IM
IronMonkey Threat Research
LIVE
|
Articles 27,190
|
CVEs 350,872
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,158 articles — Page 869 of 906
Wiz Blog | RSS feed ·

Handpicked by our research team: The annual list of 16 thought leaders you need on your feed.

Information Technology
Maxwell Dulin's Resources ·

Conic uses the Curve protocol for trying to earn rewards. It has a concept of omnipools where the same underlying asset is distributed among multiple Curve pools. Currently, I'm not seeing the...

Critical Manufacturing
Wiz Blog | RSS feed ·

Enhance software security and supply chain risk management with Wiz's agentless scanning technology for effortless SBOM creation

Information Technology Government Facilities
@BushidoToken Threat Intel ·

Online and at conferences, people ask me how to get started in threat intel. What I usually offer as advice to budding analysts starting out is to practise analysing things in the wild. And by...

Financial Services Energy
Maxwell Dulin's Resources ·

ssh-agent is a program for hold private keys for authentication through ENV variables. Agent forwarding is the process of forwarding from further remote hosts, removing the need for authentication...

maxwelldulin ·

In every field, there are people at the top and bottom. Why is this? What makes somebody elite at a subject? This is what the post is about. With so many aspiring people, there has to be a secret....

Wiz Blog | RSS feed ·

Our investigation of the security incident disclosed by Microsoft and CISA and attributed to Chinese threat actor Storm-0558, found that this incident seems to have a broader scope than originally...

Storm-0558 Information Technology
McAfee Labs | McAfee Blogs ·

Authored by Yukihiro Okutomi McAfee’s Mobile team observed a smishing campaign against Japanese Android users posing as a power and... The post Android SpyNote attacks electric and water public...

Financial Services Water
maxwelldulin ·

When Ethereum moved from proof of work to proof of stake, it added some new functionality. One of these with the replacement of block.difficulty with block.prevrandao. Although, the opcode is...

Kaspersky ICS CERT (English) ·

In this article (which is the first part of the report) we analyze common TTPs of implants used by threat actors to establish a persistent remote access channel into the infrastructure of...

Publications
Wiz Blog | RSS feed ·

Gain a deeper understanding of why it's essential to monitor non-standard pods and containers, including static pods, mirror pods, init containers, pause containers, and ephemeral containers...

Information Technology Energy
Wiz Blog | RSS feed ·

In the earlier posts in this series, we showed not only how to get rid of unused access keys, but also how to minimize risk by applying a least-privilege strategy. In this final post, we’ll at...

Information Technology
Orange Cyberdefense ·

It’s that time of year again where we head out to the desert, more specifically Las Vegas, for what is known as Hacker Summer Camp to attend Black Hat and DEF CON 31! Like previous years, the...

n1ghtw0lf ·

Howdy! I’m finally back with another malware deep dive report. This time we are digging into GCleaner. GCleaner is a Pay-Per-Install (PPI) loader first discovered in early 2019, it has been used...

Malware Analysis
maxwelldulin ·

In this protocol, it's a standard auction but the lowest price wins. If a user gets outbid, they get a refund but must call a function in order to perform the refund. The sale is considered ended...

Energy Critical Manufacturing
Cloud Threat Landscape ·

On 2023-07-14, an incident was reported, involving TraderTraitor, gaining initial access via End-user compromise, to achieve Supply chain attack.

Critical Manufacturing
maxwelldulin ·

The authors knew about a potential RCE in Adobe ColdFusion. So, they went to the Java code and started diffing from the previous version. While doing this, they found the function...

Maxwell Dulin's Resources ·

Rodeo Finance is a leveraged yield farming protocol. Apparently, it also supports loan functionality. The service was uses a price oracle to determine the price of assets when borrowing and...

Financial Services
Curated Intelligence ·

Threat actor profiles are made for a range of reasons. An example trigger for creating a new profile can include after an incident, e.g., an internal detection or supply chain breach has been...

Commercial Facilities Financial Services
ICS Medical Advisories ·

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 8.2 ATTENTION: Low attack complexity Vendor: Becton, Dickinson and Company (BD) Equipment: Alaris PCU, Guardrails Editor, Systems Manager, Calculation...

Critical Manufacturing Healthcare and Public Health
Cloud Threat Landscape ·

A cloud attack campaign possibly orchestrated by the threat actor known as TeamTNT. The campaign primarily involves an aggressive cloud worm that targets JupyterLab and Docker APIs to deploy...

Wiz Blog | RSS feed ·

PyLoose is a newly discovered Python-based fileless malware targeting cloud workloads. Get a breakdown of how the attack unfolds and the steps to mitigate it.

Information Technology Chemical
Cloud Threat Landscape ·

On 2023-07-11, a campaign was reported, involving Storm-0558, gaining initial access via End-user compromise, while using Phishing, LSASS dumping, with unknown impact. The following tools were...

Cloud Threat Landscape ·

In mid-2023, an unknown financially-motivated threat actor began targeting publicly exposed Jupyter Notebook instances to hijack them for running cryptomining operations. The threat actor deployed...

Cloud Threat Landscape ·

On 2023-07-11, a campaign was reported, involving APT31, gaining initial access via ,. The following tools were observed: Rekoobe.

Cloud Threat Landscape ·

In July 2023, Microsoft disclosed that Storm-0558, a threat actor attributed to China, managed to acquire a signing key that allowed them to gain illicit access to Exchange and Outlook accounts....

Cloud Threat Landscape ·

In July 2023, details of recent activities related to ScarletEel were published, showing the advancement of the attacker over time. The threat actors expanded their arsenal to include new tools...

Orange Cyberdefense ·

On red team engagements, I often use social engineering to get one of my client’s employees to run my malicious code on their machines, allowing me to get access to their system. A typical...

Information Technology
Orange Cyberdefense ·

I’ve written a couple of blog posts in the past in which I explain how to use Marcus Mengs’ truly excellent P4wnP1. The most common deployment scenario involves a Raspberry Pi Zero W, or possibly...

Commercial Facilities Information Technology
Report Feed ·

Key findings and full report from the 6th year of the Active Cyber Defence (ACD) programme.

Government Facilities