IM
IronMonkey Threat Research
LIVE
|
Articles 25,474
|
CVEs 338,055
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,442 articles — Page 810 of 849
Wiz Blog | RSS feed ·

Lock down your cloud infrastructure with the new Wiz integration with Microsoft Sentinel. Gain full context, support thorough investigations, and automate your response for ultimate security.

Information Technology
Cloud Threat Landscape ·

According to Microsoft Threat Research, during a campaign by Iranian state-sponsored actor Peach Sandstorm, they were observed utilizing password spray attacks to gain unauthorized access to...

Uncategorized - bellingcat ·

Online court filings place Kent McLellan, who goes by the alias Boneface, in Florida at the same time he claims he was fighting in last year’s bloody siege of Mariupol. The post US neo-Nazi says...

Iron Transportation Systems Defense Industrial Base Americas Investigations
Kaspersky ICS CERT (English) ·

The statistical data presented in the report was received from ICS computers protected by Kaspersky products that Kaspersky ICS CERT categorizes as part of the industrial infrastructure at organizations.

Critical Manufacturing Publications
Maxwell Dulin's Resources ·

Cryptsetup is used to unlock the system partition when using the Linux Unified Key Setup (LUKS). This is all about full disk encryption! When booting up in Linux, there is a special file system...

Transportation Systems Information Technology
Maxwell Dulin's Resources ·

Full disk encryption for an unintended computer is a surprising difficult problem to solve. A classic way of doing this is using a TPM to store an encryption key but only having the encryption key...

Maxwell Dulin's Resources ·

A commit-reveal scheme is a mechanism to have a secret value on chain without actually disclosing it until it's necessary. This is useful since everything on the blockchain is public. The commit...

Energy Financial Services
Cloud Threat Landscape ·

The security breach was discovered by Rollbar on September 6 when reviewing data warehouse logs showing that a service account was used to log into the cloud-based bug monitoring platform.Once...

Cloud Threat Landscape ·

The threat actors gained access to the customer's Azure portal, where they obtained the Azure key required to access the storage account programmatically. The adversary encoded the keys using...

Wiz Blog | RSS feed ·

The Wiz Runtime Sensor for Kubernetes graduates to general availability with proven ability to detect cloud attacks, greater customization for detections, and new cloud-native response capabilities

Information Technology
Wiz Blog | RSS feed ·

Joint customers can now detect and prioritize public exposures with Wiz and automatically remediate unwanted exposures with FortiGate NGFW.

Information Technology Chemical
Fox-IT International blog ·

Authored by Joshua Kamp (main author) and Alberto Segura. Summary Hook and ERMAC are Android based malware families that are both advertised by the actor named “DukeEugene”. Hook is the latest...

Safe Financial Services Defense Industrial Base Uncategorized
Fox-IT International blog ·

Authored by Joshua Kamp (main author) and Alberto Segura. Summary Hook and ERMAC are Android based malware families that are both advertised by the actor named “DukeEugene”. Hook is the latest...

Safe Information Technology Financial Services Uncategorized
Wiz Blog | RSS feed ·

Learn about the process of preventing security issues by changing things outside of your environment by looking at how a misconfiguration was occurring when Github Actions were integrated with AWS...

Information Technology
McAfee Labs | McAfee Blogs ·

Authored by Yashvi Shah Agent Tesla functions as a Remote Access Trojan (RAT) and an information stealer built on the... The post Agent Tesla’s Unique Approach: VBS and Steganography for Delivery...

Financial Services Government Facilities
Cloud Threat Landscape ·

The researchers observed a malicious IP address, previously flagged for conducting SSH brute force attempts, communicating with a malicious shell script named hoze. This script downloads xrx.tar,...

Wiz Blog | RSS feed ·

The Wiz research team examines Microsoft's latest Storm-0558 findings and summarizes the key learnings cloud customers should take away from the incident.

Storm-0558 Critical Manufacturing Information Technology
Blue Team Archives - Black Hills Information Security, Inc. ·

Patterson Cake // PART 1 PART 2 In part one of “Wrangling the M365 UAL,” we talked about acquiring, parsing, and querying UAL data using PowerShell and SOF-ELK. In part […] The post Wrangling the...

How-To Incident Response
Threat Analysis Group (TAG) ·

Threat Analysis Group shares findings on a new campaign by North Korean actors targeting security researchers.

Maxwell Dulin's Resources ·

The Cosmos SDK is a blockchain development framework for application specific blockchains. Built into its core is blockchain interoperability by IBC (interblockchain communication). Within the...

Transportation Systems Financial Services
Wiz Blog | RSS feed ·

During the summer of 2023, using the Wiz Sensor, Wiz Research detected several different cryptomining campaigns targeting cloud workloads. Learn about these campaigns and their associated IoCs,...

Information Technology Chemical
ICS Medical Advisories ·

1. EXECUTIVE SUMMARY ​CVSS v3 9.8 ​ATTENTION: Exploitable remotely/low attack complexity ​Vendor: Softneta ​Equipment: MedDream PACS ​Vulnerabilities: Exposed Dangerous Method or Function,...

Critical Manufacturing Healthcare and Public Health
Cloud Threat Landscape ·

On 2023-09-04, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting MinIO with unknown impact.

maxwelldulin ·

Tornado Cash is a smart contract cryptocurrency mixer. This allows users at one address to withdraw funds at another address without creating a traceable link between the two addresses. Seems...

Energy Financial Services
Wiz Blog | RSS feed ·

The integration of Wiz’s CNAPP and Google Cloud helps both cloud defenders and builders improve security and innovate faster.

Information Technology
maxwelldulin ·

Cypher is a protocol for lending, borrowing and trading using margin. Margin is the process of betting on assets using value that you are borrowing from somebody else. There are two types of...

maxwelldulin ·

The Content Security Policy (CSP) is used to restrict what can be done on a web page. This is useful for defense-in-depth on issues, like XSS, as well as framing. The origin of resources and the...

Financial Services Healthcare and Public Health
McAfee Labs | McAfee Blogs ·

Authored by Preksha Saxena McAfee labs observed a Remcos RAT campaign where malicious VBS files were delivered via phishing email.... The post Peeling Back the Layers of RemcosRat Malware appeared...

Financial Services Commercial Facilities
Cloud Threat Landscape ·

On 2023-08-29, a campaign was reported, involving Kinsing operator, gaining initial access via 1-day vulnerability, Software misconfig, while using Misconfigured PostgreSQL abuse, targeting...

Cloud Threat Landscape ·

On 2023-08-29, a campaign was reported, involving UNC4841, gaining initial access via 0-day vulnerability, targeting Barracuda ESG to achieve Data exfiltration.