UNC Path Injection with Microsoft Access
Introduction Steve Borosh is a Principal Security Consultant for Trustwave and Trustwave Government ...
Read MoreIntroduction Steve Borosh is a Principal Security Consultant for Trustwave and Trustwave Government ...
Read MoreFor June's Patch Tuesday, Microsoft is releasing four advisories and patches for a massive 88 CVEs, ...
Read MoreMay's Patch Tuesday is here and brings with it patches for 79 CVEs. Twenty-two of those CVEs are ...
Read MoreToday we released our 2019 Global Security Report. The report is based on the analysis of billions ...
Read MoreIn our previous blog we highlighted how a group of scammers were targeting financial software ...
Read MoreWhat's worse than annoying ads on a website? Crypto Miner on a website!
Read MoreScam Overview Her Majesty's Revenue & Customs (HMRC) is the UK department responsible for ...
Read MoreBack in August 2017, Trustwave Spiderlabs reported a spam campaign that distributed a new Locky ...
Read MoreEDIT (9.April.2019): We have applied for a retraction of CVE-2019-9193 previously associated with ...
Read MoreAlong with "Spring Showers" up here in the Northern Hemisphere, April also brings with it ...
Read MoreWe witnessed a widespread phishing campaign targeting O2 customers, that surfaced on 18th August, ...
Read MoreAnother round of sextortion scam emails with a pdf attachment were pushed out recently claiming to ...
Read MoreJust a short post from me today, bringing you a pretty simple Cross-Site Scripting (XSS) issue. In ...
Read MoreCon men have been exploiting human psychology since the dawn of time. Equipped with the ...
Read MoreThis month's Patch Tuesday brings with it four advisories and patches for 64 CVEs including a patch ...
Read MoreSextortion is a form of sex-themed exploitation via email where victims are coerced to give money ...
Read MoreA few days ago we encountered a breach on a Pakistani government site which was compromised to ...
Read MoreWebSockets allow a single TCP connection to have full duplexing communications. This type of ...
Read MoreWhen I first released Sheepl 0.1 in September 2018 as part of a talk, I wanted to showcase a ...
Read MoreIn the world of Phishing emails, we often see schemes which involve enticing users to open a ...
Read MoreLast week, one of my SpiderLabs colleagues was working on a PCI forensic triage for a website. ...
Read MoreWe witnessed a sophisticated phishing campaign on 16th August 2017, targeting victims by sending ...
Read MoreWe are seeing more reports from organizations being targeted by what could be called an 'altered ...
Read MoreEvading AV detection is part of a malware author's routine in crafting spam campaigns and an old ...
Read MoreWith today's Patch Tuesday for February, things are back to normal with patches for 76 CVEs and ...
Read More“Not having to worry about money is almost like not having to worry about dying.” - Mario Puzo
Read MoreWhile working on various vulnerability research projects, I encountered multiple Authenticated ...
Read More