153
submitted 1 year ago* (last edited 1 year ago) by queue to c/technology@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[-] spaghettiwestern@sh.itjust.works 99 points 1 year ago

Correct me if I'm wrong, but this doesn't look like this has anything to do with Syncthing vulnerabilities. Instead it looks like a hack that uses a preconfigured Syncthing installation to transfer sensitive data. Disturbing nonetheless.

[-] just_another_person@lemmy.world 72 points 1 year ago

It's a Phishing scam using a tool. It's no more exploiting SyncThing than TCP/IP.

[-] Holzkohlen@feddit.de 12 points 1 year ago

Bet they also utilize electricity these bastards! What's next? Physics? Oh the humanity!

[-] blackbarn@lemm.ee 9 points 1 year ago

Just like using a remote desktop tool in a scam I suppose

[-] treadful@lemmy.zip 5 points 1 year ago

Looks like a specially modified SyncThing was just used for exfil.

[-] Deebster@programming.dev 17 points 1 year ago

The article uses the word modified, but it sounds like it's just talking about configuring it and using it as normal.

[-] vext01@lemmy.sdf.org 2 points 1 year ago
this post was submitted on 08 Jun 2024
153 points (100.0% liked)

Technology

71269 readers
2561 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS