Patch Tuesday, February 2019
February 12, 2019 | Karl Sigler
With today's Patch Tuesday for February, things are back to normal with patches ...
Wowza Streaming Engine Manager Directory Traversal And Local File Inclusion
February 11, 2019 | Sean Melia
CVE-2018-19365: Root local file inclusion in Wowza SRM 4.7.4.01.
Money Laundering: Washing Your Greens in the Underground - Part 3 of 3
February 08, 2019 | SpiderLabs Researcher
“Not having to worry about money is almost like not having to worry about ...
Lifesize Team, Room, Passport & Networker Remote OS Command Injection
February 07, 2019 | Simon Kenin
While working on various vulnerability research projects, I encountered ...
Sextortion Scam Now With Malicious Downloader
February 06, 2019 | Diana Lopera
Sextortion scams were a hit campaign last year and are continuing in 2019 with ...
Sextortion Scam Now With Malicious Downloader
February 06, 2019 | Diana Lopera
Sextortion scams were a hit campaign last year and are continuing in 2019 with ...
Latest Flash 0-Day (CVE-2018-15982) Leaves its Office Doc Friend Behind
January 31, 2019 | SpiderLabs Researcher
CVE-2018-15982 is the Flash 0day that was patched by Adobe at the beginning of ...
Living off the LAN
January 23, 2019 | Alejandro Baca
When an attacker uses tools native to the operating system it is referred to as ...
Using IPv6 to Bypass Security
January 23, 2019 | SpiderLabs Researcher
Introduction
Overview of Meltdown and Spectre
January 22, 2019 | SpiderLabs Researcher
You have probably heard the news of new vulnerabilities that affect most major ...
Spam Masters of Extortion, Illusion and Evasion
January 21, 2019 | Dr. Fahim Abbasi
In 2018 we saw a rise in sextortion scams in which cyber-criminals notified ...
Patch Tuesday, January 2019
January 08, 2019 | Karl Sigler
Historically January has been a relatively light month for Patch Tuesday, but ...
Kernel Buffer Overflow in Trusteer Rapport for MacOS
December 20, 2018 | Neil Kettle
Trustwave recently reported a Kernel based vulnerability in a driver bundled ...
Rise of the Webminers
December 19, 2018 | Oren Mashal
About a year ago webminers began to appear on more and more websites. It was ...
Hacking Online Coupons
December 18, 2018 | Lena Frid
We all shop online. How many times, just before placing an online order, have ...
Microsoft Patch Tuesday, December 2018
December 11, 2018 | Karl Sigler
The last Patch Tuesday of 2018 is here and we are easing into the New Year with ...
Magecart - An overview and defense mechanisms
December 06, 2018 | Victor Hora
Summary This blog post offers insight into Magecart and offers advice on how to ...
Scavenger: Post-Exploitation Tool for Collecting Vital Data
December 05, 2018 | Philip Pieterse
‘Scavenger’ - definition [noun]: a person who searches for and collects ...
Announcing ModSecurity version 2.9.3
December 05, 2018 | Victor Hora
We are happy to announce ModSecurity version 2.9.3!
Decoding Hancitor Malware with Suricata and Lua
November 27, 2018 | Bryant Smith
Many types of malware send and receive data via HTTP. They may either be ...
Exploring and Modifying Android and Java Applications for Security Research
November 27, 2018 | Martin Rakhmanov
Sometimes pentesters and security researchers need to modify existing Java ...
Taking Advantage of AJAX for Account Enumeration
November 27, 2018 | Manuel Nader
Context AJAX stands for Asynchronous JavaScript And XML. It’s a set of web ...
Microsoft Patch Tuesday, November 2018
November 27, 2018 | Karl Sigler
The second to last Patch Tuesday of 2018 is here with patches for 55 CVEs. This ...
Sheepl : Automating People for Red and Blue Tradecraft
November 27, 2018 | Matt Lorentzen
Whilst there is a wealth of information out there about how to build ...
ModSecurity v3.0.3: What To Expect
November 27, 2018 | Felipe "Zimmerle" Costa
At precisely 155 commits ahead of the latest version, ModSecurity version 3.0.3 ...
Demystifying Obfuscation Used in the Thanksgiving Spam Campaign
November 26, 2018 | Rodel Mendrez
During Thanksgiving week, we noticed this quite unusual XML-format MS Office ...
Hacker's Wish Come True After Infecting Visitors of Make-A-Wish Website With Cryptojacking
November 19, 2018 | Simon Kenin
After coming back from a vacation, the first thing to do is catch up with what ...
DOH! DNS Over HTTPS Poses Possible Risks to Enterprises
October 26, 2018 | David Middlehurst
Introduction David Middlehurst of Trustwave SpiderLabs presented at the first ...