IM
IronMonkey Threat Research
LIVE
|
Articles 28,005
|
CVEs 357,506
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,973 articles — Page 873 of 933
Wiz Blog | RSS feed ·

Learn how Wiz's latest feature identifies outdated EKS clusters, helping organizations save millions on cloud spend. Find out how to optimize costs and reinvest savings in strategic initiatives.

Energy
Wiz Blog | RSS feed ·

Great news for State and Local Governments! Wiz for Gov is now StateRAMP authorized

Government Facilities Information Technology
Cloud Threat Landscape ·

On 2024-06-05, a campaign was reported, involving Gitloker, gaining initial access via End-user compromise, while using Repo encryption for extortion, targeting GitHub to achieve RansomOp.

Cloud Threat Landscape ·

Club Penguin fans hacked a Disney Confluence server to obtain information about their favorite game, but ended up with 2.5 GB of internal corporate data. Club Penguin, a popular MMO from 2005 to...

Cloud Threat Landscape ·

On 2024-06-05, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Vulnerability exploitation, targeting ThinkPHP to achieve Resource...

Threat Analysis Group (TAG) ·

Our bulletin covering coordinated influence operation campaigns terminated on our platforms in Q2 2024.

Defense Industrial Base
Pulsedive Blog ·

This research examines the distribution mechanisms, C2 traffic patterns, and functionality of Latrodectus loader.

Cloud Threat Landscape ·

On 2024-06-04, a campaign was reported, involving UTG-Q-008, gaining initial access via Password attack, while using SSH bruteforcing, to achieve Resource hijacking.

Cloud Threat Landscape ·

Researchers uncovered a new campaign using Muhstik malware to target Apache RocketMQ, a distributed messaging platform, exploiting a remote code execution vulnerability (CVE-2023-33246). Attackers...

Kaspersky ICS CERT ·

A total of 30 incidents were confirmed by victims. 37% of victims reported denial of operations or product shipment caused by the incident. Almost half of all incidents resulted in disruption of...

Critical Manufacturing Publications
McAfee Labs | McAfee Blogs ·

Authored by Dexter Shin Many government agencies provide their services online for the convenience of their citizens. Also, if this... The post Fake Bahrain Government Android App Steals Personal...

Financial Services Government Facilities
Cloud Threat Landscape ·

On 2024-05-31, a research was reported, involving , gaining initial access via Software misconfig, targeting GitHub to achieve Resp. disclosure.

Blue Team Archives - Black Hills Information Security, Inc. ·

Start this blog series from the beginning here: PART 1 Misconfigurations in Active Directory Certificate Services (ADCS) can introduce critical vulnerabilities into an Enterprise environment. In...

Information Technology Alyssa Snow Blue Team
Orange Cyberdefense ·

Inside industrial systems (also known as Operational Technology, or OT), devices communicate with each other and can be accessed over IP using familiar IT protocols (such as SSH, web services,...

Critical Manufacturing Communications
Wiz Blog | RSS feed ·

Detect malicious hosted AI models with Wiz AI-SPM and gain confidence in the models your data scientists use

Energy Information Technology
ICS Medical Advisories ·

View CSAF 1. EXECUTIVE SUMMARY CVSS v4 9.1 ATTENTION: Exploitable remotely Vendor: Baxter Equipment: Welch Allyn Connex Spot Monitor (CSM) Vulnerability: Use of Default Cryptographic Key 2. RISK...

Critical Manufacturing Healthcare and Public Health
ICS Medical Advisories ·

View CSAF 1. EXECUTIVE SUMMARY CVSS v4 9.4 ATTENTION: Exploitable remotely Vendor: Baxter Equipment: Welch Allyn Configuration Tool Vulnerability: Insufficiently Protected Credentials 2. RISK...

Critical Manufacturing Healthcare and Public Health
Maxwell Dulin's Resources ·

WinRAR is a Windows specific compression tool. It also has a terminal version as well. ANSI is the escapes sequences used in terminals to change the color, orientation and many other things about...

maxwelldulin ·

CVE-2023-34992 was for FortiSIEM command injection vulnerability. The phMonitor takes in a server_ip variable. This was being used to execute a python script via os.system that led to a command...

Financial Services Critical Manufacturing
Cloud Threat Landscape ·

The RedTail cryptomining malware has been updated to exploit CVE-2024-3400, a vulnerability in PAN-OS. The attackers are using private cryptomining pools for greater control, and the malware now...

Maxwell Dulin's Resources ·

A while ago, Jacob reported a bug named p2p storms that ICF deemed wasn't worth fixing. If the blocks are 20mb each and the mempool is full, then the chain liveness are severely impacted. The...

Information Technology
Pulsedive Blog ·

Pulsedive's latest V3 update to our Chrome, Firefox, and Edge add-on include new features and improved user experience.

Nuclear
Cloud Threat Landscape ·

On May 30, 2024, researchers published a report concerning activity by a threat actor dubbed UNC5537, involving abuse of stolen credentials to gain illicit access to Snowflake accounts unprotected...

ShinyHunters Information Technology
Wiz Blog | RSS feed ·

Organizations in the region can now benefit from Wiz's cloud security platform while maintaining their data sovereignty and privacy requirements.

Information Technology Energy
Wiz Blog | RSS feed ·

Wiz announces integration with Google Security Operations to help SecOps teams identify critical cloud security issues.

Information Technology Chemical
Kaspersky ICS CERT ·

In the first quarter of 2024, the percentage of ICS computers on which malicious objects were blocked decreased by 0.3 pp from the previous quarter to 21.4%. Compared to the first quarter of 2023,...

Critical Manufacturing Publications
Kaspersky ICS CERT ·

The percentage of ICS computers on which malicious objects were blocked during the quarter varied regionally from 34.2% in Africa to 11.5% in Northern Europe. Africa and South-East Asia saw their...

Critical Manufacturing Publications
maxwelldulin ·

In bug bounties, judges are a party between the auditor and the development team who reviews and handles disputes on the findings. Trust, the author of the post, has audited thousands of findings...

maxwelldulin ·

An iFrame tag is used to bring in other web pages into your own. Some pages restrict this (to prevent clickjackin and phishing, among other things) but can be awesome for developers. The src...

Wiz Blog | RSS feed ·

The Wiz Research team's investigations into AI-as-a-service providers reveals a major risk to AI systems.

Information Technology