Pretnje
9 direktnih pogodaka-
№ 043
Authentication Bypass An authentication bypass means the attacker reaches a protected part of the system without logging in the ordinary way. They need not know a password. Sometimes …pretnja · applications
-
№ 034
QR phishing - Quishing Quishing is phishing through a QR code. Instead of a visible link, the user is given an image to scan with their phone. The QR code then takes them to a fake page for a login, a payment, a document download or an account confirmation.pretnja · social eng.
-
№ 025
SIM Swapping SIM swapping does not attack the phone but the phone number. The attacker persuades, or bribes, a mobile operator to move the number to a new SIM card, citing a lost phone or a damaged card. They usually come armed with personal details from leaked databases and phishing. The moment the number moves to their card, the real phone loses signal and every call and message goes to the attacker.pretnja · identity
-
№ 021
Account Takeover … r, with the caveat that weaker forms of it can be bypassed, so stronger ones are worth considering: phishing-resistant models and hardware keys. Alongside that, …pretnja · identity
-
№ 035
Deepfake Attack … ntity. Video is not enough either, if the request bypasses the procedure.pretnja · social eng.
-
№ 012
Infostealer … a bigger prize than a password, because using it bypasses MFA.pretnja · malware
-
№ 046
Insecure Deserialization … ses it can change a user's role, crash a service, bypass the application's logic, or open access to data that was never meant to be reachable.pretnja · applications
-
№ 047
Path Traversal … characters. Paths can be encoded, normalized and bypassed in several ways if the application has no clearly bounded permissions.pretnja · applications
-
№ 039
SQL Injection … ly reads data they should not see. Sometimes they bypass the login, change the contents of the database or delete records. And if the account the application us …pretnja · applications
Tehnike
11 direktnih pogodaka-
№ 020
Access Token Manipulation This technique bypasses conventional authentication because tokens represent an already verified identity. It is especially dangerous in single sign-on environm …tehnika · privileges
-
№ 009
AiTM … ls out MFA and considers the account solved; AiTM bypasses exactly that assumption.tehnika · initial access
-
№ 016
DLL Sideloading Used by APT groups to bypass application whitelisting controls.tehnika · execution
-
№ 036
DNS Tunneling It bypasses firewalls because DNS traffic rarely undergoes deep inspection.tehnika · exfiltration / impact
-
№ 040
Domain Fronting Signal used domain fronting to bypass censorshiptehnika · C2
-
№ 010
Exploitation … or configuration to execute unauthorized code or bypass security controls. Vulnerabilities can exist in operating systems, applications, network services, or f …tehnika · execution
-
№ 014
In-Memory Execution Bypasses antivirus scanners that check files on disk.tehnika · execution
-
№ 038
Malware Delivery Attackers use various concealment techniques to bypass security controls, including packing, payload encryption, and using legitimate services for storage and d …tehnika · C2
-
№ 013
Payload Obfuscation Multi-layer packing of malware to bypass antivirus signaturestehnika · execution
-
№ 008
Physical Access Can bypass all software security measures if the disk is not encrypted.tehnika · initial access
-
№ 045
Process Injection Bypasses application whitelisting and process controls.tehnika · evasion
Odbrane
4 direktna pogotka-
№ 034
DLP … hat's sensitive either blocks everything and gets bypassed, or blocks nothing. First the data map, then the rules.odbrana · resilience
-
№ 003
EDR … tion, investigation, and response to threats that bypassed preventive controls.odbrana · endpoints
-
№ 008
Multi-Factor Authentication Multi-factor authentication requires two or more independent proofs of identity at login. It typically combines something the user knows (password), something they possess (phone, hardware key), and something they are (biometrics).odbrana · identity / access
-
№ 038
Phishing Simulations Regular testing of employees with simulated phishing messages.odbrana · people