IM
IronMonkey Threat Research
LIVE
|
Articles 27,094
|
CVEs 349,153
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,064 articles — Page 849 of 903
Wiz Blog | RSS feed ·

Wiz presents a comprehensive guide to mastering cloud security at financial services organizations.

Financial Services Information Technology
Cloud Threat Landscape ·

On 2024-03-21, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting S3 Bucket to achieve Resp. disclosure.

Threat Intelligence ·

Written by: Michael Raggi, Adam Aprahamian, Dan Kelly, Mathew Potaczek, Marcin Siedlarz, Austin Larsen During the course of an intrusion investigation in late October 2023, Mandiant observed novel...

Information Technology Government Facilities Threat Intelligence
Wiz Blog | RSS feed ·

Use the Wiz App to consume and analyze data more easily in Splunk via a dedicated dashboard.

Information Technology
Wiz Blog | RSS feed ·

Organizations can now improve their mean time to remediate (MTTR) with AI-generated remediation steps.

Information Technology
Kaspersky ICS CERT ·

The statistical data presented in the report was received from ICS computers protected by Kaspersky products that Kaspersky ICS CERT categorizes as part of the industrial infrastructure at organizations.

Critical Manufacturing Publications
Cloud Threat Landscape ·

On 2024-03-19, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using LOLBin abuse, targeting TeamCity to achieve Resource hijacking,...

Wiz Blog | RSS feed ·

Secure your applications across the SDLC by deploying only trusted images and monitoring your Kubernetes control plane in near-real time to detect potential threats.

Energy Financial Services
Maxwell Dulin's Resources ·

Locks being controlled by computers are great, until you realize that they are subject to security vulnerabilities like everything else. This post goes through hacking a smart lock through various...

Cloud Threat Landscape ·

Aiohttp is a widely used open-source library for handling concurrent HTTP requests in Python applications. The ransomware group ShadowSyndicate, has been scanning for servers vulnerable to...

maxwelldulin ·

The Content Security Policy (CSP) is a mechanism for restrictions various components of a web page to prevent attacks. Github had revamped their CSP in 2016 and this is their article explaining...

McAfee Labs | McAfee Blogs ·

Authored by ZePeng Chen and Wenfeng Yu McAfee Mobile Research Team has observed an active scam malware campaign targeting Android... The post Android Phishing Scam Using Malware-as-a-Service on...

Financial Services Healthcare and Public Health
Wiz Blog | RSS feed ·

Oracle Cloud Infrastructure customers can now effectively protect their sensitive data with Wiz’s Data Security Posture Management (DSPM) capabilities.

Information Technology
Wiz Blog | RSS feed ·

NamespaceHound is an open-source tool for detecting the risk of potential namespace crossing violations and anonymous access opportunities in multi-tenant clusters.

Information Technology Financial Services
Maxwell Dulin's Resources ·

GPUs are parallel and fast co-processors. They are designed to handle high throughout graphics and machine learning workloads. GPUs are made up of compute units for various computations, all of...

maxwelldulin ·

Sonar Source people go crazy on web security issues! Definitely one of the best blogs to read through for cutting edge security research. In this case, they have a wild XSS in the Joomla CMS. The...

Government Facilities
Maxwell Dulin's Resources ·

Multi-signature wallets are a mechanism to defend against a single key compromise leading to the stealing of all funds. Additionally, it's common for timelocks to exist to allow for auditing of...

Information Technology
Maxwell Dulin's Resources ·

Being able to debug live code deployed on mainnet is a real pain in the butt. So, this is a strategy to do that. First, fork the chain you want to work with using Foundry. This gives us control...

Information Technology
GreyNoise Labs ·

In January/2024, a new vulnerability burst onto the scene - CVE-2023-22527. As the next rising star, it came in with a blast, turning heads and creating buzz. “Atlassian Confluence bugs are often...

Financial Services confluence backdoor
Wiz Blog | RSS feed ·

Monitor code for sensitive data to reduce the risk of accidental exposure or compliance violation.

Financial Services Healthcare and Public Health
Wiz Blog | RSS feed ·

Test your investigation skills and K8s network knowledge in a new CTF event: the K8s LAN Party Challenge!

Information Technology
maxwelldulin ·

Carriage Return - Line Feed (CRLF) or response splitting is a vulnerability where a newline can be added to an HTTP response in order to modify it. For instance, it can be used to change incoming...

Pulsedive Blog ·

Pulsedive is rolling out plan and pricing updates to Community products starting on March 11, 2024.

Cloud Threat Landscape ·

Researchers uncovered a malicious campaign targeting the Meson Network, a decentralized content delivery network (CDN) that leverages blockchain for bandwidth marketplace operations. This campaign...

Information Technology Transportation Systems
maxwelldulin ·

Seneca did virtually everything wrong and then got hacked. So, sort of a funny setup. Seneca was supposed to do an audit with Sherlock but was suddenly closed for code licensing issues. They...

Healthcare and Public Health
maxwelldulin ·

Woo is some sort of finance platform that is on various blockchains. Recently, they had deployed everything on Arbitrum. WOOFi has a system that adjusts the oracle prices based on trade value. By...

GreyNoise Labs ·

Introduction This blog will cover some basic vulnerability discovery methods for developing detections. In early February, Fortinet published two reports warning users of CVE-2024-23113 and...

fortinet vulnerabilities
Cloud Threat Landscape ·

On 2024-03-08, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting S3 Bucket to achieve Resp. disclosure.

Cloud Threat Landscape ·

On 2024-03-08, a campaign was reported, involving Magnet Goblin, gaining initial access via 1-day vulnerability, targeting Ivanti Connect Secure VPN, Apache ActiveMQ, Magento, Qlink Sense with...

Wiz Blog | RSS feed ·

In a recent webinar hosted by Wiz, three esteemed CISOs shared their strategies for getting C-suite executives on board with plans for a comprehensive security program.

Information Technology