Aggregator
VMware Security Advisory VMSA-2021-0005
5 years 1 month ago
Summary
VMWare published a security advisory, VMSA-2021-0005, that addresses an authentication bypass vulnerability in the VMware Carbon Black Cloud Workload appliance.
Threat Type
Vulnerability
Overview
VMWare published a security advisory, VMSA-2021-0005, that addresses a vulnerability (CVE-2021-21982) in the VMware Carbon Black Cloud Workload appliance. The vulnerability is an authentication bypass issue which could potentially allow a remote attacker to obtain administrative access to an affected device
APT Actors Gaining Initial Access for Attacks
5 years 1 month ago
Summary
The Federal Bureau of Investigations (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint cybersecurity advisory on APT actors exploiting vulnerabilities in FortiOS to gain initial access to commercial, government, and technology services networks.
Threat Type
Vulnerability
Overview
APT actors have been observed scanning devices on certain ports which are associated with the FortiOS vulnerability, CVE-2018-13379. The actors have also been enumerating devices that
fakesh
5 years 1 month ago
半块西瓜皮
rwctf2021 Easy Escape
5 years 1 month ago
Recently I’m confused by my research. I need to p […]
pzhxbz
ICS Advisory ICSA-21-091-01
5 years 1 month ago
Summary
The ICS-CERT has published an advisory that affects Rockwell Automation's FactoryTalk AssetCentre.
Threat Type
Vulnerability
Overview
The ICS-CERT has published an advisory that affects Rockwell Automation's FactoryTalk AssetCentre. Further information is available from the advisory which is summarized below.
ICS Advisory ICSA-21-091-01 - Rockwell Automation FactoryTalk AssetCentre
CVE-2021-27462 - A deserialization vulnerability exists in how the AosService.rem service in FactoryTalk AssetCentre ve
Tax Season: Criminals Play the Numbers Game Too
5 years 1 month ago
Criminals love tax season. The stress and urgency surrounding this time of year makes the victim pool highly vulnerable to various types of schemes.
Steve Ragan
钓鱼演练踩坑笔记
5 years 1 month ago
钓鱼演练踩坑笔记
钓鱼演练踩坑笔记
5 years 1 month ago
钓鱼演练踩坑笔记
钓鱼演练踩坑笔记
5 years 1 month ago
钓鱼演练踩坑笔记
钓鱼演练踩坑笔记
5 years 1 month ago
钓鱼演练踩坑笔记
钓鱼演练踩坑笔记
5 years 1 month ago
钓鱼演练踩坑笔记
为什么早期的 Windows 需要整理碎片
5 years 1 month ago
为什么早期的 Windows 需要整理碎片
5 years 1 month ago
为什么早期的 Windows 需要整理碎片
5 years 1 month ago
为什么早期的 Windows 需要整理碎片
5 years 1 month ago
New Credential Phishing Campaign, BadBlood, Targeting US and Israeli Medical Research Personnel
5 years 1 month ago
Summary
Proofpoint Threat Research discovered in late 2020 a new credential phishing campaign named BadBlood, carried out by threat group TA453, aka Charming Kitten. The campaign targets senior medical professionals who specialize in genetic, neurology, and oncology research in the United States and Israel. These targets are not the traditional targets for TA453, however, the tactics and techniques observed in BadBlood continue to mirror those used in historic TA453 campaigns.
Threat Type
Malware, Phishing,
为什么早期的 Windows 需要整理碎片
5 years 1 month ago
【As-Exploits】你不能错过的antSword插件
5 years 1 month ago
antSword 后渗透模块,一个你不能错过的插件。本文将介绍 v1.2 更新内容,并介绍该插件目前已有的功能。
【As-Exploits】你不能错过的antSword插件
5 years 1 month ago
antSword 后渗透模块,一个你不能错过的插件。本文将介绍 v1.2 更新内容,并介绍该插件目前已有的功能。