IM
IronMonkey Threat Research
LIVE
|
Articles 27,189
|
CVEs 349,550
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 27,157 articles — Page 880 of 906
maxwelldulin ·

This post is part 2 of a chain of bugs that lead to getting code execution. In part 1, a SSRF and line feed injection bug in a query language were found. However, the LQL injection is blind. In...

maxwelldulin ·

Google Nest Hub is an always on smart home display. It runs a device based upon the Amlogic S905D3G SoC. The device has a hidden USB port, making it prime-time for attackers. By holding a...

Critical Manufacturing
maxwelldulin ·

Sam Curry decided to hit the auto industry. This ranges from BMW to Ferrari. First, they were looking at a platform with a custom SSO. They started with OSINT tools like gau and ffuf, to find a...

Transportation Systems Critical Manufacturing
Wiz Blog | RSS feed ·

Learn how to detect malicious persistence techniques in AWS, GCP & Azure after potential initial compromise, like with the CircleCI incident

Stone Panda Cozy Bear Information Technology
Wiz Blog | RSS feed ·

Wiz announces availability of new regional data center and adds support for Essential Eight controls.

Information Technology Financial Services
Wiz Blog | RSS feed ·

Hear from security leaders about their plans, strategies, and priorities for the new year.

Financial Services Transportation Systems
Wiz Blog | RSS feed ·

In this second blog post, we will discuss lateral movement risks from Kubernetes to the cloud. We will explain attacker TTPs, and outline best practices for security practitioners and cloud...

Information Technology
Cloud Threat Landscape ·

On December 29, 2022, CircleCI's security team were alerted to suspicious activity on one of their customer's GitHub OAuth tokens. The team then rotated all GitHub OAuth tokens on December 31,...

Wiz Blog | RSS feed ·

The developers of PyTorch (a popular machine-learning framework) recently identified a malicious dependency confusion attack on the open-source project. Security teams are advised to check for...

Information Technology
Curated Intelligence ·

Jair Santanna (from Northwave Security) in collaboration with Curated Intelligence recently shared his methodology about how to analyze the databases of cybercriminal websites that offer...

Information Technology
Cloud Threat Landscape ·

PyTorch-nightly Linux packages installed via pip between December 25th and December 30th, 2022 ran a malicious binary. The malicious binary was introduced by a dependency, torchtriton, that was...

Critical Manufacturing Information Technology
maxwelldulin ·

The iPod 1G Touch was the first version in an amazing line of devices from Apple. So, the author wanted to emulate the device for future generations to enjoy. This was done via a branch of QEMU;...

maxwelldulin ·

While looking at Cambium, the authors found a simple SQL injection vulnerability. As always, the authors were not using parameterized queries, leading to string concatenation for a SQL injection....

Government Facilities Communications
@BushidoToken Threat Intel ·

Welcome to the final BushidoToken blog of 2022. Over the last year or so, an associate of mine in the UK has been targeted by a persistent Chinese-speaking scammer. The scammer often calls once or...

Financial Services Energy
Maxwell Dulin's Resources ·

The three minute video consists of the author trying to access JTAG ports within the chip. So, they scrape off the SoC with a pair of tweezers then use some acid to get to the reset. After this,...

Information Technology
maxwelldulin ·

Google Home is a suite of products for around the house automation. While using the device, they noticed how seamless adding users was. Additionally, the set of automated routines, that can be ran...

Communications Critical Manufacturing
Blog ·

In the past few years I created some twitter threads (e.g. Windows Kernel Security Linux Kernel Security) on a number of publications I found the most interesting within the vulnerability research...

Energy Apple XNU
Cloud Threat Landscape ·

Permiso identified a credential harvesting campaign targeting cloud infrastructure for the purpose of harvesting credentials. The majority of the victim system were running public facing Juptyer...

Information Technology
Wiz Blog | RSS feed ·

Critical RCE vulnerability found in Linux kernel's `ksmbd` module: remote attackers can execute code without authentication. The module is not enabled by default on most operating systems.

Maxwell Dulin's Resources ·

Omni is an NFT money market on Ethereum. It allowed for borrowing and lending via NFTs. For instance, a user could borrow an ERC20 asset for the NFT put up as collateral. This makes the NFT more...

Healthcare and Public Health
maxwelldulin ·

ping is a program to test network reachability of remote hosts. ping makes use of raw sockets in order to make ICMP messages. ping reads raw IP packages from the network responses. As part of this...

maxwelldulin ·

CheckMk is an IT infrastructure monitoring solution written in Python and C++, similar to Zabbix and Icinga. The architecture has an Apache reverse proxy which directs request to several web...

maxwelldulin ·

The NXP SoC chip has various fuse configurations for security sensitive operations. Once a fuse has been blown, the functionality is forever disabled. The fuse SDP_READ_DISABLE is used to prevent...

Silver Fox Transportation Systems Government Facilities
Maxwell Dulin's Resources ·

Riot Games is a video game creator with many different websites. Because of this, there are many different endpoints that need access to metadata associated with the user. In order to do this,...

Wiz Blog | RSS feed ·

A new exploit method targeting CVE-2022-41080 and CVE-2022-41082 vulnerabilities in Exchange servers, which can bypass previous workarounds, has been discovered and exploited in the wild....

Wiz Blog | RSS feed ·

Wiz enhances its Dynamic Scanner to detect publicly exposed, unauthenticated APIs

Healthcare and Public Health Information Technology
Cloud Threat Landscape ·

On 2022-12-21, an incident was reported, involving an unknown actor, gaining initial access via Unknown, targeting GitHub to achieve Data exfiltration.

Wiz Blog | RSS feed ·

Easily detect dangling domains to reduce the risk of phishing campaigns and cookie harvesting of organization’s customers.

Information Technology
n1ghtw0lf ·

In the previous post we talked about writing x64dbg scripts, now let’s dive deeper and write our own plugin to do the same job (automatically dumping unpacked PE payloads in memory). x64dbg comes...

Transportation Systems Tutorials
Wiz Blog | RSS feed ·

Wiz extends its cloud analysis with an external scanner, giving customers an attacker's view of their externally exposed resources to reduce noise.

Information Technology