JSAC2026 -Day 1-
ID: ca975494-7641-5cdd-86df-6537e5a6d3f5
STIX ID: report--ca975494-7641-5cdd-86df-6537e5a6d3f5
Feed Name: JPCERT Blog
This JSAC2026 Day 1 highlights briefing summarizes multiple active threats and incident analyses presented by researchers: a supply-chain-style compromise via DNS poisoning redirecting legitimate app updates; gateway/edge device surveillance frameworks; campaigns attributed to Chinese-linked groups (Earth Lusca/Krahang, Tianwu), North Korea-linked Konni with GSRAT, and Earth Kurma; large-scale exploitation of Ivanti Connect Secure devices with SPAWN/TextDoor and credential theft; and infrastructure-less C2 techniques abusing Microsoft Graph API, cloud services, and dead-drop resolvers. Presentations emphasize detection-evasion methods, use of legitimate services for C2 and exfiltration, investigative challenges on edge devices, and recommended mitigations including encrypted DNS, endpoint monitoring, cloud API traffic inspection, and sharing YARA/Sigma rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
