logo

JSAC2026 -Day 1-

ID: ca975494-7641-5cdd-86df-6537e5a6d3f5

STIX ID: report--ca975494-7641-5cdd-86df-6537e5a6d3f5

Feed Name: JPCERT Blog

Threat Score
78/100

Date Published: 2026-02-20

Date Updated: 2026-04-19

Author: 亀井 智矢(Tomoya Kamei)

...
...

This JSAC2026 Day 1 highlights briefing summarizes multiple active threats and incident analyses presented by researchers: a supply-chain-style compromise via DNS poisoning redirecting legitimate app updates; gateway/edge device surveillance frameworks; campaigns attributed to Chinese-linked groups (Earth Lusca/Krahang, Tianwu), North Korea-linked Konni with GSRAT, and Earth Kurma; large-scale exploitation of Ivanti Connect Secure devices with SPAWN/TextDoor and credential theft; and infrastructure-less C2 techniques abusing Microsoft Graph API, cloud services, and dead-drop resolvers. Presentations emphasize detection-evasion methods, use of legitimate services for C2 and exfiltration, investigative challenges on edge devices, and recommended mitigations including encrypted DNS, endpoint monitoring, cloud API traffic inspection, and sharing YARA/Sigma rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.