IM
IronMonkey Threat Research
LIVE
|
Articles 28,005
|
CVEs 357,506
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,973 articles — Page 874 of 933
Bitdefender Labs ·

Bitdefender researchers investigated a series of incidents at high-level organizations in countries of the South China Sea region, all performed by the same threat actor we track as Unfading Sea...

Unfading Sea Haze Defense Industrial Base
Bitdefender Labs ·

Bitdefender researchers investigated a series of incidents at high-level organizations in countries of the South China Sea region, all performed by the same threat actor we track as Unfading Sea...

Unfading Sea Haze Defense Industrial Base
Threat Intelligence ·

Written by: Michael Raggi Mandiant Intelligence is tracking a growing trend among China-nexus cyber espionage operations where advanced persistent threat (APT) actors utilize proxy networks known...

Information Technology Communications Threat Intelligence
Wiz Blog | RSS feed ·

Learn where CNAPP and CWPP overlap, where they differ, and how the market is shifting to the more comprehensive and integrated CNAPP.

Information Technology Financial Services
Threat Intelligence ·

Written by: Mark Swindle While investigating recent exposures of Amazon Web Services (AWS) secrets, Mandiant identified a scenario in which client-specific secrets have been leaked from...

Information Technology Threat Intelligence
Maxwell Dulin's Resources ·

Apache Guacamole is a remote Desktop gateway used for accessing hosts and isolated applications from the webs browser. The application itself contains a client facing server written in Java and a...

Commercial Facilities
Wiz Blog | RSS feed ·

Wiz’s vulnerability scanning is now certified by Red Hat, providing customers with refined assessment of vulnerabilities for Red Hat Products

maxwelldulin ·

Across protocol allows users to bridge funds between various EVM chains very fast - faster than finality. There are a couple of main users. First, the relayer who has funds on all chains. Second,...

Transportation Systems
Wiz Blog | RSS feed ·

Empowering every cloud security stakeholder by eliminating barriers.

Information Technology Transportation Systems
Maxwell Dulin's Resources ·

The Graph is a decentralized indexing protocol. Developers can access and query data across different blockchain using web2 APIs. Many projects, use this for UIs but also for backend services. It...

Energy Healthcare and Public Health
Maxwell Dulin's Resources ·

Compound and AAVE both have a bug that allows the entire protocol to be drained IF there's empty market open. Apparently, this has destroyed a large amount of forks. Sonne was aware of this issue...

Cloud Threat Landscape ·

Researchers observed recent activities surrounding the Kinsing malware, which primarily targets Linux-based cloud infrastructure. Kinsing exploits various vulnerabilities to gain unauthorized...

Information Technology
Blog | Threat Intelligence & Memory Forensics | Volexity ·

Last month, Volexity reported on its discovery of zero-day, in-the-wild exploitation of CVE-2024-3400 in the GlobalProtect feature of Palo Alto Networks PAN-OS by a threat actor Volexity tracks as...

Bitdefender Labs ·

Since 2014, Bitdefender IoT researchers have been looking into the world's most popular IoT devices, hunting for vulnerabilities and undocumented attack avenues. This report documents four...

Bitdefender Labs ·

Since 2014, Bitdefender IoT researchers have been looking into the world's most popular IoT devices, hunting for vulnerabilities and undocumented attack avenues. This report documents four...

Low-level adventures ·

During one of the recent working days, I was tasked with fuzzing some Go applications. That's something I had not done in a while, so my first course of action was to research the current state of...

Information Technology
Wiz Blog | RSS feed ·

Prevent misconfigurations in your environment from being exploited with Wiz’s real-time CSPM.

Information Technology
Wiz Blog | RSS feed ·

Wiz assists Incident Response (IR) and SOC teams with containment through automated assessment of security incidents by identifying possible root causes and calculating the potential blast radius...

Information Technology
McAfee Labs | McAfee Blogs ·

Authored by Vignesh Dhatchanamoorthy, Rachana S Instagram, with its vast user base and dynamic platform, has become a hotbed for... The post How Scammers Hijack Your Instagram appeared first on...

Financial Services Commercial Facilities
maxwelldulin ·

Within the VGAState struct of VirtualBox there is a bitmap used for tracking dirty pages of a VRAM buffer. This bitmap is large enough to use the maximum vram allowed by vbox at 256MB. When...

maxwelldulin ·

Using the drag and drop functionality with invalid data, innerHTML was being set. Johan Carlsson was approached about needing a CSP bypass on Github.com for this XSS in order to make it...

Maxwell Dulin's Resources ·

The web browser attempts to isolate all pages by default but allows some cross-domain communication. An interesting, yet new to me, method is by using the hash. This has been documented for a long...

Information Technology
Virus reviews ·

May 13, 2024 In 2023, Trojan.AutoIt trojan apps, created with the AutoIt scripting language, were once again among the most active threats. They are distributed as part of other malicious software...

Energy Financial Services
Pulsedive Blog ·

In part 3, we examine the challenges, organizational context, and issues with methods used for cyber threat intelligence sharing.

maxwelldulin ·

Apache Guacamole is a remote desktop gateway server. The architecture consists of a Java component with a C backend server. So, they go through a classic difference between two parsers to create...

Information Technology
maxwelldulin ·

NextJS is an extremely popular 'static' site generator, which this website actually uses. So, finding configuration issues or straight up vulnerabilities in NextJS is awesome for bug hunting,...

Nuclear
maxwelldulin ·

Pike Finance integrated with Circles cross chain USDC protocol CCTP. This works by off-chain signers sending an attestation that an event occurred once finality has been reached out chain A to the...

maxwelldulin ·

UTF8 is the standard variable length encoding format with over 1M possible characters. There are other standards for UTF like UTF1, UTF16 and UTF32 but this is the most well-used standard. A code...

Financial Services Healthcare and Public Health
maxwelldulin ·

Curvance appears to be a lending and borrowing protocol. In order to ensure their protocol was secure, they asked Trail of Bits to write a large amount of fuzz tests for their project. This...

Financial Services
maxwelldulin ·

Mutation XSS (mXSS) is a type of XSS that occurs from browser quirks in HTML parsing. In particular, how the browser will rewrite HTML that is considered invalid or what happens when they change...