A week in security (August 3 – 9)
Last week on Malwarebytes Labs, on our Lock and Code podcast, we talked about identity and access management technology. We...
Last week on Malwarebytes Labs, on our Lock and Code podcast, we talked about identity and access management technology. We...
When switching devices from Android to iOS or the other way round, users were not able to retain the chat...
News overview Not just one but two new DDoS amplification methods were discovered last quarter. In mid-May, Israeli researchers reported...
Flask Session Cookie Decoder/EncoderDepencenciesPython 2 or Python 3itsdangerousFlaskInstallationBlackArch Linux# pacman -S flask-session-cookie-manager{3,2}GitArchLinuxBoth python3 etn python2:$ git clone https://github.com/noraj/flask-session-cookie-manager.git && cd...
Arcane is a simple script designed to backdoor iOS packages (iphone-arm) and create the necessar y resources for APT repositories....
Throughout the first half of the year, we released updates and features to help security teams work more effectively and...
Residents of Russia began to receive SMS about a way to get $10 million from the US State Department. In...
Around half a million online users were affected due to the breach of online examination software called "ProctorU," a platform...
IRFuzz is a simple scanner with yara rules for document archives or any files.Install1. PrerequisitesLinux or OS XYara: just use...
Evine is a simple, fast, and interactive web crawler and web scraper written in Golang. Evine is useful for a...
C# port of the Get-AppLockerPolicy PS cmdlet _____ _ ___ _ _/ ___| | / _ | | | |...
An extensible and freshly updated collection of phishingkits for forensics and future analysis topped with simple statsDisclaimerThis repository holds a...
By Marshall Chen, Loseway Lu, Yorkbing Yap, and Fyodor Yarochkin (Trend Micro Research) A series of ongoing business email compromise...
Findings of Link11's Security Operations Center (LSOC) uncovered a 97% increase in the number of attacks for the months of...
Quarterly highlights Targeted attacks The second quarter often saw phishers resort to targeted attacks, especially against fairly small companies. To...
FestIn is a tool for discovering open S3 Buckets starting from a domains.It perform a lot of test and collects...
Chalumeau is automated,extendable and customizable credential dumping tool based on powershell and python.Main FeaturesWrite your own PayloadsIn-Memory executionExtract Password ListDashboard...
This blog post is part 2 of a two-part blog series recapping Rapid7’s Black Hat debriefs as part of Virtual...
Face recognition AI is increasingly being used at Airports and at other security outlets, especially during a pandemic to heed...
It is noted that hackers use streaming platforms, TV series and movies to distribute advertising and malware. They can add...
Alexander Vurasko, a leading Infosecurity analyst at Softline Company, said that during the pandemic, scammers learned how to qualitatively fake...
As we continue to track web threats and credit card skimming in particular, we often rediscover techniques we’ve encountered elsewhere...
In June 2020, the online exam service ProctorU suffered a data breach which was subsequently shared extensively across online...
Download full report (PDF) As an incident response service provider, Kaspersky delivers a global service that results in global visibility...