Attacker Tracking Users Seeking Pakistani Passport

March 04, 2019 | SpiderLabs Researcher

A few days ago we encountered a breach on a Pakistani government site which was ...

Bangladesh Embassy Website in Cairo Compromised

February 27, 2019 | Nikita Kazymirskyi

In the world of Phishing emails, we often see schemes which involve enticing ...

Digging Deep Into Magecart Malware

February 21, 2019 | Rodel Mendrez

Last week, one of my SpiderLabs colleagues was working on a PCI forensic triage ...

Stealing Money by Asking for It: Business Email Compromise via Altered Invoices

February 14, 2019 | Phil Hay

We are seeing more reports from organizations being targeted by what could be ...

Malware Xeroing in on Cloud Accounting Customers

February 14, 2019 | Dr. Fahim Abbasi

We witnessed a sophisticated phishing campaign on 16th August 2017, targeting ...

Patch Tuesday, February 2019

February 12, 2019 | Karl Sigler

With today's Patch Tuesday for February, things are back to normal with patches ...

Money Laundering: Washing Your Greens in the Underground - Part 3 of 3

February 08, 2019 | SpiderLabs Researcher

“Not having to worry about money is almost like not having to worry about ...

Lifesize Team, Room, Passport & Networker Remote OS Command Injection

February 07, 2019 | Simon Kenin

While working on various vulnerability research projects, I encountered ...

Sextortion Scam Now With Malicious Downloader

February 06, 2019 | Diana Lopera

Sextortion scams were a hit campaign last year and are continuing in 2019 with ...

Sextortion Scam Now With Malicious Downloader

February 06, 2019 | Diana Lopera

Sextortion scams were a hit campaign last year and are continuing in 2019 with ...

Latest Flash 0-Day (CVE-2018-15982) Leaves its Office Doc Friend Behind

January 31, 2019 | SpiderLabs Researcher

CVE-2018-15982 is the Flash 0day that was patched by Adobe at the beginning of ...

Living off the LAN

January 23, 2019 | Alejandro Baca

When an attacker uses tools native to the operating system it is referred to as ...

Using IPv6 to Bypass Security

January 23, 2019 | SpiderLabs Researcher

Introduction

Overview of Meltdown and Spectre

January 22, 2019 | SpiderLabs Researcher

You have probably heard the news of new vulnerabilities that affect most major ...

Kernel Buffer Overflow in Trusteer Rapport for MacOS

December 20, 2018 | Neil Kettle

Trustwave recently reported a Kernel based vulnerability in a driver bundled ...

Rise of the Webminers

December 19, 2018 | Oren Mashal

About a year ago webminers began to appear on more and more websites. It was ...

Hacking Online Coupons

December 18, 2018 | Lena Frid

We all shop online. How many times, just before placing an online order, have ...

Microsoft Patch Tuesday, December 2018

December 11, 2018 | Karl Sigler

The last Patch Tuesday of 2018 is here and we are easing into the New Year with ...

Magecart - An overview and defense mechanisms

December 06, 2018 | Victor Hora

Summary This blog post offers insight into Magecart and offers advice on how to ...

Scavenger: Post-Exploitation Tool for Collecting Vital Data

December 05, 2018 | Philip Pieterse

‘Scavenger’ - definition [noun]: a person who searches for and collects ...

Announcing ModSecurity version 2.9.3

December 05, 2018 | Victor Hora

We are happy to announce ModSecurity version 2.9.3!

Decoding Hancitor Malware with Suricata and Lua

November 27, 2018 | Bryant Smith

Many types of malware send and receive data via HTTP. They may either be ...

Exploring and Modifying Android and Java Applications for Security Research

November 27, 2018 | Martin Rakhmanov

Sometimes pentesters and security researchers need to modify existing Java ...

Taking Advantage of AJAX for Account Enumeration

November 27, 2018 | Manuel Nader

Context AJAX stands for Asynchronous JavaScript And XML. It’s a set of web ...

Microsoft Patch Tuesday, November 2018

November 27, 2018 | Karl Sigler

The second to last Patch Tuesday of 2018 is here with patches for 55 CVEs. This ...

Sheepl : Automating People for Red and Blue Tradecraft

November 27, 2018 | Matt Lorentzen

Whilst there is a wealth of information out there about how to build ...

ModSecurity v3.0.3: What To Expect

November 27, 2018 | Felipe "Zimmerle" Costa

At precisely 155 commits ahead of the latest version, ModSecurity version 3.0.3 ...

Demystifying Obfuscation Used in the Thanksgiving Spam Campaign

November 26, 2018 | Rodel Mendrez

During Thanksgiving week, we noticed this quite unusual XML-format MS Office ...