IM
IronMonkey Threat Research
LIVE
|
Articles 28,719
|
CVEs 366,928
|
APT Groups 800
|
Tools 2,196
|
Updated recently
Today Yesterday All 28,691 articles — Page 922 of 957
Wiz Blog | RSS feed ·

CISOs share how to build effective, collaborative teams and land your next role.

Curated Intelligence ·

BackgroundFor the last couple of years, the threat actors associated with the CL0P ransomware group have occasionally ditched encryption in favour of exploiting file transfer applications in mass...

TA505 Graceful Spider Lace Tempest Financial Services
Maxwell Dulin's Resources ·

Q (lolz) is a proof of stake EVM compatible blockchain. It's native currency is Q tokens that are used for voting, staking and much more. The voting mechanism has four components: A proposal is...

Commercial Facilities Financial Services
Maxwell Dulin's Resources ·

The Yield Protocol is a fixed-rate borrowing and lending protocol on Ethereum. As demonstrated by the name "Yield", getting yield from the assets provided is an extremely important part of this...

Emergency Services Energy
Maxwell Dulin's Resources ·

SSH is used to log in to servers by everyone. Finding a vulnerability in the authentication process for this would be catastrophic. This is exactly what the author found here! In this case, it is...

Information Technology Communications
Wiz Blog | RSS feed ·

Reduce noise of traditional CSPM tools with context-based deep risk assessment, enabling you to prioritize the misconfigurations that put your environment at critical risk.

Chemical Information Technology
maxwelldulin ·

Jimbo creates a semi-stablecoin via rebalancing. This is version 2 of the protocol, which was an attempt to fix the first version with too many bugs in it. The whole point of this protocol is...

Wiz Blog | RSS feed ·

Put yourself to the test with our unique CTF challenge and boost your AWS IAM knowledge. Do you have what it takes to win The Big IAM Challenge?

Information Technology
Maxwell Dulin's Resources ·

DFX Finance is a decentralized foreign exchange protocol that allows users to swap many stablecoins. DFX is an AMM that exchanges tokens according to a bonding curve, which is dynamically...

Energy Healthcare and Public Health
Wiz Blog | RSS feed ·

Agentless visibility and risk assessment paired with Wiz Runtime Sensor real-time detection for the best of both worlds

Information Technology Financial Services
Wiz Blog | RSS feed ·

Today we are excited to announce the Wiz Runtime Sensor. The sensor collects signals in real-time from the workload runtime to simplify threat detection and response in the cloud as part of our...

Information Technology Energy
Cloud Threat Landscape ·

According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment by exploiting a WSO2 RCE vulnerability (CVE-2022-29464) affecting...

Cloud Threat Landscape ·

According to CrowdStrike research, in a certain incident Cosmic Wolf compromised a target organization’s cloud environment using a stolen credential. They used this to authenticate using a CLI and...

Cosmic Wolf
Cloud Threat Landscape ·

According to CrowdStrike research, in a certain incident an unknown actor compromised a target organization’s cloud environment using an RCE vulnerability affecting PHP applications on multiple...

Wiz Blog | RSS feed ·

Detect and mitigate CVE-2023-34362, a remote code execution vulnerability in MOVEit Transfer exploited in the wild. Organizations should patch urgently.

Information Technology
Maxwell Dulin's Resources ·

The author of this post had recently bought a Phillips Sonicare toothbrush. When reviewing the documentation, it says that the product operates at 13.56MHz, which indicates this uses NFC. The...

Healthcare and Public Health Critical Manufacturing
Maxwell Dulin's Resources ·

CosmWasm is a smart contract platform that can be used on Cosmos. This allows for a similar interaction of Solidity based smart contracts on the EVM. Being able to find a denial of service (DoS)...

Maxwell Dulin's Resources ·

Security Enhanced Linux (SELinux) is an added layer of security to the OS kernel. Using it, access controls can be put on applications, processes and file on a system. Just because you have root...

Wiz Blog | RSS feed ·

Learn how to identify unused and unnecessary long-lived IAM User access keys.

Kaspersky ICS CERT (English) ·

During IR, while trying to figure out what went wrong, we’ve found numerous issues

Publications
Orange Cyberdefense ·

For our annual internal hacker conference dubbed SenseCon in 2023, I decided to take a quick look at Docker Desktop Extensions. Almost exactly a year after being announced, I wondered what the...

Financial Services
Maxwell Dulin's Resources ·

Solidity has error handling like most languages do. It looks similar to JavaScript with try and catch blocks. The docs can be read at here. In the initial example, the author gives a fairly simple...

Energy
@BushidoToken Threat Intel ·

I wanted to do something a bit different and fun so I created a new site hackerfiction.medium.com with one purpose: Telling fictional short stories about hacking using AI. I’ve explained why and...

Financial Services Energy
Maxwell Dulin's Resources ·

The article goes into the finance between many different DeFi algorithms. This is a large article with many protocols in it, including Bancor, Uniswap, Curve, Clipper and more.

Maxwell Dulin's Resources ·

Decentralized Finance (DeFi) is great eco-system for opening up everyone to many financial instruments. You know what's not great? DeFi hacks. A large percentage of these occur from manipulating...

Financial Services Transportation Systems
Maxwell Dulin's Resources ·

Reentrancy is a fundamental attack in the Solidity security space. This is when a user can recursively call a contract while it has not had it's state fully updated. Developers should follow the...

Transportation Systems Financial Services
Maxwell Dulin's Resources ·

Since Ethereum and other layer 1 blockchains are slow and expensive, there are many layer 2 (L2) protocols appearing. The idea is to roll all the transactions on the L2 EVM into a single...

maxwelldulin ·

The Binance Chain IAVL Merkle Tree hack gained from flags on security issues within the Cosmos SDK. As a result, the developers started diving into the code base to look for further issues. From...

Orange Cyberdefense ·

Rogan brought half of his hardware parts bin to the hackathon! Michael Rodger, Daniel Scragg, Isak van der Walt, Thulani Mabuza and Rogan Dawes formed the Chubby Hackers team to investigate the...

Critical Manufacturing Information Technology
0xToxin ·

Part 2 of analyzing the KrakenKeylogger Malware

Information Technology Threat Hunting KrakenKeylogger