Patch Tuesday, June 2019

June 11, 2019 | Karl Sigler

For June's Patch Tuesday, Microsoft is releasing four advisories and patches ...

Patch Tuesday, May 2019

May 14, 2019 | Karl Sigler

May's Patch Tuesday is here and brings with it patches for 79 CVEs. Twenty-two ...

Reversing Gh0stRAT part 2: the DDOS-ening

May 02, 2019 | James Quinn

This is a guest post James Quinn, a SOC analyst from Binary Defense.

Announcing the 2019 Trustwave Global Security Report

April 25, 2019

Today we released our 2019 Global Security Report. The report is based on the ...

“Don’t Mine Me” – Coinhive

April 22, 2019 | Anat Davidi

What's worse than annoying ads on a website? Crypto Miner on a website!

VAT Return with a Vengeance

April 22, 2019 | Dr. Fahim Abbasi

Scam Overview Her Majesty's Revenue & Customs (HMRC) is the UK department ...

Fake Power and Broadband Utility Bills serve Banking Trojans to Aussies

April 22, 2019 | Dr. Fahim Abbasi

In our previous blog we highlighted how a group of scammers were targeting ...

Unauthenticated Remote Code Execution In Kentico CMS

April 15, 2019 | Manoj Cherukuri

CVE-2019-10068: RCE as Administrator via deserialization vulnerability in ...

Locky Part 1: Lukitus Spam Campaigns and Their Love for Game of Thrones

April 11, 2019 | Nicholas Ramos

Back in August 2017, Trustwave Spiderlabs reported a spam campaign that ...

Authenticated Arbitrary Command Execution on PostgreSQL 9.3 > Latest

April 09, 2019 | Jacob Wilkin

EDIT (9.April.2019): We have applied for a retraction of CVE-2019-9193 ...

Patch Tuesday, April 2019

April 09, 2019 | Karl Sigler

Along with "Spring Showers" up here in the Northern Hemisphere, April also ...

Emotet lives another day using Fake O2 invoice notifications

April 08, 2019 | Dr. Fahim Abbasi

We witnessed a widespread phishing campaign targeting O2 customers, that ...

Spammed PNG file hides LokiBot

April 05, 2019 | Phil Hay, Rodel Mendrez

Contributing authors: Phil Hay, Rodel Mendrez

Fake CIA Sextortion Scam Uses SatoshiBox

April 04, 2019 | Diana Lopera

Another round of sextortion scam emails with a pdf attachment were pushed out ...

Remote Code Execution In BlogEngine.NET

March 28, 2019 | Dustin Cobb

CVE-2019-6714: RCE via path traversal in BlogEngine.NET 3.3.6.0.

The odd case of a Gh0stRAT variant

March 25, 2019 | James Quinn

This is a guest post by independent security researcher James Quinn. This will ...

CVE-2018-19386: Reflected XSS in SolarWinds Database Performance Analyzer

March 21, 2019 | Jacob Wilkin

Just a short post from me today, bringing you a pretty simple Cross-Site ...

BEC Payroll Scam: Your Salary is Mine!

March 13, 2019 | Dr. Fahim Abbasi

Con men have been exploiting human psychology since the dawn of time. Equipped ...

Patch Tuesday, March 2019

March 12, 2019 | Karl Sigler

This month's Patch Tuesday brings with it four advisories and patches for 64 ...

QRCode Used in Extortion Spam Campaign

March 07, 2019 | Homer Pacag

Sextortion is a form of sex-themed exploitation via email where victims are ...

Detecting Malicious Behavior by Unmasking WebSockets

March 04, 2019 | Bryant Smith

WebSockets allow a single TCP connection to have full duplexing communications. ...

Sheepl 2.0: Automating People for Red and Blue Tradecraft

March 04, 2019 | Matt Lorentzen

When I first released Sheepl 0.1 in September 2018 as part of a talk, I wanted ...

Attacker Tracking Users Seeking Pakistani Passport

March 04, 2019 | SpiderLabs Researcher

A few days ago we encountered a breach on a Pakistani government site which was ...

Bangladesh Embassy Website in Cairo Compromised

February 27, 2019 | Nikita Kazymirskyi

In the world of Phishing emails, we often see schemes which involve enticing ...

Digging Deep Into Magecart Malware

February 21, 2019 | Rodel Mendrez

Last week, one of my SpiderLabs colleagues was working on a PCI forensic triage ...

Stealing Money by Asking for It: Business Email Compromise via Altered Invoices

February 14, 2019 | Phil Hay

We are seeing more reports from organizations being targeted by what could be ...

Malware Xeroing in on Cloud Accounting Customers

February 14, 2019 | Dr. Fahim Abbasi

We witnessed a sophisticated phishing campaign on 16th August 2017, targeting ...

Password Protected Word Document Delivers HERMES Ransomware

February 13, 2019 | SpiderLabs Researcher

Evading AV detection is part of a malware author's routine in crafting spam ...