标签:#news
找到 9223 篇相关文章
Microsoft Disclosure Provides Rare Glimpse of Tax Haven Tactics
South Korea's SK Hynix launches $28B US listing to ride global AI wave
Tell HN: I managed to unsubscribe from Adobe CC without being charged
I had an educational Adobe CC subscription that went from ~£25 per month to ~£67 recently. When I went to cancel after I realised I didn't really use it that much and could just use Affinity, I was shocked to find out that I was going to be charged ~£250 because although I pay monthly I was in a yearly contract. (I did know that, which is on me, but it's easy to forget that because of the payment structure). It's a serious barrier, so I looked at the other options, and you're able to transfer to
OfficeCLI: Office suite for AI agents to read and edit Microsoft Office files
Florida Hospitals Act Fast to Discharge Gun Victims Especially If Not Insured
Ask HN: Are systems ready for the first negative leap second?
It’s been 10 years since we had the last leap second and it looks like we will get the first negative one soonish. Are systems ready for that?
Wisk, Boeing Sued over eVTOL Software Safety Claims
Former Xbox studios Double Fine and Compulsion will keep games after going indie
Microsoft is spinning off four of its Xbox game studios - Compulsion Games, Double Fine Productions, Ninja Theory, and Undead Labs - as part of the restructuring announced today. However, two that are going independent, Double Fine and Compulsion, will get to keep their franchises and games catalogs, according to Xbox CEO Asha Sharma. "Compulsion […]
Orasort: 5x faster column-sorting with an expired patent from Oracle
Alleged Operators of HiAnime Piracy Ring Arrested in Vietnam with U.S. Support
Show HN: Pulpie – Models for Cleaning the Web
Hey HN, I'm Shreyash, founder of Feyn. We built Pulpie, a family of Pareto optimal models for cleaning the web. Pulpie strips boilerplate (ads, footers, sidebars) from raw HTML and returns just the main content as HTML or Markdown. We match SOTA extraction quality while being 20x cheaper. Cleaning 1 billion webpages costs $7,900 with Pulpie versus $159,000 with Dripper, the current leading extractor. The gains come from architecture. Today's leading extractors are decoders that generate output o
Union Busters Coming After Me
Operation DragonReturn: DcRAT Deployment via Fake ITR Utilities
Originally published on satyamrastogi.com Seqrite Labs identifies multi-stage DcRAT campaign impersonating India's Income Tax Department. Attackers exploit tax professional workflows to deliver remote access trojans capable of data exfiltration and lateral movement. Operation DragonReturn: DcRAT Deployment via Fake ITR Utilities Executive Summary A China-nexus threat cluster is actively exploiting the predictable workflows of Indian tax professionals, corporate finance teams, and individual taxpayers through phishing campaigns distributing DcRAT (Dark Crystal Remote Access Trojan). Operation DragonReturn, as tracked by Seqrite Labs, demonstrates sophisticated understanding of Indian taxation cycles and organizational structures - critical operational intelligence required for high-success-rate social engineering. From an attacker's perspective, this campaign is methodologically sound: it targets a specific, predictable event (tax filing deadlines), uses trusted entity impersonation (Income Tax Department), and deploys a mature RAT with established evasion capabilities. The selection of DcRAT indicates access to commodity malware-as-a-service (MaaS) infrastructure, likely from Chinese underground forums where such tools are actively monetized and continuously updated. Attack Vector Analysis This operation chains multiple MITRE ATT&CK techniques into a cohesive infection chain: Initial Compromise: Spear-Phishing with Pretexting Attackers execute T1566.002 (Phishing - Spearphishing Attachment) by crafting emails impersonating legitimate Indian Income Tax Department communications. The social engineering layer leverages T1598.003 (Phishing - Spearphishing Link) with URLs pointing to malicious tax filing utilities. Pretexting is enhanced through T1589.001 (Gather Victim Identity Information - Credentials) , as attackers likely harvested tax professional contact lists from public records, LinkedIn OSINT, or previous data breaches. The timing of campaigns around Indian fis