IM
IronMonkey Threat Research
LIVE
|
Articles 25,474
|
CVEs 338,055
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,442 articles — Page 800 of 849
McAfee Labs | McAfee Blogs ·

The explosive growth of Generative AI has sparked many questions and considerations not just within tech circles, but in mainstream... The post Generative AI: Cross the Stream Where it is...

Financial Services Commercial Facilities
Wiz Blog | RSS feed ·

Secure Microsoft Azure AI Services, including Azure OpenAI, with Wiz AI-SPM providing full visibility into AI pipelines and risks on the Wiz Security Graph

Energy Information Technology
Kaspersky ICS CERT ·

What UN Regulations 155 and 156 require from vehicle manufacturers in reality, and how to ensure compliance with requirements and prepare for certification if necessary

Publications
maxwelldulin ·

Hypervisor-Protected Code Integrity (HVCI) is a method of preventing compromise of various kernel parts even when an attacker has compromised part of the kernel itself. While creating a Windbg...

Information Technology
maxwelldulin ·

The Cosmos SDK is a blockchain development framework written in Golang. The security of this system is crucial. So, they have fuzzing integrated into the framework, which the author is going to...

Healthcare and Public Health
Maxwell Dulin's Resources ·

Aptos Roll is a secure instant randomness API. This is done with a bunch of pretty crazy cryptography schemes. Unlike Chainlink VRF, this is on-chain, which makes it faster and cheaper to use....

Wiz Blog | RSS feed ·

The Wiz research team unpacks the security implications of the new EKS access and identity management features and recommends best practices when using them.

Wiz Blog | RSS feed ·

Detect and mitigate CVE-2023-46805, CVE-2024-21887, CVE-2024-21888 and CVE-2024-21893, critical vulnerabilities in Ivanti VPN products. Organizations should patch urgently, and government agencies...

Government Facilities
Orange Cyberdefense ·

Sometimes you need to get in the way of a hardware device and its controller, and see what it has to say for itself. If you are lucky, the two parts are communicating using a serial port, and then...

Critical Manufacturing Defense Industrial Base
Threat Analysis Group (TAG) ·

a blue square that reads "Threat Analysis Group"

Commercial Facilities
Cloud Threat Landscape ·

On 2024-02-06, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Azure Batch abuse, targeting Azure Batch to achieve Resource...

Wiz Blog | RSS feed ·

Detect and mitigate “Leaky Vessels”, container escape vulnerabilities affecting runC and BuildKit. Learn how to prioritize patching and detect exploitation attempts in runtime.

Energy Critical Manufacturing
Wiz Blog | RSS feed ·

Safeguard Amazon Bedrock with Wiz AI-SPM capabilities to gain visibility into GenAI pipelines and detect and proactively remove risks

Energy Information Technology
maxwelldulin ·

Address Space Layout Randomization (ASLR) is a security protection that randomizes the addresses of a process. By doing this, it requires exploits to have an information leak or get really lucky...

Cloud Threat Landscape ·

Mispadu Stealer, a banking Trojan first reported in November 2019, has been observed exploiting the Windows SmartScreen bypass vulnerability, CVE-2023-36025. This variant of Mispadu spreads...

Financial Services
Blog | Threat Intelligence & Memory Forensics | Volexity ·

In a recent series of blog posts related to two zero-day vulnerabilities in Ivanti Connect Secure VPN, Volexity shared details of active in-the-wild exploitation; provided an update on how...

Wiz Blog | RSS feed ·

Gain visibility into non-human identities in your environment and protect against risky service accounts with the new Non-Human Identities Dashboard.

Information Technology Critical Manufacturing
Blue Team Archives - Black Hills Information Security, Inc. ·

In An SMB Relay Race – How To Exploit LLMNR and SMB Message Signing for Fun and Profit, Jordan Drysdale shared the dangers of lack of SMB Signing requirements and […] The post Bypass NTLM Message...

Healthcare and Public Health Alyssa Snow Blue Team
Cloud Threat Landscape ·

On 2024-02-01, a research was reported, involving , gaining initial access via Exposed secret, Cloud native misconfig, while using Cloud key compromise, to achieve Resp. disclosure.

Cloud Threat Landscape ·

On November 23, 2023, Cloudflare detected activity in their network related to the Okta support system supply chain attack.

Critical Manufacturing Transportation Systems
Cloud Threat Landscape ·

This campaign, active since the beginning of 2024, deploys a benign container through the Commando project, escaping it to run multiple payloads on the Docker host. Docker is used as an initial...

Financial Services Information Technology
Kaspersky ICS CERT ·

Most of the described trends have been observed before. However, some of them have reached a critical mass of creeping changes, which could lead to a qualitative shift in the threat landscape

Publications
Orange Cyberdefense ·

TL;DR I wanted to better understand EDR’s so I built a dummy EDR and talk about it here. EDR (Endpoint Detection and Response) is a kind of security product that aims to detect abnormal activities...

Reaper
Cloud Threat Landscape ·

On 2024-01-31, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, while using Credential stuffing, VPN anonymization, Email C2, to achieve Data...

Cloud Threat Landscape ·

On 2024-01-31, an incident was reported, involving an unknown actor, gaining initial access via Exposed secret, while using Cloud API e, Create new cloud user, Create or modify firewall or...

Wiz Blog | RSS feed ·

Learn why Forrester recognized Wiz as the top ranked in the current offering category on the market out of the top 13 providers, and how their analysis connects with the Wiz vision.

Information Technology
Maxwell Dulin's Resources ·

Flask is a very popular Python based web framework. The author was poking around their tech stack and noticed a library called Flask_Session, which was used for server-side session application...

Wiz Blog | RSS feed ·

Wiz is releasing a new report providing insight into various jobs in the field of cloud security and compensation packages they offer; here are 5 key facts from our data.

Information Technology Commercial Facilities
Maxwell Dulin's Resources ·

Chess.com is a very popular online Chess platform. The author decided to look into this site for security issues. On the platform, you can add friends. When reviewing this request, it is a GET...

Information Technology
Maxwell Dulin's Resources ·

SMTP, the Simple Mail Transfer Protocol, is the base email protocol that helps run the world today. Finding emails in servers could allow for terrible email spoofing and mass havoc being caused....

Information Technology