IM
IronMonkey Threat Research
LIVE
|
Articles 27,190
|
CVEs 350,872
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,158 articles — Page 871 of 906
Maxwell Dulin's Resources ·

The Yield Protocol is a fixed-rate borrowing and lending protocol on Ethereum. As demonstrated by the name "Yield", getting yield from the assets provided is an extremely important part of this...

Emergency Services Energy
Maxwell Dulin's Resources ·

SSH is used to log in to servers by everyone. Finding a vulnerability in the authentication process for this would be catastrophic. This is exactly what the author found here! In this case, it is...

Information Technology Communications
Wiz Blog | RSS feed ·

Reduce noise of traditional CSPM tools with context-based deep risk assessment, enabling you to prioritize the misconfigurations that put your environment at critical risk.

Chemical Information Technology
maxwelldulin ·

Jimbo creates a semi-stablecoin via rebalancing. This is version 2 of the protocol, which was an attempt to fix the first version with too many bugs in it. The whole point of this protocol is...

Wiz Blog | RSS feed ·

Put yourself to the test with our unique CTF challenge and boost your AWS IAM knowledge. Do you have what it takes to win The Big IAM Challenge?

Information Technology
Maxwell Dulin's Resources ·

DFX Finance is a decentralized foreign exchange protocol that allows users to swap many stablecoins. DFX is an AMM that exchanges tokens according to a bonding curve, which is dynamically...

Energy Healthcare and Public Health
Wiz Blog | RSS feed ·

Agentless visibility and risk assessment paired with Wiz Runtime Sensor real-time detection for the best of both worlds

Information Technology Financial Services
Wiz Blog | RSS feed ·

Today we are excited to announce the Wiz Runtime Sensor. The sensor collects signals in real-time from the workload runtime to simplify threat detection and response in the cloud as part of our...

Information Technology Energy
Cloud Threat Landscape ·

According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment by exploiting a WSO2 RCE vulnerability (CVE-2022-29464) affecting...

Cloud Threat Landscape ·

According to CrowdStrike research, in a certain incident Cosmic Wolf compromised a target organization’s cloud environment using a stolen credential. They used this to authenticate using a CLI and...

Cosmic Wolf
Cloud Threat Landscape ·

According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment using an RCE vulnerability affecting PHP applications on multiple...

Wiz Blog | RSS feed ·

Detect and mitigate CVE-2023-34362, a remote code execution vulnerability in MOVEit Transfer exploited in the wild. Organizations should patch urgently.

Information Technology
Maxwell Dulin's Resources ·

The author of this post had recently bought a Phillips Sonicare toothbrush. When reviewing the documentation, it says that the product operates at 13.56MHz, which indicates this uses NFC. The...

Healthcare and Public Health Critical Manufacturing
Maxwell Dulin's Resources ·

CosmWasm is a smart contract platform that can be used on Cosmos. This allows for a similar interaction of Solidity based smart contracts on the EVM. Being able to find a denial of service (DoS)...

Maxwell Dulin's Resources ·

Security Enhanced Linux (SELinux) is an added layer of security to the OS kernel. Using it, access controls can be put on applications, processes and file on a system. Just because you have root...

Wiz Blog | RSS feed ·

Learn how to identify unused and unnecessary long-lived IAM User access keys.

Kaspersky ICS CERT (English) ·

During IR, while trying to figure out what went wrong, we’ve found numerous issues

Publications
Orange Cyberdefense ·

For our annual internal hacker conference dubbed SenseCon in 2023, I decided to take a quick look at Docker Desktop Extensions. Almost exactly a year after being announced, I wondered what the...

Financial Services
Maxwell Dulin's Resources ·

Solidity has error handling like most languages do. It looks similar to JavaScript with try and catch blocks. The docs can be read at here. In the initial example, the author gives a fairly simple...

Energy
@BushidoToken Threat Intel ·

I wanted to do something a bit different and fun so I created a new site hackerfiction.medium.com with one purpose: Telling fictional short stories about hacking using AI. I’ve explained why and...

Financial Services Energy
Maxwell Dulin's Resources ·

The article goes into the finance between many different DeFi algorithms. This is a large article with many protocols in it, including Bancor, Uniswap, Curve, Clipper and more.

Maxwell Dulin's Resources ·

Decentralized Finance (DeFi) is great eco-system for opening up everyone to many financial instruments. You know what's not great? DeFi hacks. A large percentage of these occur from manipulating...

Financial Services Transportation Systems
Maxwell Dulin's Resources ·

Reentrancy is a fundamental attack in the Solidity security space. This is when a user can recursively call a contract while it has not had it's state fully updated. Developers should follow the...

Transportation Systems Financial Services
Maxwell Dulin's Resources ·

Since Ethereum and other layer 1 blockchains are slow and expensive, there are many layer 2 (L2) protocols appearing. The idea is to roll all the transactions on the L2 EVM into a single...

maxwelldulin ·

The Binance Chain IAVL Merkle Tree hack gained from flags on security issues within the Cosmos SDK. As a result, the developers started diving into the code base to look for further issues. From...

Orange Cyberdefense ·

Rogan brought half of his hardware parts bin to the hackathon! Michael Rodger, Daniel Scragg, Isak van der Walt, Thulani Mabuza and Rogan Dawes formed the Chubby Hackers team to investigate the...

Critical Manufacturing Information Technology
0xToxin ·

Part 2 of analyzing the KrakenKeylogger Malware

Information Technology Threat Hunting KrakenKeylogger
Maxwell Dulin's Resources ·

Most staking contracts are simply a copy of the SushiSwap MasterChef contract. By understanding this, we will be able to understand most in-moment math handling and most staking contracts. The...

Energy
Maxwell Dulin's Resources ·

The author was hunting for a CSRF vulnerability when they noticed some odd functionality: a random subdomain was capable of performing authorized actions on the main API of the website. This was...

Wiz Blog | RSS feed ·

This blog post will discuss lateral movement risks from on-prem to the cloud. We will explain attacker TTPs, and outline best practices for cloud builders and defenders to help secure their cloud...

Information Technology