KOVTER and CERBER on a One-Two Punch using Fake Delivery Notification

We previously outlined a spam campaign that delivered FAKEGLOBE and CERBER ransomwares. This week ...

Read More

Microsoft Patch Tuesday, June 2017

For the June 2017 Patch Tuesday Microsoft is releasing 97 CVEs, nearly double the number of ...

Read More

The WannaCry Impact on Databases Trustwave Database Security Knowledgebase Special Update 5.15

WannaCry is a network worm that exploits a vulnerability in Microsoft's implementation of the SMB ...

Read More

FakeGlobe and Cerber Ransomware: Sneaking under the radar while WeCry

Recently, we observed a constant influx of spam that distributes two ransomware families, perhaps ...

Read More

Necurs Recurs

The Necurs botnet, which was responsible for millions of malicious spam messages last year, has ...

Read More

URSNIF is Back Riding a New Wave of Spam

The infamous data-stealing URSNIF malware has done it again and it's here to collect more ...

Read More

Advanced Malware Detection with Suricata Lua Scripting

Normal IDPS signatures using either Snort or Suricata have quite a few options and, if regex is ...

Read More

TheShadowBrokers Babytalk Translation

TheShadowBrokers have just released a blog post (written in a child-like style to mock the lack of ...

Read More

WannaCry: We Want to Cry

Contributors: Phil Hay, Rodel Mendrez, Gerald Carsula, Nicholas Ramos, Homer Pacag For the last few ...

Read More

WannaCry: We Want to Cry

For the last few days the WannaCry ransomware event created mayhem, where organizations worldwide ...

Read More

The WannaCry Ransomware Campaign

By now you have likely heard about the WannaCry (aka WannaCrypt) ransomware campaign that has taken ...

Read More

Airachnid: Web Cache Deception Burp Extender

Introduction

Read More

Microsoft Patch Tuesday, May 2017

Microsoft is releasing 56 CVEs for the May 2017 Patch Tuesday today. This includes 15 CVEs rated ...

Read More

Carbanak Continues To Evolve: Quietly Creeping into Remote Hosts

Introduction

Read More

Multiple Vulnerabilities in Avast Antivirus

Last year I decided to do some security research on an antivirus product. Avast seemed a good ...

Read More

Microsoft Patch Tuesday, April 2017

April Patch Tuesday is here and, like the change of the seasons, this release comes with changes in ...

Read More

Understanding and Discovering Open Redirect Vulnerabilities

One of the most common and largely overlooked vulnerabilities by web developers is Open Redirect ...

Read More

And Then? Where is the Risk with Steganography?

In the previous posts, Steganography... what is that? and Steganalysis, the Counterpart of ...

Read More

Protecting Yourself from MongoDB Ransomware

In the realm of malware, ransomware has been king for the last few years, compromising unsecured ...

Read More

Exploiting Privilege Escalation in Serv-U by SolarWinds

I was recently working on an external network penetration test where I identified a new ...

Read More

Authentication and Encryption in PAS Web Shell Variant

Introduction During a recent incident response case, we were tasked with discovering the point of ...

Read More

Database Security Knowledgebase Update 5.12

This month's update for Database Security Knowledgebase is now available. Knowledgebase version ...

Read More

Hey Buddy, Can You Spare a Log? Adventures in Log-Based Threat Hunting

Introduction

Read More

Microsoft Patch Tuesday, March 2017

We knew that the Microsoft's Valentine's gift to cancel Patch Tuesday on February 14th was only ...

Read More

Undocumented Backdoor Account in DBLTek GoIP

Trustwave recently reported a remotely exploitable issue in the Telnet administrative interface of ...

Read More

Hanz Ostmaster’s revenge: An SSL Validation issue

Why would I title a blog post with the name 'Hanz Ostmaster'? Don't worry, it's not some new named ...

Read More

Unauthenticated Backdoor Access in Unanet

The default configuration of the Unanet web application has a backdoor that can allow ...

Read More

Database Security Knowledgebase Update 5.11

This month's update for Database Security Knowledgebase is now available.

Read More