IM
IronMonkey Threat Research
LIVE
|
Articles 25,474
|
CVEs 338,055
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,442 articles — Page 848 of 849
McAfee Labs | McAfee Blogs ·

Authored by: Sang Ryol Ryu and Chanung Pak McAfee Mobile Research team has found another variant of MalBus on an... The post MalBus Actor Changed Market from Google Play to ONE Store appeared...

Financial Services Commercial Facilities
Blog ·

In order to learn about serverless architecture, I experimented with implementing a quick proof of concept crash triaging tool using AWS Lambda Functions. There are many benefits of serverless...

Lambda Serverless
Cloud Threat Landscape ·

On 2020-04-08, a campaign was reported, involving an unknown actor, gaining initial access via , targeting Kubernetes to achieve Resource hijacking.

Financial Services
McAfee Labs | McAfee Blogs ·

While not a new practice, the sheer volume of people required to adhere to social distancing best practices means we... The post Transitioning to a Mass Remote Workforce – We Must Verify Before...

Financial Services Commercial Facilities
McAfee Labs | McAfee Blogs ·

Although the use of global events as a vehicle to drive digital crime is hardly surprising, the current outbreak of... The post COVID-19 Threat Update – now includes Blood for Sale appeared first...

Lead Financial Services Commercial Facilities
Kaspersky ICS CERT ·

In the past month, 10 more hospitals have fallen victim to Ryuk attacks in the US

Healthcare and Public Health Publications
Blog ·

Recently Apple patched a vulnerability (CVE-2020-3919) in IOHIDFamily in their security update 10.15.4 which may allow a malicious application to execute arbitrary code with kernel privileges. It...

Apple XNU
Orange Cyberdefense ·

Introduction Recently, I encountered a fully password-less environment. Every employee in this company had their own smart card that they used to login into their computers, emails, internal...

Kaspersky ICS CERT ·

We found just three almost unique samples, all in one country. So we consider the attacks to be targeted and have currently named this operation WildPressure.

Publications
Kaspersky ICS CERT ·

LibVNC client code contains heap buffer overflow vulnerability in commit prior to 6073771eed1caf72f196e410182471e0dfd32149. This could possible result into remote code execution. This attack...

Advisories
Kaspersky ICS CERT ·

TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readSetCursor. This vulnerability occurs due to insufficient sanitization of...

Advisories
Kaspersky ICS CERT (English) ·

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Exploitation of this vulnerability could potentially result into remote code...

Advisories
Kaspersky ICS CERT (English) ·

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDecoder due to incorrect value checks. Exploitation of this vulnerability...

Advisories
Kaspersky ICS CERT (English) ·

TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack memory in ZRLEDecoder. If decoding routine would throw an exception,...

Advisories
Kaspersky ICS CERT (English) ·

TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::decodeRect. Vulnerability occurs due to the signdness error in processing...

Advisories
Kaspersky ICS CERT (English) ·

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server version 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1...

Critical Manufacturing Advisories
Kaspersky ICS CERT (English) ·

Moxa’s cellular management software OnCell Central Manager Version lower than 2.4.1 was affected to XML External Entity (XXE) due to vulnerable third-party component usage (Apache Flex BlazeDS).

Communications Transportation Systems Advisories
Kaspersky ICS CERT (English) ·

Moxa’s cellular management software OnCell Central Manager Version lower than 2.4.1 was affected to Remote Code Execution due to vulnerable third-party component usage (Apache Flex BlazeDS).

Communications Transportation Systems Advisories
Orange Cyberdefense ·

Intro In this blog post I want to show a simulation of a real-world Resource Based Constrained Delegation attack scenario that could be used to escalate privileges on an Active Directory domain. I...

Tick Information Technology
Orange Cyberdefense ·

Intro Last Christmas I was doing quite a bit of research around an exploit for Chrome’s JavaScript engine, V8. While most of the concepts around the exploit might seem familiar: for example, what...

Energy Food and Agriculture
Blue Team Archives - Black Hills Information Security, Inc. ·

Do you know what your attackers know? There’s a good chance you know, but you might not be aware of just how much information can be found historically and in […] The post Webcast: Enterprise...

Communications Information Technology Author Blue Team
Blog ·

This article will show some initial research into booting a KSAN kernel, testing the KASAN functionality and some initial groundwork on KSANCOV. This functionality is super useful when performing...

Apple XNU
Kaspersky ICS CERT (English) ·

Beijing, 23-27 December 2019: Kaspersky ICS CERT together with the China Industrial Control Systems Cyber Emergency Response Team (CIC) conducted a training course on digital forensics and...

Critical Manufacturing Emergency Services Events
nao_sec ·

Abstract Several targeted attack groups share the tools used in the attack and are reported to be doing similar attacks. Attack tools are also shared in attacks targeting Japanese organizations,...

Goblin Panda
Report Feed ·

A summary of the NCSC’s security analysis for the UK telecoms sector

Communications Information Technology
Orange Cyberdefense ·

Hacking PlayStation DualShock controllers to stream audio to their internal speakers. Ciao a tutti. Introduction I didn’t really know what this project was going to be about and where or how it...

Communications Critical Manufacturing
Terrorism Archives - Security Affairs ·

US military claims to have disrupted the online propaganda activity of the Islamic State (ISIS) in a hacking operation dating back at least to 2016. In 2016, the US Cyber Command carried out...

Lotus Blossom Silk Typhoon Communications
Kaspersky ICS CERT (English) ·

The company has been forced to stop its operations almost completely. Production recovery will take at least a week

Publications
Cloud Threat Landscape ·

On 2020-01-16, a campaign was reported, involving Kinsing operator, gaining initial access via Software misconfig, 1-day vulnerability, while using Vulnerability exploitation, Misconfigured Docker...

Kaspersky ICS CERT ·

Dustman is an upgraded version of the ZeroCleare wiper. The attack exploited a vulnerability in VPN appliances

Energy Publications