This blog was written by Vallabh Chole & Oliver Devane Over the years, the cybersecurity industry has seen many threats... The post Hancitor Making Use of Cookies to Prevent URL Scraping appeared...
This blog was written by Kiran Raj & Kishan N. Introduction In the last few years, Microsoft Office macro malware... The post Zloader With a New Infection Technique appeared first on McAfee Blog.
While the world continues to wait for Kaseya to issue an update to patch VSA installations against a vulnerability exploited by the REvil ransomware gang, security researchers spotted a malware...
Executive Summary Ryuk is a ransomware that encrypts a victim’s files and requests payment in Bitcoin cryptocurrency to release the... The post New Ryuk Ransomware Sample Targets Webservers...
Huntress is tracking a critical ransomware incident affecting MSPs and their customers, caused by a sophisticated Kaseya VSA supply chain attack.
Kaspersky ICS CERT discovered a Denial of Service of the device through GET HTTP request to the web server of camera.
Kaspersky ICS CERT has discovered that the web service of the Robert Bosch GmbH CPP HD/MP cameras does not correctly parse the HTTP protocol. Scope Scope changed
Kaspersky ICS CERT discovered a reflected XSS in a page parameter. Scope Scope changed
Kaspersky ICS CERT discovered multiple reflected XSS in URI handlers. Scope Scope changed
Kaspersky ICS CERT has discovered missing authentication vulnerability for execution critical commands by HTTP requests.
The reversing tale of GrimAgent malware used by Ryuk
Introduction: ImageMagick is a hugely popular open source software that is used in lot of systems around the world. It... The post Fuzzing ImageMagick and Digging Deeper into CVE-2020-27829...
Deep Dive into Prolific RaaS Affiliates' TTPs
Huntress is aware of PrintNightmare, a critical RCE and local privilege escalation vulnerability. This serious security flaw affects many Windows servers.
Introduction Microsoft Windows Graphics Device Interface+, also known as GDI+, allows various applications to use different graphics functionality on video... The post Analyzing CVE-2021-1665 –...
The 10 must-attend sessions at Black Hat 2021
The McAfee Advanced Threat Research team today published the McAfee Labs Threats Report: June 2021. In this edition we introduce... The post McAfee Labs Report Highlights Ransomware Threats...
Providing cybersecurity services involves some risk and liability. Learn why managed detection and response could be the key to lowering your cyber risk.
Gaming publishing giant Electronic Art (EA games) has lost 780 GB of sensitive gaming data in a recent data breach.
Gaming publishing giant Electronic Art (EA games) has lost 780 GB of sensitive gaming data in a recent data breach.
Executive Summary The McAfee Advanced Threat Research team (ATR) is committed to uncovering security issues in both software and hardware to help developers... The post A New Program for Your...
Dive into a threat analysis with us as we dissect a PowerShell command with an environmentally keyed malware payload.
Introduction Virtualization technology has been an IT cornerstone for organization for years now. It revolutionized the way organizations can scale... The post Are Virtual Machines the New Gold...
Last week Wiz closed its Series B, which we had previously announced in March, with an additional $120 million investment from Salesforce Ventures and Blackstone with participation from Aglaé Ventures.
APT41 likely behind a third-party attack on Air India
Today’s hackers know how to outsmart automation and evade detection. Learn how managed threat detection and response can help you fight back.
Our ThreatOps team details stumbling across Raccine, a ransomware remedy that works by hooking onto IFEO debuggers, for the first time.
On 2021-06-07, a campaign was reported, involving Siloscape operator, gaining initial access via 1-day vulnerability, Web vulnerability, while using TOR anonymization, Thread impersonation to...
Attribution secrets: Who is behind stealing credentials and bank card data by asking to install fake Flash Player, browser or font updates?
In this testimonial, learn firsthand from one of our Security Awareness Consultants at Curricula about how a fake IRS phishing scam worked on one student.