Continuing to walk down Linux Kernel exploitation lane. This time around with an unanticipated topic: DirtyPipe as it actually nicely fits the series as an example.
The Colonial Pipeline story has taken an unexpected plot twist after Darkside announced the cessation of their criminal operations.
Colonial Pipeline has fallen victim to a ransomware attack, forcing its 5,500-mile pipeline to shutdown.
The Colonial Pipeline story has taken an unexpected plot twist after Darkside announced the cessation of their criminal operations.
Colonial Pipeline has fallen victim to a ransomware attack, forcing its 5,500-mile pipeline to shutdown.
This report outlines the risks associated with the use of official and third party app stores.
On 2022-05-04, a campaign was reported, involving UNC2903, gaining initial access via , while using IMDS abuse, SSRF,.
Wiz Research discovers a chain of critical vulnerabilities in the widely used Azure Database for PostgreSQL Flexible Server.
A technical analysis of a new variant of the SparrowDoor malware.
There are a number of key questions which are always asked by people wanting to get into security research, find out more about how others go about it or just generally improve their processes. In...
On 2022-04-21, a campaign was reported, involving LemonDuck, gaining initial access via ,.
On the last day of March 2022, Claroty (Team82) published an article on two vulnerabilities they had identified in Rockwell Automation products. We believe that the severity of these...
On April 12, 2022, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and...
Russian-speaking ransomware gang OldGremlin resumes attacks in Russia
Fake giveaways hit bitcoiners again. Now on YouTube
Community Feature - @SteveD3There has been a noticeable uptick in the number of Fake Anti-Virus (Fake AV) phishing pages in Q1 2022. During his normal daily phishing scans, in the first quarter...
Denonia is a newly discovered type of malware targeting AWS Lambda environments. It was recently exposed by Cado Security, who named it after the domain it communicates with. Once the malware is...
Expel’s SOC detected unauthorized access into one of their customer’s Amazon Web Services (AWS) environments. The attacker used a long-term access key to gain initial access. Once they got in,...
Community Feature - @Ch33r10Curated Intelligence member Xena Olsen (aka @Ch33r10) has shared a useful guide for how CTI analysts can handle dealing with cybersecurity crises on a global scale. The...
Authored by Vallabh Chole and Oliver Devane Scammers are very quick at reacting to current events, so they can generate... The post Scammers are Exploiting Ukraine Donations appeared first on McAfee Blog.
Learn how to address Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments.
Researcher Jose Bertin described the exploitation of several vulnerabilities in a Tekon-Automatics automation solution. We analyze the real scope of what has happened and offer our take on whether...
What we know about Spring4Shell so far
Kaspersky ICS CERT received a letter from FIRST, notifying that its membership has been temporarily suspended. Kaspersky is disappointed by this decision and believes that it hurts the...
Group-IB unveils three groups of fraudsters behind delivery scams in Singapore
On 2022-03-28, a campaign was reported, involving Muhstik operator, gaining initial access via ,.
Learn how to harden your cloud environment against LAPSUS$-like threat actors
Assessing the security of network equipment.
According to Microsoft Threat Research, as part of LAPSUS$’s large-scale social engineering and extortion campaigns, they also gained access to several of their targets’ cloud environments.LAPSUS$...
Community Feature - @cPeterrCurated Intelligence member Chuong Dong has recently shared his findings in a blog after reverse engineering the infamous LockBit ransomware family, version 2.0. Most...