusive)</li>
</ul>
</li>
</ul>
<h2 id="vulnerability-class">Vulnerability Class</h2>
<ul>
<li><strong>CWE-23:</strong> Relative Path Traversal</li>
<li><strong>CWE-94:</strong> Improper Control of Generation of Code (&lsquo;Code Injection&rsquo;)</li>
</ul>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability could lead to the execution of arbitrary code or commands on the affected system.</p>
<h2 id="technical-analysis">Technical Analysis</h2>
<h3 id="attack-vector">Attack Vector</h3>
<ul>
<li><strong>Attack Vector:</strong> Network</li>
<li><strong>Attack Complexity:</strong> Low</li>
<li><strong>Privileges Required:</strong> None</li>
<li><strong>User Interaction:</strong> None</li>
<li><strong>Scope:</strong> Unchanged</li>
</ul>
<h3 id="cvss-metrics">CVSS Metrics</h3>
<h4 id="cna-cvss-score">CNA CVSS Score</h4>
<ul>
<li><strong>CVSS v3.1 Base Score:</strong> 9.6</li>
<li><strong>CVSS v3.1 Base Severity:</strong> CRITICAL</li>
<li><strong>Vector String:</strong> <code>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</code></li>
<li><strong>Attack Vector (AV):</strong> Network (N)</li>
<li><strong>Attack Complexity (AC):</strong> Low (L)</li>
<li><strong>Privileges Required (PR):</strong> None (N)</li>
<li><strong>User Interaction (UI):</strong> None (N)</li>
<li><strong>Scope (S):</strong> Unchanged (U)</li>
<li><strong>Confidentiality Impact (C):</strong> High (H)</li>
<li><strong>Integrity Impact (I):</strong> High (H)</li>
<li><strong>Availability Impact (A):</strong> High (H)</li>
</ul>
<h4 id="cisa-adp-cvss-score">CISA ADP CVSS Score</h4>
<ul>
<li><strong>CVSS v3.1 Base Score:</strong> 9.8</li>
<li><strong>CVSS v3.1 Base Severity:</strong> CRITICAL</li>
<li><strong>Vector String:</strong> <code>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</code></li>
<li><strong>Attack Vector (AV):</strong> Network (N)</li>
<li><strong>Attack Complexity (AC):</strong> Low (L)</li>
<li><strong>Privileges Required (PR):</strong> None (N)</li>
<li><strong>User Interaction (UI):</strong> None (N)</li>
<li><strong>Scope (S):</strong> Unchanged (U)</li>
<li><strong>Confidentiality Impact (C):</strong> High (H)</li>
<li><strong>Integrity Impact (I):</strong> High (H)</li>
<li><strong>Availability Impact (A):</strong> High (H)</li>
</ul>
<h3 id="cisa-adp-ssvc">CISA ADP SSVC</h3>
<ul>
<li><strong>SSVC Version:</strong> 2.0.3</li>
<li><strong>SSVC ID:</strong> CVE-2023-34990</li>
<li><strong>Timestamp:</strong> 2024-12-19T00:00:00+00:00</li>
<li><strong>Options:</strong>
<ul>
<li>Exploitation: None</li>
<li>Automatable: Yes</li>
<li>Technical Impact: Total</li>
<li><strong>Role:</strong> CISA Coordinator</li>
</ul>
</li>
</ul>
<h2 id="mitigation">Mitigation</h2>
<ul>
<li>Upgrade to FortiWLM version 8.6.6 or later.</li>
<li>Upgrade to FortiWLM version 8.5.5 or later.</li>
</ul>
<h2 id="references">References</h2>
<ul>
<li><a href="https://fortiguard.com/psirt/FG-IR-23-144">Fortiguard Advisory</a></li>
<li><a href="https://vulnerability.circl.lu/vuln/CVE-2023-34990">NIST NVD CVE Details</a></li>
<li><a href="https://vulnerability.circl.lu/vuln/ghsa-2pp3-2hr3-936m">GitHub Security Advisory</a></li>
<li><a href="https://vulnerability.circl.lu/vuln/GSD-2023-34990">GSD Vulnerability ID</a></li>
</ul>
<h2 id="additional-sightings">Additional Sightings</h2>
<h3 id="mastodon">Mastodon</h3>
<ul>
<li><a href="https://infosec.exchange/users/mttaggart/statuses/113676180752563416">https://infosec.exchange/users/mttaggart/statuses/113676180752563416</a></li>
<li><a href="https://infosec.exchange/users/cve/statuses/113673904010874634">https://infosec.exchange/users/cve/statuses/113673904010874634</a></li>
<li><a href="https://infosec.exchange/users/screaminggoat/statuses/113674791142313324">https://infosec.exchange/users/screaminggoat/statuses/113674791142313324</a></li>
<li><a href="https://infosec.exchange/users/screaminggoat/statuses/113674904259060282">https://infosec.exchange/users/screaminggoat/statuses/113674904259060282</a></li>
<li><a href="https://infosec.exchange/users/adulau/statuses/113674914309627637">https://infosec.exchange/users/adulau/statuses/113674914309627637</a></li>
<li><a href="https://infosec.exchange/users/screaminggoat/statuses/113674927052267535">https://infosec.exchange/users/screaminggoat/statuses/113674927052267535</a></li>
<li><a href="https://infosec.exchange/users/screaminggoat/statuses/113675208676939403">https://infosec.exchange/users/screaminggoat/statuses/113675208676939403</a></li>
<li><a href="https://cyberplace.social/users/GossiTheDog/statuses/113674232166302816">https://cyberplace.social/users/GossiTheDog/statuses/113674232166302816</a></li>
<li><a href="https://social.circl.lu/users/circl/statuses/113674370374104492">https://social.circl.lu/users/circl/statuses/113674370374104492</a></li>
<li><a href="https://infosec.exchange/users/edwardk/statuses/113679655471686245">https://infosec.exchange/users/edwardk/statuses/113679655471686245</a></li>
<li><a href="https://infosec.exchange/users/jbhall56/statuses/113679787983720927">https://infosec.exchange/users/jbhall56/statuses/113679787983720927</a></li>
</ul>
<h3 id="bluesky">Bluesky</h3>
<ul>
<li><a href="https://bsky.app/profile/nimblenerd.social/post/3ldnubko4bc2n">https://bsky.app/profile/nimblenerd.social/post/3ldnubko4bc2n</a></li>
<li><a href="https://bsky.app/profile/nimblenerd.social/post/3ldnuagu2lw2e">https://bsky.app/profile/nimblenerd.social/post/3ldnuagu2lw2e</a></li>
<li><a href="https://bsky.app/profile/nimblenerd.social/post/3ldnuh5j6z72k">https://bsky.app/profile/nimblenerd.social/post/3ldnuh5j6z72k</a></li>
<li><a href="https://bsky.app/profile/potato.software/post/3ldnuipavmq2c">https://bsky.app/profile/potato.software/post/3ldnuipavmq2c</a></li>
<li><a href="https://bsky.app/profile/hackingne.ws/post/3ldnwrxvui22v">https://bsky.app/profile/hackingne.ws/post/3ldnwrxvui22v</a></li>
<li><a href="https://bsky.app/profile/nimblenerd.social/post/3ldogmyckhc2e">https://bsky.app/profile/nimblenerd.social/post/3ldogmyckhc2e</a></li>
<li><a href="https://bsky.app/profile/bolhasec.com/post/3ldnrh54g5i2b">https://bsky.app/profile/bolhasec.com/post/3ldnrh54g5i2b</a></li>
<li><a href="https://bsky.app/profile/nihonmatsu.bsky.social/post/3ldnrwzdzps2b">https://bsky.app/profile/nihonmatsu.bsky.social/post/3ldnrwzdzps2b</a></li>
<li><a href="https://bsky.app/profile/nidouille.bsky.social/post/3ldnywp2izk2f">https://bsky.app/profile/nidouille.bsky.social/post/3ldnywp2izk2f</a></li>
<li><a href="https://bsky.app/profile/jbhall56.bsky.social/post/3ldnyyoiymc2g">https://bsky.app/profile/jbhall56.bsky.social/post/3ldnyyoiymc2g</a></li>
</ul>
<h3 id="news">News</h3>
<ul>
<li><a href="https://thehackernews.com/2024/12/fortinet-warns-of-critical-fortiwlm.html">https://thehackernews.com/2024/12/fortinet-warns-of-critical-fortiwlm.html</a></li>
<li><a href="https://www.darkreading.com/vulnerabilities-threats/fortinet-addresses-unpatched-critical-rce-vector">https://www.darkreading.com/vulnerabilities-threats/fortinet-addresses-unpatched-critical-rce-vector</a></li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 20th December 2024</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-89 - Guidelines for Notifying CSIRT/CERT of Red Teaming and Penetration Testing Exercises - Enhancing Detection and Coordination</title>
      <link>https://www.circl.lu/pub/tr-89/</link>
      <pubDate>Tue, 12 Nov 2024 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-89/</guid>
      <description>Objective This document outlines recommended practices for notifying Computer Security Incident Response Teams (CSIRT) and Computer Emergency Response Teams (CERT) when organizations plan to conduct red teaming, penetration testing, or other cybersecurity exercises. It highlights the importance of communication, coordination, and technical readiness to detect and differentiate simulated attacks from real threats.&amp;#xA;Who The guidelines are applicable to organizations (in Luxembourg or abroad) performing security exercises that involve simulated attacks on production or critical infrastructure, especially those that could trigger alerts in national or sectoral CSIRTs and CERTs.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="objective">Objective</h2>
<p>This document outlines recommended practices for notifying Computer Security Incident Response Teams (CSIRT) and Computer Emergency Response Teams (CERT) when organizations plan to conduct red teaming, penetration testing, or other cybersecurity exercises. It highlights the importance of communication, coordination, and technical readiness to detect and differentiate simulated attacks from real threats.</p>
<h2 id="who">Who</h2>
<p>The guidelines are applicable to organizations (in Luxembourg or abroad) performing security exercises that involve simulated attacks on production or critical infrastructure, especially those that could trigger alerts in national or sectoral CSIRTs and CERTs.</p>
<h2 id="why">Why</h2>
<ul>
<li>Reducing Misinterpretation: Why notifying CSIRTs/CERTs is essential to avoid misinterpreting simulated attacks as real threats, potentially disrupting incident response processes.</li>
<li>Enhancing Collaboration: The role of CSIRTs/CERTs in monitoring and threat intelligence and how advance notification strengthens collaboration but also improve existing detection mechanisms.</li>
</ul>
<h2 id="notification">Notification</h2>
<h3 id="what-to-notify">What to Notify</h3>
<ul>
<li>Scope and objectives of the exercise. We don&rsquo;t require a lot of details just a minimal description with the parties involved.</li>
<li>Timeframe (start and end) and schedule of testing activities in UTC.</li>
<li>Technical indicators and selectors to facilitate the detection by CIRCL.</li>
<li>A contact person or organisation if we have any question or specific issues during a potential detection.</li>
</ul>
<h3 id="when-to-notify">When to Notify</h3>
<ul>
<li>We recommend to notify us at least one week in advance before the scheduled testing activities start.</li>
</ul>
<h2 id="technical-recommendations">Technical Recommendations</h2>
<h3 id="indicators-and-selectors">Indicators and Selectors</h3>
<ul>
<li>Techniques for tagging or otherwise marking payloads and simulated malicious infrastructure to aid in detection.</li>
<li>It is recommended to assign a randomly generated unique tag (such as a SHA256 hex value or even YARA rule for detecting the payload) to be embedded in malicious payloads, scripts, or even in the headers of infrastructure components.</li>
<li>Classification such as <code>exercise:generic=&quot;red-teaming&quot;</code> in the <a href="https://www.misp-project.org/taxonomies.html#_exercise">exercise taxonomy</a> is recommended if a detection is shared after the timetrame period of the exercise. In case of detection in the wild, CIRCL will tag and share the information with reporting parties if it&rsquo;s publicly detected.</li>
</ul>
<h2 id="references">References</h2>
<ul>
<li><a href="https://csrc.nist.gov/pubs/sp/800/115/final">NIST SP 800-115 Technical Guide to Information Security Testing and Assessment</a></li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 12th November 2024</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-88 - Motivation, procedure and rationale for leaked credential notifications</title>
      <link>https://www.circl.lu/pub/tr-88/</link>
      <pubDate>Fri, 30 Aug 2024 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-88/</guid>
      <description>Motivation, Procedure, and Rationale for Leaked Credential Notifications Summary In today’s digital landscape, protecting user data is essential for every organization. When public data leaks expose customer credentials, it is critical to respond promptly to mitigate risks. This document outlines why CIRCL sends notifications about such leaks and explains the procedure we expect organizations to follow. The goal is to safeguard both the organization’s infrastructure and its customers, while ensuring compliance with legal requirements and maintaining trust.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="motivation-procedure-and-rationale-for-leaked-credential-notifications">Motivation, Procedure, and Rationale for Leaked Credential Notifications</h2>
<h3 id="summary">Summary</h3>
<p>In today’s digital landscape, protecting user data is essential for every organization.
When public data leaks expose customer credentials, it is critical to respond promptly to mitigate risks.
This document outlines why CIRCL sends notifications about such leaks and explains the procedure we expect organizations to follow.
The goal is to safeguard both the organization&rsquo;s infrastructure and its customers, while ensuring compliance with legal requirements and maintaining trust.</p>
<h3 id="motivation">Motivation</h3>
<p>We believe it is both necessary and beneficial for any organization to be informed about public data leaks involving their customers. The main objectives are:</p>
<ul>
<li>To protect the organization&rsquo;s sensitive information and assets.</li>
<li>To help safeguard the customer’s personal data and prevent further misuse.</li>
</ul>
<h3 id="procedure">Procedure</h3>
<p>When CIRCL receives information about leaked credentials affecting user accounts for services in Luxembourg, we are committed to promptly informing the impacted service owners.
Typically, we compile and share relevant information with the identified contact of the organization. <strong>This process relies heavily on the accuracy of WHOIS data, emphasizing the importance of keeping this information current.</strong></p>
<p>We expect the organization to take the following steps:</p>
<ul>
<li><strong>Reset the leaked passwords</strong> for the affected accounts.</li>
<li><strong>Inform their customers</strong> about the breach, advising them to reset passwords on other services where they may have used the same credentials.</li>
<li><strong>Investigate potential abuse</strong> of leaked accounts, for instance by analyzing login activity for unusual IP addresses or patterns.</li>
<li><strong>Notify the CNPD within 72 hours</strong> if there is evidence of unauthorized access to accounts, as required by GDPR. Such incidents are classified as data breaches and must be reported accordingly.</li>
<li><strong>Improve Authentication and Auditing</strong> if MFA (Multi-factor authentication) is available, we recommend to enable MFA for the users accessing the organization&rsquo;s infrastructure.</li>
</ul>
<h3 id="rationale">Rationale</h3>
<p>While we understand the operational and financial implications of handling security notifications, prioritizing data protection is essential for both the organization and its customers.
As the CERT for Luxembourg&rsquo;s private sector, operating under NIS regulations, our goal is to minimize the economic and reputational damage of security incidents while ensuring regulatory compliance.</p>
<p>Here are the key reasons why this approach is critical:</p>
<ul>
<li>
<p><strong>Legal Obligations:</strong> Organizations have a legal duty to protect customer data. Unauthorized access must be reported to the CNPD within the 72-hour window required by GDPR. Failing to do so can lead to significant legal penalties.</p>
</li>
<li>
<p><strong>Customer Trust:</strong> Customers are more likely to trust notifications from their service provider rather than from a third-party CERT. Direct communication from the organization can reassure users and prompt them to take action, such as resetting their passwords. Additionally, the organization can automate mass password resets and provide tailored guidance, further reducing risks to its infrastructure and customers.</p>
</li>
<li>
<p><strong>Direct Contact Limitations:</strong> In many cases, the leaks lack customers&rsquo; email addresses and contain only user names, limiting our ability to notify users directly. Organizations, however, have this access and can communicate with their customers more efficiently and effectively.</p>
</li>
<li>
<p><strong>Proactive Security:</strong> Organizations should take immediate actions such as resetting passwords, notifying users, and conducting forensic investigations into potential breaches. Early and decisive action helps identify compromised accounts and limits further exposure, improving overall security posture. Incorporating these steps into regular risk assessments and technical controls is a proactive way to ensure readiness for potential incidents.</p>
</li>
</ul>
<p>In conclusion, we believe that involving organizations in the communication process with their customers is the most effective strategy. This ensures compliance with legal obligations, maintains customer trust, and allows for a more comprehensive investigation of potential risks to the organization’s infrastructure.</p>
<h2 id="references">References</h2>
<ul>
<li><a href="/pub/tr-46/">TR-46 - Information Leaks Affecting Luxembourg and Recommendations</a></li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 29th August 2024</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>Learning from the Recent Windows/Falcon Sensor Outage - Causes and Potential Improvement Strategies in Linux with Open Source</title>
      <link>https://www.circl.lu/pub/learning-from-falcon-sensor-outage/</link>
      <pubDate>Tue, 23 Jul 2024 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/learning-from-falcon-sensor-outage/</guid>
      <description>Learning from the Recent Windows/Falcon Sensor Outage: Causes and Potential Improvement Strategies in Linux Using Open Source Solutions At the time of writing, most people have probably heard about the massive Windows outage caused by a faulty kernel driver in Falcon Sensor, a CrowdStrike software. On Friday, July 19, 2024, a software configuration update designed to target newly observed malicious artifacts used in cyberattacks prevented several million Windows machines to boot. How can a configuration file crash an OS? Because the real issue is not the configuration file itself, but the kernel driver using it. Let’s take a quick, non-technical tour of the potential reasons behind this situation, how it is addressed in the Linux kernel, and what you as users or customers can do to avoid such issues.&amp;#xA;</description>
      <content:encoded><![CDATA[<h2 id="learning-from-the-recent-windowsfalcon-sensor-outage-causes-and-potential-improvement-strategies-in-linux-using-open-source-solutions">Learning from the Recent Windows/Falcon Sensor Outage: Causes and Potential Improvement Strategies in Linux Using Open Source Solutions</h2>
<p>At the time of writing, most people have probably heard about the massive <a href="/pub/tr-87/">Windows outage caused by a faulty kernel driver in <strong>Falcon Sensor</strong></a>, a CrowdStrike software. On <strong>Friday, July 19, 2024</strong>, a software configuration update designed to target newly observed malicious artifacts used in cyberattacks prevented several million Windows machines to boot. How can a configuration file crash an OS? Because the real issue is not the configuration file itself, but the kernel driver using it. Let&rsquo;s take a quick, non-technical tour of the potential reasons behind this situation, how it is addressed in the Linux kernel, and what you <strong>as users or customers</strong> can do to avoid such issues.</p>
<h2 id="developing-kernel-drivers-is-hard">Developing Kernel Drivers is Hard</h2>
<p>Kernel drivers allow code to be executed at the kernel level without modifying the kernel itself. This method is used by several software developers for the purposes of low level interactions, such as connecting to specific hardware, firewalling, and security monitoring. Bugs in these drivers are often critical, as they may be exploited by attackers or lead to a denial of service of the operating system.</p>
<p>Creating flawless code is a significant challenge for any developer. Most drivers are still developed in <strong>C</strong> or <strong>C++</strong>, which are powerful but complex and <strong>not inherently memory-safe</strong> languages. Moreover, achieving full code coverage through thorough testing of kernel drivers can be difficult due to the complexity of tracing a running kernel. These challenges, along with other factors such as dealing with undocumented kernel structures, closed-source kernels, and legacy code, can unfortunately lead to bugs and security vulnerabilities.</p>
<p>While we respect third-party companies, some may have less rigorous code review and development processes compared to OS kernel developers. This is a common issue in the software industry, where the focus may sometimes be on rapid feature development rather than code quality or stability. Consequently, as long as third-party companies continue to rely on kernel drivers, the risk of kernel panic (<em>A kernel panic is a safety measure in an operating system, triggered by a critical error from which it cannot safely recover, causing the system to halt or restart</em>) is likely to be higher compared to the risk from the OS kernel itself. Robust testing and advanced development practices are essential to mitigate these risks, but completely eliminating such errors remains a challenging task.</p>
<h2 id="can-this-happen-to-linux">Can This Happen to Linux?</h2>
<p>Kernel panics <strong>can occur on any operating system</strong>. However, the Linux kernel has been moving away from relying on third party kernel drivers. How is this being achieved? The answer is <strong>eBPF</strong> (Extended Berkeley Packet Filter). This technology enables code to run within the Linux kernel without the need to modify kernel source code or load kernel modules. A full explanation of how eBPF works is beyond the scope of this post; if you&rsquo;re interested in learning more, please refer to the <a href="#ebpf">references section</a>.</p>
<p>The power of eBPF lies in the fact that the code executed is not machine code but bytecode, which is interpreted by a virtual machine running in the kernel. Before execution, the bytecode is subjected to <a href="https://www.kernel.org/doc/html/latest/bpf/verifier.html">a code verifier</a> that checks for any potential programming mistakes that could impact kernel functionality. Since every eBPF program has a maximum number of instructions it can execute (no endless loops are possible), the verifier can check <strong>every single</strong> instruction. If <strong>the verifier</strong> detects issues, it will reject the bytecode, preventing it from being loaded into the kernel. This mechanism aims to ensure that <strong>faulty code never reaches the kernel</strong>, so the only component that may fail is your userland application trying to load eBPF code—a clever way to avoid kernel panics, don&rsquo;t you think?</p>
<p>Of course, no software is entirely free from bugs, and eBPF sub-system is no exception. While it is true that bugs can occur, the current design and verification process make the likelihood of eBPF bytecode causing a kernel panic <strong>extremely low</strong>.</p>
<h2 id="why-not-ebpf-on-windows">Why Not eBPF on Windows?</h2>
<p><strong>Microsoft</strong> is currently working on bringing eBPF to <strong>Windows</strong>, and you can track their progress in the <a href="https://github.com/microsoft/ebpf-for-windows">ebpf-for-windows repository</a>. However, it&rsquo;s important to note that it is still far from offering the same functionality as eBPF on Linux. This limitation restricts its use to specific networking tasks, leaving out critical areas such as performance monitoring and security tracing. For security vendors, these capabilities are essential for building robust and feature-rich products. As a result, they are likely to continue using traditional kernel drivers until eBPF for Windows meets all their requirements.</p>
<h2 id="what-do-we-do-at-circl">What Do We Do at CIRCL?</h2>
<p>At <strong>CIRCL</strong>, we are strong advocates of open source. Consequently, we are investing time and resources to provide <strong>an open-source alternative to monitoring products</strong> for Linux. Introducing <a href="https://github.com/kunai-project/kunai">Kunai</a>, a security monitoring tool for Linux written in <strong>Rust</strong> and powered by <strong>eBPF</strong>.</p>
<p>Inspired by <a href="https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon">Sysmon for Windows</a>, we developed this project to offer a similar experience for <strong>Linux</strong> users. Like its Windows counterpart, <strong>Kunai</strong> monitors various system events, including binary and script execution, shared objects being loaded, network connections, and <a href="https://why.kunai.rocks/docs/category/kunai---events">many other events</a> that can be used to build robust <strong>threat detection and hunting</strong> scenarios. It also tracks security events generated by any Linux container technology, allowing users to monitor activities within their containers. Additionally, it features a <a href="https://why.kunai.rocks/docs/advanced/rule_configuration">rule engine</a> for creating powerful detection and log filtering primitives. Furthermore, it can be integrated with any <strong>Threat Intelligence Provider</strong>, enabling <strong>real-time, IoC (<a href="https://why.kunai.rocks/docs/advanced/ioc_configuration">Indicators of Compromise</a>) based scanning</strong> .</p>
<p>Although <strong>Kunai</strong> is primarily designed for <strong>threat detection and hunting</strong>, it can also be a valuable ally for <strong>forensic analysis</strong> on Linux systems. Its logs provide detailed insights into the <strong>full activity</strong> of a given process, which is crucial for understanding what happened on a system.</p>
<p>If you have any <strong>security monitoring</strong> needs for your Linux hosts, consider giving <a href="https://github.com/kunai-project/kunai">Kunai</a> a try. Don’t hesitate to open issues on GitHub or reach out to us if you encounter problems or want to contribute to its improvement.</p>
<h2 id="what-you-can-do-as-a-customer">What You Can Do as a Customer?</h2>
<p>As a customer, <strong>you have the power to choose</strong> the best solutions and should thoroughly understand and review the technologies you use. Failing to do so can lead to <strong>vulnerabilities</strong> (including potential outages) in your infrastructure, making you partly responsible for any issues that arise. It is essential to have <strong>a robust</strong> technology and product evaluation process. If you find a vendor or technology that meets most of your requirements but falls short in some areas, request a roadmap to address these gaps and ensure your needs are fully met. As a general rule, <strong>running third-party kernel drivers should be avoided</strong> when viable alternatives are available.</p>
<p>If <strong>any product</strong> requires kernel drivers, a good evaluation metric is to check whether these drivers are implemented in a <strong>memory-safe language</strong> such as <strong>safe Rust</strong>. In addition to its memory safety capabilities, <strong>safe Rust</strong> enforces a number of good programming practices by design and provides strong guarantees about the code. This ultimately improves the overall quality of critical code running inside the kernel. Even though Rust is very attractive for kernel level applications, it will likely be necessary to use <strong>unsafe Rust</strong> (similar to C/C++), but its use should be minimized to the strictest extent possible. It is worth noting that while kernel code implemented in <strong>Rust</strong> will not prevent kernel panics, it will provide <strong>most</strong> of the <strong>Rust</strong> guarantees and inherently reduce the risk.</p>
<h2 id="conclusions">Conclusions</h2>
<p>Kernel panics have existed for ages and will continue to occur. However, operating system developers take this issue very seriously. While alternatives to relying on traditional C or C++ written kernel modules exist, such as using a <strong>safer</strong> programming language or another technology like eBPF, some software providers may prefer the conventional approach, likely because developing something from scratch using a completely different method can be too costly. In such cases, remember that <strong>as a user or customer</strong>, it is your responsibility to push for improvements or opt out of such practices if you do not agree with them.</p>
<h2 id="references">References</h2>
<ul>
<li><a href="/pub/tr-87/">CIRCL Technical Report</a></li>
<li><a href="https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/">CrowdStrike Windows Outage</a></li>
<li><a href="https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/">CrowdStrike Linux Kernel Crash</a></li>
</ul>
<h2 id="ebpf">eBPF</h2>
<ul>
<li><a href="https://ebpf.io/what-is-ebpf/">What is eBPF</a></li>
<li><a href="https://en.wikipedia.org/wiki/EBPF">Wikipedia: eBPF</a></li>
<li><a href="https://www.kernel.org/doc/html/latest/bpf/index.html">BPF kernel documentation</a></li>
<li><a href="https://www.kernel.org/doc/html/latest/bpf/verifier.html">eBPF verifier</a></li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 22nd July 2024</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>TR-87 - CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor</title>
      <link>https://www.circl.lu/pub/tr-87/</link>
      <pubDate>Fri, 19 Jul 2024 00:00:00 &#43;0000</pubDate>
      <guid isPermaLink="true">https://www.circl.lu/pub/tr-87/</guid>
      <description>CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor.&amp;#xA;Vulnerable Version And Products Latest version of CrowdStrike Falcon Agent on Windows Fixes and workaround Boot Windows into Safe Mode or the Windows Recovery Environment Navigate to the C:\Windows\System32\drivers\CrowdStrike directory Locate the file matching C-00000291*.sys, and delete it. Boot the host normally. We received reports that only the Windows Recovery Environment mode works, as the driver still seems to be loaded in safe mode.&amp;#xA;</description>
      <content:encoded><![CDATA[<p>CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor.</p>
<h2 id="vulnerable-version-and-products">Vulnerable Version And Products</h2>
<ul>
<li>Latest version of CrowdStrike Falcon Agent on Windows</li>
</ul>
<h2 id="fixes-and-workaround">Fixes and workaround</h2>
<ul>
<li>Boot Windows into Safe Mode or the Windows Recovery Environment</li>
<li>Navigate to the C:\Windows\System32\drivers\CrowdStrike directory</li>
<li>Locate the file matching <code>C-00000291*.sys</code>, and delete it.</li>
<li>Boot the host normally.</li>
</ul>
<p>We received reports that only the Windows Recovery Environment mode works, as the driver still seems to be loaded in safe mode.</p>
<h2 id="detection-and-investigative-assessment-before-the-latest-patchrelease-from-crowdstrike">Detection and investigative assessment (before the latest patch/release from CrowdStrike)</h2>
<ul>
<li>Windows system stuck in a boot loop. There is a blue screen where the mention is &ldquo;What failed: csagent.sys&rdquo;.</li>
</ul>
<p>The &ldquo;buggy&rdquo; driver has the following hashes:</p>
<ul>
<li>
<p>MD5 - 1618cd13c5263720ec958c3b24b9d1c8</p>
</li>
<li>
<p>SHA-1 - cb8a27c7347d19bc0b23093a99816dfd8240dbc5</p>
</li>
<li>
<p>SHA-256 - ad492bc8b884f9c9a5ce0c96087e722a2732cdb31612e092cdbf4a9555b44362</p>
</li>
<li>
<p>SSDEEP - 384:bIy44Wo45c59r/qQqu1QhSn88MyU64guxkP5O84VLv8xB0+Cn:9495c59rSQBG8CJxfexBl0</p>
</li>
<li>
<p>TLSH - T1EF03B83AFA108F99D071C0F7D9370B9EB394AD9C2B8257A37A5DBB3D48B55180DC046A</p>
</li>
<li>
<p><a href="https://www.virustotal.com/gui/file/ad492bc8b884f9c9a5ce0c96087e722a2732cdb31612e092cdbf4a9555b44362/detection">Virustotal reference</a></p>
</li>
<li>
<p><a href="https://www.circl.lu/doc/misp/feed-osint/10a54888-bba3-4af5-bc5b-fcda933ac0e2.json">MISP event with the &ldquo;buggy&rdquo; file</a> available in the MISP OSINT feed</p>
</li>
</ul>
<h2 id="crowdstrike-themed-malwarephishing-campaigns">CrowdStrike-themed malware/phishing campaigns</h2>
<p>There are ongoing CrowdStrike-themed malware/phishing campaigns such as <a href="https://www.virustotal.com/gui/file/96dec6e07229201a02f538310815c695cf6147c548ff1c6a0def2fe38f3dcbc8">this malware sample using fake updates.</a>.</p>
<h2 id="known-affected-software-in-luxembourg">Known affected software in Luxembourg</h2>
<ul>
<li>Impact currently unknown in Luxembourg but impact seen at least in US, Australia and India.</li>
</ul>
<h2 id="references">References</h2>
<ul>
<li>CrowdStrike <a href="https://supportportal.crowdstrike.com/s/article/Tech-Alert-Windows-crashes-related-to-Falcon-Sensor-2024-07-19">Falcon Sensor Windows Crashes</a></li>
<li>CrowdStrike <a href="https://www.crowdstrike.com/blog/technical-details-on-todays-outage/">Technical Details on Today’s Outage</a></li>
<li>CIRCL <a href="/pub/learning-from-falcon-sensor-outage/">Learning from the Recent Windows/Falcon Sensor Outage - Causes and Potential Improvement Strategies in Linux with Open Source</a></li>
</ul>
<h2 id="classification-of-this-document">Classification of this document</h2>
<p><a href="/pub/traffic-light-protocol/">TLP:CLEAR</a> information may be distributed without restriction, subject to copyright controls.</p>
<h2 id="revision">Revision</h2>
<ul>
<li>Version 1.0 - TLP:CLEAR - First version - 19th July 2024</li>
<li>Version 1.1 - TLP:CLEAR - Recovery versus safe mode from users + clarification of the BSOD - 19th July 2024</li>
<li>Version 1.2 - TLP:CLEAR - IOC of the buggy driver added + MISP reference - 19th July 2024</li>
<li>Version 1.3 - TLP:CLEAR - Updated TR after the CrowdStrike updates - 20th July 2024</li>
<li>Version 1.4 - TLP:CLEAR - CrowdStrike-themed malware/phishing campaigns - 21st July 2024</li>
<li>Version 1.5 - TLP:CLEAR - Learning from the recent outage reference added - 23rd July 2024</li>
</ul>
]]></content:encoded>
    </item>
  </channel>
</rss>
