Authored by Oliver Devane, Vallabh Chole, and Aayush Tyagi McAfee has recently observed several malicious Chrome Extensions which, once installed,... The post Imposter Netflix Chrome Extension...
I would like to think that you're all smart enough to know better, but just in case... No, there aren't women in Ukraine are keen to have a sexy webcam chat with you right now. But that doesn't...
Disclaimer - Curated Intelligence is a private trust group and members are able to publish their research under our banner without it being attributed to them. We thank our members for their...
The statistical data presented in the report was received from ICS computers protected by Kaspersky products that Kaspersky ICS CERT categorizes as part of the industrial infrastructure at organizations.
Wiz is excited to announce its new integration with ServiceNow Vulnerability Response (VR), creating a combined vulnerability management workflow that eliminates blind spots and prioritizes risks.
Table fo contents Disclaimer: This post will cover basic steps to accomplish a privilege escalation based on a vulnerable driver. The basis for this introduction will be a challenge from the...
This summary provides an overview of APT attacks on industrial enterprises disclosed in H2 2021.
The Curated Intelligence community is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional free threat intelligence. Slava...
Learn more about the Chrome notifications on Android mobile devices such as phones and tablets, and how McAfee Mobile Security protects users from malicious sites leveraging these notifications....
Community Feature - @ChicagoCyberA Curated Intelligence APT hunter - Joshua Miller - recently published new intelligence with Proofpoint on TA402 (aka Molerats), a likely Palestinian-aligned...
Community Feature - JCyberSec_Curated Intelligence members - JCyberSec - recently created an enlightening YouTube video analysing phishing kits designed to look like Royal Mail asking for a parcel...
With ransomware attacks on the rise, companies need to take a proactive approach to security. Group-IB has put together a list of actionable tips to help you protect your organization from the...
When I got a new MacBook with an M1 Pro chip, I was excited to see the performance benefits. The first thing I did was to fire up hashcat which gave an impressive benchmark speed for NT hashes...
Overview of current GLIBC heap exploitation techniques up to GLIBC 2.34, including their ideas and introduced mitigations along the way
Disclaimer: These are unfiltered study notes mostly for myself. Guaranteed not to be error free. So if you did land here, managed to get to the end of it and found some mistakes just hit me up,...
For each CVE, the Wiz Research team maintains data from multiple threat intelligence sources and our own independent research. Now that we’ve added support for the new CISA KEV catalog, learn how...
Learn how to achieve compliance security at scale with Wiz and RegScale, supporting a variety of compliance framework controls.
Jordan Drysdale // Azure has replaced AWS in my personal development pipeline. This may sound crazy but hear me out. Microsoft has solidified its offerings, done nothing but improve its […] The...
Weak points in modern-day corporate email security
Introduction “533 million Facebook users’ phone numbers leaked” was one of the highlighted titles that flooded many social networks’ pages. The leak that was initially for sale in 2020 has more...
Community Feature - @Bank_SecurityCurated Intelligence member Bank_Security has recently shared an overview of the most commonly advertised information related to financial institutions on the...
Authored By: Kiran Raj In a recent campaign of Emotet, McAfee Researchers observed a change in techniques. The Emotet maldoc... The post Emotet’s Uncommon Approach of Masking IP Addresses appeared...
In this post, we discuss five security limitations of endpoint security agents and also explain how adding agentless solutions can improve your cloud environment security.
On 2022-02-02, a campaign was reported, involving CoinStomp operator, gaining initial access via , while using Timestomping, Reverse shell, Cron persistence,. The following tools were observed: CoinStomp.
Cybersecurity analyst's guide on how to use machine learning to show cybercriminals' true colors
The Belarusian Cyber Partisans have shared documents related to another hack, and explained that Curated Intel member, SttyK, would “understand some of the methods used.”Written by @BushidoToken...
Community Feature - @Rag_secCurated Intelligence member Rag_sec has stitched together images of the Yelna military deployment area and motor pool using Maxar satellite imagery and geolocation...
An unauthenticated attacker with the ability to communicate with the affected device via a broadcast address can perform administrative operations on it. It is possible to upload firmware and...
An attacker can capture and decrypt the communication between the configuration software and the affected devices, since a symmetric encryption algorithm with a fixed key is used to encrypt the...
Targets of spyware attacks in which each malware sample has a limited-scope and a short lifetime include industrial enterprises. Victim organizations’ SMTP services are abused to send phishing...