Simplifying Password Spraying

December 01, 2017 | Jacob Wilkin

As a penetration tester, attaining Windows domain credentials are akin to ...

Using Buildroot for Security Research of IoT and Other Embedded Systems

November 22, 2017 | Martin Rakhmanov

These days many vendors, like IoT vendors, use Linux running on top of ARM CPU ...

Helping to Secure your PostgreSQL Database

November 17, 2017 | Christopher Bielinski

When big high-tech companies like Apple, Red Hat and Cisco use PostgreSQL in ...

Microsoft Patch Tuesday, November 2017

November 14, 2017

It's that time of the month again for Microsoft updates. November's Patch ...

Denial of Service Vulnerability in Brother Printers

November 06, 2017

A vulnerability in the web front-end of Brother printers (called Debut) allows ...

The Complexity amidst Simplicity: Exploiting the MS Office DDE Feature

October 31, 2017 | Nicholas Ramos

Albert Einstein once said, "Out of Complexity, Find Simplicity" but it also ...

An Easy Introduction to Steganography

October 26, 2017 | Jesus Olguin

Some time ago, a person reached out to Trustwave to get answers regarding some ...

ModSecurity Web Application Firewall - Commercial Rules Update(4)

October 18, 2017 | Victor Hora

We have recently released new commercial rules for ModSecurity Web Application ...

Locky Part 2: As the Seasons Change so is Locky

October 12, 2017 | Homer Pacag

It's that time of year when the seasons are changing. The Northern Hemisphere ...

Microsoft Patch Tuesday, October 2017

October 10, 2017

October is here and brings with it patches for 62 CVEs and a handful of ...

Post-Soviet Bank Heists: A Hybrid Cybercrime Study

October 09, 2017

Today we are publishing a SpiderLabs Advanced Threat Report that details a ...

Reviewing Ethereum Smart Contracts

September 27, 2017 | Eric Rafaloff

This article examines the similarities between traditional code review and ...

Introducing Burplay, A Burp Extension for Detecting Privilege Escalations

September 15, 2017 | SpiderLabs Pen Testing LAC

The seventh entry on the most recent OWASP Top 10 release (from 2013, due to ...

ModSecurity Web Application Firewall - Commercial Rules Update (3)

September 14, 2017 | Victor Hora

We have released new commercial rules for ModSecurity Web Application Firewall ...

Linux Based Inter-Process Code Injection Without Ptrace (2)

September 05, 2017 | Rory McNamara

This article shows a technique to inject code into a Linux process without ...

ModSecurity version 3.0.0 first release candidate

August 30, 2017 | Victor Hora

Recently we announced the first release candidate for libModSecurity (also as ...

The Spam, JavaScript and Ransomware Triangle

August 29, 2017 | Dr. Fahim Abbasi

Authors: Dr. Fahim Abbasi and Nicholas Ramos

Cuckoo Linux Subsystem: Some Love for Windows 10

August 25, 2017 | Gerald Carsula

I normally use Linux for my malware analysis lab machine. But, recently, I got ...

Necurs Unleashed “Locky diablo” from Hell

August 23, 2017 | Nicholas Ramos

Over two days in early August (the 8th and 9th), amidst of the active ...

ModSecurity Web Application Firewall - Commercial Rules Update (2)

August 22, 2017 | Victor Hora

We have released new commercial rules for ModSecurity Web Application Firewall ...

Announcing ModSecurity version 2.9.2

August 09, 2017 | Felipe "Zimmerle" Costa

We recently released ModSecurity version 2.9.2. The release contains a number ...

Chip Off the Old EMV

August 08, 2017 | Shawn Kanady

Recently, Jason Knowles of ABC 7's I-Team asked us, "What is the security risk ...

Microsoft Patch Tuesday, August 2017

August 08, 2017

August's Patch Tuesday brings with it a relatively light month closing holes in ...

Tale of the Two Payloads – TrickBot and Nitol

August 04, 2017 | Rodel Mendrez

A couple of weeks ago, we observed the Necurs botnet distributing a new malware ...

Spammed JScript Phones Home To Download NemucodAES And Kovter

July 25, 2017 | Nicholas Ramos

Contributed by: Gerald Carsula, Rodel Mendez and Nicholas Ramos

ModSecurity Web Application Firewall - Commercial Rules Update (1)

July 13, 2017 | SpiderLabs Researcher

We have released new commercial rules for ModSecurity Web Application Firewall ...

Petya From The Wire: Detection using IDPS

July 13, 2017 | Bryant Smith

Most malware that traverses a network do so with specific indicators, some of ...

Microsoft Patch Tuesday, July 2017

July 11, 2017

July's Patch Tuesday brings patches for 54 CVEs, nearly half the number patched ...