Microsoft Patch Tuesday, November 2015

November's Patch Tuesday marks a return to business as usual. Where October was a rather light ...

Read More

SpiderLabs Radio for the Week of November 2, 2015 - Final Episode

In this week's episode:

Read More

Oracle Database 11.2 SQLi in XML index statistics processing (CVE-2015-4900)

In the October 2015 'Critical Patch Update' Oracle fixed a flaw in XML index support code: namely ...

Read More

About Lenovo System Update Vulnerabilities and CVE-2015-6971

Over the past seven months, a number of vulnerabilities in Lenovo System Update software have come ...

Read More

SpiderLabs Radio for the Week of October 19, 2015

Two separate SpiderLabs vulnerabilities released:

Read More

Joomla SQL Injection Vulnerability Exploit Results in Full Administrative Access

Trustwave SpiderLabs researcher Asaf Orpani has discovered an SQL injection vulnerability in ...

Read More

How To Decrypt Ruby SSL Communications with Wireshark

Debugging a program that communicates with a remote endpoint usually involves analyzing the network ...

Read More

Zero-day in Magmi database client for popular e-commerce platform Magento targeted in the wild

We've observed HTTP requests associated with an exploit attempt on the Magento e-commerce platform. ...

Read More

AppDetectivePRO and DbProtect Knowledgebase Update 4.54

This month's update for our AppDetectivePRO and DbProtect Knowledgebase is now available.

Read More

Microsoft Patch Tuesday for October 2015

October's Patch Tuesday is upon us and with only six bulletins, it's one of lightest releases we've ...

Read More

SpiderLabs Radio for the Week of September 28, 2015

In this week's episode:

Read More

Jumping through the hoops: multi-stage malicious PDF spam

We've recently encountered a number of malicious spam messages with PDFs attached. The PDFs ...

Read More

Quaverse RAT: Remote-Access-as-a-Service

***UPDATE as of September 28, 2015 - see the bottom of this post for removal instructions***

Read More

HOW TO: Setting up Encrypted Communications Channels in Oracle Database

In this article, I will explain how to set up an encrypted communications channel in Oracle ...

Read More

SpiderLabs Radio for the Week of September 14, 2015

In this week's episode:

Read More

HOW TO: Setting up Encrypted Communications Channels in Oracle Database (1)

In this article, I will explain how to set up an encrypted communications channel in Oracle ...

Read More

Microsoft Patch Tuesday, September 2015

Today marks Patch Tuesday for September and this month brings with it 12 bulletins. Four are rated ...

Read More

Lessons in Spam JavaScript Obfuscation Layers

Spammers seem to be adding layers of obfuscation to their malware attachments in an attempt to ...

Read More

SpiderLabs Radio for the Week of August 31, 2015

In this week's episode:

Read More

Debugging SAP ASE .NET Provider Issues

I've recently been chasing a bug that made it impossible to call one built-in stored procedure ...

Read More

About Two SAP Adaptive Server Enterprise (ASE) Extended Procedure Subsystem Vulnerabilities

Recently SAP patched two important security issues in Adaptive Server Enterprise (ASE). One is ...

Read More

SpiderLabs Radio for the Week of August 24, 2015

In this week's episode:

Read More

SpiderLabs Radio for the Week of August 17, 2015

In this week's episode:

Read More

Two Vulnerabilities Reported by SpiderLabs Fixed in Oracle Critical Patch Update July 2015

In July, Oracle released a Critical Patch Update for multiple products including Oracle Database ...

Read More

Microsoft Patch Tuesday for August 2015

Today marks Patch Tuesday for August. Almost identical to last month's list, August clocks in with ...

Read More

SpiderLabs Radio for the Week of July 27, 2015

In this week's episode:

Read More

RIG Reloaded - Examining the Architecture of RIG Exploit Kit 3.0

A few months ago the RIG exploit kit took quite a hit when its source code was leaked by a ...

Read More

Username Enumeration against OpenSSH-SELinux with CVE-2015-3238

I recently disclosed a low-risk vulnerability in Linux-PAM versions prior to 1.2.1 which allows ...

Read More