IM
IronMonkey Threat Research
LIVE
|
Articles 27,320
|
CVEs 351,673
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,291 articles — Page 859 of 910
@BushidoToken Threat Intel ·

IntroductionA Chinese Ministry of Public Security (MPS) contractor called iSOON (also known as Anxun Information) that specializes in network penetration research and related services has had its...

Shadow Brokers Poison Carp Red Scylla Healthcare and Public Health Information Technology
Bitdefender Labs ·

CVE-2024-23204 sheds light on the critical importance of continuous security vigilance. Apple's Shortcuts application, designed to enhance user automation, can inadvertently become a potential...

Bitdefender Labs ·

CVE-2024-23204 sheds light on the critical importance of continuous security vigilance. Apple's Shortcuts application, designed to enhance user automation, can inadvertently become a potential...

Cloud Threat Landscape ·

Researchers identified a malicious campaign focusing on Apache big-data solutions, particularly Apache Hadoop and Apache Druid. This campaign leverages the Lucifer DDoS botnet, infecting Linux...

Wiz Blog | RSS feed ·

We explore “proof-of-storage" cryptocurrencies like Chia, the potential for proof-of-storage cryptojacking attacks, and steps defenders can take to detect them.

Financial Services Information Technology
Cloud Threat Landscape ·

On 2024-02-21, a research was reported, involving , gaining initial access via Insider threat, to achieve Resp. disclosure.

Cloud Threat Landscape ·

On 2024-02-21, an incident was reported, involving an unknown actor, gaining initial access via Unknown, while using Data exfiltration from cloud storage, targeting S3 Bucket to achieve Data...

Uncategorized - bellingcat ·

Satellite images newly obtained by Bellingcat shed light on how a stranded barge at the centre of a major oil spill ended up aground and leaking oil off the Tobago coast. The post How a Leaking...

Energy Communications Americas Investigations
Cloud Threat Landscape ·

A new campaign named Migo targeting Redis servers running on Linux hosts to mine cryptocurrency. The campaign was identified following suspicious activities on a Redis honeypot, where a malicious...

Financial Services
Cloud Threat Landscape ·

On 2024-02-20, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using SSH propagation, targeting Confluence Server to achieve Resource...

Orange Cyberdefense ·

I created a small crypto style CTF for Black Hat last year (we’re training again this year, check our courses out) and hid the starting point in an “easter egg” on a deck of cards. The deck of...

Cloud Threat Landscape ·

On 2024-02-18, a research was reported, involving , gaining initial access via Software misconfig, to achieve Resp. disclosure.

Commercial Facilities
maxwelldulin ·

Last year, a web cache deception caching vulnerability was discovered in ChatGPT. The vulnerability was that anything ending in a particular file type was cached but it had a fuzzy path...

security – Ars Technica ·

Feds once again fix up compromised retail routers under court order.

APT 2 Sofacy APT 28 Critical Manufacturing Nuclear
security – Ars Technica ·

Disagreement over security disclosures and bug-fixing priorities led to split.

Nuclear Communications
Wiz Blog | RSS feed ·

In cloud security, the most compelling love story is the one between developers and security teams. This Valentine’s Day, let's shine a spotlight on these dynamic duos.

Information Technology
maxwelldulin ·

The Polygon proof of stake network relies on three different parts: a consensus layer called Heimdall, an execution layer called Bor (fork of Geth) and a set of smart contracts. For this...

Transportation Systems Energy
maxwelldulin ·

Within the Olympus ecosystem, they have three different price feeds that can be used. If one of them reverts, then it simply uses the other ones. So, what could possibly go wrong? The key to the...

maxwelldulin ·

Before even diving into the target itself, the author goes through how they themselves pick a target. Ecosystem: the more mature the thing, the more bugs it's going to have. TVL range: very large,...

Commercial Facilities Energy
Cloud Threat Landscape ·

On 2024-02-15, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve Resource hijacking. The following tools...

maxwelldulin ·

JumpServer is a privileged access management (PAM) system that is open source. Typically, a jump server is a server that can be connected to from the outside world in order to talk to internal and...

Bitdefender Labs ·

Bitdefender Labs has been keeping up with the latest modus operandi of cybercrooks who adapt emerging technologies to siphon money from consumers. Artificial intelligence is just one of the many...

Financial Services Transportation Systems
Bitdefender Labs ·

Bitdefender Labs has been keeping up with the latest modus operandi of cybercrooks who adapt emerging technologies to siphon money from consumers. Artificial intelligence is just one of the many...

Financial Services Transportation Systems
Threat Analysis Group (TAG) ·

blue squares forming the abstract shape of an arrow set against a white background

Commercial Facilities Financial Services
Threat Analysis Group (TAG) ·

blue squares forming the abstract shape of an arrow set against a white background

Commercial Facilities Defense Industrial Base Safety & Security Threat Analysis Group
Cloud Threat Landscape ·

On 2024-02-14, a research was reported, involving , gaining initial access via Cloud native misconfig, while using Cloud key compromise, targeting Azure Storage to achieve Resp. disclosure.

Cloud Threat Landscape ·

On 2024-02-14, a research was reported, involving , gaining initial access via Software misconfig, targeting Ansible, NGINX to achieve Resp. disclosure.

Blog | Threat Intelligence & Memory Forensics | Volexity ·

Through its managed security services offerings, Volexity routinely identifies spear-phishing campaigns targeting its customers. One persistent threat actor, whose campaigns Volexity frequently...

Charming Kitten Mint Sandstorm CharmingCypress Critical Manufacturing
Cloud Threat Landscape ·

Water Hydra group (AKA DarkCasino), whose activity was first detected in 2021, is known for their cyberattacks targeting the financial industry globally, including banks, cryptocurrency platforms,...

Evilnum Water Hydra Financial Services
Cloud Threat Landscape ·

On 2024-02-13, an incident was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Confluence Server to achieve Data exfiltration.