IM
IronMonkey Threat Research
LIVE
|
Articles 27,143
|
CVEs 349,423
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,111 articles — Page 851 of 904
Wiz Blog | RSS feed ·

NamespaceHound is an open-source tool for detecting the risk of potential namespace crossing violations and anonymous access opportunities in multi-tenant clusters.

Information Technology Financial Services
Maxwell Dulin's Resources ·

GPUs are parallel and fast co-processors. They are designed to handle high throughout graphics and machine learning workloads. GPUs are made up of compute units for various computations, all of...

maxwelldulin ·

Sonar Source people go crazy on web security issues! Definitely one of the best blogs to read through for cutting edge security research. In this case, they have a wild XSS in the Joomla CMS. The...

Government Facilities
Maxwell Dulin's Resources ·

Multi-signature wallets are a mechanism to defend against a single key compromise leading to the stealing of all funds. Additionally, it's common for timelocks to exist to allow for auditing of...

Information Technology
Maxwell Dulin's Resources ·

Being able to debug live code deployed on mainnet is a real pain in the butt. So, this is a strategy to do that. First, fork the chain you want to work with using Foundry. This gives us control...

Information Technology
GreyNoise Labs ·

In January/2024, a new vulnerability burst onto the scene - CVE-2023-22527. As the next rising star, it came in with a blast, turning heads and creating buzz. “Atlassian Confluence bugs are often...

Financial Services confluence backdoor
Wiz Blog | RSS feed ·

Monitor code for sensitive data to reduce the risk of accidental exposure or compliance violation.

Financial Services Healthcare and Public Health
Wiz Blog | RSS feed ·

Test your investigation skills and K8s network knowledge in a new CTF event: the K8s LAN Party Challenge!

Information Technology
maxwelldulin ·

Carriage Return - Line Feed (CRLF) or response splitting is a vulnerability where a newline can be added to an HTTP response in order to modify it. For instance, it can be used to change incoming...

Pulsedive Blog ·

Pulsedive is rolling out plan and pricing updates to Community products starting on March 11, 2024.

Cloud Threat Landscape ·

Researchers uncovered a malicious campaign targeting the Meson Network, a decentralized content delivery network (CDN) that leverages blockchain for bandwidth marketplace operations. This campaign...

Information Technology Transportation Systems
maxwelldulin ·

Seneca did virtually everything wrong and then got hacked. So, sort of a funny setup. Seneca was supposed to do an audit with Sherlock but was suddenly closed for code licensing issues. They...

Healthcare and Public Health
maxwelldulin ·

Woo is some sort of finance platform that is on various blockchains. Recently, they had deployed everything on Arbitrum. WOOFi has a system that adjusts the oracle prices based on trade value. By...

GreyNoise Labs ·

Introduction This blog will cover some basic vulnerability discovery methods for developing detections. In early February, Fortinet published two reports warning users of CVE-2024-23113 and...

fortinet vulnerabilities
Cloud Threat Landscape ·

On 2024-03-08, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting S3 Bucket to achieve Resp. disclosure.

Cloud Threat Landscape ·

On 2024-03-08, a campaign was reported, involving Magnet Goblin, gaining initial access via 1-day vulnerability, targeting Ivanti Connect Secure VPN, Apache ActiveMQ, Magento, Qlink Sense with...

Wiz Blog | RSS feed ·

In a recent webinar hosted by Wiz, three esteemed CISOs shared their strategies for getting C-suite executives on board with plans for a comprehensive security program.

Information Technology
Blue Team Archives - Black Hills Information Security, Inc. ·

Be sure to read PART 1! Metadata and a New-Fashioned Bank Robbery Let’s face it, some cases are just more interesting than others and, when you do incident response for […] The post OSINT for...

Financial Services Information Technology Incident Response Informational
Threat Analysis Group (TAG) ·

This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q1 2024. It was last updated on July 8, 2024.JanuaryWe blocked 4 domains …

Wiz Blog | RSS feed ·

Detect and mitigate CVE-2024-27198 (CVSS score: 9.8) and CVE-2024-27199 (CVSS score: 7.3), authentication bypass vulnerabilities in JetBrains TeamCity.

@BushidoToken Threat Intel ·

In this blog, we shall investigate a Russia-based mercenary group that has appeared in multiple CERT-UA reports after sending waves of spam to Ukrainian organisations. These mercenaries use tried...

Armageddon Fancy Bear Financial Services Energy
Wiz Blog | RSS feed ·

Wiz customers can now secure everything they build and run on Akamai Linode Cloud, providing organizations the broadest cloud coverage out of any CNAPP

Information Technology Chemical
Cloud Threat Landscape ·

Researchers observed threat actor z0Miner targeting Korean WebLogic servers as download servers for distributing malware, including miners and network tools. It is recommended to look for...

Cloud Threat Landscape ·

On 2024-03-06, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, to achieve Data exfiltration.

Financial Services
Cloud Threat Landscape ·

Researchers observed threat actors exploiting misconfiguration in servers running Apache Hadoop YARN, Docker, Confluence, or Redis with new Golang-based malware, which uses worm-like behavior to...

Threat Intelligence ·

Written by: Aseel Kayal During the analysis of a banking trojan sample targeting Android smartphones, Mandiant identified the repeated use of a string obfuscation mechanism throughout the...

Financial Services Information Technology Threat Intelligence
ICS Medical Advisories ·

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.8 ATTENTION: Low attack complexity Vendor: Santesoft Equipment: Sante FFT Imaging Vulnerability: Out-of-Bounds Write 2. RISK EVALUATION Successful...

Critical Manufacturing Healthcare and Public Health
maxwelldulin ·

Facebook has an extra security mechanism after logging in to ensure the user is valid. This could be a captcha, MFA but is commonly referred to as a chcekpoint. This is implemented within an...

maxwelldulin ·

SolChat claimed to be an encrypted chat application and audio calls using WebRTC. So, the author decided to take a look at it. They first took to reviewing the JavaScript code. Since the JS map...

maxwelldulin ·

In the first two posts they found two vulnerabilities that were already patched in LayerZero. This time, they go through a vulnerability in a different section of code. When calling an external...

Energy Financial Services