Sha1-Hulud: The Second Coming of The New npm GitHub Worm

December 03, 2025 | Karl Sigler

Sha1-Hulud is back with a new evolution of its supply-chain attack that targets ...

SpiderLabs IDs New Banking Trojan Distributed Through WhatsApp

November 19, 2025 | Nathaniel Morales, John Basmayor, and Nikita Kazymirskyi

LevelBlue SpiderLabs researchers have recently identified a banking Trojan we ...

Bolstering Cybersecurity Resilience in the Public Sector

October 29, 2025

With digital transformation continuing unabated, the prevalence of legacy ...

Data in the Dark: The Public Sector on the Dark Web

October 15, 2025

The dark web serves as a refuge for threat actors to gather intel, trade ...

Notepad++ DLL Hijacking (CVE-2025-56383): CVSS 8.4 or CVSS 0.0?

October 03, 2025

A vulnerability on a popular source-code editor has been recently released ...

Understanding DocumentDB’s Network Security Trade-Offs: The VPC Challenge

August 05, 2025 | Selam Gebreananeya

AWS DocumentDB by default is securely isolated within a VPC, unreachable from ...

Lights Out and Stalled Factories: Using M.A.T.R.I.X to Learn About Modbus Vulnerabilities

May 06, 2025 | Karl Biron

Let’s explore the critical role of Modbus in energy and manufacturing systems, ...

Bring Your Own Installer: Bypassing EDR Through Agent Version Change Interruption

May 05, 2025 | John Ailes and Tim Mashni

Bring Your Own Installer is a technique which can be used by threat actors to ...

A Deep-Rooted Infestation: How the ILOVEYOU Bug Continues its Legacy in Modern Worms

May 02, 2025 | Pauline Bolaños

A quarter century ago, a former computer science student from the Philippines ...

Agent In the Middle – Abusing Agent Cards in the Agent-2-Agent (A2A) Protocol To ‘Win’ All the Tasks

April 21, 2025 | Tom Neaves

I think you’ll agree with me that growth in the AI landscape is pretty full-on ...

Fort Knox for Your Data: How Elasticsearch X-Pack Locks Down Your Cluster – Part 2

March 20, 2025 | Karl Biron

In Part 1 of Fort Knox for Your Data: How Elasticsearch X-Pack Locks Down Your ...

2025 Trustwave Risk Radar Report: Top Cyber Threats Targeting the Manufacturing Sector

February 26, 2025

2025 Trustwave Risk Radar Report Unveils Top Cyber Threats to Manufacturing: ...

Beyond the Chatbot: Meta Phishing with Fake Live Support

February 04, 2025 | Mike Casayuran and John Kevin Adriano

In a previous Trustwave SpiderLabs’ blog, we explored how cybercriminals ...

Cracking the Giant: How ODAT Challenges Oracle, the King of Databases

January 27, 2025 | Karl Biron

In the past decade, Oracle Database (Oracle DB) has reigned supreme in the ...

CVE-2024-55591: Fortinet FortiOS/FortiProxy Zero Day

January 14, 2025

In late November and December 2024, Arctic Wolf observed evidence of a mass ...

The State of Magecart: A Persistent Threat to E-Commerce Security

January 09, 2025 | Rodel Mendrez

Trustwave SpiderLabs first blogged about Magecart back in 2019; fast forward ...

Emerging Risks in Third-Party AI Solutions and How to Help Address Them

December 04, 2024 | Scott Swanson and Kris Kimmerle

As the cyber threat landscape changes due the introduction of new threat ...

Lessons from a Honeypot with US Citizens’ Data

November 13, 2024 | Radoslaw Zdonczyk and Nikita Kazymirskyi

Prior to last week’s US Presidential Election, the Trustwave SpiderLabs team ...

The Mounted Guest EDR Bypass

November 11, 2024 | Colin Meek

The Mounted Guest EDR Bypass is a tactic used in cyber attacks to evade ...

Hooked by the Call: A Deep Dive into The Tricks Used in Callback Phishing Emails

October 21, 2024 | Katrina Udquin

Introduction Previously, Trustwave SpiderLabs covered a massive fake order spam ...

How Threat Actors Conduct Election Interference Operations: An Overview

October 18, 2024 | Pauline Bolaños

The major headlines that arose from the three most recent US presidential ...

Bypassing EDR through Retrosigned Drivers and System Time Manipulation

September 13, 2024 | Zachary Reichert

The Retrosigned Driver EDR Bypass is a novel modification of a technique ...

Distributed Denial of Truth (DDoT): The Mechanics of Influence Operations and The Weaponization of Social Media

September 13, 2024 | Jose Tozo

With the US election on the horizon, it’s a good time to explore the concept of ...

Exploring an Experimental Windows Kernel Rootkit in Rust

September 09, 2024

Around two years ago, memN0ps took the initiative to create one of the first ...

Hypervisor Development in Rust for Security Researchers (Part 1)

September 06, 2024

In the ever-evolving field of information security, curiosity and continuous ...

Deep Dive and Simulation of a MariaDB RCE Attack: CVE-2021-27928

August 16, 2024 | Karl Biron

In early 2021, a new vulnerability, identified as CVE-2021-27928, was ...

Cloudy with a Chance of Hackers: Protecting Critical Cloud Workloads

July 22, 2024 | David Broggy

If you've been following along with David's posts, you'll have noticed a ...

Responding to the CrowdStrike Outage: Implications for Cyber and Technology Professionals

July 19, 2024

This client alert provides an overview of the current global IT outage that is ...