IM
IronMonkey Threat Research
LIVE
|
Articles 25,455
|
CVEs 337,950
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,423 articles — Page 825 of 848
maxwelldulin ·

The TRACE method is used for debugging applications. When a request is made with this method, it will send the full request with the specified verb and reflect this in the response. The HTTPOnly...

Maxwell Dulin's Resources ·

Cache poisoning vulnerabilities are typically complicated and hard to come by. This author found a load of them and put them together in a single post. The first issue is a problem with a load...

Cloud Threat Landscape ·

On 2022-11-16, a campaign was reported, involving WatchDog, gaining initial access via ,.

McAfee Labs | McAfee Blogs ·

Authored by Oliver Devane It hasn’t taken malicious actors long to take advantage of the recent bankruptcy filing of FTX,... The post Threat Actors Taking Advantage of FTX Bankruptcy appeared...

Financial Services Commercial Facilities
McAfee Labs | McAfee Blogs ·

Following up on our previous blog, How to Stop the Popups, McAfee Labs saw a sharp decrease in the number... The post Microsoft’s Edge over Popups (and Google Chrome) appeared first on McAfee Blog.

Financial Services Commercial Facilities
Maxwell Dulin's Resources ·

DFX Finance is a decentralized exchange for stablecoins. The exchange had flash loan functionality as well. A flash loan is where a large amount of money can be borrowed by a user, as long as the...

Wiz Blog | RSS feed ·

Fully understand the impact and architecture behind any threat to streamline and speed effective response with a first-of-its-kind integration combining the Wiz Security Graph’s deep cloud and...

Information Technology
UpGuard Cybersecurity News ·

Medibank suffered a data breach that compromised 9.7 million current and former customers.

Financial Services Information Technology
UpGuard Cybersecurity News ·

Cybercriminals believed to be working for a criminal or state-sponsored operation breached Optus' internal network, compromising personal information impacting up to 9.8 million customers.

Information Technology Energy
UpGuard Cybersecurity News ·

Medibank suffered a data breach that compromised 9.7 million current and former customers.

Financial Services Information Technology
UpGuard Cybersecurity News ·

Cybercriminals believed to be working for a criminal or state-sponsored operation breached Optus' internal network, compromising personal information impacting up to 9.8 million customers.

Information Technology Energy
Maxwell Dulin's Resources ·

Apache Batik is a library used for parsing Scalable Vector Graphics (SVG) and transforming them into other formats. Even crazier, the documentation mentioned executing JavaScript, loading and...

McAfee Labs | McAfee Blogs ·

Authored by: Christy Crimmins and Oliver Devane Football (or Soccer as we call it in the U.S.) is the most... The post Don’t Get Caught Offsides with These World Cup Scams appeared first on McAfee Blog.

Tick Financial Services Commercial Facilities
Maxwell Dulin's Resources ·

In April of 2022, Meta announced a Contract Point Deanonimization. These guidelines are bugs that enable matching of Uniquely Identifiable Information (UII) to User IDs. This goes from finding...

Maxwell Dulin's Resources ·

Recently, the author of this post had found an issue with the account recovery flow. While trying to send multiple OTP codes, they hit an SMS captcha flow. Most people would stop here, but the...

maxwelldulin ·

Extensions within the Chrome browser are immensely important for building out the correct functionality. However, these extensions have incredible capabilities compared to the standard web page....

maxwelldulin ·

Team Finance, a crypto token launchpad, was hacked. They were attempting to migrate from the Uniswap v2 to v3. This whole project was a safe keeping for funds will some sort of migration was...

Wiz Blog | RSS feed ·

vSphere integration makes Wiz the first cloud security platform to protect both on-premises and cloud environments without an agent.

Information Technology
Orange Cyberdefense ·

The goal of this blog post is to present a privilege escalation I found while working on ADCS. We will see how it is possible to elevate our privileges to NT AUTHORITY\SYSTEM from virtual and...

Information Technology
maxwelldulin ·

Kerberos is an old authentication protocol that is still used all over the place. The core security concept is using encryption to prove knowledge of user credentials. In the handshake process for...

maxwelldulin ·

The goal of the talk was to figure out what a user could do with no permissions. Android has three types of permissions for actions: Application defined. These are permissions and capabilities...

maxwelldulin ·

While reviewing the Java standard library, the author came across a strange attack surface: a custom JIT compiler for XSLT programs. The reason this looked so juicy was that this was exposed to...

Information Technology
maxwelldulin ·

JunOS is a service to automate network operations and many other things. For this, there is a client application that allows for securing connecting to it called SSLVPN. This is what the author...

maxwelldulin ·

Static site generators, such as Jekyll, Hugo, Next.js and others were meant to be so bare bones that security risks were eliminated. This was because, in the past, people were getting pwned with...

Nuclear
Maxwell Dulin's Resources ·

The original XBox had many security problems that resulted in two mods bypassing all of the security checks to run unsigned code. First, the hardware mod required soldering on a modchip to the...

Commercial Facilities
Curated Intelligence ·

Community Feature - @1ce7eaCurated Intelligence member Robin Dimyan has shared his methodology behind developing an Early Warning System (EWS) using Cyber Threat Intelligence. The blog poses the...

Commercial Facilities Financial Services
Maxwell Dulin's Resources ·

Curve is a popular Automated Market Maker (AMM) that uses a Liquidity Pool (LP) to get the funds. Many contracts interact with Curve to find out the going rate of a token. The get_virtual_price()...

Energy
Cloud Threat Landscape ·

Dropbox disclosed a security breach where attackers stole 130 code repositories from one of its GitHub accounts by using credentials obtained from phishing Dropbox employees. The breach was...

Cloud Threat Landscape ·

On 2022-11-01, an incident was reported, involving an unknown actor, gaining initial access via End-user compromise, targeting GitHub to achieve Data exfiltration.

Maxwell Dulin's Resources ·

Jupyter Notebooks is an interactive computing platform while VS Code is a text editor. Somebody wrote an extension for Jupyter Notebooks to work with VS code. In the past, there was an XSS...