Seedworm ha trasformato software firmato e affidabile nel percorso di consegna, quindi la consueta assunzione che i vendor o i security binaries siano sicuri qui non vale. Un eseguibile legittimo che avvia una DLL malevola e una PowerShell successiva può sembrare normale attività software, il che rende facili da mancare le regole basate solo su hash e sui unsigned-binary.
Part of the PlainSec briefing for 2026-05-14
Every edition of this story: Le Signed Security Binaries Sono Diventate il Percorso Stealth di Seedworm