Skip to content

Intel

  • Blog
  • About
  • Admin
  • Categories
    • X
    • Telegram
    • GitHub
    • Bluesky
  • July 31, 2025

    KAWA4096’s Ransomware Tide: Rising Threat With Borrowed Styles

    KAWA4096, a ransomware whose name includes “Kawa”, the Japanese word for “river”, first emerged in June 2025. This new threat features a leak site that follows the style of the Akira ransomware group, and a ransom note format similar to Qilin’s, likely an attempt to further enrich their visibility and credibility. In this blog post,…

    Cybersecurity, Security, Vulnerabilities
    #cybersecurity, #penetration_testing, #security, #vulnerability
  • July 31, 2025

    The Breach Beyond the Runway: Cybercriminals Targeted Qantas Through a Trusted Partner

    On July 3, 2025, Qantas confirmed in an update statement that a cyber incident had compromised data from one of its contact centers, following the detection of suspicious activity on June 30. The breach didn’t strike at the heart of Qantas’ systems; it snuck in through a third-party provider. Go to Source

    Cybersecurity, Security, Vulnerabilities
    #cybersecurity, #penetration_testing, #security, #vulnerability
  • July 31, 2025

    Tracing Blind Eagle to Proton66

    Trustwave SpiderLabs has assessed with high confidence that the threat group Blind Eagle, aka APT-C-36, is associated with the Russian bulletproof hosting service provider Proton66. Blind Eagle is a threat actor actively targeting organizations across Latin America, with a notable focus on Colombian financial institutions. Go to Source

    Cybersecurity, Security, Vulnerabilities
    #cybersecurity, #penetration_testing, #security, #vulnerability
  • July 31, 2025

    CVE-2025-20281: Cisco ISE API Unauthenticated Remote Code Execution Vulnerability

    On January 25th, 2025, the Trend Zero Day Initiative (ZDI) received a report from Kentaro Kawane of GMO Cybersecurity by Ierae regarding a deserialization of untrusted data vulnerability in Cisco Identity Services Engine (ISE). This pre-authentication vulnerability existed in the enableStrongSwanTunnel method of the DescriptionRegistrationListener class. While analyzing this vulnerability, I noticed that the same…

    Cybersecurity, Security, Vulnerabilities
    #cybersecurity, #security, #zero_day
  • July 31, 2025

    Trustwave SpiderLabs’ 2025 Risk Radar Report: Technology Sector

    Explore key insights from Trustwave SpiderLabs’ latest report on securing tech firms against evolving cyber threats. Discover how ransomware attacks are impacting technology companies and learn about the most prolific threat actors in 2025.  Find out the best practices and mitigation strategies technology organizations can adopt to enhance their cybersecurity defenses. Threat actors know that…

    Cybersecurity, Security, Vulnerabilities
    #cybersecurity, #penetration_testing, #security, #vulnerability
  • July 31, 2025

    CVE-2025-4919: Corruption via Math Space in Mozilla Firefox

    In recent years, there has been an increase interest in the JavaScript engine vulnerabilities in order to compromise web browsers. Notably, vulnerabilities in JIT engines are among the most favorite ones as it provides strong primitives and well-known techniques are already available to facilitate compromise. At Pwn2Own Berlin 2025, Manfred Paul compromised the Mozilla Firefox…

    Cybersecurity, Security, Vulnerabilities
    #cybersecurity, #security, #zero_day
  • July 31, 2025

    Dire Wolf Strikes: New Ransomware Group Targeting Global Sectors

    Dire Wolf is a newly emerged ransomware group first observed in May 2025 and Trustwave SpiderLabs recently uncovered a Dire Wolf ransomware sample that revealed for the first time key details about how the ransomware operates. Go to Source

    Cybersecurity, Security, Vulnerabilities
    #cybersecurity, #penetration_testing, #security, #vulnerability
  • July 31, 2025

    The Attack Vector: Database Triggers as Persistence Mechanisms

    Organizations often assume that restoring a backup to a patched environment eliminates threats. However, backups encapsulate both data and schema objects, including triggers. A compromised backup, often taken after an initial breach, may contain hidden triggers that reactivate the attacker’s access upon restore. This post explores how malicious triggers in compromised backups can serve as…

    Cybersecurity, Security, Vulnerabilities
    #cybersecurity, #penetration_testing, #security, #vulnerability
  • July 31, 2025

    The July 2025 Security Update Review

    It’s the second Tuesday of the month, and as expected, Adobe and Microsoft have released their latest security patches. Take a break from your scheduled activities and join us as we review the details of their latest security alerts. If you’d rather watch the full video recap covering the entire release, you can check it…

    Cybersecurity, Security, Vulnerabilities
    #cybersecurity, #security, #zero_day
  • July 31, 2025

    Extracting Embedded MultiMediaCard (eMMC) contents in-system

    Every complex modern device needs non-volatile storage to keep program and configuration data while unpowered. There are several competing options on the market available to today’s systems designers: serial Flash, raw NAND chips, (micro)SD, and Embedded MultiMediaCard (eMMC). eMMC is the topic of this discussion, and specifically how to interact with it without removing the…

    Cybersecurity, Security, Vulnerabilities
    #cybersecurity, #security, #zero_day
Previous Page
1 … 116 117 118 119 120 … 243
Next Page

Designed by Alireza Gharib