IM
IronMonkey Threat Research
LIVE
|
Articles 25,483
|
CVEs 338,519
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,451 articles — Page 785 of 849
Recorded Future ·

Explore 2024 Check Fraud Report: Rising U.S. fraud trends, geographic hotspots, and threat actors, with insights from Telegram data.

WeLiveSecurity ·

The discovery of the NGate malware by ESET Research is another example of how sophisticated Android threats have become

Financial Services
WeLiveSecurity ·

Demystifying CVE-2024-7262 and CVE-2024-7263

APT-C-60
Recorded Future ·

We are thrilled to announce our latest development for our integration of Recorded Future with Google Security Operations, also known as Security Operations (Formerly known as Google Chronicle).

Nuclear
Cloud Threat Landscape ·

The critical vulnerability CVE-2023-22527 is being actively exploited for cryptojacking activities, turning affected Confluence Data Center and Server instances into cryptomining networks....

Information Technology Financial Services
Maxwell Dulin's Resources ·

USDC is one of the biggest assets in crypto by usage and TVL. Circle, the owners of USDC, created the protocol Cross Chain Transfer Protocol (CCTP). Although this is a general message passing...

Transportation Systems
WeLiveSecurity ·

In the digital graveyard, a new threat stirs: Out-of-support devices becoming thralls of malicious actors

Critical Manufacturing
Maxwell Dulin's Resources ·

As a precursory, I really don't like how this article is written. It takes more time to hype up the bug and the companies work than actually explain the vulnerability. Additionally, the...

Information Technology Financial Services
WeLiveSecurity ·

The world of Android threats is quite vast and intriguing. In this episode, Becks and Lukáš demonstrate how easy it is to take over your phone, with some added tips on how to stay secure

The DFIR Report ·

Key Takeaways In December 2023, we observed an intrusion that started with the execution of a Cobalt Strike beacon and ended in the deployment of BlackSuit ransomware. The threat actor … Read More

Information Technology
Checkmarx Zero - Medium ·

In July 2024, the software supply chain security landscape faced unprecedented challenges, marked by sophisticated attacks from state-sponsored actors and organized cybercriminal groups. North...

Information Technology Financial Services
WeLiveSecurity ·

Phishing using PWAs? ESET Research's latest discovery might just ruin some users' assumptions about their preferred platform's security

Financial Services
Cloud Threat Landscape ·

The threat actor group Bling Libra (behind ShinyHunters ransomware) has been observed infiltrating an organization's Amazon Web Services (AWS) environment, focusing on extortion rather than...

Wiz Blog | RSS feed ·

Attackers can take advantage of a quirk of the default AWS configuration (without SourceIdentity configured) to potentially make detecting and attributing their actions more difficult.

WeLiveSecurity ·

Android malware discovered by ESET Research relays NFC data from victims’ payment cards, via victims’ mobile phones, to the device of a perpetrator waiting at an ATM

Financial Services Communications
Wiz Blog | RSS feed ·

This case study serves to highlight the importance of rapid, heuristic, accurate, and contextualized detection and response in the cloud.

Information Technology Government Facilities
WeLiveSecurity ·

Should the payment of a ransomware demand be illegal? Should it be regulated in some way? These questions are some examples of the legal minefield that cybersecurity teams must deal with

Financial Services Chemical
Maxwell Dulin's Resources ·

The authors of the post were trying to find SSRF bugs within Microsoft Copilot after finding 2 but recently patched bugs. They found that when providing key phrases it was possible to trigger an...

Information Technology Financial Services
Research & Threat Intel News- Outpost24 Blog ·

Welcome to the Threat Context monthly blog series where we provide a comprehensive roundup of the most relevant cybersecurity news and threat information from KrakenLabs, Outpost24’s cyber Threat...

Financial Services Information Technology
WeLiveSecurity ·

ESET analysts dissect a novel phishing method tailored to Android and iOS users

Financial Services
Recorded Future ·

Explore GreenCharlie’s expanding cyber threat against US political and government entities. Learn how this Iran-nexus group uses advanced phishing techniques and malware like GORBLE and POWERSTAR.

GreyNoise Labs ·

In this blog, the second in the series, you will learn about how to build a database of Bluetooth Low-Energy (BTLE) Generic Attribute (GATT) Universally Unique Identifiers (UUIDs) capable of...

Healthcare and Public Health Energy
Maxwell Dulin's Resources ·

Agave and Jito are Solana validator clients. Solana executes eBPF bytecode from an ELF file when being executed. The development toolchain aligns the ELF program. During the ELF sanitization...

Maxwell Dulin's Resources ·

Modern JS frameworks like react, Angular and Vue safeguard against XSS. If you want to include input as HTML, there are mechanisms to do this but are dangerous. Vue.js uses the mustache template...

Maxwell Dulin's Resources ·

Jetpack Compose is a new way for building UIs in Android, replacing the fragments style. Now, navigation between screens represents composable functions. Hence, the Jetpack Navigation library is...

Maxwell Dulin's Resources ·

Soko is Go software for publishing Gentoo Linux packages. It uses an ORM which should in theory make us safe against SQL injection attacks. However, the code authors were misusing the prepared...

Maxwell Dulin's Resources ·

The Threshold Network is a collection of various services that use threshold cryptography by relying on multiple secret keepers. One of these services is tBTC that bridges native assets. The...

Transportation Systems Healthcare and Public Health
Maxwell Dulin's Resources ·

The Apache HTTP server is constructed with modules, with 136 listed in the documentation and about half that are in normal use. To the author this, there was a bad code smell: a giant request_rec...

Maxwell Dulin's Resources ·

Browsers can request any data via HTTP using JavaScript. From a website, it's possible to make requests to items on the local network, such as localhost. Should this be allowed? IP scanning and...

Energy Information Technology
Maxwell Dulin's Resources ·

ControlLogix 1756 is a series of programmable automation controllers from Rockwell for highly scalable industrial automation. This device is a chassis component that servers as the enclosure for...

Critical Manufacturing