IM
IronMonkey Threat Research
LIVE
|
Articles 27,191
|
CVEs 350,872
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,159 articles — Page 866 of 906
Threat Intelligence ·

At Google Cloud, our mission is to help organizations transform cybersecurity with frontline intelligence, expertise, and AI-powered innovation. Nowhere is this needed more than in security...

Information Technology Security & Identity
Cloud Threat Landscape ·

On 2023-09-18, a research was reported, involving , gaining initial access via Software misconfig, targeting Azure Storage to achieve Resp. disclosure.

Cloud Threat Landscape ·

Researchers uncovered a cryptojacking operation targeting AWS services such as AWS Amplify, AWS Fargate, and Amazon SageMaker to mine cryptocurrency. The timeline of this operation spans from May...

Financial Services
@BushidoToken Threat Intel ·

The dozens of cybercriminals that made up the Conti group continue to launch campaigns unabated. Previously in 2022, I blogged about how following the Conti Leaks, the operators of Conti continued...

Financial Services Energy
Threat Intelligence ·

For any company, naming a product or service is complex and time-consuming. This process is particularly challenging in the pharmaceutical industry. Typically, companies start by brainstorming and...

Information Technology AI & Machine Learning Developers & Practitioners
Threat Intelligence ·

In October 2022, BigQuery launched the search indexes and SEARCH function that enable using Google Standard SQL to efficiently pinpoint specific data elements in unstructured text and...

Information Technology Developers & Practitioners Data Analytics
Threat Intelligence ·

Engineers use Bigtable to hold vast amounts of transactional and analytical information as part of their data workflow. We are excited about the release of Bigtable change streams that will...

Information Technology Infrastructure Data Analytics
Wiz Blog | RSS feed ·

Lock down your cloud infrastructure with the new Wiz integration with Microsoft Sentinel. Gain full context, support thorough investigations, and automate your response for ultimate security.

Information Technology
Cloud Threat Landscape ·

According to Microsoft Threat Research, during a campaign by Iranian state-sponsored actor Peach Sandstorm, they were observed utilizing password spray attacks to gain unauthorized access to...

Uncategorized - bellingcat ·

Online court filings place Kent McLellan, who goes by the alias Boneface, in Florida at the same time he claims he was fighting in last year’s bloody siege of Mariupol. The post US neo-Nazi says...

Iron Transportation Systems Defense Industrial Base Americas Investigations
Kaspersky ICS CERT (English) ·

The statistical data presented in the report was received from ICS computers protected by Kaspersky products that Kaspersky ICS CERT categorizes as part of the industrial infrastructure at organizations.

Critical Manufacturing Publications
Maxwell Dulin's Resources ·

Cryptsetup is used to unlock the system partition when using the Linux Unified Key Setup (LUKS). This is all about full disk encryption! When booting up in Linux, there is a special file system...

Transportation Systems Information Technology
Maxwell Dulin's Resources ·

Full disk encryption for an unintended computer is a surprising difficult problem to solve. A classic way of doing this is using a TPM to store an encryption key but only having the encryption key...

Maxwell Dulin's Resources ·

A commit-reveal scheme is a mechanism to have a secret value on chain without actually disclosing it until it's necessary. This is useful since everything on the blockchain is public. The commit...

Energy Financial Services
Cloud Threat Landscape ·

The security breach was discovered by Rollbar on September 6 when reviewing data warehouse logs showing that a service account was used to log into the cloud-based bug monitoring platform.Once...

Cloud Threat Landscape ·

The threat actors gained access to the customer's Azure portal, where they obtained the Azure key required to access the storage account programmatically. The adversary encoded the keys using...

Wiz Blog | RSS feed ·

The Wiz Runtime Sensor for Kubernetes graduates to general availability with proven ability to detect cloud attacks, greater customization for detections, and new cloud-native response capabilities

Information Technology
Wiz Blog | RSS feed ·

Joint customers can now detect and prioritize public exposures with Wiz and automatically remediate unwanted exposures with FortiGate NGFW.

Information Technology Chemical
Fox-IT International blog ·

Authored by Joshua Kamp (main author) and Alberto Segura. Summary Hook and ERMAC are Android based malware families that are both advertised by the actor named “DukeEugene”. Hook is the latest...

Safe Financial Services Defense Industrial Base Uncategorized
Fox-IT International blog ·

Authored by Joshua Kamp (main author) and Alberto Segura. Summary Hook and ERMAC are Android based malware families that are both advertised by the actor named “DukeEugene”. Hook is the latest...

Safe Information Technology Financial Services Uncategorized
Wiz Blog | RSS feed ·

Learn about the process of preventing security issues by changing things outside of your environment by looking at how a misconfiguration was occurring when Github Actions were integrated with AWS...

Information Technology
McAfee Labs | McAfee Blogs ·

Authored by Yashvi Shah Agent Tesla functions as a Remote Access Trojan (RAT) and an information stealer built on the... The post Agent Tesla’s Unique Approach: VBS and Steganography for Delivery...

Financial Services Government Facilities
Cloud Threat Landscape ·

The researchers observed a malicious IP address, previously flagged for conducting SSH brute force attempts, communicating with a malicious shell script named hoze. This script downloads xrx.tar,...

Wiz Blog | RSS feed ·

The Wiz research team examines Microsoft's latest Storm-0558 findings and summarizes the key learnings cloud customers should take away from the incident.

Storm-0558 Critical Manufacturing Information Technology
Blue Team Archives - Black Hills Information Security, Inc. ·

Patterson Cake // PART 1 PART 2 In part one of “Wrangling the M365 UAL,” we talked about acquiring, parsing, and querying UAL data using PowerShell and SOF-ELK. In part […] The post Wrangling the...

How-To Incident Response
Threat Analysis Group (TAG) ·

Threat Analysis Group shares findings on a new campaign by North Korean actors targeting security researchers.

Maxwell Dulin's Resources ·

The Cosmos SDK is a blockchain development framework for application specific blockchains. Built into its core is blockchain interoperability by IBC (interblockchain communication). Within the...

Transportation Systems Financial Services
Wiz Blog | RSS feed ·

During the summer of 2023, using the Wiz Sensor, Wiz Research detected several different cryptomining campaigns targeting cloud workloads. Learn about these campaigns and their associated IoCs,...

Information Technology Chemical
ICS Medical Advisories ·

1. EXECUTIVE SUMMARY ​CVSS v3 9.8 ​ATTENTION: Exploitable remotely/low attack complexity ​Vendor: Softneta ​Equipment: MedDream PACS ​Vulnerabilities: Exposed Dangerous Method or Function,...

Critical Manufacturing Healthcare and Public Health
Cloud Threat Landscape ·

On 2023-09-04, a campaign was reported, involving an unknown actor, gaining initial access via 1-day vulnerability, targeting MinIO with unknown impact.