IM
IronMonkey Threat Research
LIVE
|
Articles 25,453
|
CVEs 337,950
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 25,421 articles — Page 829 of 848
Vulnerabilities – Threatpost ·

The CISA has seen a resurgence of the malware targeting a range of verticals and critical infrastructure organizations by exploiting RDP, firewall vulnerabilities.

Healthcare and Public Health Information Technology Malware Vulnerabilities
Wiz Blog | RSS feed ·

How Wiz Research uncovered multiple related vulnerabilities in PostgreSQL-as-a-Service offerings from GCP, Azure, and others.

Information Technology
maxwelldulin ·

Before the internet, the Super Nintendo (SNES) had an online gaming community via the XBAND Video Game Modem. The goal of the author was to create complete emulation support for XBAND. XBAND...

Commercial Facilities Financial Services
maxwelldulin ·

While playing around with the GreatFET One, the author found that Xorg would crash with format string payloads. After an advisory from Xorg that related to "input devices" the author decided to...

Critical Manufacturing
maxwelldulin ·

The hacker has picked up a random IoT alarm from China. In parts 1 and 2, they dumped the firmware and figured out how it works. In this post, they decided to go through the reverse engineering of...

Communications
maxwelldulin ·

MicroTik recently added the ability to containerize application running on their routing. This is the functionality being targeted in this attack. An interesting feature is allowing for mount...

maxwelldulin ·

Cloudflare Email Routing was in a closed beta, with the author not being invited. A check in the UI was placed to allow access to the functionality or not; this could be bypassed via changing a...

Information Technology
maxwelldulin ·

Virtualization, especially with hypervisors in place, needs to ensure that no assets leak from one virtual machine to the other or from the hypervisor to the virtual machine. Failure to do so may...

Commercial Facilities
Wiz Blog | RSS feed ·

Just two years since its launch, Wiz protects hundreds of the world’s leading organizations by enabling them to build faster and more securely in the cloud

Information Technology Chemical
Wiz Blog | RSS feed ·

Wiz continues momentum with addition of security luminary Emily Heath to board of directors; expands executive team to lead hyper-growth

Information Technology Transportation Systems
Wiz Blog | RSS feed ·

Q&A: Why Wiz caught the attention of DocuSign’s Former CTSO

Information Technology
Wiz Blog | RSS feed ·

Companies are turning to Wiz every day to gain instant visibility into their cloud environments.

Information Technology Chemical
Wiz Blog | RSS feed ·

In just two years, Wiz helps hundreds of customers protect their cloud infrastructure and innovate more quickly. As a result, Wiz has become the fastest-growing software company ever, scaling from...

Information Technology
Vulnerabilities – Threatpost ·

August Patch Tuesday tackles 121 CVEs, 17 critical bugs and one zero-day bug exploited in the wild.

Vulnerabilities full
Wiz Blog | RSS feed ·

Founded in 2020, Wiz is the youngest company on the list.

Information Technology
Maxwell Dulin's Resources ·

Charged Particles is a decentralized NFT marketplace. A ERC721 NFT is called a Proton, which is ready to be energized by adding interest-bearing assets to it. A Charged Particle can have a...

Maxwell Dulin's Resources ·

Maximal/Miner Extractable Value (MEV) is a measure of the profit that a miner can make by ordering the blocks they produce. For an attacker, this can be includes, excluding or reordering the...

Food and Agriculture Government Facilities
Maxwell Dulin's Resources ·

Sovryn is a decentralized trading and lending protocol. It is deployed on RSK, a sidechain of the Bitcoin blockchain. When lending give out money, they earn interest on their BTC being used for...

Financial Services Healthcare and Public Health
Wiz Blog | RSS feed ·

Wiz is excited to be back in Las Vegas for Black Hat 2022 as a sponsor of this year's conference. At Black Hat, you'll have the opportunity to learn from our research and product experts,...

Chemical Commercial Facilities
Kaspersky ICS CERT ·

The attackers were able to penetrate dozens of enterprises and even hijack the IT infrastructure of some, taking control of systems used to manage security solutions. The goal of this series of...

Publications
maxwelldulin ·

Yield farming is lending or staking cryptocurrency in exchange for a percentage of interest. By providing some funds as an individual, you can take some of the groups profit. In yield farming, a...

Energy Food and Agriculture
Maxwell Dulin's Resources ·

Vesper is a DeFi platform that should work and make money for you. This money is called yield from using your DeFi in various places. When the function rebalance() is called, it takes the...

Food and Agriculture Financial Services
n1ghtw0lf ·

YARA is a tool aimed at helping malware researchers to identify and classify malware samples. It’s considered to be the pattern matching swiss knife for malware researchers. If you are not...

Tutorials
Cloud Threat Landscape ·

A threat actor dubbed “Oktapus” / “ScatterSwine” conducted a widespread SMishing campaign against 136 organizations, and in some cases (Such as MailChimp, DoorDash and Digital Ocean) was...

Maxwell Dulin's Resources ·

Zapper is a wallet platform that helps make the platform easy to use. When joining a pool, you need several different types of assets. If a user wanted to join this pool, it would require many...

Maxwell Dulin's Resources ·

PancakeSwap uses Crowdin for localization management. This is making the website available in many different languages. The API key on the website for Crowdin had bad permissions though. Instead...

Healthcare and Public Health
Vulnerabilities – Threatpost ·

Separate phishing campaigns targeting thousands of victims impersonate FedEx and Microsoft, among others, to trick victims.

Transportation Systems Hacks Vulnerabilities
Spam – Graham Cluley ·

Did Russian security Kaspersky really choose to send an email to its customers addressing them as "dear and lovely"? Had Kaspersky suffered a data breach? Had a hacker found a way to send messages...

Spam Vulnerability
Wiz Blog | RSS feed ·

Wiz finds Azure customers remain unpatched from cloud middleware vulnerability and collaborates with Microsoft to introduce an auto-patching solution against cloud middleware security issues and...

Information Technology Transportation Systems
Wiz Blog | RSS feed ·

Affected organizations are required to update installed agents that use the OMI cloud middleware software

Information Technology Transportation Systems