OT HAPPY THANKSGIVING DAY CANADA |
2010-10-11 | Adrien de Beaupre | OT: Happy Thanksgiving Day Canada |
OT |
2025-03-06/a> | Guy Bruneau | DShield Traffic Analysis using ELK |
2025-02-13/a> | Guy Bruneau | DShield SIEM Docker Updates |
2025-01-16/a> | Jesse La Grew | Extracting Practical Observations from Impractical Datasets |
2024-12-26/a> | Jesse La Grew | Capturing Honeypot Data Beyond the Logs |
2024-12-09/a> | Jesse La Grew | CURLing for Crypto on Honeypots |
2024-11-06/a> | Jesse La Grew | [Guest Diary] Insights from August Web Traffic Surge |
2024-10-09/a> | Xavier Mertens | From Perfctl to InfoStealer |
2024-09-13/a> | Jesse La Grew | Finding Honeypot Data Clusters Using DBSCAN: Part 2 |
2024-09-06/a> | Jesse La Grew | Enrichment Data: Keeping it Fresh |
2024-08-16/a> | Jesse La Grew | [Guest Diary] 7 minutes and 4 steps to a quick win: A write-up on custom tools |
2024-07-10/a> | Jesse La Grew | Finding Honeypot Data Clusters Using DBSCAN: Part 1 |
2024-06-17/a> | Xavier Mertens | New NetSupport Campaign Delivered Through MSIX Packages |
2024-06-07/a> | Johannes Ullrich | Finding End of Support Dates: UK PTSI Regulation |
2024-04-25/a> | Jesse La Grew | Does it matter if iptables isn't running on my honeypot? |
2024-04-17/a> | Xavier Mertens | Malicious PDF File Used As Delivery Mechanism |
2024-04-15/a> | Johannes Ullrich | Quick Palo Alto Networks Global Protect Vulnerablity Update (CVE-2024-3400) |
2024-04-13/a> | Johannes Ullrich | Critical Palo Alto GlobalProtect Vulnerability Exploited (CVE-2024-3400) |
2024-03-10/a> | Guy Bruneau | What happens when you accidentally leak your AWS API keys? [Guest Diary] |
2024-03-07/a> | Jesse La Grew | [Guest Diary] AWS Deployment Risks - Configuration and Credential File Targeting |
2024-03-03/a> | Guy Bruneau | Capturing DShield Packets with a LAN Tap [Guest Diary] |
2024-02-28/a> | Johannes Ullrich | Exploit Attempts for Unknown Password Reset Vulnerability |
2024-02-25/a> | Guy Bruneau | Utilizing the VirusTotal API to Query Files Uploaded to DShield Honeypot [Guest Diary] |
2024-02-18/a> | Guy Bruneau | Mirai-Mirai On The Wall... [Guest Diary] |
2024-02-15/a> | Jesse La Grew | [Guest Diary] Learning by doing: Iterative adventures in troubleshooting |
2024-02-03/a> | Guy Bruneau | DShield Sensor Log Collection with Elasticsearch |
2024-01-30/a> | Johannes Ullrich | What did I say to make you stop talking to me? |
2024-01-17/a> | Jesse La Grew | Number Usage in Passwords |
2024-01-07/a> | Guy Bruneau | Suspicious Prometei Botnet Activity |
2023-12-27/a> | Guy Bruneau | Unveiling the Mirai: Insights into Recent DShield Honeypot Activity [Guest Diary] |
2023-12-13/a> | Guy Bruneau | T-shooting Terraform for DShield Honeypot in Azure [Guest Diary] |
2023-12-10/a> | Guy Bruneau | Honeypots: From the Skeptical Beginner to the Tactical Enthusiast |
2023-11-30/a> | John Bambenek | Prophetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today |
2023-11-27/a> | Guy Bruneau | Decoding the Patterns: Analyzing DShield Honeypot Activity [Guest Diary] |
2023-11-22/a> | Guy Bruneau | CVE-2023-1389: A New Means to Expand Botnets |
2023-11-20/a> | Jesse La Grew | Overflowing Web Honeypot Logs |
2023-11-09/a> | Guy Bruneau | Routers Targeted for Gafgyt Botnet [Guest Diary] |
2023-10-15/a> | Guy Bruneau | Domain Name Used as Password Captured by DShield Sensor |
2023-09-18/a> | Johannes Ullrich | Internet Wide Multi VPN Search From Single /24 Network |
2023-09-14/a> | Jesse La Grew | DShield and qemu Sitting in a Tree: L-O-G-G-I-N-G |
2023-09-09/a> | Guy Bruneau | ?Anyone get the ASN of the Truck that Hit Me?!?: Creating a PowerShell Function to Make 3rd Party API Calls for Extending Honeypot Information [Guest Diary] |
2023-09-05/a> | Jesse La Grew | Common usernames submitted to honeypots |
2023-09-02/a> | Jesse La Grew | What is the origin of passwords submitted to honeypots? |
2023-08-31/a> | Guy Bruneau | Potential Weaponizing of Honeypot Logs [Guest Diary] |
2023-08-21/a> | Xavier Mertens | Quick Malware Triage With Inotify Tools |
2023-08-12/a> | Guy Bruneau | DShield Sensor Monitoring with a Docker ELK Stack [Guest Diary] |
2023-07-23/a> | Guy Bruneau | Install & Configure Filebeat on Raspberry Pi ARM64 to Parse DShield Sensor Logs |
2023-07-13/a> | Jesse La Grew | DShield Honeypot Maintenance and Data Retention |
2023-07-06/a> | Jesse La Grew | IDS Comparisons with DShield Honeypot Data |
2023-06-22/a> | Brad Duncan | Qakbot (Qbot) activity, obama271 distribution tag |
2023-06-11/a> | Guy Bruneau | DShield Honeypot Activity for May 2023 |
2023-05-22/a> | Johannes Ullrich | Probes for recent ABUS Security Camera Vulnerability: Attackers keep an eye on everything. |
2023-05-14/a> | Guy Bruneau | DShield Sensor Update |
2023-05-09/a> | Russ McRee | Exploratory Data Analysis with CISSM Cyber Attacks Database - Part 2 |
2023-04-17/a> | Jan Kopriva | The strange case of Great honeypot of China |
2023-04-12/a> | Brad Duncan | Recent IcedID (Bokbot) activity |
2023-03-11/a> | Xavier Mertens | Overview of a Mirai Payload Generator |
2023-03-02/a> | Didier Stevens | YARA: Detect The Unexpected ... |
2023-02-28/a> | Brad Duncan | BB17 distribution Qakbot (Qbot) activity |
2023-02-24/a> | Brad Duncan | URL files and WebDAV used for IcedID (Bokbot) infection |
2023-02-09/a> | Xavier Mertens | A Backdoor with Smart Screenshot Capability |
2023-02-07/a> | Yee Ching Tok | A Survey of Bluetooth Vulnerabilities Trends (2023 Edition) |
2023-02-05/a> | Didier Stevens | Video: Analyzing Malicious OneNote Documents |
2023-02-01/a> | Didier Stevens | Detecting (Malicious) OneNote Files |
2023-01-31/a> | Jesse La Grew | DShield Honeypot Setup with pfSense |
2023-01-25/a> | Xavier Mertens | A First Malicious OneNote Document |
2023-01-05/a> | Brad Duncan | More Brazil malspam pushing Astaroth (Guildma) in January 2023 |
2022-12-29/a> | Jesse La Grew | Opening the Door for a Knock: Creating a Custom DShield Listener |
2022-12-21/a> | Guy Bruneau | DShield Sensor Setup in Azure |
2022-12-20/a> | Xavier Mertens | Linux File System Monitoring & Actions |
2022-12-02/a> | Brad Duncan | obama224 distribution Qakbot tries .vhd (virtual hard disk) images |
2022-11-02/a> | Brad Duncan | Who put the "Dark" in DarkVNC? |
2022-10-16/a> | Didier Stevens | Video: Analysis of a Malicious HTML File (QBot) |
2022-10-13/a> | Didier Stevens | Analysis of a Malicious HTML File (QBot) |
2022-10-07/a> | Xavier Mertens | Critical Fortinet Vulnerability Ahead |
2022-09-18/a> | Didier Stevens | Video: Grep & Tail -f With Notepad++ |
2022-09-12/a> | Johannes Ullrich | VirusTotal Result Comparisons for Honeypot Malware |
2022-09-05/a> | Didier Stevens | Quickie: Grep & Tail -f With Notepad++ |
2022-08-30/a> | Johannes Ullrich | Two things that will never die: bash scripts and IRC! |
2022-08-24/a> | Brad Duncan | Monster Libra (TA551/Shathak) --> IcedID (Bokbot) --> Cobalt Strike & DarkVNC |
2022-08-19/a> | Brad Duncan | Brazil malspam pushes Astaroth (Guildma) malware |
2022-08-18/a> | Johannes Ullrich | Honeypot Attack Summaries with Python |
2022-08-12/a> | Brad Duncan | Monster Libra (TA551/Shathak) pushes IcedID (Bokbot) with Dark VNC and Cobalt Strike |
2022-07-27/a> | Brad Duncan | IcedID (Bokbot) with Dark VNC and Cobalt Strike |
2022-07-10/a> | Guy Bruneau | Excel 4 Emotet Maldoc Analysis using CyberChef |
2022-07-07/a> | Brad Duncan | Emotet infection with Cobalt Strike |
2022-07-05/a> | Jan Kopriva | EternalBlue 5 years after WannaCry and NotPetya |
2022-06-30/a> | Brad Duncan | Case Study: Cobalt Strike Server Lives on After Its Domain Is Suspended |
2022-06-28/a> | Johannes Ullrich | Possible Scans for HiByMusic Devices |
2022-06-24/a> | Xavier Mertens | Python (ab)using The Windows GUI |
2022-06-15/a> | Johannes Ullrich | Terraforming Honeypots. Installing DShield Sensors in the Cloud |
2022-06-09/a> | Brad Duncan | TA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt) |
2022-05-30/a> | Xavier Mertens | New Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme (CVE-2022-30190) |
2022-05-19/a> | Brad Duncan | Bumblebee Malware from TransferXL URLs |
2022-05-12/a> | Rob VandenBrink | When Get-WebRequest Fails You |
2022-05-03/a> | Johannes Ullrich | Some Honeypot Updates |
2022-04-20/a> | Brad Duncan | "aa" distribution Qakbot (Qbot) infection with DarkVNC traffic |
2022-04-19/a> | Johannes Ullrich | Resetting Linux Passwords with U-Boot Bootloaders |
2022-03-31/a> | Johannes Ullrich | Spring Vulnerability Update - Exploitation Attempts CVE-2022-22965 |
2022-03-25/a> | Xavier Mertens | XLSB Files: Because Binary is Stealthier Than XML |
2022-03-16/a> | Brad Duncan | Qakbot infection with Cobalt Strike and VNC activity |
2022-03-10/a> | Xavier Mertens | Credentials Leaks on VirusTotal |
2022-03-03/a> | Johannes Ullrich | Attackers Search For Exposed "LuCI" Folders: Help me understand this attack |
2022-03-02/a> | Johannes Ullrich | The More Often Something is Repeated, the More True It Becomes: Dealing with Social Media |
2022-02-16/a> | Brad Duncan | Astaroth (Guildma) infection |
2022-02-15/a> | Xavier Mertens | Who Are Those Bots? |
2022-02-09/a> | Brad Duncan | Example of Cobalt Strike from Emotet infection |
2022-01-25/a> | Brad Duncan | Emotet Stops Using 0.0.0.0 in Spambot Traffic |
2022-01-19/a> | Brad Duncan | 0.0.0.0 in Emotet Spambot Traffic |
2022-01-07/a> | Xavier Mertens | Custom Python RAT Builder |
2021-12-28/a> | Russ McRee | LotL Classifier tests for shells, exfil, and miners |
2021-12-22/a> | Brad Duncan | December 2021 Forensic Contest: Answers and Analysis |
2021-12-16/a> | Brad Duncan | How the "Contact Forms" campaign tricks people |
2021-12-02/a> | Brad Duncan | TA551 (Shathak) pushes IcedID (Bokbot) |
2021-11-26/a> | Guy Bruneau | Searching for Exposed ASUS Routers Vulnerable to CVE-2021-20090 |
2021-11-20/a> | Guy Bruneau | Hikvision Security Cameras Potentially Exposed to Remote Code Execution |
2021-11-16/a> | Brad Duncan | Emotet Returns |
2021-11-04/a> | Tom Webb | Xmount for Disk Images |
2021-11-04/a> | Brad Duncan | October 2021 Forensic Contest: Answers and Analysis |
2021-11-01/a> | Yee Ching Tok | Revisiting BrakTooth: Two Months Later |
2021-10-20/a> | Xavier Mertens | Thanks to COVID-19, New Types of Documents are Lost in The Wild |
2021-10-04/a> | Johannes Ullrich | Boutique "Dark" Botnet Hunting for Crumbs |
2021-09-23/a> | Xavier Mertens | Excel Recipe: Some VBA Code with a Touch of Excel4 Macro |
2021-08-31/a> | Yee Ching Tok | BrakTooth: Impacts, Implications and Next Steps |
2021-08-13/a> | Brad Duncan | Example of Danabot distributed through malspam |
2021-07-24/a> | Bojan Zdrnja | Active Directory Certificate Services (ADCS - PKI) domain admin vulnerability |
2021-07-24/a> | Xavier Mertens | Agent.Tesla Dropped via a .daa Image and Talking to Telegram |
2021-06-30/a> | Brad Duncan | June 2021 Forensic Contest: Answers and Analysis |
2021-06-24/a> | Xavier Mertens | Do you Like Cookies? Some are for sale! |
2021-05-14/a> | Xavier Mertens | "Open" Access to Industrial Systems Interface is Also Far From Zero |
2021-04-15/a> | Johannes Ullrich | Why and How You Should be Using an Internal Certificate Authority |
2021-04-06/a> | Jan Kopriva | Malspam with Lokibot vs. Outlook and RFCs |
2021-04-02/a> | Xavier Mertens | C2 Activity: Sandboxes or Real Victims? |
2021-03-06/a> | Xavier Mertens | Spotting the Red Team on VirusTotal! |
2021-03-03/a> | Brad Duncan | Qakbot infection with Cobalt Strike |
2021-02-28/a> | Didier Stevens | Maldocs: Protection Passwords |
2021-02-23/a> | Jan Kopriva | Qakbot in a response to Full Disclosure post |
2021-02-22/a> | Didier Stevens | Unprotecting Malicious Documents For Inspection |
2021-02-17/a> | Brad Duncan | Malspam pushing Trickbot gtag rob13 |
2021-02-13/a> | Guy Bruneau | vSphere Replication updates address a command injection vulnerability (CVE-2021-21976) - https://www.vmware.com/security/advisories/VMSA-2021-0001.html |
2021-01-28/a> | Daniel Wesemann | Emotet vs. Windows Attack Surface Reduction |
2021-01-26/a> | Brad Duncan | TA551 (Shathak) Word docs push Qakbot (Qbot) |
2021-01-20/a> | Brad Duncan | Qakbot activity resumes after holiday break |
2021-01-15/a> | Guy Bruneau | Obfuscated DNS Queries |
2020-12-09/a> | Brad Duncan | Recent Qakbot (Qbot) activity |
2020-12-04/a> | Guy Bruneau | Detecting Actors Activity with Threat Intel |
2020-11-18/a> | Xavier Mertens | When Security Controls Lead to Security Issues |
2020-11-03/a> | Brad Duncan | Emotet -> Qakbot -> more Emotet |
2020-10-23/a> | Russ McRee | Sooty: SOC Analyst's All-in-One Tool |
2020-10-20/a> | Xavier Mertens | Mirai-alike Python Scanner |
2020-10-14/a> | Brad Duncan | More TA551 (Shathak) Word docs push IcedID (Bokbot) |
2020-09-29/a> | Xavier Mertens | Managing Remote Access for Partners & Contractors |
2020-08-24/a> | Xavier Mertens | Tracking A Malware Campaign Through VT |
2020-08-22/a> | Guy Bruneau | Remote Desktop (TCP/3389) and Telnet (TCP/23), What might they have in Common? |
2020-08-19/a> | Xavier Mertens | Example of Word Document Delivering Qakbot |
2020-08-03/a> | Xavier Mertens | Powershell Bot with Multiple C2 Protocols |
2020-08-01/a> | Jan Kopriva | What pages do bad bots look for? |
2020-07-15/a> | Brad Duncan | Word docs with macros for IcedID (Bokbot) |
2020-07-01/a> | Jim Clausing | Setting up the Dshield honeypot and tcp-honeypot.py |
2020-06-28/a> | Guy Bruneau | tcp-honeypot.py Logstash Parser & Dashboard Update |
2020-06-25/a> | Johannes Ullrich | Tech Tuesday Recap / Recordings: Part 2 (Installing the Honeypot) release. |
2020-06-20/a> | Tom Webb | Pi Zero HoneyPot |
2020-06-13/a> | Guy Bruneau | Mirai Botnet Activity |
2020-06-05/a> | Remco Verhoef | Not so FastCGI! |
2020-06-05/a> | Johannes Ullrich | Cyber Security for Protests |
2020-05-20/a> | Brad Duncan | Microsoft Word document with malicious macro pushes IcedID (Bokbot) |
2020-05-06/a> | Xavier Mertens | Keeping an Eye on Malicious Files Life Time |
2020-05-01/a> | Jim Clausing | Attack traffic on TCP port 9673 |
2020-04-20/a> | Didier Stevens | KPOT AutoIt Script: Analysis |
2020-04-12/a> | Didier Stevens | Reader Analysis: "Dynamic analysis technique to get decrypted KPOT Malware." |
2020-04-02/a> | Tom Webb | TPOT's Cowrie to ISC Logs |
2020-04-01/a> | Brad Duncan | Qakbot malspam sent from an infected Windows host |
2020-03-23/a> | Didier Stevens | KPOT Deployed via AutoIt Script |
2020-03-22/a> | Didier Stevens | More COVID-19 Themed Malware |
2020-03-21/a> | Guy Bruneau | Honeypot - Scanning and Targeting Devices & Services |
2020-03-18/a> | Brad Duncan | Trickbot gtag red5 distributed as a DLL file |
2020-01-28/a> | Brad Duncan | Emotet epoch 1 infection with Trickbot gtag mor84 |
2020-01-23/a> | Xavier Mertens | Complex Obfuscation VS Simple Trick |
2020-01-12/a> | Guy Bruneau | ELK Dashboard and Logstash parser for tcp-honeypot Logs |
2019-12-24/a> | Brad Duncan | Malspam with links to Word docs pushes IcedID (Bokbot) |
2019-12-18/a> | Brad Duncan | Emotet infection with spambot activity |
2019-12-15/a> | Didier Stevens | VirusTotal Email Submissions |
2019-12-11/a> | Brad Duncan | German language malspam pushes yet another wave of Trickbot |
2019-11-13/a> | Brad Duncan | An example of malspam pushing Lokibot malware, November 2019 |
2019-11-03/a> | Didier Stevens | You Too? "Unusual Activity with Double Base64 Encoding" |
2019-10-30/a> | Xavier Mertens | Keep an Eye on Remote Access to Mailboxes |
2019-10-02/a> | Brad Duncan | A recent example of Emotet malspam |
2019-09-24/a> | Xavier Mertens | Huge Amount of remotewebaccess.com Sites Found in Certificate Transparency Logs |
2019-09-18/a> | Brad Duncan | Emotet malspam is back |
2019-09-03/a> | Johannes Ullrich | [Guest Diary] Tricky LNK points to TrickBot |
2019-08-14/a> | Brad Duncan | Recent example of MedusaHTTP malware |
2019-08-08/a> | Johannes Ullrich | [Guest Diary] The good, the bad and the non-functional, or "how not to do an attack campaign" |
2019-07-26/a> | Kevin Shortt | DVRIP Port 34567 - Uptick |
2019-06-28/a> | Rob VandenBrink | Verifying Running Processes against VirusTotal - Domain-Wide |
2019-05-16/a> | Xavier Mertens | The Risk of Authenticated Vulnerability Scans |
2019-03-13/a> | Brad Duncan | Malspam pushes Emotet with Qakbot as the follow-up malware |
2019-03-06/a> | Brad Duncan | Malspam with password-protected word docs still pushing IcedID (Bokbot) with Trickbot |
2019-02-14/a> | Xavier Mertens | Old H-Worm Delivered Through GitHub |
2019-01-16/a> | Brad Duncan | Emotet infections and follow-up malware |
2019-01-10/a> | Brad Duncan | Heartbreaking Emails: "Love You" Malspam |
2019-01-09/a> | Russ McRee | gganimate: Animate YouR Security Analysis |
2018-12-23/a> | Guy Bruneau | Scanning Activity, end Goal is to add Hosts to Mirai Botnet |
2018-12-18/a> | Brad Duncan | Malspam links to password-protected Word docs that push IcedID (Bokbot) |
2018-12-05/a> | Brad Duncan | Campaign evolution: Hancitor changes its Word macros |
2018-12-04/a> | Brad Duncan | Malspam pushing Lokibot malware |
2018-11-15/a> | Brad Duncan | Emotet infection with IcedID banking Trojan |
2018-11-14/a> | Brad Duncan | Day in the life of a researcher: Finding a wave of Trickbot malspam |
2018-11-09/a> | Tom Webb | Playing with T-POT |
2018-09-26/a> | Brad Duncan | One Emotet infection leads to three follow-up malware infections |
2018-07-26/a> | Xavier Mertens | Windows Batch File Deobfuscation |
2018-07-24/a> | Brad Duncan | Recent Emotet activity |
2018-06-27/a> | Renato Marinho | Silently Profiling Unknown Malware Samples |
2018-06-16/a> | Russ McRee | Anomaly Detection & Threat Hunting with Anomalize |
2018-06-13/a> | Remco Verhoef | From Microtik with Love |
2018-05-27/a> | Guy Bruneau | Capture and Analysis of User Agents |
2018-05-19/a> | Xavier Mertens | Malicious Powershell Targeting UK Bank Customers |
2018-05-09/a> | Xavier Mertens | Nice Phishing Sample Delivering Trickbot |
2018-03-08/a> | Xavier Mertens | CRIMEB4NK IRC Bot |
2017-11-30/a> | Brad Duncan | More Malspam pushing Emotet malware |
2017-11-28/a> | Xavier Mertens | Apple High Sierra Uses a Passwordless Root Account |
2017-11-25/a> | Guy Bruneau | Exim Remote Code Exploit |
2017-11-11/a> | Xavier Mertens | Keep An Eye on your Root Certificates |
2017-10-19/a> | Brad Duncan | HSBC-themed malspam uses ISO attachments to push Loki Bot malware |
2017-08-15/a> | Brad Duncan | Malspam pushing Trickbot banking Trojan |
2017-08-10/a> | Didier Stevens | Maldoc Analysis with ViperMonkey |
2017-08-03/a> | Johannes Ullrich | Using a Raspberry Pi honeypot to contribute data to DShield/ISC |
2017-07-28/a> | Didier Stevens | Static Analysis of Emotet Maldoc |
2017-07-27/a> | Xavier Mertens | TinyPot, My Small Honeypot |
2017-07-26/a> | Brad Duncan | Malspam pushing Emotet malware |
2017-07-19/a> | Xavier Mertens | Bots Searching for Keys & Config Files |
2017-06-28/a> | Brad Duncan | Petya? I hardly know ya! - an ISC update on the 2017-06-27 ransomware outbreak |
2017-05-08/a> | Renato Marinho | Exploring a P2P Transient Botnet - From Discovery to Enumeration |
2017-03-12/a> | Guy Bruneau | Honeypot Logs and Tracking a VBE Script |
2017-02-21/a> | Jim Clausing | Quick and dirty generic listener |
2017-02-10/a> | Brad Duncan | Hancitor/Pony malspam |
2017-01-10/a> | Johannes Ullrich | Port 37777 "MapTable" Requests |
2017-01-07/a> | Xavier Mertens | Using Security Tools to Compromize a Network |
2017-01-06/a> | John Bambenek | Great Misadventures of Security Vendors: Absurd Sandboxing Edition |
2016-12-31/a> | Xavier Mertens | Ongoing Scans Below the Radar |
2016-12-07/a> | Xavier Mertens | The Passwords You Should Never Use |
2016-11-13/a> | Guy Bruneau | Bitcoin Miner File Upload via FTP |
2016-09-15/a> | Xavier Mertens | In Need of a OTP Manager Soon? |
2016-09-10/a> | Xavier Mertens | Ongoing IMAP Scan, Anyone Else? |
2016-08-22/a> | Russ McRee | Red Team Tools Updates: hashcat and SpiderFoot |
2016-07-27/a> | Xavier Mertens | Analyze of a Linux botnet client source code |
2016-07-07/a> | Johannes Ullrich | Patchwork: Is it still "Advanced" if all you have to do is Copy/Paste? |
2016-06-15/a> | Richard Porter | Warp Speed Ahead, L7 Open Source Packet Generator: Warp17 |
2016-06-03/a> | Tom Liston | MySQL is YourSQL |
2016-05-14/a> | Guy Bruneau | INetSim as a Basic Honeypot |
2016-04-27/a> | Tom Webb | Kippos Cousin Cowrie |
2016-03-15/a> | Xavier Mertens | Dockerized DShield SSH Honeypot |
2016-03-13/a> | Xavier Mertens | SSH Honeypots (Ab)used as Proxy |
2016-02-26/a> | Xavier Mertens | Quick Audit of *NIX Systems |
2016-01-31/a> | Guy Bruneau | Windows 10 and System Protection for DATA Default is OFF |
2016-01-23/a> | Didier Stevens | Sigcheck and VirusTotal for Offline Machine |
2016-01-08/a> | Mark Hofman | SLOTH, attack on TLS using MD5 |
2015-10-12/a> | Guy Bruneau | Critical Vulnerability in Multiple Cisco Products - Apache Struts 2 Command Execution http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2 |
2015-08-06/a> | Didier Stevens | Sigcheck and virustotal-search |
2015-07-21/a> | Didier Stevens | Searching Through the VirusTotal Database |
2015-07-17/a> | Didier Stevens | Process Explorer and VirusTotal |
2015-07-17/a> | Didier Stevens | Autoruns and VirusTotal |
2015-07-17/a> | Didier Stevens | Sigcheck and VirusTotal |
2015-04-14/a> | Johannes Ullrich | Odd POST Request To Web Honeypot |
2015-04-08/a> | Tom Webb | Is it a breach or not? |
2015-03-16/a> | Johannes Ullrich | Automatically Documenting Network Connections From New Devices Connected to Home Networks |
2015-03-02/a> | Johannes Ullrich | How Do You Control the Internet of Things Inside Your Network? |
2015-02-12/a> | Johannes Ullrich | Did You Remove That Debug Code? Netatmo Weather Station Sending WPA Passphrase in the Clear |
2015-02-06/a> | Johannes Ullrich | Anthem, TurboTax and How Things "Fit Together" Sometimes |
2014-10-09/a> | Johannes Ullrich | CSAM: My servers started speaking IRC, and that is when I started to listen! |
2014-10-03/a> | Johannes Ullrich | CSAM: The Power of Virustotal to Turn Harmless Binaries Malicious |
2014-08-16/a> | Lenny Zeltser | Web Server Attack Investigation - Installing a Bot and Reverse Shell via a PHP Vulnerability |
2014-07-31/a> | Chris Mohan | A Honeypot for home: Raspberry Pi |
2014-07-30/a> | Rick Wanner | Symantec Endpoint Protection Privilege Escalation Zero Day |
2014-07-28/a> | Johannes Ullrich | Interesting HTTP User Agent "chroot-apach0day" |
2014-07-14/a> | Johannes Ullrich | The Internet of Things: How do you "on-board" devices? |
2014-06-30/a> | Johannes Ullrich | Should I setup a Honeypot? [SANSFIRE] |
2014-06-28/a> | Mark Hofman | No more Microsoft advisory email notifications? |
2014-06-04/a> | Richard Porter | p0f, Got Packets? |
2014-05-01/a> | Johannes Ullrich | Busybox Honeypot Fingerprinting and a new DVR scanner |
2014-03-04/a> | Daniel Wesemann | Triple Handshake Cookie Cutter |
2014-02-07/a> | Rob VandenBrink | Hello Virustotal? It's Microsoft Calling. |
2014-01-16/a> | Kevin Shortt | Port 4028 - Interesting Activity |
2013-12-07/a> | Guy Bruneau | Suspected Active Rovnix Botnet Controller |
2013-11-22/a> | Rick Wanner | Port 0 DDOS |
2013-11-02/a> | Rick Wanner | Protecting Your Family's Computers |
2013-10-26/a> | Guy Bruneau | Active Perl/Shellbot Trojan |
2013-10-05/a> | Richard Porter | Adobe Breach Notification, Notifications? |
2013-09-18/a> | Rob VandenBrink | Cisco DCNM Update Released |
2013-09-02/a> | Adrien de Beaupre | [OT] Happy Labo(u)r Day USA and Canada! |
2013-08-13/a> | Swa Frantzen | Microsoft security advisories: RDP and MD5 deprecation in Microsoft root certificates |
2013-08-11/a> | Bojan Zdrnja | XATattacks (attacks on xat.com) |
2013-08-09/a> | Kevin Shortt | Copy Machines - Changing Scanned Content |
2013-07-25/a> | Johannes Ullrich | A Couple of SSH Brute Force Compromises |
2013-07-13/a> | Lenny Zeltser | Decoy Personas for Safeguarding Online Identity Using Deception |
2013-05-19/a> | Kevin Shortt | Port 51616 - Got Packets? |
2013-04-14/a> | Johannes Ullrich | Protocol 61 Packets Follow Up |
2013-04-04/a> | Johannes Ullrich | Microsoft April Patch Tuesday Advance Notification |
2013-03-29/a> | Chris Mohan | Does your breach email notification look like a phish? |
2013-03-09/a> | Guy Bruneau | IPv6 Focus Month: IPv6 Encapsulation - Protocol 41 |
2013-03-02/a> | Scott Fendley | Evernote Security Issue |
2013-02-21/a> | Bojan Zdrnja | SSHD rootkit in the wild |
2013-02-16/a> | Lorna Hutcheson | Fedora RedHat Vulnerabilty Released |
2013-01-15/a> | Russ McRee | Cisco introducing Cisco Security Notices 16 JAN 2013 |
2013-01-09/a> | Rob VandenBrink | Hotmail seeing some temporary access issues |
2013-01-08/a> | Richard Porter | A picture worth a 1000 barcodes? |
2012-12-06/a> | Johannes Ullrich | How to identify if you are behind a "Transparent Proxy" |
2012-10-26/a> | Russ McRee | Cyber Security Awareness Month - Day 26 - Attackers use trusted domain to propagate Citadel Zeus variant |
2012-08-22/a> | Adrien de Beaupre | Apple Remote Desktop update fixes no encryption issue |
2012-07-12/a> | Rob VandenBrink | Today at SANSFIRE - Dude Your Car is PWND ! |
2012-07-05/a> | Adrien de Beaupre | Microsoft advanced notification for July 2012 patch Tuesday |
2012-05-22/a> | Johannes Ullrich | The "Do Not Track" header |
2012-05-22/a> | Johannes Ullrich | When factors collapse and two factor authentication becomes one. |
2012-04-26/a> | Richard Porter | Define Irony: A medical device with a Virus? |
2012-03-16/a> | Russ McRee | MS12-020 RDP vulnerabilities: Patch, Mitigate, Detect |
2012-02-28/a> | Russ McRee | QOTD from securityburnout.org |
2012-02-27/a> | Johannes Ullrich | Odd Vanishing Signatures in OS X XProtect |
2011-12-08/a> | Adrien de Beaupre | Microsoft Security Bulletin Advance Notification for December 2011 |
2011-12-06/a> | Pedro Bueno | The RedRet connection... |
2011-11-28/a> | Tom Liston | A Puzzlement... |
2011-11-22/a> | Pedro Bueno | Updates on ZeroAccess and BlackHole front... |
2011-11-19/a> | Pedro Bueno | Dragon Research Group (DRG) announced the white paper entitled "VNC: Threats and Countermeasures" : https://dragonresearchgroup.org/insight/vnc-tac.html |
2011-10-26/a> | Rob VandenBrink | The Theoretical "SSL Renegotiation" Issue gets a Whole Lot More Real ! |
2011-10-01/a> | Mark Hofman | Adobe Photoshop for Windows Vulnerability (CVE-2011-2443) |
2011-09-20/a> | Swa Frantzen | Diginotar declared bankrupt |
2011-09-19/a> | Guy Bruneau | MS Security Advisory Update - Fraudulent DigiNotar Certificates |
2011-09-15/a> | Swa Frantzen | DigiNotar looses their accreditation for qualified certificates |
2011-09-13/a> | Swa Frantzen | More DigiNotar intermediate certificates blocklisted at Microsoft |
2011-09-07/a> | Lenny Zeltser | GlobalSign Temporarily Stops Issuing Certificates to Investigate a Potential Breach |
2011-09-06/a> | Swa Frantzen | DigiNotar audit - intermediate report available |
2011-09-06/a> | Johannes Ullrich | Microsoft Releases Diginotar Related Patch and Advisory |
2011-09-01/a> | Swa Frantzen | DigiNotar breach - the story so far |
2011-08-31/a> | Johannes Ullrich | Firefox/Thunderbird 6.0.1 released to blocklist bad DigiNotar SSL certificates |
2011-08-11/a> | Guy Bruneau | BlackBerry Enterprise Server Critical Update |
2011-08-04/a> | Johannes Ullrich | IRC traffic on non standard ports |
2011-07-29/a> | Richard Porter | Apple Lion talking on TCP 5223 |
2011-07-02/a> | Pedro Bueno | Bootkits, they are back at full speed... |
2011-06-21/a> | Chris Mohan | StartSSL, a web authentication authority, suspend services after a security breach |
2011-06-08/a> | Johannes Ullrich | Spam from compromised Hotmail accounts |
2011-05-14/a> | Guy Bruneau | Websense Study Claims Canada Next Hotbed for Cybercrime Web Hosting Activity |
2011-04-28/a> | Chris Mohan | Gathering and use of location information fears - or is it all a bit too late |
2011-04-28/a> | Chris Mohan | DSL Reports advise 9,000 accounts were compromised |
2011-04-20/a> | Daniel Wesemann | Virustotal.com hiccup |
2011-04-03/a> | Richard Porter | Extreme Disclosure? Not yet but a great trend! |
2011-02-28/a> | Deborah Hale | Possible Botnet Scanning |
2011-02-14/a> | Richard Porter | Anonymous Damage Control Anybody? |
2011-01-12/a> | Richard Porter | How Many Loyalty Cards do you Carry? |
2011-01-12/a> | Richard Porter | Has Big Brother gone Global? |
2011-01-11/a> | Kevin Shortt | Spam Cannons on Holiday |
2011-01-10/a> | Manuel Humberto Santander Pelaez | VirusTotal VTzilla firefox/chrome plugin |
2010-12-19/a> | Raul Siles | Intel's new processors have a remote kill switch (Anti-Theft 3.0) |
2010-11-18/a> | Chris Carboni | Stopping the ZeroAccess Rootkit |
2010-11-18/a> | Chris Carboni | All of your pages are belonging to us |
2010-11-05/a> | Adrien de Beaupre | Bot honeypot |
2010-11-01/a> | Manuel Humberto Santander Pelaez | Checkpoint UTM-1 edge VPN boxes worldwide did an unscheduled reboot |
2010-10-19/a> | Rob VandenBrink | Cyber Security Awareness Month - Day 19 - Remote Access Tools |
2010-10-19/a> | Rob VandenBrink | Cyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split? |
2010-10-19/a> | Rob VandenBrink | Cyber Security Awareness Month - Day 19 - Remote User VPN Access – Are things getting too easy, or too hard? |
2010-10-19/a> | Rob VandenBrink | Cyber Security Awareness Month - Day 19 - VPN and Remote Access Tools |
2010-10-11/a> | Adrien de Beaupre | OT: Happy Thanksgiving Day Canada |
2010-10-04/a> | Mark Hofman | Online Voting |
2010-10-03/a> | Adrien de Beaupre | H went down. |
2010-08-19/a> | Daniel Wesemann | Casper the unfriendly ghost |
2010-07-29/a> | Rob VandenBrink | FBI, Slovenian and Spanish Police announce more arrests of Mariposa Botnet Creator, Operators |
2010-07-21/a> | Adrien de Beaupre | Adobe Reader Protected Mode |
2010-07-21/a> | Adrien de Beaupre | Dell PowerEdge R410 replacement motherboard firmware contains malware |
2010-06-15/a> | Manuel Humberto Santander Pelaez | Mastercard delivering cards with OTP device included |
2010-06-14/a> | Manuel Humberto Santander Pelaez | New way of social engineering on IRC |
2010-05-12/a> | Rob VandenBrink | Adobe Shockwave Update |
2010-05-07/a> | Johannes Ullrich | Stock market "wipe out" may be due to computer error |
2010-05-02/a> | Mari Nichols | Zbot Social Engineering |
2010-04-23/a> | Adrien de Beaupre | Shadowserver botnet rules |
2010-03-25/a> | Kevin Liston | Zeus wants to do your taxes |
2010-03-15/a> | Adrien de Beaupre | Spamassassin Milter Plugin Remote Root Attack |
2010-03-11/a> | donald smith | Cert write up on Skype IMBot Logic and Functionality. |
2010-03-10/a> | Rob VandenBrink | Microsoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7 |
2010-03-10/a> | Rob VandenBrink | Microsoft re-release of KB973811 - attacks on Extended Protection for Authentication |
2010-02-19/a> | Mark Hofman | MS10-015 may cause Windows XP to blue screen (but only if you have malware on it) |
2010-02-09/a> | Adrien de Beaupre | When is a 0day not a 0day? Samba symlink bad default config |
2010-02-02/a> | Johannes Ullrich | Pushdo Update |
2010-02-02/a> | Guy Bruneau | Cisco Secure Desktop Remote XSS Vulnerability |
2010-02-01/a> | Rob VandenBrink | NMAP 5.21 - Is UDP Protocol Specific Scanning Important? Why Should I Care? |
2010-01-25/a> | William Salusky | "Bots and Spiders and Crawlers, be gone!" - or - "New Open Source WebAppSec tools, Huzzah!" |
2009-12-21/a> | Marcus Sachs | iPhone Botnet Analysis |
2009-12-07/a> | Rob VandenBrink | Layer 2 Network Protections – reloaded! |
2009-11-14/a> | Adrien de Beaupre | Microsoft advisory for Windows 7 / Windows Server 2008 R2 Remote SMB DoS Exploit released |
2009-11-13/a> | Deborah Hale | Pushdo/Cutwail Spambot - A Little Known BIG Problem |
2009-11-13/a> | Adrien de Beaupre | TLS & SSLv3 renegotiation vulnerability explained |
2009-11-12/a> | Rob VandenBrink | Windows 7 / Windows Server 2008 Remote SMB Exploit |
2009-11-11/a> | Rob VandenBrink | Layer 2 Network Protections against Man in the Middle Attacks |
2009-11-08/a> | Kevin Liston | FireEye takes on Ozdok and Recovery Ideas |
2009-11-05/a> | Swa Frantzen | TLS Man-in-the-middle on renegotiation vulnerability made public |
2009-11-05/a> | Swa Frantzen | RIM fixes random code execution vulnerability |
2009-10-30/a> | Rob VandenBrink | New version of NIST 800-41, Firewalls and Firewall Policy Guidelines |
2009-10-26/a> | Johannes Ullrich | Web honeypot Update |
2009-10-10/a> | Tony Carothers | User Notification for Possible Infected Systems |
2009-10-06/a> | Adrien de Beaupre | Cyber Security Awareness Month - Day 6 ports 67&68 udp - bootp and dhcp |
2009-10-05/a> | Adrien de Beaupre | Time to change your hotmail/gmail/yahoo password |
2009-09-18/a> | Jason Lam | Results from Webhoneypot project |
2009-09-16/a> | Raul Siles | IETF Draft for Remediation of Bots in ISP Networks |
2009-09-07/a> | Jim Clausing | Request for packets |
2009-08-29/a> | Guy Bruneau | Immunet Protect - Cloud and Community Malware Protection |
2009-08-18/a> | Deborah Hale | Security Bulletin for ColdFusion and JRun |
2009-07-23/a> | John Bambenek | Missouri Passes Breach Notification Law: Gap Still Exists for Banking Account Information |
2009-06-27/a> | Tony Carothers | New NIAP Strategy on the Horizon |
2009-06-11/a> | Jason Lam | Dshield Web Honeypot going beta |
2009-05-07/a> | Deborah Hale | Botnet hijacking reveals 70GB of stolen data |
2009-04-24/a> | John Bambenek | Data Leak Prevention: Proactive Security Requirements of Breach Notification Laws |
2009-03-26/a> | Mark Hofman | Webhoneypot fun |
2009-02-17/a> | Jason Lam | DShield Web Honeypot - Alpha Preview Release |
2008-12-01/a> | Jason Lam | Call for volunteers - Web Honeypot Project |
2008-11-05/a> | donald smith | Bot net hunters get an improved tool from SRI bothunters |
2008-11-05/a> | donald smith | hacking the election |
2008-09-09/a> | Swa Frantzen | The complaint that's an attack |
2008-09-01/a> | John Bambenek | The Number of Machines Controlled by Botnets Has Jumped 4x in Last 3 Months |
2008-08-16/a> | Marcus Sachs | Another Infected Digital Photo Frame |
2008-07-22/a> | Mari Nichols | ‘Cold Boot’ Attack Utility Tools |
2008-07-19/a> | William Salusky | A twist in fluxnet operations. Enter Hydraflux |
2008-07-15/a> | Maarten Van Horenbeeck | Bot controller mimicry |
2008-05-25/a> | Stephen Hall | Cisco's Response to Rootkit presentation |
2008-05-23/a> | Mike Poor | Cisco IOS Rootkit thoughts |
2008-05-06/a> | Marcus Sachs | Industrial Control Systems Vulnerability |
2008-04-08/a> | Swa Frantzen | Notes file viewer vulnerabilities |
2008-04-07/a> | John Bambenek | Got Kraken? |
2008-04-07/a> | John Bambenek | Kraken Technical Details: UPDATED x3 |
2008-03-13/a> | Jason Lam | Remote File Include spoof!? |
2006-11-20/a> | Joel Esler | MS06-070 Remote Exploit |
2006-08-31/a> | Swa Frantzen | NT botnet submitted |
2006-08-31/a> | Joel Esler | MS06-040 Worm |
HAPPY |
2013-03-25/a> | Johannes Ullrich | IPv6 Focus Month: IPv6 over IPv4 Preference |
2010-10-11/a> | Adrien de Beaupre | OT: Happy Thanksgiving Day Canada |
THANKSGIVING |
2010-10-11/a> | Adrien de Beaupre | OT: Happy Thanksgiving Day Canada |
DAY |
2025-03-11/a> | Johannes Ullrich | Microsoft Patch Tuesday: March 2025 |
2025-03-11/a> | Johannes Ullrich | Apple Fixes Exploited WebKit Vulnerability in iOS, MacOS, visionOS and Safari |
2024-12-10/a> | Johannes Ullrich | Microsoft Patch Tuesday: December 2024 |
2024-07-09/a> | Johannes Ullrich | Microsoft Patch Tuesday July 2024 |
2024-06-11/a> | Johannes Ullrich | Microsoft Patch Tuesday June 2024 |
2024-03-12/a> | Johannes Ullrich | Microsoft Patch Tuesday - March 2024 |
2024-03-05/a> | Johannes Ullrich | Apple Releases iOS/iPadOS Updates with Zero Day Fixes. |
2024-01-22/a> | Johannes Ullrich | Apple Updates Everything - New 0 Day in WebKit |
2023-12-12/a> | Johannes Ullrich | Microsoft Patch Tuesday December 2023 |
2023-10-10/a> | Johannes Ullrich | October 2023 Microsoft Patch Tuesday Summary |
2023-09-07/a> | Johannes Ullrich | Apple Releases iOS/iPadOS 16.6.1, macOS 13.5.2, watchOS 9.6.2 fixing two zeroday vulnerabilities |
2023-06-22/a> | Johannes Ullrich | Apple Patches Exploited Vulnerabilities in iOS/iPadOS, macOS, watchOS and Safari |
2023-05-16/a> | Jesse La Grew | Signals Defense With Faraday Bags & Flipper Zero |
2023-04-07/a> | Johannes Ullrich | Apple Patching Two 0-Day Vulnerabilities in iOS and macOS |
2023-02-14/a> | Johannes Ullrich | Microsoft February 2023 Patch Tuesday |
2022-11-29/a> | Johannes Ullrich | Packet Tuesday Episode 3: TCP Urgent Flag. https://packettuesday.com |
2022-08-17/a> | Johannes Ullrich | Apple Patches Two Exploited Vulnerabilities |
2022-05-10/a> | Renato Marinho | Microsoft May 2022 Patch Tuesday |
2022-05-03/a> | Rob VandenBrink | Finding the Real "Last Patched" Day (Interim Version) |
2022-02-10/a> | Johannes Ullrich | iOS/iPadOS and MacOS Update: Single WebKit 0-Day Vulnerability Patched |
2022-01-11/a> | Johannes Ullrich | Microsoft Patch Tuesday - January 2022 |
2021-11-27/a> | Didier Stevens | Video: SANS Holiday Hack Challenge 2021 Q&A with Ed Skoudis |
2021-09-14/a> | Renato Marinho | Microsoft September 2021 Patch Tuesday |
2021-04-13/a> | Richard Porter | Microsoft April 2021 Patch Tuesday |
2021-03-03/a> | Johannes Ullrich | Microsoft Releases Exchange Emergency Patch to Fix Actively Exploited Vulnerability |
2020-12-08/a> | Johannes Ullrich | December 2020 Microsoft Patch Tuesday: Exchange, Sharepoint, Dynamics and DNS Spoofing |
2020-06-18/a> | Jan Kopriva | Broken phishing accidentally exploiting Outlook zero-day |
2020-05-14/a> | Rob VandenBrink | Patch Tuesday Revisited - CVE-2020-1048 isn't as "Medium" as MS Would Have You Believe |
2020-05-01/a> | Jim Clausing | Attack traffic on TCP port 9673 |
2020-03-23/a> | Didier Stevens | Windows Zeroday Actively Exploited: Type 1 Font Parsing Remote Code Execution Vulnerability |
2020-03-10/a> | Johannes Ullrich | Microsoft Patch Tuesday March 2020 |
2019-07-09/a> | John Bambenek | MSFT July 2019 Patch Tuesday |
2019-04-25/a> | Rob VandenBrink | Unpatched Vulnerability Alert - WebLogic Zero Day |
2018-12-11/a> | Richard Porter | Microsoft December 2018 Patch Tuesday |
2018-10-09/a> | Johannes Ullrich | October 2018 Microsoft Patch Tuesday |
2018-09-11/a> | Johannes Ullrich | Microsoft September Patch Tuesday Summary |
2018-06-12/a> | Johannes Ullrich | Microsoft June 2018 Patch Tuesday |
2018-02-01/a> | Johannes Ullrich | Adobe Flash 0-Day Used Against South Korean Targets |
2017-07-11/a> | Renato Marinho | July's Microsoft Patch Tuesday |
2017-05-02/a> | Richard Porter | Do you have Intel AMT? Then you have a problem today! Intel Active Management Technology INTEL-SA-00075 |
2017-03-14/a> | Johannes Ullrich | February and March Microsoft Patch Tuesday |
2017-02-14/a> | Johannes Ullrich | Microsoft Patch Tuesday Delayed |
2017-02-04/a> | Xavier Mertens | Detecting Undisclosed Vulnerabilities with Security Tools & Features |
2017-01-10/a> | Johannes Ullrich | January 2017 Microsoft Patch Tuesday |
2016-09-13/a> | Rob VandenBrink | Microsoft Patch Tuesday Analysis |
2016-08-25/a> | Xavier Mertens | Out-of-Band iOS Patch Fixes 0-Day Vulnerabilities |
2016-07-12/a> | Johannes Ullrich | Microsoft Patch Tuesday Summary for July 2016 |
2016-05-12/a> | Xavier Mertens | Adobe Released Updates to Fix Critical Vulnerability |
2016-04-06/a> | Bojan Zdrnja | YAFP (Yet Another Flash Patch) |
2016-02-09/a> | Johannes Ullrich | Microsoft February 2016 Patch Tuesday |
2016-02-09/a> | Johannes Ullrich | Adobe Patch Tuesday - February 2016 |
2016-01-12/a> | Alex Stanford | January 2016 Microsoft Patch Tuesday |
2015-12-08/a> | Johannes Ullrich | December 2015 Microsoft Patch Tuesday |
2015-11-10/a> | Johannes Ullrich | November 2015 Microsoft Patch Tuesday |
2015-10-13/a> | Alex Stanford | October 2015 Microsoft Patch Tuesday |
2015-09-08/a> | Johannes Ullrich | September 2015 Microsoft Patch Tuesday |
2015-08-11/a> | Manuel Humberto Santander Pelaez | August 2015 Microsoft Patch Tuesday |
2015-07-27/a> | Daniel Wesemann | Angler's best friends |
2015-07-14/a> | Johannes Ullrich | July 2015 Microsoft Patch Tuesday |
2015-07-12/a> | Rick Wanner | Another Adobe Flash Zero Day http://www.kb.cert.org/vuls/id/338736 |
2015-06-09/a> | Johannes Ullrich | Microsoft Patch Tuesday Summary for June 2015 |
2015-05-12/a> | Johannes Ullrich | May 2015 Microsoft Patch Tuesday Summary |
2015-04-14/a> | Alex Stanford | Microsoft Patch Tuesday - April 2015 |
2015-03-10/a> | Johannes Ullrich | Microsoft March Patch Tuesday |
2015-02-10/a> | Mark Baggett | Microsoft Update Advisory for February 2015 |
2015-02-05/a> | Johannes Ullrich | Adobe Flash Player Update Released, Fixing CVE 2015-0313 |
2015-01-23/a> | Adrien de Beaupre | Infocon change to yellow for Adobe Flash issues |
2015-01-13/a> | Johannes Ullrich | Microsoft Patch Tuesday - January 2015 (Really? Telnet?) |
2014-12-09/a> | Alex Stanford | Microsoft Patch Tuesday - December 2014 |
2014-11-18/a> | Jim Clausing | Microsoft November out-of-cycle patch MS14-068 |
2014-11-11/a> | Johannes Ullrich | Microsoft November 2014 Patch Tuesday |
2014-10-14/a> | Johannes Ullrich | Microsoft October 2014 Patch Tuesday |
2014-09-09/a> | Alex Stanford | Microsoft Patch Tuesday - September 2014 |
2014-08-12/a> | Alex Stanford | Microsoft Patch Tuesday - August 2014 |
2014-07-30/a> | Rick Wanner | Symantec Endpoint Protection Privilege Escalation Zero Day |
2014-07-28/a> | Johannes Ullrich | Interesting HTTP User Agent "chroot-apach0day" |
2014-07-08/a> | Alex Stanford | Microsoft Patch Tuesday - July |
2014-06-10/a> | Alex Stanford | Microsoft Patch Tuesday June 2014 |
2014-06-06/a> | Johannes Ullrich | Microsoft June Patch Tuesday Advance Notification |
2014-05-21/a> | John Bambenek | New, Unpatched IE 0 Day published at ZDI |
2014-05-13/a> | Johannes Ullrich | Microsoft May 2014 Patch Tuesday |
2014-05-01/a> | Johannes Ullrich | Microsoft Announces Special Patch for IE 0-day (Win XP included!) |
2014-04-08/a> | Richard Porter | April 2014 Microsoft Patches |
2014-03-24/a> | Johannes Ullrich | New Microsoft Advisory: Unpatched Word Flaw used in Targeted Attacks |
2014-03-11/a> | Johannes Ullrich | Microsoft Patch Tuesday March 2014 |
2014-03-08/a> | Guy Bruneau | Microsoft March Patch Pre-Announcement |
2014-02-20/a> | Stephen Hall | Abobe out of band patch announcement (APSB14-07) |
2014-02-14/a> | Chris Mohan | FireEye reports IE 10 zero-day being used in watering hole attack |
2014-02-11/a> | Johannes Ullrich | February 2014 Microsoft Patch Tuesday |
2014-02-07/a> | Johannes Ullrich | Microsoft Advance Notification for February 2014 |
2014-01-14/a> | Johannes Ullrich | Microsoft Patch Tuesday January 2014 |
2013-12-10/a> | Johannes Ullrich | Microsoft December Patch Tuesday |
2013-12-07/a> | Guy Bruneau | Microsoft December Patch Pre-Announcement |
2013-11-28/a> | Rob VandenBrink | Microsoft Security Advisory (2914486): Vulnerability in Microsoft Windows Kernel 0 day exploit in wild |
2013-11-12/a> | Johannes Ullrich | November 2013 Microsoft Patch Tuesday |
2013-11-09/a> | Guy Bruneau | IE Zero-Day Vulnerability Exploiting msvcrt.dll |
2013-10-08/a> | Johannes Ullrich | Microsoft October 2013 Patch Tuesday |
2013-09-10/a> | Swa Frantzen | Adobe September 2013 Black Tuesday Overview |
2013-09-10/a> | Swa Frantzen | Microsoft September 2013 Black Tuesday Overview |
2013-08-28/a> | Bojan Zdrnja | MS13-056 (false positive)? alerts |
2013-08-13/a> | Swa Frantzen | Microsoft security advisories: RDP and MD5 deprecation in Microsoft root certificates |
2013-08-13/a> | Swa Frantzen | Microsoft August 2013 Black Tuesday Overview |
2013-07-09/a> | Swa Frantzen | Microsoft July 2013 Black Tuesday Overview |
2013-07-09/a> | Swa Frantzen | Adobe July 2013 Black Tuesday Overview |
2013-07-06/a> | Guy Bruneau | Microsoft July Patch Pre-Announcement |
2013-06-11/a> | Swa Frantzen | Microsoft June 2013 Black Tuesday Overview |
2013-06-11/a> | Swa Frantzen | Adobe June 2013 Black Tuesday Overview |
2013-06-11/a> | Swa Frantzen | Other Microsoft Black Tuesday News |
2013-06-11/a> | Swa Frantzen | vmware security advisory VMSA-2013-0008 |
2013-05-14/a> | Swa Frantzen | Microsoft May 2013 Black Tuesday Overview |
2013-05-14/a> | Swa Frantzen | Firefox & Thunderbird released |
2013-05-14/a> | Swa Frantzen | Adobe May 2013 Black Tuesday Overview |
2013-05-14/a> | Swa Frantzen | Microsoft Security Advisory 2846338 |
2013-05-09/a> | John Bambenek | Adobe Releases 0-day Security Advisory for Coldfusion, Exploit Code Available. Advisory here: http://www.adobe.com/support/security/advisories/apsa13-03.html |
2013-05-04/a> | Kevin Shortt | The Zero-Day Pendulum Swings |
2013-04-09/a> | Swa Frantzen | Microsoft April 2013 Black Tuesday Overview |
2013-04-09/a> | Swa Frantzen | Adobe April 2013 Black Tuesday Overview |
2013-04-04/a> | Johannes Ullrich | Microsoft April Patch Tuesday Advance Notification |
2013-03-12/a> | Swa Frantzen | Microsoft March 2013 Black Tuesday Overview |
2013-03-12/a> | Swa Frantzen | Adobe March 2013 Black Tueday |
2013-02-14/a> | Adam Swanger | ISC Monthly Threat Update - February 2013 http://isc.sans.edu/podcastdetail.html?id=3121 |
2013-02-12/a> | Adam Swanger | Microsoft February 2013 Black Tuesday Update - Overview |
2013-02-12/a> | Swa Frantzen | Adobe Feb 2013 Black Tuesday patches |
2013-02-08/a> | Johannes Ullrich | Microsoft February Patch Tuesday Advance Notification |
2013-02-07/a> | John Bambenek | Adobe Releases Patches for 0-day Vulnerability in Flash Player for Windows and Mac, Upgrade now: http://www.adobe.com/support/security/bulletins/apsb13-04.html |
2013-01-22/a> | Richard Porter | Using Metasploit for Patch Sanity Checks |
2013-01-14/a> | Richard Porter | Microsoft Out of Cycle Patch: IE http://technet.microsoft.com/en-us/security/bulletin/ms13-jan |
2013-01-14/a> | Richard Porter | January 2013 Microsoft Out of Cycle Patch |
2013-01-13/a> | Stephen Hall | Java 0-Day patched as Java 7 U 11 released |
2013-01-12/a> | Stephen Hall | Java 0-day impact to Java 6 (and beyond?) |
2013-01-10/a> | Adam Swanger | ISC Monthly Threat Update New Format |
2013-01-08/a> | Richard Porter | Microsoft January 2013 Black Tuesday Update - Overview |
2013-01-04/a> | Daniel Wesemann | Patch pre-notification from Adobe and Microsoft |
2013-01-02/a> | Russ McRee | EMET 3.5: The Value of Looking Through an Attacker's Eyes |
2012-12-11/a> | John Bambenek | Microsoft December 2012 Black Tuesday Update - Overview |
2012-11-26/a> | John Bambenek | Online Shopping for the Holidays? Tips, News and a Fair Warning |
2012-11-13/a> | Jim Clausing | Microsoft November 2012 Black Tuesday Update - Overview |
2012-10-09/a> | Johannes Ullrich | Microsoft October 2012 Black Tuesday Update - Overview |
2012-10-04/a> | Johannes Ullrich | Microsoft October Patch Pre-Announcement |
2012-09-17/a> | Rob VandenBrink | IE Zero Day is "For Real" |
2012-09-11/a> | Adam Swanger | Microsoft September 2012 Black Tuesday Update - Overview |
2012-09-01/a> | Russ McRee | Blackhole targeting Java vulnerability via fake Microsoft Services Agreement email phish |
2012-08-14/a> | Rick Wanner | Microsoft August 2012 Black Tuesday Update - Overview |
2012-08-04/a> | Kevin Liston | Vendors: More Patch-Release Options Please |
2012-07-10/a> | Swa Frantzen | Microsoft July 2012 Black Tuesday Update - Overview |
2012-07-10/a> | Swa Frantzen | Microsoft revoking trust in Microsoft certificates - SA 2728973 |
2012-07-10/a> | Swa Frantzen | Microsoft fix-it to disable gadgets - SA 2719662 |
2012-07-05/a> | Adrien de Beaupre | Microsoft advanced notification for July 2012 patch Tuesday |
2012-06-12/a> | Swa Frantzen | Java 7u5 and 6u33 released |
2012-06-12/a> | Swa Frantzen | Adobe June 2012 Black Tuesday patches |
2012-06-12/a> | Swa Frantzen | Microsoft June 2012 Black Tuesday Update - Overview |
2012-06-01/a> | Johannes Ullrich | What Does "IPv6 Day" mean to you? |
2012-05-23/a> | Mark Baggett | Problems with MS12-035 affecting XP, SBS and Windows 2003? |
2012-05-08/a> | Adam Swanger | Microsoft May 2012 Black Tuesday Update - Overview |
2012-04-15/a> | Rick Wanner | .Net update affects printing from some applications |
2012-04-10/a> | Swa Frantzen | Microsoft April 2012 Black Tuesday Update - Overview |
2012-04-10/a> | Swa Frantzen | Adobe April 2012 Black Tuesday Update |
2012-04-06/a> | Johannes Ullrich | Microsoft April Patch Tuesday Pre-Announcement (6 Patches): http://technet.microsoft.com/en-us/security/bulletin/ms12-apr |
2012-03-13/a> | Lenny Zeltser | March 2012 Microsoft Black Tuesday |
2012-02-14/a> | Johannes Ullrich | February 2012 Microsoft Black Tuesday |
2012-01-10/a> | Adrien de Beaupre | January 2012 Microsoft Black Tuesday Summary |
2012-01-10/a> | Adrien de Beaupre | Adobe January 2012 Black Tuesday overview |
2012-01-06/a> | Guy Bruneau | January 2012 Patch Tuesday Pre-release |
2011-12-29/a> | Richard Porter | ASP.Net Vulnerability |
2011-12-25/a> | Deborah Hale | Merry Christmas, Happy Holidays |
2011-12-21/a> | Chris Mohan | The off switch |
2011-12-13/a> | Johannes Ullrich | December 2011 Microsoft Black Tuesday Summary |
2011-12-08/a> | Adrien de Beaupre | Newest Adobe Flash 11.1.102.55 and Previous 0 Day Exploit |
2011-12-08/a> | Adrien de Beaupre | Microsoft Security Bulletin Advance Notification for December 2011 |
2011-11-16/a> | Jason Lam | Potential 0-day on Bind 9 |
2011-11-08/a> | Swa Frantzen | Microsoft November 2011 Black Tuesday Overview |
2011-11-08/a> | Swa Frantzen | Abobe November 2011 Black Tuesday Overview |
2011-11-08/a> | Swa Frantzen | Apple Black Tuesday |
2011-11-03/a> | Guy Bruneau | November 2011 Patch Tuesday Pre-release |
2011-10-11/a> | Swa Frantzen | Microsoft Black Tuesday Overview October 2011 |
2011-09-13/a> | Swa Frantzen | Microsoft September 2011 Black Tuesday |
2011-09-13/a> | Swa Frantzen | Adobe September 2011 Black Tuesday overview |
2011-09-09/a> | Johannes Ullrich | Early Patch Tuesday Today: Microsoft September 2011 Patches |
2011-09-08/a> | Mark Hofman | Microsoft has released their advanced notification for patch Tuesday. 15 Vulnerabilities to be addressed. more here --> http://blogs.technet.com/b/msrc/archive/2011/09/08/advanced-notification-for-the-september-2011-bulletin-release.aspx |
2011-08-09/a> | Swa Frantzen | Microsoft August 2011 Black Tuesday Overview |
2011-08-09/a> | Swa Frantzen | Adobe August 2011 Black Tuesday Overview |
2011-07-12/a> | Swa Frantzen | Microsoft July 2011 Black Tuesday Overview |
2011-07-10/a> | Raul Siles | Jailbreakme Takes Advantage of 0-day PDF Vuln in Apple iOS Devices |
2011-06-14/a> | Swa Frantzen | Adobe releases patches |
2011-06-14/a> | Swa Frantzen | Microsoft June 2011 Black Tuesday Overview |
2011-05-10/a> | Swa Frantzen | May 2011 Microsoft Black Tuesday Overview |
2011-05-06/a> | Richard Porter | Unpatched Exploit: Skype for MAC |
2011-04-11/a> | Jim Clausing | April 2011 Microsoft Black Tuesday Summary |
2011-04-08/a> | Johannes Ullrich | Dark Black Tuesday Coming Up: 17 Microsoft Bulletins |
2011-03-08/a> | Jim Clausing | March 2011 Microsoft Black Tuesday Summary |
2011-02-08/a> | Joel Esler | Feburary 2011 Microsoft Black Tuesday Summary |
2011-01-11/a> | Kevin Shortt | January 2011 Microsoft Black Tuesday Summary |
2011-01-11/a> | Kevin Shortt | Spam Cannons on Holiday |
2011-01-08/a> | Guy Bruneau | January 2011 Patch Tuesday Pre-release |
2010-12-23/a> | Mark Hofman | IE 0 Day, just in time for Christmas |
2010-12-22/a> | John Bambenek | IIS 7.5 0-Day DoS (processing FTP requests) |
2010-12-20/a> | Guy Bruneau | Patch Issues with Outlook 2007 |
2010-12-14/a> | Manuel Humberto Santander Pelaez | December 2010 Microsoft Black Tuesday Summary |
2010-11-24/a> | Bojan Zdrnja | Privilege escalation 0-day in almost all Windows versions |
2010-11-09/a> | Johannes Ullrich | November 2010 Microsoft Black Tuesday Summary |
2010-11-01/a> | Manuel Humberto Santander Pelaez | CVE-2010-3654 exploit in the wild |
2010-10-28/a> | Manuel Humberto Santander Pelaez | CVE-2010-3654 - New dangerous 0-day authplay library adobe products vulnerability |
2010-10-26/a> | Pedro Bueno | Firefox news |
2010-10-19/a> | Rob VandenBrink | Cyber Security Awareness Month - Day 19 - Remote Access Tools |
2010-10-19/a> | Rob VandenBrink | Cyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split? |
2010-10-19/a> | Rob VandenBrink | Cyber Security Awareness Month - Day 19 - VPN Architectures – SSL or IPSec? |
2010-10-19/a> | Rob VandenBrink | Cyber Security Awareness Month - Day 19 - Remote User VPN Access – Are things getting too easy, or too hard? |
2010-10-19/a> | Rob VandenBrink | Cyber Security Awareness Month - Day 19 - VPN and Remote Access Tools |
2010-10-12/a> | Adrien de Beaupre | October 2010 Microsoft Black Tuesday Summary |
2010-10-11/a> | Adrien de Beaupre | OT: Happy Thanksgiving Day Canada |
2010-10-08/a> | Rick Wanner | Patch Tuesday Pre-release -- 16 updates |
2010-09-14/a> | Adrien de Beaupre | September 2010 Microsoft Black Tuesday Summary |
2010-08-10/a> | Jim Clausing | August 2010 Micrsoft Black Tuesday Summary |
2010-08-07/a> | Stephen Hall | Countdown to Tuesday... |
2010-07-13/a> | Jim Clausing | July 2010 Microsoft Black Tuesday Summary |
2010-06-08/a> | Manuel Humberto Santander Pelaez | June 2010 Microsoft Black Tuesday Summary |
2010-06-03/a> | Guy Bruneau | Microsoft Patch Tuesday June 2010 Pre-Release |
2010-05-11/a> | Scott Fendley | May 2010 Microsoft Patches |
2010-05-08/a> | Guy Bruneau | Microsoft Patch Tuesday May 2010 Pre-Release |
2010-04-13/a> | Johannes Ullrich | Microsoft April 2010 Patch Tuesday |
2010-04-08/a> | Guy Bruneau | Microsoft Patch Tuesday April 2010 Pre-Release |
2010-03-09/a> | John Bambenek | March 2010 - Microsoft Patch Tuesday Diary |
2010-03-01/a> | Mark Hofman | IE 0-day using .hlp files |
2010-02-09/a> | Adrien de Beaupre | When is a 0day not a 0day? Samba symlink bad default config |
2010-02-09/a> | Johannes Ullrich | February 2010 Black Tuesday Overview |
2010-02-04/a> | Johannes Ullrich | Microsoft Patch Tuesday Pre-Release |
2010-01-21/a> | Johannes Ullrich | Microsoft January Out of Band Patch |
2010-01-14/a> | Bojan Zdrnja | 0-day vulnerability in Internet Explorer 6, 7 and 8 |
2010-01-12/a> | Johannes Ullrich | Pre-Announced Adobe Reader and Acrobat Patch Found! |
2010-01-12/a> | Johannes Ullrich | Microsoft Security Bulletin: January 2010 |
2010-01-07/a> | Daniel Wesemann | Static analysis of malicious PDFs |
2010-01-07/a> | Daniel Wesemann | Static analysis of malicous PDFs (Part #2) |
2009-12-27/a> | Patrick Nolan | Pressure increasing for Microsoft to patch IIS 0 day |
2009-12-15/a> | Johannes Ullrich | Adobe 0-day in the wild - again |
2009-12-08/a> | Deborah Hale | December 2009 Black Tuesday Overview |
2009-11-22/a> | Marcus Sachs | IE6 and IE7 0-Day Reported |
2009-11-10/a> | Swa Frantzen | Microsoft November Black Tuesday Overview |
2009-10-13/a> | Johannes Ullrich | Microsoft October 2009 Black Tuesday Overview |
2009-09-08/a> | Adrien de Beaupre | Microsoft Security Advisory 975191 Revised |
2009-09-08/a> | Guy Bruneau | Microsoft September 2009 Black Tuesday Overview |
2009-09-04/a> | Adrien de Beaupre | Vulnerabilities (plural) in MS IIS FTP Service 5.0, 5.1. 6.0, 7.0 |
2009-08-31/a> | Pedro Bueno | Microsoft IIS 5/6 FTP 0Day released |
2009-08-11/a> | Swa Frantzen | Microsoft August 2009 Black Tuesday Overview |
2009-07-22/a> | Bojan Zdrnja | YA0D (Yet Another 0-Day) in Adobe Flash player |
2009-07-17/a> | Bojan Zdrnja | A new fascinating Linux kernel vulnerability |
2009-07-14/a> | Swa Frantzen | Microsoft July Black Tuesday Overview |
2009-07-14/a> | Swa Frantzen | Oracle Black Tuesday |
2009-07-06/a> | Stephen Hall | 0-day in Microsoft DirectShow (msvidctl.dll) used in drive-by attacks |
2009-07-03/a> | Adrien de Beaupre | Happy 4th of July! |
2009-06-09/a> | Swa Frantzen | Microsoft June Black Tuesday Overview |
2009-06-09/a> | Swa Frantzen | Adobe June Black Tuesday upgrades |
2009-05-12/a> | Swa Frantzen | MSFT's version of responsible disclosure |
2009-05-12/a> | Swa Frantzen | May Black Tuesday Overview |
2009-04-29/a> | Jason Lam | Two Adobe 0-day vulnerabilities |
2009-04-14/a> | Swa Frantzen | April Black Tuesday Overview |
2009-03-18/a> | Adrien de Beaupre | Adobe Security Bulletin Adobe Reader and Acrobat |
2009-03-10/a> | Swa Frantzen | March black Tuesday overview |
2009-02-25/a> | Andre Ludwig | Adobe Acrobat pdf 0-day exploit, No JavaScript needed! |
2009-02-10/a> | Swa Frantzen | February Black Tuesday Overview |
2009-01-13/a> | Johannes Ullrich | January Black Tuesday Overview |
2008-12-12/a> | Kevin Liston | IE7 0day expanded to include IE6 and IE8(beta) |
2008-12-12/a> | Johannes Ullrich | MSIE 0-day Spreading Via SQL Injection |
2008-12-10/a> | Bojan Zdrnja | 0-day exploit for Internet Explorer in the wild |
2008-12-09/a> | Swa Frantzen | December Black Tuesday Overview |
2008-11-11/a> | Swa Frantzen | November Black Tuesday Overview |
2008-11-02/a> | Adrien de Beaupre | Daylight saving time |
2008-10-14/a> | Swa Frantzen | October Black Tuesday Overview |
2008-09-09/a> | Swa Frantzen | September 2008 Black Tuesday Overview |
2008-08-12/a> | Stephen Hall | August 2008 Black Tuesday Overview |
2008-07-08/a> | Swa Frantzen | July 2008 black tuesday overview |
2008-06-10/a> | Swa Frantzen | June 2008 Black Tuesday Overview |
2008-05-13/a> | Swa Frantzen | May 2008 black tuesday overview |
2008-04-08/a> | Swa Frantzen | April 2008 - Black Tuesday Overview |
2008-03-11/a> | Swa Frantzen | March Black Tuesday Overview |
2008-02-12/a> | Swa Frantzen | February Black Tuesday Overview |
2008-01-08/a> | Swa Frantzen | January Black Tuesday overview |
2007-12-11/a> | Swa Frantzen | December black tuesday overview |
2007-11-13/a> | Swa Frantzen | november black tuesday overview |
2007-10-09/a> | Swa Frantzen | October Black Tuesday overview |
2007-09-11/a> | Swa Frantzen | September microsoft patch overview |
2007-08-14/a> | Swa Frantzen | August 'Black Tuesday' overview |
2007-07-10/a> | Swa Frantzen | July 'Black Tuesday' overview |
2007-06-12/a> | Johannes Ullrich | June 2007, Microsoft Patch Tuesday Overview. |
2007-05-08/a> | Swa Frantzen | May 2007, Black Tuesday patch overview |
2007-04-10/a> | Swa Frantzen | Microsoft black Tuesday patches - April 2007 |
2007-04-03/a> | Swa Frantzen | * Microsoft out of cycle patch |
2007-02-13/a> | Swa Frantzen | Microsoft Black Tuesday patches - February 2007 |
2007-01-09/a> | Swa Frantzen | Microsoft Patches - January 2007 - overview |
2006-12-12/a> | Swa Frantzen | Microsoft Black Tuesday - December 2006 overview |
2006-12-12/a> | Robert Danford | MS06-078: 2 Windows Media Format Vulnerabilities (CVE-2006-4702, CVE-2006-6134) |
2006-11-29/a> | Toby Kohlenberg | Week of Oracle bugs cancelled |
2006-11-14/a> | Swa Frantzen | Microsoft Black Tuesday Overview |
2006-10-09/a> | Swa Frantzen | Microsoft black tuesday - October 2006 STATUS |
2006-09-28/a> | Swa Frantzen | Powerpoint, yet another new vulnerability |
2006-09-28/a> | Swa Frantzen | MSIE: One patched, one pops up again (setslice) |
2006-09-22/a> | Swa Frantzen | Yellow: MSIE VML exploit spreading |
2006-09-19/a> | Swa Frantzen | Yet another MSIE 0-day: VML |
2006-09-15/a> | Swa Frantzen | MSIE DirectAnimation ActiveX 0-day update |
2006-09-12/a> | Swa Frantzen | Microsoft security patches for September 2006 |
CANADA |
2014-06-17/a> | Rob VandenBrink | Canada's Anti-Spam Legislation (CASL) 2014 |
2010-10-11/a> | Adrien de Beaupre | OT: Happy Thanksgiving Day Canada |
2010-10-03/a> | Adrien de Beaupre | Canada's Cyber Security Strategy released today |