Phishing in the Cloud
February 19, 2020 | Dr. Fahim Abbasi, Phil Hay
Credential phishing is one of the leading threats faced by organizations today. ...
Perls of Wisdom: Responding to NetScaler CVE-2019-19781
February 13, 2020 | Noah Rubin and Erik Iker
On December 17, 2019, Citrix announced a vulnerability affecting NetScaler ...
Multiple Phishing Attacks Discovered Using the Coronavirus Theme
February 13, 2020 | Homer Pacag
It’s out there in the newspaper, social media, and television headlines. The ...
Patch Tuesday February 2020
February 11, 2020 | Karl Sigler
February's Patch Tuesday is here and brings with it patches for 98 CVEs. These ...
CVE-2020-2551: Unauthenticated RCE In Oracle WebLogic
February 04, 2020
Unauthenticated Remote Code Execution in IIOP protocol via Malicious JNDI ...
Reversing (and Recreating) Cryptographic Secrets Found in .NET Assemblies Using Python
February 04, 2020 | Tom Neaves
Picture the scene - you’re on a penetration test, somehow you’ve got hold of a ...
Why should you use correlation rules on top of traditional signatures?
February 04, 2020 | Javier Ruiz
The LevelBlue Labs team is in charge of writing correlation rules and releasing ...
Microsoft Internet Explorer Remote Code Execution 0-Day (CVE-2020-0674)
January 21, 2020 | SpiderLabs Researcher
2020 is not starting out quietly for Microsoft, it seems. After the first Patch ...
ModSecurity Denial of Service Details - CVE-2019-19886
January 20, 2020 | Trustwave SpiderLabs
ModSecurity is an open-source WAF engine maintained by Trustwave. As a lively ...
Windows CryptoAPI Spoofing Vulnerability - CVE-2020-0601
January 17, 2020 | Karl Sigler
One of the most notable vulnerabilities patched during Microsoft's first Patch ...
Citrix ADC/Netscaler - CVE-2019-19781
January 16, 2020 | Bryant Smith
The Citrix vulnerability (CVE-2019-19781) was first identified in December of ...
Patch Tuesday, January 2020
January 14, 2020 | Karl Sigler
Happy 2020! Microsoft is helping you celebrate the new decade with patches for ...
ModSecurity v3.0.4 Released!
January 14, 2020 | SpiderLabs Researcher
It is a pleasure to announce the release of ModSecurity version 3.0.4 ...
Windows Debugging & Exploiting Part 3: WinDBG Time Travel Debugging
January 09, 2020 | Bruno Oliveira
Introduction Hi, my fellow friends! How are you? Hopefully, you had a terrific ...
Technical Analysis of an Active Cryptomining Worm by LevelBlue Labs
January 09, 2020 | Fernando Dominguez
This blog post provides an overview of the LevelBlue Labs™ technical analysis ...
Using the InterPlanetary File System For Offensive Operations
January 02, 2020 | Stephan Borosh
Introduction In this blog post, I intend to provide some insight into using the ...
Leveraging Disk Imaging Tools to Deliver RATs
December 23, 2019 | Joshua Deacon, Diana Lopera, Fahim Abbasi
This year we observed a notable uptick in disc imaging software (like .ISO) ...
Undressing the REvil
December 20, 2019 | Rodel Mendrez
Contributors: Lloyd Macrohon and Rodel Mendrez
Anyone Can Check for Magecart with Just the Browser
December 18, 2019 | Michael Yuen
In the past, there have been plenty of articles and blog posts recommending the ...
Typosquatting in Python Repositories
December 13, 2019 | Radoslaw Zdonczyk
Python's popularity is amazing and constantly growing. For the first time, ...
Patch Tuesday, December 2019
December 10, 2019 | Karl Sigler
December's Patch Tuesday is upon us, and, as in years gone by, it's a rather ...
SCshell: Fileless Lateral Movement Using Service Manager
December 09, 2019 | Charles Hamilton
During red team engagements, lateral movement in a network is crucial. In ...
CVE-2019-1429: (Another) Microsoft Internet Explorer 0-Day
December 05, 2019 | SpiderLabs Researcher
November’s Patch Tuesday from Microsoft included a patch for yet another ...
Introducing Password Cracking Manager: CrackQ
December 04, 2019 | Daniel Turner
Today we are releasing CrackQ, a queuing system to manage password cracking ...
Time Windows for Penetration Testing
November 22, 2019 | Albert Campa
Often when penetration tests are scheduled, it will be requested that testing ...
CVE-2019-15652: SatLink VSAT Vulnerabilities
November 21, 2019 | Robert Foggia
Back in May of this year, I discovered a few vulnerabilities in the SatLink ...
Fake Windows Update Spam Leads to Cyborg Ransomware and Its Builder
November 19, 2019 | Diana Lopera
Recently, fake Microsoft Windows Update emails were spammed with the following ...
Windows Debugging & Exploiting Part 2 - WinDBG 101
November 18, 2019 | Bruno Oliveira
Introduction Hello again! After our previous post about the environment setup, ...