Microsoft Advance Notification for April 2013

Ah, April, for most of us the weather is turning warm, birds return to their trees, flowers start ...

Read More

Jamming With WordPress Sessions

Let's talk about some targeted attacks where session management can be targeted to side step multi ...

Read More

Breaking the Authentication Chain

This little post is going to talk about how authentication goes beyond just usernames and passwords.

Read More

SpiderLabs Radio March 29, 2013 w/ Space Rogue

This week's episode of SpiderLabs Radio hosted by Space Rogue covers OMG DDoS Nukes Take out Net!, ...

Read More

Cracking IKE Mission:Improbable (Part 1)

All too often during pen tests I still find VPN endpoints configured to allow insecure Aggressive ...

Read More

Hooked on Packets: Reading PCAPs for D Students - Preview

SOURCE Boston is coming up in April, and Mike Ryan and I are giving a presentation about making ...

Read More

Did Grum Really Get Killed?

For several years before July 2012 takedown, Grum was one of the notorious spam botnets and at one ...

Read More

SpiderLabs Radio March 22, 2013 w/ Space Rogue

This week's episode of SpiderLabs Radio hosted by Space Rogue covers Korea, teamSpy, Scan all the ...

Read More

Baiting Attack Exercise – The Old School Way Still Works

In the past few months, we have had quite a few social engineering and client-side penetration ...

Read More

Mongodb - Security Weaknesses in a typical NoSQL database

Over the last year or so, I've noticed 2 ports appearing more frequently during internal ...

Read More

SpiderLabs Radio March 15, 2013 w/ Space Rogue

This week's episode of SpiderLabs Radio hosted by Space Rogue covers China, celebs breached, NVD ...

Read More

Fresh Coffee Served by CoolEK

As you may already know, the past few months have been problematic to Oracle when it comes to ...

Read More

Mimicking Attackers: Building Malware for CCDC

This past weekend my fellow coworkers/friends and myself had the opportunity and the privilege to ...

Read More

Microsoft Patch Tuesday, March 2013 – Happy St. Patch-rick's Day!

Saint Patrick's day is quickly becoming Saint Patrick's week. Some cities have scheduled their ...

Read More

SpiderLabs Radio March 8, 2013 w/ Space Rogue

This week's episode of SpiderLabs Radio hosted by Space Rogue covers Pwn2own, Chrome free, ...

Read More

Microsoft Advance Notification for March 2013

First the raw numbers; we have seven bulletins this month, four critical, and three important. ...

Read More

Upcoming Webinars: 2013 Trustwave Global Security Report Threat Trends

A few weeks ago we released the 2013 Trustwave Global Security Report. This year, Trustwave ...

Read More

OS Image Wrangling

On most PenTests, alot of research goes into the things you find along the way. You find obscure ...

Read More

My 2013 RSA Conference Keynote the Jimmy Kimmel Influence

Read More

The Life Cycle of Web Server Botnet Recruitment

This blog post is an excerpt taken from the recently released Global Security Report (GSR) for 2013.

Read More

Kelihos is Dead… No wait… Long Live Kelihos! Again!

This post is inspired by a news article which highlighted a recent presentation at RSA. Kelihos, ...

Read More

You Injected What? Where?

While harder to detect, there are still some instances of websites exploitable via partially blind ...

Read More

'Cyber' Security - must become a board level issue in the UK ...really?

The UK Government is "committed to helpingreduce vulnerability to attacks and ensure that the UK is ...

Read More

New Year, New Data, Same Mistakes: Passwords

Like a late-arriving Christmas, one of the gifts of the new year is the release of SpiderLabs' ...

Read More

SpiderLabs Radio March 1, 2013 w/ Space Rogue

This week's episode of SpiderLabs Radio hosted by Space Rogue covers Half a Stuxnet, MiniDuke, MBU, ...

Read More

More on the TrustKeeper Phish

Yesterday we alerted people to a widespread phishing campaign misusing Trustwave's brand. Here we ...

Read More

SpiderLabs Radio February 22, 2013 w/ Space Rogue

This week's episode of SpiderLabs Radio hosted by Space Rogue covers The Mandiant RedScare, ...

Read More

Trustwave TrustKeeper PCI Scan Notification - Phishing ALERT

Over the last few hours, Trustwave has received multiple reports of individuals receiving fake ...

Read More