IM
IronMonkey Threat Research
LIVE
|
Articles 28,595
|
CVEs 365,725
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,563 articles — Page 900 of 953
Threat Analysis Group (TAG) ·

This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q1 2024. It was last updated on July 8, 2024.JanuaryWe blocked 4 domains …

Wiz Blog | RSS feed ·

Detect and mitigate CVE-2024-27198 (CVSS score: 9.8) and CVE-2024-27199 (CVSS score: 7.3), authentication bypass vulnerabilities in JetBrains TeamCity.

@BushidoToken Threat Intel ·

In this blog, we shall investigate a Russia-based mercenary group that has appeared in multiple CERT-UA reports after sending waves of spam to Ukrainian organisations. These mercenaries use tried...

Armageddon Fancy Bear Financial Services Energy
Wiz Blog | RSS feed ·

Wiz customers can now secure everything they build and run on Akamai Linode Cloud, providing organizations the broadest cloud coverage out of any CNAPP

Information Technology Chemical
Cloud Threat Landscape ·

Researchers observed threat actor z0Miner targeting Korean WebLogic servers as download servers for distributing malware, including miners and network tools. It is recommended to look for...

Cloud Threat Landscape ·

On 2024-03-06, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Cloud key compromise, to achieve Data exfiltration.

Financial Services
Cloud Threat Landscape ·

Researchers observed threat actors exploiting misconfiguration in servers running Apache Hadoop YARN, Docker, Confluence, or Redis with new Golang-based malware, which uses worm-like behavior to...

Threat Intelligence ·

Written by: Aseel Kayal During the analysis of a banking trojan sample targeting Android smartphones, Mandiant identified the repeated use of a string obfuscation mechanism throughout the...

Financial Services Information Technology Threat Intelligence
ICS Medical Advisories ·

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.8 ATTENTION: Low attack complexity Vendor: Santesoft Equipment: Sante FFT Imaging Vulnerability: Out-of-Bounds Write 2. RISK EVALUATION Successful...

Critical Manufacturing Healthcare and Public Health
maxwelldulin ·

Facebook has an extra security mechanism after logging in to ensure the user is valid. This could be a captcha, MFA but is commonly referred to as a chcekpoint. This is implemented within an...

maxwelldulin ·

SolChat claimed to be an encrypted chat application and audio calls using WebRTC. So, the author decided to take a look at it. They first took to reviewing the JavaScript code. Since the JS map...

maxwelldulin ·

In the first two posts they found two vulnerabilities that were already patched in LayerZero. This time, they go through a vulnerability in a different section of code. When calling an external...

Energy Financial Services
maxwelldulin ·

In the first part, the author goes over how the EVM part of Layer Zero works. In this part, they go over some bugs that they found within the ecosystem. Being able to shut down an individual cross...

Transportation Systems Energy
The DFIR Report ·

Below is a recent Threat Brief that we shared with our customers. Each year, we produce over 20 detailed Threat Briefs, which follow a format similar to the below. Typically, … Read More

maxwelldulin ·

Several folks wrote about issues to look for in Cosmos-based blockchains. I have a personal list of these but it's nice to see a large external list! Cosmos is built via writing Go code at the...

Energy Financial Services
maxwelldulin ·

zksync is a zero knowledge (ZK) project that was building out a ZK EVM. The contest had 1.1M in rewards. The winner Winnie had never touched ZK stuff before but decided to ramp up on it before the...

Critical Manufacturing Energy
maxwelldulin ·

Youssef specializes in finding vulnerabilities in clientside JavaScript code. Specifically, with Facebook integrations. In this article, he goes through a chain of issues that led to an account...

Maxwell Dulin's Resources ·

This article is a list of different ways to get window references. When doing client side security, getting a reference to a window is big way to cause havoc. First, looking at the window. Using...

Transportation Systems
security – Ars Technica ·

Worms could potentially steal data and deploy malware.

Financial Services Nuclear
McAfee Labs | McAfee Blogs ·

Authored by Yashvi Shah and Preksha Saxena McAfee Labs has recently observed a significant surge in the distribution of prominent... The post Rise in Deceptive PDF: The Gateway to Malicious...

Financial Services Government Facilities
maxwelldulin ·

LayerZero is a very large blockchain bridge that holds a large amount of value, as well as many cross-chain applications made by other developers. The functionality for calling is fairly simple on...

Energy
Wiz Blog | RSS feed ·

Wiz customers can now detect vulnerabilities in MacOS workloads and their software components with agentless scanning, and assess their secure configurations against built-in CIS Benchmarks for Apple MacOS

Bitdefender Labs ·

Social media platforms are overflowing with scams. In the past couple of months, Bitdefender Labs has been monitoring a steep increase in fraudulent social media ads on Facebook promoting various...

Financial Services Transportation Systems
Bitdefender Labs ·

Social media platforms are overflowing with scams. In the past couple of months, Bitdefender Labs has been monitoring a steep increase in fraudulent social media ads on Facebook promoting various...

Financial Services Transportation Systems
ICS Medical Advisories ·

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.8 ATTENTION: Low attack complexity Vendor: MicroDicom Equipment: DICOM Viewer Vulnerabilities: Heap-based Buffer Overflow, Out-of-Bounds Write 2. RISK...

Critical Manufacturing Healthcare and Public Health
McAfee Labs | McAfee Blogs ·

Authored by: Vignesh Dhatchanamoorthy In the ever-evolving landscape of cybersecurity threats, staying ahead of malicious actors requires a deep understanding... The post GUloader Unmasked:...

Financial Services Commercial Facilities
Cloud Threat Landscape ·

The Singapore-based company, which provides AI-powered tools for designing image and video content, has suffered a massive data breach that compromised the personal information of nearly 20...

Cloud Threat Landscape ·

Pure Incubation was founded in 2012, and the company later rebranded to DemandScience.Back in March 2024, an actor named KryptonZambie posted a thread on Breach Forums selling a database belonging...

Bitdefender Labs ·

Here at Bitdefender, we're constantly working on improving detection capabilities for our macOS cyber-security products; part of this effort involves revisiting old (or digging up new) samples...

Financial Services
Bitdefender Labs ·

Here at Bitdefender, we're constantly working on improving detection capabilities for our macOS cyber-security products; part of this effort involves revisiting old (or digging up new) samples...

Financial Services