IM
IronMonkey Threat Research
LIVE
|
Articles 25,482
|
CVEs 338,519
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,450 articles — Page 789 of 849
FalconForce - Medium ·

FalconFriday — Detecting MMC abuse using “GrimResource” with MDE — 0xFF24Last week, Elastic Security Labs released a blog post detailing the “GrimResource” technique used by both red teams and...

falconfriday grimresource
Wiz Blog | RSS feed ·

Microsoft has honored Wiz as Commercial Marketplace 2024 Partner of the Year for excellence in go-to-market and joint-selling opportunities.

Information Technology Chemical
Research & Threat Intel News- Outpost24 Blog ·

While reviewing common TTPs in malware campaigns used last year Outpost24’s Cyber Threat Intelligence team, KrakenLabs, came across several reports and articles describing a novel infection...

Financial Services
Threat Analysis Group (TAG) ·

Today we are sharing updated insights about DRAGONBRIDGE, the most prolific IO actor Google’s Threat Analysis Group (TAG) tracks.

Communications
GreyNoise Labs ·

Recently Sift caught an interesting payload. As it turns out, the exploit was CVE-2024-0769, which is now tagged here: D-Link DIR-859 Information Disclosure Attempt . This vulnerability is a path...

Transportation Systems Information Technology vulnerabilities cybersecurity
Cloud Threat Landscape ·

A Chinese company named Funnull acquired the Polyfill domain and GitHub repo, and inserted malware into polyfill.js that redirected users to gambling websites. Further pivoting revealed that...

Critical Manufacturing
Cloud Threat Landscape ·

Rabbit AI's codebase included several hardcoded API keys for ElevenLabs, Azure, Yelp, Google Maps, and SendGrid. According to the researchers who discovered this, this access would have allowed an...

Wiz Blog | RSS feed ·

Wiz Research discovered CVE-2024-37032, an easy-to-exploit Remote Code Execution vulnerability in the open-source AI Infrastructure project Ollama.

Cloud Threat Landscape ·

Between November 2023 and April 2024, researchers observed RedJuliett, a likely Chinese state-sponsored cyber-espionage group, targeting entities primarily in Taiwan but also across Asia, Africa,...

maxwelldulin ·

Currently, analyzing transactions for EVM chains is super easy. There are ways to fork the chain and run it locally, you can step through step by step in a debugger and there are great graphing...

Financial Services Energy
Maxwell Dulin's Resources ·

MailCleaner is an email filtering service. An email address has two parts: the local and the domain, which are separated by an @ symbol. The domain part typically contains letters, numbers,...

Maxwell Dulin's Resources ·

Within portions of the BSD kernel, the mbuf object is used in networking. It consists of a header and data, which are both fixed size. _MSIZE is used for the total message of the buffer and MLEN...

Maxwell Dulin's Resources ·

The XRP blockchain have a feature called partial payment. This allows a payment to deliver part of what the amount fields says. Why? I'm guessing this is a feature to break up large transfers over...

Financial Services
Maxwell Dulin's Resources ·

EOS is a blockchain with smart contract capabilities that is fairly unique compared to Ethereum in some regards. EOS transactions have 5 different states: Executed: Transaction succeeded with no...

Maxwell Dulin's Resources ·

In Bitcoin, there is a concept known as replace by fee (RBF) to allow the use of other transactions to replace unconfirmed ones. There are many ways to go about doing this type of scheme. Fee...

Financial Services
Maxwell Dulin's Resources ·

How does a crypto exchange know when you sent it funds? Well, there is an address associated with the exchange. In particular, this is unique per user. A transfer is made to this address, which...

Defense Industrial Base Energy
Cloud Threat Landscape ·

On 2024-06-21, a campaign was reported, involving Boolka, gaining initial access via Web vulnerability, while using SQL injection, to achieve Resource hijacking.

Wiz Blog | RSS feed ·

The deployment of GenAI, LLMs, and chat interfaces expands potential attack surfaces and poses increased security threats.

Financial Services Healthcare and Public Health
Orange Cyberdefense ·

Introduction

Infostealers Archives | InfoStealers ·

Learn about Infostealers with actual real life breaches caused by Infostealer infections with Leonid Rozenberg, Hudson Rock’s Head of Partnerships & Integrations. To discover how your organization...

Financial Services
Pulsedive Blog ·

Quantitative and qualitative insights inform our roadmap and best practices to achieve success in CTI networking.

Wiz Blog | RSS feed ·

We are excited to be ‘in-process’ for DoD IL4, continuing our commitment to helping public sector secure everything they build and run in the cloud

Defense Industrial Base Information Technology
Maxwell Dulin's Resources ·

Going from unicode to ASCII is required for some applications. How is this done though? This is a document that explains how this is done in the many different forms. Canonical equivalence is when...

Maxwell Dulin's Resources ·

The author was playing around with some functionality on a website. While doing this, they realized that part of the URL was being copied into an open graph tag. Given that open graph tags are...

GreyNoise Labs ·

On June 5, 2024, SolarWinds published an advisory detailing CVE-2024-28995 - a path-traversal vulnerability in Serv-U, discovered by Hussein Daher. The affected versions are: SolarWinds Serv-U...

Transportation Systems solarwinds serv-u
Maxwell Dulin's Resources ·

Sei Network is a layer 1 blockchain built on Cosmos with some pretty crazy functionality. In particular, there are two execution runtimes for smart contracts in both EVM and CosmWasm. The EVM can...

Energy
Maxwell Dulin's Resources ·

Orange Tsai (of course) found a vulnerability within PHP. In particular, they found an issue that affects XAMPP (a popular way for admins to deploy PHP apps) to get RCE. The original post did not...

Maxwell Dulin's Resources ·

HTTP Smuggling is just a difference in understanding of HTML parsers. What about differences in parsers for other things? The Bishop Fox article dives into differences between JSON...

Financial Services Government Facilities
Maxwell Dulin's Resources ·

Constant time cryptography is a method of preventing side channel leaks via timing differences on various operations. Without this, it'd be possible to learn about the cryptographic operations...

Defense Industrial Base Critical Manufacturing
Maxwell Dulin's Resources ·

While testing, Sam Curry noticed that his modem was compromised. All requests being sent through it were being forwarded to a different domain. Years later, he decided to investigate the Cox ISP...

Communications Commercial Facilities