Ukraine suspected of attack on state-owned lender
Malicious e-commerce campaign ongoing since December 2021
Version française: 🇫🇷 Regulatory frameworks of some countries may require companies operating in their territory to use specific software. While their integration does not usually present any technical concern, such software can be used by adversaries as an entry point to a computer network. The...
Articles
AuthPoint users cannot log in to Windows server after they change a password over RDP
DNSWatchGO data storage information and server locations
M-series Firebox powered state behavior after a power failure
PMKID does not match between AP and client
Why does the Firebox generate "Archived lo...
Results suggest the attack was executed using tools and techniques associated with Chinese APTs.
Majority of third-party domain names impersonating the biggest global brands use domain privacy services, indicating the owner’s intention to mask their identity
How to find and take advantage of exposed EBS snapshots.
The move would shed light on hackers and sound the alarm more widely on cyber-threats in the country.
The hackers used PRoot to increase the scope of their operations to several Linux distributions
After reading this post about ChatGPT imitating Linux, I wanted it to be a database server.
Let’s try it out!
Imagine you are a Microsoft SQL Server. I type commands, and you reply with the result, and no other information or descriptions. Just the result. Start with exec xp_cmdshell ‘whoami’;
Wow,...
EU-funded study finds concerning levels of risky behavior
Lupovis used decoys to find out more about threat actors
Introduction You’ve probably enjoyed my previous post about bypassing Intel DCM’s authentication mechanism to gain unauthorized access. This gave us the lowest possible “Guest” privileges in the DCM console. The second part will now show you a possible way to get Remote Code Execution on the underly...
Secret Service says discovery may be the tip of the iceberg
The known impact was isolated to a portion of the firm's Hosted Exchange platform
Zero-knowledge (ZK) proofs are useful cryptographic tools that have seen an explosion of interest in recent years, largely due to their applications to cryptocurrency. The fundamental idea of a ZK proof is that a person with a secret piece of information (a cryptographic key, for instance) can prove...
The hackers allegedly stole PII, including names, Aadhar numbers and IFSC codes
Businesses are getting better at preventing cyber incidents, Orange Cybedefense’s head of Security Research Center said
DotHouse Health experienced a data breach due to suspicious activity on their computer systems, potentially impacting patient information. The breach occurred between October 31, 2022, and November 27, 2022. It was claimed under the Alphv/BlackCat brand on July 26th, 2023.
The flaw relates to a type confusion bug in the V8 JavaScript engine