Click here to download all references as Bib-File.•
| 2025-02-19
⋅
CISA
⋅
#StopRansomware: Ghost (Cring) Ransomware Cring |
| 2025-01-30
⋅
CISA
⋅
Contec CMS8000 Contains a Backdoor CMS8000 Backdoor |
| 2025-01-29
⋅
Google
⋅
ScatterBrain: Unmasking the Shadow of PoisonPlug's Obfuscator POISONPLUG ShadowPad SNAPPYBEE |
| 2024-12-17
⋅
SOCRadar
⋅
Dark Peep #17: Dark Web Manifesto, Hacker Forums, and Ransomware Misadventures INDOHAXSEC TEAM |
| 2024-10-16
⋅
CISA
⋅
Iranian Cyber Actors’ Brute Force and Credential Access Activity Compromises Critical Infrastructure Organizations |
| 2024-09-20
⋅
Trend Micro
⋅
How Ransomhub Ransomware Uses EDRKillShifter to Disable EDR and Antivirus Protections RansomHub Water Bakunawa |
| 2024-09-05
⋅
CISA
⋅
AA24-249A: Russian Military Cyber Actors Target US and Global Critical Infrastructure WhisperGate |
| 2024-07-30
⋅
Spamhaus
⋅
Too big to care? - Our disappointment with Cloudflare’s anti-abuse posture |
| 2024-07-29
⋅
Mandiant
⋅
UNC4393 Goes Gently into the SILENTNIGHT Black Basta QakBot sRDI SystemBC Zloader UNC3973 UNC4393 |
| 2024-07-26
⋅
Darktrace
⋅
Disarming the WarmCookie Backdoor: Darktrace’s Oven-Ready Solution WarmCookie |
| 2024-07-16
⋅
JPCERT/CC
⋅
MirrorFace Attack against Japanese Organisations LODEINFO NOOPDOOR |
| 2024-05-10
⋅
CISA
⋅
AA24-131A: #StopRansomware: Black Basta Black Basta Black Basta |
| 2024-04-10
⋅
0ffset Blog
⋅
Resolving Stack Strings with Capstone Disassembler & Unicorn in Python Conti |
| 2024-04-04
⋅
Mandiant
⋅
Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies BRICKSTORM TONERJAM |
| 2024-04-04
⋅
Mandiant
⋅
Cutting Edge, Part 4: Ivanti Connect Secure VPN Post-Exploitation Lateral Movement Case Studies BRICKSTORM TONERJAM UNC3569 UNC5266 UNC5291 UNC5330 UNC5337 UTA0178 |
| 2024-03-29
⋅
CISA
⋅
Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094 xzbot |
| 2024-03-20
⋅
CISA
⋅
Review of the Summer 2023 Microsoft Exchange Online Intrusion Storm-0558 |
| 2024-02-07
⋅
CISA
⋅
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure ScanLine |
| 2024-02-07
⋅
CISA
⋅
MAR-10448362-1.v1 Volt Typhoon ScanLine |
| 2024-01-15
⋅
Russian Panda Research Blog
⋅
From Russia With Code: Disarming Atomic Stealer AMOS |