<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[CyberThreat Report: Security awareness]]></title><description><![CDATA[Naprakész információkat, gyakorlati tippeket és szakértői tanácsokat kaphatsz, amelyek segítenek megóvni személyes adataidat és vállalkozásodat a digitális fenyegetésektől.]]></description><link>https://www.cyberthreat.report/s/cyber-security-awareness</link><image><url>https://substackcdn.com/image/fetch/$s_!Lmtw!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50383b70-eecb-4f1b-8260-d05e48d1dbc9_256x256.png</url><title>CyberThreat Report: Security awareness</title><link>https://www.cyberthreat.report/s/cyber-security-awareness</link></image><generator>Substack</generator><lastBuildDate>Thu, 30 Apr 2026 20:33:47 GMT</lastBuildDate><atom:link href="https://www.cyberthreat.report/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[CyEx Kft.]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[ferencfresz@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[ferencfresz@substack.com]]></itunes:email><itunes:name><![CDATA[Ferenc Frész]]></itunes:name></itunes:owner><itunes:author><![CDATA[Ferenc Frész]]></itunes:author><googleplay:owner><![CDATA[ferencfresz@substack.com]]></googleplay:owner><googleplay:email><![CDATA[ferencfresz@substack.com]]></googleplay:email><googleplay:author><![CDATA[Ferenc Frész]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[A „Zelenszkij embere” videó technikai és tartalmi elemzése]]></title><description><![CDATA[&#201;rzelmi mozg&#243;s&#237;t&#225;s &#233;s kamp&#225;ny-manipul&#225;ci&#243;]]></description><link>https://www.cyberthreat.report/p/a-zelenszkij-embere-video-technikai</link><guid isPermaLink="false">https://www.cyberthreat.report/p/a-zelenszkij-embere-video-technikai</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Thu, 12 Mar 2026 07:17:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!iI01!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iI01!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iI01!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!iI01!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!iI01!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!iI01!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iI01!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2954970,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/190698263?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iI01!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!iI01!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!iI01!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!iI01!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F84303ef6-be01-4617-a882-731943cea9fc_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Ferenc Fr&#233;sz.</figcaption></figure></div><p>Ez az &#246;sszefoglal&#243; a digit&#225;lis elemz&#233;s legfontosabb meg&#225;llap&#237;t&#225;sait tartalmazza a &#8222;Zelenszkij embere&#8221; c&#237;men terjed&#337;, 2026. m&#225;rciusi vide&#243;val kapcsolatban.</p><p><strong>Vizsg&#225;lt vide&#243;k:</strong> A 2026-os B&#233;kemenetre h&#237;v&#243;, narr&#225;torral &#233;s feliratokkal ell&#225;tott klip &#233;s a <em>Pryamyi TV</em> (ukr&#225;n ellenz&#233;ki csatorna), 2026. m&#225;rcius 9-i interj&#250; felv&#233;tel.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberthreat.report/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">CyberThreat Report is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><ul><li><p><strong>Hamis identit&#225;s:</strong> A klip &#225;ll&#237;t&#225;s&#225;val ellent&#233;tben az interj&#250;alany (Hrihorij Omelcsenko) <strong>nem az ukr&#225;n korm&#225;ny k&#233;pvisel&#337;je</strong>, hanem egy radik&#225;lis ellenz&#233;ki figura, aki az eredeti felv&#233;telen &#233;lesen b&#237;r&#225;lja Zelenszkij eln&#246;k&#246;t.</p></li><li><p><strong>Cheapfake technol&#243;gia:</strong> A klip nem mesters&#233;gesen gener&#225;lt teljes deepfake, hanem a val&#243;di, 60 perces interj&#250;b&#243;l <strong>sz&#225;nd&#233;kosan &#246;sszeoll&#243;zott</strong> (stitching) manipul&#225;ci&#243;. A k&#233;sz&#237;t&#337;k egym&#225;st&#243;l t&#246;bb percre elhangzott mondatokat v&#225;gtak egym&#225;s mell&#233;.</p></li><li><p><strong>Sz&#225;nd&#233;kos vizu&#225;lis zaj:</strong> A vide&#243; ugr&#225;l&#243; k&#233;pe &#233;s rossz min&#337;s&#233;ge nem technikai hiba, hanem <strong>strat&#233;giai &#225;lca</strong>. A laggol&#225;s seg&#237;t elrejteni a durva v&#225;g&#225;si pontokat &#233;s a mesters&#233;gesen illesztett sz&#225;jmozg&#225;st (lip-sync).</p></li><li><p><strong>Tartalmi torz&#237;t&#225;s:</strong> Az elemz&#233;s megmutatta, hogy Omelcsenko eredeti, karmikus &#225;tokr&#243;l sz&#243;l&#243; fejteget&#233;s&#233;t a v&#225;g&#225;sok seg&#237;ts&#233;g&#233;vel <strong>k&#246;zvetlen fizikai/terrorista fenyeget&#233;ss&#233;</strong> alak&#237;tott&#225;k &#225;t a kontextus (pl. az ukr&#225;n gyerek&#225;ldozatok eml&#237;t&#233;s&#233;nek) tudatos t&#246;rl&#233;s&#233;vel.</p></li><li><p><strong>Kamp&#225;nyc&#233;l&#250; felhaszn&#225;l&#225;s:</strong> A vide&#243; szerkezete (narr&#225;ci&#243; + feliratok + mozg&#243;s&#237;t&#243; &#252;zenet) bizony&#237;tja, hogy a tartalom egy el&#337;re tervezett <strong>pszichol&#243;giai hadvisel&#233;si eszk&#246;z</strong>, amelynek c&#233;lja a f&#233;lelemkelt&#233;s &#233;s a politikai mozg&#243;s&#237;t&#225;s.</p></li></ul><p>A vizsg&#225;lt anyag digit&#225;lis bizony&#237;t&#233;kok alapj&#225;n <strong>tudatos hamis&#237;tv&#225;ny</strong>. A technikai hib&#225;k (ugr&#225;l&#225;s, pixeliz&#225;ci&#243;) val&#243;j&#225;ban a manipul&#225;ci&#243; nyomai, amelyek a kontextus&#225;b&#243;l kiragadott &#233;s sorrendj&#233;ben megv&#225;ltoztatott besz&#233;det hivatottak hitelesnek felt&#252;ntetni.</p><div><hr></div><h2>Szem&#233;lyazonoss&#225;g &#233;s hiteless&#233;g ellen&#337;rz&#233;se</h2><ul><li><p><strong>A szem&#233;ly:</strong> Hrihorij Omelcsenko (75 &#233;ves), nyugalmazott SZBU-alt&#225;bornagy, volt parlamenti k&#233;pvisel&#337;.</p></li><li><p><strong>St&#225;tusz:</strong> <strong>NEM</strong> korm&#225;nyzati tiszts&#233;gvisel&#337;, <strong>NEM</strong> Zelenszkij embere. S&#337;t, az eredeti interj&#250; 43. perc&#233;t&#337;l kem&#233;nyen b&#237;r&#225;lja az ukr&#225;n eln&#246;k&#246;t.</p></li><li><p><strong>Forr&#225;s:</strong> <em>Pryamyi TV</em> (ukr&#225;n ellenz&#233;ki csatorna), &#233;l&#337; interj&#250;, 2026. m&#225;rcius 9.</p></li><li><p><strong>Konkl&#250;zi&#243;:</strong> A &#8222;Zelenszkij embere&#8221; megnevez&#233;s <strong>t&#233;nybeli hazugs&#225;g</strong>.</p></li></ul><div><hr></div><h2>A Stitching (&#214;ssze&#246;lt&#233;s) t&#233;rk&#233;pe</h2><p>Ez a vide&#243; egy 60 perces interj&#250;b&#243;l k&#233;sz&#252;lt, &#233;s az al&#225;bbi id&#337;k&#243;dokb&#243;l rakt&#225;k &#246;ssze egyetlen percc&#233;:</p><ul><li><p><strong>0:03 &#8211; 0:15:</strong> Az interj&#250; <strong>38:44</strong>-es r&#233;sz&#233;t&#337;l indul (Lakc&#237;m &#233;s szok&#225;sok).</p></li><li><p><strong>0:15 &#8211; 0:35:</strong> Az interj&#250; <strong>39:06</strong>-os r&#233;sz&#233;t&#337;l folytat&#243;dik (Putyin b&#369;nei &#233;s a Karma b&#252;ntet&#233;se).</p></li><li><p><strong>0:35 &#8211; 0:45:</strong> Az interj&#250; <strong>39:45</strong>-&#246;s r&#233;sz&#233;re ugrik (Az 5 gyermek &#233;s 6 unoka).</p></li><li><p><strong>0:45 &#8211; 0:51:</strong> Az interj&#250; <strong>34:55</strong>-&#246;s (vagy 43:43-as) r&#233;sz&#233;b&#337;l veszi ki a v&#225;laszt&#225;si d&#225;tumot.</p></li></ul><div><hr></div><h2>A sz&#246;veg elemz&#233;se (Z&#225;r&#243;jelezett v&#225;g&#225;sokkal)</h2><p>Az al&#225;bbiakban az eredeti ukr&#225;n interj&#250; sz&#246;vege l&#225;that&#243;. A <strong>vastagbet&#369;s</strong> r&#233;szek maradtak a vide&#243;ban, a [<em>z&#225;r&#243;jelbe tett, d&#337;lt</em>] r&#233;szeket tudatosan kiv&#225;gt&#225;k.</p><p><strong>I. blokk: A megfigyel&#233;s l&#225;tszata (Eredeti: 38:44)</strong></p><blockquote><p>&#8222;<strong>[</strong><em>Pane (&#218;r)</em><strong>] Zelenszkij, [</strong><em>a mi szervezet&#252;nknek</em><strong>,] a Karma [</strong><em>nev&#369; szervezet&#252;nknek</em><strong>] nincs sz&#252;ks&#233;ge Orb&#225;n c&#237;m&#233;re. [</strong><em>M&#225;r elmondtam kor&#225;bban is:</em><strong>] Tudjuk, hol lakik, hol t&#246;lti az &#233;jszak&#225;t, </strong>[<em>hol iszik s&#246;rt, bort, hov&#225; j&#225;r ki, kikkel tal&#225;lkozik &#233;s &#237;gy tov&#225;bb.</em>]&#8221;</p></blockquote><ul><li><p><strong>A manipul&#225;ci&#243;:</strong> A &#8222;Pane Zelenszkij&#8221; megsz&#243;l&#237;t&#225;ssal Omelcsenko val&#243;j&#225;ban az ukr&#225;n eln&#246;k&#246;t oktatja ki, de ezt a vide&#243; elej&#233;n a narr&#225;tor &#250;gy &#225;ll&#237;tja be, mintha Omelcsenko Zelenszkij <em>megb&#237;z&#225;s&#225;b&#243;l</em> besz&#233;lne.</p></li></ul><p><strong>II. blokk: A politikai b&#369;n&#246;ss&#233;g (Eredeti: 39:06)</strong></p><blockquote><p>&#8222;<strong>Ez&#233;rt, ha Orb&#225;n nem v&#225;ltoztatja meg </strong>[<em>Ukrajn&#225;val szembeni]</em> <strong>ukr&#225;nellenes &#225;ll&#225;spontj&#225;t, &#233;s tov&#225;bbra is Putyin h&#225;bor&#250;s b&#369;neinek cinkosa marad, </strong>[<em>amir&#337;l &#233;n rengeteg bizony&#237;t&#233;kot gy&#369;jt&#246;ttem,</em>] <strong>eml&#233;kezzen r&#225;, hogy a Karma soha nem bocs&#225;tja meg senki b&#369;neit.</strong> [<em>A Karma el&#337;l nem lehet elrejt&#337;zni &#233;s nem lehet megv&#225;s&#225;rolni.</em>]&#8221;</p></blockquote><ul><li><p><strong>A manipul&#225;ci&#243;:</strong> Kiv&#225;gt&#225;k a hivatkoz&#225;st a saj&#225;t nyomoz&#225;saira, &#237;gy az nem egy r&#246;geszm&#233;s nyugd&#237;jas mag&#225;nv&#233;lem&#233;ny&#233;nek, hanem egy k&#337;kem&#233;ny ultim&#225;tumnak t&#369;nik.</p></li></ul><p><strong>III. blokk: Az &#233;rzelmi zsarol&#225;s (Eredeti: 39:45)</strong></p><blockquote><p>&#8222;[<em>Mivel a b&#369;n&#246;k&#233;rt a lesz&#225;rmazottak is felelnek,</em>] <strong>gondolkodjon el Orb&#225;n az &#246;t gyermek&#233;n &#233;s a hat unok&#225;j&#225;n! </strong>[<em>Vajon hogyan tud a szem&#252;kbe n&#233;zni, mik&#246;zben az &#337; b&#369;n&#246;s politik&#225;ja miatt ukr&#225;n gyerekek halnak meg nap mint nap?</em>]&#8221;</p></blockquote><ul><li><p><strong>A manipul&#225;ci&#243;:</strong> Itt t&#246;rt&#233;nik a legs&#250;lyosabb torz&#237;t&#225;s. Az eredeti mondatban Omelcsenko egy (zavaros) erk&#246;lcsi p&#225;rhuzamot von az ukr&#225;n &#225;ldozatok &#233;s a karma k&#246;z&#246;tt. A v&#225;g&#225;ssal ezt elt&#252;ntett&#233;k, &#237;gy a mondat egy indokl&#225;s n&#233;lk&#252;li, tiszta fenyeget&#233;ss&#233; v&#225;lt a csal&#225;d ellen.</p></li></ul><div><hr></div><h2>Technikai &#233;s vizu&#225;lis diagn&#243;zis</h2><ul><li><p><strong>A Lip-sync hiba:</strong> Mivel a 38. &#233;s a 39. percn&#233;l a besz&#233;l&#337; m&#225;s fizikai poz&#237;ci&#243;ban volt, az egym&#225;s mell&#233; v&#225;gott szavakn&#225;l (pl. a &#8220;tudjuk&#8221; &#233;s a &#8222;gyermekei&#8221; k&#246;z&#246;tt) a sz&#225;j mozg&#225;sa ugrik. Ezt pr&#243;b&#225;lja az MI elmosni, ami a vide&#243;ban l&#225;that&#243; vibr&#225;l&#225;st &#233;s term&#233;szetellenes arcmozg&#225;st okozza.</p></li><li><p><strong>Vizu&#225;lis but&#237;t&#225;s:</strong> A vide&#243; sz&#225;nd&#233;kosan rossz min&#337;s&#233;g&#369; (pixeles), hogy ne legyenek tiszt&#225;n l&#225;that&#243;ak azok a pontok, ahol a v&#225;g&#243;oll&#243; vagy az MI beleny&#250;lt a k&#233;pbe.</p></li><li><p><strong>A narr&#225;ci&#243; szerepe:</strong> A vide&#243; elej&#233;n l&#225;that&#243; influenszer-narr&#225;tor adja meg a hamis &#233;rtelmez&#233;si keretet: &#337; mondja ki a &#8222;Zelenszkij embere&#8221; hazugs&#225;got, amit a n&#233;z&#337; m&#225;r k&#233;sz t&#233;nyk&#233;nt fogad el, miel&#337;tt a t&#225;bornok megsz&#243;lalna.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hwJb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hwJb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png 424w, https://substackcdn.com/image/fetch/$s_!hwJb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png 848w, https://substackcdn.com/image/fetch/$s_!hwJb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png 1272w, https://substackcdn.com/image/fetch/$s_!hwJb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hwJb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png" width="1456" height="1444" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1444,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:645844,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/190698263?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hwJb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png 424w, https://substackcdn.com/image/fetch/$s_!hwJb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png 848w, https://substackcdn.com/image/fetch/$s_!hwJb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png 1272w, https://substackcdn.com/image/fetch/$s_!hwJb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2677c3dd-55cf-4de6-803c-1f2c0d59ff88_2468x2448.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>A FRANKENSTEIN-V&#193;G&#193;S MENETE (Id&#337;k&#243;dok)</h3><ol><li><p><strong>START:</strong> 38:44 (Lakc&#237;m eml&#237;t&#233;se)</p></li><li><p><strong>UGR&#193;S:</strong> 22 m&#225;sodpercet el&#337;re (39:06 - Fenyeget&#233;s)</p></li><li><p><strong>UGR&#193;S:</strong> 32 m&#225;sodpercet el&#337;re (39:45 - Gyermekek eml&#237;t&#233;se)</p></li><li><p><strong>UGR&#193;S:</strong> 5 percet vissza (34:55 - V&#225;laszt&#225;si d&#225;tum)</p></li></ol><div><hr></div><p>A b&#233;kemenetre mozg&#243;s&#237;t&#243; vide&#243; k&#233;sz&#237;t&#337;i a zajos, ugr&#225;l&#243; k&#233;pet &#233;s a pixeless&#233;get haszn&#225;lt&#225;k arra, hogy ne lehessen &#233;szrevenni, hogy <strong>egy 60 perces besz&#233;lget&#233;st daraboltak sz&#233;t</strong>, &#233;s a legijeszt&#337;bb szavakat pakolt&#225;k egym&#225;s mell&#233;, olyan sorrendben, ahogy azok soha nem hangzottak el.</p><p>A vide&#243; nem az&#233;rt ugr&#225;l, mert rossz a technika, hanem az&#233;rt, mert <strong>percekben m&#233;rhet&#337; t&#225;vols&#225;gokat hidaltak &#225;t vele</strong>, hogy egy nem l&#233;tez&#337;, &#246;sszef&#252;gg&#337; fenyeget&#233;st alkossanak.</p><p>Ez a verzi&#243; egy <strong>pszichol&#243;giai hadvisel&#233;si eszk&#246;z</strong>. A 60 perces interj&#250;b&#243;l kicsemeg&#233;zt&#233;k azokat a r&#233;szeket, amelyek a magyar n&#233;z&#337;kb&#337;l a leger&#337;sebb v&#233;delmez&#337; &#246;szt&#246;nt (csal&#225;d f&#233;lt&#233;se) v&#225;ltj&#225;k ki, majd ezt egy politikai rendezv&#233;nyre (B&#233;kemenet) val&#243; felh&#237;v&#225;ssal k&#246;t&#246;tt&#233;k &#246;ssze.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberthreat.report/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">CyberThreat Report is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[A C2 irányító rendszerek fejlődése és a patkányok]]></title><description><![CDATA[A Moonrise RAT technikai elemz&#233;se]]></description><link>https://www.cyberthreat.report/p/a-c2-iranyito-rendszerek-fejlodese</link><guid isPermaLink="false">https://www.cyberthreat.report/p/a-c2-iranyito-rendszerek-fejlodese</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Wed, 25 Feb 2026 07:25:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mPZY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mPZY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mPZY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mPZY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mPZY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mPZY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mPZY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2801001,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/189050942?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mPZY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!mPZY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!mPZY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!mPZY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc8d641c8-9567-4a4c-95ea-9febfaed66a2_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Ferenc Fr&#233;sz.</figcaption></figure></div><p>A kiberbiztons&#225;g vil&#225;g&#225;ban az elm&#250;lt &#233;vekben nagyot v&#225;ltoztak a t&#225;voli el&#233;r&#233;st biztos&#237;t&#243; tr&#243;jai programok (<strong>R</strong>emote<strong>A</strong>ccess<strong>T</strong>rojan). A r&#233;gi, egyszer&#369;bb k&#225;rtev&#337;k helyett ma m&#225;r modul&#225;ris &#233;s rugalmas rendszereket haszn&#225;lnak a t&#225;mad&#243;k. Ezek k&#246;z&#252;l a Moonrise RAT a technikai megold&#225;sai &#233;s az elemz&#233;sekkel szembeni ellen&#225;ll&#225;sa miatt &#233;rdemel figyelmet. Az ir&#225;ny&#237;t&#243; C2 rendszer ma m&#225;r nem csak egy szerver, hanem egy olyan kapcsolat, amivel a t&#225;mad&#243;k a fert&#337;z&#233;s ut&#225;n hossz&#250; ideig l&#225;thatatlanul ir&#225;ny&#237;thatj&#225;k az &#225;ldozat g&#233;p&#233;t. Ez a cikk a Moonrise RAT m&#369;k&#246;d&#233;s&#233;t, h&#225;l&#243;zati megold&#225;sait &#233;s a t&#225;mad&#243;k m&#243;dszereit mutatja be, k&#252;l&#246;n&#246;s tekintettel a Golang nyelvre &#233;s a WebSocket protokollra.</p><p>A C2 rendszer a t&#225;mad&#225;sok k&#246;zpontja. Ezen kereszt&#252;l kap a k&#225;rtev&#337; utas&#237;t&#225;sokat a fert&#337;z&#233;s ut&#225;n, &#233;s itt k&#252;ldi vissza az ellopott adatokat. A t&#225;mad&#243;k legnehezebb feladata, hogy elrejts&#233;k ezt a forgalmat a biztons&#225;gi eszk&#246;z&#246;k (p&#233;ld&#225;ul t&#369;zfalak) el&#337;l. Ez&#233;rt olyan m&#243;dszereket haszn&#225;lnak, amik hasonl&#237;tanak a norm&#225;l internetes forgalomra. A k&#225;rtev&#337; rendszeresen hazasz&#243;l (beaconing) a szervernek, hogy van-e &#250;j feladat, &#237;gy a t&#225;mad&#243;k adatokat lophatnak vagy &#250;jabb k&#225;rt&#233;kony modulokat t&#246;lthetnek le.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberthreat.report/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">CyberThreat Report is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>A technol&#243;gia sokat fejl&#337;d&#246;tt: a r&#233;gi, k&#246;nnyen &#233;szrevehet&#337; protokollok helyett ma m&#225;r HTTPS-t, DNS-t vagy felh&#337;szolg&#225;ltat&#225;sokat haszn&#225;lnak &#225;lc&#225;nak. A Moonrise RAT a WebSocket protokollt haszn&#225;lja, ami az&#233;rt j&#243; a t&#225;mad&#243;knak, mert egyetlen nyitott kapcsolaton kereszt&#252;l, val&#243;s id&#337;ben &#233;s gyorsan tudnak adatokat cser&#233;lni a fert&#337;z&#246;tt g&#233;ppel.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7rFU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7rFU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png 424w, https://substackcdn.com/image/fetch/$s_!7rFU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png 848w, https://substackcdn.com/image/fetch/$s_!7rFU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png 1272w, https://substackcdn.com/image/fetch/$s_!7rFU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7rFU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png" width="1026" height="336" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:336,&quot;width&quot;:1026,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:195619,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/189050942?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe1de503b-aace-4915-bed5-61fbcf6bc4f6_1026x336.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7rFU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png 424w, https://substackcdn.com/image/fetch/$s_!7rFU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png 848w, https://substackcdn.com/image/fetch/$s_!7rFU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png 1272w, https://substackcdn.com/image/fetch/$s_!7rFU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd210b582-1e4b-4d66-8aef-cd1f23732e21_1026x336.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>A Moonrise RAT fel&#233;p&#237;t&#233;se &#233;s jellemz&#337;i</strong></h2><p>A Moonrise RAT egy modern, Golang (Go) nyelven &#237;rt program, amely 2026 elej&#233;n jelent meg. A Go nyelv v&#225;laszt&#225;sa az&#233;rt okos d&#246;nt&#233;s, mert &#237;gy a program t&#246;bb oper&#225;ci&#243;s rendszeren is m&#369;k&#246;dik, &#233;s minden sz&#252;ks&#233;ges &#246;sszetev&#337;t mag&#225;ban hordoz (statikus linkel&#233;s). Emiatt a c&#233;lponton nem kell k&#252;l&#246;n telep&#237;teni semmit, &#233;s a biztons&#225;gi elemz&#337;knek is nehezebb dolguk van a k&#243;d vizsg&#225;latakor.</p><h3><strong>Azonos&#237;t&#243;k &#233;s f&#225;jladatok</strong></h3><p>Az ANY.RUN elemz&#233;sei szerint a Moonrise bin&#225;ris f&#225;jljai 64 bites Windows rendszerekre k&#233;sz&#252;ltek. A t&#225;mad&#243;k gyakran elt&#225;vol&#237;tj&#225;k a f&#225;jlokb&#243;l a hibakeres&#233;si inform&#225;ci&#243;kat, hogy nehezebb legyen r&#225;j&#246;nni, hogyan &#237;rt&#225;k a programot. Az al&#225;bbi t&#225;bl&#225;zat a <code>moonrise-client.exe</code> f&#337;bb adatait mutatja:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h9Gh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h9Gh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png 424w, https://substackcdn.com/image/fetch/$s_!h9Gh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png 848w, https://substackcdn.com/image/fetch/$s_!h9Gh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png 1272w, https://substackcdn.com/image/fetch/$s_!h9Gh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h9Gh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png" width="1026" height="348" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:348,&quot;width&quot;:1026,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:164815,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/189050942?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F44efda8b-6020-4a6d-8592-df466769b618_1026x348.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h9Gh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png 424w, https://substackcdn.com/image/fetch/$s_!h9Gh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png 848w, https://substackcdn.com/image/fetch/$s_!h9Gh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png 1272w, https://substackcdn.com/image/fetch/$s_!h9Gh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0f3b6bc-a72d-43cd-8313-55fc67e2eb0c_1026x348.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Fontos megjegyezni, hogy a Moonrise eleinte nem szerepelt a VirusTotal list&#225;j&#225;n, teh&#225;t a k&#233;sz&#237;t&#337;i sikeresen ker&#252;lt&#233;k el a lebuk&#225;st a hagyom&#225;nyos v&#237;rusirt&#243;k el&#337;tt. Ez&#233;rt van sz&#252;ks&#233;g a viselked&#233;salap&#250; v&#233;delemre (EDR).</p><h3><strong>M&#369;k&#246;d&#233;s a rendszerben</strong></h3><p>A Moonrise RAT fut&#225;s k&#246;zben megpr&#243;b&#225;l be&#233;p&#252;lni a Windows m&#233;lyebb r&#233;tegeibe. Gyakran olyan neveket v&#225;laszt, amik hasonl&#237;tanak a val&#243;di rendszerf&#225;jlokra, p&#233;ld&#225;ul az <code>svchost.exe</code>-re. Az ANY.RUN szerint a folyamat &#237;gy n&#233;z ki: a k&#225;rtev&#337; el&#337;sz&#246;r l&#233;trehoz egy m&#225;solatot mag&#225;r&#243;l az ideiglenes k&#246;nyvt&#225;rban (<code>\AppData\Local\Temp\WindowsServices\svchost.exe</code>), &#233;s onnan dolgozik tov&#225;bb.</p><p>A program a <code>svchost.exe</code> &#225;lc&#225;ja alatt ind&#237;tja el a parancssort (<code>cmd.exe</code>) &#233;s a PowerShellt, hogy parancsokat futtasson. Emellett be&#237;rja mag&#225;t a Windows &#8220;Ind&#237;t&#243;pult&#8221; k&#246;nyvt&#225;r&#225;ba &#233;s a Registry-be (be&#225;ll&#237;t&#225;sjegyz&#233;k) is, hogy a g&#233;p minden &#250;jraind&#237;t&#225;sa ut&#225;n automatikusan elinduljon.</p><h2><strong>Kommunik&#225;ci&#243; &#233;s parancsok</strong></h2><p>A h&#225;l&#243;zati kapcsolat a WebSocket protokollra &#233;p&#252;l, ami korszer&#369;bb megold&#225;s a sima HTTP-n&#233;l. Itt a kapcsolat tart&#243;s marad, &#237;gy a szerver b&#225;rmikor k&#252;ldhet utas&#237;t&#225;st a k&#225;rtev&#337;nek an&#233;lk&#252;l, hogy megv&#225;rn&#225;, am&#237;g az &#250;jra bejelentkezik.</p><h3><strong>JSON alap&#250; utas&#237;t&#225;sok</strong></h3><p>A t&#225;mad&#243; &#233;s a k&#225;rtev&#337; JSON form&#225;tum&#250; &#252;zenetekkel besz&#233;lget egym&#225;ssal. Ez a m&#243;dszer &#225;tl&#225;that&#243; &#233;s j&#243;l rendszerezett ir&#225;ny&#237;t&#225;st tesz lehet&#337;v&#233;. A Moonrise az al&#225;bbi t&#237;pus&#250; parancsokat haszn&#225;lja:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Vmyz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Vmyz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png 424w, https://substackcdn.com/image/fetch/$s_!Vmyz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png 848w, https://substackcdn.com/image/fetch/$s_!Vmyz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png 1272w, https://substackcdn.com/image/fetch/$s_!Vmyz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Vmyz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png" width="965" height="216" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:216,&quot;width&quot;:965,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113618,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/189050942?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7cf4e260-237e-4911-8735-b608e02c7c02_965x216.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Vmyz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png 424w, https://substackcdn.com/image/fetch/$s_!Vmyz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png 848w, https://substackcdn.com/image/fetch/$s_!Vmyz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png 1272w, https://substackcdn.com/image/fetch/$s_!Vmyz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F33802f24-50bf-465e-b95c-6fd75e6f6ebd_965x216.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>A program hiba&#252;zeneteket is k&#252;ld vissza, p&#233;ld&#225;ul ha nem tud k&#233;perny&#337;k&#233;pet k&#233;sz&#237;teni (<code>"message":"no disp"</code>) [Image context]. Ebb&#337;l a t&#225;mad&#243; l&#225;tja, ha valami nem siker&#252;lt, &#233;s pr&#243;b&#225;lkozhat m&#225;shogy.</p><h3><strong>&#193;lc&#225;z&#225;s a h&#225;l&#243;zaton</strong></h3><p>A Moonrise megpr&#243;b&#225;lja elhitetni a v&#233;delemmel, hogy &#337; csak egy sima Microsoft szolg&#225;ltat&#225;s. Ez&#233;rt olyan c&#237;mekre k&#252;ld adatokat, mint a <code>settings-win.data.microsoft.com</code> vagy a <code>login.live.com</code>. Sok biztons&#225;gi eszk&#246;z ezeket alapb&#243;l megb&#237;zhat&#243;nak tartja, &#237;gy a k&#225;rtev&#337; &#233;szrev&#233;tlen maradhat. Emellett megn&#233;zi a g&#233;p internetes be&#225;ll&#237;t&#225;sait is, hogy biztosan ki tudjon jutni a h&#225;l&#243;zatr&#243;l.</p><h2><strong>Mire k&#233;pes a Moonrise RAT?</strong></h2><p>A program f&#337; c&#233;lja a megfigyel&#233;s &#233;s az adatlop&#225;s. A Go nyelv miatt hat&#233;konyan tud egyszerre t&#246;bb feladatot is v&#233;gezni, p&#233;ld&#225;ul hangot &#233;s vide&#243;t r&#246;gz&#237;teni.</p><h3><strong>Kamera &#233;s mikrofon el&#233;r&#233;se</strong></h3><p>A k&#225;rtev&#337; hozz&#225; tud f&#233;rni a webkamer&#225;hoz &#233;s a mikrofonhoz is. Ehhez gyakran PowerShell parancsokat haszn&#225;l, amikkel list&#225;zza az el&#233;rhet&#337; eszk&#246;z&#246;ket (p&#233;ld&#225;ul: <code>Get-PnpDevice -Class Camera -Status OK</code>). Mivel a PowerShell egy gy&#225;ri Windows eszk&#246;z, a haszn&#225;lata kev&#233;sb&#233; t&#369;nik gyan&#250;snak, mint ha a program k&#246;zvetlen&#252;l pr&#243;b&#225;lna a kamer&#225;hoz ny&#250;lni. A Moonrise nem csak k&#233;peket tud l&#337;ni, hanem folyamatos k&#233;perny&#337;&#225;tvitelre is k&#233;pes, &#237;gy a t&#225;mad&#243; &#233;l&#337;ben l&#225;tja, mit csin&#225;l az &#225;ldozat.</p><h3><strong>Kriptovaluta-lop&#225;s</strong></h3><p>A Moonrise bin&#225;ris k&#243;dj&#225;ban olyan mint&#225;kat (YARA szab&#225;lyok) tal&#225;ltak, amik kriptovaluta-c&#237;mek (p&#233;ld&#225;ul Bitcoin vagy Ethereum) felismer&#233;s&#233;re szolg&#225;lnak. Amikor a felhaszn&#225;l&#243; kim&#225;sol egy ilyen c&#237;met a v&#225;g&#243;lapra, a k&#225;rtev&#337; &#233;szleli azt, &#233;s kicser&#233;lheti a t&#225;mad&#243; saj&#225;t c&#237;m&#233;re. Ezt nevezik &#8220;clipper&#8221; funkci&#243;nak. A parancsk&#233;szletben k&#252;l&#246;n utas&#237;t&#225;sok vannak a t&#225;mad&#243; &#225;ltal haszn&#225;lt p&#233;nzt&#225;rcac&#237;mek kezel&#233;s&#233;re.</p><h2><strong>Hogyan ker&#252;li el a lebuk&#225;st?</strong></h2><p>A fejleszt&#337;k sokat dolgoztak azon, hogy a Moonrise-t ne vegy&#233;k &#233;szre az elemz&#337;k vagy az automata rendszerek (homokoz&#243;k). A program &#250;gy viselkedik, mint egy rootkit: akt&#237;van figyeli, hogy vizsg&#225;lj&#225;k-e.</p><h3><strong>Elemz&#337; eszk&#246;z&#246;k keres&#233;se</strong></h3><p>A k&#225;rtev&#337; a mem&#243;ri&#225;j&#225;ban egy hossz&#250; list&#225;t t&#225;rol az ismert elemz&#337; programokr&#243;l (p&#233;ld&#225;ul <code>x64dbg</code>, <code>IDA</code>, <code>Procmon</code>). Ha &#233;szreveszi, hogy valamelyik fut a g&#233;pen, akkor vagy le&#225;ll, vagy teljesen &#225;rtalmatlanul kezd viselkedni, hogy ne bukjon le. Emellett m&#243;dos&#237;tja a rendszerh&#237;v&#225;sokat (API hooking), hogy elrejtse a saj&#225;t f&#225;jljait &#233;s folyamatait a Windows el&#337;l.</p><h3><strong>K&#246;rnyezetellen&#337;rz&#233;s</strong></h3><p>A program ellen&#337;rzi a g&#233;p nyelv&#233;t &#233;s a Windows verzi&#243;j&#225;t is, hogy kisz&#369;rje a tesztk&#246;rnyezeteket. K&#233;pes felismerni a g&#233;pi tanul&#225;son alapul&#243; v&#233;delmet is, &#233;s megv&#225;ltoztatja a h&#225;l&#243;zati forgalom &#252;tem&#233;t, hogy az ne t&#369;nj&#246;n gyan&#250;san szab&#225;lyosnak.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TqQf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TqQf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png 424w, https://substackcdn.com/image/fetch/$s_!TqQf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png 848w, https://substackcdn.com/image/fetch/$s_!TqQf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png 1272w, https://substackcdn.com/image/fetch/$s_!TqQf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TqQf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png" width="1026" height="296" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:296,&quot;width&quot;:1026,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:150421,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/189050942?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb22cb6f7-cfa2-4f9c-a5a3-61a5d0713bc1_1026x296.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TqQf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png 424w, https://substackcdn.com/image/fetch/$s_!TqQf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png 848w, https://substackcdn.com/image/fetch/$s_!TqQf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png 1272w, https://substackcdn.com/image/fetch/$s_!TqQf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71907e1e-3a31-43cc-98af-14177ebf5d7e_1026x296.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Hogyan terjed? A TikTok &#233;s a ClickFix m&#243;dszerek</strong></h2><p>A Moonrise RAT gyakran a &#8220;ClickFix&#8221; nev&#369; kamp&#225;nyokkal terjed, amik a felhaszn&#225;l&#243;k &#225;tver&#233;s&#233;re &#233;p&#237;tenek. Ezek a m&#243;dszerek technikai tr&#252;kk&#246;ket &#233;s pszichol&#243;giai nyom&#225;st kombin&#225;lnak.</p><h3><strong>&#193;tver&#337;s vide&#243;k a TikTokon</strong></h3><p>2025-ben kezdtek el terjedni olyan, mesters&#233;ges intelligenci&#225;val k&#233;sz&#252;lt vide&#243;k, amik szoftverek (pl. Windows, Office, Spotify, CapCut) ingyenes aktiv&#225;l&#225;s&#225;t &#237;g&#233;rik. A vide&#243;k egy weboldalra ir&#225;ny&#237;tj&#225;k az embert, ahol egy parancs futtat&#225;s&#225;t vagy egy f&#225;jl let&#246;lt&#233;s&#233;t k&#233;rik. Ez val&#243;j&#225;ban a Moonrise-t vagy m&#225;s adatlop&#243;kat telep&#237;ti a g&#233;pre. Mivel a vide&#243; hitelesnek t&#369;nik, a felhaszn&#225;l&#243; maga hajtja v&#233;gre a fert&#337;z&#233;st okoz&#243; l&#233;p&#233;seket.</p><h3><strong>Szoftverfelt&#246;r&#233;sek &#233;s hamis hirdet&#233;sek</strong></h3><p>A Moonrise el&#337;szeretettel rejt&#337;zik ingyen k&#237;n&#225;lt, felt&#246;rt programokba (cracks) is. Emellett megt&#233;veszt&#337; hirdet&#233;seken kereszt&#252;l is terjedhet, amik hasznos programnak &#225;lc&#225;zz&#225;k magukat. Ez f&#337;leg azokat vesz&#233;lyezteti, akik nem hivatalos forr&#225;sb&#243;l szereznek be szoftvereket.</p><h2><strong>&#214;sszefoglal&#225;s &#233;s v&#233;dekez&#233;s</strong></h2><p>A Moonrise RAT egy nagyon vesz&#233;lyes &#233;s modern eszk&#246;z. A Go nyelv, a WebSocket kapcsolat &#233;s a fejlett rejt&#337;zk&#246;d&#233;si technik&#225;k miatt sok&#225;ig &#233;szrev&#233;tlen maradhat. M&#225;r nem csak egy egyszer&#369; v&#237;rus, hanem egy komplex rendszer r&#233;sze.</p><p>A v&#233;dekez&#233;shez a c&#233;geknek &#233;s felhaszn&#225;l&#243;knak is szintet kell l&#233;pni&#252;k:</p><ul><li><p><strong>Viselked&#233;salap&#250; v&#233;delem (EDR):</strong> Nem csak a f&#225;jlokat, hanem a programok gyan&#250;s viselked&#233;s&#233;t is figyelni kell.</p></li><li><p><strong>H&#225;l&#243;zati ellen&#337;rz&#233;s:</strong> Fontos a titkos&#237;tott forgalom &#233;s a gyan&#250;s Microsoft-c&#237;mek alapos vizsg&#225;lata.</p></li><li><p><strong>Szigor&#250; hozz&#225;f&#233;r&#233;s (Zero Trust):</strong> Minden h&#225;l&#243;zati k&#233;r&#233;st ellen&#337;rizni kell, f&#252;ggetlen&#252;l att&#243;l, honnan j&#246;n.</p></li><li><p><strong>Biztons&#225;gos ment&#233;s:</strong> A ment&#233;seknek el&#233;rhetetlennek kell lenni&#252;k a k&#225;rtev&#337;k sz&#225;m&#225;ra (offline ment&#233;s), hogy egy fert&#337;z&#233;s ut&#225;n helyre&#225;ll&#237;that&#243; legyen a rendszer.</p></li></ul><p>A Moonrise RAT elleni k&#252;zdelemben a legfontosabb a gyors &#233;szlel&#233;s &#233;s az &#243;vatoss&#225;g, k&#252;l&#246;n&#246;sen az ismeretlen forr&#225;sb&#243;l sz&#225;rmaz&#243; szoftverek &#233;s webes utas&#237;t&#225;sok eset&#233;n.</p>]]></content:encoded></item><item><title><![CDATA[A megtévesztés iparága - a 20 Forintos dezinformáció kora]]></title><description><![CDATA[Hogyan &#225;razta be a feketepiac a digit&#225;lis bizalmat?]]></description><link>https://www.cyberthreat.report/p/a-megtevesztes-iparaga-a-20-forintos</link><guid isPermaLink="false">https://www.cyberthreat.report/p/a-megtevesztes-iparaga-a-20-forintos</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Tue, 23 Dec 2025 08:21:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bqrP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bqrP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bqrP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bqrP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bqrP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bqrP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bqrP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:481645,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/182227098?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bqrP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bqrP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bqrP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bqrP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe99462d3-83d0-4125-a7ec-b56e0ae04ae4_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Ferenc Fr&#233;sz.</figcaption></figure></div><p>Gondolkodt&#225;l m&#225;r azon, mi&#233;rt lepik el a k&#246;z&#246;ss&#233;gi oldalakat a furcsa hozz&#225;sz&#243;l&#225;sok, vagy mi&#233;rt kapsz egyre t&#246;bb gyan&#250;s SMS-t? A v&#225;lasz sokkal egyszer&#369;bb &#233;s ijeszt&#337;bb, mint hinn&#233;nk: az&#233;rt, mert <strong>olcs&#243;</strong>.</p><p>A digit&#225;lis t&#233;rben zajl&#243; manipul&#225;ci&#243;r&#243;l sokszor hallunk, de ritk&#225;n l&#225;tunk a sz&#237;nfalak m&#246;g&#233;. Mostan&#225;ig a kiberb&#369;n&#246;z&#233;s dezin&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/a-megtevesztes-iparaga-a-20-forintos">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Hogyan hekkelik meg az agyunkat? – Útmutató a digitális csapdákhoz]]></title><description><![CDATA[Mi&#233;rt &#233;rezz&#252;k &#250;gy, hogy mindenki meg&#337;r&#252;lt az interneten?]]></description><link>https://www.cyberthreat.report/p/hogyan-hekkelik-meg-az-agyunkat-utmutato</link><guid isPermaLink="false">https://www.cyberthreat.report/p/hogyan-hekkelik-meg-az-agyunkat-utmutato</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Thu, 11 Dec 2025 12:39:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lTq0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lTq0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lTq0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lTq0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lTq0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lTq0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lTq0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:915791,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/181325419?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lTq0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lTq0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lTq0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lTq0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feef47592-13c1-42b1-8fdc-55097cc6757d_2752x1536.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">created with AI by Ferenc Fr&#233;sz</figcaption></figure></div><p>Gyakran &#233;rezz&#252;k &#250;gy, hogy az interneten, &#233;s k&#252;l&#246;n&#246;sen a Facebookon vagy a TikTokon k&#233;t teljesen k&#252;l&#246;n vil&#225;g l&#233;tezik. Az egyik oldalon &#8220;feket&#233;t&#8221; mondanak, a m&#225;sikon &#8220;feh&#233;ret&#8221;, &#233;s a k&#233;t t&#225;bor nemhogy nem &#233;rti egym&#225;st, de mintha nem is ugyanazon a bolyg&#243;n &#233;lne. Sz&#225;mtalan kutat&#225;s folyik a t&#233;m&#225;ban, ezek alapj&#225;n kijelenthet&#337;, ho&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/hogyan-hekkelik-meg-az-agyunkat-utmutato">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Havi globális és regionális kiberfenyegetettségi helyzetkép, 2025. Szeptember-Október]]></title><description><![CDATA[A geopolitikai fesz&#252;lts&#233;gek &#8211; k&#252;l&#246;n&#246;sen az orosz-ukr&#225;n, az ir&#225;ni-izraeli &#233;s a k&#237;nai-nyugati konfliktusok &#8211; ny&#237;ltan manifeszt&#225;l&#243;dtak a kibert&#233;rben.]]></description><link>https://www.cyberthreat.report/p/havi-globalis-es-regionalis-kiberfenyegetettsegi</link><guid isPermaLink="false">https://www.cyberthreat.report/p/havi-globalis-es-regionalis-kiberfenyegetettsegi</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Mon, 03 Nov 2025 16:30:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ka6j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ka6j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ka6j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ka6j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ka6j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ka6j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ka6j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1645261,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/177896821?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ka6j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ka6j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ka6j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ka6j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7a9aa1c9-ab0f-4cfc-8025-75aa723f3017_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Ferenc Fr&#233;sz</figcaption></figure></div><p>/ TL;DR</p><p>A 2025. szeptember-okt&#243;beri id&#337;szak a kiberbiztons&#225;g ter&#252;let&#233;n paradigmav&#225;lt&#225;st hozott, ahol a t&#225;mad&#225;sok f&#243;kusza a mennyis&#233;gr&#337;l a min&#337;s&#233;gre, a sz&#233;les k&#246;r&#369;, alacsony hat&#225;sfok&#250; pr&#243;b&#225;lkoz&#225;sokr&#243;l a prec&#237;zen c&#233;lzott, rendszerszint&#369; k&#225;rokoz&#225;sra helyez&#337;d&#246;tt &#225;t. K&#233;t kulcsfontoss&#225;g&#250; esem&#233;ny &#8211; a Collins Aerospace &#233;s a Jagua&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/havi-globalis-es-regionalis-kiberfenyegetettsegi">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Emberi tényezőből fegyver]]></title><description><![CDATA[A &#8222;muddled libra&#8221; (scattered spider) h&#225;l&#243;zat felemelked&#233;se]]></description><link>https://www.cyberthreat.report/p/emberi-tenyezobol-fegyver</link><guid isPermaLink="false">https://www.cyberthreat.report/p/emberi-tenyezobol-fegyver</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Sat, 16 Aug 2025 07:21:04 GMT</pubDate><enclosure url="https://substack-video.s3.amazonaws.com/video_upload/post/171110548/82fe15a9-79de-4450-bae4-9cc6d61bed24/transcoded-1755328748.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A modern kiberb&#369;n&#246;z&#233;s egyre ink&#225;bb elfordul a tiszt&#225;n technikai sebezhet&#337;s&#233;gek kihaszn&#225;l&#225;s&#225;t&#243;l, &#233;s a legkisz&#225;m&#237;thatatlanabb, m&#233;gis legsebezhet&#337;bb c&#233;lpontra, az emberre f&#243;kusz&#225;l. Ennek a trendnek a legf&#233;lelmetesebb k&#233;pvisel&#337;je a Muddled Libra &#8211; sz&#225;mos m&#225;s n&#233;ven is ismert, mint Scattered Spider, Octo Tempest, UNC3944 &#8211; csoport, amely az emberi megt&#233;veszt&#233;&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/emberi-tenyezobol-fegyver">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[A protokoll gyengesége: a „MadeYouReset” HTTP/2 sebezhetőség]]></title><description><![CDATA[Hogyan alak&#237;tj&#225;k a saj&#225;t hibakezel&#233;sedet a t&#225;mad&#243;k fegyverr&#233;?]]></description><link>https://www.cyberthreat.report/p/a-protokoll-gyengesege-a-madeyoureset</link><guid isPermaLink="false">https://www.cyberthreat.report/p/a-protokoll-gyengesege-a-madeyoureset</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Sat, 16 Aug 2025 06:24:58 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/171108916/6a72fa349566e9f5f3177b87f7095769.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>A digit&#225;lis infrastrukt&#250;r&#225;nk alapj&#225;t k&#233;pez&#337; protokollok rejtett, logikai sebezhet&#337;s&#233;gei rendszerszint&#369; kock&#225;zatot jelentenek az internet eg&#233;sz&#233;re n&#233;zve. Ezt a fenyeget&#233;st t&#246;k&#233;letesen p&#233;ld&#225;zza a nemr&#233;giben felfedezett &#8222;MadeYouReset&#8221; HTTP/2 sebezhet&#337;s&#233;g, amely a webes kommunik&#225;ci&#243; egyik sarokk&#246;v&#233;t teszi sebezhet&#337;v&#233; a szolg&#225;ltat&#225;smegtagad&#225;si (DoS) t&#225;mad&#225;sokkal szemben. A digit&#225;lis vil&#225;g teljes&#237;tm&#233;ny&#233;nek &#233;s hat&#233;konys&#225;g&#225;nak n&#246;vel&#233;s&#233;re tervezett protokollok &#246;sszetetts&#233;ge gyakran rejt mag&#225;ban olyan logikai hib&#225;kat, amelyek kihaszn&#225;l&#225;s&#225;val a t&#225;mad&#243;k komoly zavarokat okozhatnak. A &#8222;MadeYouReset&#8221; sebezhet&#337;s&#233;g t&#246;k&#233;letes p&#233;ld&#225;ja ennek a jelens&#233;gnek, amely a HTTP/2 protokoll egyik alapvet&#337; funkci&#243;j&#225;t ford&#237;tja fegyverr&#233; a szerverek ellen.</p><p>TL;DR</p><ul><li><p><strong>A protokollszint&#369; sebezhet&#337;s&#233;gek rendszerszint&#369; kock&#225;zatot jelentenek.</strong> A &#8222;MadeYouReset&#8221; &#233;s el&#337;dje, a &#8222;Rapid Reset&#8221; r&#225;vil&#225;g&#237;t arra, hogy az internet alapj&#225;t k&#233;pez&#337; protokollok tervez&#233;si hib&#225;i tov&#225;bbra is s&#250;lyos, sz&#233;les k&#246;rben kihaszn&#225;lhat&#243; sebezhet&#337;s&#233;gek forr&#225;sai lehetnek. Ezek megel&#337;z&#233;se &#233;s kezel&#233;se proakt&#237;v kutat&#225;st &#233;s az ipar&#225;gi szerepl&#337;k (kutat&#243;k, gy&#225;rt&#243;k, koordin&#225;ci&#243;s k&#246;zpontok) szoros egy&#252;ttm&#369;k&#246;d&#233;s&#233;t ig&#233;nyli.</p></li><li><p><strong>A kifinomult t&#225;mad&#225;sok a protokoll logik&#225;j&#225;t ford&#237;tj&#225;k &#246;nmaga ellen.</strong> A &#8222;MadeYouReset&#8221; nem egy egyszer&#369; t&#250;lterhel&#233;ses t&#225;mad&#225;s, hanem egy intellektu&#225;lis ugr&#225;s, ahol a t&#225;mad&#243; a szervert k&#233;nyszer&#237;ti a kapcsolatok le&#225;ll&#237;t&#225;s&#225;ra, ezzel megker&#252;lve azokat a v&#233;delmeket, amelyek a kliensoldali viselked&#233;st figyelik. Ez a m&#233;lyrehat&#243;, a m&#246;g&#246;ttes logikai hib&#225;t orvosl&#243; jav&#237;t&#225;sok fontoss&#225;g&#225;t hangs&#250;lyozza a fel&#252;letes, t&#252;neti kezel&#233;sekkel szemben.</p></li><li><p><strong>A koordin&#225;lt k&#246;zz&#233;t&#233;tel kulcsfontoss&#225;g&#250; a megel&#337;z&#233;sben.</strong> A &#8222;MadeYouReset&#8221; esete a felel&#337;s k&#246;zz&#233;t&#233;teli folyamat siker&#233;nek mintap&#233;ld&#225;ja. A kutat&#243;k, a hibajav&#237;t&#243; programot m&#369;k&#246;dtet&#337; v&#225;llalat (Akamai) &#233;s a koordin&#225;ci&#243;s k&#246;zpont (CERT/CC) egy&#252;ttm&#369;k&#246;d&#233;se lehet&#337;v&#233; tette a jav&#237;t&#225;sok kidolgoz&#225;s&#225;t &#233;s elterjeszt&#233;s&#233;t, miel&#337;tt a t&#225;mad&#243;k kihaszn&#225;lhatt&#225;k volna a sebezhet&#337;s&#233;get, ellent&#233;tben a &#8222;Rapid Reset&#8221; esettel, amelyet m&#225;r akt&#237;v t&#225;mad&#225;sok sor&#225;n fedeztek fel.</p></li></ul><p>/TL;DR</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberthreat.report/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">CyberThreat Report is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>A http/2 stream kezel&#233;s m&#369;k&#246;d&#233;se &#233;s a vissza&#233;l&#233;s lehet&#337;s&#233;gei</h2><p>A HTTP/2 protokoll forradalmas&#237;totta a webes kommunik&#225;ci&#243;t az&#225;ltal, hogy bevezette a multiplexing koncepci&#243;j&#225;t, amely lehet&#337;v&#233; teszi t&#246;bb k&#233;r&#233;s &#233;s v&#225;lasz egyidej&#369; tov&#225;bb&#237;t&#225;s&#225;t egyetlen TCP kapcsolaton kereszt&#252;l. Ez a p&#225;rhuzamoss&#225;g &#8222;streamek&#8221; vagy adatfolyamok seg&#237;ts&#233;g&#233;vel val&#243;sul meg, amelyek a kapcsolaton bel&#252;li logikai csatorn&#225;kk&#233;nt funkcion&#225;lnak. A szerverek t&#250;lterhel&#233;s&#233;nek megakad&#225;lyoz&#225;s&#225;ra a protokoll tartalmaz egy fontos v&#233;delmi mechanizmust, a</p><p><code>SETTINGS_MAX_CONCURRENT_STREAMS</code> param&#233;tert. Ez a be&#225;ll&#237;t&#225;s meghat&#225;rozza, hogy egy kliens egy adott kapcsolaton bel&#252;l legfeljebb h&#225;ny akt&#237;v streamet tarthat fenn egyidej&#369;leg, ami elm&#233;letben korl&#225;tozza a szerverre nehezed&#337; terhel&#233;st.</p><p>A protokolltervez&#233;s sor&#225;n a fejleszt&#337;knek gondolniuk kell a hibakezel&#233;sre &#233;s a rugalmass&#225;gra is. Ennek egyik eleme a stream-vissza&#225;ll&#237;t&#225;s (<code>RST_STREAM</code>) funkci&#243;ja. Ez egy legitim mechanizmus, amely lehet&#337;v&#233; teszi a kliens vagy a szerver sz&#225;m&#225;ra, hogy egy streamet id&#337; el&#337;tt lez&#225;rjon, p&#233;ld&#225;ul ha a k&#233;rt er&#337;forr&#225;sra m&#225;r nincs sz&#252;ks&#233;g, vagy ha hiba l&#233;p fel. A &#8222;MadeYouReset&#8221; &#233;s el&#337;dje, a &#8222;Rapid Reset&#8221; t&#225;mad&#225;sok pontosan ezt a legitim, a protokoll m&#369;k&#246;d&#233;s&#233;hez sz&#252;ks&#233;ges funkci&#243;t haszn&#225;lj&#225;k ki rosszindulat&#250;an, hogy a szerver er&#337;forr&#225;sait kimer&#237;ts&#233;k.</p><h2>Technikai lebont&#225;s: hogyan ker&#252;li meg a &#8222;madeyoureset&#8221; a v&#233;delmi mechanizmusokat?</h2><p>A &#8222;MadeYouReset&#8221; (CVE-2025-8671) t&#225;mad&#225;s egy kifinomultabb megk&#246;zel&#237;t&#233;st alkalmaz a szerverek t&#250;lterhel&#233;s&#233;re, mint a kor&#225;bbi, hasonl&#243; jelleg&#369; sebezhet&#337;s&#233;gek. A t&#225;mad&#225;s l&#233;nyege, hogy a kliens nem k&#246;zvetlen&#252;l k&#252;ld nagy mennyis&#233;g&#369; <code>RST_STREAM</code> keretet, hanem sz&#225;nd&#233;kosan hib&#225;s, de a protokoll szintaktik&#225;ja szerint &#233;rv&#233;nyes vez&#233;rl&#337;kereteket tov&#225;bb&#237;t a szerver fel&#233;. A kutat&#243;k t&#246;bb ilyen &#8222;primit&#237;vet&#8221; is azonos&#237;tottak, amelyekkel a t&#225;mad&#225;s kiv&#225;lthat&#243; :</p><ul><li><p>Egy <code>WINDOW_UPDATE</code> keret k&#252;ld&#233;se, amelynek n&#246;vekm&#233;nye 0, vagy amelynek hat&#225;s&#225;ra az &#225;raml&#225;svez&#233;rl&#233;si ablak m&#233;rete meghaladn&#225; a 231&#8722;1 &#233;rt&#233;ket.</p></li><li><p><code>HEADERS</code> vagy <code>DATA</code> keretek k&#252;ld&#233;se egy olyan streamen, amelyet a kliens oldalon m&#225;r lez&#225;rtak (az <code>END_STREAM</code> jelz&#337;vel).</p></li><li><p>Egy <code>PRIORITY</code> keret k&#252;ld&#233;se, amelynek hossza nem a specifik&#225;ci&#243;ban el&#337;&#237;rt 5 b&#225;jt.</p></li></ul><p>A HTTP/2 protokoll specifik&#225;ci&#243;ja (RFC 9113) egy&#233;rtelm&#369;en el&#337;&#237;rja, hogy a szervernek az ilyen t&#237;pus&#250; protokolls&#233;rt&#233;sekre <code>PROTOCOL_ERROR</code> hib&#225;val &#233;s az &#233;rintett stream <code>RST_STREAM</code> kerettel t&#246;rt&#233;n&#337; lez&#225;r&#225;s&#225;val kell v&#225;laszolnia. &#201;s itt rejlik a t&#225;mad&#225;s kulcsa: a szerver, miut&#225;n elk&#252;ldte a</p><blockquote><p><code>RST_STREAM</code> keretet, a streamet lez&#225;rtnak tekinti, &#233;s cs&#246;kkenti az akt&#237;v streamek sz&#225;ml&#225;l&#243;j&#225;t. Azonban sok implement&#225;ci&#243;ban a h&#225;tt&#233;rben fut&#243; alkalmaz&#225;slogika nem &#225;ll&#237;tja le azonnal a k&#233;r&#233;s feldolgoz&#225;s&#225;t, &#233;s tov&#225;bbra is &#233;rt&#233;kes CPU- &#233;s mem&#243;ria-er&#337;forr&#225;sokat em&#233;szt fel. Mivel a szerveroldali sz&#225;ml&#225;l&#243; &#8222;felszabadult&#8221;, a kliens azonnal jogosultt&#225; v&#225;lik egy &#250;j stream megnyit&#225;s&#225;ra, m&#233;g miel&#337;tt a kor&#225;bbi k&#233;r&#233;s feldolgoz&#225;sa t&#233;nylegesen befejez&#337;d&#246;tt volna. Ezzel a m&#243;dszerrel a t&#225;mad&#243; a <code>SETTINGS_MAX_CONCURRENT_STREAMS</code> limitet gyakorlatilag a v&#233;gtelens&#233;gig kij&#225;tszhatja, korl&#225;tlan sz&#225;m&#250;, er&#337;forr&#225;s-ig&#233;nyes k&#233;r&#233;st z&#250;d&#237;tva a szerverre egyetlen TCP kapcsolaton kereszt&#252;l.</p></blockquote><h2>&#214;sszehasonl&#237;t&#243; elemz&#233;s: &#8222;madeyoureset&#8221; vs. &#8222;rapid reset&#8221; (cve-2023-44487)</h2><p>A &#8222;MadeYouReset&#8221; sebezhet&#337;s&#233;g meg&#233;rt&#233;s&#233;hez elengedhetetlen &#246;sszehasonl&#237;tani azt a 2023-ban felfedezett &#233;s sz&#233;les k&#246;rben kihaszn&#225;lt &#8222;Rapid Reset&#8221; (CVE-2023-44487) t&#225;mad&#225;ssal. A &#8222;Rapid Reset&#8221; mechanizmusa egyszer&#369;bb volt: a t&#225;mad&#243; kliens nagy sz&#225;mban nyitott meg streameket, majd szinte azonnal le is z&#225;rta azokat saj&#225;t maga &#225;ltal k&#252;ld&#246;tt <code>RST_STREAM</code> keretekkel. Ez a gyors nyit&#225;s-z&#225;r&#225;s ciklus szint&#233;n a szerver er&#337;forr&#225;sainak kimer&#237;t&#233;s&#233;t c&#233;lozta, kihaszn&#225;lva a stream lez&#225;r&#225;sa &#233;s a h&#225;tt&#233;rfeldolgoz&#225;s le&#225;ll&#237;t&#225;sa k&#246;z&#246;tti k&#233;sleltet&#233;st.</p><p>Az ipar&#225;g erre a fenyeget&#233;sre viszonylag gyorsan reag&#225;lt, de sokan a legegyszer&#369;bb, reakt&#237;v megold&#225;st v&#225;lasztott&#225;k: a kliens &#225;ltal k&#252;ld&#246;tt <code>RST_STREAM</code> keretek sz&#225;m&#225;nak vagy ar&#225;ny&#225;nak korl&#225;toz&#225;s&#225;t. Ez a megk&#246;zel&#237;t&#233;s egyfajta &#8222;t&#252;neti kezel&#233;s&#8221; volt, amely a t&#225;mad&#225;s egy specifikus megnyilv&#225;nul&#225;s&#225;t c&#233;lozta, nem pedig a m&#246;g&#246;ttes logikai hib&#225;t.</p><p>A &#8222;MadeYouReset&#8221; egy&#233;rtelm&#369;en a &#8222;Rapid Reset&#8221; elleni v&#233;dekez&#233;sek elemz&#233;s&#233;b&#337;l sz&#252;letett evol&#250;ci&#243;s l&#233;p&#233;s. A t&#225;mad&#243;k felismert&#233;k a kliensoldali korl&#225;toz&#225;sok gyenges&#233;g&#233;t, &#233;s ahelyett, hogy maguk k&#252;lden&#233;k a resetet, a szervert &#8222;k&#233;nyszer&#237;tik&#8221; annak gener&#225;l&#225;s&#225;ra. Ezzel a kifinomult m&#243;dszerrel a t&#225;mad&#225;s teljesen megker&#252;li azokat az egyszer&#369;s&#237;tett v&#233;delmi mechanizmusokat, amelyek csup&#225;n a kliens viselked&#233;s&#233;t figyelik. Ez a t&#225;mad&#225;s egy intellektu&#225;lis ugr&#225;st k&#233;pvisel: a strat&#233;gia a &#8222;t&#246;bb resetet k&#252;ldeni&#8221; helyett az lett, hogy &#8222;a megl&#233;v&#337; v&#233;delmet kihaszn&#225;lni &#246;nmaga ellen&#8221;.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5qKC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5qKC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png 424w, https://substackcdn.com/image/fetch/$s_!5qKC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png 848w, https://substackcdn.com/image/fetch/$s_!5qKC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png 1272w, https://substackcdn.com/image/fetch/$s_!5qKC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5qKC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png" width="1009" height="316" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:316,&quot;width&quot;:1009,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:158942,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/171108916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffd720ec1-2978-4f79-87ec-5ded77dbb7c3_1009x316.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5qKC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png 424w, https://substackcdn.com/image/fetch/$s_!5qKC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png 848w, https://substackcdn.com/image/fetch/$s_!5qKC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png 1272w, https://substackcdn.com/image/fetch/$s_!5qKC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd67de5a0-ae23-4adf-8f1b-b521897b9dd5_1009x316.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">1. t&#225;bl&#225;zat: a &#8222;madeyoureset&#8221; &#233;s a &#8222;rapid reset&#8221; t&#225;mad&#225;sok technikai &#246;sszehasonl&#237;t&#225;sa.</figcaption></figure></div><h2>Ipari hat&#225;s &#233;s &#233;rintett rendszerek jegyz&#233;ke</h2><p>A sebezhet&#337;s&#233;g potenci&#225;lis hat&#225;sa &#243;ri&#225;si, tekintve, hogy a weboldalak t&#246;bb mint egyharmada haszn&#225;lja a HTTP/2 protokollt a jobb teljes&#237;tm&#233;ny &#233;rdek&#233;ben. A felel&#337;s k&#246;zz&#233;t&#233;teli folyamatnak k&#246;sz&#246;nhet&#337;en a sebezhet&#337;s&#233;get m&#233;g a sz&#233;les k&#246;r&#369; kihaszn&#225;l&#225;s el&#337;tt siker&#252;lt orvosolni, de a probl&#233;ma sz&#225;mos, sz&#233;les k&#246;rben haszn&#225;lt szoftvert &#233;s rendszert &#233;rintett. A koordin&#225;lt bejelent&#233;s ut&#225;n t&#246;bb gy&#225;rt&#243; is meger&#337;s&#237;tette term&#233;keinek sebezhet&#337;s&#233;g&#233;t, &#233;s kiadta a sz&#252;ks&#233;ges jav&#237;t&#225;sokat.</p><p>Az &#233;rintett rendszerek list&#225;ja r&#225;vil&#225;g&#237;t a szoftverell&#225;t&#225;si l&#225;nc komplexit&#225;s&#225;ra, ahol egyetlen protokollimplement&#225;ci&#243;s hiba t&#246;bb tucat, egym&#225;sra &#233;p&#252;l&#337; term&#233;kben is megjelenhet. A CERT Coordination Center (CERT/CC) &#225;ltal k&#246;zz&#233;tett lista alapj&#225;n a sebezhet&#337;s&#233;g sz&#225;mos n&#233;pszer&#369; keretrendszert, szervert &#233;s h&#225;l&#243;zati eszk&#246;zt &#233;rintett.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RCkg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RCkg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png 424w, https://substackcdn.com/image/fetch/$s_!RCkg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png 848w, https://substackcdn.com/image/fetch/$s_!RCkg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png 1272w, https://substackcdn.com/image/fetch/$s_!RCkg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RCkg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png" width="1009" height="372" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:372,&quot;width&quot;:1009,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:184411,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/171108916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc2d03b2-55f9-410f-991b-a7e86cc61f61_1009x372.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RCkg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png 424w, https://substackcdn.com/image/fetch/$s_!RCkg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png 848w, https://substackcdn.com/image/fetch/$s_!RCkg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png 1272w, https://substackcdn.com/image/fetch/$s_!RCkg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d7400-dabb-4db0-854d-e37d44f2c116_1009x372.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>2. t&#225;bl&#225;zat: a &#8222;madeyoureset&#8221; (cve-2025-8671) sebezhet&#337;s&#233;gben &#233;rintett f&#337;bb gy&#225;rt&#243;k &#233;s szoftverek.</em></figcaption></figure></div><h2>V&#233;dekez&#233;si &#233;s jav&#237;t&#225;si strat&#233;gi&#225;k</h2><p>A &#8222;MadeYouReset&#8221; sebezhet&#337;s&#233;g kezel&#233;se a kiberbiztons&#225;gi &#246;kosziszt&#233;ma egy&#252;ttm&#369;k&#246;d&#233;s&#233;nek mintap&#233;ld&#225;ja. A sebezhet&#337;s&#233;get a Tel-Avivi Egyetem kutat&#243;i fedezt&#233;k fel, &#233;s az Akamai bug bounty programj&#225;n kereszt&#252;l jelentett&#233;k. Ezt k&#246;vet&#337;en az Akamai, a kutat&#243;k &#233;s a CERT/CC szorosan egy&#252;ttm&#369;k&#246;dve, egy koordin&#225;lt folyamat keret&#233;ben &#233;rtes&#237;tett&#233;k az &#233;rintett gy&#225;rt&#243;kat, lehet&#337;v&#233; t&#233;ve sz&#225;mukra, hogy a nyilv&#225;noss&#225;gra hozatal el&#337;tt kifejlessz&#233;k &#233;s kiadj&#225;k a sz&#252;ks&#233;ges jav&#237;t&#225;sokat. Ez a proakt&#237;v megk&#246;zel&#237;t&#233;s megakad&#225;lyozta, hogy a sebezhet&#337;s&#233;get a t&#225;mad&#243;k sz&#233;les k&#246;rben kihaszn&#225;lhass&#225;k, ellent&#233;tben a &#8222;Rapid Reset&#8221; esettel, amelyet m&#225;r akt&#237;v t&#225;mad&#225;sok sor&#225;n fedeztek fel.</p><p>&#201;rdekes tanuls&#225;g, hogy a &#8222;Rapid Reset&#8221; elleni kor&#225;bbi v&#233;dekez&#233;sek hat&#233;konys&#225;ga nagyban befoly&#225;solta a &#8222;MadeYouReset&#8221; elleni v&#233;detts&#233;get. Azok a gy&#225;rt&#243;k, mint p&#233;ld&#225;ul az Akamai, amelyek a &#8222;Rapid Reset&#8221; ellen egy robusztusabb, a probl&#233;ma gy&#246;ker&#233;t c&#233;lz&#243; megold&#225;st implement&#225;ltak &#8211; ahelyett, hogy csup&#225;n a kliens &#225;ltal k&#252;ld&#246;tt reseteket sz&#225;molt&#225;k volna &#8211;, automatikusan v&#233;dettek voltak a &#8222;MadeYouReset&#8221; t&#225;mad&#225;ssal szemben is. Ez al&#225;h&#250;zza a m&#233;lyrehat&#243;, a m&#246;g&#246;ttes logikai hib&#225;t orvosl&#243; jav&#237;t&#225;sok fontoss&#225;g&#225;t a fel&#252;letes, t&#252;neti kezel&#233;sekkel szemben.</p><p>A szervezetek sz&#225;m&#225;ra a v&#233;dekez&#233;s els&#337;dleges &#233;s legfontosabb l&#233;p&#233;se a sebezhet&#337; szoftverek azonos&#237;t&#225;sa &#233;s a gy&#225;rt&#243;k &#225;ltal kiadott jav&#237;t&#225;sok azonnali telep&#237;t&#233;se. Azokban az esetekben, ahol a jav&#237;t&#225;s azonnal nem lehets&#233;ges, &#225;tmeneti enyh&#237;t&#337; int&#233;zked&#233;sek alkalmazhat&#243;k:</p><ul><li><p><strong>Szerveroldali </strong><code>RST_STREAM</code><strong> korl&#225;toz&#225;sa:</strong> A szerver &#225;ltal egy kapcsolaton bel&#252;l k&#252;ld&#246;tt <code>RST_STREAM</code> keretek sz&#225;m&#225;nak vagy ar&#225;ny&#225;nak korl&#225;toz&#225;sa ideiglenes v&#233;delmet ny&#250;jthat.</p></li><li><p><strong>Protokollszab&#225;lyok szigor&#237;t&#225;sa:</strong> A webszerverek &#233;s a h&#225;l&#243;zati v&#233;delmi eszk&#246;z&#246;k (pl. WAF) konfigur&#225;l&#225;sa a protokoll anom&#225;li&#225;inak szigor&#250;bb ellen&#337;rz&#233;s&#233;re. A hib&#225;s vez&#233;rl&#337;keretek (pl. null&#225;s n&#246;vekm&#233;ny&#369; <code>WINDOW_UPDATE</code>) fogad&#225;sakor a kapcsolat azonnali bont&#225;sa hat&#233;konyan megakad&#225;lyozhatja a t&#225;mad&#225;st.</p></li></ul><div><hr></div><p>A &#8222;MadeYouReset&#8221; sebezhet&#337;s&#233;g r&#225;vil&#225;g&#237;tott, hogy a digit&#225;lis infrastrukt&#250;r&#225;nk technikai alapjai tov&#225;bbra is rejtenek olyan logikai hib&#225;kat, amelyek kihaszn&#225;l&#225;sa rendszerszint&#369; kock&#225;zatot jelent. A t&#225;mad&#225;s kifinomults&#225;ga, amely a szerver saj&#225;t hibakezel&#233;si mechanizmus&#225;t ford&#237;tja fegyverr&#233;, egy&#233;rtelm&#369;en jelzi a t&#225;mad&#225;si technik&#225;k evol&#250;ci&#243;j&#225;t.</p>]]></content:encoded></item><item><title><![CDATA[Orosz GRU célzott támadásai nyugati logisztikai és technológiai entitások ellen]]></title><description><![CDATA[Logisztikai &#233;s technol&#243;giai v&#225;llalatok fenyegetetts&#233;ge, bele&#233;rtve a magyar IP kamera h&#225;l&#243;zat t&#225;mad&#225;s&#225;t is.]]></description><link>https://www.cyberthreat.report/p/orosz-gru-celzott-tamadasai-nyugati</link><guid isPermaLink="false">https://www.cyberthreat.report/p/orosz-gru-celzott-tamadasai-nyugati</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Thu, 22 May 2025 09:50:40 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/164147403/624c02d4a691e93139baf05e8b26e679.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Ez a <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141a">k&#246;z&#246;s kiberbiztons&#225;gi figyelmeztet&#233;s (CSA)</a> egy orosz &#225;llami t&#225;mogat&#225;s&#250; kiberkamp&#225;nyra h&#237;vja fel a figyelmet, amely nyugati logisztikai entit&#225;sokat &#233;s technol&#243;giai v&#225;llalatokat c&#233;loz, bele&#233;rtve azokat is, amelyek Ukrajn&#225;nak ny&#250;jtott k&#252;lf&#246;ldi seg&#233;ly koordin&#225;l&#225;s&#225;ban, sz&#225;ll&#237;t&#225;s&#225;ban &#233;s k&#233;zbes&#237;t&#233;s&#233;ben vesznek r&#233;szt. 2022 &#243;ta a nyugati logisztikai entit&#225;sok &#233;s IT-v&#225;llalatok fokozott kock&#225;zatnak vannak kit&#233;ve az orosz vez&#233;rkar F&#337;felder&#237;t&#337; Igazgat&#243;s&#225;ga (GRU) 85. F&#337; Speci&#225;lis Szolg&#225;ltat&#243; K&#246;zpontja (85. GTsSS), katonai egys&#233;g 26165 &#8211; a kiberbiztons&#225;gi k&#246;z&#246;ss&#233;g &#225;ltal t&#246;bb n&#233;ven ismert (l&#225;sd: &#8222;Kiberbiztons&#225;gi Ipar&#225;gi K&#246;vet&#233;s&#8221;) &#8211; &#225;ltali c&#233;lz&#225;snak. A szerepl&#337;k kibert&#225;mad&#225;si c&#233;l&#250; kamp&#225;nya, amely technol&#243;giai v&#225;llalatokat &#233;s logisztikai entit&#225;sokat c&#233;loz, kor&#225;bban nyilv&#225;noss&#225;gra hozott taktik&#225;k, technik&#225;k &#233;s elj&#225;r&#225;sok (TTP-k) kever&#233;k&#233;t haszn&#225;lja. A figyelmeztet&#233;st kiad&#243; &#252;gyn&#246;ks&#233;gek hasonl&#243; c&#233;lz&#225;si &#233;s TTP-haszn&#225;latra sz&#225;m&#237;tanak a j&#246;v&#337;ben is.</p><ul><li><p>A c&#233;lzott vertik&#225;lisok a NATO tag&#225;llamaiban, Ukrajn&#225;ban &#233;s nemzetk&#246;zi szervezetekn&#233;l tal&#225;lhat&#243;k, &#233;s magukban foglalj&#225;k:</p></li><li><p><strong>V&#233;delmi ipar</strong></p></li><li><p><strong>Sz&#225;ll&#237;t&#225;s &#233;s Sz&#225;ll&#237;t&#225;si K&#246;zpontok (kik&#246;t&#337;k, rep&#252;l&#337;terek stb.)</strong></p></li><li><p><strong>Tengeri</strong></p></li><li><p><strong>L&#233;gi Forgalom Ir&#225;ny&#237;t&#225;s</strong></p></li><li><p><strong>IT Szolg&#225;ltat&#225;sok</strong></p></li><li><p>A t&#225;mad&#225;si &#233;letciklus sor&#225;n az egys&#233;g 26165-&#246;s egys&#233;g&#233;nek szerepl&#337;i azonos&#237;tottak &#233;s c&#233;lzottan k&#246;vettek tov&#225;bbi, az els&#337;dleges c&#233;lponttal &#252;zleti kapcsolatban &#225;ll&#243; entit&#225;sokat a sz&#225;ll&#237;t&#225;si szektorban, kihaszn&#225;lva a bizalmi kapcsolatokat a tov&#225;bbi hozz&#225;f&#233;r&#233;s megszerz&#233;s&#233;re [T1199].</p></li><li><p>Reconnaissance tev&#233;kenys&#233;get v&#233;geztek legal&#225;bb egy vas&#250;ti ir&#225;ny&#237;t&#225;si ipari vez&#233;rl&#337;rendszer (ICS) alkatr&#233;szek gy&#225;rt&#225;s&#225;val foglalkoz&#243; entit&#225;s ellen is, b&#225;r a sikeres kompromitt&#225;l&#225;st nem er&#337;s&#237;tett&#233;k meg [TA0043].</p></li><li><p>A c&#233;lzott entit&#225;sokkal rendelkez&#337; orsz&#225;gok k&#246;z&#233; tartozik t&#246;bbek k&#246;z&#246;tt <strong>Bulg&#225;ria, Csehorsz&#225;g, Franciaorsz&#225;g, N&#233;metorsz&#225;g, G&#246;r&#246;gorsz&#225;g, Olaszorsz&#225;g, Moldova, Hollandia, Lengyelorsz&#225;g, Rom&#225;nia, Szlov&#225;kia, Ukrajna &#233;s az Egyes&#252;lt &#193;llamok.</strong></p></li><li><p>Az <strong>IP kamer&#225;k c&#233;lz&#225;sa</strong> r&#233;szek&#233;nt a t&#225;mad&#243;k RTSP (Real Time Streaming Protocol) szervereket pr&#243;b&#225;ltak enumer&#225;lni &#233;s hozz&#225;f&#233;r&#233;st szerezni a kamer&#225;k stream-jeihez<strong>.</strong> A DESCRIBE k&#233;r&#233;sek Base64-k&#243;dolt hiteles&#237;t&#337; adatokat tartalmaztak, gyakran publikusan dokument&#225;lt alap&#233;rtelmezett vagy val&#243;sz&#237;n&#369;leg brute force-olt jelszavakat<strong>. </strong>A megc&#233;lzott kamer&#225;k t&#246;bb mint 80%-a Ukrajn&#225;ban volt, a marad&#233;k t&#246;bbs&#233;ge pedig a szomsz&#233;dos orsz&#225;gokban (<strong>Rom&#225;nia, Lengyelorsz&#225;g, Magyarorsz&#225;g, Szlov&#225;kia</strong>)<strong>.</strong></p></li></ul>]]></content:encoded></item><item><title><![CDATA[A közösségi média információs hadszínterei - AI podcast]]></title><description><![CDATA[Dezinform&#225;ci&#243;, propaganda &#233;s a magyar "Harcosok Klubja" jelens&#233;g &#233;s a gyermekek v&#233;delme]]></description><link>https://www.cyberthreat.report/p/a-kozossegi-media-informacios-hadszinterei-01b</link><guid isPermaLink="false">https://www.cyberthreat.report/p/a-kozossegi-media-informacios-hadszinterei-01b</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Wed, 21 May 2025 14:43:20 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/164087420/da756d67809b2039e23bab5b19948c4f.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;15a7c3e4-4f1c-4bab-9f6a-0b89dace61e8&quot;,&quot;caption&quot;:&quot;Az inform&#225;ci&#243;s hadvisel&#233;s, dezinform&#225;ci&#243; &#233;s propaganda kora a k&#246;z&#246;ss&#233;gi m&#233;di&#225;ban&quot;,&quot;cta&quot;:&quot;Read full story&quot;,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;A k&#246;z&#246;ss&#233;gi m&#233;dia inform&#225;ci&#243;s hadsz&#237;nterei - nagyelemz&#233;s&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:122890928,&quot;name&quot;:&quot;Ferenc Fr&#233;sz&quot;,&quot;bio&quot;:&quot;Cyber security senior expert conducting cybersecurity and cyber defense capability development on numerous international fronts.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcd5b576-d747-4724-bdf2-51ed3225c5d3_96x96.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-05-21T14:12:28.610Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda5608d5-4ab0-4cd2-9de1-3fbb984dbeaa_3840x2961.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.cyberthreat.report/p/a-kozossegi-media-informacios-hadszinterei&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:164072847,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:null,&quot;publication_name&quot;:&quot;CyberThreat Report&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50383b70-eecb-4f1b-8260-d05e48d1dbc9_256x256.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberthreat.report/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">A CyberThreat Report egy az olvas&#243;k &#225;ltal t&#225;mogatott kiadv&#225;ny. Az &#250;j bejegyz&#233;sek fogad&#225;s&#225;hoz &#233;s a munk&#225;nk t&#225;mogat&#225;s&#225;hoz fontold meg, hogy ingyenes tag maradsz vagy fizet&#337;s el&#337;fizet&#337;v&#233; v&#225;lsz.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Stratégiai váltás a tanúsítványkezelésben]]></title><description><![CDATA[Az SSL/TLS tan&#250;s&#237;tv&#225;nyok &#233;rv&#233;nyess&#233;gi Idej&#233;nek cs&#246;kkent&#233;se]]></description><link>https://www.cyberthreat.report/p/strategiai-valtas-a-tanusitvanykezelesben</link><guid isPermaLink="false">https://www.cyberthreat.report/p/strategiai-valtas-a-tanusitvanykezelesben</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Sun, 27 Apr 2025 07:29:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ulxl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ulxl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ulxl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Ulxl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Ulxl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Ulxl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ulxl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2973249,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/162225629?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ulxl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Ulxl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Ulxl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Ulxl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F048a95f1-874a-4e80-8975-30a76520101f_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Ferenc Fr&#233;sz.</figcaption></figure></div><p>Az internetes biztons&#225;gi k&#246;rnyezet dinamikus fejl&#337;d&#233;se &#250;jabb m&#233;rf&#246;ldk&#337;h&#246;z &#233;rkezett. A CA/Browser F&#243;rum, az ipar&#225;g meghat&#225;roz&#243; szab&#225;lyoz&#243; test&#252;lete, d&#246;nt&#233;st hozott az SSL/TLS tan&#250;s&#237;tv&#225;nyok maxim&#225;lis &#233;rv&#233;nyess&#233;gi idej&#233;nek szignifik&#225;ns cs&#246;kkent&#233;s&#233;r&#337;l. Ez a l&#233;p&#233;s alapvet&#337; v&#225;ltoz&#225;sokat vet&#237;t el&#337;re a webhelyek &#252;zemeltet&#233;s&#233;ben&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/strategiai-valtas-a-tanusitvanykezelesben">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Kiberbiztonsági események - havi összefoglaló - 2025. április]]></title><description><![CDATA[Listen now | AI gener&#225;lt audio &#246;sszefoglal&#243;]]></description><link>https://www.cyberthreat.report/p/kiberbiztonsagi-esemenyek-havi-osszefoglalo-407</link><guid isPermaLink="false">https://www.cyberthreat.report/p/kiberbiztonsagi-esemenyek-havi-osszefoglalo-407</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Sat, 26 Apr 2025 21:44:22 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/162223958/4a1b5f305aac58bc6bac8e4d6260028a.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberthreat.report/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">A CyberThreat Report egy az olvas&#243;k &#225;ltal t&#225;mogatott kiadv&#225;ny. Az &#250;j bejegyz&#233;sek fogad&#225;s&#225;hoz &#233;s a munk&#225;nk t&#225;mogat&#225;s&#225;hoz fontold meg, hogy ingyenes tag maradsz vagy fizet&#337;s el&#337;fizet&#337;v&#233; v&#225;lsz.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Az al&#225;bbi jelent&#233;s r&#246;vid, audi&#243; &#246;sszefoglal&#243;ja:</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;a2f3cc5e-bae6-4878-87e8-7d4c8612a609&quot;,&quot;caption&quot;:&quot;A h&#243;napot jelent&#337;s adatv&#233;delmi incidensek, a sebezhet&#337;s&#233;gek gyors &#233;s sz&#233;les k&#246;r&#369; kihaszn&#225;l&#225;sa, fokozott &#225;llamilag t&#225;mogatott kibertev&#233;kenys&#233;g, valamint kulcsfontoss&#225;g&#250; szab&#225;lyoz&#225;si v&#225;ltoz&#225;sok jellemezt&#233;k. A t&#225;mad&#243;k tov&#225;bbra is kifinomult taktik&#225;kat alkalmaztak, k&#252;l&#246;n&#246;s hangs&#250;lyt fektetve a hiteles&#237;t&#337; adatok megszerz&#233;s&#233;re &#233;s a kev&#233;sb&#233; v&#233;dett rendszerek, p&#233;ld&#225;ul a felh&#337;k&#246;rnyezetek &#233;s a h&#225;l&#243;zati peremeszk&#246;z&#246;k megc&#233;lz&#225;s&#225;ra. A mesters&#233;ges intelligencia (MI) egyre ink&#225;bb kett&#337;s szerepet j&#225;tszik, mind a t&#225;mad&#243;k eszk&#246;zt&#225;r&#225;t b&#337;v&#237;tve, mind pedig a v&#233;dekez&#233;si strat&#233;gi&#225;k potenci&#225;lis elemek&#233;nt megjelenve. A jelent&#233;s c&#233;lja, hogy r&#233;szletes elemz&#233;st ny&#250;jtson ezekr&#337;l az esem&#233;nyekr&#337;l &#233;s trendekr&#337;l, kontextusba helyezve a legfontosabb fejlem&#233;nyeket &#233;s azok lehets&#233;ges k&#246;vetkezm&#233;nyeit.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Kiberbiztons&#225;gi esem&#233;nyek - havi &#246;sszefoglal&#243; - 2025. &#225;prilis&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:122890928,&quot;name&quot;:&quot;Ferenc Fr&#233;sz&quot;,&quot;bio&quot;:&quot;Cyber security senior expert conducting cybersecurity and cyber defense capability development on numerous international fronts.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcd5b576-d747-4724-bdf2-51ed3225c5d3_96x96.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-04-26T21:20:30.797Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F57dc8ecf-38eb-44c3-89ab-44806ace3e65_1536x1024.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.cyberthreat.report/p/kiberbiztonsagi-esemenyek-havi-osszefoglalo&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:162216356,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:null,&quot;publication_name&quot;:&quot;CyberThreat Report&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50383b70-eecb-4f1b-8260-d05e48d1dbc9_256x256.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p> </p>]]></content:encoded></item><item><title><![CDATA[Nemzetközi összefogással lekapcsolták a világ egyik legnagyobb pedofil tartalmú platformját]]></title><description><![CDATA[K&#246;zel 72 ezer b&#225;ntalmaz&#243; vide&#243;val &#233;s 1,8 milli&#243; felhaszn&#225;l&#243;val m&#369;k&#246;d&#246;tt a Kidflix a lekapcsol&#225;sakor. B&#225;r a platform megsz&#369;nt, a vesz&#233;ly nem m&#250;lt el.]]></description><link>https://www.cyberthreat.report/p/nemzetkozi-osszefogassal-lekapcsoltak</link><guid isPermaLink="false">https://www.cyberthreat.report/p/nemzetkozi-osszefogassal-lekapcsoltak</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Mon, 07 Apr 2025 19:49:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uuHs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uuHs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uuHs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!uuHs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!uuHs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!uuHs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uuHs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:694870,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/160749997?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uuHs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!uuHs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!uuHs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!uuHs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40b8d019-7463-4204-8204-f1a9efc004b2_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>K&#233;t &#233;vnyi &#246;sszehangolt nyomoz&#225;s &#233;s nemzetk&#246;zi b&#369;n&#252;ld&#246;z&#337;i egy&#252;ttm&#369;k&#246;d&#233;s eredm&#233;nyek&#233;nt <strong>2025. m&#225;rcius 11-&#233;n sikeresen felsz&#225;molt&#225;k a vil&#225;g egyik legnagyobb gyermekpornogr&#225;f platformj&#225;t, a &#8222;Kidflix&#8221;-et</strong>. A m&#369;veletet a n&#233;met Bajor B&#369;n&#252;gyi Rend&#337;rs&#233;g &#233;s a Bajor Kiberb&#369;n&#246;z&#233;s Elleni K&#246;zponti &#220;gy&#233;szs&#233;g vezette, az Europol koordin&#225;&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/nemzetkozi-osszefogassal-lekapcsoltak">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Kiszivárogtatták a kompetenciamérés rendszerének felhasználói adatait – 55 ezer rekord nyilvánosságra került]]></title><description><![CDATA[Az Oktat&#225;si Hivatal &#225;ltal m&#369;k&#246;dtetett Tehets&#233;gkapu rendszerb&#337;l di&#225;kok, tan&#225;rok &#233;s hivatalnokok adatai sziv&#225;rogtak ki &#8211; a k&#246;zz&#233;tev&#337; ny&#237;lt kritik&#225;t is megfogalmazott az oktat&#225;si rendszerrel szemben.]]></description><link>https://www.cyberthreat.report/p/kiszivarogtattak-a-kompetenciameres</link><guid isPermaLink="false">https://www.cyberthreat.report/p/kiszivarogtattak-a-kompetenciameres</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Fri, 28 Mar 2025 17:17:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!EJux!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EJux!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EJux!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!EJux!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!EJux!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!EJux!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EJux!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:591630,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/160080393?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EJux!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!EJux!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!EJux!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!EJux!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48ea788b-242b-436e-bc31-f9382fb0875b_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>2025 m&#225;rcius 26-&#225;n nyilv&#225;noss&#225;gra ker&#252;lt, hogy illet&#233;ktelenek hozz&#225;f&#233;rtek a Tehets&#233;gkapu rendszer egyik k&#246;zponti adatb&#225;zis&#225;hoz &#233;s onnan jelent&#337;s mennyis&#233;g&#369; felhaszn&#225;l&#243;i adatot sziv&#225;rogtattak ki. Az incidens t&#233;ny&#233;t az Oktat&#225;si Hivatal &#8211; mint a rendszer fenntart&#243;ja &#8211; hivatalos k&#246;zlem&#233;nyben m&#233;g aznap meger&#337;s&#237;tette<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>.</p><p>A nyilv&#225;&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/kiszivarogtattak-a-kompetenciameres">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[ClickFix: a felhasználó, mint támadási eszköz - a Booking.com kampány]]></title><description><![CDATA[Egy &#250;jabb interakt&#237;v social engineering technika, amely m&#225;r nemcsak becsapja a felhaszn&#225;l&#243;t, hanem k&#246;zvetlen&#252;l r&#225; is b&#237;zza a t&#225;mad&#225;s v&#233;grehajt&#225;s&#225;t.]]></description><link>https://www.cyberthreat.report/p/clickfix-a-felhasznalo-mint-tamadasi</link><guid isPermaLink="false">https://www.cyberthreat.report/p/clickfix-a-felhasznalo-mint-tamadasi</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Sun, 23 Mar 2025 07:45:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!T4RG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!T4RG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!T4RG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!T4RG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!T4RG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!T4RG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!T4RG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:695536,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/159615781?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!T4RG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!T4RG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!T4RG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!T4RG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F45184a79-6c48-4295-88fd-9ef56c256e25_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>A social engineering, vagyis az emberi viselked&#233;s manipul&#225;l&#225;s&#225;ra &#233;p&#237;t&#337; t&#225;mad&#225;si technik&#225;k a kezdetek &#243;ta jelen vannak a kiberfenyeget&#233;sek eszk&#246;zt&#225;r&#225;ban. Az elm&#250;lt id&#337;szakban azonban egyre gyakoribb, hogy a kiberb&#369;n&#246;z&#337;k m&#225;r nem el&#233;gszenek meg az egyszer&#369; adathal&#225;sz e-mailekkel &#233;s kattint&#225;sokkal, hanem elmozdultak az inte&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/clickfix-a-felhasznalo-mint-tamadasi">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Online csalások Magyarországon: Tízmilliárdok tűnnek el évente - első rész]]></title><description><![CDATA[Az internet t&#233;rh&#243;d&#237;t&#225;s&#225;val az online csal&#225;sok sz&#225;ma is drasztikusan megn&#337;tt Magyarorsz&#225;gon, &#233;vente t&#237;zmilli&#225;rd forintos k&#225;rt okozva.]]></description><link>https://www.cyberthreat.report/p/online-csalasok-magyarorszagon-tizmilliardok</link><guid isPermaLink="false">https://www.cyberthreat.report/p/online-csalasok-magyarorszagon-tizmilliardok</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Sun, 23 Feb 2025 10:39:10 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/157733156/6327061115c3fc4744d680adf7116604.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>A MasterCard adatai szerint 2023-ban a b&#369;n&#246;z&#337;k <strong>30 milli&#225;rd forint k&#225;rt okoztak 13 ezer k&#225;rosultnak &#225;tutal&#225;sokat &#233;rint&#337; csal&#225;sokkal</strong>. A Bank360.hu elemz&#233;se szerint <strong>2024 m&#225;sodik negyed&#233;v&#233;ben </strong>a bankk&#225;rty&#225;s &#233;s banksz&#225;ml&#225;s csal&#225;sok <strong>csaknem 9 milli&#225;rd forint</strong> k&#225;rt okoztak. A rend&#337;rs&#233;g adatai szerint 2023-ban <strong>167 ezer b&#369;ncselekm&#233;nyt</strong> k&#246;vettek el &#233;s a b&#369;ncselekm&#233;nyekhez kapcsol&#243;d&#243;an ind&#237;tott elj&#225;r&#225;sokban a <strong>k&#225;r megt&#233;r&#252;l&#233;se csup&#225;n 21-22 sz&#225;zal&#233;kos</strong> volt. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!icLz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!icLz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png 424w, https://substackcdn.com/image/fetch/$s_!icLz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png 848w, https://substackcdn.com/image/fetch/$s_!icLz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png 1272w, https://substackcdn.com/image/fetch/$s_!icLz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!icLz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png" width="1456" height="847" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:847,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:477131,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/157733156?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!icLz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png 424w, https://substackcdn.com/image/fetch/$s_!icLz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png 848w, https://substackcdn.com/image/fetch/$s_!icLz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png 1272w, https://substackcdn.com/image/fetch/$s_!icLz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a16b651-58e3-4f40-b9f9-a5054c0b94c3_3099x1803.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Fontos kiemelni, hogy m&#237;g <strong>2023-r&#243;l 2024-re 36 sz&#225;zal&#233;kkal cs&#246;kkent a banki &#252;gyfelek ellen elk&#246;vetett csal&#225;sok sz&#225;ma, addig a v&#225;llalatok elleni kibercsal&#225;sok sz&#225;ma megh&#225;romszoroz&#243;dott</strong>. K&#252;l&#246;n&#246;sen aggaszt&#243;, hogy a <strong>18-29 &#233;ves koroszt&#225;ly</strong> tagjai, a digit&#225;lis bennsz&#252;l&#246;ttek, a <strong>legvesz&#233;lyeztetettebbek</strong> az online csal&#225;sok szempontj&#225;b&#243;l, annak ellen&#233;re, hogy &#337;k magukat tartj&#225;k a legfelk&#233;sz&#252;ltebbnek.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GWjF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GWjF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png 424w, https://substackcdn.com/image/fetch/$s_!GWjF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png 848w, https://substackcdn.com/image/fetch/$s_!GWjF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png 1272w, https://substackcdn.com/image/fetch/$s_!GWjF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GWjF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:408681,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.cyberthreat.report/i/157733156?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GWjF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png 424w, https://substackcdn.com/image/fetch/$s_!GWjF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png 848w, https://substackcdn.com/image/fetch/$s_!GWjF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png 1272w, https://substackcdn.com/image/fetch/$s_!GWjF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f87d27-90c2-4213-8714-54343c5ad7fa_2955x2236.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h2><strong>A korm&#225;ny &#233;s a hat&#243;s&#225;gok fell&#233;p&#233;se</strong></h2><p>A magyar korm&#225;ny &#233;s a hat&#243;s&#225;gok sz&#225;mos int&#233;zked&#233;st hoztak az online csal&#225;sok elleni k&#252;zdelemben. A legt&#246;bb t&#225;mad&#225;s a k&#246;zszolg&#225;ltat&#225;sokat, a sz&#225;ll&#237;tm&#225;nyoz&#225;st &#233;s a p&#233;nz&#252;gyi &#225;gazatokat &#233;rte. A k&#246;zszolg&#225;ltat&#225;sokat &#233;rt t&#225;mad&#225;sok 35%-a pszichol&#243;giai manipul&#225;ci&#243;n alapul&#243; adathal&#225;szat volt.</p><p>A korm&#225;ny c&#233;lja, hogy felgyors&#237;tsa a b&#369;ncselekm&#233;nyek felder&#237;t&#233;s&#233;t &#233;s az elj&#225;r&#225;sok lefolytat&#225;s&#225;t, valamint hogy minimaliz&#225;lja a csal&#225;dokat &#233;rt k&#225;rokat. Ennek &#233;rdek&#233;ben 2024 augusztus&#225;ban &#250;j t&#246;rv&#233;nycsomag l&#233;pett &#233;letbe, amelynek legfontosabb elemei a k&#246;vetkez&#337;k:</p><ul><li><p><strong>Bankok k&#246;z&#246;tti inform&#225;ci&#243;csere felgyors&#237;t&#225;sa:</strong> A bankok gyorsabban megoszthatj&#225;k egym&#225;ssal az inform&#225;ci&#243;kat az elcsalt &#246;sszegekr&#337;l, ami seg&#237;t a csal&#243;k azonos&#237;t&#225;s&#225;ban &#233;s a p&#233;nzek befagyaszt&#225;s&#225;ban.</p></li><li><p><strong>Gyorsabb inform&#225;ci&#243;szerz&#233;s a rend&#337;rs&#233;g sz&#225;m&#225;ra:</strong> A rend&#337;rs&#233;g gyorsabban hozz&#225;f&#233;rhet a sz&#252;ks&#233;ges inform&#225;ci&#243;khoz, ami felgyors&#237;tja a nyomoz&#225;st.</p></li><li><p><strong>Online piacterek bevon&#225;sa a csal&#225;sok elleni k&#252;zdelembe:</strong> Az online piactereknek int&#233;zkedni&#252;k kell a csal&#225;sokra haszn&#225;lt felhaszn&#225;l&#243;i fi&#243;kok t&#246;rl&#233;s&#233;r&#337;l.</p></li><li><p><strong>&#220;gyteher eloszt&#225;sa a b&#237;r&#243;s&#225;gok k&#246;z&#246;tt:</strong> A b&#237;r&#243;s&#225;gok az &#225;ltal&#225;nos illet&#233;kess&#233;g alapj&#225;n j&#225;rhatnak el az online csal&#225;sok &#252;gy&#233;ben, nincs sz&#252;ks&#233;g speci&#225;lis szak&#233;rtelemre.</p></li><li><p><strong>Nyomoz&#243; hat&#243;s&#225;gok adatlek&#233;r&#233;si jogosults&#225;g&#225;nak b&#337;v&#237;t&#233;se:</strong> A nyomoz&#243; hat&#243;s&#225;g &#252;gy&#233;szi enged&#233;ly n&#233;lk&#252;l k&#233;rhet le bizonyos banki &#233;s telekommunik&#225;ci&#243;s adatokat, ami gyorsabb&#225; teszi a szem&#233;lyek azonos&#237;t&#225;s&#225;t.</p></li></ul><p>A rend&#337;rs&#233;g 2023 okt&#243;ber&#233;ben 300 f&#337;s orsz&#225;gos kibernyomoz&#243;i h&#225;l&#243;zatot hozott l&#233;tre a M&#225;trix Projekt keret&#233;ben, amelynek c&#233;lja az online csal&#225;sok visszaszor&#237;t&#225;sa. A projekt keret&#233;ben a rend&#337;rs&#233;g folyamatosan figyeli az online teret, &#233;s fell&#233;p a csal&#243;k ellen.</p><p>A korm&#225;nyzati int&#233;zked&#233;sek mellett fontos szerepe van a KiberPajzs programnak is, amely a p&#233;nz&#252;gyi fogyaszt&#243;k v&#233;delm&#233;ben j&#246;tt l&#233;tre. A program keret&#233;ben a p&#233;nz&#252;gyi szektor szerepl&#337;i, a b&#369;n&#252;ld&#246;z&#337; szervek &#233;s a hat&#243;s&#225;gok egy&#252;ttm&#369;k&#246;dnek az online csal&#225;sok megel&#337;z&#233;se &#233;rdek&#233;ben. A KiberPajzs honlapj&#225;n naprak&#233;sz inform&#225;ci&#243;k &#233;s tan&#225;csok tal&#225;lhat&#243;k az online csal&#225;sokr&#243;l &#233;s a megel&#337;z&#233;s lehet&#337;s&#233;geir&#337;l.</p><h2><strong>J&#243;gyakorlatok az online csal&#225;sok elker&#252;l&#233;s&#233;re</strong></h2><p>A bemutatott statisztik&#225;k &#233;s csal&#225;si m&#243;dszerek ismeret&#233;ben fontos, hogy tiszt&#225;ban legy&#252;nk azzal, hogyan v&#233;dhetj&#252;k meg magunkat.</p><ul><li><p><strong>Legyen &#243;vatos az adatai megad&#225;s&#225;val:</strong> Soha ne adja meg a bankk&#225;rtya adatait vagy az internetbanki bel&#233;p&#233;si adatait e-mailben, SMS-ben vagy telefonon kereszt&#252;l. A bankok &#233;s a megb&#237;zhat&#243; web&#225;ruh&#225;zak sosem k&#233;rnek ilyen inform&#225;ci&#243;kat.</p></li><li><p><strong>Ellen&#337;rizze a weboldalakat:</strong> Miel&#337;tt online v&#225;s&#225;rolna vagy megadna b&#225;rmilyen szem&#233;lyes adatot, ellen&#337;rizze a weboldal c&#237;m&#233;t a b&#246;ng&#233;sz&#337; c&#237;msor&#225;ban, &#233;s gy&#337;z&#337;dj&#246;n meg arr&#243;l, hogy biztons&#225;gos (https). A https azt jelzi, hogy az oldal titkos&#237;tott kapcsolaton kereszt&#252;l kommunik&#225;l, &#237;gy adatai v&#233;dve vannak. Fontos hogy ellen&#337;rizze, hogy val&#243;ban a szolg&#225;ltat&#243; weboldal&#225;nak c&#237;me olvashat&#243; a b&#246;ng&#233;sz&#337; c&#237;msor&#225;ban &#233;s nem egy hamis&#237;tott c&#237;m.</p></li><li><p><strong>Ne kattintson gyan&#250;s linkekre:</strong> Ne kattintson olyan linkekre, amelyeket e-mailben vagy SMS-ben kapott, ha nem biztos a felad&#243;ban. Ha egy link gyan&#250;snak t&#369;nik, ink&#225;bb &#237;rja be manu&#225;lisan a weboldal c&#237;m&#233;t a b&#246;ng&#233;sz&#337;be.</p></li><li><p><strong>Haszn&#225;ljon er&#337;s jelszavakat:</strong> Haszn&#225;ljon er&#337;s &#233;s egyedi jelszavakat az online fi&#243;kjaihoz. A jelsz&#243; legal&#225;bb 12 karakter hossz&#250; legyen, &#233;s tartalmazzon kis- &#233;s nagybet&#369;ket, sz&#225;mokat &#233;s speci&#225;lis karaktereket.</p></li><li><p><strong>Legyen naprak&#233;sz a biztons&#225;gi friss&#237;t&#233;sekkel:</strong> Rendszeresen friss&#237;tse az oper&#225;ci&#243;s rendszer&#233;t &#233;s a szoftvereit a leg&#250;jabb biztons&#225;gi friss&#237;t&#233;sekkel. A friss&#237;t&#233;sek gyakran tartalmaznak olyan jav&#237;t&#225;sokat, amelyek biztons&#225;gi r&#233;seket z&#225;rnak be.</p></li><li><p><strong>Haszn&#225;ljon v&#237;ruskeres&#337;t:</strong> Telep&#237;tsen v&#237;ruskeres&#337;t a sz&#225;m&#237;t&#243;g&#233;p&#233;re, &#233;s rendszeresen friss&#237;tse. A v&#237;ruskeres&#337; seg&#237;t megv&#233;deni a sz&#225;m&#237;t&#243;g&#233;pet a k&#225;rt&#233;kony programokt&#243;l.</p></li><li><p><strong>Legyen gyanakv&#243;:</strong> Ha egy aj&#225;nlat t&#250;l j&#243;nak t&#369;nik ahhoz, hogy igaz legyen, val&#243;sz&#237;n&#369;leg &#225;tver&#233;s. A csal&#243;k gyakran irre&#225;lisan magas hozamot vagy nyerem&#233;nyt &#237;g&#233;rnek, hogy becsapj&#225;k az &#225;ldozatokat.</p></li></ul><blockquote><p><strong>(A vide&#243;t az <a href="https://invideo.sjv.io/c/6054827/883681/12258">invideo AI</a> generat&#237;v vide&#243; k&#233;sz&#237;t&#337; haszn&#225;lat&#225;val Fr&#233;sz Ferenc k&#233;sz&#237;tette)</strong></p></blockquote><div><hr></div><h3>Kapcsol&#243;d&#243; bejegyz&#233;s&#252;nk:</h3><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;bb3fa309-457b-489b-83b0-7c2200c6b0c4&quot;,&quot;caption&quot;:&quot;Mianmar az elm&#250;lt &#233;vekben a d&#233;lkelet-&#225;zsiai online csal&#225;si ipar&#225;g egyik k&#246;zpontj&#225;v&#225; v&#225;lt. A hat&#243;s&#225;gok becsl&#233;se szerint t&#246;bb t&#237;zezer ember, k&#246;zt&#252;k k&#237;nai, indiai, afrikai &#233;s m&#225;s nemzetis&#233;g&#369; &#225;llampolg&#225;rok v&#225;ltak k&#233;nyszermunka &#225;ldozat&#225;v&#225;, miut&#225;n online csal&#225;si k&#246;zpontokba csalt&#225;k &#337;ket hamis &#225;ll&#225;saj&#225;nlatokkal.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;md&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Digit&#225;lis dzsungelh&#225;bor&#250;: Mianmar csak a kezdet&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:108763897,&quot;name&quot;:&quot;Katalin B&#233;res&quot;,&quot;bio&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcc0aee8-919f-49e5-bd27-53d0312fbbeb_144x144.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null},{&quot;id&quot;:122890928,&quot;name&quot;:&quot;Ferenc Fr&#233;sz&quot;,&quot;bio&quot;:&quot;Cyber security senior expert conducting cybersecurity and cyber defense capability development on numerous international fronts.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcd5b576-d747-4724-bdf2-51ed3225c5d3_96x96.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-02-22T12:20:23.699Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3993557-b344-4af4-9bf5-1874c7ccf715_1920x1088.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.cyberthreat.report/p/digitalis-dzsungelhaboru-mianmar&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:157625284,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:null,&quot;publication_name&quot;:&quot;CyberThreat Report&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50383b70-eecb-4f1b-8260-d05e48d1dbc9_256x256.png&quot;,&quot;belowTheFold&quot;:true,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><pre><code><strong>Felhaszn&#225;lt forr&#225;sok:

</strong><a href="https://index.hu/belfold/2023/12/16/online-csalas-rendorseg/">https://index.hu/belfold/2023/12/16/online-csalas-rendorseg/</a>

<a href="https://www.police.hu/hu/hirek-es-informaciok/bunmegelozes/internet-biztonsag/csalasok-az-online-terben">https://www.police.hu/hu/hirek-es-informaciok/bunmegelozes/internet-biztonsag/csalasok-az-online-terben</a>

<a href="https://tudastar.money.hu/hir/20240816/legy-okosabb-a-csaloknal-igy-vedd-meg-magad-az-online-csalasoktol/">https://tudastar.money.hu/hir/20240816/legy-okosabb-a-csaloknal-igy-vedd-meg-magad-az-online-csalasoktol/</a>

<a href="https://support.microsoft.com/hu-hu/office/v%C3%A9dekez%C3%A9s-az-online-csal%C3%A1sok-%C3%A9s-t%C3%A1mad%C3%A1sok-ellen-0109ae3f-fe61-4262-8dce-2ee3cd43bac7">https://support.microsoft.com/hu-hu/office/v%C3%A9dekez%C3%A9s-az-online-csal%C3%A1sok-%C3%A9s-t%C3%A1mad%C3%A1sok-ellen-0109ae3f-fe61-4262-8dce-2ee3cd43bac7</a>

<a href="https://www.erstebank.hu/hu/ebh-nyito/biztonsagi-kozpont/tippek/igy-vedekezhetsz-a-telefonos-csalasok-ellen">https://www.erstebank.hu/hu/ebh-nyito/biztonsagi-kozpont/tippek/igy-vedekezhetsz-a-telefonos-csalasok-ellen</a>

<a href="https://24.hu/fn/gazdasag/2024/09/17/csalok-havi-3-milliardot-lopnak-banki-ugyfelektol/">https://24.hu/fn/gazdasag/2024/09/17/csalok-havi-3-milliardot-lopnak-banki-ugyfelektol/</a>

<a href="https://www.portfolio.hu/bank/20250220/csatlakozott-a-mastercard-a-nagy-magyar-banki-kibervedelmi-egyuttmukodeshez-742765">https://www.portfolio.hu/bank/20250220/csatlakozott-a-mastercard-a-nagy-magyar-banki-kibervedelmi-egyuttmukodeshez-742765</a>

<a href="https://telex.hu/techtud/2025/02/20/kiberpajzs-kiberbiztonsag-kiberbunozes-mastercard-jelentes-nki-bankszovetseg-rendorseg">https://telex.hu/techtud/2025/02/20/kiberpajzs-kiberbiztonsag-kiberbunozes-mastercard-jelentes-nki-bankszovetseg-rendorseg</a>

<a href="https://www.otpbank.hu/portal/hu/adathalaszat">https://www.otpbank.hu/portal/hu/adathalaszat</a>

<a href="https://www.police.hu/hu/hirek-es-informaciok/bunmegelozes/internet-biztonsag/csalasok-a-kiberterben">https://www.police.hu/hu/hirek-es-informaciok/bunmegelozes/internet-biztonsag/csalasok-a-kiberterben</a>

<a href="https://hirlevel.egov.hu/2024/07/21/uj-torveny-lep-eletbe-augusztus-elsejetol-az-online-csalasok-ellen/">https://hirlevel.egov.hu/2024/07/21/uj-torveny-lep-eletbe-augusztus-elsejetol-az-online-csalasok-ellen/</a>

<a href="https://www.police.hu/hu/hirek-es-informaciok/bunmegelozes/aktualis/megint-egy-lepessel-elorebb-az-online-csalasok">https://www.police.hu/hu/hirek-es-informaciok/bunmegelozes/aktualis/megint-egy-lepessel-elorebb-az-online-csalasok</a></code></pre>]]></content:encoded></item><item><title><![CDATA[Amikor nem a tech óriás a hibás – Hogyan szivárogtak ki milliók OpenAI-fiókjainak adatai?]]></title><description><![CDATA[A t&#225;mad&#243;k nem az OpenAI-t t&#246;rt&#233;k fel, hanem a felhaszn&#225;l&#243;kat vett&#233;k c&#233;lba. Az infostealerek &#233;szrev&#233;tlen&#252;l lopj&#225;k a jelszavakat &#8211; lehet, hogy a te fi&#243;kod is vesz&#233;lyben van?]]></description><link>https://www.cyberthreat.report/p/amikor-nem-a-tech-orias-a-hibas-hogyan</link><guid isPermaLink="false">https://www.cyberthreat.report/p/amikor-nem-a-tech-orias-a-hibas-hogyan</guid><dc:creator><![CDATA[Katalin Béres]]></dc:creator><pubDate>Mon, 17 Feb 2025 07:42:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JUoT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JUoT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JUoT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!JUoT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!JUoT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!JUoT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JUoT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp" width="1456" height="832" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:832,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:545188,&quot;alt&quot;:&quot;A cybersecurity-themed image depicting a 'DATA BREACH' warning on a screen with hacked OpenAI accounts for sale. A human silhouette is framed in a digital crosshair, symbolizing users as prime targets of cyber threats.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="A cybersecurity-themed image depicting a 'DATA BREACH' warning on a screen with hacked OpenAI accounts for sale. A human silhouette is framed in a digital crosshair, symbolizing users as prime targets of cyber threats." title="A cybersecurity-themed image depicting a 'DATA BREACH' warning on a screen with hacked OpenAI accounts for sale. A human silhouette is framed in a digital crosshair, symbolizing users as prime targets of cyber threats." srcset="https://substackcdn.com/image/fetch/$s_!JUoT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp 424w, https://substackcdn.com/image/fetch/$s_!JUoT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp 848w, https://substackcdn.com/image/fetch/$s_!JUoT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp 1272w, https://substackcdn.com/image/fetch/$s_!JUoT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3eb856a-7da7-48e0-8cdd-ac3d74375596_1792x1024.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Generated with AI by Katalin B&#233;res</figcaption></figure></div><p>2025 febru&#225;r 6-&#225;n a kiberbiztons&#225;g vil&#225;g&#225;t megr&#225;zta egy hacker bejelent&#233;se: &#225;ll&#237;t&#225;sa szerint t&#246;bb mint 20 milli&#243; OpenAI felhaszn&#225;l&#243; adataihoz f&#233;rt hozz&#225;. A bejelent&#233;s gyorsan elterjedt a ChatGPT felhaszn&#225;l&#243;k k&#246;r&#233;ben is, &#233;s sokan att&#243;l tartottak, hogy az OpenAI rendszereit felt&#246;rt&#233;k. Azonban az els&#337; vizsg&#225;latok hamar tis&#8230;</p>
      <p>
          <a href="https://www.cyberthreat.report/p/amikor-nem-a-tech-orias-a-hibas-hogyan">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[A kibertámadások átlátható kommunikációja]]></title><description><![CDATA[A kibert&#225;mad&#225;sok sor&#225;n a hat&#233;kony kommunik&#225;ci&#243; kulcsfontoss&#225;g&#250; a k&#225;rok minimaliz&#225;l&#225;s&#225;ban &#233;s az &#233;rintettek megfelel&#337; t&#225;j&#233;koztat&#225;s&#225;ban.]]></description><link>https://www.cyberthreat.report/p/a-kibertamadasok-atlathato-kommunikacioja</link><guid isPermaLink="false">https://www.cyberthreat.report/p/a-kibertamadasok-atlathato-kommunikacioja</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Sat, 15 Feb 2025 15:22:45 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/157199823/642764fe74615b96c42e4f54be2296c3.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>A KonBriefing Research<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> kutat&#225;sa is j&#243;l r&#225;vil&#225;g&#237;t arra, hogy a kibert&#225;mad&#225;sok kommunik&#225;ci&#243;ja egy komplex folyamat, amely t&#246;bb kulcsfontoss&#225;g&#250; ter&#252;letre kell hogy f&#243;kusz&#225;ljon. A hat&#233;kony v&#225;laszad&#225;s &#233;rdek&#233;ben azonnali reag&#225;l&#225;s sz&#252;ks&#233;ges, mik&#246;zben biztos&#237;tani kell az &#233;rintettek megfelel&#337; t&#225;j&#233;koztat&#225;s&#225;t &#233;s a transzparens kommunik&#225;ci&#243;t. A kommunik&#225;ci&#243;s csatorn&#225;k sz&#233;les sk&#225;l&#225;j&#225;t kell haszn&#225;lni, bele&#233;rtve a bels&#337; platformokat, hivatalos k&#246;zlem&#233;nyeket, sajt&#243;kapcsolatokat &#233;s k&#246;z&#246;ss&#233;gi m&#233;di&#225;t.</p><h2>F&#337;bb pontok</h2><ul><li><p><strong>Azonnali reag&#225;l&#225;s:</strong> A gyors &#233;s pontos kommunik&#225;ci&#243; kritikus az els&#337; &#243;r&#225;kban</p></li><li><p><strong>&#201;rintettek azonos&#237;t&#225;sa:</strong> Minden &#233;rintett f&#233;l (&#252;gyfelek, partnerek, hat&#243;s&#225;gok) id&#337;ben t&#246;rt&#233;n&#337; &#233;rtes&#237;t&#233;se</p></li><li><p><strong>Transzparencia:</strong> &#336;szinte &#233;s &#225;tl&#225;that&#243; kommunik&#225;ci&#243; a bizalom meg&#337;rz&#233;se &#233;rdek&#233;ben</p></li><li><p><strong>Folyamatos t&#225;j&#233;koztat&#225;s:</strong> Rendszeres friss&#237;t&#233;sek a helyzet alakul&#225;s&#225;r&#243;l</p></li></ul><h2>Kommunik&#225;ci&#243;s csatorn&#225;k</h2><ul><li><p>Bels&#337; kommunik&#225;ci&#243;s platformok</p></li><li><p>Hivatalos k&#246;zlem&#233;nyek</p></li><li><p>Sajt&#243;kapcsolatok</p></li><li><p>K&#246;z&#246;ss&#233;gi m&#233;dia</p></li></ul><h2>Teend&#337;k</h2><ul><li><p>Kommunik&#225;ci&#243;s protokoll kidolgoz&#225;sa</p></li><li><p>V&#225;ls&#225;gkommunik&#225;ci&#243;s csapat &#246;ssze&#225;ll&#237;t&#225;sa</p></li><li><p>Sablonok &#233;s folyamatok el&#337;k&#233;sz&#237;t&#233;se</p></li><li><p>Kapcsolattart&#243;k kijel&#246;l&#233;se</p></li></ul><p>Teh&#225;t a kibert&#225;mad&#225;sok sor&#225;n a <strong>gyors &#233;s pontos kommunik&#225;ci&#243; </strong>kulcsfontoss&#225;g&#250;, <strong>&#233;rintettek azonos&#237;t&#225;sa &#233;s transzparens t&#225;j&#233;koztat&#225;s</strong> sz&#252;ks&#233;ges. K<strong>ommunik&#225;ci&#243;s protokoll kidolgoz&#225;sa &#233;s v&#225;ls&#225;gkommunik&#225;ci&#243;s csapat fel&#225;ll&#237;t&#225;sa</strong> elengedhetetlen a hat&#233;kony v&#225;laszad&#225;shoz.</p><p>Podcast epiz&#243;dunk az <a href="https://try.elevenlabs.io/it48us3gulup">ElevenLabs</a> voice generat&#237;v AI rendszer&#233;vel k&#233;sz&#252;lt.</p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p><a href="https://konbriefing.com/en-topics/cyber-attack-communication-assessment.html">https://konbriefing.com/en-topics/cyber-attack-communication-assessment.html</a></p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Sötét árnyak a Mesterséges Intelligencia világában]]></title><description><![CDATA[Generat&#237;v AI seg&#237;ts&#233;g&#233;vel k&#233;sz&#237;tett Dark Noir st&#237;lus&#250; "romantikus" vide&#243; epiz&#243;dunk egy &#250;j, az AI fejleszt&#337;ket &#233;rint&#337; t&#225;mad&#225;s megjelen&#233;s&#233;t dolgozza fel.]]></description><link>https://www.cyberthreat.report/p/sotet-arnyak-a-mesterseges-intelligencia</link><guid isPermaLink="false">https://www.cyberthreat.report/p/sotet-arnyak-a-mesterseges-intelligencia</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Sat, 08 Feb 2025 13:35:31 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/156727311/66352bd9c6606e45bcacecfb8347ca00.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberthreat.report/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">A CyberThreat Report egy olvas&#243;k &#225;ltal t&#225;mogatott kiadv&#225;ny. Ha szeretn&#233;d megkapni az &#250;j bejegyz&#233;seket &#233;s t&#225;mogatni a munk&#225;nkat, fontold meg, hogy ingyenes vagy fizet&#337;s el&#337;fizet&#337; leszel.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>A t&#225;mad&#243;k a megszokott malware terjeszt&#233;si m&#243;dszerek helyett most a fejleszt&#337;i k&#246;z&#246;ss&#233;g &#225;ltal gyakran haszn&#225;lt ML modelleket haszn&#225;lj&#225;k fel k&#225;rt&#233;kony k&#243;djuk terjeszt&#233;s&#233;re. </p><p>A Hugging Face egy sz&#233;les k&#246;rben haszn&#225;lt platform, ahol fejleszt&#337;k &#233;s kutat&#243;k g&#233;pi tanul&#225;si modelleket oszthatnak meg egym&#225;ssal. A platform n&#233;pszer&#369;s&#233;ge &#233;s ny&#237;lt jellege miatt ide&#225;lis c&#233;lpontt&#225; v&#225;lt a rosszindulat&#250; szerepl&#337;k sz&#225;m&#225;ra. A t&#225;mad&#243;k kihaszn&#225;lt&#225;k azt a t&#233;nyt, hogy a fejleszt&#337;i k&#246;z&#246;ss&#233;g &#225;ltal&#225;ban megb&#237;zik a platformon megosztott tartalmakban, &#233;s gyakran tov&#225;bbi ellen&#337;rz&#233;s n&#233;lk&#252;l haszn&#225;lj&#225;k fel azokat projektjeikben.</p><p><strong>R&#233;szletes elemz&#233;s&#252;nket itt olvashatod: </strong></p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;6e83c9e4-71a9-42b7-ba4c-843d964fcfbd&quot;,&quot;caption&quot;:&quot;A kiberbiztons&#225;g vil&#225;g&#225;ban egy &#250;j, kifinomult t&#225;mad&#225;si m&#243;dszer jelent meg, amely a n&#233;pszer&#369; g&#233;pi tanul&#225;si platformot, a Hugging Face-t veszi c&#233;lba. A t&#225;mad&#243;k a megszokott malware terjeszt&#233;si m&#243;dszerek helyett most a fejleszt&#337;i k&#246;z&#246;ss&#233;g &#225;ltal gyakran haszn&#225;lt ML modelleket haszn&#225;lj&#225;k fel k&#225;rt&#233;kony k&#243;djuk terjeszt&#233;s&#233;re.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Supply Chain t&#225;mad&#225;s a g&#233;pi tanul&#225;s vil&#225;g&#225;ban&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:122890928,&quot;name&quot;:&quot;Ferenc Fr&#233;sz&quot;,&quot;bio&quot;:&quot;Cyber security senior expert conducting cybersecurity and cyber defense capability development on numerous international fronts.&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fcd5b576-d747-4724-bdf2-51ed3225c5d3_96x96.png&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2025-02-08T12:36:53.231Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fe6f551-e2d0-4004-b70e-885616f9e60f_1920x1088.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.cyberthreat.report/p/supply-chain-tamadas-a-gepi-tanulas&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:156723653,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:0,&quot;comment_count&quot;:0,&quot;publication_id&quot;:null,&quot;publication_name&quot;:&quot;CyberThreat Report&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F50383b70-eecb-4f1b-8260-d05e48d1dbc9_256x256.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div>]]></content:encoded></item><item><title><![CDATA[Kibertámadások]]></title><description><![CDATA[A l&#225;thatatlan h&#225;bor&#250; titkai]]></description><link>https://www.cyberthreat.report/p/kibertamadasok</link><guid isPermaLink="false">https://www.cyberthreat.report/p/kibertamadasok</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Fri, 07 Feb 2025 19:14:05 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/156693673/cc96021912261ec1ab146ba270cb05b4.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Ez az epiz&#243;d az APT28 orosz &#225;llami t&#225;mad&#243; csapatr&#243;l sz&#243;l. Kik &#337;k, hogyan &#233;s kiket t&#225;madnak.</p><p>R&#233;szletes elemz&#233;s&#252;nket itt olvashatod: </p><p><a href="https://www.cyberthreat.report/p/a-gru-digitalis-karma-a-fancy-bear?r=215z8w&amp;utm_campaign=post&amp;utm_medium=web&amp;showWelcomeOnShare=false">A GRU digit&#225;lis karma: A Fancy Bear m&#369;veletei a kibert&#233;rben</a></p><p>A podcast epiz&#243;d az <a href="https://try.elevenlabs.io/it48us3gulup">ElevenLabs</a> hangalap&#250; generat&#237;v AI eszk&#246;z haszn&#225;lat&#225;val k&#233;sz&#252;lt.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.cyberthreat.report/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">A CyberThreat Report egy olvas&#243;k &#225;ltal t&#225;mogatott kiadv&#225;ny. Ha szeretn&#233;d megkapni az &#250;j bejegyz&#233;seket &#233;s t&#225;mogatni a munk&#225;mat, fontold meg, hogy ingyenes vagy fizet&#337;s el&#337;fizet&#337; leszel.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Játékosok figyelem! Veszélyes YouTube átverés terjed]]></title><description><![CDATA[A Call of Duty, Fortnite &#233;s Minecraft j&#225;t&#233;kosok k&#252;l&#246;n&#246;sen vesz&#233;lyeztetettek.]]></description><link>https://www.cyberthreat.report/p/jatekosok-figyelem-veszelyes-youtube</link><guid isPermaLink="false">https://www.cyberthreat.report/p/jatekosok-figyelem-veszelyes-youtube</guid><dc:creator><![CDATA[Ferenc Frész]]></dc:creator><pubDate>Wed, 05 Feb 2025 20:09:58 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/156549972/c5b370136dcba3e2bd8a435d4c113613.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Egy &#250;j, vesz&#233;lyes t&#225;mad&#225;si hull&#225;m s&#246;p&#246;r v&#233;gig a YouTube platformon, amely kifejezetten a j&#225;t&#233;kosk&#246;z&#246;ss&#233;get, k&#252;l&#246;n&#246;sen a Call of Duty, Fortnite &#233;s Minecraft j&#225;t&#233;kosokat c&#233;lozza meg. A csal&#243;k vonz&#243; linkeket helyeznek el YouTube vide&#243;k le&#237;r&#225;s&#225;ban, amelyek ingyenes skineket, cheateket vagy exclusive tartalmakat &#237;g&#233;rnek, val&#243;j&#225;ban azonban malware-t telep&#237;tenek &#233;s szem&#233;lyes adatokat lopnak el.</p><p>A t&#225;mad&#225;s elleni v&#233;dekez&#233;s legfontosabb elemei: csak hivatalos forr&#225;sb&#243;l t&#246;rt&#233;n&#337; let&#246;lt&#233;s, megb&#237;zhat&#243; v&#237;rusirt&#243; haszn&#225;lata, &#233;s a t&#250;l cs&#225;b&#237;t&#243; aj&#225;nlatok ker&#252;l&#233;se. Ha valaki &#225;ldozatt&#225; v&#225;lik, azonnal v&#225;ltoztassa meg jelszavait, ellen&#337;rizze banksz&#225;ml&#225;j&#225;t, &#233;s jelentse az esetet az illet&#233;kes hat&#243;s&#225;goknak.</p><h2>Mi t&#246;rt&#233;nik pontosan?</h2><p>Csal&#243;k olyan YouTube vide&#243;kat tesznek k&#246;zz&#233;, amelyek le&#237;r&#225;s&#225;ban vonz&#243; linkeket helyeznek el. Ezek &#225;ltal&#225;ban:</p><ul><li><p>Ingyenes j&#225;t&#233;k skineket &#237;g&#233;rnek</p></li><li><p>K&#252;l&#246;nleges j&#225;t&#233;kbeli el&#337;ny&#246;ket k&#237;n&#225;lnak</p></li><li><p>Cheat k&#243;dokat vagy m&#243;dos&#237;t&#243;kat rekl&#225;moznak</p></li><li><p>Exclusive tartalmakat aj&#225;nlanak fel</p></li></ul><h2>Mi&#233;rt vesz&#233;lyes ez?</h2><p>Amikor a gyan&#250;tlan felhaszn&#225;l&#243; r&#225;kattint ezekre a linkekre, t&#246;bb vesz&#233;lynek is kiteszi mag&#225;t:</p><ul><li><p>K&#225;rt&#233;kony programok telep&#252;lhetnek a sz&#225;m&#237;t&#243;g&#233;p&#233;re</p></li><li><p>Ellophatj&#225;k a j&#225;t&#233;kfi&#243;kja bejelentkez&#233;si adatait</p></li><li><p>Szem&#233;lyes &#233;s bankk&#225;rtya adatai ker&#252;lhetnek illet&#233;ktelen kezekbe</p></li><li><p>Zsarol&#243;v&#237;rus &#225;ldozat&#225;v&#225; v&#225;lhat</p></li></ul><h2>Hogyan ismerheted fel a csal&#225;st?</h2><p>Figyelj az al&#225;bbi figyelmeztet&#337; jelekre:</p><ul><li><p>T&#250;l j&#243;, hogy igaz legyen aj&#225;nlatok</p></li><li><p>S&#252;rget&#337; &#252;zenetek, mint p&#233;ld&#225;ul "Csak ma!" vagy "Utols&#243; lehet&#337;s&#233;g!"</p></li><li><p>Gyan&#250;san sok pozit&#237;v komment ugyanolyan st&#237;lusban &#237;rva</p></li><li><p>Hivatalos j&#225;t&#233;kfejleszt&#337;i oldalt&#243;l elt&#233;r&#337; domain nevek</p></li></ul><h2>Hogyan v&#233;dekezhetsz?</h2><p>A biztons&#225;god &#233;rdek&#233;ben k&#246;vesd ezeket a tan&#225;csokat:</p><ul><li><p>Csak hivatalos forr&#225;sb&#243;l (j&#225;t&#233;k &#225;ruh&#225;zakb&#243;l, fejleszt&#337;i oldalakr&#243;l) t&#246;lts le tartalmakat</p></li><li><p>Haszn&#225;lj megb&#237;zhat&#243; v&#237;rusirt&#243;t &#233;s tartsd naprak&#233;szen</p></li><li><p>Ne add meg szem&#233;lyes vagy bankk&#225;rtya adataidat ismeretlen oldalakon</p></li><li><p>Ha k&#233;ts&#233;ged van, k&#233;rdezz r&#225; a j&#225;t&#233;kos k&#246;z&#246;ss&#233;gekben, miel&#337;tt b&#225;rmire r&#225;kattintan&#225;l</p></li></ul><h2>Mit tegy&#233;l, ha m&#225;r &#225;ldozatt&#225; v&#225;lt&#225;l?</h2><p>Ha &#250;gy gondolod, hogy m&#225;r &#225;ldozatul est&#233;l egy ilyen t&#225;mad&#225;snak:</p><ul><li><p>Azonnal v&#225;ltoztasd meg minden &#233;rintett fi&#243;kod jelszav&#225;t</p></li><li><p>Ellen&#337;rizd a banksz&#225;ml&#225;dat gyan&#250;s tev&#233;kenys&#233;gek ut&#225;n kutatva</p></li><li><p>Futtass teljes v&#237;ruskeres&#233;st a sz&#225;m&#237;t&#243;g&#233;peden</p></li><li><p>Jelentsd az esetet a platform &#252;zemeltet&#337;j&#233;nek &#233;s a hat&#243;s&#225;goknak</p></li></ul><p>A j&#225;t&#233;k&#233;lm&#233;ny fontos, de a biztons&#225;god m&#233;g fontosabb. L&#233;gy &#243;vatos &#233;s gondolkodj, miel&#337;tt kattintasz!</p><div><hr></div><p><strong>Eml&#233;keztet&#337;:</strong> A hivatalos j&#225;t&#233;kfejleszt&#337;k soha nem k&#233;rnek p&#233;nzt vagy szem&#233;lyes adatokat YouTube vide&#243;k kommentszekci&#243;j&#225;ban vagy k&#252;ls&#337; oldalakon kereszt&#252;l.</p><div><hr></div><div class="poll-embed" data-attrs="{&quot;id&quot;:268775}" data-component-name="PollToDOM"></div><p></p><p><strong>Felhaszn&#225;lt forr&#225;s: </strong><a href="https://www.forbes.com/sites/daveywinder/2025/02/02/critical-youtube-hack-warning-cod-fortnite-minecraft-gamers-at-risk/">https://www.forbes.com/sites/daveywinder/2025/02/02/critical-youtube-hack-warning-cod-fortnite-minecraft-gamers-at-risk/</a></p>]]></content:encoded></item></channel></rss>