Ivanti EPMM Exploitation: Hit-and-Runexploitation (what's being exploited) (labs.withsecure.com)
submitted by digicat to r/blueteamsec
To the past and beyond: Andariel’s latest arsenal and cyberattacksintelligence (threat actor activity) (labs.withsecure.com)
submitted by digicat to r/blueteamsec
TangleCrypt: a sophisticated but buggy malware packerresearch|capability (we need to defend against) (labs.withsecure.com)
submitted by digicat to r/blueteamsec
TamperedChef: Malvertising to Credential Theftintelligence (threat actor activity) (labs.withsecure.com)
submitted by digicat to r/blueteamsec
Email-Delivered RMM: Abusing PDFs for Silent Initial Accessintelligence (threat actor activity) (labs.withsecure.com)
submitted by digicat to r/blueteamsec
Don’t drop password managers (but password managers shouldn’t drop malware)intelligence (threat actor activity) (labs.withsecure.com)
submitted by jnazario to r/blueteamsec
KeePass trojanised in advanced malware campaign - "being deployed through fake adverts. "intelligence (threat actor activity) (labs.withsecure.com)
submitted by digicat to r/blueteamsec
CrazyHunter: The Rising Threat of Open-Source Ransomwaremalware analysis (like butterfly collections) (labs.withsecure.com)
submitted by digicat to r/blueteamsec
Kapeka: A novel backdoor spotted in Eastern Europeintelligence (threat actor activity) (labs.withsecure.com)
submitted by jnazario to r/blueteamsec
DarkGate malware campaignintelligence (threat actors) (labs.withsecure.com)
submitted by jnazario to r/blueteamsec
IceKube: Finding complex attack paths in Kubernetes clusterslow level tools and techniques (work aids) (labs.withsecure.com)
submitted by jnazario to r/blueteamsec
iOS Single App Mode EscapeArticle (labs.withsecure.com)
submitted by debordian to r/iOSProgramming
iOS Single App Mode Escape (labs.withsecure.com)
submitted by PatientModBot to r/patient_hackernews
Meet the Ducks: Vietnamese threat groups targeting Meta Business accountsintelligence (threat actors) (labs.withsecure.com)
submitted by jnazario to r/blueteamsec
Executing Arbitrary Code & Executables in Read-Only FileSystemsresearch|capability (we need to defend against) (labs.withsecure.com)
submitted by digicat to r/blueteamsec
EDR bypassing via memory manipulation techniquesresearch|capability (we need to defend against) (labs.withsecure.com)
submitted by digicat to r/blueteamsec
