IM
IronMonkey Threat Research
LIVE
|
Articles 30,305
|
CVEs 370,538
|
APT Groups 581
|
Tools 2,196
|
Updated recently
Today Yesterday All 30,273 articles — Page 1002 of 1010
Wiz Blog | RSS feed ·

Cloud identity permissions are complex. So complex that innocent looking permissions provided to 3rd party vendors can lead to unintended exposure of all of your data.

Critical Manufacturing Information Technology
Wiz Blog | RSS feed ·

With an estimated 90% of cloud workloads running Linux based OS, with sudo being common across distributions, many Linux cloud assets are at risk and may be affected. Versions released as far back...

Information Technology
Kaspersky ICS CERT ·

Siemens has released a security alert which describes some cases of SCALANCE X-200/X-200IRT/X-300 switches using hardcoded encryption keys, making them prone to man-in-the-middle attacks

Publications
Wiz Blog | RSS feed ·

SolarWinds attack explained by Wiz CTO Ami Luttwak

Information Technology Government Facilities
Orange Cyberdefense ·

In this post I want to share two things. First, a quick primer on how you would you go about navigating the source code when contributing to objection, and secondly an application specific proxy...

Healthcare and Public Health
Kaspersky ICS CERT ·

Weak implementation of cryptographic data protection allows various types of attacks and enables attackers to identify the key in captured traffic

Publications
Orange Cyberdefense ·

It’s too easy when hacking, to assume something is invulnerable and not interrogate it. This was the case for me when it came to Duo’s two-factor authentication solution. However, we were able to...

McAfee Labs | McAfee Blogs ·

McAfee’s Advanced Threat Research team just completed its second annual capture the flag (CTF) contest for internal employees. Based on tremendous... The post McAfee ATR Launches...

Financial Services Commercial Facilities
Kaspersky ICS CERT ·

Vulnerabilities in Schneider Electric’s low-voltage distribution system configuration software could enable attackers to upload arbitrary files defining electrical system parameters

Publications
Kaspersky ICS CERT ·

Sсhneider Electric has published an advisory on a critical vulnerability in the web server used in TM3 I/O expansion modules

Publications
Kaspersky ICS CERT ·

The vulnerability could cause a Windows local user privilege escalation when using EcoStruxure™ Operator Terminal Expert and Pro-face BLUE software and WinGP runtime environment by Schneider Electric.

Critical Manufacturing Publications
Kaspersky ICS CERT (English) ·

DoS vulnerabilities have been disclosed in the integrated web server of Siemens SCALANCE X-200 / X-200IRT / X-300 switches. Measures proposed by the vendor do not prevent all possible attacks.

Publications
Kaspersky ICS CERT (English) ·

How many industrial organizations had installed backdoored SolarWinds versions? We present the results of our analysis.

Publications
Group-IB Blog ·

Forensic examination of incidents involving source code leaks

Huntress Blog ·

Read about Huntress’ Managed Antivirus service and how it enables MSPs and IT admins to strengthen endpoint protection and rebalance their cyber stack.

Information Technology
Cloud Threat Landscape ·

See Dreambus operator for more information.

Report Feed ·

Technical report on best practice use of this fundamental data routing protocol.

Information Technology Communications
Huntress Blog ·

Microsoft Defender Antivirus is among one of the leading antivirus contenders. Here’s why it’s worth taking another look at Defender AV.

Information Technology
Huntress Blog ·

Microsoft Defender Antivirus is among one of the leading antivirus contenders. Here’s why it’s worth taking another look at Defender AV.

Information Technology
McAfee Labs | McAfee Blogs ·

Depending on your life experiences, the phrase (or country song by Eric Church) “two pink lines” may bring up a... The post Two Pink Lines appeared first on McAfee Blog.

Financial Services Commercial Facilities
McAfee Labs | McAfee Blogs ·

As we gratefully move forward into the year 2021, we have to recognise that 2020 was as tumultuous in the... The post A Year in Review: Threat Landscape for 2020 appeared first on McAfee Blog.

Financial Services Commercial Facilities
McAfee Labs | McAfee Blogs ·

The December 2020 revelations around the SUNBURST campaigns exploiting the SolarWinds Orion platform have revealed a new attack vector –... The post 2021 Threat Predictions Report appeared first...

Charming Kitten Government Facilities Financial Services
Huntress Blog ·

Learn manual malware analysis techniques used by threat researchers. Explore static & dynamic analysis, reverse engineering tools, and real-world investigation methods.

Information Technology
Low-level adventures ·

It has been a while since I did some hardware hacking, and this time I want to review the basics. The LinkSys EA6100 router intrigued me since I was only able to find encrypted firmware images (or...

Communications Critical Manufacturing
nao_sec ·

Abstract We introduced the “Royal Road RTF Weaponizer” in our previous blog [1] (and presented at Japan Security Analyst Conference 2020 and CPX 360 CPRCon 2020). Royal Road is a tool shared by...

Huntress Blog ·

At Huntress, beta means learning. Our goal is to accelerate and streamline security defense, which means releasing what we’re working on often.

Information Technology
Group-IB Blog ·

As part of UltraRank's new campaign, Group-IB Threat Intelligence team discovered 12 eCommerce websites infected with their JavaScript-sniffer.

Tick UltraRank Information Technology
Blog ·

Inspired by Kevin Backhouse’s great work on finding XNU remote vulnerabilities I decided to spend some time looking at CodeQL and performing some variant analysis. This lead to the discovery of a...

Communications Apple XNU
Huntress Blog ·

We take a look back at some of the more interesting — and innovative — hacker tradecraft we saw over the course of 2020.

Information Technology
McAfee Labs | McAfee Blogs ·

In a blog post released 13 Dec 2020, FireEye disclosed that threat actors compromised SolarWinds’s Orion IT monitoring and management... The post How A Device to Cloud Architecture Defends Against...

Information Technology