IM
IronMonkey Threat Research
LIVE
|
Articles 28,005
|
CVEs 357,506
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,973 articles — Page 875 of 933
Maxwell Dulin's Resources ·

GitHub Enterprise Servers (GHES) is a locally hosted version of Github that teams can run. It runs functionality the same as the regular Github service and is written in Ruby. Reflections in Ruby...

Maxwell Dulin's Resources ·

The author of this post decided to take a trip down memory lane by reviewing a vulnerability they found in VirtualBox 5 years ago. The post is heavy into the methodology, which I always...

Maxwell Dulin's Resources ·

Cryptography feels like black magic. When auditing code at QuarksLab, there are many little things that they report but don't just kill the security of the implementation immediately. In this...

Government Facilities
McAfee Labs | McAfee Blogs ·

Authored by Yashvi Shah and Preksha Saxena AsyncRAT, also known as “Asynchronous Remote Access Trojan,” represents a highly sophisticated malware... The post From Spam to AsyncRAT: Tracking the...

Financial Services Commercial Facilities
Wiz Blog | RSS feed ·

Extending a heartfelt thanks to our customers, investors, and Wizards

Energy
Cloud Threat Landscape ·

On 2024-05-07, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Ivanti Connect Secure VPN to achieve Resource hijacking. The following...

Wiz Blog | RSS feed ·

Enabling security outcomes for cloud builders and defenders, from code to cloud to defense.

Information Technology Energy
Cloud Threat Landscape ·

Microsoft has identified a Morocco-based cybercrime group, Storm-0539, known for sophisticated phishing attacks to steal and sell gift cards. Active since 2021, the group targets large retailers...

Information Technology
Cloud Threat Landscape ·

Threat actors are attempting to monetize their illicit access to LLMs while the cloud account owner bears the costs. The attackers target a variety of LLM services across AWS, Azure, and GCP. In...

Cloud Threat Landscape ·

On 2024-05-03, a research was reported, involving , gaining initial access via Cloud native misconfig, targeting Google Cloud Storage to achieve Data exfiltration.

Blue Team Archives - Black Hills Information Security, Inc. ·

| Niccolo Arboleda | Guest Author Niccolo Arboleda is a cybersecurity enthusiast and student at the University of Toronto. He is usually found in his home lab studying different cybersecurity […]...

Blue Team Guest Author
Cloud Threat Landscape ·

Researchers investigated a series of ransomware attacks targeting poorly managed MS-SQL servers by the TargetCompany ransomware group. This group primarily installs Mallox ransomware, with recent...

Threat Intelligence ·

Written by: Ofir Rozmann, Asli Koksal, Adrian Hernandez, Sarah Bock, Jonathan Leathery APT42, an Iranian state-sponsored cyber espionage actor, is using enhanced social engineering schemes to gain...

Charming Kitten Yellow Garuda Mint Sandstorm Government Facilities Information Technology Threat Intelligence
Threat Intelligence ·

Written by: Matthew McWhirt, Omar ElAhdan, Glenn Staniforth, Brian Meyer Multi-faceted extortion via ransomware and/or data theft is a popular end goal for attackers, representing a global threat...

Information Technology Security & Identity Threat Intelligence
McAfee Labs | McAfee Blogs ·

Authored by Yashvi Shah, Lakshya Mathur and Preksha Saxena McAfee Labs has recently uncovered a novel infection chain associated with... The post The Darkgate Menace: Leveraging Autohotkey &...

Financial Services Government Facilities
Threat Intelligence ·

Executive Summary A growing amount of malware has naturally increased workloads for defenders and particularly malware analysts, creating a need for improved automation and approaches to dealing...

Information Technology Security & Identity Threat Intelligence
The DFIR Report ·

Key Takeaways In August 2023, we observed an intrusion that started with a phishing campaign using PrometheusTDS to distribute IcedID. IcedID dropped and executed a Cobalt Strike beacon, which was...

Information Technology Healthcare and Public Health
FalconForce - Medium ·

TL;DRIn this blog post I explain how reply URLs in Azure Applications can be used as a vector for phishing. The impact of this can range from data leaks to complete tenant takeover; just by luring...

Information Technology
Threat Intelligence ·

Written by: Kelli Vanderlee, Jamie Collier Executive Summary The election cybersecurity landscape globally is characterized by a diversity of targets, tactics, and threats. Elections attract...

Government Facilities Information Technology Security & Identity Threat Intelligence
Fox-IT International blog ·

Authored by Willem Zeeman and Yun Zheng Hu This blog is part of a series written by various Dutch cyber security firms that have collaborated on the Cactus ransomware group, which exploits Qlik...

Blog
Fox-IT International blog ·

Authored by Willem Zeeman and Yun Zheng Hu This blog is part of a series written by various Dutch cyber security firms that have collaborated on the Cactus ransomware group, which exploits Qlik...

Healthcare and Public Health Blog
Wiz Blog | RSS feed ·

Detect and mitigate CVE-2024-4040, a critical vulnerability in CrushFTP exploited in the wild. Organizations should patch urgently.

Maxwell Dulin's Resources ·

Hedgey Finance is a token vesting and locking tool. I linked one article but I also like the Rekt News article. During a campaign creation, the user transfers the locked tokens to a smart contract...

Healthcare and Public Health Defense Industrial Base
Cloud Threat Landscape ·

Cisco reported two zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls that have been exploited by a state-backed hacking group known as...

Wiz Blog | RSS feed ·

Ensure that your Kubernetes environments are secure and follow OWASP's Kubernetes Top 10 framework. Generate reports quickly and easily and remediate any issues with actionable insights.

Chemical Energy
Pulsedive Blog ·

In part 2 of this series, discover where practitioners share during CTI collaboration - from peer to peer trust groups to paid memberships.

Threat Intelligence ·

Attackers are taking greater strides to evade detection. This is one of the running themes in our latest release: M-Trends 2024. This edition of our annual report continues our tradition of...

Information Technology Security & Identity Threat Intelligence
GreyNoise Labs ·

Introduction Decrypting Fortinet’s FortiGate FortiOS firmware is a topic that has been thoroughly covered, in part because of the many variants and permutations of FortiOS firmware, all differing...

fortinet vulnerabilities
Maxwell Dulin's Resources ·

Gains is a leverage-trading platform. In particular, users can provide small amount of funds yet still gain high exposure to a given asset. The leverage portion allows for gains or losses of...

Financial Services
Threat Intelligence ·

Written by: Beleswar Prasad Padhi, Tina Johnson, Michael Bailey, Elliot Chernofsky, Blas Kojusner FakeNet-NG is a dynamic network analysis tool that captures network requests and simulates network...

Information Technology Threat Intelligence