IM
IronMonkey Threat Research
LIVE
|
Articles 25,474
|
CVEs 338,055
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,442 articles — Page 801 of 849
The DFIR Report ·

Key Takeaways In late December 2022, we observed threat actors exploiting a publicly exposed Remote Desktop Protocol (RDP) host, leading to data exfiltration and the deployment of Trigona...

Commercial Facilities Information Technology
Cloud Threat Landscape ·

Trigona ransomware has been active since at least June 2022, targeting MSSQL servers. Mimic ransomware was first identified in June 2022, with a January 2024 attack by a Turkish-speaking threat...

Maxwell Dulin's Resources ·

Chrome extensions have lots of power but do have limitations. They can read the DOM but they can't execute exe files, change settings or many other things. Securing Chrome Extensions from taking...

Maxwell Dulin's Resources ·

Alchemix Finance is a synthetic asset protocol around tokenizing future yield. Using the DAO, it's possible to access the future yield. This is done by issuing a synthetic token that represents...

Financial Services Food and Agriculture
Wiz Blog | RSS feed ·

NASCIO has released its top ten policy and technology priorities for 2024! Learn about how Wiz can help you meet all of the new priorities on the list.

Information Technology Government Facilities
FalconForce - Medium ·

SOAPHound — tool to collect Active Directory data via ADWSTL;DRSOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active...

Information Technology Transportation Systems bloodhound active-directory
Cloud Threat Landscape ·

In January 2024, researchers at RedHunt Labs discovered that Mercedes-Benz accidentally included an access token in a one of their public GitHub repositories that granted access to an internal...

Wiz Blog | RSS feed ·

We're excited to announce the release of a comprehensive guide to mastering Kubernetes security: "Kubernetes Security for Dummies." Wiz collaborated with Wiley publications to create this...

Bitdefender Labs ·

SMS services remain a critical part of telecommunications; they don't require Internet access, and companies use them to inform their customers. This combination of features makes them incredibly...

Financial Services Transportation Systems
Bitdefender Labs ·

SMS services remain a critical part of telecommunications; they don't require Internet access, and companies use them to inform their customers. This combination of features makes them incredibly...

Financial Services Transportation Systems
Fox-IT International blog ·

Authors: Axel Boesenach and Erik Schamper In this blog post we will go into a user-friendly memory scanning Python library that was created out of the necessity of having more control during...

Uncategorized
Fox-IT International blog ·

Authors: Axel Boesenach and Erik Schamper In this blog post we will go into a user-friendly memory scanning Python library that was created out of the necessity of having more control during...

Information Technology Uncategorized
Wiz Blog | RSS feed ·

The Cloud Threat Landscape is a threat intelligence database that summarizes cloud incidents and offers insights into targeting patterns and initial access methods.

Information Technology
Report Feed ·

An NCSC assessment focusing on how AI will impact the efficacy of cyber operations and the implications for the cyber threat over the next two years.

Government Facilities Information Technology
Wiz Blog | RSS feed ·

Mutual Wiz and HashiCorp customers can leverage this integration to scan their IaC configuration and enforce security best practices to reduce risk.

Information Technology Energy
ICS Medical Advisories ·

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.1 ATTENTION: Exploitable remotely/low attack complexity Vendor: Orthanc Equipment: Osimis Web Viewer Vulnerability: Cross-site Scripting 2. RISK EVALUATION...

Critical Manufacturing Healthcare and Public Health
Threat Analysis Group (TAG) ·

This bulletin includes coordinated influence operation campaigns terminated on our platforms in Q4 2023. It was last updated on January 19, 2024.OctoberWe terminated 8 Y…

Commercial Facilities Defense Industrial Base
Maxwell Dulin's Resources ·

Metamask is a popular crypto wallet in the web browser. Even if you're not using it to store your funds, it's likely interacting with your hardware wallet. Obviously, having a safe crypto wallet...

Critical Manufacturing Information Technology
Maxwell Dulin's Resources ·

Rounding bugs that lead to massive loss of funds have alluded me for a while. I see them in large hacks but don't understand where they're useful and how to find them. This post is a good step for...

Critical Manufacturing
Maxwell Dulin's Resources ·

A blockchain bridge is used when you want to have one asset owned by one blockchain on another. Having lots of funds on different blockchain makes it harder to use so bridges are a good thing....

Energy
Cloud Threat Landscape ·

Datadog observed an attacker leveraging a compromised IAM user access key to gain initial access to an AWS environment, at which point they immediately began spinning up hundreds of ECS Fargate...

Cloud Threat Landscape ·

Datadog observed an attacker leveraging a compromised IAM user access key to gain initial access to an AWS environment, at which point they checked SES quotes and enumerated cloud identities. The...

Cloud Threat Landscape ·

On January 19, 2023, Microsoft disclosed that email accounts of multiple employees had been compromised by Nobelium (which overlaps with APT29).According to Microsoft, beginning in late November...

Nobelium
maxwelldulin ·

Finding bugs dynamically via testing frameworks is amazing as a development team. Security issues and general bugs get through less and it requires less person power to go through. There are many...

Blog | Threat Intelligence & Memory Forensics | Volexity ·

On January 15, 2024, Volexity detailed widespread exploitation of Ivanti Connect Secure VPN vulnerabilities CVE-2024-21887 and CVE-2023-46805. In that blog post, Volexity detailed broader scanning...

UTA0178 Financial Services
Threat Analysis Group (TAG) ·

an illustrated blue box with the phrase "Threat Analysis Group" in white

Star Blizzard UNC4057 Hacking Team Defense Industrial Base Information Technology
Cloud Threat Landscape ·

On 2024-01-18, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting Apache ActiveMQ to achieve Resource hijacking. The following tools...

Cloud Threat Landscape ·

On 2024-01-18, a campaign was reported, involving Mimo operator, gaining initial access via 1-day vulnerability, targeting VMware Horizon, Confluence Server, WSO2, Apache ActiveMQ, PaperCut to...

Financial Services
Cloud Threat Landscape ·

On 2024-01-18, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, while using Proxyjacking, targeting Docker to achieve Resource hijacking. The...

maxwelldulin ·

Gitlab is a platform similar to Github. Recently, a user found an awful password reset issue that borks the security of the entire system. I love the beginning sentence from the DayZeroSec folks:...