2025-01-13 | Johannes Ullrich | Hikvision Password Reset Brute Forcing |
2024-11-06 | Jesse La Grew | [Guest Diary] Insights from August Web Traffic Surge |
2024-10-31 | Guy Bruneau | October 2024 Activity with Username chenzilong |
2024-10-16 | Johannes Ullrich | The Top 10 Not So Common SSH Usernames and Passwords |
2024-08-22 | Johannes Ullrich | OpenAI Scans for Honeypots. Artificially Malicious? Action Abuse? |
2024-08-07 | Guy Bruneau | Same Scripts, Different Day: What My DShield Honeypot Taught Me About the Importance of Security Fundamentals [Guest Diary] |
2024-07-13 | Didier Stevens | 16-bit Hash Collisions in .xls Spreadsheets |
2024-06-26 | Guy Bruneau | What Setting Live Traps for Cybercriminals Taught Me About Security [Guest Diary] |
2024-02-28 | Johannes Ullrich | Exploit Attempts for Unknown Password Reset Vulnerability |
2024-01-17 | Jesse La Grew | Number Usage in Passwords |
2024-01-06 | Xavier Mertens | Are you sure of your password? |
2023-10-29 | Guy Bruneau | Spam or Phishing? Looking for Credentials & Passwords |
2023-10-15 | Guy Bruneau | Domain Name Used as Password Captured by DShield Sensor |
2023-09-29 | Xavier Mertens | Are You Still Storing Passwords In Plain Text Files? |
2023-09-05 | Jesse La Grew | Common usernames submitted to honeypots |
2023-09-02 | Jesse La Grew | What is the origin of passwords submitted to honeypots? |
2023-08-10 | Bojan Zdrnja | Some things never change ? such as SQL Authentication ?encryption? |
2023-08-04 | Xavier Mertens | Are Leaked Credentials Dumps Used by Attackers? |
2023-06-23 | Xavier Mertens | Word Document with an Online Attached Template |
2023-06-05 | Johannes Ullrich | Brute Forcing Simple Archive Passwords |
2023-05-04 | Xavier Mertens | Infostealer Embedded in a Word Document |
2023-04-19 | Rob VandenBrink | Taking a Bite Out of Password Expiry Helpdesk Calls |
2023-02-18 | Guy Bruneau | Spear Phishing Handlers for Username/Password |
2022-09-16 | Didier Stevens | Word Maldoc With CustomXML and Renamed VBAProject.bin |
2022-09-15 | Xavier Mertens | Malicious Word Document with a Frameset |
2022-09-10 | Guy Bruneau | Phishing Word Documents with Suspicious URL |
2022-08-13 | Guy Bruneau | Phishing HTML Attachment as Voicemail Audio Transcription |
2022-06-12 | Didier Stevens | Quickie: Follina, RTF & Explorer Preview Pane |
2022-06-06 | Didier Stevens | "ms-msdt" RTF Maldoc Analysis: oledump Plugins |
2022-06-05 | Didier Stevens | Analysis Of An "ms-msdt" RTF Maldoc |
2022-05-30 | Xavier Mertens | New Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme (CVE-2022-30190) |
2022-05-17 | Xavier Mertens | Use Your Browser Internal Password Vault... or Not? |
2022-05-09 | Xavier Mertens | Octopus Backdoor is Back with a New Embedded Obfuscated Bat File |
2022-04-24 | Didier Stevens | Analyzing a Phishing Word Document |
2022-04-04 | Johannes Ullrich | Emptying the Phishtank: Are WordPress sites the Mosquitoes of the Internet? |
2022-03-10 | Xavier Mertens | Credentials Leaks on VirusTotal |
2022-02-22 | Xavier Mertens | A Good Old Equation Editor Vulnerability Delivering Malware |
2022-02-13 | Guy Bruneau | DHL Spear Phishing to Capture Username/Password |
2022-02-02 | Johannes Ullrich | Finding elFinder: Who is looking for your files? |
2021-12-02 | Brad Duncan | TA551 (Shathak) pushes IcedID (Bokbot) |
2021-11-30 | Johannes Ullrich | Hunting for PHPUnit Installed via Composer |
2021-11-15 | Rob VandenBrink | Changing your AD Password Using the Clipboard - Not as Easy as You'd Think! |
2021-08-06 | Xavier Mertens | Malicious Microsoft Word Remains A Key Infection Vector |
2021-05-14 | Xavier Mertens | "Open" Access to Industrial Systems Interface is Also Far From Zero |
2021-04-24 | Guy Bruneau | Base64 Hashes Used in Web Scanning |
2021-02-19 | Xavier Mertens | Dynamic Data Exchange (DDE) is Back in the Wild? |
2021-02-02 | Xavier Mertens | New Example of XSL Script Processing aka "Mitre T1220" |
2021-01-28 | Daniel Wesemann | Emotet vs. Windows Attack Surface Reduction |
2021-01-26 | Brad Duncan | TA551 (Shathak) Word docs push Qakbot (Qbot) |
2021-01-24 | Didier Stevens | Video: Doc & RTF Malicious Document |
2021-01-23 | Didier Stevens | CyberChef: Analyzing OOXML Files for URLs |
2021-01-13 | Brad Duncan | Hancitor activity resumes after a hoilday break |
2021-01-10 | Didier Stevens | Maldoc Analysis With CyberChef |
2021-01-09 | Didier Stevens | Maldoc Strings Analysis |
2021-01-06 | Johannes Ullrich | Scans for Zyxel Backdoors are Commencing. |
2020-12-24 | Xavier Mertens | Malicious Word Document Delivering an Octopus Backdoor |
2020-10-14 | Brad Duncan | More TA551 (Shathak) Word docs push IcedID (Bokbot) |
2020-09-18 | Xavier Mertens | A Mix of Python & VBA in a Malicious Word Document |
2020-08-19 | Xavier Mertens | Example of Word Document Delivering Qakbot |
2020-08-07 | Brad Duncan | TA551 (Shathak) Word docs push IcedID (Bokbot) |
2020-07-26 | Didier Stevens | Cracking Maldoc VBA Project Passwords |
2020-07-15 | Brad Duncan | Word docs with macros for IcedID (Bokbot) |
2020-07-13 | Didier Stevens | VBA Project Passwords |
2020-06-10 | Brad Duncan | Job application-themed malspam pushes ZLoader |
2020-05-20 | Brad Duncan | Microsoft Word document with malicious macro pushes IcedID (Bokbot) |
2020-04-06 | Didier Stevens | Password Protected Malicious Excel Files |
2020-03-18 | Brad Duncan | Trickbot gtag red5 distributed as a DLL file |
2020-01-22 | Brad Duncan | German language malspam pushes Ursnif |
2019-12-11 | Brad Duncan | German language malspam pushes yet another wave of Trickbot |
2019-11-01 | Didier Stevens | Tip: Password Managers and 2FA |
2019-10-02 | Brad Duncan | A recent example of Emotet malspam |
2019-09-18 | Brad Duncan | Emotet malspam is back |
2019-07-18 | Xavier Mertens | Malicious PHP Script Back on Stage? |
2019-06-10 | Xavier Mertens | Interesting JavaScript Obfuscation Example |
2019-01-24 | Brad Duncan | Malspam with Word docs uses macro to run Powershell script and steal system data |
2018-12-18 | Brad Duncan | Malspam links to password-protected Word docs that push IcedID (Bokbot) |
2018-12-17 | Didier Stevens | Password Protected ZIP with Maldoc |
2018-11-15 | Brad Duncan | Emotet infection with IcedID banking Trojan |
2018-10-26 | Xavier Mertens | Dissecting Malicious Office Documents with Linux |
2018-08-22 | Deborah Hale | Email/password Frustration |
2018-07-12 | Johannes Ullrich | New Extortion Tricks: Now Including Your Password! |
2018-06-13 | Xavier Mertens | A Bunch of Compromized Wordpress Sites |
2018-01-09 | Jim Clausing | Are you watching for brute force attacks on IPv6? |
2017-11-28 | Xavier Mertens | Apple High Sierra Uses a Passwordless Root Account |
2017-11-07 | Xavier Mertens | Interesting VBA Dropper |
2017-08-17 | Xavier Mertens | Maldoc with auto-updated link |
2017-05-17 | Richard Porter | Wait What? We don?t have to change passwords every 90 days? |
2017-05-05 | Xavier Mertens | HTTP Headers... the Achilles' heel of many applications |
2017-04-26 | Johannes Ullrich | If there are some unexploited MSSQL Servers With Weak Passwords Left: They got you now (again) |
2017-04-23 | Didier Stevens | Malicious Documents: A Bit Of News |
2017-04-10 | Didier Stevens | Password History: Insights Shared by a Reader |
2017-02-07 | Johannes Ullrich | My Password is [taco] Using Emojis for Stronger Passwords |
2017-02-04 | Xavier Mertens | Detecting Undisclosed Vulnerabilities with Security Tools & Features |
2016-12-07 | Xavier Mertens | The Passwords You Should Never Use |
2016-09-15 | Xavier Mertens | In Need of a OTP Manager Soon? |
2016-07-21 | Didier Stevens | Practice ntds.dit File |
2016-06-20 | Xavier Mertens | Using Your Password Manager to Monitor Data Leaks |
2015-12-06 | Mark Hofman | Malware SPAM a new run has started. |
2015-06-26 | Daniel Wesemann | Cisco default credentials - again! |
2015-05-09 | Didier Stevens | Malicious Word Document: This Time The Maldoc Is A MIME File |
2015-03-13 | Guy Bruneau | Blind SQL Injection against WordPress SEO by Yoast |
2015-02-20 | Tom Webb | Fast analysis of a Tax Scam |
2014-11-20 | Johannes Ullrich | Critical WordPress XSS Update |
2014-09-19 | Guy Bruneau | Added today in oclhashcat 131 Django [Default Auth] (PBKDF2 SHA256 Rounds Salt) Support - http://hashcat.net/hashcat/ |
2014-08-22 | Richard Porter | OCLHashCat 1.30 Released |
2014-08-06 | Johannes Ullrich | All Passwords have been lost: What's next? |
2014-07-22 | Daniel Wesemann | WordPress brute force attack via wp.getUsersBlogs |
2014-06-19 | Tony Carothers | WordPress and Security |
2014-05-22 | Rob VandenBrink | Another Site Breached - Time to Change your Passwords! (If you can that is) |
2014-03-14 | Richard Porter | Word Press Shenanigans? Anyone seeing strange activity today? |
2014-03-12 | Johannes Ullrich | Wordpress "Pingback" DDoS Attacks |
2013-11-22 | Rick Wanner | Tales of Password Reuse |
2013-07-21 | Guy Bruneau | Ubuntu Forums Security Breach |
2013-06-11 | Swa Frantzen | Store passwords the right way in your application |
2013-05-14 | Jim Clausing | So what passwords are those ssh scanners trying? |
2013-03-18 | Kevin Shortt | Cisco IOS Type 4 Password Issue: http://tools.cisco.com/security/center/content/CiscoSecurityResponse/cisco-sr-20130318-type4 |
2013-01-18 | Russ McRee | Interesting reads for Friday 18 JAN 2013 |
2013-01-04 | Daniel Wesemann | Blue for Reset? |
2012-11-15 | Jim Clausing | Another month another password disclosure breach |
2012-07-16 | Jim Clausing | An analysis of the Yahoo! passwords |
2012-06-06 | Jim Clausing | Potential leak of 6.5+ million LinkedIn password hashes |
2012-05-22 | Johannes Ullrich | nmap 6 released |
2012-04-21 | Guy Bruneau | WordPress Release Security Update |
2012-01-05 | Russ McRee | WordPress 3.3.1 fixes 15 issues with WordPress 3.3 including XSS. Download 3.3.1 or visit Dashboard --> Updates in your site admin panel. |
2012-01-03 | Rick Wanner | Analysis of the Stratfor Password List |
2011-10-10 | Tom Liston | What's In A Name? |
2011-08-10 | Johannes Ullrich | Theoretical and Practical Password Entropy |
2011-06-30 | Guy Bruneau | WordPress 3.1.4 Security Update - http://wordpress.org/news/2011/06/wordpress-3-1-4/ |
2011-06-28 | Johannes Ullrich | Hashing Passwords |
2011-06-22 | Guy Bruneau | WordPress Forces Password Reset |
2011-05-30 | Johannes Ullrich | Allied Telesis Passwords Leaked |
2011-04-18 | John Bambenek | Wordpress.com Security Breach |
2011-02-08 | Mark Hofman | WordPress 3.0.5 (and 3.1 RC4) are out |
2010-12-30 | Johannes Ullrich | Critcal Wordpress Security Update http://wordpress.org/news/2010/12/3-0-4-update/ |
2010-12-28 | John Bambenek | Mozilla Notifies of Relatively Minor Security Breach |
2010-12-15 | Manuel Humberto Santander Pelaez | HP StorageWorks P2000 G3 MSA hardcoded user |
2010-12-13 | Deborah Hale | Gawker Media Breach of Security |
2010-12-02 | Kevin Johnson | SQL Injection: Wordpress 3.0.2 released |
2010-11-26 | Mark Hofman | Using password cracking as metric/indicator for the organisation's security posture |
2010-08-27 | Mark Hofman | FTP Brute Password guessing attacks |
2010-05-19 | Kyle Haugsness | Wordpress blog attacks... again |
2010-05-10 | Toby Kohlenberg | Another round of WordPress Attacks |
2010-03-30 | Pedro Bueno | Sharing the Tools |
2010-02-25 | Chris Carboni | Pass The Hash |
2010-02-05 | Jim Clausing | WordPress iframe injection? |
2010-02-02 | Johannes Ullrich | Twitter Mass Password Reset due to Phishing |
2009-12-04 | Daniel Wesemann | The economics of security advice (MSFT research paper) |
2009-11-30 | Bojan Zdrnja | Distributed Wordpress admin account cracking |
2009-11-02 | Daniel Wesemann | Password rules: Change them every 25 years |
2009-10-23 | Johannes Ullrich | Little new tool: reversing md5/sha1 hashes http://isc.sans.org/tools/reversehash.html |
2009-10-21 | Pedro Bueno | WordPress Hardening |
2009-08-11 | Swa Frantzen | Wordpress unauthenticated administrator password reset |
2008-11-11 | Swa Frantzen | Phishing for Google adwords |
2008-09-22 | Jim Clausing | Lessons learned from the Palin (and other) account hijacks |
2008-09-09 | Swa Frantzen | wordpress upgrade |
2008-07-17 | Mari Nichols | Adobe Reader 9 Released |
2008-07-09 | Johannes Ullrich | Unpatched Word Vulnerability |
2008-04-23 | Mari Nichols | What's New, Old and Morphing? |