I was surprised to receive an email this week telling me that I had renewed my annual subscription for McAfee virus protection. Would you, or a member of your family, have fallen for this scam?
Enzyme Finance is an asset management built on Ethereum. Anyone can create, manage or invest using custom investment strategies with a variety of assets. The tool is designed to make it easy to...
Celer is a blockchain protocol that enables cross-chain communication. It is built on top of Cosmos with the Stage Guardian Network (SVNv2). Validators of SGN are responsible for monitoring the...
Two parameters are used in order to prevent validators from holding onto transactions until it's convenient for them to spend. First, there is slippage. This is used in order to prevent a...
[…] a real example of an AWS Kubernetes cluster infection through a software development supply chain compromise. The attackers were able to get AWS credentials from a DevOps workstation and use...
I recently came across a cool GitHub repo from Zscaler's ThreatLabz team (see here) which contains a whole array of ransom notes from known and new ransomware families. I imagine that Zscaler has...
Detect and mitigate CVE-2023-32784, a vulnerability in KeePass which allows the extraction of the master password in cleartext from the application's memory.
Part 1 of analyzing the KrakenKeylogger Malware
Frost & Sullivan applauds Wiz for its innovation and impact in the cloud security industry.
CS:GO is a popular online game from 2012 with many public servers. Mods, textures, 3D models and more all create a great attack surface. The source engine has it's own TCP-like network stack over...
I recently came across an interesting campaign that is using fake websites to distribute malware. Although this TTP is not new, it seems to be on the rise. Anecdotally, I've seen it in multiple...
There's good news if you're plagued by shared Google Drive files from strangers. Google Drive is getting a spam folder.
Google has announced a new policy on dealing with inactive accounts - and it's an important read for anyone who doesn't regularly login. Read more in my article on the Hot for Security blog.
Tricking a plug with a too-long name could lead to buffer overflows, injections.
rvrsh3ll // Introduction This blog post is intended to give a light overview of device codes, access tokens, and refresh tokens. Here, I focus on the technical how-to for standing […] The post...
In 2022, Mandiant identified attacker activity centered in Microsoft Azure that Mandiant attributed to UNC3944. Mandiant’s investigation revealed that the attacker employed malicious use of the...
8220 Gang, a financially-motivated Chinese threat actor known for their cryptojacking activity, has been observed by researchers to be exploiting CVE-2020-14883, a remote code execution (RCE)...
KubeCon Europe is the largest open-source community conference in Europe with hundreds of talks. We picked our favorite Kubernetes security sessions available online.
This website gets itself over TLS and comments on every single byte. It's a really neat visualization of the process.
Wiz for DSPM: Additional enhancements to help you correlate suspicious events related to unprotected data in near real-time.
Das U-Boot - the universal boot loader, is a bootloader for embedded boards for ARM, MIPS and several other processors. This is typically installed early on in the boot process to initialize...
Docker is a containization platform used all around. I knew use it to host the Spokane Cyber Cup! Docker was ported from Linux to Windows with a completely different under-the-hood implementation...
There are many, many ways to login to AWS. The console and the CLI via Access Keys and Secret Keys is one of them. Multi Factor Authentication (MFA) can be setup to work on the CLI as well. To do...
The goal of this post for the author was created a modchip for the Wii U. It has a few known vulnerabilities, but not ever many good for homebrew. Additionally, the Wii's encrypted per-console OTP...
The Adobe suite of products are immensly popular, especially their PDF readers. The PDF rendering process runs in a protected mode called a sandbox with restricted permissions. The PDF renderer...
LinkedIn is a social media site for business professionals. An entity on a website is commonly referenced by an identifier. On LinkedIn, this could be a post, picture or many other things. When...
Authored by: Anandeshwar Unnikrishnan Stage 1: GULoader Shellcode Deployment In recent GULoader campaigns, we are seeing a rise in NSIS-based... The post GULoader Campaigns: A Deep Dive Analysis...
Optimeyes's Jenkins instance was publicly exposed, albeit with few viewable workspaces and locked down admin permissions. However, the build information for each past build contained a link to the...
Authored By Anuradha McAfee Labs has recently observed a new wave of phishing attacks. In this wave, the attacker has... The post New Wave of SHTML Phishing Attacks appeared first on McAfee Blog.
Images made with Bing Create AIPrologueI find uncovering new campaigns and sharing research on novel threats is one the most enjoyable parts of my job as a CTI researcher. Especially the types of...