Cobalt Strike & Metasploit Tools Were Attacker Favorites in 2020
Research reveals APT groups and cybercriminals employ these offensive security tools as often as red teams.Cobalt Strike and Metasploit were the offensive security tools most commonly used to host...
The US Capitol was breached by rioters. What has to happen next?
When drawing up plans for IT security in the US Congress, Congressional tech employees most likely didn’t have an attack by hundreds, if not several thousand, irate supporters of...
United States suspends French tariffs over digital services tax
The United States has indefinitely suspended 25% tariffs on French cosmetics, handbags and other imports it had planned in retaliation for a digital services tax Washington says will harm...
Kill, laugh, love: what should we do with deepfakes?
2020 was an impressive year in many ways but one. We haven’t seen social order destroyed by deepfakes, an AI-powered media manipulation technique. The tech carries a nuclear potential...
Retrohunting APT37: North Korean APT used VBA self decode technique to inject RokRat
A North Korean threat group has swapped the usual Hangul Office lures for a cleverly packed Office macro.
This post was authored by Hossein Jazi
On December 7 2020 we...
DoJ’s Microsoft 365 Email Accounts Compromised in SolarWinds Attacks
Enterprise VulnerabilitiesFrom DHS/US-CERT's National Vulnerability Database
CVE-2020-25498PUBLISHED: 2021-01-06Cross Site Scripting (XSS) vulnerability in Beetel router 777VR1 can be exploited via the NTP server name in System Time and "Keyword" in...















