Top 11 books on digital forensics, incident response, and malware analysis
Introduction
I was recently on a mobile assessment where you could only register one profile on the app, per device. To use another account you had to first deactivate the profile and then register a new one....
While working on DoubleAgent as part of the Introduction To Red Teaming course we’re developing for RingZer0, I had a look at Anti-Malware Scan Interface (AMSI) bypasses. One of the objectives I...
Read about the value of Huntress' Ransomware Canaries service, a mechanism to deliver faster detection of a ransomware incident.
Exposed session token in Honeywell ControlEdge PLC and RTU.
Unencrypted password transmission on the network in Honeywell ControlEdge PLC and RTU.
On June 16th, the Department of Homeland Security and CISA ICS-CERT issued a critical security advisory warning covering multiple newly discovered vulnerabilities affecting... The post Ripple20...
At Huntress, our goal is not only to chase after changing threats but to remove obstacles that get in the way of new security innovation.
SmokeLoader is a well known bot that is been around since 2011. It’s mainly used to drop other malware families. SmokeLoader has been under development and is constantly changing with multiple...
On 2020-06-19, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.
In 2019, McAfee Advanced Threat Research (ATR) disclosed a vulnerability in a product called BoxLock. Sometime after this, the CEO... The post My Adventures Hacking the iParcelBox appeared first...
Package delivery is just one of those things we take for granted these days. This is especially true in the... The post What’s in the Box? Part II: Hacking the iParcelBox appeared first on McAfee Blog.
There’s no end to the stealthy ways in which attackers develop and execute their tradecraft. In this case, it's as simple as hiding in plain sight.
According to Kaspersky ICS CERT data, a number of industrial companies are currently experiencing targeted attacks involving the Snake encryption ransomware.
Kaspersky ICS CERT has identified a series of attacks targeting, among others, organizations in various industrial sectors. Victims include suppliers of equipment and software for industrial enterprises.
How do we calculate the total impact of a data breach? Visit the Huntress Blog to learn more about how cyber security awareness training can help to mitigate risk.
EXECUTIVE SUMMARY The RagnarLocker ransomware first appeared in the wild at the end of December 2019 as part of a... The post RagnarLocker Ransomware Threatens to Release Confidential Information...
There are number of ways scammers use to target personal information and, currently, one example is, they are taking advantage... The post OneDrive Phishing Awareness appeared first on McAfee Blog.
Kent and Jordan are back to continue their journey to make the world a better place. This time around, they will be reviewing a series of tools commonly used on […] The post Webcast: A Blue Team’s...
Intro The last few months I’ve been studying Chrome’s v8 internals and exploits with the focus of finding a type confusion bug. The good news is that I found one, so the fuzzing and analysis...
When ice burns through bank accounts
Vulnerabilities that can lead to unsanctioned account access or remote code execution.
Kaspersky ICS CERT has discovered vulnerabilities that may allow threat actors to modify configuration files, execute arbitrary code remotely or access user passwords.
On May 28, 2020, the NSA released a cybersecurity advisory on Russian APT group Sandworm exploiting CVE-2019-10149, a vulnerability in Exim Mail Transfer Agent (MTA) software. An unauthenticated...
Intro Last year I wrote how to weaponize CVE-2018-19204. This blog post will continue and elaborate on the finding and analysis of two additional vulnerabilities that were discovered during the...
Victims included a railway stock manufacturer, an electric utility company and a steel producer. One incident brought operations to a halt
Missing Authentication in Emerson OpenEnterprise SCADA versions before 3.3.4 might lead to arbitrary code execution. The affected components may allow an attacker to run an arbitrary commands with...
Inadequate Encryption Strength in Emerson OpenEnterprise SCADA versions before 3.3.4.
Improper Ownership Management in Emerson OpenEnterprise SCADA versions before 3.3.4.