Victims included a railway stock manufacturer, an electric utility company and a steel producer. One incident brought operations to a halt
Missing Authentication in Emerson OpenEnterprise SCADA versions before 3.3.4 might lead to arbitrary code execution. The affected components may allow an attacker to run an arbitrary commands with...
Inadequate Encryption Strength in Emerson OpenEnterprise SCADA versions before 3.3.4.
Improper Ownership Management in Emerson OpenEnterprise SCADA versions before 3.3.4.
Introduction This blog describes how McAfee ATP (Adaptive Threat Protection) rules are used within McAfee Endpoint Security products. It will... The post How To Use McAfee ATP to Protect Against...
As part of our preparations for our upcoming RingZer0 “Q Division” Training, I have been working on making a software image for the FriendlyArm NanoPi R1S Single Board Computer (SBC) that we’ll be...
Ransomware protection and incident response is a constant battle for IT, security engineers and analysts under normal circumstances, but with... The post ENS 10.7 Rolls Back the Curtain on...
The COVID-19 pandemic has prompted many companies to enable their employees to work remotely and, in a large number of... The post Cybercriminals Actively Exploiting RDP to Target Remote...
Special thanks to Prajwala Rao, Oliver Devane, Shannon Cole, Ankit Goel and members of Malware Research for their contribution and... The post COVID-19 – Malware Makes Hay During a Pandemic...
PrefaceHey there! After quite some time the second part will be finally published :) !Sorry for the delay, real life can be overwhelming..Last time I have introduced this series by covering Data...
NCSC technical paper about the privacy and security design of the NHS contact tracing app developed to help slow the spread of coronavirus.
Co-authored by Marc RiveroLopez. In collaboration with Northwave As we highlighted previously across two blogs, targeted ransomware attacks have increased... The post Tales From the Trenches; a...
Do security issues associated with working remotely affect critical infrastructure enterprises? Should organizations take additional protective measures? A view of regulators in the area of...
The vulnerabilities could allow attackers to remotely compromise hosts, cause denial-of-service conditions or elevate their privileges
Israeli authorities have warned of possible attacks on SCADA systems of wastewater treatment, water pumping and sewerage facilities
The attackers use PoetRAT, a new RAT Trojan distributed via Microsoft Word documents
On the 27th of April 2020 SensePost created a CTF challenge (https://challenge.sensepost.com) for the public. The names of those who managed to capture flags would be placed in a draw for a seat...
The statistical data presented in the report was received from ICS computers protected by Kaspersky products that Kaspersky ICS CERT categorizes as part of the industrial infrastructure at organizations.
This section presents an overview of threats related to ransomware activity against municipal institutions, industrial enterprises and critical infrastructure facilities.
Overview of APT attacks on industrial enterprises information on which was published in 2019.
The analysis of vulnerabilities was performed based on vendor advisories, publicly available information from open vulnerability databases (US ICS-CERT, CVE, Siemens Product CERT), as well as the...
Malicious objects were blocked on 46.6% and ransomware on 1.0% of ICS computers. Kaspersky ICS CERT identified 103 vulnerabilities in industrial systems, IIoT/IoT systems, and other types of solutions.
I’ve been spending some time building new content for our Introduction to Red Teaming course, which has been great for diving into AV/EDR bypass techniques again. In this blog post, I will...
In my previous blog post I dug into a general overview of the KASAN implementation in XNU. This post goes more in depth in detecting kernel uninitialized information leaks using it (no 0days...
Siemens industrial solutions are affected by SegmentSmack and FragmentSmack vulnerabilities, which could lead to device denial of service
In new ransomware attacks, victims face the choice between paying the ransom and seeing their sensitive data published by the attackers
If exploited, the vulnerabilities could lead to arbitrary code execution, file manipulations, denial of service and the creation of an admin account
Authored by: Sang Ryol Ryu and Chanung Pak McAfee Mobile Research team has found another variant of MalBus on an... The post MalBus Actor Changed Market from Google Play to ONE Store appeared...
In order to learn about serverless architecture, I experimented with implementing a quick proof of concept crash triaging tool using AWS Lambda Functions. There are many benefits of serverless...
On 2020-04-08, a campaign was reported, involving an unknown actor, gaining initial access via , targeting Kubernetes to achieve Resource hijacking.