What's in a window name? Turns out that it could be a sneaky tracking code, so Firefox has put a stop to that.
Read more
In January, we learned about a Chinese espionage campaign that exploited four zero-days in Microsoft Exchange. One of the characteristics of the campaign, in the later days...
Read more
Google’s Project Zero discovered, and caused to be patched, eleven zero-day exploits against Chrome, Safari, Microsoft Windows, and iOS. This seems to have been exploited by...
Read moreNew episode - listen now! (And find out what HAFNIUM really stands for.)
Read moreMore on the Chinese Zero-Day Microsoft Exchange Hack
March 10 2021
Nick Weaver has an excellent post on the Microsoft Exchange hack:
The investigative journalist Brian Krebs has produced a handy timeline of events and a few things stand...
Read more
Webshells explained, with some (safe) examples you can try at home if you want to learn more.
Read moreBeginning in January 2021, Mandiant Managed Defense observed multiple instances of abuse of Microsoft Exchange Server within at least one client environment. The observed activity included creation...
Read moreBeginning in January 2021, Mandiant Managed Defense observed multiple instances of abuse of Microsoft Exchange Server within at least one client environment. The observed activity included creation...
Read moreFour Microsoft Exchange Zero-Days Exploited by China
March 4 2021Microsoft has issued an emergency Microsoft Exchange patch to fix four zero-day vulnerabilities currently being exploited by China. EDITED TO ADD (3/12): Exchange Online is not affected.
Read moreIt's déjà vu all over again! New month, new Chrome zero-day bug being exploited in the wild.
Read more
Recent Comments